LEGAL
Privacy Notice
This Notice explains what personal data ClickCrit processes, why we use it, who receives it, how long we keep it, and the choices available to you.
Effective date: September 13, 2026 · Version: 2026-09-13
Controller and contact
ClickCrit is a service operated by Haoverse, an individual trading as ClickCrit, located in Hong Kong (“ClickCrit”, “we”, “us”). ClickCrit is the controller of personal data described in this Notice. To make a privacy, access, correction, deletion, or other data request, email support@clickcrit.com.
Data we collect
- Account and authentication data: your Google account identifier or verified email address, the email address, name, avatar URL, and authentication metadata made available through sign-in; password-verification, session, email-confirmation, password-reset, and policy-acceptance records. ClickCrit does not receive or store your plaintext password.
- Project and content data: game and campaign details, reference images, generation instructions, generated images, selections, edits, exports, and file metadata.
- Payment and Credit data: Stripe customer, Checkout, payment, invoice, subscription, and refund or dispute identifiers; plan, amount, currency, payment status, Credit grants, Credit transactions, and expiration dates. Stripe collects and processes card details. ClickCrit does not normally receive or store your full card number.
- Support data: messages, email address, attachments, and transaction or account details you choose to provide when contacting support.
- Technical and security data: limited event, error, browser, device, network, request, timestamp, CAPTCHA, and security information generated when you use the service. To prevent repeated free-trial abuse, we retain pseudonymous hashes derived from verified sign-in provider identifiers, a verified email address, IP address or network prefix, and a random browser installation identifier. We do not store the raw email, IP address, or browser identifier in the trial-claim record.
Why we use data and our legal bases
Where applicable law requires a legal basis, we process data as follows:
- Contract: to create and secure your account, provide private projects, generate and export images, administer Credits, process purchases, and provide billing support.
- Legitimate interests: to protect the service and users, prevent abuse and fraud, diagnose failures, measure limited product-funnel performance, enforce our terms, and improve reliability, provided those interests are not overridden by your rights.
- Legal obligations: to keep business and payment records, respond to lawful requests, and handle tax, accounting, refund, and dispute obligations.
- Consent: where required for an optional feature or processing activity. You may withdraw consent for future processing, without affecting processing already carried out lawfully.
Account, project, generation, and payment information is necessary to provide the corresponding service. If you do not provide it, ClickCrit may be unable to create an account, generate images, or complete a purchase.
Private content and image generation
Image generation providers. When you start a generation, ClickCrit transmits your reference image, generation instructions, and a short-lived signed URL to contracted third-party AI generation and infrastructure providers for the purpose of producing the requested output. These providers may use downstream subprocessors and may process data in countries outside your country of residence.
ClickCrit does not make your private project materials available to other users. Information about our current subprocessors is available upon request by contacting support@clickcrit.com.
Service providers and international transfers
We disclose data only as needed to operate the service to: Google for sign-in; Supabase for authentication, database, and private storage; Stripe for Checkout, billing, and payment processing; contracted AI generation, infrastructure, and downstream providers for image generation; Vercel for application hosting; Cloudflare for network, scheduled-task, DNS, and email-routing services; PostHog for limited product analytics; and Sentry for error reporting.
These providers may process data in Hong Kong, the United States, the European Economic Area, and other countries where they or their subprocessors operate. Where required, we rely on the provider's contractual transfer safeguards or another lawful transfer mechanism. Provider processing is also subject to its own privacy notice and terms.
ClickCrit does not sell personal data and does not share personal data with third parties for cross-context behavioural advertising.
Cookies, sessions, analytics, and error reporting
ClickCrit and Supabase use strictly necessary cookies or similar browser storage to maintain secure Google and email/password sign-in sessions, email confirmation and password recovery requests, protect sign-in flows, and store a random browser installation identifier used to limit repeated free-trial claims. Stripe may use necessary technologies on its hosted Checkout and Billing Portal. Separate Cloudflare Turnstile challenges process limited request and device information to protect authentication and free-trial claims.
PostHog is configured in cookieless mode, without person profiles, automatic capture, session recording, or persistent PostHog cookies or browser storage. It receives an allowlist of product-funnel events and limited public-page or product-category values.
Sentry is configured to minimize and scrub sensitive data. ClickCrit removes request, user, breadcrumb, custom context, URL transaction, and error-message values before reporting. Sentry may still receive technical stack frames, source-map identifiers, timestamps, software environment, and similar information needed to diagnose an error.
Retention and deletion
- Account and profile data: kept while the account is active and then deleted or anonymized when no longer needed, subject to legal, fraud-prevention, dispute, and security requirements.
- Reference images, generated results, edits, and exports: retained by ClickCrit for up to 30 days unless you delete the relevant project or asset earlier. Expired files are queued for deletion from private storage. The generation provider's published retention is described above.
- Orders, payments, refunds, Credit records, and related webhook records: retained for at least 7 years from the relevant transaction where required for Hong Kong business, tax, accounting, audit, fraud-prevention, or legal-claim purposes.
- Operational, trial-claim, and security records: kept for the shortest practical period allowed by provider settings and needed to investigate errors, enforce one trial per eligible identity, secure the service, prevent abuse, and resolve disputes, then deleted, anonymized, or aggregated. A minimum pseudonymous trial-claim marker may remain after account deletion where needed to prevent repeat claims.
- Support messages: kept while needed to resolve the request and maintain a reasonable support and dispute history, then periodically reviewed for deletion unless a legal or accounting reason requires longer retention.
- Backups: deleted data may remain in access-restricted backups until the backup is overwritten through the normal rotation cycle. We do not restore deleted data to active use unless needed for disaster recovery, security, or legal compliance.
You can delete projects and assets in the product where available. For account or other personal-data deletion, email support@clickcrit.com. We may retain the minimum data required by law or needed to establish, exercise, or defend legal claims.
Your rights
Depending on where you live and subject to legal exceptions, you may have rights to access, correct, delete, restrict, or object to processing of your personal data; receive certain data in a portable format; withdraw consent; and complain to a privacy regulator. Hong Kong users may request access to and correction of personal data under the Personal Data (Privacy) Ordinance. EEA and UK users may also contact the supervisory authority where they live or work.
Send requests to support@clickcrit.com. We may need to verify your identity before acting on a request.
Security
We use private storage, access controls, signed URLs, encryption in transit, limited provider access, and other technical and organizational measures intended to protect personal data. No online service can guarantee absolute security.
Public sharing and future gallery features
ClickCrit does not currently publish your project content in a public gallery. If a gallery or public-sharing feature is introduced, only content you expressly choose to publish will be made public. Before launch, we will explain the public visibility, retention, withdrawal, and deletion controls and update this Notice as needed.
Changes to this Notice
We may update this Notice as the service or legal requirements change. For material changes, we will provide reasonable notice by email or a prominent in-service notice before the change takes effect where practicable. Urgent security or legal changes may take effect sooner. The effective date and version above identify the current Notice.