AI HUB
About Services Models API AI Agent
English
Sign In

Privacy Policy

Effective Date: September 18, 2026 · Version 1.3

On this page

  1. Our Role Under the PDPA
  2. What Personal Data We Collect
  3. How We Use Your Data
  4. Data Sharing and Cross-Border Transfers
  5. Social Platform Permissions
  6. Publicly Addressable Media
  7. Data Retention
  8. Your Rights
  9. Contact Us
  10. Updates to This Policy
  11. Disclaimer
Jump to section
  1. Our Role Under the PDPA
  2. What Personal Data We Collect
  3. How We Use Your Data
  4. Data Sharing and Cross-Border Transfers
  5. Social Platform Permissions
  6. Publicly Addressable Media
  7. Data Retention
  8. Your Rights
  9. Contact Us
  10. Updates to This Policy
  11. Disclaimer

This document is provided in English.

Alchemist Marketing Sdn. Bhd. (Company Registration No. 202101000044 (1400342-A)) ("Company", "we", "us", or "our") operates AI HUB at aimodelhub.ai and console.aimodelhub.ai (the "Site" and "Service").

This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you access or use our Service. This Policy is issued in compliance with the Personal Data Protection Act 2010 (PDPA) of Malaysia.

By accessing, registering, or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree, you must not use the Service. Capitalised terms used but not defined in this Privacy Policy have the meanings given to them in our Terms of Service, which also states this Policy's governing law and dispute-resolution mechanism.

Our Role Under the PDPA

1.1 Controller and Processor. Under the Personal Data Protection Act 2010 (PDPA), Company acts as a Data Controller for account and billing data, and as a Data Processor for other personal data processed through the Service.

1.2 Where This Applies, and the Two Processor Exceptions. This Policy applies to the marketing site at aimodelhub.ai and the console at console.aimodelhub.ai. Company is the controller for the data described in this Policy, except in two situations where the roles reverse and Company acts strictly as processor: comments and profile details of people who engage with your social posts (Section 2.9), and the personal data of your own end-users where you build on the Developer API (Terms of Service, Section 4.5).

1.3 Model Training. Company operates no model training of any kind. Nothing submitted, uploaded, generated, or published through AI HUB is used by Company to train anything, on either the BYOK or the managed path. What happens to a request after it reaches a Model Provider is a matter between you and that provider on BYOK, and between the aggregator described in Section 4.1 and that provider on the managed Hub Key path; Company selects aggregators consistent with a no-training-on-API-data posture but is a customer of theirs, not an auditor of their internal practice, and gives no warranty about it.

What Personal Data We Collect

2.1 Account and Billing Data. Email address, username, authentication credentials (a bcrypt hash of your password if you set one), language preference, and account role. No phone number or postal address is collected. Where your account belongs to an organisation, Company additionally holds that organisation's name, contact email address, and plan, and for each invitation the invited email address, a one-way hash of the invitation token, and the times at which the invitation was issued, accepted, or cancelled.

2.2 Google Sign-In. If you sign in with Google, the sign-in happens on Google's own servers and Google returns four fields: name, email address, Google account ID, and profile picture URL. Nothing else, and never your Google password.

2.3 Keys and Tokens. Model Provider keys are stored encrypted at rest; only the last four characters are kept in clear text to display a masked tail such as sk-…4f2a. The full key is never displayed back to you, never sent to your browser, and never written to logs. Developer API keys are shown once at creation; Company thereafter stores only a one-way SHA-256 hash and a masked tail, so the plaintext can be neither displayed nor recovered. Social connection tokens are stored encrypted, including a refresh token where the platform supports one; Company records the expiry, refreshes automatically where possible, and prompts reconnection rather than acting on a stale token. Section 5 lists the scopes requested per platform.

2.4 Content You Create and Upload. Prompts, model responses, generated images/audio/video, product photographs and cast images uploaded to Ad Studio (Section 2.5), documents uploaded for retrieval, presentation decks together with any document a deck is generated from, long-form video scripts and the individual clips and takes generated for them, the description of your brand you save to Brand DNA, composed posts, and per-call metadata (provider, model, token counts, cost, latency, success). Performance and insights data for content you publish (likes, comments, shares, saves, reach, impressions, profile visits, video views, average watch time, and account-level figures such as follower count) is collected to the extent each platform exposes it. Company stores the styles you save, including their words, input names, settings and up to three kept images, as content you create.

2.5 Cast Photographs. We do not run facial recognition or attempt to identify individuals, and we compute and store no biometric template. A photograph placed in an Ad Studio cast slot is stored under a directory scoped to your account; on generation it is sent to the image Model that composes the advertisement frame, reached through the aggregators named in Section 4.1, and the composed frame, not the original photograph, is what reaches the video Model that animates it. An uploaded photograph that no generated item, saved run, or generation job still refers to is deleted automatically seven (7) days after it was uploaded; one that is still referenced is kept until you delete the item referring to it, or until you ask Company to remove it at [email protected]. The Service does not knowingly process personal data of anyone under eighteen (18).

2.6 Billing and Wallet Data. A prepaid US-dollar balance and a ledger of every top-up, per-call charge, and Hermes plan fee. Payment details are entered on Stripe's own encrypted form and go straight to Stripe; Company never sees or stores a full card number, CVV, bank login, or Alipay credential. For a saved card, Company retains only what Stripe returns for display: brand, last four digits, expiry month and year, and a Stripe payment-method reference.

2.7 Technical Data. IP address and browser user agent on your active session, used to keep you signed in and to detect abuse; the IP address and user agent of each acceptance record described in Section 2.8; and IP addresses used transiently to enforce rate limits. IP addresses are not attached to your usage history, your prompts, or your activity log, and no third-party analytics or advertising tracker runs on the console.

2.8 Records of Your Agreement. When you accept the Terms of Service and this Policy, Company writes a record containing your user ID, the action you were taking, the moment of acceptance in Coordinated Universal Time, the version of each document as it then stood, a SHA-256 digest of the exact text of those versions, the display language, and the IP address and browser user agent the acceptance came from. These records are retained for as long as the account exists and afterwards for as long as a claim relating to the agreement could still be brought. They are not combined with your usage data, not used to profile you, and not shared.

2.9 Comments and Third-Party Data. When engagement on a published post is read back, Company also reads and stores the public comments and replies on it: the commenter's display name, platform account ID, profile picture URL, comment text, like count, timestamp, and the raw platform response. Those commenters are not Company's customers; for that data, you are the controller and Company is the processor, per Section 1.2. Comments and metrics are deleted when you delete the post they belong to; disconnecting a social account does not delete them, because disconnection stops further access but does not erase publishing history. If a commenter asks to be removed, delete the comment on the platform and the post from AI HUB, or email [email protected] to have the stored copy purged.

2.10 Hermes Managed Agents. Provisioning a Hermes agent causes Company to process: the agent's instructions, AI provider, Model, and enabled tools or skills ("configuration"); the token or session data required to send and receive on a connected messaging channel, encrypted at rest ("channel credentials"); and the messages the agent exchanges, the tasks it performs, and operational metrics used to meter your wallet ("runtime data"). Each agent's data, including its conversation history and any files it handles, is deleted when you delete the agent.

2.11 The Public Playground. Company does not store a Playground prompt or its reply; it stores one metered usage row per call against an internal demo account, containing no prompt text and nothing that identifies you. Your IP address is used only to enforce the request limits stated in the Terms of Service and lives in a short-lived rate-limit cache, not a database table. Because there is no account, there is no way for Company to act on an access or deletion request about a Playground prompt.

2.12 Security Measures. Provider API keys, social platform tokens, and Hermes channel credentials are encrypted at rest, decrypted in memory only for the duration of a request you initiated, and never returned to your browser beyond a masked tail. Developer API keys are stored as a one-way SHA-256 hash only, and account passwords as bcrypt hashes. Hermes agents run in isolated per-customer containers with default-deny network egress, described fully in Terms of Service Section 7.2. Payments are handled entirely by Stripe, a PCI-DSS-compliant gateway; card, bank, and Alipay details never reach Company's servers. Two things Company wants you to know rather than have you assume: two-factor authentication is not yet offered on password-based accounts, and media URLs described in Section 6 are unauthenticated by design and should be treated as secrets. Report a vulnerability in good faith to [email protected].

2.13 Public Name and Community. Company assigns every account a public name ("handle") when the account is created, and shows it only once that account publishes a style. If you publish a style to Community, Company shows your handle to each user of the Service, together with the published style's name, tagline, words, cover image and kept images. Company does not show your real name, email address or account identifier. Company also records your agreement to publish, as Section 2.8 describes, together with the version of the style you agreed to share; the result of the automated check on each version, being a pass or a refusal and its reason; and counts of the people who used and copied your style, which only you can see. The automated check sends the style's words and pictures to a Model through the aggregators named in Section 4, in the same way as any other request. The check reports whether a person appears in a kept image; under Section 2.5, Company runs no facial recognition and does not identify that person.

2.14 Reports. When you report a style, Company stores your account identifier, the style and version you reported, the reason you chose, any details you wrote, and when and how Company resolved the report. Company tells the creator of a hidden style the reason for hiding it and does not tell the creator who reported it. Company keeps the reports on a style after its creator unpublishes it, so that unpublishing and republishing a style does not clear its reports.

How We Use Your Data

We use your personal data for providing and operating the Service, processing payments, authenticating your identity, responding to your inquiries, and complying with legal obligations. We do not sell your personal data or use your Inputs or Outputs to train our own models, consistent with Section 1.3.

Data Sharing and Cross-Border Transfers

We share data with third parties only as necessary to provide the Service:

  • MyTokenGate and ATP, the inference aggregators behind the managed Hub Key. Every managed prompt, image, audio, or video request reaches its Model through one of them, along with any attached file.
  • The Model Providers themselves (OpenAI, Anthropic, Google, DeepSeek, MiniMax, and ByteDance among others, depending on the Model selected) receive the prompt and any attached files.
  • Jina AI receives the text of documents uploaded for retrieval, in chunks, on the managed path only, and returns a numeric embedding of each chunk. On BYOK, documents go to your own provider and Jina never sees them.
  • Stripe processes every payment and receives your name, email address, and the payment details entered on its own form.
  • Resend delivers transactional email and receives your email address and the content of each message sent to you.
  • Meta (Facebook, Instagram, Threads), TikTok, and Google (sign-in and YouTube) receive the posts, captions, and media published through the Service, plus the OAuth context their APIs require, and return the metrics and comments described in Section 5.
  • Hosting, database, and object-storage providers hold data at rest and process it only on Company's instruction.
  • Messaging platforms connected to a Hermes agent (which may include WhatsApp, Telegram, Discord, Slack, Matrix, Mattermost, email, IRC, or ntfy) receive that agent's messages. You supply the credential and choose the destination.

Your data may be transferred to recipients located outside Malaysia in compliance with applicable laws; none of the recipients above is located in Malaysia, so using the Service means your Inputs, uploaded files, cast photographs, and published content routinely cross international borders to reach them. By using the Service you consent to that transfer. Company does not sell personal data and does not share it with advertisers, data brokers, or analytics networks.

Social Platform Permissions

Social connections use OAuth: you authenticate on the platform's own page, and Company never sees, receives, or stores your username, password, or login credential for it. Permissions requested are limited to what publishing and insights require:

  • Meta, Facebook Pages. pages_show_list, pages_manage_posts, pages_read_engagement, business_management, and public_profile. Company stores the Page ID, name, and the Meta-issued tokens.
  • Meta, Instagram. instagram_business_basic, instagram_business_content_publish, and instagram_business_manage_insights. Instagram's API offers no delete endpoint, so Company cannot delete an Instagram post on your behalf.
  • Meta, Threads. threads_basic, threads_content_publish, threads_manage_insights, threads_read_replies, and threads_delete. Meta has approved all five, so deleting a Threads post through the Service is available to you.
  • TikTok. user.info.basic, user.info.stats, video.upload, video.publish, and video.list. Company stores your TikTok open ID, display name, and the TikTok-issued token, never your TikTok login.
  • YouTube. youtube.upload and youtube.readonly only. Company stores your channel ID, title, and the Google-issued tokens.

All five platforms are open to every customer. Meta has approved every permission listed above for Facebook Pages, Instagram, and Threads, and TikTok has approved Company's application including direct publication to your account. We read insights only on your own content and the public comments on your own posts, never read private or direct messages, and never use social data for advertising or profiling.

Publicly Addressable Media

Media uploaded or generated through the Service is served from publicly accessible URLs of the form https://…/media/…. This is required for social media platforms: Instagram, Facebook, Threads, and TikTok publish by fetching a URL from their own servers, not by accepting an upload from Company, and a login-protected URL would make publishing impossible. What protects the file is its name: every stored file is given a random forty (40) character filename at the moment of upload or generation, unrelated to its contents, your account, or anything guessable, and the route returns a 404 for any name that does not exist. This is a secret held in a URL, not an access control. You should treat a media URL like a password and not share it with unauthorised persons; you may delete any media file through the console. This applies to generated images, audio and video, uploaded product photographs and cast photographs, social media attached to a post, and documents uploaded for retrieval.

Data Retention

We retain your personal data only as long as necessary for the purposes set out in this Policy, or as required by applicable laws. Certain billing and transaction records may be retained for up to seven (7) years under Malaysian law, specifically Section 82 of the Income Tax Act 1967 and the AMLA 2001.

Automatic Schedules. Four categories of data are purged on a schedule. Everything else is retained until you delete it or Company closes your account under Section 8.

  • An uploaded image that no generated item, saved run, or generation job still refers to is deleted seven (7) days after it was uploaded, and a format run that was never saved and cost nothing is deleted one (1) day after it was started.
  • A document uploaded for a presentation deck that no deck refers to is deleted seven (7) days after it was uploaded.
  • Developer API request records, being the endpoint called, the Model requested, the status, the latency, and the token counts, and never the content of a request or its reply, are deleted after ninety (90) days.
  • A stopped Hermes agent has its container and data reclaimed thirty (30) days after being paused, with warning emails at day seven (7) and day twenty-five (25). The configuration record survives, so the agent can be redeployed.

Community. Company keeps your handle for as long as your account exists, and keeps check results and reports for as long as the style they relate to exists, and afterwards for as long as a claim relating to that style could still be brought. When Company closes your account, your published styles leave Community; copies other users saved before then are their content and stay in their accounts, as Terms of Service Section 6.10 describes.

Your Rights

Under the PDPA, you have the right to access, correct, and request deletion of your personal data, and to object to or restrict Company's processing of it. To exercise these rights, contact us at [email protected]. We will respond in accordance with applicable law. You may change your handle on your account page once every thirty (30) days. Company retires the handle you leave behind and does not make it available to any other account.

Most of this is self-service: disconnect a social account from the Connections tab to revoke its token and delete the stored credential immediately; revoke a BYOK or Developer API key from the console, effective at once; delete a Hermes agent to destroy its container, memory, documents, and channel credentials; and delete conversations, generated media, uploaded documents, and social posts directly. Closing the account itself is not yet self-service: email [email protected] from the address on the account, and Company confirms your identity and closes it by hand, revoking every key and token and deleting conversations, documents, media, posts, agents, and their containers. Wallet ledger entries, top-up records, invoices, receipts, and the acceptance records described in Section 2.8 are retained under Section 7 and are not used for any purpose of Company's after closure. Any remaining Credit balance is forfeited on closure under Terms of Service Section 3.3. If you are unhappy with how a request was handled, you may complain to the Personal Data Protection Department of Malaysia under the Personal Data Protection Act 2010.

Contact Us

For questions regarding this Privacy Policy or your personal data:

Alchemist Marketing Sdn. Bhd. (Company Registration No. 202101000044 (1400342-A))
Block C-38-2 (Second Floor), Zenith Corporate Park,
1, Jalan SS 7/26, SS7, 47301 Petaling Jaya, Selangor, Malaysia.

Email: [email protected]

Want to manage your data? Disconnect accounts, revoke keys and export or delete your information from your account.

Email our privacy team
Back to top ↑

Updates to This Policy

We may update this Privacy Policy from time to time. The Effective Date at the top of this page indicates when it was last revised, and Terms of Service Section 12 states how notice of a material change is given. Continued use of the Service after that notice period constitutes acceptance.

Disclaimer

THE SERVICE IS PROVIDED "AS IS". TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE DISCLAIM ALL WARRANTIES AND LIMIT OUR LIABILITY AS SET FORTH IN OUR TERMS OF SERVICE.

AI HUB
Pricing Models Hermes API docs About Contact Sign in
© 2026 Alchemist Marketing Sdn Bhd · Company Registration No. 202101000044 (1400342-A) · Terms of use · Privacy policy · Data processing