1. Who this policy covers
This policy explains how Software Tailor (HK) Limited ("Software Tailor", "we", "us") handles personal data through softwaretailor.com, our current-generation AI applications, AI Server, AI Admin Console, registration and licensing services, support channels, and related business services. We are the controller for data handled in our own services. An organisation operating AI Server or administering its own users may be a separate controller; its instructions and privacy notice also apply.
This policy distinguishes on-device processing, customer-operated infrastructure, Software Tailor services, and third-party services because they are different data paths.
2. Local and customer-operated processing
On a local-model path, prompts, documents, images, audio and generated results are processed on the device. They are not sent to Software Tailor for inference. Local histories, settings, indexes, model files and other app data may be encrypted or unencrypted depending on the app and data type. Some user-data folders deliberately survive an uninstall so that a reinstall does not destroy work; use the app's delete controls or remove the documented data folders when you want those copies erased.
When a customer operates AI Server, inference content travels between the approved client and infrastructure chosen by that customer. Software Tailor does not receive that inference content merely because AI Server is used. The customer controls its network, access, logs, backups, models, retention and connected providers.
3. Optional cloud and connected tools
If you deliberately select a cloud model, remote AI Server, web search, website fetch, MCP tool, sharing feature, mail or calendar provider, or another connected service, the inputs required for that feature leave the device. Depending on the feature, that can include prompts, conversation context, retrieved document excerpts, source text, images, audio, voice-cloning samples, email or calendar content, search queries, and tool parameters. The destination is shown or configured in the app. The selected provider's terms and privacy practices apply.
Software Tailor normally relays no copy of third-party inference content to itself. A provider may retain or use content under the account and configuration you chose, so do not use a cloud route for material that the provider is not authorised to receive.
4. App identifiers, telemetry and diagnostics
Our apps create an installation identifier and may derive a stable pseudonymous machine identifier from operating-system or hardware identifiers. These are not advertising IDs. They support entitlement, abuse prevention, release quality, aggregate usage, cross-app installation recognition and support. They can be joined to registration, licence, historical website-attribution or support records in our restricted operator systems; they are therefore pseudonymous personal data, not anonymous data. When an app includes those identifiers in an outbound website URL, the replacement website does not copy them into browser storage, a form record or an attribution event; the hosting and security layer can still receive the requested URL as ordinary request data.
With telemetry enabled, an app may send the app and version, release channel, operating system and architecture, locale/region, session identifier, install and machine identifiers, feature events, performance information, and redacted error messages, stacks and context. Product content is not intentionally included in telemetry, but free-form error context can create residual disclosure risk. Telemetry defaults require explicit opt-in in the EU/EEA, UK, Switzerland, Canada and Brazil and in Apple-distributed builds; current builds may enable it by default in other regions. You can change the telemetry choice in Settings. Events already buffered locally may be sent if telemetry is later re-enabled.
5. Registration, licences and purchases
Registration can collect an email address, optional name, marketing choice, app and version, platform, locale, install and machine identifiers, registration status, and subscription or licence history. Licence systems also process keys, tier, validity, activation, machine or node labels, and security/fraud signals. Free-Pro applications can include organisation, role/category and justification, together with review decisions and audit history.
Microsoft Store, Apple App Store, Google Play, Stripe and other sales channels process purchases under their own notices. We receive the purchase, subscription, entitlement, refund and customer information needed to fulfil, secure, account for and support the transaction. Payment-card data entered into a hosted payment page remains with the payment processor.
6. Support, issues and live chat
When you report an issue or use live support, we process the title, description, category, app and diagnostic metadata, install and machine identifiers, registration email when available, comments, status and operator audit history. You may also choose to upload screenshots, logs, documents, images, audio, video or other attachments. Live chat stores message history and operator identity. If both sides accept a recorded voice call, the call audio, local transcript and a short transcript preview are uploaded and retained with the support session.
Please remove unnecessary secrets and sensitive content before submission. Support data is visible to authorised Software Tailor operators through the staff Admin Dashboard.
7. Enterprise identity and administration
AI Admin Console and related services may process organisation name, tenant and identity-provider identifiers, member name and work email, roles, entitlements, policy, server enrolment and health, usage totals, administrative actions, marketplace fulfilment and content-free audit metadata. The Console does not perform inference. Administrative audit and usage records are designed not to contain prompts, responses or documents.
Operators who use Software Tailor's staff Admin Dashboard authenticate with a configured work identity. The Dashboard can show registration, licensing, commerce, website enquiries, support, device and telemetry timelines appropriate to the operator's role.
8. Other optional features
Optional public display names and training certificates publish the name or achievement you ask us to publish, after moderation. Image Tool face grouping and similar biometric templates are opt-in and processed on-device; the templates are encrypted and are not sent to Software Tailor by that feature. Live image co-annotation can send encrypted annotations and operational metadata such as group identifiers, public keys, roles, display names, timing and padded message sizes through a relay. Product-specific interfaces provide the immediate notice and controls for these paths.
AI Academy stores learner profile names, the adult-selected learning band, lesson progress and quiz results locally in encrypted app storage. The learning band adapts content and is not sent as a verified date of birth. Labs measurement is separately consent-gated and content-free; it does not intentionally include learner names, lesson text, questions, answers or progress. A parent or legal guardian must install, configure and supervise use for a learner who cannot legally make these choices.
AI-generated output can reveal information present in an input. Review exports before sharing them, and obtain any consent required to process another person's image, voice, communications or other data.
9. Website and communications
Our hosting and security providers receive ordinary request data such as IP address, time, URL, user agent and security signals. If you contact us, subscribe, book a meeting, join a community feature, submit a wishlist item, download a Labs build or use checkout, we process the fields shown at collection together with delivery, anti-abuse, transaction and referral parameters present in the request. The Contact form sends the name, email, optional company and telephone, topic, message, consent record, locale, IP address and user agent to our contact service; it can also include campaign or app referral parameters when they are present. Form contents are explicitly masked from Clarity.
With your optional analytics consent, the site loads Google Analytics and Microsoft Clarity. They process identifiers and cookies, IP-derived approximate location, browser/device information, requested and referring URLs, session timing and interactions such as clicks and scrolling. Before either service loads, the site removes app-originated st_iid, st_mid, st_app, ref, installid and machineid parameters from the browser URL so they are not used as analytics dimensions. Clarity can create a reconstruction of page interactions; form input and explicitly masked regions are not intentionally uploaded. We use this information to understand aggregate use, diagnose confusing pages and measure successful enquiries—not for behavioural advertising. These services remain blocked until you allow them, and the persistent “Privacy choices” control lets you withdraw consent. See the cookie and browser-storage notice for the technologies and controls.
The deployment planner works in the browser. It saves a plan in the current browser tab only when you choose the contact hand-off, so the Contact page can prepare the enquiry. Nothing is sent until you submit the form or send the prepared email.
10. Purposes and legal grounds
We use personal data to provide requested products and support, perform contracts and purchases, authenticate and license software, secure services and prevent abuse, maintain reliability, administer organisations, respond to enquiries, meet accounting and legal duties, and—with the required choice—measure product or website use or send marketing. Depending on the location and context, the legal ground is performance of a contract, steps requested before a contract, compliance with law, consent, or our legitimate interests in operating and protecting the service. Website Analytics and Clarity measurement rely on consent where consent is required; rejecting them does not restrict ordinary access to static pages. You may withdraw consent without affecting earlier lawful processing.
11. Retention
Retention follows the data's purpose and any legal hold:
- raw product telemetry events and diagnostic error rows: normally up to 180 days; derived statistics may be kept longer in aggregated or pseudonymous form;
- website analytics and masked interaction data: under the shortest practical settings we configure and the providers' documented schedules; withdrawal stops future collection but does not automatically remove reports already lawfully created;
- enterprise administrative audit: the organisation's configured period, with 90 days as the normal default; licence evidence may be retained longer;
- support chat message bodies and consented call recordings/transcripts: normally up to 365 days, unless a case, dispute or legal duty requires longer;
- registration, entitlement, activation, support-case and public-profile records: while the relationship or feature remains active and afterward as needed for security, support, accounting, legal claims or a valid deletion request;
- optional encrypted AI Cloud Storage: a 90-day read-only recovery period after a plan ends, then content deletion; escrowed key material can remain for up to 12 months;
- transaction and tax records: for the period required by applicable accounting and tax law.
Local app and AI Academy learner data remains until you delete it, including data deliberately stored outside an app sandbox or retained across reinstall.
12. Recipients and transfers
We use service providers only for functions we need, including Cloudflare for hosting, Workers, D1/R2 storage and security; Amazon Web Services for transactional email and marketplace delivery; Microsoft for Clarity, identity and marketplaces; Google for Analytics, identity and marketplaces; Apple for identity and marketplaces; Stripe for direct commerce; and communication or collaboration providers chosen for a particular engagement. Customer-selected AI, search, MCP and infrastructure providers receive data only when their route is used.
Data can be processed in Hong Kong, the United States, the European Union and other locations where we or a provider operate. Where transfer rules apply, we use the provider and contractual safeguards appropriate to the transfer. We may disclose information when required by law, to protect rights or security, or in a corporate transaction subject to appropriate protections.
13. Your choices and rights
You can choose a local instead of cloud model where supported, change product telemetry and marketing choices, reject or withdraw website analytics through “Privacy choices”, clear planner session data, delete local histories and learner profiles, remove public display names, and use in-app registration deletion where available. Depending on applicable law, you may request access, correction, deletion, restriction, objection or portability and may complain to your data-protection authority.
A deletion initiated for one installation removes records associated with that installation; records for another device, a transaction we must retain, provider-held analytics, or a customer-operated server may require a separate request. We may need to verify the request and will respond within the period required by applicable law; Hong Kong data-access requests normally require a response within 40 days. Contact [email protected].
14. Security, children and changes
We use access controls, encryption in transit, restricted staff authentication, secret redaction and other measures proportionate to the service. No system is risk-free. Keep devices, servers, provider keys and exported unencrypted files secure. We maintain an incident process to investigate, contain, document and, where the applicable threshold is met, notify affected people and regulators of a personal-data breach.
Most products are general-audience tools and we do not knowingly create independent online accounts for a child who cannot legally provide the required consent. AI Academy is the exception in content design: it includes adult-selected learning bands, including child-oriented bands, while keeping learner profiles and progress locally encrypted. A parent or legal guardian must configure and supervise use by a child, decide whether optional cloud routes are appropriate, and make any Labs or telemetry choice. We do not use learner data for advertising.
We will post material changes here and change the date above. A product interface may provide a more specific just-in-time notice where a feature creates a new data path.
15. Contact
Software Tailor (HK) Limited
17/F, 80 Gloucester Road, Wanchai, Hong Kong
[email protected]
+852 2781 3049
You may also complain to the Office of the Privacy Commissioner for Personal Data in Hong Kong or, where another data-protection law applies, the competent authority for your location.