ComicBand Privacy Policy

Effective August 11, 2026

This policy explains how STS WORKS (“we”) handles information in the iOS app ComicBand (“the app”).

Photos and AI generation

The full photo selected from the photo library or camera stays on the device for editing and compositing. We do not upload the full photo.

When the user confirms generation, only the rectangular band selected by the user is converted to JPEG without location or EXIF metadata and sent through our Amazon Web Services infrastructure to the Black Forest Labs (“BFL”) FLUX API. The app does not detect eyes or faces, so the selected area is sent even if it is not over a person’s eyes. The generated band is returned to the device and composited into the original photo on the device. Our AWS service processes input and output images in memory and does not store them in a database or file store.

BFL’s public FLUX API terms permit BFL to use inputs and outputs to operate, develop, train, and improve its products, services, algorithms, and AI models. BFL’s public privacy policy does not specify a fixed retention period. It says information is retained for as long as reasonably necessary for service provision, legal obligations, disputes, safety, security, and related purposes. The app cannot guarantee immediate deletion from BFL systems or exclusion from model improvement.

If the selected band contains a person’s face or likeness, it may be personal or biometric information under applicable law. The app does not use it for identification, face recognition, surveillance, or sensitive-attribute inference.

Conditions for AI use

AI generation is available only to users who are 18 or older. Images containing anyone under 18 must not be submitted. Before each photo is sent, the user must confirm that they are an adult, that no minor appears, that all depicted people gave the necessary informed consent, and that they understand BFL may use inputs and outputs for model training and improvement.

The onboarding demo only switches among ten finished examples bundled with the app: five color styles and five monochrome styles. It does not send an image, call BFL, show an ad, make a purchase, or consume a generation credit.

Other information

We process a Firebase anonymous user ID, generation-credit and request state, AI-consent version and confirmation state, App Store purchase and anti-duplication transaction data, RevenueCat purchase status, app interaction events, crash and diagnostic data, notification tokens after permission, and information provided to support. We do not include photos, free-form prompts, signed purchase data, or transaction IDs in analytics or crash events.

Rewarded advertising is disabled by Remote Config at the Version 1.0 launch. The app does not start the advertising flow, show advertising consent, request App Tracking Transparency permission, or show an ad, and additional generations are sold only as consumable credit packs. However, the binary includes an AdMob path intended for later activation, so the App Store privacy answers disclose advertising data, approximate location, advertising purposes, and device-ID tracking. Before advertising is actually enabled, the app will obtain any required consent through UMP and ATT.

Service providers

  • Apple: app distribution, StoreKit purchases, photos, sharing, and push notifications
  • RevenueCat: product offerings, purchase state, and purchase analytics
  • Amazon Web Services: CloudFront, WAF, Lambda, DynamoDB, Secrets Manager, KMS, and CloudWatch
  • Google Firebase: anonymous authentication, Remote Config, Analytics, Crashlytics, Messaging, and App Check
  • Black Forest Labs: FLUX API generation and its associated operation, safety, training, and improvement uses

We do not send the Firebase user ID or purchase information to BFL. The BFL API key is stored in AWS Secrets Manager and is not embedded in the app.

Storage, deletion, and rights

Unselected results and source photos remain in memory until editing or review ends. A finished image is saved to app history only after the user chooses to save or share it. It is added to the photo library only after the user chooses that action.

Generation state and AI confirmations are stored in DynamoDB. Users can delete app history, cached images, and server-side usage state from Settings > Delete User Data. Minimal purchase transaction identifiers may be retained where necessary to prevent duplicate grants or meet legal obligations. Copies already saved to the photo library or shared elsewhere are not deleted.

Before sending, the user can close the confirmation screen to stop the transfer. For access, correction, deletion, restriction, or objection requests, contact us. Requests involving BFL will be handled within the limits of applicable law and our provider agreement.

Security and international processing

Transfers use HTTPS. We use AWS access controls, encryption, WAF, Firebase anonymous authentication, App Check, server-side model allowlists, quotas, and idempotency controls. Providers may process information outside Japan.

Contact

STS WORKS

Email: contact@sts.works

Support: https://sts.works/support/