Know Your Wisdom

Privacy Policy

2026-08-27

中文版本:隐私政策 · Related: Terms of Service · Refund Policy · Acceptable Use Policy

Effective date: 27 August 2026 Last updated: 27 August 2026

This policy explains how the operator of KnowUV — Wuhan Zhizhizhi Trading Co., Ltd. (武汉市知之智商贸有限公司), Wuhan, Hubei Province, People's Republic of China — handles personal data.

Contact for anything in this policy: cjh@knowuv.com.

1. Two kinds of people, two different roles

KnowUV is a link service, so personal data reaches us on two distinct paths. Which one you are on decides who is legally responsible for your data.

CustomersVisitors
WhoPeople with a KnowUV account who create linksPeople who click or scan a link a Customer made
Our roleController — we decide why and howProcessor — the Customer decides why and how
Ask questions toUs, at cjh@knowuv.comThe Customer whose link you followed; we will help you reach them

If you clicked a KnowUV link and want your data erased, the fastest route is the organisation whose link you followed. If you cannot identify them, write to us and we will either forward your request or identify the account holder for you, as the law requires.

2. What we collect from Customers

Account data. Username, email address, phone number, display name, avatar, and a salted hash of your password (we never store the password itself).

Third-party sign-in identifiers. If you sign in with Google, the identifier and basic profile in the Google ID token. If you connect a WeChat Official Account, the WeChat openid, unionid, nickname and avatar for your account.

Verification data. One-time SMS codes and the phone number they were sent to, held briefly (see section 6) to prove a number belongs to you.

Content you create. Destination URLs, link settings and plugin configuration, landing-page content, form definitions, uploaded images and files.

Billing data. Your credit balance and a ledger of every top-up and deduction (amount, resulting balance, reason, reference); order records; and, where you pay us directly, the payment channel and transaction reference. We never receive or store your full card number — card data goes directly to the payment provider.

Technical and usage data. IP address, browser and device information, pages you view in the dashboard, API token usage, and server logs.

Support correspondence. What you write to us and what we write back.

3. What we collect from Visitors

When someone opens a short link or scans a dynamic QR code, we record a visit on behalf of the Customer who owns it:

  • The link opened, the time, and the referring page
  • IP address, and the approximate location derived from it (country, region, city — not a precise location)
  • Browser, operating system, device type, user agent, and the in-app browser identifier (X-Requested-With)
  • A pseudonymous visitor identifier stored in a cookie, used to keep a visitor on the same destination across visits

Two further items are collected only when the Customer has switched on the corresponding feature, and only then:

  • Verified phone number — where the Customer has enabled the SMS phone-verification gate, the visitor must verify a phone number by SMS before reaching the destination, and that number is attached to the visit record. Customers who enable this gate must tell their visitors why, and have a lawful basis for it.
  • WeChat openid — where the Customer has enabled the WeChat routing feature, the visitor's openid for that Official Account.

Gated links record nothing until the gate is passed. If a visitor is shown a password prompt or a phone-verification page and leaves, no visit record is created.

We do not use this data to build cross-customer advertising profiles, and we do not sell it.

PurposeDataLegal basis (GDPR Art. 6)
Providing the Service — resolving links, applying your settings, running your dashboardAccount, content, technicalContract
Metering and billingBilling, usageContract
Authentication and account securityAccount, verification, technicalContract; legitimate interests
Reviewing destinations for abuse (see section 5)Destination URL and its rendered contentLegitimate interests — preventing phishing, malware and fraud; legal obligation
Rate limiting, fraud and bot preventionTechnical, usageLegitimate interests
Analytics reporting to the Customer who owns the linkVisit recordsProcessor, on the Customer's instructions
Service emails, and marketing email you can unsubscribe fromAccountContract; consent
Complying with the law, and responding to lawful requestsAs requiredLegal obligation

Where we rely on legitimate interests, we have weighed them against your rights, and you may object — see section 8.

5. Automated destination review

Because URL shorteners are a well-known vehicle for phishing and malware, every destination that is not already trusted is reviewed before the link resolves for anyone. That review is automated: an isolated browser loads the destination, follows redirects, decodes any QR code it finds, and captures the page's text and a screenshot. Those two artefacts are passed to a content-classification model that returns a risk score and a short reason. Links assessed as violating are disabled.

Three things worth being explicit about:

  1. The destination page is fetched from our infrastructure, not from a visitor's device. No visitor data is involved in review.
  2. The captured text and screenshot are sent to a third-party model provider for classification. They are used for that classification only, and we contract against their use for model training.
  3. The decision can be appealed to a human. Write to cjh@knowuv.com with the short code. Where a decision meaningfully affects you, you have the right to human review, to state your case, and to contest the outcome.

Full detail is in the Acceptable Use Policy.

6. How long we keep things

DataRetention
Account dataWhile the account is open, then 90 days after closure
Link definitions and settingsWhile the account is open, then 90 days after closure
Visit records720 days (about 24 months) from when the record is written, then automatically deleted by the database
Verified phone numbers on visit recordsDeleted with the visit record they belong to
One-time SMS codes5 minutes, then automatically discarded
Billing ledger, orders and invoices10 years — required by PRC accounting and tax law
Abuse reports and review decisions24 months, to detect repeat offenders
Server logs90 days
Support correspondence24 months after the ticket closes

Backups are overwritten on a rolling cycle and cleared within 90 days. Where the law requires us to keep something longer, we keep only that, and only for that reason.

7. Who we share it with

We do not sell personal data. We share it with these categories of recipient, each under a contract limiting them to our instructions:

RecipientWhat forWhere
Alibaba CloudHosting, CDN, object storage, SMS deliveryChina; CDN edges worldwide
Paddle.com Market LtdMerchant of record for international sales — checkout, tax, invoicing, refundsUK / EU
Alipay (Ant Group), WeChat Pay (Tencent)Payment processing for purchases in mainland ChinaChina
Tencent / WeChatOfficial Account features, openid resolutionChina
Google LLCGoogle Sign-In; website analyticsUS
IP geolocation providerTurning an IP address into a country/region/city
Content-classification model providerDestination review (section 5)

We also disclose data where we are legally required to, to establish or defend legal claims, or to protect the rights and safety of users and the public — including passing evidence to law enforcement, platform trust-and-safety teams and anti-phishing bodies in response to abuse.

If the business is sold or merged, data may transfer to the acquirer; we will tell you before that happens and it remains subject to this policy.

8. Your rights

Depending on where you live you may have the right to: access your data; correct it; delete it; restrict or object to processing; portability; withdraw consent at any time (without affecting past processing); and not to be subject to a solely automated decision with legal or similarly significant effect.

Exercise any of them at cjh@knowuv.com, with PRIVACY at the start of the subject line. We reply within 30 days, and will tell you if we need longer. We will ask you to verify your identity first. We do not charge for this and we will not treat you differently for asking.

If you are in the EEA or UK you may also complain to your local supervisory authority. In mainland China, your rights under the Personal Information Protection Law (PIPL) — including the right to request an explanation of our processing rules and to have a deceased relative's data handled by their next of kin — apply in full.

If you are a Visitor, the Customer who owns the link is the controller: send erasure and access requests to them. We will assist, and will identify them to you where the law requires.

9. International transfers

We operate primarily from mainland China, and our infrastructure is mainly in China. Some recipients in section 7 are outside it.

  • Transfers out of the EEA/UK rely on the European Commission's Standard Contractual Clauses (or the UK Addendum), with a transfer risk assessment where required.
  • Transfers out of mainland China are made on the basis of the PIPL standard contract, with separate consent obtained where PIPL requires it.

Ask us at cjh@knowuv.com for a copy of the safeguards for a specific transfer.

10. Cookies and similar technologies

We use a small number of cookies, and no third-party advertising cookies:

CookiePurposeLifetime
Session / authKeeps you signed inSession, or until sign-out
Locale preferenceRemembers your language12 months
SlV2<code>Keeps a visitor on the same destination for a given linkPer link
SlOtp<code>Remembers that a visitor already passed phone verification, so they are not sent a second SMS. HttpOnly.Up to 5 minutes
Google AnalyticsAggregate website statisticsUp to 24 months

Session, locale and the two Sl* cookies are strictly necessary for the features they support. You can block cookies in your browser, but link gating and sign-in will stop working. Where consent is required for analytics, we ask for it before setting those cookies.

11. Security

We use TLS in transit, encryption at rest for sensitive fields, salted password hashing, scoped API tokens you can revoke, least-privilege access for staff, and audit logging of administrative actions. Phone verification credentials are held in an HttpOnly cookie and re-checked against the server on every use — the cookie itself grants nothing.

No system is perfectly secure. If we suffer a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours where required, and notify you without undue delay where the breach is likely to result in a high risk to your rights.

Found a vulnerability? Report it to cjh@knowuv.com with SECURITY at the start of the subject line. We will not pursue legal action against good-faith research that respects user privacy and does not degrade the Service.

12. Children

The Service is not directed at children under 14, and we do not knowingly collect their personal data. If you believe a child has given us data, write to cjh@knowuv.com and we will delete it. Customers must not use the phone-verification gate, forms or landing pages to collect data from children.

13. Changes

We will update this policy as the Service changes. For material changes we will give notice by email or in-product at least 30 days before they take effect, and we will update the "Last updated" date. The current version always lives at this URL.

14. Contact

All enquiries go to one mailbox: cjh@knowuv.com

We are a small team, so a single address reaches us fastest. To help us triage, start your subject line with one of these tags:

TagUse it for
ABUSEPhishing, malware, spam or another abusive link — triaged first
SECURITYVulnerability reports
PRIVACYData access, correction, deletion and other privacy rights
REFUNDRefund requests and billing questions
APPEALA link or account you believe we disabled in error
SUPPORTEverything else

Staffed 08:00–22:00 China Standard Time (UTC+8), Monday to Friday. Reports tagged ABUSE are triaged outside those hours.

Postal: Wuhan Zhizhizhi Trading Co., Ltd., Wuhan, Hubei Province, People's Republic of China.