Effective Date: December 15, 2025Issuing Entity: Zhengzhou Qianshu Network Technology Co., Ltd. (hereinafter referred to as "the Company")
Zhengzhou Qianshu Network Technology Co., Ltd. (hereinafter referred to as "the Company") aims to process users' personal information in compliance with the basic principles of privacy protection and relevant data protection laws and regulations, in particular the Personal Data Protection Law No. 6698(hereinafter referred to as the "Personal Data Protection Law") and other applicable regulations. In addition to the Personal Data Protection Law, if the EU General Data Protection Regulation (Regulation 2016/679, "GDPR") applies, this Policy shall also specify the additional rights enjoyed by individuals.
The personal information you have provided/will provide to the Company and/or the Company has obtained through any external channels may be processed by the Company as a data controller in the following ways:
Process the data in a necessary and appropriate manner based on the purposes of personal information processing and relevant connections;
Ensure that personal information is accurate, consistent with the content declared or notified to the Company, and updated in a timely manner;
Record, store, preserve, and organize personal information, and provide relevant information as required by legally authorized authorities; under the circumstances specified by laws and regulations, and with your explicit consent when necessary, transmit, classify, and share personal information with third parties inside and outside the territory;
Process personal information by other methods specified by laws and regulations and comply with other procedural requirements stipulated by laws and regulations.
This Privacy Policy is intended to ensure that the Company continuously conducts and improves relevant business activities in accordance with the principles specified in the Personal Data Protection Law.
This Privacy Policy will explain to you the types of data we collect, how we use, store, protect, and share the collected data, the ways for you to withdraw your consent to data processing, and the methods for data correction and modification.
Unless otherwise defined, all capitalized terms in this Policy shall have the same meanings as those defined in the Terms of Service.
The Company will only process your personal information for the purposes specified in this Privacy Policy.
The personal information of users collected and used by the Company mainly includes: messages, phrases, texts, information, photos, images, videos, screenshots and other data uploaded or transmitted by you to the "AI Health Tracker" application (hereinafter referred to as "AI Health Tracker"); specific health information detailed below; and Internet Protocol (IP) address.
Identification and Contact InformationName, surname, phone number, and email address (only when you take the initiative to contact the Company)
Process Security InformationInternet traffic data (network activities, IP address, access data, time and date information, information related to your access and use of the Company's application, duration of use in AI Health Tracker, number of daily logins), device name, token ID (only when you allow receiving notifications through the device), Android ID, GAID
User-Generated ContentMessages, posts, communication records, statements, information, phrases, entries, texts, questions, replies, answers, options; files, documents, links, images, photos, videos, screenshots, charts, media files and similar materials and their accompanying texts.
Health Information
Terms for Processing Biometric Information
Collection Scenarios and Data Types: When using the health detection function, you need to authorize the device camera permission. We will collect facial images, blood flow characteristics, and physiological indicators such as heart rate, respiratory rate, and heart rate variability.
Processing Purposes: The above data is only used to generate health analysis reports and provide health recommendations.
Security Measures: Data will be encrypted and transmitted to servers located within the territory of China, and de-identified during storage to ensure that it cannot be directly associated with personal identity. Original biometric data is only used for real-time analysis, not stored for a long time, and will not be shared with third parties.
Supplementary Explanation: We adhere to the principle of data minimization and only collect personal information necessary for functions such as health detection, account management, and security assurance. If you refuse to provide non-essential information, it may affect the experience of some functions, but will not hinder the normal use of basic services.
Brief Explanation of User RightsWe collect the above information mainly to provide services (e.g., tracking heart rate, calculating heart rate variability, etc.). Your health information (excluding gender and age) is only stored locally on your device and will not be transmitted to the Company's servers for processing. Unless you voluntarily choose to share, such data will not be disclosed to third parties.You may request the deletion of such data (and exercise other rights) at any time. For details of your specific rights regarding such data, please refer to the relevant provisions of this Privacy Policy.
Marketing Data
The Company may directly collect the above data from you through electronic or physical media, your mobile device, third-party applications, or third-party channels through which you can access the Company's application (such as the Apple App Store, Google Play Store, collectively referred to as "App Stores") and similar platforms, to fulfill legal obligations, improve service quality, manage your use of the Company's services, and provide you with a more convenient service experience.
We may collect log data generated when you use the Company's services/applications (through the Company's products or third-party products). Such log data may include the Internet Protocol (IP) address of your device, device name, operating system version, application configuration when using the Company's services/applications, time/date of using the services/applications, and other statistical information.
As a data controller, the Company will process personal information in accordance with the following basic principles pursuant to this Privacy Policy:
Principle of compliance with laws and regulations and good faith;
Principle of ensuring accuracy and timely update when necessary;
Principle of processing information for specific, clear and legitimate purposes;
Principle of being compatible with processing purposes and adhering to data minimization;
Principle of storing information for the period specified by relevant laws and regulations or the reasonable period necessary to achieve the processing purposes.
In accordance with applicable laws and regulations, as well as the provisions of Articles 5 and 6 of the Personal Data Protection Law (circumstances explicitly permitted by law, circumstances of entering into a contract or directly related to the performance of the contract, and circumstances of realizing the Company's legitimate interests on the premise of protecting your fundamental rights and freedoms), the Company will process your personal information through automatic or non-automatic means for the following purposes.
Subject to the above general conditions, your personal information will be used for the following purposes in accordance with the provisions of this document:
Identification and Contact InformationConduct business activities in compliance with regulatory requirements; comply with laws and regulations to protect individuals' rights, privacy and security; conduct operational activities related to the Company's/product/service commitments; conduct communication-related activities; conduct/audit business activities; provide after-sales services for goods/services, communicate with you to send relevant information or service information (with your consent) and service-related marketing information; conduct sales processes for goods/services; conduct storage and archiving activities; conduct agreement-related processes; product operation.
Process Security InformationConduct information security-related processes; conduct audit/compliance activities; conduct/audit business activities; conduct activities to ensure business continuity; provide information to authorized individuals, institutions and organizations.
Customer Transaction InformationConduct/audit business activities; provide after-sales services for goods/services; conduct sales processes for goods/services; conduct customer satisfaction-related activities; conduct agreement-related processes.
User-Generated ContentProduct operation (e.g., generating response content based on your input); provide after-sales services for goods/services, communicate with you to send relevant information or service-related content; conduct business activities in compliance with regulatory requirements; comply with laws and regulations to protect individuals' rights, privacy and security; prevent crimes and other illegal activities; conduct agreement-related processes; conduct storage and archiving activities; conduct/audit business activities; conduct activities to ensure business continuity; conduct customer satisfaction-related activities.
Health InformationService operation (e.g., displaying your heart rate data); provide service-related support services and information; fulfill legal obligations and ensure compliance with regulatory requirements.
Marketing DataConduct marketing analysis and research; conduct processes related to advertising/marketing activities/promotions.
In addition, the purposes of personal information processing may be updated in accordance with the Company's policies and obligations specified by laws and regulations, including in particular:Create accounts for service recipients/application users; customize the Company's services, understand users and their preferences to improve user experience and satisfaction, and optimize user experience; inform users of new products, services and application information, and send you advertising and promotion-related information; process digital subscriptions and in-app purchase processes of service recipients; process automatic renewal subscription services to enable users to access content, services or premium features in the Company's services; conduct information security-related processes; conduct business activities in compliance with regulatory requirements; respond to requests from competent authorities; conduct financial and accounting-related processes; conduct communication-related activities; conduct contract-related processes; conduct strategic planning activities; follow up on user requests and complaints.
Identification and Contact InformationProcessing your personal information is necessary for establishing a contractual relationship with you or directly related to the Company's performance of contractual obligations; the Company must process relevant data to establish, exercise and safeguard its own rights; obtaining your consent (e.g., you agree that the Company sends you marketing materials).
User-Generated ContentProcessing your personal information is necessary for establishing a contractual relationship with you or directly related to the Company's performance of contractual obligations; the Company must process relevant data to establish, exercise and safeguard its own rights; processing information is necessary to realize the Company's legitimate interests on the premise of not impairing your fundamental rights and freedoms; processing information is necessary for the Company to fulfill its legal obligations; obtaining your consent.
Health InformationObtaining your explicit consent to the processing of health data; processing your personal information is necessary for establishing a contractual relationship with you or directly related to the Company's performance of contractual obligations; the Company must process relevant data to establish, exercise and safeguard its own rights; processing information is necessary for the Company to fulfill its legal obligations.
Process Security and Application DataCircumstances where laws explicitly stipulate that the Company may process your personal information; circumstances necessary for fulfilling the Company's legal obligations; processing your personal information is necessary for establishing a contractual relationship with you or directly related to the Company's performance of contractual obligations; processing information is necessary to realize the Company's legitimate interests on the premise of not impairing your fundamental rights and freedoms; obtaining your consent.
Marketing DataObtaining your explicit consent (obtained through Apple and/or Google platforms).
AI Health Tracker may contain links to other websites or applications that are unknown to the Company and whose content is not controlled by the Company. The terms of such linked websites or applications may differ from those of the Company, and the Company shall not be liable for the use or disclosure of information that may be processed by such websites or applications. Similarly, the Company shall not be liable for any links to the Company's AI Health Tracker provided by other websites or applications.
We collect information in a fair and legal manner only with your informed consent. At the same time, we will explain to you the reasons for collecting information and how it will be used. You are free to refuse our information collection requests, but please note that without such information, we may not be able to provide you with some of the services you need.
When using the AI Health Tracker application, you may provide information to the Company through third-party websites and applications. Please be aware that your responsibilities and obligations to third-party applications or websites remain valid, and the Company shall not be liable for any terms, conditions, rules or policies formulated by third parties.
Cookies are small text files stored on the browser or hard disk of your computer or mobile device when you visit a web page or application. Cookies can improve the operating efficiency of websites, realize personalized web page display, and provide you with a faster and more personalized access experience. Cookies only contain historical data of your access to websites through the Internet, and will not collect any personal data/files stored on your computer or mobile device. We may use Cookies when operating services, improving service performance and functions, and providing content (including advertisements) related to your interests on our website or third-party websites. You can delete existing Cookies on your computer and prevent Internet browsers from recording/storing Cookies.
Internet browsers are set to automatically accept Cookies by default. Since different browsers manage Cookies differently, you can check the help menu of your browser or application for detailed operation information.
Your data will be stored for the period specified by applicable laws and regulations, or the reasonable period necessary to achieve the processing purposes, or during the statutory limitation period for litigation.
If required by other laws or you grant additional authorization, the Company may continue to store your personal information even after the expiration of the period required for the purpose of use.
If you agree to allow the Company to extend the storage period of personal information, such data will be immediately deleted, destroyed or anonymized when the extended storage period expires or the processing purposes cease to exist.
The Company will store the personal information it processes for the period specified by relevant laws and regulations or the period necessary to achieve the processing purposes. The Company commits to taking all necessary technical and administrative measures and exercising due diligence to ensure the confidentiality, integrity and security of personal information. Under this premise, we will take necessary measures to prevent the illegal processing, unauthorized access, illegal disclosure, modification or damage of personal information. Correspondingly, the Company adopts the following technical and administrative protection measures for the personal information it processes:
Antivirus Programs: Install regularly updated antivirus programs on all computers and servers of the Company's information technology infrastructure.
Firewalls: Data centers and disaster recovery centers hosting the Company's servers are all equipped with regularly updated software firewalls; relevant next-generation firewalls will control the Internet connections of all employees and prevent viruses and similar security threats during the control process.
Virtual Private Network (VPN): Suppliers may access the Company's servers or systems through SSL-VPN configured in the firewall. Each supplier is assigned an independent SSL-VPN identifier; through this identifier, suppliers can only access the systems they need for work or are authorized to access.
User Identity Authentication: The system permissions of the Company's employees are strictly limited to the scope required by their job responsibilities; if an employee's permissions or responsibilities change, their system permissions will be updated synchronously.
Information Security Threat and Incident Management: Security incidents occurring on the Company's servers and firewalls will be reported to the "Information Security Threat and Incident Management System". When a security threat is detected, the system will issue an early warning to the relevant person in charge so that they can take immediate response measures.
Encryption Technology: Sensitive data will be stored in an encrypted manner and transmitted in an encrypted environment when necessary; encryption keys will be stored in a secure and diversified environment.
Log Recording: All transaction records related to sensitive data will be securely recorded.
Two-Factor Authentication: Remote access to sensitive data requires authorization through at least two-factor authentication.
Penetration Testing: Regular penetration testing is conducted on servers in the Company's system. Security vulnerabilities found in the test will be repaired in a timely manner, and the elimination of vulnerabilities will be confirmed through verification testing. In addition, the Information Security Threat and Incident Management System will automatically perform penetration tests, and the test results will be recorded and archived.
Information Security Management System (ISMS): In the ISMS meetings held within the Company, the topics involved in the control forum will be reviewed monthly by the Chief Information Officer and the Chief Financial and Operations Officer.
Employee Training: Regular training is provided to employees to improve their awareness of various information security violations and minimize the impact of human factors on information leakage incidents.
Physical Data Security: Personal information stored on paper carriers must be kept in locked file cabinets and only accessible to authorized personnel. Adequate security protection measures (such as protection against electric leakage, fire, flood, theft, etc.) are taken according to the characteristics of the sensitive data storage environment.
Data Backup: The Company regularly backs up stored data. Backup mechanisms include using backup services provided by cloud infrastructure providers, and when necessary, adopting independently developed backup solutions in accordance with relevant laws and regulations and the requirements of this Policy.
Confidentiality Agreements: Sign confidentiality agreements with employees involved in the processing of sensitive personal information.
Transmission of Sensitive Personal Data: If sensitive personal data needs to be transmitted via email, it must be done through the following methods: (1) encrypted corporate email; (2) registered email.
Despite the necessary information security measures taken by the Company, if AI Health Tracker or the Company's systems are attacked, resulting in damage to personal data or unauthorized access to personal data by third parties, the Company will immediately notify users and, if necessary, report to the relevant data protection authority, and take necessary remedial measures.
The Company does not allow minors under the age of 16 to use this application.
The Company will not intentionally collect or process personal information of individuals under the age of 16. If you find that an individual under the age of 16 has provided us with personal information, please contact us via email at qianshu41@gmail.com. Users under the age of 18 must obtain the consent of their parents or legal guardians to use the Company's services.
The procedures and principles for the transmission of personal information shall comply with the provisions of Articles 8 and 9 of the Personal Data Protection Law. Given that the Company may use servers and cloud systems located outside the territory, users' personal information and special category data may be transmitted to third parties inside and outside the territory.
Your personal information may be transmitted outside the territory for the following reasons:
Conducting storage and archiving activities;
Conducting business activities;
Providing after-sales services for goods/services;
Managing customer relationship management processes.
The Company may also transmit your personal information to the Company's service providers and third parties embedded in the Company's services (such as Facebook SDK, Adjust, Google Analytics) for the following purposes:
Sharing identification, communication and transaction security information with legally authorized authorities to conduct activities in compliance with regulatory requirements, supervise and handle legal matters, and provide information to authorized individuals, institutions and organizations;
Sharing identification and contact information to manage after-sales services, conduct business activities and manage customer relationship management processes.
Pursuant to the provisions of Article 11 of the Personal Data Protection Law, you may submit an application to the Company to exercise the following rights with respect to your personal information:
Confirm whether your personal information is being processed;
Request to be informed whether your personal information is being processed;
Understand the purposes of personal information processing and whether the data is used in accordance with the established purposes;
Know which third parties (inside and outside the territory) your personal information has been transmitted to;
If the processing of personal information is incomplete or incorrect, request to notify the third parties that have received the personal information of the relevant processing status;
If the purpose of processing ceases to exist, request the deletion, destruction or anonymization of personal information, and request to notify the third parties that have received the personal information of the relevant processing status;
Object to adverse results arising solely from the analysis of personal information through automated systems;
Request compensation if you suffer losses due to the illegal processing of personal information.
If the EU GDPR applies, data subjects shall also enjoy the following additional rights:
Right of Access — Confirm whether personal information is being processed; if so, access your personal information and relevant processing information;
Right to Rectification — Request the Company to correct information you believe is inaccurate or supplement incomplete information;
Right to Erasure — Request the deletion of personal information under the circumstances specified by the GDPR;
Right to Restriction of Processing — Request the restriction of personal information processing under the circumstances specified by the GDPR;
Right to Objection — Object to the processing of personal information under the circumstances specified by the GDPR;
Right to Data Portability — Request the direct transmission of data collected by the Company to another institution, or transmission under specific conditions;
Right to Object to Automated Decision-Making — Object to adverse results arising solely from the analysis of processed data through automated systems (including profiling).
When submitting an application, you need to explain the rights you enjoy as a data subject and clearly state the specific request for exercising the above rights; the content of the application must be clear and understandable; if the application is made on your own behalf or on behalf of others, you must provide written proof to obtain relevant special authorization; the application materials must include identity and address information, and be accompanied by identity documents. The Company will provide a "Data Subject Application Form" through the email address qianshu41@gmail.com as a channel for you to submit such applications. Pursuant to the provisions of Article 13 of the Personal Data Protection Law, the Company will complete the processing of your application free of charge within 30 days at the latest according to the nature of the application matter. If the application is rejected, the Company will notify you in writing or electronically of the reasons and basis for the rejection.
If you believe that the Company or the third parties to whom the Company has transmitted your data have infringed your legitimate rights, you may file a complaint with the data protection authority and other relevant regulatory authorities in your country/region.
This Privacy Policy may be revised by the Company as needed. If you continue to access AI Health Tracker and use or access the services provided by the Company after the expiration of the public notice period, it will be deemed that you agree to the revised content of this Privacy Policy.