UPMEE PRIVACY POLICY
Effective date: August 10, 2026
Last updated: August 12, 2026
Shenzhen Janyun Internet Technology Co., Ltd. ("Upmee") is the data controller responsible for the Upmee mobile application and related services. In this Policy, "we," "us," and "our" refer to Upmee. This Privacy Policy explains the personal information we process, the purposes and methods of processing, when information is disclosed or processed by service providers, how long it is retained, the safeguards we use, and how you can manage your information. Please read this Policy carefully before using Upmee.
SECTION 1 — INFORMATION WE PROCESS
1.1 Account, contact, and profile information
When you register, sign in, recover an account, or use guest access, we may process your user ID, email address, verification status, encrypted or hashed credentials, login tokens, and account status. Passwords are not stored in plain text. If you complete your profile, we may process your nickname, gender, date of birth, height, weight, and unit preferences. If you contact support or submit feedback, you may optionally provide a phone number, email address, WeChat ID, or other contact details.
1.2 Device, smart ring, and technical information
To connect and manage a compatible smart ring, we process smart-ring identifiers, smart-ring model and product information, firmware version, Bluetooth connection and pairing status, battery or device status, and related synchronization records. We may also process an app or device identifier, phone model, operating system and version, app version, language, country or region, time zone, network status, IP address, request timestamps, product interaction records, and security or service logs. We do not use advertising identifiers such as IDFA for targeted advertising.
1.3 Activity, sleep, and cycle information
Depending on the functions supported by your smart ring and the information you choose to record or use, Upmee may process:
(1) activity and workout information, such as steps, calories, activity intensity, workout type, time, duration, distance, and route;
(2) sleep information, such as sleep duration, stages, timing, score, and trends;
(3) optional menstrual-cycle or period records and related symptoms.
These categories may be sensitive personal information or special-category data. Smart-ring, activity, sleep, and cycle data is generally stored locally on your device. Selected snapshots, summaries, or reports may be transmitted off the device only when you affirmatively request a function that needs them—for example, when you ask the AI assistant for personalized insights, generate an activity or weekly report, or choose to include relevant data in feedback or diagnostics. We do not continuously upload this data merely because you open the app, and we do not use it for medical diagnosis or treatment.
1.4 Precise location and route information
With your permission, Upmee may access precise location while you use an outdoor activity, distance or route function, weather feature, or location-aware AI request. Outdoor activity routes are generally stored on your device. When you request weather or location-aware assistance, current coordinates, city, country or region, or a derived location context may be sent to our regional server and the applicable weather provider. Upmee does not continuously collect precise location outside a function that you enable.
1.5 AI assistant and user content
If you use the AI assistant, we process the text you submit, assistant responses, conversation and message identifiers, feedback ratings, language and time-zone settings, and feature context needed to answer your request. Depending on your question and affirmative choices, this context may include profile details, activity, sleep, activity reports, weekly reports, or location context. If you use voice input, your audio recording is uploaded for speech recognition and a transcript is created. If voice playback is enabled, text may be sent for speech synthesis.
The current AI assistant accepts text and voice input only and does not provide an image-submission function. Photos attached through feedback are not used by the AI assistant. AI output may be inaccurate and must not be treated as medical, legal, financial, or other professional advice. The AI assistant does not make automated decisions that produce legal or similarly significant effects about you.
Using the AI assistant is optional. Information is sent only when you affirmatively start an AI request. You may choose not to use the AI assistant and should avoid including unnecessary sensitive information in a prompt.
1.6 Feedback, support, photos, and diagnostics
When you submit feedback, we process the feedback category and text, optional contact details, any photos you choose to attach, account and device identifiers, smart-ring model, phone model, app and system version, language, time zone, and submission status. If you separately choose to include diagnostics, we may also receive app and device logs, Bluetooth and network status, performance measurements, crash reports, and other troubleshooting information. Diagnostic artifacts are uploaded only when you submit feedback or take another consent-based diagnostic action.
Do not include identity documents, complete medical records, financial-account details, verification codes, or another person's information in feedback photos or text unless it is necessary to resolve the issue and you have lawful authority to provide it.
1.7 Information stored only on your device
Some settings, smart-ring data, activity routes, menstrual-cycle records, cached content, and feature preferences may remain only on your device. We do not collect them unless you use a function that explicitly requires transmission. Information processed only on your device is not sent to our servers.
SECTION 2 — PURPOSES AND LEGAL BASES
2.1 How we use information
We process personal information only for specific, reasonable, and necessary purposes, including to:
(1) create, authenticate, secure, recover, and delete accounts;
(2) connect to and manage your smart ring, synchronize smart-ring data, and provide device or firmware functions;
(3) display activity, sleep, trend, cycle, activity-report, and weekly-report features;
(4) provide outdoor activity, route, distance, weather, and location-aware functions;
(5) process AI text, voice, and personalized-report requests;
(6) respond to support requests and investigate feedback;
(7) diagnose crashes, Bluetooth or network problems, and improve reliability, performance, and usability;
(8) prevent abuse, protect account and service security, and maintain service availability; and
(9) comply with legal obligations and resolve disputes.
We do not sell personal information. We do not use Upmee data for cross-app tracking, targeted advertising, or advertising measurement, and we do not provide it to data brokers.
2.2 Legal bases
Depending on applicable law, our legal bases may include performing our agreement with you or taking requested steps before entering into it; complying with legal obligations; pursuing legitimate interests in account, network, and service security; and your consent. For precise location, microphone, photos, the AI assistant, and menstrual-cycle information that may be sensitive personal information or special-category data, we obtain separate consent, explicit consent, or another valid authorization where required. You may decline optional processing, but a function may be unavailable if you do not provide information necessary to perform it.
SECTION 3 — PERMISSIONS AND YOUR CHOICES
Upmee requests system permission only when the corresponding function needs it:
(1) Bluetooth: connect, synchronize, and manage a compatible smart ring;
(2) Location While Using the App: record outdoor activity distance or route and provide location-related weather functions;
(3) Microphone: record voice input for the AI assistant and convert it to text;
(4) Photos: select and attach photos to feedback; and
(5) Local Network: connect to a compatible smart ring on the same Wi-Fi network and transfer a firmware package where supported.
You can deny or later disable a permission in iOS Settings. The related optional function may stop working, but unrelated functions will remain available where technically possible. Withdrawal does not affect processing that was lawful before withdrawal. Where applicable law requires separate consent for sensitive information, disclosure to another controller, or an international transfer, we provide a separate notice and obtain the required consent before the relevant processing starts.
SECTION 4 — SHARING AND SERVICE PROVIDERS
We provide recipients only the minimum information necessary to perform a function you affirmatively request. The recipients depend on your region, feature availability, and request type and may include:
(1) Tencent Cloud and Tencent MaaS/TokenHub: regional cloud services, feedback attachments, diagnostic files, speech synthesis, and, where enabled, AI text processing. Data may include account or device identifiers, feedback files, diagnostic information, audio, prompts, and selected context needed for the request. Tencent Cloud Privacy Policy: https://www.tencentcloud.com/document/product/301/17345
(2) Alibaba Cloud Model Studio (Bailian/DashScope): where enabled, speech recognition, speech synthesis, or related AI processing. Data may include voice recordings, text, language settings, and selected context needed for the request. Alibaba Cloud Privacy Policy: https://www.alibabacloud.com/help/en/legal/latest/alibaba-cloud-international-website-privacy-policy
(3) OpenWeather: weather, geocoding, air-quality, and forecast requests. Data may include coordinates, city, country or region, and the weather query needed to return results. OpenWeather Privacy Policy: https://openweather.co.uk/privacy-policy
(4) Apple: App Store distribution and iOS system services such as location and maps. Apple processes information under its own terms when you use those system services. Apple Privacy Policy: https://www.apple.com/legal/privacy/
Our company-operated regional services and self-hosted AI workflows may route a request to an applicable provider listed above. We use contracts, access controls, and security measures to require processors to process information only on our instructions and for agreed purposes. When a recipient acts as an independent controller or equivalent entity under applicable law, it is responsible under its own privacy policy. Except where required by law, we do not provide personal information for a third party's own advertising or marketing purposes.
We may also disclose information where required by law or necessary to protect users or service security. In a merger, acquisition, restructuring, or asset transfer, personal information may transfer with the relevant business. We will provide notice where required and require the recipient to continue protecting the information to a standard no less protective than this Policy.
SECTION 5 — REGIONAL PROCESSING AND INTERNATIONAL TRANSFERS
Upmee uses regional routing. Users in mainland China are generally served by our China region; other users are generally served by our Singapore region. Country or region and time-zone signals may be used to select the regional endpoint. A feature you affirmatively request may also involve a provider in another jurisdiction. Account, AI, feedback, weather, or support requests may therefore be processed and stored in the applicable region.
When personal information is transferred outside your country or region, we comply with applicable transfer rules and, where needed, use lawful safeguards such as standard contractual clauses, data-processing agreements, security assessments or certifications, encryption, and access controls. Where required by law, before a transfer we explain the overseas recipient, purposes, data categories, and method of exercising rights, and obtain separate consent. You may contact us to ask about safeguards applicable to a transfer.
SECTION 6 — RETENTION AND DELETION
We retain information only for as long as necessary for the purposes described in this Policy, legal obligations, and dispute handling, and then delete or anonymize it. In general:
(1) account, profile, and cloud-service records are retained until account deletion or for a longer period required by law;
(2) AI conversation text and related voice records are retained as needed to provide conversation history or playback until you delete the relevant content, delete the account, or we no longer need the record;
(3) feedback text and case metadata are retained as needed to handle the issue and maintain reasonable support records;
(4) feedback attachments and diagnostic artifacts are generally deleted automatically within 3 days under the current configuration and are not retained for more than 30 days unless a security incident, dispute, or legal obligation requires limited extended retention;
(5) security and service logs are retained only as needed for security, troubleshooting, and legal obligations; and
(6) local information remains on your device until you delete it, clear app data, or uninstall the app, although device backups may be governed by Apple and your backup settings.
To delete an account in the app, go to My > Personal Information > Delete Account. If you cannot access the app, visit:
https://www.jyhl.top/account-deletion.html
After a valid deletion request, we start an account-lock and background-cleanup process to delete or anonymize account credentials, profile records, AI conversations and audio, feedback files, device associations, and other account-linked server information. A minimal record may be retained where required by law or necessary for security, fraud prevention, or dispute handling. Uninstalling the app does not automatically delete a cloud account. Information stored only on the device must be removed in the app, by clearing app data, or by uninstalling the app.
SECTION 7 — SECURITY
We use technical and organizational measures appropriate to the risk, including encrypted transport, access control, authentication, logging, least-privilege access, data minimization, and security monitoring. Access to support and diagnostic information is limited to authorized personnel who need it for their work. No transmission or storage method is completely secure. If a personal-information incident may affect your rights, we will take remedial steps and notify you or the competent authority where required by law.
SECTION 8 — YOUR RIGHTS AND REGIONAL SUPPLEMENTS
8.1 General rights
Subject to applicable law, you may request access to, a copy of, correction of, supplementation of, deletion of, restriction of, or an explanation about your personal information; withdraw consent for optional processing; manage system permissions; delete available conversations, activity, cycle, or other local records; delete your account; object to automated processing or request human assistance; and complain to us or a competent regulator.
You can manage available information in the app or email Janyun@mail.janyun.com. We may need to verify account ownership but will not ask you to email a password or verification code. We respond within the period required by applicable law.
8.2 European Economic Area, United Kingdom, and Switzerland
Where local data-protection law applies, you may also have rights to data portability, to object to processing based on legitimate interests, and to complain to your local supervisory authority. You may withdraw consent at any time. International transfers rely on applicable standard contractual clauses, an adequacy decision, or another lawful mechanism; contact us for information about applicable safeguards. If processing is based only on consent or provides an optional feature, refusing or withdrawing consent does not affect unrelated core functions.
8.3 California, United States
If the California Consumer Privacy Act applies, you may request to know, access, correct, or delete personal information and may limit the use and disclosure of sensitive personal information as provided by law, without discriminatory treatment for exercising a right. We do not sell personal information or share it for cross-context behavioral advertising, so we do not offer an opt-out mechanism for such sale or sharing. You or an authorized agent may submit a request through the email listed in this Policy.
SECTION 9 — CHILDREN AND MINORS
Upmee is not offered to children under 14. If your jurisdiction sets a higher minimum age, that higher age applies. A person below the applicable minimum age must not register for or use Upmee or submit personal information to us. If we learn that we collected a child's personal information in error, we will stop the processing and delete it as required by law. A parent or guardian may contact us using the details below.
SECTION 10 — CHANGES TO THIS POLICY
We may update this Policy when functions, data practices, providers, or legal requirements change. For a material change, we will provide an in-app notice, website announcement, or other appropriate notice and obtain renewed consent where required. The “Last updated” date at the top indicates the latest revision. Each language version is intended to have the same meaning. If you identify a translation difference, please contact us for correction; mandatory rights under applicable law are not affected.
SECTION 11 — CONTACT US
Data controller:
Shenzhen Janyun Internet Technology Co., Ltd.
Email:
Janyun@mail.janyun.com
Website:
https://www.jyhl.top
Last updated: August 12, 2026