Privacy Policy
Last updated: August 2, 2026
SLG Inc. ("we," "us," or "our") operates the AI video creation service "Stepeee" (the "Service") and is committed to protecting your personal information. This Privacy Policy explains what personal data we collect and how we use and manage it. Because Stepeee is used by customers around the world, we comply with data protection laws in the relevant regions, including the GDPR (EU General Data Protection Regulation), CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act), LGPD (Brazil's General Data Protection Law), and APPI (Japan's Act on the Protection of Personal Information).
1. Information We Collect
1.1 Account Information
- Email address
- Username (nickname)
- Profile picture (optional)
- Plan type (Free / Vault / Plus / Pro / Team)
- Account creation date
- Public profile details (optional): website URL, social media links (X, Instagram, YouTube, TikTok)
- Team membership details: team name, your role within the team (owner / admin / member), invitation date, join date
1.2 Authentication Information
- Google sign-in data: when you sign in with Google, we receive your email address and display name (Stepeee uses passwordless authentication — you sign in with a magic link or a Google account)
- Social media connection data (TikTok, Instagram, X): OAuth tokens obtained when you connect a social account for posting (this is separate from account sign-in)
- Two-factor authentication (2FA) data: two-factor authentication secret information and recovery codes (stored encrypted)
- Sign-in activity: last sign-in time, failed sign-in attempts, account lock status
- Magic link tokens (temporary; expire after 30 minutes)
1.3 Location Information
- Country, detected via GeoIP: automatically identified from your IP address when you register, used for tax calculation and region-specific features
- Billing address (optional): name, address, postal code, country, state/prefecture
1.4 Payment Information
- Partial credit card details: card brand, last 4 digits, expiration date (we never store your full card number — all payment data is handled in Stripe's PCI DSS-compliant environment)
- Billing details: name, email address, phone number, address
- Payment history: transaction amount, currency, tax amount, payment status, receipt URL
- Subscription details: plan type, billing cycle, renewal date, cancellation date
- Auto-recharge settings: threshold, recharge amount, monthly cap, recharge history
- Prepaid card / gift card information (for referral payouts): recipient email address
1.5 Usage Data
- Project information: project name, creation date, description
- Uploaded file details: file name, size, category (image / video / audio / BGM), upload date, file format, resolution, duration
- Video generation history: generation date, model used, Tokens consumed, processing time
- AI processing data: prompts you enter for text, image, video, voice, and BGM generation
- Storage usage
- Token balance and consumption history
- Feature usage
- Knowledge base entries: business information, product/service details, expertise, communication guidelines, FAQs, and other information you register in advance
1.6 Social Media Connection Information
- Connected platforms: YouTube, TikTok, Instagram, X, WordPress
- Account name, account ID, and profile picture on each platform
- Access tokens and refresh tokens (stored encrypted)
- Granted permission scopes
- Connection date, last used date, connection status
- For WordPress: site URL, application password (stored encrypted), post category/tag settings, and similar details
1.7 Technical Information
- IP address
- Browser type and version
- Device information (OS, screen resolution)
- Access logs (access date/time, referring URL)
- Cookie data
- IP address and user agent recorded when you change your email address (for audit purposes)
1.8 Content Data
- Uploaded images, videos, audio, and BGM files
- AI-generated content (images, videos, audio, BGM, text)
- Editing project data (editor state, version history)
- Finished videos and their metadata
1.9 Feedback and Survey Data
- Survey responses: video production experience, software you use, feature requests, UI suggestions, satisfaction ratings
- Bug reports and feature suggestions
- Cancellation survey: reason for cancellation, feedback, length of use
- Referral content submissions: URL of the referral video or article, email address (optional), publicly available information such as the creator's name, channel name, or blog name, and any supplementary notes
2. How We Collect Information
2.1 Provided Directly by You
We collect information you provide directly, such as when you register an account, update your profile, enter payment details, upload content, contact us, or respond to a survey.
2.2 Collected Automatically
As you use the Service, we automatically collect technical information (IP address, browser information, access logs, etc.), GeoIP location data, cookie data, and usage data.
2.3 Received from Third Parties
If you sign in with a Google account, we receive your email address and display name from Google. OAuth connections with TikTok, Instagram, and X are used only for posting to social media, never for sign-in. We also receive payment-processing information from Stripe.
3. Legal Basis for Processing
Under the EU/EEA/UK General Data Protection Regulation (GDPR), we process personal information based on the following legal grounds.
| Purpose | Legal Basis |
|---|---|
| Account management and service delivery | Performance of a contract (GDPR Art. 6(1)(b)) |
| Payment processing and subscription management | Performance of a contract (GDPR Art. 6(1)(b)) |
| Security and fraud prevention | Legitimate interests (GDPR Art. 6(1)(f)) |
| Usage analysis and service improvement | Legitimate interests (GDPR Art. 6(1)(f)) |
| Using content to improve AI generation quality | Consent (GDPR Art. 6(1)(a)) |
| Retaining tax records | Legal obligation (GDPR Art. 6(1)(c)) |
| Processing Referral Program rewards and managing payout information (prepaid card / gift card) | Performance of a contract (GDPR Art. 6(1)(b)) |
| Sending important service notices | Performance of a contract (GDPR Art. 6(1)(b)) |
| Team management, member invitations, and data sharing within a team | Performance of a contract (GDPR Art. 6(1)(b)) |
Where processing is based on consent, you may withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
4. How We Use Your Information
4.1 Providing the Service
- Account management and user authentication (including social sign-in and 2FA)
- Video production features (AI image generation, video generation, voice synthesis, BGM generation, text generation)
- Project management features
- File storage
- Posting videos to social media platforms
4.2 Billing and Payments
- Subscription management and renewals
- Token purchases and auto-recharge
- Tax calculation (applying the appropriate rate for your country of residence)
- Issuing invoices and receipts
- Processing refunds
- Calculating, confirming, and paying out referral rewards (Token exchange, prepaid card / gift card)
4.3 Improving the Service
- Statistical analysis of usage
- Developing new features
- Improving system performance
- Improving AI generation quality (only with your consent)
4.4 Communicating with You
- Important service notices (plan changes, security alerts, etc.)
- Payment-related notices (payment confirmations, renewal reminders, etc.)
- Responding to your inquiries
- Reviewing and confirming referral content submissions, and deciding whether to publish them
4.5 Keeping the Service Safe
- Preventing and detecting fraud
- Fraud risk-scoring performed by our payment processor (Stripe)
- Preventing abuse of first-time offers (limited to one purchase per Account)
- General security measures
- Detecting violations of our Terms of Service
5. Use in AI and Machine Learning
5.1 Data Sent for AI Processing
When you use the Service's AI features, the following data is sent to external AI service providers for processing:
- Text generation: the prompts you enter are sent to our AI text-generation provider
- Image, video, audio, and BGM generation: your prompts and related input data are sent to our AI processing servers
- Knowledge base entries: information you've registered (business details, product information, expertise, etc.) is included as part of the prompt when generating content and is sent to our AI processing providers
This data is promptly deleted by each provider once processing is complete. We never provide your content to third-party AI services for model training. That said, how each AI service provider handles data is governed by that provider's own policies.
5.2 Use for Improving Service Quality
Only if you explicitly opt in, we may use anonymized content data to:
- Improve video generation quality
- Improve image recognition accuracy
- Develop new features
5.3 Your Rights
- Consenting to the use of your content for AI quality improvement is optional, and you can withdraw your consent at any time
- Withdrawing your consent does not affect your access to the Service's core features
- We do not use personally identifiable information for AI quality improvement
6. Sharing and Disclosure to Third Parties
We may share the minimum information necessary with third parties for the purposes described below. We never sell your personal information to third parties.
6.1 Service Providers
We share information, to the extent necessary to provide the Service, with the following categories of providers:
- Stripe (payment processor): card information, billing address, email address, IP address
- Prepaid card / gift card issuers: email address, referral payout amounts
- Cloud infrastructure providers: user files, database
- Content delivery providers: uploaded files, generated content
- AI processing providers: prompts, input data (promptly deleted after processing)
- Analytics providers: anonymized usage data
- Email delivery providers: email address
6.2 Social Sign-In Providers
If you sign in with a Google account, we receive the information necessary for authentication (email address, display name) from Google. We don't share any additional information about you with Google. OAuth connections with TikTok, Instagram, and X are used solely for social media posting, never for sign-in.
6.3 Social Media Platforms
If you use the Service's social media or blog posting features, your post content (text, images, videos, audio, titles, descriptions, tags, etc.) is sent to the platform you choose (YouTube, TikTok, Instagram, X, WordPress). Each platform handles this information under its own privacy policy (for WordPress posts, the policy of the connected site applies).
6.4 Data Shared Within a Team
If you use a Team plan, the following information is shared within the team:
- Team members' usernames (nicknames) and profile pictures
- Roles within the team (owner / admin / member)
- Team project content (scripts, images, videos, audio, and other production data)
Team members' email addresses, payment information, and personal (non-team) project data are never shared with other team members. If you leave a team, you lose access to that team's projects.
6.5 Legal Requests
We may disclose information to the extent permitted by law when required by law, in response to a lawful request from law enforcement or a regulator, or when necessary to protect the rights or safety of you or others.
6.6 Business Transfers
If all or part of our business is transferred, merged, or divided, personal information may be transferred as part of that transaction. In that case, we will require the recipient to protect your information to a standard at least equal to this Policy.
7. International Data Transfers
We are based in Japan. In the course of operating the Service, your personal information may be transferred to the following countries and regions.
7.1 Transfer Destinations
- United States: Stripe (payments), prepaid card / gift card issuers (payouts), cloud infrastructure providers, content delivery providers, analytics providers
- Other regions: wherever our AI processing servers are located
7.2 Safeguards
When we transfer personal information outside Japan, we apply the following safeguards:
- Standard Contractual Clauses (SCCs) or equivalent contractual protections
- Verifying the recipient's data protection certifications (e.g., SOC 2, ISO 27001)
- Encrypting data in transit and at rest
- Access controls based on the principle of least privilege
- Regular security audits
For data belonging to EU/EEA residents, we apply appropriate safeguards under GDPR Article 46. Japan has also received an adequacy decision from the European Commission.
8. How Long We Keep Your Data
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, or as required by law.
| Data Category | Retention Period |
|---|---|
| Account information | Permanently deleted 3 days after you request account deletion |
| Project data | Deleted at the same time as your account |
| Uploaded files (Free plan) | Step 1–3 information and related material deleted 30 days after setup is finalized (the setup screen lock is then released) |
| Uploaded files (after canceling a paid plan) | Deleted 30 days after moving to the Free plan (the number of days remaining until the scheduled deletion date is always shown on screen; upgrading restores your files) |
| Authentication data (2FA) | Deleted when 2FA is disabled |
| OAuth tokens | Deleted when you disconnect the integration |
| Social media connection data | Deleted when you disconnect the integration |
| Log data | Deleted after 1 year |
| Payment records | Retained for 7 years, as required by law |
| Feedback and surveys | Deleted after 3 years |
| Referral rewards and payout information (prepaid card / gift card) | Retained for 7 years from the last transaction |
| Team membership data | Deleted when you leave the team or the team is disbanded |
After the retention period ends, personal information is securely deleted or anonymized. Where retention is legally required, we delete the data once that legally required period has passed.
9. Data Security
We take the following technical and organizational measures to protect your personal information from unauthorized access, loss, tampering, and disclosure.
9.1 Technical Measures
- Industry-standard encryption at rest for authentication information (two-factor authentication secret information, OAuth tokens, registered external API keys, etc.)
- TLS/SSL encryption in transit
- Encrypted storage of authentication and OAuth tokens
- Magic link authentication (passwordless; temporary tokens are stored hashed and expire after 30 minutes)
- CSRF protection, XSS prevention, and SQL injection prevention
- Account protection via two-factor authentication (2FA)
- Progressive lockout after failed sign-in attempts
9.2 Organizational Measures
- Access controls based on the principle of least privilege
- Monitoring of access logs
- Regular security audits
- Security training for employees
9.3 Where Data Is Stored
- User files: cloud storage services (encrypted)
- Database: cloud database services (encrypted)
- Backups: distributed across multiple regions
10. Cookies and Similar Technologies
We use cookies and similar browser storage technologies for the following purposes.
10.1 Essential Cookies
- Keeping you signed in (session management)
- CSRF protection tokens
- Security features
These cookies are required for the Service to function and cannot be disabled.
10.2 Analytics Cookies
- Analytics services: analyzing usage and measuring performance
- Collecting statistics to improve the Service
You can disable analytics cookies through your browser settings or the relevant service's opt-out feature.
10.3 Functional Cookies and Browser Storage
We store the following settings in your browser's sessionStorage and localStorage:
- Language preference (lang, lang_select)
- Theme preference (color_theme: light/dark)
- Navigation display state
This data stays in your browser and is never sent to our servers. You can clear it from your browser settings.
11. Your Rights
Depending on where you live, you may have the following rights under applicable law.
11.1 Right of Access
You can ask us what personal information we hold about you and how we're processing it.
11.2 Right to Correction
If your personal information is inaccurate, you can ask us to correct it. You can also update most information directly from your account settings.
11.3 Right to Deletion ("Right to Be Forgotten")
Under certain conditions, you can ask us to delete your personal information. You can also delete your account directly from your account settings. Note that we may be unable to delete certain data — such as payment records — until any legally required retention period has passed.
11.4 Right to Restrict Processing
Under certain conditions, you can ask us to restrict how we process your personal information.
11.5 Data Portability
You can download any files you've uploaded or created within the Service.
11.6 Right to Object
You can object to processing that is based on our legitimate interests.
11.7 Right to Withdraw Consent
Where processing is based on your consent, you can withdraw it at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
11.8 How to Exercise These Rights
To exercise any of these rights, please contact us using the details at the end of this Policy. After verifying your identity, we will respond within the timeframe required by applicable law (generally within 30 days).
12. Additional Rights for EU/EEA/UK Residents
Under the EU/EEA/UK General Data Protection Regulation (GDPR/UK GDPR), residents of the EU, EEA, and UK have the following additional rights.
12.1 Complaints to a Supervisory Authority
If you're not satisfied with how we handle your personal information, you can file a complaint with your local data protection authority.
12.2 Data Controller
The data controller for the Service is SLG Inc. (1-3-3-303 Okubo, Shinjuku-ku, Tokyo 169-0072, Japan).
12.3 International Data Transfers
Japan has received an adequacy decision from the European Commission. For transfers to other countries, we apply appropriate safeguards such as Standard Contractual Clauses (SCCs).
12.4 Privacy Inquiries
For GDPR-related inquiries, please contact us using the details at the end of this Policy.
13. Additional Rights for California Residents (CCPA/CPRA)
Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents have the following rights.
13.1 Right Regarding the Sale or Sharing of Personal Information
We do not sell or share your personal information with third parties. Because of this, there's no need to submit a "Do Not Sell or Share My Personal Information" request, but if you contact us about it, we'll confirm it for you promptly.
13.2 Categories of Personal Information We Collect
Over the past 12 months, we have collected the following categories of personal information:
- Identifiers: email address, username, IP address, unique identifiers
- Commercial information: payment history, subscription details, Token purchase history
- Internet or network activity: browser information, access logs, usage data
- Geolocation data: country code (from GeoIP), billing address
- User-generated content: uploaded files, AI-generated content, project data
13.3 Additional Rights for California Residents
- Right to know: request disclosure of the categories and specific pieces of personal information we've collected
- Right to delete: request deletion of your personal information
- Right to correct: request correction of inaccurate personal information
- Right to non-discrimination: you won't be treated differently for exercising your privacy rights
13.4 How to Submit a Request
To exercise any of these rights, please contact us using the details at the end of this Policy. We will respond within 45 days of receiving your request.
14. Additional Rights for Brazilian Residents (LGPD)
Under Brazil's General Data Protection Law (LGPD), in addition to the rights described in Section 12, Brazilian residents have the right to:
- Withdraw consent to the processing of personal information
- Request anonymization, blocking, or deletion of personal information
- Be informed about the sharing of personal information between public and private entities
- Be informed of the consequences of refusing to give consent
You may also file a complaint with Brazil's national data protection authority (ANPD).
15. Children's Personal Information
The Service is not directed at children under 16 (or under 13 in the United States). We do not knowingly collect personal information from children under 16.
If we learn that a child under 16 (or under 13 in the United States) has provided us with personal information, we will delete it promptly.
If a minor uses the Service, a parent or guardian's consent and supervision is required. Parents and guardians may request deletion of their child's personal information.
17. Content Ownership and Licensing
17.1 Your Content
You retain copyright in the content you upload. We obtain only a limited license to use your content, and only to the extent necessary to provide the Service (storing, displaying, delivering, and backing it up). This license ends when you delete the content.
17.2 AI-Generated Content
You are granted the right to use content generated with the Service's AI features (images, videos, audio, text, etc.).
17.3 Public Content
If you make content public through the Service's community features, other users can view it. You choose whether to make content public, and you can switch it back to private at any time.
17.4 Referral Content
Copyright in referral videos or articles (“Referral Content”) submitted by users through the Content Submissions page remains with the user. The scope of the license we obtain, whether and for how long content is published, and how correction or removal requests are handled are set out in the Referral Content Publication Terms.
18. Data Breach Notification
If a security incident occurs — such as a leak, loss, or unauthorized alteration of personal information — we will take the following steps.
18.1 Notifying Regulators
For incidents subject to GDPR, we will notify the relevant supervisory authority within 72 hours of becoming aware of the incident. For incidents subject to Japan's Act on the Protection of Personal Information, we will promptly report to the Personal Information Protection Commission.
18.2 Notifying You
If an incident is likely to pose a significant risk to your rights or freedoms, we will notify affected users without undue delay. Our notification will describe the incident, the type of data affected, the steps we're taking, and what you should do.
19. Changes to This Policy
We may update this Privacy Policy to reflect changes in the law, improvements to the Service, or changes in our business.
19.1 How We'll Notify You
- For minor changes, we'll notify you within the Service
- The current version is always available on this page
19.2 When Changes Take Effect
Changes take effect as soon as the updated Policy is posted on this page. For material changes, we may provide a 30-day notice period after posting. If you continue using the Service after that period, we'll treat that as your acceptance of the changes.
20. Contact Us
For questions about how we handle personal information, to exercise your rights, or to file a complaint, please contact us at:
After receiving your inquiry, we will verify your identity and respond within the timeframe required by applicable law. We typically respond within 30 days, though this may be extended up to 90 days depending on the complexity of your request — we'll let you know in advance if that happens.