# DialPop Privacy Policy
**Effective date:** [Please fill in]
**Last updated:** [Please fill in]
DialPop (the “App”) is operated by [full legal name of the operator] (“we,” “us,” or “our”). We respect and protect your personal information. This Privacy Policy explains how we collect, use, store, share, and protect information that you provide or that is generated when you use the DialPop mobile app and its related services.
Please read this Privacy Policy carefully before using the App. For processing activities involving sensitive personal information, providing personal information outside mainland China, or any other activity requiring separate consent by law, we will provide additional notice and obtain the required consent. If you do not agree to this Privacy Policy, you may be unable to use features that require the relevant information, such as AI creation, but you may still use basic features that do not depend on that information.
## 1. Our Services
The App primarily provides the following features:
1. Entering a text-based creative brief and using AI to generate Wear OS watch-face layouts, color schemes, and static artwork;
2. Browsing and caching watch faces from the marketplace;
3. Transferring watch-face installation packages from the phone to a connected Wear OS watch; and
4. Saving, viewing, and deleting creations and favorites locally on the phone.
The current version does not provide a user photo-upload feature and does not process personal information for advertising, personalized advertising, or user profiling.
## 2. Information We Process and How We Use It
### 2.1 AI creation content
When you use the AI creation feature, we process the text prompt you actively enter, as well as the resulting layout plans, watch-face artwork, quality-review results, and creation records. We use this information to fulfill your creation request, generate candidate watch faces, perform quality checks, and display or save results locally when you choose to save them.
The App uses Firebase AI Logic to call Google Vertex AI generative AI services. To complete generation and quality review, your prompt, necessary creative context, and generated or reviewed watch-face images may be sent to Google and its relevant services for processing. The retention, logging, and security practices of those AI services are also governed by their applicable terms and privacy policies. Please do not include identity-card numbers, bank-card numbers, passwords, precise home addresses, medical information, information about minors, or other sensitive information unrelated to the creative task in your prompts.
### 2.2 Anonymous account and technical information
When you first use AI creation, the App may create an anonymous account through Firebase Authentication. This account is used to identify and protect AI requests, prevent abuse, and maintain the service. It does not require you to provide your name, phone number, email address, or social-media account.
Firebase, Google Play services, or network service providers may process an anonymous account identifier, app-instance identifier, device model or operating-system version, App version, IP address, request time, error information, and related logs for authentication, App Check integrity verification, network communication, and security protection. We do not use this technical information for marketing unrelated to the App.
### 2.3 Wear OS connection and installation
To discover connected Wear OS devices, determine whether the watch-side App is online, and transfer watch-face installation packages, the App may process a watch node ID, device display name, proximity status, connection status, watch-side capability information, installation progress, and installation results locally and between the phone and the watch.
This information is primarily transferred between the phone and the watch through the Google Play services Wear OS Data Layer. We do not actively upload it to our own servers. We do not use this feature to read contacts, text messages, call records, health data, or other information from the watch that is unrelated to watch-face installation.
### 2.4 Marketplace content and network requests
When you browse the marketplace or download a watch face, the App requests catalog data, preview images, watch-face installation packages, and verification information from our content-distribution endpoints. These requests may generate IP addresses, User-Agent information, request times, request URLs, response statuses, and traffic logs. Such information may be processed by CDN providers, cloud-service providers, or network operators under their own rules for content delivery, caching, troubleshooting, and security protection.
### 2.5 Information stored locally
When you save a creation or favorite a marketplace watch face, the App stores the creative prompt, name, description, creation time, visual parameters, quality score, preview image, generated artwork, and necessary installation-package cache in the Android app-specific storage area. You can delete creations or remove favorites in the App, or clear the App’s data through Android system settings.
The current version excludes the user-creation directory from Android cloud backup and device transfer. Android, Google Play services, or other device services may nevertheless process necessary system diagnostics according to their own settings and policies.
## 3. Permissions We Request and Use
The current version declares only network-access permission, which is used for AI requests, marketplace content loading, and necessary service communication. The current version does not actively request or use camera, microphone, contacts, SMS, telephone, precise-location, calendar, or storage read/write permissions.
If a future version adds a feature requiring additional permissions, we will explain the purpose of each permission before enabling the feature and obtain authorization as required by law. You can manage or withdraw permissions through Android system settings. Withdrawing a permission may make the corresponding feature unavailable but will not affect other features that do not depend on that permission.
## 4. Third-Party Services and Sharing
We do not sell your personal information and do not use it for advertising marketing unrelated to the App. To provide the services described in this Privacy Policy, we may engage or use the following third-party services:
| Third-party service | Purpose | Information potentially involved |
| --- | --- | --- |
| Firebase Authentication | Anonymous account creation, identity protection, and abuse prevention | Anonymous account identifier, app-instance information, and security logs |
| Firebase AI Logic and Google Vertex AI | Layout generation, image generation, and quality review | Prompts, creative context, generated or reviewed images, and request technical information |
| Google Play services / Wear OS Data Layer | Watch discovery, connection checks, and installation-package transfer | Node ID, device name, connection status, and installation status |
| CDN/cloud-storage providers, currently including Amazon CloudFront | Delivery of marketplace catalogs, previews, and watch-face installation packages | IP address, request and network logs, and downloaded content |
Third-party services may process relevant information outside mainland China. The current version is configured to use the `global` Vertex AI service location, so AI requests may be processed by infrastructure outside mainland China. Where separate consent, cross-border-transfer notice, or other compliance measures are required by law, we will provide the relevant notice and complete the required process before the applicable feature is used. Third-party processing is also subject to the privacy policies and terms of those providers. We recommend that you review the public notices of Google, Amazon, and the relevant service providers.
Unless permitted or required by law, we will not provide your personal information to unrelated third parties. If we undergo a merger, separation, acquisition, or asset transfer involving personal information, we will notify you as required by law and take appropriate protective measures.
## 5. Retention Period
1. Local creations, favorites, and caches are generally retained until you delete them, clear the App’s data, or uninstall the App. Temporary files may be deleted when a task ends, a cache is evicted, or the system performs cleanup.
2. In principle, we do not retain your AI creation records on our own servers for an extended period. Logs, abuse-monitoring records, caches, and retention periods maintained by third-party AI services are governed by the actual configurations and rules of Firebase, Google Cloud, and other services used.
3. The anonymous Firebase account and related service-side records will be deleted or anonymized after you submit a deletion request, the service relationship ends, or the applicable retention period expires, subject to applicable law and third-party service rules. Information in backups may remain during the applicable backup cycle.
## 6. Information Security
We take security measures appropriate to the processing activities, including using HTTPS/TLS to protect data in transit, Firebase App Check and anonymous-account mechanisms to protect requests, restricting access to app files, verifying the integrity and signatures of downloaded watch-face packages, and applying data-minimization principles.
Although we work to protect your information, no network transmission or electronic storage method can be guaranteed to be completely secure. If a personal-information security incident occurs, we will take remedial measures and notify you as required by law.
## 7. Your Rights
Subject to applicable law, you may request to:
1. Access or copy personal information relating to you that we process;
2. Correct or supplement inaccurate or incomplete information;
3. Delete personal information or ask us to stop processing it;
4. Withdraw consent or refuse processing that is not necessary; and
5. Cancel the anonymous account, obtain an explanation of the processing rules, or exercise other rights available under applicable law.
Because the App currently uses an anonymous account and primarily stores creation records locally, you can first use the in-App deletion feature or clear the App’s local data through Android system settings. For other requests, email [privacy contact email] with the subject “Personal Information Rights Request.” After verifying the requester’s relationship to the relevant information, we will process and respond within the period required by law. If you are dissatisfied with our response, you may contact the competent regulatory authority in [operator’s jurisdiction] or pursue other remedies available under applicable law.
## 8. Protection of Minors