Back to collection

Privacy notice

Data we process

Google or GitHub sign-in provides a stable account identifier, verified email and any display name the provider returns. Email-code sign-in processes your email address and briefly stores an encrypted code hash, expiration and failed-attempt count. We also store hashed session identifiers, purchase and entitlement references, security events and necessary technical logs.

Payment data

Waffo Pancake processes payments. Visual Prompts does not store complete card numbers. We receive order, product, amount, currency, status and refund information needed to manage access.

Cookies and security

The sign-in cookie contains only a random session token and uses HttpOnly, Secure and SameSite=Lax protections. The database stores only its hash. OAuth state, PKCE records and email-code challenges are short-lived and invalidated after use. Resend delivers verification emails.

Use and retention

We use data to authenticate users, restore purchases across devices, process access, prevent fraud, provide support and meet financial or legal obligations. We retain it only for service operation, security review and applicable record-keeping periods.

Your choices

You can sign out or email chaoqiang.tian@gmail.com to request access, correction or deletion. The 365-day access pass does not renew automatically. Transaction records required by law may not be deleted immediately.

Contact: chaoqiang.tian@gmail.com