Privacy Policy


Last Updated: August 22, 2026
 
Tinyphoton (Wuhan) Technology Co., Ltd. (hereinafter referred to as “Tinyphoton” or “we”) is a limited liability company established under the laws of the People’s Republic of China. We attach great importance to maintaining and protecting users’ personal information, and have formulated the “DWARFLAB Privacy Policy” (hereinafter referred to as “this Policy”) applicable only to the DWARFLAB App (hereinafter referred to as “this App”).
 
Before using our products or services, please carefully read and fully understand this Policy. By tapping “I agree” or using this software or service, you are deemed to have read and agreed to all the terms of this Policy.
 
This Policy will help you understand:
  1. How we collect and use your personal information
  2. How we use SDK (Software Development Kit)
  3. How we share, transfer and publicly disclose your personal information
  4. How we protect your personal information
  5. Your rights
  6. How we handle children’s personal information
  7. Storage and Cross-Border Transfer of Personal Information
  8. How this Policy is updated
  9. How to contact us
 
We understand the importance of personal information to you and will do our best to protect the security and reliability of your personal information. We are committed to maintain your trust in us and abide by the following principles to protect your personal information: the principle of consistent authority and responsibility, the principle of clear purpose, the principle of choice of agreement, the principle of minimum sufficient, the principle of ensuring security, the principle of subject participation, the principle of openness and transparency. At the same time, we promise that we will take Appropriate safety protection measures to protect your personal information in accordance with the mature safety standards in the industry.
 

1.How we collect and use your personal information

Personal information refers to various information recorded electronically or by other means that can identify a specific individual’s identity either alone or in combination with other information, or reflect specific activities of a particular individual.
 
We will only collect and use your personal information for the purposes stated in this Policy:
 

1.1 Connecting DWARF hardware products

DWARF Device Information. If you use this App to connect to a wireless local area network on an Android device, you may need to manually enter the DWARF device password. For your convenience, we provide a “Copy Device Password” button to allow you to copy the device password to the phone clipboard. By choosing to use the copy device password function, you understand and agree that this App will access your clipboard to copy the password. We have taken strict security measures to ensure that this App only accesses the clipboard when you actively choose to copy the password, and does not read the contents of the clipboard. The copied device password text will be stored in the system storage of your mobile device. We recommend that you delete the password information after use to ensure password security.
 
Region Information. To ensure that this App operates normally in different countries and regions and complies with applicable local wireless-communication requirements, we may read your mobile device’s country or region code. This information is used only for wireless-communication adaptation at the country or region level and does not include your precise location.
 
DWARF Device Connection Information. To connect to and control a DWARF device, this App may read settings for the currently connected DWARF device, including its name, connection password, and local network IP address, and store the relevant settings in this App’s internal storage. To remain compatible with already-sold DWARF device firmware, when you use device control, device album, panorama preview, or device-media access features, this App may communicate with the DWARF device through that local network IP address using HTTP. This communication occurs only within the local network shared by your phone or tablet and the DWARF device, and is used only for device connection, control, and media access. It is not used to transmit DWARFLAB account credentials, Community login credentials, cloud access tokens, or other information unrelated to the local device connection, and we do not upload that local network IP address to our servers.
 
Bluetooth & network permissions. To enable the automatic discovery and connection of DWARF devices, after you open the App and grant the relevant permissions, we may use Bluetooth permissions to discover and connect to nearby DWARF devices. In a local network environment, we may also use network permissions and UDP communication to identify available DWARF devices on the same local network. These permissions are used solely for device discovery and connection and do not involve accessing or collecting your personal information.
 
To ensure the stability of network connections between your mobile device and our hardware products, as well as to maintain proper functionality, we may request access to your Wi-Fi status/parameters and WLAN access point information (such as SSID, BSSID, RSSI, etc.). This data collection is solely for the purpose of network status detection and will not be used for user identification or data storage.
 

1.2 Device Permission Calls

In order to ensure the normal implementation of this App’s product functions, we may apply for or use access permissions for your mobile device:
Permissions
OS Involvement
Access Method
Access Purpose
Local Network Permission
iOS/Android
User Authorization
DWARF Product Search, Connect, Control
Bluetooth Permission
iOS/Android
User Authorization
DWARF Product Search, Connect
Internet Permission
iOS/Android
User Authorization
Tutorial Access, Log Upload, Firmware Upgrade, use of the App’s built-in AI Voice Assistant, Photonverse, Stellar Studio
Storage Permission
iOS/Android
User Authorization
Download Files from DWARF Product
Photo/Videos Permission
iOS/Android
User Authorization
Download photos/videos from DWARF Product
GPS Permission
iOS/Android
User Authorization
Enable GPS, Obtain Location
Precise Location Access
iOS/Android
User Authorization
Astronomical Observation, Calculate Target’s Position,Record geographic location information in JPEG images (requires users to manually enable the location tag feature)
Microphone Permission
iOS/Android
User Authorization
Voice command interaction
Downloaded files using storage and album permissions will be saved to the internal storage of your mobile device.
Other device permissions mentioned in this policy (if any) do not involve persistent storage or uploading of related data during their invocation process.
 

1.3 Explanation of GPS Permission Usage

To provide the “recording geographic location information in JPEG images” feature, when you actively enable the “Location Tag” function in this App and grant authorization, we will invoke your device’s GPS (or location-based services) permission. This permission is used to obtain and record the corresponding geographic coordinates when you capture JPEG images. This location information will be written into the image file attributes and may be visible in your device’s photo gallery or image properties. If you choose to upload images to our cloud servers, this geographic location data will be uploaded and stored together with the images.
 
If you actively choose to make the shooting location public when uploading images to the cloud, we will display the corresponding shooting location information through the access link generated for that task after your confirmation. Any internet user who obtains this link can view the relevant information you have chosen to make public. You can find the corresponding upload task within the App and modify the publicity settings for the image’s shooting location (public/private) at any time. If you wish to completely delete uploaded images and location information so that they are no longer public and are removed from our cloud servers, you need to delete the corresponding images from the task list.
The “Location Tag” feature is disabled by default. You can disable this feature at any time in the App settings. Once disabled, JPEG images captured afterward will no longer record geographic location information.
 

1.4 Disclosure on Microphone Permission Usage

This App invokes the microphone permission only when you actively activate the voice assistant and engage in voice interaction. It will not invoke the microphone silently in the background.
1. Purpose and method of collection
To enable voice command interaction, after you actively trigger voice interaction, the App collects microphone audio and transmits it through encrypted channels to a compliant and authorized cloud voice service provider solely for the current speech-to-text (STT) processing. We do not save your raw voice audio files; the compliant and authorized voice service provider also does not save the raw audio files you input. The text command generated after speech-to-text conversion will be used for subsequent large-model understanding, result generation, and text-to-speech (TTS) processing. The above processing results are used only to complete the current voice assistant interaction and will not be used for purposes unrelated to this interaction.
2. Impact of refusing authorization
If you refuse or disable microphone permission, you will be unable to use the voice assistant feature, but this will not affect your use of other features of this App.
3. Withdrawal of consent
You may go to your operating system’s Settings > Privacy > Microphone at any time to disable this permission and withdraw your consent. After withdrawal, the voice assistant feature will be unavailable.
4. Risk notice
Speech-to-text results may be inaccurate. Please independently verify their accuracy and applicability, and they are not recommended as a basis for professional decision-making in medical, legal, financial, and other fields. In the above scenarios, this platform has fulfilled its reasonable disclosure and security protection obligations, except where your loss is caused by this platform’s intentional misconduct or gross negligence.

1.5 Services and Support

Log Information. When you report bugs or suggestions to us, in order to provide solutions promptly, we may need to collect your DWARF product usage log records (including timestamps, error messages, user operations, notification information, key running records of App functions, running status of hardware products, hardware products names and passwords,and phone system version and phone model information). To facilitate contacting you, we may need to collect your email address. By using the ‘Log Upload’ feature, you understand and agree that this App obtains your log records and email address. Log data is used exclusively for troubleshooting and bug fixing, and will not be used for any other purposes.
 

1.6 Atlas Sensor Mode

When you point your mobile device towards the sky, the star atlas automatically aligns with the device’s orientation. To enable this functionality, we may utilize your device’s sensors, including the accelerometer, magnetometer, and gyroscope. This sensor data is exclusively used to determine the device’s orientation and position, facilitating the automatic alignment feature of the star map. It is important to note that this data is not used for personal identification purposes. Furthermore, the use of this feature does not disclose your specific direction or location. All data is processed temporarily and is not stored on any medium.
 

1.7 App Updates

To detect the version status of our application and provide upgrade services, we may access information about installed applications on your device when you attempt to navigate to the app marketplace for an update. This process is solely to confirm whether the target application is installed and to verify its version. This operation is exclusively used to facilitate the upgrade functionality and will not be utilized for any other purposes. We do not collect or store any personal information during this process.
 

1.8 Account Registration and Account Deletion

To complete account registration or login, you may need to provide us with the following information: phone number, email address, created username, and password. During registration, to verify your identity, we will send a verification code to your phone number or email for verification. After registering an account, you may choose to provide your nickname, avatar, and gender. Except for circumstances explicitly specified in this agreement, we will not share, transfer, or disclose your personal information.
 
You have the right to request the deletion of your DWARFLAB account at any time through the App. After the account is deleted, it will no longer be accessible or available for login. Personal information associated with the account will be deleted or anonymized in accordance with applicable laws and regulations. Once the account is deleted, it cannot be restored. Please proceed with caution.
 
Please note that refusing to provide the above information will not affect account usage. If you choose not to register an account, you can still use the App to control DWARFLAB telescopes.
 

1.9 Community

When you use Community Features, including posting updates or posts, uploading images or videos, commenting, replying, liking, favoriting, following, sharing, reporting, viewing or managing your profile page, we may collect and use community information related to your account, including account ID, nickname, avatar, profile information, text, images, videos and related descriptions that you actively post or upload, interaction records such as comments, replies, likes, favorites and follows, report and appeal records, content review status, and necessary security and risk-control records. The above information is used only to provide community content publishing, display, interaction, review, order maintenance, account security, and user rights protection functions.
 
When you select images or videos from a DWARF device album for preview or upload to the Community, this App may provide the relevant page with restricted access to device media through a temporary proxy that listens only on the loopback address of your phone or tablet. The temporary proxy permits access only to read-only images, videos, and other media actually returned and registered by the currently connected DWARF device, and is closed when you exit the page, switch the device connection, or when access times out. The selected media files are uploaded to the Community service only after you actively select and confirm the upload. For files in the system album on your phone or tablet, this App obtains access to the file you select through the Android system file picker and does not read other files you have not selected.
 
Please note that content you actively post in the Community and your nickname, avatar, profile information, interaction information and other information that you set as public may be displayed to other users. If you share relevant content to public pages or third-party platforms, it may also be viewed by more Internet users. You may delete or manage content you have posted, cancel interactions, or adjust relevant settings within the functions provided by the App. After you delete relevant content, we will delete or anonymize it in accordance with laws and regulations and to the extent technically feasible. However, due to caching, backups, or lawful saving or forwarding by other users, relevant information may not be immediately or completely removed from all display or storage locations.
If the images or videos you choose to upload contain metadata such as shooting location or EXIF information, such information may be uploaded or stored together with the file. We recommend that you confirm before posting whether the content and file metadata contain sensitive information or information you do not wish to disclose. If the App provides settings to display, hide, delete, or process location information or metadata, you may select or adjust them according to the on-page prompts.
Please do not post sensitive personal information about yourself or others, or post personal information of others without authorization in the Community. If the content you post contains personal information of others, you should ensure that you have obtained lawful authorization and bear the resulting responsibilities. To maintain community security and lawful rights and interests, we may review your posted content, handle user reports, and take necessary measures in accordance with community rules and legal and regulatory requirements.

1.10 Optimizing App Experience

To ensure the security, stability, continued availability, device compatibility, and proper functioning of the DWARFLAB App, as well as to understand how its features are used, evaluate their effectiveness, and improve the user experience, we may collect information about your device and software environment. This information may include the device brand, model, manufacturer, and type; screen specifications; operating system and version; App version and build number; language and time zone settings; App installation and runtime environment; network connection type; and device operational status, such as battery level and charging status. We may also collect records of your use of and interactions with App features, event timestamps and session information, internal user identifiers, randomly generated analytics and session identifiers, and pseudonymized identifiers generated by hashing the serial numbers of DWARFLAB hardware devices.
We use this information to maintain security, ensure compatibility, provide relevant features, diagnose and resolve technical issues, analyze product usage, deduplicate data, and improve the user experience. We do not use this information for third-party advertising purposes. If we are unable to collect information necessary to provide a particular feature, that feature may be unavailable or may not function properly, but this will not affect your use of other features of the DWARFLAB App.

1.11 Exceptions with authorized consent

You fully acknowledge that in the following circumstances, we have the right to collect and use your personal information without your authorization or consent:
(1) Directly related to national security and defense.
(2) Directly related to public safety, public health, and significant public interest.
(3) Directly related to crime investigation, prosecution, trial and execution of judgments, etc.
(4) For the protection of your or other individuals’ life, property and other significant legitimate rights and interests but it is difficult to obtain your consent.
(5) Where the personal information collected from you is disclosed to the public by you.
(6) Your personal information collected from legitimate public disclosures, such as legitimate news reports, government information disclosure and other channels.
(7) Necessary for the conclusion or performance of contracts and other written documents at your request.
(8) Necessary for maintaining the safe and stable operation of the products and/or services provided, such as the detection and disposal of product and/or service failures.
(9) Personal information controller is a news organization and necessary for the public interest its in the conduct of legitimate news reporting.
(10) Academic research institutions based on the public interest to carry out statistical or academic research necessary, and when providing the results of academic research or description to the public, de-identification or anonymization of the personal information contained in the results.
(11) Other circumstances specified by laws and regulations.
 

2.How we use SDK (Software Development Kit)s

To provide and optimize our services, third-party SDKs may be embedded in our App. While these third-party SDKs help us provide you with more comprehensive services, they may collect your personal information. We will take necessary measures to control such third parties’ collection and use of your personal information to ensure that your personal information is effectively protected. For details on the identity of third parties, the purpose of collection, links to third-party privacy policies, etc., please refer to Appendix 1 of this Policy – Description of Third Party SDKs

3.How we share, transfer and publicly disclose your personal information

3.1 Sharing

We will not share your personal information with any other companies, organizations and individuals, except for the following cases.
 
(1) Sharing with explicit consent. We will share your personal information with other parties after obtaining your explicit consent.
(2) We may share your personal information with external parties in accordance with laws and regulations, or as mandated by government authorities.
 

3.2 Transfer

We will not transfer your personal information to any company, organization, or individual, except for the following.
 
(1) Transferring with express consent. We will transfer your personal information to other parties after obtaining your explicit consent.
(2) In the event of a merger, acquisition or bankruptcy and liquidation involving the transfer of personal information, we will then require the new company or organization holding your personal information to continue to be bound by this policy, or we will require the company or organization to seek your authorized consent again for the new privacy policy.

3.3 Public Disclosure

We will only disclose your personal information publicly when.
(1) After obtaining your explicit consent.
(2) Disclosure based on law. We may publicly disclose your personal information when compelled to do so by law, legal process, litigation or government authorities.
Information that you actively publish, share, or set as public when using the Community Features, including your nickname, avatar, profile information, posted content, comments, replies, likes, follows, and other interaction information, constitutes content that you voluntarily choose to make public and may be displayed to other users on Community pages or in related sharing scenarios. Please exercise caution when posting personal information involving yourself or others.
 

3.4 Exceptions to prior authorized consent for sharing, transferring, or publicly disclosing information

 
Please understand that, in accordance with laws and regulations and relevant national standards, we are not required to obtain your authorized consent for sharing, transferring, or publicly disclosing your personal information in the following cases.
 
(1) Directly related to national security and national defense security.
(2) Directly related to public safety, public health, and significant public interests.
(3) Directly related to crime investigation, prosecution, trial and execution of judgments, etc.
(4) For the protection of your or other individuals’ life, property and other significant legitimate rights and interests but it is difficult to obtain your consent.
(5) Information that you disclose to the public on your own.
(6) Gathered from lawful public disclosures, such as lawful news reports, government information disclosure and other channels.

4.How we protect your personal information

We have used security measures that meet industry standards to protect the personal information you provide against unauthorized access, public disclosure, use, modification, damage or loss of personal information.
 
We will take all reasonable and practicable steps to ensure that no unrelated personal information is collected. We will only retain your personal information for as long as necessary to achieve the purposes described in this policy, unless an extended retention period is required or permitted by law.
 
The Internet is not an absolutely secure environment, we will do our best to ensure the security of any information you send to us. Even if we make great efforts and take all reasonable and necessary measures, it may still be impossible to prevent your personal information from being illegally accessed, illegally stolen, illegally tampered with or destroyed, resulting in damage to your legitimate rights and interests, please understand the above-mentioned risks of information networks and voluntarily assume them.
 
After the unfortunate occurrence of personal information security incident, we will inform you in a timely manner in accordance with the requirements of laws and regulations: the basic situation of the security incident and the possible impact, the disposal measures we have taken or will take, the suggestions you can independently prevent and reduce the risk, the remedial measures for you, etc. We will promptly inform you of the event-related situation by email, letter, telephone, push notification, etc. When it is difficult to inform the subject of personal information one by one, we will take a reasonable and effective way to issue an announcement. At the same time, we will also take the initiative to report the disposition of personal information security incidents in accordance with the requirements of the regulatory authorities.
 

5.Your rights

5.1 Deletion of your personal information

You can request us to delete your personal information in the following cases.
(1) If we handle personal information in violation of laws and regulations.
(2) If our handling of personal information violates our agreement with you.
 
When you make a deletion request to us, we may require you to verify your identity to safeguard your account. When you delete information from our service, we may not immediately delete the corresponding information from our backup system because of Applicable laws and security technology, and we will store your information securely until the backup can be erased or anonymized. However, your decision to delete will not affect our previous processing of personal information based on your authorization.
For information related to Community Features, you may, within the scope of functions provided by the App, delete content, comments, or replies you have posted, cancel likes, favorites, follows, or other interactions, or manage your profile information according to on-page prompts. After account deletion, Community Feature information associated with that account will be deleted or anonymized in accordance with applicable laws and regulations, except where retention is required by laws and regulations, immediate deletion is technically difficult, or retention is necessary to protect the lawful rights and interests of other users.
 

5.2 Alter Your Consent Authorization

You may at any time grant or withdraw your consent to the collection and use of personal information that has been gathered. And you may reconfigure your consent regarding the use of your personal information by accessing the authorization page within this App.
 
Upon your withdrawal of consent, we will cease the processing of the relevant personal information. However, your decision to withdraw consent will not affect any personal information processing conducted previously based on your authorization.
 
 

5.3 Automatic Information System Decision Making

In some business functions, we may make decisions based solely on automated, non-human decision-making mechanisms, including information systems and algorithms. If these decisions significantly affect your legal rights, you have the right to request an explanation from us and we will provide Appropriate remedies.
 

5.4 To respond to your request above

For security purposes, you may be required to provide a written request or otherwise prove your identity. We may ask you to verify your identity before we process your request.
 
For your reasonable requests, we do not charge a fee in principle, but for requests that are repeated several times and exceed reasonable limits, we will charge a cost fee depending on the circumstances. We may deny requests that are unwarrantedly repetitive, require excessive technical means (for example, requiring the development of new systems or fundamental changes to current practices), pose a risk to the legal rights of others, or are highly impractical. Please also understand that we may not be able to respond to some of your requests due to safety and security concerns, requirements of relevant laws and regulations, or technical limitations, such as the following.
 
(1) Related to the personal information controller to fulfill the obligations under laws and regulations.
(2) Directly related to national security and national defense security.
(3) Directly related to public safety, public health, and significant public interest.
(4) Directly related to crime investigation, prosecution, trial and execution of judgments, etc.
(5) Where the controller of personal information has sufficient evidence of subjective malice or abuse of rights by the subject of personal information.
(6) For the purpose of safeguarding the life, property and other significant legitimate rights and interests of the subject of personal information or other individuals but where it is difficult to obtain the consent of the person.
(7) Responding to the request of the subject of personal information will lead to serious damage to the legitimate rights and interests of the subject of personal information or other individuals or organizations.
(8) Where commercial secrets are involved.
 

6.How we handle children’s personal information

Our products, websites and services are intended for adults only. We recommend that children use this App and related services under the accompaniment of their parents or guardians.
 
In cases where children’s personal information is collected with the consent of parents and guardians, we will only process such information when permitted by law and with parents’ or guardians’ explicit consent, or when necessary to protect children. When processing children’s information, we will handle it in accordance with laws and special personal information rules.
 
Although local laws and customs define children differently, we consider anyone under the age of 14 to be a child.
 
If we find out that we have collected personal information of children without first obtaining verifiable parental consent, we will try to delete the relevant data as soon as possible.

7.Storage and Cross-Border Transfer of Personal Information

(1) Scope of Personal Information Storage
Except for the following circumstances, all personal information collected by this App during service provision is stored locally on your device and will not be transferred or transmitted across borders in any form: User account information;
Content and interaction information generated or posted based on your account when you use the Community Features, including nickname, avatar, profile information, posted content, comments, replies, likes, favorites, follows, report records, content review records, etc. Such information is stored in association with user account information and is subject to the same storage regions, storage service providers, and cross-border processing rules as user account information.
Log information that you actively upload;
Text commands, interaction results, and other information generated after speech-to-text conversion when you use the built-in AI Voice Assistant feature (excluding raw voice audio files); Geographic location information contained in images you upload (depending on whether you have enabled the location tag feature). When you use this App to upload JPEG images to the cloud, if location tags were enabled when the images were captured, the geographic location data contained therein will be synchronously uploaded and stored on our servers. You can synchronously delete the images and associated information stored on our servers by deleting the corresponding images from the task list.
(2) Storage Locations and Cross-Border Processing
Currently, personal information, such as user accounts, log data, and location, collected and generated within the territory of the People’s Republic of China (excluding Hong Kong, Macau, and Taiwan regions) will be stored on Tencent Cloud Object Storage servers in the Nanjing region. Personal information collected and generated outside the territory of the People’s Republic of China and in Hong Kong, Macau, and Taiwan regions of the People’s Republic of China will be stored on Amazon S3 Object Storage servers located in the US-EAST-1 region (Northern Virginia) in the United States. We have signed confidentiality agreements with the relevant information storage providers and will implement strict confidentiality measures for the aforementioned personal information. The log information will be stored for a period within 14 days, after which the system will automatically delete it. The above information does not involve domestic or cross-border transfer scenarios. If transfer is required due to judicial procedures, government actions, or other demands from state organs, we will confirm whether transfer is necessary according to the laws of both the transferring and receiving countries.

Description of Data Storage and Transmission for AI Voice Assistant

Services within Mainland China: For users in Mainland China, AI Voice Assistant-related data is supported by domestic cloud services provided by Volcengine. Relevant processing and the storage of information that needs to be stored occur within Mainland China; neither we nor Volcengine’s voice service save your raw voice audio files, in compliance with national laws and regulations.
International Services: For users outside Mainland China, technical support is provided through BytePlus. To facilitate global service availability, relevant data may be transmitted and processed across BytePlus’s global nodes (including but not limited to regions such as Singapore, the United States, and Europe); neither we nor the applicable voice service provider save your raw voice audio files.
Inquiry Path: As service nodes may be adjusted due to technical optimizations, specific information regarding Service Availability Zones (AZ) shall be subject to the official technical specifications published by Volcengine/BytePlus and the actual service endpoint you are connected to.
Protection Principles: Regardless of where the data is processed, we require our service providers (Volcengine/BytePlus) to implement equivalent encryption and de-identification standards, ensuring that the level of data protection is no less than the standards committed to in this Privacy Policy.
 
(3) Personal Information Retention Period
 
We retain personal information only for the shortest period necessary to achieve the purposes described in this Policy. Unless laws and regulations provide otherwise, a different retention period is specified in this Policy, or retention is necessary to continuously provide services such as account and content storage that you actively use and manage, other personal information will be retained for no more than one year from the date it is generated. Where a specific retention period is stated in this Policy, that period applies. Information that you continuously use or actively manage, such as account information, Community content, upload tasks, and images, is retained during the life of the relevant account or content. After you delete content or cancel your account, we will delete or anonymize it within the period required by laws and regulations and to the extent technically feasible.
 
When a retention period expires, the processing purpose has been achieved or can no longer be achieved, the processing purpose is no longer necessary, or you lawfully withdraw consent, delete information, or cancel your account, we will stop the relevant processing and delete or anonymize the relevant personal information. Where laws and regulations require continued retention, we will keep the information in isolated storage only for the statutory retention period and necessary scope and will not use it for the original processing purpose; it will be deleted or anonymized when the statutory period expires.
 
For information that cannot be deleted immediately because of system backups, disaster recovery, or security mechanisms, we will isolate it from day-to-day processing systems, restrict access and further processing, and delete or anonymize it when the backup rotation or recovery cycle expires.

8.How this Policy is updated

Our Privacy Policy may change. We will post any changes made to this Policy on this page. For major changes, we will provide more prominent notices.
 
Major changes referred to in this Policy include but are not limited to:
(1)Major changes in our service model, such as the purposes of personal information processing, types of personal information processed, and ways in which personal information is used.
(2)Major changes in the main objects of sharing, transferring, or publicly disclosing personal information.
(3)Your rights regarding participation in personal information processing and the ways in which those rights are exercised undergo major changes.
 
By continuing to use this App and services after the updated Policy takes effect, you indicate that you have fully read, understood and accepted the updated Policy and are willing to be bound by the updated Policy.
 

9.How to contact us

If you have questions, comments, suggestions, complaints, or reports regarding this Policy, our personal information processing activities, or our personal information protection measures, or if you wish to exercise your personal-information rights, you may contact us at:
 
Personal Information Protection Complaint and Report Email: support@dwarflab.com
 
After verifying your identity, we will investigate, handle, and provide feedback on your request, complaint, or report within 15 working days. If we are unable to respond to your request, we will explain the reasons.
 
If you are dissatisfied with our handling, especially where you believe that our personal information processing activities have harmed your lawful rights and interests, you may also file a complaint or report with competent regulatory authorities, including cyberspace affairs, public security, and market-regulation authorities, or bring an action before a court with jurisdiction in accordance with law.

Appendix 1

To ensure the stable operation of DWARFLAB or provide related functions, we may integrate software development kits (SDKs) or third-party service interfaces (APIs) provided by third parties. The following list identifies the relevant third-party services. You may review their data-use and data-protection rules through the links provided below. Please note that the types of personal information processed by third-party services may change because of version upgrades or policy adjustments; the relevant service provider’s published rules will apply.
 
Except where necessary to provide the relevant feature, we will initialize the relevant third-party SDKs only after you agree to this Privacy Policy. Analytics and troubleshooting services such as PostHog and Firebase are enabled only after your consent; NetEase Qiyu Customer Service is used only when you actively enter the customer-service feature; and voice services are invoked only when you actively use the voice assistant feature.
Third-Party SDKServices
OS Involvement
Access Purpose
User Information Involved
Privacy Policy Link
Google Firebase (SDK)
Android / iOS
Crash Data Collection
Usage statistics, crash analysis, troubleshooting, and service-instance management
Network Status, Device Information
App instance identifier, Firebase Installations identifier, Crashlytics installation identifier, device and operating-system information, App version, network information, feature-use statistics, crash logs, and the time an exception occurs
https://policies.google.com/privacy?hl=zh-cn
Volcengine (SDK)
Android / iOS
Provides Voice Recognition and Synthesis (STT/TTS) for users in Mainland China
Microphone audio data, Network information
https://www.volcengine.com/docs/6256/64902?lang=zh
Volcengine (API)
Server-side
 
Provides AI Large Model Interaction and Content Generation for users in Mainland China
User command text, Interaction logs (De-identified)
https://www.volcengine.com/docs/6256/64902?lang=zh
BytePlus (SDK)
Android / iOS
Provides Voice Recognition and Synthesis (STT/TTS) for users outside Mainland China
Microphone audio data, Network information
BytePlus (API)
Server-side
Provides AI Large Model Interaction and Content Generation for users outside Mainland China
User command text, Interaction logs (De-identified)
PostHog (SDK)
Android / iOS
 
Product-usage statistics, feature-effect analysis, and troubleshooting
App version, device model, operating system, language, time zone, feature-use records, random analytics identifiers, network type, and mobile network operator name
NetEase Qiyu Customer Service (SDK)
Android / iOS
Online customer service, problem feedback, and customer-service sessions
Account or visitor identifier, device and operating-system information, network information, and the text, images, files, and contact details you actively submit
End.