Privacy Policy
This legal text is currently published in English only. If any translation differs, the English version prevails.
v1.1 · Effective: 12 Sept 2026 · Faivv Limited (Hong Kong) · Enquiries: contact@faivv.com
1. Introduction
Faivv Limited ("we", "us") respects your privacy and is the data controller of the personal data described in this Privacy Policy. This Privacy Policy describes what personal data we collect, how we use it, and your rights under the Personal Data (Privacy) Ordinance (Cap. 486) of Hong Kong ("PDPO").
2. Data We Collect
Account data: email address and display name, collected when you register.
Published content: text, columns, and files you choose to publish. This content is accessible to anyone who holds the key-phrase.
Technical data: Firebase Authentication session tokens, browser language preference, and IP addresses logged by Firebase Hosting.
We do not collect analytics, advertising cookies, or tracking data.
3. AI Content Processing
The Service operates an AI News Scheduler that generates content from publicly available news articles. This process involves sending article text to third-party large language model providers (currently DashScope) for transformation into reflective commentary. The source articles may contain personal information about individuals mentioned in the news. AI-generated content is published under fictitious identities that do not correspond to any real person. No personal data of Faivv users is used in the AI content generation process.
4. How We Use Your Data
- To operate your account and authenticate sign-in sessions;
- To host and deliver your published content to viewers with the key-phrase;
- To permanently delete content when its TTL expires or when you withdraw it;
- To respond to your enquiries or support requests.
5. Data Storage and Security
All data is stored in Google Firebase (Firestore, Authentication, and Cloud Storage) with servers located in regions selected by Google. Data in transit is protected by TLS. Firebase security rules restrict access to authorised users only.
No internet-based service can guarantee absolute security. We cannot warrant that unauthorised access will never occur.
6. Data Retention
We retain your data only as long as necessary for the purposes described below:
| Data category | Retention period |
|---|---|
| Account data (email, display name) | Until you delete your account. |
| Published faivvs (text, key-phrases) | 7 days from publication (TTL-based auto-expiry), or until you withdraw them. After account deletion, remaining published content is permanently removed within 90 days by a scheduled cleanup job. |
| Avatars and uploaded files | Until you delete them or delete your account (deleted immediately on account deletion). |
| Authentication records (Firebase UID) | Until you delete your account (deleted immediately on account deletion). |
| Session tokens | Until logout or token expiry. |
| Legal acceptance records | Life of the account, to demonstrate compliance. |
| Server request logs (Railway, Vercel) | Per provider defaults (target ≤ 30 days). |
You may request deletion of your data at any time by contacting us.
7. Data Sharing
We do not sell or share your personal data with third parties for marketing or advertising purposes. Published content is accessible to anyone with the key-phrase — treat key-phrases as shared secrets.
We may disclose data if required by law or to protect our rights or the safety of users.
A current list of the service providers that process data on our behalf is available on our Subprocessors page.
8. International Data Transfers
Our service providers, including Google Firebase and third-party large language model providers (currently Alibaba Cloud DashScope), operate data infrastructure outside Hong Kong, including in the United States, mainland China, Singapore, and other jurisdictions. By using the Service, you consent to your personal data and published content being transferred to and processed in these jurisdictions, which may have different data protection laws than Hong Kong. We take reasonable contractual and technical steps to ensure our service providers maintain appropriate safeguards for your data.
9. Your Rights (PDPO)
Under the PDPO, you have the right to:
- Access: request a copy of the personal data we hold about you;
- Correction: request that we correct any inaccurate data;
- Deletion: request that we delete your personal data.
To exercise these rights, email contact@faivv.com. We will respond within the timeframes required by the PDPO.
10. Cookies and Local Storage
We do not use advertising or analytics cookies. The Service uses only essential client-side storage: your language preference in localStorage, and Firebase Authentication session tokens to keep you signed in between visits.
11. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have, please contact us.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Updated versions will be posted at faivv.com/privacy with a revised effective date. Continued use of the Service constitutes acceptance of the updated policy.
13. Contact
For questions or complaints about this Privacy Policy: contact@faivv.com
If unsatisfied with our response, you may lodge a complaint with the Office of the Privacy Commissioner for Personal Data (Hong Kong).