Issued: August 5, 2026 | Last revised: August 6, 2026 | Effective: August 6, 2026
1. Our Core Commitment
NALING treats "your data belongs only to you" as a non-negotiable bottom line. Every clause below exists to protect it: your email address, your AI chat history and your comments are encrypted and strictly isolated. Apart from your own signed-in session and the operations strictly required for the service to run, nobody can read them, and we never disclose them to any other user or third party.
On "can my email address leak?" — this has been closed off technically: our public comment APIs no longer return any email information (not even a masked form), and email addresses are stored encrypted in the database. Details below.
2. Email Addresses: Encrypted at Rest, Never Disclosed
This is the question our users care about most, so here is a clear, verifiable answer:
Encrypted storageWhen written to the database, your email address is first encrypted with AES-256-GCM (field emailEnc). A SHA-256 hash (field emailHash) is computed only for matching lookups. New registrations and all subsequent data no longer store email addresses in plaintext.
Never disclosedAll interfaces visible to other users (comments, public profiles, etc.) return no email information at all — neither the full address nor a masked form such as "first two characters + domain". Others only see the display name you choose.
Isolated accessEvery read, update or delete operation verifies both the caller's identity and data ownership (emailHash === current signed-in account); any mismatch is rejected with 403. Administrators cannot read your plaintext email either.
Key isolationThe key used to decrypt email addresses (ENC_KEY) exists only in the server runtime environment. It is never shipped to the browser, never present in public source and never sent to clients.
In short: through the APIs others can only obtain your display name; in the database your address is ciphertext; even with direct database access the address cannot be recovered without the server-side key.
3. AI Chat History: Encrypted and Isolated per Account
Content encryption: every message exchanged with NALING is encrypted with AES-256-GCM (field contentEnc) before it is stored. The key lives only on the server.
Bound to your account: every conversation and message is bound to the account you signed in with. At the database layer the system only returns data belonging to the current signed-in account.
Unauthorised access is blocked: before any chat is read, sent or deleted, the backend verifies conversation owner === current account, otherwise it returns 403. Nobody can enter or read another user's conversation.
Not even administrators: administrator privileges are limited to deleting public comments (see section 7) and never extend to decrypting or reading anyone's private chats. The encryption applies equally to everyone, administrators included.
4. Other Encryption and Security Principles
Randomly signed identity tokens (JWT): the token you receive after signing in is signed with a random secret (JWT_SECRET) held only in the server environment, exactly like the encryption keys. Third parties cannot forge another user's identity to reach your data.
Secrets never enter source code or the front end: all keys (ENC_KEY, JWT_SECRET, every API key) are configured as server environment variables. No usable key exists in our public repositories or front-end bundle.
Sign-in code protection: sign-in uses "email address + one-time code". Codes expire, are single-use, and are rate-limited per IP to prevent brute-force attempts.
Minimal third parties: only services strictly required to operate are used, all listed here:
Tencent CloudBase: database storage and cloud function runtime hosting your account, chat and comment data.
Large language model services (e.g. DeepSeek): receive the message you send in order to generate a reply; used only at the moment of the conversation and not retained for other purposes.
Email service: used solely to deliver your sign-in verification code; no plaintext address is provided to it for marketing purposes.
Content moderation services (third-party or built-in): review public content you publish (comments, display names) for compliance, including text and image checks for political, adult, violent, advertising or abusive material. Moderation applies only to public content you actively post and never touches your private AI chats. Content judged non-compliant is blocked or forwarded to an administrator.
We do not provide any third party with a plaintext, personally identifiable email address for marketing, and we do not share your private chat history with them.
Comments are public by nature: what you post in the comment area is public content shown to all visitors under your display name; comment bodies are therefore not separately encrypted — an inherent property of a public community, unlike private chats.
5. What We Collect
Account identifier (email address): for sign-in; stored encrypted (see section 2).
Display name and avatar: optional, shown in the comment area.
AI chat content: your conversations with NALING; stored encrypted (see section 3).
Public comments: posts you publish in the comment area and your "like" relations.
Basic technical logs: sign-in IP, time and device type, used only for rate limiting and security; never for profiling.
We do not collect real names, identity card numbers, bank card details, address books or precise location data, and we do not read other files on your device outside of the chat.
6. How Information Is Used
To provide the AI conversation feature and, once you are signed in, to show you your own chat history and comments.
To send you a sign-in verification code (that purpose only).
To display you under your display name in the comment area and to maintain "like" interactions.
To enforce rate limits and security protections and keep the community orderly.
We do not use your chat content, email address or comments for advertising, and we do not sell or exchange your personal information with advertisers.
We will not use email addresses collected to send users marketing or promotional email that is not triggered by the user.
7. Data Retention and Your Controls
Delete your account: from the "Profile" page you may delete your account at any time; comments, likes and profile data under that address are removed and cannot be restored.
Delete a single comment: you may delete any comment you posted.
Administrator deletion: only specific administrator accounts may delete other users' public comments in order to remove non-compliant content; that privilege does not extend to reading chats or email addresses.
8. Violations and Enforcement Levels
To keep the community orderly and to comply with applicable laws and regulations, violations are handled in graduated levels. The severity of each level is published so that anyone can anticipate the consequence:
Level 1 (minor): light advertising, meaningless flooding, mildly unfriendly language. Action: warning + removal of the content; no ban on the first occurrence, escalation after 3 accumulated cases.
Level 2 (moderate): insulting or attacking others, posting false information, malicious traffic diversion, repeated posting of non-compliant content. Action: account ban of 1–7 days and removal of the related comments; lifted automatically when it expires, with no sign-in during the ban.
Level 3 (serious): adult content, gambling, fraud, privacy infringement (e.g. disclosing another person's email address or phone number), harassment. Action: 30-day ban or permanent ban, plus removal of all non-compliant content.
Level 4 (unlawful): politically unlawful content, terrorism, child sexual abuse material, organising illegal activity, clearly illegal fraud or drug-related content. Action: immediate permanent ban, retention of the relevant logs and content, and reporting to and cooperation with the competent authorities as required by law.
Enforcement notes: (1) bans are applied after automated review or administrator verification, and administrators may delete public comments and apply necessary account measures; (2) a sanctioned account may appeal through "Contact us", and we review within 15 business days; (3) once an account is judged level 4, it is in principle not reinstated and we reserve the obligation to report to the authorities.
9. Protection of Minors
This service is intended primarily for adult users. Minors are advised to use it under the guidance of a guardian. If we learn that we have collected personal information of a minor without guardian consent, we will delete it as soon as possible. Guardians may contact us at the address below.
10. Contact Us
For questions, suggestions or complaints about this policy, the processing of your data, or the exercise of your rights, please contact:
Email: furrynaling@outlook.com
We will respond and handle your request as soon as possible (normally within 15 business days).
Email opt-out: if you no longer wish to receive our system notification emails, you may reply to that email or contact us at the address above to unsubscribe; once received, we will stop sending to that address.
11. Changes to This Policy
As the service evolves and regulations change, we may revise this policy, update the "last revised" date on this page, and where necessary notify you through in-site notices or email. Continuing to use the service after a material change constitutes acceptance of the updated terms.
Thank you for trusting NALING — protecting every piece of your privacy is our underlying design, not just a promise.