Privacy Policy
This policy explains what information Hyaloria processes across accounts, collaboration and creative workflows, why it is used, how long it is kept and how you can exercise your rights.
1. Scope and controller
This policy applies to the Hyaloria web app and its account, team, project and access-key features. The service is currently a non-commercial public beta operated by the Hyaloria project team. The registered entity, address and dedicated privacy contact will be published before paid commercial service begins.
2. Information we process
- Account data: name, email, irreversible password hash, account status and registration time.
- Security data: sign-in time, session identifiers, IP address, browser and device details used for authentication, abuse prevention and audits.
- Collaboration data: workspaces, members, invitations, projects, versions, comments and activity records.
- Creative content: stories, storyboards, prompts, images, videos and other assets you submit. Public beta does not send these to external generation models.
- Key data: platform-key name, permissions, status and hash. The full key is shown only once when created.
3. Purpose and legal basis
We process necessary information only to provide accounts and workspaces, save projects, enable collaboration, protect the service, troubleshoot faults and meet legal obligations. Consent can be withdrawn where processing relies on consent, without affecting prior lawful processing. Some features may be unavailable without essential account or service data.
4. Retention and storage location
Account and project data is generally kept until account closure or deletion, and only while still needed. Security audit records are retained for the shortest period required for security and dispute resolution. Public-beta infrastructure may include servers outside mainland China. The actual storage region and any required cross-border safeguards will be disclosed and assessed before paid service to users in mainland China.
5. Sharing and processors
We do not sell personal information or send creative content to external generation APIs during public beta. When backup, email, object-storage, payment or model providers are enabled, we will update the provider list, impose appropriate safeguards and obtain separate consent where required.
6. Security measures
We use password hashing, session isolation, least privilege, rate limits, admin auditing, backup verification, container isolation and security headers. No internet service is absolutely secure. If an incident may affect your rights, we will take remedial action and meet applicable notification or reporting duties.
7. Your rights
You can review and update certain profile data, manage sessions, keys and projects, and request access, copies, deletion, restriction, consent withdrawal or account closure. Until a dedicated privacy channel is enabled, submit requests through the contact entry on the About page. We will verify identity and respond within a reasonable period.
8. Children
The service is not directed to children under 14. If we discover that a child’s information was processed without guardian consent, we will delete it or take other necessary action promptly.
9. Policy updates
We will provide prominent notice of material changes to processing purposes, methods or data categories. Where renewed consent is required, we will obtain it before continuing. The current version and effective date appear at the top of this page.