Privacy Policy

personaX Privacy Policy

English Reference Version — v1.0  ·  Effective Date: 30 April 2026

The Thai version is the legally binding and controlling version.

1. Introduction and Data Controller

TENSOR ART HK LIMITED ("personaX", "we", CR No. 77289411, BR No. 77289411, RM 1903, 19/F LEE GARDEN ONE, 33 HYSAN AVENUE, CAUSEWAY BAY, HONG KONG) operates the personaX mobile application (the "Service"). This Privacy Policy describes how we handle your Personal Data under the Personal Data Protection Act B.E. 2562 ("PDPA") of the Kingdom of Thailand.

By using the Service, you acknowledge this Privacy Policy. This Policy applies together with our Terms of Service. Where specific processing requires your consent, we will seek it separately.

Data Protection Contact: personax@echo.tech

Thailand Local Representative (PDPA s.37/5): TENSOR ART HK LIMITED (pending formal appointment); contact: personax@echo.tech

2. Data We Collect, Why, and Legal Basis

The table below summarises all Personal Data we collect, the purpose for which it is used, and the legal basis under the PDPA.

Data collectedHow / whenPurposeLegal basis (PDPA)
Email address, hashed passwordYou provide at registrationAccount creation and authenticationContract (s.24(3))
Display name, avatar, bioYou provide (optional)Profile and community featuresContract (s.24(3))
User Content: OCs, generated images/video, posts, comments, messagesYou create or uploadCore Service features; moderation (public content auto+human; messages only on report); displaying to other usersContract (s.24(3)) / Legitimate interest (s.24(5))
AI prompts and reference images you submitYou input to AI featuresSending to AI model providers to generate outputsContract (s.24(3))
Device model, OS, language, timezone, device IDsAuto-collected on useAnalytics; crash reporting; fraud preventionLegitimate interest (s.24(5))
IP address, carrier, connection type, city-level location (not GPS)Auto-collected on useSecurity; approximate location for service deliveryLegitimate interest (s.24(5))
Feature usage, actions, session data, error logsAuto-collected on useService improvement; analyticsLegitimate interest (s.24(5))
Apple IDFA / Android Ad IDAuto-collected (subject to device settings)Analytics only — no third-party ads are currently servedLegitimate interest (s.24(5))
Camera / photo library accessOnly when you initiate uploadImage upload for OC creationContract (s.24(3))
Push notification tokenWhen you grant permissionDelivering in-App notificationsConsent (s.24(1))
Email, push tokenRegistration (opt-in)Product updates and promotional messagesConsent (s.24(1))
Support communications via email or Facebook PageWhen you contact usCustomer supportContract (s.24(3))
Any relevant dataAs required by lawCompliance with Thai law (CCA, tax law, law enforcement requests)Legal obligation (s.24(6))

We do not collect: precise GPS location, biometric data, health data, financial account numbers, national ID numbers, or PDPA s.26 sensitive data, unless you voluntarily include such information in User Content (which we strongly discourage).

Withdrawing consent. Where we rely on consent (e.g., marketing), you may withdraw at any time via in-App settings or personax@echo.tech, without affecting the lawfulness of prior processing.

3. How AI Features Process Your Data

Self-hosted open-source models (majority of image and video generation). We run AI models on our own infrastructure located in Mainland China. Your prompts and reference images are sent to these servers for processing. We deploy open-source models, including community models from our affiliated service TensorArt. We do not use your content to train or fine-tune these models, except with your separate explicit consent.

Third-party AI providers. Some features use third-party AI models:

ProviderPurposeLocationTraining policy
Google Gemini 2.5 Flash Image ("Nano Banana") — paid APIImage generationUSA (transient caching per Google's published policy)Google does NOT use your prompts/outputs to train its models on the paid API tier
Text AI provider (to be disclosed)Chat features (if launched)TBDTBD

What we will NOT do with your AI inputs/outputs: We will not use them to train any AI model owned by personaX or TensorArt (except with your explicit consent), sell them to third parties, or use them for any purpose outside operating the Service.

4. Third-Party Providers, Affiliates, and Data Transfers

Other service providers. We may engage providers for: cloud hosting, analytics and crash reporting (e.g., Firebase), push notification delivery, email delivery, and customer support tools (including our Facebook Page, operated by Meta — data shared there is also subject to Meta's privacy practices). All providers act as data processors under our instructions. Specific provider names will be disclosed before launch.

TensorArt affiliate. personaX and TensorArt are operated under the same corporate entity (TENSOR ART HK LIMITED). We may share data within this entity for shared infrastructure, cross-service fraud prevention, and aggregated analytics. We do not share individual User Content or private messages between the two products without your separate consent.

Cross-border transfers. Your data is transferred to: (i) Hong Kong SAR (our corporate base); (ii) Mainland China (our AI inference servers); (iii) United States (Google Gemini API); (iv) other jurisdictions where our cloud/analytics/email providers operate. Where the destination lacks PDPA-comparable protections, we rely on contractual safeguards (standard contractual clauses or equivalent) and technical measures (encryption, access controls) consistent with PDPA ss.28-29.

Legal disclosures. We may disclose Personal Data without consent to comply with Thai court orders, CCA obligations, PDPC requests, or other lawful demands; to enforce our Terms; to protect safety; to prevent fraud; or in a corporate transaction where the acquirer agrees to this Policy.

5. Data Retention

DataRetention period
Account data (email, hashed password)Account lifetime + 90 days after deletion
Public User Content (posts, comments, OCs)Account lifetime; removed from public display on deletion; backup purged within 90 days
Private messagesAccount lifetime (indefinite); removed from your view on deletion; copies held by other users may persist
AI prompts and generated outputsUp to 90 days (abuse detection); longer if legally required
Payment / transaction records (future)5 years (Thai tax law)
Login and security logs6–12 months
Moderation recordsUp to 2 years
Suspended / terminated account dataUp to 90 days for appeal; then deleted or anonymized

6. Your PDPA Rights

You have the right to: access, rectify, erase, restrict, object to, and port your Personal Data; withdraw consent at any time; and lodge a complaint with the PDPC (https://www.pdpc.or.th / pdpc@mdes.go.th).

Exercise most rights directly in the App (account deletion, data access, marketing opt-out). For other requests, contact personax@echo.tech. We respond within 30 days. Identity verification may be required.

7. Security, Children, Marketing, and Tracking

Security. We use TLS encryption in transit, hashed password storage, access controls, and incident response procedures. In the event of a high-risk breach, we will notify you and the PDPC within 72 hours as required by PDPA s.37(4). Note: private messages are NOT end-to-end encrypted — please do not share sensitive information (ID numbers, bank details, passwords) in messages.

Children. The Service is for users 18+. We do not knowingly collect data from anyone under 18. If discovered, we will delete it and terminate the Account. Contact personax@echo.tech if you believe a child has shared data with us.

Marketing. We send promotional emails and push notifications only with your consent (opt-in at registration). Opt out anytime via in-App settings, email unsubscribe links, or personax@echo.tech. Transactional messages (security alerts, Terms updates, support replies) continue regardless.

Tracking. We use device identifiers and SDK-based analytics for session management, preference memory, crash reporting, and fraud prevention. We do not currently serve third-party advertising. If advertising is introduced, we will update this Policy and obtain consent where required.

8. Changes, Language, and Contact

Changes. Material changes will be notified by email and in-App push at least 14 days before taking effect. Continued use constitutes acceptance.

Language. This Policy is available in Thai and English. The Thai version is the legally binding and controlling version.

Company: TENSOR ART HK LIMITED

Company Registration No.: 77289411

Business Registration No.: 77289411

Registered Address: RM 1903, 19/F LEE GARDEN ONE, 33 HYSAN AVENUE, CAUSEWAY BAY, HONG KONG

All Inquiries (Support / Legal / PDPA): personax@echo.tech

Thailand Local Representative (PDPA s.37/5): TENSOR ART HK LIMITED (pending formal appointment); contact: personax@echo.tech

PDPC (regulator): https://www.pdpc.or.th | pdpc@mdes.go.th

— End of Privacy Policy —