PRIVACY POLICY
Last updated: April 18, 2025
OnomaAI, Inc. (hereinafter “Illustrious,” the “Company,” “we,” or “us”) values the privacy of our users and is committed to protecting personal information. This Privacy Policy explains what information we collect through our AI generative service (the “Service”), how we use and protect that information, and the rights you have to your personal information.
You must be 18 years of age, or the age of majority in your province, territory or country to use our Services or create an account on our Services. By using Illustrious, you represent and warrant that you meet this requirement and that you agree to the practices described in this Policy. If you do not agree, please discontinue use of the Service.
1. Information We Collect and How We Collect It
Categories of Information that We Collect
The types of personal information we collect when you use our Services includes, but is not limited to, the following:
Identifying information (e.g., name)
Contact information (e.g., email address)
Location information (information regarding user’s region when processing payment)
Payment and billing information
Transactional information (e.g., details about payments made to and from you, other details of products and services you have purchased from us, etc.)
Usage information (e.g., information about how you use our Services, interests, preferences, feedback and survey responses, actions you take using your account, access history, record of unauthorized usages, etc.)
Marketing and communication information (e.g., your communication preferences, and your preferences in receiving marketing from us, etc.)
Automatic Data Collection
Device and Log Information: When you access Illustrious, we automatically collect technical information such as your device type, operating system, browser type, IP address, timestamps of usage, and basic usage logs (e.g., pages or screens viewed, interactions).
Cookies and Similar Technologies: We use a minimal set of cookies or similar technologies to maintain session status (e.g., keep you logged in) and remember your preferences. We do not use them for advertising or tracking you across third-party sites. You can disable cookies through your browser, but certain features (like staying logged in) may not function properly.
No Collection of Sensitive Data
We do not collect biometric data (fingerprints, facial recognition), voice recordings, government-issued IDs or financial information unless you explicitly consent for a specific purpose. In general, we do not request or require such information, and we ask you not to provide it.
Information We Receive from Other Sources
On occasion, we may combine or compare information we have collected from you with information collected from other third-party sources and add it to the information you have provided.
Third parties that are unaffiliated with us may also collect information about you, including tracking your browsing history, when you use our Service. We do not have control over these third-party collection practices and advise you to adjust the settings of your browsers or install plug-ins and add-ins if you wish to minimize these third-party collections.
2. Purpose of Collecting and Using Personal Information
We use your personal information for the following purposes:
Providing and Improving the Service:
Generate AI outputs from your inputs
Maintain and enhance existing features
Debug and optimize performance
Account Management and Authentication
Create and manage your account.
Verify account credentials.
Send administrative notices (account confirmations, password resets, etc.).
Customer Support and Communications:
Respond to support inquiries.
Inform you of significant changes to the Service or this Privacy Policy.
We do not send marketing emails unless you opt in.
Service Improvement and Research (with Consent):
If you opt in to share prompts or generated content for AI improvement, we handle that data in anonymized form and store it separately from account data.
Security and Fraud Prevention:
Detect and prevent abusive or unlawful activity (e.g., suspicious logins).
Ensure the integrity of the Service and protect user accounts.
Legal Compliance:
Fulfill obligations under applicable laws and regulations.
Respond to lawful requests from authorities or courts.
Enforce our Terms of Service and defend legal claims.
Ensure the integrity of the Service and protect user accounts.
If we need to use your personal information for new purposes not covered by this Policy, we will request additional consent or provide appropriate notice.
3. Disclosure of Personal Information to Third Parties
We do not sell or rent your personal information to third parties. We disclose it only under the following circumstances:
With Your Consent
You specifically authorize us to share certain information (e.g., integration with an external partner).
Service Providers Processing on Our Behalf:
Data center/cloud hosting providers.
Email or customer support services.
These providers act under our direction, are contractually obliged to protect your data, and cannot use it for unrelated purposes.
Legal Obligations and Safety
Comply with a subpoena, court order, or other valid legal process.
Protect our rights, property, or safety, or that of others (e.g., investigating fraud or abuse).
Business Transfers
In the event of a merger, acquisition, or sale of assets. Your information would remain subject to this Privacy Policy or a comparable policy.
No Third-Party Advertising or Analytics:
We do not use external advertising networks that collect personal data for marketing or profiling.
We do not implement external trackers that follow you outside the Service.
No Sale of Personal Information:
We do not sell personal information. There is no need for an opt-out mechanism for “data sales” under Delaware law, because no such activity takes place.
Furthermore, we entrust the following personal information processing tasks to the third-parties listed below in order to provide you with the Services:
/table
4. Your Rights to Your Personal Information
You have control over your personal information and how it is collected, used, and shared by the Company. As a user of our Services, you may exercise the following rights concerning your personal information:
Right of Access: You can request confirmation of whether we are processing your personal information. You can obtain a copy of your data, including the categories of personal information, the purposes of processing, and the third parties to whom your data has been disclosed.
Right to Rectification (Correction): You can request that we correct inaccurate or incomplete personal information we maintain about you.
Right to Erasure (Deletion): You can request deletion of your personal information when it is no longer needed for the purpose for which it was collected, if you withdraw consent (where consent was the basis of collection), or under other circumstances specified by applicable laws. When we comply with a deletion request, we will also instruct our service providers that process your personal information on our behalf to delete it, unless a legal requirement or exception allows retention.
Right to Withdraw Consent: Where our processing relies on your consent (e.g., you opted in to share content for research), you may withdraw that consent at any time. Processing completed before withdrawal remains lawful.
Right to Data Portability: You can request a copy of the personal information you previously provided to us in a portable, readily usable format that allows you to transmit the data to another organization without hindrance (when processing is carried out by automated means based on your consent or a contract).
Right to Opt-Out of Certain Processing: You may opt out of:
The processing of personal information for targeted advertising.
The sale of personal information (note: as stated elsewhere, we do not sell personal information).
Profiling that produces legal or similarly significant effects concerning you.
Exercising Your Rights
How to Submit a Request: To exercise any of the above rights, please email us at illustrious@onomaai.com.
Verification: We may require you to provide information verifying your identity to ensure the security of your data. We will outline the verification process when you contact us.
Response Time: We strive to respond to verifiable consumer requests without undue delay. Please note that we may deny your request if there is a legitimate reason prescribed by law.
Right to Appeal: If we decline to take action on your request, we will notify you with the reason for the refusal and explain how you may appeal our decision.
5. Retention and Use Period of Personal Information
We keep personal information only as long as necessary to fulfill the purposes for which it was collected or as required by law. Examples:
Account Information: Retained while your account is active. If you delete your account, we remove or anonymize associated personal information unless legal obligations require further retention.
Usage Logs: Retained for a limited time for operational or security analysis. Anonymized or aggregated data may be retained longer.
User-Provided Content: Processed in real time and not stored unless you choose to save it in your account. If you opt in to share your Generated Content for improvement, we store that content in anonymized form.
Legal Compliance: Where applicable laws require retention (e.g., financial records, legal proceedings), we retain only as long as necessary and securely isolate that data.
After retention periods end or upon your valid deletion request, we securely delete or anonymize data according to our internal protocols.
6. Destruction of Personal Information
When personal information is no longer needed or you request deletion, we follow secure procedures:
Destruction Procedure:
Mark data for deletion in our databases and systems.
Ensure service providers also delete or return the data if they process it on our behalf.
Methods:
Electronic Data: Use industry-standard deletion or overwriting methods so that data cannot be reconstructed.
Physical Documents: Shred, incinerate, or otherwise destroy paper records containing personal information.
Timing:
Periodic automated processes handle routine data deletion.
Deletion requests are fulfilled as promptly as possible, typically within 30 days unless there is a legal basis for retention.
7. Security Measures
We implement technical, administrative, and physical safeguards to protect personal information from unauthorized access or disclosure:
Encryption: Use SSL/TLS to encrypt data during transmission. Passwords are encrypted or hashed at rest.
Access Control: Limit data access to employees/contractors who need it for their job duties. Require secure authentication (e.g., multi-factor).
Network Security: Maintain firewalls, intrusion detection, and patch management on our servers.
Training Policies: Provide staff with privacy/security training; enforce internal policies on data handling.
Regular Audits: Conduct periodic reviews and testing to improve our defenses.
No transmission method is 100% secure, but we continuously update these measures to align with industry best practices. In the event of a breach affecting your data, we will notify you and relevant supervisory authorities as required by applicable law.
You are responsible for ensuring the security of your personal information. This includes choosing a sufficiently strong password and keeping your credentials, including your password, confidential at all times. You are also obligated to respect the privacy and personal information of others and must not infringe upon or misuse third-party personal information. Please avoid disclosing your personal information, such as your password, and refrain from actions that may harm or compromise the personal information or privacy of others.
While we employ rigorous security measures to protect your personal information, we will not be liable for any loss, unauthorized access, or misuse of your personal information that results from your own actions, such as failing to secure your account or sharing your password with others. It is your responsibility to safeguard your personal information and respect the privacy and security of others.
It is equally important that the personal information we hold about you is accurate and up to date. Please notify us promptly if any of your personal information changes during your use of our Services, to help us maintain the accuracy and integrity of the information. We will not be liable for any loss, unauthorized access, or misuse of your personal information that occurs as a result of your failure to promptly update your personal information.
8. Children's Privacy
You must be 18 years of age, or the age of majority in your province, territory or country to use our Services or create an account on our Services. We do not knowingly collect personal information from such minors.
No Use by Minors: If you are under 18, or the age of majority in your province, territory, or country, do not use Illustrious.
If a Minor Registers: We will promptly delete any data from an underage user once discovered.
Parental Inquiries: If you believe we have inadvertently collected a minor’s data, please contact illustrious@onomaai.com
Region Specific Notices
Out of respect for your privacy, we have implemented additional measures to comply with the obligations and rights associated with the collection of personal information as dictated by the laws governing the regions of our users.
Disclosures for residents of California
If you are a resident of California, you have certain rights and we aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your personal information. This supplemental section, together with other relevant sections of this Privacy Policy, provides information about your rights and how to exercise them under the California Consumer Privacy Act and the California Privacy Rights Act (collectively, “CCPA”), and any and all regulations arising therefrom. Unless otherwise expressly stated, all terms in this section have the same meaning as defined in the CCPA.
Right to know and right to access: You have the right to request certain information we have collected about you. Once we receive and confirm a verifiable request from you, we will disclose to you, to the extent permitted by law:
The categories of personal information we collected about you.
The purposes the categories of personal information are collected or used for.
The specific pieces of personal information we hold about you.
The categories of sources from which Information about you is collected.
The purposes for collecting, selling, or sharing your personal information.
Right to data portability: You have the right to request that the personal information is delivered in a format that is both portable and easily usable, as long as it is technically possible to do so.
Right to correct: You have the right to request that we correct your inaccurate personal information taking into account the nature of the personal information and the purposes of the processing of the personal information.
Right to delete: You have the right to request deletion of your personal information.
Right to opt-out of the sale and sharing:  You have the right to opt-out of the sale of your personal information which may include selling, disclosing, or transferring personal information to another business or a third-party for monetary or other valuable consideration.
Right to limit the use of your personal information:  You have the right to restrict our use of your personal information and disclosure solely to what is essential for carrying out or delivering the Services or operating the Website in a manner reasonably anticipated by an average user, or for certain business objectives as specified by law. However, we do not use personal information for any purposes other than those legally permitted or beyond the scope of this Privacy Policy.
Right to limit the use of your sensitive personal information:  If we collect any sensitive personal information, you have the right to limit our use and disclosure of your sensitive personal information to that which is necessary to perform our services or provide goods as reasonably expected.
Right to non-discrimination:  You have the right to not be discriminated against in the Services or quality of Services you receive from us for exercising your rights. We may not, and will not, treat you differently because of your data subject request activity, or charge different rates for goods or Services, or suggest that we would treat you differently because of your data subject request activity.
Shine the Light:  California residents that have an established business relationship with us have the right to know how their personal information is disclosed to third parties for their direct marketing purposes under California’s “Shine the Light” law, or the right to opt out of such practices.
To exercise any of your rights, simply contact us at illustrious@onomaai.com. After we receive and verify your request, we will process it to the extent possible within our capabilities.
Disclosures for residents of the United Kingdom
Lawful Management of Personal Information under the UK General Data Protection Regulation (UK GDPR): We process your personal information under the following conditions.
You are explicitly consenting to the use and processing of your personal information.
The processing is necessary for executing a contract that you are a part of or for initiating steps required by a you before entering into a contract. This may involve member management, identification, service provision, payment, and settlement of fees, among others. 
The processing is a legal requirement for the Company, such as adherence to relevant legislation, rules, legal procedures, or governmental requests. 
The processing is crucial to protect users or other individuals' vital interests, for example, detecting, preventing, and responding to fraud, abuse, security threats, and technical issues that could harm users or other individuals. 
The processing is necessary for a task conducted in public interest or in the execution of official authority given to the Company. 
The processing is essential for the legitimate interests pursued by the Company or by a third party, except where such interests are overridden by the interests or basic rights and freedoms of the data subject, especially where the data subject is a child. 
Rights of Users: Users or their legal representatives have the following rights in relation to the collection, use, and disclosure of personal information by the Company:
Right to access personal information: Users or their legal representatives can request access to their data and verify the records of the collection, usage, and sharing of their data under the law.
Right to correction:  Users or their legal representatives can request corrections for any inaccurate or incomplete data.
Right to deletion:  Users or their legal representatives can request the deletion of their data after the completion of its purpose and the revocation of their consent.
Right to restrict processing:  Users or their legal representatives can request a temporary suspension of data processing in the event of disputes over data accuracy and the legality of data processing, or if data retention is necessary.
Right to data portability:  Users or their legal representatives can request the provision or transfer of their data.
Right to object:  Users or their legal representatives can object to data processing if the data is used for direct marketing, legitimate interests, official duty execution, and research and statistics.
Right to avoid automated individual decision-making, including profiling:  Users or their legal representatives can request to stop automated processing of personal information, including profiling, which significantly impacts or can legally affect them.
Data Transfer Across Borders: Given the Company's worldwide operations, users' personal information may be shared with entities in other countries for explicitly stated purposes in this Policy. In regions where personal information is transferred, stored, or processed, the Company enforces adequate measures to protect the data. If personal information from the United Kingdom is used or disclosed, the Company will employ measures or secure user consent following the UK GDPR regulations, such as using a standard contractual clauses, or ensuring suitable safeguards, such as transferring only to countries that have obtained adequacy status by the Secretary of State.
10. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. When we make material changes:
Notice: We will post a prominent notice on our site or email users (for material updates) before the revised Policy becomes effective.
Consent: If we need new or additional consent (e.g., for collecting new data types), we will request it before implementing such changes.
Effective Date: The date at the top of this Policy indicates when the latest version took effect. Continued use of the Service after the effective date means you accept the updated Policy.
11. Contact Information
If you have questions or concerns about this Privacy Policy, or wish to exercise any privacy rights under Delaware law, please contact us:
Company Name: OnomaAI, Inc.
Address: 32, Maeheon-ro 16-gil, Seocho-gu, Seoul, 06770, Rep. of KOREA
Email: illustrious@onomaai.com
Data Protection Officer (DPO): You may address any privacy-related inquiries to our DPO at the email above, or by mail addressed to “Data Protection Officer.”
When you make a request, we may ask for additional information to verify your identity. We will respond within a reasonable timeframe (generally within 30 days), or as required by law.
Thank you for using Illustrious. We strive to uphold strong privacy protections for our users and comply with Delaware law. If you have any questions, please reach out to us.

by Onoma AI

Address : 201, 2F, D-dong, 47, Maeheon-ro 8-gil, Seocho-gu, Seoul, 06770, Rep. of KOREA

Business Registration Certificate : 450-86-02454

CEO : Min Song

Contact : illustrious@onomaai.com