Privacy Policy

Privacy Policy

【V0.8】

Updated: August 24, 2026

Effective: August 31, 2026

Yunwang Innovation Intelligence (Shenzhen) Co., Ltd. and its affiliates (hereinafter referred to as “we”, “us”, “our”, or “Yunwang”) fully understand the importance of your personal information and will endeavor to protect the security and reliability of your personal information. We are committed to maintaining your trust in us, adhering to the principles of consistency of rights and responsibilities, legitimacy, lawfulness, transparency, minimum necessity, ensuring security, subject participation, and openness and transparency, and taking corresponding protective measures in accordance with industry-accepted security standards.

If you use the terminal applications provided by Yunwang (including but not limited to the “Yunwang Innovation APP” and the “Yunwang Innovation” WeChat Mini Program, hereinafter individually referred to as the “APP” or the “WeChat Mini Program”, and collectively as the “Applications”) and the related services of the accompanying smart automatic foam roller hardware, or if you engage in any non-public interaction with Yunwang (for example, using the “Online Customer Service”) (collectively, the “Products and Services”), please refer to this Privacy Policy (the “Policy”) to understand how we collect, use, and share your personal information and what rights you have. Where a specific product or service we provide has a separate privacy policy or special provisions in the corresponding user service agreement, that product’s privacy policy shall prevail; for matters not covered by such product privacy policy and user service agreement, this Policy shall apply.

Please carefully read and understand this Policy before using our Products or Services, especially the clauses marked in bold, which you should read with particular attention, and begin use only after confirming that you fully understand and agree. Unless otherwise stated, disagreement with this Policy or its updates may affect your normal use or continued normal use of our Products/Services.

The device’s basic massage functions support offline use without login or network connection. In this mode, no usage records will be uploaded or stored in the cloud, and local data will not be automatically supplemented and uploaded upon subsequent network connection. You may enable “Local Mode” in the App settings, under which all data is stored only locally on your device.

If you have any questions, comments, or suggestions regarding this Policy, you may contact us through the contact methods provided in this Policy.You understand and agree that once you click to accept this Policy during the Yunwang account registration process and complete Yunwang account registration, or once you actually use any of our Products or Services, you are deemed to agree that we may collect, use, store, and share your related information in accordance with this Policy.

I. How We Collect and Use Your Personal Information

(1) Personal Information Collected and Used for Basic Business Functions

The basic business functions of the Products and Services we provide to you include: (i) logging in to and using the Yunwang Innovation APP; (ii) non-public interactions between you and us for communication and handling of questions and inquiries you may raise; (iii) connecting to and controlling smart hardware devices via Bluetooth. In the following scenarios, for the purpose of basic business functions, you need to provide the following categories of personal information; otherwise, you may be unable to enjoy the corresponding Products and Services.

1. Account registration, login, and verification. When you register a Yunwang account, you need to provide at least your mobile phone number or email address. If you agree to use a user account from a third-party application (WeChat account, Apple ID, Google account, or Facebook account) as your Yunwang account for login, we will also collect related information from such third-party applications, including ID, avatar, and nickname. When you log in to the Yunwang Innovation Mini Program through the WeChat application, you need to authorize us to obtain your avatar and nickname. The foregoing information will be used to verify your identity, match and aggregate a series of operational activities you perform using your Yunwang account, send you notices regarding material changes and updates to service functions, communicate with you, or handle inquiries and issues you raise. We will assign a specific Yunwang ID to your Yunwang account; such ID consists of a random string and cannot alone be used to inquire into your real identity. When you perform account login, password reset, or change of bound mobile phone number operations, we will use the mobile clipboard function to read specific Yunwang-related information (mobile verification codes) to provide you with a more convenient operational experience.

2. Hardware connection and device information. When you connect to a smart device via Bluetooth, we will collect device model, device serial number, firmware version, Bluetooth pairing records, hardware unique identifiers, device operating status, fault codes, and other information. Such information is used solely for device identification, connection control, firmware updates, and troubleshooting, and will not be used to track your location. The device serial number is used only to bind your account and provide after-sales services, and will not be associated with your identity information for other purposes.

3. Use of Applications. When you use the Applications, to ensure the quality of the services we provide and the security of your information, we may record the categories and methods of services you use, operational information during service use, and log information related to the services, such as your mobile device ID, device unique identifiers (IMEI/Android ID/IDFA/OpenUDID), IP address, system version, App version, and crash logs.

4. Diagnostic data and crash logs. To improve product stability and fix faults, we will collect anonymized application crash logs, device performance data, and error reports. Such data is collected anonymously by default, is not associated with your account identity, and is used only for statistical analysis and product improvement.

5. Purchase and delivery of Products and Services. When you purchase or receive goods or services through the APP or WeChat Mini Program, you need to provide us with the recipient’s name (or nickname), the recipient’s mobile phone number, and the delivery address. When you make a payment, we collect your payment order number and payment amount. When you need an invoice, you need to provide us with the invoice recipient’s name or company information and the email address for receiving electronic invoices. When you need after-sales service, you need to provide us with your transaction information, including product name, price, quantity, order number, logistics tracking number, device serial number, and fault description. At the same time, we will also collect information you provide when contacting customer service.

6. Health and body-related sensitive personal information. After your explicit authorization, exercise type, exercise duration, pain/fatigue body parts, feedback on limited physical activity, massage intensity preferences, exercise recovery plans, free-text descriptions that you voluntarily enter when enabling Yunwang AI, as well as body posture and range of motion reflected in uploaded photos and videos, and descriptions of bodily sensations in voice recordings, constitute special-category sensitive personal information relating to health. We process the foregoing information to identify and understand your exercise and physical condition, pain or fatigue feedback, movement and activity status, and recovery needs, to provide you with personalized exercise recovery suggestions related to Yunwang AI features, suggestions on massage areas and intensity, suggestions for adjusting training or recovery plans, movement prompts, and safety reminders, and to answer related questions you raise. Photos and videos are used only to analyze body posture, movements, and range of motion; voice is used only to identify and understand the bodily sensations and service needs you express. We do not perform facial or voiceprint biometric recognition based on the foregoing materials, nor do we generate biometric templates; materials are stored privately by default, and uploading of third-party individuals, medical records, or identity document privacy materials is prohibited.

7. User-uploaded audio and video materials. Camera, album, and microphone permissions are invoked only when the user manually takes photos, selects images, or records audio; original audio and video materials are automatically deleted within 24 hours after a massage plan is generated; they are retained in the cloud only if the user manually checks “Save to History”, and the user may delete individual items at any time. Structured body parts, movement preferences, and generated massage plans automatically extracted by the system are retained long-term in accordance with account history rules.

8. Offline mode data. The device’s basic massage functions support offline use without login or network connection. In this mode, no usage records will be uploaded or stored in the cloud, and local data will not be automatically supplemented and uploaded upon subsequent network connection. Offline non-login mode does not collect or store usage behavior or preference data. Usage records stored locally on the device are retained only on the device, and you may clear them at any time by restoring factory settings.

9. You acknowledge and agree that, with respect to the contact methods you provide during use of the Products and/or Services (for example, contact phone number), we may, in the course of operations, send various types of notices (by SMS or phone call) to one or more of them for purposes of user message notification, identity verification, security verification, user experience surveys, dispute resolution, and the like; in addition, we may also use the mobile phone numbers collected in the foregoing process to send you, by SMS or phone call, commercial information regarding services, features, or activities that may interest you. However, please rest assured that if you do not wish to receive such information, you may unsubscribe through the unsubscribe method provided in the SMS (please refer to the method provided in the SMS), or contact our customer service directly to unsubscribe.

(2) Personal Information Collected and Used for Extended Business Functions

To improve existing products or support our development of new products, and to provide you with higher-quality products and services, we will collect and use the following personal information. If you refuse to use the following functions or refuse to provide us with the following personal information, it will not affect the foregoing basic business functions.

1. User research activities. We may display or invite you to participate in certain research activities in the APP or WeChat Mini Program. When you choose to participate in such activities, depending on the specific settings of the activity, we may collect questionnaire information you fill in and your contact information.

2. Internal data analysis and research for product and service performance improvement and upgrades. We use the browsing and operation records we collect of your use of the WeChat Mini Program, your APP operation logs (including data related to APP and device network pairing), and problem feedback you provide to us through customer support services, to conduct internal data analysis and research.

3. Algorithm model training. Data required for a single Yunwang AI plan generation is necessary processing for the service; using data for model training and algorithm optimization is an independent optional processing item. The feature switch is disabled by default at the factory and requires the user to manually enable authorization, which may be withdrawn at any time in privacy settings; withdrawing authorization does not affect Yunwang AI basic plan recommendations. Training data sources prioritize anonymization, aggregation, and de-identification processing, with strict limitations on internal personnel access privileges.

4. Display and push of marketing messages. We may provide or promote marketing information about products and services of us and our affiliates on Application pages and pop-up advertisements (which you may close with one click). Such marketing methods do not affect your normal use of the original functions of Yunwang Products or Services. You may turn off personalized recommendations in App settings; after turning them off, we will not push targeted advertisements based on your usage preferences, but may still display non-personalized general announcements.

5. Anti-fraud and security risk control. To prevent security risks such as phishing websites, fraud, and account theft, we may collect your network usage habits, commonly used software information, risky URL access records, and abnormal login information to assess account risk levels. Such information is used solely for security protection purposes and will not be used for other commercial purposes.

6. Posting your reviews. When you post comments in the Applications, you need to provide us with your Yunwang account, avatar, and nickname.

7. Additional services based on system permissions. When you use the APP or WeChat Mini Program, to provide you with the services you choose to use, or to ensure service quality and experience, you may need to authorize enabling of operating system permissions. For the application and use of requested app permissions, please see Annex I. To ensure that the application can normally receive device status push notifications while in the background, the application may use auto-start/associated-start capabilities; such behavior is used only for push notifications and will not be used for other purposes.

If we use information for purposes not stated in this Policy, or use information collected for a specific purpose for other purposes, or if we proactively obtain your personal information from third parties, we will obtain your consent in advance.

You fully understand and agree that we may collect and use your personal information without your authorized consent in the following circumstances: (1) where necessary for entering into or performing a contract to which you are a party; (2) where necessary for performing statutory duties or statutory obligations; (3) where necessary to respond to a public health emergency, or in an emergency to protect the life, health, and property safety of a natural person; (4) where necessary to maintain the secure and stable operation of the Products and/or Services provided, such as discovering and handling faults of the Products and/or Services; (5) to prevent, detect, and investigate fraud, threats to security, or illegal acts to protect the legitimate rights and interests of you, other users, or us; (6) other circumstances provided by laws and administrative regulations.

Please note that, in accordance with applicable law, if we apply technical measures and other necessary measures to process personal information such that the data recipient cannot re-identify a specific individual and cannot restore the data, or if we may conduct de-identified research, statistical analysis, and prediction on collected information to improve our content and layout, provide product or service support for business decisions, and improve our Products and Services (including using anonymous data for machine learning or model algorithm training), then the use of such processed data does not require separate notice to you or obtaining your consent. De-identified or aggregated information does not constitute personal information, and we may use it for research, analysis, and product improvement without additional notice to you.

(3) Personal Information Collected by Third-Party SDKs

To ensure the realization of Application-related functions and the secure and stable operation of the Applications, we integrate software development kits (SDKs) provided by third parties for such purposes. While such SDKs work with us to provide you with more comprehensive services, they may collect and use your application list information, sensors, and device serial numbers in accordance with their privacy policies; for details, please see Annex II.

II. How We Share, Transfer, and Disclose Personal Information

1. Sharing. We will not share your personal information with any enterprise, organization, or individual other than Yunwang and its affiliates, except in the following circumstances: (1) Affiliates and service providers. We will share your personal information with third-party service providers and any subcontractors as needed to provide you with our Products and Services. For circumstances in which we share your personal information with third-party service providers, please see Annex III. (2) Third-party links and websites. Our Applications may contain links to third-party websites. (3) Sharing with your explicit consent.

We undertake not to sell any user personal information, not to share health and body data with advertising service providers, and not to push personalized commercial advertisements. For companies, organizations, and individuals with whom we share personal information, we will enter into strict confidentiality agreements requiring them to process personal information in accordance with our instructions, this Policy, and any other relevant confidentiality and security measures.

2. Transfer. We will not transfer your personal information to any enterprise, organization, or individual, except in the following circumstances: (1) Transfer with your explicit consent. (2) Transfer arising from a change of control. Due to sale, acquisition, merger, reorganization, or other change of control, personal information may be transferred to a third party. In such circumstances, we will require the new company or organization holding your personal information to continue to be bound by this Policy; otherwise, we will require such company, organization, or individual to seek your authorized consent again.

3. Disclosure. We will disclose your personal information only in the following circumstances: (1) Disclosure with your explicit consent. (2) Disclosure required by law. We may disclose your personal information in response to lawful requests from government authorities. Subject to applicable laws and regulations, when we receive a disclosure request, we will require corresponding legal documents, such as a subpoena or investigation letter. We carefully review all requests to ensure they have a lawful basis.

4. Exceptions to prior authorized consent for sharing, transferring, or publicly disclosing personal information: (1) where necessary for entering into or performing a contract; (2) where necessary for performing statutory duties or statutory obligations; (3) where necessary to respond to a public health emergency, or in an emergency to protect the life, health, and property safety of a natural person; (4) other circumstances provided by laws and administrative regulations.

III. How We Use Cookies and Similar Technologies

1. Cookies. To enable our Products and Services to function properly, we sometimes place small data files called Cookies on your computer, mobile device, or other devices; the APP embeds H5 pages. Cookies enable websites to remember your actions and preferences over a period of time (such as login status). We will not use Cookies for any purpose other than those described in this Policy. You may modify the degree of Cookie acceptance or refuse Cookies through your browser settings.

2. Cookie-like technologies. In addition to Cookies, we may also use website beacons, pixel tags, and similar technologies on H5 pages to understand your Product or Service preferences and improve customer service. For example, emails we send you may contain click URLs linking to content on our website, and we may track such clicks to help understand customer preferences.

IV. How We Use SDKs

To provide and optimize our services, our Applications may embed third-party SDKs. While these third-party SDKs work with us to provide you with more comprehensive services, they may collect and use your personal information in accordance with their privacy policies. We will take necessary measures to control such third-party SDKs’ collection and use of your personal information, and ensure through contracts and other means that your personal information is protected to a degree no less than that stipulated in this Policy. For the identity of third-party SDKs and the purposes of collection, please see Annex II of this Policy.

V. Your Rights

1. Access, correct, and supplement your information. You have the right to access, correct, or supplement your information. You may log in to the APP, go to “Me” to access, correct, or supplement personal profile and other information, or seek assistance through “Service Center” – “Online Customer Service”.

The App includes a built-in “Privacy and Data Management” functional module, through which you may self-service view and correct basic account profile information, delete individual health inputs, massage history, and AI plans, export all personal data, turn off/withdraw optional authorizations such as model training, unbind third-party logins, turn off system permissions, and apply for human review of automated AI processing. We will not rely solely on Yunwang AI health data to make automated decisions that have a significant legal impact on users, and will not use health data for price discrimination, credit assessment, insurance risk control, or targeted commercial advertising.

2. Delete your personal information. In the following circumstances, you may request that we delete personal information: (1) if our collection and use of personal information violates laws and regulations; (2) if our processing of personal information violates our agreement with you; (3) if you no longer use our Products or Services, or you have cancelled your account; (4) if we no longer provide Products or Services to you; (5) if you withdraw consent after having agreed to our collection and use of your personal information. If we decide to respond to your deletion request, we will also notify entities that obtained your personal information from us to delete it promptly, unless otherwise provided by laws and regulations.

Please understand that after you or we assist you in deleting relevant information, due to applicable laws and security technologies, we may be unable to immediately delete the corresponding information from backup systems. We will securely store your personal information and isolate it from any further processing until the backup can be cleared or anonymization is achieved.

3. Personal information subject account cancellation. You may cancel your Yunwang account by logging in to the APP and going to “Me” – “Settings” – “Cancel Account”. For detailed cancellation rules, please refer to Article 3 of the User Service Agreement.

4. Copy/export your information: You may request a copy of your personal information based on the information in “Contact Information” below, and we will provide a copy of your personal information within 15 business days.

5. Change the scope of your authorized consent. Each business function requires some basic personal information to be completed. For the collection and use of additionally collected personal information, you may withdraw your consent or authorization decision at any time. After you withdraw consent, we will no longer process the corresponding personal information, but your decision to withdraw consent or authorization will not affect the validity of personal information processing activities we previously conducted based on your consent.

6. Constrain automated decision-making. In features such as Yunwang AI, we may use algorithms and other non-human automated decision-making mechanisms to generate suggestions. If such decisions significantly affect your legitimate rights and interests, you have the right to require us to provide an explanation, and also the right to refuse decisions made solely through automated decision-making.

7. Device local data management. You may perform a factory reset on the smart device at any time to clear all usage records, pairing information, and personal preferences stored locally on the device. This operation is irreversible; please proceed with caution.

8. Request that we explain this Policy. You have the right to request that we explain this Policy to you at any time.

9. Withdraw Privacy Policy authorization: You may do so through the [Delete Account] operation. After you withdraw Privacy Policy authorization, we will no longer process your personal information and will be unable to continue providing you with terminal Application services. At the same time, we will delete all of your personal information; unless you re-register a Yunwang account, you will be unable to continue using the product functions provided by Yunwang. Please proceed with caution. Depending on the scope of your withdrawal of consent, it may result in your inability to continue enjoying Yunwang’s Products or Services. However, your decision to withdraw consent or authorization will not affect the validity of personal information processing activities we previously conducted based on your consent.

10. Responding to your above requests. To ensure security, you may need to provide a written request or otherwise prove your identity. We may first require you to verify your identity before processing your request. We will respond within 15 business days. If you are dissatisfied, you may also complain to service@rheofit.com or to a regulatory authority. For your reasonable requests, we generally do not charge fees, but for multiple repetitive requests or requests exceeding a reasonable limit, we will charge a certain cost fee as appropriate.

In the following circumstances, in accordance with laws and regulations, we will be unable to respond to your request: (1) directly related to national security or defense security; (2) directly related to public security, public health, or major public interests; (3) directly related to criminal investigation, prosecution, trial, and enforcement of judgments; (4) where there is sufficient evidence that you have subjective malice or are abusing rights; (5) where responding to your request would cause serious harm to the legitimate rights and interests of you or other individuals or organizations; (6) involving trade secrets; (7) other circumstances provided by laws and regulations.

VI. Cross-Border Transfer of Personal Information

Personal information collected and generated in the course of our operations within the People’s Republic of China will be stored within China. In the following circumstances, after fulfilling obligations provided by law, we will provide your personal information to overseas entities: (1) where applicable law expressly so provides; (2) where we have obtained your explicit authorization; (3) where you engage in personal proactive acts such as cross-border transactions via the Internet.

For the above circumstances, we will ensure through contracts and other means that your personal information is protected to a degree no less than that stipulated in this Policy. Specific compliance mechanisms:

(1) For users in mainland China: before transfer, fully inform the receiving entity, location, data types, purposes, and channels for users to exercise rights; separately obtain special consent for outbound transfer, complete a personal information protection impact assessment, and use security assessment, outbound standard contracts, third-party certification, and other compliance paths in accordance with regulations;

(2) For users in the European Union, the United Kingdom, and Switzerland: adopt EU adequacy decisions, Standard Contractual Clauses, the UK international data transfer addendum, and other compliant transfer tools, assess the data protection laws of the receiving country, and implement additional encryption, access control, and other supplementary protections;

(3) Our internal cross-border access implements least privilege, approval records, full-process auditing, transmission encryption, and personnel confidentiality constraints.

Global regional compliance supplements: (1) Mainland China: body and health information is classified as statutory sensitive personal information, and special consent is separately obtained before processing; (2) European Union, United Kingdom, and Switzerland: users fully enjoy data rights under the GDPR, including access, rectification, erasure, restriction of processing, data portability, objection to processing, and withdrawal of consent at any time; (3) United States: we do not sell or share personal information for cross-context behavioral advertising, prohibit the use of health data for targeted advertising, and comply with CCPA and other state privacy laws; (4) Canada, Japan, Korea, and other Asia-Pacific regions: we follow principles of purpose limitation, minimum necessity, and transparent notice, and respond to user rights requests in accordance with local regulations.

VII. How We Protect Personal Information

We strive to safeguard the security of your personal information to prevent leakage, tampering, loss, improper use, unauthorized access, and disclosure of personal information. We have used security protection measures consistent with industry standards to protect the personal information you provide, including:

(1) Data encryption: using SSL/TLS, AES-256, and other encryption technologies during data transmission and storage, with sensitive information stored encrypted;

(2) Access control: applying the principle of minimum necessary authorization to employees who may access your information, strictly controlling data access processes and approval mechanisms, signing confidentiality agreements, and monitoring operations;

(3) Security auditing: regularly conducting log security checks, penetration testing, and vulnerability scanning to promptly discover and address security risks;

(4) Security certification: we build security management processes in accordance with information security management system standards such as ISO 27001;

(5) Management measures: establishing a dedicated personal information protection department and regularly conducting employee security and privacy protection training.

We implement full-link protection matched to data risk levels, and conduct personal information protection impact assessments for sensitive health data, automated AI decision-making, model training, and cross-border transfers.

Please understand that due to limitations of technical levels and various possible malicious acts, personal information security incidents may occur due to factors beyond our control. If a security incident occurs, we will, in accordance with the requirements of laws and regulations, promptly inform you of: the basic circumstances of the security incident and possible impacts, the disposal measures we have taken or will take, suggestions for you to independently prevent and reduce risks, remedial measures for you, and the like. Where it is difficult to notify individually, we will use reasonable and effective methods to issue announcements, and at the same time proactively report the handling status as required by regulatory authorities.

The Internet is not an absolutely secure environment. We strongly recommend that you do not send personal information through unofficial channels. Please use complex passwords to help us ensure the security of your account. If you discover a personal information leak, especially a leak of account passwords, please contact customer service immediately.

VIII. Retention Period of Your Personal Information

To achieve the purposes of this Policy, we will retain personal information related to you or your device. When such personal information is no longer needed for these purposes, unless law requires us to retain personal information for a longer period, we will delete such personal information or retain it in a form that cannot identify you.

Specific retention period standards:

(1) Account entities and cloud history records are retained during the existence of the account; cleared according to rules after user single-item deletion or account cancellation;

(2) User original voice, photos, and videos are automatically deleted 24 hours after plan generation; materials manually saved to history may be deleted by the user at any time;

(3) After account cancellation, data in the online production database is deleted or irreversibly anonymized within 30 days;

(4) System backup copies are automatically cleared within 90 days as backups are rotated;

(5) Security audit and risk control logs are basically retained for 6 months, and may be extended in scenarios of regulatory investigation or security incidents;

(6) Network logs and transaction records are retained for the minimum period required by laws and regulations;

(7) Statistical data that has been de-identified or anonymized may be retained long-term.

IX. Privacy Policy for Minors

If you are a minor who has reached the age of 14 but has not reached the age of 18, before using Yunwang and related services, you should read and agree to this Policy together under the guardianship and guidance of your parents or other guardians.

Our websites, Products, and Services set corresponding minimum legal ages of consent for different jurisdictions: 14 years of age for mainland China, 13 years of age for the United States, and other regions in accordance with local law. We will not proactively collect personal information of minors who have not reached the legal age.

Minors who have not reached the legal age are prohibited from independently registering accounts or using Yunwang AI smart features; minors who have not reached the legal age are only permitted to use offline, account-free basic massage under the full on-site supervision of the minor’s parents or other guardians; minors who have not reached the legal age are prohibited from uploading any body, voice, or image sensitive materials.

If you are a minor who has not reached the legal age, you may use our Products or Services only after obtaining prior consent from your guardian. If you are a parent or other guardian of a minor who has not reached the legal age, and believe that the minor under your guardianship has provided any personal information to us, please contact us through the methods disclosed in Article XI of this Policy, and we will respond and handle such information in accordance with laws and regulations.

X. Policy Changes

We may revise this Policy from time to time. When material changes occur to the terms of the Privacy Policy, we will present the changed Policy to you upon your login and version updates through push notifications, pop-ups, or other appropriate forms that comply with legal requirements. For material changes involving health data, algorithm training, cross-border transfers, core user rights, and the like, we will also provide more prominent notice (including but not limited to email, SMS, or special prompts on push pages) and re-obtain your special consent.

If you continue to use our Products and Services after this Policy update takes effect, it means that you have fully read, understood, and accepted the updated Policy and are willing to be bound by the updated Policy. If you do not agree to the changed content, you may stop using the relevant services or cancel your account.

XI. Contact Information

We have appointed a personal information protection officer. If you have any questions, complaints, or suggestions regarding this Policy or personal information protection matters, you may contact us through any of the following methods. We will review the matters involved as soon as possible and reply within 15 business days after receiving your feedback:

(1) Send your questions to the email: service@rheofit.com

(2) Mail to the following

Contact address: Room 301, Building C, Building 5, Shenzhen International Innovation Valley, Xingke 1st Street, Yuncheng Community, Xili Street, Nanshan District, Shenzhen, Guangdong Province (Attn.), Postal Code: 518055.

XII. Supplementary Provisions

1. The interpretation of this Policy and the resolution of disputes shall be governed by the laws of the People’s Republic of China. Any dispute related to this Policy shall be resolved by the parties through friendly consultation; if consultation fails, you hereby agree to submit the dispute to the Shenzhen Court of International Arbitration for arbitration in Shenzhen. The arbitral award is final and binding on both parties.

2. If any clause of this Policy is held invalid through arbitration, such clause will be removed from this Policy, but the invalidity of such clause shall not affect the validity of the remaining clauses of this Policy. The remaining clauses of this Policy will continue to be enforced.

3. Affiliates referred to in this Policy mean other enterprises in which the platform entity directly holds equity or indirectly controls, as well as two or more enterprises that are under the common control of a certain enterprise.

Yunwang Innovation Intelligence (Shenzhen) Co., Ltd.

Annex I: Device Permission Invocation List

To ensure the realization of service functions and secure and stable operation, we may apply for or use related operating system permissions. All permissions are not enabled by default and will only be requested for authorization when you use specific features. You may turn them off at any time in system settings:

(1) Bluetooth permissions (BLUETOOTH, BLUETOOTH_SCAN, BLUETOOTH_CONNECT): used to scan, pair with, and connect Yunwang smart hardware devices, and control massage functions;

(2) Location permissions (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION): required only by the underlying Bluetooth scanning on older Android systems; we do not collect or upload actual location;

(3) Camera permission (CAMERA): used when the user actively takes photos to upload to Yunwang AI or customer service;

(4) Album/storage permission (READ_EXTERNAL_STORAGE): used when the user selects images to upload or saves files;

(5) Microphone permission (RECORD_AUDIO): used when the user actively records voice descriptions to upload to Yunwang AI or customer service;

(6) Network permissions (INTERNET, ACCESS_NETWORK_STATE): account login, cloud sync, AI plan generation, firmware updates;

(7) Notification permission (POST_NOTIFICATIONS): sending device status, firmware update, and safety reminder push notifications;

(8) Wake lock permission (WAKE_LOCK): keeping the device awake during continuous operations such as firmware upgrades;

(9) Auto-start/associated-start permissions: used to receive device status push notifications while the application is in the background, and not used for other purposes.

Annex II: Third-Party SDKs

– PdfiumAndroid: used for PDF file rendering, does not involve user personal information, privacy policy link: https://pdfium.googlesource.com

– WeChat OpenSDK Android (Shenzhen Tencent Computer Systems Company Limited): used for WeChat login and sharing, SDK privacy policy link: https://support.weixin.qq.com/cgi-bin/mmsupportacctnodeweb-bin/pages/RYiYJkLOrQwu0nb8

The following SDKs are included in the application dependency libraries, but related functions are not activated in the current version and will not collect or transmit any user data: Google Account Login, Facebook Login SDK, Firebase Authentication, Firebase Storage, Facebook Core Android SDK, Google Protobuf, Fresco. If the foregoing functions are enabled in the future, we will update the Privacy Policy and obtain the user’s express consent.

Annex III: List of Third-Party Service Providers and Shared Personal Information

We send information to third-party service providers that support our business, such support including technical infrastructure services entrusted by us, provision of customer service, payment facilitation, and logistics services. For companies, organizations, and individuals with whom we share personal information, we will require them to process personal information in accordance with our instructions, this Policy, and any other relevant confidentiality and security measures.

I. Cloud Infrastructure and Backend Services

(1) Tencent Cloud CloudBase SDK

1. Scope of use: RheoFit mainland China version.

2. Third-party service name: Tencent Cloud CloudBase.

3. Personal information processed: mobile phone number, verification code, user identifier (uid), nickname, avatar, login credentials and session information; device identifiers and device information, including UDID, device model, operating system version, App version, region; application runtime logs, problem feedback content, and images actively uploaded by users; files actively uploaded by users or synchronized to the cloud.

If you register or log in using a password, related passwords or authentication credentials will be securely processed through authentication services, and we will not display or store your password in plaintext.

4. Purpose of processing: to provide account registration and login, user identity authentication, user profile storage, cloud database, cloud file storage, necessary runtime information logging, firmware or configuration delivery, problem log upload, and troubleshooting services for the mainland China version.

5. Service region: mainland China; the specific storage region is subject to the online configuration and the agreement signed with the service provider.

6. Third-party privacy policy: https://cloud.tencent.com/document/product/301/11470

(2) Google Firebase SDK

1. Scope of use: RheoFit versions outside mainland China.

2. Third-party service name: Google Firebase.

3. Personal information processed: email address, user identifier (uid), nickname, avatar and other account profile information, login credentials or session information, device and application instance-related identifiers, files actively uploaded by users or synchronized to the cloud, application runtime information, crash information, problem feedback content, and necessary device and usage information processed by analytics modules that are actually enabled.

If you register or log in using a password, related passwords or authentication credentials will be securely processed through authentication services, and we will not display or store your password in plaintext.

4. Purpose of processing: to provide account authentication, user profile storage, cloud database, file storage, application runtime statistics, crash analysis, problem log upload, and troubleshooting services for versions outside mainland China.

5. Service region: the specific storage region and enabled modules are subject to the online configuration. Before going live, we will verify the actually enabled modules such as Firebase Authentication, Cloud Firestore, Cloud Storage, Analytics, and Crashlytics, and update this list based on actual processing circumstances.

6. Third-party privacy policy: https://firebase.google.com/support/privacy

II. Mobile Phone Number Authentication Services

(1) Jiguang Security Authentication SDK

1. Scope of use: RheoFit mainland China version.

2. Third-party service name: Jiguang Security Authentication SDK.

3. Personal information processed: mobile phone number; device identifiers such as Android ID, OAID, and IDFA; device model, device hardware, and operating system information; network information such as network type, carrier, IP address, and Wi-Fi status; and SIM card-related information necessary to implement number authentication. The specific scope of processing may vary depending on the device system, carrier, and user authorization circumstances.

4. Purpose of processing: to provide one-tap login with the device’s own mobile phone number, number authentication, and login security risk control, and to ensure the secure and stable operation of the number authentication service.

5. Third-party privacy policy: https://www.jiguang.cn/license/privacy

(2) China Mobile, China Unicom, and China Telecom Carrier Gateway Authentication Services

1. Scope of use: RheoFit mainland China version, accessed through the Jiguang Security Authentication SDK.

2. Third-party service name: China Mobile, China Unicom, and China Telecom carrier gateway authentication capabilities.

3. Personal information processed: the device’s own mobile phone number, as well as device, SIM card, and network information necessary for carrier gateway number retrieval and number verification.

4. Purpose of processing: to cooperate with the Jiguang Security Authentication SDK to complete one-tap login number retrieval for the device’s own mobile phone number, number authentication, and security verification.

5. Third-party privacy policy:

China Mobile: https://wap.cmpassport.com/resources/html/contract.html

China Unicom: https://opencloud.wostore.cn/authz/resource/html/disclaimer.html

China Telecom: https://e.189.cn/sdk/agreement/detail.do

III. Third-Party Account Login Services

(1) WeChat Open SDK

1. Scope of use: RheoFit mainland China version.

2. Third-party service name: WeChat Open SDK.

3. Personal information processed: account identifiers and authorization information such as authorization code, openid, and unionid generated during WeChat authorized login, as well as necessary device information and network status information processed by WeChat Open SDK in accordance with its rules.

4. Purpose of processing: to implement WeChat authorized login, complete third-party account identity authentication, and bind to a RheoFit account.

5. Third-party privacy policy: https://support.weixin.qq.com/cgi-bin/mmsupportacctnodeweb-bin/pages/RYIYJkLOrQwu0nb8

(2) Huawei Account Service SDK

1. Scope of use: RheoFit mainland China Android version.

2. Third-party service name: Huawei Account Service SDK.

3. Personal information processed: Huawei account identifier, Authorization Code and other authorization information, as well as necessary device and network information processed by Huawei Account Service in accordance with its rules.

4. Purpose of processing: to implement Huawei account authorized login, complete third-party account identity authentication, and bind to a RheoFit account.

5. Third-party privacy policy: https://consumer.huawei.com/cn/privacy/privacy-policy/

(3) Sign in with Apple

1. Scope of use: RheoFit versions that support Apple account login.

2. Third-party service name: Sign in with Apple.

3. Personal information processed: Apple user identifier (user), identity token (identityToken), and email address and name that the user chooses to provide within the scope of authorization.

4. Purpose of processing: to implement Apple account authorized login, complete third-party account identity authentication, and bind to a RheoFit account.

5. Third-party privacy policy: https://www.apple.com/legal/privacy/szh/

(4) Google Sign-In SDK (google_sign_in)

1. Scope of use: RheoFit versions outside mainland China.

2. Third-party service name: Google Sign-In SDK.

3. Personal information processed: basic Google account profile information provided by the user within the scope of authorization, such as email address, name, and avatar, as well as Google identity token (idToken).

4. Purpose of processing: to implement Google account authorized login, complete third-party account identity authentication, and bind to a RheoFit account.

5. Third-party privacy policy: https://policies.google.com/privacy

IV. Anti-Fraud Services

If RheoFit subsequently integrates an independent third-party anti-fraud service provider, we may entrust it to perform risk identification on abnormal logins, fake accounts, fraudulent transactions, or other abnormal operations. Related service providers may only process information necessary to achieve risk identification, and shall be subject to strict confidentiality and data security obligations.

Before determining and actually integrating an anti-fraud service provider, we will not process your personal information through unlisted third-party anti-fraud services. Before integration, we will supplement the service provider name, types of personal information processed, purpose of processing, method of processing, service region, and privacy policy link, and inform you and obtain corresponding consent in accordance with legal requirements.

V. Third-Party Services Not Yet Launched

If features such as mall, payment, logistics, and membership subscription have not yet been launched, your personal information will not be processed through related third-party service providers. Before related features are launched, we will supplement the corresponding service provider name, personal information types, purpose of processing, method of processing, service region, and privacy policy link, and update this Policy, notify you, and obtain corresponding consent in accordance with legal requirements.