Privacy notice
Updated 8 October 2026
This notice covers the CardinalDL website and the account, licensing and support services run by Cardinal Labs. It also describes downloader activity recorded by the shared account service. Streaming services process data under their own privacy notices.
1. Who is responsible
Cardinal LabsLi, Wei, CEO
501 Yincheng Middle Rd
Lujiazui, Pudong
Shanghai, Shanghai 200120
China (CN)
For privacy questions or to exercise your rights, email [email protected] . You can also write to the address above or use account support if you already have access.
2. Data and purposes
| Data | Purpose | Legal basis where GDPR applies |
|---|---|---|
| Email, display name, account identifiers, legacy username and password hash. | Register and authenticate your shared CardinalDL account; manage access and recovery. | Contract or steps you request before a contract, Article 6(1)(b). |
| Chosen services, package, term, limits, quotes, licence assignments, transaction reference and status. | Prepare your requested offer, supply the licence and maintain order records. | Article 6(1)(b); legal recordkeeping obligations under Article 6(1)(c), where applicable. |
| Session identifiers, IP addresses, device fingerprint and name, user agent, client version, timestamps, service usage counts and download reference. | Secure sign-in, enforce purchased allowances, show devices and usage, detect abuse and diagnose failures. | Article 6(1)(b) for account and licence operation; Article 6(1)(f) for proportionate security and abuse prevention. |
| Chat participants, subject, status, quote, timestamps, public keys, safety codes, encrypted key backup and encrypted message bodies. | Provide the private sales or support conversation you request. | Article 6(1)(b); Article 6(1)(f) for secure communication and necessary complaint records. |
| Administrative actions, actors, affected records and relevant audit metadata. | Accountability, security, investigating errors and establishing or defending legal claims. | Article 6(1)(f); Article 6(1)(c) where a specific obligation applies. |
Our security interests are protecting accounts, preventing fraud and keeping the service reliable. Processing must be necessary and proportionate and take account of your rights. We do not use consent as a substitute for a contract or a statutory obligation.
Email and authentication information are necessary to provide an account. Relevant configuration details are necessary for a quote or licence. You can browse the public pages without registering. Optional display names and message content are supplied by you; avoid sensitive information that is unnecessary for your request.
If you enable the downloader's settings synchronisation, the account service stores the uploaded encrypted backup and associated size, checksum, device and version information. This is separate from website chat encryption. Your local files and settings are also subject to the security of your device and any storage services you choose.
3. What chat encryption protects
Chat message bodies are encrypted in the sender's browser and decrypted on participating devices. The server stores encrypted bodies and a private-key backup encrypted with your separate chat passphrase. The passphrase and unlocked private key are not submitted as ordinary chat data. The intended Cardinal Labs participant can read your messages after unlocking their key and may use necessary information to handle your request.
End-to-end encryption does not hide your account email, participants, conversation subject, package or quote details, message timing or other metadata from the service. It does not protect a compromised device, information you export or information a recipient discloses. Verify contact safety codes where appropriate. Losing both your chat passphrase and usable recovery material can make old messages inaccessible; resetting your account password does not recover that passphrase.
4. Who can receive data
Authorised Cardinal Labs staff access data needed for account administration, sales, support and security, subject to their role. The selected chat participant receives your message content. Infrastructure suppliers that host the website or account service may process the data necessary to operate those systems under appropriate contractual instructions. Any payment provider chosen in the confirmed offer handles payment information under its own applicable notice; the current package builder does not collect payment card details.
Data may be disclosed when legally required or necessary to establish, exercise or defend a legal claim, subject to applicable safeguards. We do not run advertising or analytics trackers on this website, and the website does not sell your personal information. Clicking an external link takes you to another provider's service and privacy rules.
5. Processing locations
Cardinal Labs operates from China. Account, licence and support data may be accessed there by authorised staff. The website and account service also use infrastructure suppliers as described above; where data is processed depends on the systems used to provide the service.
Where GDPR applies, disclosures to a separate recipient outside the EEA must satisfy the applicable international-transfer rules. The appropriate mechanism depends on the parties and data flow; a Chinese business address or end-to-end encryption alone is not a transfer safeguard. You may request information about the recipients and safeguards relevant to your data.
6. Retention
Account and active licence data are kept while needed to provide the account and agreed service. Quotes, support conversations, transaction and audit records may be retained for necessary complaint handling, accounting duties, fraud prevention or legal claims. Retention depends on the data's purpose, applicable recordkeeping periods, unresolved disputes and relevant limitation periods. Data that is no longer needed should be deleted or made anonymous.
Website access tokens expire after 120 seconds. Refresh credentials expire after 30 days unless rotated during continued use; rotation starts a new validity period. Expiry or revocation stops authentication and is not a promise that every associated server record is immediately deleted. Account closure and erasure requests are assessed against any continuing legal need to keep data. Device removal and session revocation are available in the account portal.
Browser data has separate lifetimes described in the cookies and storage notice . Signing out clears the browser's website session, but it does not automatically erase local encrypted recovery material or trusted contact codes.
7. Your rights
Where GDPR applies, you can request access, correction, erasure, restriction and, where applicable, a portable copy of your data. You may object to processing based on legitimate interests and withdraw any consent for future processing. These rights have legal conditions and exceptions. We may request proportionate identity verification to avoid disclosing information to the wrong person.
You can complain to a competent data protection authority, including the authority in the EU country where you live, work or consider an infringement occurred. The European Data Protection Board lists the EU authorities . Contacting us first is optional and does not restrict this right.
8. Security and changes
Account passwords are stored as password hashes. Session controls, permission checks and chat encryption protect different parts of the service; no system can guarantee absolute security. Use a unique password, protect recovery material, review your devices and revoke sessions you do not recognise. We do not make solely automated decisions with legal or similarly significant effects described by Article 22 GDPR; you can ask for review of an access restriction.
This notice will be updated when data flows change. Material new purposes and any processing requiring consent must be explained before they begin. The date above identifies this version.