Privacy Policy
This Privacy Policy explains how Epoch AI Limited and its affiliates collect, use, store, protect, and otherwise process personal information when you use EdgeVivid mobile applications, smartwatch devices, cloud services, and related features.
Quick Links
- How the Service Collects and Uses Personal Information
- How We Use Cookies and Similar Technologies
- Other Parties in Data Use, Sharing, and Disclosure of Personal Information
- How We Store Personal Information
- How We Protect the Security of Personal Information
- Management of Your Personal Information
- Minors
- Amendments and Notices of the Privacy Policy
- How to Contact Us
- Other Provisions
- Jurisdiction-Specific Provisions
- Glossary
Preface
Epoch AI Limited and its affiliates as carriers of EdgeVivid products and services, are well aware of the importance of personal information to you, so we will protect your personal information and privacy in accordance with laws and regulations. We have formulated this Privacy Policy and would like to remind you of the following contents for your choices.
- This Privacy Policy specifies how we process your personal information in various scenarios and helps you understand how we collect, use, and protect your personal information in a straightforward and concise way.
- When you turn on relevant features and use relevant services, we will collect relevant information necessary for such purposes. Unless such information is necessary to realize product features or required by laws and regulations, you may refuse to provide it and your refusal will not affect other features or services.
- Permissions of your precise geolocation, video, microphone, photo album, and health sensors will not be activated by default, and will only be available for specific features or services with your explicit authorization. You may also withdraw the authorization at any time.
- This Privacy Policy applies to EdgeVivid products and services, including each version of the mobile application, smartwatch devices, cloud services, and all other products and services provided by us and to which this Privacy Policy applies.
- In certain scenarios, we may also explain the purpose, scope, and usage of information collection through instant notifications and function update instructions. Those notices form part of this Privacy Policy.
1. How the Service Collects and Uses Personal Information
In order to provide the Services for you, maintain the normal and safe operation of the Services, and optimize the functional experience of the Services, we will collect the personal information you provide or authorize any other party to provide when registering an account and using the Services, as well as that generated during your use of the Services, according to the following purposes and methods.
1.1 Account Service
1.1.1 Registration and Login. To use the Services, you need to create an account. The collection of a mobile phone number or email address is necessary for account creation. If you do not provide a mobile phone number or email address for registration and login, we may not be able to provide you with the Services. You can also set a nickname, avatar, gender, date of birth, height, and weight to help us provide more accurate health and fitness metrics.
Based on our cooperation with communication carriers, when you use the one-click login feature, with your explicit consent, the carriers will send your mobile phone number to us, so that we can provide you with quick login service more easily. The mobile phone number is sensitive personal information. Without it, you will not be able to register through one-click login, but it will not affect logging in by other methods.
1.1.2 Public Information of Account. You may fill in or set up your profile photo, nickname, personal signature, and personal status as you wish. This personal data you voluntarily fill in or set up will be shown to other users where such social features are made available.
1.2 Health and Fitness Data
To provide health and fitness tracking features, we collect data from your Device, some of which is classified as sensitive personal information under applicable laws, including where relevant as special category data under Article 9 of the GDPR.
- Activity data: steps taken, distance traveled, calories burned, active minutes, workout types, workout routes, and workout intensity.
- Vital signs data: heart rate, heart rate variability, blood oxygen saturation, blood pressure where supported, and respiratory rate.
- Sleep data: sleep duration, sleep stages, sleep quality scores, and sleep regularity.
- Stress data: stress level indicators and stress tracking history.
- Menstrual cycle data: cycle length, period dates, symptoms, and pregnancy-related data where applicable.
- Other health metrics: weight, body composition where supported, water intake, and manually logged health information.
1.3 AI-Powered Voice Recording and Transcription Data
Our Services include an AI-powered voice recording and transcription feature. When you use this feature, we collect relevant information based on your explicit consent.
1.3.1 Voice Recordings and Transcripts. We may collect voice recordings, transcripts generated from recordings through AI processing, and metadata such as recording timestamps, duration, file identifiers, and optional tags. Your voice is considered personal data under applicable data protection laws because it can identify you directly or indirectly.
1.3.2 Speaker Distinction and Voiceprint Processing. To improve the usefulness of transcripts, our Services may perform clustering and grouping of voices in audio files based on voice characteristics. Audio clustering only extracts characteristics used to distinguish speakers, is not used for identity verification, and does not generate voiceprint characteristics capable of independently identifying a natural person. Voiceprint features are used only for relatively differentiating speakers within a particular file, are used as intermediate data, and are automatically deleted once speaker distinguishing is finished.
1.3.3 Cloned Voice and Timbre Simulation Features. If we offer AI simultaneous interpretation, audio preview, or similar features that simulate voice or timbre, the processing does not involve identifying the speaker's personal identity, is carried out instantaneously during the current session, and does not retain voice feature information after the session ends. Any output audio is only played in real time and will not be retained.
1.3.4 AI Model Training Data Governance. We do not use identifiable voice recordings to train AI models without your explicit, separate consent. Any voice data used for AI model improvement or training is fully anonymized before use and cannot be re-identified to you.
1.4 Location Data
With your permission, we may collect precise location information from your Device's GPS to track outdoor workout routes, provide weather information on your Device, and enable location-based features. You can enable or disable GPS access at any time through your Device settings or App permissions.
1.5 Device and Technical Information
When you use our Device and App, we may automatically collect device identifiers, App usage data and logs, IP address, operating system version, mobile network information, and Bluetooth connection data for device synchronization. This information is collected on the basis of our legitimate interests in providing, maintaining, and improving our Services, and in ensuring network and information security.
1.6 User-Generated Content
We may collect content you voluntarily provide, such as feedback, bug reports, customer support inquiries, forum posts or comments if such features are offered, and photos or notes attached to health or fitness logs. Please consider carefully before sharing information that may contain your or others' personal information.
1.7 Payment and Transaction Information
If you purchase premium services, subscriptions, or accessories, we may collect billing name and address, as well as order history and transaction details. We do not directly collect or store your credit card or payment method information. Payment processing is handled by third-party payment processors that comply with applicable data protection and payment security standards.
2. How We Use Cookies and Similar Technologies
We use cookies and similar tracking technologies such as web beacons, pixels, and local storage to provide, protect, and improve our Services.
- Essential Cookies: Necessary for the operation of our Services, such as authenticating users and preventing fraudulent use.
- Preference Cookies: Used to remember your settings and preferences, such as language and display preferences.
- Analytics Cookies: Help us understand how users interact with our Services, which features are most popular, and where improvements are needed.
Most web browsers and mobile operating systems allow you to control cookies through their settings. However, if you disable cookies, some features of our Services may not function properly. We do not use cookies or similar technologies to collect personal information for cross-context behavioral advertising without your consent.
3. Other Parties in Data Use, Sharing, and Disclosure of Personal Information
3.1 Sharing with Your Consent
We may share your personal information with third parties when you have given us your explicit consent to do so, for example when you choose to share fitness data with third-party apps such as Strava, Google Fit, or Apple HealthKit.
3.2 Service Providers
We may share your information with third-party service providers who perform services on our behalf, including cloud hosting and data storage providers, AI model processing and transcription service providers, analytics and crash reporting services, customer support platforms, and payment processing providers. All service providers are contractually obligated to process your information only on our behalf and with appropriate security measures in place.
3.3 Cross-Border Data Transfers
Our Services are global and your information may be transferred to, stored, and processed in countries outside your country of residence, including but not limited to the United States, Singapore, and Japan. For EEA, UK, and Switzerland residents, when we transfer personal information to countries without an adequacy decision, we implement appropriate safeguards including Standard Contractual Clauses and supplementary measures where required.
3.4 For Legal Reasons
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of us, our users, or others.
3.5 Business Transfers
If we are involved in a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any material change in ownership or use of your personal information.
3.6 Aggregate and De-Identified Information
We may share aggregate or de-identified information that cannot reasonably be used to identify you for research, marketing, analytics, or other purposes.
3.7 No Sale of Personal Information
We do not sell your personal information to third parties and do not trade, rent, or share it for monetary or other valuable consideration.
4. How We Store Personal Information
4.1 Storage Location
Your personal information is stored on secure servers maintained by us or our authorized service providers. These servers may be located in various countries as described in Section 3.3.
4.2 Storage Period
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements.
| Category | Retention Period |
|---|---|
| Account information | Until you delete your account plus up to 30 days for account deletion processing |
| Health and fitness data | As long as your account is active, or as required to provide historical health insights |
| Voice recordings | 30 days after transcription is complete, unless you delete them earlier |
| Transcripts | As long as your account is active |
| Device logs and technical data | Up to 12 months |
| Customer support communications | Up to 24 months after inquiry resolution |
| Marketing preferences | Until consent is withdrawn or you opt out |
Voiceprint data used for speaker distinction is retained only for the duration of the processing session and is automatically deleted immediately after use.
4.3 Account Deletion
When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required for legal compliance or fraud prevention. You can delete your account through the App settings or by contacting customer support.
5. How We Protect the Security of Personal Information
We implement appropriate technical and organizational measures to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
- Encryption: Data at rest is encrypted using industry-standard algorithms such as AES-256, and data in transit is encrypted using TLS 1.2 or 1.3. Where supported, health and fitness data may also be encrypted on your Device.
- Access Controls: Access is restricted to authorized personnel who require it to perform job functions and are subject to confidentiality obligations.
- Security Incident Response: If a data breach is likely to result in a risk to your rights and freedoms, we will notify you without undue delay, notify relevant authorities where required, and take immediate mitigating steps.
- Your Responsibilities: Please maintain the security of your account credentials, choose a strong unique password, and contact us immediately if you believe your account has been compromised.
While we strive to protect your personal information, no security measure is perfect or impenetrable, and we cannot guarantee absolute security.
6. Management of Your Personal Information
You have rights regarding your personal information, which vary by jurisdiction. This section describes the core rights available to most users and how to exercise them.
- Right to Access: Obtain confirmation as to whether we process your personal information and receive a copy. In the App, go to Settings, Privacy, and Download My Data.
- Right to Rectification: Correct inaccurate or incomplete personal information. Most profile and health data can be edited directly within the App.
- Right to Erasure: Request deletion of your personal information under certain circumstances, including by deleting your account or specific data through the App.
- Right to Restriction of Processing: Restrict our processing of your information under certain circumstances.
- Right to Data Portability: Receive your personal information in a structured, commonly used, and machine-readable format and transmit it to another controller.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time where we rely on consent, including for health data and voice recordings, via App Settings, Privacy, and Consent Management.
We do not use your personal information for automated decision-making that produces legal or similarly significant effects on you. AI-powered features are assistive tools only.
7. Minors
Our Services are intended for adult users aged 18 years or older. We do not knowingly collect personal information from children under the age of 13, or under the age of 16 in certain jurisdictions, unless we have obtained verifiable parental or guardian consent.
- United States: We comply with COPPA and do not knowingly collect personal information from children under 13 without verifiable parental consent.
- GDPR Jurisdictions: In the EEA, UK, and Switzerland, we require parental consent for users under 16 years of age in accordance with GDPR Article 8.
- Japan: We do not knowingly collect personal information from children without appropriate consent under the APPI.
If we become aware that we have collected personal information from a child without appropriate consent, we will delete that information as soon as possible.
8. Amendments and Notices of the Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.
- For minor changes, we may notify you via the App or by email.
- For material changes, we will provide more prominent notice, such as an in-App notification requiring acknowledgment before continued use where required by law.
Your continued use of our Services after any changes take effect constitutes your acceptance of the updated Privacy Policy. If you do not agree, you must stop using the Services and may delete your account.
9. How to Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our data processing practices, please contact us:
- Data Controller: Epoch AI Limited, Room12, 15/F, CORE45, 43-45 Tsun Yip Street, Kwun Tong, Kowloon, Hong Kong
- General Privacy Email: privacy@epicaigo.com
- Data Protection Officer: dpo@epicaigo.com
- EU Representative: eu-representative@epicaigo.com
- UK Representative: uk-representative@epicaigo.com
- Japan Representative: japan-representative@epicaigo.com
10. Other Provisions
10.1 Third-Party Services. Our App and Device may contain links to third-party websites, services, or integrations such as Strava, Google Fit, Apple HealthKit, or other fitness platforms. This Privacy Policy does not apply to such third-party services.
10.2 Governing Law. This Privacy Policy is governed by the laws of the applicable jurisdiction, without limiting rights under applicable data protection laws such as the GDPR, CCPA, APPI, or PDPA.
11. Jurisdiction-Specific Provisions
11.1 European Economic Area and United Kingdom
If you are located in the EEA or the United Kingdom, we process your personal information under legal bases including performance of a contract, legitimate interests, consent, and compliance with legal obligations. Health data, biometric data used for identification, and menstrual cycle data are processed only on the basis of your explicit consent where required.
11.2 United States
If you are a California resident, the CCPA and CPRA provide rights including the right to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and be free from discrimination for exercising rights. We also comply with applicable US state consumer health data privacy laws and biometric information privacy laws where they apply.
11.3 Japan
If you are located in Japan, the APPI applies to our processing of your personal information. You may have rights to disclosure, correction, deletion, and suspension of use of retained personal data under applicable law.
11.4 Singapore
If you are located in Singapore, the PDPA applies. You may request access to personal information we hold, request correction, and withdraw consent subject to legal or contractual restrictions.
11.5 Other Asia-Pacific Jurisdictions
For users in other Asia-Pacific jurisdictions, including but not limited to Australia, South Korea, Thailand, Vietnam, Malaysia, Indonesia, and the Philippines, we comply with applicable local data protection laws. Where mandatory local law conflicts with this Privacy Policy, local law prevails.
12. Glossary
- Personal Information: Any information relating to an identified or identifiable natural person.
- Sensitive Personal Information: Personal information that reveals especially sensitive categories such as health data or biometric data, and under the GDPR may be treated as special category data under Article 9.
- Processing: Any operation performed on personal information, including collection, storage, use, disclosure, restriction, erasure, or destruction.
- Data Controller: The entity that determines the purposes and means of processing personal information.
- Data Processor: The entity that processes personal information on behalf of the Data Controller.
- Explicit Consent: A higher standard of consent requiring an affirmative act clearly indicating agreement to processing for a specific purpose.
- De-Identification: The process of removing or altering information so that it can no longer reasonably be used to identify a specific individual.
- Voiceprint: A set of measurable characteristics of a person's voice that can potentially be used for identification. In our Services, voiceprints are used only for temporary speaker distinction and are not retained.
Appendix: Summary of Data Collection by Category
| Data Category | Specific Data Types | Legal Basis (GDPR) | Retention |
|---|---|---|---|
| Account Information | Name, email, phone number, password, date of birth, height, weight | Performance of contract | Until account deletion |
| Device Information | Device ID, OS version, IP address, logs | Legitimate interests | Up to 12 months |
| Health and Fitness Data | Heart rate, steps, sleep, blood pressure, menstrual cycle, weight, body composition | Explicit consent | As long as account active |
| Voice Recordings | Audio files and metadata | Explicit consent | 30 days after transcription |
| Transcripts | Text from voice recordings | Explicit consent | Until account deletion or user deletion |
| Voiceprint Data | Temporary voice characteristics for speaker distinction | Legitimate interests or consent | Session-only and automatically deleted |
| Location Data | GPS coordinates | Consent | As long as account active |
| Payment Information | Billing name, address, order history | Performance of contract and legal obligation | As required by tax law |
| Marketing Preferences | Subscription status and interaction data | Consent | Until consent is withdrawn |