Privacy Policy (Web Service)
This Privacy Policy describes how yourcut.net ("the Service") handles information. The Service works with free browser extensions (currently face feature matching; future OCR and similar apps may be added) to provide Google Drive backup of usage history, multi-device history viewing, device registration, and billing. How each extension handles data is covered by that extension's own privacy policy. The same policy applies to shared-PC administrators and users, whether or not paid backup is used.
- Nature of the Service
The Service is a paid option for cloud sharing and backup maintenance. Extensions themselves are free; billing does not guarantee extension behavior. The Service is not intended for monitoring, evidence preservation, HR evaluation, or as definitive authentication / legal evidence (including face matching or future OCR). Provided as-is. - Information We Process
Examples include:
・Google account identifiers (e.g. email) and OAuth tokens
・Device UUID, optional label, device type (device_type; default today: face-ext), device token
・Billing data (plan, device count, PayPal-related IDs, etc.)
・Record reliability logs reported by extensions
・Encryption keys when paid backup is enabled (may be stored per device)
・Operational access logs
Face images/video and feature vectors are not sent to or stored by the Service in principle. - Purposes
Login, device registration, backup linkage, history viewing, billing, abuse prevention, support, incident response, security, and legal compliance. - Where Data Is Stored
Usage history and label names are generally backed up to the user's own Google Drive; managing that data is the shared-PC administrator's responsibility. OAuth tokens, device registration, billing state, reliability logs, device IDs, and (when paid backup is enabled) label-decryption encryption keys may be stored on the Service provider's servers. Encryption keys are not stored on Google Drive. Because of this separation, even if Google Drive backup data alone is leaked, label names cannot be decrypted, so that data alone does not normally function as information that can identify a specific individual. Transfer of backup payloads such as usage history and label names is performed by the extension or the user's browser (client-side) connecting directly to Google's services (Google Drive). The Service provider neither stores this backup payload nor relays the communication. Default backups do not include face feature vectors. - Third Parties
We use Google (OAuth / Drive API) and PayPal (payments) as needed. We do not sell personal data (except where required by law). - Retention
Data is kept and deleted according to active contracts and post-cancellation grace/deletion schedules. Drive data may not be auto-deleted by the Service. Access logs may be kept as needed for operations. - Administrator and User Responsibilities
Do not put personal information in identifiers. Managing Google Drive backups is the administrator's responsibility. Shared-PC users should understand that the administrator runs the Service and linked extensions. Administrators are expected to be adults (18+). - Changes
This policy may change without prior notice. Important changes will be announced in the admin UI or by email.