Terms & policies
Privacy Policy
Effective Date: April 22, 2026
Version: v1.0
Scope of Application: cnboxing.net website, CN Boxing KOOK bot, and all related services
Introduction
CN Boxing Tier Test (hereinafter referred to as "this platform," "the platform," or "we") understands the importance of your personal information. We are committed to protecting the personal information you provide and generate during your use of this platform in accordance with the Personal Information Protection Law of the People's Republic of China (hereinafter referred to as the "Personal Information Protection Law"), the Cybersecurity Law, the Data Security Law, and other relevant laws and regulations, by taking reasonable technical and management measures.
This Privacy Policy (hereinafter referred to as "this Policy") describes how we collect, use, store, share, disclose, transfer, and protect your personal information, and your rights regarding this information.
Please carefully read and confirm that you fully understand all the contents of this Policy before using this platform, especially the clauses marked in bold or underline. Using any service of this platform constitutes your agreement to this Policy.
This Policy applies to all services of the platform. This policy, together with the Terms of Service, Community Guidelines, and Testing Rules, constitutes the complete agreement between you and the platform. In case of any inconsistency between this policy and other rules, this policy shall prevail (limited to matters concerning personal information protection).
1. Who We Are
-
Service Name: CN Boxing Tier Test
-
Service Domain:
cnboxing.net -
Operating Entity: CN Boxing Tier Test Operations Team (hereinafter referred to as the "Operations Team")
-
Data Controller: Operations Team
-
Contact Email:
-
General Inquiries and Privacy Matters:
info@cnboxing.net -
User Support:
help@cnboxing.net -
Ticket Submission: Website
/me/tickets/new
2. Personal Information We Collect
We collect your personal information according to the principle of "minimum necessary". The table below lists the types of information we collect, the corresponding scenarios, and whether they are necessary for providing the service.
2.1 Information You Provide
| Information Category | Specific Content | Collection Scenario | Required |
| --- | --- | --- | --- |
| Account Credentials | Email address, password (stored as an argon2 hash, not plaintext) | Registration, Login | Required |
| Minecraft Account Information | MC official UUID, Username | MC account binding | Required for Tier testing and other functions |
| KOOK Account Information | KOOK User ID (kook_id) | KOOK account binding | Required when using the KOOK channel |
| Support Ticket Content | The subject, body, and additional information you fill in on the support ticket | Appeals, Feedback, Reports, Inquiries | Depends on the function |
| Rating and Evaluation | Style/Combat score and written comments filled in by the Tester after the test | Tier test review | Required for Testers |
| Recording Link | Tester Or the URL of a test recording submitted by a player | Recording is required for LT3 / HT3 / LT2 / HT2 / LT1 / HT1 tests | Required for specific scenarios |
| Email Password (Employee Email) | Employee email password hash independent of website password | Enable @cnboxing.net email | Staff optional |
2.2 Information Automatically Generated During Use
| Information Category | Specific Content | Collection Scenario |
| --- | --- | --- |
| Chat Log | Text and system messages in Tier test chat channels and ticket channels (tier_test_chat_messages, ticket_messages) | Test process, ticket flow |
| Test Archive | Complete state machine record for each Tier test (queued → finalized, etc.) | Tier test flow |
| Historical Changes | Player Tier change history (tier_test_history) | Each finalize / null | | Voting Records | Tester voting records for applications and S nominations | Tester System Operation |
| Online Heartbeat | Redis cache of Tester online status (presence:tester:{uid}) | Tester Heartbeat Mechanism |
2.3 Device and Access Information
To ensure service security and compliance, we automatically record:
-
IP Address (server access log);
-
User-Agent (browser/client identifier);
-
Access timestamp and request path;
-
JWT Token validity period and issuance information;
-
Security events such as abnormal logins and frequency control triggers;
-
Necessary server logs (error stack traces, critical business events).
2.4 Cookies and Local Storage
-
We use necessary cookies / LocalStorage to store your login token, interface preferences (such as language, theme), etc., to maintain the session and improve the experience.
-
We do not use third-party ad tracking cookies, nor do we sell your cookie data to advertisers.
-
You can clear cookies at any time through your browser settings, but this may require you to log in again or lose some personalized settings.
2.5 Information We Do Not Collect
We will not proactively collect the following sensitive personal information (unless required by law or regulation, or with your separate consent and informed of the specific purpose):
-
National identity identifiers such as ID card number and passport number;
-
Biometric information such as facial recognition and fingerprints;
-
Financial accounts such as bank card numbers and payment accounts;
-
Precise geographical location (GPS level);
-
Your private address book, SMS messages, and call logs;
-
Your operational data in the Minecraft game, except for that required for Tier testing;
-
Your behavioral data on the KOOK platform, except for that required for binding your identity and message mirroring.
3. How We Use Personal Information
We use your personal information for the following purposes, and never beyond the scope of this section:
3.1 Providing Core Services
-
Account registration, login, binding, and password retrieval;
-
Running the entire Tier testing process (queuing, matching Testers, chat, scoring, and results);
-
Maintaining the Tester system (application, voting, heartbeat, penalties);
-
Running the ticket system, announcements, and document center;
-
Sending system emails (registration verification, password reset, important notifications).
3.2 Maintaining Platform Credibility and Security
-
Detecting and preventing fraud, cheating, proxy testing, insider trading, and other violations;
-
Responding to security incidents, ticket appeals, and Tier rating disputes;
-
Maintaining service stability and troubleshooting;
-
Preventing account theft.
3.3 Service Improvement
-
Based on anonymized or aggregated statistical data, analyze usage trends, rating distribution, and tester workload to improve business processes and rules;
-
This type of analysis is not targeted at any specific individual and is not used for user profiling or commercialization.
3.4 Fulfilling Legal Obligations
- Cooperate with authorized agencies in lawful inquiries;
Fulfill the legal requirements of judicial, administrative, and arbitration institutions;
Respond to legal obligations such as the protection of minors and cybersecurity compliance.
3.5 Matters Regarding Not Using Your Information
We promise will not:
-
Sell your personal information to third parties;
-
Target you with targeted advertising based on your personal information;
-
Use your data to train commercial AI models independent of platform operations;
-
Publicly disclose your work orders and private messages without legal justification.
4. Sharing, Disclosure, and Transfer of Personal Information
4.1 Proactive Disclosure
By joining the Tier testing process, you agree to the following information being disclosed under the corresponding functions:
-
Your MC username;
-
Your finalized Tier rating, total score, and position on the leaderboard;
-
Your public test profile (
/tier-tests/:id) and historical changes (tier_test_history); -
The time you participated in the test, Tester, basic battle description, and video link (if submitted).
During the 72-hour provisional insurance period, your Tier rating, although in
provisionalstatus, will still be reflected in your public profile (marked). Upon expiration, it will be officially locked to the leaderboard.
4.2 Scenarios of Sharing with Third Parties
In principle, we do not proactively share your personal information with third parties. Necessary sharing may only occur in the following situations:
| Third Party | Scenario | Sharing Scope |
| --- | --- | --- |
| KOOK Operator | Sending messages via Bot, binding identity, querying group identity | KOOK ID, necessary message content |
| Minecraft Server Plugin | Binding verification, PreLogin code generation, battle status callback | MC UUID, username, binding status |
| Cloud Service Provider (Tencent Cloud) | Server hosting, data storage, backup | Encrypted database content |
| Email Infrastructure (Postfix/Dovecot) | Employee email delivery, system emails | Email address, hashed password |
| SMS/Email Gateway | Sending verification emails | Email address, verification content |
We have conducted due diligence on the above third parties and require them to assume corresponding security obligations for the shared information; however, these third parties have their own privacy policies, and you are also bound by their policies when using related functions.
4.3 Mandatory Disclosure by Law
When we receive a request for assistance in an investigation from a competent state authority, we may be required to disclose relevant personal information. We will request legal documents to the extent permitted by law and will limit the scope of disclosure to what is necessary.
4.4 Mergers, Acquisitions, and Service Shutdown Scenarios
-
If the platform undergoes a change of ownership, merger, acquisition, or liquidation, we will require the new controlling party to continue to comply with this policy; if they are unable to continue compliance, we will notify you within a reasonable period and provide you with the option to cancel your account and export your data.
-
If the platform is permanently shut down, we will issue an advance notice before the shutdown and make reasonable efforts to assist you in exporting critical data.
4.5 Data Export
-
The platform's main data infrastructure is located in China.
-
We do not proactively export your personal information.
-
If future business requires data to be exported, we will conduct a security assessment in accordance with the Personal Information Protection Law, obtain your separate consent, and take appropriate contractual and technical measures.
5. Storage and Retention of Personal Information
5.1 Storage Location
-
Key business data (PostgreSQL, Redis, application logs) is stored on Tencent Cloud servers used by the operations team, located within China.
-
Employee email data is stored on the same infrastructure.
5.2 Storage Period
We retain personal information according to the "minimum period necessary to achieve the purpose", see below for details:
| Data Category | Retention Period |
| --- | --- |
| Basic Account Information | Account duration + 30 days after account cancellation (freeze period, for accidental recovery) |
| Finalized Tier Test Archives | Long-term retention (community public records); after account cancellation, anonymization will be performed as requested, retaining the data structure but removing the identity identifier |
| Chat Logs | 90 days after the corresponding business is closed |
| Work Order Records | 180 days after the work order is closed, after which it can be de-identified and archived |
| Server Access Logs | Usually no more than 180 days, security incident related logs can be extended to 2 years |
| Temporary Tokens such as Email Verification and Binding Codes | Expires immediately after expiration, retained in the background for no more than 7 days |
| Redis Online Status / Temporary Cache | By TTL Control, Automatic Cleanup Upon Expiration |
5.3 Deletion and Anonymization
-
Upon reaching the retention period or after you apply for account cancellation, we will delete or anonymize the relevant information according to the above strategy.
-
Anonymized data (such as the final tier, time, and unidentified digest of a tier test profile) may continue to be retained for ranking stability and historical reference.
-
If laws and regulations mandate retention, the corresponding data may be retained for an extended period, during which the security obligations of this policy still apply.
6. Data Security Measures
We take reasonable technical and management measures to protect your information:
6.1 Technical Measures
-
Password Hashing: Website passwords are hashed using argon2 and are not stored in plaintext; employee email passwords are stored using a hash format supported by Dovecot.
-
Transmission Encryption: HTTPS is mandatory across the entire site;
cnboxing.netuses TLS 1.2+.- Layered Authentication: The API uses JWT Bearer + middleware authentication; internal callback interfaces (/internal/*) use Bearer + HMAC dual authentication to prevent forgery. -
Minimum Privileges: Authentication is completed at the middleware layer; handlers do not repeatedly check roles, ensuring clear role boundaries.
-
Database Access Control: The database is only accessible to backend services, prohibiting direct public network connections.
-
KOOK Echo Protection: Bot and Website identity groups are synchronously protected with echo protection to prevent circular writes.
-
Unique Constraints: Partial unique indexes prevent business vulnerabilities such as concurrent dual-open testing and multiple KOOK account bindings by one person.
-
Regular Backups: Critical databases are backed up regularly, and backup data is also protected by access controls.
6.2 Management Measures
-
Operations team members must understand and agree to adhere to confidentiality obligations before accessing personal information;
-
Management backend access records are auditable;
-
High-risk operations (such as batch deletion, permission modification) require additional confirmation and logging;
-
Regularly review permissions and investigate abnormal behavior.
6.3 Risks Cannot Be Completely Eliminated
Despite the above measures, no internet platform can be absolutely secure. Please understand:
-
Internet transmission itself carries the risk of interception and eavesdropping;
-
You are responsible for the proper security of your own devices and accounts;
-
If your account is stolen or your password is leaked, please change your password immediately and contact us.
6.4 Data Breach Response
-
In the event of a personal information breach, we will assess the severity of the incident within 72 hours of becoming aware of it.
-
For events that may significantly impact your rights, we will notify you via site messages, emails, announcements, etc.:
-
Scope and type of disclosure;
-
Potential impact;
-
Remedial measures we have taken;
-
Self-protection measures you can take;
-
Contact information.
-
We will also report to the competent authorities in accordance with the law.
7. Protection of Minors
7.1 General Principles
-
This platform is concerned about the rights of minors and calls on guardians to actively fulfill their guardianship responsibilities and correctly guide underage users to use internet services healthily.
-
If you are a child under fourteen (14) years old, we will provide services to you only with the consent of your guardian. Guardians can contact us at
help@cnboxing.netto exercise their rights to access, copy, correct, and delete children's personal information. -
If you are a minor aged fourteen to eighteen, please read this policy with your guardian's accompaniment and obtain their consent before using the platform services. ### 7.2 Special Measures for Minors
-
We will not intentionally collect information from minors beyond what is necessary;
-
We will not use minors' information for commercial profiling or advertising;
-
If we discover suspected instances of minors engaging in illegal offline transactions, accepting monetary ratings, or being misled by others, we have the right to suspend their accounts and notify their guardians;
-
Work requests involving minors will only be processed to the minimum extent possible.
7.3 Guardians' Rights
If you are the guardian of a minor, you can contact us at help@cnboxing.net to assert the following rights:
- View the basic account information of your ward's minor;
Request correction/deletion of the minor's account and related information;
Withdraw previously given consent;
Understand the key activities of your ward's minor on the platform.
We will verify your identity and process your request within a reasonable timeframe.
8. Your Rights
Within the scope permitted by law, you have the following rights regarding your personal information:
8.1 Access and Copying
-
You can view your account's basic information, binding status, and testing history on
/me. -
For parts of your personal information in the database that are not directly displayed on the front end, you can request a copy through a support ticket.
8.2 Correction and Supplementation
-
You can directly change your email address and password on your account page;
-
Changes to MC and KOOK bindings require a support ticket application and may require you to provide proof of identity;
-
Other information, such as errors in the Tier profile, can be corrected through a
tier-appeal/bugsupport ticket.
8.3 Deletion and Account Cancellation
-
You can apply to cancel your account via a support ticket;
-
After cancellation, we will delete or anonymize your identifiable information after the retention period described in Section 5.2 of this policy;
-
Some public records (such as finalized test files) will be retained anonymously.
8.4 Withdrawal of Consent
-
You can withdraw your previous consent to the processing of specific information at any time;
-
Withdrawal of consent may result in your inability to continue using some or all services, which we will explain to you when processing your application;
-
Withdrawal of consent does not affect the legality of the processing already carried out based on consent prior to the withdrawal.
8.5 Obtaining Copies and Data Portability
-
You can apply to export your basic account information, test history, and support ticket content via a support ticket, provided in structured data (JSON/CSV) format;
-
We will usually respond within 15 business days;
-
For parts involving the privacy or security of others, we may perform necessary anonymization on the exported content.
8.6 Complaints and Reports
-
If you believe that the platform's processing of personal information violates the law or this policy, you can report it to us via
help@cnboxing.netor by submitting a support ticket; -
We will reply within 15 business days of receiving your report;
-
If the processing result still does not satisfy you, you have the right to file a complaint or lawsuit with the competent cyberspace administration, public security, or other relevant authorities.
9. Third-Party Services and Links
-
The platform may contain links to third-party websites, services, video platforms (Bilibili, Douyin, video hosting, etc.). These sites have their own privacy policies and are not subject to this policy.
-
When clicking on external links or uploading content to third-party services, please make your own judgment and be careful to protect your information.
10. Cookies and Similar Technologies
10.1 Cookies We Use
| Type | Purpose | Required |
| --- | --- | --- |
| Session Cookie / Local Token | Maintain Login State (JWT) | Required |
| Preference Cookie / LocalStorage | Language, Theme, Interface Preferences | Optional |
| Security Cookie | CSRF, Anti-Abuse | Required |
10.2 Management
-
You can clear or disable cookies through your browser settings;
-
Disabling required cookies will result in loss of login state and some functions becoming unavailable;
-
We do not use cross-site tracking advertising cookies, nor do we share them with advertising networks.
11. Changes to this Policy
-
We may update this policy from time to time due to legal regulations, business adjustments, etc. The updated policy will be published in
/rules/privacy. -
Major changes (such as adding new types of personal information, changing cross-border rules, or adjusting the scope of third-party sharing) will be communicated to us in advance via site messages, announcements, emails, etc., for no less than 7 calendar days.
-
Your continued use of this platform constitutes acceptance of the changes; if you do not agree, you may stop using the platform and apply to cancel your account.
-
Archives of previous versions of this policy can be provided upon request.
12. Interpretation and Application of this Policy
-
This policy is governed by the laws of the People's Republic of China.
-
The title of this policy is for convenience only and does not affect its interpretation.
-
The right to interpret this policy rests with the operations team, provided it does not violate the law; the interpretation that best protects your legitimate rights and interests shall prevail.
13. Contact Us
If you have any questions, suggestions, or complaints regarding this policy, the processing of your personal information, or the platform's practices:
| Scenario | Contact Information |
| --- | --- |
| Privacy Inquiry | info@cnboxing.net |
| User Support, Complaints, Appeals | help@cnboxing.net or /me/tickets/new |
| For Guardians of Minors Only | help@cnboxing.net (Please indicate "Guardianship Matters" in the email subject) |
We will respond to your inquiry or process your request within 15 business days. For complex matters, we may extend the processing time, but we will promptly explain the reasons and the estimated timeframe to you.
Last Updated: April 22, 2026
Version: v1.0
Thank you for carefully reading this policy. Your trust is the foundation for maintaining community credibility and continuously improving our services.
Last updated 6/17/2026, 9:58:54 PM
