Alofy

Privacy Policy

Last updated: 27 August 2026

This Privacy Policy explains how HYPERIONMAX (operating as “HYPERIONMAX,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data when you use the Alofy mobile application (the “App”) for iOS, distributed through the Apple App Store. By creating an account or using the App, you acknowledge the practices described in this Policy.

Data controller. HYPERIONMAX, registered at Kausar street 29, Almaty, Republic of Kazakhstan, is the controller responsible for your personal data. For any privacy request, contact us at .

1. Scope of this Policy

This Policy applies to personal data we process through the Alofy App and related support channels. It does not apply to third-party services we do not control, including Apple's operating system and App Store, or to any external websites you may reach through links in the App. Those services are governed by their own privacy policies.

2. Information we collect

We collect the following categories of personal data:

CategoryExamplesSource
Reference-lookup requests When the App fetches reference photographs and species information, it requests them directly from public botanical and encyclopedic APIs. Those requests carry the species name and, necessarily, your device's IP address. They carry no account identifier and none of your own photos. Sent by your device
Account identifiers Email address; or, where you use Sign in with Apple, the Apple ID private relay email and a unique user identifier provided by Apple. (If you choose Apple's “Hide My Email” option, we receive only a relay address, not your real email.) You / Apple
User-submitted content Photographs of plants you upload, together with any notes, labels, or care preferences you add. You
Subscription & purchase data Subscription status, plan type, renewal/expiry dates, and transaction identifiers. Apple processes your payment; we do not receive your full card number or financial account details. Apple In-App Purchase / RevenueCat
Device & usage diagnostics Device model and operating-system version, app version, language/region settings, crash logs, performance metrics, and in-app interaction events used to operate and improve the App. Automatically collected

We do not require you to provide special categories of data (such as health, biometric, or precise-location data) to use the App, and we ask that you not include such data in the photos or notes you submit.

3. How your plant photos are processed (third-party AI)

The core function of Alofy is to analyze photographs of plants and return identification and care guidance. To do this, the images you submit are transmitted, via our secure backend proxy, to a third-party artificial-intelligence / large language model (LLM) provider — OpenAI (GPT models) and/or Google (Gemini models) — which acts as our sub-processor. The provider analyzes the image and returns results (for example, a likely species, health assessment, or care recommendations) to the App. Our backend proxy relays your images to the AI provider and does not retain copies of them.

Please avoid including people, faces, documents, or other sensitive content in the photos you submit, as those images are sent to the AI provider for processing.

4. How and why we use your data

5. Legal bases for processing (GDPR)

Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:

6. How we share data & sub-processors

We share personal data only as described below. We do not sell your personal data.

7. International data transfers

We are based in the Republic of Kazakhstan, and our service providers (including the AI sub-processor) may process data in other countries, including outside the European Economic Area. Where we transfer personal data internationally, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), transfers to jurisdictions recognized as providing an adequate level of protection, or your explicit consent where permitted. You may request a copy of the safeguards we use by contacting us at .

8. Data retention & deletion

You can request deletion at any time from within the App or by contacting .

9. Your rights (GDPR)

If you are in the EEA, the UK, or another jurisdiction granting comparable rights, you have the right to:

To exercise these rights, contact . We will respond within the time limits required by applicable law. You also have the right to lodge a complaint with your local data-protection supervisory authority.

10. U.S. residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights. In the preceding 12 months we have collected the categories of personal information described in Section 2, namely identifiers, customer-records information (e.g., subscription data), internet/device activity (diagnostics), and visual information (the photos you submit), for the business purposes described in Section 4.

We do not sell, and we do not “share” (as defined under the CPRA for cross-context behavioral advertising), your personal information. To exercise your rights, contact . You may use an authorized agent, and we will verify requests as required by law.

11. Kazakhstan personal-data rights

We process personal data in accordance with the Law of the Republic of Kazakhstan No. 94-V dated 21 May 2013 “On Personal Data and Its Protection” and related regulations.

Requests under Law No. 94-V may be sent to .

12. Children's privacy

Alofy is not directed to children. The App is intended for users aged 16 and over, and in any event not for children under 13. We do not knowingly collect personal data from children under these ages. Consistent with the U.S. Children's Online Privacy Protection Act (COPPA) and Article 8 of the GDPR, if we learn that we have collected personal data from a child without appropriate consent, we will delete it promptly. If you believe a child has provided us personal data, contact .

13. Security & breach notification

We implement administrative, technical, and organizational measures designed to protect personal data, including encryption of data in transit, access controls, and contractual restrictions on our sub-processors. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected users without undue delay, as required by applicable law (including GDPR Art. 33–34 and Kazakhstan Law No. 94-V).

14. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where required by law, provide additional notice within the App. Your continued use of the App after an update takes effect constitutes acknowledgment of the revised Policy.

15. Contact us

For privacy questions, requests, or to reach our data-protection contact: