Skip to content
ArchiveZaunEkko Docs
Reading
Text size
Fonts
简体中文English
Show contents

Privacy policy

Status
Current
Updated
2026-09-18
Scope
Portal / Account / ZaunEkko's Blog / API Marketplace / Status / Docs

Effective 18 September 2026.

This page explains what ZaunEkko collects, why, how long it is kept, who can see it, and what you can do about it.

There is no "we may" or "where necessary" hedging here: if something is not implemented, it is not claimed. For security reasons, the parts that protect your account state their purpose and scope without describing how they work.

This is a translation. The Chinese version governs if the two differ.

Who processes your information

OperatorZaunEkko (operated by an individual)
ICP filing辽 ICP 备 2021005136 号
Contactsupport@zaunekko.com

This policy covers six sites: Portal, Account, ZaunEkko's Blog, API Marketplace, Status and Docs. They share one account system, so they share one privacy policy.

What we do not do

What we collect

What you give us

InformationWhenRequired
EmailSign-up, change of addressRequired for password sign-up; must be verified
UsernameSign-upRequired, publicly visible
Display nameSign-upRequired, publicly visible
PasswordSign-upRequired for password sign-up; never stored in plain text
AvatarWhen you upload oneOptional, publicly visible
Comments and submissionsWhen you postOptional, publicly visible
Support ticketsWhen you submit oneOptional
Two-factor secret and recovery codesWhen you enable two-factor yourselfOptional

What social sign-in brings

When you sign in with GitHub, Google, QQ or Linux DO, we receive and store:

Providers differ, and the difference matters:

ProviderCan we obtain your email?
GoogleYes, when you agree on its consent screen
GitHubYes, when you agree on its consent screen
Linux DONo
QQNo. QQ only gives an identifier scoped to this site. We never see your QQ number or your email

When no usable email is available, that sign-in creates a new account. If you already had one here, sign in the way you used before and then link the social account under Security.

What using the site produces

RecordWhy
Sign-in and device recordsSo you can review your own sign-ins and end any you do not recognise
Security logThe only trail available if an account is compromised
Points ledgerLedger integrity. Never rewritten, never deleted
Activity totalsRunning counts, used for levels and badges

These records are visible only to you and to site administrators.

Why we collect it

PurposeInformation involved
Letting you sign inSign-in identifier and credentials, social identity
Confirming the email is yoursEmail, verification code
Keeping accounts and the sites secureSign-in and device records, security log
Two-factorThe method you chose to enable, and its recovery codes
Showing who you areUsername, display name, avatar
Levels and pointsActivity totals, points ledger
Answering youTicket contents, contact email

Security-related processing exists to protect the account itself. It is not used for profiling, scoring or advertising.

How long we keep it

DataRetention
Account basicsFor the life of the account
Sign-in and device recordsA fixed lifetime, after which they expire; revocable at any time under Security
"Last sign-in method" hintA fixed lifetime; cleared instantly when you click "Not me"
Security logRetained long term
Points ledgerNot deletable
Email verification codesShort-lived

The security log and the points ledger survive account closure; the reason is in the next section.

Leaving an account unused does not delete it. If you want it gone, close it yourself — see below.

Who can see it

Public (any visitor, including signed-out ones): username, display name, avatar, anything you post publicly, level and badges.

Only you and site administrators: email, sign-in and device records, points balance and ledger, ticket contents, security log.

Only two kinds of third party touch your information:

  1. Email delivery — Alibaba Mail. Verification codes and security notices pass through it, so it sees your address and the message.
  2. The social sign-in you chose — clicking Google, GitHub, QQ or Linux DO sends your browser to them, so they learn you are signing in to this site. We do not push your information to them, and we do not pull anything beyond the granted scope.

There is nothing else. No analytics vendor, no ad network, no "partners".

Where it is stored

Servers are located in mainland China. We do not transfer your personal information outside it.

Social sign-in is an exception in the opposite direction: it is your browser that contacts Google or GitHub, not us sending your data abroad. If you would rather avoid that interaction, sign up with an email and password.

What you can do

All of the following are self-service under Account → Security:

What closing an account actually does

Closure is anonymisation, not physical erasure:

What remains: the points ledger and the security log. They no longer point to you, but the records stay — the points ledger is never rewritten, and the security log is the only trail available afterwards. If that is unacceptable to you, contact us before closing.

Closing requires a second factor, because it cannot be undone.

Cookies

We use only first-party cookies, all of them serving sign-in itself. There are no third-party or advertising cookies. See Cookies.

Children

This site is not directed at children under 14. If you are a minor, please use it with a guardian's guidance. If we learn we have collected a child's personal information without knowing, we will delete it promptly.

Changes

Material changes — new data collected, a new purpose, a new third party — update the effective date on this page and are noted in the site changelog. Wording clarifications are not announced separately.

Contact

Any privacy question, any difficulty exercising the rights above, or a complaint: support@zaunekko.com.