Privacy policy
OfflineMP3 is operated by Bo Zhang, an individual, not a company. This policy describes the content pages and the Video to MP3 processing page. The public site has not been released. offlinemp3.com is registered and is not connected to a hosting Worker.
Who this policy is from
The operator is Bo Zhang. OfflineMP3 is not a company, and this page does not use a company registration number. The planned content hostname is www.offlinemp3.com. The planned processing hostname is app.offlinemp3.com. Neither hostname is connected in this draft.
How to reach the operator
Email support@offlinemp3.com for a privacy question or a security report. If you send that email, it includes the address you write from and the text you choose to include. That message is not an account record and it is not a diagnostic event.
Conversion of your media file
When you select a local media file for Video to MP3, OfflineMP3 does not upload that file to its own server in order to convert it. The conversion runs on your device. Your media file stays on your device. This is local, on-device conversion.
That boundary does not cover advertising, diagnostics, or a remote media request you explicitly start. This draft does not load an ad, does not send a diagnostic event, and does not fetch remote media for you.
The processing page does not load ads, an ad-consent module, third-party analytics, or session replay.
Authorized content
The tool is for media you own, or media the rights holder has allowed you to copy, convert, and download. It is not a way to open a stream that sits behind a login, a payment check, DRM, or another access control.
Beta, accounts, and price
No account is required. This draft does not ask for your name, email address, or payment details in order to convert a file. The public Beta has not started. During that Beta, the product is meant to be free to use. Free during Beta is not a promise that the product will stay free, that use will have no cap, or that the business model will stay the same.
What this draft stores
These pages do not set a product cookie. They do not write localStorage or sessionStorage for an account or for tracking. The processing page holds the file you selected, and the task state, in memory for that visit.
When you save, the verified MP3 is written to a location you choose. Save completed means that write finished and the file was closed. If the browser only receives a download, the product calls that Download started, not a confirmed save.
Your browser may keep its own history, cache, and download record. That is the browser's record, not an OfflineMP3 account.
Advertising that a content page may show later
This draft loads no ad script, no ad tag, and no ad connection hint. A future content page may show one manual ad. The ad is planned to sit away from the main action, with a full block of content between the ad and the button. Automatic ads, vignette ads, and sticky ads are not part of the plan. An ad must not block saving a completed output. The processing page will not load an ad.
Static HTML is planned to stay free of ad code. On each top-level navigation, a content page may ask a same-origin gate, by POST /api/ad-eligibility, whether one ad is allowed for that visit. The gate is not built in this draft.
Advertising eligibility is a temporary permission for that one navigation. It requires all of the following to agree: the production domain, a United States region estimate, your privacy choice, and the gate. If any condition is missing, fails, or is uncertain, the page has no advertising eligibility.
The planned gate fails closed. An unknown region, Tor, a region outside the United States, a preview domain, an error, or a timeout means the page makes no request to Google. The decision is not stored for a later visit. The region estimate is a commercial rollout estimate. It is not a legal location guarantee.
The first ads, if they are added, are planned for United States visits and would use Restricted Data Processing. Canada, Australia, the EEA, the United Kingdom, and Switzerland need a separate review before any ad is shown there. A browser Global Privacy Control signal, or a manual opt-out, is a privacy choice that means no ad. The manual opt-out is not built in this draft. An ad choice is separate from a choice to send a diagnostic event.
Diagnostic data, only if you choose to send it
A diagnostic service is not part of this draft. Nothing on these pages sends a diagnostic event.
If a diagnostic endpoint is added, it will be a separate first-party service. It will not accept the media file. After a task ends in success, failure, or cancellation, the processing page may show a share control. That control is not pre-selected. The choice is not stored for the next task. A task that ends in a crash is not reported afterwards to fill a gap.
If you choose to share, the product sends one privacy-minimized diagnostic event for that task: one coarse final state. The event uses an allowed list of labels, plus buckets for size, duration, and elapsed time. It does not include the media, the file name, raw metadata, a full URL, an exact file property, a user identifier, a session identifier, or a stable hash. Sending it is still a disclosure. The product does not give the event a stronger privacy label.
Each event would have its own diagnostic deletion credential. That credential is a one-time 256-bit secret used only to delete that one event while the raw event is still kept. It does not identify you, a session, or any other task. The server would store a keyed lookup value for the secret. You can copy or download the credential. It is not placed in a cookie, a URL, or localStorage. If you lose it, it cannot be restored.
A deletion request would carry the secret as a Bearer token. If the event exists, is missing, was already deleted, or has expired, the response is the same: 204. The token is not written into the log.
An IP address on that request would be used only for short-lived rate limiting at the edge. It would not be written into the stored event or into an analytics record.
Raw events would be kept for 30 days. After that window, the product would keep an aggregate only when a group has at least 20 events. Smaller groups would be discarded. Aggregates would be kept for at most 13 months. A minimum group size is not a legal assurance that a person cannot be singled out.
Before a send, a local package would show the field list, and you would send it yourself. The default package does not include a trace.
Hosting
This draft does not add a product log of visitors. When a page is later served from a hosting Worker, that host will see the connection data it needs to return the page, such as an IP address and a user agent. This policy does not claim that the host keeps none of that data. offlinemp3.com is not connected to a hosting Worker yet.
Children
OfflineMP3 does not offer an account for children and does not ask for a date of birth or other contact details on these pages.
Governing law
This policy is governed by the laws of the Hong Kong Special Administrative Region of the People's Republic of China. The courts of Hong Kong have jurisdiction over any dispute arising out of this policy.
Changes
The effective date of this draft is 11 October 2026. If the policy changes, this page will show a new effective date. These pages stay out of search indexes until the operator confirms a public release.