Privacy

Privacy Policy

This policy explains how Hey Mori collects, uses, stores, and protects information when you use the service.

Last updated: 2026-07-11

Contact: [email protected]

1. Data controller

Your use of Hey Mori is also governed by the Terms of Service at https://heymori.design/legal/terms-of-service.

The data controller for the Service is SHIJIE LI, an individual developer, with contact address at No. 71, Shangcheng International, Longhua County, Chengde, Hebei Province, China.

The privacy contact email and customer support email are both [email protected]. We have not appointed a separate Data Protection Officer (DPO); privacy, data-rights, account deletion, and security requests may be sent to that email address.

2. Personal information we collect

Information you provide may include account email, display name, avatar, language preference, workspace details, project names, product details, brand materials, prompts, uploaded images, reference assets, generated outputs, support emails, feedback, refund reasons, and other information you submit while using the Service.

If you sign in through Google or another third-party provider, we receive basic identity information needed to create, verify, and protect your account, such as email, name, avatar, and sign-in verification result. We do not ask you to set a separate Hey Mori password.

Payment and order information may include plan name, subscription status, credit balance, order ID, transaction status, amount, currency, tax, refund status, customer-portal access status, and non-card information returned by the payment processor. We do not store full card numbers, CVV, or payment-card authentication data.

Information collected automatically may include IP address, device type, operating system, browser type, time zone, language, page visits, feature usage, operation logs, error logs, performance data, security events, anti-abuse signals, and cookie or local-storage identifiers.

3. How we use personal information

We use personal information to create and maintain accounts, verify sign-in, provide AI generation, image editing, image translation, video generation, asset management, workspace storage, subscription billing, credit deduction, order handling, refund review, customer support, security checks, troubleshooting, service notices, and product improvement.

Where privacy laws such as GDPR apply, we generally process account, generation, storage, billing, and support information to perform our contract with you; safety, anti-fraud, service notices, troubleshooting, basic analytics, and product improvement based on legitimate interests; tax, accounting, dispute, refund, chargeback, and compliance records based on legal obligations; and marketing only with your consent and an unsubscribe path.

We may use aggregated or de-identified data to understand feature usage, improve user experience, maintain system reliability, and improve creative quality. Such data is not used to identify a specific individual.

4. AI inputs, uploaded assets, and generated content

Product images, reference images, brand materials, prompts, and generated outputs are processed to complete the creative tasks you request and may be saved in your workspace, project assets, or generation history so you can continue editing, downloading, managing, or reusing them.

To complete generation, editing, translation, video, or other AI processing tasks, we may send necessary input content, parameters, and context to third-party AI models, cloud services, storage services, or safety-review services. These third-party services may be located in different countries or regions.

We will not use your inputs or generated outputs to train Hey Mori's own models without your explicit consent. Third-party AI model providers may process data according to their own policies, data-processing agreements, and security mechanisms.

Do not upload sensitive personal data, private information about others, restricted business materials, infringing assets, or unlawful content that you are not authorized to process. You can manage or delete supported assets inside the product.

5. Cookies and local storage

We may use cookies, local storage, and similar technologies to keep you signed in, remember language preference, store security tokens, preserve feature state, and support basic analytics. Strictly necessary technologies support sign-in, security, and core functionality and generally cannot be disabled; functional and analytics technologies support preferences, anonymous statistics, and product improvement.

We use Google Analytics through Google tag for basic traffic and product analytics, including page views, approximate region, device/browser information, and usage events. Google processes this information under its own terms and privacy policy at https://policies.google.com/privacy. We do not intentionally use third-party advertising tracking pixels, and we provide choices or opt-out mechanisms where required by applicable law.

You can limit cookies in your browser settings. Limiting strictly necessary cookies may affect sign-in, workspace state, payment-status synchronization, or certain features.

6. Sharing and disclosure of personal information

We do not sell your personal information, including “sale” as defined by laws such as the CCPA. We share information only as needed to provide the Service, fulfill orders, process payments, meet legal obligations, protect security, or with your consent.

We may share necessary information with cloud hosting, PostgreSQL database, Cloudflare R2 or S3-compatible object storage, payment processing, login verification, email, AI model providers, security and anti-abuse, logging, Google Analytics, and basic analytics service providers. These providers are expected to process information only for agreed purposes.

Payment card data is handled by the payment processor Waffo Pancake, which satisfies payment-security requirements, and is not stored on Hey Mori servers. We may store non-card details needed for order ID, transaction status, subscription status, amount, currency, tax, refund status, and customer-portal access.

We may also disclose information when required by law, court order, regulatory request, rights protection, security investigation, fraud prevention, chargeback dispute, merger, acquisition, or asset transfer.

7. Security measures

We use TLS/HTTPS, access controls, encryption, audit logs, least-privilege practices, server-side secret management, outsourced payment-card handling by compliant payment processors, abnormal-use monitoring, and security review to protect information.

If a security incident may affect your rights, we will notify you and relevant regulators after confirmation as required by applicable law. Where laws such as GDPR apply, we will follow applicable notification deadlines, including the 72-hour regulatory notification requirement where applicable.

No internet service can be guaranteed to be completely secure. You should also protect your account sign-in method, email account, and devices and should not share login credentials with others.

8. Retention of personal information

Account details, workspace content, persistent project assets, and generated outputs are generally retained while the account is active so you can continue accessing, editing, downloading, and managing them. Temporary reference images, videos, and audio files uploaded as creative inputs are generally deleted about 24 hours after upload. After account closure, deletion, or long inactivity, we generally delete or anonymize non-essential data within 90 days, except where retention is needed for legal compliance, dispute handling, safety, fraud prevention, backup recovery, or abuse prevention.

Transaction, tax, accounting, refund, chargeback, and dispute records are generally retained as required by law, payment networks, and audit obligations and may be retained for up to 7 years. Support records, security logs, login events, and anti-abuse records are generally retained for no more than 24 months, unless fraud, abuse, dispute, compliance investigation, or legal obligation requires longer retention.

If you delete in-product assets, the relevant content is removed from the visible workspace; however, backups, audit logs, transaction records, or compliance retention copies may remain for a limited period until backup rotation or legal obligations end.

9. Your data rights

Where applicable law allows, you may request to know, access, correct, delete, or export your personal information, and may request restriction of processing, object to processing based on legitimate interests or marketing, and withdraw consent-based processing authorization.

To submit a privacy request, contact us at [email protected]. To protect your account, we may need to verify your identity before acting on the request and generally respond within 30 calendar days.

If you believe we have not properly handled your privacy request, you may contact us again with the issue. Where applicable law allows, you may also complain to your local data protection authority or regulator.

10. Marketing communications and opt-out

We may send service-required notices, such as sign-in security, billing, order, subscription, refund, policy update, feature change, and security alerts. These notices are necessary for the Service and generally cannot be fully opted out of.

If we send marketing, product promotion, or non-essential commercial email, we will obtain your consent where required by applicable law and provide an unsubscribe link, account-setting option, or support-email opt-out path. Opting out of marketing does not affect service-required notices.

11. International data transfers

Hey Mori's servers, databases, object storage, payment processor, login service, AI model providers, email service, or other partners may be located in the United States, outside China, or in their global operating regions. Your information may therefore be accessed, processed, transferred, or stored outside your country or region.

Where required by applicable law, we use data-processing agreements, Standard Contractual Clauses (SCCs), adequacy decisions, vendor security assessments, or other reasonable measures to protect personal information in cross-border transfers.

12. Children

Hey Mori is intended for users who are at least 18 years old or have reached the local age required to enter into online service agreements independently. Minors should use the service only with consent and supervision from a parent or guardian. We do not knowingly collect personal information from children below the local legal age.

If you believe a minor has provided personal information to us without authorization, contact us at [email protected], and we will take deletion or restriction measures after reasonable verification.

13. Third-party links and services

The Service may include third-party links or integrate with Waffo Pancake, Google, Cloudflare, third-party AI model providers, email service providers, and other external services. This policy applies only to information processing activities directly controlled by Hey Mori.

Third-party services may have their own privacy policies, terms of service, data-processing rules, and security mechanisms. You should read their policies before using them; we are not responsible for data practices of third parties that we do not control.

14. Changes to this policy

We may update this policy because of product, legal, technical, payment-channel, AI model provider, or operational changes. Material changes will be notified at least 15 days in advance through a page notice, in-product notice, registered email, or another reasonable method, and the last updated date at the top of this page will be updated.

Continued use of the Service after the update takes effect means you have read and accepted the updated Privacy Policy. If you do not agree with the update, you should stop using the Service and may submit data-related requests under this policy.

15. Contact us

Privacy contact email: [email protected]. Customer support email: [email protected]. Data controller: SHIJIE LI, individual developer. Contact address: No. 71, Shangcheng International, Longhua County, Chengde, Hebei Province, China.

To help us process requests, please contact us from your account email where possible and include the relevant order ID, account details, screenshots, asset links, or a clear description of the issue.