Privacy Policy

Scope
The Deal app and related services
Effective date
July 31, 2026
Last updated
July 31, 2026
Version
V1.3
Published by
Hangzhou Rongjing Future Technology Co., Ltd.

This English text is a translation provided for your convenience. The Chinese version is the legally binding original — in the event of any discrepancy, the Chinese version shall prevail.

Hangzhou Rongjing Future Technology Co., Ltd. (“we”, “us” or “our”) understands the importance of your personal information and is committed to keeping it secure. This Privacy Policy explains how we collect, use, store, share and protect your personal information when you use the Deal app and related services (together, the “Services”), and what rights you have.

[Important notice] Please read this Policy in full before using the Services. When you tick “I have read and agree” or begin using the Services, you are deemed to consent to our handling of your personal information as described here. For sensitive personal information (such as recorded audio), we will obtain your separate consent through a prominent prompt such as a dialog.

1. How we collect and use your personal information

We collect personal information only to the extent necessary to provide the Services, following the principle of minimum necessity.

1.1 Registration and sign-in

Mobile number and SMS verification code: used to register or sign in, verify your identity and recover your account. Messages are sent through Alibaba Cloud’s communication service.

(Note: we do not collect unique device identifiers such as IDFA or IDFV, nor device serial numbers.)

1.2 Recording and speech transcription

  • Microphone permission and recorded audio: used when you actively start a recording. Recordings are stored only on your local device by default.
  • Audio transcription: when you request a transcription, the audio file is uploaded over an encrypted connection to our cloud storage (located in mainland China) and made available to Alibaba Cloud’s speech recognition service through a time-limited authorised link. Once recognition is complete, the transcript is returned and the temporary audio copy is deleted automatically within 24 hours.
  • Speaker separation: if you enable this feature, the transcript includes labels segmented by speaker.

Microphone permission is requested the first time you actively use the recording feature, and you may revoke it at any time in your system settings. Doing so disables recording features but does not affect your use of other services.

1.3 AI insights, document generation and AI assistant conversations

  • Content you submit: including transcripts, text, PDF files and images. This is forwarded through our servers to large language model and document parsing services (DeepSeek, Alibaba Cloud Bailian and Zhipu GLM — see the Third-Party Information Sharing List) for summarisation and analysis, fact extraction, document and image parsing, and conversational replies.
  • Automatic triggering of AI insights: once a recording has been transcribed, the system automatically submits the full transcript of that recording to the model provider used for insights, without requiring action from you each time. If you prefer otherwise, you can choose not to transcribe that recording, or disable the relevant modules on the insights page.
  • AI conversation history: used to provide contextually coherent replies during your current session.
  • Web search: where an AI feature needs public information from the internet, your question may be used as a search query through the model provider’s web search capability. This processing does not occur when such features are not enabled.

1.4 Cloud sync and file storage

  • Notes, templates and generated documents: once you enable cloud sync, these files are uploaded over an encrypted channel to Alibaba Cloud Object Storage Service and held in private storage space we lease.
  • Sync metadata: such as sync time and file size, used to keep your devices consistent.

1.5 Plan purchases and payment

  • iOS: purchase status, Apple transaction receipt and product ID. One-time consumable passes are purchased through Apple StoreKit; we receive only Apple’s verification result and the activation details. We do not collect your bank card number, Apple account password or other payment credentials. Payment is handled by Apple and governed by Apple’s privacy policy.
  • Android (where applicable): payments made through WeChat Pay or Alipay are handled by the respective payment institution. We receive only the payment result and order status, and do not collect your bank card number or payment account password.

1.6 Customer service and feedback

Contact details (such as email), problem descriptions, screenshots and logs: used to respond to your enquiries, complaints and feedback.

1.7 Security and operations

  • API call logs and IP address: recorded automatically by our servers when you access the Services, used for troubleshooting, service stability, detecting abnormal behaviour and preventing abuse. We do not integrate any third-party crash reporting or analytics SDK in the app.
  • Authentication tokens: issued by our servers after you sign in, used solely as session credentials and containing no sensitive information.

1.8 Recording location (off by default, requires you to opt in)

If you turn on Profile → Record Recording Location in the app, we obtain your approximate location once at the end of each recording and immediately convert it into a place name (for example “Xihu District · a certain building”) to label where that recording took place.

We make the following commitments about this feature:

  1. it is off by default and takes effect only after you turn it on and grant system location permission;
  2. we save and sync only the converted place-name text; we do not store or upload your latitude and longitude;
  3. location is obtained once at the end of a recording only — there is no background positioning and no tracking of your movements;
  4. location accuracy is set to the hundred-metre level; we do not obtain precise positions;
  5. you may turn the switch off in the app or revoke location permission in system settings at any time. Afterwards we no longer obtain any location information, and previously labelled place names can be cleared by deleting the corresponding recordings.

1.9 Permissions you may decline

  • Microphone: used for recording. Declining makes recording unavailable.
  • Photos and files: used to select local audio, images and PDFs. Declining prevents importing local material.
  • Location: used to label where a recording took place, only after you opt in. Declining or disabling it does not affect recording or any other feature.
  • Notifications: used to deliver local reminders on this device, such as an interrupted recording (remote push is not currently used). Declining means you will not receive reminders.
  • Network: used for transcription, AI services and cloud sync. Declining leaves only local browsing available.

Other than the circumstances described above, we do not collect your contacts, text messages, calendar, health data or other personal information that is not necessary for the Services, and we do not obtain any location information unless you have enabled the recording location feature.

1.10 Separate consent for sensitive personal information

When processing the following sensitive personal information, we will inform you separately and prominently — through dialogs or secondary confirmation — of the purpose, method, scope and possible impact, and obtain your express consent:

  1. microphone permission and recorded audio (including voiceprint and other vocal characteristics that may be involved);
  2. location information: only when you turn on the Record Recording Location switch, at which point the system prompts you for location authorisation;
  3. sensitive details that may be contained in PDFs, images and documents you upload, such as ID numbers, bank accounts, medical and health information or movement records. Please redact such information before uploading; we strongly recommend not uploading sensitive information unrelated to the Services.

If you decline to give separate consent, this does not affect your use of other features that do not rely on the information above.

2. Local storage and similar technologies

We use local storage (such as the system keychain and app preferences) only where necessary to maintain sessions — storing sign-in credentials, user preferences and cached data. We do not use third-party advertising or tracking SDKs.

3. How we share, transfer and publicly disclose your personal information

3.1 Sharing

To deliver the functionality of the Services, we share your personal information with third-party partners within the minimum necessary scope, applying protective measures such as encrypted transmission. For the full list of partners, the data shared, the purposes and links to their privacy policies, please see the Third-Party Information Sharing List (available in the app under Profile → About Us). We have signed data processing agreements with our partners requiring them to handle your personal information in accordance with this Policy and applicable law, and not to use it for any purpose beyond what has been agreed.

3.2 Transfer

We do not transfer your personal information to any third party except in the following circumstances:

  1. we have obtained your explicit prior consent;
  2. in the event of a merger, acquisition or reorganisation — in which case we will require the new controlling party to continue to honour this Policy, failing which we will seek your authorisation again.

3.3 Public disclosure

We may publicly disclose information only where:

  1. we have obtained your explicit consent;
  2. it is required by laws and regulations, or by administrative or judicial authorities following statutory procedures.

4. How we store your personal information

  1. Storage location: your personal information is stored on servers within the People’s Republic of China.
  2. Retention period: information is retained while we provide the Services to you. After you delete your account or remove content, we will delete or anonymise it in our production systems within 30 days. Where laws and regulations provide otherwise (for example transaction records must be kept for at least five years), we follow those requirements.
  3. Local cache: recordings, transcripts and generated documents are cached on your device, and you can clear them in the app or in system settings.

5. How we protect your personal information

  1. Transmission security: HTTPS/TLS encryption is used end to end between client and server; file uploads go directly through time-limited signed channels.
  2. Storage security: sensitive credentials are encrypted, masked or access-controlled as necessary; server keys are managed through environment variables and must never be committed to a database or written to logs.
  3. Access control: internal staff access personal information on a least-privilege basis, and their actions are logged and auditable.
  4. Security incident response: in the event of a personal information breach, we will promptly inform you of the possible impact and the measures we have taken — via in-app message, email or push, as required by law — and report to the regulator.

6. Your rights

Under the Personal Information Protection Law and related regulations, you have the following rights over your personal information:

  • Access and copy: in the app under Profile → Personal Info, or request an export by email.
  • Correct and supplement: edit your profile in the app.
  • Delete: remove individual notes or files; deleting your account removes all associated data.
  • Withdraw consent: revoke the relevant permission in system settings, or turn off features such as cloud sync in the app.
  • Delete your account: in the app under Profile → Personal Info → Delete Account.
  • Complaints and reports: email eog-global@eoger.com.

We will respond within 15 working days of receiving your request. We generally do not charge for reasonable requests; for repetitive requests or those beyond reasonable limits, we may charge a cost-based fee or decline.

Appendix: additional rights under GDPR and CCPA (applicable only to users in the relevant jurisdictions)

  1. If you are located in the EU or the UK, you additionally have the right to data portability, the right to object to processing, the right to object to automated decision-making, and the right to lodge a complaint with your local data protection authority.
  2. If you are a California resident, you additionally have the right to know, the right to delete, and the right to opt out of sale or sharing. We confirm that we do not “sell” your personal information.
  3. Please exercise these rights by contacting us at eog-global@eoger.com; we will respond within the period required by law.

7. Protection of minors

  1. The Services are designed and marketed for adults and are not directed at minors. We do not knowingly collect personal information from users below the minimum age of consent under applicable law (14 years old in mainland China).
  2. If you are below that age, please read this Policy together with your guardian and use the Services only with your guardian’s explicit consent. Upon a valid request from a guardian, we will delete the relevant personal information.
  3. If you are a guardian and discover that a minor in your care has used the Services or provided personal information without your consent, please contact us using the details at the end of this Policy. After verification we will help delete the information and close the account.
  4. We do not profile minors or target them with marketing, and we do not push commercial advertising to minors.

8. Updates to this Policy

This Policy may be updated in light of laws, regulations and business changes. Material changes — such as a change of collection purpose, an expansion of the scope of sensitive personal information, or new third-party sharing — will be notified prominently in the app or your consent will be sought again. Other changes will be published in the app.

9. Cross-border data transfers

  1. Our primary servers and data storage are located within the People’s Republic of China.
  2. If you use the Services from outside mainland China, you understand and agree that, in order to deliver the Services, your personal information will be transferred to servers within the People’s Republic of China and stored and processed there.
  3. We apply contractual clauses, encrypted transmission and access controls to safeguard cross-border transfers. Where applicable law imposes additional requirements, we will transfer data on the legal basis that law prescribes.
  4. You may request a copy of the specific safeguards for cross-border transfers by writing to the email address in the “Contact us” section below.

10. Contact us

If you are not satisfied with our response, you may complain to regulators including the cyberspace administration, the industry and information technology authority, the public security authority and the market regulator.

This Policy, together with the User Service Agreement and the Membership Service Agreement, constitutes the complete set of terms between you and us.