# SIPAI PRIVACY POLICY
- Effective date
- Pending approved legal text
- Last updated
- Pending approved legal text
- Version
- 1.0
SIPAI PRIVACY POLICY
**Effective Date: 15Jun2026** **Last Updated: 15Jun2026**
1. Introduction
This Privacy Policy explains how the operator of the service known as “SipAI” (“SipAI”, “we”, “us” or “our”) collects, uses, discloses, stores, retains and protects personal data in connection with the Services.
SipAI is the data user responsible for determining the purposes for which and the manner in which personal data is collected, held, processed and used in connection with the Services.
Privacy and data access or correction requests may be addressed to the SipAI Privacy Officer using the contact details set out in this Privacy Policy.
- the SipAI website and related webpages;
- the SipAI mobile applications made available through the Apple App Store, Google Play or other application marketplaces;
- the SipAI discussion forum, communities and related functions;
- communications, reports, enquiries and support services relating to SipAI; and
- any updates, replacements or successor versions of the above,
collectively, the “Services”.
This Privacy Policy also serves as our general Privacy Policy Statement in relation to personal data handled through the Services.
Please read this Privacy Policy carefully before using the Services or providing personal data to us.
By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. Where consent is required by applicable law, we will request that consent separately and will not rely solely on your acknowledgement of this Privacy Policy.
2. Scope
This Privacy Policy applies to personal data processed by or on behalf of SipAI in connection with the Services.
It does not apply to:
- information that has been irreversibly anonymised so that no individual can reasonably be identified;
- third-party websites, applications, services or platforms that operate under their own privacy policies; or
- information processed by another person independently of SipAI.
The Services are intended only for persons aged eighteen or above.
3. Meaning of Personal Data
For the purposes of this Privacy Policy, “personal data” means information that relates to an identified or reasonably identifiable individual, including information which may identify an individual when combined with other information.
Personal data may include account information, online identifiers, technical information, communications, public forum activity and other information described in this Privacy Policy.
4. Personal Data We Collect
The personal data we collect depends on how you use the Services, the features you access and the information you choose to provide.
4.1 Account and authentication information
When you create, access or maintain an account, we may collect:
- your email address;
- your username, display name or account identifier;
- authentication credentials or authentication tokens;
- encrypted or hashed password information, where password login is supported;
- information received from an approved third-party sign-in provider;
- records showing whether and when you accepted our Terms of Use, Privacy Policy or other notices;
- account creation, login, verification, recovery and deletion records;
- account status, including warnings, restrictions, suspensions or bans; and
- confirmation that you meet the minimum-age requirement.
We do not normally require your legal name, Hong Kong identity card number, passport number or exact date of birth in order to create a standard SipAI account.
We may request additional verification information where reasonably necessary to investigate fraud, unauthorised access, impersonation, legal complaints, serious safety matters or account-ownership disputes.
4.2 Profile information
We may collect profile information that you choose to provide, such as:
- a display name;
- a biography or profile description;
- interests, preferred forum sections or content preferences;
- language preferences; and
- other profile fields made available through the Services.
Unless expressly indicated otherwise, profile information may be visible to other users.
4.3 User Content and forum activity
When you use the forum or community functions, we may collect and process:
- posts and discussion threads;
- titles, comments and replies;
- images and other permitted attachments;
- links and references included in your Content;
- timestamps and edit history;
- forum categories, tags and posting activity;
- reactions, votes, bookmarks, follows or similar interactions, where available;
- information indicating that Content has been deleted, hidden, edited or moderated;
- Content visibility and status information;
- reports made about your Content or account; and
- information that you voluntarily include in User Content.
User Content posted in public areas is public information. You should not include sensitive personal data, confidential information, authentication credentials, private keys, exact private-location information or information concerning another person unless you have lawful authority and all necessary consent.
4.4 Image and file information
Where you upload an image or permitted file, we may process:
- the image or file itself;
- file name, format, MIME type and file size;
- image dimensions and technical properties;
- upload date and time;
- storage path or object identifier;
- information required to scan, validate, resize, compress, reformat, proxy, cache or deliver the file;
- metadata contained in the file, although we may remove some metadata during processing; and
- moderation, report or enforcement information associated with the file.
We may reject, compress, convert, remove, restrict or delete files that do not comply with technical, safety or legal requirements.
4.5 Reports, complaints and moderation information
If you report Content, a user or other activity, or if another person reports you, we may collect:
- the identity and account details of the reporting user;
- the identity or account details of the reported user;
- the Content, conduct or account being reported;
- the report category and explanation;
- supporting screenshots, links, documents or communications;
- report timestamps and technical records;
- previous related reports or enforcement history;
- moderator notes and internal assessments;
- investigation records;
- decisions, warnings, restrictions, suspensions, removals or appeals; and
- communications with affected users, service providers, advisers or authorities.
Reports are generally not public. We do not normally disclose the reporting user’s identity to the reported user, but disclosure may occur where required by law, necessary for legal proceedings, or reasonably necessary to investigate or resolve a matter.
4.6 Communications and support information
When you contact us, we may collect:
- your name, username, email address and contact details;
- the contents of your enquiry or communication;
- attachments and supporting information;
- technical and account information relevant to your request;
- our responses and internal notes;
- the date, time and status of the enquiry; and
- information required to verify your identity or authority.
This includes communications concerning support, privacy rights, account recovery, deletion, safety, copyright, legal notices and appeals.
4.7 Device, network and technical information
When you access or use the Services, we may automatically collect:
- internet protocol address;
- device type, manufacturer and model;
- operating system and version;
- browser type and version;
- application version and build number;
- device, installation, session or application identifiers;
- language, time zone and general regional settings;
- screen size and technical configuration;
- referring page, requested URL and navigation information;
- access dates and times;
- session duration and interaction events;
- network, server and content-delivery information;
- error, crash, performance and diagnostic information;
- security, authentication and fraud-prevention signals;
- cookie, local-storage and cache identifiers; and
- push-notification token, where notifications are enabled.
An internet protocol address or similar technical information may indicate an approximate city or region. We do not use such information to determine your precise real-time location.
4.8 Usage information
We may collect information concerning how the Services are used, including:
- pages, screens and forum sections viewed;
- features used;
- search queries entered within the Services;
- posts opened, created, edited or deleted;
- clicks, reactions and navigation events;
- notification interactions;
- session frequency and duration;
- feature performance and errors; and
- aggregated usage trends.
Where analytics tools are enabled, analytics information may be associated with an account, device, session or pseudonymous identifier. We do not use third-party advertising trackers unless this Privacy Policy and the relevant consent mechanism are updated accordingly.
4.9 Information received from third parties
We may receive information from:
- Apple, Google or another approved sign-in provider;
- Apple App Store, Google Play or another application marketplace;
- hosting, database, authentication, storage, security or content-delivery providers;
- email, notification, analytics or error-monitoring providers;
- users who report Content, accounts or conduct;
- legal advisers, regulators, courts, law-enforcement agencies or public authorities;
- persons making copyright, privacy or other legal complaints; and
- publicly available sources, where reasonably necessary to investigate misuse, impersonation, fraud, security incidents or legal complaints.
We process third-party information only for purposes that are reasonably connected to operating, securing, moderating or protecting the Services or complying with law.
4.10 Information we do not ordinarily collect
The Services are not designed to require access to:
- your contacts or address book;
- precise GPS location;
- microphone recordings;
- health records;
- payment card information;
- government identity documents; or
- biometric identifiers.
If a future feature requires any such information, we will provide an appropriate notice, request any required permission or consent, and update this Privacy Policy where necessary.
5. Mandatory and Optional Information
Certain information is required in order for us to provide the Services.
Account information such as an email address, authentication information, username or account identifier, and acceptance records may be mandatory. If you do not provide mandatory information, we may be unable to:
- create or maintain your account;
- authenticate you;
- provide posting or community functions;
- secure or recover your account;
- process an account-deletion request; or
- comply with legal or safety obligations.
Profile information, optional Content, images, notification permissions and non-essential preferences are generally voluntary. Choosing not to provide optional information may prevent you from using the corresponding optional feature but should not prevent access to unrelated functions.
A collection screen may provide a more specific Personal Information Collection Statement where required.
6. How We Use Personal Data
We may use personal data for the following purposes and purposes directly related to them.
6.1 Providing and administering the Services
We use personal data to:
- create, authenticate and maintain accounts;
- provide website, application and forum functions;
- publish, display, organise and deliver User Content;
- enable posting, commenting, reporting, blocking and account-management features;
- maintain user settings and preferences;
- synchronise information across devices;
- provide notifications and service communications;
- process account recovery, correction and deletion requests; and
- provide customer and technical support.
6.2 Content hosting and delivery
We use personal data and User Content to:
- store and retrieve posts, comments and images;
- process, resize, compress, reformat and deliver images;
- operate content-delivery, caching and proxy services;
- maintain backups and service continuity;
- manage Content status, visibility and deletion; and
- prevent unauthorised or harmful file uploads.
6.3 Safety, moderation and community integrity
We may use personal data to:
- receive and evaluate reports;
- identify potentially prohibited Content or conduct;
- temporarily hide Content following report-volume or safety thresholds;
- conduct manual review;
- investigate spam, harassment, impersonation, fraud, ban evasion or other abuse;
- issue warnings or impose restrictions;
- suspend or terminate accounts;
- prevent suspended or banned users from improperly returning;
- preserve relevant evidence;
- protect users, moderators, employees, contractors and the public; and
- enforce our Terms of Use.
Moderation may involve human review and automated rules based on report volume, account activity, technical signals or security risk. We do not guarantee that all prohibited Content or activity will be identified.
6.4 Security, authentication and fraud prevention
We may use personal data to:
- authenticate users and maintain sessions;
- detect suspicious login activity;
- protect accounts and infrastructure;
- prevent automated abuse, scraping, spam and malicious uploads;
- investigate vulnerabilities and security incidents;
- enforce rate limits and technical controls;
- maintain security logs;
- detect relationships between accounts, devices or network activity where reasonably necessary to prevent abuse; and
- protect our legal rights, property and systems.
6.5 Service operation, analysis and improvement
We may use personal data to:
- understand how the Services perform;
- diagnose crashes, errors and latency;
- test and improve features;
- evaluate forum activity and service reliability;
- maintain capacity and infrastructure;
- conduct internal audits and quality assurance;
- generate aggregated statistics;
- develop new functions; and
- carry out limited product experiments or phased releases.
Where reasonably practicable, we use aggregated or pseudonymised information for analysis and development.
6.6 Communications
We may use contact information to send:
- account verification or recovery messages;
- security alerts;
- moderation and enforcement notices;
- responses to reports, appeals and support enquiries;
- notices concerning changes to the Services, Terms of Use or Privacy Policy;
- administrative or legal notices; and
- notifications you have chosen to receive.
Service-related communications are not marketing communications and may be necessary for the operation or security of your account.
6.7 Legal and regulatory purposes
We may use personal data to:
- comply with laws, regulations, court orders and lawful requests;
- respond to regulators, law-enforcement agencies and public authorities;
- investigate or defend legal claims;
- exercise or protect legal rights;
- investigate suspected illegal activity;
- prevent serious harm;
- handle copyright, privacy and other rights complaints;
- obtain professional advice; and
- maintain records reasonably required for compliance, insurance, audit or dispute resolution.
6.8 Corporate transactions
We may process and disclose personal data in connection with an actual or proposed:
- investment;
- financing;
- restructuring;
- merger;
- acquisition;
- sale of assets or business;
- transfer of operations;
- insolvency process; or
- due-diligence exercise.
Where appropriate, recipients will be subject to confidentiality and data-protection obligations.
7. Legal Grounds Where Applicable
Where applicable data-protection law requires us to identify a legal ground for processing, we may rely on one or more of the following:
- performance of a contract, including providing the Services under our Terms of Use;
- legitimate interests, including operating, securing, moderating, improving and protecting the Services, provided those interests are not overridden by applicable individual rights;
- consent, where we specifically request consent;
- compliance with a legal obligation;
- establishment, exercise or defence of legal claims;
- protection of vital interests or prevention of serious harm; and
- other grounds permitted by applicable law.
Where we rely on consent, you may withdraw that consent through the relevant settings or by contacting us. Withdrawal does not affect processing that occurred lawfully before withdrawal and may make certain optional features unavailable.
8. Public Content and Forum Visibility
The Services include public discussion areas.
Information that may be publicly visible includes:
- your username or display name;
- profile information designated as public;
- posts, comments, replies and images;
- posting and editing timestamps;
- public reactions or interaction history;
- account status indicators made visible through the Services; and
- other information you choose to publish.
Public Content may be:
- viewed by registered and unregistered users;
- indexed by search engines;
- copied, quoted, linked to or screenshotted;
- shared outside the Services;
- cached by search engines, browsers or content-delivery services; and
- retained by other users after you delete the original.
We cannot control copies independently created or retained by other persons.
You should not publish information that you expect to remain confidential.
9. Cookies, Local Storage and Similar Technologies
Our website and applications may use cookies, local storage, software development kits, session tokens, cache files and similar technologies.
These technologies may be used to:
- keep you signed in;
- authenticate requests;
- maintain security;
- remember settings and language preferences;
- prevent fraud and automated abuse;
- maintain session state;
- measure performance;
- diagnose errors; and
- understand general usage of the Services.
Some technologies are essential for the Services to function. Disabling them may prevent login, account security or other core functions from working correctly.
Where non-essential analytics or similar technologies require consent under applicable law, we will provide an appropriate choice mechanism before using them.
Unless we expressly notify you otherwise, we do not use third-party advertising cookies or software development kits to sell personal data or conduct cross-service behavioural advertising.
10. Mobile Application Permissions
Depending on the functions you use, the mobile application may request permission to access:
- your photo library or selected media, so that you can upload an image;
- your camera, if a direct camera-upload feature is made available;
- notifications, so that we can send alerts you choose to receive; and
- device storage or file-selection functions required to select an attachment.
Permissions are controlled through your device settings. Refusing or withdrawing a permission may prevent the corresponding feature from working.
We only intend to access information within the scope of the permission and feature selected by you.
11. Disclosure of Personal Data
We may disclose personal data to the following classes of recipients for the purposes described in this Privacy Policy.
11.1 Service providers and processors
We may disclose personal data to providers that assist with:
- authentication and account management;
- database and backend infrastructure;
- cloud hosting;
- object and image storage;
- content delivery, caching and proxy services;
- cybersecurity and abuse prevention;
- email delivery;
- push notifications;
- crash reporting and error monitoring;
- analytics and performance measurement;
- customer support;
- legal, accounting, insurance or professional services; and
- backup, continuity and disaster recovery.
Service providers may process personal data only for authorised purposes and subject to contractual, technical or other safeguards that we consider appropriate.
11.2 Current infrastructure providers
Our infrastructure may include:
- Supabase, for authentication, database, backend and related infrastructure services;
- Cloudflare, for hosting, network security, content delivery, image delivery, proxying and object-storage services;
- Apple, in connection with distribution through the Apple App Store, Apple platform services and any Apple sign-in function that we enable;
- Google, in connection with distribution through Google Play, Google platform services and any Google sign-in function that we enable
This list may change as our infrastructure changes. A replacement provider may perform substantially similar functions. We will update this Privacy Policy where a change materially affects how personal data is handled.
11.3 Other users and the public
We disclose public profile information and public User Content to other users and members of the public in accordance with the design of the Services.
We do not ordinarily disclose private reports, private account information or internal moderation records to other users.
11.4 Application marketplaces and platform operators
We may disclose or receive information in connection with:
- application distribution;
- sign-in services;
- security and fraud prevention;
- platform analytics;
- crash and diagnostic reporting;
- account deletion or token revocation;
- policy compliance; and
- review or investigation by a platform operator.
Apple, Google and other platform operators may process information independently under their own privacy policies.
11.5 Professional advisers and business counterparties
We may disclose personal data to lawyers, accountants, auditors, insurers, consultants, investors, lenders, purchasers or other professional or commercial counterparties where reasonably necessary and subject to appropriate confidentiality arrangements.
11.6 Authorities and legal recipients
We may disclose personal data where we reasonably believe disclosure is necessary to:
- comply with applicable law or a legally binding request;
- respond to a court, regulator, law-enforcement agency or public authority;
- investigate suspected crime, fraud, child exploitation, serious threats or security incidents;
- protect the rights, safety or property of users, SipAI or another person;
- establish, exercise or defend legal claims;
- enforce our Terms of Use; or
- prevent serious harm.
Where legally permitted and reasonably practicable, we may assess the validity and scope of a request before disclosing information.
11.7 Corporate transactions
Personal data may be disclosed to parties involved in an actual or proposed corporate transaction described in Section 6.8.
If control of all or part of the Services changes, personal data may be transferred to the relevant successor, purchaser or operator, subject to applicable law.
12. No Sale of Personal Data and Direct Marketing
We do not sell or rent personal data to data brokers or unrelated third parties.
We do not presently use personal data for third-party targeted advertising.
We may send communications that are necessary to operate, secure or administer the Services.
We will not use personal data for direct marketing where consent or another legal requirement applies unless we have first:
- provided the required information;
- obtained any required consent or indication of no objection; and
- provided a free and reasonably accessible means to opt out.
If we introduce newsletters, promotional messages, advertising services or materially different marketing practices, we will provide an appropriate notice and update this Privacy Policy where required.
13. International Processing and Transfers
SipAI is operated from Hong Kong, but our service providers and infrastructure may process or store personal data in other jurisdictions.
These jurisdictions may include Hong Kong, Singapore, the United States and other locations in which our service providers, their affiliates or infrastructure operate.
As a result, personal data may be subject to laws that differ from those of your place of residence.
Where required, we take reasonable steps designed to ensure that international processing or transfers are subject to appropriate safeguards. These may include:
- contractual data-protection obligations;
- access and confidentiality controls;
- data-processing agreements;
- security assessments;
- transfer mechanisms required by applicable law; and
- limiting data access to what is reasonably necessary.
Use of the Services from outside Hong Kong constitutes an instruction to process information as necessary to provide the Services across the relevant infrastructure, subject to applicable law.
14. Moderation, Safety and Automated Rules
We may process account information, User Content, reports, technical information and activity records for moderation and safety purposes.
We may use automated rules to:
- identify unusual account or network activity;
- enforce technical limits;
- detect spam or repeated abuse;
- identify possible ban evasion;
- reject prohibited file types;
- temporarily hide Content after a specified reporting or safety threshold;
- prioritise Content or reports for human review; and
- protect the security and availability of the Services.
Automated rules may produce errors. We may permit an appeal or manual review where appropriate, but urgent or temporary action may occur before human review.
We are not required to disclose confidential safety thresholds, anti-abuse methods, security signals or internal risk assessments where disclosure could undermine the integrity or security of the Services.
15. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including operation of the Services, safety, security, dispute resolution and legal compliance.
Our ordinary retention approach is as follows:
15.1 Active accounts
Account information is generally retained while the account remains active and for a limited period afterwards to complete deletion, resolve account issues and maintain security.
15.2 Account-deletion requests
Following a valid account-deletion request, personal account information in active production systems will ordinarily be deleted or anonymised within thirty days, unless a longer period is reasonably necessary or legally permitted.
15.3 Public User Content
Public posts, comments and images may be retained until:
- you delete them;
- we remove them;
- your account is deleted; or
- they are no longer required for the relevant purpose.
When an account is deleted, public User Content may be:
- deleted;
- anonymised;
- retained after removal or irreversible separation of direct account identifiers; or
- retained where legally required or reasonably necessary to protect safety, investigate abuse or preserve legal evidence.
Where public Content is retained after account deletion, we will not ordinarily continue to display the deleted account’s email address or direct account identifier.
15.4 Security and technical logs
Security, authentication, server and technical logs may ordinarily be retained for up to twelve months.
Relevant logs may be retained for longer where reasonably necessary to investigate security incidents, fraud, abuse, ban evasion, legal complaints or technical failures.
15.5 Moderation and report records
Reports, moderation decisions, enforcement records and related evidence may ordinarily be retained for up to twenty-four months after final resolution.
Serious safety, child-protection, fraud, repeated-abuse or legal matters may be retained for longer where reasonably necessary.
We may retain limited identifiers, security markers or enforcement records after account deletion where reasonably necessary to prevent serious abuse or banned users from improperly returning.
15.6 Support and legal communications
Support correspondence may ordinarily be retained for up to twenty-four months after the matter is closed.
Legal notices, rights complaints, dispute records and information relevant to actual or anticipated legal proceedings may be retained for the applicable limitation period and for as long as a related proceeding, investigation or enforcement matter remains active.
15.7 Backups and caches
Residual copies may remain in encrypted or access-controlled backups, caches and disaster-recovery systems for up to ninety days after deletion from active systems.
Backup copies are not ordinarily restored except for service continuity, security or disaster recovery. If restored, deletion processes may be reapplied.
15.8 Anonymised and aggregated information
We may retain irreversibly anonymised or aggregated information indefinitely because it no longer identifies an individual.
Actual retention periods may vary depending on the nature and sensitivity of the information, legal requirements, safety risks, technical limitations and whether information is required for an existing dispute or investigation.
16. Account and Data Deletion
You may request deletion of your SipAI account:
- through the account-deletion function in the application or account settings;
- by contacting privacy@sipai.ai where another deletion method is unavailable.
We may take reasonable steps to verify that a deletion request is made by the account holder or an authorised person.
Account deactivation, suspension or logout is not the same as account deletion.
When a valid deletion request is completed:
- access to the account will end;
- account credentials and directly identifying profile information will be deleted or anonymised, subject to permitted retention;
- linked personal data will be deleted, anonymised or irreversibly separated from the account where appropriate;
- public Content will be handled as described in Section 15.3;
- notification tokens and active sessions will be revoked or deleted where applicable; and
- residual information may remain temporarily in backups or be retained for lawful safety, security, fraud-prevention, legal or dispute-resolution purposes.
Deletion may not remove:
- copies independently made by other users;
- quotations or screenshots posted by others;
- information already lawfully disclosed to an authority;
- information that has been irreversibly anonymised; or
- information we are required or permitted to retain under applicable law.
You should delete any individual posts or comments that you wish to remove before deleting your account, where that function is available.
17. Your Privacy Rights
Depending on applicable law, you may have rights concerning personal data held about you.
These rights may include the right to:
- request confirmation of whether we hold personal data about you;
- request access to a copy of personal data;
- request correction of inaccurate, incomplete, misleading or outdated personal data;
- update certain account information directly through the Services;
- request deletion of an account and associated personal data;
- withdraw consent where processing is based on consent;
- object to or request restriction of certain processing;
- request portability of certain information, where applicable;
- opt out of direct marketing;
- lodge a complaint with an applicable privacy or data-protection authority; and
- obtain information about our personal-data policies and practices.
Rights are subject to applicable legal conditions, exemptions and limitations.
To protect users, we may require information sufficient to verify:
- your identity;
- your connection to the relevant account or data;
- your authority to act for another person; and
- the scope of your request.
We may refuse or limit a request where permitted by law, including where a request is fraudulent, abusive, repetitive, technically disproportionate, affects another person’s rights, compromises safety or security, or concerns information that we are required or permitted to retain.
Where permitted by law, we may charge a reasonable fee for processing a data-access request. We will not charge a fee merely for opting out of direct marketing or requesting account deletion.
Requests concerning access to or correction of personal data may be sent to:
- Privacy Contact: SipAI Privacy Officer
- Email: privacy@sipai.ai
18. Data Accuracy
We take reasonably practicable steps to keep personal data accurate having regard to the purposes for which it is used.
You are responsible for ensuring that account information and Content you provide are accurate and up to date.
You may update certain information through your account settings. If information cannot be updated through the Services, you may contact us.
We may retain a record of previous information where reasonably necessary for security, moderation, fraud prevention, legal compliance or dispute resolution.
19. Data Security
We take reasonably practicable technical, organisational and administrative measures designed to protect personal data against unauthorised or accidental access, processing, erasure, loss, use, alteration, disclosure or transfer.
Depending on the nature of the information and Services, measures may include:
- encrypted transmission;
- authentication and session controls;
- access restrictions and role-based permissions;
- database security policies;
- logging and monitoring;
- rate limiting and abuse controls;
- secure cloud infrastructure;
- backup and recovery procedures;
- software and dependency updates;
- restrictions on administrative access;
- staff or contractor confidentiality obligations; and
- incident-response procedures.
No website, mobile application, transmission method or storage system is completely secure. We cannot guarantee absolute security or that unauthorised persons will never defeat security measures.
You are responsible for using a strong and unique password, protecting your login credentials, keeping your device secure and notifying us promptly of suspected unauthorised access.
20. Data Incidents
If we become aware of a personal-data incident, we may:
- investigate and contain the incident;
- take steps to reduce possible harm;
- preserve evidence;
- require password resets or revoke sessions;
- notify affected users;
- notify regulators, platform operators or other authorities; and
- take other steps we consider appropriate.
The timing and content of any notification will depend on the nature of the incident, available information, applicable law, security considerations and instructions from relevant authorities.
21. Children and Young Persons
The Services are intended only for users aged eighteen or above.
We do not knowingly permit persons under eighteen to create or maintain accounts.
If we reasonably believe that an account belongs to a person under eighteen, we may:
- restrict or suspend the account;
- request age-related information;
- delete the account and associated personal data; and
- take appropriate safety or reporting action.
If you believe that a person under eighteen has provided personal data through the Services, please contact privacy@sipai.ai.
This Section does not limit our ability to preserve and report information concerning suspected child exploitation, abuse or serious safety risks.
22. Third-Party Websites and Services
The Services may contain links to third-party websites, applications, products or services.
We do not control the privacy, security or data-handling practices of independent third parties.
Before providing personal data to a third party, you should review its privacy policy and terms.
A link, reference or technical integration does not mean that SipAI endorses or accepts responsibility for the third party’s privacy practices.
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to the Services;
- changes to our technology or service providers;
- new legal or regulatory requirements;
- changes to our data-handling practices;
- safety or security requirements; or
- clarification of existing provisions.
The updated version will be published through the Services and will state its last-updated date.
Where a change materially affects how personal data is collected, used or disclosed, we may provide additional notice and request consent where required by law.
Your continued use of the Services after an updated Privacy Policy takes effect constitutes acknowledgement of the updated policy, but does not replace consent where consent is legally required.
24. Relationship with the Terms of Use
This Privacy Policy should be read together with the SipAI Terms of Use.
The Terms of Use govern matters including User Content, acceptable conduct, moderation, suspension, intellectual property, disclaimers and liability.
If there is an inconsistency concerning the collection, use, disclosure, retention or protection of personal data, this Privacy Policy will apply to that privacy matter, subject to applicable law.
25. Language
This Privacy Policy may be made available in English and Chinese.
The Chinese version is provided for convenience. In the event of inconsistency, ambiguity or conflict between the English and Chinese versions, the English version prevails to the fullest extent permitted by applicable law.
26. Contact Us
For privacy questions, requests, complaints or concerns, please contact:
- Trading name: SipAI
- Privacy contact: SipAI Privacy Officer
- Email: privacy@sipai.ai
- General support: support@sipai.ai
- Safety and moderation reports: safety@sipai.ai
- Website: sipai.ai