Alofy
Privacy Policy
Last updated: 27 August 2026
This Privacy Policy explains how HYPERIONMAX (operating as “HYPERIONMAX,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data when you use the Alofy mobile application (the “App”) for iOS, distributed through the Apple App Store. By creating an account or using the App, you acknowledge the practices described in this Policy.
1. Scope of this Policy
This Policy applies to personal data we process through the Alofy App and related support channels. It does not apply to third-party services we do not control, including Apple's operating system and App Store, or to any external websites you may reach through links in the App. Those services are governed by their own privacy policies.
2. Information we collect
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Reference-lookup requests | When the App fetches reference photographs and species information, it requests them directly from public botanical and encyclopedic APIs. Those requests carry the species name and, necessarily, your device's IP address. They carry no account identifier and none of your own photos. | Sent by your device |
| Account identifiers | Email address; or, where you use Sign in with Apple, the Apple ID private relay email and a unique user identifier provided by Apple. (If you choose Apple's “Hide My Email” option, we receive only a relay address, not your real email.) | You / Apple |
| User-submitted content | Photographs of plants you upload, together with any notes, labels, or care preferences you add. | You |
| Subscription & purchase data | Subscription status, plan type, renewal/expiry dates, and transaction identifiers. Apple processes your payment; we do not receive your full card number or financial account details. | Apple In-App Purchase / RevenueCat |
| Device & usage diagnostics | Device model and operating-system version, app version, language/region settings, crash logs, performance metrics, and in-app interaction events used to operate and improve the App. | Automatically collected |
We do not require you to provide special categories of data (such as health, biometric, or precise-location data) to use the App, and we ask that you not include such data in the photos or notes you submit.
3. How your plant photos are processed (third-party AI)
The core function of Alofy is to analyze photographs of plants and return identification and care guidance. To do this, the images you submit are transmitted, via our secure backend proxy, to a third-party artificial-intelligence / large language model (LLM) provider — OpenAI (GPT models) and/or Google (Gemini models) — which acts as our sub-processor. The provider analyzes the image and returns results (for example, a likely species, health assessment, or care recommendations) to the App. Our backend proxy relays your images to the AI provider and does not retain copies of them.
- Purpose. Images are processed solely to generate the plant-analysis results you request and to operate and improve the accuracy of that feature.
- No identification of individuals. The analysis is directed at plants. We do not use the images to identify, profile, or recognize any human individual, and we do not perform facial recognition.
- Contractual safeguards. Each sub-processor is bound by data-processing terms that restrict use of your images to providing the service to us. Please review OpenAI's and Google's own data-handling terms for details of their retention and training practices.
Please avoid including people, faces, documents, or other sensitive content in the photos you submit, as those images are sent to the AI provider for processing.
4. How and why we use your data
- To create and administer your account and authenticate you;
- To provide the App's core functionality, including AI-based plant identification and care guidance derived from the photos you submit;
- To process and manage your auto-renewable subscription and verify entitlements;
- To provide customer support and respond to your requests;
- To maintain, secure, troubleshoot, and improve the App, including diagnostics and analytics;
- To detect, prevent, and address fraud, abuse, and security incidents; and
- To comply with legal obligations and enforce our Terms of Use.
5. Legal bases for processing (GDPR)
Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the App and the services you request, including processing your photos to return analysis results and managing your subscription.
- Consent (Art. 6(1)(a)) — for the transmission of your photos to our third-party AI sub-processor for analysis, and for any optional analytics or communications that require consent. You may withdraw consent at any time (see Section 9).
- Legitimate interests (Art. 6(1)(f)) — to secure the App, prevent abuse, and improve our services, balanced against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)) — to comply with applicable law.
6. How we share data & sub-processors
We share personal data only as described below. We do not sell your personal data.
- AI/LLM sub-processors (OpenAI and/or Google) — receive the photos you submit to perform plant analysis, as described in Section 3.
- Apple — processes Sign in with Apple authentication and all In-App Purchase transactions and subscription billing.
- RevenueCat — our subscription-management provider. It receives a pseudonymous user identifier and your subscription and entitlement status, so the App knows whether your Alofy Pro subscription is active. It does not receive your photos.
- Cloudflare — operates the backend proxy through which your photos are relayed to the AI provider, as described in Section 3. The proxy does not retain copies of your images.
- iNaturalist and the Wikimedia Foundation (Wikipedia / Wikimedia Commons) — public reference sources the App queries directly from your device to retrieve species information and example photographs. These requests carry the species name and your IP address, and are governed by those organizations' own privacy policies. No account identifier and none of your own photos are sent to them.
- Infrastructure & service providers — cloud hosting, storage, crash reporting, and analytics vendors that process data on our behalf under written agreements.
- Legal & safety — authorities or third parties where disclosure is required by law, to enforce our Terms, or to protect the rights, property, or safety of our users or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
7. International data transfers
We are based in the Republic of Kazakhstan, and our service providers (including the AI sub-processor) may process data in other countries, including outside the European Economic Area. Where we transfer personal data internationally, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses (SCCs), transfers to jurisdictions recognized as providing an adequate level of protection, or your explicit consent where permitted. You may request a copy of the safeguards we use by contacting us at hello@contacts.hyperionmax.business.
8. Data retention & deletion
- Plant photos. We do not store the photos you submit on our servers. The images remain on your device and are transmitted to our AI provider only at the time of analysis to generate your results; we do not retain copies afterward. See Section 3 for how the AI provider processes them.
- Account data. We retain account identifiers and associated content for as long as your account is active.
- Deletion on account closure. When you delete your account, we delete or anonymize your account data within a reasonable period, except where retention is required for legal, accounting, security, or fraud-prevention purposes.
- Diagnostics. Aggregated or de-identified diagnostic data that can no longer be linked to you may be retained for analytics.
You can request deletion at any time from within the App or by contacting hello@contacts.hyperionmax.business.
9. Your rights (GDPR)
If you are in the EEA, the UK, or another jurisdiction granting comparable rights, you have the right to:
- Access the personal data we hold about you (Art. 15);
- Rectification of inaccurate or incomplete data (Art. 16);
- Erasure (“right to be forgotten”) (Art. 17);
- Restriction of processing (Art. 18);
- Data portability — to receive your data in a structured, commonly used, machine-readable format (Art. 20);
- Object to processing based on legitimate interests (Art. 21); and
- Withdraw consent at any time, without affecting processing carried out before withdrawal (Art. 7(3)).
To exercise these rights, contact hello@contacts.hyperionmax.business. We will respond within the time limits required by applicable law. You also have the right to lodge a complaint with your local data-protection supervisory authority.
10. U.S. residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights. In the preceding 12 months we have collected the categories of personal information described in Section 2, namely identifiers, customer-records information (e.g., subscription data), internet/device activity (diagnostics), and visual information (the photos you submit), for the business purposes described in Section 4.
- Right to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients;
- Right to delete personal information we have collected, subject to legal exceptions;
- Right to correct inaccurate personal information;
- Right to opt out of the sale or sharing of personal information; and
- Right to non-discrimination for exercising your rights.
We do not sell, and we do not “share” (as defined under the CPRA for cross-context behavioral advertising), your personal information. To exercise your rights, contact hello@contacts.hyperionmax.business. You may use an authorized agent, and we will verify requests as required by law.
11. Kazakhstan personal-data rights
We process personal data in accordance with the Law of the Republic of Kazakhstan No. 94-V dated 21 May 2013 “On Personal Data and Its Protection” and related regulations.
- Lawful processing & consent. We collect and process your personal data on the basis of your consent and as necessary to perform our agreement with you. You may withdraw consent at any time, subject to legal and contractual limits.
- Cross-border transfer. Your personal data, including photos you submit, may be transferred to and processed in countries outside Kazakhstan (including by our AI sub-processor and infrastructure providers). We carry out such transfers only where the receiving country ensures protection of personal data or where you have consented, consistent with the requirements of Law No. 94-V.
- Your rights. You may request information about the processing of your personal data, request that it be corrected, blocked, or destroyed where it is incomplete, outdated, unlawfully obtained, or no longer necessary for the stated purpose.
Requests under Law No. 94-V may be sent to hello@contacts.hyperionmax.business.
12. Children's privacy
Alofy is not directed to children. The App is intended for users aged 16 and over, and in any event not for children under 13. We do not knowingly collect personal data from children under these ages. Consistent with the U.S. Children's Online Privacy Protection Act (COPPA) and Article 8 of the GDPR, if we learn that we have collected personal data from a child without appropriate consent, we will delete it promptly. If you believe a child has provided us personal data, contact hello@contacts.hyperionmax.business.
13. Security & breach notification
We implement administrative, technical, and organizational measures designed to protect personal data, including encryption of data in transit, access controls, and contractual restrictions on our sub-processors. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority and affected users without undue delay, as required by applicable law (including GDPR Art. 33–34 and Kazakhstan Law No. 94-V).
14. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where required by law, provide additional notice within the App. Your continued use of the App after an update takes effect constitutes acknowledgment of the revised Policy.
15. Contact us
For privacy questions, requests, or to reach our data-protection contact:
- Entity: HYPERIONMAX
- Address: Kausar street 29, Almaty, Republic of Kazakhstan
- Email: hello@contacts.hyperionmax.business