Privacy Policy
Operator: PPGS Global LLC (“Asiago,” “we,” “us,” or “our”)
Business address: 11756 Borman Drive, St. Louis, MO 63146
Privacy contact: privacy@ppgs.global
This Privacy Policy explains how Asiago handles information for the Asiago AI-entertainment service at stream.asiago.ai, including public viewing, viewer accounts, profiles, comments, reposts, creator-interest features, and support communications. The launch service is offered only in the United States and is not intended for children under 13.
1. Information we collect
Accounts and authentication
When you create or use an account, we may collect your name, email address, username, account identifier, password verifier, account status and role, verification records, and sign-in activity. If you choose Google sign-in, Google provides authorized account identifiers and profile information; the authentication system may retain provider tokens needed for the connection. Asiago does not receive your Google password.
Authentication and security records may include session identifiers and tokens, expiration times, IP address, user agent, rate-limit records, verification values, and authorized administrator support activity.
Viewing, interaction, and recommendations
We collect information about feed use, including videos shown or watched, watch time and progress, completions, skips, replays, likes, unlikes, shares, reposts, follows, unfollows, comment votes, feed mode, rank position, and timestamps. We use this information to operate the feed, remember activity, calculate aggregate performance, and derive topic or creator affinities and recommendation groupings.
Visitors who are not signed in receive a random identifier in the essential asiago_viewer HTTP-only session cookie. Server-side activity may be associated with that identifier. If a visitor signs in and accepts the current policies, Asiago may merge the matching browser session’s viewing and preference history into the account.
Search terms are used to return results. The application does not maintain a separate search-history field, but URLs or query parameters may appear in proxy, access, or error logs. The production log-format and redaction review must be completed before this candidate is published.
Public profiles, comments, and community activity
If these features are enabled and you choose to use them, we collect profile fields such as display name, handle, and biography, plus comments, votes, reposts, and follower/following relationships. Public profile fields, comments, aggregate vote counts, follower/following counts, and repost collections may be visible to anyone and may be copied or reshared by others.
Watch history, private likes, authentication information, and recommendation scores are not intended to be public. A public profile must require explicit opt-in; ordinary viewing or engagement must not silently create one.
Comments may be analyzed and grouped with similar comments into audience themes used as bounded input to future fictional stories. A vote or comment does not control a storyline or guarantee attribution.
Creator interest and applications
Creator subscriptions are “Coming soon”; no subscription, payment, entitlement, or publication guarantee is offered at launch. If a separate creator-application feature is later enabled, it may collect account identity, proposed creator information, concept and performance text, rights and AI acknowledgments, identity/reference images, optional voice recordings, review status, and reviewer notes.
Creator intake and publication remain disabled until a separate Creator Program Agreement, privacy workflow, consent/release process, vendor review, and asset-deletion procedure are approved.
Communications, reports, and legal requests
We collect information you provide when you ask for support, exercise a privacy right, report content, appeal a decision, submit a copyright complaint, or otherwise contact us. Please provide only information reasonably necessary for the request.
Device, log, and security information
Asiago’s servers and service providers may process IP address, user agent, requested URL, timestamps, response codes, referrer, security events, and related diagnostic information. Web-server access and error logging are enabled. Final production log fields, access, rotation, and retention must be verified against the 30-day target below.
The site currently requests fonts from Google-hosted domains, so a visitor’s browser may contact Google and disclose ordinary connection information such as IP address and user agent. Release Integration should self-host the fonts or retain this disclosure after verifying the live behavior.
2. How we use information
We use information to:
- provide and secure public viewing, accounts, sessions, profiles, comments, follows, and reposts;
- remember viewing activity and provide or evaluate recommendations;
- measure playback, engagement, reliability, and service performance;
- organize community feedback into bounded story-development signals;
- operate future creator review only after its separate launch requirements are met;
- detect abuse, protect people and systems, enforce policies, and investigate complaints;
- respond to support, privacy, safety, copyright, and legal requests;
- comply with law and establish, exercise, or defend legal claims; and
- maintain, troubleshoot, and improve Asiago.
We do not use private messages, support data, authentication data, sensitive-trait inferences, precise location, or vulnerable emotional states for advertising. No advertising is enabled on day one.
3. AI processing
Asiago uses AI systems to create fictional entertainment, analyze content quality, organize audience feedback, and support recommendations. Current repository capabilities include local LTX/ComfyUI/Ollama/Whisper processing, OpenRouter with a configurable downstream model for scripting or creator concepts, and FAL/MiniMax generation capability. A capability in source is not proof that it is enabled for every production request.
If comments are enabled, a summarized audience theme may become part of later story-development input. Creator application text or media must not be sent to an external AI provider until the exact provider, model, retention, training, rights, security, region, and contract terms are approved and disclosed.
Do not put passwords, government identifiers, financial details, health information, precise location, private messages, or other sensitive information in comments, creator concepts, prompts, or uploads.
4. Service providers and other disclosures
Asiago does not sell personal information for money, does not share personal information with advertisers, and does not share it for cross-context behavioral advertising. Day-one paid ads, house promotions, advertiser ingestion, advertising targeting, billing, and advertising trackers are disabled.
Asiago may disclose information:
- to infrastructure and service providers that process it only to provide contracted services, such as rented public-web, GPU, storage, backup, authentication, font, AI-processing, communications, security, and professional services;
- to Google when you choose Google sign-in, and through the current remotely hosted font request;
- to OpenRouter and a configured downstream model, or FAL/MiniMax, only when the corresponding AI capability is enabled and approved;
- publicly when you intentionally use a public profile, comment, repost, or other public feature;
- at your direction or with your consent;
- when reasonably necessary to comply with law, legal process, or lawful government request, or to protect rights, safety, and security; and
- in a merger, financing, acquisition, bankruptcy, reorganization, or sale of all or part of the business, subject to applicable law and notice requirements.
Keeping data on rented servers still involves infrastructure providers that may process or host the data. The exact live vendor names, regions, subprocessors, retention/training terms, security terms, and contracts are under verification and must be added or linked before publication if required for an accurate notice.
5. Cookies and similar storage
Asiago uses only service-operation storage in the inspected launch source:
| Storage | Purpose | Duration |
|---|---|---|
asiago_viewer HTTP-only cookie | Assign a random anonymous viewer session and protect write identity from caller spoofing | Session cookie with no fixed persistent expiry; normally ends when the browser session ends |
| Authentication cookies | Maintain account login, security, and session continuity | Until the configured session expires, you log out, or the session is revoked |
| OAuth state or verification storage | Complete an authentication request and prevent abuse | Short-lived, according to the authentication flow |
| Limited browser session/local storage | Interface state and removal of an older client-side viewer identifier | Session or until cleared by the application/browser |
The inspected launch source does not include a third-party analytics SDK, advertising cookie, payment cookie, or cross-site advertising tracker. Google or linked sites may set or use their own storage after you choose their services; their policies apply to them.
A valid Global Privacy Control or equivalent opt-out preference signal will be treated as a request to opt out of sale or cross-context advertising sharing. Asiago’s day-one posture already prohibits those practices. Technical handling must be verified before publication; this sentence is not a claim that every signal is presently detected.
6. Retention
Asiago has adopted the following maximum routine retention targets. They are release requirements, not a claim that current systems already delete automatically. This candidate must not be published as an implemented schedule until operations verifies purge, synchronized deletion, provider handling, legal holds, and backup expiry.
| Record class | Retention target |
|---|---|
| Anonymous viewer identifier, raw viewing events, and derived affinities | 90 days after last activity; then delete or de-identify |
| Account, profile, follows, reposts, and account preferences | While active, then 30 days after verified deletion request or closure |
| Sessions and OAuth tokens | Until expiry, revocation, or closure; purge expired/revoked credentials within 30 days |
| Terms/privacy acceptance | 7 years after account closure, separated from active product data |
| Public comments and votes | While public, then 30 days after deletion or account closure |
| Closed moderation, safety, privacy, and support cases | 3 years after closure |
| Copyright, repeat-infringer, and legal-notice records | 7 years after closure or final action |
| Unfinished creator applications | 30 days after last activity |
| Rejected/withdrawn applications and original identity/voice assets | 90 days after rejection or withdrawal |
| Accepted creator records and licensed assets | Active relationship plus 1 year, subject to the future agreement and rights holds |
| Removed/rejected generated media, temporary inputs, and worker jobs | 30 days after final disposition |
| Published media and provenance | While published, then 90 days after removal, subject to rights/legal holds |
| Application, proxy, access, error, and security logs | 30 days, except evidence retained in an applicable case |
| Backups and snapshots | 35-day rolling maximum |
Records may be retained longer when reasonably necessary for a documented legal obligation, legal claim, fraud/security investigation, safety case, or rights dispute. Access must be restricted and the hold reviewed. Deleted active data may remain in protected backups until the 35-day cycle expires; it must be suppressed from ordinary restoration.
7. Your choices and privacy rights
You may ask to access, correct, delete, or receive a portable copy of personal information associated with you by contacting privacy@ppgs.global. You may also object to or request restriction of certain uses, appeal a denied privacy request where applicable, or use an authorized agent where law permits.
We may verify your identity and the authority of an agent before fulfilling a request. We will not discriminate against you for exercising a privacy right. A lawful exception or documented hold may limit a request; if so, we will explain the basis when permitted.
Depending on the state where you live and whether applicable legal thresholds are met, you may have additional rights to know categories or specific pieces of information, correct inaccuracies, delete information, obtain a copy, opt out of sale/sharing or targeted advertising, limit certain sensitive-data uses, and appeal a decision. Asiago’s launch posture is not to sell or share personal information for cross-context advertising.
Self-service deletion and the full two-server/provider deletion workflow are not yet implemented. Until they are, verified requests must be handled through the privacy contact under a tested manual process before account/community activation.
Revoking Google access through Google Account settings does not by itself delete the Asiago account or Asiago-held records.
8. Children and teenagers
Asiago is not directed to children under 13, and account creation requires an attestation that the user is at least 13. If you are 13 through 17, use Asiago only with the permission of a parent or legal guardian. If we learn that we collected personal information from a child under 13 without legally sufficient authorization, we will take appropriate steps to delete it.
Parents, guardians, or others with a child-privacy concern may contact privacy@ppgs.global or safety@ppgs.global.
9. Security
Asiago uses administrative, technical, and physical safeguards designed for the nature of the information processed. Source-level measures include HTTPS-oriented deployment, server-side secrets, HTTP-only anonymous identity, access-controlled administrative routes, rate limits, restricted permissions for identified data files, and publication holds for creator media. No storage or transmission method is completely secure.
Production verification is still required for encryption at rest and in backups, OAuth-token protection, administrator access review, secret preflight, incident response, recovery, patching, vendor security, and live route authorization. This policy does not claim controls that have not been verified.
10. United States processing
Asiago is offered only in the United States at launch. Information is primarily stored on rented infrastructure selected by PPGS Global LLC. Some service providers may process information in other regions under their own infrastructure. Exact provider locations and transfer terms remain part of the processor audit.
11. Changes to this policy
We may update this policy to reflect changes in the service or law. We will post the revised version and effective date and provide additional notice or renewed assent when legally required. Material account-policy changes must be versioned so the service can request new acceptance.
12. Contact
PPGS Global LLC
11756 Borman Drive
St. Louis, MO 63146
Privacy: privacy@ppgs.global
General support: support@ppgs.global
Safety and community complaints: safety@ppgs.global
Legal notices: legal@ppgs.global
Copyright complaints: dmca@ppgs.global
ASIAGO