Privacy Policy
Last updated: 2026-09-27
This policy describes what actually happens on this site. No speculative features are described here.
1. Your files (the most important part)
All eight online tools process files locally in your browser. Your images, videos and subtitle files are never uploaded to our servers or any third party. You can verify this in your browser's developer tools (Network panel): no file content is transmitted when you use the tools.
2. Account (email sign-in)
Browsing requires no account. When you start a processing task, you are asked to sign in with an email address and a 6-digit verification code sent to that address.
- Stored: your email address, one-way hashed verification codes (the code itself is never stored), and session records. Billing also keeps a persistent hashed account mapping, quotas, orders and credit ledger — no name, no phone number, no password (accounts are code-verified).
- Session: a signed, HttpOnly login cookie that keeps you signed in for up to 30 days. Sessions are recorded server-side so that signing out revokes them: after "Sign out" or "Delete", the old cookie is immediately invalid everywhere.
- Purpose: to operate the sign-in flow and anti-abuse rate limiting (per-email counters are stored server-side; coarse per-IP counters are kept in memory only).
- Deletion: use "Delete account data" in the account menu, or the Contact page. Deleting revokes all your sessions and removes the stored email record and verification-code entries. Verification codes expire within 10 minutes.
3. Usage quotas & credits (billing)
- What is recorded: for tools with weekly free limits, the server keeps a counter per account per tool per week. Purchased credits are tracked as an integer ledger. Both are keyed by a one-way hash of your email address — the quota tables themselves do not contain your email in plain text.
- Deletion boundary: "Delete account data" removes your sign-in records but does not reset free-use counters or erase purchased credits — otherwise deleting and re-signing-in would be a way to reset quotas. This is intentional and disclosed here. If you want your quota records and credit balance removed as well, contact us via the Contact page and we will delete them.
- Credits: paid credits do not expire, are not auto-renewed, and cannot be transferred or withdrawn. Failed or cancelled tasks restore your points. Credits are valid only for services on this site.
- During acceptance testing: live payments remain disabled. Local simulated purchases are restricted to localhost. PayPal sandbox purchases require developer test accounts. No self-service cash refund feature is provided; failed or cancelled tasks restore points.
4. Cookies & local storage
- aippxp_lang — remembers your language choice (English / 简体中文). Set only when you switch languages.
- Session cookie — as described above, only after you sign in.
- localStorage — on older article pages, likes and comments you write are stored in your own browser only.
5. Analytics & advertising
The site currently runs no third-party analytics and no advertising scripts. We do keep server access logs (for security and troubleshooting) via our hosting provider, Cloudflare.
6. Email delivery
Verification emails are sent through a transactional email provider. It receives only the recipient address and the message content; it is not used for marketing. There is no newsletter.
7. Children
The site is not directed at children under 14, and we do not knowingly collect their data.
8. Changes
If the site later adds analytics, ads or uploads, this policy will be updated first — and such features will not silently ship while this text says otherwise.