Privacy Policy
Effective date: 17 September 2026 · version 2026-09-17
This policy explains what HoloAR (https://holo-ar.com), operated by Netanel Huri, collects when you use the site, why, how long we keep it and what you can ask us to do.
1. What we collect
- Google sign-in: when you sign in we receive from Google your account identifier (a number Google assigns to your account), your email address and whether Google has verified it. We use them to create your HoloAR account and to show you your greetings. We do not receive or store your Google password, and we do not ask for access to Google Drive, contacts, calendar or any files.
- Session: after sign-in we store a random session identifier in a cookie in your browser (HttpOnly, valid for 30 days or until you sign out). It only tells our server which account is signed in.
- The video you upload, the settings you choose (background mode, figure height, language) and the greeting files we create from it.
- Greeting records: which account created each greeting, when it was created, when it became ready, its end date, whether it was paid, and the version and time of your acceptance of the terms.
- Payment: handled by Paddle.com, our Merchant of Record. Paddle collects your name, email, billing country and payment details under its own privacy policy (https://www.paddle.com/legal/privacy). We receive a transaction ID, the amount, the currency and a Paddle customer reference; we never see your card number.
- Technical data needed to run the site: IP address, browser type and time of request, kept in server logs for a short period for security and troubleshooting.
- Emails you send us.
We do not use advertising trackers or third-party analytics. The site keeps a few settings in your browser (language, the message you drafted, the ID of your last greeting) so that a page can be restored after a refresh; these stay in your browser.
2. How we use it
- To identify you and show you your own greetings in "My Greetings".
- To create, store and serve your greeting and its files for its one-year period.
- To take payment and match it to your greeting and your account.
- To keep the site secure, fix problems and prevent abuse.
- To answer your messages and handle refunds.
We do not send marketing emails, and signing in or buying is not consent to receive any. We currently do not send expiry reminders by email; the end date of each greeting is shown on its result page and in "My Greetings".
3. Who can see a greeting
A greeting is visible to anyone who has its link or QR code, without signing in. Links are long and random and are not listed anywhere, but they are not password protected. Your list of greetings is visible only to your signed-in account.
4. Who processes your data
- Google LLC (sign-in): Google learns that you signed in to HoloAR, under Google's privacy policy.
- Paddle.com (payments, tax, receipts).
- Replicate, Inc. (AI background removal): when you choose automatic background removal, the normalised video is sent to Replicate for processing and deleted from Replicate after the run.
- DigitalOcean (server hosting, EU data centre) and Cloudflare (DNS and network protection).
- Google Fonts (font files on the landing pages; Google may see your IP address).
We do not sell your data and do not share it with anyone else, unless required by law.
5. How long we keep it
- Unpaid uploads: deleted after 24 hours.
- Greeting videos and files: available for one year from the moment the greeting became ready, then blocked; the files are deleted from our server within about 30 days after that. Files you downloaded to your device are outside our control and stay with you.
- Greeting records (without the video): kept after the year so that "My Greetings" can still show what you bought and when, and so that payments can be reconciled. Removed when you ask us to delete your account, except where a payment record must be kept (see below).
- Account (Google identifier, email): kept until you ask us to delete the account.
- Sessions: 30 days, or until you sign out.
- Payment records (transaction ID, amount, currency, Paddle customer reference): as long as required for accounting and tax purposes, even after other data is deleted.
- Backups: the server is backed up daily and the last 7 backups are kept, so deleted data can remain in a backup for up to about 7 days before it is overwritten. We do not restore deleted greetings from backups.
- Server logs: a short rolling period.
6. Your rights and requests
You can ask us to delete a greeting, to delete your account, or to tell you what we hold about you, by emailing [email protected] from the email address of your account (or with the greeting link). Deleting the account removes the account record, the sessions and the greeting videos; the minimal payment records described above are kept as long as the law requires. If you are in the EU/EEA or UK you also have the rights given by the GDPR, including the right to complain to your data protection authority. Payment-related requests may be handled by Paddle.
7. Children
The service is intended for adults. Do not upload videos of children without the consent of their parent or guardian.
8. Changes and contact
We may update this policy; the version on this page applies and is dated at the top. Contact: [email protected]. Controller: Netanel Huri, Israel.