Infistar Privacy Policy
Last updated: October 5, 2026. Effective: October 5, 2026.
This policy covers every Infistar service: infistar.ai, infistar.cc, the user console, the chat app (owui.infistar.ai, chat.infistar.cc), Infinite Canvas, AI Create, the documentation sites, and the Android app (together, the "Service"). The Service is operated by Wuhan Luye Network Technology Co., Ltd. ("we", "us"), which is the controller of the personal data described here.
It explains what personal data we collect, why, on what legal basis, how long we keep it, who receives it, and how you can access, correct, or delete it.
1. What we collect and why
Account When you sign up we collect the username and password you choose and any referral code you enter. We store only an irreversible hash of your password. We do not ask for a phone number or identity document. We use this to create and secure your account and to record referrals. Legal basis: performance of our contract with you.
Bot protection Sign-up and sign-in use Alibaba Cloud's captcha service. Its widget reads device and interaction signals in your browser to tell people from bots; our server sends Alibaba Cloud only the captcha token, never your account details. A successful check is remembered in your browser for 7 days. Legal basis: our legitimate interest in preventing abuse.
Sign-in and security records For each sign-in we record the method, IP address, browser user agent, and time. Security actions such as changing your password or managing API keys are also logged with IP address and user agent. We use these records to protect your account, show you your active sessions, and investigate misuse. If you enable two-factor authentication or a passkey, we store the corresponding secret or public key. Legal basis: contract and legitimate interest in security.
API usage and billing records For each API call we record the time, key name, model, input and output usage, latency, charge, request ID, and the supply line used, for billing, reconciliation, and troubleshooting. These records do not include your IP address unless you turn on "Record IP address" in Security settings. We do not store your prompts or model replies in usage records, with three exceptions: asynchronous image and video jobs keep the provider's job result (including result file links) so you can retrieve it; failed calls keep the provider's error message, which may quote part of your request; and request bodies cached for accurate billing are deleted automatically within 5 minutes. Legal basis: contract; IP logging is based on your consent.
Chat app Conversations, uploaded files, and the search index built from those files in the chat app are stored on our servers so you can see your history and ask questions about your files. You sign in to the chat app with your Infistar account; we pass it only an internal identifier derived from your account number and your display name, not your email. You can delete conversations in the chat app. Legal basis: contract.
Infinite Canvas Canvas projects, assets, and generation history are stored in your own browser, not on our servers. Generation requests pass through our gateway to the model provider, and the gateway keeps job records as described above.
AI Create Images and videos you make in AI Create, together with the description and settings you entered, are stored on our servers so you can view and download them under My works. They are deleted automatically after 30 days, and you can delete them yourself at any time. Reference pictures you upload to generate a video are kept for 1 day so the model provider can fetch them, then deleted automatically. Portrait and photo-restoration scenes ask you to confirm that the people in the photo agreed, and we record when you confirmed. Your feedback on results (such as liked or disliked) is used to improve them. Legal basis: contract; feedback is based on our legitimate interest in improving the Service.
Payments For top-ups we record the order number, amount, payment method, status, the payment provider's transaction ID, and time. Website top-ups are currently paid through WeChat Pay; payment happens inside WeChat Pay and we do not receive your card or WeChat account details. For redemption codes we record the code and amount. Legal basis: contract and legal obligations for accounting.
Support tickets Ticket descriptions, messages, and attached images are stored on our servers to resolve your request. If you contact support on WeChat, we receive what you share there. Staff notifications about new tickets contain only the ticket number and category. Legal basis: contract.
Notifications If you add a notification email, webhook, Bark, or Gotify address in your settings, we store it and send alerts such as low balance to it. If you register a service-notice email, we store the address, verification time, and consent record, and use it only for security, outage, pricing, and address-change notices. Legal basis: consent.
Referral source On your first visit a 30-day cookie records which site referred you (only the site name for search engines, AI sites, and similar sources, the landing page, and the time; never the full URL). It is linked to your account at sign-up so we can measure which channels work. We skip this when your browser sends Do Not Track or Global Privacy Control. We use no third-party analytics, advertising, or tracking tools. Legal basis: legitimate interest.
Referral fraud prevention At sign-up your browser creates a random device identifier. We send a one-way hash of your IP address, device identifier, user agent, and email (if any) to our referral settlement system to detect mass sign-ups and self-referrals; that system does not keep the originals. These automated checks affect only referral rewards, and you can ask for a person to review a decision. Legal basis: legitimate interest in preventing fraud.
Referral partners If you join our referral partner program and request a payout, we collect your legal name, national ID number, bank account name and number, and bank branch to verify your identity, pay you, and handle taxes. Before you submit your ID number and bank account, we ask for your separate consent and record when you gave it. We use these only for payouts and mask them in staff views. Legal basis: contract, legal obligations, and your consent.
Service operations We compile per-account usage, first successful call time, and low-balance events for billing, service quality, and capacity planning. We do not share these with third parties or use them for targeted advertising. Legal basis: legitimate interest.
Android app The Android app is a shell around this website and requests only network access. It asks for the camera or microphone only when a web page feature needs them, and you can decline. It contains no third-party push, analytics, crash-reporting, or advertising SDKs.
2. Cookies and browser storage
Cookies we set Sign-in credential (new_api_refresh, 30 days, not readable by scripts) and session marker (new_api_has_session, 30 days); sign-in flow state (session); captcha pass (infistar_captcha_pass, 7 days); referral source (infistar_acq, and infistar_docs_entry from the documentation site, 30 days); a one-time hand-off when you open the chat app (60 seconds). All are set by us; there are no third-party advertising cookies.
Local storage Your browser stores your language, theme, layout preferences, referral code, the random device identifier used at sign-up, and Playground conversations and settings. This stays on your device and you can clear it at any time.
Your choices You can block or clear cookies in your browser. Without the sign-in cookies you cannot use the console.
3. Sharing and international transfers
Model providers What you submit through the API, chat app, Canvas, or AI Create (prompts, context, files, images) is sent to the provider of the model you choose, or to its authorized access partner, which processes it and returns the result. This is necessary to provide the Service. We do not attach your account, name, or IP address; if your request itself contains an identifier such as a user field, it is passed through unchanged. Providers differ by model; the model directory shows each model's vendor. Many providers are located outside the country you are in, for example in the United States, Singapore, or mainland China, and choosing their models transfers your input there. We ask for your separate consent to this when you sign up. Each provider handles and retains data under its own privacy policy, which we do not control, so please do not include personal or sensitive data your task does not need.
Other service providers Alibaba Cloud provides bot protection at sign-up and sign-in. Tenpay (WeChat Pay) processes website payments. Some resources on the documentation sites (doc.infistar.ai, doc.infistar.cc) load from the content delivery network of our documentation platform provider, Mintlify, which can see your IP address and browser details.
Where your data is stored Personal data we collect is stored on our own servers in mainland China. Traffic to infistar.ai enters through Alibaba Cloud in Hong Kong and is forwarded to those servers. If you are in the European Economic Area, the United Kingdom, or another region with transfer rules, this means your data is transferred to China, a country that has not received an adequacy decision from the European Commission. We transfer it because it is necessary to perform our contract with you.
Legal requests We disclose information when required by law or by a lawful request from a court or authority, limited to what is required.
What we do not do We do not sell your personal data or share it with third parties for their marketing. If personal data must move because of a merger, split, or acquisition, we will tell you who receives it and require them to keep to this policy.
4. How long we keep data
Account details, usage records, payment records, sign-in and security records, and support tickets are kept while your account exists. After you delete your account, usage, payment, and sign-in and security records are kept for reconciliation, dispute handling, and legal retention duties (for example, Chinese law requires network logs to be kept for at least six months). Chat app conversations and files are kept until you delete them in the chat app. AI Create works, with their descriptions and settings, are deleted automatically after 30 days, or earlier if you delete them. These are deleted automatically: reference pictures uploaded to AI Create after 1 day, ended sign-in sessions after 7 days, sign-in and verification flow records after 24 hours, low-balance events after 35 days, rate-limit records after 14 days, and billing request caches after 5 minutes. Cookie lifetimes are listed in section 2.
5. Security
All traffic uses HTTPS. Passwords are stored only as irreversible hashes. Sign-in credentials live in cookies scripts cannot read. Staff tools are separate from user accounts, and staff access data according to their role. Sensitive details are masked in staff views. Databases are backed up regularly. If a personal data breach occurs, we will notify you and the relevant authorities as the law requires.
6. Your rights
Access and correction You can view your account details, usage records, payment records, and active sessions in the console, and change your display name, password, and notification settings yourself.
Account deletion You can delete your account in Security settings. After deletion you can no longer sign in and your API keys stop working immediately; records listed in section 4 are retained as described there.
Other requests To delete other data such as support tickets, to get a copy of your personal data in a portable format, to restrict or object to processing, or to withdraw consent, contact us as described in section 9. We will verify your identity and reply within 15 business days. You can delete chat app conversations and AI Create works yourself.
Withdrawing consent You can turn off "Record IP address", remove your service-notice email, clear cookies and local storage, or enable Do Not Track at any time. Withdrawal does not affect processing that already took place.
Complaints If you believe we have not handled your data properly, please contact us first. You also have the right to complain to the data protection authority where you live or work.
7. Children
The Service is intended for adults and business developers. Children under 14 must not sign up or use it, and anyone under 18, or under the age of digital consent where they live, needs a parent or guardian's permission. If we learn we have collected data from a child under 14 without that permission, we will delete it.
8. Changes to this policy
We publish updates on this page and change the date at the top. For significant changes, such as new purposes or new recipients, we also post a notice on the site.
9. Contact
Controller: Wuhan Luye Network Technology Co., Ltd. Submit a ticket in the console (Tickets, after you sign in), or use Contact support at the top of the site to reach us on WeChat, and tell us about your privacy request.