xanther · Privacy Policy
Version: v1.0 Effective date: 2026-05-21 Last updated: 2026-05-21
Preamble
Hello, dear.
"xanther" (the "App", "we", "us") is an emotional-wellness product operated by Shenzhen Nanshengshijia Network Co., Ltd. The App uses the five-element emotion ring (the "Ring") to collect your physiological data, and combines it with an awareness diary and emotion trend analysis to help you recognize, sense, and manage your emotional state.
To help you use the App with peace of mind, we have written this Privacy Policy. It explains what information we collect about you, why, how we use it, with whom we share it, and the rights you have and how to exercise them.
We have tried to keep it plain-spoken, but this is a legally binding document. Please read it carefully before registering or using the App. Continuing to use the App means you have read and agreed to all of its terms. If you do not agree, please stop registering and using the App.
If you are under 14, please do not register or use the App. See the Children's Personal Information Protection Rules for details.
This Policy is drafted in accordance with the Personal Information Protection Law of the People's Republic of China (PIPL), the Data Security Law, the Cybersecurity Law, the Information Security Technology — Personal Information Security Specification (GB/T 35273), and related regulations.
Chapter 1 — Personal Information We Collect
We follow the principles of minimum necessity, clear purpose, and user consent, and only collect information necessary to provide our services. The tables below list collected items by scenario.
1.1 Registration and Sign-in
| Information | Required? | Purpose | Retention |
|---|---|---|---|
| Phone number (Chinese mainland, 11 digits) | Required (SMS sign-in) | Account identification, sign-in credential, security risk control, necessary service notices | Lifetime of account + 15-day waiting period after deletion request |
| WeChat openid | Optional (WeChat sign-in) | Unique account identification | Same as above |
| WeChat nickname / avatar | Optional (WeChat sign-in) | Personalized display | Same as above; you can change or clear it any time in Me → Edit Profile |
| WeChat unionid | Optional (WeChat sign-in) | Unique identification within our own product family | Same as above |
| Apple sub (Apple user unique identifier) | Optional (Apple sign-in) | Unique account identification | Same as above |
| SMS verification code | Required | Verify the authenticity of your phone number | Destroyed within 10 minutes after verification |
1.2 Ring Pairing and Wear
| Information | Required? | Purpose | Retention |
|---|---|---|---|
| Ring Bluetooth MAC address | Required | Uniquely identify your ring, pair, and reconnect | 30 days after unpairing |
| Ring firmware version | Required | Protocol compatibility, OTA upgrades | Same as above |
| Wear-start / wear-end timestamps | Required | Calculate wear duration and validate data | 24 months |
| Ring battery level | Required | Show charging reminders in the App | Latest value only |
1.3 Health Data
The ring collects the following physiological data at frequencies ranging from per-second to per-minute.
| Information | Required? | Purpose | Retention |
|---|---|---|---|
| Heart rate (BPM) | Required | Health dashboard, input to emotion algorithm | 24 months; deletion on request |
| Heart-rate variability (HRV, ms) | Required | Same as above | 24 months |
| RR interval (ms) | Required | Key input to the emotion algorithm (sent to the Bian-An Mind algorithm) | 24 months |
| Blood-oxygen saturation (SpO₂, %) | Optional | Health dashboard | 24 months |
| Body temperature (°C) | Optional | Health dashboard | 24 months |
| Steps | Optional | Health dashboard | 24 months |
| Sleep stages (deep / light / awake) | Optional | Health dashboard | 24 months |
| Stress index (algorithm-derived) | Optional | Health dashboard | 24 months |
Health data is "sensitive personal information" under Article 28 of the PIPL. We apply field-level AES-256 encryption and least-privilege access. Before using any relevant feature (opening the dashboard, viewing trend charts, first-time ring pairing), we will separately tell you the purpose and method of collection.
1.4 Emotional Data (Awareness Diary)
| Information | Required? | Purpose | Retention |
|---|---|---|---|
| Text you enter into the awareness diary | Optional | Emotion insights, AI personalization, statistics | Controlled by you; you can delete individual entries or all entries at any time |
| Images you upload to the awareness diary | Optional | Same as above | Same as above |
| Emotion keywords and tags | Optional | Same as above | Same as above |
| Recording timestamps | Optional | Trend analysis | Same as above |
| Your wear location (geolocation, captured only as a coarse one-time location when you actively "check in this moment") | Optional | Associate emotion with context | Same as above |
We will not continuously collect your location in the background without your knowledge.
1.5 AI Emotion Baby Dialogue
| Information | Required? | Purpose | Retention |
|---|---|---|---|
| Text dialogue between you and the "Emotion Baby" | Optional (when using the dialogue feature) | Generate AI responses, improve dialogue quality | Controlled by you; deletable any time |
| Recent dialogue context (last several turns) | Optional | Help the AI understand the dialogue context | Same as above |
The AI dialogue feature (Emotion Baby) is not yet live in this release. Once a large model is integrated: mainland China accounts' dialogue content will be processed onshore only and will not leave the country; overseas accounts will be processed by a model in their region (a cross-border transfer). In all cases, the first time you use the AI dialogue feature, we will separately disclose the data flow and ask for your consent. See Chapter 4.
1.6 Device and Log Information
| Information | Required? | Purpose | Retention |
|---|---|---|---|
| OS type and version (iOS / Android) | Required | Compatibility | 90 days |
| App version | Required | Upgrades and compatibility | 90 days |
| Device model (brand, model) | Required | Compatibility troubleshooting | 90 days |
| Network type (Wi-Fi / cellular) | Required | Sync strategy | 90 days |
| Crash and error logs (desensitized) | Required | Defect localization, stability improvements | 90 days |
| Push token (if you enable notifications) | Optional | Push notifications | Destroyed immediately after notifications are disabled |
We do not collect IMEI, IMSI, MEID, Android ID, advertising ID, or other strong identifiers.
1.7 Information We Do Not Collect
We do not collect your ID number, bank-card number, detailed home address, biometric information (fingerprint / face / voiceprint), contacts list, SMS, call logs, full photo-library scans, or the list of other apps installed on your device.
Chapter 2 — How We Use Your Information
We use the information described above only within the following scope:
2.1 Providing the Core Service
- Health monitoring (dashboard, trend charts)
- Emotion insights (emotion-frequency recognition by algorithm, weekly/monthly statistics)
- AI dialogue with the Emotion Baby (not live in this release; see 1.5 / 4.2)
- Ring pairing, connection, and firmware upgrades
2.2 Improvement and Personalization
- After de-identification and anonymization, training and optimizing the emotion-recognition algorithm, AI dialogue quality, and product features
- Personalized recommendations and reminders (based on your preferences; not based on sensitive attributes such as race, ethnicity, political views, religious beliefs, or sexual orientation)
2.3 Customer Service and Support
- When you contact us with feedback or to exercise your rights
2.4 Security and Risk Control
- Preventing fraud, credential stuffing, automated abuse, and bonus farming
- Meeting log-retention requirements imposed by law
2.5 Legal Obligations
- Cooperating with lawful requests issued by regulatory or judicial authorities
2.6 Things We Commit Not To Do
- We will not use your personal information for third-party commercial advertising (the App does not display third-party ads)
- We will not sell your information to any third party
- We will not use sensitive personal information (health / emotional data) for automated decision-making such as scoring, insurance pricing, credit assessment, or recruitment screening
Chapter 3 — Sharing, Transfer, and Public Disclosure
3.1 No Sharing by Default
We keep your personal information strictly confidential and do not share it with any third party by default.
3.2 Exception — With Your Authorization
- You actively enable a feature that requires third-party processing (for example, WeChat sign-in or AI dialogue)
- You actively export, share, or forward your own data
3.3 Exception — Required by Law
- National security, public safety, criminal investigation, public-health events, and other statutorily defined situations
3.4 Exception — Third-Party SDKs and Service Providers
To provide a complete service, we use several third-party SDKs and cloud services. They process only part of your information under the principles of minimum necessity, clear purpose, and contractual constraint. For the full list, see the Third-Party SDK and Service Inventory.
3.5 Exception — Mergers and Restructurings
In the event of a merger, acquisition, bankruptcy, asset transfer, or similar event, your personal information may be transferred together with our other assets. The successor entity will continue to perform this Policy. If there is a material change, we will re-obtain your consent in a prominent manner.
3.6 Public Disclosure
We will not disclose your personal information publicly on our own initiative. Public disclosure will occur only with your explicit consent or when required by law.
Chapter 4 — Data Storage and Cross-Border Transfer
4.1 Storage Location
For users in mainland China, personal information is stored entirely in the Tencent Cloud Shanghai region:
- Relational data: Tencent Cloud CynosDB MySQL Serverless (Shanghai)
- Time-series and full-text indexes: Tencent Cloud Elasticsearch Serverless (Shanghai)
- Object storage (avatars, diary images): Tencent Cloud COS (Shanghai)
4.2 Cross-Border Transfer
- Mainland China accounts — data does not leave the country. Your health data, awareness diary, and account information are stored entirely in the Tencent Cloud Shanghai region and are not provided to any party outside mainland China.
- AI dialogue is not yet live in this release, and no dialogue data is currently sent to any large-model provider (onshore or offshore). When it is launched, the routing principle is:
- Mainland China accounts — processed by an onshore large model; data does not leave the country;
- Overseas accounts — processed by a large model in their region, which constitutes a cross-border transfer; before first use we will separately disclose the overseas recipient, purpose, and data types and obtain your separate consent, in accordance with Articles 38–39 of the PIPL.
4.3 Third-Party Large-Model Processors
No large-model processor is integrated in this release. Before integration, we will list the specific provider, purpose, data flow, and cross-border status here and in the Third-Party SDK & Service Inventory, and will sign a Data Processing Agreement (DPA) requiring protection no less stringent than this Policy, under which dialogue content will not be used to train any large model.
4.4 Safeguards
- Transport: TLS 1.2+ end-to-end
- Storage: AES-256 field-level encryption for sensitive fields
- Access: Role-based access control (RBAC) with least privilege
- Audit: All database reads and writes are audit-logged
Chapter 5 — Your Rights
Under Chapter 4 of the PIPL, you have the rights below regarding your personal information. We provide in-app entry points for each, and you may also assert these rights by emailing sznssj2021@163.com.
5.1 Access and Copy
- Me → Edit Profile: view your profile information
- Me → Awareness Stats / Home: view your health and emotion data
- Me → Data Export: download a complete copy of your data in JSON / CSV format (see Data Export Format)
5.2 Correction
- Me → Edit Profile: change your avatar, nickname, gender, date of birth, etc., at any time
5.3 Deletion
- A single diary entry or single AI dialogue turn: long-press the entry or tap delete
- All diary entries or all AI dialogue: Me → Settings → Data Management (bulk delete)
- Health data: Me → Settings → Data Management → Clear Health Data
5.4 Withdrawal of Consent
- The consents you granted during sign-in can be withdrawn one-by-one in Me → Settings → Privacy Authorization Management
- Withdrawing a specific authorization may affect the availability of the corresponding feature but will not affect other features or the processing already performed
5.5 Account Deletion
- Entry point: Me → Delete Account
- Process: Initiate deletion → 15-day waiting period (within which you may restore the account from Me) → after the period, we will permanently delete all of your personal information, including backups (except for logs we are required by law to retain, such as the 6-month network logs required by the Cybersecurity Law)
- After deletion, the same phone number / WeChat / Apple ID can register again, but no historical data will be restored
5.6 Data Portability
- Use Me → Data Export to obtain a machine-readable JSON / CSV copy of your data for migration to another service
5.7 Complaints and Appeals
- Internal: email sznssj2021@163.com — response within 24 hours, resolution within 15 days
- External: complaints or lawsuits may be filed with the Cyberspace Administration, MIIT, Ministry of Public Security, consumer protection authorities, or a people's court with jurisdiction
5.8 Opt-Out of Solely Automated Decisions
You have the right to refuse decisions that significantly affect you and are made solely based on automated decision-making. The App currently has no such decisions (the emotion algorithm's output is for reference only and does not determine any rights or interests of yours).
Chapter 6 — How We Protect Your Information
We invest reasonable resources to continually protect your information:
- Encryption in transit: TLS 1.2+ end-to-end
- Encryption at rest: Field-level AES-256 encryption for sensitive fields; full-disk encryption for the database
- Log redaction: Phone numbers, ID numbers (if any), and tokens are recorded in logs in masked form
- Access management: Role-based access control with least privilege; all access is auditable
- Network isolation: Internal VPC and security groups; databases are not exposed to the public internet
- Regular testing: Internal security self-checks every quarter; third-party penetration testing every year
- Personnel management: All staff with access to personal information sign an NDA; access is revoked upon departure
- Vulnerability disclosure: security@xanther.cn — we welcome responsible disclosure from white-hat researchers
In the event of a personal information security incident, we will notify you and the regulator in a timely manner pursuant to Article 57 of the PIPL, describing the type of incident, possible impact, measures taken, and recommended remediation.
Chapter 7 — Protection of Minors
- We do not provide the App's services to children under 14. Date of birth is verified at registration; users under 14 cannot complete registration
- If a guardian discovers a mistaken child registration, please contact sznssj2021@163.com promptly; we will delete the account within 7 business days after identity verification
- Minors aged 14 and over but under 18 must obtain guardian consent before using the App
- See Children's Personal Information Protection Rules
Chapter 8 — Cookies and Similar Technologies
- The App is a native application and does not use cookies
- We use a local session token to keep you signed in; it becomes invalid after the App is closed or uninstalled
- We use anonymized behavior tracking (e.g., click counts, dwell time) to understand feature usage. Such tracking does not include your personal identity information
Chapter 9 — Policy Changes
- We may revise this Policy in response to legal or product changes
- Material changes (broader collection scope, new processing purposes, additional sharing recipients, changes in cross-border transfer, etc.) will be prominently displayed in the App and re-consented
- Non-material changes (wording revisions, contact updates, etc.) will result in an update of the "Last updated" date on this page; continued use after the effective date constitutes acceptance
Chapter 10 — Contact Us
- Operating entity: Shenzhen Nanshengshijia Network Co., Ltd.
- Shenzhen office address: 22/F, Financial Technology Tower, No. 11 Keyuan Road, Science and Technology Park Community, Yuehai Subdistrict, Nanshan District, Shenzhen, China
- Phone: +86 13524723215
- ICP filing number: 粤ICP备2025440292号 (entity) / 粤ICP备2025440292号-3 (xanther.cn)
- Data Protection Officer (DPO): sznssj2021@163.com
- Customer-service and privacy enquiries: sznssj2021@163.com
- Security vulnerability disclosure: sznssj2021@163.com
We commit to responding to your request within 15 business days. If you are not satisfied with the response, you may sue in a people's court with jurisdiction; the court of jurisdiction is the People's Court of Nanshan District, Shenzhen.
Appendix A — Third-Party SDK List
See the Third-Party SDK and Service Inventory.
Appendix B — Personal Information Collection Checklist
See the Personal Information Collection Checklist.
Appendix C — Related Documents
- Terms of Service
- Children's Personal Information Protection Rules
- Apple Privacy Nutrition Label / Google Play Data Safety mapping
- Data Export Format
Change Log
| Version | Date | Change |
|---|---|---|
| v1.0 | 2026-05-21 | Initial release |