OKNote

Children's Personal Information Protection Policy

Last updated: 8 September 2026

This policy forms part of the OKNote Privacy Policy and explains specifically how we handle children's personal information. Where this policy differs from the Privacy Policy, this policy prevails. Guardians should read it in full before allowing a child to use the service.

Scope: which part actually involves children's personal information

The OKNote application itself (notes, tasks, mail, AI and related features) is rated suitable for ages 3 and up. It contains no pornography, violence, horror, profanity, simulated gambling or any other restricted content, and sets no minimum age of use.

OKNote is self-hosted software: it is deployed and runs on a server, NAS or hosting environment that you control, and your notes, tasks, mail and attachments are stored there. That data is under your control — we cannot access it and it is never transmitted to us. Content a child creates inside a self-hosted deployment is therefore not personal information collected by us under this policy; its security and legal compliance are the responsibility of whoever operates the deployment, normally the guardian.

The only part where we actually collect a child's personal information is the website and account system operated by us (Magic Forest (Chongqing) Technology Co., Ltd.) at oknote.vip. That account exists for purchases, licence management and multi-device licence verification, and requires an email address or mobile number. This policy governs that part.

In this policy a "child" means a minor under 14 years of age. We give children's personal information special protection in accordance with the Personal Information Protection Law of the People's Republic of China, the Provisions on the Online Protection of Children's Personal Information, the Law on the Protection of Minors and other applicable laws and regulations.

1. Purposes, methods and scope of collecting, storing, using, transferring and disclosing children's personal information

We apply the principle of minimum necessity: we do not collect any children's personal information that is not required for the purposes listed below.

Personal informationHow it is collectedPurposeScope and necessity
Email address or mobile numberEntered by the guardian on the sign-up pageCreating the account, sign-in and identity verification, password recovery, account-security noticesNecessary; either one is sufficient
PasswordEntered by the guardian on the sign-up / sign-in pageSign-in authenticationNecessary; stored only as a salted hash — we neither keep nor can recover the plaintext
Display nameEntered voluntarily by the guardianShown on the account pageNot necessary; a default name is used if left blank
Order and licence recordsGenerated by the payment flow when a purchase is madeProcessing purchases, licences and renewals, issuing receipts, handling refunds and after-sales supportNecessary; only generated if a paid purchase occurs
Device hardware fingerprint (a hash derived from device identifiers) and device nameGenerated and reported automatically by the client during licence verificationVerifying the licence and device binding so that one licence cannot be copied without limitNecessary; only generated when paid licensed features are used
IP address, device and browser type, language, access time, error logsRecorded automatically when the website or API is accessedDetecting and preventing abnormal sign-ins and network attacks, troubleshooting, keeping the service stableNecessary; used only for security and operations, never for profiling or advertising

Our rules on transferring, disclosing and sharing children's personal information are as follows:

  • Transfer: we do not transfer children's personal information to any third party, except where laws or regulations require it or where separate guardian consent has been obtained.
  • Disclosure: we do not publicly disclose children's personal information.
  • Sharing (entrusted processing): only to the minimum extent necessary to fulfil the purposes above do we provide information to the following processors, each bound by contract to confidentiality and security obligations and permitted to process it only on our instructions — payment providers (processing and confirming transactions), Apple (App Store in-app purchases and subscription management), and hosting and infrastructure providers (running the website and account service on our behalf). They may not use the information for any other purpose.
  • We do not use children's personal information for targeted push, marketing or user profiling, and we do not sell children's personal information.

2. Where children's personal information is stored, for how long, and what happens when that period ends

  • Location: we are located in China and children's personal information is stored and processed on servers within mainland China. Where a cross-border transfer is genuinely required, we will obtain separate guardian consent in advance and disclose the overseas recipient's name and contact details, the purpose and method of processing, and the categories of personal information involved.
  • Retention period: for as long as the account exists and for as long as is necessary to provide the website and account service. In addition, paid order and licence records are retained for the period required by accounting and tax law (not less than five years from completion of the transaction), and security and access logs are retained for no more than six months.
  • What happens afterwards: once those periods expire, or the guardian withdraws consent, or the account is deleted, we delete the corresponding children's personal information. Where immediate deletion is technically impracticable — for example data already written to offline backup media — we stop all processing other than storage and the security measures necessary to protect it, and complete erasure within the backup rotation cycle. Where law requires continued retention, we first anonymise the data so that it can no longer identify a particular child.

3. Security measures for children's personal information

  • Protection in transit: the website and account service use HTTPS throughout. For self-hosted deployments on a local network where HTTPS has not yet been enabled, the client encrypts mobile numbers, email addresses, passwords, API keys and similar data at the application layer with a one-time negotiated key (X25519 key agreement + HKDF-SHA256 + AES-256-GCM) before sending, so that packet capture reveals no plaintext. To be clear: this layer defends against passive eavesdropping on the link and is not a substitute for HTTPS; we recommend enabling HTTPS for self-hosted deployments via a reverse proxy.
  • Protection at rest: passwords are stored only as salted hashes (bcrypt) — we neither keep nor can recover the plaintext. Sensitive fields such as mailbox authorisation codes, AI provider API keys and tunnel tokens are stored encrypted in the database.
  • Access control: internal access to children's personal information is restricted on a least-privilege basis, requires approval and is logged. Everyone who may come into contact with such data signs a confidentiality agreement and is held to it.
  • Designated responsibility: we have designated specific personnel responsible for the protection of children's personal information; their contact details appear at the end of this policy. Staff in relevant roles receive regular personal-information-protection training.
  • Incident response: if children's personal information is or may have been leaked, altered or lost, we activate our incident response plan immediately, promptly inform the guardians of affected accounts of the incident and the remedial measures by email or other means, and report to the competent authorities as required.

4. Guardian consent and the consequences of declining

We do not knowingly open a website account for a child under 14 on their own. Where a child genuinely needs an account (for purchases or licence management), the guardian must read and agree to this policy and then complete or assist with the registration; submitting the registration is taken as guardian consent having been given.

A guardian may withdraw consent at any time. On withdrawal we stop processing the corresponding children's personal information and delete it under the rules in section 2. Withdrawal does not affect the validity of processing carried out on the basis of consent before it was withdrawn.

If we discover that we have collected a child's personal information without guardian consent, we will delete it as soon as possible.

  • Declining to provide an email address or mobile number, or a password: the website account cannot be created or signed in to, so online purchases, licence management and licence verification across multiple devices are unavailable.
  • Declining to provide a display name: no effect on any feature; the account uses a default name.
  • Declining to provide the device hardware fingerprint and device name: paid features that require licence verification cannot be used.
  • None of the above affects use of the OKNote application itself. OKNote can be used entirely without a website account — once deployed on your own server or NAS, a local account gives access to all free features including notes, tasks and mail. In other words, declining to provide the personal information above does not prevent a child from using the basic functionality of the software.

5. How to complain or report a concern

If a guardian or the child believes that our collection, storage, use, transfer or disclosure of children's personal information breaches laws, regulations or this policy, or identifies a risk to children's personal information in our products or services, they may complain or report through the following channels:

  • Email: service@oknote.vip (please put "Children's personal information complaint" in the subject line and include the account's email address or mobile number together with the details, so that we can verify it quickly)
  • Website support page: https://oknote.vip/support
  • Operator: Magic Forest (Chongqing) Technology Co., Ltd.

We will verify and respond within 15 working days of receiving a complaint or report. If you are not satisfied with the outcome, you may also report the matter to the competent authorities — including the national cyberspace administration, the telecommunications regulator or the public security organs — or bring proceedings before a court of competent jurisdiction.

6. How to correct or delete children's personal information

Where children's personal information we hold is inaccurate, the guardian has the right to have it corrected. The guardian has the right to have it deleted where any of the following applies: our collection, storage, use, transfer or disclosure of the information breaches laws, administrative regulations or the agreement between us; the information goes beyond the agreed purpose or the necessary retention period; the guardian withdraws consent; or the guardian or child stops using the product or service, for example by deleting the account.

  • Self-service correction: sign in and open Settings → Account in the client to change the email address, mobile number and display name.
  • Self-service deletion (account deletion): open Settings → Account → Danger zone → Delete account in the client. To confirm it is really you, deletion requires the account password and typing DELETE by hand; if an email address or mobile number is bound, a verification code is also required. The deletion dialog offers a checkbox, "Also delete all notes stored on this device", so you can choose whether the notes, attachments and mail held on your self-hosted server are permanently deleted along with the account. Once deletion completes, the account and the personal information associated with it are permanently erased and cannot be recovered.
  • By email: if self-service is not convenient, send a correction or deletion request to service@oknote.vip. To protect the account we first verify the guardian's identity, and once verified we complete the request and reply within 15 working days.

7. Updates to this policy and how to contact us

If this policy is updated we will publish the new version on this page and update the "Last updated" date at the top. Where the purpose, method or scope of processing children's personal information changes materially, we will seek guardian consent again.

  • Operator: Magic Forest (Chongqing) Technology Co., Ltd.
  • Website: https://oknote.vip
  • Children's personal information protection officer: service@oknote.vip