Data transparency

Privacy notice

This layered notice explains what the Laintas main site and account system process, why, who receives data, how long it is kept, and how you can make a request.

Effective and last updated: August 4, 2026

01

Necessary account and billing data operates, secures and settles the service.

02

Google Analytics is enabled only after you consent to optional analytics cookies.

03

You can request access, correction or deletion of personal data controlled by Laintas.

01

Who is responsible and scope

This notice covers the laintas.com website, unified account, billing, support and APIs directly provided by the main site. “Laintas” means the project operator providing the service and responding to data requests at [email protected]. Individual products, self-hosted instances, GitHub, Google Drive and third-party checkout pages may have separate controllers and privacy rules.

02

Data we process

Depending on the features you use, we may process:

  • account data: username, email, verification status, linked Google/GitHub identity and account role;
  • security and technical data: sessions, IP address, device/browser information, captcha result, security events and necessary logs;
  • transaction and subscription data: Laintas order ID, amount, currency, method, processor transaction reference, balance changes, plan and expiry;
  • usage data: product, model, call count, token count, time, errors and allowance use;
  • submitted content: support messages and prompts, context, file excerpts or tool results sent when using cloud AI;
  • preferences and analytics: language, theme, cookie choice and, after consent, page-view analytics.
03

Sources of data

Most data comes directly from you when you register, sign in, pay, use a product or contact support; some comes from your browser, device and service activity. With Google or GitHub sign-in, we receive the basic identity data returned within the authorised scope. Payment status and transaction references come from PayPal, WeChat Pay or crypto payment providers. We do not buy personal profiles from data brokers.

04

Purposes and legal bases

We use data only for the purposes below. Where law requires a legal basis, it may be performance of a contract, legitimate interests, legal obligation or your consent:

  • creating accounts, verifying identity, maintaining sessions and providing requested products and APIs;
  • calculating allowances, deducting balance, confirming payments, managing subscriptions, processing refunds and keeping financial records;
  • preventing fraud, abuse, duplicate payments and unauthorised access, and protecting the service and users;
  • responding to support, troubleshooting, evaluating performance and improving products;
  • performing visit analytics after consent; you may withdraw by clearing site data or changing cookie choices.
05

AI inputs, project files and model services

Helpwo project files are stored in the user’s browser IndexedDB by default rather than automatically uploaded to the Laintas main site. When you invoke cloud AI, web search, a remote Agent or another server feature, the relevant prompts, selected context, file excerpts and tool results are sent to the Laintas backend and the model or search provider needed to fulfil the request. Do not submit passwords, private keys, full payment-card data, health data or other unnecessary sensitive information. Self-hosted processing depends on your own configuration.

06

Recipients and service providers

We do not sell personal data. To provide a requested function, limited data may be provided to:

  • hosting, database, network and security infrastructure providers;
  • Resend for verification, password-reset and support email; Google and GitHub for sign-in and cloud-drive/repository functions you expressly authorise;
  • PayPal, WeChat Pay and crypto payment providers for checkout, status confirmation, refunds or disputes;
  • AI model, web-search or content-processing providers needed for the feature you select;
  • Google Analytics only after optional analytics consent, and regulators, courts or law enforcement where legally required.
07

Cookies, local storage and controls

Essential cookies support authentication, sessions and security; account features may fail if blocked. Browser localStorage stores language, theme and cookie choice; Helpwo may use IndexedDB for local projects. Google Analytics starts with analytics storage denied and receives permission only after “Accept all”. You can clear cookies, localStorage and IndexedDB in your browser. Doing so may sign you out or delete projects stored only on that device.

08

Retention

We keep data only as long as needed to operate features, resolve disputes, protect security and meet financial or legal duties. The current system purges detailed metered-billing transaction and subscription-usage records older than 12 months. Account, session, core order/ledger, subscription, support and security records may remain longer while an account is active, a dispute is open or records are legally required. One-time codes and authorisation states expire quickly. Browser-local and third-party cloud data is controlled by you or that provider. After a valid deletion request, we delete or de-identify data no longer needed and not legally required.

09

International processing

Laintas and its providers may operate servers in different countries. Using hosted features means data may be processed outside your location. We select reasonable technical and contractual protections for the service, but privacy rules differ by region. Payment and OAuth providers determine processing locations under their global networks and policies.

10

Security measures and your role

We use email verification, password-length requirements, session expiry, captcha, access controls, payment-callback verification, rate limits and logging to reduce risk, but no internet service is perfectly secure. Use a unique strong password, secure your email and devices, review OAuth scopes, and never send passwords or private keys in support messages or prompts. Report vulnerabilities responsibly through support without accessing other people’s data.

11

Your choices and rights

Depending on applicable law, you may request access, correction, deletion, restriction or objection, a portable copy, withdrawal of consent, or complain to a regulator. We first verify the requester’s relationship to the account. Some order, security or financial records may be retained for legal or dispute needs. You may also unlink sign-in providers, reject analytics cookies, stop using cloud AI or choose self-hosting. Submit requests to the address below with the account email and requested scope.

12

Children, changes and contact

The services are not designed specifically for children and do not intentionally seek children’s personal data. Users without full legal capacity should have lawful guardian consent and supervision. We update this notice as products and law change and show the revision date. Material changes to purposes or sharing will receive reasonable notice. Use the contact below for privacy questions or requests.

Contact and requests

Contact us from the account email and include the relevant order ID or request scope. Never send passwords, verification codes, full card numbers, seed phrases or private keys.

[email protected]