Privacy Policy
Last updated: 2026-08-17
The Link ("we," "us," or "our") is operated by MasonX / TimeToRaid, whose operating entity is G.M Software Technology Co. Ltd. (湖州瑰眸软件科技有限责任公司; Unified Social Credit Code: 91330502MA2JLQG804). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we retain it, and what rights you have. Please read it carefully before using our services.
This policy applies to: The Link Windows desktop application, The Link (灵可The Link) mobile companion app (iOS / Android / HarmonyOS NEXT), and The Link website (linkactivate.com).
1. Data We Collect
We collect the following categories of personal data:
Account & Authentication Data
- Phone number: collected when you register or log in via SMS one-time password (OTP). It is stored as a verified sign-in identity in our PostgreSQL database, with database-level access controls and encryption at rest. It may also associate a purchased license and devices, and is never displayed publicly in the community (only display names and avatars are public).
- Steam ID and public profile: collected when you sign in with Steam or verify ownership of a Steam purchase. We store the public 64-bit Steam account ID as the stable sign-in identity and may store the public persona name, avatar, and profile URL for display. Steam sign-in does not itself prove or grant a software entitlement; purchase ownership is checked separately.
- Email address: collected when you request a passwordless email sign-in link or code. It is stored as a verified sign-in identity only after successful verification.
- Google sign-in profile: when you choose Google sign-in, we store Google's stable account subject identifier and may store the verified email status, email address, display name, avatar, and locale returned in the signed ID token. We do not use a matching email address alone to merge accounts.
Device & Technical Data
- Device identifier (device_id): a hardware-derived identifier generated by The Link desktop application when it first runs on your PC. Used to enforce the one-active-PC-per-license model. We store the first-bind time, last-seen timestamp, software version, and channel (Standard/Beta/Legacy).
- Mobile install identifier: a random installation ID generated locally by The Link mobile app the first time it's needed (not necessarily at the exact moment the app first launches). It initially identifies only this one installation on this one phone, but becomes linked to your account once pairing succeeds — so it isn't accurate to call it wholly unrelated to your identity. When you pair with a desktop by scanning its QR code, this identifier is sent to our servers together with the one-time QR pairing code; it's sent again whenever the app refreshes its sign-in state, so we can recognize and manage your paired devices.
- IP address: collected in server logs when you access our API or website. Retained for up to 30 days for security and abuse prevention.
- API request metadata: server access logs may record the endpoint and query details requested alongside your IP address. For the public model catalog, this can include model search terms, filters, model IDs viewed, and download requests. These logs are retained for up to 30 days for security and abuse prevention; they are not used for advertising or cross-service tracking.
- Clipboard: when a text field is on screen in the mobile app (for example, typing your PC's IP address manually, submitting feedback, or signing in with your phone number), the system input component reads the clipboard's content description — whether it currently holds pasteable text — in order to decide whether to offer you a "Paste" action. This read happens transiently in local device memory: it is never persisted and never uploaded to our servers, and it is not used for device fingerprinting or profiling. The clipboard's actual text is read only when you tap "Paste" yourself, at which point it is placed in that field and handled under whichever section of this policy covers that field.
Public Model Library & User Submissions
- Model submissions: motion models (configuration files) you voluntarily submit to the public model library, including associated metadata (title, description, tags, and thumbnail image). Every submission is manually reviewed; only approved submissions become publicly visible and downloadable.
- Likes and bookmarks: records of which public models you have liked or bookmarked. They provide personalized state and public aggregate counts. Model authors can see aggregated new-like counts for their own models, but other users are not shown the identities of people who liked a model.
- Creator profile: display name, avatar image, and social links you voluntarily provide on your creator profile page. Publicly visible.
- Safety interactions: model reports and creator blocks you submit, used for moderation and to hide every model from blocked creators in your public library.
Session & Cookie Data
- Website sign-in identities: when you sign in with Steam, phone, email, or Google, we store the provider's stable account identifier, verification time, and display name and avatar when available. Multiple sign-in identities can connect to the same The Link account. We do not retain Google access or refresh tokens solely for website sign-in.
- Website session cookie: a Secure, HttpOnly cookie named
__Host-link_sessioncontaining a random opaque session token. The server stores only a hash of the token and records session creation, recent activity, and coarse device, IP-country, and network information used to detect unusual sign-ins. It authenticates protected requests and is not used for advertising or cross-service tracking. - Authentication security records: one-time sign-in challenges record expiry and use/attempt state. Where delivery applies, they also record its outcome and a provider request identifier when available. Phone and email abuse controls store an HMAC-derived network quota key rather than the full source IP in the challenge record. These records do not contain the plaintext verification code, magic-link token, or session token.
- Short-lived authentication cookies: Secure, HttpOnly cookies named
__Host-link_oauthand__Host-link_emailbind an OAuth/OpenID redirect or email magic link to the browser that started it. They expire after at most 10 minutes and are not used for advertising or cross-service tracking.
Camera & Motion Data
- The Link desktop application processes video streams and the raw pose coordinates and motion frames needed for real-time recognition entirely on your local device. No video frames, raw pose landmarks, or biometric data are transmitted to our servers. All AI inference runs locally; aggregate workout records produced by a recognition session are covered separately under "Mobile Workout Data" below.
- Mobile camera and microphone (iOS, Android, and HarmonyOS NEXT): when you actively use the "phone as camera" or related voice feature, your phone captures video/audio in real time and sends it only over a routable local-network connection, directly to your own paired PC, for local pose recognition and voice processing. The LAN media channel does not currently use TLS. Camera and microphone access is requested only when you use the corresponding feature. This video/audio is never uploaded to our servers — our servers never see its contents, and we do not perform facial or voice recognition on it.
- Camera orientation sensor: During wireless-camera streaming, the Android app reads the platform orientation sensor; the HarmonyOS NEXT app reads the gravity sensor first and uses the accelerometer only when gravity data is unavailable; and the iOS app reads accelerometer data through Apple Core Motion. These readings are used only on the phone to correct the orientation of video frames sent to your PC. On HarmonyOS NEXT, the app subscribes to the relevant sensor only while the app is in the foreground and wireless-camera streaming is active; the subscription stops when streaming stops, the app enters the background, or you withdraw privacy consent. Android also uses its orientation sensor to correct frames during on-device QR scanning; the iOS QR scanner uses Apple AVFoundation directly and does not need motion data. All sensor readings are processed transiently in local phone memory and never leave the phone; only the orientation-corrected video frames are sent to your paired PC over the local network. Sensor readings are never persisted or uploaded and are not used to fingerprint your device or build a user profile.
Local Saved-Model Library Sync Between Phone and PC
- When you actively choose "Sync All Models" in the mobile app, The Link directly exchanges your saved motion-model configurations between the phone and its paired desktop over a local-network WebSocket connection. Content is sent as chunked compressed archives; file hashes, sizes, modification times, and transfer-progress metadata are used to validate and coordinate the transfer.
- The model configurations and sync metadata are handled in each device's app-private storage. The local model-library sync feature does not upload them to our servers. If you separately use the private cloud model library or submit a model to the public library, that content is instead governed by the "Public Model Library & User Submissions" and "Data Retention and Deletion" terms in this policy.
Mobile Workout Data
- Once you sign in / link your PC account on the mobile app, the complete session record generated at the end of a desktop recognition session is synced to our cloud servers. It includes a session identifier, start time, duration, mode and game name, average frame rate and latency, total and dropped frames, active/walking/engaged time, steps, jumps, best combo, estimated calories, and data version. The server also uses it to maintain aggregate motion statistics, XP, level, and reward-settlement state. This data provides cross-device workout history and statistics and synchronizes account progress, levels, and rewards. Without an account link, it remains on your local devices and is never uploaded.
Feedback
- Text content you voluntarily submit via the mobile app's "Feedback" feature, along with any contact information you optionally provide, is sent to our servers for customer support and product improvement. Submitting feedback does not require being signed in.
2. How We Use Your Data
We use the data we collect to:
- Authenticate you through Steam, phone OTP, passwordless email, or Google, and separately verify any entitlement to use The Link.
- Enforce license terms: specifically, the one-active-PC-per-license limit. Your device_id lets us determine whether a new device activation is permitted.
- Provide the public model library: review, store, and display submitted models; count downloads and likes; provide authors with aggregated like notifications; and process reports and creator blocks.
- Operate and improve the service: aggregate, non-personal usage statistics help us identify performance issues, prioritize feature development, and fix bugs. We do not build individual behavioral profiles for marketing purposes.
- Ensure security and prevent abuse: IP addresses and request logs help us detect brute-force attacks, license abuse, and community spam.
- Respond to legal requests: in the event of a valid legal demand (court order, subpoena, law enforcement request), we may disclose data as required by law.
We do not use your data to serve targeted advertising, sell it to third parties, or share it with data brokers.
3. Third-Party Sharing
We share limited data with the following third parties:
Steam (Valve Corporation) When you choose Steam website sign-in, your browser is redirected to Steam's OpenID service. Steam returns a signed assertion containing your public Steam ID; our server validates it with Steam and may request your public persona name, avatar, and profile URL. If you separately verify a Steam purchase, we send the provided Steam authentication ticket to the Steam Web API to confirm ownership of App ID 1285430. We do not share your phone number, email address, Google identity, or The Link account data with Steam.
Google Sign-In (Google LLC)
When you choose Google sign-in, your browser is redirected to Google's authorization service and our server exchanges the one-time authorization code with Google. We request only the openid, email, and profile scopes.
- Data received: Google's stable subject identifier, email address and verification status, display name, avatar URL, and locale when available
- Purpose: authenticating you and displaying your chosen Google profile information on your The Link account
- Retention: we retain the verified identity/profile fields described in Section 1, but do not retain Google access or refresh tokens solely for website sign-in
- Links: https://policies.google.com/privacy | https://myaccount.google.com/permissions
Resend Email Delivery (Plus Five Five, Inc.) When you request passwordless email sign-in, our server uses Resend's HTTPS email API to deliver the one-time link and fallback code.
- Data shared: your email address, the one-time login link and code, their validity period, and ordinary delivery metadata
- Purpose: delivering the email needed to sign in
- Scenario: whenever you request an email sign-in message
- Method: server-side API call (HTTPS)
- Privacy policy: https://resend.com/legal/privacy-policy
Tencent Cloud SMS (Tencent Cloud Computing (Beijing) Co., Ltd.)
When you request an SMS verification code on the sign-in or registration page, we send it to your phone number via the Tencent Cloud SMS API (sms.tencentcloudapi.com).
- Data shared: your phone number, the verification code, its validity period, and the timestamp of the request (as part of the request context)
- Purpose: delivering the SMS code needed to sign in or register
- Scenario: whenever you request an SMS verification code
- Method: server-side API call (HTTPS)
- Privacy policy: https://cloud.tencent.com/document/product/301/11470
Google ML Kit Barcode Scanning (Google LLC; Android only) The "scan the desktop's QR code to pair" feature in The Link Android app uses Google ML Kit's Barcode Scanning model, which ships bundled with the app and runs its recognition on your device. The camera image content and the decoded QR value itself are never uploaded to Google or any other third-party server. However, the SDK does send Google its own diagnostic and usage-analytics telemetry whenever it runs. The iOS app instead uses Apple AVFoundation's on-device QR scanner; it does not include Google ML Kit or send this telemetry to Google.
- Data shared: technical telemetry Google uses for its own diagnostics and usage analytics — device and app information, package name and version, a per-install identifier that is not intended to uniquely identify a user or specific device, performance metrics (such as latency), API configuration (such as image format and resolution), input/output data sizes, the feature version, feature event types (such as initialization, detection, and resource release), and the error codes for those events — not the camera image or the decoded QR result
- Purpose: recognizing the QR code to complete phone-to-desktop pairing; the diagnostic data is used by Google to maintain and improve its SDK
- Scenario: when you tap "Scan to connect to desktop" in the mobile app
- Method: QR recognition is processed on-device; diagnostic telemetry is sent by the SDK to Google over HTTPS
- Links: https://developers.google.com/ml-kit/terms | https://developers.google.com/ml-kit/android-data-disclosure | https://policies.google.com/privacy
HarmonyOS System QR Scanning (Huawei Scan Kit; HarmonyOS NEXT only) When you actively choose "Scan to link desktop account," the app opens the HarmonyOS system Scan Kit interface and restricts input to QR codes. QR camera images are captured and decoded on the device; The Link does not retain those images or transmit them in its own network requests. After decoding, the short-lived one-time pairing credential and the random mobile installation identifier described above are sent to our server over HTTPS to complete the account link you requested. "On-device decoding" therefore does not mean the pairing credential remains on the phone: submitting that credential to our server is required to link the account.
Apple and Microsoft (future) If and when iOS App Store or Microsoft Store purchase verification is implemented in a future phase, we will update this policy to describe the data exchange with those platforms. At the time this policy was last updated, these integrations are not yet active.
Infrastructure Providers Our backend runs on a dedicated cloud server that we control and for which Tencent Cloud provides the infrastructure; the access, receiving, and storage regions are described in Section 4. We do not use third-party cloud analytics, CDN user tracking, or A/B testing platforms that collect personal data. Server logs are retained in our production backend and service storage.
Legal Authorities As described in Section 2, we may disclose data in response to valid legal demands. We will notify you of such disclosures unless prohibited by law.
4. Cross-Border Processing for Users in Mainland China
Transfer path and receiving/storage regions When you access The Link website or API from mainland China, the request ordinarily reaches our Tencent Cloud ingress node in Shanghai first; that node may directly serve website pages, static assets, or protected download copies. API requests that require account or other server-side processing are forwarded from Shanghai over a certificate-verified HTTPS connection to our Tencent Cloud production backend in Silicon Valley, United States. The Link's sole authoritative account database (PostgreSQL), primary server-side file storage, and logs are also located in Silicon Valley. The mainland node is therefore an ingress, relay, or mirror; it does not mean that the server-side personal information below is processed or stored only in China.
The overseas production system remains operated and controlled by Huzhou Guimou Software Technology Co., Ltd., the operating entity identified at the start of this policy, and can be contacted about privacy matters at masonx@timetoraid.com. Tencent Cloud supplies the cloud infrastructure in Shanghai and Silicon Valley. Copies of some published model files, public profile material, or download content may additionally be stored in Shanghai for mainland delivery. The authoritative database in Silicon Valley is also backed up daily; one encrypted, restore-validated, non-authoritative disaster-recovery copy is stored in a restricted directory in Shanghai on a rolling 30-day retention window.
Categories and purposes of outbound data Only when you use the corresponding online feature, the following data is transmitted over the public internet to Silicon Valley and stored or processed for the periods stated in Section 5:
- Account, authentication, and device data: phone or email identity, Steam / Google sign-in identifiers and public profile data, The Link account identifier, nickname, avatar and account status, session and authentication-security records, product entitlements and license associations, records of linked desktop and mobile devices, desktop
device_id, random mobile installation identifier, and one-time pairing credential; used for sign-in, account linking, device pairing, license management, and abuse prevention. - Model, search, browsing, and interaction data: private cloud models or public model submissions you upload, creator profile data, search terms, filters, model-view or download requests, and likes, bookmarks, reports, and blocks; used to provide cloud models, the public model library, personalized state, content moderation, and safety features.
- Workout records and account progress: complete workout sessions, aggregate active time, steps, jumps, estimated calories, XP, level, unlocked/equipped rewards, and reward-settlement state after you sign in or link an account; used to show workout history and statistics across devices and synchronize account progress, levels, and rewards. This data may reveal health, physiological status, or activity habits, and unauthorized access or misuse could expose that information. It is handled as sensitive personal information when applicable law classifies it that way. If you do not sign in or link an account, session records remain local and cross-device workout history, progress, and reward synchronization are unavailable.
- Feedback: feedback text and optional contact information you choose to submit; used for support and product improvement.
- Network and technical data: IP address, requested endpoints and query parameters, timestamps, app version, device or channel information, and security logs; used for request routing, troubleshooting, security, and abuse prevention.
Camera images, microphone audio, raw pose/sensor data, and phone-to-PC local model-library sync that Section 1 identifies as local-only are not sent to our servers and are not part of this cross-border transfer. The Steam, Google, Resend, Tencent Cloud SMS, and Google ML Kit processing described in Section 3 remains subject to the recipient, purpose, and linked-policy information stated there; those providers may process data in regions other than Silicon Valley.
Rights, consent, and withdrawal boundaries You may exercise applicable rights to access, copy, correct, delete, restrict, or object to processing as described in Section 6 and contact the operating entity through Section 7. Where consent is the lawful basis and applicable law requires consent specifically for a personal-information export or for sensitive-personal-information processing, separate consent for the export, separate consent for sensitive information, and acceptance of the general privacy policy are distinct matters. Merely displaying this policy or obtaining bundled consent does not replace any legally required separate consent.
Using "Withdraw Privacy Consent" in the Android or HarmonyOS NEXT app stops the app's subsequent network connections and therefore stops subsequent outbound transfers initiated by the app; the effects of sign-out and account deletion are described in Section 5. Withdrawal does not affect processing that was completed before withdrawal and had a lawful basis at that time, and it does not automatically erase data already transmitted; you may make a separate deletion request. If you do not provide data required for server processing, the corresponding online features—such as sign-in/account linking, cloud workout history, cloud or public model libraries, search and interactions, and online feedback—cannot be provided.
Publication of this policy does not replace any legally applicable personal-information protection impact assessment, separate consent, data-export security assessment, standard contract, or personal-information protection certification procedure, and we do not claim completion of any procedure that has not actually been completed.
5. Data Retention and Deletion
We retain your data for as long as your account is active. Specifically:
- The link between your phone number and this account: retained indefinitely while your account exists; this link itself is deleted when you delete your account (or upon your deletion request). Your phone number may still appear in a purchased license/CD-key record or an inert revoked-token stub; public model profile data is deleted by in-app account deletion as described below.
- Device records (device_id): retained for up to 24 months after the device's last-seen timestamp. Records of revoked (unbound) devices are retained for 12 months for audit purposes, then deleted.
- Public model content: while your account is active, your creator profile and approved model submissions remain public until you delete them, delete your account, or an administrator removes them for a policy violation. Pending and rejected submissions are never public.
- Likes, bookmarks, reports, and blocks: retained while your account is active to provide aggregate counts, personalized state, and safety moderation. The identities of people who like, bookmark, or report content are not displayed publicly.
- Website sessions and authentication challenges: sessions expire after 30 consecutive days of inactivity and require re-verification 180 days after the initial sign-in even if active. Tokens rotate periodically and can be revoked immediately when you sign out, remove a device, or we detect unusual activity. A fully inactive session rotation family is retained for up to 30 additional days for security auditing, then deleted. Expired one-time authentication challenges are retained for up to seven days, then deleted.
- Server logs (IP addresses and API request metadata): retained for up to 30 days.
- Third-party sign-in identifiers (Steam ID and Google subject) and email/phone identities: retained while your account exists for sign-in and account linking; disconnected and deleted when you delete the account unless law or anti-fraud obligations require otherwise.
- Mobile workout data: retained while your account exists, for cross-device viewing; see account deletion below.
- Feedback content: retained for support follow-up and product improvement, with no automatic deletion timeline; contact us via Section 7 if you'd like it removed.
What happens when you delete your account in-app: Both the mobile app and the desktop app's settings offer a "Delete Account" option. Once submitted:
- Immediate effect: every Steam, phone, email, and Google sign-in identity is disconnected and deleted, allowing that identity to register a new account; every sign-in token for the account is revoked; private cloud models and workout history are immediately removed from queries and device sync; and your creator profile, all approved/pending/rejected submissions and their public server paths, plus likes, bookmarks, reports, and blocks you created are immediately removed from the service. Revoked sign-in token records may remain as inert, unusable stubs; contact us through Section 7 if you also want those removed.
- Public submission files are moved out of our writable CDN origin before the deletion request succeeds. Copies already downloaded by another user cannot be recalled, and an independent CDN edge may serve a previously cached copy until we purge it or its cache entry expires.
- We retain the account shell plus the removed private cloud models and workout history (including the model files themselves on our servers) internally for up to 30 days, solely for our own abuse-investigation and operational-security purposes, after which they are permanently and physically erased. This 30-day window is not a self-service "recover my account" feature — deletion takes effect immediately and is irreversible; this period exists solely for our internal review of anomalous activity.
- Models saved locally on your phone or computer, including LAN-synchronized copies, are not stored on our servers and are not deleted by in-app account deletion. Delete those files on the corresponding device if desired.
- Your purchased license (CD-key entitlement) is not cleared by account deletion. It remains bound to your phone number or Steam ID as a record of your purchase. Signing in again creates a fresh empty account with none of the old private cloud data, public submissions, or interaction records; the purchased license continues to work. Contact us below if you also want the purchase record removed.
How to request deletion (for anything the in-app option doesn't cover): Email masonx@timetoraid.com with the subject line "Data Deletion Request" and include your The Link account ID or the sign-in identity you used. We will process your request within 30 days and confirm by email when deletion is complete.
6. Your Rights
Depending on your country of residence, you may have the following rights regarding your personal data:
All users:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate data.
- Deletion: request that we delete your personal data (see Section 5 for process).
- Portability: request a machine-readable export of your public model submissions and creator profile.
- Consent and system-permission controls: in the Android or HarmonyOS NEXT app, open "Settings > Privacy & Permissions" to view this policy, open the system permission controls, or choose "Withdraw Privacy Consent." Withdrawal immediately disables the app's network connections and related data processing and returns the app to its privacy notice. On HarmonyOS NEXT, camera, audio, and orientation-sensor processing stops when you leave the streaming screen or the app enters the background; withdrawal prevents those features from starting again until you consent. In-app privacy consent does not itself grant system permissions. On HarmonyOS NEXT, camera access is requested only when you start wireless-camera streaming or QR scanning, and microphone access is requested only when the paired PC asks for the phone microphone and you continue. You can manage or disable those permissions at any time in system settings. The declared normal accelerometer permission is used only as a gravity-sensor fallback for foreground camera-stream orientation and does not create a separate runtime authorization prompt.
EU/EEA residents (GDPR): in addition to the above, you have the right to object to processing, restrict processing, and lodge a complaint with your national data protection authority.
China residents (PIPL): in accordance with China's Personal Information Protection Law, you have the right to access, copy, correct, delete, and transfer your personal information. You may withdraw consent at any time. To exercise these rights, contact us at the address in Section 7.
California residents (CCPA): you have the right to know what personal information we collect, to request deletion, and to opt out of sale. We do not sell personal information.
We will respond to all rights requests within 30 days of receipt. In some cases we may need to verify your identity before processing your request.
7. Contact
For privacy inquiries, rights requests, or data deletion requests:
Email: masonx@timetoraid.com Subject line: "Privacy Request — [Your Topic]"
We aim to respond within 5 business days. For formal rights requests (GDPR/PIPL), we will respond within 30 days as required by law.
Effective date: 2026-08-17. MasonX / TimeToRaid (operating entity: Huzhou Guimou Software Technology Co., Ltd.) reserves the right to update this policy. If the purpose or method of processing, or the categories of personal information processed, change materially, we will provide a prominent notice such as an in-app dialog and obtain renewed consent where required by law.