AMPX Desktop — optional metrics and GDPR choices
In the desktop app, Settings → Privacy & metrics provides two independent optional categories. On first launch, terms and optional analytics are separate steps. Suggested choices do not enable collection: only the explicit Enable selected analytics action does. Continue without analytics is equally available. Expanded source-service and diagnostic-code collection require renewed consent. Consent is used to improve application reliability and understand platform usage. Licensing and necessary service/security processing are separate and do not depend on these choices.
- Conversion metrics: one count per completed or failed operation attempt, its local calendar date and hour, source service (such as YouTube, Spotify or SoundCloud, with other/local/unknown categories), conversion type (audio, video, remux or local transcode) and success/failure. A playlist operation counts once, not once per media file. Retries are separate attempts. Cancelled or paused operations are excluded.
- Device metrics: operating system family (Windows, Linux or macOS), CPU architecture (x64, ARM64 or unknown), application version and build number, sent when enabled and on application launch.
Each category uses a separate random installation identifier and authentication secret. AmpX stores the identifier, a hash of the secret, consent version, receipt/last-seen timestamps and conversion batch IDs for deduplication. These records are pseudonymous, not anonymous. No content URLs, titles, file names, file contents, account/license identifiers, hardware serial numbers, cookies, error messages or stack traces are included. Network infrastructure necessarily processes connection addresses; those are not stored in the desktop metrics tables.
Metrics go directly to the configured AmpX core (development builds to development, production builds to production) and our application database. They are visible to authorized dashboard administrators. They are not sent to a third-party analytics SDK or sold.
Current retention: 3 calendar months (default 3). The administrator can configure 1–36 months in PHP / Backend settings. Expired metric batches, inactive installation records and legacy aggregates are removed by hourly maintenance. Repeated activity does not extend the lifetime of old conversion batches. No longer-lived conversion aggregate is created after expiration.
Turning an option off immediately stops new collection for that category and requests deletion from our live database. If offline, the app retains the deletion credential and retries on next launch; Settings also provides Retry server deletion. A request already in flight may finish before the deletion request. Unsent conversion events are held only in a bounded in-memory queue and are not replayed from download history; unavailable network/service requests can be lost. Consent and deletion credentials use the operating system's secure storage. Removing the app's secure storage can remove the credential needed to identify these pseudonymous records; the retention window still applies.
For access, portability or other GDPR requests, contact the privacy address listed on this page. Desktop metrics are separate from account exports because they are not linked to your account. The authenticated desktop metrics endpoint supports access and deletion using the installation credential; never send your authentication secret in a support message. Website cookie consent does not enable desktop metrics.
With conversion analytics enabled, fixed diagnostic error codes (such as Spotify audio authorization failures) are included after you accept the updated analytics choice. Raw errors, URLs, media identifiers and credentials are never included.
Coming soon and availability notifications
Opening an interest form does not register a demand signal. Submitting your email registers interest in that specific feature and permits availability notifications about it, not unrelated marketing. We store the normalized email, feature identifier, signup time, website host and a deduplication hash. New registrations do not store submitted content URLs or IP addresses in the waitlist. Historical records may contain previously collected fields. Repeat registrations for the same feature count once. Authorized administrators can review/export these registrations. Each availability email includes a scoped unsubscribe link. Contact the privacy address on this page to withdraw or request deletion.
Optional email updates
Registered AMPX accounts can be selected for account-wide news, offers and calls to action without a separate marketing opt-in. Account → Privacy → Email updates lets you opt out. Saved opt-outs and unsubscribed addresses are excluded from account-wide campaigns, including campaigns targeting explicit marketing subscribers. Feature demand signups permit notifications for that feature only. Essential account and security messages do not depend on marketing consent.
Our database stores your email, recipient name, consent time, subscription scope, queued campaign and delivery status. We recheck account eligibility, preferences and feature subscriptions before sending and include an unsubscribe link. Withdrawal stops pending messages; an email already being sent may still arrive. The mailer adds no open pixels or click tracking and does not collect content/download URLs. Loading an email image can contact the server hosting that image.
Recipient details in processed campaign history are removed after 90 days (default 90; configurable 1–365). Queued recipient details remain until processed or cancelled. Aggregate campaign counts remain without recipient details. Subscriptions remain until withdrawn; minimal email and scope suppression records remain to honor withdrawal. Mail is processed by AMPX and its configured mail delivery provider. Account data export includes email preferences and retained delivery history; account erasure removes these records. Contact the privacy address for feature-only subscriptions or other rights requests.
سياسة الخصوصية
توضح هذه السياسة ما البيانات التي نجمعها وكيف نستخدمها وما هي خياراتك.
1. البيانات التي نجمعها
قد نجمع تفاصيل الحساب، مقاييس الاستخدام، بيانات تعريف المهمة، وبيانات السجل الأساسية (مثل عنوان IP وبيانات المتصفح). تتم معالجة الملفات لتقديم الخدمة.
2. كيف نستخدم البيانات
نستخدم البيانات لتشغيل الخدمة ومنع سوء الاستخدام وتقديم الدعم وتحسين الأداء.
نعالج البيانات لتقديم الخدمة وحمايتها ومنع إساءة الاستخدام والامتثال للالتزامات القانونية، وللتحليلات الاختيارية بعد موافقتك. لا يصل مقدمو الاستضافة والتخزين والمعالجة والمراقبة والتحليلات إليها إلا عند الحاجة. لا نبيع البيانات الشخصية.
3. ملفات تعريف الارتباط والتحليلات
نستخدم ملفات تعريف الارتباط الأساسية للجلسات والتفضيلات. قد تُستخدم التحليلات لفهم اتجاهات الاستخدام.
4. المشاركة
لا نبيع بياناتك. قد نشاركها مع مزودي الخدمة أو عندما يقتضي القانون ذلك.
5. الاحتفاظ
نحتفظ بالبيانات فقط طالما يلزمها تشغيل الخدمة أو الفوترة أو الالتزامات القانونية.
تُحفظ الملفات المؤقتة وبيانات المهام بقدر الحاجة للتشغيل والأمان وتشخيص الأخطاء ثم تُحذف أو تُجهّل. قد يعالجها مزودون خارج بلدك مع تطبيق ضمانات النقل المناسبة.
البيانات التي تعالجها AMPX
يُدرج هذا الجدول الفئات الرئيسية لبياناتك الشخصية والبيانات التشغيلية التي قد تعالجها AMPX عندما تنشئ حسابًا أو تستخدم الأدوات أو ترسل مهام تحويل أو تُدير الفواتير أو تتواصل معنا.
| الفئة | أمثلة | الهدف | الاحتفاظ | المعالجون |
|---|---|---|---|---|
| Account profile | name, email address, email verification state, account timestamps | Create accounts, authenticate users, support account management, and contact users about their account. | Kept while the account exists, then deleted or anonymized unless retention is required for security, billing, or legal reasons. | Application database, email provider when email is sent |
| Authentication and security | hashed password, session identifiers, remember tokens, rate-limit and abuse-prevention signals | Protect accounts, prevent abuse, and keep users signed in. | Session data expires automatically. Security logs are kept only as long as needed for abuse prevention and diagnostics. | Application database, cache/session storage, hosting provider |
| API access and plans | API key metadata, service scope, plan limits, daily/monthly/total usage counters, last used timestamps | Authorize API requests, enforce plan limits, meter usage, and provide account usage reporting. | Kept while API access is active and deleted with the account or API key unless anonymized usage records are retained. | Application database, worker/API infrastructure |
| Conversion and utility jobs | job token, selected service, conversion options, submitted URLs or file metadata, status/error data, bytes processed | Queue and process conversions, return job status/download links, troubleshoot failures, and enforce usage limits. | Job records and temporary files are kept only for operational needs. Account-linked logs are removed or anonymized when account data is erased. | Qless workers, temporary file storage, hosting provider |
| Billing and subscriptions | Stripe customer ID, subscription ID, price ID, subscription status, renewal/cancellation timestamps, billing email | Create checkout sessions, manage subscriptions, reconcile billing status, and provide billing support. | Kept while the subscription/account exists and as needed for tax, accounting, dispute, fraud, and legal obligations. | Stripe, application database |
| Privacy and support requests | request type, request notes, status, submitted/completed/canceled timestamps | Track and respond to access, export, deletion, correction, restriction, objection, and portability requests. | Kept while the request is active and then only as long as needed to document the response or comply with law. | Application database, support mailbox if used |
| Site diagnostics | IP address, session ID, user agent or request metadata where logged by infrastructure, status codes, error messages | Operate the service, debug failures, detect abuse, and protect the infrastructure. | Kept for the shortest practical period for diagnostics and security, then deleted or aggregated. | Hosting provider, application logs, analytics/monitoring tools if enabled |
| AMPX Desktop optional metrics (separate opt-ins) | conversion count, local date/hour, source service, type and result, OS family, architecture, app version/build, separate random category identifiers, credential hashes, batch IDs and receipt timestamps | Consent-based reliability and platform usage statistics; no content URLs, filenames, cookies or license/account identifiers. | 3 calendar months (default 3); hourly expiration, or category deletion requested by switching off in desktop Settings → Privacy & metrics. Offline deletion retries on next launch. | AMPX core/application database, authorized AMPX dashboard administrators |
| Optional email updates and feature notifications | email address, recipient name, consent time and feature subscription, campaign delivery state and unsubscribe preference | Send account-wide news and offers, or notifications for subscribed features, and honor withdrawals. No open pixels or click tracking. | 90 days for recipient delivery history after processing; subscription until withdrawn; minimal suppression record while needed to honor withdrawal. | AMPX application database, configured mail delivery provider |
6. خياراتك
يمكنك طلب الوصول أو التصحيح أو حذف بيانات حسابك بالتواصل معنا.
بحسب موقعك، يمكنك طلب الوصول أو التصحيح أو الحذف أو التقييد أو الاعتراض أو النقل، وسحب الموافقة وتقديم شكوى إلى جهة حماية البيانات المختصة.
إذا كان لديك حساب AMPX، يمكنك استخدام لوحة التحكم لتصدير بيانات حسابك وتقديم طلبات للوصول أو الحذف/المحو أو التصحيح أو التقييد أو الاعتراض أو قابلية النقل أو أي مراجعة خصوصية أخرى. يمكنك أيضًا حذف حسابك من لوحة التحكم؛ تُحذف سجلات الحساب وتُخفي السجلات التشغيلية المرتبطة به قدر الإمكان.
لا تبيع AMPX البيانات الشخصية. قد نستخدم مزودي خدمات مثل بنية الاستضافة، بنية قوائم الطابور/العامل، مزودي البريد الإلكتروني، أدوات التحليل والمراقبة إذا كانت مفعّلة، وStripe للفوترة. نحن لا نخزن تفاصيل بطاقات الدفع الكاملة.
لا ترفع أو ترسل بيانات شخصية حساسة إلا إذا كانت ضرورية للمهمة التي تنفذها. قد تُعالج الملفات المؤقتة وروابط URL والخيارات ومعرفات المهام وبيانات الأخطاء لإكمال المهمة واستكشاف أسباب الأعطال.
التواصل
لطلبات الخصوصية تواصل عبر support@ampx.cc. اذكر اسم الخدمة والمعلومات اللازمة ولا ترسل كلمات مرور أو بيانات حساسة غير ضرورية.
7. تحديثات السياسة
قد نقوم بتحديث هذه السياسة. استمرار استخدامك للخدمة يعني قبولك للنسخة المحدثة.
آخر تحديث: 2026-09-20