xanther · Third-Party SDK and Service Inventory
Version: v1.0 Effective date: 2026-05-21
This inventory is drafted in accordance with the MIIT Notice on Carrying Out the Special Action for App Personal-Information Protection Governance and the Information Security Technology — Mobile Internet Application (App) SDK Security Guide (GB/T 41391). It discloses all third-party SDKs and cloud services integrated by the App, the types of personal information they collect, their purposes, and whether they are based offshore.
Read together with the Privacy Policy and the Personal Information Collection Checklist.
I. Device and Hardware
| SDK / Service | Provider | Purpose | Personal information collected | Integration | Privacy policy | Offshore? |
|---|---|---|---|---|---|---|
| Hua Xinzhi BLE SDK (CSSBLE) | Shenzhen Hua Xinzhi Technology | Ring Bluetooth connection; collection of physiological data such as heart rate, HRV, RR interval | Ring MAC, firmware version, battery level, raw physiological data stream (locally processed) | iOS / Android native SDK | Provided by ring manufacturer [placeholder] | No (China) |
| Bian-An Mind emotion-algorithm service | Shenzhen Bian-An Mind Technology | Output of emotional frequency and stress index based on RR intervals | Raw RR intervals, timestamps (no personally identifiable information) | Through our backend via Kafka | https://example.bianan.com/privacy [placeholder] | No (China) |
II. Account and Sign-in
| SDK / Service | Provider | Purpose | Personal information collected | Integration | Privacy policy | Offshore? |
|---|---|---|---|---|---|---|
| Tencent Cloud SMS | Tencent Cloud Computing (Beijing) Co., Ltd. | Send sign-in verification codes and security notices | Phone number | Server-side API, SDKAppID 1401119920 |
https://privacy.qq.com | No (China) |
| WeChat Open Platform | Shenzhen Tencent Computer System Co., Ltd. | WeChat one-tap sign-in, authorized access to nickname and avatar | openid, unionid, nickname, avatar | iOS / Android native SDK | https://privacy.qq.com | No (China) |
| Sign in with Apple | Apple Inc. | Apple ID sign-in on iOS | Apple sub, (with user consent) email | iOS system capability | https://www.apple.com/legal/privacy/ | Yes (United States) |
III. Cloud Storage and Infrastructure
| SDK / Service | Provider | Purpose | Personal information collected | Integration | Privacy policy | Offshore? |
|---|---|---|---|---|---|---|
| Tencent Cloud Object Storage (COS) | Tencent Cloud Computing (Beijing) Co., Ltd. | Store user avatars and images uploaded to the awareness diary | Avatars, diary images | Server-side API + client-side pre-signed direct upload | https://privacy.qq.com | No (Tencent Cloud, Shanghai region) |
| Tencent Cloud CynosDB MySQL Serverless | Tencent Cloud | Relational data storage | Account information, ring bindings, awareness diary, settings | Server-side calls | Same as above | No (Shanghai region) |
| Tencent Cloud Elasticsearch Serverless | Tencent Cloud | Time-series and full-text indexing (health data, diary search) | Health metrics, diary keywords | Server-side calls | Same as above | No (Shanghai region) |
| Tencent Location Service (LBS) | Tencent Location Service | Captures a coarse one-time location only when you actively "check in this moment" | Latitude/longitude, geographic description | iOS / Android native SDK | https://lbs.qq.com/privacy.html | No (China) |
IV. AI and Algorithms
Not integrated in this release. The AI Emotion Baby dialogue feature is not yet live, and no third-party large-model service is integrated; no dialogue data is sent to any model provider.
Before integration, we will list the specific provider, data flow, and cross-border status here, separately notify you in-app and obtain consent, and sign a Data Processing Agreement (DPA) prohibiting use of dialogue content for model training.
Routing principle once live: mainland China accounts are processed by an onshore model (data does not leave the country); overseas accounts are processed by a model in their region (a cross-border transfer, enabled only after separate notice and consent).
V. Client-Side Frameworks and Tools (collect no personal information)
| SDK / Service | Provider | Purpose | Personal information collected |
|---|---|---|---|
| Expo SDK | Expo / 521 Labs Inc. | React Native application framework and native modules | None |
| React Native | Meta Platforms, Inc. | Cross-platform UI framework | None |
| Expo Application Services (EAS, build-time only) | Expo | Client build and signing, not included in the release package | None |
| Lucide React Native | Lucide Contributors | UI icon library, purely static resources | None |
| antd-mobile | Ant Group | UI component library | None |
The above client-side frameworks and tools run only at build time or purely locally, and do not upload any user information to any server.
VI. Statement of Capabilities Not Enabled
For transparency, we hereby state that the App does not integrate the following types of SDKs:
- Third-party advertising SDKs (no advertising SDK at all)
- Third-party push SDKs (we currently do not push proactively; if we integrate one in the future, this inventory will be updated and you will be notified)
- Third-party analytics or user-profiling SDKs (none)
- Third-party sharing SDKs (no off-app sharing currently; this inventory will be updated if added in the future)
- Third-party map SDKs (Tencent Location Service is used only for location acquisition; no map is displayed)
VII. SDK Security Management Commitments
For all third-party SDKs, we commit to:
- Pre-integration evaluation: Evaluate the SDK's compliance, security, and necessity
- Contract: Sign a Data Processing Agreement (DPA) with every SDK provider, requiring compliant processing
- Least privilege: Grant the SDK only the permissions necessary to perform its function
- Continuous monitoring: Track SDK security advisories and vulnerabilities via SBOM and version management
- Auditable: The SDK inventory and changes are maintained in the repository under
docs/legal/, version-controlled, and traceable
VIII. SDK Change Notifications
- New additions, removals, or material version upgrades will be reflected in this inventory before the next App release
- Where the change broadens the collection scope or alters data flows, we will re-obtain your consent in the App
Contact Us
- Personal information protection: sznssj2021@163.com
- Customer service: sznssj2021@163.com
- Security: security@xanther.cn
Change Log
| Version | Date | Change |
|---|---|---|
| v1.0 | 2026-05-21 | Initial release |