Privacy Policy / 隐私政策
Last updated / 更新日期:2026-09-13
Developer / 开发者:何宇涛
Privacy contact / 隐私联系邮箱:brooklyn509@hotmail.com
Google account linking (Android 2.0.9 and later): You can continue watching as a guest. Before starting a new membership purchase, we ask you to link a Google account to your current MagiDrama user ID. With your Google sign-in authorization, our server verifies a short-lived identity token, stores a hash of your Google account identifier and an encrypted copy of the verified email address, and displays only a masked email hint. From Android 2.0.11, we also store your Google-provided display name and profile picture URL after verified sign-in, to display your profile in Account and help authorised support staff identify the correct account. These display fields do not determine account ownership. They refresh when you link, recover or explicitly sync your Google profile; if unavailable, a local placeholder is used. Displaying the photo requests it from Google image servers without sending a page referrer. Name and photo URL are removed together with the Google link when account deletion is completed. We do not receive your Google password and do not retain the raw identity token. Linking does not create a second MagiDrama account. After reinstalling or changing devices, verifying the same linked Google account restores access to the original user ID, membership and server-side viewing history; it does not merge another guest account's records. Account recovery is separate from Google Play purchase restoration and the Google accounts used may differ. Signing out removes this installation's access without deleting the account. The Google link is removed when an account deletion request is completed, subject to the retention exceptions described below.
Privacy Policy
This policy describes how MagiDrama (可乐剧场), provided by 何宇涛, processes information when you use our Android application (package com.movie.shaweng.xique) and related MagiDrama websites. Contact us at brooklyn509@hotmail.com about privacy, access, correction or deletion.
1. Information we process
- Account and installation identifiers. The current Android client creates a random installation identifier and sends it to our server to establish a device account. We process account identifiers, session credentials, account-transfer information and language settings to recognise your account, protect access and associate your membership and history. A device account is still an account even if you do not enter a name or email.
- Device and network information. Requests include IP address and user-agent information. We process device model, operating system and browser/WebView versions, app version, language and time zone for compatibility, security and service analysis. Country or region may be supplied by our network infrastructure from the connection; it is approximate, not precise GPS location.
- Viewing and activity. We record the dramas and episodes you play, playback progress and times, favourites, likes, chosen interests, searches, page and button interactions, and notification interactions. These support viewing history, resume playback, recommendations, service operation and statistics.
- Purchases and subscriptions. We process product and plan identifiers, purchase tokens, order references, amount and currency, transaction times, payment and subscription status, renewals, refunds and membership expiry. Google Play processes Android payments. The current client does not ask you to give us your full card number, card security code or Google password. Google Play sends purchase and subscription updates to our server so we can verify and maintain your access.
- Support and diagnostics. When you contact us, we process your message, subject, optional contact details and related account, drama or order information. Playback diagnostics can include the episode, error, source type, playback position, player version and network type. Do not send passwords, complete card details, private keys or purchase tokens in support messages.
- Referrals and campaign information. We process invitation/share tokens, referring campaigns, link parameters and click identifiers when provided. They support attribution and the inviter's assigned library, paywall and language experience, as well as promotion analysis.
2. Purposes and choices
We use information to deliver videos, maintain your account, verify payments, provide membership, restore purchases, handle support, secure the service, measure use and improve recommendations. Selecting interests, providing a contact address and sending feedback are optional. Account identifiers and information needed to fulfil a feature are required for that feature.
Local app storage and website cookies/local storage keep installation, session, language and preference information. Clearing storage or reinstalling can change local identity or remove local settings; it does not itself delete server records or cancel a subscription.
The current website and Android client offer optional campaign measurement. You can change it in Account → Campaign measurement settings; landing pages offer Measurement settings. The current server-side promotion integration also checks this choice before sending. Operational records such as viewing history, security, library access and order verification remain necessary for those features. AdMob has separate ad privacy choices.
3. Recipients and third-party services
- Service infrastructure: our hosting, network and video delivery providers process requests, IP addresses and technical information needed to deliver and secure the service. Authorised operational personnel handle support and records necessary for their work.
- Payments: Google Play handles Android purchases and subscription management. Where a MagiDrama website offers Stripe or PayPal checkout, the selected provider processes the payment under its own policy. Those website checkout options are not offered by the current Android client's payment flow.
- Campaign measurement: when configured and enabled, Meta Pixel and Meta Conversions API can receive consented page, playback, checkout and verified purchase/subscription events, available Meta click/cookie identifiers, hashed account identifiers, content and transaction information. Native events are marked as app events, not website activity. Hashing is not anonymisation. A random campaign token restores the selected drama/episode through Google Play Install Referrer or an app link; it does not recover identity or grant membership. Newly acquired accounts retain their assigned library. We do not fingerprint devices to match installations. Routine campaign click identifiers and event matching data are cleared after 90 days when maintenance runs; essential library assignments, deduplication and financial records are retained for their stated purposes. Revocation stops queued optional transmissions; it cannot recall events already sent.
- Legacy Android versions: older versions, including the 1.6.x generation, integrated Google advertising/Firebase and Facebook login, with advertising mediation components such as Pangle, Meta, AppLovin, Vungle, ironSource, LINE and Unity. Depending on the components actually enabled, permissions and your use, those services can process advertising/device identifiers, IP and device information, ad interactions and diagnostics; a third-party sign-in can provide profile or email information you authorise. Android 2.0.3–2.0.5 did not include those SDKs. Starting with 2.0.6 (versionCode 65), the new client integrates Google AdMob and its User Messaging Platform for the app-only limited-free feature; it does not reintroduce the legacy social-login or mediation SDKs.
- Limited-free and advertising: when enabled for your app/account, Google AdMob can process IP-based approximate location, device/advertising identifiers, app interactions and diagnostics for advertising, measurement and fraud prevention. We request ads only when Google’s consent tooling permits requests; non-personalised ads can still process data. Where required, you can reopen “Ad privacy choices” in Account. Rewarded ads require your explicit choice. We record promotion/episode access, opaque reward challenges, signed reward transactions, ad interactions and estimated ad revenue separately from purchase orders. App authenticity verification uses Google Play Integrity (app/version/signature, licence and device-integrity verdicts). Raw integrity tokens are not retained. Native access sessions expire after one hour; routine ad interaction diagnostics are removed after 90 days when scheduled maintenance runs. Reward and unlock records remain for entitlement verification and fraud prevention, or until a verified deletion request is processed. Google handles its own retention under its policy.
- Legal and security purposes: information may be disclosed where required by applicable law or necessary to address fraud, security incidents and disputes. Third-party sites you choose to open apply their own privacy practices.
Related provider policies: Google, Meta, Stripe and PayPal. Provider availability and data use differ between the website, legacy app and current app.
4. Security, storage and retention
The current Android client uses HTTPS for service requests. Access controls, restricted credentials and server-side purchase verification help protect records. No transmission or storage system is completely risk-free. Service providers may process information outside your country; the protections and legal requirements can differ.
Account, viewing and preference information is retained while needed to provide the associated service, or until an applicable deletion request is processed. Support and diagnostic records are kept as needed to investigate the request or fault. Transaction, refund and security records may be retained for accounting, fraud prevention, disputes and applicable legal obligations even after other account data is removed. Retention depends on the record and purpose, rather than one universal period. Contact us for information about retention applicable to your records.
5. Request account and data deletion
You do not need to install or log in to the app to start a request. Email brooklyn509@hotmail.com with the subject “MagiDrama account and data deletion”. State whether you want the whole account deleted or particular data removed.
If available, include the account ID shown in Account, or a previous support reference, to help us locate your records. If you cannot access your account, describe the situation; we will work with you on proportionate ownership verification. Never send your password or complete payment credentials.
In the app, go to Account → Request data deletion. The request enters a seven-day cancellation window and can be withdrawn from the same area while pending. The displayed scheduled date is a processing schedule, not confirmation that every record has already been deleted. You may also email us to follow up or request assistance.
Deletion covers the account and associated non-required personal data, including viewing history, saved preferences and support data. Records that must be retained for the purposes in section 4 are restricted to those purposes. We can explain applicable exceptions when handling your request. Copies in backups may remain until the relevant backup is rotated out; they are not intended for ordinary active use.
Deleting an account, clearing app data or uninstalling does not cancel Google Play renewal or automatically issue a refund. Manage or cancel renewal in Google Play subscriptions. Cancellation is not a prerequisite for contacting us about deletion.
6. Children, requests and policy updates
The service is not directed to children below the minimum age required by applicable local law. If you believe a child has provided personal information without appropriate permission, contact us so we can investigate and address it.
You may contact us about access, correction, deletion, objections or other privacy rights available where you live. We may need limited information to verify that a request concerns your account. We will update this page when our practices change and provide additional notice or obtain consent where required. The date above identifies this revision.
Google 账号绑定(Android 2.0.9 及之后版本):你仍可作为游客观看;开始新的会员购买前,需要将 Google 账号绑定到当前 MagiDrama 用户 ID。经你授权 Google 登录后,服务器验证短期身份令牌,保存 Google 账号标识的哈希值及加密后的已验证邮箱,只在界面显示遮挡后的邮箱提示。从 Android 2.0.11 开始,还会在验证登录后保存 Google 提供的昵称和头像网址,用于个人中心展示,以及授权客服在后台识别账号;这些展示资料不用于判定账号所有权。绑定、找回或主动同步 Google 资料时更新;缺失时使用本地默认资料。展示头像时会向 Google 图片服务器请求图片,不发送页面来源信息。账号删除完成时,昵称和头像网址随 Google 绑定信息一并删除。我们不接收 Google 密码,不保留原始身份令牌。绑定不会另建 MagiDrama 账号。重装或换机后,验证同一已绑定 Google 账号,可恢复原 ID、会员及服务器上的观看记录,不会合并另一个游客账号的数据。账号找回与 Google Play 恢复购买是不同操作,使用的 Google 账号可以不同。退出只解除当前安装的访问,不删除账号;账号删除申请处理完成后移除 Google 绑定,但下文说明的必要保留记录除外。
隐私政策
本政策说明何宇涛提供的 MagiDrama(可乐剧场)Android 应用(包名 com.movie.shaweng.xique)及相关网站如何处理信息。隐私咨询、查询、更正和删除请求,请联系 brooklyn509@hotmail.com。
1. 我们处理的信息
- 账号和安装标识:当前 Android 客户端生成随机安装标识并发送到服务器,以建立设备账号。我们处理账号标识、会话凭据、账号迁移信息和语言设置,用于识别账号、保护访问并关联会员和历史记录。即使没有填写姓名或邮箱,设备账号仍然属于账号。
- 设备和网络信息:网络请求包含 IP 地址和 User-Agent 信息。我们处理设备型号、操作系统、浏览器/WebView 版本、应用版本、语言和时区,以支持兼容性、安全和服务分析。网络基础设施可能根据连接提供国家或地区,这是粗略地区信息,并非精确 GPS 位置。
- 观看与使用活动:播放过的短剧和集数、播放进度与时间、收藏、点赞、选择的兴趣、搜索、页面与按钮操作、消息交互,用于观看记录、续播、推荐、服务运营和统计。
- 购买与订阅:商品和方案标识、购买凭证、订单编号、金额与币种、交易时间、支付和订阅状态、续费、退款及会员到期信息。Android 付款由 Google Play 处理。当前客户端不会要求你向我们提供完整银行卡号、安全码或 Google 密码。Google Play 向服务器发送购买和订阅更新,以便我们验单和维护权益。
- 客服与诊断:你提交的消息、主题、选填联系方式及相关账号、短剧或订单信息。播放诊断可包括集数、错误、片源类型、播放位置、播放器版本和网络类型。请勿在反馈中发送密码、完整支付凭据、私钥或购买 token。
- 邀请和推广信息:在链接带有相关信息时,我们处理邀请/分享凭证、来源活动、链接参数和点击标识,用于来源归因、继承邀请人的剧库、付费面板和语言,以及推广分析。
2. 用途与选择
信息用于视频服务、维护账号、支付验证、会员开通、恢复购买、客服、安全、使用统计和推荐改进。选择兴趣、提供联系地址、提交反馈是可选操作;账号标识及完成某项功能所需的信息是该功能运行的必要数据。
App 本地存储及网站 Cookie/本地存储保存安装、会话、语言和偏好信息。清除存储或重新安装可能改变本地身份、移除本地设置,但不会直接删除服务器记录,也不会取消订阅。
当前网站和 Android 客户端提供可选的推广效果衡量,可在“账户 → 推广效果衡量设置”中修改,落地页也有“效果衡量设置”。当前服务端投放集成在发送前同样检查该选择。观看记录、安全、剧库访问和订单验证等记录是相应功能必需的,不随推广衡量关闭。AdMob 广告隐私选择独立设置。
3. 接收方及第三方服务
- 服务基础设施:托管、网络和视频分发服务商处理提供内容和保障安全所需的请求、IP 地址和技术信息。经授权的运营人员处理其工作所需的客服和业务记录。
- 支付:Android 购买和订阅管理由 Google Play 提供。MagiDrama 网站如提供 Stripe 或 PayPal 结账,则由所选服务商按其政策处理支付;当前 Android 客户端的付款流程不提供这些网站结账方式。
- 推广衡量:配置并启用后,Meta Pixel 和 Conversions API 可以接收已同意衡量的页面、播放、结账、已核实购买及订阅事件,以及可用的 Meta 点击/Cookie 标识、哈希账号标识、内容及交易信息。原生应用事件标记为 App,不伪装成网页事件;哈希不等于匿名。随机推广令牌通过 Google Play 安装来源或应用链接还原指定剧目/集数,不用于恢复账号或授予会员。投放带来的新账号保留其指定剧库,不通过设备指纹匹配重装。计划维护运行时,超过 90 天的常规推广点击标识和事件匹配数据会被清理;必要的剧库归属、去重及财务记录按其用途保留。撤回同意会停止待发送的可选回传,不能收回已经发送的数据。
- 旧版 Android:旧版本(包括 1.6.x 系列)集成过 Google 广告/Firebase、Facebook 登录以及 Pangle、Meta、AppLovin、Vungle、ironSource、LINE、Unity 等广告聚合组件。根据实际启用的组件、权限及使用情况,这些服务可以处理广告/设备标识、IP 和设备信息、广告交互和诊断;第三方登录可以提供你授权的资料或邮箱。Android 2.0.3–2.0.5 未集成这些 SDK。从 2.0.6(versionCode 65)开始,新客户端为 App 专属限免功能接入 Google AdMob 及 User Messaging Platform,不重新引入旧版社交登录和广告聚合 SDK。
- 限免与广告:在你的 App/账号启用后,Google AdMob 可处理基于 IP 的概略位置、设备/广告标识、应用交互及诊断信息,用于广告、效果衡量和防欺诈。仅在 Google 同意管理工具允许请求后请求广告;非个性化广告仍可能处理数据。适用时,可从账户页重新打开“广告隐私选项”。激励广告由你主动选择观看。我们分别记录活动/分集权限、不直接包含账号身份的奖励挑战、已验签的奖励交易、广告交互及预估广告收入,不将广告奖励写为购买订单。App 来源验证使用 Google Play Integrity(应用版本/签名、安装许可和设备完整性结论),不保留原始完整性令牌。原生访问会话一小时后失效;计划维护运行时清理超过 90 天的常规广告交互诊断。奖励和解锁记录为权益验证、防欺诈保留,或在核实并处理删除请求时删除。Google 按其自身政策管理保留期限。
- 法律与安全:在适用法律要求,或处理欺诈、安全事件及争议确有必要时,可能披露有关信息。你选择访问的第三方网站适用其自身的隐私规则。
相关服务商政策:Google、Meta、Stripe、PayPal。网站、旧版和当前 App 的服务启用情况及数据使用存在差异。
4. 安全、存储与保留
当前 Android 客户端通过 HTTPS 请求服务。访问控制、受限凭据和服务端验单用于保护相关记录,但任何传输或存储方式都不能保证绝对安全。服务商可能在你所在国家或地区以外处理信息,相应保护和法律要求可能不同。
账号、观看与偏好信息在提供相关服务所需期间保留,或保留至相应删除请求处理完成。客服和诊断记录按处理问题所需保留。交易、退款和安全记录可能为会计、防欺诈、争议处理及适用法律义务而在其他账号数据删除后继续保留,并限制于这些用途。保留期取决于记录及用途,而非所有数据使用同一固定期限;可联系我们了解适用于你的记录的保留情况。
5. 申请删除账号与数据
无需安装 App 或登录即可发起申请。向 brooklyn509@hotmail.com 发送邮件,主题填写“MagiDrama 账号与数据删除”,说明申请删除整个账号还是特定数据。
如方便,可提供个人中心显示的账号 ID 或以前的客服编号,帮助定位记录。无法访问账号时,请说明情况,我们会与你核实必要的账号归属信息。请勿发送账号密码或完整支付凭据。
App 内入口:个人中心 → 申请删除数据。提交后进入七天的可撤销期,待处理期间可以在同一位置撤销。页面显示的计划日期是处理安排,不表示每项记录已经删除;也可以通过邮件跟进或申请协助。
删除范围包括账号及相关的非必要保留个人数据,如观看历史、保存的偏好和客服数据。因第 4 节所述原因需要保留的记录,仅限于相关用途,我们可在处理申请时说明适用的例外。备份中的副本可能保留至相应备份轮换,不用于普通的日常业务访问。
删除账号、清除 App 数据或卸载应用,不会取消 Google Play 自动续费,也不会自动退款。请在 Google Play 订阅管理 中管理或取消续订。取消订阅不是联系咨询或申请删除的前置条件。
6. 未成年人、权利请求与政策更新
本服务不面向低于当地适用法律规定最低年龄的儿童。如果你认为儿童在未获得适当许可的情况下提供了个人信息,请联系我们调查处理。
你可联系我们行使所在地适用的查询、更正、删除、反对处理等隐私权利。我们可能需要有限信息核实申请属于你的账号。数据处理方式变化时会更新本页,并在需要时另行通知或征求同意。页首日期标识本次修订。