Privacy Policy
Privacy is not just our policy, it is built into our architecture.
Overview
This application uses a cloud-lite architecture. Content is processed transiently by cloud infrastructure solely to perform requested functions and is never stored, retained, or logged. All persistent data remains exclusively on the user's device (web browser).
1. Zero Data Retention
We do not maintain any copy, backup, log, or record of your private data at any point during or after processing. Once a cloud processing task is complete, any transient data held in memory is immediately discarded. Our cloud infrastructure functions purely as a processing engine, performing computations and returning results without retaining anything. No databases, backups, or third-party storage services are used to hold user content.
2. Your Data, Your Device
All content, files, and personal information are stored exclusively on your own device, within your browser (via local storage, session storage, or cache). We have no access to this data and cannot retrieve it, since it never resides on our systems. You retain full control to access, delete, or export your data at any time via your browser settings. Clearing this data resets your on-device content, since we hold no backup copy elsewhere.
3. Cookies and Browser Storage
As a web-based application, we may use functional browser storage mechanisms strictly necessary for the app to operate, such as maintaining your session or language preference. We do not use tracking cookies for advertising or cross-site profiling.
4. Subscription and Billing
Payment and subscription details are processed by our third-party payment processor. We do not store full payment card information on our servers. We may retain minimal billing metadata (subscription status, transaction dates) for account and invoicing purposes only, separate from your private content data. Please refer to our payment processor's own privacy policy for details on how they handle payment information.
5. Compliance and Security
We aim to comply with applicable data protection laws in each user's jurisdiction, including:
- India's Digital Personal Data Protection Act (DPDPA): we act as a data fiduciary with minimal obligations given our zero-retention model.
- European Union GDPR: no personal data is stored; any transient processing is based on legitimate interest or consent.
- China's Personal Information Protection Law (PIPL): our architecture avoids cross-border data storage entirely since nothing is retained.
Our zero-retention, on-device storage model inherently satisfies core requirements across these frameworks, including purpose limitation and data minimization.
Data in transit is encrypted using industry-standard protocols. Since no data rests on our servers, there is no server-side data at risk of breach.
6. Multilingual Support
This policy is available in the app's supported languages, including Mandarin, Japanese, French, German, and Arabic, to ensure clarity for all users regardless of region.
7. Your Rights
Since your data lives on your device, you retain full access, deletion, and export control at all times. You may request information regarding any limited processing metadata we might handle.
Your data is processed, not possessed. Nothing stored. Nothing retained. Nothing at risk on our servers.
BS2D