Legal
Version 1.20 · Last updated 3 October 2026 · Effective 3 October 2026 (the change of controller in section 1 still takes effect on 12 October 2026)
版本 1.20 · 最後更新 2026 年 10 月 3 日 · 生效日 2026 年 10 月 3 日(第一條之控管者變更仍自 2026 年 10 月 12 日生效)
What changed in 1.20. New section 9B describes the OpenStela browser extension (it reads only page addresses, song titles and media file links on the sites it works on, and sends nothing until you press its button) and how we read links to social posts and download files you send from Higgsfield. Nothing new is collected about you; effective on publication.
What changed in 1.19. Section 9A: platform accounts you add to your profile are shown on your public page as soon as you add them, marked self-declared until you verify them. Remove an account to stop showing it.
What changed in 1.18. Section 9A: you may verify a YouTube channel by signing in with Google. This uses YouTube API Services; we read the list of channels your Google Account owns once, keep only the channel ID and title, and never store the access token. Optional; nothing changes if you do not use it.
What changed in 1.17. Section 3.1A: your public page and record cards show a public account number (AC-…), generated at random. From now on registration records name the registrant by that number instead of an internal identifier; it is not derived from your email or internal ID. Nothing else changes.
What changed in 1.16. Sections 1 and 12A: from 12 October 2026 the controller is Chen Law Cultural Enterprise Co., Ltd., a company incorporated in Taiwan, which takes over the Service from the sole proprietorship that has operated it so far. Your data moves with the Service unchanged: the same data, the same purposes, the same retention periods and the same contacts. Sections 5 and 9A: if you use our iPhone, iPad or Android app, push notifications you turn on are delivered through Apple Push Notification service or Google Firebase Cloud Messaging, which receive a device token, and a fee paid inside the iPhone or iPad app is processed by Apple. Nothing changes if you only use the website.
What changed in 1.15. Section 9A: optional push notifications (we store each device's push subscription until you turn it off or delete your account; messages are end-to-end encrypted through your browser's push service); series you create; characters you follow (the holder sees a count, not who); suggested accounts, based on who the people you follow follow and on recent public activity.
What changed in 1.14. Section 9A: search is open to visitors; your public profile can show links you add and your verified platform accounts; holders see how many times their items were saved (a count only, not who); the outcome of a report is sent to the reporter and to the author of removed content; your account copy now also includes mutes, saves, quotes and liked comments.
What changed in 1.13. Section 9A: posts can include images, a video and a link preview. We remove photo metadata (including location) and the location and device data in videos before storing them. Nothing is collected unless you post.
What changed in 1.12. Section 9A: the list of public profiles that liked an item, and your following and follower lists, are now visible; public profiles and posts can be searched. Like, follow and repost notifications stay in the app.
What changed in 1.11. Section 9A adds posts. Nothing is collected unless you post.
What changed in 1.10. Section 9A: reports can now be made about a post (a character or work) as well as a comment; the same data is kept on the same terms.
What changed in 1.9. Section 9A adds quotes, mentions, saves, mutes and likes on comments. Nothing is collected unless you use these features.
What changed in 1.8. Section 9A adds what we store for the new comments, likes, reposts, blocks and reports, what is public, and what happens when you delete a comment or your account. Nothing is collected unless you use these features.
What changed in 1.7. This version removes processing that no longer happens. The Service stopped generating images on 19 September 2026 and no longer sells credits, so generation events became model-processing events (model used, token counts, failure modes — from drafting a specification out of your images and from evidence checks), and image counts, consistency scores, training sets and credit balances were struck out. Images are sent to Google's Gemini API for analysis only, not for generation. Every change narrows what we collect; nothing was added. Sections 2, 3.2, 3.3, 4, 7 and 12. Effective on publication.
What changed in 1.6. Works can be registered without a character; their attribution name, claimed creation date and AI-contribution declaration are part of an anchored record and public by default. Characters with a registry number and registered works are shown on the market and on public pages unless marked private. The evidence checks no longer analyse image content (marker, palette and face-similarity checks were withdrawn on 18 September 2026). Works bound only to a character move with it when it is sold. Sections 3.1A, 4 and 9A.
1.20 版變更摘要。新增第九之二條,說明 OpenStela 瀏覽器擴充功能(僅於其支援之網站讀取網址、歌名與作品檔連結,使用者按下按鈕前不傳送任何資料),以及本平台讀取社群貼文連結、下載使用者自 Higgsfield 送出之檔案的方式。未新增任何蒐集項目;自公告日起生效。
1.19 版變更摘要。第九之一條:使用者新增之平台帳號,新增後即顯示於公開個人頁,驗證前標示為「自行填寫」;移除該帳號即不再顯示。
1.18 版變更摘要。第九之一條:得以 Google 登入驗證 YouTube 頻道。此功能使用 YouTube API 服務;本平台僅讀取一次使用者 Google 帳戶所擁有之頻道清單,只保存頻道 ID 與名稱,不保存存取權杖。此為選用功能,未使用者不受影響。
1.17 版變更摘要。第 3.1A 節:公開個人頁與紀錄卡片顯示一組隨機產生之公開帳號編號(AC-…);自此登錄紀錄以該編號記載登記人,不再使用內部識別碼;該編號無法由 email 或內部 ID 推得。其餘未變更。
1.16 版變更摘要。第一條、第十二之一條:自 2026 年 10 月 12 日起,控管者為設立於台灣之誠律文化事業有限公司,承接迄今營運本服務之獨資商號。使用者資料隨同本服務原樣移轉:資料內容、處理目的、保存期間與聯絡窗口均不變。第五條、第九之一條:使用本平台 iPhone、iPad 或 Android App 並開啟推播者,推播經由 Apple 推播通知服務或 Google Firebase 雲端通訊傳送,該等服務取得裝置權杖;於 iPhone 或 iPad App 內支付之手續費由 Apple 處理。僅使用網站者,無任何變更。
1.15 版變更摘要。第九之一條:選用之推播通知(儲存每台裝置之推播訂閱,至使用者關閉或刪除帳號為止;訊息經由瀏覽器之推播服務端對端加密傳送);使用者建立之系列;使用者追蹤之角色(持有人僅見人數,不知追蹤者);推薦追蹤,依使用者所追蹤之人之追蹤對象及近期公開活動產生。
1.14 版變更摘要。第九之一條:搜尋對訪客開放;公開個人頁得顯示使用者填寫之外部連結及已驗證之平台帳號;持有人得看見其項目被收藏之次數(僅次數,不含收藏者);檢舉處理結果通知檢舉人及被移除內容之作者;帳號副本另包含靜音、收藏、引用及對留言之喜歡。
1.13 版變更摘要。第九之一條:貼文得含圖片、影片及連結預覽。圖片之中繼資料(含拍攝地點)及影片之位置與裝置資料於儲存前移除。未發文者不因此蒐集任何資料。
1.12 版變更摘要。第九之一條:按喜歡之公開帳號名單、追蹤與粉絲名單改為可見;公開個人頁與貼文可供搜尋。喜歡、追蹤、轉發之通知僅於站內顯示。
1.11 版變更摘要。第九之一條新增貼文。未發佈貼文者,不因本版蒐集任何資料。
1.10 版變更摘要。第九之一條:檢舉除留言外,亦得針對貼文(角色或作品)為之;所存資料與保存方式相同。
1.9 版變更摘要。第九之一條新增引用轉發、提及、收藏、靜音與對留言之喜歡。未使用上述功能者,不因本版蒐集任何資料。
1.8 版變更摘要。第九之一條新增留言、喜歡、轉發、封鎖與檢舉之儲存項目、公開範圍,以及刪除留言或帳號時之處理。未使用上述功能者,不因本版蒐集任何資料。
1.7 版變更摘要。本版刪除已不再發生之處理行為。本服務已於 2026 年 9 月 19 日停止產製影像,亦不再銷售 credits,故「生成事件」改為「模型處理事件」(所用模型、token 數、失敗模式——來自自圖片草擬規格及佐證檢驗),並刪除影像數、一致性分數、訓練集與 credits 餘額等項目。圖片送交 Google Gemini API 僅供分析,不供產製。各處變更均為縮減蒐集範圍,未新增任何項目。修訂第二條、第三之二節、第三之三節、第四條、第七條及第十二條。自公告日起生效。
1.6 版變更摘要。作品得不以角色為前提登錄;其署名、聲明創作日及 AI 貢獻聲明構成錨定紀錄之一部,預設公開。已取得登錄編號之角色及已登錄之作品刊登於市集並具公開頁面,除非標為不公開。佐證檢驗不再分析圖像內容(特徵、色票與臉部相似度檢驗已於 2026 年 9 月 18 日撤除)。僅綁定於某角色之作品於該角色出售時隨同移轉。修訂第三之一 A、四、九之一節。
This English version is the legally binding one. A Traditional Chinese translation is provided for convenience only.
Chen Law Cultural Enterprise Co., Ltd. (誠律文化事業有限公司, unified business no. 62107935), a limited company incorporated in Taiwan that operates the Service under the name OpenStela, is the controller of the personal data described here. Until 11 October 2026 the controller was OpenStela, a sole proprietorship established in Taiwan; on 12 October 2026 the Service and the data it holds passed to the company unchanged — the same data, used for the same purposes, kept for the same periods, with the same contacts below. The Service was named Avatar Lab (avatar-lab.app) until 16 September 2026; the controller and your data are unchanged by the rename to OpenStela (openstela.io).
Privacy contact: privacy@openstela.io · General contact: support@openstela.io
| Data | Source | Why |
|---|---|---|
| Email address (verified) | Google or GitHub, at sign-in | Identifies the account; carries quota, files and billing |
| Display name (if provided) | Google or GitHub | Shown in the interface |
| Internal user ID (random string) | Generated by us | Used everywhere in place of the email, so that changing an email does not move your data |
| Account creation time | Generated by us | Support and abuse handling |
| Handle, display name and bio (optional) | Entered by you in Account settings | Your public creator page — see 3.1A |
| Notifications (in-product records of deal progress, messages, anchoring and channel expiry) | Generated by us from your activity | Shown in the notification list; used to send product-notice emails |
Public creator page. If you set a handle, a page at /u/<handle> shows your
handle, display name, bio, the characters that have a registry number and the works you have registered — all of
them unless you mark an item private. That page is visible to anyone,
including search engines and social-media link previews, and can be shared by anyone. Your email address and
internal user ID are never shown. Your page and your record cards also show a public account number
(AC-…), generated at random and not derived from your email or internal ID; from version 2 onward,
registration records name the registrant by this number. Records written before 28 September 2026 contain an internal identifier and are kept unchanged because anchored records cannot be altered, but public endpoints no longer return their contents; only your own Proof Pack includes the full record. Remove the handle in Account settings and the page is gone; links you have
already shared will stop working.
Notifications. We keep the most recent 200 notifications per account. They are included in your data export and deleted with your account. Product-notice emails (deal progress, new messages, anchoring, channel expiry, billing and security) are sent to your sign-in email through our email provider (section 5) as part of providing the Service. Deal and message notices are batched into at most one email per 15 minutes; everything else goes into a daily digest. Every email carries a one-click unsubscribe link, and you can turn product-notice emails off in Account → Preferences at any time; in-product notifications continue regardless. Marketing emails are separate and are sent only with your explicit opt-in.
We request only the minimum OAuth scopes: openid email profile from Google,
user:email from GitHub. We do not receive your password, contacts, files, calendar or any
other data from those providers.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the Service you asked for: accounts, storage, registration, anchoring, adapters | Performance of a contract |
| Charging deal fees, billing, preventing abuse of free registration | Performance of a contract; legitimate interests |
| Security, fraud prevention, service-wide rate limiting | Legitimate interests |
| Debugging and improving quality using model-processing metadata | Legitimate interests — assessed as low impact, since it concerns model behaviour rather than the content of your character |
| Service emails (account, billing, material changes to terms) | Performance of a contract |
| Complying with legal obligations, including tax records held by our payment processor | Legal obligation |
Where we rely on legitimate interests, you may object — see Section 8.
We do not sell personal data and do not share it for advertising. We use the following processors and providers:
| Provider | What it receives | Purpose | Location |
|---|---|---|---|
| Google (Gemini API) | Character specification text and reference/uploaded images submitted for analysis | Image analysis | Google infrastructure |
| Google Identity / GitHub | Sign-in exchange only | Authentication; returns verified email | US / global |
| Zeabur (hosting) | Everything stored by the Service | Application hosting and persistent storage | Tokyo, Japan |
| Cloudflare | Request metadata (IP, user agent) | DNS, CDN, protection | Global |
| Polar Software Inc. | Email, internal user ID, purchase details | Payment processing as Merchant of Record; Polar is the seller of record and handles tax | US / global |
| Resend, Inc. (email delivery) | Email address, internal user ID and the content of the notice (character name, deal status, message preview) | Sending product-notice emails (3.1A) | US / global |
| Apple (Apple Push Notification service, In-App Purchase) | Only if you use our iPhone or iPad app: a device token and the notification content when you turn on push; the purchase details of a fee paid in the app | Delivering push notifications; processing in-app payments | US / global |
| Google (Firebase Cloud Messaging) | Only if you use our Android app and turn on push: a device token and the notification content | Delivering push notifications | US / global |
| Arbitrum One (public blockchain) | A 32-byte Merkle root only — no personal data, no readable content | Timestamp anchoring of specification hashes | Public, permanent |
We may also disclose data where required by law, court order, or to establish or defend legal claims.
Your data is stored in Japan and transmitted to providers in the United States and elsewhere. Where a transfer is from the EEA or UK, it is made on the basis of the European Commission's Standard Contractual Clauses or an adequacy decision, as applicable to the provider concerned.
| Data | Retention |
|---|---|
| Account and content | For as long as the account exists |
| After account deletion | Held recoverable for 14 days, then deleted; backups purged within a further 30 days |
| Generation metadata (events, funnel) | Retained after account deletion in a form detached from your email, keyed only to the internal user ID, for product analysis |
| Billing records | As required by tax law — held principally by Polar as Merchant of Record |
| Blockchain anchors | Permanent and undeletable — see Section 9 |
Subject to your location, you may have the right to: access your data; correct it; delete it; export it in a portable format; restrict or object to processing based on legitimate interests; and withdraw consent where processing rests on consent.
Export is partly built into the product: character specifications, reference images and adapter packs can be downloaded from the interface at any time, in open formats (JSON, standard image files, plain text).
Export and deletion are built into the product. Settings → Your data downloads a complete copy of your account; Settings → Delete account removes it, and the account is held recoverable for 14 days before it is purged. All other requests are handled on request — write to privacy@openstela.io. We acknowledge within 5 working days and complete within 30 days. There is no charge unless a request is manifestly unfounded or excessive.
If a character of yours was issued a Character ID and anchored, a hash of its specification forms part of a Merkle tree whose root was written to a public blockchain.
We can, and on request will, delete the local batch record that connects your character to a position in that tree — after which the on-chain root can no longer be used to demonstrate anything about your character. Please note that doing so also destroys your ability to use the anchor as evidence.
Works. If you register works (audio, video, images, or links), with or without a character, we store the uploaded files and their metadata to operate the feature: title, private notes, the rights declaration, the attribution name you give (which may be a pen name), the creation date you claim, whether AI tools were used and, if so, the description of your own contribution, and timestamps. Attribution, claimed date, AI-use and contribution form the work's authorship record; only the SHA-256 fingerprint of that record and of the file — never the work or the text itself — enters the public blockchain anchoring described in Section 9, but the record cannot be edited after registration. Public by default: unless you switch the work off, its title, attribution, claimed date, contribution description, fingerprints, anchoring status and bound characters are shown on your public page and on the work's own public page, which anyone can read and share. Private notes are never shown. Deleting a work removes the file from our storage; the authorship record, any binding record and the anchored fingerprints cannot be removed, and the public verification endpoint will state the work has been deleted. For linked works we store a snapshot of the linked page or its oEmbed record fetched once at registration; we do not monitor the link afterwards. When a character is sold through the deal room, the works bound only to that character move to the buyer's account with their files and records; the authorship record continues to show your display name as the original registrant, and the buyer sees it.
Evidence records. For each work bound to a character we run automated checks on how it relates to that character: file dates against the character's registration date, the names and dates found on the linked page, the rights you declared, how long the work has been public, and whether the link falls under a channel you have verified. The results, a timestamp and the method version are stored as records and their fingerprints are anchored. These checks do not analyse image content. The marker, palette and face-similarity checks that earlier versions of this policy described were withdrawn on 18 September 2026; no biometric measurement of any kind is performed, and no biometric templates exist or are created. Earlier records of those checks remain in the registry (they are anchored and cannot be removed) but are no longer displayed.
Channel verification. If you verify a channel (a website or social account), we store the channel URL, the one-time code, the date and method of verification and a snapshot of the page where the code was found. Verification lapses after 90 days.
YouTube sign-in verification. This service uses YouTube API Services. If you verify a YouTube channel by signing in with Google, we read the list of channels owned by your Google Account once, with read-only access, to match the channel; we store only the channel ID and title, never keep the access token, and do not read your videos, comments or any other YouTube data. You can revoke this access at any time at myaccount.google.com/permissions. Use of this feature is also subject to the Google Privacy Policy and the YouTube Terms of Service.
Deal room. If you negotiate or sign a contract in the deal room, we store the draft and signed contract text, the parameters and clauses each party set, in-app messages between the parties, signature timestamps, payment-sent and payment-received confirmations, dispute notes and the resulting transfer record. The counterparty sees the legal names and contact details you enter into the contract; the public character page shows only platform handles. Signed contract fingerprints are anchored (Section 9); the text itself is never published. Deal records are kept for as long as either party's account exists and for 6 years thereafter, because they evidence a transfer of rights that either party may need to prove later.
Posts. If you post, we store the text, the time, any character or work you attach and your account, and any images, video or link you add. Images are re-encoded before they are stored, which removes their metadata (including camera details and location); in mp4 and mov videos we blank the location and device data before storing them (other embedded data in a video may remain, so check your file before posting). For a link we store the preview we fetched from that page (title, summary and a copy of its image), so viewers' browsers do not contact the linked site until they open it or play an embedded player. Posts are public on your profile and in your followers' feeds. Deleting a post deletes it; deleting your account deletes all your posts, and they are included in your account copy. Posts are not anchored.
Comments, quotes, likes, saves, reposts, mutes and blocks. If you comment or quote, we store the text, the time, the item it is on and your account; if you mention someone, they are notified unless they have muted or blocked you. Comments are public: anyone who can see the item sees the comment with your profile name, address and avatar. Likes (including likes on comments) and reposts are shown as counts, and anyone can open the list of accounts with a public profile that liked an item; a repost or quote is shown to your followers with your name. Who you follow and who follows you are shown on your public profile, together with any links you add and the platform accounts you add (marked self-declared until you verify them). Anyone, signed in or not, can search public profiles and posts by name, handle, bio or text. Saves, mutes and blocks are visible only to the account that set them; the holder of an item sees how many times it was saved, but not by whom. You may follow a character; its holder sees how many people follow it, but not who. Series you create (title, description, which works and in what order) are shown on your profile when you make them public. We suggest accounts to follow based on who the people you follow follow and on recent public activity. Push notifications are off until you turn them on for a device; we then store that device's push subscription (an address at your browser's push service and its keys) until you turn it off or delete your account, and send messages, deal steps and mentions (and likes, follows and comments only if you choose), end-to-end encrypted, through that service (for example Google, Mozilla, Apple or Microsoft). In our iPhone, iPad and Android apps, push is delivered instead through Apple Push Notification service or Google Firebase Cloud Messaging: we store the device token they issue, on the same terms, and the app tells us its version and platform (iOS or Android) with each request. When we act on a report, the reporter is told the outcome (not who was reported) and the author of removed content is told it was removed and why. If you report a comment or a post (a character or work) we store your account, the reason and any note you add, and keep the report for up to 2 years to handle it and to deal with repeated abuse. Deleting a comment deletes its text. Deleting your account deletes the text of all your comments (a comment that has replies keeps a "deleted" placeholder so the replies still make sense) and removes your follows, likes (including likes on comments), saves, reposts, mutes and blocks. Your account copy (Section 8) includes your comments and quotes, follows, likes, saves, reposts, mutes and blocks. None of this is anchored.
Browser extension. The OpenStela extension runs only on StreetVoice, Suno, SoundCloud and Higgsfield. On those pages it reads the page address, song titles and the addresses of video and image files shown on the page, so it can offer a "Register on OpenStela" button. It does not read your account on those sites, your cookies, your browsing on other sites or anything you type, and it sends nothing anywhere until you press its button. Pressing it opens OpenStela with the song or file address filled in; nothing is registered until you submit the form. The extension has no analytics and stores nothing.
Links to social posts. When you register a link to an Instagram, TikTok, X, Facebook or Threads post, we read the post's public preview (TikTok's and X's public oEmbed service, or the page's preview tags) and keep that snapshot as part of the record, as we do for other links. If the platform gives no public preview, we record only the address you supplied and mark the record "link supplied by the registrant".
Files sent from Higgsfield. When you register a Higgsfield creation through the extension, we download that file from Higgsfield's file servers using the address on the page and store it like an uploaded file. The record notes that the file came from Higgsfield; the download address itself is kept only in your account and is not shown on public pages.
Sessions use signed cookies with expiry; login tokens are stored hashed, never in plain text; unverified email addresses are rejected outright; webhook payloads from the payment provider are signature-verified and processed idempotently. Access to production data is limited to the operator.
No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify you and the relevant authority as the law requires.
The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact privacy@openstela.io and it will be deleted.
We do not make decisions producing legal or similarly significant effects about you by automated means. Evidence-check results are measurements about content, presented to you and — if you list the character — to the public; they are not decisions taken about you. Quota and storage limits are applied automatically as contractual rules, not as profiling. The platform's dispute decisions in the deal room (Terms, Section 4B) are taken by a person.
This Section applies if you are in the European Economic Area, the United Kingdom or Switzerland, and supplements the rest of this Policy under the GDPR, the UK GDPR and the Swiss FADP.
Controller and representative. The controller is Chen Law Cultural Enterprise Co., Ltd., a company incorporated in Taiwan that operates the Service as OpenStela (Section 1). We have not appointed a representative in the EU or the UK under Article 27 GDPR, relying on the exemption for occasional, low-risk processing; if our processing of data of persons in the EEA or UK ceases to be occasional, we will appoint one and name it here. We have not appointed a data protection officer; the privacy contact in Section 1 handles all requests.
Legal bases. The table in Section 4 states the Article 6 basis for each purpose. Where we rely on legitimate interests (security, abuse prevention, quality improvement from generation metadata), we have balanced those interests against your rights and concluded that the processing is limited to technical metadata and does not concern the content of your characters. You may object at any time (Section 8). Where processing rests on consent (none of the current processing does, other than your choice to list a character publicly), you may withdraw it at any time without affecting prior processing. We do not process special categories of personal data (Article 9) and ask you not to upload any.
International transfers. We are established in Taiwan, which is not the subject of an adequacy decision. Data you provide to us is processed by us in Taiwan and stored with our hosting provider in Japan (Section 5). Onward transfers to our processors in the United States (Google, Cloudflare, Polar) are made under the European Commission's Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, or under the EU-U.S. Data Privacy Framework where the provider is certified. You may request a copy of the relevant safeguards from the privacy contact.
Your rights. You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and the right not to be subject to solely automated decisions (Art. 22). Export and deletion are built into the product (Section 8); other requests go to the privacy contact and are answered within one month, extendable by two further months for complex requests with notice. You also have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work or place of the alleged infringement; a list is published by the European Data Protection Board, and in the UK the authority is the Information Commissioner's Office.
The limit on erasure. Section 9 explains that fingerprints anchored to a public blockchain cannot be erased. Those values are 32-byte hashes that contain no personal data and cannot be reversed to recover any content; everything we hold ourselves is erased on request or on account deletion, subject to the retention periods in Section 7 and Section 9A.
Retention. Section 7 and Section 9A state the retention periods. We do not retain personal data longer than stated there.
Children. The Service is not offered to anyone under 18 (Section 11), which exceeds the age-of-consent thresholds under Article 8 GDPR in every member state.
We will post any change here with a new version date, and give notice by email or in-product at least 14 days before a material change takes effect.
Contact: privacy@openstela.io
本中文版僅供參考。具法律拘束力者為英文版。
誠律文化事業有限公司(統一編號 62107935,設立於台灣之有限公司,以「OpenStela」之名營運本服務)為本政策所述個人資料之控管者。至 2026 年 10 月 11 日止,控管者為設立於台灣之獨資商號 OpenStela;自 2026 年 10 月 12 日起,本服務及其所保有之資料原樣移轉予該公司——資料內容、處理目的、保存期間及下列聯絡窗口均不變。本服務於 2026 年 9 月 16 日前名為「Avatar Lab」(avatar-lab.app);更名為 OpenStela(openstela.io)不影響控管者與使用者資料。
隱私事務聯絡:privacy@openstela.io · 一般聯絡:support@openstela.io
| 資料 | 來源 | 用途 |
|---|---|---|
| Email(已驗證) | 登入時由 Google 或 GitHub 提供 | 辨識帳號;額度、檔案與計費均掛於此 |
| 顯示名稱(如有) | Google 或 GitHub | 於介面顯示 |
| 內部使用者 ID(隨機字串) | 本平台產生 | 全站以此代替 email,使變更 email 不致搬動資料 |
| 帳號建立時間 | 本平台產生 | 客服與濫用處理 |
| 門牌(handle)、顯示名稱與簡介(選填) | 使用者於帳號設定輸入 | 使用者之公開創作者頁——見 3.1A |
| 通知(交易進度、訊息、上鏈、管道到期之站內紀錄) | 本平台依使用者活動產生 | 顯示於通知清單;用於寄送產品通知信 |
公開創作者頁。使用者設定門牌後,/u/<門牌> 頁面會顯示門牌、顯示名稱、簡介、已取得登錄編號之角色及已登錄之作品——除非使用者將個別項目標為不公開。該頁對任何人可見(含搜尋引擎與社群平台之連結預覽),亦可被任何人分享。Email 與內部使用者 ID 絕不顯示。個人頁與紀錄卡片另顯示一組隨機產生之公開帳號編號(AC-…),無法由 email 或內部 ID 推得;自第二版起,登錄紀錄以該編號記載登記人。2026 年 9 月 28 日前寫入之舊紀錄含內部識別碼,因紀錄一經上鏈即不可更改而原樣保留,但公開端點不再輸出其內容,僅持有人自行下載之存證包內含完整紀錄。於帳號設定移除門牌即撤下該頁;已分享之舊連結將失效。
通知。每帳號保留最近 200 則通知,隨資料匯出一併提供、隨帳號刪除一併刪除。產品通知信(交易進度、新訊息、上鏈、管道到期、帳務與安全)作為提供本服務之一部分,經第五節所列之寄信供應商寄至登入 email。交易與訊息類每 15 分鐘至多合併寄送一封,其餘納入每日摘要。每封信均附一鍵退訂連結,亦可隨時於「帳號 → 偏好」關閉產品通知信;站內通知不受影響。行銷信另計,僅於使用者明示同意後寄送。
僅要求最小 OAuth 範圍:Google 為 openid email profile,GitHub 為 user:email。本平台不會取得使用者之密碼、通訊錄、檔案、行事曆或其他任何資料。
| 目的 | 法律依據(GDPR 第 6 條) |
|---|---|
| 提供使用者所要求之服務:帳號、儲存、登記、上鏈、適配包 | 契約履行 |
| 成交手續費收取、計費、防止濫用免費登記 | 契約履行;正當利益 |
| 安全、防詐、全站流量限制 | 正當利益 |
| 以模型處理中繼資料進行除錯與品質改善 | 正當利益——經評估影響輕微,因其涉及模型行為而非角色內容 |
| 服務性通知(帳號、計費、條款重大變更) | 契約履行 |
| 遵循法定義務,包含金流服務商保存之稅務紀錄 | 法定義務 |
以正當利益為依據者,使用者得表示反對,見第八條。
本平台不出售個人資料,亦不為廣告目的分享。所使用之處理者與供應商如下:
| 供應商 | 取得內容 | 目的 | 所在地 |
|---|---|---|---|
| Google(Gemini API) | 送交分析之角色規格文字與參考/上傳圖片 | 影像分析 | Google 基礎設施 |
| Google Identity/GitHub | 僅登入交換過程 | 身分驗證;回傳已驗證 email | 美國/全球 |
| Zeabur(主機) | 本服務儲存之全部資料 | 應用程式託管與持久儲存 | 日本東京 |
| Cloudflare | 請求中繼資料(IP、瀏覽器識別字串) | DNS、CDN、防護 | 全球 |
| Polar Software Inc. | Email、內部使用者 ID、交易明細 | 以 Merchant of Record 身分處理金流;Polar 為登記賣方並負責稅務 | 美國/全球 |
| Resend, Inc.(寄信服務) | Email、內部使用者 ID 及通知內容(角色名稱、交易狀態、訊息預覽) | 寄送產品通知信(3.1A) | 美國/全球 |
| Apple(推播通知服務、應用程式內購買) | 僅限使用本平台 iPhone 或 iPad App 者:開啟推播時之裝置權杖及通知內容;於 App 內支付手續費之交易明細 | 傳送推播通知;處理 App 內付款 | 美國/全球 |
| Google(Firebase 雲端通訊) | 僅限使用本平台 Android App 並開啟推播者:裝置權杖及通知內容 | 傳送推播通知 | 美國/全球 |
| Arbitrum One(公有區塊鏈) | 僅 32 bytes 之 Merkle 樹根,不含個人資料與可讀內容 | 規格雜湊之時間戳記錨定 | 公開、永久 |
法律要求、法院命令,或為主張及防禦法律請求所必要時,本平台亦得揭露資料。
使用者資料儲存於日本,並傳輸至位於美國及其他地區之供應商。傳輸源自歐洲經濟區或英國者,依各該供應商情形,以歐盟執委會標準契約條款或適足性認定為依據。
| 資料 | 期間 |
|---|---|
| 帳號與內容 | 帳號存續期間 |
| 帳號刪除後 | 保留 14 日可復原,期滿刪除;備份於再 30 日內清除 |
| 生成中繼資料(事件、漏斗) | 帳號刪除後仍保留,惟已與 email 脫鉤,僅以內部使用者 ID 為索引,供產品分析 |
| 計費紀錄 | 依稅法規定;主要由 Polar 以 Merchant of Record 身分保存 |
| 區塊鏈錨定 | 永久且不可刪除——見第九條 |
視所在地不同,使用者可能享有下列權利:查閱、更正、刪除、以可攜格式匯出、限制或反對基於正當利益之處理,以及於處理係基於同意時撤回同意。
匯出部分已內建於產品:角色規格、參考圖集與適配包得隨時自介面下載,格式為開放格式(JSON、標準影像檔、純文字)。
其餘請求,包含刪除帳號及其內容,均以申請方式辦理:請來信 privacy@openstela.io,本平台於 5 個工作日內回覆確認,並於 30 日內完成。除請求顯無理由或過度者外,不收取費用。
使用者之角色如已取得角色身分證並完成錨定,其規格之雜湊值即構成某一 Merkle 樹之一部分,該樹之樹根已寫入公有區塊鏈。
本平台得應請求刪除本地端之批次紀錄——即連結該角色與樹中位置之資料;刪除後,鏈上樹根即無從再用以證明該角色之任何事項。惟請注意,此舉同時使該錨定喪失作為證據之作用。
作品。使用者登錄作品(音訊、影片、圖文或連結,不以角色為前提)者,本平台為提供功能而儲存上傳檔案及其中繼資料:標題、私人備註、權利聲明、使用者所填之署名(得為筆名)、所聲明之創作日、是否使用 AI 工具及使用者本人貢獻之說明,以及時間戳。署名、聲明創作日、AI 使用與貢獻說明構成該作品之著作紀錄;進入第九條所述區塊鏈錨定者僅為該紀錄及檔案之 SHA-256 指紋,作品本體與文字從不上鏈,惟紀錄於登錄後不得修改。預設公開:除非使用者關閉,作品之標題、署名、聲明創作日、貢獻說明、指紋、錨定狀態及所綁定之角色,顯示於使用者之公開頁及該作品之公開頁面,任何人均可閱覽與分享。私人備註絕不顯示。刪除作品即自儲存空間移除檔案;著作紀錄、綁定紀錄及已錨定之指紋無法移除,公開驗證端點將註明該作品業已刪除。連結型作品僅於登錄當下擷取一次頁面或 oEmbed 快照,其後不再監看該連結。角色經交易室出售時,僅綁定於該角色之作品連同檔案與紀錄移轉至買方帳號;著作紀錄仍以使用者之顯示名稱載明原登錄人,買方可見。
佐證紀錄。就每件綁定至角色之作品,本平台執行自動化檢驗以記錄其與該角色之關聯:檔案日期與角色登錄日之先後、連結頁面所載名稱與日期、使用者聲明之權利、作品公開之期間,以及連結是否落於使用者已驗證之管道。檢驗結果、時間戳與方法版本以紀錄形式儲存,其指紋並予錨定。該等檢驗不分析圖像內容。本政策先前版本所述之特徵、色票與臉部相似度檢驗已於 2026 年 9 月 18 日撤除;本平台不進行任何生物特徵量測,亦不存在或建立任何生物特徵樣板。先前該等檢驗之紀錄仍留存於登錄簿(已錨定、無法移除),但不再顯示。
管道驗證。使用者驗證管道(網站或社群帳號)時,本平台儲存管道網址、一次性驗證碼、驗證日期與方法,以及找到驗證碼之頁面快照。驗證 90 日後失效。
以 YouTube 登入驗證。本服務使用 YouTube API 服務。使用者以 Google 登入驗證 YouTube 頻道時,本平台以唯讀權限讀取一次該 Google 帳戶所擁有之頻道清單以核對頻道,只保存頻道 ID 與名稱,不保存存取權杖,亦不讀取影片、留言或其他 YouTube 資料。使用者得隨時於 myaccount.google.com/permissions 撤銷授權。使用此功能並受 Google 隱私權政策及 YouTube 服務條款拘束。
交易室。使用者於交易室協商或簽署契約時,本平台儲存草稿與已簽契約文本、各方所設參數與條款、雙方站內訊息、簽署時間戳、已付款與已收訖之確認、爭議說明及所生之移轉紀錄。使用者填入契約之法定姓名與聯絡方式,對造可見;角色公開頁面僅顯示平台帳號。已簽契約之指紋予以錨定(第九條),文本本身絕不公開。交易紀錄於任一方帳號存續期間及其後 6 年內保存,因其為權利移轉之證據,任一方日後均可能需要舉證。
貼文。使用者發佈貼文時,本平台儲存內文、時間、所附之角色或作品與帳號,以及其所加入之圖片、影片或連結。圖片於儲存前重新編碼,其中繼資料(含相機資訊與拍攝地點)隨之移除;mp4 及 mov 影片於儲存前清除其位置與裝置資料(影片中其他嵌入資料仍可能留存,發佈前請自行檢查檔案)。就連結,本平台儲存自該網頁擷取之預覽(標題、摘要及其圖片之副本),觀看者之瀏覽器於開啟連結或播放嵌入播放器前,不會連線至該網站。貼文於其個人頁及其追蹤者之動態公開顯示。刪除貼文即予刪除;刪除帳號時刪除其全部貼文;帳號副本包含貼文。貼文不予錨定。
留言、引用、喜歡、收藏、轉發、靜音與封鎖。使用者留言或引用轉發時,本平台儲存內文、時間、所屬項目與帳號;提及他人時,除對方已靜音或封鎖該使用者外,對方會收到通知。留言為公開:凡能看見該項目者,均可看見留言及使用者之個人頁名稱、網址與頭貼。喜歡(含對留言之喜歡)與轉發以數量顯示,任何人並得查看對某項目按喜歡之公開帳號名單;轉發與引用轉發並會連同使用者名稱顯示予其追蹤者。使用者之追蹤名單與粉絲名單,以及其自行填寫之外部連結與新增之平台帳號(驗證前標示為「自行填寫」),顯示於其公開個人頁。任何人(無論是否登入)得依名稱、帳號、簡介或內文搜尋公開個人頁與貼文。收藏、靜音與封鎖僅設定之帳號可見;項目之持有人得看見該項目被收藏之次數,但不知收藏者為何人。使用者得追蹤角色,角色持有人僅見追蹤人數,不知追蹤者為何人。使用者建立之系列(名稱、說明、所含作品及其順序)於設為公開時顯示於其個人頁。本平台依使用者所追蹤之人之追蹤對象及近期公開活動推薦可追蹤之帳號。推播通知預設關閉,使用者於特定裝置開啟後,本平台儲存該裝置之推播訂閱(瀏覽器推播服務之位址及金鑰),至使用者關閉或刪除帳號為止,並經由該推播服務(例如 Google、Mozilla、Apple 或 Microsoft)以端對端加密方式傳送私訊、交易待辦及提及之通知(讚、追蹤及留言僅於使用者選擇時傳送)。於本平台 iPhone、iPad 及 Android App 中,推播改經由 Apple 推播通知服務或 Google Firebase 雲端通訊傳送:本平台依相同條件儲存該等服務發給之裝置權杖,App 並於每次請求時告知其版本及平台(iOS 或 Android)。本平台處理檢舉後,將處理結果通知檢舉人(不揭露被檢舉人),並於內容經移除時通知作者及其理由。使用者檢舉留言或貼文(角色或作品)時,本平台儲存其帳號、檢舉原因及補充說明,保存至多 2 年,以處理該檢舉及因應重複濫用。刪除留言即刪除其內文;刪除帳號時,刪除該帳號全部留言之內文(有回覆之留言保留「已刪除」字樣,以免回覆失去脈絡),並移除其追蹤、喜歡(含對留言之喜歡)、收藏、轉發、靜音與封鎖。帳號副本(第八條)包含使用者之留言與引用、追蹤、喜歡(含對留言之喜歡)、收藏、轉發、靜音與封鎖。上開資料均不予錨定。
瀏覽器擴充功能。OpenStela 擴充功能僅於街聲、Suno、SoundCloud 及 Higgsfield 執行。於上述網頁,僅讀取網址、歌名及頁面上顯示之影片與圖片檔案位址,用以提供「登記到 OpenStela」按鈕;不讀取使用者於上述網站之帳號、cookie、其他網站之瀏覽紀錄或任何輸入內容,且於使用者按下按鈕前不傳送任何資料。按下按鈕後,會開啟 OpenStela 並帶入該歌曲或檔案位址;使用者送出表單前不會登記任何內容。擴充功能不含分析工具,亦不儲存任何資料。
社群貼文連結。使用者登記 Instagram、TikTok、X、Facebook 或 Threads 貼文之連結時,本平台讀取該貼文之公開預覽(TikTok 與 X 之公開 oEmbed 服務,或該頁面之預覽標籤),並如同其他連結,將該快照保存為紀錄之一部分。平台未提供公開預覽者,本平台僅記錄使用者提供之網址,並將該紀錄標示為「作者自行提供的連結」。
自 Higgsfield 送出之檔案。使用者經擴充功能登記 Higgsfield 作品時,本平台依頁面上之位址自 Higgsfield 之檔案伺服器下載該檔案,並比照上傳檔案保存。紀錄載明該檔案來自 Higgsfield;下載位址本身僅保存於使用者帳號內,不顯示於公開頁面。
Session 使用具到期時間之簽章 cookie;登入 token 僅存雜湊值,不存明文;未驗證之 email 一律拒絕;金流服務商之 webhook 均經簽章驗證並以冪等方式處理。生產環境資料之存取限於營運者本人。
無任何系統絕對安全。事故如可能對使用者權利造成風險,本平台將依法通知使用者及主管機關。
本服務非以未滿 18 歲者為對象,本平台亦不會在知情之情況下蒐集兒童資料。如認有兒童向本平台提供個人資料,請聯絡 privacy@openstela.io,本平台將予刪除。
本平台不以自動化方式作成對使用者產生法律效果或類似重大影響之決定。佐證檢驗結果係關於內容之量測,向使用者呈現(角色刊登時亦向公眾呈現),非對使用者所作之決定。額度與儲存上限係依契約規則自動套用,非剖析。交易室之爭議處置(服務條款第四之二條)由人工作成。
本條適用於位於歐洲經濟區、英國或瑞士之使用者,依 GDPR、UK GDPR 及瑞士 FADP 補充本政策其餘部分。
控管者與代表。控管者為設立於台灣、以 OpenStela 之名營運本服務之誠律文化事業有限公司(第一條)。本平台未依 GDPR 第 27 條於歐盟或英國指定代表,係援用偶發性、低風險處理之豁免;如對歐洲經濟區或英國居民資料之處理不再屬偶發性,將指定代表並於此公告。本平台未設資料保護長;一切請求由第一條之隱私事務聯絡窗口處理。
法律依據。第四條之表格載明各目的所依據之第 6 條事由。援用正當利益者(安全、濫用防制、以模型處理中繼資料改善品質),本平台已就該利益與使用者權利為衡量,結論為處理範圍限於技術中繼資料、不涉及角色內容。使用者得隨時提出異議(第八條)。以同意為依據者(現行處理中僅使用者選擇公開刊登角色一項),得隨時撤回,不影響撤回前之處理。本平台不處理特種個人資料(第 9 條),並請使用者勿上傳。
國際傳輸。本平台設立於台灣,台灣未獲適足性認定。使用者提供之資料由本平台於台灣處理,並儲存於位於日本之代管服務商(第五條)。向美國之處理者(Google、Cloudflare、Polar)之後續傳輸,依歐盟執委會標準契約條款(2021/914)及英國國際資料傳輸附錄為之,服務商已取得歐美資料隱私框架認證者則依該框架。使用者得向隱私事務聯絡窗口索取相關保障措施之副本。
使用者權利。使用者享有查閱(第 15 條)、更正(第 16 條)、刪除(第 17 條)、限制處理(第 18 條)、資料可攜(第 20 條)、異議(第 21 條)及不受純自動化決定拘束(第 22 條)之權利。匯出與刪除已內建於產品(第八條);其他請求向隱私事務聯絡窗口提出,於一個月內答覆,複雜請求經通知得再延長兩個月。使用者亦有權向其慣常居所地、工作地或涉嫌違法行為地之監督機關申訴;名單由歐洲資料保護委員會公布,英國之監督機關為資訊專員辦公室(ICO)。
刪除權之界限。第九條說明已錨定於公有區塊鏈之指紋無法刪除。該等數值為 32 bytes 之雜湊,不含個人資料,亦無法反推任何內容;本平台自行保有之一切資料,於請求或帳號刪除時刪除,惟受第七條及第九之一條保存期間之限制。
保存期間。第七條及第九之一條載明保存期間。本平台保存個人資料不逾該等期間。
兒童。本服務不對未滿 18 歲者提供(第十一條),高於 GDPR 第 8 條於各會員國之同意年齡門檻。
任何變更將於本頁公告並更新版本日期;重大變更將於生效前至少十四日以 email 或站內通知。
聯絡方式:privacy@openstela.io