Privacy Policy
The data controller is Semen Vasilev, a self-employed individual (the “Controller”), contact: neiroivanych@gmail.com. This Policy describes what data the HVPC Mosaic service (https://mosaic.neiroivanych.io) collects, why, and for how long.
1. What data is processed
| Data | Purpose | Retention |
|---|---|---|
| Email address | Account sign-in, sign-in code emails, payment confirmation and subscription reminders | While the account exists |
| Uploaded photos and processed results | Delivering the service — cutting the image, keeping results in “My files” | Per the plan's storage rules (see Terms); drafts — up to a few hours |
| Acceptance of the Terms (fact and date), interface language | Proof of consent, showing the interface in the chosen language | While the account exists |
| Payment records: payment identifier, currency, amount, status | Activating and accounting for subscriptions | 3 years (accounting and dispute resolution) |
| Technical data: IP address, browser type, request timestamps | Security, abuse prevention, error diagnostics — in server logs | Up to 30 days |
| Cookies | Keeping the sign-in session, remembering theme and language | Up to 1 year or until sign-out |
The Controller does not receive or store card details; they are processed by the payment agent Lava.top.
2. Legal basis
- Performance of the contract (the Terms of Service) accepted by the User at first sign-in.
- The User's consent, given by ticking “I have read and accept the terms of service and the privacy policy”.
- The Controller's legitimate interest in the security and stable operation of the Service (technical logs).
3. Who receives the data
- Lava.top (lava.top) — payment agent, payment processing. Receives the email address, amount and currency.
- Resend (Resend, Inc., USA, resend.com) — sending service emails (sign-in code, payment confirmation, reminders). Receives the email address and the message text. This is a cross-border transfer: the service's servers are located outside Russia.
- Aeza (aeza.net) — hosting provider, on whose servers the Service's data is stored.
- Public authorities — only upon a lawful request.
The Controller does not sell data and does not use uploaded images for advertising, model training or any purpose other than delivering the service. The site uses no advertising or third-party trackers.
4. Public links
If the User creates a direct link to a file, that file becomes accessible to anyone who knows the address. The Controller does not control whom the User shares the link with. The link can be disabled at any time; the file is deleted under the general storage rules.
5. Your rights
- View, change or delete your files — in the Service interface.
- Delete the account with all data — by request to neiroivanych@gmail.com from the account email; deletion is performed within 10 business days. Payment records are kept for the period stated in section 1.
- Withdraw consent — in the same way; after withdrawal the Service can no longer be used.
- Obtain a copy of your data or ask about processing — at the same address.
6. Security
- Connections to the Service are encrypted (HTTPS).
- Server access is key-based only; the User's files are not accessible to anyone else unless the User creates a public link.
- One-time sign-in codes are valid for 10 minutes and stored in an irreversible form.
7. Cookies
The Service uses only strictly necessary cookies: a session identifier (so you do not enter a code on every visit) and local browser settings (theme, language). There are no analytics or advertising cookies. Disabling cookies in the browser makes sign-in impossible.
8. Time
Retention periods and all dates in the Service and in emails are counted in Moscow time — GMT+3 (Europe/Moscow).
9. Changes
The Controller may update this Policy. The current version is always available on this page; for material changes the Service asks for renewed acceptance at sign-in.