隐私政策 / Privacy Policy
最后更新 · Last updated 2026-10-09
一句话:常规修图在你自己的浏览器里完成,这一步不上传;唯一会把内容送到我们服务器的是 AI 生图与 AI 改图(保留 14 天,只对你本人可见)。除此之外,我们只收集你自己交出来的联系方式、反馈,以及维持服务所需的少量日志。
In one line: ordinary retouching is processed in your browser and is not uploaded; the one step that does send content to our servers is AI generation and AI edits (kept for 14 days, readable only by you). Beyond that we collect only the contact details and feedback you choose to give us, plus the small amount of logging a service needs to run.
隐私政策
1. 你的图片
常规修图不上传。编辑器(包括从落地页「打开」或粘贴进去的图片)完全在你的设备上运行:像素在浏览器的 WebAssembly 里处理,这一步不会上传、不会被我们读取或存储。
AI 生图与 AI 改图是唯一的例外,而且要登录后才能用:提示词与参数发到我们的服务器,再交给第三方模型服务(阿里云百炼 DashScope)生成;AI 改图还会把那张源图一起发过去(长边压到 512–2048 像素、不超过 10MB)。
这一步我们存下:提示词、你选的档位与尺寸、消耗的点数,以及改图时的源图与生成结果。它们只对你本人可见(要鉴权才读得到),14 天后自动删除;也可以随时写信要求提前删除。
常规修图不经过我们的服务器,所以我们没有办法恢复你丢失的编辑成果 —— 请自己保存文件。
2. 我们自己收集什么
只有下面这些,而且都是你自己交出来的:
- 账号数据(只有你注册时才有):站点提供可选的账号。注册或登录后我们存:邮箱;你设置的密码的 bcrypt 哈希(只有设置过密码的用户才有,纯验证码或 Google 登录的用户没有密码);Google 登录返回的邮箱与账号标识;你的收藏与下载记录;你自定义的导航栏次序;账号的创建与最后更新时间。用途只有一个:让这些个性化功能在你登录后跨设备可用。
- 候补邮箱:你留下邮箱时,我们存下邮箱、界面语言、来源页面、你选填的留言、提交时间与当时的 IP(用于限流与滥用排查)。用途只有一件:上线时通知你一次。
- 公测反馈:你在服务台写的问题,我们存下文字、来源页面、时间与 IP。它不需要邮箱,也不与你留下的邮箱自动关联。
- AI 任务记录(只有你用 AI 生图或 AI 改图才有):提示词、档位与尺寸、消耗的点数、成功还是失败;改图还包括那张源图与生成结果。用途是完成这一次生成、退还有关点数与排查故障。保留 14 天后自动删除(见第 1 条)。
- 赞助记录:支付成功后,支付服务商回调告诉我们订单号、金额、币种、测试/正式环境与你填写的邮箱;我们把它记进收款记录用于对账。卡号等支付信息不会到我们这里。
- 访问日志:服务器与 CDN 会记录 IP、User-Agent、请求时间,用于安全与容量。
- 产品使用事件:你在编辑器里的操作会以匿名事件上报 —— 打开了哪个菜单、选了哪个工具、开了/导出了哪一类文件(只记 PSD/图片这种类别)、导出成没成、耗时多少,以及你在界面骨架(菜单、工具栏、面板)上的点击位置,用来做热力图与操作路径分析。这些事件不含图片内容、不含文件名、不含你输入的文字、不含账号标识;会话标识只在这一次打开期间有效,不写 Cookie。自建 Umami 无 Cookie,GA4 已开启 IP 匿名化。
- 我们不做会话回放:编辑器画布上就是你自己的照片,录屏/录 DOM 等于把图传出去 —— 所以统计只到「点了哪个菜单」这一层为止。
3. 账号,以及「我们不做什么」
修图派的编辑器不需要账号:打开 retouchpi.com 就能修图,浏览与常规修图都无需登录;这一步图片只在这台设备上处理,不上传。(AI 生图与 AI 改图要登录,它们也是唯一会离开这台设备的一步 —— 见第 1 条。)
站点另外提供可选的账号(邮箱验证码或密码,也可以用 Google 登录),用来记住你的收藏、下载记录与导航栏个性化。不注册也照样能浏览与修图 —— 账号不是使用编辑器的前提。
付款不需要账号:它只记录你填写的收据邮箱,与你是否注册无关。⛔ 但「终生免广告」这项权益要登录后才认得出是你 —— 请用登录本站的那个邮箱付款(详见《服务条款》第 4 节)。
不卖数据、不做跨站画像。
广告:本站部分页面由 Google AdSense 展示广告,广告脚本来自 Google。Google 作为第三方供应商,会用 Cookie(包括 DoubleClick Cookie)根据你以前在本站或别的网站上的访问情况投放广告。广告投放由 Google 处理,不经我们的服务器;我们拿到的是聚合的展示与点击数据,不是你的身份。
关掉个性化广告:你可以在 Google 广告设置(https://www.google.com/settings/ads)退出基于兴趣的广告,也可以用任何拦截器直接不加载广告脚本。退出后你仍会看到广告,只是不再按你的兴趣投放。
买断免广告:一次付清 US$9.99(或同一邮箱累计净付款达到 US$9.99)之后,我们不再向你展示广告 —— 广告位在渲染阶段就不产生,浏览器也不会为它向 Google 发请求。
4. 谁替我们处理
为了让服务跑起来,下面这些第三方会接触到对应的数据:
- Waffo Pancake —— 支付服务商(merchant of record),处理收款、税费与凭证。
- 阿里云百炼(DashScope) —— AI 生图与 AI 改图的模型服务:只在你主动用这两个功能时收到你的提示词(改图还包括那张源图)。常规修图不经过它。
- 自建 Umami 统计 —— 我们自己部署的访客统计:不使用 Cookie、不采集个人标识,只统计页面访问量。
- Google Analytics(GA4) —— 用于了解站点流量。它可能写入 Google 的 Cookie;可用浏览器拦截器或 Google 的停用工具关掉。
- Google AdSense —— 在部分页面展示广告。它会写入 Google 的 Cookie(含 DoubleClick Cookie)用于投放基于兴趣的广告;可在 https://www.google.com/settings/ads 退出个性化,或用任何拦截器不加载广告脚本。
- 托管与 CDN —— 承载站点与静态资源,会看到访问日志。
5. 保留多久、你的权利
候补邮箱保留到我们发出上线通知并确认送达之后;反馈与访问日志用于改进与排障,长期保留但会定期清理;AI 任务的提示词、源图与结果保留 14 天后自动删除;收款记录按财税要求保留。
你可以随时要求查询、更正或删除上面这些数据:写信到 605577690@qq.com,说明你的邮箱或提交时间,我们核对后处理。
6. 未成年人
本服务面向成年人与具备相应民事行为能力的用户;我们不面向 13 岁以下儿童,也不会主动收集他们的信息。
7. 变更
隐私政策变化时我们会更新本页顶部的日期;涉及新增数据用途时会在这里说明,而不是悄悄改口。
Privacy Policy
1. Your images
Ordinary retouching is not uploaded. The editor — including images opened from the landing page or pasted in — runs entirely on your device: pixels are processed in the browser by WebAssembly, and for that step nothing is uploaded to us, read by us, or stored by us.
AI generation and AI edits are the single exception, and they require a signed-in account: your prompt and settings go to our server and on to a third-party model provider (Alibaba Cloud Model Studio, DashScope); for an AI edit, that source image goes with them (longest side fitted to 512–2048 px, up to 10MB).
For that step we store the prompt, the tier and size you chose, the credits spent, and for an edit the source image and the results. Only you can read them (the path is authenticated), they are deleted automatically after 14 days, and you can ask us to delete them sooner at any time.
Ordinary retouching never passes through our servers, so we cannot recover work you lose; please save your files.
2. What we collect ourselves
Only this, and only what you choose to give us:
- Account data (only if you register): the site offers an optional account. When you register or sign in we store: your email; a bcrypt hash of your password if you set one (users who only ever use email codes or Google have no password); the email and account identifier Google returns; your favorites and download records; your custom navigation order; and the account creation and last-updated timestamps. The only purpose is to make those personalised features available across your devices while you are signed in.
- Waitlist email: when you leave an address we store the email, your interface language, the page you came from, an optional note, the time, and the IP at submission (for rate limiting and abuse checks). It is used for exactly one thing: telling you when the agent feature ships.
- Beta feedback: the text you write on the beta desk, the page it came from, the time, and the IP. It needs no email and is not linked to your waitlist address automatically.
- AI job records (only if you use AI generation or AI edits): the prompt, the tier and size, the credits spent, and whether it succeeded or failed; for an edit, that source image and the results too. The purpose is to carry out the generation, refund credits when it fails, and debug. Deleted automatically after 14 days (see section 1).
- Contribution records: after a payment, the payment provider calls us back with the order id, amount, currency, test/prod mode and the email you entered; we store that for reconciliation. Card details never reach us.
- Server logs: our server and CDN record IP, user agent, and request time for security and capacity.
- Product usage events: actions inside the editor are reported as anonymous events — which menu was opened, which tool was picked, which kind of file was opened or exported (just the category, e.g. PSD or image), whether an export succeeded, how long it took, and where you clicked on the interface chrome (menus, toolbar, panels) to build heatmaps and path analysis. These events contain no image content, no file names, no text you typed and no account identifier; the session id lives only for this page load and is not a cookie. Our self-hosted Umami sets no cookies, and GA4 runs with IP anonymisation.
- No session replay: the canvas holds your own photo, so recording the screen or the DOM would mean sending it out. Tracking stops at “which menu was opened”.
3. Accounts, and what we do not do
The editor needs no account: open retouchpi.com and start editing — browsing and ordinary retouching require no sign-in, and for that step your photos are processed only on your own device and not uploaded. (AI generation and AI edits do need a sign-in, and they are the one step where content leaves your device — see section 1.)
The site separately offers an optional account (email code or password, or Google sign-in) that remembers your favorites, download records and navigation preferences. You can browse and edit without registering — an account is not a condition of using the editor.
Paying needs no account: it records only the receipt email you type, independently of whether you have one. ⛔ But the ads-removed-for-life entitlement can only be recognised once you sign in — pay with the email you sign in with (see section 4 of the Terms).
We do not sell data and we do not build cross-site profiles.
Advertising: some pages of this site carry ads served by Google AdSense, and the ad script comes from Google. As a third-party vendor Google uses cookies (including the DoubleClick cookie) to serve ads based on your prior visits to this and other websites. Serving is handled by Google, not by our servers; what comes back to us is aggregated impression and click data, not your identity.
Turning off personalised ads: you can opt out of interest-based advertising in Google's Ads Settings (https://www.google.com/settings/ads), or block the ad script outright with any content blocker. You will still see ads after opting out — they just are no longer based on your interests.
Buying the ads off: one payment of US$9.99 (or US$9.99 in net payments accumulated on one email address) and we stop showing you ads — the ad slots are not produced at render time, so your browser makes no request to Google for them.
4. Who processes data for us
So that the service runs, these third parties see the relevant data:
- Waffo Pancake — payments (merchant of record): collection, tax, and receipts.
- Alibaba Cloud Model Studio (DashScope) — the model provider behind AI generation and AI edits: it receives your prompt (and, for an edit, that source image) only when you use those two features. Ordinary retouching never goes through it.
- Self-hosted Umami analytics — our own deployment: no cookies, no personal identifiers, just page view counts.
- Google Analytics (GA4) — to understand overall traffic. It may set Google cookies; you can block it with any content blocker or Google's opt-out tool.
- Google AdSense — serves ads on some pages. It sets Google cookies (including the DoubleClick cookie) to run interest-based advertising; opt out at https://www.google.com/settings/ads, or block the ad script with any content blocker.
- Hosting and CDN — they serve the site and static assets and see access logs.
5. How long we keep it, and your rights
Waitlist addresses are kept until the launch notice has gone out and been confirmed; feedback and access logs are kept for improvement and troubleshooting and pruned periodically; prompts, source images and results from AI jobs are deleted automatically after 14 days; payment records are kept as tax and accounting rules require.
You can ask to see, correct, or delete this data at any time: write to 605577690@qq.com with the email or the submission time, and we will act on it after verifying.
6. Children
The Service is aimed at adults and users able to enter into a contract; it is not directed at children under 13, and we do not knowingly collect their data.
7. Changes
When this policy changes we update the date at the top; when we add a new use of data, we say so here instead of quietly changing our story.