PoLang Privacy Policy

Last updated: September 18, 2026 | Effective: September 18, 2026

查看中文版 · 繁體中文

Core promise: PoLang is a smart photo gallery app (with camera capability) built privacy-first. We believe your photos, face data, and voice are highly sensitive personal information. That's why PoLang adopts an On-Device First architecture — photos, videos, faces, voice and other media data are processed locally on your device and never uploaded to any cloud server.

1. Information We Collect

PoLang accesses your device and data only to the minimum extent necessary for each feature. Depending on the features you use, the following types of information may be involved:

1.1 Camera & Image Data

Data type Purpose Handling
Camera preview frames Real-time beauty preview, capture Local GPU only, never uploaded
Captured photos Saved to gallery, local editing Stored in the device gallery, never uploaded
Face landmarks Drive beauty effects (slim face, enlarge eyes, etc.) Local MediaPipe/MNN real-time, never uploaded
Gallery photos / videos Browse and edit existing photos Local read only, never uploaded

1.2 Voice Data

Data type Purpose Handling
Voice command recordings Voice camera control Discarded immediately after local ASR, never uploaded
Wake-word audio Trigger voice interaction Local real-time detection, never uploaded

1.3 Device & Network Information

Data type Purpose Handling
Network connection state Decide whether remote LLM orchestration is available (optional) Local check only, no network details collected
Bluetooth state Detect Bluetooth accessories (e.g. remote shutter) Local detection only, never uploaded
Device storage space Check free space before model download Local check only, never uploaded

1.4 Account Data (Email Registration)

Data typePurposeHandling
Email address Account registration & login identifier, LLM free-trial quota billing (default 100 calls/account) Stored on api.polang.net; only the email and the SHA-256 hash of the login token are kept; no plaintext password is collected (verification-code login)

1.5 Device Identifier (Guest Trial Quota)

Data typePurposeHandling
Device identifier (Android device ID / locally generated ID) LLM free-trial call counting for unregistered guests Sent to api.polang.net; only call counts are tallied by identifier; not used to identify individuals, not shared with third parties. Deletable in Settings → Data & Privacy → Clear guest data

2. App Permissions

PoLang requests the following Android system permissions, each tied directly to a specific feature:

Permission Level Purpose Required
CAMERA Dangerous Camera preview, capture, recording Yes (core feature)
RECORD_AUDIO Dangerous Voice command recording, video audio No (voice optional)
READ_MEDIA_IMAGES Dangerous Read gallery images for organizing, search and editing Yes (gallery core)
READ_MEDIA_VIDEO Dangerous Read gallery videos for organizing and playback Yes (gallery core)
ACCESS_MEDIA_LOCATION Dangerous Read photo EXIF location for place grouping and place search (local only, never uploaded) No (place features optional)
MANAGE_MEDIA Dangerous "No more delete prompts" switch (off by default): when enabled, delete/trash actions skip system confirmation; items still go to the system recycle bin and can be restored No (off by default, requires manual grant)
READ_EXTERNAL_STORAGE Dangerous Read gallery on Android 12 and below No (gallery optional)
WRITE_EXTERNAL_STORAGE Dangerous Save photos on Android 9 and below No (legacy only)
BLUETOOTH_CONNECT Normal Connect Bluetooth accessories (e.g. shutter remote) No (accessory optional)
INTERNET Normal AI chat remote inference (text/metadata only, never photos or videos) No (media works offline; AI chat needs network)
ACCESS_NETWORK_STATE Normal Network status detection (e.g. silent model pre-download on WiFi only) Yes
POST_NOTIFICATIONS Normal Model download and gallery scan progress/completion notifications No (notifications optional)
FOREGROUND_SERVICE Normal Background model download service Yes (model download)
FOREGROUND_SERVICE_DATA_SYNC Normal Gallery tagging scan foreground service (data sync type, all processing on-device) Yes (tagging scan)
SCHEDULE_EXACT_ALARM Normal Scheduled dispatch for idle-time automatic scanning No (auto scan optional)
WAKE_LOCK Normal Keep CPU awake during scan/download to prevent task interruption Yes (background tasks)
SYSTEM_ALERT_WINDOW Dangerous Floating chat bubble (AI assistant entry over other apps, off by default) No (floating bubble optional, requires manual grant)
REQUEST_IGNORE_BATTERY_OPTIMIZATIONS Normal Background scan keep-alive (request battery optimization whitelist, not requested by default) No (optional, requires manual grant)

3. How We Process Data

3.1 On-Device First Principle

PoLang's core architecture follows the On-Device First principle:

3.2 Privacy-Tier Guard

PoLang has a built-in PrivacyGuard tiering system that automatically classifies and routes each command:

Tier Data type Policy
RESTRICTED Coordinates, face data Forced local execution; network transfer never allowed
SENSITIVE Photos, OCR content Forced local execution; network transfer never allowed
PUBLIC Camera control commands (e.g. "take a photo") Local-first; user may opt into remote orchestration

3.3 AI Chat Inference (Remote)

AI chat and command parsing run on a remote large language model (DeepSeek / Tongyi and other OpenAI-compatible endpoints) and require a network connection:

4. Data Storage & Retention

4.1 Photos & Videos

4.2 Conversation Memory

4.3 Model Files

4.4 Account Data Retention

5. Data Sharing & Third Parties

Important: PoLang never sells, rents, or shares any of your data with third parties.

Third-party open-source components used by PoLang and how they handle data:

Component Purpose Handling
MediaPipe Face landmark detection Fully local, no network communication
MNN Neural-network inference engine Fully local, no network communication
ML Kit OCR text recognition Fully local, no network communication
Sherpa-ONNX Speech recognition (ASR) Fully local, no network communication

6. Your Rights

As a PoLang user, you have the following rights:

7. Children's Privacy

PoLang is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we may have collected a child's information, contact us and we will delete it promptly.

8. Security Measures

PoLang takes the following technical and organizational measures to protect your data:

9. Policy Updates

We may update this privacy policy from time to time. Material changes will be announced via in-app notice or the changelog. Continued use of PoLang constitutes acceptance of the revised policy.

10. Contact Us

If you have any questions or suggestions about this privacy policy, reach us at: