SayTalk Privacy Policy Last Updated: 2026-09-22 Effective Date: 2026-09-22 SayTalk (hereinafter referred to as "we") fully understands the importance of your personal information. We will take appropriate security measures in accordance with laws and regulations to protect the security and controllability of your personal information. This Privacy Policy will help you understand the following: 1. How We Collect and Use Your Personal Information 2. How We Use Cookies and Similar Technologies 3. How We Share, Transfer, and Publicly Disclose Your Personal Information 4. How We Protect Your Personal Information 5. Your Rights 6. How We Handle Minors' Personal Information 7. How Your Personal Information Is Transferred Globally 8. How This Privacy Policy Is Updated 9. How to Contact Us This policy is closely related to your use of our services. We recommend that you read the entire policy carefully. If you have any questions while reading, you may contact us through the methods listed in Section 9. 1. How We Collect and Use Your Personal Information We collect and use your personal information for the following purposes described in this policy: (1) Helping you become a registered user and use account services When you register a SayTalk account, you may choose one of the following registration methods: 1. Phone registration: You need to provide your phone number, verification code, and login password. We will also collect your nickname, avatar, gender, date of birth, and height during registration to complete your profile and display it to other users. 2. Email registration: You need to provide your email address, verification code, login password, as well as your nickname, avatar, gender, date of birth, and height. 3. Third-party account registration: You may register using WeChat, Alipay, WhatsApp, Facebook, Google, or Apple accounts. With your authorization, we will obtain your public information from the third-party platform, including your user ID (openid), nickname, avatar, and the email address returned by the platform (if available). If you refuse to provide the above information, you will not be able to register an account, but you may still browse public content in the app. While using account services, we will also collect your login time, login device identifier, and login IP address for account security and risk control purposes. (2) Providing you with instant messaging services When you use SayTalk's chat features, we collect the content of messages you send and receive, including: 1. Text message content; 2. Image and video files and their metadata (capture time, file size); 3. Audio content of voice messages; 4. Latitude/longitude coordinates, location name, and detailed address of location messages; 5. Gift-giving records (sender, recipient, gift type, diamond quantity). The above information is used to deliver message content between chat participants and is stored on servers to support message history queries. (3) Providing you with location-based services When you send a location message in a chat or use the "Nearby People" feature, with your location permission authorization, we will collect your precise geographic location (latitude and longitude). Location information is only used to deliver location messages to the other party when you actively send them, or to display nearby users sorted by distance. You may disable location permission at any time in system settings. (4) Providing you with photography, voice, and media storage services When you use features such as taking profile photos, sending images/videos, or sending voice messages, we will request the following system permissions from you: 1. Camera permission: Used to take photos or videos as avatars or chat messages; 2. Microphone permission: Used to record voice messages; 3. Storage permission: Used to save images and videos downloaded from chats to your local device. The above permissions are all non-mandatory. You can still use basic features such as text chat after refusing authorization, but you will not be able to use the corresponding features. (5) Providing you with payment and top-up services When you use paid features such as diamond top-up, membership subscription, or gift giving, we complete transactions through third-party payment channels. We collect order information (order number, amount, product type, transaction status), but we do not collect your bank card number, password, or other payment-sensitive information—payment information is collected directly by third-party payment institutions such as Alipay, WeChat Pay, and Google Play Billing. (6) Providing you with message push services To deliver chat message notifications, friend request notifications, system announcements, and other service information to you in a timely manner, we collect your device push token. Depending on the app version you use, push tokens are delivered through the following channels: 1. Domestic version: Umeng U-Push channel token; 2. Overseas version: Firebase Cloud Messaging (FCM) channel token. We also collect device model, operating system version, and app version number to troubleshoot push anomalies. Message push is a necessary service feature and is not used for targeted commercial advertising. You may disable the app's notification permission in your phone's system settings to stop receiving push notifications. (7) Device information and security risk control To ensure account security and stable service operation, we collect the following device information: 1. Device model, operating system name and version; 2. Device identifier (Android uses system Build.ID, iOS uses identifierForVendor; we do not collect IMEI, MAC address, or installed app lists); 3. Network type (Wi-Fi / mobile network). The above information is used for abnormal login detection, service troubleshooting, and deduplication of multiple accounts on the same device. (8) Customer service and feedback When you contact customer service or submit feedback, we collect your account information, the problem description you actively provide, and your contact information to process your request. (9) Third-party SDK collection timing and frequency To ensure normal service operation, our app integrates third-party SDKs (see Appendix 1 for details). The initialization and personal information collection of all third-party SDKs follow these principles: 1. 【Collection Timing】Third-party SDKs will only initialize and collect personal information after you launch the app for the first time and agree to this Privacy Policy. Before your consent, we will not start any SDK that collects personal information, nor will we read sensitive information such as the clipboard. 2. 【Collection Frequency】The information collection frequency of third-party SDKs is strictly controlled within the minimum range necessary to implement the service: - Push SDKs (Umeng U-Push / Firebase FCM): Only obtain the push token once when the app starts, and re-obtain it when the token is refreshed (usually once every few weeks to months); no high-frequency periodic collection. - Payment SDKs (Alipay / WeChat / Google Play Billing): Only collect order information when you initiate a payment; no personal information is collected at other times. - Login SDKs (WeChat / Google / Apple): Only obtain the user identifier when you log in with a third-party account; no collection at other times. - Clipboard: Only read once when the app starts after you agree to the Privacy Policy, used to identify invitation codes for sharing attribution; no background periodic reading, and clipboard content is not persisted after reading. 3. 【Information Not Collected】We and third-party SDKs do not collect sensitive personal information such as IMEI, IMSI, device MAC address, SUPI, SUCI, installed app lists, contacts, call logs, calendars, SMS, or local phone numbers. Location information is only obtained on demand after your authorization when you actively send a location message or use the Nearby People feature; it is not continuously collected in the background. 4. 【Device Identifiers】To implement push services, account security risk control, and statistical analysis, third-party push SDKs (Umeng U-Push / Firebase FCM) may read device identifiers (such as Android Build.ID, iOS identifierForVendor, device serial number, etc.) after you agree to this Privacy Policy, to generate push tokens and identify devices. These identifiers are only used for the above purposes, will not be associated with your personally identifiable information, and will not be sold to any third party. 2. How We Use Cookies and Similar Technologies We do not use cookies in the mobile app. We may use local storage (SharedPreferences) in the app to record your login status and preference settings (such as language, theme). You can delete the above information by clearing app data. 3. How We Share, Transfer, and Publicly Disclose Your Personal Information (1) Sharing We do not sell your personal information to any third party. We will only share your personal information with third parties in the following circumstances: 1. Sharing with your explicit consent; 2. Sharing with authorized partners: Some of our services are provided by authorized partners. We will only share your personal information for the lawful, legitimate, necessary, specific, and explicit purposes stated in this policy. For the specific list of third-party SDKs, see Appendix 1 of this policy; 3. Sharing your personal information externally in accordance with laws and regulations, or as required by mandatory requirements of government authorities. (2) Transfer We will not transfer your personal information to any company, organization, or individual, except in the following cases: 1. With your prior explicit consent; 2. In the event of a merger, acquisition, or bankruptcy liquidation, if the transfer of personal information is involved, we will require the new company or organization holding your personal information to continue to be bound by this policy. (3) Public Disclosure We will only publicly disclose your personal information in the following circumstances: 1. With your explicit consent; 2. In accordance with laws and regulations, legal procedures, litigation, or mandatory requirements of government authorities. 4. How We Protect Your Personal Information 1. We have used security measures that meet industry standards to protect the personal information you provide, preventing data from unauthorized access, public disclosure, use, modification, damage, or loss. 2. We will take all reasonable and feasible measures to ensure that irrelevant personal information is not collected. 3. The Internet is not an absolutely secure environment. We strongly recommend that you do not use communication methods not recommended by SayTalk to send your information. 4. Unfortunately, despite our security measures, please understand that in the Internet industry, due to technical limitations and various possible malicious means, even if we do our best to strengthen security measures, it is impossible to always guarantee 100% information security. 5. In the unfortunate event of a personal information security incident, we will promptly inform you in accordance with the requirements of laws and regulations: the basic situation and possible impact of the security incident, the disposal measures we have taken or will take, suggestions for you to independently prevent and reduce risks, and remedial measures for you. We will promptly notify you by push notification, email, etc. When it is difficult to notify you individually, we will issue an announcement in a reasonable and effective manner. 5. Your Rights In accordance with relevant Chinese laws, regulations, and standards, as well as common practices in other countries and regions, we guarantee that you exercise the following rights over your personal information: 1. Right of access: You can view your account information and personal profile in "Me - Personal Profile". 2. Right to correction: You can modify your nickname, avatar, gender, date of birth, and height in "Me - Personal Profile". 3. Right to deletion: You can apply to delete your personal information or cancel your account through customer service channels. After account cancellation, we will delete or anonymize your personal information, unless otherwise provided by laws and regulations. 4. Right to withdraw consent: You can disable camera, microphone, location, storage, notification, and other permissions in system settings, or cancel your account to withdraw your previous consent. Withdrawal of consent does not affect the information processing that has been carried out based on your consent before the withdrawal. 5. Right to cancel account: You can apply to cancel your account in "Me - Settings - Account and Security - Cancel Account". 6. Right to complain and report: If you believe that our personal information processing behavior has damaged your legitimate rights and interests, you can complain to us through the methods listed in Section 9 of this policy. 6. How We Handle Minors' Personal Information Our services are mainly targeted at adults. We do not provide services to minors under the age of 18, nor do we actively collect personal information of minors. If you are the guardian of a minor and find that the ward has provided us with personal information without your consent, please contact us through the methods listed in Section 9 of this policy, and we will delete the relevant information as soon as possible. 7. How Your Personal Information Is Transferred Globally Our services are aimed at global users, and your personal information may be stored on servers outside your country or region. When transferring your personal information abroad, we will comply with applicable data protection laws and regulations and take necessary measures to ensure the security of your personal information. 8. How This Privacy Policy Is Updated We may revise the terms of this policy from time to time, and such revisions form part of this policy. When this policy changes, we will prompt you of the changes within the app. If you do not agree with the revised content, you may choose to stop using our services; if you continue to use, it is deemed that you accept the revised policy. 9. How to Contact Us If you have any questions, comments, or suggestions about this Privacy Policy, or if you need to exercise your personal information rights, please contact us through the following methods: - Customer service email: support@saytalk.com - Online customer service: Contact us through "Me - Help and Feedback" in the app Under normal circumstances, we will reply to your request within fifteen working days. Appendix 1: List of Third-Party SDKs To provide you with complete services, our app embeds the following third-party software development kits (SDKs). We conduct strict security assessments on our partners and require them to take appropriate data security protection measures. 1. Umeng U-Push SDK - Purpose: Push chat messages, friend requests, and system notifications to domestic version users - Types of personal information collected: Device push token, device model, operating system version, network type - Privacy policy link: https://developer.umeng.com/docs/119267/detail/118546 2. Firebase Cloud Messaging SDK (FCM) - Purpose: Push chat messages, friend requests, and system notifications to overseas version users - Types of personal information collected: Device push token, device identifier, device model, operating system version - Privacy policy link: https://firebase.google.com/support/privacy 3. Alipay SDK - Purpose: Provide payment services for diamond top-up and membership subscription for domestic version users - Types of personal information collected: Order number, payment amount, transaction status (sensitive information such as bank card number and password during payment is collected directly by Alipay, and we do not have access to it) - Privacy policy link: https://render.alipay.com/p/c/k2cx0tg8 4. WeChat Open Platform SDK - Purpose: Provide WeChat login and WeChat Pay services for users - Types of personal information collected: WeChat user ID (openid), nickname, avatar (login scenario only); order information (payment scenario only) - Privacy policy link: https://www.tencent.com/zh-cn/privacy-policy.html 5. Google Sign-In SDK - Purpose: Provide Google account login service for overseas version users - Types of personal information collected: Google user ID, email address, nickname, avatar - Privacy policy link: https://policies.google.com/privacy 6. Sign in with Apple SDK - Purpose: Provide Apple account login service for users - Types of personal information collected: Apple user ID, email address (if the user chooses to share) - Privacy policy link: https://www.apple.com/legal/privacy/ 7. Google Play Billing SDK - Purpose: Provide in-app purchase (diamonds, membership subscription) payment services for overseas version users - Types of personal information collected: Order number, transaction status (payment card information is collected directly by Google, and we do not have access to it) - Privacy policy link: https://policies.google.com/privacy 8. Google ML Kit Translation SDK - Purpose: Provide local real-time translation of chat messages for users - Types of personal information collected: None (the translation model runs locally on your device, and text content is not uploaded to Google servers) - Privacy policy link: https://developers.google.com/ml-kit/terms Note: WhatsApp and Facebook login are completed by jumping to a third-party authorization page in the browser, without additional client SDK integration; we only obtain the user ID, nickname, avatar, and email returned by them after obtaining your authorization.