Privacy policy
Privacy Policy
We process information needed to operate accounts, membership, image generation, security, and support. We do not sell personal information. This Policy explains what we process, why, where it goes, and how you can control it.
01Scope and controller
This Policy applies to personal information processed through xiaoxiaodong.ai, www.xiaoxiaodong.ai, vip.xiaoxiaodong.ai, and the related Service. The operator of the Xiaoxiaodong Member Site is the controller or personal-information processor for the processing described here, except where an independent provider acts under its own policy.
This Policy should be read with the Terms of Service and AIGC Acceptable Use Policy. A third-party destination you choose to visit is governed by that provider’s privacy notice.
This English version is provided for accessibility. If it conflicts with the Chinese version, the Chinese version controls to the extent permitted by law. Mandatory privacy rights remain unaffected.
02Information we process
| Category | Examples | Purpose |
|---|---|---|
| Account and identity | Email, password hash, Google sign-in identifier and profile data, nickname, avatar, role, account status, session and device identifiers, device public key (not the private key), and timestamps | Create and secure accounts, authenticate users, enforce a single-device session, display profiles, and administer access. The device private key is never sent to our server. |
| Membership and orders | Plan, price, currency, term, redemption record, order and provider transaction IDs, payment status, reconciliation and refund data | Activate membership, reconcile payments, prevent duplicate fulfillment, provide support, and meet accounting or legal duties. |
| Usage and security | IP-derived request data, user agent, request time, route, response status, session and rate-limit signals, error and audit logs | Operate the Service, diagnose faults, prevent abuse, protect accounts, and investigate security incidents. |
| Sign-up and purchase funnel | Random event ID, random tab-session ID, event type, site language, page path without query parameters, selected payment provider, and an account ID only when already signed in | Identify, in aggregate, where sign-up or checkout becomes blocked. This funnel does not store IP addresses, user agents, referrer URLs, search terms, page content, or free-form fields. |
| Preferences and activity | Favorites, ratings, navigation and layout preferences, notification state, newsletter status, and account-linked actions | Provide personalized state, saved items, communications, ordering, and continuity across sessions or devices. |
| Image generation | Prompts, additional instructions, reference images, size, quality, quantity, selected model/provider, task state, and errors | Queue, execute, retry, secure, and display requested generation tasks. |
| Generation history | Generated files and thumbnails, task and work IDs, timestamps, parameters, prompts, references, and draft snapshots | Allow you to view, resume, organize, or delete your private history across devices. |
| Custom image API | Provider name, endpoint, model, encrypted API key, masked last characters, priority, and recent-use time | Call the compatible provider you configure and support provider fallback. Keys are decrypted only when operationally necessary. |
| Support and rights requests | Email, account or order reference, communications, complaint evidence, and identity-verification material | Answer questions, handle refunds, appeals, privacy requests, infringement reports, and disputes. |
Do not submit unrelated identity documents, financial-account details, precise location, health or biometric data, children’s information, trade secrets, full API keys, or other sensitive information in prompts, references, profile data, or support messages.
03Purposes and legal bases
Depending on the context and applicable law, we process information to perform a contract or take requested pre-contract steps; comply with legal, tax, accounting, anti-fraud, and regulatory duties; protect users, the Service, and legal rights; pursue legitimate operational and security interests where recognized; or act on consent for optional communications or functions.
Where consent is required, you may withdraw it for future processing. Some information is necessary to create an account, fulfill a purchase, run a generation request, protect the Service, or satisfy law; without it, the relevant feature may be unavailable.
04Cookies, local storage, and analytics
We use essential cookies or similar storage for login sessions, security state, theme, layout, navigation, generation drafts, recent filters, and other settings. sessionStorage also holds a random ID for the current tab session so sign-up and purchase steps can be deduplicated and measured in aggregate; closing the tab ends that browser session, and we do not use it for cross-site advertising. The browser also stores a non-extractable device private key in IndexedDB to sign short session-renewal challenges; our server stores only its public key. If persistent CryptoKey storage is unavailable, the key is temporary and shared only among currently open tabs, so closing all tabs requires sign-in again. Blocking essential cookies, Web Crypto, or IndexedDB may prevent member sign-in or saved preferences.
Cloudflare may process network and security data to deliver, protect, and cache the Service. Where enabled, Cloudflare Web Analytics provides aggregated traffic measurements such as page views, referrers, device or browser categories, and approximate geography. We do not use this Policy to authorize third-party advertising cookies or cross-site behavioral advertising.
05Image-generation data and model providers
When you request generation, the prompt, reference image, chosen settings, and necessary technical metadata are transmitted to the selected image-model or API provider. If you configure your own compatible provider and API key, the request is sent to the endpoint you selected. That provider may process data independently under its own terms and privacy policy.
Review provider policies before using a model, especially for confidential, personal, or regulated information. We do not use private generation history as a public catalog. We do not authorize third parties to train models on your private history merely because files are stored through the Service.
06Sharing and disclosure
We do not sell personal information. We disclose only what is reasonably necessary to categories such as hosting, security, database and object-storage providers; sign-in providers; payment processors; email-delivery services; model or API providers selected for generation; professional advisers; and competent authorities or counterparties where law, safety, fraud prevention, dispute handling, or rights protection requires it.
Providers receive information under their service role, instructions, contracts, technical configuration, or independent legal obligations. If the business is reorganized, merged, or transferred, relevant information may transfer with appropriate notice and safeguards required by law.
07International and cross-border processing
Cloud infrastructure, Google sign-in, email delivery, payment, and model providers may process information outside your country or region. The destination, provider, and route depend on the feature and provider you choose. Where cross-border transfer rules apply, we will use a lawful mechanism and provide notices, obtain consent, complete assessments, or adopt contractual and security safeguards as required.
08Retention
- Account and membership records are kept while the account is active and as reasonably necessary afterward for deletion processing, disputes, and legal duties.
- Payment and order records are retained for reconciliation, tax, accounting, fraud prevention, refunds, and statutory periods.
- Generation history is retained until you delete it, close the account, or the applicable feature or retention rule changes, subject to backup cycles, disputes, security holds, and legal obligations.
- API configurations are retained until deleted or the account is closed; encrypted secrets may persist briefly in protected backups until rotation.
- Security, audit, and error logs are retained only for a period reasonably necessary for reliability, abuse prevention, investigation, and legal claims.
- Short session leases and challenges expire promptly; a device public key remains until another device login replaces it, the account is closed, or it is no longer needed.
When information is no longer needed, we delete, anonymize, or securely isolate it unless continued retention is required or permitted by law.
09Security
We use measures appropriate to risk, including HTTPS, password hashing, encrypted API keys, access controls, account and object isolation, private generated-history paths, input validation, rate limits, logging, backups, and incident handling. No system is absolutely secure, so use unique credentials, restrict API-key scope, and notify us promptly about suspected compromise.
If a personal-information incident is likely to create legally significant risk, we will contain and investigate it, notify affected persons and regulators where required, and provide available mitigation guidance.
10Your privacy rights
Subject to identity verification, applicable law, and lawful exceptions, you may request access or a copy; correction or completion; deletion; withdrawal of consent; restriction or objection; portability where available; an explanation of material automated decisions; appeal of a refused request; or account closure.
Some controls are available directly through settings, unsubscribe links, generation history, and API configuration pages. For other requests, use the contact details below and identify the account and request. We may limit a manifestly unfounded, repetitive, abusive, or rights-conflicting request, or retain information needed for another person’s rights, trade secrets, security, transactions, claims, or law, and will explain where required.
11Email and notifications
We may send service messages needed for account security, payment, membership, password recovery, important policy changes, or requested support. Optional newsletters may be managed in settings or through an unsubscribe link. Disabling optional marketing does not stop essential transactional or security messages.
12Children and minors
The Service is intended primarily for persons with full legal capacity and is not directed to children under 14. Minors should use and purchase only with guardian involvement. If we learn that a child’s information was processed without required authorization, we will delete it or take another legally required measure. Guardians may contact us using the details below.
13Policy changes
We may update this Policy for legal, security, provider, or product changes and will publish the updated date. If a change materially affects your rights or expands processing, we will provide prominent or direct notice and seek consent where required. An update does not retroactively authorize processing for which we lacked a lawful basis.
14Contact us
To exercise a privacy right, report a data-security risk, ask about this Policy, or appeal a response, identify the relevant account and request and provide only the evidence reasonably necessary for verification.
Controller / processor: Operator of the Xiaoxiaodong Member Site
Website: https://vip.xiaoxiaodong.ai
Privacy and support email: yeschenxiang@gmail.com
WeChat support: Open support chat
You may also complain to a competent data-protection, cybersecurity, market-supervision, or other regulator, or seek a judicial remedy where available.