Legal
Privacy Policy
Last updated: August 28, 2026
This policy explains how AutoWorkflows collects, uses, and protects your information. See also our Terms of Service, Refund Policy, and Cookie Policy.
1. Data Controller
The data controller for the Service is: • Name: Yao Huibing (individual operator) • Location: People's Republic of China • Privacy contact: [email protected] • Data Protection Officer (DPO): Not applicable — small-scale processing; no DPO appointed.
2. Information We Collect
2.1 Information you provide • Account information: email address, password (hashed), display name, and profile preferences. • Payment information: transaction amounts and payment status. We do not store full card numbers — card data is handled exclusively by our payment processor (see Section 5). • Content you submit: scripts, prompts, uploaded assets, and generated project metadata, processed to provide the Service. • Communications: support emails and form submissions. 2.2 Information collected automatically • Device and network: IP address, device type, operating system, browser type, and time zone. • Usage data: pages visited, features used, generation jobs, session duration, and error logs. • Moderation screening: to enforce our Acceptable Use Policy, user-submitted text prompts are screened by a content moderation service before generation. We do not collect precise location data and we do not offer third-party social login.
3. How We Use Your Information
We use your information for the following purposes, each paired with its legal basis: • Providing and maintaining the Service — contract performance • Billing and payment processing — contract performance • Customer support — contract performance / legitimate interests • Service notifications (billing, security, policy updates) — legitimate interests • Security, fraud, and abuse prevention (including content moderation) — legitimate interests • Product improvement and analytics — legitimate interests • Legal compliance — legal obligation • Marketing emails (only where you opt in) — your consent We may aggregate or de-identify data for statistical analysis. Aggregated data cannot identify individual persons.
4. Cookies & Tracking Technologies
We use the following cookie categories: • Strictly necessary — maintaining login and core functionality — cannot be disabled • Functional — language and preference settings — can be disabled • Analytics — anonymized usage statistics — can be disabled We use Google Analytics on the marketing site, loaded only after you accept non-essential cookies via our Cookie Banner. See our Cookie Policy for details and opt-out instructions.
5. Sharing of Information
We do not sell your personal information, including as "sale" is defined under applicable law such as the CCPA. We share information only in these circumstances: • Service providers (under confidentiality obligations): Waffo Pancake (payment processing), Vercel (hosting), Supabase (database), Cloudflare (file storage and CDN), Google Analytics (marketing-site analytics, consent-based), and AI generation providers — Anthropic (Claude Sonnet, script writing), OpenAI (GPT-5, script writing; gpt-image-2, image generation), ByteDance (Seedance 1.5 Pro, video), Kuaishou (Kling v3 Omni, video), MiniMax (H3, video), and ElevenLabs (v3, voice) — which process prompts and project data solely to generate your outputs. • Content moderation: user-submitted prompts are screened by our content moderation provider to detect prohibited content. • Legal and regulatory requirements: where required by law, court order, or a competent authority. • Business transfers: in a merger, acquisition, or asset sale, with notice and continued protection obligations where required. • With your consent: for other purposes following your explicit prior consent. Payment card data is processed exclusively by Waffo Pancake, our PCI-DSS compliant payment processor, and is never stored on our servers.
6. Data Security
We implement administrative, technical, and organizational measures to protect personal data: • Encryption in transit (TLS / HTTPS) • Passwords hashed; sensitive fields encrypted • Access on a least-privilege basis • Regular dependency and vulnerability reviews If a security incident affects your rights, we will notify you and relevant regulators within 72 hours of discovery, as required by applicable law. No method of transmission or storage is 100% secure; please keep your credentials secure and do not share them.
7. Data Retention
We retain personal data as follows: • Account information — while your account is active; 90 days after closure — then deleted or anonymized • Billing and transaction records — 7 years (tax and accounting requirements) — archived or deleted as required by law • Support communications — 24 months — then securely deleted • Security and access logs — 12 months — then securely deleted • Generated content and project data — stored with your account; removed within 90 days of account closure You may request earlier deletion of your data at any time (Section 8), subject to legal retention requirements.
8. Your Data Rights
Depending on your jurisdiction (including GDPR and CCPA where applicable), you may have the right to: • Access — obtain a copy of your personal data • Rectification — correct inaccurate or incomplete data • Erasure — request deletion (subject to legal retention) • Restriction — pause processing in certain circumstances • Portability — receive your data in a machine-readable format • Objection — object to processing based on legitimate interests or marketing • Withdraw consent — withdraw consent-based processing at any time To exercise any right, contact [email protected]. We respond within 30 calendar days. If you believe we have not handled your request properly, you may lodge a complaint with your local data protection authority.
9. Marketing Communications
By default we send only service-essential emails (receipts, security notices, and policy updates). Marketing emails are sent only if you opt in. You can unsubscribe at any time via the unsubscribe link in any marketing email, in your account settings, or by contacting [email protected]. Unsubscribing does not affect essential service notices.
10. Cross-Border Data Transfers
Our servers and service providers are located in the United States and other regions outside your country. Where personal data is transferred across borders, we apply appropriate safeguards, including standard contractual clauses (SCCs) and transfers only to recipients offering adequate protection.
11. Children's Privacy
The Service is intended for users aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with information, contact [email protected] and we will delete it promptly.
12. Third-Party Links & Services
The Service may contain links to third-party websites or services. This Policy covers only information we collect directly. We are not responsible for third-party data practices; review their privacy policies before using them.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced at least 15 days before taking effect via email or in-product notice, and the "Last updated" date on this page will be updated. Continued use after the effective date constitutes acceptance of the revised Policy.
14. Contact Us
• Privacy contact: [email protected] • Customer support: [email protected] • Operator: Yao Huibing, People's Republic of China • Response hours: Monday–Friday, 09:00–18:00 (UTC+8) This Privacy Policy is provided for informational purposes and does not constitute legal advice.