Last updated: [DATE]
[LEGAL_ENTITY] ("we", "us") operates PitaHime (pitahime.com). This Privacy Policy explains what personal data we collect, why, and your rights. Payments are processed by Paddle.com as Merchant of Record: when you purchase a subscription, Paddle acts as the data controller for payment and billing data (see Section 7).
We do not collect special categories of personal data.
| Category | Examples | Purpose |
|---|---|---|
| Account data | Email address, username, password (hashed) | Account creation, login, service emails |
| Payment metadata | Plan, billing period, invoice reference | Membership management (card data handled solely by Paddle — we never see or store full card numbers) |
| Usage data | Feature interactions, model uploads, streaming sessions | Operating and improving the Service |
| Device / log data | IP address, browser type, device identifiers | Security, fraud prevention, debugging |
| Support data | Messages you send us | Handling inquiries |
We use strictly necessary cookies for login sessions. You can control cookies via your browser settings.
We do not sell personal data or use it for third-party advertising.
Your data is hosted in Singapore (cloud infrastructure) with CDN delivery via Cloudflare. Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms.
Current as of [DATE]; an up-to-date list is available on request.
| Provider | Role | Data |
|---|---|---|
| Paddle.com | Merchant of Record, payments, tax | Billing data, card data (as controller for payment) |
| Neon / cloud host | Database hosting | Account and service data |
| Upstash | Redis (sessions, rate limiting) | Session and rate-limit data |
| Cloudflare | CDN, WAF, bot protection (Turnstile) | IP, request metadata |
| Resend | Transactional email | Email address, email content of verification/receipt mail |
Depending on your jurisdiction (EU/UK GDPR, CCPA/CPRA, and others), you may have the right to:
We apply encryption in transit (TLS), hashed passwords, encrypted model files, least-privilege access, and audit logging. No system is perfectly secure; we notify affected users and authorities of breaches as required by law.
The Service is not directed to children under 13 (or the applicable minimum age). We delete data of children we learn to be under that age.
We will post any changes here and update the "Last updated" date; material changes will be notified by email or in-product notice.
Privacy contact: [LEGAL_ENTITY], [ADDRESS] — support@pitahime.com