hyperreal.← Back to app

Legal

Privacy Policy

Last updated: August 10, 2026

1. Controller and Scope

The controller of personal information processed through hyperreal. is ASKITMORE Inc.(the “Company”). This Policy applies to the hyperreal website, accounts, payments, support, and image and video generation.

2. Information We Process

  • Account: user ID, email, name, profile image, authentication provider, plan, credit balance, and account dates
  • Inputs and Outputs: prompts, negative prompts, uploaded reference images or videos, generated images or videos, selected presets, and generation settings
  • Generation history: model, status, credit cost, provider job identifier, result location, error, and timestamps
  • Payment: Stripe customer and transaction identifiers, product, amount, currency, payment and refund status, subscription status and dates, and checkout consent record; the Company does not receive full card numbers or security codes
  • Usage and device: feature and pricing interactions, access time, IP address, browser or device information, cookies, request and security logs, and diagnostics
  • Support: account and contact details, inquiry content, attachments, and our response

Do not upload government identifiers, financial credentials, health information, intimate content, images of minors, or another person’s personal information unless it is necessary, lawful, and you have the required permission. Uploaded media may contain biometric characteristics even though the Company does not use it to identify or authenticate a person.

3. Purposes and Legal Bases

  • Performing our contract: account access, generation, result history, credits, billing, cancellation, and support
  • Consent where required: social sign-in, immediate digital-service supply, and optional processing
  • Legitimate interests: Service security, abuse prevention, debugging, measurement, and product improvement that does not override your rights
  • Legal obligations: tax and transaction records, consumer requests, fraud prevention, disputes, and lawful government requests

We do not sell personal information or share it for cross-context behavioral advertising.

4. How AI Generation Data Is Handled

We send the prompt, generation settings, and reference media needed for a request to Google’s Gemini and Veo APIs. The generated response is returned to the Company and saved to your private Service history. The Company does not use Inputs or Outputs to train its own general-purpose AI models.

  • Image interactions are submitted without provider-side interaction-state storage.
  • Certain video interactions require provider-side storage to complete and retrieve the job. Google states that stored Interactions API records are retained for up to 55 days on paid tiers (or a shorter configured period) and 1 day on free tiers, after which they are deleted.
  • Google may separately retain limited prompts and responses for safety, abuse prevention, reliability, and legal compliance under its applicable terms. For paid API services, Google states that it does not use prompts or responses to improve its products.

5. Retention and Deletion

  • Temporary reference uploads: deleted from our upload storage after the generation request finishes or fails; provider copies follow Section 4
  • Generation history, prompts, and results: kept until you delete the generation or close the account, unless needed for security, a dispute, or law
  • Account and credit records: kept while the account is active and then deleted or de-identified, subject to the statutory records below
  • Contract, withdrawal, payment, and supply records: 5 years where Korean electronic-commerce law applies
  • Consumer complaint and dispute records: 3 years where Korean electronic-commerce law applies
  • Access logs: 3 months where the Korean Communications Secrets Protection Act applies, or a shorter operational period otherwise
  • Support records: up to 3 years after resolution, or longer if reasonably necessary for an active dispute

We delete electronic records using methods designed to prevent recovery and securely dispose of physical records. Residual encrypted backups are isolated and removed on the provider’s backup cycle. Information required by law is separated from ordinary use and processed only for the required purpose.

6. Processors, Recipients, and International Transfers

The following providers receive data by encrypted network transmission when you sign in, use the Service, make a payment, or request support. Transfers are necessary to perform the Service contract; if you do not want the transfer, you may not be able to use the relevant feature and may request account closure.

  • Supabase, Inc. (configured cloud region and United States): authentication, database, and private file storage; account, generation, result, and billing records; retained for the Service relationship or until Company deletion, subject to backups and law
  • Google LLC (United States and Google processing locations): Google sign-in and Gemini/Veo AI generation; account sign-in data, prompts, reference media, settings, and Outputs; retained as described in Section 4 and Google’s applicable legal terms
  • Stripe, Inc. and applicable Stripe affiliate (United States and global payment locations): checkout, card processing, subscriptions, refunds, fraud prevention, and billing portal; account and transaction data; Stripe generally retains relevant transaction data for the period required by payment and financial laws, which may be five years or longer after the relationship or last transaction
  • Vercel Inc. (primarily United States and its global infrastructure): web hosting, delivery, request processing, and security logs; request, device, network, and limited Service content; retained for the minimum contractual, security, and legal period
  • Amazon Web Services, Inc. (configured storage region): private reference media and generated results; retained until deletion or the applicable operational retention period

Stripe may act as an independent controller for payment compliance and fraud prevention. We may also disclose information when you direct us, in a corporate transaction subject to appropriate protections, or when reasonably necessary to comply with law or protect rights and safety.

7. Your Rights

Depending on your location, you may request access, a copy, correction, deletion, restriction or suspension, portability, withdrawal of consent, or an explanation of processing, and may object to certain processing. You may delete individual generation records in History. For account-level requests, email help@askitmore.com from the account email. We will verify the request proportionately and respond within the period required by law. You may appoint a lawful representative and may complain to your local privacy regulator. Korean users may also contact the Personal Information Infringement Report Center (118) or the Personal Information Dispute Mediation Committee (1833-6972).

8. Cookies and Analytics

We use essential cookies to maintain authentication and security. We also record limited first-party pricing and feature events to understand Service use. We do not currently use those events for third-party targeted advertising. Browser settings can block cookies, but authentication and other core features may stop working.

9. Security and Incidents

We use access controls, private storage, signed file URLs, encryption in transit, restricted administrative keys, logging, and least-privilege database rules. No system is completely secure. If an incident creates a legally reportable risk, we will notify affected users and authorities as required.

10. Children

The Service is for adults aged 18 or older and is not directed to children. If you believe a minor submitted personal information, contact us so we can investigate and delete it where appropriate.

11. Changes and Privacy Contact

We will post Policy updates here. We will give advance or prompt notice of a material change that affects your rights, as required by law. The privacy contact below handles rights requests and complaints.

Controller: hyperreal., ASKITMORE Inc.
Mailing address: 982 Main St, Ste 4, Fishkill, NY 12524, United States
Privacy and support email: help@askitmore.com
hyperreal.

An AI generation platform for images, video, and Motion Copy.

Operated by hyperreal., ASKITMORE Inc.
982 Main St, Ste 4, Fishkill, NY 12524, United States
help@askitmore.com

Product

  • Video
  • Image
  • Motion Copy
  • Pricing

Account

  • My account
  • History
  • Troubleshooting

Legal

  • Terms of Service
  • Refund Policy
  • Privacy Policy

© 2026 hyperreal. All rights reserved.

TermsRefundsPrivacy