SeeFunny
English中文

Privacy Policy

1.0.0-draft.1

Status
Draft
Effective date
Not effective
LEGAL DRAFT

This version is not effective and is not used for consent. Operator details and legal review are still required before publication.

SeeFunny Privacy Policy

Version: 1.0.0-draft.1 Status: Draft only; not effective and not eligible for user acceptance Drafted: September 22, 2026

Important: This is not legal advice. The operator, hosting locations, subprocessors, retention periods, and international transfers must be completed and reviewed before publication.

1. Who we are

The personal information handler/data controller is [full legal name], with registered address, privacy contact, and privacy email [to be completed]. This Policy describes how we process personal data when you use SeeFunny / 稀饭 and its Interest Agents, recommendations, Taste Graph, people discovery, account, sync, and subscription features.

2. Data we process

Subject to a final data inventory, the Service may process:

  • account data: email, user ID, verification status, account dates, basic Google/GitHub identity data, and linked sign-in methods;
  • profile data: display name, avatar, locale, time zone, and discoverability;
  • interest data: Taste, Curiosity, graph relationships, and visibility choices;
  • activity data: saves, feedback, Agent configuration, and instructions;
  • operations and metering: run state, provider/model/source, token usage, cost status, and error codes;
  • device and security data: limited IP/device information, timestamps, request IDs, and authentication/security events;
  • transaction data: plan, order, payment status, and refund records, but not complete payment-card details;
  • support and report data; and
  • information from compliant public sources, such as content links and public project or author details.

Do not place unnecessary sensitive identifiers, financial credentials, detailed medical records, or unpublished contact details in interests, queries, or Agent instructions.

3. Purposes and legal bases

Depending on your location and the activity, we process data to perform our contract with you, based on consent, to meet legal obligations, or under another lawful basis. Purposes include authentication; saving your workspace; running discovery and recommendations; metering and billing; support and reports; security and fraud prevention; compliance; and improving quality where properly authorized. We do not use vague "service improvement" language to justify unrelated processing or private-interest advertising.

4. Taste, recommendations, and automated processing

Taste, Curiosity, feedback, and Agent configuration are private by default. Only information you deliberately publish is used for public profiles or people discovery. Recommendations may use declared interests, feedback, viewed or saved items, topics, quality, novelty, and Surprise Score. This ranking changes content order; it is not intended to make decisions with legal or similarly significant effects. Available controls include feedback, interest reset, visibility settings, and privacy requests.

5. AI and cloud Agents

When you request a cloud Agent or model-backed feature, we may send the minimum necessary query, context snippets, and content summaries to an approved model provider. The product should disclose the provider category, data categories, purpose, and billing impact. Unless separately disclosed and lawfully authorized, providers must not use private inputs to train general-purpose models. Local Agents are also governed by the tool you choose; SeeFunny processes only data actually returned to the platform.

6. Sharing and processors

We do not sell personal data. We may use providers for authentication and databases (the current architecture includes Supabase), Google or GitHub when you choose social sign-in, email, hosting, storage, monitoring, security, approved LLM/embedding services, payment, support, and professional compliance services. Before launch, we will publish the actual processor, purpose, data category, and region list. Limited disclosure may also occur where legally required, necessary for safety, or part of a corporate transaction, subject to applicable notice and consent duties.

7. International transfers

Primary hosting and processing locations are [to be completed]. Before transferring personal data outside the relevant jurisdiction, we will assess applicable requirements, disclose the recipient, purpose, method, data categories, location, and rights channel, and implement required contracts, certification, assessment, consent, or other safeguards. Undisclosed transfers must not be enabled by default.

8. Retention

We keep personal data only as long as necessary. Before launch, placeholders must be replaced with approved periods for: account and workspace data; security logs; metering, orders, and refunds; legal-acceptance evidence; and backups. On expiry, data will be deleted, anonymized, or isolated where retention is legally required.

9. Your rights

Depending on applicable law, you may request access, a copy, correction, completion, deletion, consent withdrawal, visibility changes, account deletion, portability, information about automated recommendations, restriction or objection, and complaint to a regulator. The final in-product request path and privacy email are [to be completed]. We may verify identity before acting and will respond within applicable time limits.

10. Cookies and local storage

Necessary cookies or local storage may maintain authentication, locale, security state, and device-local features. Any non-essential analytics or advertising technology must be separately listed and offered with applicable choices before activation. Administrative data, provider secrets, payment credentials, and authentication tokens must not be placed in an unprotected offline cache.

11. Security and incidents

We use risk-appropriate access controls, encryption, least privilege, audit logs, backups, key management, remediation, and incident response. No Internet service is absolutely secure. If an incident may affect your rights, we will remediate and notify users and authorities as required.

12. Children

The minimum age is [to be determined]. We do not knowingly collect personal data from children under 14. If the Service is later offered to children, we will adopt dedicated rules, verified guardian consent, stronger minimization, and safeguards. Contact us if you believe a child submitted data without appropriate authorization.

13. Versions and updates

Published policies are immutable and versioned. Material changes may include purposes, data categories, recipients, international transfers, automated processing, or rights. We will provide advance notice and request renewed consent where required. Historical versions and change summaries will remain accessible.

14. Contact and complaints

Privacy lead/DPO: [to be completed] Privacy email: [to be completed] Address: [to be completed] Regulatory complaint channel: [to be completed for each service region]

Privacy Policy 1.0.0-draft.1 · SeeFunny