LEGAL
PRIVACY POLICY
Last updated: 31-08-26
1. What we collect
We collect only data reasonably necessary to operate and secure the Services:
- Account data: email address, display name, account identifier, password hash (not your plaintext password), account creation/update information and failed-login/temporary-lock information.
- Google sign-in data: where you choose Google sign-in, your Google account subject identifier, email address and name supplied through Google's authentication service.
- Session and security data: authentication session identifiers, session-expiry information, OAuth security-state cookies and technical information required to prevent unauthorised access.
- Saved-project data: if you choose to save a project while signed in, the uploaded source image/file, a generated preview, filename, file type, project settings, palette/map information, aggregate project count and download/save metadata.
- Limited service analytics: event names and small non-identifying technical/feature metadata, for example upload, generate or download events. We do not intentionally attach these event counters to your account identity.
- Communications: information you send us by email or through a support request.
You do not have to create an account to use the basic in-browser editor. However, you must provide account data if you want to save and reopen projects in your library. If you decline to provide required account data, those account-based features will not be available.
2. Why we use personal data
We use personal data to:
- provide, authenticate and secure accounts and saved libraries;
- process your saved image and project settings so that you can reopen, update, download or delete a project;
- prevent fraud, misuse, unauthorised access and technical abuse;
- maintain, troubleshoot and improve reliability and usability of the Services using limited aggregate event data;
- respond to enquiries and meet legal obligations; and
- enforce the Terms of Use and protect our rights, users and third parties.
We do not currently use personal data for direct marketing. If we later wish to use your personal data in direct marketing, we will obtain any consent required under the PDPO before doing so.
3. How project images are handled
Normal image-to-pattern generation occurs in your browser. Your image is sent to our project storage only when you choose to save a project while signed in. A saved project stores the original file, generated preview and the settings required to reopen it.
We do not sell your uploaded images, private projects or outputs. We do not use them for advertising, public display or AI-model training without your separate, affirmative permission.
4. Who may receive data
We may disclose data only for the purposes above to:
- Cloudflare, which provides hosting, database and object-storage infrastructure used for accounts and saved projects;
- Google, when you choose Google sign-in;
- service providers that help us operate, secure or support the Services and are bound to handle data only for authorised purposes;
- authorised administrators, only where necessary to operate, secure, support or investigate the Services; and
- regulators, courts, law-enforcement bodies or other parties where required by law or necessary to establish, exercise or defend legal rights.
We do not sell personal data.
5. International processing
The Services use Cloudflare and Google infrastructure. Personal data may be processed or stored outside Hong Kong, depending on the location and configuration of those providers' systems. Where we use a data processor, we take practicable steps to require it to protect personal data and use it only for authorised purposes.
[[Before publication: confirm Cloudflare account settings, R2 jurisdiction/location, backup locations and any overseas support access.]]
6. Retention and deletion
We retain personal data only for as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
- Authentication sessions expire after 30 days, unless renewed through continued use.
- Saved projects remain available until you delete them or your account is deleted.
- When you delete a saved project, we delete its active database record and associated source and preview assets. Backup copies may persist for [[verified backup-retention period]] before being overwritten or deleted.
- Account data is retained while your account is active. You may request account deletion at info@massill.uk. We will verify your identity and delete or anonymise account data, subject to lawful retention requirements and the verified backup-retention period.
- Support communications are retained for [[verified support-retention period]], unless a longer period is needed to handle a complaint, dispute, fraud investigation or legal obligation.
7. Cookies
We use essential first-party cookies to maintain your sign-in session and to protect the Google sign-in process. These cookies are necessary for account functionality and security. We do not currently use advertising cookies.
8. Security
We take practicable steps to protect personal data from unauthorised or accidental access, processing, erasure, loss or use. Measures include HTTPS transport security, hashed passwords, signed-in access controls for saved project assets, access-limited administration and security controls supplied by our infrastructure providers.
No method of online transmission or storage is completely secure. Please protect your account credentials and keep your own backups of important work.
9. Children
The Services are not directed to children under 13. If you believe a child has provided personal data without appropriate consent, contact us at info@massill.uk so that we can review and take appropriate action.
10. Updates to this Policy
We may revise this Policy to reflect changes in our Services, technology or legal obligations. We will post the new version here and update the “Last updated” date. For material changes, we will give reasonable notice through the Services or by email where appropriate.
11. Contact and complaints
For privacy questions, requests or complaints, contact info@massill.uk. You may also contact the Office of the Privacy Commissioner for Personal Data, Hong Kong, where appropriate.