TOOOONY

Privacy Policy

Last updated: 7/31/2026

Welcome to TOOOONY services. This Privacy Policy explains how we collect, use, store, and protect your personal information.

Important Notice: We strictly follow the principle of "minimum necessary". Before you read and agree to this Privacy Policy, neither this app nor any integrated third-party SDK will collect your personal information or sensitive device data. We will only begin collecting information for the purposes, in the manner, and within the scope described in this Policy after you have explicitly agreed to it.

1. Information Collection

1.1 Information You Provide

  • Account information (username, email, phone number)
  • Content and data you upload when using our services
  • Feedback and opinions when communicating with our support

1.2 Automatically Collected Information

After you agree to this Privacy Policy, we collect information for the following purposes, via the following methods, and within the following scope:

  • Device and app information: device brand, model, manufacturer, OS version, app version, and a random client device ID generated and stored locally by the app. The Google Play version does not collect non-resettable persistent device identifiers such as IMEI, IMSI, SIM serial number, or MAC address, and does not link such identifiers with personal and sensitive user data or resettable advertising identifiers.
  • Log information: IP address, access time, pages visited, API results, crash logs
  • Location information, only with your separate permission, for GPS watch faces, weather, altitude display, nearby device discovery, or Bluetooth scanning compatibility on Android versions below 12; we do not continuously track your location in the background.
  • Camera, microphone, and screen-sharing data, only when you actively use QR scanning, image capture/selection, audio recording, remote control, or screen-casting features and grant the relevant permission.
  • Bluetooth scan results, only when you use device discovery, binding, connection, or near-field control features and grant the relevant permission.
  • Installed app list: the Google Play version does not read or upload a full installed app list; it only checks whether a related app or system capability is available when you actively start external payment, sharing, file opening, or policy-compliant security checks.
  • Contacts / SMS: we do not read your contacts or SMS content. SMS verification codes are sent by our server and may be entered manually; if your system provides verification-code autofill, that process is handled by the operating system and the app does not read your SMS inbox.
  • Cookies and similar technologies

1A. Third-Party SDKs

Third-party SDKs integrated in the app are initialized and begin collecting information only after you agree to this Privacy Policy.

SDKProvider / PurposeInformation CollectedTrigger
Flutter plugin libraries (e.g. device_info_plus)Flutter official / device identification and compatibility adaptationDevice brand, model, manufacturer, OS version, and random client device IDAfter user consent
Bluetooth, location, QR scanning, recording, image selection, and remote-connection feature pluginsDevice connection, GPS watch faces, weather/altitude display, QR scanning, media upload, audio recording, and remote controlBluetooth scan results, location information, camera frames, microphone audio, user-selected images or files, and remote-connection session dataOnly when the user actively uses the corresponding feature and grants permission
Payment and in-app purchase pluginsGoogle Play Billing, Apple StoreKit, or applicable third-party payment SDKsOrder number, product information, transaction status, and necessary payment-channel result dataOnly when the user purchases, pays, restores purchases, or checks an order

2. Information Use

  • Provide, maintain and improve our services
  • Send service notifications, updates and marketing information
  • Respond to your inquiries and requests
  • Conduct data analysis and user research
  • Protect service security and prevent fraud
  • Comply with legal and regulatory requirements

3. Data Retention and Deletion

We do not retain user data permanently. Unless a longer period is required by law, regulation, or security audit obligations, we retain and delete data as follows:

  • Account profile data: retained while your account remains active; after you delete your account or request deletion of account data, we will delete or anonymize the relevant personal information within 15 business days.
  • Content and service data you upload: retained while you use the relevant feature; after you delete the content, delete your account, or request deletion, we will delete or anonymize it within 15 business days.
  • Device information, crash logs, access logs, and security logs: used only for troubleshooting, service security, fraud prevention, and audit purposes, and normally retained for no more than 180 days before deletion or anonymization.
  • Customer support, complaint, and handling records: normally retained for no more than 3 years to process your requests and meet compliance obligations, unless a longer period is required by law.
  • Payment, order, invoice, and transaction records: where a transaction feature is involved, retained for the period required by tax, accounting, consumer protection, or other applicable laws.
  • Data read temporarily on device: location, Bluetooth scan results, camera, microphone, screen sharing, user-selected images or files, and similar data are read only when you authorize and use the corresponding feature; if they are not uploaded to our servers, we do not store or retain them on our servers.
  • Backup data: to maintain service continuity, residual copies in backup systems will be cleared or overwritten within a rolling backup cycle of no more than 90 days after a deletion request is completed.

Deletion Policy: You may request access, correction, deletion of personal information, or account deletion through the account or privacy settings in the app, the Account and Data Deletion page, or by emailing support@toooony.cn. After an account deletion request is submitted, the account enters a 15-day cooling-off period. If the request is not canceled when the cooling-off period ends, we will delete the personal information associated with the account. If we need to retain certain information for legal compliance, security, fraud prevention, or dispute resolution, we will retain only the necessary data and delete or anonymize it after the retention purpose is fulfilled.

4. Your Rights

  • Access: View the personal information we hold about you
  • Correction: Request correction of inaccurate information
  • Deletion: Request deletion of your personal information
  • Withdraw Consent: Withdraw previously given consent at any time

5. Contact Us

  • Email: support@toooony.cn
  • Address: China

© 2025 Toooony. All rights reserved.