นโยบายความเป็นส่วนตัวPrivacy Policy
ภาษาไทย
1.เราคือใคร
Ellon Studio ให้บริการโดย TODO: ชื่อผู้ให้บริการ / บริษัท ซึ่งเป็นผู้ควบคุมข้อมูลส่วนบุคคลตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 ติดต่อเรื่องข้อมูลส่วนบุคคลได้ที่ TODO: อีเมลติดต่อ / contact email ที่อยู่ TODO: ที่อยู่ผู้ให้บริการ
2.ข้อมูลที่เราเก็บ
- ข้อมูลบัญชี: อีเมล ชื่อที่ใช้เรียก และรหัสผ่านซึ่งเก็บเป็นค่าแฮช (scrypt) ไม่เคยเก็บรหัสผ่านจริง ถ้าเข้าสู่ระบบด้วย Google เราได้รับชื่อ อีเมล และรหัสบัญชี Google ของคุณ
- การเข้าสู่ระบบ: คุกกี้เซสชันหนึ่งตัวที่จำเป็นต่อการใช้งาน ฝั่งเราเก็บเพียงค่าแฮชของคุกกี้และวันหมดอายุ เราไม่ใช้คุกกี้โฆษณาหรือตัวติดตามของบุคคลที่สาม
- สิ่งที่คุณใส่เข้ามา: ไอเดีย บท คำอธิบายตัวละคร รูป เสียง และวิดีโอที่อัปโหลด รวมถึงรูปของคุณเองถ้าคุณเลือกใช้หน้าตัวเองเป็นตัวละคร
- งานที่สร้าง: ภาพ เสียง วิดีโอ บท และบันทึกการค้นคว้าที่ระบบทำให้คุณ
- API key ของคุณ: เข้ารหัสด้วย AES-256-GCM ก่อนเก็บ ถอดรหัสเฉพาะตอนที่งานของคุณกำลังทำ
- การเชื่อมต่อ YouTube และ Facebook: โทเค็นการเข้าถึง (เข้ารหัสก่อนเก็บ) รหัสและชื่อช่อง YouTube รหัสและชื่อบัญชี Facebook ของคุณ รหัส ชื่อ หมวดหมู่ และรูปของเพจ และรหัสวิดีโอหรือโพสต์ที่ส่งจากสตูดิโอ
- บันทึกการใช้งาน: งานที่สั่ง ผู้ให้บริการที่ใช้ ราคาประเมินและราคาจริง และข้อผิดพลาด เพื่อแสดงค่าใช้จ่ายให้คุณ คุมเพดาน และแก้ปัญหา
3.เราใช้ข้อมูลทำอะไร
- ให้บริการตามที่คุณสั่ง: สร้างงาน เก็บงาน และโพสต์ไปยังช่องที่คุณเลือก
- แสดงค่าใช้จ่ายและบังคับเพดานค่าใช้จ่ายของบัญชี
- รักษาความปลอดภัย ป้องกันการใช้ผิดข้อกำหนด และแก้ปัญหาเมื่อคุณขอความช่วยเหลือ
- ปฏิบัติตามกฎหมาย
ฐานทางกฎหมายหลักคือความจำเป็นเพื่อปฏิบัติตามสัญญาให้บริการ ประโยชน์โดยชอบด้วยกฎหมายด้านความปลอดภัย และความยินยอมของคุณในกรณีที่ขอ เช่น การเชื่อมบัญชี YouTube หรือ Facebook เราไม่ขายข้อมูลของคุณ ไม่ใช้ข้อมูลเพื่อโฆษณา และไม่นำเนื้อหาของคุณไปฝึกโมเดล AI
4.ใครได้รับข้อมูลของคุณ
- ผู้ให้บริการ AI ที่คุณใช้ ผ่านคีย์ของคุณ เฉพาะเนื้อหาที่จำเป็นต่องานนั้น: Anthropic (นโยบาย), Google Gemini (นโยบาย), ElevenLabs (นโยบาย), Kling และ TypeSafe (Jev) ถ้าคุณเปิดใช้ ผู้ให้บริการเหล่านี้ประมวลผลข้อมูลตามนโยบายของตน และอาจอยู่นอกประเทศไทย
- YouTube และ Facebook เฉพาะวิดีโอและข้อมูลประกอบที่คุณสั่งให้โพสต์
- ผู้ให้บริการโครงสร้างพื้นฐาน ที่เก็บระบบและไฟล์ให้เรา: TODO: ผู้ให้บริการโฮสติ้ง / hosting provider
- หน่วยงานรัฐ เมื่อกฎหมายบังคับเท่านั้น
5.ข้อมูลผู้ใช้ Google และ YouTube API Services
เข้าสู่ระบบด้วย Google ขอสิทธิ์ openid, email และ profile ใช้เพื่อยืนยันตัวตนและผูกกับบัญชีของคุณเท่านั้น
การเชื่อมช่อง YouTube ใช้ YouTube API Services และขอสิทธิ์ดังนี้
- youtube.upload: อัปโหลดวิดีโอที่คุณสั่งโพสต์
- youtube.readonly: แสดงชื่อช่องของคุณ ตรวจสถานะการอัปโหลดและการประมวลผลวิดีโอ และอ่านชาร์ตวิดีโอยอดนิยมสาธารณะของ YouTube เพื่อหาไอเดียจากกระแส เมื่อคุณขอ
- youtube.force-ssl: ตั้งชื่อ คำอธิบาย ภาพปก และเวลาเผยแพร่ ของวิดีโอที่ส่งจากสตูดิโอ
- yt-analytics.readonly: อ่านสถิติของช่องและวิดีโอของคุณ (ยอดดู เวลาดู จุดที่คนเลิกดู และภาพรวมกลุ่มผู้ชมแบบไม่ระบุตัวตน) เพื่อทำรายงานให้คุณ
เราใช้ข้อมูลจาก Google เฉพาะเพื่อทำสิ่งที่คุณสั่งในสตูดิโอ ไม่ใช้เพื่อโฆษณา ไม่ขาย และไม่ส่งต่อให้ใคร ยกเว้นเท่าที่จำเป็นต่อการให้บริการหรือที่กฎหมายกำหนด ไม่มีพนักงานคนใดอ่านข้อมูลนี้ เว้นแต่คุณขอให้ช่วยแก้ปัญหา เพื่อความปลอดภัย หรือเมื่อกฎหมายบังคับ การใช้และการส่งต่อข้อมูลที่ได้รับจาก Google APIs เป็นไปตาม Google API Services User Data Policy รวมถึงข้อกำหนด Limited Use
การใช้ฟีเจอร์ YouTube ถือว่าคุณยอมรับ ข้อกำหนดการให้บริการของ YouTube ข้อมูลของคุณอยู่ภายใต้ นโยบายความเป็นส่วนตัวของ Google ด้วย ยกเลิกสิทธิ์ได้ที่ตั้งค่า → YouTube ในสตูดิโอ หรือที่ หน้าการเข้าถึงของบัญชี Google เมื่อยกเลิก เราลบโทเค็นที่เก็บไว้ทันที
6.ข้อมูลจาก Facebook
การเชื่อมเพจ Facebook ขอสิทธิ์ pages_show_list เพื่อแสดงรายชื่อเพจที่คุณดูแลให้เลือก และ pages_manage_posts เพื่อโพสต์วิดีโอ Reels และรูปไปยังเพจที่คุณเลือก และ pages_read_engagement กับ read_insights เพื่ออ่านสถิติของโพสต์บนเพจของคุณ (ยอดเล่น การเข้าถึง เวลาดู) มาทำรายงาน
เราเก็บรหัสและชื่อบัญชี Facebook ของคุณ โทเค็นผู้ใช้แบบอายุยาว (เข้ารหัส) ซึ่งใช้อ่านรายชื่อเพจที่คุณดูแลอีกครั้ง และของแต่ละเพจ ได้แก่ รหัส ชื่อ หมวดหมู่ รูปเพจ และโทเค็นของเพจ (เข้ารหัส) ยกเลิกได้ที่ตั้งค่า → Facebook เพจ ในสตูดิโอ ซึ่งลบโทเค็นทั้งหมดทันที ทั้งโทเค็นผู้ใช้และโทเค็นของเพจ หรือที่ การตั้งค่า Facebook → การผสานรวมทางธุรกิจ
7.การเก็บรักษาและความปลอดภัย
ข้อมูลแต่ละบัญชีเข้าถึงได้เฉพาะเจ้าของบัญชี คีย์และโทเค็นเข้ารหัส รหัสผ่านเก็บเป็นค่าแฮช เราเก็บข้อมูลไว้ตราบที่บัญชียังใช้งาน ไฟล์ส่งออกเก็บไว้จนกว่าคุณจะลบเอง หรือจนกว่าบัญชีถูกลบ เมื่อลบบัญชี ข้อมูลถูกลบตามข้อ 8 สำเนาสำรองของระบบที่ทำไว้ก่อนวันลบอาจยังมีข้อมูลนั้นอยู่จนกว่าสำเนาชุดนั้นจะถูกลบ สำเนาสำรองเข้าถึงได้เฉพาะผู้ดูแลระบบ และใช้เพื่อกู้ระบบเท่านั้น
8.วิธีลบข้อมูลและบัญชี
- ลบงาน ตัวละคร และซีรีส์แต่ละชิ้นได้เองในสตูดิโอ
- ลบ API key ได้ที่ ตั้งค่า → คีย์ API
- ยกเลิกการเชื่อม YouTube หรือ Facebook ได้ที่หน้าตั้งค่าของแต่ละช่องทาง โทเค็นถูกลบทันที
- ลบบัญชีทั้งหมด: ส่งอีเมลจากอีเมลที่ใช้สมัครมาที่ TODO: อีเมลติดต่อ / contact email หัวข้อ "ลบบัญชี" เราจะยืนยันตัวตน ลบบัญชีและข้อมูลทั้งหมด (งาน ไฟล์ คีย์ โทเค็น และบันทึกการใช้งาน) ภายใน 30 วัน และแจ้งกลับทางอีเมล
เราอาจเก็บข้อมูลบางส่วนต่อเท่าที่กฎหมายบังคับ เช่น หลักฐานการชำระเงิน วิดีโอที่โพสต์ไปแล้วยังอยู่บน YouTube หรือ Facebook จนกว่าคุณจะลบที่แพลตฟอร์มนั้น
9.สิทธิของคุณ
ตามพระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล คุณมีสิทธิขอเข้าถึงและขอสำเนาข้อมูล ขอให้โอนข้อมูล แก้ไขให้ถูกต้อง ลบ ระงับการใช้ คัดค้านการประมวลผล และถอนความยินยอม ติดต่อได้ที่ TODO: อีเมลติดต่อ / contact email และมีสิทธิร้องเรียนต่อ สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคล
10.เด็ก
บริการไม่ได้ทำมาสำหรับเด็กอายุต่ำกว่า 13 ปี และเราไม่เก็บข้อมูลของเด็กโดยรู้ตัว ผู้ใช้ที่ยังไม่บรรลุนิติภาวะต้องได้รับความยินยอมจากผู้ปกครอง การทำคลิปสำหรับคนดูที่เป็นเด็กทำได้ แต่เจ้าของบัญชีต้องเป็นผู้ใหญ่
11.การแก้ไขนโยบาย
เมื่อมีการเปลี่ยนแปลงสำคัญ เราจะแจ้งในบริการหรือทางอีเมลก่อนมีผล และปรับวันที่มีผลบังคับใช้ที่ด้านบนของหน้านี้
English
1.Who we are
Ellon Studio is operated by TODO: operator / company name, the data controller under Thailand's Personal Data Protection Act B.E. 2562 (2019). Contact us about your personal data at TODO: อีเมลติดต่อ / contact email, or write to TODO: operator address.
2.Information we collect
- Account information: your email, display name, and password, stored only as a scrypt hash. If you sign in with Google, we receive your name, email address and Google account ID.
- Sign-in: one strictly necessary session cookie. On our side we store only a hash of it and its expiry. We use no advertising cookies or third-party trackers.
- Content you provide: ideas, scripts, character descriptions, and images, audio and video you upload, including photos of yourself if you choose to use your own likeness.
- Generated content: images, audio, video, scripts and research notes the Service makes for you.
- Your API keys: encrypted with AES-256-GCM before storage and decrypted only while your own work is running.
- YouTube and Facebook connections: OAuth access and refresh tokens (encrypted), your YouTube channel ID and title, your Facebook user ID and name, each Page's ID, name, category and picture, and the IDs of videos or posts published from the Service.
- Usage records: the jobs you run, which provider handled them, estimated and actual cost, and errors, so we can show your spending, enforce ceilings and fix problems.
3.How we use information
- To provide the Service you ask for: generating, storing and publishing your work to the channels you choose.
- To show your costs and enforce your account's spending ceilings.
- To keep the Service secure, prevent abuse, and help when you ask for support.
- To comply with the law.
Our legal bases are performance of our contract with you, our legitimate interest in security, and your consent where we ask for it, such as when you connect YouTube or Facebook. We do not sell your data, do not use it for advertising, and do not use your content to train AI models.
4.Who receives your information
- The AI providers you use, through your own keys, receiving only the content a task needs: Anthropic (policy), Google Gemini (policy), ElevenLabs (policy), Kling, and TypeSafe (Jev) if you enable it. They process data under their own policies and may be located outside Thailand.
- YouTube and Facebook, only for the videos and details you choose to publish.
- Infrastructure providers that host the Service and its files for us: TODO: ผู้ให้บริการโฮสติ้ง / hosting provider
- Public authorities, only where the law requires it.
5.Google user data and YouTube API Services
Sign in with Google requests the openid, email and profile scopes, used only to authenticate you and link the sign-in to your account.
Connecting a YouTube channel uses YouTube API Services and requests these scopes:
- youtube.upload: to upload the videos you choose to publish;
- youtube.readonly: to show your channel name, check upload and processing status, and read YouTube's public most-popular chart for trend ideas when you ask for them;
- youtube.force-ssl: to set the title, description, thumbnail and publish time of videos sent from the Service;
- yt-analytics.readonly: to read your own channel and video statistics (views, watch time, where viewers stop watching, and aggregated, anonymous audience breakdowns) for your reports.
We use Google user data only to do what you ask in the Service. We do not use it for advertising, do not sell it, and do not transfer it to others except as necessary to provide the Service or as required by law. No person reads it unless you ask for support, for security purposes, or where the law requires. Ellon Studio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
By using YouTube features you agree to the YouTube Terms of Service, and your information is also subject to the Google Privacy Policy. You can revoke access at any time under Settings → YouTube in the Service, or from your Google Account permissions page. When you disconnect, we delete the stored tokens immediately.
6.Facebook data
Connecting a Facebook Page requests pages_show_list, to list the Pages you manage so you can choose one, and pages_manage_posts, to publish videos, Reels and photos to the Pages you choose, plus pages_read_engagement and read_insights, to read your own Page posts' statistics (plays, reach, watch time) for your reports.
We store your Facebook user ID and name, your long-lived user access token (encrypted), used to read the list of Pages you manage again, and for each Page its ID, name, category, picture and Page access token (encrypted). You can disconnect under Settings → Facebook Pages in the Service, which immediately deletes all of these tokens, the user token and the Page tokens alike, or from Facebook Settings → Business Integrations.
7.Retention and security
Each account's data is accessible only to that account. Keys and tokens are encrypted and passwords are hashed. We keep your data while your account is active; export files are kept until you delete them or your account is deleted. When you delete your account, data is removed as described in section 8. System backups made before the deletion may still contain that data until those backups are themselves deleted; backups are accessible only to the operator and are used only to restore the Service.
8.How to delete your data and account
- Delete individual projects, characters and series yourself in the Service.
- Delete API keys under Settings → API Keys.
- Disconnect YouTube or Facebook from each one's settings page; the tokens are deleted immediately.
- To delete your whole account: email TODO: อีเมลติดต่อ / contact email from the address you signed up with, with the subject "Delete my account". We will verify the request, delete your account and all associated data (projects, files, keys, tokens and usage records) within 30 days, and confirm by email.
We may retain limited records where the law requires, such as payment records. Videos already published remain on YouTube or Facebook until you delete them there.
9.Your rights
Under the PDPA you may request access to and a copy of your data, data portability, correction, deletion, restriction, objection to processing, and withdrawal of consent. Contact us at TODO: อีเมลติดต่อ / contact email. You may also complain to Thailand's Personal Data Protection Committee.
10.Children
The Service is not directed to children under 13 and we do not knowingly collect their data. Minors need a parent's or guardian's consent. You may make videos for young audiences, but the account holder must be an adult.
11.Changes to this policy
For material changes we will notify you in the Service or by email before they take effect, and update the effective date at the top of this page.