Privacy Notice.
Notice at collection
Altifigence processes information supplied through account registration, sign-in, checkout, product workspaces, support, and legal or security communications, together with technical records needed to operate and protect those services. Paddle processes eligible online orders as Merchant of Record. The public site does not load advertising pixels or advertising profiles.
Information collected
Depending on the feature used, information may include name, email, organization, country or region, authentication and security metadata, plan and entitlement status, Paddle transaction identifiers, currency, tax and receipt data, support or legal messages, and customer content that you deliberately submit to a Cloud, AI, synchronization, or support feature.
Hosting and security systems may create records such as IP address, request time, URL, user agent, response status, session integrity signals, and abuse-prevention events. Essential browser storage maintains language, acknowledgement, account-session, request-integrity, security, and checkout continuity.
Purposes of use
Altifigence uses information to create and protect accounts, authenticate users, provide selected product and workspace features, manage subscription and feature access, deliver public downloads, reconcile orders and refunds, answer requests, prevent misuse and meet legal, tax, accounting and contractual duties.
Consent records and notice versions
Clarification dated 4 October 2026.
At sign-up, we record agreement to the terms, acknowledgement of the privacy notice, the sign-up notice version and the time. The sign-up notice version identifies that notice; it is separate from the revision of each linked legal document. Checkout separately presents the order, payment and renewal terms and Paddle buyer and privacy notices. Publishing a revised legal page does not itself mean you accepted it or authorized another payment. Optional marketing and analytics choices are separate from the required sign-up choices and can be withdrawn through their respective controls.
Account and organization management explanation: 2026-09-30
This supplement explains the Account features described below when they are offered. Existing orders, statutory rights and purpose-specific retention duties continue to apply. Material changes to an existing contract still require the applicable notice and consent process.
Organization membership and permissions
When you use organization administration, Account processes member and invitation identifiers, names and email addresses, organization membership, group membership, roles and permission assignments, and records of management actions. These records support invitations, access control, administration and review of security-related changes. Audit entries identify the acting account, the action, its target, its outcome and its time; they may include relevant change details.
Members with the required permissions can view or manage the corresponding membership, invitation, group, role or audit information for their organization. Access is limited to the authorized organization and function. A group or role assignment does not authorize access to another organization's information, or enable an external institution's SSO or SCIM connection.
Optional marketing email
Account preference and browser-memory notice version: 2026-09-21. These options apply when the corresponding feature is offered; this notice does not enroll existing accounts.
Altifigence (알티피전스), 160 Landmark-ro, Yeonsu-gu, Incheon, Republic of Korea, asks separately for permission to use your account email for its product news and offers and permission to send those marketing emails. Both choices are off by default; you can create and use an account without either. No other personal information is used for this marketing purpose. The marketing use lasts until you withdraw either choice or close your account. Consent choices, notice version, source and time are recorded to demonstrate and respect your decision; they are not permission to continue marketing after withdrawal.
Change or withdraw your choices without charge in Altifigence Account → Preferences → Marketing email, or contact contact@altifigence.com. Security, account and necessary service messages are separate. Changing your account email resets both marketing choices. Marketing delivery is not enabled by the preference feature alone; any future marketing email must identify Altifigence, include a working unsubscribe method that does not require sign-in, and check your current permission before sending. This optional consent does not replace other applicable privacy rights or legal bases for account processing.
Signed-in accounts on this browser
Browser-session notice updated 4 October 2026. Auth shows only accounts with a valid authentication session in this browser's account chooser. Browser sessions follow a 30-day inactivity limit. Where session renewal is available, the service may extend the deadline after verifying activity in a visible, focused page; restoring a cookie or keeping a background page open does not revive an expired or revoked session. The server checks the central Auth session and each linked service session separately. Account-selection data is held in an encrypted, host-only, HttpOnly, Secure, SameSite=Lax cookie on auth.altifigence.com. Essential authentication cookies may persist for up to 30 days. Browser settings, cookie removal, sign-out or a security action may end access sooner. Expired or revoked accounts are removed on the next validation. Removing an account also revokes its associated central session. This does not authorize marketing or analytics, share cookies with other sites, or change product permissions. Additional authentication may still be required for sensitive actions. Remove each account after using a shared device.
Public downloads
A public installer download does not require an account or payment information. Files released through the official pipeline are served by Cloudflare from controlled storage. Requests can generate IP, time, requested path, user-agent, response and abuse-prevention records, including rate-limit checks. Public access does not mean anonymous network traffic or an absence of security records.
Service providers and sharing
Cloudflare, Inc. provides hosting, storage and security for the selected account and Cloud features and processes the account identifiers, request and security metadata, and customer content needed by those features. The Paddle entity identified at checkout receives buyer, billing and payment information to handle eligible online orders as Merchant of Record. Authentication, email, repository, accounting and other providers are used as needed for the selected service or legal duties. Altifigence does not sell personal information or share it for cross-context behavioral advertising.
When you choose an AI or Cloud feature, the submitted conversation, selected project context or job inputs may contain design source and other customer information. Cloudflare provides hosting, security and API transport; a selected compute route may use Google Cloud. AI-provider connections can include OpenAI, Anthropic, xAI and Z.ai, according to the connection you select and the feature available to your account. Provider billing, processing and retention can also be governed by your own provider agreement. Customer content, API keys and AI data handling.
International processing
Infrastructure, payment and selected AI providers may process data outside your country. Do not assume that a local app, a Korean-language page or an API-key connection keeps every request in Korea. Where applicable law requires transfer-specific disclosure, consent or safeguards, those requirements apply to the relevant feature and contract; accepting these general terms is not blanket consent to every overseas transfer. Contact contact@altifigence.com for a privacy or transfer-related request.
Plugin and external-tool data
Developer integration clarification updated: October 3, 2026
The data handled by an external tool or plugin depends on the actual integration and its permissions. Before choosing to use one, check the publisher's privacy notice, the files and credentials it can access, any external recipients, and the applicable storage and transfer conditions. Where an Altifigence integration handles personal information, this Privacy Notice and the applicable feature notice continue to apply; a third-party notice does not remove Altifigence's responsibilities for its own processing.
Reading documentation, viewing a catalog, or obtaining SDK/example source is not consent for a tool to read project files, execute programs, use credentials, or transmit data. Such access must have the required authorization for the actual feature and data. Public examples and issue reports should not contain credentials, personal information, confidential designs, or other restricted material. Plugin and external-tool availability and licenses.
Privacy requests and user rights
Privacy-related requests may be sent to contact@altifigence.com. Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Identity verification may be required before action is taken, and legal, security, tax, accounting, contract, and IP evidence records may need to be retained.
You may separately request access, correction, deletion, restriction or withdrawal of consent while automatic account closure needs further review. An unresolved payment, refund, dispute or product connection is not a blanket refusal of these rights. Requests are checked individually under applicable law, and any limitation and its reason are explained through the privacy-request route: contact@altifigence.com.
Account closure and personal information
Request account closure in Altifigence Account. Successful closure ends account sign-in, revokes authentication sessions and withdraws the account's marketing-email choices. The personal profile and primary and additional account-email records held by the Account identity service, authentication credentials, linked social identities and OAuth grants are deleted as part of closure. A minimal closed-account identifier and closure-processing evidence remain to record that the identity is closed and prevent old sessions or credentials from restoring access; they are not an active personal profile.
Necessary transaction, refund, dispute, security and request-processing evidence is handled according to its specific purpose and applicable legal basis. Shared-organization invitation and membership history may remain, and earlier security and administration audit entries may contain account identifiers and relevant prior change details, including email copies. Closure does not authorize continued marketing. Information that must be preserved under another law is stored and managed separately from active-account information, with restricted access. Personal information is destroyed without delay when it is no longer needed and no applicable retention ground remains. This notice does not set one retention period for every record or promise immediate deletion from every protected backup or independent provider.
Account closure does not by itself cancel subscription renewal or delete an organization's or connected product's data. The Account page explains what needs separate handling before automatic processing. Account closure guidance.
Retention
Information is kept only as long as reasonably needed for the stated purpose and applicable legal, tax, accounting, security, support, dispute, and audit duties. Account and entitlement records may remain while an account or subscription is active; commerce and consumer-dispute records are retained for the periods required by applicable law. Data is deleted or de-identified when those purposes and duties end, subject to protected backup rotation.
Cloud active-time analytics
Cloud analytics addendum: 4 October 2026. Notice: cloud-privacy-20261004. Optional analytics stays off until you separately confirm adult eligibility and agree to analytics and international processing under this notice. Historical usage is not backfilled.
For overall Cloud product improvement, consenting adults' first-party account identifiers and completed one-minute active-time samples contribute to account-linked daily totals for Digital Design Studio, ALcad and shared Cloud screens. These are personal data, not anonymous statistics. Measurement requires a visible, focused page and recent trusted interaction, with a small batch at most every five minutes per open window. Authorized staff see only whole-product totals for completed UTC days, rounded down to 15 minutes; product/day values with fewer than five contributing accounts are hidden. Individual durations and last-active times are not provided. Estimates are not billing records or live presence.
Minors are excluded. Before choosing analytics, you must separately confirm that you are at least 19 years old and legally an adult where you live; we do not request or store a birth date or identity document for this self-declaration. It is not verified age. Windows and Linux local apps, Business accounts and members of Business or Enterprise-contract organizations are also excluded. This analytics contract does not record raw IP addresses, full URLs, project or file paths, source code, chat contents, or keystroke contents. Security and service/billing records are separate and are not converted into active-time analytics.
Account-linked daily contributions expire within 30 days and are excluded from reports after expiry; scheduled cleanup removes expired rows. A product watermark used only to prevent duplicate delivery expires after seven minutes and is removed by the next successful cleanup. Turning analytics off deletes your operational analytics contributions and blocks new collection. Your current choice is kept for the life of your account. A separate minimal consent receipt binds the adult self-declaration and separately confirmed analytics and international-transfer choices to the notice version, revision and time. A valid consent receipt is kept while that consent remains current; withdrawal, replacement or loss of eligibility retires it. Retired receipts, including withdrawal receipts, expire after 30 days and are deleted by the next successful scheduled cleanup even while collection is disabled. Earlier receipts cannot reactivate consent. New manual backups exclude analytics records, preferences and consent receipts. Deletion from D1 Time Travel recovery copies is not instantaneous: a deleted record may remain there for up to 30 additional days. Older backups and recovery copies must be restored with collection disabled, analytics data and preferences cleared, and fresh consent required before collection resumes. Unrelated security and billing records are not deleted by this control. The separate international-processing disclosure below applies to this feature.
Adult confirmation, optional analytics consent and international-transfer consent each start unchecked. Refusing or withdrawing does not affect product access, quota or pricing. An earlier notice cannot supply these new choices; ordinary software updates do not reset a valid current choice. Global Privacy Control and Do Not Track block collection in that browser. Manage your choice and delete your analytics contributions in Settings > Privacy: Cloud Privacy settings.
Altifigence operates optional analytics on specific, revocable consent. General terms, signup, login and opening the setting are not consent. Privacy requests are handled at contact@altifigence.com. You may request access, correction, deletion or cessation of processing. This feature is not used for advertising profiles, individual work evaluation or automated decisions with legal or similarly significant effects. The separate international-processing disclosure and choice are below.
Optional Cloud analytics: international processing
This disclosure covers only optional Cloud analytics, not every Altifigence service or every Cloudflare product. It identifies the current provider processing scope using our configuration and Cloudflare's public service documents, checked 4 October 2026. Consent is requested separately from analytics and general terms; this page does not grant it.
Recipient and contact | Cloudflare, Inc. (United States), privacyquestions@cloudflare.com, processes infrastructure data for Altifigence. Our privacy contact and rights-request point is contact@altifigence.com. Cloudflare may use the service-specific infrastructure and authorized support subprocessors described below; we do not send this feature's records to its AI Gateway, Workers AI or advertising vendors. |
|---|---|
Items and purpose | Account identifier; Cloud/Digital Design Studio/ALcad product category; completed minute samples and account-linked daily totals; short-lived duplicate-prevention watermark; analytics choice, adult self-declaration, separate transfer-consent evidence bound to this notice, revision and time. Cloudflare Workers processes requests and D1 stores these records to provide the optional product-improvement statistics and honor choices, deletion and recovery controls. No birth date or identity document is collected. |
Timing and method | The setting request is transmitted when you make or withdraw a choice. Analytics is sent only after current consent, in small encrypted HTTPS batches at most once every five minutes per open, active Cloud window. Cloudflare service bindings connect the edge and Account owner; data is encrypted in transit and at rest. Necessary security and service traffic exists independently of this optional analytics. |
Countries and locations | Our current D1 primary was observed in Singapore, with Asia-Pacific placement, no jurisdiction restriction and read replication disabled. APAC is a placement setting, not a Singapore-only residency promise. Requests use Cloudflare's global network; the possible edge-processing countries and territories are listed below. The Developer Platform subprocessor list names the United States, Australia, India, United Kingdom, Japan, Canada, Singapore and the EEA countries listed below. Authorized affiliate engineering/support locations also include South Korea, Germany, Portugal, France, Netherlands, United Arab Emirates, Mexico, Malaysia, Sweden and Switzerland. These are possible processing/support locations, not a claim that each record is stored in all of them. |
Retention and recovery | Daily analytics contributions: up to 30 days; duplicate watermark: seven minutes, then the next successful cleanup. Current choice: account lifetime. A current consent receipt: while valid; retired or withdrawal receipts: 30 days, then the next successful cleanup. D1 Time Travel can retain a deleted record for up to 30 additional days. New manual R2 backups exclude all five analytics, preference and receipt tables' data. R2's APAC placement and incomplete-upload cleanup do not establish expiry of older completed backups. Older backup contents are not claimed to be inspected or erased; recovery requires collection OFF, analytics and preferences cleared, and fresh consent before restart. |
Refuse or withdraw | Leave either optional consent unchecked, cancel, or turn the toggle off in Cloud Settings > Privacy. Turning off deletes operational analytics contributions and stops new collection; recovery-copy expiry is not instantaneous. You can also request withdrawal or deletion at contact@altifigence.com. Refusal or withdrawal leaves service access, quota, prices and necessary security/billing records unchanged. |
Named processing locations and source documents
Global edge countries/territories
United States (US), Canada (CA), Brazil (BR), Chile (CL), Paraguay (PY), Colombia (CO), Barbados (BB), Argentina (AR), Guyana (GY), Mexico (MX), Guatemala (GT), Ecuador (EC), Jamaica (JM), Bolivia (BO), Peru (PE), Panama (PA), Suriname (SR), Trinidad & Tobago (TT), Costa Rica (CR), Puerto Rico (PR), Honduras (HN), Dominican Republic (DO), Grenada (GD), Netherlands (NL), Greece (GR), Spain (ES), Serbia (RS), Germany (DE), France (FR), Slovakia (SK), Belgium (BE), Romania (RO), Hungary (HU), Moldova (MD), Denmark (DK), Ireland (IE), Switzerland (CH), Sweden (SE), Finland (FI), Türkiye (TR), Russia (RU), Ukraine (UA), Portugal (PT), Slovenia (SI), United Kingdom (GB), Luxembourg (LU), Italy (IT), Belarus (BY), Cyprus (CY), Norway (NO), Czechia (CZ), Iceland (IS), Latvia (LV), North Macedonia (MK), Bulgaria (BG), Estonia (EE), Albania (AL), Austria (AT), Lithuania (LT), Poland (PL), Croatia (HR), Jordan (JO), Iraq (IQ), Lebanon (LB), Saudi Arabia (SA), Qatar (QA), United Arab Emirates (AE), Israel (IL), Kuwait (KW), Bahrain (BH), Oman (OM), Palestine (PS), Côte d’Ivoire (CI), Ghana (GH), Ethiopia (ET), Algeria (DZ), Madagascar (MG), Egypt (EG), South Africa (ZA), Senegal (SN), Tanzania (TZ), Djibouti (DJ), Cameroon (CM), Botswana (BW), Zimbabwe (ZW), Uganda (UG), Rwanda (RW), Congo - Kinshasa (CD), Nigeria (NG), Angola (AO), Zambia (ZM), Mozambique (MZ), Kenya (KE), Burkina Faso (BF), Mauritius (MU), Réunion (RE), Tunisia (TN), Namibia (NA), India (IN), Kazakhstan (KZ), Azerbaijan (AZ), Brunei (BN), Thailand (TH), Kyrgyzstan (KG), Philippines (PH), Bangladesh (BD), Sri Lanka (LK), Vietnam (VN), Indonesia (ID), Tajikistan (TJ), Japan (JP), Hong Kong (HK), Pakistan (PK), Malaysia (MY), Taiwan (TW), Nepal (NP), Macao (MO), Maldives (MV), Cambodia (KH), South Korea (KR), Singapore (SG), Georgia (GE), Bhutan (BT), Mongolia (MN), Laos (LA), Armenia (AM), Australia (AU), New Zealand (NZ), Guam (GU), New Caledonia (NC), Fiji (FJ), French Polynesia (PF).
EEA countries named by the service-specific scope
Austria (AT), Belgium (BE), Bulgaria (BG), Croatia (HR), Cyprus (CY), Czechia (CZ), Denmark (DK), Estonia (EE), Finland (FI), France (FR), Germany (DE), Greece (GR), Hungary (HU), Ireland (IE), Italy (IT), Latvia (LV), Lithuania (LT), Luxembourg (LU), Malta (MT), Netherlands (NL), Poland (PL), Portugal (PT), Romania (RO), Slovakia (SK), Slovenia (SI), Spain (ES), Sweden (SE), Iceland (IS), Liechtenstein (LI), Norway (NO).
The edge list is a dated snapshot of the public global network, excluding the separately offered mainland-China network, which is not part of this feature. It is a routing scope, not the location of every database, backup or provider log. Cloudflare's subprocessor page attributes Google LLC to Developer Platform processing in the EEA, United States, Australia and India, and Oracle America, Inc. to Developer Platform processing in the United States, EEA, United Kingdom, Japan, Australia, Canada and Singapore. Their presence on that service-wide list does not mean every subprocessor processes each request. Support access is limited to the provision of the service under the DPA.
Cloudflare publishes its processor DPA, service-specific subprocessor list and transfer safeguards. We rely on the applicable provider contract and its safeguards, including the DPA's provisions for covered EU/UK/Swiss transfers, rather than treating your optional choice as a substitute for provider obligations. Cloudflare's Global PRP certification is supporting evidence, not a claim that Altifigence is certified or automatically exempt from Korean transfer-consent requirements. A material change to this feature's purpose, recipient or disclosed transfer scope requires a revised notice and fresh consent; older receipts are not silently reused.
Official sources: Cloudflare DPA · Cloudflare service subprocessors · Cloudflare global network · D1 data location · Global PRP.
Do not submit sensitive material
Do not send passwords, API keys, private keys, full card numbers, government identifiers, customer data, unreleased designs, or other secrets through public email or forms. Use a product workspace or a separately agreed secure channel only when its interface and terms permit that material.
Contact
Privacy / general | |
|---|---|
Legal/IP | |
Security | |
Billing |