VI
Bắt đầu miễn phí

Privacy Policy

Last updated 2026-09-13 · This page is written in English.

This policy explains what aix0 ("we") collects when you use the aix0 website and related services, why we collect it, who we pass it to, how long we keep it, and how you can control it. It forms part of the Terms of Service.

1. What we collect

We collect only what the service needs, in six categories:

  • Account information: your email address, a hash of your password (we never store the password itself), and your interface language. If you sign in with Google or Telegram, also the account identifier and email address that provider returns.
  • What you submit: images and material you upload, the prompts you write, the generation parameters you choose, and the results they produce.
  • Generation and billing records: the status of each task, the capability and parameters used, credit holds and deductions, and order and payment status.
  • Session and device information: a hash of the session token, your IP address, and your browser's User-Agent. The last two are used to spot unusual sign-ins and prevent abuse, and are attached to the session record only.
  • Product analytics: the page route, the domain of the referring site, a device-level anonymous identifier, and the event name. This data is subject to the hard limits in Section 6.
  • Correspondence: feedback and appeals you submit, and email exchanges with us.

We do not collect card numbers, bank account numbers, or any payment credentials. Payment happens on the payment provider's own pages and that information never reaches our servers. See Section 3.

2. How we use it

  • To run the service: carry out the generations you submit, store your work, and keep you signed in.
  • For billing: meter credit use, process orders and subscriptions, reconcile accounts, and issue receipts.
  • For security and anti-abuse: detect unusual sign-ins, limit bulk registration and farming, and protect accounts and the platform.
  • For moderation and compliance: check submitted material and generated results against the Acceptable Use Policy, and handle reports and appeals.
  • To improve the service: use aggregated usage data to judge which features earn their place and where the interface breaks.
  • To meet legal obligations: accounting, tax, lawful requests from authorities, and records the law requires us to keep.

We do not sell your personal information to anyone, and we do not use it for third-party advertising.

3. Who we share it with

To carry out what you ask for, the following providers see the corresponding information. They may process it only on our instructions and only for the purpose listed.

  • AI model providers: to complete a generation, your prompt and uploaded material are sent to whichever model provider the request is routed to. Currently that is OpenAI, Google (Gemini), Volcengine, Alibaba Cloud Qwen, and MiniMax. We do not guarantee which one handles any particular generation.
  • Payment provider: checkout, charging, receipts, and refunds are handled by Paddle as Merchant of Record. The name, billing address, tax identifier, and payment credentials you enter at checkout are collected by Paddle directly; we receive only the order reference, amount, currency, country, and payment status.
  • Object storage: uploaded material and generated results are stored in Alibaba Cloud Object Storage (OSS).
  • Email delivery: verification codes and notification emails are sent through the mail provider we have configured, which sees your email address and the contents of the message.

We may also disclose information where the law requires it, where authorities lawfully request it, or where it is necessary to protect someone's vital interests.

4. Generated content and model training

We do not use your prompts or uploaded material to train any model of our own.

The model providers' terms are not identical. Some commit in writing, on their paid tiers, not to use submitted content for training and to retain logs only briefly for abuse detection. Others make no written commitment on the point. We therefore cannot promise in general terms that your content will never be used for training by anyone — that is not ours alone to decide.

What we do commit to: we send only the content needed to complete your request, only to the provider needed to complete it, and we do not supply your content to any third party for training purposes.

Please do not put sensitive personal information into prompts or uploads that you would not want processed by a third party.

5. Cookies and local storage

aix0 uses no third-party advertising or analytics cookies, and embeds no third-party tracking scripts. We set three cookies in total, all of them either strictly necessary or a direct result of a choice you made:

  • __Host-aix0_session (aix0_session on deployments without HTTPS): keeps you signed in. HttpOnly, Secure, SameSite=Lax, and unreadable by page scripts. It expires after 24 hours idle, or 30 days at the outside.
  • __Host-aix0_oauth (same naming rule): prevents cross-site request forgery during a third-party sign-in redirect. It lasts 10 minutes and is cleared as soon as sign-in completes.
  • aix0_locale: remembers the interface language you picked. It lasts one year.

The device identifier used for product analytics lives in your browser's localStorage rather than in a cookie. It links visits and conversions on one device only — never across devices or across sites — and clearing your browser's site data resets it.

Because we set no non-essential cookies, we do not show a cookie consent banner.

6. The limits on product analytics

We measure visits and conversions with our own events table rather than a third-party analytics service. The table is constrained by design so that it cannot hold information that identifies a person:

  • No IP address is recorded, and no User-Agent.
  • Only the route of a page address is kept. Anything after the question mark is discarded once in the browser and again on the server, so a token or an email address that appeared in a URL is not retained.
  • Only the domain of a referrer is kept, never the full referring URL.
  • Event properties accept scalar values only. Field names such as email, prompt, phone, and address — and any value shaped like an email address — are rejected rather than stored.
  • When an account is deleted, the link between these records and the account is cleared, leaving a funnel shape that points at nobody.

7. How long we keep it

  • Account information: for as long as the account exists; after deletion, as set out in Section 8.
  • Uploads and generated results: for as long as the account exists, or until you delete them.
  • Sessions: 30 days at the outside, expiring after 24 hours idle. Signing out ends that session immediately.
  • Orders, payments, and the credit ledger: for the period required by applicable accounting and tax law. These records survive account deletion, but are unlinked from your identity.
  • Moderation records and administrative audit logs: to handle appeals, prevent repeat breaches, and meet legal requirements.
  • Generation records and content-labelling logs: as required by Section 6 of the Terms of Service and applicable regulation.
  • Free-credit grant records: only a hash of the email address is stored, never the address, and it is kept after the account is deleted — its sole purpose is to stop the same mailbox claiming free credits again by deleting and re-registering. The record cannot be turned back into your address.

8. Account deletion

You can request deletion from your account settings. Two things happen immediately: every session is revoked, and the account enters a pending-deletion state in which the service cannot be used.

Deletion carries a 30-day grace period. During those 30 days you can cancel the request and the account returns to normal with its data intact. After the grace period ends we delete or anonymise your account information, uploads, and generated results.

The following do not go away with deletion: order, payment, and ledger records the law requires us to keep (retained with the identity link removed); the free-credit email hash described in Section 7; and moderation records for a breach already found, kept to prevent a repeat.

Deleting your account does not cancel a subscription. Cancel it first on the billing page, as described in the Refund Policy, or charges may continue.

9. Your rights

You have the right to access, correct, export, and delete your personal information, to withdraw consent you previously gave, and to object or complain about how we handle it.

Most of these you can exercise directly in the product: account settings show and change your account information, the work list deletes uploads and results, and account settings start a deletion request.

For anything else, use the feedback page in the app. We will verify who you are and respond within the period applicable law allows. We will not treat you differently for exercising a right.

10. International transfers

Your prompts and uploaded material are sent to model providers whose servers may be in other countries or regions. Payment information is processed by Paddle on its own infrastructure.

Where a transfer crosses a border, we require the recipient by contract to provide protection no lower than this policy.

11. Children

We do not offer the Services to anyone under 14. If you are under 18, you may use them only with the consent of a parent or legal guardian.

If we find that we have unknowingly collected information from a child who does not meet those conditions, we will delete it promptly. A guardian may ask us to delete it using the contact below.

12. Security

Passwords are stored as salted hashes and cannot be recovered by us. Session cookies are HttpOnly and Secure and are checked against a CSRF token. Third-party provider keys are encrypted in the database. The admin console has its own permission system and multi-factor authentication, and its actions are audited.

No system can be guaranteed secure. If a breach occurs that may affect your rights, we will notify you and the relevant authority as applicable law requires.

13. Changes and contact

We may revise this policy. Material revisions will be announced on the site before they take effect.

Contact: the feedback page in the app.