Scope and operator
This policy covers the Captain Who website and website accounts. The operator is 焦申华, an adult individual. The initial beta is for individuals and businesses in mainland China. Contact sh_jiao@zju.edu.cn for support, privacy, security or personal information requests.
The operator manages this mailbox; its university domain does not mean the university operates, sponsors or endorses the product. This policy does not replace notices for desktop software, user-selected models, MCP servers or other third-party services.
Information and purposes
- Identity and login: email, username, CloudBase user ID, email-verification and account status, and sessions for registration, verification, login and recovery. Tencent CloudBase handles password verification; the website business database does not store passwords.
- Business profile: user ID, display name, language, role, status and timestamps for account service and administration. The beta does not collect business-verification or payment data. The website currently does not collect desktop installation IDs or hardware serial numbers.
- Choices and requests: policy versions, consent status, source and time, plus deletion reason category, status and processing times, to honor choices and rights requests.
- Security and administration: necessary IP addresses, request times, client type, request IDs, errors and security events, plus administrator, action, subject and time records, for abuse prevention, troubleshooting and security traceability. We do not collect unrelated personal information for website accounts.
- Support: your email, description and necessary attachments to handle enquiries. Do not send passwords, verification codes, keys or identity documents. Identity checks use only the minimum information proportionate to the request.
Homepage interactive-preview input is used only for the current page display. That feature does not submit it to a server or retain it after refresh. Necessary website access logs are separate. We do not sell account information to advertisers or require optional marketing or analytics for basic accounts.
Providers and locations
Tencent Cloud EdgeOne Pages hosts the website using overseas acceleration excluding mainland China nodes. Page access sends an IP address, request path and necessary connection information to the relevant nodes. CloudBase handles email verification, passwords and identity; the business API and PostgreSQL database use the Shanghai environment. Passwords and verification codes are sent to the identity service, not stored in the website business database.
Email codes use CloudBase’s built-in sender; necessary human verification uses the service integrated through its SDK. Support uses the published mailbox and its email provider. See the Tencent Cloud Privacy Statement for provider processing. A database in Shanghai does not establish that all website information is processed only in mainland China.
Providers receive information necessary for their functions. We explain new purposes, recipients or material changes and address applicable notice, consent and personal information protection requirements.
Adopted retention rules
These are the operator’s adopted retention and cleanup rules. During beta, the operator records, verifies and manually performs cleanup; this is not a claim that automatic erasure has been deployed.
- Account data: kept while the account exists; the authentication identity and main-database account data are deleted within 15 working days after verification of a cancellation request.
- Related backups: rotated and erased within 30 days after main-database deletion, isolated from routine use meanwhile. Confirmed deletions are reapplied after restoration. Cloud business-data automatic backups are not enabled for the current shared database; necessary maintenance copies enter the same cleanup register.
- Necessary network security logs: retained for 6 calendar months from creation, then deleted, not a basis for indefinite business-data retention.
- Support email: relevant messages and working copies deleted within 90 days of case closure.
- Minimal proof and audit: consent proof, cancellation proof and necessary administrative audit retained for 3 years from creation, then deleted. Linkable records are not described as anonymous.
These periods do not establish independent verification of all provider-level logs or copies. The operator coordinates provider-held information through available management and rights-request channels and communicates outcomes; submitting a request is not cleanup completion. Legally required or dispute-related retention is restricted in scope, purpose and duration and ends when its reason ends. The 15-working-day, 30-day, 90-day and 3-year periods are adopted operating rules, not universal statutory deadlines.
Access, correction, export and deletion
Available account controls support viewing, correction and export. You may also contact sh_jiao@zju.edu.cn for access, copies, correction, deletion, withdrawal of consent, account cancellation or an explanation. Website suspension does not prevent email requests.
Cancellation is handled manually by email in this round. Use your registered mailbox, without sending a password or verification code. After proportionate identity verification, the operator records a case reference, scope and deadline, and notifies you of the outcome. If a request cannot be met, we explain why and how to follow up.
Withdrawal does not invalidate earlier processing; stopping processing essential account information may prevent continued service. A message or request is not confirmation that identity, database records and all backups have been erased. Minimal proof and logs follow their separate rules.
Necessary storage and security
Necessary browser storage maintains sign-in. We do not enable first-party optional behavioral analytics or advertising tracking. Cloud infrastructure can produce necessary operational and security logs. Clearing website data or signing out requires another sign-in for account use; sign-out does not promise immediate revocation of all issued CloudBase tokens.
The website uses HTTPS, email verification, necessary rate limits, SDK human verification and server-side authorization. Website administrators can view, suspend and restore website accounts, with an administrative audit trail. Suspension restricts website business APIs and data, without deleting the CloudBase identity. These protections cannot guarantee absolute security. Beta flows still require real human tests; page messages and unit tests are not complete acceptance evidence.
Report security concerns through the public mailbox. Personal information incidents are handled and notified as required.
Age eligibility
Initial registration is limited to users aged 18 or older; it is not offered to minors. Business representatives must also meet the age requirement and have appropriate authority. Below-age accounts will have service stopped and their information reviewed and handled. Routine registration does not collect identity documents.
Version and activation
This version applies to the free website-account beta. Its effective date and version are shown on this page. Registration requires an affirmative age confirmation and acceptance of these policies; consent is not preselected and binds to the accepted versions.
Material changes are clearly notified, with renewed consent where required. You may retain this page and its version; historical consent records follow the retention rules above.