The data controller responsible for your personal data is:
This Privacy Policy applies to all personal data collected through:
This policy is governed by the Personal Data (Privacy) Ordinance (Cap. 486, Laws of Hong Kong) and its six Data Protection Principles (DPPs). Where you are located in a jurisdiction with additional data protection requirements (such as the EU/EEA GDPR), we endeavour to comply with those requirements as well.
We collect personal data only to the extent necessary for providing the Service. Below is a complete list:
| Data Category | Specific Data | Source |
|---|---|---|
| Account Data | Telegram user ID, first name, last name, username, language code | Telegram API on /start |
| User Content | Photos you upload, text prompts and commands sent to the Bot | Your messages to the Bot |
| Generated Content | AI-generated images and videos created for you | Service processing |
| Transaction Data | Generation pack purchases, generation usage history, payment confirmation IDs | Bot and payment processor |
| Technical Data | Device type, operating system, Telegram client version, IP address (for Website visits only) | Automatic collection |
| Support Data | Messages and attachments sent to support | Your communications |
We do not collect: payment card numbers, bank account details, government IDs, or precise geolocation.
In compliance with DPP1 (Purpose and Collection) and DPP3 (Use), your data is used only for the purposes stated below:
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Providing the Service (generation, delivery) | Account, User Content, Generated Content | Performance of contract |
| Processing payments | Account, Transaction Data | Performance of contract |
| Customer support | Account, Support Data | Legitimate interest |
| Service improvement and bug fixing | Technical Data, aggregate usage statistics | Legitimate interest |
| Abuse prevention and Terms enforcement | Account, User Content, Technical Data | Legitimate interest |
| Service announcements (non-promotional) | Account (Telegram ID) | Legitimate interest |
| Promotional messages (opt-in) | Account (Telegram ID) | Consent |
We will not use your data for any purpose not listed above without obtaining your explicit consent first.
When you upload a photo, our AI models analyse facial features (face geometry, skin tone, hair characteristics) to generate the requested stylized output. This processing is:
The Service currently uses the following third-party AI models to process your data:
The models used may change over time as we improve the Service. Your photos are sent to these providers' APIs solely for the purpose of generation and are subject to their respective data processing agreements with us.
Uploaded source photos are stored on our servers for the duration necessary to provide the Service (so you can re-use them for new generations). You may request deletion at any time (see Section 9).
Intermediate AI processing data (feature vectors used during generation) is ephemeral and is not retained after the generation is complete.
We do not sell your personal data. We share data only in the following limited circumstances:
| Recipient | Data Shared | Purpose |
|---|---|---|
| Payment processors | Transaction data (no photos) | Processing your payment |
| Cloud infrastructure providers | All data (encrypted at rest) | Server hosting |
| AI model providers (Google DeepMind, Kuaishou Technology) | Photos (for generation only) | Performing AI generation |
| Law enforcement | As required | Legal obligation |
All third-party processors are bound by contractual obligations to protect your data and use it only for the stated purpose.
Your data is stored on servers located in __DATA_LOCATION__.
| Data | Retention Period |
|---|---|
| Account data | As long as your account exists, plus 30 days after deletion request |
| Uploaded photos | Until you request deletion or account is closed |
| Generated images/videos | Until you request deletion or account is closed |
| Transaction records | 7 years (legal/tax requirements) |
| AI processing data (feature vectors) | Not retained — deleted immediately after generation |
| Support correspondence | 2 years after resolution |
This complies with DPP2 (Accuracy and Retention): data is kept only as long as necessary for the purpose for which it was collected.
We implement the following measures to protect your data:
While we take all practicable steps to protect your data, no system is 100% secure. You acknowledge this inherent risk.
Your data may be transferred to and processed in jurisdictions outside Hong Kong (for example, where our cloud infrastructure or AI model providers are located).
When your data leaves Hong Kong, we ensure protection through:
Under the PDPO (DPP6: Access and Correction) and applicable international law, you have the following rights:
| Right | What It Means | How to Exercise |
|---|---|---|
| Access | Obtain a copy of the personal data we hold about you | Email support@yourdomain.com with your Telegram username and a description of your request |
| Correction | Request correction of inaccurate or incomplete data | |
| Deletion | Request deletion of your uploaded photos, generated content, and/or account | |
| Opt-out | Unsubscribe from promotional messages at any time |
If you believe we have handled your personal data improperly, you have the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data, Hong Kong (www.pcpd.org.hk).
MIOMIO is not intended for anyone under 18 years of age (or the minimum age required by the laws of your jurisdiction, whichever is higher). We do not knowingly collect personal data from children.
If you believe a child has provided us with personal data, please contact us immediately. We will promptly delete such data from our systems.
The MIOMIO Website does not currently use cookies or third-party analytics services.
If this changes in the future, we will update this section and notify users accordingly. Any analytics implementation will be limited to aggregate, non-identifying usage statistics.
The Telegram Bot does not use cookies (Telegram's infrastructure handles sessions).
In the event of a personal data breach that is likely to result in a real risk of significant harm to affected individuals, we will:
We may update this Privacy Policy from time to time. In compliance with DPP5 (Openness):
For any questions, requests, or complaints regarding your personal data:
You may also file a complaint with the Office of the Privacy Commissioner for Personal Data:
Website: www.pcpd.org.hk
Hotline: +852 2827 2827