Privacy Policy
Effective date: August 10, 2026 · Prepared with reference to applicable data-protection laws
This policy describes how AIRR ("we", "us"), operated by Chenghuan Gongying (Guangzhou) E-commerce Co., Ltd., collects, uses, stores, shares, and protects your personal information when you use airrapp.com (the "Service").
1. What we collect
1.1 Information you actively provide
- Email & sign-in: the email address you use to sign in; we send a one-time passcode (verification code) to that address for login. Email may also be used for order confirmations, generated-result notices, support replies, or optional feedback follow-up
- Questionnaire answers: choices and free-form text submitted in the AI Companion Letter flow
- Basic info: identity, role, work context, AI-tool usage, and other information you voluntarily provide
- Payment info: handled by Waffo Pancake (online reseller / Merchant of Record). We receive only necessary order records such as order ID, amount, and payment status. Full card numbers are processed by Waffo Pancake, not by AIRR servers. Waffo Pancake processes card data, order, tax, receipt, and refund-related payment information
1.2 Automatically collected
- Technical logs: IP (region-level via Cloudflare), User-Agent, timestamp, access path
- Local storage: draft & report cache (stored in your browser localStorage — not uploaded)
- Cookies: see §5 below
1.3 What we do NOT collect
We do not collect your full credit-card number, government ID, contacts, face/voice, or any biometric data. Full card numbers are handled by the Merchant of Record / payment provider shown at checkout, not by us.
1.4 Sensitive answers & consent
2. Why we collect (legal basis)
| Purpose | Data | GDPR basis |
|---|---|---|
| Account login & identity verification | Email, one-time passcode | Contract, Art. 6(1)(b) |
| Generate personalized AI digital content | Answers + basic info | Contract, Art. 6(1)(b) |
| Send order/receipt/support emails | Contract, Art. 6(1)(b) | |
| Security / anti-abuse | IP, UA, logs | Legitimate interest, Art. 6(1)(f) |
| Legal obligation (tax, anti-fraud) | Orders + IP | Legal obligation, Art. 6(1)(c) |
3. Sub-processors
We use the following providers for hosting, email delivery, payment, and AI inference. Each provider handles relevant data under applicable contracts, published terms, and law:
| Vendor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | CDN, DNS, edge compute (Workers/KV/D1), DDoS | US / global edge |
| Resend | Transactional email (login passcodes, notices) | US / overseas |
| Waffo Pancake | Payment processing, receipts, tax compliance (Merchant of Record) | EU / overseas |
| Overseas model providers (as configured for the Service) | AI inference for users of airrapp.com | Overseas |
Only one Merchant of Record processes a given checkout. The checkout page names the provider that applies to that order.
Your questionnaire text is transmitted to AI service providers in request-response form for the current generation only. We do not use your answers to train any AI model.
Models & regions: The Service on airrapp.com is intended for users outside mainland China and uses corresponding overseas model providers for AI inference. Questionnaire text is used for the current generation only and not for model training.
4. Retention & deletion
- Account info (email): retained while your account is active; login-related logs may be retained as required by applicable law.
- Questionnaire answers: by default used only to generate your report on the fly. Not persisted on our servers when you are not signed in; when you sign in and a generation completes, see the "Generation inputs" item below.
- Free reports: primarily stay on the current device unless you actively save them to your account; saved reports remain until you delete them or close the account.
- AI Companion Letter and attachments: after a signed-in generation completes, they are synced to your account for cross-device access and retained until you delete the history item or close the account. When not signed in, they remain in browser localStorage on that device.
- Generation inputs (answers and calibration): after a signed-in generation completes, we retain the questionnaire selections, additions, and midpoint calibration needed for cross-device regeneration. We do not retain raw drafts from your editing process. These inputs remain until you delete the related history item or close the account.
- Temporary generation and interaction data: some data used for interruption recovery, cross-device continuation, or interactive features is retained for the relevant function, generally no longer than 14–90 days.
- Order records (incl. email): retained 7 years for tax/anti-fraud obligations.
- Technical, feedback, and payment-security records: generally retained for 30–90 days, unless law requires a longer period.
Email support@airrapp.com any time to request earlier deletion.
5. Cookies & similar tech
We use no third-party advertising or tracking cookies. Only:
- Strictly necessary localStorage for draft, report cache, language preference, and payment session reference;
- Cloudflare __cf_bm cookie: ~30 min, bot-management only.
6. Your rights
Depending on your jurisdiction (EEA/UK/California/others), you have rights to:
- Access a copy of your data
- Rectify inaccuracies
- Erase / be forgotten
- Restrict processing
- Data portability
- Object to automated decisions
- California: opt out of "sale/sharing" (we never sell, but you may confirm explicitly)
To exercise: email support@airrapp.com. We reply within 30 days and will not discriminate against you for exercising a right.
7. Children
The Service is not directed at children. We do not knowingly collect personal information from users under 16 (or under 13 where that is the applicable threshold). For users under 18, guardian consent may be required under local law. If you believe a minor submitted data, contact us to delete it promptly.
8. International data transfers
Cloudflare uses a global edge network, so technical data may be processed in multiple countries. Questionnaire content is transmitted to overseas model providers to complete generation. Email passcodes and notices are sent through Resend. Payment data is processed by Waffo Pancake (Merchant of Record). Where a cross-border personal-data transfer occurs, we apply the notice, consent, contractual, certification, or other safeguards required by applicable law. Measures include:
- transferring only data necessary for the relevant function;
- TLS encryption in transit;
- using applicable contractual or statutory transfer mechanisms.
9. Security
We use HTTPS everywhere, TLS 1.3, Cloudflare DDoS, JWT signed tokens, and Cloudflare Workers Secrets for key management (invisible to developers). Still, no Internet transmission is 100% secure — please protect your device and email account.
10. Breach notification
If a personal-data security incident occurs, we will take remedial action and notify regulators as required by applicable law. Where individual notice is required, we will use registered email, a service notice, or another effective channel.
11. Changes to this policy
We may update this policy occasionally. Material changes will be posted on the homepage and the "Effective date" above will be updated.
12. Data-protection contact
Data-protection matters: support@airrapp.com.
Company information is listed on the Company Information page.