LHLocal Highlights

Candidate legal draft · not for publication

Privacy

  1. Who operates this tool. [OWNER_LEGAL_NAME_OR_SOLE_TRADER_NAME], trading as [OWNER_BRAND_NAME]. Privacy contact: [OWNER_PRIVACY_EMAIL].
  2. Local content. Content, file names, paths, titles, authors, notes, tags and output you select are processed only in browser memory. They are not uploaded, stored by the service, or included in events. Refreshing, closing or clearing removes temporary content without changing the source or an already downloaded file.
  3. Anonymous beta measurement. Only after consent, the closed event set is landing_view, demo_complete, real_file_preview, checkout_opened, paid and zip_downloaded. Each record has exactly event_name, occurred_at_utc, a random anonymous_experiment_id, language and fixed error_code=NONE. The application event store does not keep IP address, User-Agent, referrer URL, fingerprint or cookie. Hosting/security providers may transiently process network metadata under their policies.
  4. Payment and entitlement. Paddle is Merchant of Record and handles email, payment method, billing address, tax, receipt, refund and dispute. The tool never handles card data. We keep the minimum transaction and entitlement data: Paddle transaction, product/price, currency, transaction/refund state, time, opaque entitlement ID and credential hash—never reading content.
  5. Browser storage. Measurement choice, random anonymous ID and opaque entitlement token may be stored locally. Interface language is session-only. Clearing site data removes local recovery credentials but does not cancel or refund a transaction.
  6. Support. Email or receipt data voluntarily sent to [OWNER_SUPPORT_EMAIL] is used only for support/recovery. Never attach an export, highlight, note, title or ZIP. Support records are deleted 30 days after ticket closure unless a legal or dispute duty requires longer.
  7. Retention. Event detail is deleted 30 days after the experiment closes, leaving only non-reidentifiable aggregate counts. Paddle and necessary transaction/entitlement records follow [OWNER_PAYMENT_RECORD_RETENTION_BASIS]. This placeholder blocks publication.
  8. Choices and rights. Rejecting measurement does not block demo, preview or purchase. Privacy access/deletion requests go to [OWNER_PRIVACY_EMAIL]. Records Paddle must legally retain may not be deletable by this tool.
  9. Processors and links. Intended processors: Cloudflare for hosting/data infrastructure and Paddle for Merchant-of-Record payment. The support email provider remains unconfigured and is not enabled. See Paddle Privacy Notice.

候选法律草案 · 不得公开

隐私说明

  1. 运营主体。[OWNER_LEGAL_NAME_OR_SOLE_TRADER_NAME],使用品牌[OWNER_BRAND_NAME];隐私联系邮箱[OWNER_PRIVACY_EMAIL]。
  2. 本地内容。你主动选择的正文、文件名、路径、标题、作者、笔记、标签和输出只在浏览器内存处理,不上传、不由服务保存、不进入事件。刷新、关闭或清除会删除临时内容,不修改源文件或已下载文件。
  3. 匿名测试统计。只有同意后才记录 landing_view、demo_complete、real_file_preview、checkout_opened、paid、zip_downloaded 六个事件;字段严格为 event_name、occurred_at_utc、随机 anonymous_experiment_id、language 和固定 error_code=NONE。应用事件库不保存 IP、User-Agent、来源URL、指纹或Cookie;托管和安全供应商可能依其政策瞬时处理网络元数据。
  4. 支付与权益。Paddle 作为 Merchant of Record 处理邮箱、付款方式、账单地址、税、收据、退款和争议;本工具不接触银行卡数据。我们只保存最小交易/权益数据:Paddle交易、产品/价格、币种、交易/退款状态、时间、不透明权益ID与凭证哈希,绝不保存阅读内容。
  5. 浏览器存储。测量选择、随机匿名ID和不透明权益凭证可本地保存;界面语言只在会话内保留。清除站点数据会删除本地恢复凭证,但不会取消交易或退款。
  6. 支持。你主动发至[OWNER_SUPPORT_EMAIL]的邮箱或收据只用于支持/恢复。请勿附上导出文件、摘录、笔记、标题或ZIP。工单关闭30天后删除支持记录,法律或争议义务要求除外。
  7. 保留。实验关闭30天后删除事件明细,仅留不可回溯个人的聚合计数。Paddle及必要交易/权益记录遵循[OWNER_PAYMENT_RECORD_RETENTION_BASIS];占位未补齐会阻止公开。
  8. 选择与权利。拒绝统计不影响演示、预览或购买。隐私访问/删除请求发至[OWNER_PRIVACY_EMAIL];Paddle依法必须保留的记录可能无法由本工具删除。
  9. 处理方与链接。拟使用Cloudflare提供托管/数据基础设施、Paddle提供Merchant-of-Record支付。支持邮箱供应商尚未配置且未启用。参见Paddle隐私声明。