HobbyLink Privacy Policy
Welcome to HobbyLink (hereinafter referred to as the “Platform”), a social service. This Privacy Policy explains the rules governing how the Platform collects, uses, stores and shares your personal information, as well as your statutory privacy rights. You must tick the consent box during registration before an account can be created. By clicking register and checking the consent box, you confirm that you have fully read and accept all terms of this Privacy Policy. If you do not agree with this Policy, please discontinue your use of the Platform.
This Privacy Policy is published as an independent HTTPS document. Its link is available on our App Store listing page and inside the App so that you may access it at any time.
1. Collection and Use of Information
1.1 Mandatory Collected Information
Sensitive Personal Information
- North American (NANP format) mobile phone number: collected exclusively for account registration, login and account ownership verification. It will never be used for promotional advertising or unauthorized external sharing. By actively submitting your phone number during registration, you are deemed to have given explicit consent to such collection. This App currently only supports registration with NANP North American phone numbers; registrations using phone numbers from other countries or regions are not available at this time. Based on the Platform’s North American localized operational plan, should the eligible registration regions be expanded in the future, in addition to updating this Privacy Policy, the relevant content on the App Store product page will be updated simultaneously.
- Sensitive login device information (device model, OS version, IP address, login time and location, unique device identifiers): automatically collected by the system when you log in. This information is categorized as sensitive personal data under applicable local laws and is only used for platform security audits. It will not be used for cross-device behavioral advertising tracking or user profiling.
- Chat behavioral data: your one-on-one chat content (text) will never be used for commercial advertising, AI training, machine learning or any automated model training, and is strictly prohibited from being used for commercial advertising, AI or model training purposes.
1.2 System Permission Rules
- Camera: used solely for capturing and uploading your profile avatar. Upon the first use, a native system permission pop-up will appear, allowing you to independently grant or deny the permission. The camera is only temporarily invoked when you actively take a profile photo and will be immediately deactivated once the action is complete. Disabling camera permissions in your device’s system settings will not interfere with the normal operation of basic text chat functions.
- Photo Album: used solely for selecting a profile avatar image from your album. Upon the first image selection, a native system permission pop-up will appear, allowing you to independently grant or deny the permission. The photo album is only temporarily accessed when you actively select avatar materials and will cease to be accessed once the operation is complete. Disabling photo album permissions in your device’s system settings will not interfere with the normal operation of basic text chat functions.
- Local Storage: only saves message input drafts and cached avatar thumbnails. We never store passwords, bank card details or other sensitive privacy data locally. All locally cached files remain solely on your device, and the App will never silently or automatically upload locally cached content to our cloud servers. You may clear the App’s local storage data at any time through your device’s system settings.
- Network Permission: essential for message synchronization and content loading and cannot be disabled.
1.3 Scope of Information Use
Collected information is only used for the following purposes: delivering services including chat and message synchronization; reviewing content for violations; troubleshooting and product optimization based on fully anonymized data; fulfilling statutory obligations and cooperating with lawful official investigations; and processing user feedback and complaints. All data will never be used for cross-context behavioral advertising tracking, or sold, rented or otherwise disclosed without authorization.
2. Data Storage and Security
2.1 Retention Period and Storage Description
- We retain your account, device and behavioral data while your account remains active.
- In accordance with the statutory requirements regarding finance, taxation and anti-money-laundering in your jurisdiction, compliance audit data shall be retained for the period prescribed by local laws and regulations, not exceeding a maximum of 7 years.
- Data not subject to mandatory legal retention in your jurisdiction will be deleted within 30 days following your account cancellation. Data subject to statutory retention is exempt from deletion upon account closure and will be permanently deleted or irreversibly anonymized upon expiry of the statutory retention period.
- Following your account cancellation, your personal information will be deleted or irreversibly anonymized within 30 days. Only audit logs required by laws and regulations will be retained for the statutory period.
- Once an account is cancelled, it cannot be restored and the associated data cannot be recovered.
2.2 Private Chat Message Storage
Our servers do not store private chat messages. Private chat messages are transmitted with full-link encryption and stored solely on your local device. A uniform storage rule applies to all users:
- Local Device: The App stores private chat messages in an encrypted local database, retaining only content from the most recent 48 hours. The client automatically clears expired cache beyond this retention window. Local cached data will be permanently lost and is unrecoverable by us in the following scenarios: you manually delete messages or conversations; you clear the App cache; you uninstall the application; or your device automatically purges files due to insufficient storage space.
2.3 Security Safeguards
- All data transmission is protected by SSL/TLS1.3 full-link encryption.
- Sensitive information such as phone numbers and device identifiers is stored with AES-256 encryption, with strict internal access control.
- We maintain 24/7 security monitoring, regular vulnerability testing, intrusion prevention and operational auditing.
- In the event of a data breach as defined by applicable regulations, we will promptly notify affected users and regulatory authorities in accordance with the law and implement corresponding remedial measures.
3. General Rules for Third-Party Data Sharing
The Platform solemnly declares: this Platform shall never sell or rent any user personal information. User data may only be shared on a minimum-necessary basis in compliance with the following scenarios. All cooperating partners maintain data security capabilities equivalent to those of the Platform, and all cooperating third parties have signed formal data security cooperation agreements stipulating equivalent data protection responsibilities and prohibiting unauthorized secondary data circulation.
- Judicial and Administrative Authorities: We will only provide the corresponding information in accordance with the law and to the extent necessary upon receipt of a formal legal instrument issued by a competent judicial or administrative authority in your jurisdiction that complies with local laws. The Platform reserves the right to refuse to provide user data in response to legal instruments from jurisdictions other than your own in accordance with applicable local laws.
Except as set out above, we will not disclose personal information to any third party without your explicit consent (confirmed via an in-app pop-up or checkbox). All third-party data processing by the Platform adheres to the principle of data minimization, with no advertising tracking, no sale of user profiles and no unlawful data sharing.
4. Specific Compliance Statement for Third-Party SDKs
To deliver core functions of instant messaging and content security moderation, this North American edition of the App integrates overseas compliance-edition third-party SDKs. North American user data is preferentially processed and stored on compliant North American cloud nodes, unless otherwise mandated by law. Service providers likewise comply with the privacy laws of their corresponding jurisdictions to protect data security. All SDK data processing is solely for enabling core product features and is not used for advertising tracking, AI training, commercial sale or any other extraneous purpose.
4.1 Content Moderation
Service Provider: DEEPCLEER TECHNOLOGY PTE. LTD.
Official Privacy Link: https://www.deepcleer.com/legal/terms
Function and Purpose: Conducts compliance risk-control moderation of user chat content, intercepts pornographic, violent, spam and harassing content and other violations to ensure platform content safety.
Data Collection and Usage Rules:
Only content data actively published by users, de-identified device identifiers, IP addresses and session IDs are collected for moderation. All moderation data is preferentially verified and processed on compliant North American nodes, with strict restrictions on data transfer to mainland China. Such data is not used for advertising push, user profiling or AI training, is not sold or improperly shared externally, and is purged in accordance with North American compliance cycles following completion of moderation.
4.2 SMS Verification
The SMS verification code service is provided by METAVERSE CLOUD PTE. LTD. For the purposes of completing mobile phone registration, password recovery and similar functions, the mobile phone number you submit is transmitted in encrypted form to the service provider’s servers and is used solely for SMS dispatch and identity verification. It will never be used for advertising push or user profiling.
4.3 Exclusive North American Market Compliance Commitment
All service providers used by this App have been selected in their international overseas editions, which have been adapted to North American local privacy regulations. The Platform relies on commercial cooperation agreements to bind service providers in respect of their data processing and cross-border data transfer compliance obligations.
No cross-app advertising tracking is enabled for any third-party data processing, fully complying with the privacy policies of the Apple and Google platforms and applicable North American local laws and regulations. There is no unauthorized collection or sharing of any user data.
You may proactively disable the corresponding features by turning off camera, photo album or storage permissions, without affecting the use of the App’s basic text chat functions, thereby fully safeguarding your privacy choices as a North American user.
5. Minor Protection
This Platform is only open for registration and use by users who are 18 years of age or older. Users under the age of 18 cannot complete account registration. During the registration process, a pop-up will mandatorily require you to enter your date of birth, and the system will automatically verify your age. Any applicant identified as being under 18 will be directly blocked from registration, and no personal information relating to minors will be collected whatsoever.
6. Your Statutory Privacy Rights
- Right to Access: You may independently view all of your personal data, including your phone number, device records and usage history, in the App’s personal center.
- Right to Rectification: You may submit a request for correction of your personal information via the privacy email privacy@hobbylink.app; the Platform will complete the review and processing within 3 business days.
- Right to Erasure: You may independently initiate an account cancellation request within the App, and the Platform will complete the deletion or irreversible anonymization of all your personal information within 30 days. You may independently delete individual chat messages. California residents may at any time request the deletion of all sensitive personal information retained by the Platform.
- Right to Withdraw Consent: You may turn off camera, photo album and storage permissions at any time in your device’s system settings, and the App will no longer collect data corresponding to those permissions once they are turned off. Withdrawal of consent does not affect the lawfulness of data processing that was previously carried out in compliance with this Policy. Historical data will continue to be retained in accordance with the retention rules of this Policy, and you may exercise the right to complete deletion through account cancellation.
- Special Reaffirmation of the Non-Sale Commitment: The Platform shall never sell or rent any user personal information, now or in the future, nor will it engage in any business involving the sale of personal information. If, in the future, we are required by local laws and regulations to carry out compliant sharing of personal information (whether paid, unpaid or for advertising attribution purposes), we will provide 30 days’ advance notice, and you may submit an opt-out request via the privacy email.
- Global Privacy Opt-Out Mechanism: The Platform automatically recognizes the privacy opt-out preference signals transmitted by your device or system. Upon receiving such a signal, the Platform will by default cease to participate in the external sharing of personal information.
- Right to Data Portability: You may request your personal account information in a structured, machine-readable format to support data migration across service providers.
- Right to Complain: If you have any objections regarding data processing, you may provide feedback via the official customer support email. We will respond and resolve the matter within 7 business days.
Account Cancellation Rules
- You may submit an account cancellation request within the App at any time. The cancellation process is handled automatically by the system without manual review or approval.
- Upon submission of your cancellation request, your account will be deactivated immediately. All your personal information will be permanently deleted or irreversibly anonymized within 30 calendar days.
- Data that is required to be retained under applicable statutory obligations (such as financial audit logs) will be retained for the legally mandated period and is exempt from deletion upon account closure. Such data will be permanently deleted or irreversibly anonymized upon expiry of the statutory retention period.
- Private chat messages stored locally on your device are under your sole control and cannot be remotely cleared by us. You may manually delete such data before or after account cancellation through your device settings.
- Once an account is cancelled, it cannot be restored under any circumstances. All associated account data, in-app assets and membership privileges will be permanently lost and are irrecoverable.
- If you wish to use the Platform again after cancellation, you must register a new account, which will not be associated with or able to recover any data from your previous cancelled account.
7. Policy Update Rules
The Platform may revise this Privacy Policy in accordance with updates to laws and regulations, industry standards and reasonable business adjustments. Material amendments that affect the scope of personal information collection or your core privacy rights will be notified via an in-app pop-up notice and a public announcement in the personal center for a minimum of 30 days, and the privacy policy link displayed on the Apple App Store product page will be updated simultaneously. Non-material amendments will take effect upon publication, and your continued use of the Platform will be deemed as acceptance of the new version. If you do not agree with the updated terms, you may cancel your account and terminate use. Historical versions of the Privacy Policy are archived on the privacy page within the App’s personal center, and you may review and compare them at any time.
8. Disclaimer
- Where the Platform has fulfilled its reasonable and adequate security protection obligations, it shall not be liable for data losses caused by force majeure events or failures of compliant third-party service providers, but will make every effort to assist users in mitigating losses and resolving issues.
- Where a data breach is caused by the Platform’s own fault or its failure to fulfil its supervisory obligations under third-party security agreements, the Platform shall not invoke this disclaimer and shall bear corresponding legal liability in accordance with the law.
- You shall bear sole responsibility for any privacy leakage risks arising from your voluntary disclosure of personal privacy information to other Platform users. The data processing activities of third-party service providers are governed by their own privacy policies. The Platform has completed compliance qualification screening and has contractually bound them to data protection obligations, and shall not be legally liable for intentional violations committed by third parties.
9. Contact Information
Customer Support and Privacy Email: privacy@hobbylink.app
For all privacy-related requests (data access, data deletion, complaints), the Platform undertakes to respond and resolve the matter within 7 business days.
HobbyLink Operation Team