1. Who collects your data, and what this covers
Your data is collected by 悠藍微光有限公司 (Tax ID 62148730), the operator of Yuralume Cloud. Our support email (danny@yuralume.com) and the full disclosure are on the Merchant and support information page. This policy covers the notification form on yuralume.com, the Hosted demo, the Yuralume Cloud account center, and the live Hosted service.
If you deploy Self-host Core yourself, you manage your own database, characters, memories, and model keys by default. Unless you deliberately connect Cloud features or a third-party provider, Yuralume Cloud does not receive your character content simply because you run Self-host.
2. Why we collect data, and what kinds
| Situation | Data that may be involved | Purpose |
|---|---|---|
| OAuth sign-in | Discord / Google identifier, display name, email address, avatar, sign-in records | Creating your account, verifying who you are, keeping sign-in secure |
| Hosted service | Character settings, chats, memories, schedules, generation requests, usage and error records | Providing the AI character service you asked for, debugging, and running the service securely |
| Orders and payments | Order number, product, amount, payment status, payment provider transaction ID, refund and dispute records | Delivering the service, reconciliation, refunds, fraud prevention, statutory accounting |
| Lumes (closed-loop AI credits) | Paid and gifted balance, and records of Lumes granted, held, spent, refunded, and expired | Metering, showing your balance, resolving disputes |
| Character Plaza | Creator nickname and avatar, submitted cards and their versions, original / fan-made declarations, review and report records, hearts, follows and bring-home records, and records of reward points granted, exchanged, and clawed back | Showing and reviewing cards on the Character Plaza, handling reports and notices from rights holders, preventing inflated hearts, and calculating and granting reward points |
| Support and security | What you write to us, IP address, device / browser information, audit and anti-abuse events | Answering complaints, protecting your account and the service |
| Arriving through a promotional link or from another website | The utm parameters in the address (utm_source, utm_medium, utm_campaign, utm_content), ref, the page you landed on, and the domain of the website that sent you (the domain only, never its path or query string) | Measuring how each promotional channel performs |
| Getting-started activity (hosted cloud service only) | The steps you take after signing up, for example whether you entered the game, which official characters you were shown, which card you picked, whether the opening scene was delivered, whether you sent a first message and how long the reply took and how many characters it ran, and whether you linked LINE. It is tied only to your account ID; we do not record your IP address, your browser's User-Agent, or the content of your conversations | Improving the first-time experience |
3. How long we keep personal data, where it is processed, who receives it, and how
- How long: only as long as the purposes above require. After your account is deleted or the contract ends, anything still needed for the law, accounting, dispute handling, or backup rotation is kept for the necessary period, then deleted or de-identified.
- Getting-started activity: deleted after 180 days. It is collected only on the hosted cloud service; self-hosted installs do not collect it. After your account is deleted, this activity is still kept until 180 days have passed since it was collected, then deleted; it is no longer used or provided together with your account data.
- Where: we operate mainly in Taiwan. When we use OAuth, cloud infrastructure, email, payment, or AI providers, your data may be processed in the regions where those services run.
- Who: Yuralume's operations staff, plus the service providers we need in order to complete sign-in, send email, collect payments, host, monitor, or deliver the AI capabilities you request. Where the law requires it, we may also provide data to the competent authority or a court.
- How: through automated systems, the human support that is genuinely needed, and security checks. Yuralume does not sell personal data, and does not hand private character content to third parties for advertising unrelated to delivering the service.
Payment is processed by an authorised third-party payment service provider, which receives only the order and payment data needed to complete the transaction. The main categories of service provider we rely on are as described in this section.
What the Character Plaza makes public: the creator nickname you use on the Character Plaza, your creator page avatar (the cover of one of your own listed cards), and the content of your listed cards are shown publicly to other players signed in to Yuralume Cloud, together with how many cards you have listed and how many hearts and followers you have. The hearts and follows you give are not shown to other players under your name. How many Lumes (closed-loop AI credits) you spend on characters shared by other players is used only to decide whether the hearts you give count toward that card's rewards, and is not shown to the creator. The text and images of submitted cards are checked first with the help of automated tools, including models provided by AI providers. The details are in the Character Plaza Submission and Reward Points Terms.
4. Browser storage and third-party sign-in
The site may use necessary cookies, localStorage, or sessionStorage to keep your sign-in state, language, OAuth PKCE verification data, and CSRF / security state. If you turn that necessary storage off, sign-in and account features may stop working; purely public pages can still be read.
Alongside that necessary storage there is one non-essential entry, for marketing attribution: if you arrive through a promotional link (carrying utm parameters or ref) or from another website, we keep that first visit's parameters, landing path and the referring site's domain (the domain only, never its path or query string) in your browser's localStorage for 30 days, purely to measure how the channel performed. It is not created if you type the address in directly or arrive from a bookmark, clearing your browser storage removes it, and its absence has no effect on sign-in, purchases, refunds, or any part of the service.
The promotional attribution and getting-started activity above are processed only in our own systems; this site uses no third-party analytics tools and no tracking cookies.
Discord, Google, payment providers, and any AI provider you choose handle the data sent to them under their own policies. Yuralume only sends what the feature you chose needs, and limits how it may be used through service settings and contract terms.
5. Your rights, and how to exercise them
Under Taiwan's Personal Data Protection Act you may ask to look up or review your data, receive a copy, have it supplemented or corrected, stop its collection, processing, or use, and have it deleted. The account center offers data export and deletion where available; you can also send a request through our support channels.
When you delete a single AI character, that character's active data (its settings, chat, memory, and schedule) and media files are deleted; generation-usage and accounting/audit records are kept for the necessary retention period under the accounting and dispute-handling exception described above.
Getting-started activity is not deleted when you delete your account: it is kept until 180 days have passed since it was collected, then deleted, and it is no longer used or provided together with your account data.
When you delete your account, all your cards leave the Character Plaza, your creator page becomes anonymous (your nickname and avatar are cleared), the hearts and follows you gave are deleted, and your unexchanged reward points are forfeited. The characters other players have already brought home are copies in their accounts and are not deleted. Review, report, and enforcement records about cards are kept under the dispute-handling and legal-obligation exceptions described above.
To stop someone acting in your name, we may need to verify your identity in a reasonable way. If data must still be kept for accounting, a dispute, a security incident, or another statutory obligation, we will explain why and when it will be deleted.
6. Whether you have to provide data, and what happens if you don't
Without the account, contact, and order data the Hosted service needs, you may not be able to sign in, complete payment, receive the service, get a refund, or have a complaint handled. Optional character details only affect the personalized features built on them.
7. Security, minors and updates to this policy
We apply access controls, transport protection, auditing, backups, and incident handling proportionate to how sensitive the data is. If an incident could affect your rights, we assess it, act on it, and notify as the law requires.
Minors need their legal representative's consent before using paid services. We announce material changes on the site and notify users who have given us contact details before those changes take effect. We do not treat continued browsing as consent to using your data in ways unrelated to the original purpose.
