Privacy policy
- Status
- Current
- Updated
- 2026-09-18
- Scope
- Portal / Account / ZaunEkko's Blog / API Marketplace / Status / Docs
Effective 18 September 2026.
This page explains what ZaunEkko collects, why, how long it is kept, who can see it, and what you can do about it.
There is no "we may" or "where necessary" hedging here: if something is not implemented, it is not claimed. For security reasons, the parts that protect your account state their purpose and scope without describing how they work.
This is a translation. The Chinese version governs if the two differ.
Who processes your information
| Operator | ZaunEkko (operated by an individual) |
| ICP filing | 辽 ICP 备 2021005136 号 |
| Contact | support@zaunekko.com |
This policy covers six sites: Portal, Account, ZaunEkko's Blog, API Marketplace, Status and Docs. They share one account system, so they share one privacy policy.
What we do not do
- No advertising tracking, and no analysis of your browsing for advertising purposes.
- We do not build a reading profile of you. The activity figures on your account page are running totals only (for example "visit days: 5"), used for levels and badges.
- No plaintext passwords. Passwords are stored in an irreversible form. We cannot see your original password, so we cannot "recover" it — only reset it.
- We do not sell, trade or rent your personal information.
- We do not train models on your content.
What we collect
What you give us
| Information | When | Required |
|---|---|---|
| Sign-up, change of address | Required for password sign-up; must be verified | |
| Username | Sign-up | Required, publicly visible |
| Display name | Sign-up | Required, publicly visible |
| Password | Sign-up | Required for password sign-up; never stored in plain text |
| Avatar | When you upload one | Optional, publicly visible |
| Comments and submissions | When you post | Optional, publicly visible |
| Support tickets | When you submit one | Optional |
| Two-factor secret and recovery codes | When you enable two-factor yourself | Optional |
What social sign-in brings
When you sign in with GitHub, Google, QQ or Linux DO, we receive and store:
- The subject identifier that provider issues for you — not your QQ number or your email, but an ID that is only meaningful to this site
- Your username, display name and avatar URL on that platform
- A verified email, but only when the provider gives us one
Providers differ, and the difference matters:
| Provider | Can we obtain your email? |
|---|---|
| Yes, when you agree on its consent screen | |
| GitHub | Yes, when you agree on its consent screen |
| Linux DO | No |
| No. QQ only gives an identifier scoped to this site. We never see your QQ number or your email |
When no usable email is available, that sign-in creates a new account. If you already had one here, sign in the way you used before and then link the social account under Security.
What using the site produces
| Record | Why |
|---|---|
| Sign-in and device records | So you can review your own sign-ins and end any you do not recognise |
| Security log | The only trail available if an account is compromised |
| Points ledger | Ledger integrity. Never rewritten, never deleted |
| Activity totals | Running counts, used for levels and badges |
These records are visible only to you and to site administrators.
Why we collect it
| Purpose | Information involved |
|---|---|
| Letting you sign in | Sign-in identifier and credentials, social identity |
| Confirming the email is yours | Email, verification code |
| Keeping accounts and the sites secure | Sign-in and device records, security log |
| Two-factor | The method you chose to enable, and its recovery codes |
| Showing who you are | Username, display name, avatar |
| Levels and points | Activity totals, points ledger |
| Answering you | Ticket contents, contact email |
Security-related processing exists to protect the account itself. It is not used for profiling, scoring or advertising.
How long we keep it
| Data | Retention |
|---|---|
| Account basics | For the life of the account |
| Sign-in and device records | A fixed lifetime, after which they expire; revocable at any time under Security |
| "Last sign-in method" hint | A fixed lifetime; cleared instantly when you click "Not me" |
| Security log | Retained long term |
| Points ledger | Not deletable |
| Email verification codes | Short-lived |
The security log and the points ledger survive account closure; the reason is in the next section.
Leaving an account unused does not delete it. If you want it gone, close it yourself — see below.
Who can see it
Public (any visitor, including signed-out ones): username, display name, avatar, anything you post publicly, level and badges.
Only you and site administrators: email, sign-in and device records, points balance and ledger, ticket contents, security log.
Only two kinds of third party touch your information:
- Email delivery — Alibaba Mail. Verification codes and security notices pass through it, so it sees your address and the message.
- The social sign-in you chose — clicking Google, GitHub, QQ or Linux DO sends your browser to them, so they learn you are signing in to this site. We do not push your information to them, and we do not pull anything beyond the granted scope.
There is nothing else. No analytics vendor, no ad network, no "partners".
Where it is stored
Servers are located in mainland China. We do not transfer your personal information outside it.
Social sign-in is an exception in the opposite direction: it is your browser that contacts Google or GitHub, not us sending your data abroad. If you would rather avoid that interaction, sign up with an email and password.
What you can do
All of the following are self-service under Account → Security:
- Review: sign-in and device records, linked sign-in methods, points ledger
- Correct: display name, avatar; the username can be changed once within the window after sign-up
- Change your email: re-verification required
- Unlink a social sign-in: this deletes the identity information we hold from that platform. You cannot unlink your last remaining sign-in method — that would lock you out
- End any device or sign-in
- Turn off mention notifications
- Close your account
What closing an account actually does
Closure is anonymisation, not physical erasure:
- The username is replaced with a meaningless identifier and the display name becomes "已注销用户" (closed account)
- Email, password and two-factor are all cleared
- Every sign-in and remembered device is invalidated immediately
- Everything received from the social platform is deleted
- The account is marked closed
What remains: the points ledger and the security log. They no longer point to you, but the records stay — the points ledger is never rewritten, and the security log is the only trail available afterwards. If that is unacceptable to you, contact us before closing.
Closing requires a second factor, because it cannot be undone.
Cookies
We use only first-party cookies, all of them serving sign-in itself. There are no third-party or advertising cookies. See Cookies.
Children
This site is not directed at children under 14. If you are a minor, please use it with a guardian's guidance. If we learn we have collected a child's personal information without knowing, we will delete it promptly.
Changes
Material changes — new data collected, a new purpose, a new third party — update the effective date on this page and are noted in the site changelog. Wording clarifications are not announced separately.
Contact
Any privacy question, any difficulty exercising the rights above, or a complaint: support@zaunekko.com.