Privacy Policy

Last updated: 2 July 2026

LINGYANG Convert ("LINGYANG", "we", "us") provides browser-based tools for converting bank statements and tables. This policy explains what happens to statement contents and what operational personal data may be processed for the website, payments, license validation, analytics and support.

Operator and contact

Operating entity name: LINGYANG Convert. LINGYANG Convert is currently published as an independent software project. Legal and privacy contact: support@antelope.tools. A formal registered region or postal notice address has not yet been published; if you need one for a privacy or legal notice, email us and we will provide the current notice address and update this page when a formal entity record is available.

Local Mode and network requests

Statement contents are never transmitted in Local Mode. The website may make separate requests for page delivery, anonymous analytics, payment processing and license validation. These requests never contain statement contents.

Current OCR is on-device OCR using self-hosted Tesseract.js assets. We do not currently use a cloud OCR provider for statement contents.

Files and model training

Data categories and retention

CategoryExamplesPurposeRetention
Statement contentsPDFs, scans, images, extracted rows, exported filesLocal conversion and review in your browserNot retained by LINGYANG
Device storageLicense key stored in browser localStorageKeep Pro active on your deviceUntil you remove it or clear browser storage
License validationLicense key and Gumroad product referenceConfirm a Pro license is validHandled by Gumroad and operational logs according to provider policies
Purchase and payment recordsPurchase email, order ID, license record, refund status, payment metadataDeliver license keys, process refunds, tax/accounting and fraud preventionAs long as needed for license, refund, tax, accounting and legal obligations
Support emailsEmail address, message content, attachments you choose to sendCustomer support, refunds, privacy requests and security reportsUp to 24 months after last contact unless a longer legal or security need applies
Anonymous analyticsPage URL, referrer, device/browser summary, approximate country-level locationUnderstand page usage and improve the websiteAggregate analytics retained according to Plausible Analytics workspace settings
Page delivery and security logsIP address, user agent, requested URL, timestamps, security eventsDeliver the website, operate TLS/CDN, prevent abuse and investigate incidentsRetained by Cloudflare according to operational and security log policies

Providers and regions

Payment provider: Gumroad. Analytics tool: Plausible Analytics, when configured. Hosting/CDN: Cloudflare Pages. Operational data may be processed in the United States and the European Union/EEA depending on the provider and request path. See the Subprocessors page for the current provider list, purposes, data categories and regions.

Deletion and access requests

There is no app account, but purchase records, support emails, license validation records, analytics logs and payment records may be personal data. To request access, correction or deletion, email support@antelope.tools with the subject "Privacy Request" and include the purchase email or license key if the request relates to a Pro purchase. We may need to keep some records where required for tax, refund, fraud-prevention, security or legal reasons.

You can remove a license key from your own device at any time from the converter page or by clearing the site's browser storage.

Cloud OCR

No cloud OCR subprocessor is currently used. If cloud OCR is added later, it will be listed on the Subprocessors page before launch, will be opt-in, will not be used to train models, and will be treated as a separate upload security product.

Before any cloud OCR launch, uploads must use server-side real MIME/magic-byte validation in addition to extension checks; file size, PDF page count, image dimensions and decompressed size limits; rejection of abnormal archives or container files; randomized private storage names; short-lived signed URLs for upload and download; authenticated or licensed upload access; antivirus, sandboxing or content disarm and reconstruction where practical; OCR containers with deny-by-default outbound network access; CPU, memory and time limits; automatic file deletion with verification records; logs that exclude original file names, transaction content, amounts and account numbers; API and upload rate limiting; PDF parser resource-exhaustion protections; and regular updates for PDF, Excel and image parsing dependencies.

Changes

We may update this policy as the product, providers or legal requirements change. Material changes will be reflected by the last updated date above and, where appropriate, the Changelog.

Back to home