Privacy Policy
Last updated: May 25, 2026
This Privacy Policy describes how Nyza Creations LLC (“we”, “us”, “our”), a Washington State limited liability company doing business as Hardik Trehan, collects, uses, shares, and protects information when you use hardiktrehan.com, including HT Hub (the games and AI tools sub-site), the 17 AI tools (astrology suite, Prompt Lab, Code Duel, Roast Battle, Model Showdown, AI Battle Arena, and others), our paid subscription plans, the public user profiles and leaderboards, and any related services (collectively, the “Site”).
By using the Site you agree to the practices described here. If you do not agree, please don’t use the Site. This policy is part of our broader Legal Center and is incorporated into our Terms of Service by reference.
For the full subprocessor list and our position under GDPR / CCPA / CPRA, see the Data Processing Addendum. For cookies and local storage, see the Cookie Policy.
1. Information We Collect
a. Account information (only if you sign in)
The Site uses Firebase Authentication. If you choose to sign in — for example, with Google or with email and password — Firebase provides us with:
- Your display name
- Your email address
- Your profile photo URL (Google sign-in only)
- A unique user ID (uid)
We store this in Google Cloud Firestore under your user record so we can identify you across sessions and on the public leaderboards if you opt in.
b. Game scores (only if you opt in to the cloud leaderboard)
By default, your game scores stay on your own device. Public leaderboard submission is off by default. If you turn on the “Visible on the public leaderboard” switch on the HT Hub page, the following will be sent to Firestore for each game you finish: your display name, your uid, the game name and your numeric score, and a timestamp.
You can turn this off at any time, and you can delete every leaderboard score we have for you with the “Delete my scores” button on the HT Hub page.
c. Public user profiles
If you opt in to the public leaderboard, the Site also exposes a public profile page at /hthub/u/<username> displaying your display name, profile picture, achievements, game scores, and aggregate stats. You can disable the public profile by turning off leaderboard visibility — your scores will be hidden and the profile page becomes a private record.
d. AI tool inputs and outputs
When you use any AI tool on the Site — astrology readings, Prompt Lab, Code Duel, Roast Battle, Model Showdown, AI Battle Arena, etc. — the inputs you type (birth dates, names, prompts, topics, code snippets) and the AI’s outputs are transmitted to third-party AI providers via OpenRouter so the models can generate responses. The current model providers reachable through OpenRouter include Google (Gemini), OpenAI, Anthropic, Meta, Mistral, DeepSeek, xAI, Moonshot, and Qwen; the specific model picked depends on the tool. AI Battle Arena results may also be stored locally in your browser (localStorage) for the history feature.
For paid tiers, voice narration in AI Battle Arena is generated via ElevenLabs — the text we send to ElevenLabs is the model’s output, not your input. Web-research lookups in Arena are powered by Perplexity.
Treat all AI inputs as public. Do not enter confidential, sensitive, regulated, or personally identifying information into AI tools beyond what is strictly required for the reading (e.g. an astrology birth date). See the AI Disclaimer.
e. Billing data (paid plans and credit packs)
When you purchase a Plus ($5/mo) subscription or a one-off credit pack ($1.99 / $7.99 / $24.99), payment is processed by Stripe. Your card data never touches our servers — Stripe collects and stores it directly per the Stripe Privacy Policy. We receive only:
- A Stripe Customer ID linked to your Firebase uid
- The plan or pack you purchased and the amount
- Subscription status (active, canceled, past_due)
- The last 4 digits of your card and brand (for display only)
- Billing country (for tax and compliance)
We maintain a server-side credit ledger in Firestore that records each credit grant (from purchase or monthly renewal) and each credit deduction (when you use a paid AI tool). This ledger is essential to deliver the paid service — without it we cannot know your balance.
f. Analytics and server logs
We use standard server logs and Google Analytics 4 (gtag) to measure traffic, identify broken pages, and improve the Site. GA4 collects pseudonymized data such as IP address (truncated for EU visitors), browser type, page paths, referrers, approximate location, and aggregated event counts. We do not use GA4 for cross-site advertising. To opt out, install the Google Analytics opt-out browser add-on or block analytics cookies via your browser.
g. Cookies and local storage
We use cookies for essential authentication (Firebase) and Stripe fraud-detection. Local storage holds game preferences, history, AI Battle Arena cache, and similar non-sensitive client state. We do not use third-party advertising trackers on hardiktrehan.com. Our mobile apps show ads through Google AdMob, described in section 1h below and in our Cookie Policy.
h. Mobile apps (Stage Rush and other Nyza Creations apps)
Our mobile apps — including Stage Rush on Google Play — are ad-supported and behave differently from the website:
- Advertising (Google AdMob). The apps display ads through Google AdMob. The Google Mobile Ads SDK collects and shares your device’s advertising ID and other identifiers, approximate location (estimated from IP address), in-app activity, and device & diagnostic information. This data is used by Google and its ad partners for advertising, analytics, and fraud prevention.
- Google Play Games (optional). Leaderboards and achievements use Google Play Games Services. Signing in is optional and never required to play.
- On-device data. Game progress, scores, and settings are stored locally on your device and are not sent to us.
You can reset or delete your advertising ID at any time in your Android device settings (Settings → Privacy → Ads). See Google’s advertising policies.
i. Live multiplayer — HT Island (presence, chat & voice)
When you enter HT Island, our realtime server relays live presence so other visitors can see you: your avatar’s position and appearance, your chosen display name, and a country flag derived from your approximate location. We look up that approximate country from your IP address at connection time (an on-server geo-IP lookup) only to pick the flag; you can switch the flag off. This presence data is ephemeral — it lives only in the server’s memory while you are connected and is discarded when you leave. There is no multiplayer database, and world chat and direct messages are relayed in real time, not stored on our servers after delivery.
Proximity voice chat is opt-in. It only starts after you grant your browser’s microphone permission, and you can mute or leave voice at any time. Voice audio travels peer-to-peer (WebRTC) directly between participants’ browsers — our server only helps the two browsers find each other (signaling); it does not receive, route, record, or store your microphone audio. Conduct in these live spaces is governed by our Community Guidelines.
2. How We Use the Information
- To provide the Site, games, AI tools, and paid features.
- To grant and deduct credits from your ledger so paid AI calls actually work.
- To display you on the public leaderboard, but only if you opted in.
- To send transactional emails (receipts, password resets, account notices).
- To respond to messages you send via the contact form or support email.
- To analyze usage in aggregate so we can improve the Site.
- To detect abuse, fraud, and security incidents.
- To comply with legal obligations and respond to lawful requests.
We do not sell your personal data. We do not share your data with advertisers on the website. AI inputs are sent to AI providers solely to produce the output you asked for, not for those providers’ own training (subject to the providers’ own terms — see the Data Processing Addendum for current zero-retention commitments where available).
3. Third-Party Subprocessors
We rely on the following subprocessors to deliver the Site. Each one has its own privacy policy; we are not responsible for their practices. The full table with categories, regions, and links is in the Data Processing Addendum.
- Stripe — payment processing for subscriptions and credit packs
- Firebase / Google Cloud — authentication, Firestore, hosting
- OpenRouter — gateway routing AI inputs to model providers (Google, OpenAI, Anthropic, Meta, Mistral, DeepSeek, xAI, Moonshot, Qwen)
- ElevenLabs — text-to-speech narration for paid users in AI Battle Arena
- Perplexity — web research in AI Battle Arena
- Google Analytics 4 — aggregate traffic analytics
- Google AdMob — ads in our mobile apps (not on the website)
- Google Play Games Services — optional in our mobile games
4. Legal Basis (EEA / UK Visitors)
If GDPR applies to you, we rely on the following legal bases:
- Performance of a contract — to provide the Site, paid plans, and credit ledger you signed up for.
- Consent — for the optional public leaderboard, optional account creation, and analytics where required.
- Legitimate interests — to operate, secure, and improve the Site, prevent abuse, and respond to support requests.
- Legal obligation — to retain records for tax, accounting, and to respond to lawful requests.
5. Data Retention
Account records and Firestore user documents persist until you ask us to delete them or your account is closed. Public leaderboard scores persist until you delete them with the in-app button or until we remove them for abuse. Billing and credit-ledger records are retained for at least seven (7) years to satisfy U.S. tax and accounting obligations. Server logs are retained for up to 90 days. Local storage data lives in your browser until you clear it.
To delete your account or remaining data, email support@hardiktrehan.com from the email tied to your account. See the Contact & Disputes page for the formal data-subject-request process.
6. Your Choices and Rights
- Decide when to sign in. You can browse the Site without an account. Free games still work without sign-in.
- Opt out of the public leaderboard. Toggle off the switch on the HT Hub page.
- Delete your scores. Use the “Delete my scores” button on the HT Hub page.
- Cancel paid plans. From your account settings — see the Subscription & Refund Policy.
- Sign out at any time from the account menu.
- Request access, correction, deletion, portability, objection, or restriction. Email legal@hardiktrehan.com. We respond within 30 days (extendable to 90 in complex cases).
If you are in the EU/UK, California, Colorado, Virginia, Connecticut, Utah, or another jurisdiction with additional data-protection rights, we honor valid requests under those laws. California residents specifically: we do not sell or share your personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
7. Security
We use industry-standard measures (Firebase security rules, HTTPS, server-side authentication checks, Stripe for card handling) to protect data. No system is 100% secure; we cannot guarantee absolute security. If we become aware of a breach affecting your data we will notify you and any required authority without undue delay.
8. Children
The Site is not directed to children under 13. We do not knowingly collect personal information from children under 13. See the Children & COPPA Policy for our full position and how parents can act.
9. International Transfers
We are based in the United States, and our subprocessors operate worldwide. If you access the Site from outside the U.S., your data will be transferred to and processed in the U.S. and other countries that may not provide the same level of protection as your home jurisdiction. Where required (e.g. for EU/UK personal data), we rely on appropriate safeguards such as Standard Contractual Clauses published by the European Commission.
10. Do Not Track
Most browsers offer a “Do Not Track” setting. There is no industry consensus on how to honor it, so the Site does not respond to DNT signals. We do, however, honor the Global Privacy Control (GPC) signal as an opt-out of sale/sharing under the CCPA — which is moot for us because we do not sell or share personal data for cross-context behavioral advertising anyway.
11. Changes
We may update this policy as the Site evolves. The “Last updated” date at the top reflects the most recent change. For material changes (e.g. a new category of data collection) we will notify signed-in users by email or with an in-product notice. Continued use of the Site after a change means you accept the updated policy.
12. Contact
Questions about this Privacy Policy?
Privacy & legal requests: legal@hardiktrehan.com
Account / technical: support@hardiktrehan.com
General: contact@hardiktrehan.com
Postal: Nyza Creations LLC, Washington State, USA. (Mail a request to legal@hardiktrehan.com first and we’ll provide the mailing address.)

















