hny.sh
Privacy Policy

Privacy Policy

This policy explains what personal data henyuu collects across all hny.sh services, how it is used, stored, and protected, and what rights you have over your data. This document is served at legal.hny.sh/privacy.

By using any hny.sh service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with how we handle your data, please stop using our services and submit an erasure request if applicable.

This Privacy Policy applies to all services operated by henyuu under the hny.sh domain and its subdomains, including but not limited to the hny.sh website, Discord bots, paid plans via Stripe, hosted services, and any associated APIs or integrations (collectively, "the Services").

henyuu is the data controller for personal data collected through these Services. For the purposes of this policy, "we", "us", and "our" refer to henyuu and its operators.

This policy does not apply to third-party services that integrate with hny.sh (such as Discord, Stripe, Rotector, or ERPSearcher). Each of those services operates under its own privacy policy.

We collect data in the following categories depending on which Services you use:

Data you provide directly

  • Account registration details (e.g. email address, username).
  • Payment information submitted via Stripe (we do not store raw card data; see Section 6).
  • Support tickets, correspondence, and communications you send to us.
  • Content or data you submit through hosted services or APIs.

Data collected automatically

  • IP address and approximate geographic location (country/region level).
  • Browser type, operating system, and device information.
  • Pages visited, referring URLs, and interaction timestamps.
  • API usage logs including request timestamps, endpoints accessed, and response codes.
  • Error logs and diagnostic data necessary for service stability.

Data from Discord bots

  • Discord user IDs, server (guild) IDs, and channel IDs where the bot operates.
  • Command inputs and interaction data submitted to the bot.
  • Server configuration data set by administrators.

Data from third-party integrations

  • Detection results or flags returned by Rotector and ERPSearcher APIs when used through our Services.
  • Identifiers (e.g. Roblox user IDs) passed to third-party APIs as part of moderation workflows.
We do not collect: sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, biometric data, or health information. We do not knowingly collect data from individuals under 13 years of age.

We use the data we collect for the following purposes:

Purpose Legal Basis
To provide and operate the Services — account management, API access, bot functionality, hosted service delivery. Contract performance
To process payments — billing, subscription management, invoicing via Stripe. Contract performance
To ensure security and prevent abuse — fraud detection, rate limiting, Terms enforcement, blacklist management. Legitimate interests
To maintain and improve the Services — debugging, performance monitoring, feature development based on usage patterns. Legitimate interests
To respond to your enquiries — support tickets, legal requests, and direct communications. Contract performance / Legal obligation
To comply with legal obligations — responding to lawful requests, retaining records as required by law. Legal obligation

We do not use your data for advertising, profiling, or sale to third parties.

We do not sell, rent, or trade your personal data. We share data only in the following circumstances:

Service providers

  • Stripe — payment processing. Data shared is limited to what is necessary to complete transactions. See Stripe's Privacy Policy.
  • Discord — where our bots operate on your server. Interaction data is processed in accordance with Discord's Privacy Policy.
  • Rotector — identifiers (e.g. Roblox user IDs) may be passed to Rotector's API for detection purposes. Subject to Rotector's API conditions.
  • ERPSearcher — identifiers may be passed to ERPSearcher's API for detection purposes. Subject to ERPSearcher's Terms.
  • Infrastructure and hosting providers — data is stored on servers operated by our infrastructure providers, bound by contractual data processing agreements.

Legal requirements

We may disclose your data if required to do so by law, court order, or regulatory authority, or where we reasonably believe disclosure is necessary to protect the rights, property, or safety of henyuu, our users, or the public.

Business transfers

In the event that henyuu undergoes a change of ownership or transfer of assets, your data may be transferred as part of that transaction. You will be notified of any such transfer and applicable changes to this policy.

We never share your data with advertisers, data brokers, or any party for marketing purposes.

We may use cookies and similar technologies to operate and improve the Services. These include:

  • Strictly necessary cookies — required for authentication, session management, and security. These cannot be disabled without breaking core functionality.
  • Functional cookies — used to remember your preferences and settings.
  • Analytics cookies — used to understand how users interact with the Services (e.g. pages visited, time spent). Analytics data is aggregated and not linked to individual identities where possible.

We do not use advertising, retargeting, or behavioural tracking cookies.

You may control cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of the Services.

All payment processing is handled by Stripe. henyuu does not collect, store, or have access to your full payment card details (card number, CVV, expiry). This data is submitted directly to Stripe's secure infrastructure.

We retain the following billing-related data:

  • Your email address associated with the payment.
  • Transaction identifiers, amounts, dates, and subscription status.
  • Billing country and partial card information (last 4 digits, card type) as returned by Stripe for display purposes.

This data is retained for as long as necessary to manage your account, comply with tax and financial reporting obligations, and resolve disputes. Financial records may be retained for up to 7 years in compliance with applicable accounting laws.

For questions about how Stripe handles your financial data, refer to Stripe's Privacy Policy.

We retain your personal data only for as long as necessary for the purposes described in this policy, or as required by law. The following general retention periods apply:

Data Type Retention Period
Account data (email, credentials) Duration of account + 30 days after deletion
API logs and usage data Up to 90 days
Support correspondence Up to 2 years
Billing and financial records Up to 7 years (legal obligation)
Security and abuse logs Up to 1 year
Discord bot interaction data Up to 30 days unless server config requires longer

After the applicable retention period, data is securely deleted or anonymised. Note that some data may be retained longer where required by law or for the resolution of outstanding disputes.

We take reasonable technical and organisational measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit via TLS/HTTPS.
  • Access controls limiting data access to authorised personnel only.
  • Regular review of security practices and infrastructure.
  • API key hashing and secure credential storage.

However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users as required by applicable law.

If you discover or suspect a security vulnerability in any hny.sh service, please report it immediately to legal@hny.sh.

henyuu operates internationally and your data may be stored or processed in countries outside your own, including countries that may not offer the same level of data protection as your home jurisdiction.

Where data is transferred internationally, we take steps to ensure appropriate safeguards are in place, including relying on service providers who maintain adequate data protection standards or enter into appropriate contractual arrangements.

By using the Services, you acknowledge and consent to the transfer of your data as described in this section.

Depending on your jurisdiction, you may have the following rights regarding your personal data:

Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
Right to Restriction
Request that we limit the processing of your data in certain circumstances.
Right to Portability
Request a machine-readable copy of your personal data for transfer to another service.
Right to Object
Object to processing based on legitimate interests, including profiling.
Right to Withdraw Consent
Where processing is based on consent, withdraw it at any time without affecting prior processing.
Right to Lodge a Complaint
Lodge a complaint with your local data protection authority if you believe your rights have been violated.

To exercise any of these rights, contact us at legal@hny.sh. We will respond within a reasonable timeframe and in accordance with applicable law. We may need to verify your identity before processing your request.

You have the right to request the deletion of all personal data we hold about you. This right is subject to certain exceptions — for example, we may be legally required to retain certain financial or compliance records even after an erasure request.

To submit an erasure request:

  • Email legal@hny.sh with the subject line Request for Erasure of Personal Data.
  • Include your account email address, any associated usernames or identifiers, and a description of the data you wish erased.
  • We may ask you to verify your identity before proceeding.

We will acknowledge your request promptly and complete the erasure (or provide a justified reason for partial retention) within 30 days. In complex cases we may extend this period by a further 30 days with notice.

Note: Erasure of your personal data will result in the termination of your account and access to all associated Services. Data shared with third-party processors (Stripe, Rotector, ERPSearcher) must be addressed directly with those providers under their own policies.

The Services are not directed at children under the age of 13, and we do not knowingly collect personal data from children under 13. If you believe we have inadvertently collected data from a child under 13, please contact us immediately at legal@hny.sh and we will take prompt steps to delete that data.

Users between the ages of 13 and 17 may only use the Services with parental or guardian consent, as outlined in our Terms of Usage. Parents or guardians may request access to or deletion of a minor's data on their behalf.

We may update this Privacy Policy at any time. When material changes are made:

  • New users: Changes take effect immediately upon posting.
  • Existing users: A notice will be posted on the relevant dashboard or service. Changes become effective 7 days after that notice is posted.

The "Last updated" date at the bottom of this page will reflect the most recent revision. We encourage you to review this policy periodically. Continued use of any Service after the effective date constitutes acceptance of the updated policy.

For any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data, please contact henyuu through the following channels:

For erasure requests specifically, email legal@hny.sh with the subject line Request for Erasure of Personal Data.

This policy is served at legal.hny.sh/privacy. The companion Terms of Usage document is available at legal.hny.sh/tos.