ChinaSource App — Privacy Policy
Effective June 14, 2026
This Privacy Policy explains what information the ChinaSource mobile application ("the App") collects, how it is used, and the third-party services involved. The App is published by ChinaSource. By using the App you agree to this policy.
What we collect
- Account data. If you create an account, we collect your email address, an optional display name, and the password hash. If you sign in with Apple or Google, we receive a unique identifier from those providers and, where you permit it, your email address and name.
- Email verification status. We store whether your email has been verified, and a short-lived verification code while a verification is in progress.
- App content you create. Articles you save, folders you create, authors you follow, and notes / highlights you make on articles are stored locally on your device and (if you are signed in) synchronized to our backend so they are available across your devices.
- Audio playback positions. Where you stop listening to a Text-to-Speech (TTS) reading of an article is stored locally on your device for resume purposes; it is not sent to our backend.
- Usage analytics. We use Firebase Analytics to understand which features and articles are used, so we can improve the App. This is configured in a privacy-preserving mode: we do not collect advertising identifiers (IDFA), do not enable ad personalization, and do not link this usage data to your account or use it to track you across other apps or websites.
- Push notification token. If you enable notifications, we register a device token provided by Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM). It identifies your app installation so we can deliver alerts about new content. It is used only to send notifications — never for tracking or advertising.
How we use the information
- To authenticate you and protect your account.
- To deliver verification emails and password-reset emails.
- To synchronize your saved content across the devices you sign in on.
- To serve the article content and TTS audio you request.
- To send push notifications about new articles, when you have enabled them.
We do not sell your information, do not share it with advertisers, and do not use it to track you across other apps or websites.
Third-party services we use
- Aldero Auth — handles email/password authentication, Sign in with Apple, Sign in with Google, password reset, and email verification on our behalf. Hosted on AWS in the United States.
- Amazon Web Services (AWS). Our sync backend (Lambda + DynamoDB) and audio storage are operated on AWS in the United States.
- Cloudflare R2. Article TTS audio files are stored and served from Cloudflare R2.
- Apple. If you sign in with Apple, Apple sends us an identity token; we do not receive your Apple ID password. See Apple's privacy practices for Sign in with Apple.
- Google. If you sign in with Google, Google sends us an identity token; we do not receive your Google password. See Google's privacy practices.
- OpenAI. We use OpenAI's text-to-speech API to generate audio versions of articles. Article text is sent to OpenAI for synthesis; we do not send your personal information.
- ChinaSource WordPress. The article content shown in the App is fetched from our public website chinasource.org.
- Apple APNs / Google Firebase Cloud Messaging. Used to deliver push notifications to your device. We send them your device token and the notification content; they do not receive your account credentials.
- Google Firebase Analytics. Used to collect anonymous usage events (screen views and feature-use events such as article opens, audio plays, and searches). These individual events are not linked to your account identity. Configured in a privacy-preserving (non-tracking) mode: advertising identifiers are not collected, ad personalization is disabled, and usage data is not linked to your account or used to track you across other apps or websites.
Data location and retention
Account records and synchronized content are stored in AWS DynamoDB in the United States. We retain account data while your account is active. You can delete your account by contacting us; doing so removes your saved articles, notes, folders, and followed authors from our backend.
Security
All network traffic between the App and our servers uses HTTPS. Passwords are hashed with bcrypt and never stored in plaintext. Access tokens stored on your device are kept in iOS Keychain / Android Keystore.
Children
The App is intended for users 13 years of age or older. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete that information.
Your rights
- You can view and edit your display name from the account screen in the App.
- You can sign out at any time from the account screen.
- You can request account deletion or a copy of your data by contacting us at the address below.
Changes to this policy
If we change this policy materially, we will update the effective date above and surface notice in the App.