Operator and scope
鹤瞰科技有限公司 operates this website and the related services under the Baihe Labs brand. It is the personal information handler described in this policy. Use the contact page for privacy questions or rights requests.
This policy covers the public website, Account Center, Workspace, DataCraft, Skills, Inspiration, Oracle, Garden, MBTI Lite, and Work Style. A third-party website or service has its own rules, which this policy does not replace.
Information we handle
Each feature handles a different set of information. Listing a category here does not mean we collect it when you do not use the relevant feature. The current service handles the following categories.
- Contact requests: name, contact details, request type, message, and form source. The service also stores hashes of the network address and browser identifier for rate limiting, abuse prevention, and troubleshooting.
- Accounts and security: username, email, display name, password hash, profile fields, account status, session times, and hashes of the network address and browser identifier. Login attempts and security events create security records.
- Workspace: tasks, client and contact records, communication notes, proposals, tags, attachment descriptions, saved outputs, and links between those records. Only a signed-in account can read Workspace data linked to that account.
- DataCraft: the current page reads CSV, TSV, or TXT files in the browser, then sends the table text, title, and analysis goal to the server. The server creates an analysis job and stores field profiles, quality results, a brief, and export content. These records are created even when “Save to Workspace” is not selected; that option only controls the additional Workspace link.
- Skills: every run stores the input, structure settings, output, and execution metadata. A guest run also creates a server-side record. “Save to Workspace” only controls whether the result is also linked to the signed-in account's Workspace.
- Reflection and entertainment tools: the current Inspiration, MBTI Lite, and Work Style flows store a result summary and network-address hash, not the raw answers submitted by the page. Oracle creates a cast session and card for every cast; it stores the question text and a Workspace record only when a signed-in user chooses to save. Garden stores ratings, notes, and a state card only when a signed-in user chooses to save.
Why we handle information
We handle this information to provide a feature you request, respond to an enquiry, maintain accounts and Workspace records, generate and store outputs, secure the service, limit abuse, and investigate faults.
Where consent is required, the page asks for it before submission. We may also handle information where necessary to provide a requested service, meet a legal duty, address a security event, or protect lawful interests as permitted by applicable law. Withdrawing consent does not undo processing completed before the withdrawal.
Cookies and technical logs
Account sign-in uses a session cookie and a CSRF security cookie. A user session cookie lasts for up to fourteen days, and an admin session lasts for up to eight hours. Production sets these cookies as Secure and marks session cookies as HttpOnly.
The current public frontend does not include third-party advertising or behavioural analytics scripts. The server records the request time, endpoint status, and de-identified network-address data needed to operate rate limits, troubleshoot faults, and maintain security logs.
Retention and deletion
The current service does not publish one automatic deletion period for contact records, analysis jobs, or generation records. They remain in the operational database until authorised operations staff delete them or we complete a verified deletion request. Disabling an account, allowing a cookie to expire, or signing out does not immediately delete the related business records.
We keep records only while needed for the stated purpose, dispute handling, security, or a legal duty. Where law requires retention or immediate deletion is not technically possible, processing will be limited to storage and necessary protection. Do not submit identity documents, financial accounts, health records, trade secrets, or other highly sensitive material through a public tool.
Sharing and service providers
We do not sell personal information or use your business material in public marketing. If a hosting, database, email, or security provider must handle information to operate the service, we limit its purpose, scope, and security obligations. We may provide necessary information to a competent authority where law requires it or where it is needed to address an immediate safety risk.
Current public Skill runs use local rules and do not send the input to an external model service. If a later feature needs to provide personal information to an external model or another recipient, we will identify the recipient, purpose, information categories, and handling method before activation, and obtain separate consent where required.
Security measures
Passwords are stored as hashes. Account data is separated by user, while admin actions require role, session, and CSRF checks. Login and high-risk actions create security or audit records. The service also applies input limits, rate limits, and access controls.
These measures reduce the risk of unauthorised access, disclosure, alteration, or loss, but no online service can promise absolute security. If a personal information incident requires notice under applicable law, we will take remedial action and notify affected people and authorities as required.
Your choices and rights
You may ask about our handling, request access or a copy, correct inaccurate information, withdraw consent, restrict or object to particular handling, and request deletion where the applicable conditions are met. The current Account Center does not provide every rights control, so submit the request through the contact page.
To protect the account and its records, we verify the requester's identity, relationship to the account, and request scope. If we cannot fulfil a request, we will explain why. Security, dispute, or legally required records may not be eligible for immediate deletion.
Children, policy updates, and contact
Do not submit personal information about a child under fourteen without the consent of the child's parent or guardian. A guardian who believes such information was submitted can contact us for verification and handling.
We will update this policy when the purpose, information categories, disclosure method, or rights process changes materially. This page keeps the current online version. The contact page is the entry point for questions and rights requests under this policy.