Effective date: July 22, 2026
Privacy Policy
How we collect, use, share, and protect personal data
1. Information we collect
This Privacy Policy explains how we collect, use, share, retain, and protect personal data when providing accounts, authentication, Didymoi-owned software, Usage Credits, API usage, and support. You may choose whether to provide non-essential data; refusing necessary data may make a related feature unavailable.
We may collect account email, display name, login methods, OAuth identity information, session information, IP address, user agent, device and browser information, activity logs, API usage records, Usage Credit history, payment order status, provider transaction identifiers, and necessary payment event payloads.
Depending on the features you use, we may also process prompts, messages, files, images, audio, code, other inputs, service outputs, and related metadata that you submit, upload, generate, or transmit, together with task or request records needed for execution, billing, troubleshooting, and security. Do not submit content that you are not authorized to process.
We do not store full card numbers, CVV, or complete payment credentials in this system. Sensitive payment information is processed by authorized payment service providers or acquirers. We may receive order status, amount, currency, transaction identifiers, and event records needed for risk controls.
Information may come from you directly, be generated when you use a feature, be returned by a third-party login or connected service, payment provider, third-party AI or infrastructure provider used to generate results, or be provided by a partner with lawful authorization. We do not intentionally ask you to submit identity documents, card passwords, biometric information, or other sensitive data unrelated to the services in prompts, files, or conversations.
Unless a feature expressly supports the information and we have provided appropriate notice, obtained necessary authorization, or completed an applicable written arrangement, do not submit government-issued identification numbers, complete financial-account details, precise health or medical information, biometric templates, racial or ethnic origin, religious or political beliefs, sex-life or sexual-orientation information, criminal records, or other sensitive personal data that receives special legal protection.
2. How we use information
We use information to create and secure accounts, authenticate users, perform requested software, API, model-inference, and content-generation functionality, process Usage Credit Pack purchases and issuance, meter API usage, create billing records, run security and fraud checks, troubleshoot issues, provide support, and meet compliance and audit obligations.
We may use aggregated operational metrics that do not contain user content and cannot be used to identify an individual to improve performance, reliability, and user experience. Unless you separately and explicitly opt in, we do not use your inputs, files, prompts, or outputs to train or fine-tune Didymoi-owned general-purpose generative AI models. Processing needed to generate requested results, protect the services, detect abuse, or troubleshoot errors is not model training. Third-party model providers process relevant content under their applicable data-processing terms.
Unless you authorize it, law requires it, or it is needed to complete a transaction you request, we do not sell personal data or use account information for personalized advertising unrelated to the services.
3. Legal bases where required
For account creation, authentication, software, API, model-inference, content-generation, subscription, Usage Credit, and customer-support services, we generally process information to perform our contract with you or take requested steps before entering into a contract.
We process necessary information to comply with legal obligations involving transaction, tax, refund, dispute, and compliance records or lawful requests from competent authorities.
We may rely on legitimate interests to secure accounts and services, prevent fraud and abuse, maintain reliability, troubleshoot errors, and establish, exercise, or defend legal claims. We assess those interests against the rights and interests of affected individuals.
We rely on consent for non-essential cookies, marketing, use of customer content for model training, and other processing where consent is required by law. You may withdraw consent at any time, without affecting processing lawfully carried out before withdrawal.
The specific legal basis may vary by location, feature, data type, and our role in relation to an organizational customer.
4. Third-party processors and sharing
To provide the services, we may disclose limited data to identity, database, cloud hosting, storage, email, logging, monitoring, security, customer-support, and other necessary service providers. Applicable contracts or service terms require them to use reasonable confidentiality and security measures.
Some functionality is supported by third-party AI model or infrastructure providers. To generate requested results, execute tasks, detect abuse, or troubleshoot errors, we may transmit necessary inputs, files, context, and technical information to them and receive corresponding outputs or status information. Their processing is also subject to the applicable data-processing terms.
A payment provider, acquirer, seller, or Merchant of Record identified at checkout, which may include Paddle and Stripe, may act as an independent controller or processor for payment, tax, billing, identity-verification, fraud-prevention, and payment-support purposes and apply its own terms and privacy policy. Paddle's Privacy Notice is available at https://www.paddle.com/legal/privacy, and Stripe's Privacy Policy is available at https://stripe.com/privacy. Relevant payment providers may also collect transaction, device, and browser information through their hosted checkout pages, SDKs, embedded components, cookies, or similar technologies for payment processing, authentication, analytics, and fraud prevention and detection. We do not receive complete card details and retain only the order status, transaction identifiers, amount, currency, and event records needed for fulfillment, billing, support, and risk controls.
Where permitted or required by law, we may also disclose necessary information to professional advisers, law-enforcement or regulatory authorities, or relevant recipients in connection with a merger, financing, reorganization, asset transfer, or similar business transaction. If control of the services changes, we provide notices required by law and require the recipient to honor applicable privacy obligations.
5. Cookies and sessions
We use necessary cookies, local storage, or server-side sessions to maintain login state, language preferences, security checks, and OAuth flows. Disabling necessary cookies may make login or purchases unavailable.
Necessary cookies are not used for personalized advertising. If analytics or marketing cookies are introduced, we will provide the choices and controls required by applicable law.
A payment provider's hosted checkout page, SDK, or embedded component may use its own cookies or similar technologies under that provider's privacy and cookie rules. Where required by applicable law, we or the relevant provider will provide notice, consent, or management choices for non-essential technologies.
6. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy. The period depends on the data type, account status, service security, dispute handling, and applicable legal, tax, accounting, payment, fraud-prevention, and audit requirements.
Session data, verification codes, and temporary authorization records are generally retained only as long as needed for login, security checks, or authorization. Account data is generally retained while the account remains active. Order, Usage Credit, subscription, refund, chargeback, payment-event, and audit records may be retained after a transaction is completed or an account is closed for fulfillment, reconciliation, disputes, fraud prevention, and legal obligations.
When the purpose and applicable retention period end, we delete, anonymize, or securely handle the information as permitted by law. You may request account or personal-data deletion through the Contact page. We process the request after identity verification, except for information that must be retained by law or to establish, exercise, or defend legal claims; that information is handled when the relevant basis for retention ends.
7. Security
We use access controls, server-side secret isolation, encrypted transport, audit logs, and least-privilege principles to protect data. No internet service can guarantee absolute security.
If an incident may affect personal-data security, we will contain, investigate, remediate, and provide notices as required by applicable law, with cooperation from relevant processors.
8. Your rights
Subject to applicable law, you may request access, correction, deletion, or export of your personal data, object to or restrict certain processing activities, and withdraw consent at any time for processing based on consent.
To submit a privacy request, contact us using the support email listed on the Contact page. We may need to verify your identity before processing the request.
Please identify the account email, request type, data scope, and preferred reply method. We will respond within a reasonable period; if we cannot complete a request, we will explain why and identify available appeal or complaint channels.
9. Children’s privacy
The services are intended only for users who are at least 18 years old. Persons under 18 must not register for, purchase, or use the services.
If a guardian believes that a person under 18 has provided personal data to us, contact us through the Contact page. After necessary verification, we will delete or otherwise handle that information as required by applicable law.
10. International transfers
We and our service providers may process and store personal data outside your country or region, including countries where their operating facilities, cloud infrastructure, or support personnel are located. The actual processing locations depend on the services, infrastructure, and providers used.
For international transfers, where required by applicable law, we use applicable contractual arrangements, adequacy decisions, certification mechanisms, statutory derogations, or other recognized transfer mechanisms together with reasonable security measures such as access controls and encryption.
Where applicable law gives you the right to information about the transfer mechanism or a copy of relevant safeguards, you may submit a request through the Contact page. We may provide available information without disclosing trade secrets or security-sensitive material.
11. Policy updates
We may update this Privacy Policy as our services, laws, technology, or security practices change. Updated versions will be posted on this page with a new effective date.
For material changes involving processing purposes, data types, sharing recipients, or user rights, we will provide notice through the page, in-product notices, or another method required by applicable law.
12. Controller, processor, and privacy requests
Didymoi / Didymoi Cloud is a software and online-services brand independently operated by its developer. That operator determines the purposes and means of Didymoi's direct processing and acts as the relevant data controller. Privacy requests may be submitted using the support email on the Contact page. We may verify your identity before processing an access, correction, deletion, portability, or restriction request.
Where an API customer, OAuth application operator, or organizational customer determines the purposes and means of processing its end users' personal data, that customer is generally the relevant controller. Where applicable, Didymoi processes the data as a processor or service provider on that customer's instructions and only to provide the requested functionality. End users should generally direct their requests to the relevant customer first.
A payment provider, seller, or Merchant of Record identified at checkout, including Paddle or Stripe where applicable, may act as an independent controller for payment, tax, billing, identity-verification, fraud-prevention, and payment-support purposes and process relevant data under its own privacy policy identified in section 4 above.
If you believe our processing violates applicable law, you may also complain to the data protection authority with jurisdiction in your location.
13. Third-party services and external links
The services may include third-party login, payment, documentation, applications, or links. When you use them, the third party may collect and process information directly under its own terms and privacy policy; please review those rules before use.
Unless we explicitly state otherwise, third-party websites, applications, SDKs, and services are not governed by this Policy. We select necessary processors with care, but cannot perform their independent privacy and security obligations for them.
14. Definitions
“Personal data” means information that identifies, or can reasonably be combined with other information to identify, a natural person. “Sensitive personal data” means data that could materially affect personal or property safety, or other significant interests, if disclosed or misused.
“Process” includes collecting, storing, using, transmitting, providing, disclosing, deleting, and other operations involving personal data. “De-identification” means processing that cannot identify a specific person without additional information.
生效日期:2026 年 7 月 22 日
隐私政策
我们如何收集、使用、共享和保护你的个人信息
1. 我们收集的信息
本政策说明我们在提供账号、认证、自有软件、API 使用积分和客户支持服务时如何收集、使用、共享、保存和保护个人信息。你可以根据具体功能选择是否提供非必要信息;拒绝提供必要信息可能导致相应功能无法使用。
我们可能收集账号邮箱、显示名称、登录方式、OAuth 身份信息、会话信息、IP 地址、User-Agent、设备与浏览器信息、操作日志、API 调用记录、积分流水、支付订单状态、渠道交易 ID 及必要的支付事件 payload。
根据你使用的功能,我们还可能处理你提交、上传、生成或传输的提示词、消息、文件、图片、音频、代码、其他输入内容、服务输出及相关元数据,以及为执行、计费、排错和保障安全所需的任务或调用记录。请勿提交你无权处理的内容。
我们不会在本系统中存储完整银行卡号、CVV 或完整支付凭证。支付敏感信息由授权支付服务商或收单机构处理。我们可能接收订单状态、金额、币种、交易标识和风险控制所需的事件记录。
信息可能来自你主动填写或上传、你使用功能时自动产生、第三方登录或关联服务、支付服务商、为生成结果所使用的第三方 AI 或基础设施提供商,或在取得合法授权后由合作方提供。我们不会故意要求你在提示词、文件或对话中提交身份证件、银行卡密码、生物识别信息等与服务无关的敏感信息。
除非相关功能明确支持且我们已提供适当告知、取得必要授权或完成适用的书面安排,请勿提交政府签发的身份号码、完整金融账户资料、精确健康或医疗信息、生物识别模板、种族或族裔、宗教信仰、政治观点、性生活或性取向、犯罪记录以及其他依法受到特别保护的敏感个人信息。
2. 我们如何使用信息
我们使用信息来创建和保护账号、提供登录认证、执行你请求的软件、API、模型推理和内容生成功能、处理使用积分包购买和发放、执行 API 计费、生成账务记录、进行安全风控、排查故障、提供客服支持以及满足合规和审计要求。
我们可能使用不包含用户内容且无法用于识别个人的聚合运营指标改进产品性能、可靠性和用户体验。除非你另行明确选择并同意,我们不会使用你的输入、文件、提示词或输出内容训练或微调 Didymoi 自有的通用生成式人工智能模型;为生成你请求的结果、保障安全、检测滥用或排查故障而进行的必要处理不属于模型训练。第三方模型提供商会依照其适用的数据处理条款处理相关内容。
除非获得你的授权、法律要求或为完成你请求的交易,我们不会出售你的个人信息,也不会将账号信息用于与服务无关的个性化广告。
3. 处理依据(适用时)
为创建账号、提供认证、软件、API、模型推理、内容生成、订阅、使用积分及客户支持,我们通常基于履行与你之间的合同或在订立合同前应你的请求采取必要措施处理信息。
为保存依法要求的交易、税务、退款、争议及合规记录,或回应有权机关的合法要求,我们基于适用的法律义务处理必要信息。
为保障账号和服务安全、防止欺诈与滥用、维护系统可靠性、排查故障以及建立、行使或抗辩法律权利,我们可能基于相应的合法利益处理必要信息;我们会评估该等利益与用户权利之间的平衡。
对于非必要 cookie、营销、将用户内容用于模型训练或法律要求取得同意的其他处理,我们仅在取得相应同意后进行。你可以随时撤回同意,但撤回不影响此前基于同意进行处理的合法性。
具体处理依据可能因你所在地区、使用的功能、数据类型以及我们与企业客户之间的角色而不同。
4. 第三方服务与数据共享
为提供服务,我们可能向身份认证、数据库、云托管、存储、邮件、日志监控、安全、客户支持和其他必要服务提供商披露其完成相应功能所需的有限数据。我们会通过适用的合同或服务条款要求其采取合理的保密和安全措施。
部分功能由第三方 AI 模型或基础设施提供商支持。为生成你请求的结果、执行任务、检测滥用或排查故障,我们可能向其传输必要的输入、文件、上下文和技术信息,并接收相应输出或状态信息。其处理活动同时受适用的数据处理条款约束。
结账页面列明的支付服务商、收单机构、销售方或 Merchant of Record(可能包括 Paddle 和 Stripe)可能作为独立控制者或受托处理者处理付款、税务、账单、身份验证、反欺诈和支付支持所需的信息,并适用其自身的条款和隐私政策。Paddle 隐私政策见 https://www.paddle.com/legal/privacy;Stripe 隐私政策见 https://stripe.com/privacy。相关支付服务商还可能通过其托管结账页面、SDK、嵌入式组件、cookie 或类似技术收集交易数据、设备和浏览器信息,用于支付处理、认证、分析及预防和检测欺诈。我们不接收完整银行卡资料,仅保存履约、账务、客服和风控所需的订单状态、交易标识、金额、币种和事件记录。
在法律允许或要求的范围内,我们还可能向专业顾问、执法或监管机关披露必要信息,或在合并、融资、重组、资产转让及类似业务交易中向相关接收方披露信息。发生运营主体变更时,我们会依法通知并要求接收方继续履行适用的隐私义务。
5. Cookie 与会话
我们使用必要的 cookie、本地存储或服务端 session 来维持登录状态、语言偏好、安全校验和 OAuth 流程。禁用必要 cookie 可能导致登录或购买流程不可用。
必要 cookie 不用于个性化广告;如未来启用分析或营销 cookie,我们会在适用法律要求时提供相应的选择和管理入口。
支付服务商的托管结账页面、SDK 或嵌入式组件可能使用其自身的 cookie 或类似技术,并依照该服务商的隐私及 cookie 规则运行。在适用法律要求时,我们或相关服务商会为非必要技术提供相应告知、同意或管理选择。
6. 数据保留
我们仅在实现本政策所述目的所必需的期间保留个人信息,并根据数据类型、账号状态、服务安全、争议处理以及适用的法律、税务、会计、支付、反欺诈和审计要求确定具体期限。
会话数据、验证码和临时授权记录通常仅在完成登录、安全校验或授权所需期间保留。账号资料通常在账号存续期间保留;订单、积分、订阅、退款、拒付、支付事件和审计记录可能在交易完成或账号关闭后继续保留,以满足履约、对账、争议处理、反欺诈以及法定义务。
保留目的实现或适用期限届满后,我们会删除、匿名化或以法律允许的方式安全处理相关信息。你可以通过 Contact 页面申请删除账号或个人信息;我们会在核验身份后处理,但依法或为建立、行使、抗辩法律权利而必须保留的数据不受该请求影响,并会在相关保留依据消失后处理。
7. 数据安全
我们采用访问控制、服务端密钥隔离、加密传输、审计日志和最小权限原则保护数据。但任何互联网服务都无法保证绝对安全。
如发生可能影响个人信息安全的事件,我们会根据适用法律采取遏制、调查、修复和通知措施,并要求相关处理方及时协助。
8. 你的权利
在适用法律允许的范围内,你可以请求访问、更正、删除、导出你的个人信息,反对或限制某些处理活动;对于基于同意的处理,你还可以随时撤回同意。
如需提交隐私请求,请通过 Contact 页面列明的支持邮箱联系我们。我们可能需要验证你的身份后处理请求。
请求应尽量说明账号邮箱、请求类型、涉及的数据范围和可接受的回复方式。我们会在合理期限内回复;如无法完成请求,会说明原因及可用的申诉或投诉渠道。
9. 未成年人信息保护
本服务仅面向年满 18 周岁的用户。未满 18 周岁者不得注册、购买或使用服务。
如监护人发现未满 18 周岁者向我们提供了个人信息,请通过 Contact 页面联系我们;在完成必要核验后,我们会删除或按适用法律处理相关信息。
10. 跨境传输
我们及服务提供商可能在你所在国家或地区以外处理和存储个人信息,包括其运营设施、云基础设施或支持人员所在的国家或地区。实际处理地点取决于所使用的服务、基础设施和提供商。
发生跨境传输时,如适用法律要求,我们会采用适用的合同安排、充分性决定、认证机制、法定例外或其他受认可的传输机制,并结合访问控制、加密等合理安全措施。
如适用法律赋予你了解跨境传输机制或取得相关保障措施副本的权利,你可以通过 Contact 页面提交请求;我们可能在不披露商业秘密或安全敏感信息的前提下提供可用说明。
11. 政策更新
我们可能因服务、法律、技术或安全变化更新本隐私政策。更新后的版本会发布在本页面,并以新的生效日期为准。
如变更涉及处理目的、个人信息类型、共享对象或用户权利等重大事项,我们会根据适用法律通过页面提示、站内通知或其他适当方式告知。
12. 数据控制者、数据处理者与隐私请求
Didymoi / Didymoi Cloud 是由独立开发者运营的软件及在线服务品牌。该运营者决定 Didymoi 直接处理的个人信息之处理目的和方式,并作为相应的数据控制者。隐私请求可发送至 Contact 页面列明的支持邮箱;我们可能在处理访问、更正、删除、导出或限制处理请求前验证你的身份。
当 API 客户、OAuth 应用运营者或组织客户决定其终端用户个人信息的处理目的和方式时,该客户通常是相应的数据控制者;在适用情况下,Didymoi 仅为提供客户请求的功能而按照其指示作为数据处理者或服务提供商处理相关信息。终端用户通常应先向相应客户提交请求。
结账页面列明的支付服务商、销售方或 Merchant of Record(包括适用交易中的 Paddle 或 Stripe)可能就付款、税务、账单、身份验证、反欺诈和支付支持目的作为独立数据控制者,并依照本政策第 4 节所列的自身隐私政策处理相关信息。
如你认为我们处理个人信息的方式违反适用法律,你也可以向所在地有管辖权的数据保护机构提出投诉。
13. 第三方服务与外部链接
服务可能包含由第三方提供的登录、支付、文档、应用或链接。你使用该等服务时,第三方可能按照其自身条款和隐私政策直接收集和处理信息;请在使用前阅读其规则。
除非我们明确说明,否则第三方网站、应用、SDK 或服务不受本政策控制。我们会审慎选择必要处理方,但不能替代其履行自身的隐私和安全义务。
14. 术语说明
“个人信息”是指能够单独或与其他信息结合识别自然人的信息;“敏感个人信息”是指一旦泄露或滥用可能对人身、财产安全或人格权益造成较大影响的信息。
“处理”包括收集、存储、使用、传输、提供、公开、删除和其他与个人信息相关的操作;“去标识化”是指在不使用额外信息的情况下无法识别特定个人的处理方式。