Privacy Policy
Last updated: 2026-10-02
1. Encrypted transfer: we cannot read your content
Content in Encrypted transfer is encrypted in your browser before upload. The server stores only ciphertext and cannot decrypt it.
- The encryption key is set by you and is never uploaded. We do not hold it.
- Your login password is used for signing in only and is unrelated to protecting encrypted content.
Even if the database were stolen in full, an attacker would get only ciphertext. But please remember: if you forget your encryption key, that content cannot be recovered.
2. What data we collect
1. Account data
- The custom ID you choose
- Your email (entered at sign-up). It is stored in a separate table, readable only by you and administrators, and is never shown on the forum or your profile page
- A one-way hash of your password (handled by Supabase Auth — we never see the original)
2. Service data
- Content you save in Encrypted transfer, stored as ciphertext
- Prompts you submit to AI customization, plus the generated tool code and config (visible only to you)
- Forum posts and comments you publish (this part is public)
- Device info: device name (inferred from the browser UA), a random device identifier, last activity time
3. Security and operations data
- Timestamps and event types for security events such as sign-in, password change and account recovery
- A salted hash of your network address (used for anti-abuse and rate limiting). We do not store your plain IP, and the hash cannot be reversed
- Front-end and sandbox error messages and stacks (for troubleshooting). They do not include what you typed into tools
3. Data involved in AI customization and payments
1. AI customization
- The prompt you enter is sent to a third-party model provider (currently DeepSeek) to generate a result. This is a precondition for the feature to work
- Generated code and tool config are stored in our database, visible only to you
- Please do not write passwords, keys or national ID numbers into a prompt — it leaves our servers
2. Top-ups and payments
- Payments are handled by Lemon Squeezy as Merchant of Record, under its own privacy policy
- We never see or store your card number or full payment credentials
- We only keep the order id, amount, currency and credit-grant result, for reconciliation and support
4. What we do not do
- We do not sell, rent or trade your data.
- We do not use third-party advertising or behavioural-tracking SDKs.
- We do not read your encrypted content (we technically cannot).
- We do not train models on your encrypted or forum content.
- Apart from “AI customization sends your prompt to a model provider” and “payments go through Lemon Squeezy”, we do not share your data with third parties.
5. Where data is stored
Servers are located in Hong Kong SAR, China (Alibaba Cloud). If you access the service from another jurisdiction, your data will be transferred to and processed there. Using the service means you understand and accept this cross-border transfer.
Database backups are kept compressed and encrypted in a restricted directory on the server. The most recent 14 are retained and older ones roll off automatically. Backups contain ciphertext and service data, and no plaintext keys.
6. Local storage
We use the following local storage in your browser (no third-party tracking cookies):
localStorage: random device id, tool preferences and favouritessessionStorage: error de-duplication markersIndexedDB: unlock state for Encrypted transfer (expires after 7 days by default; not written in private mode)- Supabase auth cookie: keeps you signed in
Clearing browser data clears all of the above; you will then need to sign in again and re-enter your transfer key.
7. Your rights
To the extent applicable law (such as GDPR or CCPA) provides, you may request to access your account data, correct inaccurate information, delete your account and related data, and export your data.
Because of the encryption design, the “your data” we can hand over directly is mainly account metadata and the ciphertext itself. Only you can decrypt the plaintext of encrypted transfers.
To exercise these rights, contact: support@mirrorangel.com
8. Data retention
- Account and service data: until you delete them.
- Security event logs: automatically cleared after 180 days.
- Front-end and sandbox error logs: automatically cleared after 180 days.
- Rate-limit and sign-up attempt records: automatically cleared after 7 days.
- Database backups: the most recent 14 are retained; older ones roll off automatically.
9. Minors
This service is not directed at children under 13, and we do not knowingly collect their data.
10. Changes
If this policy changes materially, we will update the “Last updated” date on this page. Continued use means you accept the revised policy.
This English version is provided for convenience. If there is any discrepancy, the Chinese version prevails.