Last Updated: October 2, 2026
This policy explains how Haze Method ("Haze Method", "Haze", "we", "us"), the app operated at hazemethod.xyz, handles information when you use the Haze Method website, Discord bot, browser extension, and backend at api.hazemethod.xyz. It also covers the website Ticket Center and optional integrations such as TikTok.
Haze Method, operated from the Philippines, is responsible for the Haze processing described here. Contact haze@hazemethod.xyz for privacy questions or requests. This notice explains our practices; it does not require you to waive privacy rights or provide blanket consent. Optional permissions and any consent required by law are handled separately.
Video processing at a glance: the standard Haze patch runs locally in your browser. When you post to TikTok, your browser uploads the video directly to TikTok after you confirm.
When you sign in with Discord or use the Haze bot, we may process your Discord user ID, username, avatar, server membership, and Haze-related roles. We use this information to authenticate you, provide bot commands, determine your tier, grant or remove roles, and keep the website and Discord server in sync. Haze's OAuth flow does not request your Discord email address.
The bot processes the commands, buttons, and other interactions you send to it. Depending on the feature used, it stores information needed for Haze Credits, XP and levels, moderation and anti-abuse controls, sticky messages, server statistics, donation roles, and feature settings. Chat activity may earn XP, but it does not earn Haze Credits. When a feature depends on a Discord message event, the bot processes the message and channel identifiers and the content needed to perform that feature.
Card payments, Premium Monthly and the free trial go through our checkout partner Whop, which collects your payment details directly; Haze never receives your full card number. From Whop we receive and store the membership and payment identifiers, the plan, amount, currency, payment status, and trial, renewal and cancellation dates, linked to your Discord user ID. We also record each purchase agreement: your Discord user ID, the Terms and Refund Policy version you accepted, which checkout it was for, and when. We use these records to grant and renew Premium, stop renewals when you cancel, allow one free trial per person, answer refund requests, and respond to payment disputes.
For donation tickets, we store the ticket number, Discord account, selected payment method and amount, ticket status, associated Discord channel, staff decision, rejection reason when provided, and role expiry. Payment services may provide Haze with a transaction identifier, amount, and payment status so we can prevent duplicate processing and grant the correct role.
The website Ticket Center shows your ticket's status only — number, payment method, amount, months, and creation date. It does not display, store, or transmit the messages in your Discord ticket channel.
Messages, attachments and proofs you choose to send in a Discord support or payment ticket are processed through Discord and can be viewed by the staff handling it. We may keep information necessary to resolve the request or payment claim. Discord's own retention and permissions apply; deleting a channel or message does not necessarily remove an independently retained transaction record. Do not send passwords, full card details, or unrelated sensitive information.
We store records used to operate the service, including your weekly and purchased Haze Credits, temporary processing reservations, detected resolution, frame rate and file-size pricing data, upload count, approximate MB saved, account restrictions, warnings, and Donator or TikTok-role expiry. Weekly balances reset every Monday at 12:00 AM Manila time; lifetime totals may remain on the account record.
We do not use submitted videos to train models, advertise to you, or build advertising profiles.
Connecting TikTok is optional and uses its official OAuth Login Kit. With user.info.basic, we retrieve your display name and profile picture to identify the connected account. We store access and refresh tokens encrypted, associate them with your Discord user ID or a random anonymous ID stored in your browser, and refresh them as needed. When you confirm publishing, video.publish is used for the video and settings you select, with a direct upload to TikTok. These permissions are not used to publish without your action.
You can disconnect in Haze TikUpload to delete the saved tokens from Haze, or revoke permissions in your TikTok account. Revoking at TikTok prevents further authorized use but does not itself guarantee immediate deletion of our stored record; contact us if you also need deletion. Clearing site data can lose access to an anonymous connection, so disconnect first or revoke at TikTok and contact us with enough information to identify it. Never send us a token as proof. Disconnecting does not delete an already published TikTok post or automatically erase status history; request eligible record deletion separately.
Connection and publishing data are processed only for the purposes described here and shared with TikTok and the infrastructure needed to provide the feature. TikTok applies its own privacy policy to information it receives.
The website sends limited operational measurements to our hosting logs: app version, page category, operation category, duration, and success or failure. Performance measurements are sampled. These event payloads exclude account identifiers, tokens, video contents, filenames, captions, full URLs, and error messages. This reporting honors browser Do Not Track and Global Privacy Control signals and is capped per page session.
Separately, the website uses Vercel Web Analytics to measure traffic and page use. It uses request-derived anonymous visitor measurements without analytics cookies, and may process the page path, referring site, device or browser characteristics, and approximate region. Haze removes query strings, including query strings embedded in route hashes, before sending page URLs so sign-in callback tokens are not included. This analytics path is separate from the operational reporting above; the operational reporting's Do Not Track and Global Privacy Control gate should not be understood as a site-wide analytics opt-out. Where applicable law requires consent or an opt-out for particular processing, those requirements apply.
When you use Haze, we process normal request information such as IP address, timestamps, request metadata, and rate-limit events. For multi-account and abuse detection, we may also store a browser-generated device identifier, hashed identifiers, linked account IDs, detection outcomes, warnings, and termination status.
The website and extension store session details, basic profile and tier data, credit balances, feature preferences, and interface settings using cookies, local storage, or extension storage. Signing out clears Haze authentication data from the active browser. The extension's optional TikTok repair action deletes the ttwid cookie when you ask it to; it does not transmit that cookie's value to Haze.
Local storage also supports language choice, onboarding preferences, anonymous TikTok ownership and recent optimized files. Some storage is necessary for the features you request; clearing it may sign you out, reset preferences or remove access to an anonymous connection. A cookie or local identifier is not proof that a particular individual authorized a payment.
The Haze bot uses one Discord privileged gateway intent, Server Members. This section describes what it is used for and the controls available to you. Message-content features (such as info commands and link moderation) are provided by a separate companion bot.
Used to welcome new members, log departures for moderators, and keep your Haze tier in sync when donation or booster roles change. As described above, we store your Discord user ID, assigned tier, and role expiry off-platform; this is required to grant your perks.
We do not sell personal information or share it with advertisers or data brokers.
Where data-protection law (such as the Philippine Data Privacy Act of 2012 or the GDPR) asks for a legal basis, we rely on:
| Information | Typical retention |
|---|---|
| Local optimizer video and recent-output cache | Original and downloaded files remain on your device. Cached outputs expire after 3 days and are removed during cache use/cleanup; browser storage can be cleared sooner. |
| Ticket records | Retained while the donation record is needed |
| TikTok connection tokens | Until deleted through Haze disconnect or an applicable deletion request; expired or revoked permissions may prevent use before the stored record is deleted. |
| TikTok post records | 90-day retention window, with older records removed during post-record storage cleanup. |
| Payment, subscription, trial, and policy-acceptance records | As long as needed for accounting, tax, refund, and dispute purposes, and as the law requires, even after you stop using Haze |
| Account, credit, economy, role, and security records | While needed to operate the account, enforce limits, resolve payments, secure Haze, or meet applicable obligations |
We retain only what is reasonably necessary for the stated purpose or a legal obligation, and review retention when resolving deletion requests. Records needed for accounting, a pending dispute, fraud investigation or legal claim may remain restricted rather than immediately erased. Different records and backups may have different removal schedules; we do not promise every copy disappears instantly. We will explain a relevant retention exception when responding to your request.
Information is shared only as needed to provide a feature you use:
Authorized staff may access information needed for support, moderation, payments and security. We may disclose relevant information for a lawful request or to establish, exercise or defend a legal claim, using only what is reasonably necessary. A business transfer may involve service records, subject to applicable safeguards and notice requirements. We do not publish private support or payment evidence as a response to a refund claim.
Haze is operated from the Philippines. Hosting, database, payment and connected-service providers may process information in the United States and other countries with different privacy laws. Where applicable law requires a transfer mechanism or safeguards, we must use the applicable protections, such as appropriate contractual safeguards or a recognized lawful transfer basis. Contact us for information about safeguards relevant to your data; this notice is not itself a claim that every destination has equivalent laws.
Depending on where you live, including under the Philippine Data Privacy Act of 2012, the GDPR in the EU and UK, and US state privacy laws, you may have the right to:
Email haze@hazemethod.xyz or open an official Discord ticket. Identify the account and request, but do not send passwords, access tokens, or full card details. We may seek proportionate proof of ownership; if you have lost Discord access, contact us to discuss another way to verify the request. An authorized representative may act where the law permits. We aim to respond within 30 days and follow any shorter deadline or permitted extension under the applicable law, explaining an extension or refusal and available review or complaint routes.
We will not penalize you for using privacy rights. Deleting browser data or requesting account-data deletion does not by itself stop subscription billing. If you also want cancellation, clearly say so or cancel through Whop; a clear on-time request is treated under the Refund Policy. Necessary billing or dispute records may remain even after eligible account data is deleted.
A request to Haze can address data we control. It does not erase data independently held by Discord, TikTok, Whop, your bank or your downloaded files; use those services' own controls where necessary. Withdrawing optional consent stops the corresponding future processing unless another lawful basis applies, without invalidating earlier lawful processing.
Haze uses HTTPS for network communication, encrypted storage for TikTok tokens, signed sessions, access controls, rate limits, and other technical safeguards. No internet service can guarantee absolute security. If a breach affects your personal information, we will notify you and the authorities where the law requires it.
Haze is not intended for children under 13 or below a higher minimum age applicable to the service where they live. We do not knowingly collect their personal information. If we learn an ineligible child provided information, we will take steps to remove it, subject to any necessary legal or safety retention. Parents or guardians can contact us about a child's information. A minor's account does not prove valid parental permission or payment authorization.
We update the date when this notice changes and provide appropriate notice of material changes. If a new use of information requires consent or another legal step, publishing an updated notice or continuing to use Haze does not substitute for that requirement. Changes do not retroactively authorize a use that was unlawful when it occurred.
Haze Method, operated from the Philippines, is responsible for the information described in this policy. For privacy questions or data requests, email haze@hazemethod.xyz or contact staff through the official Discord community linked at hazemethod.xyz.
This policy applies to the Haze website, Discord bot, browser extension, and backend service. Third-party services maintain their own privacy practices.