LEGAL / PRIVACY POLICY

Privacy policy

Effective / updated: 2026-08-08Support:2439646234@qq.com

1. Who we are

Kyormar is provided by Shenzhen Luohuo Technology Co., Ltd. You can contact us at 2439646234@qq.com for privacy inquiries or requests to access, correct, delete, withdraw consent, or close an account.

2. Information we process

ACCOUNTEmail, display name, account identifier, tenant, and login session
WORKSPACETasks, sessions, tool calls, approvals, and collaboration records
PAYMENTProduct, order number, amount, payment provider, and payment status
DEVICEDevice identifier, browser, system, IP address, and security logs
ANALYTICSNormalized page paths, limited interaction labels, browser performance metrics, and a pseudonymous visitor identifier after login
SUPPORTSupport emails, issue descriptions, and refund or complaint records
PREFERENCEPreferences for communication tone, information density, and reminders

Payment credentials such as WeChat Pay passwords and full bank-card numbers are processed by WeChat Pay; the Kyormar website neither reads nor stores them.

3. Purpose and legal basis

  • Create and protect accounts, maintain login sessions, and identify anomalous access;
  • Run Agent tasks, synchronize IM, and provide team collaboration, permissions, and audit;
  • Create orders, confirm payments, activate entitlements, issue refunds, reconcile transactions, and support invoicing;
  • Handle support, complaints, security incidents, and legal obligations;
  • Improve the product experience with consent or as permitted by law.

We follow principles of specified purpose, minimum necessity, transparency, and security. For sensitive personal information or situations requiring separate consent, we disclose the purpose, method, and impact and obtain the required consent.

4. Sharing, processors, and cross-border transfer

To complete payment, we provide WeChat Pay with the order number, amount, merchant information, and data necessary for the transaction. Evaluated service providers may process necessary data to send verification codes or provide cloud infrastructure or model services. Contracts, security controls, and field minimization constrain that processing.

If a specific model, enterprise deployment, or support process involves cross-border personal-information transfer, we assess it, provide separate notice, and obtain required consent beforehand. This policy does not grant blanket authorization before those procedures are complete.

5. Retention and security

We retain information only as long as needed for the purposes above and legal obligations. Orders, invoices, and audit records follow applicable legal and financial-compliance periods; information no longer needed is deleted, anonymized, or lawfully isolated.

We use access controls, transport encryption, least privilege, log auditing, backups, and security response. No network environment can guarantee absolute security; if an incident may affect your rights, we remediate and notify as required by law.

6. Cookies and browser storage

We use essential browser storage to maintain login sessions, device security, and theme settings. This data is required for features you request. Access and refresh tokens remain only in current browser session storage and are not written to script-readable cookies. The current profile cache also remains only in that session, while the authoritative record remains on the server and the page periodically refreshes it.

For anonymous visits to Pricing, prices and plan descriptions come directly with website content. The site does not request account data from the server merely to display prices or store the server price catalog in the browser. Time-limited quotes and order snapshots after login are used only to complete that purchase; the browser-displayed amount is not the charging authority.

Anonymous analytics is enabled by default on a new visitor’s first visit, while interface preferences remain optional. Choosing “Use essential only” stops future analytics and does not save interface preferences. After accepting preference cookies, we keep an account display-name hint for up to 30 days to reduce navigation flicker on reload. The hint contains no password, access token, refresh token, email, user ID, or payment information and is deleted on logout.

Signed-out visitors use default anonymous visitor analytics. Analytics sends only page paths without queries or hashes, limited CTA labels, help-result count bands, outbound destination categories, login or payment stages, plan identifiers and billing cycles, plus aggregate CLS, FCP, INP, LCP, TTFB, client-route time, prolonged missing main content, long main-thread tasks, and frontend error categories. Events exclude form content, search terms, error messages, stacks, file URLs, complete destination URLs, account credentials, raw user or tenant identifiers, order numbers, payment amounts, task content, page body, and screenshots. Analytics transport still encounters IP and User-Agent at the network layer, but the site does not send them as custom event fields.

After login, unless “Use essential only” has been selected, the browser creates a one-way SHA-256 digest of the version-namespaced server user ID and uses it as an anonymous analytics identifier for cross-session deduplication and conversion analysis. Raw user ID, tenant ID, email, and tokens are not sent to the analytics service, and the digest is not stored in local or session storage. Logging out clears the identity for future analytics. The digest is pseudonymous rather than fully anonymous, and earlier anonymous visits are not retroactively merged.

The analytics collector for this build is https://umami.kyormar.com/. Its root path does not expose a browsable administration interface. Events are retained for up to 90 days. After you choose “Use essential only,” the site immediately stops future sends. The selection is stored for up to one year so the site remembers your setting.

7. Your rights

You may request access, copies, correction, supplementation, or deletion of personal information; restrict or object to specific processing; withdraw consent; close an account; and request an explanation of processing rules. We handle verifiable requests within legal time limits and explain when a request cannot lawfully be fulfilled.

8. Minors

This service is primarily for individuals with full civil capacity and for organizations. Minors under fourteen may not create an account or purchase services without guardian consent. Contact us to delete unauthorized child information.