Skip to content
tutu.to

Privacy Policy

Effective Date: October 3, 2026 · Version: v2.3
GDPR Compliant
EXIF Strip
TLS Transport Encryption
兔兔图床(tutu.to,以下简称“我们”或“本平台”)高度重视用户的隐私与个人信息安全。本隐私政策旨在清晰透明地向您说明在您使用本平台图片托管、存储及相关服务时,我们如何收集、使用、存储及保护您的个人信息,以及您所拥有的相关权利。

一、数据收集与存储规范

我们坚持“最小化收集”原则,仅在提供图片托管与平台安全保障所必需的范围内收集信息:
1. 您主动提交的信息
  • 注册信息:注册账号时提供的电子邮箱地址、用户名及加密凭证。
  • 用户内容:您上传的图片文件、相册分类名称及相关描述标签。
  • 联系反馈:通过联系我们或支持工单提交的姓名、邮箱及反馈内容。
2. 自动收集的访问信息
  • 网络日志:访问 IP 地址、请求时间戳、HTTP Request 头部、浏览器 User-Agent 及来源 Referer。日志仅用于安全审计与防盗链防护,保存 30 天后自动匿名化处理。
  • 设备与性能数据:屏幕分辨率、语言偏好及 CDN 边缘节点响应时间,用于优化全球加载体验。
  • WordPress plugin upload statistics: For uploads made with the new plugin, we associate the API key account with the upload source, its successful-upload count, and current quota usage for retained original images. Only tutu.to site administrators can see global and per-user statistics. We do not collect the WordPress site domain for this purpose; older uploads are not retroactively classified.

Payments and subscription data

When you purchase through Paddle, we associate your tutu.to account and order reference with the Paddle customer, transaction and subscription references, payment amounts and currencies, billing periods, and payment, renewal and refund states. We exchange the necessary account and order references with Paddle and use these records to deliver paid access, manage renewals, reconcile payments and handle refunds or disputes.
Paddle collects and processes the payment and billing information you enter at checkout, such as email, billing address and payment method details. tutu.to does not store your complete card number or card security code. Paddle may process information across countries as described in its Privacy Policy.

三、数据安全与保护措施

本平台采用行业领先的安全技术与管理手段保护您的数据不被未经授权访问、泄露或篡改:
  • 传输加密:全站强制采用 TLS 1.3 / HTTPS 加密传输,确保图片与数据在网络中不被窃听。
  • 密码哈希:用户密码采用现代加盐哈希(Argon2 / bcrypt)加密存储,绝不留存明文。
  • 物理冗余:数据托管于全球高可用云存储基础设施(Cloudflare R2 与分发边缘节点),具备多重备份与防灾复原能力。

四、您的权利与数据掌控

根据适用的数据保护法律(包括 GDPR / CCPA 等),您对自己的个人信息享有完整的自主控制权:
  • 访问与导出:在账号正常使用期间,您可以登录控制台查阅或导出个人图片资产与个人资料。
  • 图片删除:您可以主动删除已上传的图片。
  • Account deletion and the 30-day retention period: You can request account deletion by contacting [email protected]. Once deletion takes effect, the account immediately enters a pending-deletion state (soft deletion). Login and API access are disabled, and the login page explains that deletion takes a maximum of 30 days. The account and associated data are retained for 30 days, after which the system automatically and permanently deletes the account profile, login credentials, API keys, images, albums, identifiable per-user upload statistics, and related operational records, except the limited records described below. Permanent deletion cannot be undone. The anonymous global count of successful WordPress-plugin uploads remains as a historical total without an identifier linking it to the deleted account. Necessary administrative audit records are retained separately to verify deletion results and investigate security events; they do not restore the account or provide continued account access.
  • Payment records and subscription cancellation: Limited order, payment, transaction and refund records may remain separately for accounting, dispute handling and statutory obligations. Retaining these records does not restore your account or images. Paddle retains information separately under its own Privacy Policy. Deleting your tutu.to account does not cancel an ongoing Paddle subscription; manage and cancel renewal in the Paddle billing portal or contact [email protected] before deleting your account.
  • 隐私咨询与反馈:如对隐私保护有任何疑问或需要行使相关权利,请随时联系我们的隐私合规团队: