Microdrama AI IconMicrodrama AI Logo
Create Drama

Huling na-update: 13 August 2026

Privacy Policy

This policy explains what personal data we collect when you use Microdrama AI, the legal basis on which we process it, who we share it with, how long we keep it, and which rights you can exercise under Law Number 27 of 2022 on Personal Data Protection.

1. Data Controller

The controller of the processing described in this policy is PT Redrama Inovasi Global, with its office at Infiniti Office, Menara Cakrawala, 12th Floor, Unit 05A, Jalan M.H. Thamrin, Kebon Sirih, Menteng, Central Jakarta 10340, Indonesia.

For privacy questions, requests to exercise data subject rights, or objections to processing, contact us at support@microdrama.id with the subject Personal Data Request, or at the postal address above.

This policy applies to microdrama.id, the studio application at studio.microdrama.id, and the accompanying interfaces. It does not apply to third-party sites or services you may reach through links from our Services.

2. Personal Data We Collect

Identity and account data. Email address, display name, profile picture, email verification status, the identity provider you use together with your identifier at that provider, time zone, and last sign-in time.

Creative content and activity data. Text prompts you write, scripts, titles, descriptions, cover art, reference material you upload, character and visual style configurations, render task history, and the dramas and episodes you produce, whether still private or published.

Transaction and monetisation data. Purchase history for Credits, Coins, and VIP subscriptions; Credit and Coin balances and movements; paid-episode unlock history; creator earnings records; payout requests and their status; and bank account details and taxpayer identification number if you join the Monetisation Programme. We do not store your full payment card numbers.

Usage and device data. Internet protocol address, browser type and version, operating system, device identifiers, pages accessed, session and watch duration, interactions such as likes, saves, and comments, referral source, and system error logs.

Communications data. The content of messages you send through the in-product messaging feature, public comments, content reports you file, support requests, feedback, and your correspondence with our team.

Microdrama Academy learning data. The courses you enrol in, the sections you mark as done, your completion time, and the certificate number issued to you. Your name appears on the certificate verification page only if you give explicit consent when completing the course. You may withdraw that consent at any time by contacting us, and withdrawing it does not revoke a certificate already issued.

3. How We Obtain Data

We obtain data directly from you when you register, complete your profile, create and publish work, make purchases, apply for monetisation, or contact support.

We obtain data automatically as you use the Services, through server logs, cookies, and similar technologies as described in the Cookie Policy.

We obtain data from third parties, namely identity providers such as Google when you choose to sign in with that account, and payment service providers that confirm your transaction status to us.

5. Material You Submit to AI Systems

When you run a production process, the prompts and reference material you provide are transmitted to third-party AI model providers for processing, and the results are returned to us and stored in your account. This transmission is technically necessary for the feature to work.

We do not use your prompts, reference material, or work to train our own AI models without your separate and express consent.

We cannot guarantee that the retention and training policies of third-party model providers are entirely within our control. We therefore recommend that you do not enter specific personal data, health data, financial data, trade secrets, or other confidential information into prompts or reference material.

6. Sharing With Third Parties

We do not sell your personal data. We share data only as necessary with the following categories of recipient, each bound by confidentiality and data protection obligations.

Infrastructure and storage providers, namely Cloudflare for edge computing, object storage, video delivery, and protection against automated traffic; and Supabase for the primary service database.

AI model providers, namely OpenRouter as our language model gateway, Google Gemini, OpenAI, MiniMax, and Seedance for script, image, video, and voice generation, and RunPod as a graphics computing capacity provider.

Payment service providers, namely Xendit as our primary payment processor, together with Mayar and Whop for certain payment channels. Transactional email provider Resend, for account verification, notifications, and newsletters.

We may also disclose data to law enforcement, courts, or competent authorities where required by law or to protect the rights, safety, and security of users or the public. In the event of a merger, acquisition, or transfer of assets, data may pass to the successor entity, on notice to you.

7. Transfers Outside Indonesia

Some processing and storage takes place on infrastructure located outside the Republic of Indonesia. The primary service database is currently hosted in the Southeast Asia region with its data centre in Singapore, while AI model providers and some supporting services may process data in the United States, the European Union, and other jurisdictions in which they operate.

We carry out such transfers in accordance with Article 56 of Law Number 27 of 2022 on Personal Data Protection, by ensuring the destination country provides an equivalent or higher level of protection, or by applying adequate and binding safeguards through data processing agreements with the recipient.

By using the Services you understand that your data will be processed across borders as described above. If you object to such transfers, you may contact us, on the understanding that some features may then be unavailable to you.

8. Retention Periods

Account and profile data is kept while your account is active. After you request account deletion, we delete or anonymise account data within thirty calendar days at the latest, except for data we are required to retain under the provisions below.

Financial transaction data, purchase records, creator earnings, and payout evidence are kept for at least ten years from the end of the relevant financial year, in accordance with the corporate document retention obligation under Law Number 8 of 1997 on Company Documents and applicable tax rules.

Moderation records, content reports, and evidence of breaches are kept for a maximum of two years after handling concludes, or longer where connected to an ongoing legal dispute. System access logs are kept for a maximum of twelve months for security and audit purposes.

Work you have published and that viewers have unlocked may be retained to the extent necessary to honour the rights of viewers who have paid and to settle revenue-share obligations, even after your account has been deleted.

9. Data Security

We apply reasonable technical and organisational measures to protect personal data, including encryption of communication channels, role-based access restrictions, separation of development and production environments, email verification, and protection against suspicious automated traffic.

Even so, no electronic system is entirely immune. We cannot guarantee absolute security for data transmitted over the internet. You also play a part by not sharing your account credentials and by telling us promptly if you suspect unauthorised access.

In the event of a personal data protection failure, we will give written notice to you as data subject and to the competent authority no later than three times twenty-four hours after we become aware of it, in accordance with Article 46 of Law Number 27 of 2022. That notice will describe the data disclosed, when and how it was disclosed, and the handling and recovery steps we have taken.

10. Your Rights as a Data Subject

Under Law Number 27 of 2022 you have the right to obtain information about our identity, the legal basis, and the purposes of processing; to access and obtain a copy of your personal data; to complete, update, and correct errors in your data; to end processing of, delete, and destroy your personal data; to withdraw consent you have given; and to object to decisions based solely on automated processing.

You also have the right to postpone and restrict processing proportionately, to obtain and use your personal data in a commonly used, machine-readable format, to transmit that data to another controller where the systems are interoperable, and to claim and receive compensation for breaches in the processing of your personal data.

To exercise these rights, send a request to support@microdrama.id from the email address registered to your account. We may request additional identity verification before acting, in order to protect you against fraudulent requests. We will respond no later than three times twenty-four hours after receiving your request, in accordance with applicable rules.

Some rights may be limited where permitted by law, for example where meeting the request would disclose another person's personal data, impede an ongoing law enforcement process, or conflict with financial record retention obligations. In such cases we will explain our reasons to you.

If you consider our handling unsatisfactory, you have the right to complain to the competent personal data protection authority.

11. Cookies and Similar Technologies

We use cookies and local storage to keep you signed in, remember your language and region preferences, protect forms against automated abuse, and understand page usage in aggregate.

A full description of the cookies we use, their purposes, and how you can manage them is set out in the Cookie Policy, which forms an integral part of this policy.

12. Children's Data

The Services are not directed at children and are intended only for users who are at least eighteen years old. We do not knowingly collect children's personal data.

If we learn that we have collected personal data from someone under eighteen, we will suspend the account concerned and delete that data within a reasonable time. A parent or guardian who believes their child has provided data to us may contact support@microdrama.id so that we can act promptly.

13. Changes to This Policy

We may update this Privacy Policy as the Services develop, as we adopt new providers, or as the law changes. The date of the most recent update always appears at the top of this page.

For material changes, such as adding a new processing purpose or a new category of data recipient, we will give notice by email or inside the Services before the change takes effect, and where required by law we will seek your consent again.

This English text is a translation provided for convenience. The Indonesian version of this document is the binding version, and it prevails in the event of any difference in interpretation.

Kaugnay na dokumento