Privacy Policy
Last updated: July 22, 2026 · Operator of XHS Downloader (xiaohongshudownloader.com)
1. Plain-language summary
This tool is built so we do not keep a public archive of the note links you paste or the media files you download. That does not mean we collect zero technical data. Hosting, security (rate limits), short-lived caches, analytics, and error monitoring process limited information so the site can run safely. We do not currently use Google Analytics 4 (GA4). Absolute “we never store anything” claims are inaccurate — this policy describes what actually happens.
2. Data categories and purposes
| Category | Examples | Purpose |
|---|---|---|
| Request / security data | IP address, User-Agent, path, status, timestamps | Deliver pages/APIs; abuse prevention; debugging |
| Parse / cache data | Note ID, media URLs, title/author when available | Speed up repeat parses (~24h TTL); reduce upstream load |
| Rate-limit counters | IP + minute bucket counters | Cap abusive traffic (~60 second keys) |
| Analytics | Pageviews, funnel events; Clarity session signals | Understand product use and fix UX issues |
| Ops metrics / alerts | Success/failure rates, error codes; short-lived redacted failure samples (host / path kind / note ID; token-stripped URLs for invalid pastes — never raw token values) | Detect outages; debug parse failures |
| Communications you send us | Email to hello@ / privacy@ / abuse@; optional waitlist email if you tap "Notify Me When Ready" on a coming-soon product page (e.g. Douyin or TikTok) | Support, privacy requests, DMCA / abuse handling; launch notices for waitlisted features only |
3. What we intentionally do not keep as a product feature
- No user accounts, profiles, or download history pages tied to you.
- No permanent gallery of Xiaohongshu / RedNote media hosted for public browsing.
- Failed parses are not saved as a personal download history. We may keep short-lived, redacted ops samples (error code, host, note ID when known; for invalid pastes, a token-stripped URL — never the raw
xsec_token) to fix the tool.
4. Server access logs and IP addresses
Yes — IPs and request metadata can be processed.
- Hosting access logs: The site is hosted on cloud infrastructure (currently Vercel). Like most websites, the host may log HTTP requests — typically including approximate time, path, status code, User-Agent, and IP address — under the host’s retention and security policies. We do not sell these logs.
- Rate limiting: To reduce abuse, parse/API endpoints derive a client IP (from headers such as
CF-Connecting-IP,X-Forwarded-For, orX-Real-IP) and store a short counter keyed by IP for about 60 seconds (in application cache and/or Upstash Redis when configured).
5. Short-lived technical caches (not a user archive)
Successful parses may cache structured note metadata and media URLs keyed by note ID for about 24 hours (in-memory and/or Cloudflare KV when configured). Purpose: speed and fewer repeated upstream requests. This is not a searchable public library of what you downloaded.
6. Analytics — Plausible and Microsoft Clarity (not GA4)
- Plausible Analytics: Privacy-oriented, cookieless pageview and custom events (for example paste / parse / download funnel events). Plausible processes aggregated traffic metrics; see Plausible’s privacy policy.
- Microsoft Clarity: Session analytics that may include page interactions and heatmaps / session insights. Clarity typically uses cookies and similar identifiers. See Microsoft Privacy Statement.
- Google Analytics 4: Not installed on this site at the time of this update. If we add GA4 or similar tools later, we will update this page first.
7. Cookies and similar technologies
We aim to keep first-party product cookies minimal (no account login cookies). However:
- Clarity may set cookies / local storage for analytics.
- Plausible is designed to work without cookies.
- Your browser and CDN/hosting layers may set strictly necessary technical cookies or cache headers unrelated to advertising profiles.
- Future ads (for example Google AdSense) would introduce additional cookies; we would disclose that before enabling them.
You can block or delete cookies in your browser settings; some analytics features may stop working.
8. Retention summary
- Rate-limit keys: ~60 seconds.
- Parse note-ID cache: ~24 hours.
- In-process parse metrics: ~1-hour sliding window.
- Redacted parse-failure samples (ops): up to ~7 days in memory — error code, note ID when known, link host / path kind, whether an
xsec_tokenwas present (not the token value), device class, a short redacted error snippet, and for invalid / unparseable pastes a token-stripped URL (or short paste preview). Rawxsec_tokenvalues are never stored. Lost on server restart. - Host / platform logs: per Vercel (and any CDN) plan — typically days to weeks for debugging, not indefinite marketing storage.
- Analytics vendors: according to Plausible / Microsoft retention for their products.
- Support / legal email: as long as needed to resolve the request and meet legal obligations.
9. Third-party services and CDNs
| Service | Role | Typical data touched |
|---|---|---|
| Vercel (hosting) | Serves the site and API | Request IP, headers, paths, responses; deploy logs |
| Cloudflare KV / Upstash (optional) | Cache & rate-limit storage | Note-ID cache payloads; IP rate-limit keys |
| Xiaohongshu / RedNote CDN | Source of public media (via our proxy) | Our servers request CDN URLs with required Referer; CDN sees our egress IP and the media URL — not a user account password |
| Plausible | Privacy-friendly analytics | Pageviews / custom events; cookieless by design |
| Microsoft Clarity | UX / session analytics | Usage signals; may use cookies / device identifiers |
| Optional scraper / parse backends | Fallback when page parse fails | Note URLs or IDs needed to resolve public media; governed by those providers’ terms when enabled |
Media downloads are streamed through our /api/proxy allowlist for Xiaohongshu CDN hosts so the browser can save the file. We do not use that proxy to build a permanent media library.
10. International / cross-border processing
xiaohongshudownloader.com is operated for a global audience. Infrastructure and vendors (for example Vercel, Plausible, Microsoft) may process data in the United States, the European Economic Area, and other regions where they operate. By using the site you understand that technical data may be transferred across borders subject to those providers’ safeguards and applicable law.
11. Legal bases (high level)
- Legitimate interests: running a secure free tool, rate limiting, reliability metrics, cookieless product analytics (Plausible).
- Consent: where required for non-essential cookies / Clarity-style session analytics in your jurisdiction.
- Legal obligation: responding to valid legal process or copyright notices.
12. Your rights
Depending on where you live (for example GDPR / UK GDPR / CCPA), you may have rights to access, correct, delete, restrict, or object to certain processing, and to lodge a complaint with a supervisory authority. Email privacy@xiaohongshudownloader.com with enough detail to locate your request. We may need to verify identity for sensitive requests. Some data (host platform logs, vendor analytics) cannot be fully erased by us alone.
13. Children
The service is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). Do not use it if you are under that age.
14. Changes
We may update this policy when infrastructure or analytics change. The “Last updated” date at the top will change when we do. Material changes (for example adding GA4 or ads) will be reflected here before or when those features go live.
15. Contact
Privacy questions: privacy@xiaohongshudownloader.com. General contact: Contact page.