Privacy Policy
This Privacy Policy explains what personal information the ByeRisk United States site collects, why we use it, who else is involved in processing it, where it is stored, and the choices and rights you have, including the rights of residents of California and other U.S. states. Please read the section titled âWhere Your Information Is Storedâ carefully: your personal information is stored and processed in the Peopleâs Republic of China. Please read this Policy together with our Terms of Service.
1. Scope of This Policy
This Policy applies to the ByeRisk United States site (the âUS siteâ), meaning the website and web application available at www.byerisk.com/us in English-language and Chinese-language interfaces, and to the personal information we process when you use it.
Your ByeRisk account can also be used on other ByeRisk sites. Your use of those sites is governed by the privacy policies published for them. Where this Policy differs from the general English-language ByeRisk Privacy Policy, this Policy governs your use of the US site.
2. Who We Are
The ByeRisk service is operated by Hangzhou Runqi Technology Co., Ltd. (ćĺˇćśŚäźç§ććéĺ Źĺ¸) (âweâ, âusâ, âourâ), which is responsible for the personal information described in this Policy. For any matter concerning your personal information, including exercising the rights described in this Policy, contact us at contact@byerisk.com.
3. Personal Information We Collect
a. Account information
The email address or mobile number you register with, your display name, any avatar you upload, and a password if you choose to set one (we store passwords only in hashed form). If you sign in with Google or WeChat, see the section titled âSigning In With Google or WeChatâ for exactly what we receive.
b. Content you submit for review
The text, images and videos you upload, and the review results produced for them. If you include personal information in that content, the content contains personal information. Do not upload other peopleâs personal information without a lawful basis for doing so, and avoid including sensitive information (such as health, biometric, financial or government identification information) where the review does not require it.
When you use a free checker on our tool pages without signing in, the text you enter is processed to return the results and is not stored. We record only that a check was made and the length of the text, to measure how the tool pages are used.
c. Transaction information
Order records, the plan or credit pack purchased, the currency and amount paid, credit balances and usage history, and payment status. Payment card and wallet details are entered directly with the payment provider (Stripe, WeChat Pay or Alipay, or Apple for purchases in the iOS app); we do not receive or store your full card number or your wallet credentials.
d. Device and usage information
IP address, device and browser type, access times and system logs generated when you use the Service, and information about how you interact with our web pages collected through cookies and similar technologies (see âCookies, Analytics and Similar Technologiesâ).
4. How We Use Personal Information
We use personal information to provide the Service you request, to meet our legal obligations, and for the limited business purposes described below. Specifically:
- To create and maintain your account, authenticate you, and keep the Service secure;
- To run compliance reviews on the content you submit and return results, flagged passages and suggested rewrites;
- To process orders, allocate and deduct credits, issue receipts, and handle refunds where applicable;
- To send verification codes and service notices (for example, that a review has finished);
- To diagnose faults, prevent abuse, and improve detection quality;
- To comply with tax, accounting and other legal obligations.
Where we rely on your consent, you may withdraw it at any time; see âYour Rights and Choicesâ. Withdrawal does not affect processing carried out before you withdrew it.
5. Signing In With Google or WeChat
a. Google sign-in
What we receive. Google sign-in is available in the English-language interface. If you choose to sign in with Google, Google sends us a signed token containing your email address, whether that address is verified, your name, your profile picture, and your Google account identifier. We receive nothing else.
What we do with it. We use it only to create your ByeRisk account or to recognize you when you return, and to display your name and picture in the product. The email address becomes your account identifier and is used for service notices.
What we do not do. We do not request access to any other Google service, such as Gmail, Drive, Calendar, Contacts or Photos, and we cannot read them. We do not sell Google user data, do not use it for advertising, and do not transfer it to anyone other than the service providers listed under âThird Parties Involved in Processingâ, who act only on our instructions.
How to disconnect. You can revoke our access at any time in the security settings of your Google Account. Doing so stops future Google sign-ins, but does not by itself delete your ByeRisk account. To delete the account and the information associated with it, use the account deletion feature in the product or contact us.
b. WeChat sign-in
WeChat sign-in is available in the Chinese-language interface. If you choose to sign in with WeChat, WeChat provides us with identifiers for your WeChat account, which we use only to sign you in and to link your WeChat account to your ByeRisk account. When you first sign in this way, you are asked to link a mobile number.
6. Automated Processing
Compliance review is automated: rule engines, machine-learning moderation models and large language models assess your content and return risk levels, flagged passages and suggested rewrites. These results are advisory and are not a decision about you. They do not by themselves restrict your access to the Service, and they are not a legal opinion. You remain responsible for what you publish. If a result appears to be wrong, contact us and a member of our staff will review it.
7. Third Parties Involved in Processing
To provide the Service, we use the following categories of service providers. They process personal information to provide their services to us and are bound by confidentiality and security obligations under their terms with us:
- Cloud infrastructure and object storage providers, which host the Service, its databases and uploaded files;
- Content moderation providers, which receive your text, images or video and return risk classifications;
- Large language model providers, which receive your text for semantic review and to generate suggested rewrites;
- Speech-to-text providers, which receive the audio track of your videos and return a transcript;
- Payment service providers (Stripe for payments in the English-language interface; WeChat Pay and Alipay for payments in the Chinese-language interface), which process your payment and return the transaction status. Card details you enter on Stripeâs checkout page are collected by Stripe directly, and Stripeâs own privacy policy also applies to them;
- Messaging providers, which deliver verification codes and service notices by text message and email.
Except as stated in this paragraph, the service providers above are located in, and operate their systems within, the Peopleâs Republic of China. The exception is Stripe, which processes payments made in the English-language interface on systems located outside the Peopleâs Republic of China, including in the United States. A list of the specific providers is available on request through the contact details at the end of this Policy.
Purchases in the iOS app. Purchases in the ByeRisk iOS app are made through Appleâs in-app purchase system under Appleâs own terms and privacy policy, and Apple processes them on its own systems, including outside the Peopleâs Republic of China. Apple tells us the transaction identifier, the product purchased, the purchase and expiry dates, and the renewal and refund status, so that we can grant and update your plan or credits. We do not receive your payment details or your Apple Account password.
Third parties that collect information on our web pages for their own purposes
Our web pages, but not the ByeRisk mobile apps, load tools from the companies below. These companies collect information directly from your browser and use it under their own privacy policies, including for their own purposes such as improving their products and advertising. They are not service providers acting only on our instructions.
- Microsoft Corporation (Microsoft Clarity), for usage analytics and session replay. Microsoft states that it may use the information it collects to provide Microsoft Advertising and to create user profiles for purposes that include advertising, and that it may store and process personal data in the United States and other countries. Microsoft Privacy Statement: https://privacy.microsoft.com/en-us/privacystatement
- Baidu (Baidu Tongji), for web analytics. Baidu states that it stores the personal information of end users in the Peopleâs Republic of China, that it may use the information to improve the products of Baidu and its affiliates and partners, and that it may share de-identified user profiles with advertisers. Baidu Tongji Privacy Policy: https://tongji.baidu.com/web/help/article?id=330&type=0
- ByteDance (Toutiao search), whose script submits the address of the page you are viewing to Toutiao search so that the page can be indexed. When the script loads, ByteDance receives your IP address and browser information.
How to stop these tools from loading is explained under âCookies, Analytics and Similar Technologiesâ, and what this means under state privacy laws is explained under âU.S. State Privacy Rightsâ.
We may also disclose personal information where required by law or in response to a lawful request from a competent authority, and in connection with a merger or transfer of the business, in which case we will notify you beforehand.
8. Where Your Information Is Stored
The fact. ByeRisk is operated from the Peopleâs Republic of China. Your personal information, including account information, the content you submit for review, transaction records and technical data, is transferred to, stored and processed in the Peopleâs Republic of China, not in the United States. The limited exceptions are described under âThird Parties Involved in Processingâ.
Safeguards. Our service providers process personal information to provide their services to us under their service terms or agreements with us, which include confidentiality and security obligations. We combine this with the technical and organizational measures described under âSecurityâ.
The consequence. The data protection laws of the Peopleâs Republic of China differ from those of the United States, and information located there may be subject to lawful requests from the authorities of that jurisdiction. If you do not agree to this transfer, please do not use the Service. You may also withdraw your consent at any time as described under âYour Rights and Choicesâ, in which case we will no longer be able to provide the Service to you.
9. How Long We Keep It
- Submitted content and review history: kept while your account exists. You can delete an individual review record in the product at any time; deletion takes effect immediately.
- Account information: kept while your account exists. After you request deletion, there is a 30-day grace period during which the account can be restored; after it expires, the account information is deleted or de-identified.
- Transaction records: kept for the period required by applicable tax and accounting rules, even after the account is closed.
- Technical logs: kept for a short period for security and troubleshooting, then deleted on a routine schedule.
When the purpose of processing has been achieved, the retention period has expired, or you make a valid request, personal information is deleted or destroyed, except where the law requires us to keep it.
10. Your Rights and Choices
Subject to the law that applies to you, you may:
- Be informed about the purposes, categories and retention of the personal information we process;
- Access your personal information and obtain a copy of it in a structured, commonly used format where technically feasible;
- Correct personal information that is inaccurate or incomplete;
- Delete individual review records in the product, and request deletion of your account and the personal information associated with it;
- Withdraw consent you have given, for example by revoking Google sign-in access or closing your account;
- Object to processing that produces a decision about you based solely on automated means;
- Submit a complaint to the attorney general of your state or, if you are a California resident, to the California Privacy Protection Agency.
To exercise any of these rights, contact contact@byerisk.com. We aim to reply within 7 business days and will in any case respond within the period required by applicable law. We may ask you to verify your identity before we act, so that we do not disclose your information to someone else. If you are a resident of California or another U.S. state with a comprehensive consumer privacy law, see also the next section.
11. U.S. State Privacy Rights
This section supplements the rest of this Policy for residents of California and of other U.S. states with comprehensive consumer privacy laws. It addresses the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the âCCPAâ), and similar state laws. The rights described below apply to the extent those laws apply to us and to you.
a. Categories of personal information we collect
Using the categories defined in the CCPA, we collect the following:
- Identifiers, such as your name or display name, email address, mobile number, account identifiers, Google or WeChat account identifiers, and IP address;
- Customer records described in California Civil Code § 1798.80(e), such as your name and telephone number;
- Commercial information, such as orders, the plans and credit packs purchased, and credit usage history;
- Internet or other electronic network activity information, such as access times, system logs, device and browser type, and how you interact with our web pages;
- Audio, electronic, visual or similar information, such as the images and videos (including their audio) you submit for review and any avatar you upload;
- Other information you choose to include in content you submit for review, which may be of any type;
- Sensitive personal information, limited to account log-in credentials: your email address or mobile number in combination with a password, if you set one.
We keep each category for the periods described under âHow Long We Keep Itâ.
b. Sources
We collect personal information directly from you; automatically from your device and browser when you use the Service; from Google or WeChat when you choose to sign in with them; and from payment service providers, including Apple for purchases in the iOS app, which tell us the status of your payment.
c. Purposes and disclosures
We collect and use each category of personal information for the business purposes described under âHow We Use Personal Informationâ. We disclose it to the categories of service providers described under âThird Parties Involved in Processingâ for those purposes. Identifiers and internet activity information are also collected on our web pages by the third parties described in that section for their own purposes, as explained under âSale and sharingâ below. Otherwise, we disclose personal information only where required by law.
d. Sale and sharing
We do not exchange your personal information for money. However, our web pages allow Microsoft (through Microsoft Clarity) and Baidu (through Baidu Tongji) to collect identifiers, such as cookie identifiers and IP address, and internet or other electronic network activity information, such as the pages you view and how you interact with them, which they may use for their own purposes, including advertising; ByteDance receives similar information when its Toutiao script loads. Under the CCPA, making personal information available in this way may be considered a âsaleâ or âsharingâ for cross-context behavioral advertising. You can opt out as described under âYour rightsâ below, including by using Global Privacy Control. We do not have actual knowledge that we sell or share the personal information of consumers under 16 years of age.
e. Sensitive personal information
We use sensitive personal information only to authenticate you and keep your account secure, which are purposes permitted by the CCPA without a right to limit. We do not use or disclose it to infer characteristics about you.
f. Your rights
Subject to the conditions and exceptions set out in the law, you have the right to:
- Know and access: request the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for which we use it, and the categories of third parties to which we disclose it;
- Delete: request that we delete personal information we have collected from you;
- Correct: request that we correct inaccurate personal information about you;
- Opt out of sale or sharing: use the âYour Privacy Choicesâ link at the bottom of our web pages (https://www.byerisk.com/us/privacy-choices), or turn on Global Privacy Control in your browser. Either stops the tools described in âSale and sharingâ from loading on the US site in that browser;
- Limit the use of sensitive personal information: because we use sensitive personal information only for the permitted purposes described above, this right does not currently apply;
- Non-discrimination: we will not deny you the Service, charge you a different price, or provide a different level or quality of service because you exercised any of these rights.
g. How to submit a request
Submitting a request. Email contact@byerisk.com, tell us which right you wish to exercise, and state your state of residence. We will confirm receipt within 10 business days and respond within 45 calendar days. If we need more time, we may extend this period by up to a further 45 calendar days, and we will tell you why.
Verification. To protect your information, we will verify your identity before acting on a request to know, access, delete or correct, normally by asking you to confirm that you control the email address or mobile number associated with your account. We will use the information you provide for verification only for that purpose.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require the agent to provide your signed permission, and we may ask you to verify your identity directly with us.
Appeals. If we decline to act on your request, we will explain why. Where the law of your state provides a right to appeal, you may appeal our decision by replying to it or by emailing contact@byerisk.com with the subject line âPrivacy Appealâ. We will respond to your appeal within the period required by that law. If we deny your appeal, you may contact the attorney general of your state.
h. Direct marketing disclosures (California)
We do not sell, rent or otherwise disclose personal information to third parties so that they can send you their own direct marketing. As described under âThird Parties Involved in Processingâ, analytics providers that collect information on our web pages may use it for their own purposes, including advertising; you can stop this as described under âYour rightsâ above.
12. Security
We apply technical and organizational measures appropriate to the risk, including encryption in transit, access control and least privilege for internal systems, isolation of customer data, and logging of administrative access. No system is perfectly secure. We do not promise otherwise, and you should not upload material you cannot afford to have exposed.
13. Breach Notification
If a security incident affecting personal information occurs and it is likely to affect you, we will notify you, and any authority that must be notified, within the time required by applicable law, describing what happened, which categories of information were involved, and what you and we can do about it.
14. Childrenâs Privacy
ByeRisk is a tool for businesses and is not directed to children under 13. Consistent with the Childrenâs Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe that a child under 13 has provided us with personal information, contact us. Our Terms of Service require users to be at least 18 years old.
15. Cookies, Analytics and Similar Technologies
We use cookies and browser local storage to keep you signed in and to remember interface preferences, such as language.
Microsoft Clarity. Clarity records how you interact with our web pages, such as pages viewed, clicks, scrolling and mouse movement, and provides session replay. Text you type into input fields is masked by default, but a recording may include other content displayed on the page, including content you submitted for review when it is shown back to you in results or rewrites. Clarity sets first-party cookies (_clck, _clsk) and Microsoft cookies such as MUID, CLID and ANONCHK. Microsoft states that it keeps session recordings for 30 days.
Baidu Tongji. Baidu Tongji collects information such as the pages you view, visit times, the referring page, and device and browser information. It sets first-party cookies (named Hm_lvt_, Hm_lpvt_ and similar, followed by a site identifier) and Baidu cookies such as HMACCOUNT, which Baidu describes as used for cross-site tracking, retargeting and advertising.
Toutiao search. On our public marketing pages, ByteDanceâs Toutiao script submits the page address for search indexing, as described under âThird Parties Involved in Processingâ.
Your choices. You can stop these three tools from loading on the US site through the âYour Privacy Choicesâ link at the bottom of our web pages (https://www.byerisk.com/us/privacy-choices). If your browser sends a Global Privacy Control signal, we treat it as the same request and these tools do not load while the signal is on. Your choice applies to the browser you use. You can also opt out of interest-based advertising by Microsoft and other participating companies at https://optout.aboutads.info. These tools are not used in the ByeRisk mobile apps.
You can clear or block cookies and similar technologies in your browser settings; if you block those required for sign-in, the Service will not work. The Service does not respond to âDo Not Trackâ signals; it does honor Global Privacy Control as described above.
16. Changes to This Policy
We may update this Policy. The âLast updatedâ date at the top always reflects the current version. For changes that materially affect your rights, we will give notice in the product or by email before they take effect. If you continue to use the Service after that, you accept the updated Policy.
17. Language
This Policy is written in English, and the English version is the governing text. The Chinese version is a translation provided for convenience only. If the two versions differ or are inconsistent in meaning, the English version prevails.
For questions about this Policy, to exercise your rights, or to complain about how we handle your personal information, contact us at:
Email: contact@byerisk.com
We aim to reply within 7 business days. Requests under U.S. state privacy laws are handled within the time limits described in âU.S. State Privacy Rightsâ.