Legal

Langxun Privacy Policy

English reference version. Written under the Taiwan Personal Data Protection Act. Explains how Chen Law Cultural Enterprise Co., Ltd. collects, processes, uses and protects User Data and public social data. 中文版(正本)

Version 1.2Effective 2026-10-15
This English version is provided for reference. The Traditional Chinese version at langxun.app/privacy is the governing version; in case of any inconsistency, the Chinese version prevails.

1. Introduction and Scope

Chen Law Cultural Enterprise Co., Ltd. (誠律文化事業有限公司, "we", "us" or the "Company") operates Langxun (浪巡), a social listening and reply-assistance service (the "Service", including the website, the review interface, browser extensions, notification services and related APIs). This Policy explains how we collect, process, use and protect the following two kinds of personal data:

  1. User Data: data of customers who register for, subscribe to or use the Service, and of their team members ("Users").
  2. Public Social Data: the public post content, and the public author information attached to it, that the Service obtains from platforms such as Threads, Reddit and X in order to help Users find relevant discussions ("Public Social Data").

By using the Service, you acknowledge that you have read and understood this Policy. Matters not covered by this Policy are governed by the Taiwan Personal Data Protection Act ("PDPA") and other applicable laws.

2. Data Controller

ItemDetails
NameChen Law Cultural Enterprise Co., Ltd. (誠律文化事業有限公司)
Unified Business No.62107935
Address2F., No. 88, Jinzhuang Rd., Neihu Dist., Taipei City 114, Taiwan
Privacy contactprivacy@langxun.app

3. Categories of Personal Data Collected

(1) User Data

CategoryContentSource
Account dataName or nickname, email address, hashed password or third-party sign-in identifier, company or brand nameProvided by the User
Payment dataSubscription plan, invoice information (tax ID, title, carrier), payment status. Card numbers are handled by the payment provider; we do not store themProvided by the User; payment provider
Brand settingsBrand name, keywords, tone settings, industry rule pack selection, notification channels (Discord, LINE, etc.)Provided by the User
Linked social account dataAccount name, account ID and profile picture URL of the social accounts that the User chooses to connect; for accounts connected through an official API (e.g. the Threads API provided by Meta Platforms, Inc.), the access token issued by the platform (stored encrypted), the granted scopes and the token expiry timeProvided by the User through the platform's own authorization screen
Usage recordsSign-in time, IP address, device and browser type, actions (approve, edit, skip, send), error logsGenerated automatically
Engagement dataURLs of comments sent by the User, and their subsequent public engagement counts (likes, replies)Obtained automatically
Mode A consent and sending recordsSigner's name, the brand's social account name, the version of the terms consented to, time, IP address, browser information, limit and time-window settings; for automatically sent replies, the post URL, content sent, time, result and guardrail eventsProvided by the User; generated automatically

We do not collect or upload Users' social platform passwords or login cookies. For data processing by the browser extensions, see Section 8.

(2) Public Social Data

CategoryContent
Post dataURL, text, publication time and public engagement counts (likes, replies, reposts) of public posts
Author's public informationThe author's public username (handle) and display name

We do not collect: content of private accounts, direct messages, non-public profile information, or biometric features in photos, and we do not attempt to identify the real identity of anonymous authors.

(3) Data obtained through the Threads API

When a User chooses to connect a Threads account through the "Connect Threads account" feature, the Service calls the Threads API on the User's behalf and only within the scopes the User has granted, to obtain the following:

PermissionData obtainedPurpose
threads_basicThe User's own Threads user ID, username and profile picture URLTo show which brand is connected to which account so the User can confirm it
threads_keyword_searchPublic posts returned for keywords that the User has configured: post ID, text, timestamp, permalink, the author's public username, and whether the post has repliesTo list public discussions related to the User's professional field, so the User can decide, one by one, whether to reply
threads_manage_replies, threads_content_publishThe ID and permalink of each reply that the User has approved and the Service has posted from the User's account; publishing quota usageTo post replies that the User has approved, confirm that they were posted, and stay within platform limits
threads_read_repliesPublic replies that other people leave under a reply the User posted through the Service (count and content)To show engagement statistics ("did anyone respond")

The Service does not use the Threads API to obtain direct messages, follower lists, non-public content of the User, or non-public data of anyone else, and does not use it to publish top-level posts, delete content or change account settings on the User's behalf.

4. Specific Purposes and Legal Bases

Categories of personal data (codes under the same Ministry of Justice classification): User Data — C001 identifying an individual, C002 identifying finances, C003 identifiers in government data (e.g. tax ID), C038 occupation, C132 unclassified data (usage records, settings); Public Social Data — C001 identifying an individual (public username), C132 unclassified data (public post content and engagement counts).

DataSpecific purposes (codes per the Ministry of Justice "Specific Purposes and Categories of Personal Data under the PDPA")Legal basis
User Data〇六九 contractual, quasi-contractual or other legal relationship matters; 〇九〇 consumer and customer management and services; 一三五 information and communication services; 一三六 information, communication and database management; 一四八 online shopping and other e-commerce services; 一五七 surveys, statistics and research analysis; 一八一 other business conducted in line with the registered business scope or articles of incorporationPDPA Art. 19(1)(2) (contractual relationship) and (5) (consent)
Marketing communications〇四〇 marketingPDPA Art. 19(1)(5) (consent); Art. 20(2) and (3) (right to refuse marketing)
Public Social Data一三五 information and communication services; 一三六 information, communication and database management; 一五二 advertising or commercial conduct managementPDPA Art. 19(1)(3) (data made public by the data subject or otherwise lawfully disclosed) and (7) (data obtained from generally available sources)

5. Special Provisions for Public Social Data

  1. Purpose limitation: Public Social Data is used only to determine whether a post is relevant to the User's brand and to let the User write a public reply. It is not used for profiling, direct messages or any other non-public contact, and it is not sold, rented or provided to third parties for any other purpose.
  2. Minimization and retention: Candidate posts that the User does not use are deleted within 30 days of retrieval. For posts that have been replied to, only the post URL, the author's public username and the reply record are kept, for engagement statistics and audit, until 90 days after the User's account is closed.
  3. Notice: Under PDPA Art. 9(2)(2), notice under Art. 9(1) may be omitted for personal data made public by the data subject or otherwise lawfully disclosed. We nevertheless explain our processing publicly in this Policy and provide the opt-out channel below.
  4. Opt-out: Authors who do not want their public posts to be processed by the Service may submit a request through our opt-out form (https://langxun.app/opt-out) or the contact in Section 2. Under PDPA Art. 19(2) and Art. 11, we will delete and stop processing and using that author's data and add the account to an exclusion list so that it is not processed in the future.
  5. Platform rules: The Service obtains Public Social Data through official platform APIs (where the User has granted authorization, e.g. the Threads API), third-party data services, or the User's own logged-in browser, subject to each platform's terms. For brands connected through an official API, the Service uses the official API first. Platform terms risks are disclosed in the Terms of Service.

5-1. Special Provisions for Threads API Data

  1. Compliance with Meta's terms: We process data obtained through the Threads API ("Platform Data") in accordance with the Meta Platform Terms and Developer Policies.
  2. Purpose limitation: Platform Data is used only to provide the features the User requested — finding relevant public discussions, posting replies the User has approved, and showing engagement results — and for no other purpose.
  3. No selling, profiling or surveillance: We do not sell, rent or license Platform Data; we do not use it to build profiles of, monitor or track any individual; we do not attempt to re-identify anonymous authors; and we do not use it for ad targeting or provide it to data brokers.
  4. Human approval: Every reply posted through the Threads API is reviewed, optionally edited, and approved by the User, one by one, before it is posted. The Service also enforces a daily cap and posts at most one reply to the same author within 14 days.
  5. AI processing: The text of public posts within Platform Data, together with the User's drafts and editing instructions, is sent to our AI model provider, Anthropic, PBC (through its API service, governed by the Anthropic Commercial Terms of Service) to assess relevance and draft replies. Under those terms, Anthropic may not train models on our Customer Content (including inputs and outputs). Under its published retention policy, inputs and outputs sent through the API are by default deleted from its back-end within 30 days (except where flagged for usage-policy enforcement or where retention is required by law). We have not opted into any program that would allow the provider to train on our data, and we do not submit Platform Data to the provider as feedback or for any training purpose.
  6. No cross-use: Platform Data is not combined with other customers' data and is not shared across workspaces.

6. Period, Region, Recipients and Methods of Use

(1) Period

DataRetention period
Account and brand settingsWhile the account exists; deleted within 90 days after closure
Payment and invoice dataAs required by law: accounting vouchers at least 5 years and accounting books and financial statements at least 10 years after the annual closing procedures are completed (Business Entity Accounting Act Art. 38)
Social account access tokensDeleted immediately when the User disconnects the account, closes their Langxun account, or when we receive a deauthorization or data deletion notice from the platform
Usage records1 year
Mode A consent recordsWhile the consent is in effect, and 5 years after it is withdrawn or the account is closed (as evidence of consent and allocation of responsibility)
Mode A sending records1 year
AI drafts and call logs30 days (the final reply approved and sent by the User is kept for the engagement data period)
Public Social DataSee Section 5(2)
Search results obtained through the Threads APIIf not used by the User, deleted within 30 days of retrieval (same as Public Social Data)
Records of replies posted through the Threads APIReply ID, permalink, time and approver: kept until 90 days after the User's account is closed; upon a data deletion request for that Threads account, all data linked to that account is deleted, except de-identified statistics that contain no Platform Data

(2) Region

The cloud hosting, AI model and data service providers used by the Service may be located outside Taiwan (for example, in the United States or the European Union). We engage only providers with comparable security standards and conduct international transfers in accordance with PDPA Art. 21 and any restrictions imposed by the competent authority.

(3) Recipients (processors)

CategoryPurposeProvider
Website and API hostingRunning the website, review interface and APICloudflare (United States)
Database and sign-inData storage, account sign-inSupabase (hosted in Tokyo, Japan)
AI model serviceRelevance assessment, reply draftingAnthropic (United States)
Public data search serviceRetrieving public postsApify (Czech Republic)
Payments and e-invoicingCollecting payments, issuing invoicesNewebPay (Taiwan)
Notification emailSign-in emails, service noticesResend (United States)
Notification channelsSending review notificationsDiscord, LINE (as chosen by the User)
Official social platform APIsPosting, replying and reading engagement as authorized by the UserMeta, Reddit, X, etc. (as authorized by the User)

Each processor listed above processes data only on our instructions and only to provide its service, under its agreement or data processing addendum with us, and may not use or disclose the data for its own purposes. Anthropic (Commercial Terms of Service) and Apify (General Terms and Conditions §5.10 and Privacy Policy) have additionally committed in writing not to train AI models on our or our customers' data.

Processors may process data only within the scope of the engagement, and we supervise them appropriately in accordance with the PDPA.

(4) Methods

Collection, processing and use within the scope of the Service, by automated or manual means, including storage, matching, ranking, generating reply drafts, notifications and statistical analysis.

7. Content Sent by Users

Comments sent through the Service are published publicly from the User's own social account, after the User has reviewed them (in Mode A, replies are sent automatically according to the User's prior settings and consent). Once published, they are handled under each platform's privacy and visibility rules; we cannot delete content on a platform on the User's behalf, but the User can delete it on the platform.

8. Browser Extensions

  1. Minimal permissions: The extensions request only the minimum permissions needed to function (storing settings, scheduling, opening tabs, and accessing supported social network pages).
  2. No upload of login data: The extensions do not read or upload Users' social platform passwords or login cookies.
  3. Scope of transmission: Only candidate post URLs, public post content, drafts and action results (sent, skipped) are sent back to the Service; content of other web pages the User visits is not transmitted.
  4. Limited Use: Data obtained by the extensions is used only to provide the features of the Service; it is not sold, not used for advertising and not read by humans (except with the User's consent or where necessary for security or legal reasons). Before listing on the Chrome Web Store, this section is reviewed against the then-current User Data Policy.
  5. Auto-send edition (Mode A): Available for download only to workspaces that have completed the Mode A consent, and not listed on any store. In addition to the above, it reports the result of each automatically sent reply (success, failure reason) and the type of guardrail event (CAPTCHA, logged out, restriction message, page layout change); it does not capture or upload screenshots, direct messages or other users' data.

9. Cookies

The Service's websites use only cookies that are strictly necessary to keep you signed in and secure; we do not use analytics or advertising cookies and do not maintain a separate cookie policy. You can refuse cookies in your browser settings, but you will then be unable to sign in to the review interface.

10. Data Subject Rights and How to Exercise Them

Under PDPA Art. 3, data subjects may exercise the following rights regarding their personal data:

  1. To inquire about or request access to it;
  2. To request copies of it;
  3. To request supplementation or correction;
  4. To request that its collection, processing or use be stopped;
  5. To request its deletion.

How to exercise: Contact us through the contact in Section 2 and provide information that allows us to verify your identity (Users: the account email; authors of public posts: a way to prove you control the account, such as posting a verification code we specify from that account).

Response time: Under PDPA Art. 13, we decide on requests for inquiry, access or copies within 15 days, and on requests for supplementation, correction, stopping processing or use, or deletion within 30 days; where necessary these periods may be extended by no more than 15 days and 30 days respectively, with written notice of the reason.

If you exercise the rights in items 4 or 5, we may no longer be able to provide all or part of the Service.

10-1. Revoking Access and Deleting Data (Threads and Other Official APIs)

  1. Disconnect in Langxun: On the "Connected accounts" (帳號連結) page of the review interface, click "Disconnect" (解除連結). The access token for that account is deleted immediately, and the Service stops searching and posting with that account.
  2. Revoke in Threads: Users can also remove Langxun under Threads "Settings → Account → Website permissions" (menu names may vary). When we receive Meta's deauthorization notice, the access token is deleted immediately.
  3. Request deletion: Users can request deletion of data obtained through the Threads API in connection with their account by any of the following: choosing to delete data when removing Langxun in Threads (our data deletion callback URL: https://api.langxun.app/meta/data-deletion); emailing privacy@langxun.app; or exercising the right to deletion under Section 10.
  4. Confirmation and status: For each deletion request we issue a confirmation code and a status page at https://langxun.app/data-deletion. Deletion is completed within 30 days of the request (access tokens are deleted immediately; other data is deleted by a scheduled job).
  5. Content already posted: Replies that the User has already published on Threads are content on the platform; we cannot delete them on the User's behalf. Users can delete them directly in Threads.

11. Marketing Communications

We obtain the User's consent before sending marketing communications such as product updates or offers, and every marketing communication includes a way to unsubscribe. Once a User refuses, we stop immediately in accordance with PDPA Art. 20(2). Necessary service notices (billing, security, changes to terms) are not affected.

12. Data Security

We take appropriate security measures under PDPA Art. 20-1, including encryption in transit, encrypted storage of access tokens, role-based access with least privilege, audit logs of actions, regular backups and restore tests, and supervision of processors.

If personal data is stolen, altered, damaged, lost or leaked, we will notify the data subjects under PDPA Art. 12, report to the competent authority as required, take response measures and keep records.

No network transmission or information system can be guaranteed to be completely secure; we will keep reviewing and improving our measures.

13. Minors

The Service is provided for business use and is not directed at minors. Minors must obtain the consent of their legal representative before using the Service. The age of majority under the Taiwan Civil Code is 18.

14. Changes to This Policy

We may revise this Policy and will publish the revised version on the website. For material changes, we will notify Users by email or in-app notice at least 7 days before they take effect.

15. Contact

For any questions, requests or complaints about this Policy or the processing of personal data, please contact:

16. Language

This Policy is also provided in an English reference version (https://langxun.app/en/privacy). In case of any inconsistency between the Chinese and English versions, the Chinese version prevails.

Version 1.2, last updated 2026-10-07, effective 2026-10-15 (v1.2 was published before v1.1 took effect; it adds the data categories, purpose limitation, retention periods, access revocation and data deletion methods for Threads API connections, and this English reference version).