Privacy Policy

1. Scope

This policy explains how AgentCharacters ("we") handles personal data when you browse this website, create or access an account, buy a one-time digital character license, use a purchased character, or contact support.

2. Information We Handle

Depending on how you use AgentCharacters, we handle:

  • Account and support data: your email address, authentication-provider account identifier and profile fields the provider returns, and information you include in support messages.
  • Purchase and access data: order and payment identifiers, the character or collection purchased, amount, currency, payment or refund status, and information needed to provide access to your license. Dodo Payments collects and processes payment-card and billing data. We do not store raw card numbers or card security codes on our servers.
  • Essential technical data: Supabase authentication session information, your consent choice, and technical request or security data that our hosting and service providers process, such as IP address, user agent, and timestamps.
  • Analytics and advertising data, when you consent: with Analytics enabled, Google Analytics client and session identifiers, pages and product interactions, device and browser information, landing page, referrer, and UTM campaign parameters; with Advertising enabled, Google advertising click identifiers such as GCLID, GBRAID, and WBRAID, Meta click and browser identifiers such as FBCLID, FBC, and FBP, and explicit Meta Pixel page-view, product-view, and checkout-start events. For Meta server-side verified-purchase measurement, we also preserve the consented browser user agent and a one-way SHA-256 hash of the normalized purchaser email. We may preserve permitted attribution values through checkout and associate them with a verified purchase.

3. How and Why We Use Data

We use the information described above to:

  • authenticate users and maintain account sessions;
  • create checkout sessions, confirm purchases and refunds, and provide access;
  • answer support requests and protect the website against abuse or fraud;
  • meet accounting, tax, security, and other legal obligations;
  • understand website and product performance when analytics consent is granted; and
  • attribute Google and Meta ad clicks and enable remarketing or personalized ads when Advertising is granted, and measure verified purchases and refunds in GA4 when Analytics is granted. A consented verified purchase may also be sent directly from our server to Meta for attribution and advertising measurement. A Google Ads purchase can be reported only through the separately configured GA4 import. The browser Meta Pixel does not send a purchase event.

Where applicable, essential account, purchase, security, and compliance processing is based on providing the service you request, complying with law, and our legitimate interests in operating and protecting the service. Analytics and advertising processing by Google and Meta that requires consent is based on your choice.

4. Cookies and Your Choices

Supabase authentication cookies are essential for signing in and keeping your account session secure. They are not used for advertising and cannot be disabled through the analytics consent control if you choose to use account features.

Google Consent Mode starts with analytics storage, advertising storage, advertising user data, and advertising personalization denied. We enable the categories you accept only after you make a choice. In denied mode, Google tags do not read or write analytics or advertising cookies, and we do not send hashed user-provided data. Depending on the tag configuration, Google may receive limited cookieless technical or consent-status signals.

Analytics and Advertising are independent choices. Advertising alone may store ad-click identifiers and enable remarketing or personalized ads and may enable Meta verified-purchase measurement. Google verified purchase and refund measurement requires Analytics. The application does not send a second, direct Google Ads purchase conversion; the intended primary Ads conversion is one import of GA4's verified purchase event.

We recognize a browser-enabled Global Privacy Control signal as an opt-out of Advertising. While the signal is active, we keep Google advertising signals, Meta Pixel activity, advertising identifiers, and new Meta server-side Purchase authorization off; the Advertising control remains disabled. On a first visit with this signal, optional Analytics also starts off without showing a consent prompt. You may separately enable Analytics from Privacy choices, and you can review the applied signal there at any time.

The Meta Pixel script is not requested before you enable Advertising. If enabled, Meta may set or read first-party FBP and FBC cookies and receive explicit page-view, product-view, and checkout-start events for measurement and advertising. If you complete a verified purchase while Advertising is enabled, our server may send Meta a Purchase event with the payment identifier, product, value, currency, permitted FBP/FBC values, browser user agent, and hashed email. Your browser Advertising choice controls Meta Pixel activity and Meta cookies on this browser. When you are signed in, we also record the current choice for your account to control server-side Meta Purchase measurement across devices. We check current-notice Advertising consent when payment is verified and immediately before a queued event is sent. Withdrawing stops new Pixel events in this browser, removes the Meta cookies this website can remove, and, once the signed-in account change is received, suppresses server Purchase events not already sent or in flight. Enabling Advertising again does not revive a suppressed purchase. The browser Pixel itself does not send a purchase event.

We store your browser choice on your device so it persists between visits. When you are signed in, we also store the account-level Advertising state, a change revision, and a random choice identifier needed to enforce it for queued server events and make cross-tab or checkout retries idempotent. The choice identifier is operational consent metadata and is not sent to Meta. We retain its account-linked receipt until account deletion so a delayed duplicate withdrawal cannot override a later choice. You can reject optional processing or withdraw a previous choice at any time using the Privacy choices control on the website. A new choice applies to future processing and does not undo processing that occurred while an earlier choice was active. A withdrawal cannot recall an event already delivered to Meta or reliably cancel an external request already in flight.

5. Hashed Conversion Measurement

If you enable both Analytics and Advertising and complete a verified purchase while signed in, we may normalize your email address and transform it with SHA-256 hashing before sending the hashed value to Google for Enhanced Conversions. Google may use the hash to improve conversion attribution by matching it to information associated with a signed-in Google account. We do not send raw email addresses in page URLs or ordinary analytics events. If Advertising is enabled, we separately normalize and hash the email according to Meta's matching format before it may be included in Meta's server-side Purchase event; we do not send Meta the raw email.

6. Service Providers and Recipients

We use the following providers for the stated purposes:

  • Supabase for authentication, account data, purchase-access records, and database services;
  • Dodo Payments as payment provider and Merchant of Record for checkout, payment, tax, fraud, and refund processing;
  • Vercel for website hosting, delivery, and operational request logs;
  • Google for Google sign-in when you choose it, and, subject to your consent choice, Google Analytics, Google Ads, attribution, remarketing, and conversion measurement;
  • Meta for, subject to your Advertising choice, Meta Pixel ad attribution, page and product interaction measurement, server-side verified purchase measurement, remarketing, and personalized advertising; and
  • GitHub for sign-in when you choose it.

These providers process data under their own terms and privacy notices and may process it in countries other than yours. We do not sell personal data for money. Google Ads audience and Meta advertising or measurement activity may be treated as targeted advertising or "sharing" under some privacy laws; you can reject or withdraw it through Privacy choices. Google also describes its business data responsibilities. Meta describes its practices in the Meta Privacy Policy.

7. Retention and Security

We keep information only for as long as reasonably needed for the purposes described above, including providing licenses, resolving disputes, securing the service, and meeting accounting, tax, or other legal obligations. The period varies by data type and applicable requirements. Service providers also apply the retention settings and obligations described in their own notices.

We use technical and organizational safeguards appropriate to the nature of the information, but no online service can guarantee absolute security.

8. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, withdraw consent, or complain to a data-protection authority. Some purchase records may need to be retained when law requires it. Contact us to make a request. We may need to verify your identity before acting on it.

9. Changes to This Policy

We may update this policy when our practices or legal obligations change. We will post the revised version here and update the date below.

10. Contact and Operator

AgentCharacters is operated by Suphi Kadir Ozarpaci in Türkiye. Suphi Kadir Ozarpaci is the data controller responsible for the personal data described in this policy.

For privacy questions or requests, email support@agentcharacters.com.

Last updated: August 14, 2026