Privacy Policy

Last updated: 2026-04-21. Operator: China LLM Directory (https://china-llm.com).

1. Scope

This policy describes how China LLM Directory ("we", "the site") handles personal information of visitors and registered users. If you do not agree with any part of it, do not use the site.

2. What we collect

  • Account data. When you sign in via Google OAuth or magic-link email, we store your email address, display name, avatar URL (if provided by the OAuth provider), and an internal user ID. Password hashes are never stored — authentication is delegated to Google or one-time email tokens.
  • Session cookies. A single first-party session cookie (issued by better-auth) keeps you logged in. Expires on sign-out or after a bounded inactivity period.
  • Lead form submissions. If you submit a "Get a quote" form, we store the email address, role, target provider, and any free-text workload description you provide. This data is shared with the Provider you selected.
  • Affiliate click logs. When you click through to a Provider's site via our affiliate links, we log the source page, provider slug, and coarse timestamp. No cross-site identifiers are used.
  • Usage analytics (Plausible). We run Plausible Analytics, which is cookieless and records aggregated page-view counts, referrer domains, and coarse country. No individual-level identifiers or profiles are created.
  • Error telemetry (Sentry). If the site throws a JavaScript error, we forward the stack trace, request URL, and coarse environment metadata to Sentry. TODO(legal): confirm we strip PII from breadcrumbs before enabling in production.

3. Why we collect it (legal bases)

  • Contract performance — account data and session cookies are required to operate the signed-in areas of the site.
  • Legitimate interest — affiliate-click logs, error telemetry, and aggregated Plausible analytics are processed to maintain and improve the directory.
  • Consent — lead form submissions are processed because you chose to submit them with the stated intent of being contacted by a Provider.

4. Who we share data with

  • Providers (for lead forms only): if you submit a "Get a quote" for a given Provider, the form contents are sent to that Provider's designated contact.
  • Subprocessors: Neon (database hosting), Vercel (CDN + serverless runtime), Better-auth's OAuth upstreams (Google), Plausible Analytics, Sentry.

We do not sell personal information. TODO(legal): enumerate subprocessor DPA coverage for EU + China cross-border transfers.

5. Retention

Account data is retained until you delete your account. Lead form submissions are retained for 24 months or until your consent is withdrawn, whichever comes first. Affiliate click logs are retained for 13 months. Plausible data is retained per Plausible's policy (no user-level retention).

6. Your rights

Subject to GDPR (EU/UK residents) or PIPL (mainland China residents), you may request access, correction, export, or deletion of your personal data by emailing hello@china-llm.com. We respond within 30 days.

7. International transfers

The site's infrastructure is hosted outside mainland China. If you access the site from China, your data is transferred to the United States or the European Union for processing. TODO(legal): evaluate whether Standard Contractual Clauses or a PIPL cross-border assessment is required for our traffic profile.

8. Contact

Questions, corrections, or data-subject requests: hello@china-llm.com.