Draft — pending legal review. Not final legal advice.

Privacy Policy

Last updated: July 20, 2026

Introduction & Scope

This Privacy Policy explains how CoolTea ("we", "our", or "us") collects, uses, and shares information when you use websites and web applications operated under the cooltea.top domain and its subdomains (the "Services"), including cooltea.top, rand.cooltea.top, and pixel.cooltea.top.

This document is a draft pending legal review. It is provided for transparency during early product development and should not be treated as final legal advice.

Product-specific details appear later in this Policy.

Information We Collect

We collect only what is needed to operate the Services. Depending on which Service you use and whether you sign in, this may include:

  • Account information — such as name, email address, and optional avatar when you create or use an account.
  • Content you create — such as decision lists (Cool Rand) or canvas/layer data (Cool Pixel).
  • Authentication and session data — cookies or tokens needed to keep you signed in.
  • API credentials metadata — for Cool Pixel MCP keys (for example, key name and creation time; plaintext secrets are shown only once at creation).
  • Standard web logs — our hosting provider may collect IP address, browser type, and request metadata for security and operations.

We do not sell personal information. We do not run third-party advertising trackers on the Services.

How We Use Your Information

We use information to:

  • Provide, maintain, and secure the Services.
  • Authenticate you and enable optional features such as cloud sync or MCP access.
  • Respond to support requests you send us.
  • Monitor abuse, outages, and security incidents.

We do not use your content for advertising. We do not sell or rent your personal information.

Cookies & Tracking

We use functional cookies or similar storage only where needed (for example, session cookies for authentication). We do not use advertising cookies, web beacons for marketing, or third-party analytics suites such as Google Analytics on the Services described here.

Browser local storage may hold product data on your device when a Service supports offline or local-first usage. See Product-Specific Privacy for key names and fields.

Third-Party Services

We rely on infrastructure and vendors to run the Services, which may include:

  • Cloudflare — hosting (Pages), databases (D1), and related edge infrastructure.
  • Authentication / email providers — as configured per product (for example, Google Sign-In and transactional email).
  • Links to social platforms — footer or profile links (such as X or Xiaohongshu) take you to those platforms under their own policies.

Each third party's handling of data is governed by its own privacy policy.

Data Retention & Deletion

  • Local-only data remains on your device until you clear site data or the product provides an in-app delete action.
  • Cloud account data is retained while your account exists, or until you delete specific items in-product.
  • To request deletion of account-associated cloud data, contact cooltea311@gmail.com.

We may retain limited logs needed for security, abuse prevention, or legal obligations for a reasonable period.

Children's Privacy

The Services are not directed at children under the age of 13 (or the equivalent age threshold in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps.

Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically.

Contact

If you have questions about this Privacy Policy, contact us at cooltea311@gmail.com.

Product-Specific Privacy

The following sections describe data practices unique to each product. They apply in addition to the general Policy above.

Cool Pixel

Cool Pixel is available at pixel.cooltea.top.

Canvas and account data

Pixel canvases, layers, and related metadata you create are stored so you can edit them across sessions. When you are signed in, this data is associated with your account. Thumbnails or derived previews may be generated to support the editor experience.

API keys and MCP

Cool Pixel may let you create API keys for MCP access. We store key metadata (such as name, prefix, and timestamps) needed to authenticate and manage keys. The full plaintext key is shown only once at creation and is not retrievable later.

MCP requests authenticated with your key can read and modify canvases your account is allowed to access. Treat keys as secrets; revoke them if exposed.

Logs and infrastructure

Hosting and database providers (such as Cloudflare) may process request logs and stored canvas data as part of operating Cool Pixel. Their handling of data is governed by their own policies.

Cool Rand

Cool Rand is available at rand.cooltea.top.

Local storage

When you use Cool Rand without cloud sync, decisions and choices stay in your browser's localStorage. Keys include:

  • cool-rand:decisions:v2
  • cool-rand:choices:v2
  • cool-rand:last-active-decision-id
  • cool-rand:default-deleted

This data does not leave your device unless you sign in and choose to sync it.

Cloud sync (signed-in users)

If you sign in and enable cloud sync, decision lists, choice items, and related metadata may be stored in our Cloudflare D1 database and associated with your CoolTea account. Account profile fields (such as name, email, and optional avatar) may also be stored for authentication and display.

When cloud sync is enabled, local copies may be uploaded and then removed from the device according to the product's sync behavior.

Cookies

Cool Rand does not use advertising cookies. A session cookie may be set by the authentication stack to maintain login state.

@cooltea_dev
Privacy Policy·Terms of Service