EFFECTIVE OCTOBER 11, 2026 · VERSION 1.0

Privacy Policy.

Burning Bridges AI · Operated by JingLee, China. Contact: support@burningbridgesai.site.

Data controller

JingLee, an individual based in China, operates Burning Bridges AI at https://burningbridgesai.site and is responsible for the personal data handled by this service. Contact support@burningbridgesai.site for privacy questions, access requests, corrections or deletion requests.

Data and purposes

Google supplies an account identifier, verified email, name and profile image when you sign in. Email registration uses the submitted address and a verification link when available. Auth.js stores accounts, linked provider accounts and sessions in Cloudflare D1. Enabled creative tools store prompts, settings, task status, media ownership, uploads, generated results and content-check decisions. Credit and order records support payment reconciliation. We use these records to authenticate you, fulfill requests, maintain your library, prevent abuse and troubleshoot problems. Support correspondence contains information you choose to send.

Google account data

Burning Bridges AI requests only the openid, email and profile scopes. We receive your Google account identifier, verified email, name and profile photo to create or recognize your account, display your profile and secure access to your private workspace. Account and linked-provider records, including authentication token and expiry metadata, are stored in our Cloudflare D1 database and processed by our server; they are not published in generated media. We do not send Google profile data or Google authentication tokens to APIMart or AI model providers. Your Google profile data is not sold, used for advertising or used to develop or train AI or machine-learning models. Google Workspace APIs are not accessed or used for AI training. Cloudflare processes account data to host and protect this service. If checkout becomes available, Waffo receives your account email and the order information needed for your requested purchase. We use and transfer information received from Google APIs in accordance with the Google API Services User Data Policy, including its Limited Use requirements. Account data remains until a verified deletion request or operational cleanup, subject to the retention exceptions described below. Email support@burningbridgesai.site to request access, correction or deletion; you can also revoke the application's access in your Google account settings.

Google One Tap

When you are signed out, we load Google Identity Services to offer a One Tap sign-in prompt if your browser and Google account settings allow it. You choose whether to continue; automatic account selection is disabled. Closing the prompt does not prevent normal Google or email sign-in. Google processes the browser requests needed to display the prompt under its privacy policy. We validate the returned identity token on our server and use a short-lived, single-use browser challenge to protect sign-in. One Tap and ordinary Google sign-in use the same linked account, private library and credit balance. Switching accounts signs out the current website session before you choose another account.

Providers and international processing

Cloudflare hosts the application, database and media storage through Workers, D1 and R2. Cloudflare Email Service processes recipients and verification messages for email sign-in and forwards support correspondence to the operator’s mailbox hosted by Google. Google also handles account authentication; we request basic identity scopes without Gmail or Drive access. For enabled generation and AI assistance, APIMart and its underlying model providers receive the prompts, settings and media needed for the request. Safety review sends relevant prompts and media to a model through APIMart. Waffo Pancake receives buyer email, an account reference and order data when checkout is enabled; this website does not store full card data. Providers may process data outside your country under their own privacy practices.

Media and automated review

Media records belong to your account; uploads are not intentionally published in a public gallery. Expiring signed links let providers retrieve media for your requested job. Anyone holding such a link can access the media until it expires, so keep it private. Automated review covers prompts, reference media and results, including visual and audible content where present. Missing or inconclusive reviews prevent a request or result from proceeding. Review decisions are retained for enforcement and diagnostics. Automated checks can produce false positives or miss details. Avoid uploading unnecessary sensitive information.

Cookies and browser storage

Necessary HTTP-only cookies maintain sessions, and OAuth cookies protect the sign-in flow. Browser storage keeps draft prompts and request identifiers. A photo selected before sign-in stays in your browser with a 24-hour resume window; an expired draft is cleared on your next visit and can be discarded sooner. This local draft step does not identify faces or upload the photo. This website currently has no third-party advertising or analytics integration. You can clear browser storage yourself; disabling necessary cookies may prevent sign-in.

Retention and safeguards

Sessions expire after 30 days and email verification links after 10 minutes. Cloudflare Email Service retains delivery analytics for 31 days and sent-message previews for about seven days when preview is enabled. Expiration does not automatically erase account or job history. Account, task, media, billing and review records currently remain until reviewed and deleted through a support request or operational cleanup. Generated video files are copied into a private Cloudflare R2 bucket. Access expires 24 hours after storage completes; a scheduled task runs every two minutes to delete expired files, with a one-day R2 object lifecycle rule as fallback. Physical deletion may be delayed by outages or lifecycle processing. Download videos before expiry. Prompt, generation, credit and billing records remain after video file deletion. Uploaded references and generated images have no automatic time-based purge in this release. Self-service account deletion is not available. Request deletion by email; we verify ownership before acting and may retain limited records required for disputes, security or legal obligations. We use HTTPS, server-held credentials, ownership checks and signed media links, but cannot guarantee absolute security.

Training and privacy choices

We do not train our own AI models on uploads or sell personal information. External providers process submitted media and prompts for enabled requests; their retention and training rules may differ from ours. Review their policies before submitting sensitive content. You may decline to sign in or upload, discard local drafts, sign out, and request access, correction, export or deletion at support@burningbridgesai.site. Depending on applicable law, you may object to processing or complain to a privacy authority. Accounts are intended for adults; contact us if a minor has submitted personal data.

Changes and contact

We publish changes with the updated date and announce material changes through the website or email where appropriate. Contact JingLee, China, at support@burningbridgesai.site about this policy.

Provider privacy policies

Google · Cloudflare · APIMart · Waffo Pancake

Google sign-in data is also subject to the Google API Services User Data Policy, including its Limited Use requirements.