AI Assistant Cindy Privacy Policy

Version Release Date: July 26, 2026

Version Effective Date: July 26, 2026

Dear User,

XD Entertainment Pte. Ltd. (hereinafter referred to as "we", "the Company", or "XD"), as the operator of AI Assistant Cindy, understands the importance of personal data to you, especially in light of the European Union’s General Data Protection Regulation (GDPR) and relevant laws of other jurisdictions, and processes your personal data transparently.

This AI Assistant Cindy Privacy Policy (hereinafter referred to as "this Policy") is intended to explain to you how we collect, use, disclose, transfer, and store your personal data, as well as the rights you are entitled to. Before you accept our services, please carefully read and fully understand this Policy. If you do not agree to accept any content of this Policy, or are unable to accurately understand the meaning of the relevant terms, please do not proceed with further use of the Service.

In addition to this Policy, in specific scenarios, we will also explain to you the corresponding purposes, scope, and methods of information collection through timely notices (including pop-ups, page prompts, etc.) and feature update descriptions. Such timely notices and feature update descriptions constitute a part of this Policy and have the same effect as this Policy.

Furthermore, you acknowledge and understand that our product features will continue to evolve, and this Policy will be updated accordingly. Please continue to pay attention to the updates to this Policy. If you do not agree with any updated content of this Policy or have questions about the updates, you may contact us through the contact information provided in the "How to Contact Us" section of this Policy.

Please note that depending on how you use Cindy and your location, our role in processing data and the specific rules may differ, and are subject to the appendix applicable to your region. For additional terms applicable to your jurisdiction, please refer to the Appendix.

I. Definitions and Scope of Application

II. How We Collect and Use Your Personal Data

III. Disclosure and Sharing of Personal Data

IV. Personal Data Protection and Storage

V. Protection of Minors

VI. Rights of Data Subjects

VII. Updates to the Privacy Policy

VIII. How to Contact Us

Regional Appendices

Appendix A – European Economic Area (EEA) and the United Kingdom

Appendix B – State of California, United States

Appendix C – Other Jurisdictions

I. Definitions and Scope of Application

  1. Product: Refers to the platform and related products operated by us that provide users with multi-agent intelligent workspaces and AI-assisted tools based on artificial intelligence technology, in the form of PC clients, websites, browser extensions, and other new forms of services (collectively, "Cindy" or "the Service").
  2. Personal Data: Personal data refers to any information that identifies an individual or could identify an individual when combined with other information that an organization possesses or may possess.
  3. Data Controller: Refers to the individual or organization that, alone or jointly, determines the purposes and means of processing personal data.
  4. Data Processor: Refers to the individual or organization that processes personal data on behalf of the data controller.
  5. Gateway Forwarding and Cloud Feature Exceptions: Cindy is designed as a local-first desktop application. Conversation records, agent history, working-directory files and API keys are generally stored on your device. When you use the XD AI Gateway, remote access, account migration or other cloud or integration features, relevant content or metadata may be transmitted to XD services, model providers or connected third parties. Retention depends on the applicable service configuration and provider terms.
  6. Server-Stored or Cloud-Processed Content: Refers to information processed or retained on XD servers or other cloud services for particular features, including account information, service logs, feedback submissions and data sent to or received from selected providers. OAuth credentials are generally encrypted on your device, although certain authorization exchanges or token refreshes may be processed through XD-operated services.
  7. Input Content: Refers to all content you enter during your use of the product, including but not limited to conversation text, uploaded documents and images, code snippets, agent instructions, and AI-generated content. You confirm that you have lawful rights to the content you enter. If the content contains third-party personal data, you must ensure that you have obtained lawful authorization.
  8. Service Evolution: The Service currently primarily provides multi-agent collaborative conversation and tool invocation functions, and may gradually expand to additional features in the future. This Policy covers the data types we currently anticipate. If new features involving data processing are introduced in the future, we will explain them to you by updating this Policy or through separate notices.
  9. Enterprise Account: If you use the Service through an account assigned to you by your organization (such as your employer, school, or partner, hereinafter referred to as the "Enterprise"), your account is an "Enterprise Account." In this case, the Enterprise is responsible for determining the purposes and means of processing your personal data, and we act only as a data processor for the Enterprise, processing your personal data in accordance with the instructions of the separate agreement entered into between the Enterprise and us. When you use an Enterprise Account, the Enterprise may have its own internal privacy policy or data protection statement that applies to you. Your use of Cindy is also subject to such internal policies.

II. How We Collect and Use Your Personal Data

1. Registration and Login

You may use supported local features, including the Bring Your Own API Key (“BYOK”) mode, without registering or signing in. Registration and login are required for account-based or cloud-based features, including Cindy account services, the XD AI Gateway, account synchronization or history migration, Device Link, and remote access.

Where registration or login is required, we collect the email address you provide or the account identifier returned by a supported third-party platform, such as Apple or Google. If you use an Enterprise Account, you may also authenticate through the SSO configured by your Enterprise.

2. Profile Information

When you set up your profile after registration, you may choose to provide a display name and upload a profile picture. If you upload a profile picture, the image file will be uploaded to our object storage service (OSS) and a publicly accessible URL will be generated and associated with your account. Your display name and profile picture URL are stored alongside your account information.

You may modify or delete your display name and profile picture at any time through your account settings. Upon deletion of your profile picture, the corresponding file stored in OSS will be synchronously removed. Upon account cancellation, your display name and profile picture will be deleted or anonymized in accordance with the retention periods set forth in this Policy.

3. AI Conversation and Multi-Agent Collaboration

When you use Cindy’s AI conversation and multi-agent collaboration features, you can send instructions to the AI by entering text in the dialog box, uploading local documents and images, or through voice input. Specifically:

(1) Direct Provider or Subscription Mode: If you use your own API Key, a provider subscription or another direct provider connection, your input content may be sent from your device directly to the selected provider or configured endpoint, without passing through the XD AI Gateway.

(2) XD AI Gateway Mode: If you use the XD AI Gateway, your input content and relevant context, attachments or tool results may pass through the Gateway and be forwarded to the selected provider. XD may process this information to authenticate requests, route them, provide the service and maintain security; retention depends on the applicable service configuration and provider terms.

Conversation records are generally stored on your local device and can be viewed, deleted or exported through the product interface. If account history migration, remote access or another cloud feature is enabled, selected messages, files, metadata or execution results may also be transmitted through XD services.

Special Notice:

Please do not enter content that contains another person's privacy information, trade secrets or unpublished sensitive research data. When you use a third-party model or service, that provider's own terms, privacy policy, retention and training practices may also apply.

4. Document and File Processing

You can open, view, and edit local documents (such as Markdown files, code files) in Cindy. Related documents are read and processed on your local device. When a cloud transcoding service is called to preview files in specific formats (such as DOCX, PPTX), the relevant files will be temporarily uploaded to the server for format conversion and immediately deleted after conversion. We do not persistently store your document content.

5. Knowledge Base and Memory System

Knowledge base data and cross-agent Memory are generally stored on your local device. When you ask an Agent to use them in a model request or integration, relevant excerpts, files or metadata may be sent to the selected provider or third-party service.

6. MCP Tool Integration

Cindy has built-in MCP tools such as Feishu, Confluence, Jira, and Google Sheets. When you perform operations through these tools (e.g., "help me move this Feishu message to Jira"), Cindy may parse your instructions locally and call the relevant third-party API through your authorized OAuth connection. Depending on the integration, related authorization or service requests may be routed through XD-operated services.

To establish the above connections, OAuth authorization credentials are generally stored in encrypted local storage. For certain integrations, authorization-code exchange or token refresh may be performed through an XD-operated OAuth Broker. The relevant third-party platform may independently process account and content data under its own policy.

7. Session Sharing

You can export a session as a local .cshare file. You may choose to encrypt the export with a password before sharing it through a third-party channel. The exported file remains on your device, and XD does not participate in the sharing process or store the shared content. When another user imports the file, it is processed locally on that user's device and is not uploaded to XD solely for the import.

If you choose password protection, keep the password secure and share it separately. XD does not store or recover the password. If you export without password protection, anyone who obtains the file may be able to access its contents.

8. FeishuBot Remote Control

When you enable FeishuBot or another messaging integration, messages, instructions, files and execution results may pass through the relevant platform, XD services and your local client. Retention depends on the applicable service configuration and provider terms.

9. Scheduled Tasks and Issue Tracker

Scheduled-task configuration and run records are generally stored on your local device. If you enable project automation, remote access or a connected integration, task prompts, schedules, execution results and necessary files may be transmitted to XD services, model providers or third-party platforms.

10. Search Function

When you use web search, the query you provide or a query generated by the system may be sent to the selected search provider. Retention of queries and results depends on that provider's terms and service configuration.

11. Fault Reporting and Issue Diagnosis

To ensure the stable operation and security of the Service, we will collect and use relevant information in the following ways depending on the log type:

(1) System Operation Logs:

To maintain the gateway security and stable operation of the Cindy Service, the system automatically generates necessary request or operation logs. Such logs are a default component of the service operation and cannot be actively turned off by users. Such logs only retain the metadata necessary for gateway security, service stability analysis, and troubleshooting (such as request time, operation type, status code, network latency), and are stored and automatically cleared in accordance with the periods stipulated in this Policy.

(2) User-Submitted Diagnostic Materials

When you proactively report an issue to us or choose to participate in product diagnostics, we may, after obtaining your explicit authorization, collect the following information to help locate and resolve the issue: device information (operating system version, device model), system resource usage (such as CPU, memory usage, etc., used only for performance diagnostics). The submission of such diagnostic information is entirely voluntary and controlled by you. You can turn the diagnostic function on or off at any time through the product settings. Such information is used only to resolve the issue you reported and will not be used for other purposes.

12. Feedback and Issue Submission

If you confirm submission of a feedback report or Issue, the information you include, together with basic application and device information, may be sent to our feedback service and, where applicable, GitHub. Please do not include personal data you do not want to disclose.

13. Security Protection

To improve the security of the platform and products, protect the personal safety, property safety, and account security of you, other users, or the public, better prevent security risks such as phishing websites, fraud, network vulnerabilities, computer viruses, network attacks, network intrusions, malware, etc., and more accurately identify violations of laws and regulations or relevant agreements and rules, we and our affiliates will collect your device information and log information, and may use or integrate your device information and log information to comprehensively assess your account and usage risks, perform identity verification, detect and prevent security incidents, and take necessary recording, auditing, analysis, and response measures in accordance with the law.

14. Device Connectivity and Online Status

When you are signed in to a Cindy account and use cloud mode, we process the following device connection information to provide cloud account services, device discovery, online-status maintenance and, where enabled, remote features such as Device Link:

(1) Device name, device platform (e.g., Windows, macOS, Linux), operating system version;

(2) Application version;

(3) CPU model and memory size;

(4) Whether remote control is enabled; and

(5) Device idle/busy status.

In signed-in cloud mode, the Cindy client sends a heartbeat to our cloud services approximately every 60 seconds. The heartbeat includes your Cindy user ID (uid), platform and application version. This heartbeat mechanism is a necessary component for maintaining the functionality of remote features and cannot be disabled by users. The heartbeat is not initiated, and Device Link online status is not maintained, when you use Cindy in signed-out local mode or BYOK mode.
When you sign out or switch to local mode, the client stops and clears the relevant connection status. The above information is used only for device discovery, connection establishment and online-status maintenance, and will not be used for any other purposes.

15. Permission Requests and Management

To ensure the normal operation of Cindy’s features, we may request access to certain system permissions on your device. Such permissions are only enabled after obtaining your explicit authorization. You can turn relevant permissions on or off at any time in your device’s settings. After withdrawing authorization, we will no longer collect information related to that permission, but this does not affect the personal data processing that has already been carried out based on your authorization.

16. Paid Services

If you choose the “AI Gateway subscription” mode, we will provide the relevant AI Gateway services based on the quota you have purchased. To complete the quota purchase, manage your quota and provide the Service, we will collect the following necessary information:

(1) Account and Identity Information: Includes your Cindy account ID, registered email address. The information is used to accurately bind the quota and validity period you have purchased to your account, ensuring that you can normally use the purchased services.

(2) Subscription Order / Quota Top-Up Information: This includes the order number, selected monthly plan, purchased quota, price or amount, currency, purchase time, subscription period or validity period, and the selected payment method type (such as credit card, debit card, PayPal, or other methods available in your region). This information is used to generate and retain transaction records for your order inquiries, subscription management, after-sales processing, and dispute resolution.

(3) Payment Verification Information: This includes the transaction reference number returned by the payment platform, payment voucher, and the last four digits of the masked payment card number (if applicable) that may be provided. This information is used solely to verify payment status, complete payment reconciliation, and prevent fraudulent transactions.

(4) Subscription Status and Quota Information: This includes purchased quota, subscription plan, current subscription status, subscription period or validity period, auto-renewal status, cancellation or termination records, plan change records, and refund or refund application records (if applicable). This information is used to activate, manage, and terminate subscription services, process refunds, and prevent fraud, abuse, and unauthorized use.

(5) Invoice or Tax Information: If you require an invoice, we will collect your invoice title, taxpayer identification number (applicable to enterprise users), and necessary contact address. This information is used to lawfully issue a valid VAT invoice or commercial invoice to you.

(6) Contact Information: Your email address. We will use this email address to send you purchase confirmations, subscription expiration or auto-renewal reminders, renewal or cancellation results, plan change notifications, and important change notices related to the Service.

17. Third-Party SDKs and Technical Components

To ensure the stable operation of Cindy’s features and to implement specific services, we have embedded certain software development kits (SDKs) and other similar technical components provided by third parties or affiliates in the product. These SDKs may involve the processing of your personal data. Based on the data processing role of each SDK provider, we categorize SDKs into the following two types:

(1) SDKs Acting as Our Data Processors

Such SDK providers process data only in accordance with our instructions and do not use the data for their own purposes. We contractually require them to provide security safeguards no less than the level of this Policy.

SDK Name Provider Function and Purpose Data Types Collected
TapSDK TapTap Pte. Ltd. (Affiliate) User behavior statistical analysis, used to optimize product features and experience User ID, device type (brand, model), operating system version, feature usage data (clicks, views, page dwell time, etc.)

(2) SDKs Acting as Independent Data Controllers

Such SDK providers independently determine how to process your personal data when providing their services to you. We do not obtain data beyond the necessary scope from these SDK providers. Your data will be directly collected and processed by the third party. Please refer to their privacy policy.

SDK Name Provider Function and Purpose Data Processing Involved Provider Privacy Policy
Apple Sign In SDK Apple Inc. Supports international version users to log in via Apple ID Apple is responsible for verifying your identity; we only receive the account identifier you authorize https://www.apple.com/legal/privacy/en-ww/
Google Sign-In SDK Google LLC Supports international version users to log in via Google account Google is responsible for verifying your identity; we only receive the account identifier you authorize https://policies.google.com/privacy
Stripe Payment SDK / Stripe Checkout Stripe, Inc. and/or its applicable affiliates Supports payment processing for one-time AI Gateway quota top-ups and subscription plans, including payment authorization, transaction verification, reconciliation, refunds and fraud prevention Stripe processes payment and billing information, which may include your name, email address, billing address, payment method or payment card information, IP address, device information, transaction details and fraud-prevention signals. We may receive transaction identifiers, payment status, subscription and refund information, and limited masked payment-method details, such as the card brand and last four digits, where applicable. https://stripe.com/privacy

Note: The above SDK list is integrated in the current version. As product features evolve, we may add, remove, or replace SDKs. In the event of material changes, we will notify you by updating this Policy or through pop-ups, etc.

III. Disclosure and Sharing of Personal Data

Certain modules and features in our products will be provided by cooperative service providers. Accordingly, we may share certain personal data with our partners to provide better customer service and user experience. When cooperating with partners, we will comply with the following principles: (1) Principle of Legality, Legitimacy, and Minimum Necessity: Data processing should have a lawful basis, a legitimate purpose, and be limited to the minimum scope necessary to achieve the processing purpose; (2) Principle of Maximizing User’s Right to Know and Right to Decide: Data processing should fully respect the user’s right to know and right to decide regarding the processing of their personal data; (3) Principle of Maximizing Security Safeguards: We will take necessary measures to ensure the security of the personal data processed, prudently evaluate the purposes for which partners use data, comprehensively assess the security capabilities of these partners, and require them to comply with the relevant requirements of the cooperation agreement. We may disclose or share your data only in the following circumstances:

1. Data Processors

We may entrust affiliates or third-party service providers to process data on our behalf, including cloud infrastructure providers, payment processors, email notification service providers, and analytics service providers. We ensure through written contracts that these service providers process data only in accordance with our instructions and provide security safeguards equivalent to our own.

2. Independent Third Parties

(1) Sharing at Your Direction: When you connect to third-party services (such as Feishu or Jira), or use a provider subscription, your own API Key or another direct provider connection, the relevant data may be sent to the third party or provider you select at your direction.

(2) Legal Requirements: To comply with Singapore law, court orders, or lawful requirements from regulatory authorities (such as the Personal Data Protection Commission, PDPC).

(3) Business Transfer: In significant transactions such as mergers, acquisitions, or asset sales, your data may be transferred as part of the assets. We will require the transferee to continue to comply with this Policy or equivalent protection standards.

3. Cross-Border Data Transfer

We are headquartered in Singapore and may use service providers that operate in other countries. Your personal data may be transferred to the People’s Republic of China or other locations where privacy laws may not be as protective as those in your state, province, or country.

In the XD AI Gateway mode, your prompts and, as applicable, related context, attachments or tool results may be securely forwarded through our Gateway to the selected model providers to generate responses. The servers of those providers may be located overseas.

Users in Europe should read the important information provided in the addendum about transfer of personal data outside of Europe.

IV. Personal Data Protection and Storage

1. How We Protect Your Personal Data

We use industry-standard security measures to protect the personal data you provide, ensuring that personal data processing activities comply with laws and regulations, and preventing unauthorized access as well as personal data leakage, alteration, or loss. We will take all reasonably feasible measures to protect your personal data. Nevertheless, under current information technology, "perfect security measures" do not exist. If you discover that your personal data has been leaked, you should immediately contact us through the contact information provided in the "How to Contact Us" section of this Policy so that we can take appropriate measures.

Special Notice: Because Cindy is local-first, many conversation records, agent invocation records, knowledge-base materials and Memory items are stored on your device. Cloud, integration, remote-access, feedback and other optional features may involve transmission or cloud storage. Please protect your device and review the permissions and provider choices for each feature.

2. Storage Period

We will retain your personal data for the shortest period necessary to achieve the purposes described in this Policy, unless a reasonable extension is needed for financial, audit, or dispute resolution purposes, or unless otherwise provided by laws and regulations, or otherwise required by regulatory authorities:

(1) Account Registration Information: Retained throughout your use of the product. After you cancel your account, we will delete or anonymize your account information within thirty (30) days, unless otherwise provided by laws and regulations.

(2) OAuth Authorization Credentials: Depending on the integration, OAuth credentials may be stored locally or processed by XD-operated services. Where we process or retain such credentials, we do so only as necessary for the relevant integration and delete or deactivate them after authorization is revoked, subject to applicable legal retention requirements.

(3) Subscription transactions and related subscription management records (including renewal, cancellation, and refund or refund-request records, where applicable), and invoicing information: Retained for ten (10) years from the date of transaction.

(4) Log Data: Retained for 180 days, with rolling deletion.

(5) Crash Reports: Retained for ninety (90) days or thirty (30) days after the issue is closed, whichever is earlier.

3. Response to Information Security Incidents

In the unfortunate event of a personal data security incident, where we are required by laws and regulations to inform you, we will promptly notify you of the basic circumstances and possible impact of the security incident (including the type of information that has been or may be leaked, altered, or lost, the cause, and the potential harm), the remedial measures we have taken, the measures you can take to mitigate the harm, and our contact information. When it is difficult to notify each individual, we will publish an announcement through reasonable and effective means. In addition, we will proactively report the handling of the personal data security incident to the relevant regulatory authorities as required by law.

4. Notice of Cessation of Operations

If we cease operations, we will stop collecting your personal data and notify you of the cessation of operations through individually delivered notices or announcements, as commercially feasible, and will delete or anonymize the personal data we hold about you.

V. Protection of Minors

Our Service is intended only for individuals who are at least 18 years old or have reached the age of majority in their jurisdiction, whichever applies. We do not knowingly permit individuals below this threshold to use the Service, and parental consent does not create an alternative route to access. Please use the contact information in the "How to Contact Us" section for additional information.

If we learn that an individual below the applicable age threshold has used the Service, we will take reasonable steps to restrict access and delete or anonymize the relevant personal data, subject to applicable law. Guardians or users may contact us using the contact information in the "How to Contact Us" section of this Policy to report such circumstances.

VI. Rights of Data Subjects

We respect and protect your control over your personal data and do our utmost to protect your rights to access, correct, delete, and withdraw consent for your personal data, so that you have full capacity to protect your privacy and security. We will respond to your request within thirty (30) days. Your rights include:

  1. Access, Rectify, and Supplement Your Personal Data

You have the right to access, rectify, and supplement the personal data you provide to us. When you discover errors in the personal data we process about you, you have the right to request that we make corrections or supplements.

  1. Delete Your Personal Data

In the following circumstances, you may contact us through the contact information provided in the "How to Contact Us" section of this Policy to request the deletion of your personal data:

(1) Our processing of your personal data violates applicable laws or administrative regulations;

(2) We collected or used your personal data without your consent;

(3) Our processing of your personal data violates the agreement between us and you;

(4) The purpose of processing your personal data has been fulfilled, cannot be fulfilled, or is no longer necessary for achieving the processing purpose (for example, you no longer use our services);

(5) We no longer provide our services to you;

(6) You have withdrawn your consent to our processing of your personal data.

If we decide to respond to your deletion request, we will promptly delete your personal data, unless laws and regulations require us to retain it for a certain period. If we are unable to delete it immediately due to legal requirements, we will cease processing except for storage and necessary security protection measures.

  1. Withdraw Consent or Change the Scope of Your Authorization

You may contact us through the contact information provided in the "How to Contact Us" section of this Policy to withdraw your consent or change the scope of your authorization. After you withdraw consent, we will no longer process the relevant personal data. However, your decision to withdraw consent does not affect the personal data processing that has already been carried out based on your authorization.

  1. Cancel Your Account

You may cancel your account through Settings > General > Account Management > Cancel Account in the Cindy client, or through any other method specified in the Cindy User License Agreement and Terms of Service. After you voluntarily cancel your account, we will stop providing products or services to you and will delete or anonymize your personal data in accordance with applicable laws.

VII. Updates to the Privacy Policy

As product features are upgraded, our Privacy Policy may change. Without your explicit consent, we will not reduce the rights you should enjoy under this Policy. We will publish any changes made to this Policy through appropriate means.

VIII. How to Contact Us

If you have any questions, opinions, or suggestions about this Policy, or any opinions or suggestions regarding the processing of your personal data, you may contact us through the following contact information:

  • Data Protection Officer (DPO) Email: privacy@cindy.app
  • Mailing Address: Privacy and Data Compliance Center, 111 SOMERSET ROAD #05-11, 111 SOMERSET SINGAPORE (238164)

If the above contact information changes, the latest notice on our official website shall prevail. After receiving your request, we will reply within thirty (30) days. If you are not satisfied with our response, you have the right to file a complaint with the Personal Data Protection Commission (PDPC) of Singapore.

Regional Appendices

Appendix A – European Economic Area (EEA) and the United Kingdom (hereinafter collectively referred to as "the European Region")

This Appendix supplements and modifies this Policy to meet the requirements of the General Data Protection Regulation (GDPR) and UK data protection law.

  1. References to “personal data” in this Policy have the meaning given to that term under the GDPR, i.e., information relating to an identified or identifiable natural person.
  2. Legal Basis: We process your personal data in accordance with Article 6 of the GDPR, as described in the "How We Collect and Use Your Personal Data" section of this Policy. The specific bases are as follows:
Processing Scenario and Purpose Data Types Involved GDPR Legal Basis and Explanation
Account Registration and Login: Create and manage your Cindy account, perform identity verification. Email / Third-party account identifier (Apple ID, Google ID, etc.) / SSO account identifier Contractual Necessity (Article 6(1)(b)) – Necessary for the performance of a contract to which you are a party or in order to take steps prior to entering into a contract.
Profile Information (display name, profile picture) Display name, profile picture, OSS URL Contractual Necessity (Article 6(1)(b)) – Necessary for the performance of a contract to which you are a party or in order to take steps prior to entering into a contract.
AI Conversation (XD AI Gateway Mode): Call large language models through our AI Gateway. Input content, output content and relevant context; retention depends on the selected route and provider. Contractual Necessity (Article 6(1)(b)) – Necessary to provide you with the core service functionality of AI conversation.
Cloud Transcoding Service: When previewing files in specific formats, temporarily uploaded to the server for format conversion. Document or media content and conversion metadata, where the feature is enabled; retention depends on the applicable service configuration. Contractual Necessity (Article 6(1)(b)) – Necessary to provide the file preview or conversion feature you request.
MCP Tool Integration: Connect to third-party services (Feishu, Jira, etc.) and execute your instructions. Instructions, messages, files, account identifiers, workspace content and tool results, as applicable; retention depends on the selected route and provider. Contractual Necessity (Article 6(1)(b)) – Necessary to execute integration operations you proactively initiate.
MCP Tool Integration: Store your OAuth authorization credentials to maintain connections. OAuth access and refresh tokens, where applicable; generally encrypted locally, with certain Broker processing. Contractual Necessity (Article 6(1)(b)) – Necessary to maintain the third-party service connections you have actively authorized.
FeishuBot Remote Control: Send instructions to Cindy remotely through Feishu. Messages, instructions, files and execution results, as applicable; retention depends on the selected route and provider. Contractual Necessity (Article 6(1)(b)) – Necessary to provide the remote-control function.
Search Function: Provide real-time search results based on your search requests. User-supplied or system-generated search queries, returned results and related metadata; provider retention depends on its terms. Contractual Necessity (Article 6(1)(b)) – Necessary to respond to your search request and provide results.
System Operation Logs: Ensure gateway security, service stability, and troubleshooting. Metadata (request time, operation type, status code, network latency, etc.) Legitimate Interests (Article 6(1)(f)) – To ensure the secure and stable operation of the service and to prevent network attacks and system failures. This interest does not override your fundamental rights and freedoms.
User-Submitted Diagnostic Materials: Collect device information and system resource usage based on your authorization. Device information (model, system version), CPU/memory usage Your Consent (Article 6(1)(a)) – You may withdraw consent at any time in the settings, but this does not affect processing carried out prior to withdrawal.
Security Protection and Risk Prevention: Prevent security risks, identify violations, and protect the account and property safety of you and other users. Device information, log information Legitimate Interests (Article 6(1)(f)) – To protect the personal and property safety of you, other users, and the public, and to prevent security risks such as fraud and network attacks.
Device Connectivity & Heartbeat – Applicable only in signed-in cloud mode Device name, platform, OS version, app version, CPU, memory, remote control status, device idle/busy status, user ID, platform and app version Contractual Necessity (Article 6(1)(b)) – Necessary to provide cloud account connectivity, device discovery, online-status maintenance and related remote features.
Permission Requests and Management: Request access to system permissions on your device. Depends on the specific permission Your Consent (Article 6(1)(a)) – Each permission request requires your explicit authorization. You may withdraw at any time.
Paid Services (AI Gateway Subscription): Process AI Gateway subscription purchases, payment verification, invoicing, and subscription management. Account ID, subscription orders, payment verification information, subscription status and service entitlement information, invoice or tax information, email address Contractual Necessity (Article 6(1)(b)) – Necessary to process your subscription orders and provide subscribed services; Legal Obligation (Article 6(1)(c)) – Necessary to comply with legal requirements such as tax and financial records.
TapSDK: User behavior statistical analysis, optimize product features and experience. User ID, device type, operating system version, feature usage data Legitimate Interests (Article 6(1)(f)) – To analyze service usage and improve product quality. This interest does not override your fundamental rights and freedoms.
Third-Party Login SDK: Support login via third-party accounts such as Apple and Google. Account identifier returned by the third-party platform Not applicable – The processing of such data is the responsibility of Apple, Google, etc. as independent controllers. Please refer to their privacy policies.
Payment SDK: Process payment verification and transaction security for AI Gateway quota top-ups and subscriptions. Payment verification information, transaction reference number Not applicable – The processing of such data is the responsibility of the payment service provider as an independent controller. Please refer to their privacy policy.
  1. International Transfer: Depending on the features you use, personal data may be transferred outside the European Region to XD affiliates and service providers that support cloud infrastructure, model, search, file conversion, integration, remote-access, analytics, security, feedback or payment services, or to third-party platforms or providers you select. The data transferred is limited to information necessary for the relevant feature, such as account and login information, Input Content and files, tool or execution results, OAuth information, logs, transaction information and feedback materials. We apply appropriate contractual and other safeguards to transfers under our control; independent third parties process data under their own terms.

When we need to transfer your personal data from the European Region to third countries that have not received an adequacy decision (such as China) in accordance with this Policy, we always take the following applicable measures to ensure that your data is adequately protected:

(1) Standard Contractual Clauses (SCCs): Where required, we use the applicable module of the European Commission’s Standard Contractual Clauses under Decision 2021/914, including Module Two where we act as controller and the recipient acts as processor, as a transfer safeguard.

(2) Transfer Impact Assessment (TIA): Where required, we assess the legal environment of the data recipient country and implement supplementary measures proportionate to the transfer, such as encryption in transit, strict access controls and appropriate contractual and transparency measures.

(3) Your Rights and Safeguards: If we receive any legal request from a foreign government agency to access your data, we will:

  • Strictly review the legal validity of the request;
  • Only provide data to the minimum extent required when legally compelled to do so;
  • Promptly notify you of such request where permitted by law, unless we are legally prohibited from doing so.
  1. Extension of Your Rights: In addition to the "Rights of Data Subjects" section of this Policy, you also have the right to data portability (to obtain data in a structured, commonly used format and transfer it to another controller), the right to restrict processing, and the right to object. We will typically respond to your request within one month (or within a shorter period if required by applicable law).
  2. Right to Lodge a Complaint: You have the right to lodge a complaint with the data protection supervisory authority of the European Region member state in which you are located.

Appendix B – State of California, United States

This Appendix provides additional notices to California residents in accordance with the California Consumer Privacy Act (CCPA).

  1. No Sale/No Sharing: We do not sell your personal data, nor do we "share" your personal data for cross-context behavioral advertising purposes.
  2. Sensitive Personal Information: If we process sensitive personal information as defined by applicable law, we use it only for purposes necessary to provide the Service and do not use it to infer your personal characteristics, except as permitted by applicable law.
  3. Your CCPA Rights: You have the right to know, the right to delete, the right to correct, and the right not to be discriminated against. You may exercise your rights through the contact information in the "How to Contact Us" section, and we will respond within 45 days. You may also authorize an agent to exercise your rights on your behalf.

Appendix C – Other Jurisdictions

For other countries/regions not listed above, we will provide corresponding protection in accordance with the applicable data protection laws of the local jurisdiction. If the laws of your location have additional requirements, please contact us and we will make every effort to meet your legitimate rights requests.