Legal
Version 1.5 · Last updated 16 September 2026 · Effective 16 September 2026
版本 1.5 · 最後更新 2026 年 9 月 16 日 · 生效日 2026 年 9 月 16 日
This English version is the legally binding one. A Traditional Chinese translation is provided for convenience only.
OpenStela, a sole proprietorship established and operating in Taiwan, is the controller of the personal data described here. The Service was named Avatar Lab (avatar-lab.app) until 16 September 2026; the controller and your data are unchanged by the rename to OpenStela (openstela.io).
Privacy contact: [email protected] · General contact: [email protected]
| Data | Source | Why |
|---|---|---|
| Email address (verified) | Google or GitHub, at sign-in | Identifies the account; carries quota, files and billing |
| Display name (if provided) | Google or GitHub | Shown in the interface |
| Internal user ID (random string) | Generated by us | Used everywhere in place of the email, so that changing an email does not move your data |
| Account creation time | Generated by us | Support and abuse handling |
| Handle, display name and bio (optional) | Entered by you in Account settings | Your public creator page — see 3.1A |
| Notifications (in-product records of deal progress, messages, anchoring and channel expiry) | Generated by us from your activity | Shown in the notification list; used to send product-notice emails |
Public creator page. If you set a handle, a page at /u/<handle> shows your
handle, display name, bio and the characters you have chosen to list publicly. That page is visible to anyone,
including search engines and social-media link previews, and can be shared by anyone. Your email address and
internal user ID are never shown. Remove the handle in Account settings and the page is gone; links you have
already shared will stop working.
Notifications. We keep the most recent 200 notifications per account. They are included in your data export and deleted with your account. Product-notice emails (deal progress, new messages, anchoring, channel expiry, billing and security) are sent to your sign-in email through our email provider (section 5) as part of providing the Service. Deal and message notices are batched into at most one email per 15 minutes; everything else goes into a daily digest. Every email carries a one-click unsubscribe link, and you can turn product-notice emails off in Account → Preferences at any time; in-product notifications continue regardless. Marketing emails are separate and are sent only with your explicit opt-in.
We request only the minimum OAuth scopes: openid email profile from Google,
user:email from GitHub. We do not receive your password, contacts, files, calendar or any
other data from those providers.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the Service you asked for: accounts, storage, generation, adapters | Performance of a contract |
| Metering credits, billing, preventing quota abuse | Performance of a contract; legitimate interests |
| Security, fraud prevention, service-wide rate limiting | Legitimate interests |
| Debugging and improving quality using generation metadata | Legitimate interests — assessed as low impact, since it concerns model behaviour rather than the content of your character |
| Service emails (account, billing, material changes to terms) | Performance of a contract |
| Complying with legal obligations, including tax records held by our payment processor | Legal obligation |
Where we rely on legitimate interests, you may object — see Section 8.
We do not sell personal data and do not share it for advertising. We use the following processors and providers:
| Provider | What it receives | Purpose | Location |
|---|---|---|---|
| Google (Gemini API) | Character specification text and reference/uploaded images submitted for generation or analysis | Image generation and analysis | Google infrastructure |
| Google Identity / GitHub | Sign-in exchange only | Authentication; returns verified email | US / global |
| Zeabur (hosting) | Everything stored by the Service | Application hosting and persistent storage | Tokyo, Japan |
| Cloudflare | Request metadata (IP, user agent) | DNS, CDN, protection | Global |
| Polar Software Inc. | Email, internal user ID, purchase details | Payment processing as Merchant of Record; Polar is the seller of record and handles tax | US / global |
| Resend, Inc. (email delivery) | Email address, internal user ID and the content of the notice (character name, deal status, message preview) | Sending product-notice emails (3.1A) | US / global |
| Arbitrum One (public blockchain) | A 32-byte Merkle root only — no personal data, no readable content | Timestamp anchoring of specification hashes | Public, permanent |
We may also disclose data where required by law, court order, or to establish or defend legal claims.
Your data is stored in Japan and transmitted to providers in the United States and elsewhere. Where a transfer is from the EEA or UK, it is made on the basis of the European Commission's Standard Contractual Clauses or an adequacy decision, as applicable to the provider concerned.
| Data | Retention |
|---|---|
| Account and content | For as long as the account exists |
| After account deletion | Held recoverable for 14 days, then deleted; backups purged within a further 30 days |
| Generation metadata (events, funnel) | Retained after account deletion in a form detached from your email, keyed only to the internal user ID, for product analysis |
| Billing records | As required by tax law — held principally by Polar as Merchant of Record |
| Blockchain anchors | Permanent and undeletable — see Section 9 |
Subject to your location, you may have the right to: access your data; correct it; delete it; export it in a portable format; restrict or object to processing based on legitimate interests; and withdraw consent where processing rests on consent.
Export is partly built into the product: character specifications, reference images and adapter packs can be downloaded from the interface at any time, in open formats (JSON, standard image files, plain text).
Export and deletion are built into the product. Settings → Your data downloads a complete copy of your account; Settings → Delete account removes it, and the account is held recoverable for 14 days before it is purged. All other requests are handled on request — write to [email protected]. We acknowledge within 5 working days and complete within 30 days. There is no charge unless a request is manifestly unfounded or excessive.
If a character of yours was issued a Character ID and anchored, a hash of its specification forms part of a Merkle tree whose root was written to a public blockchain.
We can, and on request will, delete the local batch record that connects your character to a position in that tree — after which the on-chain root can no longer be used to demonstrate anything about your character. Please note that doing so also destroys your ability to use the anchor as evidence.
Works. If you register works (audio, video, images, or links) under a character, we store the uploaded files and their metadata (title, notes, rights declaration, timestamps) to operate the feature. Only the SHA-256 fingerprint of each work — never the work itself — enters the public blockchain anchoring described in Section 9. Deleting a work removes the file from our storage; the anchored fingerprint cannot be removed, and the public verification endpoint will state the work has been deleted. For linked works we store a snapshot of the linked page or its oEmbed record fetched once at registration; we do not monitor the link afterwards.
Evidence records. For each work we run automated checks on how it relates to the character (file dates, names found on the linked page, presence of the character's declared markers or palette, and — on request — a face or body similarity measurement against the character's own reference images). The results, a timestamp and the method version are stored as records and their fingerprints are anchored. These checks analyse content, not you: the face-similarity check compares images of a character to other images of the same character. It is not used to identify any natural person, and we do not build biometric templates of real people. If a work depicts a real person, do not request the visual-match check for it.
Channel verification. If you verify a channel (a website or social account), we store the channel URL, the one-time code, the date and method of verification and a snapshot of the page where the code was found. Verification lapses after 90 days.
Deal room. If you negotiate or sign a contract in the deal room, we store the draft and signed contract text, the parameters and clauses each party set, in-app messages between the parties, signature timestamps, payment-sent and payment-received confirmations, dispute notes and the resulting transfer record. The counterparty sees the legal names and contact details you enter into the contract; the public character page shows only platform handles. Signed contract fingerprints are anchored (Section 9); the text itself is never published. Deal records are kept for as long as either party's account exists and for 6 years thereafter, because they evidence a transfer of rights that either party may need to prove later.
Sessions use signed cookies with expiry; login tokens are stored hashed, never in plain text; unverified email addresses are rejected outright; webhook payloads from the payment provider are signature-verified and processed idempotently. Access to production data is limited to the operator.
No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify you and the relevant authority as the law requires.
The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact [email protected] and it will be deleted.
We do not make decisions producing legal or similarly significant effects about you by automated means. Consistency scores and evidence-check results are measurements about content, presented to you and — for evidence results, if you list the character — to the public; they are not decisions taken about you. Quota and storage limits are applied automatically as contractual rules, not as profiling. The platform's dispute decisions in the deal room (Terms, Section 4B) are taken by a person.
This Section applies if you are in the European Economic Area, the United Kingdom or Switzerland, and supplements the rest of this Policy under the GDPR, the UK GDPR and the Swiss FADP.
Controller and representative. The controller is OpenStela, a sole proprietorship established in Taiwan (Section 1). We have not appointed a representative in the EU or the UK under Article 27 GDPR, relying on the exemption for occasional, low-risk processing; if our processing of data of persons in the EEA or UK ceases to be occasional, we will appoint one and name it here. We have not appointed a data protection officer; the privacy contact in Section 1 handles all requests.
Legal bases. The table in Section 4 states the Article 6 basis for each purpose. Where we rely on legitimate interests (security, abuse prevention, quality improvement from generation metadata), we have balanced those interests against your rights and concluded that the processing is limited to technical metadata and does not concern the content of your characters. You may object at any time (Section 8). Where processing rests on consent (none of the current processing does, other than your choice to list a character publicly), you may withdraw it at any time without affecting prior processing. We do not process special categories of personal data (Article 9) and ask you not to upload any.
International transfers. We are established in Taiwan, which is not the subject of an adequacy decision. Data you provide to us is processed by us in Taiwan and stored with our hosting provider in Japan (Section 5). Onward transfers to our processors in the United States (Google, Cloudflare, Polar) are made under the European Commission's Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, or under the EU-U.S. Data Privacy Framework where the provider is certified. You may request a copy of the relevant safeguards from the privacy contact.
Your rights. You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and the right not to be subject to solely automated decisions (Art. 22). Export and deletion are built into the product (Section 8); other requests go to the privacy contact and are answered within one month, extendable by two further months for complex requests with notice. You also have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work or place of the alleged infringement; a list is published by the European Data Protection Board, and in the UK the authority is the Information Commissioner's Office.
The limit on erasure. Section 9 explains that fingerprints anchored to a public blockchain cannot be erased. Those values are 32-byte hashes that contain no personal data and cannot be reversed to recover any content; everything we hold ourselves is erased on request or on account deletion, subject to the retention periods in Section 7 and Section 9A.
Retention. Section 7 and Section 9A state the retention periods. We do not retain personal data longer than stated there.
Children. The Service is not offered to anyone under 18 (Section 11), which exceeds the age-of-consent thresholds under Article 8 GDPR in every member state.
We will post any change here with a new version date, and give notice by email or in-product at least 14 days before a material change takes effect.
Contact: [email protected]
本中文版僅供參考。具法律拘束力者為英文版。
OpenStela,設立並營業於台灣之獨資商號,為本政策所述個人資料之控管者。本服務於 2026 年 9 月 16 日前名為「Avatar Lab」(avatar-lab.app);更名為 OpenStela(openstela.io)不影響控管者與使用者資料。
隱私事務聯絡:[email protected] · 一般聯絡:[email protected]
| 資料 | 來源 | 用途 |
|---|---|---|
| Email(已驗證) | 登入時由 Google 或 GitHub 提供 | 辨識帳號;額度、檔案與計費均掛於此 |
| 顯示名稱(如有) | Google 或 GitHub | 於介面顯示 |
| 內部使用者 ID(隨機字串) | 本平台產生 | 全站以此代替 email,使變更 email 不致搬動資料 |
| 帳號建立時間 | 本平台產生 | 客服與濫用處理 |
| 門牌(handle)、顯示名稱與簡介(選填) | 使用者於帳號設定輸入 | 使用者之公開創作者頁——見 3.1A |
| 通知(交易進度、訊息、上鏈、管道到期之站內紀錄) | 本平台依使用者活動產生 | 顯示於通知清單;用於寄送產品通知信 |
公開創作者頁。使用者設定門牌後,/u/<門牌> 頁面會顯示門牌、顯示名稱、簡介與使用者選擇公開刊登之角色。該頁對任何人可見(含搜尋引擎與社群平台之連結預覽),亦可被任何人分享。Email 與內部使用者 ID 絕不顯示。於帳號設定移除門牌即撤下該頁;已分享之舊連結將失效。
通知。每帳號保留最近 200 則通知,隨資料匯出一併提供、隨帳號刪除一併刪除。產品通知信(交易進度、新訊息、上鏈、管道到期、帳務與安全)作為提供本服務之一部分,經第五節所列之寄信供應商寄至登入 email。交易與訊息類每 15 分鐘至多合併寄送一封,其餘納入每日摘要。每封信均附一鍵退訂連結,亦可隨時於「帳號 → 偏好」關閉產品通知信;站內通知不受影響。行銷信另計,僅於使用者明示同意後寄送。
僅要求最小 OAuth 範圍:Google 為 openid email profile,GitHub 為 user:email。本平台不會取得使用者之密碼、通訊錄、檔案、行事曆或其他任何資料。
| 目的 | 法律依據(GDPR 第 6 條) |
|---|---|
| 提供使用者所要求之服務:帳號、儲存、產製、適配包 | 契約履行 |
| credits 計量、計費、防止額度濫用 | 契約履行;正當利益 |
| 安全、防詐、全站流量限制 | 正當利益 |
| 以生成中繼資料進行除錯與品質改善 | 正當利益——經評估影響輕微,因其涉及模型行為而非角色內容 |
| 服務性通知(帳號、計費、條款重大變更) | 契約履行 |
| 遵循法定義務,包含金流服務商保存之稅務紀錄 | 法定義務 |
以正當利益為依據者,使用者得表示反對,見第八條。
本平台不出售個人資料,亦不為廣告目的分享。所使用之處理者與供應商如下:
| 供應商 | 取得內容 | 目的 | 所在地 |
|---|---|---|---|
| Google(Gemini API) | 送交產製或分析之角色規格文字與參考/上傳圖片 | 影像產製與分析 | Google 基礎設施 |
| Google Identity/GitHub | 僅登入交換過程 | 身分驗證;回傳已驗證 email | 美國/全球 |
| Zeabur(主機) | 本服務儲存之全部資料 | 應用程式託管與持久儲存 | 日本東京 |
| Cloudflare | 請求中繼資料(IP、瀏覽器識別字串) | DNS、CDN、防護 | 全球 |
| Polar Software Inc. | Email、內部使用者 ID、交易明細 | 以 Merchant of Record 身分處理金流;Polar 為登記賣方並負責稅務 | 美國/全球 |
| Resend, Inc.(寄信服務) | Email、內部使用者 ID 及通知內容(角色名稱、交易狀態、訊息預覽) | 寄送產品通知信(3.1A) | 美國/全球 |
| Arbitrum One(公有區塊鏈) | 僅 32 bytes 之 Merkle 樹根,不含個人資料與可讀內容 | 規格雜湊之時間戳記錨定 | 公開、永久 |
法律要求、法院命令,或為主張及防禦法律請求所必要時,本平台亦得揭露資料。
使用者資料儲存於日本,並傳輸至位於美國及其他地區之供應商。傳輸源自歐洲經濟區或英國者,依各該供應商情形,以歐盟執委會標準契約條款或適足性認定為依據。
| 資料 | 期間 |
|---|---|
| 帳號與內容 | 帳號存續期間 |
| 帳號刪除後 | 保留 14 日可復原,期滿刪除;備份於再 30 日內清除 |
| 生成中繼資料(事件、漏斗) | 帳號刪除後仍保留,惟已與 email 脫鉤,僅以內部使用者 ID 為索引,供產品分析 |
| 計費紀錄 | 依稅法規定;主要由 Polar 以 Merchant of Record 身分保存 |
| 區塊鏈錨定 | 永久且不可刪除——見第九條 |
視所在地不同,使用者可能享有下列權利:查閱、更正、刪除、以可攜格式匯出、限制或反對基於正當利益之處理,以及於處理係基於同意時撤回同意。
匯出部分已內建於產品:角色規格、參考圖集與適配包得隨時自介面下載,格式為開放格式(JSON、標準影像檔、純文字)。
其餘請求,包含刪除帳號及其內容,均以申請方式辦理:請來信 [email protected],本平台於 5 個工作日內回覆確認,並於 30 日內完成。除請求顯無理由或過度者外,不收取費用。
使用者之角色如已取得角色身分證並完成錨定,其規格之雜湊值即構成某一 Merkle 樹之一部分,該樹之樹根已寫入公有區塊鏈。
本平台得應請求刪除本地端之批次紀錄——即連結該角色與樹中位置之資料;刪除後,鏈上樹根即無從再用以證明該角色之任何事項。惟請注意,此舉同時使該錨定喪失作為證據之作用。
作品。使用者於角色名下登錄作品(音訊、影片、圖文或連結)者,本平台為提供功能而儲存上傳檔案及其中繼資料(標題、說明、權利聲明、時間戳)。進入第九條所述區塊鏈錨定者僅為各作品之 SHA-256 指紋,作品本體從不上鏈。刪除作品即自儲存空間移除檔案;已錨定之指紋無法移除,公開驗證端點將註明該作品業已刪除。連結型作品僅於登錄當下擷取一次頁面或 oEmbed 快照,其後不再監看該連結。
佐證紀錄。就每件作品,本平台執行自動化檢驗以判斷其與角色之關聯(檔案日期、連結頁面所載名稱、角色所宣告之識別特徵或色票是否出現,以及——依申請——與角色自身參考圖之臉部或身形相似度量測)。檢驗結果、時間戳與方法版本以紀錄形式儲存,其指紋並予錨定。該等檢驗分析之對象為內容而非使用者本人:臉部相似度檢驗係將某一角色之圖片與同一角色之其他圖片比對,不用於識別任何自然人,本平台亦不建立真實人物之生物特徵樣板。作品如描繪真實人物,請勿對其申請視覺比對檢驗。
管道驗證。使用者驗證管道(網站或社群帳號)時,本平台儲存管道網址、一次性驗證碼、驗證日期與方法,以及找到驗證碼之頁面快照。驗證 90 日後失效。
交易室。使用者於交易室協商或簽署契約時,本平台儲存草稿與已簽契約文本、各方所設參數與條款、雙方站內訊息、簽署時間戳、已付款與已收訖之確認、爭議說明及所生之移轉紀錄。使用者填入契約之法定姓名與聯絡方式,對造可見;角色公開頁面僅顯示平台帳號。已簽契約之指紋予以錨定(第九條),文本本身絕不公開。交易紀錄於任一方帳號存續期間及其後 6 年內保存,因其為權利移轉之證據,任一方日後均可能需要舉證。
Session 使用具到期時間之簽章 cookie;登入 token 僅存雜湊值,不存明文;未驗證之 email 一律拒絕;金流服務商之 webhook 均經簽章驗證並以冪等方式處理。生產環境資料之存取限於營運者本人。
無任何系統絕對安全。事故如可能對使用者權利造成風險,本平台將依法通知使用者及主管機關。
本服務非以未滿 18 歲者為對象,本平台亦不會在知情之情況下蒐集兒童資料。如認有兒童向本平台提供個人資料,請聯絡 [email protected],本平台將予刪除。
本平台不以自動化方式作成對使用者產生法律效果或類似重大影響之決定。一致性分數與佐證檢驗結果係關於內容之量測,向使用者呈現(佐證結果於角色刊登時亦向公眾呈現),非對使用者所作之決定。額度與儲存上限係依契約規則自動套用,非剖析。交易室之爭議處置(服務條款第四之二條)由人工作成。
本條適用於位於歐洲經濟區、英國或瑞士之使用者,依 GDPR、UK GDPR 及瑞士 FADP 補充本政策其餘部分。
控管者與代表。控管者為設立於台灣之獨資商號 OpenStela(第一條)。本平台未依 GDPR 第 27 條於歐盟或英國指定代表,係援用偶發性、低風險處理之豁免;如對歐洲經濟區或英國居民資料之處理不再屬偶發性,將指定代表並於此公告。本平台未設資料保護長;一切請求由第一條之隱私事務聯絡窗口處理。
法律依據。第四條之表格載明各目的所依據之第 6 條事由。援用正當利益者(安全、濫用防制、以產製中繼資料改善品質),本平台已就該利益與使用者權利為衡量,結論為處理範圍限於技術中繼資料、不涉及角色內容。使用者得隨時提出異議(第八條)。以同意為依據者(現行處理中僅使用者選擇公開刊登角色一項),得隨時撤回,不影響撤回前之處理。本平台不處理特種個人資料(第 9 條),並請使用者勿上傳。
國際傳輸。本平台設立於台灣,台灣未獲適足性認定。使用者提供之資料由本平台於台灣處理,並儲存於位於日本之代管服務商(第五條)。向美國之處理者(Google、Cloudflare、Polar)之後續傳輸,依歐盟執委會標準契約條款(2021/914)及英國國際資料傳輸附錄為之,服務商已取得歐美資料隱私框架認證者則依該框架。使用者得向隱私事務聯絡窗口索取相關保障措施之副本。
使用者權利。使用者享有查閱(第 15 條)、更正(第 16 條)、刪除(第 17 條)、限制處理(第 18 條)、資料可攜(第 20 條)、異議(第 21 條)及不受純自動化決定拘束(第 22 條)之權利。匯出與刪除已內建於產品(第八條);其他請求向隱私事務聯絡窗口提出,於一個月內答覆,複雜請求經通知得再延長兩個月。使用者亦有權向其慣常居所地、工作地或涉嫌違法行為地之監督機關申訴;名單由歐洲資料保護委員會公布,英國之監督機關為資訊專員辦公室(ICO)。
刪除權之界限。第九條說明已錨定於公有區塊鏈之指紋無法刪除。該等數值為 32 bytes 之雜湊,不含個人資料,亦無法反推任何內容;本平台自行保有之一切資料,於請求或帳號刪除時刪除,惟受第七條及第九之一條保存期間之限制。
保存期間。第七條及第九之一條載明保存期間。本平台保存個人資料不逾該等期間。
兒童。本服務不對未滿 18 歲者提供(第十一條),高於 GDPR 第 8 條於各會員國之同意年齡門檻。
任何變更將於本頁公告並更新版本日期;重大變更將於生效前至少十四日以 email 或站內通知。
聯絡方式:[email protected]