Release Practice Privacy Policy
Last Updated: June 27, 2026
Guangxi Xiaoyao Yunyi Technology Co., Ltd. ("we", "us") is the operator of Release Practice and related services. This policy applies to the Release Practice client applications.
Important: the current version includes account, payment, cloud sync, and cloud voice synthesis features. It is no longer a fully offline-only product.
1. Information We Collect
1.1 Account and Authentication Information
- Email address, email verification status, verification-code related data
- Session credentials (access token and refresh token)
1.2 Device and Technical Information
- Device identifier (deviceId): after you agree to this policy, the app generates an installation-scoped random UUID locally for device registration, login authentication, membership status, payment order creation, purchase restore, cloud-sync data isolation, and security/risk control. The current version does not read AndroidID, IMEI, IMSI, device MAC address, or other hardware/system fixed identifiers to generate deviceId.
- Device name, model, OS version, app version
- Device fingerprint (for security validation and risk control)
- Network status related data for request handling and troubleshooting
1.3 Membership and Payment Information
- Order data: order number, product, amount, store channel, order status, and paid time
- Google Play purchase identifiers: purchase token, order ID, product ID, and acknowledgement state
- Membership status: premium state, subscription type, start/end time
1.4 Cloud Sync Data (after login and opt-in)
- Release records (including feelings, desire type, answers)
- Emotion configuration data
- Step template data
- App settings data (used to restore preferences after device change)
- Harvest journal and other data you choose to sync
- Sync status and sync logs
1.5 Voice Guidance and TTS Data (when enabled)
- Text required for synthesis (including step text and your custom text)
- Voice parameters (such as language, voice, and model version)
- Flow and step identifiers (for audio file mapping)
- Voice-file indexes and access logs (for cache, delivery, and troubleshooting)
If you do not log in or do not enable cloud sync, related business data stays on your local device by default.
2. How We Use Information
- Account registration, login, authentication, and security checks
- Membership purchase, payment processing, order query, and purchase restore
- Cloud backup and cross-device synchronization
- Voice guidance and cloud Text-to-Speech synthesis
- Use the installation-scoped random deviceId to distinguish device sessions and data scope, avoiding data mixing across devices or users
- Error handling, security auditing, and troubleshooting
- Compliance with legal and regulatory obligations
3. Storage and Retention
3.1 Storage Location
- Local data: stored in your device sandbox
- Installation-scoped random deviceId: stored in local app preferences and transmitted over HTTPS to our data service or payment service only in necessary business requests such as login, membership, payment, purchase restore, and cloud sync
- Account and sync data: stored on our data service infrastructure (data-server)
- Payment and order data: stored on our payment service infrastructure (payment-server)
- Voice files and manifests: stored in object storage (OSS) and accessed via short-lived signed URLs
3.2 Retention Period
- Account data: retained while your account remains active
- Installation-scoped random deviceId: retained during the app installation period; after app uninstall, local data cleanup, account deletion, or device-session unbinding, it will be deleted, invalidated, or anonymized according to business rules
- Sync business data: retained while you use sync; deletable via corresponding product operations
- Order/payment data: retained for legally required periods
- Security/audit logs: retained for necessary security and audit purposes
3.3 Android System Backup Notice
Android system backup behavior may apply depending on device/system settings. Backup destination and policy are controlled by system/vendor mechanisms.
4. Sharing, Transfer, and Disclosure
4.1 Information Sharing
We share only the minimum required information to provide necessary services:
- With payment providers for payment completion (e.g., order number, amount, payment parameters)
- With email delivery service for verification code delivery
- With voice service providers for the minimum data required for synthesis (such as voice text, language, and voice parameters)
4.2 No Sale of Personal Information
We do not sell your personal information.
4.3 Legal Disclosure
We may disclose necessary information when required by applicable laws, regulations, or lawful requests from authorities.
5. App Permissions
The Android app may request the following permissions:
- INTERNET / ACCESS_NETWORK_STATE: login, payment, membership status, cloud sync
- POST_NOTIFICATIONS: reminder notifications
- RECEIVE_BOOT_COMPLETED: reschedule reminders after reboot
- SCHEDULE_EXACT_ALARM: exact reminder scheduling
- VIBRATE: haptic feedback
6. Your Rights
- Access and correction: view/edit relevant business data in app
- Deletion: delete local data; synced data can be deleted via product operations
- Disable sync: turn off cloud sync at any time
- Device management: logged-in users can manage active devices (e.g., unbind)
- Account/data requests: contact us for account deletion or data handling support
7. Security Measures
- Local storage security: local business data uses Android secure storage mechanisms (such as Room Database and DataStore) and is protected by app sandbox isolation, so other apps cannot directly access this app data.
- Transport security: network interfaces use HTTPS encryption to reduce interception or tampering risks in transit.
- Access control: account authentication, token mechanisms, and least-privilege principles are applied to limit data access scope.
- Data isolation: account and device identifiers are used for data scope control to avoid cross-user data mixing.
- Security audit and risk control: key operation logs are recorded and anomaly signals are monitored for security auditing, troubleshooting, and risk protection.
- Incident response: when a security incident occurs, we will evaluate and handle it in a timely manner and take necessary notification measures as required by laws and regulations.
8. Third-Party Services
Android may integrate or invoke the following third-party services:
- Google Play Billing service (for subscription purchase, restore, and status refresh)
- Email delivery service (verification email)
- Alibaba Cloud Bailian (DashScope) Text-to-Speech service (for voice guidance)
- Alibaba Cloud OSS object storage service (for voice file storage and delivery)
These providers process relevant information according to their own privacy policies.
9. Minors
If you are a minor, please read and use this app under guardian guidance. Guardians may contact us for any privacy-related concerns regarding minors.
10. Policy Updates and Contact
We may update this policy based on business, legal, or regulatory changes. For material changes, we will notify you via in-app popup or announcement.