Chinese company subject to PRC intelligence laws requiring government data cooperation; 2020 breach of 13M users with possible lack of user notification; disputes must be litigated in Chinese courts (Chengdu) making recourse impossible for most users; no SOC 2/ISO certifications; NowSecure flagged mobile app risks; data sovereignty risk is maximum for a non-China-classified company.
AIGC data stored on AWS US servers (not Chinese servers); explicit prohibition on face data use for training or identification; face data deletion available after use; company states it does not sell personal data to third parties; users can delete AIGC inputs; face data specifically protected from marketing use.