1. Scope and controller
Dramabyte Limited ([TODO: Hong Kong registered address]) is the controller of the personal data described here. This policy explains what we collect when you use our websites and services (the "Service"), why we collect it, who we share it with, how long we keep it, and the choices you have.
It applies to visitors who only watch free episodes, to registered users, and to people who buy Gems or subscribe. It does not apply to third-party sites we link to.
2. What we collect
Account data. Your email address; the sign-in method you used (magic link or Google) and, for Google, your Google account identifier; the timestamps of sign-ins; and, if you delete your account, the fact and time of deletion. We never receive your Google password. We do not use passwords at all.
Viewing and playback data. Which episodes you open, playback heartbeats (approximately every 15 seconds while playing), the position you reached, whether you finished an episode, playback errors, and whether you watched as a free viewer, with an unlocked episode, or under a subscription. We use this to resume playback, to rank the catalogue, and to calculate what we owe the studios that license each title.
Device and connection data. IP address, the country and region we infer from it, user agent (browser, operating system, device type), screen size, referring page, and language preference.
Anonymous identifier. A random identifier stored in your browser (anon_id) that lets us keep your place and your list before you sign in, and connect a pre-sign-in session to your account when you do sign in.
Attribution data. UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) and any referral code (ref) present in the link you arrived on, plus the landing page. We keep the first touch to attribute sign-ups and purchases to a campaign or partner.
Purchase and entitlement data. Gem purchases, bonus grants, unlocks, refunds, chargebacks, balances, subscription status and billing period, plus the payment processor's identifiers for the payment. We do not receive or store your full card number, expiry date or CVC — those are collected directly by Stripe on its own hosted checkout page.
Consent records. For auto-renewing subscriptions we store the text of the terms you accepted (as a hash), the time and your IP address, because consumer-protection law requires us to be able to prove what was disclosed.
Support correspondence. Emails you send us and our replies.
3. Why we use it
- to provide the Service: play video, remember where you stopped, keep your list, and apply your entitlements;
- to take payment, deliver Gems, run subscriptions, and keep an accurate ledger of every balance change;
- to prevent fraud and abuse: detect stolen cards, multi-account promotion abuse and paywall circumvention, and to defend chargebacks (a chargeback defence typically requires showing purchase and viewing records);
- to rank and curate the catalogue and to decide what to produce next, using aggregated statistics;
- to calculate royalties owed to the studios that license each series (they receive aggregated, per-title figures, never your identity);
- to send you transactional email: sign-in links, purchase receipts, subscription confirmations, renewal-price reminders and price-change notices;
- to meet legal, accounting and tax obligations and to establish, exercise or defend legal claims;
- to improve reliability and performance, and to debug errors.
Where a law such as the GDPR or UK GDPR applies to you, our legal bases are: performance of a contract (providing the Service and processing payments); legal obligation (tax, accounting, consumer-protection records); legitimate interests (fraud prevention, security, product analytics, royalty accounting); and consent (any optional marketing or advertising measurement, which you can withdraw at any time).
5. Viewing records and advertising (VPPA)
We do not sell your viewing history, and we do not disclose personally identifiable viewing records to advertising platforms.
If we run advertising campaigns, conversion events sent to ad platforms are limited to de-identified signals (for example "a purchase happened") and are stripped of any title, episode number or content-bearing URL before they are sent. Any measurement that would associate you with a specific title requires your separate, informed, written consent, which you can withdraw at any time.
This reflects the US Video Privacy Protection Act and equivalent state laws. If you believe your viewing records were disclosed contrary to this section, contact privacy@aidramas.example.
6. Who we share data with
We do not sell personal data. We share it only with service providers who process it on our instructions, and only as needed:
- bunny.net (video hosting and CDN) — receives your IP address, user agent and the video requests your player makes, in order to deliver the stream. Paid episodes are served with short-lived signed URLs.
- Stripe (payments) — collects and stores your card details directly on its own checkout page and returns to us only the payment result, an identifier, the billing email, the last four digits and card brand. Stripe acts as an independent controller for fraud prevention and regulatory purposes under its own privacy policy.
- Google (sign-in) — if you choose Google sign-in, Google confirms your email address and account identifier to us.
- Cloudflare (CDN, DNS and security) — processes request metadata to serve pages and block attacks.
- Our transactional email provider — receives your email address and the content of sign-in and receipt emails.
- Studios and content partners — receive aggregated, per-title performance and royalty figures only, never your identity or your individual viewing history.
We may also disclose data where required by law, court order or a valid request from a competent authority; to protect our rights, safety or property; or in connection with a merger, acquisition or sale of assets (in which case we will notify you and this policy will continue to apply until replaced).
7. Where data is processed
Our application servers and database are hosted in Hong Kong. Our CDN, payment and email providers process data in multiple countries, including the United States and the European Union.
Where a transfer is subject to the GDPR, it is made under an adequacy decision or Standard Contractual Clauses with appropriate safeguards. You may ask us for details.
8. How long we keep it
- Raw playback heartbeats: 14 days. After that they are deleted; only daily per-episode aggregates survive.
- Daily aggregated viewing statistics: up to 24 months, retained in a form that supports catalogue decisions and royalty accounting.
- Financial records (Gem purchases, ledger entries, refunds, chargebacks, invoices): retained for the period required by Hong Kong company and tax law — at least 7 years from the end of the relevant financial year.
- Subscription consent records: the longer of 3 years, or 1 year after the subscription ends, as required by US automatic-renewal laws.
- Account data: for as long as your account exists. After you delete your account we remove or irreversibly de-identify your account data within 30 days, except for the financial and consent records above and anything we must keep to defend a legal claim.
- Support emails: 24 months.
- Security and access logs: up to 90 days.
9. Your rights and choices
You can, at any time:
- See your data — your balance, ledger, unlocked episodes and subscription status are shown on your Account page;
- Delete your account — self-service from your Account page. Deletion is irreversible and forfeits any remaining Gems (see the Terms and Refund Policy);
- Request a copy, correction, or restriction of your personal data, or object to processing based on legitimate interests, by emailing privacy@aidramas.example;
- Withdraw consent you have given, without affecting processing already carried out;
- Cancel a subscription online at any time from your Account page.
California residents. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. You have the rights to know, delete, correct, and to non-discrimination for exercising them. You may use an authorised agent.
We answer verified requests within 30 days (or 45 days where the CCPA allows an extension). We verify requests by sending a confirmation link to the email address on the account.
If you are in the EEA or the UK you may also complain to your local supervisory authority. In Hong Kong you may complain to the Office of the Privacy Commissioner for Personal Data.
10. Children
The Service is not directed to children under 13 and we do not knowingly collect personal data from them. If we learn that we have collected such data, we delete the account and its data promptly.
If you are a parent or guardian and believe a child has given us personal data, email privacy@aidramas.example and we will act on it.
11. Security
We use TLS for all traffic, signed and short-lived session tokens, signed playback URLs for paid content, access controls on the administrative interface, encrypted backups, and least-privilege access for staff. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant regulator where the law requires it.
12. Changes to this policy
We may update this policy. Material changes will be announced by email or in the Service before they take effect. The date at the top of this page shows the current version.
13. Contact
Privacy enquiries and data-rights requests: privacy@aidramas.example.
Dramabyte Limited, [TODO: Hong Kong registered address]. [TODO(法务): EU/UK representative if required]
