Privacy Policy
Effective Date: 2026-05-11
Summary
This Privacy Policy explains how Zhang Jie, operating the QuickSend application and related services ("QuickSend", "we", "us", "our"), collects, uses, discloses, and protects your personal information ("Personal Information" or "Personal Data") when you use the QuickSend cross-device content transfer application and related services (the "Service").
This Policy applies worldwide. Where stricter local laws apply — including but not limited to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act and California Privacy Rights Act ("CCPA/CPRA"), other U.S. state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA), the Personal Information Protection Law of the People's Republic of China ("PIPL"), the Brazilian Lei Geral de Proteção de Dados ("LGPD"), the Personal Information Protection and Electronic Documents Act of Canada ("PIPEDA"), the Digital Personal Data Protection Act of India ("DPDP"), the Personal Information Protection Act of South Korea ("PIPA"), the Australian Privacy Act 1988, and equivalent regimes — those laws prevail to the extent of any conflict.
By creating an account or using the Service, you confirm that you have read and understood this Policy.
NOTE — QuickSend is NOT an end-to-end encrypted service. While we encrypt all data in transit and prefer peer-to-peer direct delivery (which keeps file payloads off our servers in the typical case), content that is relayed through our servers can be read by us. See Section 5 for details.
1. Who Is the Data Controller
The data controller (or, where applicable under U.S. state privacy laws, the "business"; under PIPL, the "personal information handler"; under LGPD, the "controller") responsible for the processing of your Personal Information is Zhang Jie ("QuickSend"). Postal address is available upon valid written legal request submitted to legal@ddzu.net.
For privacy-specific inquiries and to exercise your rights, contact privacy@ddzu.net. EU/UK residents may also contact their national data-protection supervisory authority.
Under Article 27 of the GDPR, QuickSend will appoint an EU representative when our EU user base exceeds the threshold requiring such appointment; until then, EU users may contact us at the address above. We will publish the representative's name and address on our website when appointed.
2. Personal Information We Collect
We collect the minimum information necessary to provide the Service. Categories include:
(a) Account data — email address, account creation time, locale (set by you or detected from the device), inferred region. We do not collect names, phone numbers, government IDs, dates of birth, photographs, biometric data, or other sensitive identifiers unless you voluntarily provide them through feedback.
(b) Device data — device model, operating-system family and version, app version, install identifier (a randomly generated UUID stored on the device), last-online timestamp, login IP address, and approximate region derived from IP geolocation. We use this data for security, fraud prevention, and service-quality monitoring.
(c) Connection metadata — records of which of your devices are connected to which other devices (account-level), the timing of those connections, and the volume of transfers. We use this to operate the Service, enforce subscription quotas, and detect abuse.
(d) Transferred content — the textual, link, or file content you transmit. We only have access to this content when (i) the recipient device is offline (Pro+ tiers only) and the content is temporarily cached for delivery; (ii) peer-to-peer direct delivery fails and the content is briefly relayed through our servers (Pro+ tiers only); or (iii) an asynchronous metadata-plus-content copy is uploaded for audit and abuse-prevention purposes (see Section 6 below). For peer-to-peer transfers, the file payload never reaches our servers.
(e) Payment metadata — subscription tier, status, currency, billing platform identifier, last four digits of the payment method (received from the payment processor; we never receive full card numbers). We do not collect bank statements, transaction histories, or other financial records.
(f) Diagnostics — anonymized crash reports, stack traces, performance metrics. We do not collect screen recordings, keystrokes, or other intrusive telemetry.
(g) Optional input — content of feedback submissions and any screenshots you choose to submit through the in-App feedback feature; we treat this as voluntarily provided.
(h) Cookies and similar technologies (web only) — when you visit our website, we may use strictly necessary cookies for session management and CSRF protection. We do not currently use analytics or advertising cookies. If we add them in the future, we will obtain prior consent as required by the EU ePrivacy Directive and ensure compliance with the Connecticut CTDPA "sensitive data" rules.
3. Sensitive Personal Information
We do NOT intentionally collect "sensitive personal information" within the meaning of CCPA/CPRA, GDPR Article 9, PIPL Article 28, or analogous categories — i.e., we do not collect government ID numbers, financial account numbers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, health data, biometric or genetic data, or trade-union membership.
If you voluntarily transmit sensitive personal information through the Service (for example, by sending a photo of an ID card to your own other device), the content is treated subject to the encryption and retention rules in Section 5 and Section 9; we do not intentionally inspect it.
California residents have the right under the CPRA to limit our use of sensitive personal information; as we do not intentionally collect it, no separate limitation request is required. If you believe we have collected sensitive information about you in error, please email privacy@ddzu.net and we will investigate and delete.
4. Sources, Purposes of Processing, and Legal Bases
We obtain Personal Information directly from you (when you register, configure your devices, send content, or contact us), automatically from your device and network (telemetry described above), and from third parties (payment processors confirming subscription status, IP-to-region databases, abuse-prevention services, and law-enforcement agencies in connection with a valid legal request).
We process Personal Information for the following purposes, relying on the indicated legal bases under GDPR (and analogous bases under other laws):
· To create and operate your account, route content between your devices, and deliver paid features — Performance of a contract (GDPR Art. 6(1)(b); PIPL Art. 13(2); LGPD Art. 7(V)).
· To send transactional emails such as sign-in codes, receipts, security alerts — Performance of a contract.
· To prevent fraud, abuse, and unauthorized access; maintain security; respond to incidents — Our legitimate interests and compliance with legal obligations (GDPR Art. 6(1)(c), (f); PIPL Art. 13(5); LGPD Art. 7(IX), (VI)).
· To process refunds, tax reporting, and statutory record-keeping — Compliance with legal obligations.
· To improve and develop the Service, debug, and analyze usage in aggregate or pseudonymized form — Our legitimate interests.
· To respond to feedback or support requests you submit — Performance of a contract / our legitimate interests.
· To respond to law-enforcement requests, judicial orders, or to assert/defend legal claims — Compliance with legal obligations / our legitimate interests.
We DO NOT sell or share your Personal Information for cross-context behavioral advertising under CCPA/CPRA (we have not sold or shared in the prior twelve (12) months and do not intend to). We DO NOT use your transferred content for any form of advertising or for training machine-learning or generative-AI models, whether ours or third parties'.
5. Transport and Storage Security
All data transferred through QuickSend is encrypted in transit, using HTTPS (TLS 1.3) for our REST APIs, WSS for real-time signaling, WebRTC DTLS-SRTP for peer-to-peer data channels, and HTTPS for any file relay or object-storage interactions.
QuickSend prefers peer-to-peer direct delivery (LAN discovery via mDNS and cross-network NAT traversal via STUN). When peer-to-peer succeeds, the underlying file payloads never reach our servers. Only metadata about the transfer event is reported to our servers under Section 6.
When peer-to-peer is not possible (e.g., the recipient device is offline, or NAT traversal fails on Pro+ tiers), payloads may be temporarily relayed through our servers. During such relays we technically have the ability to read the content, and we may do so for the limited purposes described in Sections 6 and 7.
QuickSend is NOT an end-to-end encrypted service in the cryptographic sense. If end-to-end encryption is a legal or compliance requirement for your use case (e.g., HIPAA-regulated health data, attorney-client privileged material, classified information), please do not rely on QuickSend.
At-rest secrets on our servers are encrypted using industry-standard mechanisms (e.g., disk-level encryption, key-management via cloud KMS). Account passwords (where applicable) are stored using bcrypt hashing. Access to production systems is restricted to a limited number of personnel, requires multi-factor authentication, and is logged.
6. Audit, Abuse Prevention, and Server-Side Retention
For the purposes of customer support, abuse prevention, statutory record-keeping, and legal compliance, an asynchronous metadata summary of every content item transmitted through the Service is reported to our servers, containing: sender and recipient user IDs and device IDs, content type, content body (for text/link items) or file name and download key (for relayed files), file SHA-256 hash and size (for file items), transport path (LAN_P2P / CROSS_P2P / RELAY), timestamps, and delivery status. This summary record is retained for up to ninety (90) days; associated relay file copies in object storage are deleted earlier, per the offline content schedule described below (or upon delivery).
Files transferred peer-to-peer (LAN_P2P or CROSS_P2P) do not have their content uploaded to our servers — only the metadata listed above. Files relayed through our servers (RELAY) are stored on our object-storage provider (currently Alibaba Cloud OSS; we plan to migrate to Cloudflare R2) and are deleted automatically on the retention schedule above or when the recipient acknowledges delivery, whichever comes first.
Automated scanning — Relayed content may be scanned automatically for known illegal material (e.g., child sexual abuse material via PhotoDNA-style hash matching, once available; malware via standard antivirus engines). Detection events are logged and may be reported to NCMEC or other competent authorities as required by law.
No business-records exception is asserted to circumvent statutory record-keeping requirements; where local law mandates retention of specific data categories (e.g., tax records, anti-money-laundering logs), those records are retained per the applicable law.
No use for AI / ML training — We do not use your Personal Information, your transmitted content, or your file content to train, fine-tune, or evaluate any artificial-intelligence or machine-learning model. We do not sell or share content with third parties for AI / ML training purposes. This commitment applies regardless of subscription tier and is independent of the 24-hour retention window above.
7. Disclosure to Third Parties
We disclose Personal Information to the following categories of third parties only as necessary to operate the Service:
(a) Infrastructure providers and third-party SDKs / components currently in use. Each is bound by a data-processing agreement (DPA) or, for transfers to the EEA/UK, the European Commission's Standard Contractual Clauses (SCCs) / UK International Data Transfer Addendum, restricting the provider's use of your information to the services they provide to us:
· Apple Push Notification service (APNs) — push notification delivery on iOS / macOS. Receives device push tokens.
· Firebase Cloud Messaging (FCM, Google) — push notification delivery on Android. Receives device push tokens.
· Apple StoreKit 2 — in-app subscriptions on iOS / macOS. Receives transaction identifiers; we never receive full card numbers.
· Google Play Billing — in-app subscriptions on Android. Receives transaction identifiers; we never receive full card numbers.
· Paddle — web subscription checkout. Receives email and billing identifiers; we never receive full card numbers.
· Alibaba Cloud OSS — relay file storage (planned migration to Cloudflare R2). Receives encrypted-in-transit file payloads only when peer-to-peer transfer is unavailable; objects are deleted on the schedule in Section 6.
· Gmail SMTP via Google Workspace — transactional emails (login codes, account notifications). Receives recipient email address and email body.
· MaxMind GeoLite2 — IP-to-country lookup for non-CN users. Receives IP address on a query basis; no identity attached.
· ip2region (offline local database) — IP-to-region lookup for CN users. No external transmission of your IP occurs.
(b) Payment processors — Apple (App Store In-App Purchase), Google (Google Play Billing), and Paddle (or equivalent web processor for direct purchases). These parties receive only the information needed to bill you and handle disputes.
(c) IP-to-region database providers (e.g., MaxMind GeoLite2, ip2region) — receive IP addresses on a query basis but are not provided your identity.
(d) Government authorities and law enforcement — only as required by binding legal process (subpoena, court order, search warrant, or equivalent) issued by a court or authority of competent jurisdiction, and limited to (i) account data; (ii) transfer metadata; (iii) any content or file still retained on our servers at the time of the request. We do not provide voluntary access; we will not exceed what is legally required; we will object to overbroad requests; and we will, where lawful and practicable, notify the affected user before responding so they may seek to quash the request.
(e) Successors — if all or substantially all of our assets are acquired by, merged with, or sold to a third party, Personal Information may be transferred as part of the transaction, subject to the same protections set out in this Policy. We will provide notice in advance of any such transfer where feasible.
(f) Professional advisors — our legal, accounting, and audit advisors, bound by professional confidentiality.
We do NOT sell your Personal Information for monetary or other valuable consideration. We do NOT share it for cross-context behavioral advertising under CCPA/CPRA.
8. International Data Transfers
QuickSend operates globally and your Personal Information may be processed in jurisdictions other than your country of residence. The principal jurisdictions involved (subject to change as our infrastructure evolves) are:
· Hong Kong SAR — operational and customer-support functions.
· Mainland China — primary database and file-storage infrastructure (Alibaba Cloud OSS).
· United States and European Union — secondary cloud infrastructure and content-delivery networks.
Cross-border transfer safeguards:
(a) For transfers of EEA/UK personal data outside the EEA/UK, we rely on the European Commission's Standard Contractual Clauses (SCCs, 2021), the UK International Data Transfer Addendum, supplementary technical measures (encryption in transit and at rest), and, where required, transfer impact assessments under Schrems II.
(b) For transfers of personal information out of Mainland China, we comply with PIPL Articles 38–43, including obtaining separate consent for cross-border transfers (your acceptance of this Policy is treated as such separate consent under PIPL), conducting a personal-information protection impact assessment, and using a standard contract approved by the Cyberspace Administration of China (CAC) or completing CAC security assessment where required.
(c) For transfers under LGPD (Brazil) and other regimes that require adequacy decisions or contractual safeguards, we rely on the relevant approved mechanisms.
(d) Users may request a copy of the relevant cross-border transfer safeguard documents by emailing privacy@ddzu.net.
9. Data Retention
We retain Personal Information only for as long as necessary for the purposes set out in Section 4 or as required by law. Specific retention periods:
· Account data — retained for the duration of your account. After your account is deleted, we anonymize or delete personal identifiers within thirty (30) days, except where law requires longer retention (e.g., tax records may be retained up to seven (7) years; anti-money-laundering logs as required).
· Offline content cache (server-side, only when the recipient device is offline) — Pro tier six (6) hours, Max tier twelve (12) hours, Ultra tier twenty-four (24) hours (operator-configurable). The Free tier does not support offline caching — content is dropped if the recipient is offline. Once delivered, the cached copy is removed.
· Audit summary (the asynchronous record described in Section 6) — up to ninety (90) days. Relay file copies are deleted per the offline content schedule above (or upon delivery).
· Diagnostics and crash logs — retained up to ninety (90) days in identifiable form, then anonymized or aggregated.
· Login and security logs — retained up to one (1) year for fraud prevention and security.
· Customer-support correspondence — retained for up to two (2) years after the last interaction.
· Backups — encrypted backups may be retained for up to thirty-five (35) days for disaster-recovery purposes, after which they are overwritten on a rolling basis.
· Anonymized or aggregated statistics derived from operation of the Service — may be retained indefinitely.
10. Your Rights
Subject to applicable law, you have the following rights with respect to your Personal Information. These rights are not absolute and may be subject to exceptions under applicable law.
(a) Right of access — to obtain confirmation of whether we process your Personal Information and, if so, a copy of that information.
(b) Right of rectification — to correct inaccurate or incomplete Personal Information.
(c) Right of erasure ("right to be forgotten") — to request deletion of your Personal Information.
(d) Right to restrict or object to processing — particularly where our legal basis is legitimate interests, or for direct-marketing purposes.
(e) Right to data portability — to receive a structured, commonly used, machine-readable copy of Personal Information you have provided to us, and to have that copy transmitted to another controller where technically feasible.
(f) Right to withdraw consent — where processing is based on consent, you may withdraw at any time without affecting the lawfulness of processing carried out prior to withdrawal.
(g) Right to lodge a complaint — EU/UK residents may complain to their national data-protection authority; California residents may complain to the California Privacy Protection Agency (cppa.ca.gov); other-jurisdiction users may complain to the relevant regulator.
California-specific rights (CCPA/CPRA): right to know, right to delete, right to correct, right to opt out of sale or sharing (we do not sell or share — but the right exists), right to limit use of sensitive Personal Information (we do not intentionally collect sensitive PI), and right to non-discrimination for exercising any of the above.
Other U.S. state rights (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA): the rights granted in those states are substantially similar to CCPA/CPRA; we honor them on the same basis.
PIPL (Mainland China) rights: right of access, copy, transfer, correction, deletion, withdrawal of consent, restriction of processing, and an explanation of automated decision-making.
How to exercise — Email privacy@ddzu.net with the subject "Data Rights Request" and describe the right you wish to exercise and the email address associated with your account. We may require identity verification (e.g., matching the request to a verified account email).
Response time — We will respond within thirty (30) days for GDPR/UK GDPR; forty-five (45) days for CCPA/CPRA (extendable by an additional 45 days where reasonably necessary, with notice); fifteen (15) working days for PIPL; and within the timeframe required by other applicable law. There is no fee for a reasonable request; we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive (e.g., repetitive).
Authorized agents — California residents may use an authorized agent to submit a request; we will require written authorization from you and verification of the agent's identity.
Appeals — If we deny your request, you may appeal by emailing privacy@ddzu.net with the subject "Data Rights Appeal" within sixty (60) days of the denial. Residents of certain U.S. states (Virginia, Colorado, Connecticut, Texas) have a statutory right to appeal under their state's privacy law.
11. Children
You must be at least thirteen (13) years old to use the Service. In jurisdictions where a higher minimum age for data-processing consent applies (e.g., sixteen (16) in certain EU member states under GDPR Article 8; varying ages between 13 and 16 across EEA countries), you must meet that higher age. The Service is not directed to, and we do not knowingly collect Personal Information from, anyone below the applicable minimum age.
If you are a parent or legal guardian and believe that your child has provided Personal Information to us without your consent, please contact privacy@ddzu.net and we will promptly delete the information. We comply with the Children's Online Privacy Protection Act (COPPA) of the United States, including its requirement to obtain verifiable parental consent before collecting personal information from a child under 13, where such collection would otherwise occur.
We do not knowingly market the Service to children, target advertisements to children, or sell or share children's data.
12. Automated Decision-Making and Profiling
We do not use your Personal Information for automated decision-making that produces legal effects on you or similarly significant effects, within the meaning of GDPR Article 22.
Anti-abuse heuristics (e.g., rate-limit detection, fraud-pattern matching, malware hash matching) are applied only to maintain service integrity and security; they do not constitute decisions about you as a person and you can appeal any enforcement action under Section 11 of the Terms of Service.
13. Security Incidents and Breach Notification
We maintain reasonable technical and organizational security measures appropriate to the risk, including encryption in transit and at rest, access controls, multi-factor authentication for production systems, logging, regular vulnerability assessments, and incident-response procedures.
In the event of a Personal Information breach likely to result in a risk to your rights and freedoms, we will notify affected users and the competent supervisory authority within the timeframes required by applicable law: seventy-two (72) hours after becoming aware under GDPR Article 33; "without undue delay" under PIPL Article 57; in compliance with the breach-notification rules of CCPA/CPRA and U.S. state laws; and equivalent timeframes elsewhere.
Notwithstanding the foregoing, we may delay notification to the extent required by law-enforcement authorities to avoid impeding an investigation, and only for the duration of such impediment.
14. Do Not Track and Global Privacy Control
The Service does not currently respond to "Do Not Track" browser signals, because no industry consensus on their meaning exists.
We honor the Global Privacy Control (GPC) signal where it indicates a request to opt out of sale or sharing of Personal Information. In any event, we do not sell or share Personal Information under CCPA/CPRA.
15. State-Specific Disclosures
California (CCPA/CPRA) — In the prior twelve (12) months, we have collected the categories of Personal Information described in Section 2 (identifiers, internet/electronic activity, geolocation derived from IP, customer records, and commercial information related to subscriptions). We have not sold or shared Personal Information for cross-context behavioral advertising. The business purposes for which we collect each category are described in Section 4.
Virginia / Colorado / Connecticut / Utah / Texas — We have not engaged in "targeted advertising", "profiling that produces legal or similarly significant effects", or "sale" of Personal Information within the meaning of those statutes. You have the right to opt out of any future such processing.
Nevada — Nevada law requires us to allow Nevada residents to opt out of the sale of certain "covered information". We do not engage in such sale; if we ever do, we will provide a mechanism to opt out.
16. Cookies and Similar Technologies (Web)
When you visit our website (https://ddzu.net once launched), we may use strictly necessary cookies for session management, login state, CSRF protection, and language preference. These cookies do not require prior consent under the EU ePrivacy Directive.
We do not currently use analytics, advertising, or social-media cookies. If we introduce such cookies in the future, we will (i) obtain prior informed consent through a cookie banner where required (including in the EEA and UK), (ii) provide a granular opt-in / opt-out control, (iii) honor the Global Privacy Control signal.
Mobile and desktop apps do not use HTTP cookies; we use local storage (AsyncStorage for mobile, electron-store for desktop) to persist your sign-in token and user preferences. This local storage is not accessible to third parties.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be highlighted in-App or by email at least seven (7) days before they take effect, except where shorter notice is required by law or to address an imminent privacy or security risk.
Your continued use of the Service after the effective date constitutes acceptance of the updated Policy. The "Effective Date" at the top of this Policy indicates the latest revision. We maintain an archive of prior versions, available on request.
18. Contact
Privacy inquiries and rights requests: privacy@ddzu.net
Legal notices and DMCA: legal@ddzu.net
Customer support: contact@ddzu.net
Operator: Zhang Jie. Postal address available upon valid written legal request to legal@ddzu.net.
19. AI-Assisted Drafting Disclosure
This Privacy Policy was prepared with the assistance of a large-language-model AI tool, using widely adopted SaaS templates and reference materials including GDPR/CCPA model clauses. It has not been individually reviewed by external legal counsel as of the Effective Date.
This disclosure does not affect the legal enforceability of this Policy but is provided in the interest of transparency. We encourage users to consult independent counsel if they have any questions about how this Policy affects their rights.