Privacy
Privacy Policy
This policy explains what happens when you use Thumbnail AB Test. The short version: the core score runs in your browser, an account is optional, and cloud history stores only the saved report data you choose to sync.
Last updated: July 29, 2026
- Core scoring stays localImage reading, scoring, and the deterministic preference model all run on your device before any save.
- Optional cloud historySigned-in saves store a downsized preview, title text, scores, and result metadata in your account.
- No YouTube accessWe do not connect to your YouTube account, videos, channel analytics, or Studio data.
What runs in your browser
When you run a test, your thumbnail files and title text are processed locally inside your browser.
Scoring and the deterministic 10,000-iteration preference model run on your device. The model produces a relative share within the options you provide. It does not observe real viewers, impressions, clicks, or YouTube CTR. You can compare variants without creating an account.
Device-local saved tests
If you save a test, Thumbnail AB Test stores a recent copy in your browser's IndexedDB so you can reopen it from the local history page on this device.
That local saved test includes downsized thumbnail previews, title text, scores, result metadata, and any YouTube test result you record manually. You can delete one test, clear the local history, export it as JSON, or remove it through your browser's storage settings.
When you choose Create revision, the saved titles and downsized previews are copied once into this tab's sessionStorage and removed as soon as the Tool reads them. This handoff does not contain your original image files.
Accounts and cloud history
You do not need an account to run the core tool. If you create an account, we store the account and session records needed to keep you signed in.
When you are signed in and choose to save a test, we also store the saved report in your cloud history. That record includes a downsized thumbnail preview, title text, preflight scores, the top-candidate label, relative model share, related metadata, and any YouTube test result you record manually.
If you record interest in Creator or Studio on the Pricing page, we store the plan, page language, and the times that choice was created or updated. We do not copy your email address into this record.
If you separately volunteer for product research on Pricing, we store your page language, consent version, and the times that permission was created or updated. While that permission is active, it allows us to use the verified email already on your account to invite you to voluntary Creator or Studio research. We send at most one research invitation to an account in 30 days. It does not add you to product updates or marketing, and neither the consent nor invitation record contains another copy of your email.
A research-invitation record contains a campaign key, plan, language, consent version, delivery state, and reservation, update, or sent times. An uncertain state means the provider result was not safe to treat as sent, and the system will not retry it automatically.
A completed invitation can include a private response link that expires after 45 days. The page records only interested or declined, along with the first response time. It has no free-text field and does not change your plan interest or research-contact permission. The raw link code is read from the URL fragment, removed from the address bar after a successful check, and never stored in browser storage. The server stores only its cryptographic hash and expiry.
Data controls and current limits
When the account service is available, you can delete one cloud report or every cloud test from History. Deleting cloud history does not remove copies stored in this browser.
The Dashboard can also download a newline-delimited JSON account-data file. It includes your profile, non-secret session and linked-account metadata, paid-plan interests, research-consent and invitation metadata, including a structured invitation response, subscription, API-key and team metadata, and cloud test history. Passwords, session and OAuth tokens, verification secrets, research-response link hashes, and API-key hashes are deliberately excluded.
A download is complete only if its last record is export_complete. Cloud payloads over 3 MiB from older records are represented by metadata instead of creative content.
The Dashboard can show the current session and up to 10 other active sessions, using only a coarse browser and operating-system label with update and expiry times. These labels come from browser-reported data and may be wrong. The device list does not show IP addresses, raw user-agent strings, session tokens, or OAuth tokens. You can sign out one other session or every other session while keeping the current one.
While signed in, you can change your password from the Dashboard by entering the current password and a different new password with 8 to 128 characters. A successful change signs out your other sessions and keeps this browser signed in with a new session.
You can remove a paid-plan interest or withdraw product-research permission from the Pricing page. Withdrawal stops future invitations under that permission but cannot retract an email already sent. Signed-in email and password accounts can be deleted from the Dashboard after you re-enter the account email and current password. This permanently removes the account, its plan interests, research consent, research-invitation history, and cloud data. Tests saved in the browser remain until you delete them separately.
If Polar billing is connected, deleting the account first checks for an open or processing checkout. Once clear, it immediately cancels the external subscription, revokes paid access, and asks Polar to anonymize personal billing details before removing the app account. This does not create a refund, and Polar may retain historical orders and subscription records. If that cleanup cannot be checked or confirmed, the app account and cloud data stay in place so you can retry. Deletion also pauses if you own a team with another member. Email verification, password recovery, and account email changes depend on the configured mail service.
How long we keep data
Device-local history keeps at most five tests. Saving another test removes the oldest local record. You can delete local records at any time, and your browser may clear site storage under its own settings or storage policy.
Account profiles and cloud reports do not expire automatically based on age. We keep them while the account exists, unless you delete one cloud report, all cloud tests, or the account. This keeps a saved decision history from disappearing without an action from you.
A paid-plan interest remains until you remove it or delete the account. Product-research permission remains until you withdraw it or delete the account. Withdrawing that permission removes the active consent but does not erase invitations or answers already recorded; those records remain until account deletion.
Private research-response links expire after 45 days. Product measurement is stored only as daily aggregate counts, and rows older than 400 days are removed.
Deleting live server data does not rewrite backups that already exist. The current production backup policy keeps up to seven daily copies, so deleted data can remain in those backups until the copies rotate out.
What we do not access
We do not ask for YouTube OAuth access, and we do not read your channel, videos, Studio analytics, comments, or revenue data.
A YouTube test result saved in History comes from the option you select. Thumbnail AB Test does not retrieve or verify that result through YouTube.
We do not upload your original image files for scoring. Cloud history uses the smaller saved-report preview generated after your test.
Analytics and measurement
On the production site, we use first-party product measurement on selected product pages. The browser sends a small set of events to our own endpoint. An event contains only its name, language, and coarse allowlisted states. A recorded YouTube result may be counted as matching the preflight leader, naming a different winner, or having no clear winner. You can also answer whether a result helped or not yet; that event distinguishes a first run from a rerun and broadly identifies your inputs, a saved revision, or mixed material. The event does not contain the variant label, images, titles, scores, account or test IDs, IP addresses, browser details, a raw URL or referrer, or an exact event time.
When a tab first opens an indexable page, the browser classifies the referring origin as search or other and maps the entry page to a fixed public-page label. It keeps only those two labels in the tab's sessionStorage. After the site confirms that measurement is enabled, the browser sends one entry event for that tab. It sends the same labels when the Tool starts and when the first comparison using non-sample material finishes. A page label identifies one published site page or other; it contains no raw path, query, or URL fragment. Our event collector never receives or stores the raw referrer, referring host, or full URL. Search may include paid search. An empty or suppressed referrer can count as other, and a failed request leaves a gap because it is not retried. If sessionStorage is unavailable, a later page load may be counted as another entry. These are tab-session event ratios, not pageview analytics or unique-user conversions, and they do not connect activity across tabs or devices.
The application adds accepted events to daily counts instead of saving raw events. Accepted writes and an independent daily cleanup remove aggregate rows older than 400 days. Global Privacy Control, Do Not Track, or the preference below stops measurement requests from this browser. Measurement uses no analytics cookie or third-party analytics provider.
The optional A/A instrumentation check is not currently active and has a separate switch. If activated later, it will keep only the letter a or b in sessionStorage for the current browser tab while showing both groups the same interface. Its aggregate report cannot represent unique people or conversion because reloads and new tabs can add exposures.
Product measurement preference
Checking this browser's product measurement preference.
Third parties
Cloudflare and our hosting and database infrastructure deliver and protect the site and store account or cloud-history data for signed-in users. Those services may process ordinary request metadata such as an IP address or user agent. We do not add those values to the product-event aggregate table.
If you buy Creator, Polar processes checkout, subscription, invoice, and customer-portal data. Deleting your Thumbnail AB Test account asks Polar to cancel the subscription and anonymize personal billing details, subject to Polar's retention of historical commercial records.
Because the scoring flow runs locally in your browser, no third party needs your original thumbnail files to calculate the result.
Changes to this policy
We may update this policy from time to time. When we do, we will change the last-updated date at the top of this page. Please check that date when you return.
Contact
If you have questions about this policy or about how the tool handles your data, email [email protected].
Test privately, save deliberately
Run the core test without an account. A free beta account can sync reports you choose to save across devices.