JanGentle Privacy Policy
Version 1.0. Last updated: 29 July 2026.
This Privacy Policy explains what personal data JanGentle collects, why we collect it, who we pass it to, how long we keep it, and how you can access and correct it. It serves as our Personal Information Collection Statement and Privacy Policy Statement under the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong (the "Ordinance").
The Service is operated by JanGentle, a business operating from the Hong Kong Special Administrative Region. In this Policy, "we", "us" and "our" mean JanGentle, and "you" and "your" mean the person using jangentle.com or any application we make available (the "Service").
This Policy forms part of our Terms of Service.
1. Our commitment
We collect the minimum personal data we need to run the Service, we tell you plainly what happens to it, and we delete it when we no longer need it. We comply with the requirements of the Ordinance in how we collect, hold, process and use personal data.
2. What we collect
We collect the following:
2.1 Account data
- Your email address. This is required to create an account, because we sign you in with an email magic link.
- If you choose to sign in with Google, the basic profile information Google returns to us: your name, email address, Google account identifier and profile picture URL. We do not receive your Google password.
- The version of our Terms of Service you accepted and the date and time you accepted it.
We do not store passwords, because the Service does not use them.
2.2 Content data
- Text prompts and instructions you enter.
- Images you upload.
- Images the Service generates for you.
Prompts and uploaded images may contain personal data if you choose to put personal data in them. Please only upload images of a person where you are entitled to do so.
2.3 Transaction data
- A record of each Credit purchase: amount, currency, package, date and time, and the payment reference returned by our payment processor.
- Your Credit balance and the ledger of Credits added and deducted.
We do not receive or store your full payment card number, expiry date or security code. Card details are entered on and handled by Stripe, our payment processor.
2.4 Usage and technical data
- Records of the operations you perform on the Service, such as generation, editing and upscaling requests, their timestamps and their outcomes.
- Technical log data generated when you use the Service, such as IP address, browser type and device information, and error records.
- A session cookie that keeps you signed in. It is strictly necessary for the Service to work. If you block it, you will not be able to stay signed in.
We do not use advertising cookies and we do not run third-party advertising or behavioural tracking on the Service.
2.5 Support data
- Whatever you send us through the contact page on our website or by post, including your contact details and the content of your message and any attachments.
This is collected only when you choose to contact us.
3. Whether you have to give us this data
Providing your email address is obligatory. Without it we cannot create your account, sign you in, or deliver the Service, and you will not be able to use the Service.
Providing your Google profile data is voluntary. It is collected only if you choose Google sign-in instead of the email magic link.
Providing prompts and uploaded images is voluntary, but the Service cannot generate an image without a prompt.
Providing support data is voluntary. We only receive it if you choose to contact us.
Transaction data is obligatory if you choose to buy Credits, because we cannot process or record a purchase without it. You are free to use the Service with free Credits only, and never provide it.
4. What we use it for
We use your personal data for these purposes and no others:
(a) creating, authenticating and administering your account, including sending sign-in links;
(b) generating, delivering and storing images in response to your requests;
(c) operating the Credit system: recording purchases, deducting and returning Credits, and maintaining your balance;
(d) processing payments, handling refunds, and dealing with chargebacks and payment disputes;
(e) providing customer support and responding to your enquiries;
(f) keeping the Service secure and reliable: detecting and preventing abuse, fraud and breaches of our Terms of Service, and diagnosing faults;
(g) understanding aggregate usage of the Service so that we can maintain and improve it; and
(h) complying with our legal, accounting and tax obligations, and responding to lawful requests from authorities or courts.
We do not use your prompts, uploaded images or generated images to train AI models. We do not sell your personal data.
5. Who we pass it to
To run the Service we transfer personal data to the following classes of transferee. All of them may be located outside Hong Kong.
| Class of transferee | What is transferred | Why |
|---|---|---|
| Third-party AI model providers | Your prompts and uploaded images | To generate images in response to your requests |
| Cloud infrastructure, hosting and storage providers | Account data, content data, transaction data, usage and technical data, support data | To host the Service, run the database, and store your images |
| Payment processor (Stripe) | Your email address and transaction data | To take payment, issue refunds and handle payment disputes |
| Email delivery provider | Your email address, the content of service emails, and the content of replies to your enquiries | To deliver sign-in links and service notices, and to reply to your enquiries |
| Professional advisers, and law enforcement, regulators or courts | Only what is necessary and only where required | To obtain legal or accounting advice, or to comply with a legal obligation or a lawful request |
We may also transfer personal data to a person who acquires our business, in which case this Policy continues to apply to the data transferred.
We do not disclose your personal data to any other party for that party's own purposes, and we do not provide your personal data to anyone for direct marketing.
Third-party AI model providers and cloud infrastructure providers process content under their own terms, which we do not control. We choose providers on the basis of their published terms and security practices, but we cannot guarantee the practices of any provider.
6. Direct marketing
We do not currently use your personal data for direct marketing. If we ever want to, we will tell you first, tell you what we intend to market, and obtain your consent or your indication of no objection before doing so, as the Ordinance requires. You will always be able to opt out at no cost.
7. How long we keep it
| Data | Retention |
|---|---|
| Uploaded images and generated images | 30 days from creation, then deleted automatically |
| Prompts and generation records | Kept with your account while it is open, then deleted when the account is deleted, subject to the rows below |
| Account data | While your account is open, then deleted within 30 days of account closure |
| Transaction and accounting records, and the Credit ledger | For as long as we are required to retain them under Hong Kong tax and business record-keeping law, which is currently at least seven years |
| Support correspondence | While we deal with your enquiry and for up to 12 months afterwards, then deleted |
| Technical logs | Up to 12 months, then deleted or aggregated so that you can no longer be identified |
| Records relating to a suspected breach of our Terms, a legal claim, or a report to authorities | For as long as necessary to deal with the matter and to comply with the law |
When a retention period ends, we delete the data or make it permanently anonymous.
You can close your account at any time from your account settings, or ask us to close it through the contact page on our website. Closing your account deletes your account data and content data from our live systems within 30 days, except for records we are required to keep. Backups are overwritten on a rolling cycle and any residual copies are deleted within 90 days.
8. How we protect it
- Traffic between your device and the Service is encrypted in transit.
- Stored images and database records are held with reputable cloud providers and are encrypted at rest.
- Access to production data is limited to the operator of the Service on a need-to-know basis and is protected by multi-factor authentication.
- We do not store payment card details at all, so they cannot be exposed by us.
- Sign-in uses one-time email links rather than passwords, which removes the risk of a stored password being leaked or reused.
No system is perfectly secure. If a data breach occurs that is likely to cause you real harm, we will notify you and, where appropriate, the Privacy Commissioner for Personal Data.
9. Children
The Service is for adults only. You must be at least 18 years old, and at least the age of majority in the place where you live, to use it. We do not intend to collect personal data from anyone below that age, and we do not knowingly do so. If you believe a person below that age has provided us with personal data, tell us through the contact page on our website and we will delete it and close the account.
10. Your rights of access and correction
Under the Ordinance you have the right to:
(a) ask whether we hold personal data about you;
(b) request a copy of the personal data we hold about you; and
(c) request that we correct any of your personal data that is inaccurate.
To make a request, use the contact page on our website, or write to the Data Protection Officer at the postal address in clause 12. Please tell us clearly what data you are asking for or what you say is wrong, and give us enough information to verify your identity and to locate the data. We will respond within 40 days, as the Ordinance requires.
We do not currently charge a fee for handling a data access request. If we ever charge one, it will not be excessive, and we will tell you the amount before we proceed.
If you are not satisfied with how we handle your request, you may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.
11. Changes to this Policy
We may update this Policy. If a change is material, we will notify you by email or by a notice in the Service before it takes effect. The version number and date at the top of this Policy always show the current version.
12. Contact
Requests, questions and complaints about personal data should go to:
Data Protection Officer, JanGentle
Contact page: jangentle.com/contact
Postal address: Unit H23, Room A, 8/F Excelsior Building, 68-76 Sha Tsui Road, Tsuen Wan, Hong Kong
For anything else about the Service, use the same contact page.