1. What this policy covers
This policy covers Infoholder App Studio: the website, the account you sign in with, the projects you build here, and the sites you publish from here. HONG KONG WALLET COMPANY LIMITED is the controller of the personal data described below.
It does not cover the sites you build. Once you publish a project, the site is yours: you decide what it collects from its visitors, and towards those visitors you are the controller. We process what your site stores only as your service provider. Section 8 says what that means in practice.
App Studio is a product for professional and business use. You must be old enough to enter a contract where you live, and at least 16. We do not knowingly build accounts for children, and we do not design anything here to be attractive to them.
2. What we collect
- Account: your name, your email address, a hashed password, and the email verification codes used while you sign up or reset it. Your password itself is never stored in a form we can read.
- Workspace: which workspace you belong to, your role in it, and invitations you send or accept.
- What you put into a project: the prompts you write, files the AI produces or you edit, images and 3D models you upload, project settings, and the version history of all of it.
- Project secrets: API keys and similar values you store for a project. They are encrypted before they are written down, with a key that is not the session key (see section 10).
- Build activity: the conversation with the AI, the plans it proposed, what you approved or rejected, build and preview logs, and the results of security reviews.
- Publishing: which projects are published, the addresses they serve, and any custom domain you connect.
- Billing: your plan, your usage against its limits, and the invoices Stripe issues. Card numbers go to Stripe and never reach our servers.
- Technical records: IP address, browser user agent, timestamps, the paths you requested and how they ended. These are the ordinary server logs; we keep them to find faults and to notice abuse.
3. What we do not do
This section exists because the absence of something is invisible. If we only listed what we collect, you would still have to guess about the rest.
- No third-party analytics or advertising SDK runs on these pages. Our own product metrics are counters — a number goes up when a page is viewed or a button is pressed. No identifier, no prompt, no project name, no URL is recorded with them.
- No cross-site tracking, no advertising profile, no data broker. We do not sell personal data and we do not share it for advertising.
- We do not train models on your prompts, your code, or your files, and we do not read them to build features. Section 5 covers what the model providers do.
- Our staff do not browse your projects. Access to production data is limited to the people who keep the service running, is used to fix a specific fault or answer a specific request, and is logged.
4. Why we use it
- To run the product: build what you asked for, show previews, keep versions, publish sites, and keep your workspace working. This is how we perform our contract with you.
- To keep accounts safe: verify email addresses, sign you in, detect abuse, and investigate faults.
- To bill you and to enforce plan limits, when you are on a paid plan.
- To send messages the service itself needs: verification codes, invitations, receipts, and notices about changes that affect you.
- To meet legal obligations, such as keeping tax records for the period the law requires.
Where the law we operate under asks for a basis, these rest on performing our contract with you, on our legitimate interest in a service that works and is not abused, and on legal obligation. We do not rely on consent for any of the above, so there is nothing here you would need to withdraw — except the marketing email you never receive, because we do not send any.
5. AI models and your content
Building something means sending it to a model. Your prompt, the parts of your project the model needs to answer, and the errors it is trying to fix are transmitted to the model provider configured for this deployment. There is no way to use the AI without this happening, so it is worth stating plainly rather than burying.
Which providers those are depends on how this deployment is configured; the models currently in use are listed in Settings once you sign in. We use their APIs under business terms. What each provider retains, and for how long, is governed by its own terms — we cannot make promises on their behalf, and we do not.
What we can say for ourselves: we do not train any model on your content, we do not pass it to anyone other than the provider that has to see it to answer, and the conversation stays inside your project.
8. What you publish is public
A published site is served to anyone who has the address. It is not indexed by us, but it is not secret either: an address that is guessed or shared works for whoever holds it. Do not publish something you intend only a few people to see and expect the address alone to protect it.
If you connect your own domain, we obtain a TLS certificate for it. Certificates are recorded in public certificate transparency logs, so the domain name becomes publicly visible — that is how the certificate system works, and it is not something we can turn off.
If your site collects anything from its visitors — a contact form, a sign-up, an order — those visitors are yours, not ours. You decide what to collect and you owe them their own privacy notice. We hold that data for you as your processor, act on your instructions, and delete it when you delete the project.
9. How long we keep it
- Projects, files and conversation history: for as long as the project exists. Deleting a project moves it to the recycle bin, where you can restore it; removing it from there is final.
- Account and workspace records: for as long as your account exists.
- Server logs: kept briefly, long enough to investigate a fault or an incident, then discarded.
- Billing records: for the period tax and accounting law requires, which is longer than your account may last.
- Backups: deleted data can persist in backups until they roll over. It is not restored into the live service, and it expires with the backup.
10. How it is protected
- Traffic runs over TLS. Session cookies are encrypted and HttpOnly.
- Project secrets are sealed with AES-256-GCM under a dedicated key, separate from the session key, so that rotating one cannot destroy the other.
- Builds and previews run in isolated sandboxes, so what one project does cannot reach another.
- Generated code goes through an automated security review before you publish. It is a helper, not a guarantee — section 7 of the Terms says why you still have to look.
No system is beyond reach. If a breach affects your personal data, we will tell you and the relevant authority within the time the law allows, and we will say what actually happened rather than what sounds best.
11. Your rights
Depending on where you live you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or hand it to someone else in a portable form. You can exercise these rights whether or not the law where you live grants them — we do not check your address first.
Much of it you can do yourself: edit your account details, export or delete a project, cancel a plan. For anything else, write to us at the address in section 14. We answer within 30 days, we do not charge for it, and we do not make the service worse for anyone who asks.
You may also complain to your local data protection authority. We would rather you told us first, but that is your choice, not a condition.
12. Where your data goes
The servers that run this service, and the providers in section 7, may be located in a country other than yours. That means your data crosses borders. Where the law requires a safeguard for such a transfer, we rely on standard contractual clauses or an equivalent mechanism with the provider concerned.
13. Changes to this policy
When this policy changes, the effective date at the top changes with it. If a change materially affects you — new categories of data, a new purpose, a new recipient — we will tell you by email or in the product before it takes effect, and not by quietly editing this page.
14. How to reach us
Questions about this policy, or a request about your data, go to:
- Provider
- HONG KONG WALLET COMPANY LIMITED