Back to home

Privacy Policy

How Hailuo03AI handles accounts, prompts, uploads, outputs, payments, analytics, and compliance evidence.

Last updated: 2026-08-01

Scope and Controller

This policy describes how Hailuo03AI (mini-max-h3.com) handles personal data. Questions and privacy requests may be sent to [email protected].

Data We Process

  • Account data: name, email, authentication provider, verification state, profile image, security and session records.
  • Generation data: prompts, uploaded first-frame images, parameters, task status, output URLs, credit usage, moderation decisions, input hashes, and provider error details.
  • Payment data: order, subscription, product, amount, currency, status, and payment-provider identifiers. Card details are handled by the payment processor; we do not store full card numbers.
  • Support data: emails, tickets, messages, attachments, and the information you provide to investigate a request.
  • Technical and abuse data: IP address, browser/device information, timestamps, rate-limit signals, and security events.
  • Consent and analytics data: cookie choices and, only after analytics consent, page and conversion events from configured analytics providers.

Why We Use Data

We process data to perform our contract with you, operate H3 generation, manage credits and subscriptions, provide support, secure the service, prevent prohibited use, preserve payment and compliance evidence, meet legal obligations, and improve the product with consent where required.

We do not sell personal data. We do not use your registration email as marketing consent.

Providers and International Processing

Data may be processed by hosting, database, object-storage, authentication, email, analytics, payment, content-moderation, and AI model providers. A first-frame image and prompt that pass pre-screening are transmitted to the upstream MiniMax H3 service to perform generation. Providers process data under their own terms and may operate in other countries.

Upload Privacy and Retention

Uploaded first-frame images are stored in private object storage and are not intended as a public gallery. Removing an image from the interface is a soft deletion. To document prohibited-use controls, payment disputes, and provider charges, private input evidence, hashes, moderation records, and related task data are normally retained for 365 days. An active chargeback, payment review, abuse investigation, or legal request may extend that period.

Account and transaction records are retained for as long as needed to provide the service and meet tax, fraud, payment, and legal obligations. Cookie preferences remain until changed or cleared. Support records are retained as needed to resolve and document the case.

Security

We use TLS in transit, access controls, private object storage, encrypted-at-rest storage where provided by our infrastructure, secret encryption, and limited operator access. No system is perfectly secure; do not upload content or sensitive data you do not need for generation.

Your Choices and Rights

Depending on your location, you may request access, correction, export, restriction, objection, or deletion. We may retain limited records when required for payment, fraud, security, dispute, or legal purposes. You may change functional and analytics choices through Cookie Settings and unsubscribe from non-essential email where offered.

Send a request from your account email to [email protected]. We may verify identity before acting.

Children

The service is not for children under 13. If you believe a child under 13 supplied personal data, contact us so we can investigate and take appropriate action.

Changes

We may update this policy as the service or law changes. The date above shows the current version. Material changes will be communicated where required.