Privacy Agreement

GeFit Privacy Policy 2025

Update Date: September 23, 2025

Effective Date: September 23, 2025

This privacy policy ("Privacy Policy" or "Policy") outlines the information that Shenzhen Yuanshengti Technology Co., Ltd. and its affiliated companies ("GeFit", "Yuanshengti", "Genesbot" or "we") collect and process from you. This policy applies to all websites, mobile applications (Genesbot, Smart Toys, L1), electronic toy products and other services provided by Genesbot that link to this policy, as well as our offline services (collectively referred to as "Services").

By using the Services, you agree to the practices described in this policy. If you do not agree with these practices, please do not access or use the Services. Any undefined capitalized terms in this document are defined according to the Genesbot Terms of Service. You can review this privacy policy at the bottom of the official website homepage, or in the application under "My - Settings: Version Number".

We hereby earnestly remind you that before using this product and submitting personal information, please carefully read and fully understand this policy. Only after confirming full understanding and agreement should you use the service. This policy will be presented for your reading and agreement when you register an account, and will also be displayed or linked to platforms and applications related to the collection of personal information by this product. We will strictly follow the commitments in this policy to collect and use your personal information, and will obtain your separate consent in accordance with legal requirements when necessary. We will not use forced bundling methods to collect all your personal information just because you agree to this policy. Please carefully and completely read all terms of this policy. Where we highlight categories of collected personal information and usage scenarios through bolding/underlining, and where clauses that exempt or limit liability will be highlighted in bold for attention, please pay special attention to reading them.

This privacy policy will help you understand the following:

I. Scope of Application of This Privacy Policy
II. How We Collect and Use Your Personal Information
III. How We Use Cookies and Similar Technologies
IV. Third Parties We Integrate and How We Share, Transfer, and Publicly Disclose Your Personal Information
V. How We Store and Protect Your Personal Information
VI. Your Rights Regarding Your Personal Information
VII. Terms for Minors
VIII. How Your Personal Information Is Transferred Globally
IX. Changes to This Privacy Policy
X. Dispute Resolution
XI. Appendices
XII. Other

I. Scope of Application of This Privacy Policy

This Privacy Policy only applies to product services developed by Shenzhen Yuanshengti Technology Co., Ltd. and its affiliated companies, including functions/services built into products that we commission or integrate from affiliated parties legally owned and operated. The affiliated parties mentioned herein refer to companies, organizations or individuals related due to common ownership or control; third parties refer to companies, organizations or individuals (non-affiliated companies) or other unrelated individuals that do not have related relationships due to common ownership or control. This Privacy Policy does not apply to the following situations:

(a) Personal information collected and used by third-party services (including third-party applications and websites) accessed through our products and/or services;

(b) Personal information collected and used by other third parties providing advertising services in our products and/or services;

(c) Information or other services (including websites) provided by third parties that may be included or linked in our products and/or services. These third-party services may be operated by the relevant third party. Your use of these third-party services (including any personal information you provide to the third party) is subject to the third party's terms of service and privacy policy (not this Privacy Policy), and you need to read their terms carefully. Please properly protect your personal information and only provide it to others when necessary. This Privacy Policy only applies to the information we collect, save, use, share, and disclose, and does not apply to services provided by any third party or the use of information by third parties. We are not responsible for any use of information provided by you by any third party.

II. How We Collect and Use Your Personal Information

According to the Personal Information Protection Law, personal information refers to various types of information related to identified or identifiable natural persons recorded electronically or otherwise, excluding anonymized information; sensitive personal information refers to personal information that is easily likely to cause infringement of personality rights or harm to personal or property security if leaked or illegally used, including biometric identification, religious beliefs, specific identity, medical health, financial accounts, travel trajectory information, as well as personal information of minors under fourteen years old.

In the process of users and bound members using the application, we will collect and use information actively provided by users and bound members or generated due to using the service. Users and bound members are not required to provide us with personal information, but in some cases, if you choose not to provide it, Genesbot will be unable to provide you with related products or services, nor respond to or solve problems you encounter while using our products/services.

Genesbot will only collect and use your personal information for the purposes stated in this statement and with your consent:

(1) Information We Collect

When you visit or use our services, we collect various types of information based on your usage. It is important to note that certain information is crucial for us to provide services. If you choose not to share this essential information or request its deletion, you may lose access to certain services. The information we collect can be divided into the following categories: data you directly provide to us, data automatically collected from your interactions with our services, and data we obtain from other sources.

(a) Information You Directly Provide to Us

We collect information directly from you in various ways. This happens when you interact with our services, communicate with us, register an account, subscribe to our communications, or participate in promotional activities. The information you provide may involve yourself and others, and may include a range of data types, including but not limited to:

(b) Information We Automatically Collect

Together with our third-party providers, including advertising networks and analytics companies, we may use cookies, web beacons, and other tracking technologies to collect information about the computer or device (including mobile devices) you use to access our services. The following are possible types of information that may be collected and analyzed, including but not limited to:

We also track when and how frequently you access or use our services, including your interactions and navigation with our website or mobile application. This information, including data collected by our third-party providers, is used for analysis - identifying the most frequently used parts of our services and understanding user preferences - evaluating the success of our advertising campaigns, and for other purposes described in this policy. When you visit our services, we may collect general location information that can be inferred from your IP address.

Note: The above automatically collected information is only used for service optimization and operational analysis, will not be associated with your identity information for targeted push notifications, and we have implemented de-identification measures.

(c) Information Temporarily Used by Apps or Devices

To enhance user experience, we may use the following information in visual and interactive interfaces. This information will only be temporarily used and will not be permanently saved. This includes:

We use this content to optimize App interactive experience, such as pasting content in text boxes or displaying floating effects in UI. All temporarily used sensor information will not be uploaded to servers, only processed in real-time on local devices, destroyed immediately after processing, and will not be retained long-term.

(d) Personal Information Collected for Smart Device Connections

For smart devices connected via Wi-Fi: Wi-Fi information (SSID, BSSID, Wi-Fi MAC address, Wi-Fi password), device MAC address, device ID; only used for device network configuration, Wi-Fi passwords are stored using irreversible encryption, only used on local devices, not uploaded to servers;

For smart devices connected via Bluetooth establishing local connection, then connecting via Wi-Fi: Wi-Fi information (SSID, BSSID, Wi-Fi MAC address, Wi-Fi password), device MAC address, device Bluetooth MAC address; only used for device network configuration and Bluetooth pairing, encrypted storage of necessary information after pairing completed, Wi-Fi password not stored;

BSSID is used to connect to the network when SSID is not broadcast, or to select a specified AP connection among multiple APs;

For smart devices connected via Bluetooth: Device Bluetooth MAC address, device ID; only used for Bluetooth device identification and pairing, only device ID retained for subsequent connections after pairing, Bluetooth MAC address encrypted storage;

For smart devices connected via Zigbee: Device MAC address, device ID; only used for Zigbee device networking and identification, encrypted storage;

If your device is equipped with temperature/humidity sensors or human sensors, we will also collect environmental information around the device so you can accurately view the environmental information detected by the device sensors. For example: temperature, humidity, PM2.5, and whether someone has passed by; this information is only used for local display or synchronized to your device management page under your account, not shared with third parties;

If your device is equipped with a microphone or camera, we will also collect real-time audio or video: only collected when you actively enable device monitoring/call functions, audio/video data only transmitted in real-time to your bound terminal devices, not stored on servers, and transmission process uses end-to-end encryption;

If your device is equipped with GPS positioning chip, we will also collect the device's real-time location: only collected when you actively enable positioning function and authorize, used for finding devices, location sharing, and other functions you explicitly authorize, location information encrypted storage, and you can close authorization anytime to stop collection;

Smart devices connected via Wi-Fi may scan surrounding WiFi information to determine if network switching is possible; simultaneously this information is used to prompt you to select and switch WiFi information. This information is only temporarily stored in the system and will be deleted when the device is reset. Scanned data includes: SSID, BSSID, security type, etc., scanned WiFi information is only used for device network switching, will not be used for positioning or other unnecessary purposes, and only stored locally on devices, not uploaded to servers.

(e) App Runtime Permissions and Collected Data

(f) Information Collected Through Third-Party Accounts

Whenever you connect to our account using third-party accounts, such as social media accounts ("Third-Party Account"), we may collect certain information. This collection is based on permissions you grant and may include data from your third-party account. For example, by using Facebook or Google third-party accounts to connect to our services, we receive information that helps identify your account in these services. We securely collect and store this information to simplify your connection to our services. Choosing to link your account to a third-party account is entirely up to your choice. When you begin connecting, you will have the opportunity to provide your consent. If you decide to revoke this permission, you can disconnect our services from there by logging into your third-party account, or easily achieve it through your smartphone's native application. Importantly, we may retain information previously collected from you.Supplement: We only obtain unique identifiers from third-party accounts (such as OpenID) for account association login, do not obtain friend relationships, dynamics, location information, or other information from third-party accounts; you can unbind third-party accounts in APP "My - Settings - Account & Security", deletion of corresponding third-party account association information occurs after unbinding.

(2) When You Use the Following Services, Functions, and Settings, We Will Collect and Use Your Personal Information in the Following Ways

(a) Account Registration Login, Password Recovery
When you first use the Genesbot app and services, we will collect your phone number for account registration; after successful registration, you can log in using your registered phone number or account password. If you forget your account password, you can recover it through your phone number. To change the phone number bound to your account, we require you to provide the old phone number to receive verification codes for validation, and delete the old phone number information after successful change, collecting and using your new phone number to meet requirements of laws and regulations such as the Cybersecurity Law and Internet User Account Information Management Regulations regarding identity authentication. You can optionally provide a nickname for subsequent account use, not providing a nickname will not affect normal use of other functions.Supplement: Phone numbers are only used for account verification and login, we use encryption for storage, will not use phone numbers for marketing promotion; verification codes are valid for 5 minutes, only usable once, immediately invalidated after verification completed.

(b) Improving User Information
After binding devices, you can actively fill in nicknames, real names, gender, birthday, wireless networks, and geographic location information in the application; provision of the above information is non-mandatory, users can choose to fill or not fill. Unless required by relevant laws and regulations, refusing to provide corresponding information will only affect the user experience in some services. We will also collect积分and level data of bound devices and display it on corresponding pages in the application. This data is only used for personal page display and will not be used for other purposes.Supplement: Geographic location information is only used for manual setting of device location display, not for location tracking; real name is only needed when you actively fill in invoice information/shipping information, not mandatory collection.

(c) Conversations
When you conduct conversations/text/voice/image/video/location information sending/receiving, or file transfers through application functions, we will collect voice/video/image/text/location information to ensure stable service operation. Please be assured,voice and text data are only used for immediate processing, we will not save related voice and text data.Due to differences in device models, some services may be limited to specific products. Please understand specific support situations based on the device you are using. At the same time, we will conduct legal compliance reviews of related content in accordance with applicable laws and regulations.Supplement: Conversation data transmission process uses end-to-end encryption, review only conducts keyword detection for illegal and non-compliant content, will not manually view your conversation content; location information is only transmitted when you actively send, recipients only designated contacts you specify, we do not store this location information.

(d) Ensuring Normal and Secure Service Operation, System Fault Analysis
To ensure you can use services normally and protect your account security, and to prevent viruses, Trojan programs, or other malicious programs and websites, we will record service usage log information (operation logs, service fault information) and collect your device's hardware model, operating system version number, network connection status (SIM card/WiFi) to achieve account anomaly monitoring, customer service, fault records, fraud monitoring, archiving, and backup. If you disagree to provide such information, it may affect normal service use.Supplement: Log information is only used for fault troubleshooting and security risk control, will not associate your identity information, log data retention period is 6 months, automatically anonymized processing upon expiration; hardware model and other device information is only used for function optimization adapted to different devices, not for device tracking.

(e) Location-Based Services
We will separately pop up to obtain your consent to call your real-time GPS precise location information to allow you to use find-device functions in the application; if you disagree to provide your GPS location information, you will not be able to use the above functions or services, but it will not affect your normal use of other service functions; you can always close location authorization in your mobile terminal's permission management.Supplement: Location-based services are only triggered when you actively click the "Find Device" function, location results only displayed to yourself, location data saved until you stop finding devices automatically deleted within 1 hour; we will not continuously track your location, nor share location information with third parties.

(f) Communication Services
In some devices, Genesbot provides users with emergency contact functions, which requires users to actively fill in emergency contact person's phone number and nickname. We will not force you to fill in such information, if you disagree to provide such information, you cannot use related communication services, but it will not affect the normal operation of other services.Supplement: Emergency contact person information is only used to send help information to designated contacts when you trigger emergency call function, we encrypt store this information, will not be used for other purposes; you can modify/delete emergency contact person information anytime, modification/deletion takes effect immediately.

(g) Sports Services
When the device you use supports sports/health monitoring module services, we will collect user basic information (birthday, gender, height, weight) you actively fill in the application, set training plans and daily goals, not filling or not truthfully filling will result in us being unable to assess, generate more accurate data or realize related functions, but will not affect other basic business functions of the device.Supplement: Sports/health data only stored under your account, used for generating personal health reports, not shared with third parties; you can delete all sports/health data in "Sports - Settings", deletion is irreversible.

(h) Marketing Activities, Questionnaire Research
We will send satisfaction/market research questionnaires through applications or website backends, or invite you to participate in marketing activities. If you agree to participate in corresponding questionnaire survey activities, we may collect personal information you actively provide and generate during completion of questionnaires (such as name, contact information, etc.), you can optionally provide; if you agree to participate in corresponding marketing activities, we will collect your name, mailing address, contact information according to activity needs, to realize conducting further marketing questionnaire interviews with you or sending gifts to you purposes.Supplement: Marketing activities/questionnaire research are voluntary participation, you can exit anytime; collected contact information is only used for activity notifications/gift distribution, related information deleted within 15 days after activity ends; you can close marketing activity push notifications in "My - Settings - Privacy Settings".

(i) Problem Feedback
During your use of our products, you can feedback problems encountered while using this product, we may collect your phone number or other contact information you provide, to be used for contacting you and answering your feedback questions.Supplement: Contact information is only used to reply to your feedback questions, immediately deleted after reply completed; feedback content is only used for product optimization, will not be associated with your identity information for external display.

(3) We May Process Personal Information Based on Other Legitimate Bases Prescribed by Laws and Regulations

(a) Directly related to national security, defense security, criminal investigation, prosecution, trial, and judgment execution:
(b) Necessary for fulfilling statutory duties or legal obligations;
(c) Necessary for concluding or performing contracts where you are one of the parties;
(d) Necessary for responding to sudden public health emergencies, or in emergency situations to protect natural persons' life health and property safety;
(e) In reasonable scope for news reporting, public opinion supervision, and other behaviors for public interest;
(f) In reasonable scope for processing personal information that you have made public or other already legally public information according to the Personal Information Protection Law:
(g) Other circumstances prescribed by laws and regulations.
Supplementary Note: When processing personal information based on the above circumstances, we will follow the minimum necessity principle, only processing the least amount of information required to achieve the purpose, and promptly delete/anonymize processing after completing the purpose; if involving emergency situation protection of life health, post facto inform you of processing situation (except where prohibited by laws and regulations).

(4) Other Situations

(a) Under circumstances beyond the above clauses, if we intend to use your personal information for other purposes or objectives not specified in this privacy policy, we will first seek your consent.Supplement: This consent is separate pop-up confirmation, clearly informing usage purpose, scope, duration, you can withdraw consent anytime.

(b) Unless you withdraw consent or refuse our collection and use through system settings, all personal information you provide while using our products and/or services will be continuously authorized by you for our use within the scope compliant with this Privacy Policy during your use of our products and/or services;Supplement: You can withdraw authorization consent for any function in "My - Settings - Privacy Settings - Authorization Management", withdrawal will immediately stop corresponding information collection and use, already collected information will be handled according to Part V of this policy.

(c) When you use related services in the "Mall", "Customer Service and After-sales" interfaces of applications or websites, Genesbot will jump to "Genesbot Official Mall", "Genesbot Customer Service" and other mini-programs after obtaining your consent, specific services will be provided by corresponding mini-programs, please read and understand the privacy policy displayed on their interfaces, Genesbot will not collect your personal information through these functions.Supplement: Before jumping will clearly inform you of jumping purpose and third-party entity, you can choose whether to jump; we will conduct compliance review of cooperative mini-programs to ensure their privacy policies comply with laws and regulations.

(d) Anonymized Data and Statistical Data: After collecting your personal information, we will promptly de-identify or anonymize the data through technical means. Among them, anonymized data cannot identify you and does not belong to personal information, we have the right to mine, analyze, and utilize (including commercial use) the anonymized data; additionally we will statistically analyze user usage of products and/or services and may share these statistical information with the public or third parties to show overall usage trends of our software and related services. However, these statistical information will not contain any of your personal information.Supplement: De-identification processing uses industry standard algorithms to ensure reverse identification to individuals is impossible; when sharing statistical data, only aggregate results provided, no fields containing identifiable individuals.

(e) Application Permission Calls: We will call some of your device permissions when collecting and processing your personal information to provide the above services for you. You can choose to close part or all permissions in your device's settings function to refuse our collection of corresponding personal information. In different devices, permission display methods and closing methods may differ, please refer to the instructions or guidelines provided by the device and system developer for details.Supplement: We provide permission call explanation page in APP ("My - Settings - Permission Explanation"), clearly stating each permission call purpose, method, closing path; permission calls preceded by pop-up notification, no default authorization, mandatory authorization situations.

III. How We Use Cookies and Similar Technologies

You understand and agree that when you use our products and/or services, to make your access experience easier, we may use various technologies to collect and store information, during which we may send one or more cookies or anonymous identifiers to your device. When you use our products and/or services, we may use cookies and similar technologies to collect your information for understanding your preferences and usage habits, saving you from repeatedly entering information, conducting consultation or data analysis, and timely discovering and preventing security risks. Cookies also help us count traffic information, analyze page design and advertising effectiveness.We will not use cookies for any other purposes beyond those stated in this Privacy Policy, you can retain or delete cookies according to your preferences, or clear all cookies saved in software or web pages.Supplementary Note:

1. Cookie Types and Uses: Essential Cookies: Used to maintain basic service functions (such as login status), cannot be disabled, disabling will result in service unusable; Analytics Cookies: Used for statistical user behavior, optimizing product experience, can be disabled in APP settings, disabling does not affect basic functions; Advertising Cookies: Used for personalized recommendations (such as mall product recommendations), default closed, need active enable;

2. Cookie Retention Period: Essential cookies retained until you log out, analytics/advertising cookies retention period does not exceed 90 days;

3. You can view/delete/disable non-essential cookies in APP "My - Settings - Privacy Settings - Cookie Management".

IV. Third Parties We Integrate and How We Share, Transfer, and Publicly Disclose Your Personal Information

(1) Third-Party Cooperation Processing of Your Personal Information

(a) Entrusted Processing of Personal Information
To achieve the purpose of data processing required for providing services, we will cooperate with third-party partners (third-party service providers, contractors, agents, application developers, etc.) to entrust them to process or share the personal information we collect, if we entrust third parties to process personal information, we will conduct security assessments on the entrusted party and entrusted behavior, sign entrusted agreements, require the entrusted party's processing behavior not to exceed our authorization scope, our entrustment of third parties to process your personal information is only used for providing our services/achieving the purposes stated in "How We Collect and Use Your Personal Information"/fulfilling our obligations and exercising our rights in this policy. Our typical scenarios for entrusting third parties to process your personal information based on this situation are: entrusting software service providers, smart device providers, or system service providers to process your personal information. We will entrust third-party service providers to provide location navigation, data storage, content and image compliance review services, we will entrust the above service providers to process your device information, location information, image information for achieving our services based on your authorization and settings for corresponding services. We will require the above service providers to take necessary technical measures and management measures to protect your personal information, and delete, destroy, or anonymize related information after achieving entrusted processing purposes. The above entrusted processing scenarios are all based on necessity for providing you services, if you refuse our service providers collecting necessary personal information for providing services in the above scenarios, it may lead to you being unable to enjoy services provided by this supplier during your use of our products and/or services or affect our normal provision of related products or services to you.Supplement: We will conduct strict qualification review and security assessment of third-party partners, at least once annually; entrusted agreements clearly stipulate data security responsibilities, confidentiality obligations, breach compensation clauses; you can view all cooperating party lists and entrusted processed information types and purposes in APP "My - Settings - Third-Party Information".

(b) Sharing
Sharing refers to Genesbot providing personal information to other personal information processors, both parties independently deciding processing purposes and methods in personal information processing activities. Usually Genesbot will not share your personal information externally, but the following situations are exceptions:Statutory Sharing Scenarios: Under mandatory administrative and judicial requirements required by applicable laws and regulations, according to requirements legally proposed by administrative and judicial organs, sharing your personal information externally.Supplement: Before sharing will verify legal qualifications and documents of administrative/judicial organs, only provide information within required scope, after sharing will record sharing situation (including recipient, shared information, purpose, time), and inform you when you submit application (within scope allowed by laws and regulations).
Sharing with Genesbot Affiliated Companies: Your personal information may be shared with our affiliated companies. We will only share necessary personal information and are constrained by this privacy policy. If an affiliated company wants to change the processing purpose of personal information, they will again seek your authorization and consent;Supplement: Affiliated company list can be viewed in official website "About Us - Affiliated Enterprises"; shared information is only used for providing unified service experience for you (such as cross-device data synchronization), affiliated companies need to comply with the same privacy protection standards as us; you can refuse affiliated company sharing your information in "My - Settings - Privacy Settings" (refusal may affect cross-device synchronization function). Other circumstances prescribed by laws and regulations.

(2) Transfer of Your Personal Information

We will not transfer your personal information to any company, organization, or individual outside ourselves and our affiliated companies, but the following situations are exceptions: (a) Previously obtained your explicit authorization and consent;Supplement: This authorization is separate pop-up confirmation, clearly informing transferee, information type, purpose, duration, you can withdraw authorization anytime. (b) Meeting requirements of laws and regulations, legal procedures, or mandatory government requirements or judicial determinations; (c) If we or our affiliated companies are involved in mergers, divisions, liquidations, asset or business acquisitions or sales transactions, your personal information may be transferred as part of such transactions, we will ensure confidentiality of such information during transfer, and do our utmost to ensure the new holder of your personal information continues to be constrained by this privacy policy, otherwise we will require that company or organization to re-seek your authorization and consent;Supplement: At least 30 days before transaction occurs, inform you through APP pop-ups, official website announcements, etc., you can choose to request us to delete your personal information or continue to be processed by new entity. (d) Directly related to public security, public health, major public interests; (e) Directly related to criminal investigation, prosecution, trial, and judgment execution; (f) Other circumstances prescribed by laws and regulations.Supplementary Note: During personal information transfer process, we will use encryption transmission, signing confidentiality agreements, and other methods to ensure information security; after transfer completed, if new information processor changes processing purpose/method, requires re-obtaining your consent.

(3) Public Disclosure of Your Personal Information

We will only publicly disclose your personal information in the following situations: (a) Obtained your explicit consent;Supplement: This consent is separate pop-up confirmation, clearly informing disclosure scope, channel, duration, you can withdraw consent anytime. (b) Based on requirements of laws and regulations, legal procedures, litigation, or mandatory requirements of government authorities;Supplement: Before disclosure will verify legality of related documents, only disclose information within required scope, and record disclosure situation. (c) Directly related to national security, defense; (d) Directly related to public security, public health, major public interests; (e) Directly related to criminal investigation, prosecution, trial, and judgment execution; (f) Other circumstances prescribed by laws and regulations.Supplementary Note: We will not publicly disclose your personal information for marketing, advertising, and other purposes; if publicly disclosed information contains personally identifiable content, will first conduct anonymization/de-identification processing (except where required by laws and regulations).

(4) Third-Party Disclosure

(a) Umeng Application Performance Monitoring SDK
SDK Name: Umeng Application Performance Monitoring SDK
Purpose: Provide APP application performance monitoring services (including crash monitoring, lag analysis, startup speed analysis), only used for locating and fixing APP runtime faults, optimizing APP performance, not used for user behavior analysis or advertising push
Operator: Umeng Tongxin (Beijing) Technology Co., Ltd.
Collected Personal Information Types: Device information (Android ID/IDFA/OAID/OpenUDID/GUID; optional-IMEI/IMSI/ICCID), network information, location information (optional);Supplement: Location information only collected when you actively enable "performance location analysis" function, default closed; IMEI/IMSI/ICCID only collected on Android devices when you authorize "device information permission", iOS devices do not collect; all collected information uses encrypted transmission, only for performance monitoring, not shared with third parties
Data Storage Period: Performance monitoring data saved for 90 days, automatically anonymized processing upon expiration
Closing Method: You can close Umeng SDK usage in APP "My - Settings - Privacy Settings - SDK Management", closing does not affect basic APP functions, only unable to use performance monitoring-related fault troubleshooting functions
Privacy Policy Link: https://www.umeng.com/page/policy

(b) Woodpecker SDK
To achieve application performance analysis, we use Woodpecker SDK technical components to assist client-side crash problem directional analysis. Woodpecker SDK collection situation is as follows, it may change information processing due to version upgrades and other reasons, specifically subject to their official announcement, please pay attention timely.
Cooperation Purpose: Assist client-side crash analysis and performance monitoring (only used for positioning APP crash causes, analyzing lag issues, optimizing APP operation smoothness, does not collect any user behavior data)
SDK Name: Woodpecker SDK
SDK Manufacturer: Guangzhou Dongjing Computer Technology Co., Ltd.
Collected Personal Information Fields and Purposes: Device brand model, device crash logs; used for crash analysis, compatibility analysis, performance monitoring;Supplement: Crash logs only contain APP runtime error information, do not contain user-input text, images, voice, and other content; device brand model only used for adapting fault analysis for different devices, does not associate user identity
Data Storage Period: Crash logs saved for 60 days, automatically deleted upon expiration
Closing Method: You can close Woodpecker SDK usage in APP "My - Settings - Privacy Settings - SDK Management", closing does not affect basic APP functions, only unable to quickly locate crash faults
Privacy Policy Link: https://yueying-docs.efffirst.com/privacy.html

(c) Firebase Crashlytics SDK (Only for Non-China Mainland Use)
SDK Name: Firebase Crashlytics SDK (Google Firebase)
Purpose: APP crash monitoring and stability analysis (only used for APP fault troubleshooting in non-China mainland versions, China mainland version does not access this SDK)
Operator: Google LLC
Collected Information: Device model, system version, app version, crash logs, session identifier;Supplement: Session identifier is randomly generated anonymous string, does not associate user identity; all information only stored on Google Firebase overseas servers, only used for fault troubleshooting, not shared with other third parties
Data Storage Period: Crash data saved for 90 days, automatically anonymized processing upon expiration
Closing Method: Non-China mainland users can close Google service permissions in device system settings to stop this SDK's data collection
Privacy Policy: https://firebase.google.com/support/privacy
Third-Party SDK Supplementary Notes:
1. All accessed SDKs undergo security assessment, only accessing SDKs necessary for achieving services, no redundant SDKs;
2. Information collected by SDKs is used for achieving corresponding functions, no over-scope collection;
3. We will sign data processing agreements with SDK operators, clearly defining data security responsibilities;
4. You can view all accessed SDK lists, purposes, collected information types in APP "My - Settings - Privacy Settings - SDK Management", and close non-essential SDK usage (closing does not affect basic APP functions);
5. When SDK versions update, if involving information collection scope changes, we will notify you through pop-ups and re-obtain your consent.

V. How We Store and Protect Your Personal Information

(1) Information Storage Location
We will store your personal information collected and generated during operations within China in accordance with laws and regulations. If cross-border transmission is required, we will separately obtain your authorization and consent.
Supplement:
1. Storage servers located within China (compliant Alibaba Cloud/Tencent Cloud data centers);
2. If cross-border transmission required (such as when you use services overseas), will separately pop up to inform you of transmission purpose, recipient, security measures, you can choose whether to agree;
3. Cross-border transmitted information will use encryption transmission, signing cross-border data transmission agreements, and other methods to ensure security.

(2) Storage Period
To enable you to use our products and/or services and effectively handle possible disputes, unless otherwise required by laws and regulations, our storage time for your personal information will be limited to the shortest time necessary to achieve the purposes you authorized for use, and after exceeding the above period, we will delete your personal information or anonymize it (that is, process your personal information so your identity cannot be identified by any third party). After you cancel your account, we will stop providing you with products and services, and according to your requests, delete your personal information or anonymize it. However, exceptions exist for data retained due to requirements of national laws, regulations, rules, normative documents, or government policies, commands, etc., or to fulfill our compliance obligations, for example: The Cybersecurity Law of the People's Republic of China requires taking technical measures to monitor, record network operation status, cybersecurity incidents, and retaining related network logs for no less than six months according to regulations.Supplement:
1. Different types of information storage periods:
• Account information (phone number, password hash): Saved until 15 days after you cancel your account (used for handling pre-cancellation pending matters);
• Device connection information (MAC address, device ID): Saved until 30 days after you unbind your device;
• Conversation data: Real-time processing, not stored;
• Sports/health data: Saved until you delete data or cancel your account;
• Log information: Saved for 6 months, anonymized processing upon expiration;
• Marketing activity/questionnaire research information: Saved until 15 days after activity ends;
2. Account cancellation process: You can submit cancellation application in APP "My - Settings - Account Security - Cancel Account", after cancellation application approval, except for information required to be retained by laws and regulations, remaining information completed deletion/anonymization within 15 days;
3. After storage period expires, use irreversible deletion method (including server data, backup data) to ensure unrecoverable.

(3) Ceasing Operations
If we terminate services or operations, we will notify you at least thirty days in advance in the form of individual delivery or announcement and promptly stop collecting your personal information. After terminating services or operations, we will delete or anonymize the personal information we hold, and simultaneously require third parties commissioned to process personal information to terminate cooperation and delete or anonymize your personal information according to agreements. To better protect your rights and interests, we will provide you with channels to download, copy, and destroy your personal information, for security purposes, you may need to provide written requests, or prove your identity in other ways.
Supplement:
1. Cessation of operations notification methods: APP pop-ups, SMS, email, official website announcements, app store announcements, and other methods;
2. Personal information download/copy channels: APP provides data export function internally ("My - Settings - Data Management - Export Personal Data"), supports exporting account information, device information, sports data, etc.;
3. After data deletion completed, will send confirmation notification to you;
4. If unable to notify 30 days in advance due to force majeure, will immediately notify after restoring communication and handle personal information as soon as possible.

(4) Security Measures
(a) We highly value your personal information security, will strive to take various reasonable security measures (including technical and management aspects) compliant with industry standards to protect your personal information, prevent data from inappropriate use or unauthorized access, public disclosure, use, modification, damage, loss, or leakage.
Supplement: Technical measures include but are not limited to: data encryption storage (AES-256 algorithm), transmission encryption (HTTPS/TLS 1.3), access control (minimum privilege principle, multi-factor authentication), data desensitization (partial hiding of sensitive information), vulnerability scanning/penetration testing (at least once per quarter).
(b) We will use encryption technology, anonymization processing, and other reasonably feasible means to protect your personal information, and use trusted protection mechanisms to prevent your personal information from malicious attacks.
Supplement: Encryption technology covers data storage, transmission, and usage throughout the entire process; anonymization processing uses industry standard algorithms to ensure reverse identification is impossible; deploy WAF/IDS/IPS and other security equipment to prevent malicious attacks.
(c) We will establish specialized security departments, security management systems, and data security processes to ensure your personal information security. We implement strict data display and access systems to ensure only authorized personnel can access your personal information, and periodically audit data and technology for security.
Supplement:
• Security Management Systems: Include data classification systems, access approval systems, operation log systems, personnel confidentiality agreements, etc.;
• Personnel Management: Security training (at least twice annually for all staff), background checks, regular permission reviews (once per quarter);
• Security Audits: Internal audits (once every half year), third-party audits (once annually);
• Emergency Response: Develop data leak emergency response plans, if information leak occurs, immediately activate emergency response plan, take remedial measures, and inform you within 72 hours (except where required by laws and regulations).

(5) Data Security Emergency Response Mechanism
Supplementary Content:
1. Emergency Response Organization: Establish emergency response team consisting of company executives, security department, legal department, responsible for handling data security incidents;
2. Incident Classification: Classify data security incidents into general, major, significant, and extremely significant levels based on leaked information type, quantity, impact scope;
3. Handling Process:
• Discovery: Discover incidents through security monitoring systems, user feedback, third-party notifications, etc.;
• Assessment: Emergency team immediately evaluates incident level, impact scope;
• Handling: Take measures such as cutting off attack sources, suspending related services, fixing vulnerabilities, backing up data, etc.;
• Notification: Inform affected users within specified time according to incident level, report to regulatory authorities if required;
• Rectification: After incident handling completed, analyze causes, improve security measures;
4. Compensation Measures: If information leak caused by our reasons results in your losses, we will legally bear compensation responsibility.

VI. Your Rights Regarding Your Personal Information

Supplementary Content:
According to laws and regulations such as the Personal Information Protection Law, you have the following rights regarding your personal information, we provide you with convenient channels to exercise these rights:
1. Right to Know: You can view all personal information types we collect about you, storage periods, usage purposes, sharing/transfer situations in APP "My - Settings - Data Management - View Personal Information";
2. Right to Access/Copy: You can download/copy your personal information in the above page (supports export as PDF/Excel format), effective immediately after application;
3. Right to Correction: If you find personal information incorrect, you can submit correction application in the above page, we will review and handle within 15 working days;
4. Right to Delete: You can apply to delete specific personal information (such as sports data, emergency contact information) in the above page, except for information required to be retained by laws and regulations, deletion applied immediately;
5. Right to Withdraw Consent: You can withdraw authorization consent for any function in "My - Settings - Privacy Settings - Authorization Management", withdrawal immediately stops corresponding information collection and use;
6. Right to Cancel: You can submit cancellation application in "My - Settings - Account Security - Cancel Account", after approval complete data deletion/anonymization within 15 days;
7. Right to Portability: You can apply to transfer your personal information to other service providers, we will provide industry-standard data format within 15 working days;
8. Right to Refuse Automated Decision-Making: We do not use automated decision-making methods for targeted push notifications/marketing to you, if enabled later, will provide closing channels;
9. Right to Complaints and Reports: If you believe our processing of personal information violates laws and regulations or this policy, you can provide feedback through "My - Customer Service Center - Complaints and Reports" or contact customer service hotline 400-xxxx-xxxx, we will reply with handling results within 7 working days.
Limitations on exercising rights: If exercising rights may endanger national security, public interest, or hinder investigation and evidence collection in statutory situations, we may refuse your request and explain reasons.

VII. Terms for Minors

Supplementary Content:
1. Scope of Application: This clause applies to minors under 14 years old using our services;
2. Guardian Consent: Minors using services must obtain guardian's express consent, we will confirm with guardians through pop-ups, SMS, etc.;
3. Information Collection Limitations:
- Only collect minimum necessary information for achieving services (such as device ID for binding devices), do not collect minors' portraits, biometric identification, travel trajectories, and other sensitive information;
- Do not push marketing information to minors, do not allow minors to participate in marketing activities;
4. Information Protection: Minors' personal information uses encrypted storage, only guardians can view/manage;
5. Content Review: Strictly review content accessible to minors, filter illegal, non-compliant, unsuitable content;
6. Guardian Rights: Guardians can view/correct/delete minors' personal information, can apply to cancel minors' accounts, can restrict minors' service usage duration/functions;
7. Contact Methods: If guardians find minors' personal information improperly collected, can contact customer service hotline 400-xxxx-xxxx for feedback, we will handle within 7 working days;
8. Third-Party Limitations: Do not allow third-party SDKs to collect minors' personal information, if necessary, requires separate consent from guardians.

VIII. How Your Personal Information Is Transferred Globally

Supplementary Content:
1. Principle: We only store and process your personal information within China, no cross-border transmission under normal circumstances;
2. Cross-Border Transmission Scenarios: Only possible under the following circumstances:
• You use our services overseas and actively apply for cross-border transmission;
• Required by laws and regulations or judicial/administrative organs;
• Mergers/acquisitions involving overseas entities;
3. Security Assurance:
• Before cross-border transmission will separately obtain your written consent (or pop-up confirmation), inform transmission purpose, recipient, security measures;
• Sign cross-border data transmission agreements with recipients, requiring recipients to comply with Chinese laws and regulations and this policy;
• Use encryption transmission, data desensitization, and other methods to ensure information security;
4. Regulatory Filing: If involving important data cross-border transmission, will complete security assessment/filing according to the Data Export Security Assessment Measures.

IX. Changes to This Privacy Policy

Supplementary Content:
1. Change Trigger Conditions: If laws and regulations update, service functions change, information processing methods change, etc., we may modify this policy;
2. Change Notification Methods: At least 7 days before modification inform you through APP pop-ups, official website announcements, SMS/email, etc., major changes will have separate pop-up confirmation;
3. Major Change Scope: Includes but is not limited to expanded information collection scope, changed sharing/transfer objects, extended storage periods, cross-border transmission, etc.;
4. Change Effectiveness: Modified policy takes effect from the effective date stated in the notification, if you continue using services, considered agreement to modified policy;
5. Historical Versions: You can view all historical versions and change records of this policy in official website "Privacy Policy - Historical Versions".

X. Dispute Resolution

Supplementary Content:
1. Negotiation: If you have objections to this policy or personal information processing, you can negotiate resolution with us through email jiangsenlin@genesbot.com;
2. Complaints: If negotiation fails, you can complain to regulatory authorities such as Shenzhen Cyberspace Administration, Shenzhen Consumer Association;
3. Litigation: You can also file a lawsuit with Shenzhen Longgang District People's Court;
4. Burden of Proof: Disputes arising from personal information processing, burden of proof rests with us (except where otherwise provided by laws and regulations).

XI. Appendices

Supplementary Content:
1. Definitions:
• Personal Information: Refers to various types of information related to identified or identifiable natural persons recorded electronically or otherwise, excluding anonymized information;
• Sensitive Personal Information: Refers to personal information that is easily likely to cause infringement of personality rights or harm to personal or property security if leaked or illegally used, including biometric identification, religious beliefs, specific identity, medical health, financial accounts, travel trajectory information, as well as personal information of minors under fourteen years old;
• Anonymization: Refers to the process of processing personal information so specific natural persons cannot be identified and cannot be restored;
• De-identification: Refers to the process of processing personal information so specific natural persons cannot be identified without additional information;
2. Policy Effectiveness: This policy supplements the terms of service, having equal legal effect as the terms of service, if conflicts exist, this policy prevails;
3. Language Versions: This policy has Simplified Chinese version, if translated to other languages, Simplified Chinese version prevails;
4. Contact Methods: Our personal information protection officer contact: email jiangsenlin@genesbot.com

XII. Other

Contact Information

• If you have any questions, suggestions, or complaints about this privacy policy, you can contact us through the following methods:

• Privacy Email: jiangsenlin@genesbot.com

• Company Address: Room 712, Building B Zone C, Baoneng Zhichuang Valley, Pinghu Street, Longgang District, Shenzhen, Guangdong Province

• Feedback Channel: APP "My - Feedback - Privacy Feedback"

• We will reply to your questions/feedback within 15 working days.