Matrix Beast logo Matrix Beast

Privacy Policy

This page is publicly accessible and intended for compliance review.

Matrix Beast Privacy Policy

Effective Date: January 27, 2026
Last Updated: January 27, 2026

Operator/Developer: Qingzhoushan Big Data ("we", "us", or "our")
Product: Matrix Beast (the "Product")

We value your privacy and the protection of your personal information. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the Product and related services, and how you can exercise your rights.

If you do not agree with any part of this Privacy Policy, please stop using the Product and related services.


1. Definitions

1.1 Personal Information
Information recorded electronically or otherwise that relates to an identified or identifiable natural person.

1.2 Sensitive Personal Information
Personal information that, once leaked or illegally used, may endanger personal and property safety, harm reputation, or lead to discriminatory treatment (e.g., government-issued ID numbers, financial accounts, precise location, communications content, and information of minors). Where required, we will provide separate notice and obtain your explicit consent before processing sensitive personal information.

1.3 Google User Data
Data you authorize us to access via Google APIs in connection with your Google account or Google services, as permitted by the OAuth scopes you grant.


2. Information We Collect

2.1 Information You Provide
- Registration and login information: phone number or email address; verification codes and necessary login records.
- Profile information (optional): avatar, nickname, bio, and other profile details you choose to provide.
- Identity verification (if you choose to use it): legal name, ID number and/or ID images (may be sensitive personal information).
- Customer support communications: support tickets, attachments (e.g., screenshots), contact details, and communication records.

2.2 Information Collected Automatically
- Device and log data: device model, operating system version, app version, IP address, network type, and necessary device identifiers (for security, fraud prevention, troubleshooting, and analytics).
- Usage data: feature usage, operation logs, crash logs, and session duration (to maintain and improve the Product and to diagnose issues).
- Cookies and similar technologies (for website scenarios): used to maintain login sessions, remember preferences, and perform basic analytics. You can manage or disable cookies in your browser settings; however, some features may not function properly.

2.3 Information From Third Parties (Including Google)
If you choose to sign in or link accounts via third-party services (e.g., WeChat, Google), we will receive certain information after you authorize such access, subject to the permissions you grant (e.g., third-party account identifiers, avatar, nickname, email address).


3. How We Use Your Information

We process personal information only to the extent that is lawful, fair, and necessary, including for the following purposes:
- Provide and maintain the services: account registration, login, account management, and core functionality.
- Security and compliance: identity verification, fraud prevention, risk control, auditing, and incident response.
- Customer support: respond to inquiries, handle complaints, and troubleshoot issues.
- Product improvement and analytics: analyze and improve performance and user experience, preferably using de-identified or aggregated data where feasible.
- Marketing communications (optional): only with your consent, we may send product updates and promotional information; you may unsubscribe at any time.


4. Google API Data Use (Important)

4.1 What Google Data We May Access
If you use Google-related features (e.g., Sign in with Google, linking your Google account, or other Google API features), we will access Google user data only after you explicitly authorize access via OAuth. The data we access depends on the OAuth scopes you grant, which may include:
- Basic identity information: openid, email, and profile (e.g., name, avatar) for login, account identification, and account linking.
- If you enable additional Google features (if applicable): limited Google service data needed to provide the feature you request (e.g., Google Drive or Gmail data), strictly as permitted by the scopes shown on the Google authorization screen.

4.2 Google API Services User Data Policy (Limited Use) Commitment
We comply with the Google API Services User Data Policy, including the Limited Use requirements. Specifically, with respect to Google user data obtained via Google APIs:
- We use such data only to provide or improve user-facing features that you explicitly request.
- We do not use Google user data for serving advertisements.
- We do not sell Google user data.
- We do not share, transfer, or disclose Google user data to third parties except:
  (a) as necessary to provide or improve the user-requested feature, with service providers acting on our behalf under strict contractual, confidentiality, and security obligations and on a limited-necessary basis; or
  (b) to comply with applicable laws, regulations, legal process, or governmental requests.
- We do not allow humans to read Google user data except:
  (a) with your explicit consent (e.g., for customer support troubleshooting you request);
  (b) for security purposes (e.g., investigating abuse or fraud) under strict access controls and audit;
  (c) where required by law.


5. Sharing, Transfers, and Disclosure

5.1 We Do Not Sell Personal Information
We do not sell your personal information, including Google user data obtained via Google APIs.

5.2 Service Providers (Processing on Our Behalf)
We may share limited personal information with third-party service providers that process data on our behalf and only under our instructions, for the purposes described in this Privacy Policy and subject to appropriate contractual and security safeguards. These service provider categories may include:
- Cloud infrastructure, hosting, and storage providers: to host the Product and store data securely (including backups).
- Network security and content delivery providers: to improve performance and protect against abuse (e.g., DDoS mitigation).
- Email/SMS delivery providers: to send verification codes, security alerts, and service notifications.
- Customer support platforms: to manage and respond to support requests.
- Analytics and crash reporting providers: to diagnose crashes and improve reliability (we minimize data shared and prefer de-identified data where feasible).
- Payment processors (if applicable): to process payments and prevent fraud.

5.3 Legal Disclosure
We may disclose information when required by applicable laws or in response to valid legal process, or to protect the rights, property, and safety of users, the public, or ourselves.

5.4 Business Transfers
If we are involved in a merger, acquisition, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will provide notice as required by law and require the recipient to continue to protect personal information consistent with this Privacy Policy or obtain renewed consent where required.


6. Storage and Security

6.1 Storage Location
In principle, we store personal information in the territory of the People's Republic of China. If cross-border transfer is necessary, we will comply with applicable requirements and obtain necessary consents.

6.2 Retention Period (Conservative)
We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by applicable law. We apply the following retention rules:
- Account information (e.g., phone number/email, profile): retained for as long as your account remains active. If you delete your account, we will delete or anonymize such data within 30 days, except where retention is required by law.
- Customer support records: retained for up to 24 months from the date the request is resolved, then deleted or anonymized, unless a longer period is required by law.
- Security logs and audit records (e.g., access logs, device and security events): retained for up to 180 days, then deleted or anonymized, unless a longer period is required for security, fraud prevention, dispute resolution, or legal compliance.
- Google user data obtained via Google APIs: retained only as needed to provide the user-requested features. Upon unlinking your Google account or revoking authorization, we will delete or irreversibly de-identify Google user data within 30 days (and within a reasonable period for backups to be overwritten), unless retention is required by law.

Where deletion is not technically feasible (e.g., in backups), we will store the information securely and isolate it from further processing until deletion is possible.

6.3 Security Measures
We implement reasonable and appropriate technical and organizational measures to protect personal information, including (as applicable) encrypted transmission (TLS/SSL), access controls, least-privilege permissions, logging and audit, security monitoring, regular updates and vulnerability remediation, staff confidentiality obligations and training, and incident response procedures.


7. Your Rights and Choices

Subject to applicable laws, you may have the right to access, correct, delete, or withdraw consent regarding your personal information, and to close your account. To protect your security, we may need to verify your identity before processing certain requests.

Google authorization: You may unlink your Google account within the Product (if available) or revoke access in your Google Account security settings. After revocation, related Google features may no longer be available.

We generally respond to verified requests within 15 business days, unless otherwise required by law.


8. Children's Privacy

The Product is not intended for children under 14 years old. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete or anonymize such information as required by law.


9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through appropriate means (e.g., prominent notice within the Product). Your continued use of the Product after the updated policy becomes effective indicates that you have read and understood the updated policy.


10. Contact Us

If you have any questions, comments, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Email: luoyong@qingzhoushan.com