1. Scope and controller
This policy applies to Tenelk Account, the Tenelk iOS and Android security companion app, and products connected through the shared Tenelk account. The data controller is Zhengzhou Xunbei Software Technology Co., Ltd.
For privacy questions, data requests, or complaints, contact xunbei@xunbei.art.
2. Data we process
- Account and identity data, including email, username, display name, avatar, language, time zone, and the stable account identifier issued by our identity engine.
- Security and authorization data, including sessions, connected apps, granted scopes, QR approval records, security audits, and necessary request metadata.
- Message data, including official and program message history, state, source name, title, body, tags, priority, and action link, plus encrypted APNs or FCM device tokens, platform, language, and time zone. Lock-screen pushes do not contain account-specific message bodies.
- Program-ingest data, including source and SendKey labels, an irreversible HMAC digest, key version, use timestamps, and revocation state. The complete SendKey is shown only once after creation or rotation; we store no recoverable plaintext.
- Support and rights requests, including ticket content, account exports, deletion requests, and processing state.
3. Why we use data
- Create and maintain the shared account and provide sign-in, recovery, and cross-product authorization.
- Let you approve QR sign-ins on your phone and prevent unauthorized access.
- Receive alerts sent by your own servers, scripts, and devices through SendKeys, deliver official notifications, synchronize message state, and retire invalid device tokens.
- Handle support, export, and deletion requests while maintaining security and audit records.
4. Providers, location, and sharing
We do not sell personal data, use account data for third-party advertising, or provide a public people-search or social graph.
Core account services currently run on restricted infrastructure in Vienna, Austria. Apple APNs and Google Firebase Cloud Messaging act only as system-push transports. Connected Tenelk products receive only the account data and scopes you authorize. Cross-border transfers may occur because of your location, our infrastructure location, and the push platform.
5. Retention and security
We retain data only for as long as needed to provide account, security, notification, and support functions. After deletion is completed, related account data is deleted or de-identified except for limited records needed for security, fraud prevention, disputes, or legal obligations. Backup copies leave service through controlled rotation.
We use transport encryption, restricted networks, least-privilege service accounts, encryption of device tokens at rest, versioned HMAC digests for SendKeys, audit records, and access controls. No system can guarantee absolute security.
6. Your choices and rights
- Review and correct profile data and manage connected apps, security sessions, program sources, and SendKeys.
- Export account data, revoke push endpoints, or request account deletion.
- Ask for access, correction, restriction, or objection through support, subject to rights available in your region.
7. Changes and contact
We will describe material changes on this page or through an official notice and update the effective date. Contact: xunbei@xunbei.art.