Privacy Policy
How AnyFetcher handles necessary business data, first-party product analytics, GA4, and Baidu Analytics.
Effective date: 2026-08-07; policy version: privacy-2026-08-07-v1
Data categories and purposes
Necessary business data supports sign-in, parsing, abuse prevention, orders, payment, membership, and security audit obligations. We process it when required for the service or law even if analytics is declined. First-party product analytics helps us understand source, page, device category, and session paths, including registration, upgrade, and payment funnels. GA4 (Google Analytics 4) and Baidu Analytics are supplemental traffic and behavior tools; neither is the authority for orders, payments, or revenue.
Analytics properties use an allowlist. Prohibited content includes email addresses, usernames, passwords, verification codes, tokens, full IP addresses, browser fingerprints, pasted video links, media URLs, payment QR codes or links, payment secrets, raw gateway responses, full referrer URLs, and unregistered query parameters. A Cloudflare country code is used only for regional policy. A VPN or proxy is treated according to its visible exit country; this is not an exact location claim.
Regions, cookies, and preferences
The European Economic Area (EEA), United Kingdom, Switzerland, Brazil, Canada, and unknown or untrusted country contexts use strict consent. Before affirmative consent, we create no non-essential visitor cookie, send no first-party behavior event, and load neither GA4 nor Baidu Analytics. Mainland China (CN) and other non-strict regions default to first-party anonymous analytics and configured third-party analytics, while persistent footer privacy preferences let you disable either category independently.
Withdrawal immediately stops future collection, clears the first-party visitor identifier, and queues deletion of linked anonymous raw events, sessions, identity links, and analytics attribution when that identifier can be verified. Browser withdrawal stops future GA4/Baidu requests; it cannot retroactively delete data already received by those providers. You may also use each provider's rights process.
Retention and deletion
Anonymous raw events, sessions, and anonymous links are retained for up to 90 days. Deidentified aggregates and order analytics attribution are retained for up to 2 years. Recoverable-order exports expire within 24 hours. A deletion request takes priority for identifiable first-party analytics. Necessary order, payment, membership, and audit records required for performance, disputes, or law are not deleted as anonymous analytics and remain subject to applicable retention duties.
Contact
For access, correction, withdrawal, or deletion requests, contact [email protected]. Material changes will update the version and effective date, and strict regions will be asked for consent again when required.