ByeRisk
HomePrivacy PolicyTerms of Service

Privacy Policy

Effective: 3 September 2026Last updated: 3 September 2026

This Privacy Policy explains what personal data ByeRisk collects, why we process it, who else is involved in processing it, where it is stored, and the choices and rights you have. Please read it together with our Terms of Service.

1. Scope of This Policy

This is the English-language version of our Privacy Policy. It applies to the ByeRisk website and web application across all country sites we operate, and to accounts created through any of them.

Some country sites publish a version of this policy in the local language to meet local legal requirements. Where such a version exists, it governs for users of that country site — see the section titled “Language and Local Versions”.

2. Who We Are

The controller of the personal data described in this policy is Hangzhou Runqi Technology Co., Ltd. (杭州润企科技有限公司), the operator of the ByeRisk service (“we”, “us”, “our”). For any matter concerning your personal data, including exercising the rights listed under “Your Rights”, contact us at contact@byerisk.com.

3. Personal Data We Process

a. Account data

The mobile number or email address you register with, your display name, and any avatar you upload. If you sign in with Google, see the section titled “Signing In With Google” for exactly what we receive.

b. Content you submit for review

The text, images and videos you upload, and the review results produced for them. If you include personal data in that content, the content contains personal data — do not upload other people’s personal data without a lawful basis for doing so, and avoid including specific categories of sensitive data (health, biometric, financial or criminal-record information) where the review does not require it.

c. Transaction data

Order records, the plan purchased, credit balances and usage history, and payment status. Payment instrument details (card numbers, wallet credentials) are handled directly by the payment channel — we do not store them.

d. Technical data

IP address, device and browser type, access times and system logs generated when you use the service.

4. Why We Process It

We process personal data to provide the service you asked for, to meet our legal obligations, and for the limited legitimate interests described below. Specifically:

  • To create and maintain your account, authenticate you, and keep the service secure;
  • To run compliance reviews on the content you submit and return results, flagged passages and suggested rewrites;
  • To process orders, allocate and deduct credits, issue receipts, and handle refunds where applicable;
  • To send verification codes and service notices (for example, that a review has finished);
  • To diagnose faults, prevent abuse, and improve detection quality;
  • To comply with tax, accounting and other legal obligations.

Where your consent is the basis for processing, you may withdraw it at any time — see “Your Rights”. Withdrawal does not affect processing carried out before withdrawal.

5. Signing In With Google

What we receive. If you choose to sign in with Google, Google sends us a signed token containing your email address, whether that address is verified, your name, your profile picture, and your Google account identifier. We receive nothing else.

What we do with it. We use it only to create your ByeRisk account or to recognise you when you return, and to display your name and picture inside the product. The email address becomes your account identifier and is used for service notices.

What we do not do. We do not request access to any other Google service — not Gmail, Drive, Calendar, Contacts or Photos — and we cannot read them. We do not sell Google user data, do not use it for advertising, and do not transfer it to anyone other than the processors listed under “Third Parties Involved in Processing”, who act only on our instructions.

How to disconnect. You can revoke our access at any time from your Google Account’s security settings. Doing so stops future Google sign-ins; it does not by itself delete your ByeRisk account — to delete the account and the data associated with it, use the account deletion flow in the product or contact us.

6. Automated Processing

Compliance review is automated: rule engines, machine-learning moderation models and large language models assess your content and return risk levels, flagged passages and suggested rewrites. These results are advisory and are not a decision about you. They do not by themselves restrict your access to the service, and they are not a legal opinion. You remain responsible for what you publish. If a result appears wrong, contact us — a human will look at it.

7. Third Parties Involved in Processing

To provide the service we use the following categories of processors. They may process data only on our instructions and are bound by confidentiality and security obligations:

  • Cloud infrastructure and object storage providers — the service, its databases and uploaded files are hosted there;
  • Content moderation providers — receive your text, images or video and return risk classifications;
  • Large language model providers — receive your text for semantic review and to generate suggested rewrites;
  • Speech-to-text (ASR) providers — receive the audio track of your videos and return a transcript;
  • Payment channel providers — process your payment and return transaction status;
  • Messaging providers — deliver verification codes and service notices.

All of the processors above are currently located in and operate their systems within the People’s Republic of China. See “Where Your Data Is Stored” for what that means for you. A list of the specific providers is available on request through the contact details at the end of this policy.

We may also disclose personal data where required by law or by a lawful request from a competent authority, and in the event of a merger or transfer of the business (we will notify you beforehand).

8. Where Your Data Is Stored

The fact. ByeRisk is operated from the People’s Republic of China. Your personal data — account data, the content you submit for review, transaction records and technical data — is stored and processed in the People’s Republic of China, not in your own country.

The basis. We do not claim that the receiving country has been recognised by your local authority as providing an equivalent level of protection. The transfer rests instead on binding data processing agreements with each processor — covering confidentiality, purpose limitation, security standards and a prohibition on onward transfer without authorisation — together with the consent you give by registering and accepting this policy. Where your local law requires a different or additional safeguard, the local-language version of this policy for your country site sets it out.

The consequence. You understand that data located in another jurisdiction may be subject to lawful requests from the authorities of that jurisdiction. If you do not agree to this transfer, please do not use the service; you may also withdraw your consent at any time as described under “Your Rights”, with the consequence that we can no longer provide the service to you.

9. How Long We Keep It

  • Submitted content and review history — kept while your account exists. You can delete an individual review record inside the product at any time; deletion takes effect immediately.
  • Account data — kept while your account exists. After you request deletion there is a 30-day grace period during which the account can be restored; after it expires the account data is deleted or anonymised.
  • Transaction records — kept for the period required by applicable tax and accounting rules, even after the account is closed.
  • Technical logs — kept for a short period for security and troubleshooting, then deleted on a routine schedule.

When the purpose of processing has been achieved, the retention period has expired, or you make a valid request, personal data is deleted or destroyed — except where law requires us to keep it.

10. Your Rights

Subject to the data protection law that applies to you, you have the right to:

  • Be informed about the purposes, categories and retention of the data we process;
  • Access your personal data and obtain a copy of it;
  • Correct data that is inaccurate or incomplete;
  • Stop the processing of, delete, or destroy your personal data;
  • Withdraw consent you have given;
  • Object to processing that produces a decision based solely on automated means;
  • Receive your data in a structured, commonly used format and, where technically feasible, have it transmitted to another controller;
  • Restrict processing while a dispute about accuracy or lawfulness is resolved;
  • Lodge a complaint with the data protection authority in your country;
  • Seek compensation for harm caused by unlawful processing of your personal data.

To exercise any of these rights, contact contact@byerisk.com. We will respond within the period required by the law that applies to you and, in any case, we aim to reply within 7 working days. We may ask you to verify your identity before we act, so that we do not disclose your data to someone else.

11. Security

We apply technical and organisational measures appropriate to the risk: encryption in transit, access control and least privilege for internal systems, isolation of tenant data, and logging of administrative access. No system is perfectly secure — we do not promise that, and you should not upload material you cannot afford to have exposed.

12. Breach Notification

If a failure to protect personal data occurs and it is likely to affect you, we will notify you and the competent authority within the time limit set by the applicable law, describing what happened, which categories of data were involved, and what you and we can do about it.

13. Children’s Data

ByeRisk is a tool for businesses and sellers and is not directed at children. We do not knowingly process the personal data of a child below the age at which they can consent on their own under the law that applies to them. If you believe a child has provided us with personal data, contact us and we will delete it.

14. Cookies and Local Storage

We use cookies and browser local storage to keep you signed in, to remember interface preferences such as language, and to measure aggregate usage so we can find faults and improve the product. You can clear or block them in your browser; if you block the ones required for sign-in, the service will not work.

15. Changes to This Policy

We may update this policy. The updated date at the top always reflects the current version. For changes that materially affect your rights we will give notice in the product or by email before they take effect. Continuing to use the service after that means you accept the updated policy.

16. Language and Local Versions

This English version applies to all ByeRisk country sites and is the version referenced from our Google sign-in configuration.

Where we publish a version of this policy in the official language of a country site — for example the Indonesian version for the Indonesia site — that local-language version governs for users of that country site, because local law requires agreements concluded there to be in the local language. This English version then serves as a translation for reference. For every other country site, this English version governs.

Contact and Complaints

For questions about this policy, to exercise your rights, or to complain about how we handle your personal data:

Email: contact@byerisk.com

We aim to reply within 7 working days. If you are not satisfied with our response, you may complain to the data protection authority in your country.

ByeRisk

Content compliance review for sellers and creators

Product

PricingOpen APIBlog

Country sites

ChinaIndonesia

Legal

Privacy PolicyTerms of Service
© 2026 Hangzhou Runqi Technology Co., Ltd.