Identity
Clerk user ID, verified email, name, profile image, role/status and account timestamps.
Last updated:
This policy covers the PipFoxy website, its public browser tools, optional Google-authenticated accounts, PipFoxy Credits and account-based AI tools. Account and AI availability depends on the authentication, database and AI services being configured for the environment; this policy does not claim that production Google sign-in has been manually tested on every domain.
PipFoxy’s existing text, developer, image, creator, calculator and generator tools remain public and account-free. They use browser APIs to process text, JSON, CSV, URLs, Base64 values, supported local files, images, drafts, dates and numbers on your device. Their content is not sent to the account database, Clerk or OpenRouter merely because account features exist elsewhere on PipFoxy.
PipFoxy does not intentionally log free-tool input, selected file contents or names, generated passwords or UUIDs, hashes, QR content, random-picker entries, calculator values, creator drafts, results or clipboard content. Copy and download happen when you request them. Temporary browser object URLs and working memory are released where practical when replaced, reset or no longer needed.
Tool text, selected files/images, drafts, values, generated results and local downloads.
Submitted AI content travels through PipFoxy’s server to OpenRouter and the selected model provider.
PipFoxy uses Replit-managed Clerk Auth to provide Google sign-in. When you authenticate, the service makes basic identity information available to PipFoxy: the Clerk user ID, verified email address, display name, profile image and session state. PipFoxy uses the Clerk user ID—not email—as the external authentication identifier and stores only the profile fields needed to display and administer the account.
PipFoxy does not receive your Google password and does not store Google access tokens for unrelated Google services. It does not request access to Gmail, Drive, Calendar or other unrelated Google data. Clerk, Google and the hosting provider process authentication/network data under their applicable terms and settings. Development and Production authentication user stores are separate.
Clerk user ID, verified email, name, profile image, role/status and account timestamps.
Integer balances, reservations, grants, usage charges, references and ledger timestamps.
Tool/model IDs, status, token totals, cost, duration, safe error category and timestamps.
When you run an AI tool, your entered content and selected options are sent securely to the PipFoxy server, OpenRouter and the provider serving the selected model. For screenshot review, prepared JPEG, PNG or WebP image data leaves the device. For document comparison, PipFoxy extracts text in the browser where practical and sends the extracted text rather than the original file; the extracted text still leaves the device. Scanned PDFs are not sent for OCR in this milestone.
PipFoxy does not intentionally persist full prompts, screenshots, uploaded documents, extracted document text, creator scripts or full model responses in its application database by default. Those values exist transiently in browser, server and provider request/response memory long enough to perform the request. Uploaded files are not intentionally written to persistent PipFoxy storage. AI prompts and outputs are not saved automatically. After a run, you may explicitly save the output and an optional text input summary. Original screenshots and documents are not saved. Extracted source text is stored only when you deliberately enable the separate “Save source text” control.
OpenRouter and model providers may process or retain request data according to the current provider route, account configuration and their applicable terms. PipFoxy does not promise that third-party providers keep no copy or never use content for model improvement unless the deployed provider terms/configuration specifically guarantee that. Remove secrets, confidential or highly sensitive information before submission and process only content you have permission to use.
Projects, folders, item titles, descriptions, favourites and version metadata are stored for your authenticated account. Saved result bodies, private prompt templates and support messages use authenticated AES-256-GCM encryption at rest with per-value random nonces and versioned server keys. PipFoxy decrypts content on the server only for an authorised view, search, export or support operation. This is encryption at rest, not end-to-end encryption: the application must be able to decrypt content to provide these features.
Workspace search is scoped to your account, bounded and does not retain or send the private query to analytics. Editing or restoring creates a new version. Deleted projects remain hidden and recoverable for the configured period, continue counting toward storage during that period, and are then purged by a scheduled cleanup. Content is never deleted merely because a storage limit was reached.
PipFoxy uses a database outbox and a configured delivery provider for account, payment, subscription, refund, export and support messages. Email payloads exclude full AI prompts/results and support-message bodies. Optional product and marketing messages follow your preferences; marketing is off by default and records explicit consent or unsubscribe time. Safe delivery, hard-bounce and complaint records may be retained to prevent repeated unwanted delivery.
Promotion redemption records include the campaign, hashed code reference, credits and time. Referral links contain a random code, not an email or internal user ID. A limited pre-registration cookie can attribute a new account; rewards require a first verified production purchase and a hold. PipFoxy may use a salted network hash and safe account/payment signals to flag abuse for review, but does not treat an IP signal alone as proof. Referral and promotional credits have no cash value.
Support messages are encrypted at rest. Administrators can see public ticket messages, internal notes and safe linked-resource metadata, but private saved project content is not shared or decrypted for support automatically. Ticket emails omit the full message. Attachments are not accepted in this release.
A data export can include profile data, saved content, templates, credit and AI usage metadata, billing, preferences, promotions, referrals and public support messages. Payloads are encrypted while temporarily stored, downloaded through an authenticated token submitted in the request body, and expire after the configured period. Archives are never emailed as attachments.
PipFoxy retains the internal user/tool ID, requested and resolved model, run status, prompt/completion/ total token counts, reasoning/cached token counts when available, actual provider cost converted to integer micro-US-dollars, credit reservation/settlement state, optional OpenRouter generation ID, latency, safe error category and timestamps. The append-only credit ledger records grants, debits, reservations, releases, actual AI usage and resulting balances.
Credits are virtual metered-usage units, not money or cryptocurrency. They cannot be withdrawn, transferred or redeemed for cash. PayFast processes sensitive payment details on its hosted checkout; PipFoxy does not receive card numbers, CVVs or card expiry dates. PipFoxy stores billing orders, immutable price/credit snapshots, provider transaction references, sanitised ITN verification results, receipts, subscription lifecycle events, refund/dispute records and the resulting append-only credit ledger. These records may be retained for accounting, support, fraud prevention, disputes and applicable legal obligations.
The hosting and authentication providers may process ordinary technical data such as IP address, date/time, requested route, browser/user-agent, response status and security events to serve, secure and troubleshoot the service. Retention and access depend on the applicable provider configuration and terms.
Outbound production monitoring is currently disabled. PipFoxy retains a provider-neutral redacting boundary for future reviewed monitoring. PipFoxy must not log full AI/free-tool content, filenames, raw provider errors, authentication tokens, system prompts, API keys or OAuth secrets.
PipFoxy’s optional product analytics is currently disabled and remains inactive unless the reviewed Plausible configuration is deliberately enabled. Analytics never receives email, exact balance, prompt/output, file name, document or screenshot content, creator script, authentication ID or token content.
PipFoxy does not currently display live advertising. Disabled placements collapse and make no advertising request. No consent preference is stored because the optional consent interface is currently disabled. PipFoxy may also remember up to four recently opened free-tool IDs and a non-sensitive recent model-tier choice in browser storage for convenience. Recent-tool history contains no tool input, result, filename or search text and can be cleared from its on-page control; system prompts and AI content are not stored by either preference.
Authorised PipFoxy administrators can view basic account information, roles/status, credit balances and ledger, AI run metadata, model configuration and audited administrator actions. They can grant/debit testing credits, suspend/reactivate users, disable models, review payment/refund records and reconcile uncertain runs. They do not see transient AI input/output by default. The support dashboard shows safe project metadata rather than private saved content unless a user explicitly shares content for support. Administrative changes require server-side role checks and are recorded in an append-only audit log.
Full AI content has no intentional application-database retention by default. Account, usage, credit, billing, refund, dispute, subscription and audit metadata is retained while needed to operate the account, preserve ledger integrity, prevent abuse, resolve disputes/security incidents and meet applicable legal requirements. PipFoxy does not claim a fixed deletion period that has not been implemented and verified.
Account Settings provides an authenticated, typed-confirmation deletion action. PipFoxy deletes saved projects, encrypted versions, templates, favourites and active export payloads, removes public support message content, disables referral participation and anonymises ordinary profile data. Payment, credit, promotion, referral, refund and accounting records may be retained or minimised when genuinely required; deletion therefore may not remove every legally or operationally necessary billing record. Active subscriptions must be cancelled before deletion can finish so recurring charges do not continue. The deletion action durably records the request before asking the authentication provider to delete the identity. Application profile data is anonymised only after provider deletion succeeds. A provider failure leaves the profile active and the request available for retry/support; a later application cleanup failure is flagged for reconciliation. PipFoxy does not claim deletion completed in either case.
Signed-in users can review identity, credit and usage metadata and start the explicit deletion flow from Account Settings.
Open Account SettingsThe contact page uses a mail link only when a public contact email is configured. Email is processed by your provider and the recipient’s provider. Do not send passwords, API keys, payment details, private documents or AI content in a support message. External sites control their own privacy practices.
PipFoxy uses server-side authorisation, validation, rate limits, idempotency and integer credit accounting for AI operations. Transport encryption does not make the AI flow end-to-end encrypted. No website, provider or device can be guaranteed completely secure. Keep software updated, sign out on shared devices, retain source files and independently review consequential output.
This policy may change as PipFoxy adds providers or features. Material revisions are reflected by the date at the top. Model/provider availability can change and material processing changes require updated notice. For questions, use the contact page. Also review the Terms and AI Disclaimer.