PitaHime Privacy Policy

Last updated: [DATE]

[LEGAL_ENTITY] ("we", "us") operates PitaHime (pitahime.com). This Privacy Policy explains what personal data we collect, why, and your rights. Payments are processed by Paddle.com as Merchant of Record: when you purchase a subscription, Paddle acts as the data controller for payment and billing data (see Section 7).

1. Data We Collect

We do not collect special categories of personal data.

CategoryExamplesPurpose
Account dataEmail address, username, password (hashed)Account creation, login, service emails
Payment metadataPlan, billing period, invoice referenceMembership management (card data handled solely by Paddle — we never see or store full card numbers)
Usage dataFeature interactions, model uploads, streaming sessionsOperating and improving the Service
Device / log dataIP address, browser type, device identifiersSecurity, fraud prevention, debugging
Support dataMessages you send usHandling inquiries

2. Legal Bases (GDPR)

  • Contract: providing the Service you signed up for (account, hosting models, membership).
  • Legitimate interests: security, fraud prevention, service improvement — balanced against your rights.
  • Consent: optional cookies and marketing emails (withdrawable anytime).

3. Cookies and Analytics

We use strictly necessary cookies for login sessions. You can control cookies via your browser settings.

4. How We Use Data

We do not sell personal data or use it for third-party advertising.

  • Operate, maintain, and secure the Service;
  • Manage subscriptions and entitlements;
  • Send transactional emails (verification codes, payment receipts, security alerts) via our email provider (Section 7);
  • Aggregate, de-identified analytics to improve the product.

5. Data Retention

  • Account data: kept while your account is active; deleted within 90 days of verified deletion request (except where retention is legally required, e.g., billing records — kept up to 7 years by Paddle).
  • Log data: up to 12 months.

6. International Transfers

Your data is hosted in Singapore (cloud infrastructure) with CDN delivery via Cloudflare. Where data is transferred outside the EEA/UK, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms.

7. Third-Party Processors

Current as of [DATE]; an up-to-date list is available on request.

ProviderRoleData
Paddle.comMerchant of Record, payments, taxBilling data, card data (as controller for payment)
Neon / cloud hostDatabase hostingAccount and service data
UpstashRedis (sessions, rate limiting)Session and rate-limit data
CloudflareCDN, WAF, bot protection (Turnstile)IP, request metadata
ResendTransactional emailEmail address, email content of verification/receipt mail

8. Your Rights

Depending on your jurisdiction (EU/UK GDPR, CCPA/CPRA, and others), you may have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate data;
  • Delete your data ("right to be forgotten");
  • Export your data in a portable format;
  • Object to or restrict certain processing;
  • Withdraw consent for consent-based processing.
To exercise any right, email support@pitahime.com. We respond within 30 days. You may also lodge a complaint with your local supervisory authority. California residents: we do not "sell" or "share" personal information as defined by the CCPA/CPRA.

9. Security

We apply encryption in transit (TLS), hashed passwords, encrypted model files, least-privilege access, and audit logging. No system is perfectly secure; we notify affected users and authorities of breaches as required by law.

10. Children’s Privacy

The Service is not directed to children under 13 (or the applicable minimum age). We delete data of children we learn to be under that age.

11. Changes

We will post any changes here and update the "Last updated" date; material changes will be notified by email or in-product notice.

12. Contact

Privacy contact: [LEGAL_ENTITY], [ADDRESS] — support@pitahime.com