MoiraHub Privacy Policy

Last updated: 2026-07-08

Controller: Shiyan Shihua Trading Co., Ltd.

Contact: cristalbleiserdari@gmail.com

Privacy Policy for MoiraHub

Effective date: 8 July 2026

Last updated: 8 July 2026

This Privacy Policy describes how Shiyan Shihua Trading Co., Ltd. (“we,” “us,” or “our”) processes personal data when you use MoiraHub, a Google Play Android social communication app for adults aged 18 and over. It applies to registration, profile discovery, instant messaging, live text and video conversations, optional in-app purchases, and related support functions. By creating an account or continuing to use the app after reviewing the in-app Privacy Notice and User Terms, you acknowledge this Policy. If you do not agree, do not install or use the app.


1. Scope, Platform, and Controller

MoiraHub is distributed on Google Play for Android only. This Policy does not describe iOS, App Store, or Apple-specific services unless we separately publish a different notice.

Shiyan Shihua Trading Co., Ltd. is the data controller for processing described here. Our registered address is Building 1 No.1, Group 8, Chenghuangmiao Neighborhood Committee, Chengguan Town, Yunxi County, Shiyan City, Hubei Province (Self-declaration). For privacy questions, rights requests, or complaints, contact cristalbleiserdari@gmail.com. We aim to respond within 15 business days unless applicable law requires a different timeframe.


2. Eligibility and Age Declaration

The app is intended only for users aged 18 or older. We do not operate a continuous technical age-verification system beyond the one-time age declaration you confirm during onboarding. If you are under 18, do not register or use the app. If we learn that an account was created in violation of this requirement, we may suspend or delete it and remove associated data as permitted by law.


3. Categories of Information We Process

We collect information necessary to operate a communication platform. The table below aligns with Google Play Data safety disclosures. “Collected” means obtained from you, your device, or generated through use. “Shared” means disclosed to service providers or partners that process data on our behalf or as described in Section 7.

Data typeCollectedSharedPurposeRequired / Optional
Account identifiers and profile information such as nickname, avatar, bio or interest labels, and authentication session dataYesYesProvide registration, sign-in, profile display, discovery, session integrity, fraud prevention, and account securityRequired when you create or use an account
Instant messages, conversation history, and related messaging metadata between usersYesYesDeliver private messaging, synchronize conversations, support notifications, and enforce community policiesCollected when you send or receive messages inside the app
Live video and audio session content processed when you use real-time chat or video conversation featuresYesYesEnable live text or video conversations, connection quality management, and safety workflowsRequired when you initiate or join live conversation sessions
Photos and videos captured with the camera or selected from your library for profile or shared mediaYesYesDisplay profile visuals, support media sharing in chats, and assist moderation where applicableOptional; collected only when you capture, upload, or choose profile or chat media
Usage events and diagnostics, including Device ID where applicableYesYesMeasure performance, troubleshoot issues, improve product quality, and protect against abuseRequired
In-app purchase and entitlement signals processed in connection with Google Play BillingYesYesDeliver digital goods or features, validate entitlements with Google Play, and keep purchase state consistentCollected when you make or restore purchases as applicable
Safety reports, block records, and related context you submitYesYesInvestigate abuse reports, enforce policies, and protect usersOptional; only when you use report or block safety flows

We may also receive limited technical data from Android platform frameworks and Google Play services components used for authentication, billing, and device diagnostics.


4. Sources of Information

Information comes from:

We do not require you to provide data beyond what is needed for features you choose to use, except where collection is required for security, legal compliance, or core account operation.


5. How We Use Information

Processing supports the following activities:

We do not sell personal and sensitive user data.


Where the GDPR, UK GDPR, or similar laws apply, we rely on a lawful basis for each main processing purpose:

PurposeLegal basis
Providing accounts, messaging, live conversations, and profile features you requestPerformance of a contract (or steps at your request before entering a contract)
Security monitoring, fraud prevention, service improvement analytics, and network diagnosticsLegitimate interests, balanced against your rights — we use data in ways reasonably necessary to operate and protect the service
Camera, microphone, or media access for optional profile or chat featuresConsent where required by law; you may withdraw consent through Android permission controls, though some features may stop working
Safety moderation of user-submitted contentLegitimate interests in protecting users and complying with community standards; legal obligation where applicable
In-app purchases via Google Play BillingPerformance of a contract to deliver purchased digital goods or features
Responding to regulators, courts, or mandatory legal processesLegal obligation

If you are in the EEA, UK, or Switzerland and believe we should rely on a different basis for specific processing, contact us at cristalbleiserdari@gmail.com.


7. Android Permissions and Background Access

The app requests Android permissions only for stated features. None of the sensitive permissions below are used in the background when the app is not in active use for the relevant feature.

PermissionWhen requestedPurposeBackground use
CameraCapturing profile photos or chat mediaEnable in-app photo captureNot in the background
MicrophoneLive audio or video conversationsTransmit audio during sessions you joinNot in the background
Photos and videos (read) — Android `READ_MEDIA_IMAGES` / `READ_MEDIA_VIDEO` or scoped access as applicableSelecting existing media for profiles or messagesAttach or upload library contentNot in the background
Photos and videos (write / MediaStore)Saving or sharing profile or chat media from the appWrite media you choose to save or shareNot in the background
LocationNot used for core features in the current versionN/A if not requestedNot in the background

You can manage or revoke permissions in Android Settings → Apps → MoiraHub → Permissions. Revoking access may limit camera capture, voice/video sessions, or media sharing until permission is granted again.


8. Integrated Technology and SDKs

We use third-party and platform components limited to disclosed functions:

These providers process data under contractual terms requiring appropriate safeguards and use limitations consistent with this Policy.


9. Sharing With Third Parties and Service Providers

We disclose information to categories of recipients below. This is not a sale of personal data. Structured sharing disclosures:

Cloud Hosting / CDN

Real-time Communication / Video Infrastructure

Content Moderation Service

Analytics / Performance Monitoring

Google Play (payments)

We may also disclose information when required by law, to protect users or our rights, or in connection with a merger or asset transfer subject to continued protection.


10. Retention, Storage Location, and Deletion

Data is stored on servers operated by us or our providers, which may be located outside your country, including jurisdictions that may not provide the same level of protection as your home country. Where required, we use appropriate transfer mechanisms such as standard contractual clauses.

Retention depends on data type and purpose:

You may request deletion of personal data subject to exceptions under applicable law. Account deletion options, where available in-app, initiate removal workflows; you may also email cristalbleiserdari@gmail.com.


11. Security Measures

We implement administrative, technical, and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. Measures include access controls, encryption in transit where appropriate, monitoring for abuse, and vendor security requirements. No method of transmission or storage is completely secure; if we become aware of a breach affecting your rights, we will notify you or regulators as required by law.


12. Your Privacy Rights

Depending on your location, you may have rights regarding your personal data or personal information, including:

Correction and rectification: If your personal data or personal information is inaccurate or incomplete, you may request correction or rectification. Submit details of the inaccuracy and the correction sought to cristalbleiserdari@gmail.com. We will verify your identity where appropriate and respond within 15 business days.

To exercise any right, email cristalbleiserdari@gmail.com with sufficient detail to locate your account. We may need to verify identity before fulfilling requests. If we deny a request, we will explain the reason where permitted.

Users in the EEA, UK, or Switzerland may lodge a complaint with their local supervisory authority. Brazilian users may have rights under the LGPD exercisable through the same contact channel.


13. U.S. State Privacy Rights

California and Virginia Privacy Rights

This section supplements the Policy for residents of U.S. states with comprehensive privacy laws, including California and Virginia.

California (CCPA / CPRA)

The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant California residents specific rights, including:

To exercise these rights, email cristalbleiserdari@gmail.com. We will respond within 15 business days unless extension is permitted by law.

California residents have the right to know whether we have shared their personal data with third parties, what categories of personal information are involved, and for what business purposes, as required under the CCPA. This Policy and Section 9 describe those practices.

Under the CCPA, the terms “share” and “sharing” have a specific definition under California law. They can include making personal information available to a third party for cross-context behavioral advertising, even when money does not change hands. We use service providers for hosting, communication, moderation, analytics, and payments as described in Section 9; that operational disclosure is distinct from cross-context behavioral advertising. For a full description of what we actually do, see Section 9. California residents may exercise the right to know by emailing cristalbleiserdari@gmail.com; we respond within 15 business days.

We do not sell personal information as “sale” is defined under the CCPA. We do not sell personal and sensitive user data.

Virginia (VCDPA)

The Virginia Consumer Data Protection Act (VCDPA) provides Virginia residents rights to access, correct, delete, and obtain a copy of personal data, and to opt out of certain processing. Contact cristalbleiserdari@gmail.com to exercise VCDPA rights; we respond within 15 business days.

How to opt out of certain processing under the VCDPA:

  1. Targeted advertising — We do not use personal data for cross-context targeted advertising as defined under the VCDPA. If you believe otherwise or wish to confirm your preferences, email cristalbleiserdari@gmail.com with the subject line “VCDPA Opt-Out — Targeted Advertising.”
  2. Sale of personal data — We do not sell personal data. To confirm this status or opt out of any future sale should our practices change, email cristalbleiserdari@gmail.com with “VCDPA Opt-Out — Sale.”
  3. Profiling with legal or similarly significant effects — We do not engage in profiling that produces legal or similarly significant effects concerning Virginia residents. To opt out or request confirmation, email cristalbleiserdari@gmail.com with “VCDPA Opt-Out — Profiling.”

14. Data Protection Officer (DPO)

We have designated Data Protection Officer, Shiyan Shihua Trading Co., Ltd. to oversee data protection compliance for MoiraHub. Data Protection Officer, Shiyan Shihua Trading Co., Ltd. serves as our formal contact for inquiries relating to the processing of personal data, applicable privacy rights, and coordination of responses to data subject requests. Users may contact the DPO regarding data protection and privacy matters at cristalbleiserdari@gmail.com. The DPO reviews complaints and questions about how personal data is handled and works with relevant teams to address lawful requests within applicable timeframes.


15. Changes to This Policy

We may update this Policy to reflect legal, technical, or operational changes. When we make material changes, we will provide notice through the app, Google Play listing, or other reasonable means. The “Effective date” at the top indicates the current version. Continued use after the effective date of an update constitutes acknowledgment unless applicable law requires additional consent.


16. Contact Information

RoleDetails
Data controllerShiyan Shihua Trading Co., Ltd., Building 1 No.1, Group 8, Chenghuangmiao Neighborhood Committee, Chengguan Town, Yunxi County, Shiyan City, Hubei Province (Self-declaration)
Privacy inquiries and rights requestscristalbleiserdari@gmail.com
Data Protection OfficerData Protection Officer, Shiyan Shihua Trading Co., Ltd. — cristalbleiserdari@gmail.com
Response timeframeUp to 15 business days

For account-specific issues unrelated to privacy rights, use in-app support where available.


*End of Privacy Policy*

No Sale Statement

We do not sell personal and sensitive user data.

Third-Party Sharing Mapping

Data Safety Mapping

Sensitive Permissions Background Access

Users have the right to know whether their personal data is shared with third parties and for what business purposes. We explain sharing in the Information sharing section above. Email cristalbleiserdari@gmail.com with subject Sharing Disclosure Request to exercise this right; we aim to respond within 15 business days where feasible.

Play storefront user rights summary

Depending on applicable law, you have the right to request access to the personal data that we collect about you (including, where applicable, the right to know whether we process certain categories of personal data concerning you). To exercise this right, email cristalbleiserdari@gmail.com with a clear description of your request and enough information for us to verify your identity and locate the relevant records.

You have the right to request deletion of personal data that we collect about you, subject to lawful exceptions (for example records we must retain for security, audits, disputed transactions, or legal process). Submit your request by emailing cristalbleiserdari@gmail.com with subject Deletion Request, or follow the account deletion paths described elsewhere in this policy when you use a registered profile.

How your users can opt out of the sharing or selling of their data under applicable U.S. state laws and similar regimes. How to opt-out of data sale/targeted ads: email cristalbleiserdari@gmail.com with subject Opt-out of sharing, Opt-out of sale, or Opt-out of targeted advertising to opt out of sharing, selling, or targeted ads to the extent required by law. Where verification is required, we aim to acknowledge and process qualifying requests within about 15 business days.