Last updated: July 17, 2026 | Effective: July 17, 2026
Core promise: PoLang is a smart camera app built privacy-first. We believe your photos, face data, and voice are highly sensitive personal information. That's why PoLang adopts an On-Device First architecture — all sensitive data is processed locally on your device and never uploaded to any cloud server.
PoLang accesses your device and data only to the minimum extent necessary for each feature. Depending on the features you use, the following types of information may be involved:
| Data type | Purpose | Handling |
|---|---|---|
| Camera preview frames | Real-time beauty preview, capture | Local GPU only, never uploaded |
| Captured photos | Saved to gallery, local editing | Stored in the device gallery, never uploaded |
| Face landmarks | Drive beauty effects (slim face, enlarge eyes, etc.) | Local MediaPipe/NCNN real-time, never uploaded |
| Gallery photos / videos | Browse and edit existing photos | Local read only, never uploaded |
| Data type | Purpose | Handling |
|---|---|---|
| Voice command recordings | Voice camera control | Discarded immediately after local ASR, never uploaded |
| Wake-word audio | Trigger voice interaction | Local real-time detection, never uploaded |
| Data type | Purpose | Handling |
|---|---|---|
| Network connection state | Decide whether remote LLM orchestration is available (optional) | Local check only, no network details collected |
| Bluetooth state | Detect Bluetooth accessories (e.g. remote shutter) | Local detection only, never uploaded |
| Device storage space | Check free space before model download | Local check only, never uploaded |
| Data type | Purpose | Handling |
|---|---|---|
| Email address | Account registration & login identifier, LLM free-trial quota billing (default 100 calls/account) | Stored on api.polang.net; only the email and the SHA-256 hash of the login token are kept; no plaintext password is collected (verification-code login) |
| Data type | Purpose | Handling |
|---|---|---|
| Device identifier (Android device ID / locally generated ID) | LLM free-trial call counting for unregistered guests | Sent to api.polang.net; only call counts are tallied by identifier; not used to identify individuals, not shared with third parties. Deletable in Settings → Data & Privacy → Clear guest data |
PoLang requests the following Android system permissions, each tied directly to a specific feature:
| Permission | Level | Purpose | Required |
|---|---|---|---|
| Dangerous | Camera preview, capture, recording | Yes (core feature) | |
| Dangerous | Voice command recording, video audio | No (voice optional) | |
| Dangerous | Read gallery images for editing | No (gallery optional) | |
| Dangerous | Read gallery videos for editing | No (gallery optional) | |
| Dangerous | Read gallery on Android 12 and below | No (gallery optional) | |
| Dangerous | Save photos on Android 9 and below | No (legacy only) | |
| Normal | Connect Bluetooth accessories (e.g. shutter remote) | No (accessory optional) | |
| Normal | Remote LLM orchestration (user-configured) | No (fully offline capable) | |
| Normal | Background model download service | Yes (model download) |
PoLang's core architecture follows the On-Device First principle:
PoLang has a built-in PrivacyGuard tiering system that automatically classifies and routes each command:
| Tier | Data type | Policy |
|---|---|---|
| RESTRICTED | Coordinates, face data | Forced local execution; network transfer never allowed |
| SENSITIVE | Photos, OCR content | Forced local execution; network transfer never allowed |
| PUBLIC | Camera control commands (e.g. "take a photo") | Local-first; user may opt into remote orchestration |
PoLang lets users opt in to a remote LLM API (e.g. Kimi / an OpenAI-compatible endpoint):
Important: PoLang never sells, rents, or shares any of your data with third parties.
Third-party open-source components used by PoLang and how they handle data:
| Component | Purpose | Handling |
|---|---|---|
| MediaPipe | Face landmark detection | Fully local, no network communication |
| MNN / NCNN | Neural-network inference engine | Fully local, no network communication |
| ML Kit | OCR text recognition | Fully local, no network communication |
| Sherpa-ONNX | Speech recognition (ASR) | Fully local, no network communication |
As a PoLang user, you have the following rights:
PoLang is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we may have collected a child's information, contact us and we will delete it promptly.
PoLang takes the following technical and organizational measures to protect your data:
We may update this privacy policy from time to time. Material changes will be announced via in-app notice or the changelog. Continued use of PoLang constitutes acceptance of the revised policy.
If you have any questions or suggestions about this privacy policy, reach us at: