GirlsHangout Privacy Policy
Effective Date: March 19, 2026
Data Controller: Dingzhou Xianchang Technology Co., Ltd. (hereinafter referred to as "we")
Contact Address: Room 402, Unit 3, Building 2, Yangguang 2008 Residential Community, Southern Urban Area, Dingzhou City, Hebei Province
Contact Email: carrywdiegobowlowsk@gmail.com
Data Protection Officer (DPO): A dedicated person appointed by Dingzhou Xianchang Technology Co., Ltd. to coordinate personal data protection-related work, including but not limited to compliance review of data processing, response to user rights, and communication with regulatory authorities. Users may communicate with the DPO regarding personal data matters at any time through the above contact email. We will respond to initial inquiries within 3 working days and provide a clear handling result within 15 working days.
This Privacy Policy (hereinafter referred to as "this Policy") applies to the mobile application GirlsHangout (hereinafter referred to as "this Application") developed by us. This Application is a short video platform for girls' gatherings & parties targeting adult users aged 18 and above. Developed based on Flutter/Dart, it only runs on the Android system and focuses on providing users with short video content services such as party planning, DIY decoration, and gathering records.
Before using this Application, users must carefully read and fully understand all terms of this Policy, including but not limited to the scope of personal data collection, purposes of use, processing methods, user rights, and disclaimer clauses. By checking "I agree to this Privacy Policy and the GirlsHangout User Terms", the user is deemed to have fully accepted all agreements of this Policy and agreed that we may collect, use, store, protect and process the user's personal data in accordance with the provisions of this Policy. If the user does not agree to any term of this Policy, they shall immediately stop using this Application, and shall not check to agree to the Policy or use any services of this Application.
This Policy may be revised in accordance with the update of relevant laws and regulations, the adjustment of Google Play Store policies, and the needs of the business development of this Application. The revised Policy will be prominently displayed on the splash screen and settings page of this Application for a publicity period of not less than 7 natural days, and will take effect automatically after the publicity period expires. If the user continues to use this Application after the Policy is updated, it shall be deemed that the user accepts the content of the revised Policy; if the user does not agree to the revised Policy, they shall immediately uninstall this Application and stop using all services.
I. Applicable Legal Basis
We strictly abide by relevant personal data protection laws, regulations and regulatory requirements worldwide, standardize the processing of user personal data, and ensure that all data processing activities are legal, compliant and transparent. The specific basis includes but is not limited to the following:
• Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, GDPR), covering core requirements such as data subject rights, data controller obligations, and legality of data processing;
• California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) of the State of California, USA, focusing on complying with relevant provisions such as user data access, deletion, and opt-out of sales;
• Virginia Consumer Data Protection Act (VCDPA) of the State of Virginia, USA, strictly abiding by obligations such as data collection notification, opt-out of targeted advertising, and data security protection;
• Lei Geral de Proteção de Dados (LGPD) of Brazil, implementing core rights of data subjects such as the right to know, right to correction, and right to destruction, and fulfilling data protection obligations;
• Federal Data Protection Law (FADP) of the United Arab Emirates, abiding by relevant provisions such as data confidentiality, compliant processing, and restrictions on third-party sharing;
• Google Play Store Developer Policies, Privacy Policy Requirements, and relevant supplementary requirements of the Children's Online Privacy Protection Act (COPPA) (in view of this Application targeting users aged 18+, additional risks related to the collection of minor data will be avoided);
• Other laws, regulations and industry norms related to personal data protection and consumer rights protection applicable in the user's region.
II. Scope and Purpose of Personal Data Collection
This Application has no registration or login functions, and does not require users to provide any personally identifiable information such as name, mobile phone number, email address, or ID number. It only collects personal data based on the principles of "legality, propriety, necessity, and minimization" when users actively use relevant functions. All data collection activities will clearly inform the purpose, scope and use of collection through a system pop-up window when the user uses the corresponding function for the first time. Collection can only be carried out after the user clicks "Allow". If not authorized, the function cannot be used, but it will not affect the normal use of other unrelated functions (for example, browsing the recommended video stream does not require authorization of any permissions).
All collected personal data is only used to realize the core functions of this Application and optimize user experience, and no redundant data irrelevant to the functions is collected. The specific scope, purpose and method of collection are as follows:
(I) Basic Device and Application Information
1. Collection Scope: Device model, Android system version number, installed version number of this Application, Advertising Identifier (AAID, Android Advertising ID), unique device identifier (such as IMEI, MEID, only used for device adaptation, not associated with any personally identifiable information), network connection status (such as Wi-Fi/mobile data, network type), and basic data related to application information reading permissions (such as application installation time, running status, and background running permission activation status);
2. Collection Purpose: To ensure the stable operation of this Application on the user's device, and avoid crashes, freezes and other problems caused by incompatibility between device models and system versions; to optimize application performance, adjust video playback clarity and loading speed according to device configuration; to fix program vulnerabilities, count the frequency and reasons of application crashes, and launch repair versions in a timely manner; to provide users with functional experience adapted to their devices (such as optimizing interface display according to screen size); to display personalized advertisements based on Advertising Identifier (users can turn off personalized recommendations at any time); to count application usage data (such as function usage frequency, number of active users) for product iteration and optimization;
3. Collection Method: Automatically obtained when this Application is running, collected only after the user authorizes the "application information reading" permission. If not authorized, only basic device adaptation data (such as device model, system version) is collected, and no sensitive data such as Advertising Identifier and unique device identifier is collected.
(II) Data Related to Camera Permissions
1. Collection Scope: Static images taken by the camera (such as profile photos, post screenshots), dynamic videos (such as party short videos recorded by users), and real-time images during shooting (only temporarily cached, automatically cleared if not shot and saved);
2. Collection Purpose: To provide users with a profile photo shooting function to facilitate users to improve their personal homepage display; to provide users with a screenshot function when posting posts, which can capture video frames as post covers; to provide users with a short video recording function to record party scenes, DIY decoration processes, gathering highlights and other content to meet users' creation and sharing needs; all shooting content is independently controlled by the user, and only retained after the user actively clicks the "Shoot" and "Save" buttons. Unsaved content will be cleared immediately without any storage;
3. Collection Method: When the user uses the shooting, screenshot, and recording functions for the first time, this Application will pop up a permission application window, clearly informing that "Access to your camera is required to take profile photos, capture images for posts, and record videos". After the user clicks "Allow", relevant data is collected only when the user actively clicks the "Shoot"/"Record" button. After shooting/recording, the data is only saved locally on the user's device, and no cloud upload or third-party transmission is performed; if the camera permission is not authorized, the shooting, screenshot, and recording functions cannot be used, but users can normally browse, like, and collect videos posted by others.
(III) Data Related to Microphone Permissions
1. Collection Scope: Audio data recorded by the microphone (such as audio supporting short videos, voice memo content), no background sounds or irrelevant audio are collected, only audio content actively triggered by the user is recorded;
2. Collection Purpose: To synchronously collect audio when users record short videos to ensure the completeness and interestingness of video content; to provide users with a party plan voice memo function to facilitate users to record party planning ideas, to-do items, etc. Voice memos are only saved locally on the user's device and can be deleted by the user independently; all audio recording is actively triggered by the user, and the microphone will not be activated and no audio data will be collected if the "Record" button is not clicked;
3. Collection Method: When the user uses the audio recording and short video recording functions for the first time, this Application will pop up a permission application window, clearly informing that "Access to your microphone is required to record audio when recording videos and to record voice memos for party plans". After the user clicks "Allow", the microphone is activated and audio data is collected only when the user actively clicks the "Record" button. After recording, the audio data is bound to the corresponding video and memo and saved locally on the user's device; if the microphone permission is not authorized, the audio recording and short video recording with audio functions cannot be used, but users can record silent videos and browse videos posted by others.
(IV) Data Related to Photo Library (Album)
1. Collection Scope: Images in the user's photo library (such as personal photos, party scene photos), video files (such as party videos recorded in advance by users), only reads the content actively selected by the user, and does not read or scan all content in the user's photo library; at the same time, writes the video frame screenshots generated by the user in this Application into the user's photo library;
2. Collection Purpose: To provide users with a profile photo selection function to facilitate users to select suitable images from existing photos as their personal homepage avatars; to provide users with an image and video selection function when posting posts, and users can select existing party-related content from the photo library to post without re-shooting; to provide users with a video frame saving function, which can save wonderful frame screenshots from short videos to the photo library for users' subsequent use and sharing; all content written into the photo library is actively triggered by the user, and no writing operation is performed if the "Save" button is not clicked;
3. Collection Method: When the user uses the photo library selection and video frame saving functions for the first time, this Application will pop up a permission application window, clearly informing that "Access to your photo library is required to save video frame screenshots, select profile photos, and choose images and videos for posts". After the user clicks "Allow", data reading or writing operations are performed only when the user actively selects images/videos or clicks the "Save Screenshot" button; if the photo library permission is not authorized, the photo library selection and video frame saving functions cannot be used, but users can normally shoot and record new content and save it locally in the Application.
(V) Data Related to External Storage
1. Collection Scope: Various types of data generated by this Application, including but not limited to short videos, images, voice memos created by users, user operation logs (report logs, blocked content IDs), gold balance data, gold purchase/consumption records, post release records, collection records, etc.;
2. Collection Purpose: To persistently save the content created by users to ensure that after the user uninstalls and reinstalls the Application, the relevant content can be restored through local storage (cannot be restored if the user manually deletes the application data); to store user operation logs to ensure the normal realization of the report and block functions, and to facilitate users to query their own report and block records; to save gold balance and related transaction records to ensure that the balance is accurate every time the user uses gold, avoiding data loss;
3. Collection Method: After the user authorizes the external storage permission, this Application automatically writes relevant data into the user's device external storage (such as mobile phone memory, SD card) during operation. The data storage path is the application's exclusive folder, which can only be accessed by this Application; if the external storage permission is not authorized, the content created by the user, operation logs, and gold data cannot be saved, and all temporary data will be lost after closing the Application.
(VI) Local Operation Log Data
1. Collection Scope: Various operation records of users during the use of this Application, including report logs (such as report time, reported object ID, report reason), blocked content IDs (blocked video IDs, blocking time), gold consumption/purchase records (purchase time, gold level, consumption scenario), post release records (release time, post content ID), collection records, browsing records (only temporarily cached, automatically cleared after exiting the Application);
2. Collection Purpose: To ensure the normal operation of the report and block functions. After the user reports, a local report log is generated to facilitate our subsequent optimization of the content review mechanism (no background review, only for local function optimization); to record the use of gold to facilitate users to query their own gold income and expenditure details; to record the content released and collected by users to facilitate users to find them quickly;
3. Collection Method: When the user uses the corresponding functions, this Application automatically generates and stores relevant logs locally on the user's device, without any network transmission behavior, no upload to the back-end server, and no disclosure to any third party; users can query relevant operation records through the "My" page of this Application, and can also manually delete log data.
III. Rules for Processing and Using Personal Data
We strictly follow the principles of "legality, propriety, necessity, and transparency" to process user personal data. All data processing activities are carried out around the purposes agreed in Article 2 of this Policy, without using data beyond the agreed scope, and without any processing unrelated to the services of this Application. The specific rules are as follows:
1. Restriction on Scope of Use: We only use user personal data for the purposes of realizing the core functions of this Application (such as shooting, recording, posting, reporting, blocking, gold management), optimizing user experience, fixing program vulnerabilities, and displaying advertisements. Without the user's explicit consent, we will never use personal data for any other purposes, including but not limited to selling, renting, sharing to third parties, or using it for the promotion of other products and services.
2. Data Processing Location: All collection, processing, and storage of user personal data by this Application are completed locally on the user's device, without any back-end server storage, no cross-device or cross-platform data transmission, and no upload of user personal data to our server or any third-party server, ensuring that data is safe and controllable.
3. Restriction on Data Association: The Advertising Identifier (AAID) is only used to display personalized advertisements, not associated with the user's sensitive data such as camera, microphone, and photo library, nor associated with the user's operation logs and created content, ensuring that advertising recommendations do not disclose the user's personal privacy; the unique device identifier is only used for device adaptation, not for user identification, and not bound to other personal data.
4. Local Storage Rules: Data such as gold balance, report logs, blocked content IDs, and user-created content are persistently saved locally on the user's device through SharedPreferences and the application's exclusive folder. Users can manually delete relevant data through the "My - Settings" page of this Application; they can also clear the cache and data of this Application through the device system settings. After deletion, the records of the corresponding functions will be permanently lost and cannot be recovered.
5. Content Processing Rules: We will not conduct any manual review, editing, or modification of the user's audio, video, images and other created content. Only when the user triggers the report function, a local report log is generated for subsequent function optimization; we will not extract or analyze personal information from the user's created content, nor conduct content recognition or content push association (except for content actively collected and liked by the user).
6. Data Retention Period: The retention period of personal data is consistent with the period when the user uses this Application. From the date when the user uninstalls this Application or manually deletes the application data, all personally stored personal data will be completely cleared without any traces; temporary cached data (such as browsing records) will be automatically cleared after exiting the Application, with a retention period not exceeding 24 hours.
IV. Storage and Protection of Personal Data
We attach great importance to the security of user personal data, and adopt industry-leading technical and management protection measures, combined with the characteristics of local device storage, to comprehensively ensure the security of user personal data, prevent data from being unauthorized accessed, tampered with, leaked, damaged or misused. The specific measures are as follows:
(I) Storage-related Instructions
1. Storage Location: All user personal data is only stored locally on the Android device used by the user, including device memory and external storage (SD card), without any cloud storage or cross-border data transmission behavior, and the data is always within the user's controllable scope.
2. Storage Encryption: Sensitive data stored locally on the user's device (such as audio, video, operation logs) is encrypted using the AES-256 encryption algorithm. The encrypted data can only be decrypted and accessed through this Application, and cannot be read or cracked by other applications or unauthorized personnel.
3. Storage Permission Control: After the user authorizes the external storage permission, this Application can only access the data in its own exclusive folder, and cannot access other application folders or personal files on the user's device, ensuring data isolation and avoiding other data leakage caused by misoperation.
(II) Security Protection Measures
1. Technical Protection: Adopt technical means such as permission isolation, data encryption, operation log auditing, and vulnerability scanning to conduct regular security inspections on this Application and fix potential security vulnerabilities in a timely manner; restrict data access permissions within the application, and only relevant functional modules can access corresponding data to prevent internal data leakage.
2. Management Protection: Establish a sound personal data protection management system, clarify data processing processes and division of responsibilities, conduct personal data protection training for staff involved in product development and maintenance, and strictly prohibit staff from obtaining or disclosing user personal data; staff can only access application code and functional logic, and cannot access any local data of users.
3. User Independent Protection: The security of the user's personal data also depends on the security of the user's device. We recommend that users set a device password, enable fingerprint/facial unlock, regularly update the device system and the version of this Application, do not disclose device information and application operation passwords (if any) to others, and avoid the device being stolen, lost or used by unauthorized personnel; do not click on unknown links or install unknown applications at will to prevent malicious software from stealing data of this Application on the device. We shall not be liable for personal data leakage caused by the user's own device security issues.
(III) Emergency Response to Data Leakage
If user personal data is leaked due to force majeure, device vulnerabilities, third-party malicious attacks and other unexpected situations, we will immediately take the following emergency measures: 1. Activate the security emergency response mechanism, stop relevant data processing activities, block security vulnerabilities, and prevent the expansion of the leakage scope; 2. Investigate and clean up the leaked data, take measures such as encryption and deletion to reduce the leakage risk; 3. Timely inform the affected users through pop-ups, pushes and other methods in this Application, explaining the leakage situation, emergency measures and follow-up processing plan; 4. Cooperate with the regulatory authorities in the user's region to carry out investigation and evidence collection work, and assist users in safeguarding their legitimate rights and interests.
V. User's Personal Data Rights
According to relevant laws and regulations such as GDPR, CCPA, CPRA, VCDPA, LGPD, and FADP, users in different regions enjoy corresponding personal data rights. We will provide users with convenient and efficient channels to exercise their rights in accordance with the requirements of applicable laws, without setting any unreasonable restrictions. The specific rights are as follows:
(I) General Rights (Applicable to Users in All Regions)
1. Right to Know: Users have the right to consult this Policy at any time to understand the scope, purpose, method, legal basis of our collection, use and processing of personal data, as well as the data retention period, security protection measures and other relevant information; users have the right to view the currently authorized permissions and the corresponding data collection status through the "My - Settings - Privacy Settings" page of this Application.
2. Right of Access: Users have the right to consult all personal data generated by themselves in this Application, including but not limited to created short videos, images, voice memos, operation logs (reporting, blocking, gold income and expenditure, post release), collection records, etc., which can be directly queried and exported through the relevant pages of this Application (the export function supports saving content locally on the device).
3. Right to Rectification: Users have the right to modify their personal data such as profile photos, posted content, and collection records, which can be directly operated and modified through the "My" page of this Application. After modification, the data will be updated in real time, and the old data will be automatically overwritten and deleted.
4. Right to Erasure: Users have the right to manually delete personal data in this Application, including but not limited to created content, operation logs, collection records, etc.; they can also clear all caches and data of this Application through the device system settings, or uninstall this Application. After deletion, all personally stored personal data will be permanently cleared and cannot be recovered; if the user needs to delete specific data, they can make a request to us through the contact email, and we will assist the user in completing the deletion operation.
5. Right to Withdraw Consent: Users have the right to withdraw the authorization of permissions such as camera, microphone, photo library, external storage, and application information reading at any time through the device's system settings; after withdrawing the authorization, we will immediately stop collecting relevant data of the corresponding permission, and the collected data will continue to be stored locally on the user's device (which can be manually deleted by the user), without affecting the use of other functions for which authorization has not been withdrawn.
6. Right to Complain: If the user believes that our personal data processing behavior has infringed their legitimate rights and interests, they have the right to complain to the data protection regulatory authority in the user's region. We will actively cooperate with the investigation and inspection of the regulatory authority, truthfully provide relevant materials on personal data processing, and assist the user in safeguarding their rights and interests.
(II) Additional Rights for Users in Specific Regions
1. European Union Region (Scope of GDPR Application): In addition to the above general rights, users also enjoy the following rights:
○ Right to Data Portability: The right to request us to provide their personal data to themselves or transmit it to other data controllers in a structured, commonly used and machine-readable format. We will assist the user in completing data export and transmission operations within 30 working days after receiving the request (since the data is only stored locally on the user's device, we will guide the user to export it through device operations);
○ Right to Restriction of Processing: In specific cases (such as the user has objections to the accuracy of the data, or the data processing behavior is illegal), the right to request us to restrict the processing of their personal data. During the restriction period, we will suspend the use of relevant data, only retain the data storage, and not perform any other processing;
○ Right to Object to Processing: The right to object to our personal data processing behavior based on legitimate interests (such as advertising push). After receiving the objection request, we will immediately stop the relevant data processing behavior, unless we can prove that there are legitimate interests that take precedence over the user's rights and interests, or it is necessary to fulfill legal obligations.
2. California, USA (Scope of CCPA/CPRA Application): In addition to the above general rights, users also enjoy the following rights:
○ Right to Opt-Out of Data "Sale": We clearly commit that we will not conduct any form of "sale" of user personal data (including but not limited to disclosing user personal data to third parties in the form of monetary, other interest exchanges). If it is necessary to involve the sharing of user personal data (not sale) due to business development in the future, we will publicly disclose the scope, purpose, third-party subject in advance in this Application, and provide users with a clear opt-out channel;
○ Right to Non-Discrimination: When users exercise their personal data rights (such as access, deletion, opt-out), we will not take any discriminatory service measures against them, including but not limited to increasing service prices, reducing service quality, restricting function use, and refusing to provide services;
○ Right to Know About Data Disclosure: The right to request us to inform them of the scope, purpose, sharing objects (if any) of their personal data collection, and the situation of data "sale" (this Application has no data sale behavior, and will clearly inform the user).
3. Virginia, USA (Scope of VCDPA Application): In addition to the above general rights, users also enjoy the following rights:
○ Right to Opt-Out of Targeted Advertising: The right to request us to stop targeted advertising push based on user personal data. Users can turn off personalized advertising through the "My - Settings - Advertising Settings" of this Application, or turn off the Advertising Identifier (AAID) through the device system settings. After turning off, only non-personalized advertising will be displayed, which will not affect the number of advertisements displayed and the use of application functions;
○ Right to Data Correction: The right to request us to correct their incorrect and incomplete personal data. After receiving the request, we will guide the user to complete data correction locally on the device to ensure the accuracy of the data.
4. Brazil (Scope of LGPD Application): In addition to the above general rights, users also enjoy the following rights:
○ Right to Data Correction: The right to request us to correct their incorrect and incomplete personal data. If the data is stored locally on the user's device, we will guide the user to correct it manually; if there are other situations that require assistance, we will assist the user in completing the correction within 15 working days after receiving the request;
○ Right to Data Destruction: The right to request us to destroy their personal data. After receiving the request, we will guide the user to clear the application data or uninstall the application through device settings to ensure that all personal data is permanently destroyed, and provide a destruction confirmation certificate (such as operation screenshot guidelines).
5. United Arab Emirates (Scope of FADP Application): In addition to the above general rights, users also enjoy the following rights:
○ Right to Data Confidentiality: We will strictly abide by the requirements of FADP, assume strict confidentiality obligations for the user's personal data, and will never disclose or share the user's personal data to any third party without the user's explicit consent, except as required by laws and regulations;
○ Right to Object to Data Access: If the user has objections to our personal data access and processing behavior, they have the right to raise objections to us. We will conduct an investigation within 10 working days after receiving the objection and inform the user of the investigation result and processing plan.
(III) Special Agreement on Data "Sale"
1. This Application will never conduct any form of "sale" of user personal data from beginning to end, including but not limited to disclosing or transferring user personal data to any third party in the form of monetary transactions, interest exchanges, cooperative sharing, etc., nor will it use user data for any commercial transaction activities.
2. If it is necessary to involve the sharing of user personal data (not sale, such as cooperating with third parties to optimize application performance and display advertisements) due to business development in the future, we will strictly follow the following requirements:
○ Publicly disclose it prominently on the splash screen and settings page of this Application in advance, clearly informing the user of the scope, purpose, name and contact information of the third-party subject, and the period of data sharing;
○ Sign a strict data protection agreement with the third party, requiring the third party to abide by relevant laws and regulations, take corresponding security protection measures, and not use or disclose user personal data beyond the agreed scope;
○ Provide users with a clear opt-out channel. Users can choose not to allow their personal data to be shared at any time. After choosing to opt out, we will immediately stop sharing relevant data to the third party.
3. Users have the right to choose not to allow their personal data to be shared (not sale) at any time. They can make a request by sending an email to carrywdiegobowlowsk@gmail.com. The subject of the email should be marked as "Opt-Out of Data Sharing - Device Model", and the body of the email should explain the specific type of data that needs to be opted out of sharing (such as advertising-related data, basic device data). We will assist the user in completing the relevant settings within 15 working days after receiving the request and confirm it by email reply.
VI. Third-Party Services
To realize some auxiliary functions of this Application (such as advertising display, application performance statistics), this Application may integrate a small number of third-party SDKs and services. Third-party service providers will collect and use relevant data in accordance with their own privacy policies. We have conducted strict reviews on all integrated third-party services, requiring third-party service providers to abide by relevant personal data protection laws and regulations, take necessary security protection measures to ensure user data security, and not collect or disclose user sensitive personal data (such as audio, video, photos).
All third-party services only collect the minimum range of data necessary to realize the functions, not associated with the user's sensitive data, and do not collect redundant data. The specific integrated third-party services are as follows (will be updated in real time in this Application):
(I) Advertising Service SDK
1. Integration Purpose: To display advertising content, provide support for application operation, and ensure that the application can provide services to users free of charge;
2. Collection Scope: Advertising Identifier (AAID), basic device information (device model, system version), network connection status, no sensitive data such as user's audio, video, photos, operation logs are collected;
3. Data Use: Only used to display personalized advertisements and optimize advertising delivery effects, not associated with user personally identifiable information, and not shared with subjects other than third-party advertisers;
4. User Control: Users can turn off the Advertising Identifier (AAID) through the device system settings. After turning off, the third-party advertising SDK will not be able to collect the Advertising Identifier, and only non-personalized advertisements will be displayed, which will not affect the use of application functions; users can also turn off personalized advertising push through the "My - Settings - Advertising Settings" of this Application.
(II) Application Performance Statistics SDK
1. Integration Purpose: To count application operation data, including application crash frequency, function use frequency, page loading speed, etc., for optimizing application performance, fixing program vulnerabilities, and improving user experience;
2. Collection Scope: Application crash logs, function use data (such as the number of times the shooting and posting functions are used), basic device information (device model, system version), application version number, no user personally identifiable information or sensitive data is collected;
3. Data Use: Only used for application performance optimization and vulnerability repair. The statistical data is anonymized and aggregated data (such as the crash rate of a certain type of device), which does not contain any information that can identify the user personally, nor is it associated with the user's created content;
4. Data Protection: The data collected by the third-party statistics SDK is only used for application optimization and not disclosed to any third party. We will regularly clean up relevant statistical data, with a retention period not exceeding 90 days.
We will display the list of all integrated third-party SDKs, corresponding privacy policy links and the scope of collected data on the "My - Settings - Third-Party Services" page of this Application, which users can consult at any time; if the third-party service provider adjusts its privacy policy or data collection scope, we will update the publicity content in a timely manner to ensure the user's right to know.
VII. Responsibilities of the Data Controller and DPO
To ensure that user personal data is processed in a compliant and secure manner, we clarify the responsibilities of the data controller and the Data Protection Officer (DPO), and strictly perform our obligations in accordance with relevant laws, regulations and the provisions of this Policy. The specific responsibilities are as follows:
(I) Responsibilities of the Data Controller (Dingzhou Xianchang Technology Co., Ltd.)
1. Strictly collect, use, process and store user personal data in accordance with the requirements of this Policy and relevant laws and regulations, ensure that data processing activities are legal, compliant and transparent, and do not process data beyond the agreed scope;
2. Take reasonable and effective technical and management measures to ensure the security of user personal data, prevent data from being unauthorized accessed, tampered with, leaked or damaged, and conduct regular data security inspections and vulnerability repairs;
3. Provide convenience for users to exercise their personal data rights, timely respond to user inquiries and requests (such as accessing, deleting, correcting data), and provide clear handling results within the time limit specified by laws and regulations;
4. Appoint a dedicated person as the Data Protection Officer (DPO), clarify the responsibilities and powers of the DPO, and provide necessary support (such as resources, staff cooperation) for the DPO to perform their duties;
5. Conduct Data Protection Impact Assessment (DPIA), identify security risks in the data processing process, and take corresponding risk prevention and control measures;
6. Cooperate with the data protection regulatory authorities in the user's region in investigation, inspection and law enforcement work, truthfully provide relevant materials and records on personal data processing, and actively implement regulatory requirements;
7. Update this Privacy Policy in a timely manner, revise the Policy content in accordance with laws and regulations, Google Play Store policies, and business development needs, and publicize it in the application to ensure the user's right to know;
8. If a personal data leakage incident occurs, immediately activate the emergency response mechanism, take remedial measures, timely inform the affected users, and report to the regulatory authorities (if required by laws and regulations).
(II) Responsibilities of the Data Protection Officer (DPO)
The DPO appointed by this Application strictly performs his duties in accordance with Article 38 of GDPR and relevant laws and regulations, carries out personal data protection work independently, and is not interfered by other departments or personnel. The specific responsibilities are as follows:
1. Participate in the personal data processing activities of this Application throughout the process, including compliance review of links such as data collection, use, storage, and protection, to ensure that all data processing activities comply with relevant laws, regulations and the provisions of this Policy;
2. Conduct Data Protection Impact Assessment (DPIA), identify security risks in the data processing process, put forward risk prevention and control suggestions, and supervise the implementation of relevant measures;
3. Answer user inquiries about personal data protection, handle user personal data rights requests (such as accessing, deleting, correcting data), coordinate relevant departments to give handling results, and feed back to users in a timely manner;
4. Maintain communication with the data protection regulatory authorities in the user's region, keep abreast of the update of regulatory policies, cooperate with the investigation and inspection work of the regulatory authorities, and submit relevant reports and materials;
5. Formulate and update the personal data protection management system and operation procedures of this Application, conduct personal data protection training for employees, improve employees' awareness of privacy protection, and standardize employees' operation behaviors;
6. Supervise the data processing behavior of third-party service providers, review third-party data protection agreements, and ensure that third parties strictly abide by relevant laws and regulations and ensure user data security;
7. Regularly submit a personal data protection work report to the data controller (us), reporting the compliance of data processing, security risks and improvement measures.
VIII. Protection of Minors
This Application is clearly targeted at adult users aged 18 and above. We strictly abide by relevant laws and regulations and Google Play Store policies, do not intentionally collect or process personal data of minors under 18 years old, and do not provide any services to minors.
If we find that a minor is using this Application through application usage behavior, device information, etc., we will immediately take the following measures: 1. Stop providing all application services for them and restrict their use of all functions of the application; 2. Clear all personal data stored locally on their device (including created content, operation logs, etc.); 3. Pop up a prompt in the application, inform them that this application is only for adult users, and guide them to uninstall the application.
If the guardian of a minor finds that their child is using this Application and wishes to delete relevant data and stop the service, they can make a request to us through the contact email carrywdiegobowlowsk@gmail.com. The subject of the email should be marked as "Minor Data Deletion - Guardian's Name", and the body of the email should provide relevant supporting materials (such as the guardian's ID certificate, the minor's ID certificate). We will assist in completing the data deletion and service termination operations within 7 working days after receiving the request and confirm it by email reply.
IX. Disclaimer
Within the scope permitted by relevant laws and regulations, we shall not be liable for any problems such as user personal data leakage, loss or other related issues caused by the following situations:
1. Personal data leakage and loss caused by the user's own reasons, including but not limited to: device theft, loss, password leakage, disclosure of device information and application operation records to others, random clicking on unknown links, installation of malicious software, content loss caused by manual deletion of application data, etc.;
2. Abnormal personal data processing caused by force majeure, including but not limited to natural disasters (earthquakes, floods, etc.), wars, network interruptions, device failures, changes in laws and regulations, etc. We will take remedial measures within our capabilities to minimize user losses, but shall not be liable for breach of contract;
3. Personal data leakage and loss caused by the fault of third-party service providers (such as third-party SDK vulnerabilities, data leakage). We will assist users in claiming liability from third-party service providers and provide necessary support, but shall not be directly liable; if we fail to perform our review obligations and cause third parties to process data in violation of regulations, we will bear corresponding joint and several liability;
4. We only cooperate with the investigation and evidence collection work of regulatory authorities and judicial organs within the scope required by laws and regulations, and provide relevant data (only data stored locally on the user's device, provided with the user's cooperation). We shall not be liable for personal data disclosure caused thereby;
5. We shall not be liable for any personal data leakage or loss caused by the user's use of non-official versions of this Application (such as pirated, cracked versions), and will pursue the legal liability of relevant personnel at the same time;
6. Leakage and loss caused by the user's voluntary sharing of their personal data (such as sharing created videos and images to other platforms) shall be borne by the user themselves.
X. Dispute Resolution
1. Any dispute arising from or in connection with this Policy shall first be resolved by us and the user through friendly negotiation. The negotiation period is 30 natural days. If the negotiation fails, either party has the right to file a lawsuit with the people's court with jurisdiction in the place where this Policy is signed (Dingzhou City);
2. During the dispute resolution period, other clauses of this Policy shall remain in effect, and both parties shall continue to perform their respective obligations and shall not stop performing relevant obligations due to the dispute;
3. If the laws and regulations of the user's region have special provisions on the dispute resolution method, such provisions shall prevail.
XI. Others
1. The right to interpret this Policy belongs to Dingzhou Xianchang Technology Co., Ltd. If the user has any questions about this Policy, they can consult through the contact email carrywdiegobowlowsk@gmail.com, and we will answer them in a timely manner;
2. If any clause of this Policy is deemed invalid or unenforceable, it shall not affect the validity of other clauses. Other clauses shall remain valid, and both parties shall continue to perform them;
3. This Policy constitutes a complete agreement between the user and us on personal data protection, replacing any previous oral or written relevant agreements between the two parties. If there are any supplementary agreements between the two parties, the supplementary agreement shall prevail if it is inconsistent with this Policy;
4. The user's use of this Application shall be deemed that they have fully understood and agreed to all clauses of this Policy, including the clauses after subsequent revisions.
Dingzhou Xianchang Technology Co., Ltd.
March 19, 2026