Kamay Privacy Policy
2026/04/13
Kamay respects and values your privacy. This Kamay Privacy Policy ("Policy") explains how we collect, use, store, share, transfer, and protect information about you when you access, register for, purchase, or use the Kamay website, applications, software, APIs, AI features, and related services (collectively, the "Services").
Please read this Policy carefully before using the Services, particularly the provisions relating to your rights, data sharing, cross-border transfers, protection of minors, cookies, and how to contact us.
This Policy applies to our processing of personal information and related data when we provide Services to you through the Kamay official website, web applications, mobile apps, desktop apps, APIs, plugins, customer support communications, sales processes, event registrations, and other channels that expressly reference this Policy.
This Policy does not apply to services independently provided to you by third parties. When you navigate to, connect with, or authorize third-party services through the Services, you should separately read and comply with such third party's privacy policy and service rules.
The Kamay Services are operated by the relevant legal entity and its affiliates. Specific service provider information, registered address, contact email, and notification methods are as disclosed on the official website, registration page, order page, or supplementary agreements.
Depending on the specific services, features, devices, regions, and authorizations you use, we may collect the following types of information:
Where permitted by law and where you have authorized or the third party has a lawful basis for providing such information, we may obtain information from third parties, such as:
Certain information may be considered sensitive personal information or information requiring special protection under applicable law. Unless necessary for specific functionality, please exercise caution when uploading identity documents, financial account information, precise location data, information about minors, health information, biometric information, or other highly sensitive data. Where such processing is required for specific features, we will take additional notice, authorization, or protective measures in accordance with applicable law.
We may process your information for the following purposes:
If we intend to use your information for purposes not directly or reasonably related to those described in this Policy, we will provide separate notice and obtain necessary consent in accordance with applicable law.
5.1 When you use AI-related features, we may process your input content, contextual data, configuration parameters, and generated results to execute requests, return outputs, ensure security, maintain logs, and improve service stability.
5.2 AI-generated results may be based on algorithmic inference and do not necessarily represent facts, professional opinions, or our positions. You are responsible for their use, review, publication, and consequences.
5.3 Whether your non-public inputs, outputs, and business data will be used for model training, general model optimization, human annotation, or quality evaluation shall be governed by the product settings, data processing agreements, service descriptions, or supplementary policies that we publish at the relevant time. If we provide a toggle or opt-out mechanism, we will follow such mechanism.
5.4 Please do not upload third-party personal information, trade secrets, information subject to confidentiality obligations, or other data that may not be lawfully processed without a legal basis.
Under applicable law, our legal basis for processing personal information may include:
Where applicable law requires "legitimate interests" as a basis, we will process the relevant information after balancing your rights and interests against our reasonable business needs.
To achieve the purposes described in this Policy, we may entrust third-party service providers to process certain information on our behalf, such as cloud service providers, CDNs, security service providers, payment service providers, customer service systems, analytics tool providers, email delivery service providers, identity verification service providers, logging and monitoring service providers, and third-party AI model providers. We require them to process information in accordance with our instructions, applicable law, and security standards through contracts, audits, access controls, and other measures.
We may share your information in the following circumstances:
We will not publicly disclose your personal information except in the following circumstances:
In the event of a merger, acquisition, asset transfer, bankruptcy restructuring, or similar transaction, your information may be transferred as part of the transaction. We will require the receiving party to continue to be bound by this Policy or equivalent protection standards; if the processing purposes change, we will provide separate notice and seek necessary consent as required by law.
Given that the Services may rely on global infrastructure, cross-border team collaboration, overseas cloud services, third-party models, or international payment services, your information may be transferred to countries or regions outside your jurisdiction for storage, processing, or access.
When cross-border transfers occur, we will take necessary measures in accordance with applicable law, such as:
9.1 We will retain your information for the minimum period necessary to achieve the purposes described in this Policy, unless a longer retention period is required by laws and regulations.
9.2 Retention periods for different types of data may vary depending on service scenarios, contract terms, dispute resolution, audit obligations, tax rules, security log requirements, and backup mechanisms.
9.3 When the retention period expires or the processing purpose has been fulfilled, we will delete, anonymize, or securely isolate the relevant information in accordance with applicable law and technical feasibility; except where otherwise required by laws and regulations or necessary for dispute resolution or cooperation with investigations.
To the extent provided by applicable law, you may have the following rights:
If you wish to exercise any of the above rights, please contact us through the contact methods specified in this Policy. To protect account security and prevent fraud, we may require you to complete reasonable identity verification. Where otherwise provided by laws and regulations, or where technically infeasible, disproportionately costly, or affecting the legitimate rights of others, we may not be able to fully satisfy your request, but we will explain the reasons.
11.1 We may use cookies, pixels, SDKs, local storage, and other similar technologies to maintain login status, security verification, feature configuration, preference memory, usage analytics, and service optimization.
11.2 You can manage cookies or clear local storage through your browser or device settings. Please note, however, that disabling certain cookies or similar technologies may affect the normal operation of the Services.
11.3 If we use statistical analytics, advertising attribution, or third-party tracking tools, we will fulfill applicable notice and consent obligations in accordance with applicable law.
12.1 We take reasonably practicable security measures to protect your information, including but not limited to access controls, identity authentication, encrypted transmission, log auditing, backup and recovery, permission isolation, vulnerability remediation, and security monitoring.
12.2 Nevertheless, internet and electronic storage methods cannot guarantee absolute security. In the event of or potential occurrence of personal information leakage, tampering, loss, or other security incidents, we will take remedial measures in accordance with applicable law and notify you and relevant regulatory authorities where required by law.
12.3 You should also take appropriate security measures, such as setting strong passwords, safeguarding verification codes and API Keys, enabling multi-factor authentication (where supported), and avoiding sharing sensitive data in insecure environments.
Our Services are primarily intended for adults and enterprises/organizations with full civil capacity. If you are a minor, please read this Policy with your guardian and use the Services only with your guardian's consent.
If we discover that we have collected personal information from a minor without appropriate authorization, we will promptly delete such information or take other measures required by law.
The Services may contain third-party websites, plugins, SDKs, payment channels, login interfaces, or other service entry points. Third parties operate independently and are subject to their own terms and privacy policies. We recommend that you carefully read the relevant documents before use and decide whether to authorize based on your own judgment.
We may revise this Policy in response to service changes, updates to laws and regulations, regulatory requirements, or business developments. Updated policies will be published through the official website, in-app notifications, email, pop-ups, or other reasonable means, and will take effect from the date specified therein.
Where law requires us to seek your consent for material changes, we will do so accordingly. Your continued use of the Services after this Policy is updated constitutes your acknowledgment and acceptance of the updated Policy.
If you have any questions, comments, complaints, reports, or wish to exercise your data rights regarding this Policy, please contact us through the contact information published on our official website.