Last updated · PDPO: 2026-07-22
Privacy Policy
We explain clearly how we collect, use, retain and protect personal data.
1. Overview and data collected
We process data under Hong Kong’s Personal Data (Privacy) Ordinance (Cap. 486). We may collect name, email, optional phone, transactions, invoice details, API metadata (time, model, tokens, IP and User-Agent) and essential cookies. Full card details are handled by Stripe or Airwallex.
2. Content we do not collect
API request bodies (prompts) and response bodies are not retained by default and are destroyed after proxying. Enterprise plans may enable an end-to-end encryption mode.
3. Use and disclosure
We use data to provide and improve services, process payments and invoices, send usage or security notices, meet duties such as AMLO, and analyze anonymized trends. We do not sell data; disclosure is limited to consent, lawful orders, bound providers or business transfers.
4. Storage and retention
Data is stored in AWS Hong Kong Region and is not transferred outside Hong Kong without express enterprise consent. Backups use AES-256. Account data is kept for 7 years after closure; metadata for Free 7 days, Pro 30 days and Enterprise 90 days; invoices and transactions for 7 years.
5. Your rights
Under the PDPO you may request access, correction, withdrawal of consent and deletion of data not legally required, and complain to the PCPD. Email privacy@pingai.hk; we respond within 40 days.
6. Cookies, children and incidents
Essential cookies maintain login; anonymized PostHog analytics improve the product. Blocking cookies may affect features. The service is not for anyone under 18. Personal-data incidents are notified to you and the PCPD within 72 hours in line with PDPO guidance.
7. Updates and contact
Material updates are announced by email and 30 days before taking effect. Data Protection Officer: privacy@pingai.hk; post: PingAI Data Protection Officer, Cyberport, Hong Kong.
8. Referral program (KOL)
Participants of the Referral Program receive a `pingai_ref` cookie on landing to attribute their signup; the cookie is HttpOnly, SameSite=Lax and expires after 30 days. Attribution records (IP and User-Agent are stored only as HMAC hashes, never in plain text) are retained for 90 days and then deleted automatically by a daily PDPO cleanup job. Referral ledger records (credits earned, converted or withdrawn) are kept for 7 years in accordance with tax law and can be exported as CSV at any time from the KOL dashboard.