This Policy explains how ShowForAi (“SFA” or the “Software”) collects, uses, stores, and protects information during prerelease / release-candidate operation. Our architecture is local first: core data stays on your local device by default.
Signed-out users may only list, view, run, and control existing local scripts. Recording, AI-assisted script generation, and other content-writing operations require an account with available allowance.
The following stays only on your local device in the %APPDATA%/SFA directory by default and is not uploaded to the cloud unless you enable cloud sync or sharing, or purchase/import a cloud share:
4.1 Storage location: We use Railway-hosted PostgreSQL database services located in Singapore.
4.2 Authentication: User credentials are managed through JWT (JSON Web Token). The token is encrypted at rest locally with Windows DPAPI and stored at %APPDATA%/SFA/.auth_cache.json.
4.3 Transport security: Client-cloud traffic uses HTTPS (TLS 1.2 or later).
4.4 Scope of cloud actions: Cloud sync, sharing, paid sharing, purchase, and import are user-triggered. To complete synchronization, preview, authorization, purchase, download, or import, related script structure, visual templates or screenshot crops, step parameters, and typed text may be uploaded or downloaded.
4.5 AI visual recognition: Local heuristic output may be used to finish an already-authorized generation session only after a third-party model or provider call fails. A local fallback will not bypass sign-in, allowance, or authorization. After authorization, recognition may send the screenshot crop for the current action, the operation point (click coordinates), and necessary diagnostic information to our cloud service and route them through OpenRouter to its model providers to identify the visual target region.
| Provider | Purpose | Data/status |
|---|---|---|
| Railway | Backend API hosting and PostgreSQL database | Cloud data listed in Section 2 |
| OpenRouter and its model providers | AI model routing and visual-target identification | Action-related screenshot crop, operation point (click coordinates), and necessary diagnostics from an authorized generation session |
| HuPiJiao | Domestic QR-code payments for direct paid-content purchases and memberships | Order number, amount, currency, payment state, and necessary redacted payment references |
| Stripe | Stripe-hosted Checkout for international card payments for direct paid-content purchases and memberships | Order number, amount, currency, payment state, and necessary redacted payment references. Full card numbers are handled by Stripe on its hosted page and are not sent to SFA. |
| External manual-payout channel | Manual creator payouts in CNY | Creator-supplied payout details, external transaction reference, or redacted proof summary |
We do not use third-party analytics services and do not embed tracking code.
6.1 During prerelease: Cloud data including email, script metadata, and usage statistics is retained for six months; commercial ledger, audit, refund, dispute, and manual-payout records may be retained longer for reconciliation, tax, risk-control, and legal requirements.
6.2 Account deletion: After you request account deletion, we will remove all cloud copies within 30 days.
6.3 Local data: You manage local data. We cannot remotely access or delete it.
The Software is not directed to children under 14. If you are a minor, use the Software only with a guardian’s consent.
We may update this Policy as the product evolves. Material changes, such as collecting a new category of data, will be prominently announced in the Software and require renewed consent.
Questions, complaints, or suggestions about this Policy may be sent to onesteptomu@gmail.com.