Privacy Policy
2026-08-06 (draft)
1. What Data We Collect
Account information obtained via Google Sign-In: email address, display name, and profile photo URL.
Conversion history metadata: filename, conversion type, and timestamp (not the file content itself).
Transaction records: credit ledger entries (amount, time, type, and any related Stripe transaction ID).
Files you upload for conversion and the resulting output files (retained temporarily — see retention period below).
2. How We Use Your Data
To provide the conversion service itself, manage your credits and paid balance, and prevent fraud and duplicate charges (e.g. via idempotency keys).
3. Who We Share Data With
Stripe: processes payment transactions and holds your card information; our servers never touch the card number itself.
Google Cloud / Firebase: provides authentication, database (Firestore), file storage (Cloud Storage), and compute (Cloud Run) infrastructure. Your data is physically stored in Google Cloud data centers (region: asia-east1).
We do not sell your personal data to third parties or use it for marketing unrelated to the conversion service.
4. Data Retention
Uploaded and converted files are automatically deleted after 30 days.
Billing-related records (the credit ledger) are retained longer than other data, due to tax/accounting recordkeeping requirements (the exact retention period is pending formal accounting/legal advice).
5. Your Rights Over Your Data
These rights apply to all users, and were specifically designed to satisfy EU GDPR requirements:
Access and data portability: export your personal data via your account settings (backed by GET /api/v1/me/export).
Right to erasure: delete your account yourself (backed by DELETE /api/v1/me). Your personal data and converted files are deleted immediately; financial records retained for legal/tax reasons are anonymized so they can no longer be linked back to your identity.
6. Cookies and Tracking
The site uses a cookie to remember your language preference. (If analytics tooling such as Google Analytics is added later, this section will be updated to disclose it.)
7. Data Security
We use industry-standard access controls (e.g. least-privilege server-side permissions, identity verification for all data access) and encryption in transit. No method of storage or transmission is perfectly secure, and you are responsible for keeping your account credentials safe.
8. Contact
For questions about this policy or your data, contact us at top9lab@gmail.com, or via our Contact page.
9. Changes to This Policy
Material changes to this policy will be announced on the site in advance.