Privacy Policy
Last updated: September 1, 2026
Your privacy matters to us. This policy explains what data we handle, why, and the choices you have.
1. Scope
This policy explains how we collect, use, store, share and protect personal information when you use the platform (web and open APIs), and applies to all data processed through the Service.
2. Information We Collect
Identity data: when signing in via enterprise SSO (e.g. DingTalk) we obtain your name, avatar, department and unique ID; when registering by email we collect the email address and display name.
Content data: skills, prompts, cases, attachments and version history you upload or publish.
Usage data: login logs, API call counts, storage usage and similar operational metadata collected for security and billing. We do not read content you mark as private without authorization.
3. How We Use Information
To operate core features (identity, workspace isolation, content display and search), secure the Service (brute-force protection, anomaly detection), meter quotas and billing, and send necessary notices (password reset, invitations) when such features are enabled.
We never sell personal information or use it for advertising unrelated to the Service.
4. Storage & Security
Data is stored on cloud infrastructure within mainland China. We enforce transport encryption (HTTPS), database access control, row-level multi-tenant isolation, daily automated backups and least-privilege operations.
In the event of a data breach we will notify affected users and take remediation measures as required by law.
5. Sharing & Disclosure
Within a workspace, members can see each other’s public profile (name, avatar) and in-workspace content per the collaboration settings. We disclose personal information only with consent, to comply with law, or to protect vital legitimate interests. Sub-processors (cloud hosting, database, email, object storage) process data solely to operate the Service under appropriate agreements.
6. Retention
Account and content data are retained while the Service is in use; after termination we delete or de-identify them within a reasonable period, subject to statutory retention. Log data is generally kept no longer than 12 months.
7. Your Rights
You may access, correct or delete your personal information, and export content data you are entitled to via workspace export features. Requests can be made through in-app feedback or your workspace administrator; we respond within a reasonable, lawful period.
8. Cookies
We use only cookies strictly necessary for session continuity and UI preferences (language, theme). No cross-site tracking. Clearing cookies requires re-login.
9. Minors
The Service is intended for organizations and professionals, not children under 14. Personal information collected from children without guardian consent will be deleted promptly upon discovery.
10. Updates & Contact
Updates are published on this page; material changes are separately announced. Questions about this policy or personal information protection can be sent via in-app feedback.
Related: Terms of Service