Effective date: 1 October 2026
This policy describes GigiPixel, the AI video and image generation app. The public site name is OCS Yazılım. The developer name on Google Play is the name shown on the store listing. The Android package id is com.gigicorporation.gigipixel. This policy does not include a postal address.
Privacy contact: support@ocsyazilim.com
In the app, Privacy Policy, Terms, and support open these pages and this contact address.
GigiPixel generates AI video and still images from photos, videos, and prompts that you choose to submit. You can open and look through the app without creating an account. Generating video, receiving rewarded-ad credits, and attaching a Google Play purchase to an account require a Google account.
App code asks Google Sign-In for the OpenID scope and then sends the Google ID token once to our server so the server can verify it. The app and the server do not store that ID token.
On Android, the Google Sign-In library used by this app also requests the account email and the basic profile for a standard sign-in. When a server client id is configured, that library requests an ID token and a one-time server auth code. It does not request a refresh token. App code does not read the email, name, profile photo, or server auth code, and it does not request a Google access token. App code does not read or store a Google password.
After verification, the server stores the Google account identifier. It does not store your email address, name, or profile photo. Verification reads the token issuer and that account identifier. If Google includes email, name, or a profile photo in the token, those details exist in server memory only while that token is verified, and they are not saved.
We create an account identifier on our server. It connects your jobs, credits, and signed-in devices. A copy is kept on the device in secure storage so the app can recognize the account.
A device credential is a random token stored on the device. The server stores only a SHA-256 hash of that token, not the token itself. The token is sent to our server to authorize requests. It is not sent to OpenAI, Modal, or RunPod in the generation payloads.
An older client id may still exist in app preferences until you sign out of the device or delete the account. Signing out removes the credential for that device only. Deleting the account removes every device credential linked to that account.
When you generate, the app can upload a photo, a video, and a text prompt. The server stores those uploads, the prompt in the job record, generated video or image files, and, when output is rejected, a quarantine copy.
Moderation samples frames from a video into a temporary folder, sends those frames for review, and deletes that temporary folder when the review call finishes.
The current production path uses these processors for the data described here:
com.gigicorporation.gigipixel.The application code does not read the advertising identifier, and our server does not store it. The Android release manifest includes the Advertising ID permission because the Google Mobile Ads library declares it. That library also declares Advertising Services permissions for ad ID, attribution, and topics. Google’s disclosure for this SDK version says the SDK collects, by default, device IP address, product interactions, diagnostic information, and device or account identifiers, including the Android advertising ID. Those SDK practices belong to Google. This policy does not complete the Play Data Safety form for that SDK.
The app does not include Firebase, Crashlytics, Sentry, or a separate analytics SDK in its current dependencies.
The current server defaults are: uploads 24 hours; completed outputs 7 days; quarantine copies 24 hours; terminal job metadata 7 days. Terminal job metadata means a job that has finished as completed, error, blocked, or cancelled. An active job is not removed by that metadata timer. Rewarded-ad sessions are valid for a short session window. Expired sessions are deleted after a cleanup period that defaults to 24 hours after the session expiry time.
Those periods can be changed in server configuration for security or operations. If a configured value is missing, not a number, or not greater than zero, the server uses the default above. This policy states the defaults. It does not promise that a future configuration will keep the same numbers.
These records are not on that short timer: your account, device sign-in records, credit history, credit balance, Google Play purchase records, and rewarded-ad transaction records. A deletion record can also remain so a deleted account is not treated as an active one. They stay until the account-deletion rules below, and some of them stay after deletion.
To request deletion without opening the app, use the privacy contact at the bottom of this page. That contact is the external request path. Sending the request does not delete the account by itself. The same rules below apply when the request is handled.
If you delete your account and the server accepts the request, we remove the Google account link, every device credential for that account, rewarded-ad sessions for that account, uploaded files, generated files, quarantine copies for that account’s jobs, the saved prompt for those jobs, and the stored job response. On the device, after the server confirms deletion, the app removes the device token, the stored account id, the older client id, and the local job history.
Deletion does not erase every record. For fraud prevention, purchase verification, and stopping the same purchase or rewarded-ad transaction from granting credits twice, we can keep:
Purchase and rewarded-ad records that named your account are separated from that account. They no longer belong to an active account. A new Google sign-in after deletion creates a new account. That new account cannot open the deleted media or the deleted jobs, and it does not receive the deleted account’s credit balance.
Protected generation, purchase, and rewarded-ad session requests require the device credential. The server stores that credential only as a SHA-256 hash. Release builds of the app are required to call the API over HTTPS. This policy does not claim a particular certification or that files are encrypted at rest.
This version of the app does not ask for your date of birth and does not apply an age gate. This policy does not state an age limit, because the app does not implement one.
If this policy changes, the effective date at the top of this page will change. The app does not store an email address, so it does not send policy updates by email.
Privacy questions, and account-deletion requests made outside the app, go to support@ocsyazilim.com.
In the app, the path is delete account. Contact Support and Report a Problem use support@ocsyazilim.com.