ModelStation Privacy Policy

Operator (data user / controller): ELVARON LIMITED, Registration No. 79402144, 14/F, China Building, 29 Queen's Road Central, Central, Hong Kong. Contact for data matters: support@modelstation.org

Version: 2.0 Effective date: from the date of publication on the website. Supersedes: version 1.0.


1. What this document is about

This Policy explains what data ModelStation collects, why, on what legal basis, to whom it is disclosed, how long it is retained, and what rights you have. The Policy applies to the website modelstation.org and its subdomains, the account, chat, agents, memory, payments, support, and related features (“Service”).

The Policy has been prepared taking into account the requirements of: the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (“PDPO”), including Data Protection Principles 1–6; Regulation (EU) 2016/679 (“GDPR”) and the UK GDPR — in respect of users from the EEA, Switzerland, and the United Kingdom; the California Consumer Privacy Act as amended by the CPRA (“CCPA/CPRA”) — in respect of California residents; and other applicable data-protection rules.

This Policy is not part of a commercial offer and does not expand the Company’s obligations beyond what is expressly provided by mandatory rules of law.


2. Key warning: what you should not send to the Service

The Service transmits the contents of your requests to third-party AI Providers, some of which are located outside Hong Kong, the EEA, and your country, including the United States and mainland China.

Do not send to the Service:

  • information constituting protected secrecy (medical, banking, attorney-client, state, or third-party trade secrets);
  • government identifiers (passport, ID, tax number, social-security number);
  • full payment-card details, CVV codes, bank passwords;
  • biometric data and health data;
  • personal data of children;
  • personal data of third parties for the transmission of which you have no lawful basis;
  • data the cross-border transfer of which is prohibited by law or contract applicable to you.

You independently determine the content of Input and are responsible for the lawfulness of its transmission. The Company has no practical ability to detect and block such data in advance within your requests.


3. Categories of data processed

3.1 Account data

Email address; password hash (bcrypt algorithm, cost 12 — the password is not stored in plaintext); name and nickname, if provided; avatar, if uploaded; country of registration, region, city, address, and postal code, if provided; time zone; language and interface settings; AI response-style preferences; account status; email-verification flag; date of last login.

3.2 Session and device data

Session-token hash; IP address; country code determined from network data, including from service headers transmitted by the protective proxy; User-Agent string; time of creation, last activity, and expiry of the session.

3.3 Contents of requests and outputs

Text of requests and Model responses; uploaded files and images within the interface limits; attachment metadata (name, type, size); audio transcriptions, if the feature is used; saved memory items and facts and relations extracted from a conversation; custom-agent settings; model-comparison results; ratings and reviews of models.

3.4 Consumption and billing data

Transaction identifier; selected model and provider; number of input and output tokens; tools used; calculated cost; currency; current and historical balance; top-up, debit, and adjustment operations; date and time.

3.5 Payment data

Payment identifier at the payment provider; amount; currency; status; payment method in generalized form; information necessary for accounting and fraud prevention. Full card numbers, expiry dates, and CVV are not stored on the Company’s servers — they are processed by the payment provider as an independent controller.

3.6 Support requests

Email address, text of the request, attached materials, correspondence, and the outcome of review.

3.7 Technical logs and security events

Login events and failed login attempts; rate-limit triggers; application and gateway errors; blocking events and suspicious activity. We strive not to include the full text of conversations in technical logs.

3.8 Data we do not collect

We do not request or use: information about racial or ethnic origin, political opinions, religion, trade-union membership, sexual life, or criminal convictions; precise device geolocation; data from third-party advertising networks; data-broker data. If such information enters the Service as part of your Input, it is processed as ordinary request content, at your risk and at your direction.


4. Sources of data

Data are obtained: (a) directly from you — upon registration, use of chat, file upload, or contact with support; (b) automatically — upon use of the Service (technical information, logs, consumption metrics); (c) from the payment provider — payment status and identifier; (d) from the AI Provider — the generated Output and service metrics.


5. Purposes of processing and legal bases

No.PurposeData categoriesLegal basis (GDPR / UK GDPR)PDPO alignment
1Creation and maintenance of the account, authentication3.1, 3.2Performance of a contract — Art. 6(1)(b)DPP1, DPP3
2Email verification, access recovery3.1Performance of a contract — Art. 6(1)(b)DPP1
3Execution of requests to Models, operation of agents3.3Performance of a contract — Art. 6(1)(b)DPP1, DPP3
4Retention of history and memory across chats3.3Performance of a contract; for optional features — consent, Art. 6(1)(a)DPP1, DPP3
5Cost calculation, Balance maintenance, billing3.4, 3.5Performance of a contract — Art. 6(1)(b)DPP1
6Accounting and tax records3.5Legal obligation — Art. 6(1)(c)DPP2
7User support3.1, 3.6, 3.4Performance of a contract; legitimate interest — Art. 6(1)(f)DPP1, DPP3
8Security, prevention of fraud and abuse3.2, 3.7, 3.4Legitimate interest — Art. 6(1)(f)DPP4
9Ensuring operability, error diagnosis3.7Legitimate interest — Art. 6(1)(f)DPP4
10Compliance with sanctions requirements and AI Provider requirements3.1, 3.2Legal obligation; legitimate interestDPP3
11Responses to lawful requests of authorities, defense in disputesall applicableLegal obligation; legitimate interestDPP3, DPP2
12Service notices (changes to terms, security, payments)3.1Performance of a contract; legal obligationDPP3
13Optional analytics and marketing communications3.1, 3.2Consent — Art. 6(1)(a); withdrawable at any timeDPP3 + express consent under Part VI-A PDPO

The Company does not use your data and the contents of requests to train its own models and does not sell personal data.

Direct marketing (including communications about new features and offers) is carried out only with your express consent, as required by Part VI-A PDPO; consent is withdrawn via the link in the email or by contacting support@modelstation.org and terminates such use.


6. Automated processing and AI

6.1. Technical automated mechanisms are applied for: rate-limiting requests, detecting fraud and abuse, calculating cost, and routing a request to the selected model.

6.2. Such mechanisms may result in restriction of access or rejection of a request. This decision is operational in nature; you may contact support@modelstation.org for human review of the decision.

6.3. Model Outputs are produced by probabilistic algorithms and are not a decision of the Company about you. The Company does not take automated decisions about you that produce legal effects or similarly significantly affect you, within the meaning of Art. 22 GDPR.

6.4. If you use the Service to make decisions about other people, you act as the responsible person (controller / deployer of the AI system) and must independently ensure compliance with applicable requirements, including information, risk assessment, and human involvement.


7. Disclosure of data: recipients and sub-processors

7.1. Data are disclosed in the minimum necessary volume to the following categories of recipients:

CategoryWhat is receivedRole
AI Providers of the selected Modelrequest contents, attachments, service parametersindependent processor/controller under their own terms
IntegratorAI proprietary gateway (infrastructure of the same operator)request contents, consumption metrics, memory itemsinternal processing
Infrastructure hosting providerall data in a stored state on serversprocessor
Traffic protection and delivery providerIP address, headers, request countryprocessor
Payment providerspayment and contact data necessary for the transactionindependent controller
Email provideremail address, email textprocessor
Professional advisers, auditorsas needed and to the minimum extentprocessor / recipient
Government authorities and courtsupon a lawful requestrecipient
Acquirer of the business upon reorganizationto the extent of the transaction, with protection preservedcontroller

7.2. The purpose of processing and the categories of recipients are disclosed in the document “Sub-processors”: AI Providers — with names and jurisdictions; providers of the infrastructure and ancillary layer — by category. The names of specific infrastructure providers are provided upon request in the manner described in the same document; the payment provider is indicated on the payment screen before confirmation of payment.

7.3. Important: the contents of a request are transmitted only to the AI Provider whose model you selected, or to the provider selected by automatic mode if you have enabled it. The request is not sent to other providers.

7.4. The Company requires from processors contractual guarantees regarding the purpose of processing, confidentiality, security, restriction of onward transfer, and deletion of data.

7.5. The Company does not sell or “share” personal data within the meaning of the CCPA/CPRA and does not engage in behavioral advertising on their basis.


8. International data transfers

8.1. Infrastructure and AI Providers may be located outside Hong Kong and the country of your residence, including in the United States, the EEA, Singapore, and mainland China (for Kimi/Moonshot AI and Qwen/Alibaba Cloud models).

8.2. For transfers subject to the GDPR/UK GDPR, the available mechanisms are applied: the European Commission’s standard contractual clauses (Decision 2021/914) with the relevant modules, the UK International Data Transfer Addendum, a transfer-circumstance assessment, and supplementary measures (volume minimization, channel encryption, access restriction).

8.3. Section 33 of the PDPO, which regulates transfers of data outside Hong Kong, is not in force as of the date of this version; independently of that, the Company applies contractual measures recommended by the Office of the Privacy Commissioner for Personal Data of Hong Kong (PCPD).

8.4. Special warning regarding mainland China. The legal regimes of certain countries, including the PRC, permit access by competent authorities to data. If such a transfer is unacceptable to you, do not select models of the corresponding providers and do not send them data. The Company cannot guarantee the impossibility of access by authorities of foreign states to data located in their jurisdiction.

8.5. You can reduce the volume of data transferred: do not upload files, de-identify requests, disable history and memory retention, and use models of providers in a jurisdiction of your choice.


9. Retention periods

DataRetention periodBasis
Account profile and settingswhile the account is active, then up to 90 days after confirmed deletioncontract, dispute resolution
Password hashwhile the account is activesecurity
Email-verification token24 hourssecurity
Sessions12 hours, or 30 days if “remember me” is selected; then deletion or de-identificationsecurity
Chat history, attachments, memoryuntil deleted by you, deletion of the account, or expiry of the period set by product rulescontract, consent
Consumption and billing records7 yearss. 373 Companies Ordinance (Cap. 622), s. 51C Inland Revenue Ordinance (Cap. 112)
Payment records and documents7 yearsaccounting and tax legislation
Support requestsup to 24 months after closure of the requestlegitimate interest, disputes
Security logs and access eventsup to 12 months, then deletion or de-identificationsecurity
Records of violations, blocks, fraudup to 3 years; if a dispute exists — until its conclusionprotection of rights
Materials necessary for a legal claimuntil expiry of the limitation periodprotection of rights

Certain service records of use in the internal gateway may be retained in de-identified or aggregated form after deletion of a conversation, because they are necessary for accounting, tariffication, and abuse protection.


10. Your rights

10.1. Depending on applicable law, you may:

  • PDPO: obtain confirmation of the existence of data, access to data and their correction (ss. 18–22A), and withdraw consent to direct marketing;
  • GDPR / UK GDPR: access (Art. 15), rectification (16), erasure (17), restriction of processing (18), portability (20), objection to processing based on legitimate interest (21), withdrawal of consent (7(3)), complaint to a supervisory authority (77);
  • CCPA/CPRA: know the categories of data collected and recipients, obtain a copy, delete, correct, limit the use of sensitive data, and not be discriminated against for exercising rights.

10.2. How to exercise. Send a request to support@modelstation.org from the email address linked to the account, stating the substance of the request. To protect the account, we may ask you to confirm control of the address or other reasonable information. Requests through a representative are considered upon confirmation of authority.

10.3. Response period. We respond within 30 calendar days (for the PDPO — no later than 40 days pursuant to s. 19 PDPO). The period may be extended in the event of a complex request, with notice of the reasons.

10.4. Fee. A response is provided free of charge; for manifestly unfounded or excessively repetitive requests a reasonable fee may be charged to the extent permitted by law.

10.5. Limitations. We may refuse in whole or in part if the request: infringes the rights of third parties; relates to data that must be retained by law; is connected with fraud prevention and security protection; creates a risk of disclosure of confidential information. A refusal is reasoned.

10.6. Complaints. You may contact us, as well as a supervisory authority: the PCPD (Hong Kong), the data-protection supervisory authority of an EEA country, the ICO (United Kingdom), or another competent authority.


11. Cookies and local storage

The use of cookies, local storage, and the consent procedure are described in a separate Cookie Policy. Strictly necessary cookies are used for login, session security, and form protection; optional technologies are enabled only after consent, where required by law.


12. Security

12.1. The measures applied include: encryption of traffic by TLS; storage of passwords as a bcrypt hash; limitation of session lifetime; rate-limiting of requests and login attempts; access-rights segregation and the principle of least privilege; a separate administrative-access contour with additional checks; monitoring of suspicious events; backup and infrastructure-configuration control.

12.2. Further details are set out in the Security Policy.

12.3. No internet service can guarantee absolute security. The Company does not warrant the absence of incidents and is not responsible for the consequences of compromise of your devices, mailbox, or Credentials.

12.4. In the event of an incident entailing a risk to rights and freedoms, we notify affected persons and competent authorities to the extent and within the time limits established by applicable law (for the GDPR — Arts. 33, 34).


13. Children

The Service is not intended for persons under 18 years of age and, in any event, for persons below the age of independent consent under applicable law. We do not knowingly collect children’s data. If you become aware that a child has provided us with data, notify us at support@modelstation.org — the account and related data will be deleted.


14. Changes to the Policy

We may update the Policy. The number of the current version is indicated in the heading, and the date it takes effect is indicated on the document page on the website. For material changes we notify by email or through the interface at least 30 days before they take effect, unless the law requires a different procedure. Continued use of the Service after the changes take effect constitutes acknowledgment of the updated Policy; where consent is required, it is requested separately.


15. Contacts

Operator: ELVARON LIMITED, Registration No. 79402144, 14/F, China Building, 29 Queen's Road Central, Central, Hong Kong. Data requests, communications, and complaints: support@modelstation.org

We review communications regarding the processing of personal data directly and seek to resolve them without involving third parties. A communication is sent from the email address linked to the account; the procedure and time limits for review are described in §10.