Privacy policy for Quantum Cipher Manager
Quantum Cipher Manager by Quantum Cipher Manager
Privacy policy for Quantum Cipher Manager
用户数据收集与使用说明
最后更新日期: 2025年3月13日
本说明旨在清晰阐述量子密管平台/系统收集、使用和保护用户个人信息的相关措施。
一、我们收集的信息范围
- 账号信息
- 用户注册时提供的邮箱地址(用于身份识别和登录)
- 加密数据(通过本平台/系统使用安全的加密算法进行存储)
- 用户自主保存的网站信息
- 应用账号密码
- 文档笔记
- 其他用户信息
- 用户手机号(用于二次验证)
- 用户组织机构信息(用于用户自定义的权限控制)
二、数据收集目的与用途
- 核心功能实现
- 为用户提供安全的密码存储、自动填充及跨设备同步服务
- 安全防护
- 检测异常登录行为,防范未经授权的访问
- 服务优化
- 通过匿名化统计数据分析产品性能问题(不涉及具体用户内容)
三、数据存储与保护
- 加密标准
- PQC抗量子攻击加密算法(高级用户)
- SM2/SM3/SM4加密算法(普通用户)
- 使用量子密码机生成的真随机数生成会话密钥(全量加密数据)
- 零知识架构
- 加密密钥由专用量子密码设备管理控制,服务器无法解密存储内容
- 物理防护
- 数据存储在通过ISO 27001认证的安全数据中心
- 定期进行第三方安全审计与渗透测试
- 传输安全
- SPA 单包认证方案,增强系统边界防护能力,进一步保护数据传输安全
- HTTPS传输层加密(TLS 1.2+)
四、数据使用限制
- ❌ 永不向第三方出售、出租或分享用户密码数据
- ❌ 永不将用户数据用于广告推送或商业分析
- ❌ 永不要求用户提供真实姓名、地址等非必要信息(阅后即焚功能需要实名认证)
五、用户权利保障
- 数据控制权
- 可随时导出/删除全部数据
- 支持两步验证关闭/开启
- 知情权
- 重大政策变更前30天通过注册邮箱通知
- 申诉渠道
- 安全疑虑反馈:qcm.gz@chinatelecom.cn
六、政策更新
本说明将根据技术发展及法律要求进行修订,更新版本将在官网显著位置公示。
User Data Collection and Usage Statement
Last Updated: March 13, 2025
This statement aims to clearly explain the measures taken by Quantum Cipher Manger Platform/System to collect, use, and protect users' personal information.
I. Scope of Information We Collect
- Account Information
- Email address provided during user registration (for identity verification and login)
- Encrypted Data (stored securely using encryption algorithms through this platform/system)
- Website information saved by users
- Application account passwords
- Document notes
- Other User Information
- User phone number (for two-factor verification)
- User organization information (for user-defined permission control)
II. Purpose and Usage of Data Collection
- Core Function Implementation
- Providing users with secure password storage, auto-fill, and cross-device synchronization services
- Security Protection
- Detecting abnormal login behaviors to prevent unauthorized access
- Service Optimization
- Analyzing product performance issues through anonymized statistical data (without involving specific user content)
III. Data Storage and Protection
- Encryption Standards
- PQC anti-quantum attack encryption algorithms (for advanced users)
- SM2/SM3/SM4 encryption algorithms (for regular users)
- Using true random numbers generated by quantum cryptographic devices for session keys (full encryption of data)
- Zero-Knowledge Architecture
- Encryption keys are managed and controlled by dedicated quantum cryptographic devices; servers cannot decrypt stored content
- Physical Protection
- Data stored in ISO 27001-certified secure data centers
- Regular third-party security audits and penetration tests
- Transmission Security
- SPA (Single Packet Authorization) scheme to enhance system boundary protection and further secure data transmission
- HTTPS transport layer encryption (TLS 1.2+)
IV. Data Usage Restrictions
- ❌ Never sell, rent, or share user password data with third parties
- ❌ Never use user data for advertising or commercial analysis
- ❌ Never require users to provide real names, addresses, or other unnecessary information ( The "ephemeral message" feature requires real-name authentication. )
V. User Rights Protection
- Data Control Rights
- Users can export/delete all data at any time
- Supports enabling/disabling two-step verification
- Right to Know
- Notify users via registered email 30 days before major policy changes
- Appeal Channels
- Security concerns feedback: qcm.gz@chinatelecom.cn
VI. Policy Updates
This statement will be revised according to technological developments and legal requirements. Updated versions will be prominently displayed on the official website.