隐私政策
1. 谁负责处理信息
本政策中的“我们”指 ImageHalo。有关账户、隐私、付款或退款的问题,请通过本页“客服与联系”部分列明的专用邮箱联系我们。
2. 我们处理哪些信息
- 账户信息:用户名、邮箱地址、密码哈希、账户状态与创作点余额。
- 创作内容:提示词、上传的图片或参考素材、生成和编辑结果、项目及版本关系。
- 服务与安全记录:登录和请求时间、IP 地址、设备或浏览器相关请求信息、任务状态、错误及安全审计记录。
- 交易记录:订单号、点包、金额、币种、付款状态和 Stripe 交易标识。银行卡或支付宝账号等支付工具信息由 Stripe 处理,我们不在应用数据库中保存完整卡号。
- Cookie:用于保持登录、CSRF 防护和语言/界面偏好所必需的 Cookie 或本地存储。
3. 处理目的和方式
我们仅为创建和维护账户、执行图片生成或编辑、保存作品历史、完成付款和退款、保障安全、防止滥用、处理客服或权利请求,以及履行法律义务而处理这些信息。我们不会将你的私人作品作为公开社区内容,除非你主动执行明确的公开分享操作。
4. 第三方处理与数据流转
为完成服务,必要信息可能发送给 Stripe、托管和存储供应商,以及部署时配置的模型服务商(可能包括 Azure OpenAI 或 OpenRouter 及其上游模型提供商)。这些服务可能在你所在地区以外处理数据,并适用各自的隐私和安全规则。请勿上传不适合交由这些服务处理的敏感素材。
5. 保存、删除与安全
可选访问统计:仅在启用 Google Analytics 4 且你明确同意后,我们才加载 Google 的统计脚本并使用统计 Cookie,衡量访问、注册、生成和购买转化。统计包含浏览器与设备信息、简化页面地址、来源网站、功能事件,以及购买时的订单编号、套餐、金额和币种;我们不主动发送邮箱、用户名、提示词或图片内容。Google 可能在你所在地区以外处理这些信息。拒绝不影响服务,可随时通过本节的“更改 Cookie 选择”撤回并清除本站统计 Cookie。偏好和统计 Cookie 最长保存 180 天;Google 端事件数据保存期限以部署时设置为准(默认接入指引为 2 个月)。撤回不会自动删除已发送的数据,可联系客服提出相关请求。详情参见 Google 隐私政策。
账户资料、生成记录与作品当前会在账户有效期间保存,以支持历史查看和继续编辑;订单和安全记录会按财税、反欺诈及争议处理所需期限保存。收到有效删除请求后,我们会在法律允许且不影响未决付款、争议或法定义务的范围内删除或去标识化相关信息。备份和日志可能在受控轮换周期内延迟清除。
当前产品尚未提供完整的账户内“一键删除账户”界面。你可以通过本页公开的客服邮箱提出访问、更正、复制、删除、撤回同意、限制处理或注销请求。
6. 你的权利
在适用法律范围内,你可以询问我们处理了哪些个人信息,要求访问、更正、复制或删除,撤回基于同意的处理,注销账户,或对自动化处理和跨境传输提出问题。为保护账户,我们可能要求进行合理的身份核验。
7. 未成年人
ImageHalo 面向具备相应民事行为能力的用户,不以未满 14 周岁的儿童为目标。未满 18 周岁的用户应在监护人阅读并同意本政策与服务条款后使用。若监护人认为儿童信息被不当提交,请通过客服渠道联系我们核实并处理。
Privacy Notice
1. Who is responsible for your information
“We” means ImageHalo. For account, privacy, payment, or refund questions, contact us through the dedicated email listed under “Support & Contact” on this page.
2. Information we process
- Account data: username, email address, password hash, account status, and creation-credit balance.
- Creative content: prompts, uploaded images or references, generated and edited results, projects, and version relationships.
- Service and security records: login and request time, IP address, device or browser request data, task status, errors, and security audit records.
- Transaction records: order number, credit pack, amount, currency, payment status, and Stripe transaction identifiers. Payment-instrument information, such as full card details, is handled by Stripe and is not stored in the application database.
- Cookies: essential cookies or local storage used for login, CSRF protection, and language or interface preferences.
3. Why and how we process it
We process this information only to create and maintain accounts, perform image generation or editing, retain work history, complete payments and refunds, secure the service, prevent abuse, handle support or rights requests, and comply with legal obligations. We do not publish private work to the community unless you take an explicit sharing action.
4. Third parties and international processing
To provide the service, necessary information may be sent to Stripe, hosting and storage providers, and model services configured by the operator, which may include Azure OpenAI, OpenRouter, and their upstream model providers. They may process data outside your region under their own privacy and security rules. Do not upload sensitive material that should not be handled by those services.
5. Retention, deletion, and security
Optional analytics: only when Google Analytics 4 is enabled and you explicitly consent do we load Google's analytics script and use analytics cookies to measure visits, registration, generation, and purchase conversion. Analytics includes browser and device information, simplified page addresses, referring sites, feature events, and order ID, pack, amount, and currency for purchases. We do not intentionally send email addresses, usernames, prompts, or image content. Google may process this information outside your region. Declining does not affect the service. Use “Change cookie choice” in this section to withdraw and clear this site's analytics cookies. Preferences and analytics cookies last up to 180 days; event retention at Google follows the deployment setting (our setup guide specifies 2 months). Withdrawal does not automatically delete previously sent data; contact support for related requests. See the Google Privacy Policy.
Account details, generation records, and work are currently retained while an account remains active so that history and continued editing work. Orders and security records are retained as needed for tax, fraud prevention, and dispute handling. Following a valid deletion request, we delete or de-identify relevant information where permitted and where this does not interfere with pending payments, disputes, or legal obligations. Backups and logs may clear later through controlled rotation.
The product does not yet offer a complete in-account “delete account” control. You can request access, correction, portability, deletion, withdrawal of consent, restriction, or closure through the support email published on this page.
6. Your rights
Subject to applicable law, you may ask what personal information we process, request access, correction, a copy, or deletion, withdraw consent-based processing, close your account, or ask about automated processing and international transfers. We may perform reasonable identity verification to protect the account.
7. Minors
ImageHalo is intended for users able to enter the relevant agreement and is not directed to children under 14. Users under 18 should use the service only after a guardian has reviewed and accepted this notice and the Terms. A guardian who believes a child’s data was submitted improperly should contact support for verification and handling.