# Lingying Privacy Policy Version: 2026-10-04 Effective date: The date this version is first published on jusi.pro Personal information controller: 北京燕婉科技有限公司 (“we” or “us”) Contact: In-app “Help & tickets”; yanwancy@gmail.com This Policy explains how Lingying processes personal information and how you can manage it. It covers our website, web workspace, desktop client and account, AI, project, transaction and support services directly provided by us. Use, charges and transactions are addressed in the [Lingying Terms of Service](terms.en.md). **Please note: desktop local and web cloud workspaces are stored separately; AI requests transmit necessary task content to our backend and model recipient chain; sharing requires sign-in but other signed-in link holders can view it; account closure does not immediately erase every business record or local file. Acceptance does not replace legally required separate consent for sensitive information, independent recipients or cross-border processing.** ## 1. Scope, roles and principles 1.1 Personal information concerns an identified or identifiable person. Legally anonymized information that cannot identify a person or be restored is excluded. Hashing, de-identification or removing a name does not necessarily anonymize information; account-linked records remain protected as personal information. 1.2 We follow lawfulness, fairness, necessity, transparency and minimization, explaining categories and purposes by feature. Necessary and optional processing are distinguished; refusal of an unrelated permission does not stop unrelated basic services. 1.3 This Policy does not replace policies for third-party services you enable or applications you generate and independently operate for end users. We remain responsible for our hosting, sign-in and associated processing. Third parties are addressed in Section 6. ## 2. Accounts, profiles and service administration | Scenario | Information processed | Purpose and choice | | --- | --- | --- | | Registration, sign-in and verification | Your phone number and country/region prefix; verification requests, delivery results, code hashes and attempts; password hashes, user ID, session hashes and expiry | Account creation, identity verification, protection against misuse and sign-in. A valid phone number is required for authenticated functions; password login is optional. | | Profile and account administration | Your nickname and avatar address; phone changes, password reset and closure verification records | Profile display, account management and high-impact change verification. An optional avatar is not required for basic use. | | Document acceptance | Accepted Terms and Policy versions, time, entry point and corresponding file digests | Evidence of affirmative acceptance and version dispute handling; old acceptance is not rewritten when documents change. | | Billing region and visit statistics | Registered billing region based on phone number; request IP, time, user-agent information, country/region inferred from IP and account or visit event associations | Applicable quotes, visit statistics, security and service operations. No device GPS is read and IP inference does not establish a precise location. | Network requests inherently contain an IP address and necessary protocol headers; operations generate some security and audit records. SMS recipients handle code delivery. Ordinary registration does not require contacts, identity-document scans, payment passwords or your entire photo library. ## 3. AI, projects, attachments and support | Scenario | Information processed | Purpose and choice | | --- | --- | --- | | Conversations, code and file generation | Prompts, necessary previous context, model parameters and reasoning effort, output, task status, usage and error information | AI execution, continuation, results, metering and troubleshooting. Part of an initial conversation may also be sent to a model to generate a sidebar title. | | Attachments and project files | Files you select, drop or paste; names, types, sizes, content and extraction results; source code or tool output required by the task | Preview, opening, understanding materials and creating or editing projects. Avoid selecting unrelated files. Removing a draft attachment does not recall an already submitted request. | | Local and web workspaces | Conversations, drafts, attachments, project settings, code, generated files, execution records and task associations | Work continuity. Desktop content is primarily local; web content is server-side. Whole workspaces are not automatically synchronized. | | Scheduled tasks | Instructions, schedules, tools, status, results and usage | User-configured local or cloud execution. Deletion or disabling stops future runs, not completed actions. | | Cloud publication and sharing | Materials you upload, necessary runtime files and publication settings; viewer account, access credentials and necessary access logs | Hosting, access control and sharing. Sharing requires sign-in but signed-in link holders may view and save published content. | | Help and tickets | Issues, contact details, necessary task or order information, voluntarily supplied text and files, and replies | Support, rights requests, complaints and disputes. Do not submit unnecessary identity documents, passwords, health or financial details. | File extraction, screenshots and tool results may include others’ information. Confirm authority and redact, crop or remove unnecessary material. **Sensitive information includes specific identities, financial accounts, health, biometrics, precise movements and information about children under 14. Ordinary tasks do not require it.** A feature requiring sensitive information must explain necessity and effects and obtain legally required separate consent; an overall Policy checkbox is not enough. ## 4. Device permissions, notifications and updates | Permission or capability | Trigger and scope | Controls | | --- | --- | --- | | Files and clipboard input | Reading the input when you select/drop an attachment or invoke paste; task-authorized file reading or editing | Do not select files, remove unsent attachments or stop the task. Attachment input does not continuously read the whole clipboard. | | Screen recording and accessibility | After you start recording or enable computer operation and relevant OS authorization is effective: screen, window, control and interaction information; necessary context may be sent to models | Stop recording/tasks or revoke OS permissions. Other windows and third-party information may be visible; inspect first. | | Browser and external connections | Enabled tools/plugins read task-related page state, content and necessary connection credentials | Sign out or revoke connections. External pages have their own policies; ordinary chat does not require external passwords. | | Task completion notifications | After you choose alerts and allow browser/OS permission: task identifier, type, completion status and destination; full chat, attachment or code bodies are not put in system notices | Disable alerts or revoke system permission. Preferences are saved on the device. Current delivery depends on the browser page or desktop program running. | | Desktop updates | Checking platform, architecture and version; requesting and verifying update data after your click and generating necessary network logs | Checks do not upload local projects, chats or attachments. Downloads and restart follow client workflows. | Denying a permission affects only dependent functions. Revocation does not invalidate earlier lawful transmission or erase records lawfully retained by external recipients. All device permissions are not bundled as a registration requirement. ## 5. Payments, usage and processing grounds 5.1 Purchases and metering process order identifiers, purchase quotes and currencies, amounts paid, membership periods, balance and promotional allocations, usage, reservations and settlement, transaction identifiers, signature verification and payment status. Referrals also involve invitation codes, valid registration relationships, rewards and commission. These support transactions, delivery, reconciliation, duplicate prevention and lawful retention. 5.2 General refund rules are in the Terms. Although balance has no self-service refund entry, historical refunds, legally due refunds and accounting corrections still involve reasons, necessary evidence, amounts, review and payment results. Removing an entry does not erase records. Payment providers independently process checkout authentication. We do not collect full card numbers, payment passwords or payment verification codes. 5.3 Where applicable law permits, necessary registration, task execution and purchased-service delivery rely on entering or performing a contract. Statutory records, security responses and lawful official requests rely on relevant obligations. Optional functions rely on your active choice and legally required consent. Grounds are assessed for each jurisdiction; contract necessity does not cover all collection. 5.4 **We do not sell personal information, use private prompts, files or code for targeted advertising, or acquire blanket foundation-model training authorization through this Policy.** New purposes require notice and applicable procedures. Upstream retention, training and human review require verification by actual recipient; we do not claim universal zero retention or no training without evidence. 5.5 Current services do not use solely automated decisions with significant legal or similar effects on people, or personal profiles to impose different prices for identical transaction conditions. Regional quotes and metering follow stated rules. Request explanations or raise lawful objections to automated processing results. ## 6. Entrusted processing, disclosures and sharing 6.1 Providers may participate in infrastructure, SMS and model processing. Payment, external plugins and mail services may independently determine processing for their services. Scope depends on features used. Relevant information is collected in the [Third-party Information Processing Disclosure](third-parties.en.md). 6.2 For entrusted processing, we lawfully agree purposes, duration, methods, categories, safeguards and responsibilities and oversee processing. For independent recipients, we provide legally required identity, contact, purpose, method and category notice and obtain separate consent where required. A provider list or this Policy does not replace these steps. 6.3 Model requests pass through configured gateways and upstream services, rather than only the brand shown in Lingying. Necessary data may include context, extracted attachments, tool results and authorized screens. Signing in alone does not send a whole local workspace. Changes introducing purposes, recipients or cross-border processing require renewed disclosure and authorization assessment. 6.4 Voluntary sharing displays material to signed-in link holders. Obtain necessary authority and legally required separate consent for others’ information. **Sign-in does not prevent copying or screenshots; ending sharing does not erase copies already saved.** A published link does not by itself grant editing rights to private conversations or workspace source files. 6.5 We do not publicly disclose private information without a basis. We verify authority and scope of lawful official requests and disclose only necessary information. Lawful transfers following mergers, splits, dissolution or bankruptcy require recipient identity/contact notice and continuing safeguards; purpose or method changes require applicable procedures again. ## 7. Local storage, cookies and sessions 7.1 Desktop workspaces, files, attachments, recordings and some recovery copies are primarily local. AI forwarding, cloud uploads, account services and metering still produce server-side or recipient records; local storage does not mean no transmission. 7.2 The web workspace uses localStorage and IndexedDB for sign-in, preferences and draft attachments. The sharing domain uses path-limited session cookies to authenticate viewers. These support authentication, input recovery and access controls, not current third-party advertising tracking across sites. 7.3 Clear local or site data through the app, browser or operating system. This may sign you out or remove unsent drafts but does not automatically erase cloud workspaces, published files, accounts or OS backups. Signing out revokes the corresponding server session; uninstalling is not account closure. ## 8. Locations, retention and deletion 8.1 Core accounts and web workspaces currently reside on our Shanghai, China servers; local data resides on your device. **Core server location does not establish that every recipient, model chain, mail system or backup is in Shanghai.** Sections 6 and 9 address other processing. | Data | Retention and deletion | | --- | --- | | Verification requests | Codes expire after five minutes. At startup and hourly, requests expired for more than 30 days are cleared. | | Sign-in sessions | Valid for at most 30 days and revoked on sign-out or closure. Startup/hourly cleanup removes sessions expired or revoked for more than 30 days. Sharing credentials have shorter lifetimes and depend on account status. | | Profile and workspace | Retained while needed for the account and features. You can edit, delete or submit rights requests. Local files and OS backups are managed on your device. | | Web Work conversations and attachments | Deleting a conversation removes corresponding database records and attempts to remove attachments. Recovery copies, failed deletion or necessary linked records may remain; request verification and further deletion. | | Cloud projects and publication | Seven-day restoration period after moving to trash. Expiry or emptying clears requirements, plans, build content, attachments and publication files; necessary linked records remain according to purpose. | | Scheduled tasks | Deletion/disabling stops future execution; existing results, usage and necessary audits are not immediately erased by disabling. | | Orders, settlement, complaints and security records | Retained as needed for fulfillment, reconciliation, legal duties and disputes. No promise of immediate deletion equivalent to an ordinary draft. | | Post-closure abuse-prevention records | Keyed phone digests, identity links, invitation codes and trial/reward records support the 30-day re-registration waiting period and prevent duplicate rewards. They do not restore the old account or display old profiles. | 8.2 Task records, tickets, model task configuration snapshots and server backups without uniform automatic expiry are not described as having an already implemented suggested “30-day deletion” schedule. Retention must be limited to necessary service, security, legal and outstanding-dispute purposes. Request verification and deletion of unnecessary information. A client-side clear action does not determine recipients’ own retention. 8.3 We lawfully delete or anonymize information when conditions are met. Where retention is legally required or immediate deletion is technically unavailable, processing is limited to storage and necessary security safeguards, with restricted access. Backup copies are cleared under actual rotation; restored backups remain subject to effective deletion requests. We do not promise simultaneous erasure of all backups and third-party copies. ## 9. Processing outside Mainland China 9.1 Model gateways and their upstream services may involve processing outside Mainland China. SMS to US numbers, PayPal checkout for USD memberships, external overseas services and emails you send to the Gmail support address may also involve overseas recipients. **US phone numbers, USD quotes or Mainland China servers alone do not establish where all processing occurs.** 9.2 Cross-border personal information processing requires the applicable lawful mechanism, specific recipient/contact, purpose, method, category and rights notice, necessary impact assessment and separate consent where required. This Policy is not blanket consent or evidence that assessments, contracts or certifications have been completed. 9.3 Contact us for recipients and locations for a particular task or access, correction and deletion requests. We address our own responsibilities and lawfully help relay requests to relevant recipients. Declining a particular overseas recipient may make dependent features unavailable, without affecting unrelated basic functions. ## 10. Choices and rights 10.1 You may lawfully access, copy, correct, supplement or delete information, withdraw consent-based processing, restrict or reject particular processing, request rule explanations and close your account. Available profile, conversation and project controls can be used directly; other requests go through tickets or email. Lack of a self-service button does not remove a right. 10.2 We may verify necessary identity information and explain additional evidence; unrelated identity documents are not requested without a basis. We respond within applicable legal deadlines or explain refusal and remedies. Others’ rights, required retention, repetitive or manifestly excessive requests are handled under applicable law. 10.3 Withdraw consent by stopping optional features, revoking OS permissions, disconnecting external services or contacting support. This does not affect earlier lawful processing or legally required continuing duties. Unused benefits and outstanding orders follow the Terms and law; waiving transaction rights is not a condition of exercising privacy rights. 10.4 “Settings → Account & security → Delete account” requires phone verification and confirmation. Closure disables access, revokes sessions, removes the login phone/password, stops cloud tasks and starts relevant project deletion. Running tasks, pending payments/refunds and undelivered orders must be addressed first. **Closure is irreversible, does not automatically transfer old membership, balance or content, does not immediately physically erase every record and does not delete local files.** Export necessary materials and address outstanding matters first. 10.5 The same number must wait 30 days to register again. A keyed phone digest associates historical identity to prevent duplicate registration rewards or trial resets. It remains a protected linked record rather than freely usable anonymized information. Other retention follows Section 8; further deletion requests remain available. 10.6 Where applicable in your region, portability, processing restriction, objections and opt-outs from sale/sharing or targeted advertising may be requested through the same channels. We do not discriminate for lawful rights exercise. Regional descriptions do not remove mandatory rights or remedies. ## 11. Children and security 11.1 The service is not directed to children. Information about children under 14 is sensitive; until child services and guardian consent mechanisms are implemented, children must not independently register or submit information. US children under 13 must not independently register either. Phone verification does not automatically verify age. Guardians should contact us if such accounts or information are found; after verification we take appropriate restrictions/deletion measures and do not claim an implemented dedicated child-verification system. 11.2 Measures include authentication, access controls, necessary audits, password/token hashes, encrypted model credentials and appropriate transport security. Hashing does not mean all chat, project and database contents are encrypted. Ordinary services do not claim end-to-end encryption, zero retention or unverified certification. 11.3 For leakage, alteration or loss, we take corrective, investigation and mitigation measures and provide legally required notices of categories, causes, effects and available measures to you and authorities. No network system is absolutely secure; contact us about anomalies. ## 12. Updates and contact 12.1 Material changes receive appropriate website, app or other lawful notice of changes and effective dates. Changes to purposes, methods, categories or processing requiring renewed consent trigger applicable procedures. Historical acceptance is not converted into new acceptance. Continued use does not replace separate notice or consent required by law. 12.2 Privacy questions, rights requests, complaints and child-information concerns go to “Help & tickets” or yanwancy@gmail.com. Mail may involve overseas services; in-app tickets are an alternative. Supply necessary identification and the request, not passwords, codes or unrelated sensitive information. 12.3 We verify, handle and respond as required by law. If dissatisfied, you may complain to a competent authority or seek relief in a court with jurisdiction. Chinese, English and Traditional Chinese displays should be substantively equivalent; translation differences do not reduce statutory rights.