Privacy Policy
Effective date: July 3, 2026
Welcome to SenseNova!
Tetras.AI HongKong Co., Limited (“we”, “us”, and/or “our”) operates the SenseNova website (the “Services”). This Privacy Policy (the “Policy”) describes how we collect, store, use, and share information through our Services.
We care about the protection and confidentiality of your information. We process your personal information only as described in this Policy. If you have any questions regarding this Policy, please contact us according to the information listed below under the Section “Contact Us”.
1. Personal Information We Collect
For the purpose of this Policy, “personal information” means any information relating to an identified or identifiable individual. In certain jurisdictions, this may be referred to as “personal data”. However, for the sake of consistency, this Policy will use the term “personal information” throughout to refer to such data. To the extent that our processing of your personal information is subject to certain data privacy protection laws (“applicable laws”), we will also notify you about the legal basis on which we process your personal information and your rights under such laws.
1.1. Information you provide
Through your use of the Services, you may provide us with the following information:
- Account Data: When you register for or login to your account, we collect your account name, email address. If you choose to log in using a third party service, we collect information about the service you used to log in and - depending on your chosen account settings with the third party service, e.g. Google, details about you, including your user name, email address, or unique user identifiers are automatically acquired by the website after your authorization.
- Inputs and Outputs: When you use our Service, we process the input data you submit (including but not limited to text, voice, or other content, “Inputs”) and the corresponding outputs generated (“Outputs”) based on your Inputs. You are strongly advised not to include any sensitive information in your Inputs; Please do not include personal information of other individuals in your Inputs unless you have provided all required notices, obtained all required consents, or otherwise have a lawful basis to do so under applicable laws.
1.2. Information we collect from third parties
- Third-party Account Data: When you sign in using your Google or GitHub account, we will obtain the public information that you have agreed to on the authorization page (including your nickname, profile picture, email address, and unique identifier). This information is used solely for identity verification and maintaining your login session.
1.3. Information we collect automatically
We automatically log the following information about your interactions over time with our Services:
- Device and Network Information: In accordance with the permissions set on your device or browser, your device or browser automatically provides us with information regarding the timing and manner in which you install, access, or use our Services. This information may include details such as your device type, operating system, browser data and referring web pages, mobile network and connection details, mobile carrier or internet service provider (ISP), time zone configuration, IP address (including location information inferred from your IP address), and various identifiers (such as device or advertising identifiers, probabilistic identifiers, and other unique personal or online identifiers).
- Service Usage Information: We collect information about your use of the Services, such as the dates and times of access, browsing history, information about the links you click, pages you view, and other information about how you use the Services, and technology on the devices you use to access the Services.
- Log Information: We collect information about how our Services are performing when you use them. This information includes log files. In the event that you or your device encounters an error, we may collect details about the error, the time it occurred, the feature in use at that moment, the application’s state when the error happened, and any communications or content present at the time of the error.
1.4. Cookies and other similar technologies
We and our service providers may use cookies or similar technologies to collect the above data when you access our services. Cookies are text files stored on your device that uniquely identify your browser or store information or settings within the browser to help you navigate efficiently between pages, remember your preferences, enable features, and assist us in understanding user activity and patterns.
We will not use cookies for any purposes other than those described in this policy. You may manage or delete cookies according to your preferences. You can clear all cookies saved on your computer or mobile device, and most web browsers have features to block cookies. However, if you do so, you will need to manually change user settings each time you visit our services. For more information, please see our Cookie Policy.
2. How We Use Your Information
We will only use your personal information when the applicable laws allow us to. Our legal bases for collecting and using the personal information described in this Policy depends on the personal information we collect and the specific context in which we collect the information:
- We need to perform a contract with you;
- You have given us consent to do so;
- In specific jurisdictions, processing your personal information is in our legitimate interests, including
- providing, maintaining and marketing our Services;
- detecting, preventing and enforcing violations of our Terms of Use including misuse of services, fraud, abuse, and other trust and safety protocols; and
- protecting our legal rights and the rights of others.
- We need to comply with our legal obligations under the applicable laws.
The purposes for which we process personal information, subject to applicable laws, and the legal basis on which we perform such processing, are as follows:
| Purpose | Type of Personal Information | Legal Basis |
|---|---|---|
| To provide you with functions related to user account management, such as account registration, account deletion, and account login | Account Data; Third-party Account Data | Performance of contract |
| To provide the core functionality of the Services, so that you could interact with the Services | Inputs and Outputs; Service Usage Information; Log Information | Performance of contract |
| To maintain, secure, and enhance our Services, including the development and refinement of our underlying technologies and AI models | De-identified Inputs and Outputs | Legitimate interests & Consent, where required by applicable laws |
| To monitor and protect the Services to ensure the normal operation of the Services you use, including preventing fraud, criminal activity, and misuse of our Services | Account Data; Inputs and Outputs; Third-party Account Data; Device and Network Information; Service Usage Information; Log Information | Performance of contract & Legitimate interests |
| To comply with legal obligations, and defend against legal claims and disputes | Account Data; Inputs and Outputs; Third-party Account Data; Device and Network Information; Service Usage Information; Log Information | Legal Obligations, Legitimate interests, Consent, where required by applicable laws |
3. How We Share Your Personal Information
In order to provide you with more comprehensive and high-quality Services, we will authorize our commercial partners to provide certain services to you. In such cases, we may share some of your personal information with our partners.
We will only share your personal information for lawful, legitimate, necessary, specific, and explicit purposes, and we will only share the personal information required to provide the Services. We will require our partners, through agreements, to retain data only for the necessary period and to implement adequate security measures to protect data security.
We will disclose personal information to the following categories of third parties for the purposes explained in this Policy:
- Affiliates and corporate partners. We disclose the categories of personal information described above between and among our affiliates and related entities, for legitimate business purposes and the operation of the Services, in accordance with applicable laws.
- Service providers and business partners. Third-party service providers who provide us with technology services (such as cloud storage service, cybersecurity provider) and business support (such as content security screening provider) may need to process your data. These third parties will process your personal information on our behalf under relevant contracts.
- Law enforcement agencies, public authorities or other judicial bodies and organizations. We disclose your personal information if we are legally required to do so, or if we have a good faith belief that such use is reasonably necessary to comply with a legal obligation, process or request; enforce our Terms of Use and other terms, policies, and standards, including investigation of any potential violation thereof; detect, prevent or otherwise address security, fraud or technical issues; or protect the rights, property or safety of us, our users, a third party or the public as required or permitted by applicable laws (including exchanging information with other companies and organizations for the purposes of fraud protection).
- Change of corporate ownership. If we are involved in a merger, acquisition, bankruptcy, reorganization, partnership, asset sale or other transaction, we may disclose your Information as part of that transaction.
4. How Will We Transfer Your Data Around the World
Your personal data may be processed or transferred outside the country or region where you reside. Currently, your personal information will be stored in our servers located in Malaysia. Due to the international nature of our business, your personal data may also be transferred to, accessed by our affiliates or third-party service providers and business partners located in Mainland China, in connection with the purposes set out in this Policy. Accordingly, your personal data may be transferred to and processed in jurisdictions that may have different laws and data protection compliance requirements to those that apply in the jurisdiction in which you are located.
Besides, in the event of an international transfer of personal information, when required by applicable laws, we will provide an adequate level of protection for your personal information using various means, including implementing Standard Contractual Clauses or data transfer agreements that comply with applicable laws between our affiliates and third parties or any other lawful approach that permits the lawful transfer of personal data from those countries.
5. How We Secure Your Information
We place utmost importance on personal information security and implement stringent measures to protect user data. We employ advanced security technologies including encrypted transmission and storage, access control, and HTTPS protocols.
Our server systems undergo rigorous security hardening and upgrades. Employees are subject to the principle of least privilege and receive comprehensive confidentiality training. The company has established cybersecurity emergency response protocols, conducts regular drills, and ensures timely incident response and user notification when necessary.
We also remind users to remain vigilant about network environment risks, recommending the use of strong passwords and exercising caution when sharing personal information. We are committed to continuously enhancing security safeguards. However, users should also strengthen self-protection awareness and provide personal information only when absolutely necessary.
6. How Do We Retain Your Personal Information
We adhere to retention policies for the personal information we collect to ensure that it is not retained longer than necessary for the intended purpose. Upon expiration of the retention period, we will either delete or anonymize your personal information. Measures will be taken to render the information irrecoverable or irreproducible.
If you deactivate your account, delete personal information, or the retention period is expired, we will delete or anonymize your personal information, except in the following cases:
- Compliance with legal requirements regarding data retention according to the applicable laws.
- Extension of the period for financial, audit, dispute resolution, or other legitimate purposes.
When assessing how long your personal information is retained, we consider criteria such as: (i) the nature of the personal information and the activities involved; (ii) when and for how long you use the Services; and (iii) our legitimate interests and our legal obligations.
7. Your Rights and Choices
Subject to applicable law and depending on where you reside, if you use the Service directly, you may have some rights regarding your personal information, as described below. If you have any other requests relating to your personal information, please contact us using the contact details listed in the Section “Contact Us”.
If you are an end user of an application, product, or service developed or powered by our Customer (which may include enterprise users, individual developers, or organizations utilizing SenseNova), please note that such Customer acts as the independent data controller of your personal data. Please direct your privacy rights requests to the relevant developer. We will assist such developer in responding to your requests as required by applicable laws and our agreement with that developer.
7.1 Data Access and right to obtain a copy
You may have the right to know what personal information we process about you, including the categories of personal information, the business or commercial purposes for collection, the categories of third parties to whom we disclose it and other information according to the applicable law.
You may have the right to access and obtain a copy of your personal information in accordance with the applicable laws. Where applicable, we will provide the information in a portable, machine-readable, readily usable format.
7.2 Data Correction
You may have the right to request that we correct inaccurate personal information that we retain about you, subject to certain exceptions.
7.3 Data Deletion
You have the right to delete your account and erase your personal information. Upon deleting your account, all your personal information will be deleted. Additionally, you may also request deletion of the personal information you provide by contacting us. If some of your personal information cannot be deleted, we will inform you of the reasons for not taking action.
Please note that we reserve the right to retain some of your personal information where there are valid grounds for us to do so under applicable laws.
7.4 Withdrawal of Consent
Where we process your personal information on the basis of your consent, you may withdraw your consent by contacting us. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
7.5 Objection to the Processing
Subject to applicable laws, you may object to the processing of your personal information based on our legitimate interests where there are grounds relating to your particular situation by contacting us. Please note that we may have an overriding legitimate interest to keep processing your personal information, but we will let you know where this is the case.
7.6 Restriction to the Processing
If you would like to restrict our processing of your personal information, you may contact us. You have the right to restrict the processing of your data where one of the following applies:
- the processing is unlawful and you oppose the erasure of relevant personal information;
- for the purpose of establishment, exercise or defense of legal claims, you request us to retain your personal information that we were supposed to delete;
- your objection regarding the accuracy of your personal information is pending our verification;
- your request to object to the processing of your personal information is pending our verification.
7.7 Data Portability
Data portability is the ability to obtain some of your information in a format you can move from one service provider to another (for instance, when you transfer your mobile phone number to another carrier). Depending on the context, this applies to some of your information, but not to all of your information. Should you request it, we will provide you with an electronic file of the available information, as required by applicable data protection laws.
7.8 Lodge a complaint with your local data protection authority
Subject to applicable data protection laws, you may have the right to submit your complaint to the local data protection authority where you reside if you consider that the processing of your personal information infringes any applicable data protection laws.
7.9 Not to be subject to automated decision-making
You shall have the right not to be subject to automated decision-making, which will affect you to a substantial degree. You also have the right to review your personal data used for automated decision-making, to question the results, to be informed of the reasons of the resulting decision, and to be informed of what actions you can take to secure a different decision.
7.10 Other Rights
Depending on your jurisdiction, you may be entitled to additional rights in relation to your personal information. If you would like to contact us to exercise one or more of these rights, to ask a question about these rights or any other provision of this Policy or about our processing of your personal information, or to file a complaint about how we process your personal information, you may use the contact details provided in Section “Contact Us” below.
When submitting a right request, please specify the scope and basis of your request and provide us with the necessary information to verify your identity. We may contact you to confirm your identity in order to handle your request. We will typically respond to your request no later than the timeframe required by applicable laws.
8. Use by Minors
Our Services are not provided towards, and we do not knowingly collect, sell, or share any information about minors, as defined under applicable laws in the jurisdiction where the user is located. If you become aware that a minor has provided any personal information to us while using our Services, please email us at the contact details provided in “Contact Us” below, and we will investigate the matter and, if appropriate, delete the personal information.
9. Changes to This Privacy Policy
The Services and our business may change from time to time. As a result, at times it may be necessary for us to make changes to this Policy. We recommend that you regularly check the latest version of this Policy within the Service. If there are any substantial changes to this Policy, depending on the nature of such changes, we will notify you in advance through pop-ups, push notifications, and other appropriate means.
10. Contact Us
For more information about your data subject rights, or how we process your personal information, please contact us by using the information below.
Controller: Tetras.AI HongKong Co., Limited
Address: SUITE 6503, 65/F, CENTRAL PLAZA, 18 HARBOUR ROAD, WAN CHAI, HONG KONG.
Contact Details: sensenova@sensetime.com
Data Processing Addendum for API Services
This Data Processing Addendum (“DPA”) governs the processing of the data provided by individual developer, business, and enterprises users (“Customer”, “you”, and/or “your”) through API Services offered by SenseNova, along with its affiliates (collectively referred to as “Company”, “we”, “us”, and/or “our”) on our platform (“SenseNova”, “we”, “our”, and/or “platform”) and is hereby incorporated into the Privacy Policy.
Customer and Company each agree to comply with their respective obligations under applicable data privacy and data protection laws (collectively, “Data Protection Laws”) in connection with the API Services.
Customer is the ones that determine the purposes and means for which Customer Data (as defined below) is processed (“Data Controller”), whereas we processes Customer Data in accordance with the Data Controller’s instructions and on behalf of the Data Controller (as a “Data Processor”). “Data Controller” and “Data Processor” also mean the equivalent concepts under Data Protection Laws.
For the purposes of this DPA, (i) “Personal Data” has the meaning assigned to the term “personal data” or “personal information” under applicable Data Protection Laws; and (ii) “Customer Data” means Personal Data that Customer provide to us that we process on behalf of Customer to provide the Services. We will process Customer Data as Customer’s Data Processor to provide or maintain the Services and for the purposes set forth in this DPA, the Terms of Service and/or in any other applicable agreements between Customer and us.
1. Obligations of the Company
As a Data Processor, We agree to:
- Process Customer Data only i) on Data Controller’s behalf for the purpose of providing and supporting API Services; (ii) in compliance with the written instructions received from Data Controller; and (iii) in a manner that provides no less than the level of privacy protection required by Data Protection Laws.
- Adopt reasonable and appropriate organizational and institutional measures to safeguard the security of Customer Data in accordance with the requirements under Data Protection Laws.
- Provide reasonable assistance to the requests from Data Controller to fulfill its legal obligations in accordance with Data Protection Laws.
- Inform Data Controller if we receive any complaint or request (in particular, requests for access to, rectification or blocking of Customer Data) directly from Customer’s data subjects.
- Inform Data Controller if we receive any legally binding request to disclose Customer Data to a law enforcement authority unless otherwise prohibited by laws.
2. Obligations of the Customer
- Customer shall comply with all Data Protection Laws.
- Customer represents, warrants and covenants that it has and shall maintain throughout the term all necessary rights, consents and authorizations to provide the Customer Data to us and to authorize us to use, disclose, retain and otherwise process Customer Data as contemplated by this DPA, the Terms of Service and/or other processing instructions provided to us.
- Customer shall be solely responsible for performing any of its obligations with regard to any requests from Customer’s data subjects.
- Customer shall not provide Customer Data to us except through agreed mechanisms.
3. International Data Transfer
- Customer Data may be processed or transferred outside the country or region where Customer reside. Currently, Customer Data will be stored in our servers located in Malaysia. To support our Services, we may also use computing resources in Mainland China to process the Inputs contained in the Customer Data and generate Outputs.
- We implement appropriate safeguards to ensure that any cross-border transfer of Customer Data complies with applicable Data Protection Laws and legally recognized transfer mechanisms.
4. Data Return and Deletion
- This DPA shall remain in effect as long as we carry out Customer Data processing operations on Data Controller’s behalf or until the termination of the Terms of Service.
- We will store any of the content the Customer or its End Users provide or generate while using our Services. This includes any texts, or other data you input. We will not use such Customer Data to train our models unless we have obtained Customer’s explicit consent.
- For Customer Data we will temporarily store such data for the purposes of providing the API Services or in compliance with applicable laws. We will delete such data after the termination of the Terms of Service unless otherwise required by applicable laws.