How the XMEye app collects, uses, and protects your personal information.
2023/01/05
Update date: January 5, 2023 Effective date: January 4, 2021
We (the company and its subsidiaries, referred to as "we" or "the company") take the protection of personal privacy very seriously. This mobile privacy policy explains how personal information is handled and protected when you use our products and services, including related mobile applications (collectively referred to as "products").
When using our products, please read this privacy policy carefully to understand our purposes and security measures for collecting and processing your personal data — including how we use, store, share, and transfer it.
You may exercise your privacy rights, access rights, and deletion rights to personal data by following the instructions provided. By agreeing explicitly or by continuing to use our products without expressing contrary opinions through proper contact methods, you agree to this policy.
For mobile applications of other brands supported by our company, customers decide what personal information to collect. This policy does not govern other brands' data collection or processing principles.
Account and profile information:
When you register an account, we may collect your name, email address, phone number, username, and login credentials. During product use, we may also collect nickname, country code, language preference, or timezone settings. When you authorize third-party account login, we obtain the shared account information and link it to your account in compliance with the third-party agreement.
Feedback:
When you use the feedback function, we collect your email address, phone number, feedback content, and operation logs to address problems promptly. We also collect product serial numbers and verification codes as basic information required for binding products and providing remote access services.
Device information: MAC address, IP address, Wi-Fi connection details, operating system type and version, app version number, push notification identifiers, log files, and mobile network information.
Usage information: Information about visits, clicks, downloads, messages sent and received, and other interactions with the app and services.
Log information: System and exception logs including IP address, language, OS version, access dates and times.
Location information: When you enable location services, we collect and use location data to configure smart devices. When motion detection alerts are enabled, we capture camera screenshots and push them as reminder messages. You can disable this in account settings.
Voice/audio: When using the two-way audio intercom feature, we collect submitted audio content. You can refuse by disabling microphone permissions in your device settings, but this will prevent use of this feature.
Camera: QR code scanning requires camera access. You can refuse in device settings, but this will prevent using QR-based features.
Storage: Saving photos to your device requires read/write access to storage. You can revoke this permission, but saving images will be unavailable.
Sharing: Using device or video sharing features may require submitting nicknames and relationship information. Sharing functions disclose personal information within specified scopes; please consider this carefully.
IMEI: Alarm push notifications require Token information (including third-party push SDKs) which uses IMEI data. Refusing will affect normal push service.
Device MAC address: Wi-Fi network configuration requires the device MAC address. Refusing will affect network setup.
Installed applications: On app launch, we check whether Facebook, WeChat, and Line are installed to determine which login options to display.
Basic device information: When you connect smart devices to our services, we may collect device name, device ID, online status, activation time, firmware version, and update information.
Device-reported data: Depending on the connected device type, we may collect data reported by smart devices, such as alarm events triggered by surveillance cameras.
We process personal information for the following purposes:
We only share personal information in ways you are aware of. We may share with:
Per applicable information security regulations, prior consent is not required in the following cases:
To support global operations, personal information may be transferred, stored, and processed in jurisdictions outside your country of residence. We ensure adequate protection through EU Standard Contractual Clauses approved under Article 46 of GDPR and other appropriate mechanisms.
| SDK | Purpose | Data Involved | Privacy Policy |
|---|---|---|---|
| WeChat Login | Third-party account login | Network status, Wi-Fi status, external storage | WeChat Privacy |
| Facebook Login | Third-party account login | Network status, Wi-Fi status, external storage | Facebook Privacy |
| Line Login | Third-party account login | Network status, Wi-Fi status, external storage | Line Privacy |
| Huawei Push | Message push (Huawei devices) | Network status, Wi-Fi status, external storage | Huawei Privacy |
| Tencent Bugly | Crash reporting | Network status, Wi-Fi status, device info | Bugly Agreement |
| BeiZi SDK | Advertising strategy, crash optimization | Device ID, device model, OS version, screen info | BeiZi Privacy |
| Pangolin SDK | Advertising attribution, anti-fraud | Device model, OS, app list, network info, device ID | Pangolin Privacy |
| Youlianghui SDK | Ad placement, crash optimization | Device ID, location, sensor data | Youlianghui Privacy |
| Baiqingteng SDK | Push refinement, power optimization | Device ID, IMEI, location, app list | Baiqingteng Privacy |
| Kuaishou SDK | Advertising attribution, anti-fraud | Device model, OS version | Kuaishou Privacy |
| InMobi SDK | Advertising attribution, anti-fraud | Device ID, carrier, IP, OS, language | InMobi Privacy |
| ZXing | QR code scanning | Camera permission | — |
| Permission | Purpose |
|---|---|
| READ/WRITE_EXTERNAL_STORAGE | Photo album access and third-party ad SDK |
| CAMERA | Device serial number QR code scanning |
| RECORD_AUDIO | Live preview two-way audio intercom |
| INTERNET | Wireless communication with devices |
| ACCESS_NETWORK_STATE | Network status and Wi-Fi configuration |
| ACCESS_WIFI_STATE | Wi-Fi status and hotspot information |
| WAKE_LOCK | Keep screen on during QR code network configuration |
| BLUETOOTH | Bluetooth device operations |
| ACCESS_FINE_LOCATION | Wi-Fi hotspot access and third-party ad SDK |
| FOREGROUND_SERVICE | Background push notification service |
| Feature | Purpose |
|---|---|
| Location | Get Wi-Fi hotspot information |
| Local Network | Device network configuration and local search |
| Camera | Scan device QR code |
| Notifications | Device alarm push |
| Microphone | Device two-way intercom |
| Photo Library | Save screenshots |
| Tracking | Ad attribution (IDFA) |
You have the right to access your personal information. Through the app:
For information collected for security or operational purposes that cannot be directly accessed, please contact us to request deletion or anonymization.
You can directly delete account registration information by going to Homepage → My → Account → Delete Account.
You may also request deletion in the following circumstances:
After responding to a deletion request, we also notify third parties who obtained your data and require them to delete it, unless otherwise required by law. Backup copies may not be immediately deleted but will be removed upon the next backup update.
You may change the scope of your consent or withdraw authorization by deleting information, disabling specific features, adjusting privacy settings in the app, or managing app permissions on your device. You can withdraw all authorization by canceling your account.
Note: Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
You can cancel your account at any time via: Homepage → My → Account → Delete Account, or by contacting customer service.
Account cancellation is irreversible. After cancellation, all account rights and stored personal information will be deleted and cannot be retrieved, unless otherwise required by law.
We currently do not make decisions using non-manual automated mechanisms. If such technologies are used in the future, we will notify you in advance and provide the right to appeal any decision that significantly affects your legal rights.
To obtain a copy of your personal information or for other data rights requests not covered above, please contact us via email or through the contact methods in this policy. We will respond within 15 days of verifying your identity.
For reasonable requests, no fees are charged. For unreasonably repetitive or technically complex requests, we may charge a reasonable cost or decline.
We may not respond in the following circumstances: national security matters, criminal proceedings, protection of life or property, requests showing malicious intent, trade secrets, or other legally stipulated situations.
We take reasonable measures to protect your personal information, including:
Where business functions require biometric data (such as facial recognition), we store only summary information using AES encryption. Identity authentication based on biometrics is performed locally on the device; verification results only are returned to our servers.
Although we implement reasonable security measures, no internet transmission is completely secure. We strongly recommend:
In the event of a personal information security incident, we will promptly notify affected users by email, letter, phone, or push notification regarding: the nature of the incident, its potential impact, the measures we have taken, and steps users can take to protect themselves. We will also report to the relevant regulatory authorities as required by law.
Personal information is retained only for the period necessary to fulfill the purposes described in this policy, or as required by law. After the retention period, information is destroyed. Where immediate destruction is technically infeasible, appropriate measures are taken to prevent further use.
Our services are built on Amazon Web Services (AWS) Infrastructure as a Service.
We place great importance on protecting minors' personal information. Our products and services are intended for adults with full legal capacity. If you are under 18, please have a parent or guardian read this policy and obtain their consent before using our services or providing any information.
When collecting minors' personal information with parental or guardian consent, we only use or disclose it as permitted by law, with explicit parental consent, or when necessary to protect the minor.
Parents or guardians who believe a minor has submitted personal information without prior consent may contact us through the methods listed in this policy.
We may update this policy at least once per year. For significant changes, we will notify users by email (to the address registered with your account) or by posting a prominent notice on our website before the change takes effect. We recommend reviewing this page regularly for the latest privacy practices.
If you have questions about our practices or this policy, please contact us:
Under normal circumstances, we will reply within fifteen (15) business days.
If you are unsatisfied with our response — especially if our personal information processing has harmed your legitimate rights and interests — you may file a complaint or report with the relevant regulatory authorities (cyberspace, telecommunications, public security, or market regulation).