Live
China signal desk · refreshed five times each Beijing day
Beijing
China Snapshot中国快照
Account

Search the China Snapshot archive

Search source documents or ask an evidence-grounded question.

Legal · privacy

Privacy Notice

Effective 15 August 2026

Who is responsible

CHINA SNAPSHOT LIMITED, a company incorporated in Hong Kong, is the controller of the personal data described here. Its registered office is Unit 2904-05, 29/F, Universal Trade Centre, 3 Arbuthnot Road, Hong Kong S.A.R. Business Registration No. 80961828. Privacy contact: privacy@china-snapshot.com. You may also write to the registered office above, addressed to “Privacy”. General enquiries go through the contact page.

What we collect

  • Public site use. A small allowlist of first-party aggregate events such as page views, briefing calls to action, and sample opens, with the page path, a short context label, and the referring host. These rows carry no email address, no query text, no cookie, no IP address, and no user-agent string. Vercel Web Analytics adds cookie-free visitor and page-view counts from a short-lived hash derived from request data.
  • Request-protection hashes. To enforce rate limits we store a keyed HMAC-SHA256 hash of your IP address, combined with your account identifier when you are signed in. The address itself is not stored, and the hash rows are deleted after two days.
  • Free briefing signup. Your email address, a fixed channel label recording that the signup arrived through the website, the time and version of your consent, subscription status, the sync status of the contact record at Resend, an opaque unsubscribe token, and a record of which briefing editions were sent to that token.
  • Member account. Neon Auth holds your name, email address, password credential, verification state, and sessions. Our own database holds your account identifier, plan, entitlements, email preferences and their consent timestamps, monthly usage counters, and, for API keys, a label plus a SHA-256 hash of the key rather than the key itself.
  • Product events. When signed in, a fixed allowlist of actions such as account creation, sign-in, a completed archive search, a completed Ask, feedback submission, API-key creation, and API requests, with a page path and timestamp, linked to your account identifier. The event records that the action happened, never the text you typed.
  • Feedback and support. The category, subject, up to 5,000 characters of free text, the page you sent it from, an optional reply address, and the operator’s reply. Please do not put confidential client detail in that free text.
  • Email you send us. Mail to a published china-snapshot.com address is received by Resend, recorded in our database as the sender address, subject, and up to 5,000 characters of the body, and forwarded in full, including attachments, to the operator’s personal Google (Gmail) mailbox. Treat these addresses as ordinary business email, not a secure channel.
  • Search and Ask text. See the next section. Your query is sent to third-party AI providers. Search queries are not stored in our database, and neither is an Ask you make from the command palette. The Ask research page is different: asking there opens a saved session, and the questions, the answers, and the documents those answers cited are stored against your account for 90 days.
  • Payments. Stripe processes checkout and payment details when billing is available. We store Stripe customer, checkout, subscription, and price identifiers, subscription status, entitlements, billing-period dates, and limited invoice metadata. We do not receive or store complete card numbers or security codes.

What happens to member search and Ask questions

This is the disclosure a procurement or infosec review will ask for, so it is stated plainly. When you use archive search or Ask, your text leaves our infrastructure:

  • Search. Your query is sent to Jina AI to produce the embedding used for retrieval. If the query contains no Chinese characters, it is first sent to DeepSeek to be expanded into a Chinese search query.
  • Ask. Your question, together with the archive excerpts retrieved for it, is sent to DeepSeek to generate the answer.

DeepSeek is operated from the People’s Republic of China, so member query and question text is processed there. That is a deliberate design choice about Chinese-language quality and cost, and it is disclosed rather than hidden. Both providers process this text under their own published API terms: we hold no separate data-processing agreement, no commitment that your text will not be used for model training, and no data-residency commitment with either of them. Do not enter client names, confidential deal information, or personal data into search or Ask.

What we keep afterwards

What those providers received is one thing. What we keep is another, and it depends on what you did.

  • A search. Not stored. We keep no record of the query text at all. Search queries do travel as part of the request URL, so they can appear in ordinary hosting request logs. Of the two boxes, search is the more exposed one.
  • A one-off Ask. Not stored. This is the Ask box in the command palette: the question and the answer are returned to your browser and neither is written to our database. One text-free record is always written, your plan’s counter of Ask requests used, and a second may be, depending on which of our pages you asked from: the product event listed above, saying an Ask completed on a given page at a given time. Neither carries a word of what you asked. Ask questions are sent in the body of the request rather than in the URL, so unlike searches they do not appear in request logs.
  • A saved Ask session. Stored. The Ask research page works by saving: the first question you ask there opens a session, which is how that page can be re-opened, added to and exported. It says so on the page, both before you start and in the session header afterwards, which also states how long the session is kept. We keep the text of every question in the session, the full text of every answer, and the documents each answer cited, linked to your account. There is no separate save button to avoid, so if you would rather a question were not stored, ask it in the command palette instead, or delete the session afterwards.

A saved session is kept for 90 days from the moment the session was created, not from your last question, so a session you keep adding to is still deleted 90 days after it began. The deletion is performed by a job that runs on our collection schedule, five times a day Beijing time, so a session goes on the first run after it expires: hours past the boundary, not days. You can also delete any session yourself, at any time, from the session page. That removes the session and every question and answer in it immediately. As with any deletion here, our database keeps seven days of point-in-time recovery history, so a deleted session becomes unrecoverable only once that window has passed.

Saving a session changes what we keep. It does not change what those providers saw. Your question and the retrieved archive excerpts went to DeepSeek, and your question went to Jina AI, at the moment the answer was generated, under the terms described above: no data-processing agreement, no commitment that your text will not be used for model training, no data-residency commitment. Deleting a session, or letting it expire, does not reach back into either provider. That is why the warning in the previous paragraph is the one that matters: it applies whether or not you save the session, because the transfer has already happened by then.

Published source material and headlines from public Chinese sources are also translated by DeepSeek and embedded by Jina AI as part of normal collection, independently of anything you type.

Why we use it, and on what basis

Where the GDPR or a comparable regime applies, these are the lawful bases we rely on.

  • Send the briefing and product updates you asked for: consent, which you can withdraw at any time.
  • Create your account, sign you in, apply entitlements, and run search, Ask, and the API: performance of a contract with you, or steps taken at your request before one.
  • Store a saved Ask session, meaning its question text, its answer text, and the documents cited, so that you can re-open, continue and export your own research: performance of a contract with you. Storage follows the surface you choose: an Ask from the command palette is not stored at all, a session is stored because the Ask research page is a saved workspace and you used it, and you can delete a saved session at any time. We hold it for 90 days because that is how long the feature is useful over, not because anything requires us to keep it.
  • Answer feedback and support messages: performance of a contract for members, legitimate interests in responding to everyone else.
  • Rate limiting, abuse prevention, and keeping the service available: legitimate interests in protecting the service.
  • Measure aggregate acquisition, activation, retention, and reliability: legitimate interests in operating and improving the site.
  • Accounting, tax, fraud prevention, and legal requests once billing exists: legal obligation.

Sub-processors

Every third party that receives personal data or user content, what it receives, and where it processes it. This includes the parties your browser contacts directly, which see your IP address and user agent even though we never receive that data ourselves. Link to this list as china-snapshot.com/privacy.html#subprocessors; changes will be posted here with a new effective date.

  • Neon (database and identity records) receives account, consent, entitlement, usage, product-event, feedback, and support rows. Processed in the United States; the identity endpoint runs in AWS us-east-1.
  • Vercel (hosting, serverless functions, analytics) receives request metadata including IP address and user agent in ordinary platform logs, request URLs, and cookie-free Web Analytics counts. Global edge network operated from the United States.
  • Resend (email) receives recipient addresses, outbound message content, delivery and complaint events, and every inbound message and attachment sent to a china-snapshot.com address. Our sending domain is verified in the Tokyo region (ap-northeast-1).
  • Google (Gmail) receives forwarded inbound mail in full, including attachments, in the operator’s personal mailbox. Processed on Google infrastructure.
  • CARTO serves the optional reference basemap on the member regions map. That layer is off by default; if you switch it on, your browser requests tiles directly from its content delivery network, so CARTO receives your IP address and user agent. It receives no account or query data, and nothing is requested from it while the layer stays off.
  • DeepSeek receives member search queries for Chinese expansion, member Ask questions together with the retrieved archive excerpts, and public source headlines for translation. Processed in the People’s Republic of China.
  • Jina AI receives member search queries for embedding, and public source text for embedding and article extraction. Requests are sent to the provider’s global API endpoints. Jina AI does not give us a contractual data-residency commitment, so do not treat this processing as confined to one country.
  • GitHub stores source code and the public generated data files. No personal data is published there.
  • Stripe processes checkout, payment methods, subscriptions, invoices, fraud-prevention signals, and billing communications. We receive provider identifiers and subscription state rather than complete card details.
  • Google AdSense serves the labelled advertising unit on the free public Snapshot. When the unit is requested, Google and participating advertising providers may receive your IP address, user agent, page URL, consent signals, and cookie or other device identifiers; they may place or read cookies and use web beacons for ad delivery, fraud prevention, frequency control, reporting, and, where you consent, personalisation. The unit is not requested for a confirmed Professional member or operator. Read how Google uses information from partner sites.

Subscriber email addresses and billing data are not sent to DeepSeek or Jina AI. Member query text is sent only as described above.

Cookies and local storage

One HttpOnly session cookie, cs_session, keeps you signed in. It is strictly necessary and is not used for advertising. Your language choice and scroll position are kept in your browser’s local storage. Vercel Web Analytics sets no cookie. On the free public Snapshot, Google and its advertising partners may use cookies, local storage, web beacons, IP addresses, and other identifiers as described above. Visitors in the EEA, UK, and Switzerland are shown Google’s certified consent message with “Consent”, “Do not consent”, and “Manage options” choices. You can revisit those choices through the privacy controls Google makes available on the page.

Email choices

Briefing email is opt-in. You can unsubscribe using the link in a message or contact privacy@china-snapshot.com. Unsubscribing stops marketing delivery but may not erase the record needed to honor the suppression request.

Retention

Two automatic deletions are implemented today: request-protection hashes are removed after two days, and saved Ask sessions are removed 90 days after the session was created. Everything else is kept until it is no longer needed for the purpose it was collected for, or until you ask for it to be deleted, and that deletion is currently performed by hand by the operator. These are the maximum periods we intend to enforce automatically, and which we will apply on request in the meantime:

  • Saved Ask sessions, including question text, answer text and citations: 90 days from the session’s creation, or immediately when you delete the session. Enforced, not intended.
  • Briefing list rows: 24 months after you unsubscribe.
  • Feedback, support, and forwarded inbound mail: 24 months after the request is closed.
  • Site events and product events: 14 months.
  • Account, entitlement, and consent records: while the account exists, then the period required for accounting and dispute purposes once billing starts.

The database keeps seven days of point-in-time recovery history, so a deletion becomes irreversible only after that window passes. Copies held by Resend and in the operator’s forwarded mailbox are deleted on the same request.

Security

Access is restricted through provider controls, server-side APIs, least-privilege database roles, and row-level policies. Credentials live only in encrypted deployment configuration, and API keys are stored as hashes. No internet service can guarantee absolute security.

Your requests

Under Hong Kong’s Personal Data (Privacy) Ordinance, you may request access to and correction of personal data we hold about you. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent at any time without affecting processing already carried out. Send requests to privacy@china-snapshot.com. Saved Ask sessions are the one thing you can delete yourself, from the session page, and that deletion runs immediately. Beyond that there is no self-service export or deletion tool yet: the operator fulfils requests by hand across the stores listed above and aims to respond within 30 days. We may need to verify your identity, but please do not send identity documents unless we ask for them, because mail to our published addresses is stored and forwarded as described in “What we collect”. You may also complain to your local data protection authority.

International transfers

Data reaches the United States (Neon, Vercel, GitHub, Google, and Stripe), Japan (Resend’s verified sending region), and the People’s Republic of China (DeepSeek). Advertising and optional map resources are served from global content delivery networks, so the edge location that sees your IP address for those requests depends on where you are. If you are in the EEA, the UK, or Switzerland, those are transfers outside your jurisdiction, and the transfer to the People’s Republic of China is not covered by an adequacy decision. We use the contractual and transfer mechanisms made available by each provider where applicable and assess providers before adding them. Contact us if you need information about the mechanism relevant to a particular transfer. No transfer mechanism can remove the risk that a foreign authority may lawfully request data in its jurisdiction.

Not professional advice

China Snapshot publishes market data, translated primary sources, and machine-generated interpretation. It is not investment, legal, tax, accounting, or other professional advice, and no part of this notice or the service should be relied on as such. See the Terms of Use.

Changes

Material updates, including any change to the sub-processor list, will be posted here with a new effective date.