1. Who we are
“CouldInject,” “we,” “the site” and “services” refer to the website, forums, Wiki, CISS, messages, Support, Store-related features, Snow, AI features and other related services we provide.
The operator and party responsible for processing site personal information is CouldInject Operations Team.
Our principal server location is California, United States. Server location does not establish the operator's place of incorporation.
Privacy questions and rights requests may be submitted through CouldInject Support, our Contact page or [email protected], without creating an account.
If applicable law requires a data protection officer, EU, UK, mainland China or other local representative, we will provide the corresponding valid contact details as required.
2. Services covered
This policy applies to services we provide that link to it, including accounts and invitations, forums, Wiki, CISS, private messages, notifications, Support cases, user uploads, Store and related entry points, Snow, AI assistance, security and anti-abuse systems, and other services connected to a CouldInject account.
Snow is not yet launched. References to Snow and future AI features apply when the feature is actually made available, not as a statement that it is currently operating.
Independent third-party websites, applications, payment platforms and services have their own privacy policies. Unless expressly stated otherwise, a linked third party is responsible for its independent processing. This does not remove our responsibility for processing performed on our behalf.
3. Global privacy principles
Wherever users are located, we design processing around the following principles:
- Lawfulness, transparency and fairness: no deceptive, hidden or materially unexpected processing.
- Purpose limitation: use for disclosed, specific purposes or reasonably compatible uses.
- Data minimization: collect only information reasonably needed for the function.
- Retention minimization: do not retain information indefinitely merely because it might be useful later.
- Accuracy: keep information reasonably accurate and enable corrections.
- Security: use reasonable technical and organizational measures appropriate to the information, scale and risks.
- User control: enable access, correction, deletion and copies where reasonable and legally permitted.
- Privacy-protective defaults: prefer settings with a lower privacy impact where functions can still be provided.
4. Information we collect
Categories depend on the functions you actually use.
4.1 Account and identity information
This may include your username, user ID, invitation code and associations, email address, avatar, profile, language and region settings, account status, permission groups and preferences. Account passwords are not stored in plaintext; appropriate one-way password hashing is used.
4.2 User-generated content
Posts, replies, Wiki content and edit history, comments, uploads, CISS contributions, public profiles and other material you submit may be processed. Some is public or visible to other community members.
4.3 Private communications and support
This includes private messages, cases, contact submissions, appeals, privacy requests, security reports, and communications with administrators or maintainers. Private communications and public content follow different access and handling rules.
4.4 Device, network and log information
For operation, protection and maintenance, we may record IP addresses, approximate country or region, browser, operating system and device type, request times, page access, sign-ins, sessions, errors, API calls, security incidents, unusual requests and account actions.
We ordinarily do not need precise GPS location. IP addresses may indicate an approximate country, region or city, with limited accuracy.
4.5 Security and anti-abuse information
We may generate or retain information about sign-in risk, unusual activity, spam, automated access, account or invitation abuse, fraud risk, malicious requests, content safety, bans and restrictions. This can include risk flags generated by rules, algorithms or security systems.
4.6 Store and transactions
When an actual transaction, authorization or paid feature is used, we may process order IDs, product or service details, transaction times and statuses, authorization and refund statuses, and related support records.
Where an independent payment provider processes payment, it ordinarily handles full card or payment credentials directly and we receive limited information needed for the transaction. In this version, Store is a service entry point. Transaction provisions apply only when the relevant business is actually opened and a transaction occurs. Before enabling payments, the interface will identify the actual payment provider and information flow.
4.7 AI and Snow information
If you actively use Snow or another AI feature when available, processing may include your prompts, conversation text, uploaded material, generated answers, technical request logs, safety and abuse information, and necessary context.
Do not provide unnecessary passwords, identity documents, payment credentials, private keys, medical records or other highly sensitive information to AI functions.
4.8 Sensitive information not actively requested
We ordinarily do not need government identifiers, passports or identity documents, bank passwords, full card credentials, precise location, medical or health information, biometrics, racial or ethnic information, religious or philosophical beliefs, political views, or information about sex life or sexual orientation.
If you voluntarily include such information in posts, messages, Wiki, cases or AI conversations, we may encounter it when handling your submission. Supply only the minimum needed. Questionnaire and self-test answers may also contain sensitive material you choose to provide; do not submit irrelevant sensitive information.
5. Sources
Information can come directly from you when registering, posting, editing profiles, creating cases, messaging or using AI; automatically through logs, cookies, sessions and errors; from other users through replies, reports, invitations, collaboration or support matters; from lawfully usable public sources for CISS, Wiki or research; and from vendors returning information needed to perform a service.
6. Processing purposes
6.1 Providing services
Account creation and management, sign-in verification, invitations, forums, Wiki, CISS, message delivery, preferences, and Store, Snow or AI features when actually provided.
6.2 Security and abuse prevention
Preventing account takeover, unusual sign-ins, spam, attacks and automated abuse; investigating community-rule violations; and protecting users and infrastructure.
6.3 Community management
Moderation, Wiki maintenance, reports, appeals, violation investigations and CISS maintenance.
6.4 User support
Responding to cases, technical and account problems, privacy requests and security incidents.
6.5 Maintenance and improvement
Troubleshooting, performance monitoring, error analysis, service statistics, improvements and security research. Where analysis is not strictly necessary for operation, legally required consent or opt-out mechanisms will be provided.
6.6 Legal and rights protection
Complying with applicable law, responding to valid governmental or judicial demands, disputes, establishing or defending rights, investigating fraud or security incidents, and protecting legitimate interests of CouldInject, users and others.
7. Legal bases in different regions
Legal concepts and permitted bases differ by jurisdiction; not every activity relies on the same basis everywhere. Where a specific legal basis is required, we select one appropriate to the processing.
For the EEA and similar frameworks, bases can include contract performance or requested pre-contract steps, legitimate interests, legal obligations, consent, vital interests or another basis permitted by law.
Basic sign-in and site functions ordinarily involve processing necessary to provide the service. Security logging, spam prevention and anti-abuse processing ordinarily pursue legitimate interests in service and user safety, with balancing where required. Optional tracking, some marketing and other consent-based processing require consent where applicable. Withdrawal does not affect previously lawful processing.
8. AI, Snow and automated systems
8.1 AI functions
Snow or other systems may assist with organizing information, content, search, replies, translation, analysis or other tasks. AI output can be inaccurate, incomplete or unsuitable; assess it in context.
Snow is not yet launched. This website version does not currently enable third-party model interfaces to process user personal information.
8.2 AI providers
Some future features may use third-party models, APIs, computing or infrastructure. We provide only information reasonably needed for the request and apply appropriate contractual, technical or other controls.
Before launch, we will disclose actual providers, processing locations, retention, human review, training purposes and choices. Planned processing is not described as processing that has already occurred.
8.3 Model training
Without clear separate disclosure and legally required valid authorization, private messages, private cases and non-public AI conversations will not be used to train general-purpose generative models for an unspecified audience, and entrusted providers are not authorized to use them for their own general-purpose training.
We retain our existing commitment not to use users' personal information for general-purpose training, fine-tuning or unrelated evaluation, or authorize entrusted providers to do so. A separate voluntary model-improvement program requires advance explanation and necessary authorization; declining does not affect unrelated basic services.
Appropriately anonymized or aggregated information that can no longer reasonably be linked to a person may be used for performance and security analysis.
8.4 Human review
Authorized staff may access limited AI interactions or related records for user-requested support, security or abuse investigations, reports, serious troubleshooting or legal duties. Access is limited to personnel with a work-related need and corresponding confidentiality and permission controls.
8.5 Significant automated decisions
We do not plan to use Snow or ordinary AI features to determine employment, credit, housing, insurance, medical treatment, educational admission or similar eligibility with significant legal or practical consequences.
Automated tools may detect spam, attacks, unusual sign-ins or other security risks. Permanent bans or other major account actions can generally be appealed through Support, with human review where reasonably feasible. Additional notice, access, opt-out, appeal or intervention rights required by applicable law will be provided.
8.6 Generated-content identification
Where law requires identifying the source or generated nature of images, audio, video or other AI content, we provide applicable labels, metadata or other transparency measures under the law and actual technical capabilities.
9. Snow availability by region
Third-party coverage, connectivity, infrastructure, provider policies, export or sanctions restrictions, local law and other factors can limit availability.
Snow or some related features may, when launched, be unavailable in mainland China or experience connection failure, reduced functionality, delay or temporary unavailability. Snow has not yet launched; this is a conditional future availability statement, not a claim of current operation anywhere.
Such limitations do not mean a user violated rules, has an abnormal account or is being punished, and do not remove privacy rights. Availability may change with technology, providers and law.
10. Cookies, local storage and similar technology
10.1 Necessary cookies
These may support sign-in, account security, CSRF protection, sessions, language and necessary settings. Blocking them can prevent normal use.
10.2 Functional cookies
These can retain language, interface settings and preferences.
10.3 Analytics
If non-essential statistics or analytics are enabled, we provide legally required explanations and consent or opt-out mechanisms.
10.4 Advertising and cross-site tracking
This version does not configure Google Analytics, Meta Pixel or cross-site advertising scripts. Cloudflare supports CDN, network security and associated traffic statistics. Some pages load Google Fonts, cdnjs and jsDelivr resources, disclosing IP, browser and necessary request information to those providers. External links and user embeds may use third-party technologies; we do not guarantee that those parties never correlate information across sites.
Before enabling cross-context advertising, targeted advertising, or legally defined sale or sharing, we update disclosures and provide applicable opt-outs.
11. Do Not Track and Global Privacy Control
Traditional browser DNT lacks a uniform industry implementation standard. Unless law requires otherwise, receipt does not automatically change all processing or necessary functional and security processing.
GPC and other legally recognized universal preference signals are different. Where required, valid signals are treated as applicable sale, sharing or targeted-advertising opt-outs. Where we conduct none of those activities, the signal may not change additional processing. Opt-outs that legally require no verification are not conditioned on an account or identity check.
12. No sale of personal information
Our business is not based on selling personal information. We do not sell it or share it for cross-context behavioral advertising. The Operations Team confirms no such sale or sharing in the preceding 12 months. Sale is not limited to money changing hands.
If future disclosure qualifies as sale, sharing or a similar activity even without payment, applicable disclosures and opt-outs will be provided before it begins. We do not impose legally prohibited discrimination, punitive fees or degraded basic service for exercising privacy rights.
13. Third-party disclosures
We do not disclose user data merely because another party wants it.
13.1 Service providers and processors
Providers can include hosting, databases, CDN, DDoS protection, backups, email, error monitoring, security, payments, Support infrastructure and AI providers when enabled. Their processing should be limited to necessary service purposes and applicable contractual controls.
For Support email, public case context is included in messages to the verified contact address; internal notes are excluded. Raw inbound email may retain attachments even when they are not displayed in the case interface.
13.2 Users and the public
Information you post in public forums, Wiki or profiles can be visible to other users or the public. Do not publish information you wish to keep private.
13.3 Legal requirements
Disclosure of private data to governments, law enforcement, courts or other public bodies is subject to the more specific limits in section 32. This section does not create additional permission for voluntary disclosure.
Information may be lawfully disclosed for valid legal obligations, court orders, subpoenas or other binding demands. Where permitted, we assess authority and scope and seek to limit disclosure.
13.4 Safety and rights
Necessary information may be disclosed to investigate attacks, prevent fraud or serious abuse, protect safety, or establish or defend rights.
13.5 Reorganization
Information may transfer in a merger, acquisition, reorganization, asset sale or similar transaction, subject to applicable protections and necessary notice.
14. Storage and international transfers
The principal server and core database are in California, United States. Core hosting uses BandwagonHost. Cloudflare provides global network, security and inbound email routing. Support outbound mail uses Alibaba Cloud Direct Mail in China East 1 (Hangzhou). Recipient addresses, message content and necessary delivery information are processed by Alibaba Cloud in that region; replies are routed through a separate reply subdomain and Cloudflare's private storage and processing queue back to the US server. Privacy requests to Gmail use Google's email infrastructure. Maintenance copies and vendors' global networks are not guaranteed to process only in the US. Server location is not the operator's place of incorporation.
Using the service outside the US can transfer personal information to the US. Other mandatory privacy laws do not cease to apply because of this location.
Where applicable, safeguards can include adequacy decisions, standard contractual clauses, transfer agreements, data protection addenda, impact assessments, technical and organizational measures, recognized certifications, separately required consent or another lawful mechanism.
EEA and UK transfers use mechanisms recognized under their applicable rules. For mainland China, applicable notice, separate consent, impact assessment, standard contract, certification, security assessment or other requirements are determined by the actual activity. Other regions' mandatory transfer rules also apply.
15. Retention
Information is not kept indefinitely merely because it may be useful later. Criteria include category, original purpose, account status, security, necessary community context, backup maintenance, fraud risk, disputes and legal duties.
Account profiles are ordinarily kept while the account exists; after closure, only as needed to complete deletion or necessary security, fraud prevention, disputes or legal duties. Security logs are retained for reasonable monitoring, investigation and audit periods. Cases are kept for support, disputes, security investigations and reasonable audit needs. Private messages follow the function, user actions and applicable deletion duties.
For public posts and Wiki collaboration, we may retain content or edit history, remove direct account identifiers, anonymize or pseudonymize authors, where lawful and reasonably necessary for context, integrity or abuse prevention. Legally required deletion is still honored.
Deleted online information may remain temporarily in restricted backups, which are cleaned through necessary maintenance rather than used for indefinite retention. We do not restore data to evade deletion, and confirmed deletion requests are reapplied after necessary recovery.
Retention is determined by these purpose and necessity criteria; we do not promise fixed periods that have not actually been implemented. Migration and incident-recovery copies have the same access and cleanup requirements.
16. Account deletion and public content
You can request account closure and deletion required by applicable law. Wiki history, discussion context, abuse or security records, dispute evidence, legally required records and lawfully anonymized information may require separate assessment.
Where a direct identity association is unnecessary, we prefer removing account identifiers, de-identifying, pseudonymizing or disassociating public material from the account. Community history alone is not a reason to refuse a deletion required by law. Pseudonymized information is not automatically anonymous.
17. Security measures
Reasonable measures can include password hashing, HTTPS/TLS, least-privilege access, authentication, separation of administrative permissions, logging, anti-abuse and network security controls, database access controls, backups, recovery, incident response and vendor security review.
No internet system guarantees absolute security. Unauthorized access, loss or disclosure cannot be ruled out entirely. Report vulnerabilities, unusual sign-ins or suspected breaches through Support.
18. Security incidents
We investigate, contain risks, identify affected information and users, retain necessary incident records, take reasonable remedial steps, and provide notices to users, regulators or other parties where required.
Triggers and deadlines differ across jurisdictions. We follow the law applicable to the incident and affected users, not a single country's rules for all events.
19. Baseline rights worldwide
Where reasonable and technically feasible, and without limiting mandatory law, we aim to provide:
- Access and confirmation of processing.
- Copies of personal information held about you.
- Correction of incomplete or inaccurate information.
- Deletion where information is unnecessary or must legally be deleted.
- Withdrawal of consent for consent-based activities.
- Portability in a common, structured, machine-readable format where legally required or reasonably supported.
- Objection or opt-out for covered processing.
- Restriction where applicable.
- Information, opt-out or human review regarding covered automated processing.
- Complaints to CouldInject and competent authorities as permitted by law.
Rights are not absolute. Lawful limits may protect identity verification, required retention, security investigations, fraud prevention, others' rights or legal claims. Refusal of a statutory request will include reasons and further review options where required.
20. Submitting requests
Use available account privacy features, Support, our Contact page or [email protected]. A new account is not required.
We may seek proportionate verification to prevent impersonation in data access or deletion, but not manifestly excessive information or plaintext passwords. Authorized agents may need to establish authority and identity where permitted; requests legally exempt from verification remain exempt.
Ordinary requests are free. Clearly repetitive, excessive or abusive requests may be charged for or refused only where law permits.
21. Response periods
We follow deadlines applicable to the requester. Our baseline retains an initial Support response within 24 hours and aims for a substantive answer or progress explanation within 30 days.
For CCPA access, knowledge, correction and deletion requests, receipt is acknowledged within 10 business days and a substantive response ordinarily follows within 45 calendar days. A necessary extension is explained within the original period and lasts no more than another 45 days. Identity verification does not restart the clock. Applicable sale/sharing opt-outs and sensitive-use limitations are implemented promptly, within no more than 15 business days, without identity verification where the law does not permit requiring it.
GDPR or similar requests are handled within their legal periods with notice of a lawful extension. A shorter mandatory local period controls.
22. US and California supplement
Applicability depends on residence, business scale, processing volume, revenue, statutory thresholds and other conditions. This section does not assert that every state law always applies.
22.1 California rights
Where CCPA/CPRA applies, rights may include knowledge, access to specific information, deletion, correction, opt-out of sale and sharing, limitation of certain sensitive uses or disclosures, applicable automated-decision rights and freedom from prohibited discrimination.
22.2 CCPA categories
Depending on actual functions, categories processed in the preceding 12 months can include identifiers, some customer records, commercial information where transactions occurred, internet/network activity, approximate location, user content, limited inferences and sensitive information such as credentials. Listing a legal category does not mean every item within it is collected.
22.3 Sensitive information
We do not use sensitive information to infer characteristics or beyond service, safety and legally permitted purposes without required notice and controls. If an activity triggers limitation rights, an appropriate mechanism will be provided.
22.4 Sale and sharing
We do not sell personal information or share it for cross-context advertising, including in the preceding 12 months as confirmed by the Operations Team. Any future legally defined sale or sharing requires applicable prior notice and opt-outs.
22.5 Agents
Authorized agents may submit requests where law permits; authority and identity may be checked only as legally appropriate.
22.6 GPC
Valid GPC signals are honored as sale/sharing opt-outs where required by the CCPA.
22.7 Financial incentives
We do not currently generally pay users in exchange for providing, selling or permitting sharing of personal information. A future covered data-related incentive program would have separate legally required notice and choices.
22.8 Other states
Colorado, Connecticut, Virginia, Oregon, Texas, Montana, Delaware, New Jersey, Nebraska, New Hampshire, Minnesota, Maryland and other states with comprehensive consumer privacy laws may provide access, correction, deletion, portability, opt-outs of sale, targeted advertising or certain profiling, withdrawal of consent and appeals, depending on their laws. We honor them where applicable to CouldInject.
23. EEA users
If GDPR applies, rights may include information, access, correction, erasure, restriction, portability, objection, consent withdrawal, rights concerning certain automated decisions and complaints to a competent supervisory authority.
For legitimate-interest processing, we balance our interests, reasonable expectations, the information, potential impact and safeguards where required. Transfers from the EEA to the US or another third country use a valid applicable mechanism.
If Article 27 requires an EU representative, valid contact details will be provided when that obligation applies. In the meantime, privacy requests can be sent to [email protected].
24. UK users
Where UK GDPR, the Data Protection Act 2018 and the UK framework as amended apply, corresponding access, correction, deletion, restriction, objection, portability, automated-processing and complaint rights apply. International transfers use a lawful mechanism under applicable UK rules.
If a UK representative is required, valid details will be provided when the obligation applies. Privacy requests can meanwhile be sent to [email protected].
25. Mainland China users
Where processing outside China of personal information of individuals in mainland China falls within the Personal Information Protection Law or other applicable law, we comply with applicable requirements.
These may include notice of purposes and methods, minimization, access/correction/deletion rights, additional sensitive-information protection, separate consent where required, impact assessments and legally prescribed cross-border measures.
Because principal servers are in the US, relevant processing can transfer information there. Where required, we disclose the overseas recipient, purposes, methods, categories and ways to exercise rights and fulfill applicable outbound requirements. Requirements vary with the information, scale and actual business.
If Article 53 or another rule requires a mainland establishment or representative, we will provide the relevant valid contact details when the obligation applies. Privacy requests can meanwhile be sent to [email protected].
Snow is not yet launched; future AI availability in mainland China may be limited. Unavailability does not remove statutory privacy rights.
26. Brazil users
Where LGPD applies, rights can include confirmation, access, correction, anonymization, blocking or deletion of covered data, portability, deletion of consent-based data, information about sharing and consequences of consent, withdrawal and legally available review of automated decisions.
International transfers use mechanisms recognized by applicable law and Brazil's data protection authority.
27. Australia users
Where the Privacy Act and Australian Privacy Principles apply, we process information accordingly. Australian users' information may be disclosed or transferred to US providers because principal infrastructure is there. We take reasonable steps required by applicable law to ensure overseas recipients protect the information.
28. Canada and other regions
Canadian, Japanese, Korean, Singaporean, New Zealand and other laws may apply to relevant activities. Our global baseline does not reduce mandatory local protection. Additional local rights remain effective.
29. Minors
We do not offer registration to children under 13 and require confirmation of age 13 or older. The services are not specifically designed for children under 13.
We do not knowingly collect their information contrary to applicable children's privacy law. Higher digital-consent ages, guardian-consent rules and other applicable protections are honored where required. If information was collected unlawfully, we take reasonable steps to delete or otherwise lawfully handle it. Parents or guardians may contact us. Legally applicable removal rights for minors' public content are provided.
30. Public content and privacy expectations
Forums, Wiki, CISS and public profiles may be viewed or saved by users, search engines, other websites, archives or caches. Consider whether information is suitable for continued public availability before posting. Deletion from CouldInject does not directly control independent screenshots, search caches or archives.
31. Anonymized and aggregate data
Where reasonable, information may be anonymized or aggregated for statistics, performance, security, planning and understanding community use. Information truly no longer reasonably linkable to a person may fall outside personal-information rules where law permits. We do not intentionally re-identify it to evade privacy rights.
32. Privacy is a fundamental human right; government, law-enforcement and judicial requests
CouldInject believes that privacy is a fundamental human right, not a commodity to be traded at will.
We believe users' data belongs to users. We retain or process it to provide services, not to build dossiers about users or assist surveillance unrelated to providing those services.
Except at a user's express request, direction or legally valid authorization, CouldInject does not proactively or voluntarily provide users' private data to governments, law enforcement, courts or other public bodies.
A request from a government body, officer or other institution is not by itself a reason to hand over information. Informal requests, emails, calls, oral demands, investigations lacking an appropriate legal basis and other demands lacking sufficient legal effect are not sufficient grounds for disclosure.
32.1 Default refusal
Our default position is: unless the user expressly requests disclosure or applicable law compels it, we refuse to provide users' private data.
Where the law leaves us a choice whether to disclose voluntarily, our general choice is not to disclose. Legal permission does not automatically mean we will disclose.
32.2 Compulsory legal requirements
In limited circumstances, we may receive a binding warrant, court order, subpoena or other compulsory legal process. We comply with obligations that actually bind us.
Before disclosure, where reasonably practicable we assess the legal basis, issuing authority, jurisdiction, subject, scope and procedural validity. “The government asked” is not equivalent to “the government is legally entitled to the data.”
32.3 Refusing or challenging inappropriate requests
Where legally permitted and reasonably grounded, we may refuse, seek clarification or narrowing, or raise an objection or challenge through appropriate legal procedures.
This includes requests manifestly lacking a legal basis or jurisdiction; invalid or materially defective process; clearly excessive scope; data lacking a reasonable connection to the investigation or exceeding legal authority; and material conflicts with data protection law applicable to affected users.
Where less data satisfies a valid requirement, we do not expand disclosure merely because a broader request was received.
32.4 Minimum disclosure
Even when legally compelled, we apply minimum disclosure: only data that must be provided and falls within the lawful scope.
Compelled disclosure of some data is not a reason to volunteer unrelated account content, private messages, AI conversations, access logs, IP addresses, emails, associated accounts, history, device details or other information.
A request for basic account information does not cause us to volunteer communications. A specified time window is not expanded to all history. A request concerning one account does not cause us to volunteer other users' data.
32.5 Preservation is not disclosure
An authority may lawfully require temporary preservation of specific existing records pending further lawful process. Unless the law provides otherwise, preserving data does not mean it has been disclosed to the requesting authority.
We do not volunteer the contents solely because a preservation request was received. A later disclosure obligation is reassessed only upon valid binding process applicable to the relevant data.
32.6 No proactive expansion of surveillance
We do not proactively collect otherwise unnecessary data to make potential future government investigations easier.
We do not expand logging, prolong unnecessary retention, build activity dossiers, add unnecessary identifiers or link activity across services merely to facilitate future requests.
Data minimization and retention policies do not change merely because governments might later want the information, except where applicable law expressly requires preservation.
32.7 User notice
Where law allows, our general approach is to notify affected users before disclosure, giving them an opportunity to understand the request and seek available remedies.
We comply with temporary notification prohibitions imposed by binding orders or law. If a prohibition expires and notice becomes lawful, we generally consider reasonable notice to affected users. A temporary prohibition is not treated as a permanent abandonment of transparency.
32.8 Foreign government requests
A direct request by a foreign government, foreign law-enforcement agency or another overseas public body does not automatically entitle it to user data.
We assess authority applicable to CouldInject and any valid international process, US legal process, judicial-assistance mechanism or other binding legal basis. Where a request cannot lawfully compel us, we generally do not voluntarily provide private data.
32.9 User-directed disclosure
Users may lawfully request their own data or expressly authorize disclosure to a designated third party. Proportionate identity verification may establish that the request is genuine and prevent impersonation.
A user's lawful choice about their data is fundamentally different from a government or third party seeking it without their authorization.
32.10 Mandatory reporting
Some laws require providers to report specified content, events or circumstances to designated bodies or take other mandatory measures. Where the law expressly requires CouldInject to do so, we comply.
Even then, we apply minimization and limit information as far as possible to what the law actually requires.
32.11 Data we do not hold
We do not promise to possess data that does not exist in our records. Governments, law enforcement, courts and other third parties cannot obtain from us data we have not actually retained.
Avoiding unnecessary collection and promptly deleting information no longer needed are important privacy protections. We do not artificially retain data that should otherwise be deleted to prepare for hypothetical future requests, except where law expressly requires preservation.
32.12 Transparency
Where lawful, technically feasible and consistent with user privacy, we may publish aggregate transparency information, such as requests received, refused or challenged, and requests resulting in compulsory disclosure.
We do not disclose information identifying affected users for the sake of a transparency report.
32.13 Our principles
Users' data belongs to users.
Privacy is a fundamental human right.
Data that need not be collected should not be collected for hypothetical future investigations.
Data that can be deleted should not be retained indefinitely for hypothetical future requests.
We refuse requests without a valid legal basis.
Where legally permitted, we seek to narrow or challenge overbroad requests.
When disclosure is legally compulsory, we disclose only the minimum legally required data.
Where user notice is lawful, our general choice is transparency rather than secret disclosure.
The fact that a government, law-enforcement or judicial body makes a request does not itself change our commitment to user privacy.
33. Rights despite regional unavailability
A feature being unavailable in a country or region does not remove applicable access, correction, deletion, export, withdrawal or complaint rights. Service availability and privacy rights are separate matters.
34. Third-party links
Forums, Wiki, Store or user material can link to third-party sites. We cannot control their cookies, collection, policies, content or security; review their policies. This does not eliminate our responsibility for disclosures or entrusted processing we arrange.
35. Updates
Features, AI, vendors, processing, laws, security or transfer arrangements may require updates. We change the displayed revision date and give appropriate additional notice of material changes affecting rights or expanding purposes.
Where renewed consent is required, silently updating this page is not a substitute. We do not retroactively revise the policy to secretly use existing private information for purposes materially inconsistent with prior commitments. The policy is reviewed at least every 12 months.
36. Languages
Chinese and English versions should remain substantively consistent. Ambiguity is considered with actual processing, applicable mandatory law and more specific regional notices. Translation differences do not remove statutory rights.
37. Complaints and regulators
We encourage privacy concerns through Support or the privacy contact and investigate and respond to reasonable complaints. You may also complain to competent privacy, data protection or consumer protection authorities where applicable, without first exhausting our process. We do not retaliate or discriminate unlawfully for good-faith complaints.
38. Contact
For this policy, processing, AI uses, security or rights, use CouldInject Support, the Contact page or [email protected].
Operator: CouldInject Operations Team
Principal server location: California, United States
© 2016–2026 CouldInject. All rights reserved.