思念来电 · Privacy Policy
Google Sign-in Notice — 思念来电
When you choose Google sign-in, 思念来电 requests the basic openid, email and profile permissions through Google OAuth / OpenID Connect. We verify Google's identity token and use your Google account's unique identifier, email address, email-verification status and display name to create or identify your account, display account information and secure sign-in. We do not request access to Gmail messages, Google Drive files, contacts or calendars.
Google receives the client identifier, callback address and security parameters needed for the authorization request. Authorization codes are exchanged and validated on our server. Your Google identifier, email address and display name are associated with your app account. Google sign-in is used for account identity and security. Photos, audio and conversations you separately upload are handled under the corresponding sections below.
This account information follows the account-data retention provisions below. You may request account closure in the app or contact the email published on this page for access, correction, export or deletion, subject to identity verification. You can also revoke access in your Google account's third-party connections settings. Revoking Google authorization does not itself delete information already stored in this app; request deletion separately.
Read this notice together with the Privacy Policy below.
PRIVACY POLICY
Version: privacy-2026-10-06
Effective date: October 6, 2026
Controller: Fuxin Brain Kingdom AI Technology R&D Co., Ltd.
This Policy explains how we collect, use, store, disclose, transfer, and protect personal data and how you may exercise your rights. Face data, voiceprints, voice characteristics, financial-account data, precise location, and children's data may be sensitive personal data. We process them only when necessary for a specific purpose and with separate consent or another valid legal basis where required.
1. Scope. This Policy applies to our app, website, APIs, text chat, voice calls, video avatars, voice cloning, long-term memory, paid packages, support, and security functions. Independently provided third-party services are governed by their own notices.
2. Data we process. We may process: (a) account data such as phone number, country/region code, email, display name, password hash, verification status, account status, and consent records; (b) friend profiles, relationship type, avatars, and persona notes; (c) microphone audio, voice samples, call recordings, transcripts, synthesized audio, voice IDs, and acoustic features; (d) photographs, camera video, face images, avatar materials, and extracted features; (e) messages, call type, duration, status, imported chat/audio/video materials, summaries, tags, links, embeddings, and memories; (f) orders, package type, price, currency, quota, usage, refunds, and chargebacks, while full payment credentials are normally handled by the payment provider; (g) IP address, approximate country/region, language, browser, operating system, session/device identifiers, logs, errors, and risk signals; and (h) support communications and evidence.
3. Purposes. We process data to create and secure accounts; provide chat, speech, cloning, avatar, video, and memory functions; analyze materials you choose to import; fulfill orders and manage quotas; provide support; prevent abuse and fraud; comply with law; and improve reliability. Unless separately disclosed and lawfully authorized, we do not use private chats, faces, voices, or memories to train a general-purpose model for unrelated users.
4. Device permissions. Microphone access supports calls, recording, recognition, and voice samples. Camera access supports video calls, visual understanding, and avatar media. File/photo access occurs only when you select media. Notifications support calls, messages, orders, and security notices. You may revoke permissions, but related functions may stop working.
5. Sensitive data and consent. Face and voice features may enable identification or realistic simulation. Use these functions only for yourself or an authorized person. We may require a prominent notice and separate consent before processing. You may withdraw consent and delete source materials; withdrawal does not affect prior lawful processing and may disable the feature.
6. Processors and disclosures. Depending on what the administrator has actually enabled, processors may include cloud/storage, AI model, speech, avatar, moderation, payment, email, international SMS, CAPTCHA, CDN, monitoring, and support providers, such as Volcengine/Doubao, Anam or Tavus, Paddle or PayPal, Alibaba Cloud or Tencent Cloud. A named but disabled provider does not receive data merely because it is listed. We contractually restrict processors where required. We do not sell personal data. Business transfers and legally compelled disclosures may occur subject to applicable safeguards and notice requirements.
7. International transfers. Some enabled avatar, payment, messaging, email, AI, or cloud providers may process data outside your country. Before a regulated transfer, we will use required assessments, contracts, certifications, filings, consent, and security measures and provide legally required details. If a lawful transfer mechanism is unavailable, we should restrict the transfer or disable the affected function.
8. Automated processing. The Service may automate language detection, memory retrieval, content recommendations, safety checks, risk detection, responses, and avatar animation. We do not rely solely on automated processing for decisions producing legal or similarly significant effects. Where local law applies, you may request meaningful information, object, or ask for human review.
9. Retention. Account data is generally retained while the account is active. Chats and memories are retained until deletion, account closure, or service termination. Face, voice, and media source files are retained until the related friend/material is deleted, consent is withdrawn, or the purpose ends. Transaction, tax, security, and dispute records may be retained for legally required periods. We delete or anonymize data when no longer needed, subject to reasonable backup rotation and legal holds.
10. Security and incidents. We use reasonable access controls, authentication, transmission protection, tenant separation, logs, backups, vulnerability management, and vendor controls. No service is perfectly secure. If an incident is likely to affect your rights, we will mitigate it and provide legally required notice.
11. Your rights. Subject to local law, you may request access, a copy, correction, deletion, consent withdrawal, account closure, portability, restriction or objection, limits on sensitive-data use, opt-out of sale or sharing, and human review of significant automated decisions. You may complain to us or a competent regulator. Submit requests through Settings, Support, or the published email. We may verify identity and will respond within the legally required period without unlawful discrimination.
12. Children. The Service is not directed to anyone under 18. We do not knowingly collect or process a minor's account, face, voiceprint, private memories, audiovisual content, or payment data. A parent or guardian who believes a minor provided data should contact us so we can verify the request, disable the account, and delete the data or take other legally required action.
13. Cookies and local storage. We use session identifiers, cookies, or local storage for sign-in, language, security, and necessary preferences. Browser controls may clear them but can impair functionality. We do not currently sell or share data for cross-context behavioral advertising; if this changes, we will update this Policy and provide required choices.
14. Updates and contact. We may update this Policy for legal, product, provider, or processing changes. We will prominently notify you of material changes and seek renewed consent where required.
Controller: Fuxin Brain Kingdom AI Technology R&D Co., Ltd.
Email: postmaster@brainkingdom.net