Last updated: October 7, 2026
1. Privacy by Design & Data Minimization
The principle is data minimization: the safest way to protect your information is not to collect it in the first place. We receive data only when it is required to produce the result you asked for, and every case is listed on this page.
2. Tools That Run Entirely on Your Device
These tools run in your browser and never send your files anywhere. Nothing is uploaded, at any step:
- Image compression · Video compression · Before / after comparison
- Image to text (OCR) · File format conversion · Video editor
They use WebAssembly, Canvas, Web Workers and AI models loaded into your own browser, running on your own hardware. Previews live in browser memory and are released when you close the tab or press clear. Once the page has loaded you can disconnect from the internet — the tools that do not need a server keep working.
3. Tools That Send Data Away, and Exactly What They Send
Four image tools send your image to us for processing, because the results are better than what your device can produce on its own:
| Tool | What is sent | Run it on your device instead |
|---|---|---|
| Remove background | Your image | Not available — our servers are the only engine for this tool |
| AI Colorize | Your image | Yes — choose Fast Mode and nothing leaves your device |
| Sharpen image | Your image | Yes — choose Fast and nothing leaves your device |
| Expand image | Your image | Not available — our servers are the only engine for this tool |
When you use one of those server modes, this is the whole of what happens to your file:
- It is transmitted over TLS-encrypted HTTPS to our servers.
- It is processed in memory to produce the result you asked for. It is never written to disk, never entered into a database, and never stored anywhere.
- It is gone as soon as the response is generated. There is no copy to delete afterwards, because none was kept.
- It is never used to train anything, never shared, and never seen by a person.
Expand image has one more step. To paint the new area, our server sends a copy of your image to Cloudflare Workers AI, which runs the painting model and returns the result. Cloudflare processes it on our behalf, in memory, and does not use it to train AI models. If Workers AI does not answer, our own server does the whole job instead.
Voices
Premium voices are synthesised on our own machines, on the same terms as the images above: in memory, not stored, discarded when the audio is returned.
The free voices are different. The text you ask them to read passes through our servers and is then sent to Microsoft's Edge speech service to be synthesised. We do not store it, but it does reach Microsoft, where their terms apply. If the text is private, use a premium voice.
When you download MP3, the audio you just generated is sent to our servers to be converted and returned immediately, not stored. Choose WAV instead if you would rather it did not — WAV is assembled entirely in the browser.
Audio to text
This tool has two modes, and both take audio off your device:
- Live dictation uses your browser's own speech recognition. Chrome sends the audio to Google's service and Edge to Microsoft's. We do not control that and do not receive the recording.
- File transcription sends the file straight from your browser to Groq to run the Whisper model, using your own API key. The file does not pass through our servers.
4. Mobile Applications (PhaseSnap, PaperHear & Quipline)
Our iOS applications (PhaseSnap and PaperHear) keep their data inside each app's own container:
- iOS App Sandbox: Project data, photographs, audio notes and documents live in the app's container or in iCloud storage you control.
- System Permissions: Camera, Photo Library, Location When In Use, and Speech Recognition permissions are only requested when you interactively invoke a corresponding feature.
- In-App Purchases: Pro upgrades are handled by the Apple App Store through StoreKit. Yangopen does not receive your payment details or Apple ID credentials.
- Each app maintains its own specialized privacy policy (e.g., PhaseSnap Privacy Policy).
Quipline (iPhone app and keyboard) sends nothing off your device until you tap Generate. Then the conversation text you reviewed, not images, is sent to the Quipline reply service, which forwards it to a third-party AI text provider (OpenAI) to produce your reply options; after the response is returned, our service keeps no conversation content or generated replies. The details are in the Quipline Privacy Policy.
5. Information You Send When Contacting Support
When you send a support request by email or through the contact form, we receive your name, email address and what you wrote. We use it only to reply.
6. Cookies and Technical Storage
The site stores very little in your browser:
- There are no marketing cookies, profiling cookies or cross-site tracking scripts.
- Visit counting. We count page views with Umami, an analytics tool we host on our own server. It sets no cookie, builds no profile of you and shares nothing with an advertising network; it records which page was opened, the referring site, and the browser, device type and country of the visit. It also counts a few named actions: a file chosen in a tool, a result downloaded, a buy or sign-in button pressed, an App Store link or a catalogue item opened, and how far down the catalogue a visit scrolled. Each carries only the name of the tool, app or pack — never the file, its name or anything you typed. It is not loaded on the account pages.
- Browser storage (localStorage and IndexedDB) holds your light or dark preference, your display language, the voice you chose last, the pronunciation rules you typed, your own sign-in session, and — for text to speech — the last few texts you generated together with their audio, so you can play them again. It stays on your device, with one exception: your sign-in token is sent to our servers with the requests that need to know who you are. Signing out removes your session, your text-to-speech history and saved audio, your voice choice, layout and pronunciation rules (your light or dark preference and your language stay); clearing your browser data removes everything.
7. Service Infrastructure
The site runs on Cloudflare Pages. Accounts, credit and transaction history live in a Supabase database. Both process data on our behalf and have their own policies.
A few other services receive data only when you use the feature they power:
- Signing in: Google, if you choose Continue with Google (your name, email address and profile picture come from Google); Telegram, if you choose Continue with Telegram (we keep your Telegram id and username to recognise your account). The sign-in window loads Telegram's login script from telegram.org when it opens, so Telegram can see that request even if you then sign in another way. Sign-in emails are sent through Resend.
- Paying: card payments are handled by Polar, and bank transfers in Vietnam are matched through ApiPay. They receive what a payment needs — the amount, the order reference and, for cards, the details you enter on their page. We never see your card number.
- Contact form: messages sent through the form are delivered by Formspree.
- Expand image: a copy of your image goes to Cloudflare Workers AI to paint the new area, as described in section 3. It is not stored and not used for training.
- Code and models: some tools download their code or models from jsDelivr and Hugging Face the first time you use them. Those services see the request, not your files.
- Visitor limits: for visitors without an account we keep a one-way hash of the network address for one day, only to count the day's free allowance. It cannot be turned back into an address.
Like any web server, they record standard connection details — IP address, browser user agent, timestamp — in temporary technical logs, used for routing and for keeping the connection secure.
8. Your Rights Over Your Data
You have the following rights over your data:
- Access and correction: ask us what contact information you have given us, or correct it.
- Erasure: ask us to delete support correspondence from our inbox.
- Data on your device: for tools that run in the browser, clearing your browser data removes the temporary copies.
9. Information Security
All traffic to Yangopen goes over TLS-encrypted HTTPS. The site sends these protective headers: Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options: nosniff, Referrer-Policy and X-Frame-Options.
10. Changes and Contact
When the product or the rules change, we update this page and change the date at the top.
For questions, or to exercise a data right:
- Privacy Office: [email protected]
- General Support: [email protected]
- Contact Form: Yangopen Contact Page