Privacy Policy
Last Updated: May 20, 2026
Effective Date: May 30, 2026
This Privacy Policy (hereinafter referred to as “this Policy”) is designed to clearly explain to users how the software operator (hereinafter referred to as the “Operator”) collects, uses, stores, shares, and deletes relevant data and information during the user’s use of this software and related online services. As an internet technology team that values user privacy and data security, the Operator fully recognizes the importance of personal data to users and strictly adheres to the fundamental principles of privacy protection across major global jurisdictions.
1 Scope of Information Collection
1.1 Account Registration
Depending on the applicable laws of the country or jurisdiction where the user is located, two registration mechanisms are provided:
1.1.1 General Registration Mechanism
The General Registration Mechanism applies in the vast majority of countries or jurisdictions. Under this mechanism, this software and associated online services do not collect directly identifiable personal data. Users acknowledge and agree that device IP addresses, session tokens, and similar data shall be considered as pseudonymized personal data in certain jurisdictions. Our processing of such data is strictly limited to what is necessary for maintaining service security and regional differentiated billing, and we provide protection commensurate with applicable laws. The Shared Community feature is independent, and accessing the Shared Community requires the completion of real-name verification.
1.1.2 Statutory Real-Name Verification Mechanism
Only when the laws and regulations of the country or jurisdiction where the user is located mandatorily require a real-name system for online identities shall the platform activate the Statutory Real-Name Verification Mechanism to process account registrations in accordance with such laws.
1.2 Regional and Location Determination Information
To fulfill regional differentiated billing contracts and technical compliance obligations in specific jurisdictions, this software will determine the user’s current location. Generally, this location refers to the country; however, in special regions with independent jurisdiction or quasi-constitutional autonomy (such as the Isle of Man, Jersey, Guernsey, the Faroe Islands, the Cayman Islands, Hong Kong SAR, Macau SAR, etc.), verification shall be refined to that specific subnational region. This determination is implemented solely by the server transiently verifying coarse-grained network identifiers (such as IP addresses) in memory during request interactions. The platform does not obtain precise GPS positioning. The relevant de-identified characteristics are used solely to determine whether the user is within the region corresponding to the paid service and to enforce the Traveler Grace Period rule, without any personal identity profiling association.
1.3 Automatically Collected Technical Data
During the operation of the software by the user, to ensure the normal functioning of basic services, this software will automatically collect the following technical characteristic information:
- Device Internet Protocol (IP) address (used solely for the regional determination, security handshakes, and network security protection described in Section 1.2 of this Policy. The Operator, in principle, does not actively establish a long-term database targeting user network identifiers, nor does it use them for user profiling or commercial analysis; necessary log records generated by network infrastructure, security service providers, or legal requirements shall not constitute a user identity profile actively established by the Operator);
- Locally stored characteristics or credentials used to maintain user login status and session security (such as Local Storage, session tokens, essential cookies);
- Client software crash logs and anomaly diagnostic data (relying solely on the native underlying mechanisms of the device’s operating system, without integrating third-party analytics SDKs). Crash logs may contain technical information such as device model, system version, and error stack traces.
1.4 Payment Data Characteristics
As required by the laws of various countries, the Operator must retain financial reconciliation logs for the long term within the scope of its statutory obligations. Generally, the Operator only passively receives billing data pushed by payment platforms; in the event of specific disputes, refund appeals, or when technically necessary for fiscal and tax audits, the Operator reserves the right to verify necessary transaction statuses and de-identified order credentials with the payment platform, as detailed in Section 4.5 of this Policy.
1.5 Regional Consistency Verification Characteristics
The system will automatically check and compare the user’s current device environment characteristics, such as operating system language and system time zone, to verify whether the device environment matches the region of the subscription plan purchased by the user, in order to prevent cross-region fraud. The aforementioned environmental characteristics are used solely for regional consistency verification and anti-fraud purposes, and shall not be used for user profiling, advertising push, or behavioral analysis.
2 Purposes of Information Use
The purposes for which the Operator collects and processes the aforementioned non-directly identifiable technical data are clear and limited, primarily including the following:
2.1 Regional Differentiated Billing Verification
Due to the regionalized pricing mechanism for paid subscriptions, the Operator needs to understand the user’s approximate geographical location (refer to Section 1.2) to ensure tax and legal compliance and correct billing.
2.2 Core Business Maintenance and Risk Control
Relevant technical data is used solely for account identity verification, handshakes for multi-device data synchronization protocols, software update security notifications, platform security defense risk control (such as combating malicious cyberattacks, cracking, and promo abuse), and performing basic technical troubleshooting. The Operator will not use this data for user profiling, targeted advertising push, or sell it for profit to any undisclosed third parties.
3 Protection of Minors
The Operator attaches great importance to the privacy and safety of minors. However, this software does not collect the user’s date of birth, age, or any direct personal information during registration and multi-device synchronization (only a one-time age range assessment is performed locally on the user’s device, which is not transmitted to the server). Therefore, the Operator has no technical awareness or record of the user’s age at the infrastructure level.
3.1 Shared Community Real-Name Verification Gate and Backend Traceability Mechanism
In view of the dual statutory obligations regarding the online protection of minors in specific jurisdictions and the anti-anonymity abuse of Internet User-Generated Content (UGC), the Shared Community provided by this software and its website is a completely independent, voluntarily enabled advanced feature, which is disabled by default.
- Real-Name Verification and Age Blocking: When a user actively chooses to enable this feature, the user acknowledges and agrees that mandatory real-name identity verification (including age verification) must be completed. Users must complete real-name binding through mechanisms such as third-party compliant verification agencies integrated into the platform or by linking a mainstream credit/debit card. Minor users (or those below the age specified by local law) or users who have not completed verification will be unable to use this feature.
- Liability for Illegal Traceability: The Operator’s core synchronization service maintains pure anonymity, but the Shared Community strictly enforces the principle of “voluntary in the frontend, enforced real-name verification in the backend.” If a user publishes illegal or non-compliant content within the Shared Community, endangers network security, or infringes upon the rights of others, the Operator reserves the right to report to the police/initiate litigation and take other actions to safeguard the rights and interests of the community.
3.2 Restrictions and Remedial Measures in Specific Circumstances
Given that the Operator cannot continuously verify the usage status of the user’s local application, if the Operator becomes actually aware through credible channels (such as formal notification from a guardian or a court order) that the actual user of an account is a minor and lacks effective guardian consent, the Operator will immediately prohibit the account from accessing the Shared Community feature, or, in accordance with applicable law and the guardian’s request, execute an erasure procedure for the account’s encrypted data in the cloud. Parental Controls and Contact: If a guardian believes that their ward is using this software or that there are data compliance issues, they may communicate with us via the contact email in Section 10. We will fully cooperate and take the aforementioned restriction or deletion measures.
4 Account Deletion and Data Erasure Mechanism
Users have absolute control over their accounts and synchronized data. The Operator provides users with a transparent and convenient channel for personal data removal:
4.1 Self-Service Deletion Portal
There is a clearly visible “Delete Account” function entry in the mobile application (APP) and the web-based user center page of this software. Users have the right to directly initiate a request to delete their account and all cloud-based personal data at any time through this portal or through official public technical support channels.
4.2 Response and Complete Erasure Period in Case of Active Deletion
4.2.1 Within 30 days from the date of receiving a user’s formal deletion or erasure request, the Operator will respond and execute the deletion operation, immediately cease providing synchronization services for the user, and perform logical deletion of the User-Generated Content (UGC) synchronization data hosted by the user in the cloud. 4.2.2 The relevant fully encrypted data blocks will be irrecoverably deleted within a reasonable period during the backup lifecycle and disaster recovery media rotation cycle, and will be eliminated from the backup environment through overwriting or natural obsolescence mechanisms. 4.2.3 The retention of statutory underlying logs in the event of active deletion is governed by Section 4.5.
4.3 Automatic Data Cleanup After Expiration of Paid Services
4.3.1 Upon expiration of the paid service (including any grace period, if applicable), if the user does not renew and has not actively deleted the account, this software will terminate the cloud synchronization service for that account and delete all User-Generated Content (UGC) synchronization data and historical encrypted data blocks hosted on the server for that account after 30 days. 4.3.2 During the aforementioned 30-day cleanup period, the user may renew at any time to restore service and data access; upon expiration of the cleanup period, the relevant data will be irreversibly cleared and cannot be recovered. 4.3.3 The automatic deletion of synchronization data after service expiration does not affect the continued retention of transaction-related data pursuant to statutory retention obligations, which is governed by Section 4.5.
4.4 Data Erasure Period in Case of Inability to Log In
Given the technical architecture of this software, no email address or phone number is collected when registering using the General Registration Mechanism. Therefore, when a user’s login credentials and security recovery key are permanently lost and they cannot log in to the client, the Operator is technically completely unable to uniquely verify the applicant’s substantive control over the anonymous account through any external channel (such as email or social media private messages). In order to balance reasonable deletion requests and resolutely prevent malicious third parties from exploiting external appeal channels to impersonate the original owner and attempting to maliciously destroy others’ digital assets, the Operator implements the following technical security circuit breaker cycles:
Special Note: For the review of refund eligibility, liquidation ratios, and specific financial application procedures involved in the above extreme circumstances, please strictly refer to the relevant terms of the Refund Policy. This section only elaborates on the full lifecycle processing of the associated cloud-based encrypted data.
4.4.1 Long-Term Accounts: 90-Day Security Vacancy and Activity Circuit Breaker Logic
- Security Trusted Observation: From the time the Operator receives an external appeal for the clearance of a specific anonymous account, the account’s fully encrypted data blocks in the cloud will enter a 90-calendar-day Asset Security Freeze Period. If the paid service for this account expires during this period, it shall be processed according to the routine expiration cleanup procedure in Section 4.3 of this Policy, and the freeze period and related appeal shall immediately terminate.
- Immediate Circuit Breaker upon Client Activity: During the 90-day freeze period, if the account generates any legitimate login, synchronization, or API handshake based on the original private key on the client, this directly proves that the external appeal is a malicious attack unauthorized by the original owner. The procedure will be terminated immediately.
- Irreversible Erasure: If the account remains completely silent within the 90 days without any credential response, proving that the key is indeed permanently lost and the account is in a de facto ownerless state, it will be deleted upon expiration of the freeze period.
4.4.2 Newly Purchased Accounts
For new accounts where login credentials are lost within 72 hours (3 calendar days) after purchasing a paid subscription, the Platform, after verifying the original payment stub, executes an accelerated erasure process:
- According to the terms of the Refund Policy, based on whether the target account has historical records of login, synchronization, or API communication, a 14-calendar-day “Security Silence Period” (for accounts with historical records, to strictly prevent malicious impersonation for account deletion) or a 7-calendar-day “Security Silence Period” (for brand new, vacant accounts with no historical activity records) will be applied.
- Circuit Breaker and Erasure: During this period, if any client activity record is generated, the erasure process will be immediately circuit-broken and terminated; if there is absolutely no activity record, upon expiration of the silence period, the system will, simultaneously with the execution of the refund settlement, immediately trigger the physical deletion of the fully encrypted data blocks in the cloud. After this deletion is completed, the cloud data status of the account will be consistent with Section 4.3.
4.4.3 Abnormal Data Abuse Restriction and Immediate Cloud Storage Circuit Breaker
During the 90-day freeze period or the 30-day silence isolation period, to prevent malicious attackers from exploiting the loss appeal cycle to use the Platform’s cloud as free offline cold backup space:
- Excessive Storage Circuit Breaker: If it is detected that the account abnormally uploaded data frequently and massively before applying for erasure, and the account has been downgraded to the free version due to entering the clearance process, if its occupied volume exceeds the upper limit of the free version quota, the storage space exceeding the limit will trigger an immediate circuit breaker lock.
- Termination of Read/Write and Transfer: The Operator has the right to stop any reading, writing, and transfer functions for the account’s cloud-synchronized data.
4.5 Financial Data Subject Isolation
The Operator relies on compliant third-party payment channels (such as Creem, Paddle, Stripe, etc.) to process transaction settlements. Privacy information such as the name and billing address entered by the user during payment is entirely retained within the independent security domain of the third-party payment channel. The Operator only records necessary payment information. Such reconciliation logs fall under the statutory tax and audit retention exemption category and do not fall within the scope of User-Generated Content erasure.
5 KN Sync Activity Records
5.1 Scope of Recording and Legal Basis
When a user actively enables or disables the official KN Sync service in the client settings, the Operator only records the time of operation of this action. This processing is based on the Operator’s Legitimate Interests. It is used to respond to potential third-party infringement claims, copyright disputes, or judicial evidence requisition orders. The Operator will use this record as exculpatory evidence for rights confirmation to legally prove the actual storage host destination of a specific account within a specific historical interval, thereby clearly delineating the legal liability boundary between the Platform and the user, avoiding confusion of the liable subject.
5.2 Destruction and Data Retention Policy
In strict accordance with data minimization and compliance audit requirements, the following destruction mechanism applies to this feature toggle record: After the user disables KN Sync or deletes the account, the corresponding historical toggle records will be automatically deleted after 90 calendar days.
6 Data Storage, Data Backup, and Storage Locations
6.1 Primary Data Storage Locations
In order to improve service access response speeds, ensure business continuity, and optimize user experience, the Operator implements a regionalized data storage and processing strategy based on the geographical location of the user:
- Users in the North American Region: Relevant user data and business data are primarily stored in and served from the infrastructure and servers located in Chicago, United States.
- Users in the Asia-Pacific Region: Relevant user data and business data are primarily stored in and served from the infrastructure and servers located in Singapore.
We retain trusted third-party infrastructure and cloud service providers (including but not limited to server hosting providers, data center operators, and trusted cloud storage service providers) to host our backend services. The aforementioned partners act as our Data Processors and shall strictly fulfill their confidentiality obligations and data security responsibilities in accordance with the data processing agreements, this Policy, and applicable laws and regulations. The aforementioned providers have no right to, and are unable to, directly access, retain, or read the user’s personal data in plaintext format (for a detailed list of third-party infrastructure service providers and relevant disclosures on third-party SDK integration, please refer to Section 8 [Third-Party Services and SDK Disclosure]).
[Special Notice]: Under circumstances where the user uses the Standard Version or uses the Solo Version without using KN Sync, all synchronized data of the user is strictly encrypted via standard End-to-End Encryption technology prior to leaving the user’s device (for specific encryption and authorization rules, please see the Terms of Service and End User License Agreement). Our infrastructure providers only host and store the aforementioned encrypted, unidentifiable, and irreversible binary large objects (BLOBs). No third party (including the infrastructure providers and the Operator itself) possesses plaintext decryption capabilities, nor can they read the actual content of the user’s data.
6.2 Backup Data Storage Locations
To mitigate the risk of data loss caused by unforeseen infrastructure failures, natural disasters, or other force majeure events, we have established a comprehensive off-site disaster recovery and redundant backup mechanism:
- Backup Mechanism: Users’ synchronized data and relevant system data will be securely backed up on a regular basis and stored in encrypted format in off-site cloud storage systems or redundant data centers located in a different geographical region, thereby ensuring data recoverability and high availability under extreme circumstances.
- North American Region Backup: Backup data of users in the North American region will be strictly retained in secure nodes within the United States.
- Asia-Pacific Region Backup: Backup data of users in the Asia-Pacific region will be strictly retained in secure nodes within the Asia-Pacific region (including but not limited to Sydney, Australia, and Tokyo, Japan).
7 Business Transfer and Reorganization
As the business continues to develop, the operating entity of this software may undergo strategic adjustments in the future. If this software or related platforms involve a name change, merger, acquisition, bankruptcy liquidation, significant asset transfer, or change of operating entity, the user’s basic account technical information and cloud-based encrypted data blocks, as part of the overall business assets, may be transferred to a new receiving entity. In this regard, the Operator makes the following strict statutory commitments to the user:
- Continuous Security Obligation: The new operating entity shall continue to provide a level of privacy protection substantially equivalent to this Policy and continue to fulfill relevant security obligations to the extent permitted by applicable law.
- Mandatory Notice Period: Before the occurrence of an entity change or asset transfer, the Operator will issue a formal announcement to all users at least 30 days in advance through in-app pop-ups, social media, or system messages, clearly disclosing the basic information of the new entity.
- User’s Absolute Right of Choice: During the 30-day notice period from the announcement, users have the right to refuse. If a user is unwilling to accept the management of the new operating entity, the user has the right at any time to choose to delete their account, download and export all their local assets, or completely delete all their fully encrypted data blocks in the cloud through the aforementioned deletion process.
8 Third-Party Services and SDK Disclosure
In order to achieve secure cross-border settlements, global network acceleration, high-availability underlying storage, and efficient system crash rate monitoring, this software integrates some industry-leading third-party service providers and Software Development Kits (SDKs). The processing of data by these third-party service providers is governed by their respective privacy policies, as specifically disclosed below:
| Third-Party Service Provider / SDK Name | Application Scenario and Processing Purpose | Official Privacy Policy Link |
|---|---|---|
| Creem | Online payment processing and billing settlement | Privacy Notice |
| Paddle | Online payment processing and billing settlement | Privacy Policy |
| Stripe | Online payment processing and billing settlement | Privacy Policy |
| Cloudflare | Network security defense and CDN content acceleration | Privacy Policy |
| UpCloud | Cloud server and backend infrastructure hosting | Privacy Notice |
| Vultr | Cloud server and backend infrastructure hosting | Privacy Notice |
9 Legal Basis for Data Processing
The Operator only processes relevant data where it has a lawful basis, primarily including:
- For the performance of the service contract between the user and the Operator;
- For the legitimate interests necessary to maintain platform security, prevent fraud, and protect users’ digital assets;
- For compliance with statutory obligations required by fiscal, tax, audit, anti-money laundering, and other laws and regulations;
- Other processing activities carried out as required by law or with the user’s explicit consent.
10 User Rights
To the extent permitted by applicable law, users have the right to:
- Obtain information about the processing of their data;
- Request access to, correction, or deletion of relevant data;
- Request restriction of specific processing activities;
- Obtain a copy of their data where technically feasible;
- Object to specific processing based on their particular situation;
- Lodge a complaint with a competent data protection supervisory authority. Given that this software adopts a registration mechanism that does not collect email addresses, mobile phone numbers, or real names, in some cases, the Operator may be unable to confirm the controlling relationship between the applicant and the account through traditional identity verification methods. Therefore, without affecting account security and the legitimate rights and interests of third parties, the Operator will assist users in exercising the above rights within a reasonable scope.
11 Cross-Border Data Transfers
Given that some third-party infrastructure, payment service providers, and network service providers may be located in different countries or jurisdictions, relevant data may be subject to cross-border transmission. The Operator will, in accordance with applicable legal requirements, make reasonable efforts through contractual arrangements, technical protection measures, and organizational management measures to ensure that the relevant data receives a level of protection substantially equivalent to this Policy during transmission and processing.
12 How to Contact Us
If you have any questions, comments, or suggestions regarding this Policy, or need to conduct a minor protection appeal or data erasure review, you may contact us through the following official channels:
- Official Email: privacy@easchi.com
- Response Period: We will verify and reply within 30 days of receiving your formal request (or a shorter period as required by applicable law).