LUMISTAR App隐私政策

更新日期:【2026年4月14日】
生效日期:【2026年4月14日】
适用主体:皓翊星辰(上海)机器人科技有限责任公司及其关联公司(以下简称“我们”或“LUMISTAR”) **适用产品与服务:**LUMISTAR App 及配套硬件与云服务(含:网球发球机、篮球发球机、视觉/AI 分析设备与服务、社区与排行榜、场馆/教练预约与线上课程、电商与订单、第三方地图/健康/登录集成、蓝牙/Wi‑Fi 配网、固件 OTA 等)。
LUMISTAR 深知个人信息对您的重要性。我们将依据适用法律与行业最佳实践,以合法、正当、最小必要为原则处理您的个人信息。为便于理解,我们对与您权益密切相关的条款以加粗形式提示。
当您点击同意开始使用或以其他方式确认本政策时,即表示您已阅读并同意本政策全部内容;若您不同意,请立即停止使用我们的产品/服务。

目录

  1. 我们如何收集与使用个人信息
  2. Cookie/本地存储与同类技术
  3. 我们如何委托处理、共享、转让与公开披露个人信息
  4. 个人信息的存储地点、期限与跨境传输
  5. 我们如何保护您的个人信息
  6. 您的权利及其行使(访问、更正、删除、限制/拒绝处理、撤回同意、数据可携、账号注销、自动化决策相关权利)
  7. 未成年人个人信息保护
  8. 第三方网站/服务链接
  9. 本政策的更新与通知
  10. 如何联系我们
  11. 术语与定义
  12. 附件 A:个人信息收集清单(按功能场景)
  13. 附件 B:第三方信息共享清单(SDK/合作伙伴)
  14. 附件 C:权限使用与调用场景(iOS/Android)
  15. 附件 D:数据留存与删除策略矩阵
  16. 附件 E:数据主体请求模板(访问/删除/可携/撤回)

  1. 我们如何收集与使用个人信息

1.1 处理原则

我们坚持合法、正当、透明,遵循明确目的、最小必要、确保安全的原则,仅为实现本政策所述目的处理与您相关的个人信息。如欲将信息用于未载明的新目的,我们将再次征求您的明示同意

1.2 账号注册与登录

  • 信息类型:手机号/邮箱、验证码;第三方登录(微信(如启用))的账号标识;密码(加密存储);昵称、头像(可选)。
  • 处理目的:创建与验证身份、登录安全、找回密码、账户安全审计与客服支持。
  • 法律依据:履行合约或合约前措施;为保障账号与平台安全之必要。根据法律法规要求,您在发布信息(如社区评论)前,我们需要对您的手机号进行验证以完成实名认证。

1.3 设备绑定、蓝牙/Wi‑Fi 配网与控制

  • 信息类型:蓝牙扫描信息(设备名、MAC/随机标识、信号强度)、设备 SN/UUID、固件与硬件版本、网络配置信息(仅用于将设备接入网络)、设备状态(电量/温度/料仓/故障码)、遥控指令与操作日志(含急停)、OTA 升级记录。
  • 处理目的:连接/配对与控制发球机/配件、提升稳定性、远程诊断与售后、固件升级与安全告警。
  • 法律依据:履行合约之必要;保障设备/服务安全之必要;合法权益(安全与质量)。

1.4 训练参数、实时数据与训练报告

  • 信息类型:您设定的训练模式与参数(速度/旋转/频率/球数/NTRP 等)、训练过程产生的时序指标与事件日志、热力与落点数据(如由视觉/传感器生成)、训练结果与可分享海报
  • 处理目的:实现训练功能、生成报告、历史统计与对比;您自愿分享时用于社区展示。
  • 法律依据:履行合约之必要;分享/公开展示基于您的选择同意

1.5 视觉/AI 动作分析(可选)

  • 信息类型:相机/相册/麦克风权限;您上传或录制的视频/音频(可能包含面部图像、身体姿态与背景环境)将在App内授权后,由模型产生的关键点/姿态轨迹、评分与建议;设备/网络状态用于故障排查。
  • 处理目的:为实现AI动作分析和个性化训练报告功能,我们需要调用您的摄像头权限并收集您的运动视频。该过程中可能涉及您的面部特征、体态特征等敏感个人信息。我们将仅在您开启该功能并给予单独同意后进行处理。相关数据将在分析完成后按约定存储,仅保留经去标识化处理后的分析报告数据。
  • 法律依据:您的明示同意;您可随时撤回,不影响撤回前的处理。

1.6 地图与定位(可选)

  • 信息类型:粗略或精确定位、IP 派生城市、定位相关设备标识;可能包含后台定位(仅当您在系统层授权且确为实现功能所需)。
  • 处理目的:约场、附近活动与“约球”地图、排行榜的距离排序、路线与到店导航。
  • 法律依据:您的明示同意(系统弹窗授予)。

1.7 健康与运动数据对接(可选)

  • 信息类型:来自 Apple 健康/华为健康等平台的步数、心率、卡路里、运动时长等(以您授权的具体范围为准)。
  • 处理目的:运动统计与趋势、排行榜(自愿开启)、个性化训练建议。
  • 法律依据:您的单独同意;您可在系统/平台侧随时撤回授权。

1.8 社区与互动(可选)

  • 信息类型:您发布的笔记/图片/视频、评论/点赞/收藏、话题与地理标签(如您主动添加)、UGC 元信息;违规处置/侵权投诉相关记录。
  • 处理目的:内容发布与展示、互动交流、社区治理与秩序维护。
  • 法律依据:履行合约之必要;遵守法律义务(处理侵权与违法内容)。

1.9 通知与客服

  • 信息类型:推送 Token、设备与系统消息类别、站内信、客服工单记录、通话录音(在法律允许且提示后)。
  • 处理目的:设备状态/报告完成/活动提醒、服务联络与质量跟踪。
  • 法律依据:履行合约之必要;对营销/活动类通知基于您的同意(可在设置中管理)。

1.10 日志、风控与合规

  • 信息类型:崩溃日志、性能指标、异常行为日志、反作弊与防滥用模型产生的标记(不用于对您作出不利的自动化决策)。
  • 处理目的:安全与防欺诈、稳定性改进、合规审计与争议举证。
  • 法律依据:合法权益(安全与质量);遵守法律义务。

1.11 自动化决策/画像(如适用)

为提供AI 推荐、训练参数建议、异常检测等,我们可能基于您的设备与训练数据进行自动化处理或有限画像您有权要求人工复核、表达意见、拒绝仅以自动化决策产生的结果。

  1. Cookie/本地存储与同类技术

为保持登录、存储偏好、统计性能与防欺诈,我们可能使用 CookieLocal Storage、Web Beacon、设备标识等。您可在系统中管理或拒绝;若拒绝,部分功能可能受限。

  1. 我们如何委托处理、共享、转让与公开披露个人信息

3.1 委托处理

为实现短信验证、云存储、内容审核、统计/崩溃分析、推送、在线课程/直播、支付结算、地图定位、健康数据对接、客服工单等,我们可能委托合作伙伴处理相关数据,并通过合同约定处理目的、范围、期限、安全措施与删除/返还义务;我们将对受托方实施安全评估与监督审计。

3.2 共享

我们不会出售您的个人信息。仅在以下必要情形,我们才共享最小化后的个人信息:
  • 关联公司协同提供或改进服务(仅为实现本政策所述目的);
  • 第三方合作伙伴(含 SDK):地图、推送、统计/崩溃、短信与本机号登录、视频与直播、云存储、支付、第三方登录、健康平台对接等(关于我们与之共享数据的第三方SDK及合作伙伴的具体名称、联系方式及处理类型,请务必查阅《附件B:第三方信息共享清单》。该清单为本政策不可分割的一部分);
  • 法律法规、诉讼/仲裁或监管部门依法提出要求;
  • 为保护您、我们或公众的生命财产安全而在紧急情况下需要共享的。
在共享前,我们将进行个人信息影响评估,并与接收方签署数据保护协议或要求其以政策不低于本政策的标准保护您的信息。

3.3 转让

我们不转让您的个人信息,除非获得您的明确同意,或在合并、分立、重组、资产/业务转让或破产清算等涉及个人信息转移时,我们将告知您接收方信息并要求其继续受本政策约束;如接收方变更处理目的或方式,我们将重新征求您的授权同意。

3.4 公开披露

仅在取得您的单独同意或法律/行政司法机关依法要求的情形下公开披露;对经匿名化处理的统计信息,我们可能出于研究或政策披露而公开,但无法识别到个人。

3.5 例外情形

法律另有规定或为履行法定义务、公共卫生事件、学术研究或统计(且去标识化/匿名化处理)等情形下,可不再事先征得授权同意(以法律为准)。

  1. 个人信息的存储地点、期限与跨境传输

  • 存储地点:数据将按业务发生地就近存储;中国大陆用户数据原则上在境内存储。如需跨境提供,我们将单独征得您的授权同意并依适用法实施安全评估/标准合同等措施。
  • 存储期限:基于最短必要原则(详见附件 D)。如法律另有规定,则按法定最长期限保存。
  • 跨境传输:因全球化服务、容灾备援或境外供应链(如云存储/推送/统计)的需要而进行跨境传输时,我们将开展个人信息跨境影响评估并落实合同与技术保护措施,确保接收方提供不低于本政策的保护水平。

  1. 我们如何保护您的个人信息

  • 技术与组织措施:传输与存储加密(如 TLS、HTTPS、加密密钥管理)、权限分级与最小授权、零信任访问、双人复核、访问与操作审计、入侵防御与漏洞管理、代码安全/第三方依赖审计、数据脱敏与去标识化、定期渗透测试与应急演练、多活备份与灾备。
  • 安全事件处置:一旦发生或可能发生个人信息安全事件,我们将按法律规定及时通知您事件事实、可能影响、已采取措施与自救建议,并按要求上报监管;在合理与可能范围内,我们将采取补救措施以降低风险。

  1. 您的权利及其行使

在适用法律允许范围内,您有权:访问、复制、更正、补充、删除、限制或拒绝处理、撤回同意、数据可携带、账号注销以及与自动化决策相关的权利。我们通常会在完成身份验证后20 个工作日内回复(特殊情况下不超过 30 天或法律规定期限)。

6.1 自助路径

  • 数据与权限中心:App 内路径 “我的 > 设置 > 隐私与安全” 提供权限管理、数据导出/删除;
  • 账号注销“我的 > 账户与安全 > 注销账号”
  • 健康/定位/相机等系统权限:可在设备系统设置中随时管理。

6.2 行使渠道

若您无法通过自助入口完成,请发送请求至 privacy@lumistar.ai或通过 App「帮助与反馈」提交。我们可能为验证身份与保障他人权益,要求您提供必要的信息或进行操作验证。

6.3 例外与拒绝情形

涉及国家安全/国防、公共安全、犯罪侦查/起诉/审判、履行法定义务、出于维护他人重大合法权益、存在主观恶意或滥用权利、响应将导致他人或商业秘密受损等情形,我们可能依法不予响应,并向您说明理由(法律禁止说明的除外)。
如用户不幸去世,其近亲属为了自身的合法、正当利益,可以对死者的相关个人信息行使查阅、复制、更正、删除等;死者生前另有安排的除外。

6.4 自动化决策相关权利

对基于自动化处理的个性化推荐与评分,您可要求解释拒绝仅以自动化决策为依据作出的决定(法律允许的例外除外),或选择关闭部分个性化功能。

  1. 未成年人个人信息保护

7.1 我们非常重视对未成年人信息的保护。若您是18周岁以下的未成年人,应在监护人监护、指导下阅读本政策并使用服务。
7.2 特别地,若您是14周岁以下的儿童,您应当由您的监护人注册账号并陪同使用。在收集儿童个人信息前,我们会通过弹窗等方式征得监护人的明示同意。我们将按照《儿童个人信息网络保护规则》采取严格的保护措施。对于经监护人同意而收集的儿童个人信息,我们仅在法律允许、监护人明确同意或保护儿童所必要的情况下使用或公开披露。
7.3 若我们发现未能在获得监护人同意的情况下收集了儿童个人信息,我们会设法尽快删除相关数据。
7.4 若您是监护人,当您对您所监护的未成年人的个人信息有相关疑问时,请通过第10条中的联系方式与我们联系。

  1. 第三方网站/服务链接

App 内可能包含第三方网站或服务的链接或 SDK(如地图、支付、登录、健康平台、视频/直播等)。您使用第三方服务时,还应遵守其隐私政策与服务条款;第三方对其服务独立负责。

  1. 本政策的更新与通知

我们可能根据业务、法律或技术变化更新本政策。对于重大变更(如处理目的/类型/共享对象/权利行使方式发生重大变化、所有权结构变化、数据出境机制变化等),我们将通过 App 内显著位置、弹窗或站内信进行通知。除法律另有规定或为履行法定义务外,变更不会削减您依据本政策享有的权利。

  1. 如何联系我们

  • 数据保护邮箱privacy@lumistar.ai
  • 客服电话:400-8585-168(工作日 9:00–18:00)
  • 通信地址:皓翊星辰(上海)机器人科技有限责任公司
上海市松江区中辰路299号1幢340室 我们设有数据保护负责人/团队处理您的隐私请求与投诉,并在法定时限内予以回复与处置。

  1. 术语与定义

  • 个人信息:以电子或其他方式记录的与已识别或可识别个人有关的各种信息,不包括匿名化处理后的信息。
  • 敏感个人信息:一旦泄露或被非法使用,容易导致个人尊严受侵害或人身/财产安全受危害的信息(如精确定位、健康生理数据、未成年人信息、面部图像等)。
  • 去标识化/匿名化:去标识化是通过技术处理使信息主体不可直接识别;匿名化是使信息不可再复原至特定个人的不可逆过程。

附件 A:个人信息收集清单(按功能场景)

为帮助您更清晰地了解我们在各项功能中处理您个人信息的情况,根据《中华人民共和国个人信息保护法》及相关国家标准的要求,我们特制定本按功能场景划分的个人信息收集清单。
核心原则:我们将遵循合法、正当、必要和诚信的原则,仅处理实现产品功能所必要的最小范围的个人信息。本清单未涵盖的场景,我们不会主动收集您的个人信息。
1. 账户注册与登录
收集场景
个人信息类型
收集目的
处理方式
是否为必要信息
存储期限
本机号码一键登录
手机号码、设备识别码(IMEI/IMSI)、网络IP地址
验证您的身份,为您创建账户并登录
通过运营商(移动/联通/电信)网关验证后,于本地完成登录
在您使用账户期间持续存储,您注销账户后我们将依法删除。
短信验证码登录
手机号码
向您发送动态验证码,验证身份并登录
通过合作的短信服务商发送短信
验证码即时失效。手机号码在您使用账户期间存储。
微信/Apple ID登录
第三方平台提供的唯一标识、昵称、头像(仅微信,且需您授权)
关联第三方账户,为您快捷创建或登录本地账户
从微信/Apple获取授权,于本地关联账户
唯一标识在您使用账户期间存储。昵称、头像仅用于初次完善资料。
密码登录
手机号码、密码(加密存储)
验证账户密码,完成登录
本地验证加密后的密码
密码为不可逆加密存储。
找回密码
手机号码、新密码(加密存储)
验证身份,重置账户密码
通过短信验证身份后,在本地重置密码
新密码为不可逆加密存储。
2. 设备连接与训练
添加与连接设备
设备标识码(蓝牙MAC地址、设备SN)、Wi-Fi名称(SSID)、设备位置权限(蓝牙扫描)
发现、配对和连接您的智能发球机或配件
通过手机蓝牙和Wi-Fi模块本地完成
设备标识码在您绑定期间存储,解绑后删除。Wi-Fi信息仅用于配网,不存储。
进行发球机训练
训练参数设置(如速度、落点)、训练时长、击球数量、设备状态数据
控制发球机工作,生成您的个人训练记录
通过App设置并发送指令至设备,训练记录保存在您的账户下
训练记录将长期存储,用于生成您的运动报告,您可手动删除。
生成与分享训练报告
训练数据总结、您选择生成的海报图片
为您可视化分析训练成果,并支持您将海报分享至社区
基于您的训练数据在本地生成报告和海报
生成报告是,分享社区否
报告在您账户下存储。分享至社区的内容将按社区规则公开。
2. 社区互动
收集场景
个人信息类型
收集目的
处理方式
是否为必要信息
存储期限
发布笔记/动态
用户上传的图文或视频内容、定位信息(需您授权)、添加的心情与标签
供您在社区分享训练心得、约球信息
内容经您确认后发布至社区公开或对选定好友可见
发布内容是,定位否
您发布的内容将保存在社区,您可随时编辑或删除。
浏览与互动
浏览记录、点赞、收藏、评论内容
为您推荐感兴趣的内容,记录您的互动偏好
记录您的操作以优化内容推荐
浏览记录短期存储,互动记录长期存储直至您删除。
私信交流
与球友、教练的聊天记录
为您提供站内沟通工具
通过即时通信服务加密传输和存储
聊天记录在您账户下存储,您可清空对话。
使用“约球”地图
您的位置信息(需您授权,地图/列表模式可选)
为您展示附近的球友和场馆
获取位置后用于地图展示,不持续后台追踪
单次会话期间使用,不持久化存储精确位置
参与排行榜
运动数据(如累计训练时长、击球次数、跑动距离、正反手数量、Deep shots in等)
根据您的运动成绩生成个人及全局排名,提供激励和参照
在您明确同意并开启“同步到排行榜”后,系统将您选定周期的运动数据用于排名计算
否(您可选择是否同步)
在排行榜展示周期内存储(如日榜、月榜),您关闭同步后,数据将从后续排名中移除。
查看排行榜
您浏览其他用户的排名、昵称、头像及简要数据
供您了解社区内其他用户的运动水平
系统向所有用户公开展示去标识化(仅展示昵称和头像)的排行榜单
浏览功能是,他人信息由他人授权公开
他人信息存储遵循其个人设置。
分享我的参数
您自定义或保存的训练参数组合(如“我的专项”、“我的组合”,包含速度、旋转、落点、频率等设置)
允许您将自己的训练方案生成二维码或上传至参数排行榜,供其他用户学习使用
经您主动操作后,您选择的参数组合会被系统生成可分享的二维码或列入公开的“参数排行榜”
否(由您主动分享)
被分享的参数会一直公开,直至您在本功能内删除该分享。
导入他人参数
您扫描他人分享的参数二维码,或从参数排行榜中选择
让您能够快速使用其他用户或明星推荐的训练方案
您扫描二维码或点击“一键导入”后,参数将保存至您的“自定义训练”列表中
是(实现导入功能所必需)
导入的参数作为您的个人设置保存在您的账户中。
4. AI分析与智能剪辑
收集场景
个人信息类型
收集目的
处理方式
是否为必要信息
存储期限
上传视频进行AI分析
您上传的训练或比赛视频
为您提供动作分析、生成运动报告或精彩集锦
视频上传至云端进行AI算法分析,生成结构化报告
原始视频在分析完成后默认删除,仅保留生成的报告数据,您可选择保存视频。
使用语音控制设备
设备录制的语音指令(仅在您唤醒后)
识别您的语音命令以控制发球机
在设备端或本地进行语音识别,指令文本上传执行,不保存录音
语音录音实时处理后不存储。
精彩瞬间剪辑
您上传的原始比赛或训练视频、视频元数据(时长、分辨率等)
通过AI自动识别并剪辑出视频中的精彩回合(如多拍对拉、制胜球等),为您生成短视频集锦
1.上传:您手动选择并上传视频至云端处理队列。 2. 分析:AI算法分析视频内容,识别精彩片段边界。 3. 生成:自动合成剪辑视频,并添加可选的特效或标签。 4. 交付:将生成的精彩瞬间视频返回给您预览和保存。
是(实现核心剪辑功能所必需)
1. 原始视频:云端处理完成后默认在7天内自动删除,除非您手动勾选“保留原片”。 2. 精彩瞬间视频:生成后保存在您的账户下,您可以永久保留或随时删除。 3. 控制权:您对每一步(上传、生成、保存、删除)拥有完全控制权。
5. 个人中心与系统安全
收集场景
个人信息类型
收集目的
处理方式
是否为必要信息
存储期限
完善个人资料
头像、昵称、球龄、个人简介、运动水平等
个性化展示您的社区形象,为您推荐匹配的球友或内容
由您在个人资料页主动填写和上传
头像昵称是,其他否
在您使用账户期间存储,您可随时修改。
意见反馈与客服
您的联系方式(手机/邮箱)、反馈内容、设备日志(可选上传)
联系您并解决您遇到的问题
用于客服人员与您沟通,设备日志仅用于技术排查
沟通记录保存至问题关闭后一段合理时间。
App稳定运行与安全风控
设备信息(型号、系统版本)、应用日志、操作日志、网络IP地址
保障App稳定运行,排查崩溃原因,防范安全风险
自动化收集与分析
应用日志短期存储,安全日志依法保存一定期限。

重要说明:
  1. 共享原则:我们仅共享实现功能所必要的信息,且与合作伙伴签署数据保护协议,要求其依法保护用户信息。
  2. 用户授权:在首次使用涉及共享信息的功能前,我们会通过弹窗或协议方式征得用户同意。
  3. 用户权利:您可通过“我的-设置-账号与安全”查看和管理授权情况,或通过客服联系我们撤回授权。
  4. 政策更新:本清单可能随业务调整而更新,更新后的版本将在App内发布并通知用户。

附件 B:第三方信息共享清单(SDK/合作伙伴)

为保障App功能的正常运行、提升用户体验、实现特定服务目的,我们可能会与第三方服务商共享部分必要的信息。本清单列出了App当前集成或可能调用的第三方SDK及合作伙伴信息,包括其收集的个人信息类型、使用目的及官方隐私政策链接。
中国大陆
第三方公司名称
产品/类型
共享信息名称
使用目的
使用场景
共享方式
第三方个人信息处理规则
深圳市腾讯计算机系统有限公司
应用宝SDK(腾讯YSDK)
QQ账号、手机号码、身份证号码、IP地址、AndroidID、设备型号、Wi-Fi参数等
开发者注册与登录支付,实名认证,保障账户安全,实现风险控制
用户通过应用宝渠道登录、支付或进行实名认证时
SDK集成
华为终端有限公司 / 华为软件技术有限公司
华为推送 SDK
应用基本信息(AppID、包名)、设备标识符(AAID、Push Token)、设备型号、系统版本、国家码等
向华为手机用户推送消息
向华为设备用户推送任何系统或活动通知时
SDK本机采集
北京小米移动软件有限公司
小米推送 SDK
设备标识(OAID、Android ID)、应用信息(包名、版本号)、设备信息(厂商、型号、归属地)、网络类型等
向小米手机用户推送消息
向小米设备用户推送任何系统或活动通知时
SDK本机采集
中国移动通信集团有限公司
移动认证 SDK
手机号码、设备标识符、网络状态
实现本机号码一键登录
选择"本机号码一键登录"时
SDK集成
中国联合网络通信集团有限公司
联通认证 SDK
手机号码、设备标识符、网络状态
实现本机号码一键登录
选择"本机号码一键登录"时
SDK集成
中国电信集团有限公司
电信认证 SDK
手机号码、设备标识符、网络状态
实现本机号码一键登录
选择"本机号码一键登录"时
SDK集成
深圳市腾讯计算机系统有限公司
微信开放平台 SDK
设备标识符、微信账号信息
支持微信快捷登录
用户选择微信登录时
SDK集成
Apple Inc.
Apple登录 SDK
设备标识符、Apple账号信息(可选提供邮箱)
支持Apple账号登录
用户选择Apple账号登录时
SDK集成
上海咏韵网络科技有限公司(短信宝)
短信宝 SDK/API
手机号码、验证码内容、发送状态
发送手机短信验证码
用户通过短信注册、登录或找回密码时
API接口调用
深圳市腾讯计算机系统有限公司
腾讯云即时通信 IM SDK
设备标识符、用户ID、消息内容、网络状态
提供站内私信功能
用户发送和接收站内私信时
SDK集成
深圳市和讯华谷信息技术有限公司
极光推送 SDK
设备标识符、推送记录、网络状态
实现消息推送服务
向用户推送系统消息、私信通知时
SDK集成
高德软件有限公司
高德地图 SDK
设备标识符、位置信息、网络状态
提供地图定位、场馆导航功能
用户查看附近场馆、使用约球地图功能时
SDK集成
上海七牛信息技术有限公司
七牛云对象存储 SDK
设备标识符、上传的文件(图片/视频)
提供用户内容(如图片、视频)的存储与分发服务
用户上传头像、发布社区图片/视频、上传训练视频时
SDK集成
友盟同欣(北京)科技有限公司、北京锐讯灵通科技有限公司
友盟统计 SDK
设备信息、网络信息、地理位置、读取存储(相册、媒体和其他文件)权限
统计分析用户行为,优化产品功能
收集用户使用App各功能的数据以进行分析
SDK本机采集
深圳市腾讯计算机系统有限公司
腾讯Bugly SDK
设备标识符、日志信息、异常堆栈
收集App崩溃日志,提升稳定性
监控App运行状态,收集崩溃信息以便修复
SDK本机采集
Amazon Web Services, Inc.
AWS S3 SDK
设备标识符、上传的文件(图片/视频)
提供用户内容(如图片、视频)的存储服务
用户上传头像、发布社区图片/视频时
SDK集成
EU
第三方公司名称
产品/类型
共享信息名称
使用目的
使用场景
共享方式
第三方个人信息处理规则
Google LLC
Google登录 SDK
设备标识符、Google账号信息、邮箱
支持Google账号登录
用户选择Google账号登录时
SDK集成
Apple Inc.
Apple登录 SDK
设备标识符、Apple账号标识、邮箱(可选)
支持Apple账号登录
用户选择Apple账号登录时
SDK集成
Tencent Cloud Europe B.V.
腾讯云即时通信 IM SDK (国际版)
设备标识符、用户ID、聊天内容
提供App内私信功能
用户与球友、教练发送站内私信时
SDK集成
Aurora Mobile Limited
JPush SDK (国际版)
设备标识符、推送令牌
实现消息推送服务
向用户推送私信提醒、活动通知时
SDK集成
Google LLC
Google Maps SDK
设备标识符、位置信息
提供地图与定位服务
用户使用“约球”地图、搜索场馆时
SDK集成
Adjust GmbH
Adjust SDK
设备标识符、广告标识符(IDFA)、应用内事件
统计分析用户行为,衡量广告效果
从用户安装App起,全程记录匿名化行为数据
SDK集成
Google LLC
Firebase Crashlytics SDK
设备标识符、崩溃日志、堆栈跟踪
收集崩溃信息,监控应用稳定性
App发生崩溃或非预期错误时
SDK集成
Alibaba Cloud (阿里云)
对象存储 OSS SDK
用户上传的文件(图片/视频),默认存储在德国(法兰克福) 地域。
提供用户生成内容(UGC)的存储服务
用户上传头像、发布社区图片/视频、上传训练视频时
SDK集成
Amazon Web Services, Inc.
AWS S3 SDK
用户上传的文件(图片/视频)
提供核心数据存储服务
用户上传训练视频等大型文件时
SDK集成
US
第三方公司名称
产品/类型
共享信息名称
使用目的
使用场景
共享方式
第三方个人信息处理规则
Google LLC
Google登录 SDK
设备标识符、Google账号信息、邮箱
支持Google账号登录
用户选择Google账号登录时
SDK集成
Apple Inc.
Apple登录 SDK
设备标识符、Apple账号标识、邮箱(可选)
支持Apple账号登录
用户选择Apple账号登录时
SDK集成
Tencent Cloud Europe B.V.
腾讯云即时通信 IM SDK (国际版)
设备标识符、用户ID、聊天内容
提供App内私信功能
用户与球友、教练发送站内私信时
SDK集成
Aurora Mobile Limited
JPush SDK (国际版)
设备标识符、推送令牌
实现消息推送服务
向用户推送私信提醒、活动通知时
SDK集成
Google LLC
Google Maps SDK
设备标识符、位置信息
提供地图与定位服务
用户使用“约球”地图、搜索场馆时
SDK集成
Adjust GmbH
Adjust SDK
设备标识符、广告标识符(IDFA)、应用内事件
统计分析用户行为,衡量广告效果
从用户安装App起,全程记录匿名化行为数据
SDK集成
Google LLC
Firebase Crashlytics SDK
设备标识符、崩溃日志、堆栈跟踪
收集崩溃信息,监控应用稳定性
App发生崩溃或非预期错误时
SDK集成
Alibaba Cloud (阿里云)
对象存储 OSS SDK
用户上传的文件(图片/视频),默认存储在美国(硅谷/弗吉尼亚) 地域。
提供用户生成内容(UGC)的存储服务
用户上传头像、发布社区图片/视频、上传训练视频时
SDK集成
Amazon Web Services, Inc.
AWS S3 SDK
用户上传的文件(图片/视频)
提供核心数据存储服务
用户上传训练视频等大型文件时
SDK集成

附件 C:权限使用与调用场景(iOS/Android)

为保障本应用相关功能的实现与应用安全稳定运行,我们可能需要向您申请调用以下系统权限。请您知悉,我们不会默认开启这些权限,仅在您主动确认或在具体场景中根据提示开启后,才会在权限授权范围内处理您的信息。
权限名称
对应功能模块
调用场景与目的
平台差异与说明
是否为必要
蓝牙
设备连接与控制
1.扫描并连接智能发球机及配件。 2. 向已连接设备发送控制指令(如开始训练、调节参数)。
通用:在“设备”页点击添加或连接时申请。对于Android,可能需要位置权限才能扫描蓝牙设备,此为系统限制。
是(对于连接和控制实体设备的核心功能)
位置
约球地图、场馆导航、附近球友/场馆推荐
1.使用“约球”地图时:用于展示您周围的球场和球友,方便发起或响应约球。 2. 查找/导航去场馆时:用于规划路线、估算到达时间。 3. 发布动态时(可选):用于添加位置标签。
iOS:可能区分“使用App期间”或“精确位置”。 Android:可能区分“精确位置”或“大致位置”。 说明:我们仅在相关功能前台使用时申请,不会在后台持续追踪您的位置。
是(对于地图与约球核心功能)
相机
连接设备时扫码配对
扫描设备或参数二维码:用于快速添加设备或导入训练参数。
通用:当您点击扫码、拍照或上传按钮时触发申请。
是(设备扫码配对核心交互)
相册/照片
头像/图片/视频上传、分享、保存
1.上传已有照片或视频:用于发布社区动态、上传AI分析、设置头像。 2. 保存内容到本地:用于保存训练报告海报、精彩瞬间视频等。
iOS:“照片”权限。 Android:“相册”或“存储”权限。 说明:我们仅访问您主动选择的文件。
是(对于内容上传与保存功能)
无线局域网/Wi-Fi
设备配网
当您为支持Wi-Fi的发球机进行网络配置时,用于手机连接设备热点并传输家庭Wi-Fi信息。
通用:仅在设备配网流程中调用,不会收集其他Wi-Fi网络信息。
是(对于需联网设备的初始化设置)
通知
消息中心
接收训练报告完成、设备消息、社区互动(点赞、评论、私信)、活动提醒等推送。
通用:在App首次启动时会申请,您可在系统设置中随时关闭。
否(但不开启将无法接收任何应用内消息提醒)
应用列表(Android可能涉及)
第三方登录、分享
用于判断是否安装了微信等应用,以实现快速跳转登录或分享。
Android特有:部分系统或机型上,集成第三方SDK可能涉及此权限,用于功能可用性判断。
否(用于优化交互体验)
重要说明:
  1. 权限管理:您可以在设备的 【设置】>【隐私】>【权限管理】(或类似路径)中查看上述权限状态,并随时关闭或重新开启。关闭权限仅会影响对应功能,不会影响其他功能的使用。
  2. 权限与信息:部分权限本身不直接收集个人信息,但结合其他操作可能获取。例如,开启“相机”权限后,我们仅在您主动拍照时获取照片信息。
  3. 儿童隐私:我们非常重视对未成年人个人信息的保护。如果您是未满14周岁的儿童,请在您的父母或其他监护人的指导下使用我们的服务。
  4. 政策更新:本清单可能会随功能更新而调整。若有重大变更,我们会在应用内通过显著方式通知您。
如果您对特定权限的调用有疑问,或需要更详细的解释,请通过【我的】->【设置】->【帮助与反馈】联系我们。

附件 D:数据留存与删除策略矩阵

为保障您的信息权益,我们制定了严格的数据留存期限与删除规则。本矩阵明确了不同数据类型在实现特定目的后,将被保留的时限以及删除方式。
数据类别
典型数据内容
留存期限 / 删除触发条件
删除机制与说明
1. 账户与身份信息
手机号、第三方登录标识、加密存储的密码、昵称、头像。
留存至您注销账户之时。
您提交账户注销申请后,我们将启动删除流程,在15个工作日内完成对您账户核心身份信息的匿名化或永久删除。
2. 个人资料与设置
性别、生日、个人简介、NTRP水平、发球机设备列表、训练偏好参数。
留存至您删除或修改该信息,或注销账户之时。
您可随时在App内编辑或删除该信息,更改即时生效。注销账户时一并删除。
3. 用户生成内容与记录
训练记录
单次训练的详细数据(时长、球数、落点等)。
留存至您手动删除该记录,或注销账户之时。
您可在“训练报告”或“我的-动态”中随时删除单条训练记录。
社区内容
发布的笔记、评论、分享的图片/视频、私信聊天记录。
留存至您手动删除该内容,或注销账户之时。
您可随时删除自己发布的内容。私信记录双方删除后即不可见。注销账户后,您的社区内容将匿名化处理(显示为“已注销用户”)。
AI生成内容
AI动作分析报告、生成的“精彩瞬间”视频。
报告留存至您手动删除或注销账户。原始视频在云端处理后默认7天内删除。
您对AI生成报告有完全控制权。上传的原始视频为临时处理,系统将自动清理,除非您明确选择保留。
4. 操作与日志信息
设备日志
用于故障诊断的应用崩溃日志、性能数据。
不超过30天。
为保障应用稳定性,日志信息会在收集后30天内自动匿名化处理并删除可识别个人的部分。
您的权利与操作路径
  1. 您可以通过以下方式行使您的权利,访问、更正与删除::
    1. 在App内操作:对于个人资料、训练记录、社区内容等,您可以直接在【我的】、【训练报告】、【社区】等相关页面进行编辑或删除。
    2. 通过客服申请:对于无法直接操作删除的信息,或需要注销账户,您可以通过【我的】->【设置】->【帮助与反馈】联系我们,提出删除或注销请求。
本策略可能随产品功能与法律要求进行更新,更新后我们将通过App通知等方式告知您。

  1. LUMISTAR Privacy Policy(英文)

LUMISTAR Privacy Policy

Last Updated: 【YYYY-MM-DD】 Effective Date: 【YYYY-MM-DD】
Lumistar (Shanghai) Robotics Technology Co., Ltd. and/or its affiliates (hereinafter referred to as “we”, “us”, or “our”) is committed to protecting your privacy. This Privacy Policy (hereinafter referred to as this “Policy”) explains how we collect, use, process, and protect your personal information in connection with the LUMISTAR App, our smart sports hardware (e.g., Tennis/Basketball Ball Machines), and related cloud services.
Local-specific amendments referred to below also apply to consumers in those territories and may in some cases set out different standards due to applicable local laws, rules and regulations. If so, the local-specific amendment will govern in the event of a conflict.
In addition to this Policy, we may provide you with additional privacy notices that will apply to certain personal information collected and processed by us, and such notices prevail over this Policy to the extent of any conflict.
By clicking "Agree", registering an account, or using our Services, you acknowledge that you have read and understood this Policy.
General Provisions
  1. Personal Information We Collect
We collect information to provide you with a smart sports training experience. The specific data depends on the features you use:
  1. Account and Identity Information
  • Data: Email address, verification codes; third-party login IDs (e.g., Apple, Google, Facebook); password (encrypted); nickname, and avatar (optional).
  • Purpose: To create and verify your identity, ensure login security, recover passwords, and provide account security auditing and customer support.
  1. Device Binding, Network Configuration, and Control Information
  • Data:
    • Bluetooth Scanning Information: Device name, MAC address/random identifier, and Signal Strength (RSSI);
    • Device Identifiers: Device Serial Number (SN) and UUID;
    • Version Information: Firmware version and hardware version;
    • Network Configuration Information: Wi-Fi SSID and configuration data (collected solely for the purpose of connecting the device to the network);
    • Device Status: Battery level, temperature, ball hopper status, and error/fault codes;
    • Remote Control & Operation Logs: Remote control commands, operation logs (including emergency stop/E-stop events), and usage history;
    • Update Records: OTA (Over-The-Air) firmware update records.
  • Purpose: To connect/pair and control the ball machines/accessories, improve stability, perform remote diagnostics and after-sales support, and manage firmware upgrades and safety alarms.
  1. Training Parameters, Real-time Data, and Reports
  • Data: Training modes and parameters set by you (e.g., speed, spin, frequency, ball count, NTRP level), time-series metrics and event logs generated during training, heat maps and landing point data (e.g., generated by vision/sensors), and training results and shareable posters.
  • Purpose: To implement training functions, generate reports, and provide historical statistics and comparisons.
  1. Visual / AI Motion Analysis (Optional)
  • Data: Video/audio recordings uploaded or recorded by you (which may contain facial images, body postures, and background environment), key-points/skeleton data generated by models, posture trajectories, scores, and suggestions; and device/network status used for troubleshooting.
  • Purpose: To provide AI motion analysis and personalized training reports. (Note: This involves sensitive personal information. We process this only with your separate consent.)
  1. Location Information (Optional)
  • Data: Approximate or precise location, IP-derived city, and location-related device identifiers. (Background location may be collected only if authorized by you at the system level and strictly necessary for the function).
  • Purpose: For venue booking, finding nearby activities, "Play Dates Pickup Game" map features, distance-based sorting for leaderboards, and navigation.
  1. Health and Fitness Data Integration (Optional)
  • Data: Steps, heart rate, calories, workout duration, etc., from third-party platforms (e.g., Apple Health, Huawei Health), subject to the scope of your authorization.
  • Purpose: For sports statistics, trends, leaderboards (if enabled), and personalized training suggestions.
  1. Community and Interaction (Optional)
  • Data: Notes/photos/videos you post, comments/likes/favorites, topics and geotags (if actively added by you), and UGC meta-information; records related to violation handling/infringement complaints.
  • Purpose: For content publishing and display, interactive communication, and community governance.
  1. Notifications and Customer Service
  • Data: Push Tokens, device and system message categories, in-app messages, customer service ticket records, and call recordings (where permitted by law and with notice).
  • Purpose: For device status/report completion/event reminders, service contact, and quality tracking.
  1. Logs, Risk Control, and Compliance
  • Data: Crash logs, performance metrics, abnormal behavior logs, and flags generated by anti-cheat and anti-abuse models.
  • Purpose: For security and fraud prevention, stability improvement, compliance auditing, and dispute evidence.
  1. Automated Decision-Making and Profiling (If Applicable). To provide AI recommendations, training parameter suggestions, and anomaly detection, we may perform automated processing or limited profiling based on your device and training data. You have the right to request a manual review, express your views, and object to decisions made solely based on automated decision-making.
  2. Other Information. We may collect other information that you voluntarily provide when you communicate with us and that you post on our social media channels. And with your consent where required, we may obtain information from third party partners.
  1. How We Use Your Information
We may use your data for the following purposes:
  1. To Provide and Operate Our Services We process your information to fulfill the contract between you and us, specifically to:
    1. Control and manage your hardware: Connect to your ball machine, execute remote control commands, and monitor device status (battery, errors).
    2. Deliver core functionality: Generate training reports, record your sports performance, and facilitate venue/coach bookings.
    3. Maintain device performance: Push firmware updates (OTA) to your hardware to fix bugs or add features.
  2. To Provide AI Analysis and Personalization We use your motion data and video footage (with your consent) to:
    1. Provide AI motion analysis, stroke correction suggestions, and highlight reels.
    2. Generate personalized training plans and recommendations based on your historical performance.
  3. To Communicate with You We may process your personal information to communicate with you in relation to your accounts, our services, device alerts (e.g., "Low Battery"), and your customer support requests.
  4. For Research, Development, and Improvement of Our Services We may process your personal information to maintain, improve, and analyze our websites, apps, ads, and the products and services we offer (including training and optimizing our AI algorithms). We may also process your personal information to ensure security and integrity of our services, to identify you, and to prevent and detect fraud, abuse, and other misuses (e.g., abnormal device instructions).
  5. For Targeted Advertising We may process your information to provide you with targeted advertising and offers and promotions that you may be interested in, where permitted by applicable law (unless you have opted out). You may have certain privacy rights with respect to the processing of your information for targeted advertising purposes—for instance, you may opt out in accordance with the methods specified in this Policy below.
  6. For Legal Reasons We may process your personal information under certain laws and regulations, as well as to comply with applicable legal and regulatory obligations, and to respond to lawful governmental requests, as needed.
  7. Resolving Relevant Disputes We may process your personal information to handle complaints or disputes related to you (including using device logs to investigate hardware-related incidents).
  8. Other Purposes with Your Consent We may process certain information to fulfill any other business or commercial purposes at your direction or with your consent.
  1. How We Disclose and Share Personal Information
We do not sell your personal information. We only share data in scenarios permitted by applicable law, including but not limited to:
  1. Service Providers and Vendors We may disclose personal information to our service providers, vendors, and others for business purposes and to perform functions on our behalf. These include:
    1. Cloud & Technology Services: Hosting, data management, and technical support (e.g., AWS, AliCloud);
    2. Hardware Logistics & After-sales: Logistics companies (for shipping ball machines) and authorized repair centers (for hardware maintenance);
    3. Marketing & Analysis: Distributing emails, performing research/analysis, and managing brand promotions.
  2. Third-Party Integrations Our App may include third-party software development kits (SDKs) or APIs. When you use specific features, your information may be shared with these independent third parties:
    1. Payment Processors: (e.g., Stripe) to process your orders;
    2. Map/Location Services: To provide venue navigation;
    3. Social Login: (e.g., WeChat, Apple, Google) for authentication. Please note that these third parties may collect your data directly under their own privacy policies.
  3. User-Generated Content and Public Visibility Your username, avatar, and any information that you post to our community (including reviews, comments, training videos, and leaderboards) will be available to, and searchable by, other users of our websites and apps. You can review and make changes to who can view your profile in your account settings.
  4. Affiliates and Subsidiaries We may disclose personal information to our affiliates and subsidiaries (companies controlling, controlled by, or under common control with us) to provide integrated services (e.g., unified login) or for internal management purposes.
  5. Corporate Transactions We may disclose your personal information with actual or potential buyers in connection with any actual or proposed purchase, merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, provided that we inform the buyer or transferee that it must use your personal information only for the purposes disclosed in this Policy.
  6. Legal Compliance and Protection We may disclose personal information to other parties, including government entities and regulators, to the extent necessary to: (i) comply with a government request or applicable law and to respond to legal process; (ii) prevent illegal uses of our service or violations of our Terms of Use and our policies; (iii) defend ourselves against third-party claims; and (iv) assist in fraud prevention or investigation (including investigating hardware accidents).
  7. Other Disclosures with Your Consent We may disclose your personal information to any other third party where you have provided your consent.
  1. Protection and Retention of Personal Information
We use a variety of technical, administrative, and organizational security measures, including encryption and authentication tools in certain circumstances, that are intended to protect your personal information. Please be aware that despite our efforts, no data security measures can guarantee security. You can help keep your data safe by taking reasonable steps to protect your personal information against unauthorized disclosure or misuse.
We retain your personal information for as long as reasonably necessary to fulfill the purposes described in this Policy or disclosed to you at the time of collection, unless otherwise required or permitted by law.
  1. Cross-Border Transfers of Personal Information
LUMISTAR operates globally. Your data may be transferred to, stored, and processed in a jurisdiction other than where you live (e.g., our servers in [USA / EU / China]).
Regardless of the company or person who processes your information and where it is processed, we will take steps to transfer and protect your information through appropriate safeguards in accordance with applicable data protection laws and this Policy.
  1. Managing Your Privacy Rights and Choices
You may have certain rights identified below under applicable laws of where you reside with respect to your personal information: (i) access, correct and update your personal information; (ii) delete your personal information; (iii) change the scope of your consent or withdraw your authorization; (iv) deregister from our account; and (v) other rights as stipulated by applicable laws and regulations.
You may submit a request to exercise these rights via email to [privacy@lumistar.ai]. Once we receive your request, we may verify it by requesting information sufficient to confirm your identity.
We will respond to your request consistent with applicable law, including applicable exceptions. Depending upon the applicable law, access to your rights may be denied, such as: (a) when denial is required or permitted by law; (b) when granting access would have a negative impact on another's privacy; or (c) to protect our rights and properties.
  1. About Cookies and Similar Technologies
We, our service providers and third parties collect information, which may include personal information, from your browser, devices, or apps when you use our platform using a variety of methods, such as cookies, pixel tags, identifiers for mobile devices, and other similar technologies. The information collected by these cookies and similar technologies may include your: [IP address; unique cookie identifier and information obtained through cookies; unique device identifier and device type; domain, browser type and language, operating system, and system settings; country and time zone; previously visited websites; information about your interaction with our platform such as click behavior, purchases and indicated preferences; and access times and referring URLs].
We use cookies and similar technologies to analyze and understand how you access, use, and interact with us and our consumer’s preferences (such as country and language choices), as well as to assess, secure, protect, optimize, and improve the performance of our platform. This enables us to provide services to our consumers and improve their online experience. We also use cookies and pixel tags to obtain aggregate data about platform traffic and interaction, to conduct analytics, identify trends and obtain statistics so that we can improve our platform. We also use cookies and similar technologies to target advertising and content across our platform and third-party sites and services.
If you wish to disable cookies, or want to be notified before they are places, you may do this in your browser setting. However, we may not be able to provide certain service or you may not be able to view certain parts of this site if you have disabled cookies.
  1. Children’s Privacy We do not intend for our websites or app services to be used by, and do not knowingly collect information from, anyone under the relevant minimum age under applicable local law ("Children"). Additionally, we do not knowingly sell or share personal information of our customers under the age of 18 for targeted advertising purposes. If you are a parent or guardian and believe we may have collected information about your child without your consent, please contact us immediately as described in this Policy. If we become aware that we have collected personal information from a child without verification of parental consent, we will take steps to remove that information from our servers and terminate the applicable account.
    Please note that the use of our hardware (Ball Machines) by minors should always be under the strict supervision of a guardian. While this Privacy Policy covers data, please refer to our User Manual and Safety Guidelines for physical safety requirements regarding minors.
  2. Changes to Our Privacy Policy
Applicable law and our practices change over time. If we decide to update our Privacy Policy, we will post the changes on our websites and/or app. If we materially change the way in which we process your personal information, we will provide you with prior notice, including via email to the address we have on file, or where legally required, request your consent prior to implementing such changes. We strongly encourage you to read our Privacy Policy and keep yourself informed of our practices.
  1. Contact Us
We welcome your questions, comments and concerns about this Policy. You can contact us online at lumistar.ai (by postal mail at: privacy@lumistar.ai).
You may reach our [Global Privacy Department] and our [Data Protection Officer] at privacy@lumistar.ai.
Local-Specific Provisions
The above-mentioned general provisions applicable to your personal information may be subject to local specific rules. To know more about any specific rules applicable to you, please select the related jurisdiction below.
PART A: USA
If you visit and use our websites / mobile apps while in the United States of America, or if you are purchasing our products via our websites / mobile apps to be shipped to the United States of America, please read and agree this additional specific provision:
  1. What Data Do We Collect and Who Do We Share It With?
The categories of Data we collect about you depend on your activity and interaction with us. The Data we may collect is outlined in Section 1 of this Policy. In addition, we may also collect the additional categories of Data described below and share that information with the following categories of third parties:
Category
Examples
Categories of Third Parties to whom this Information is Disclosed
Financial Information
Credit or debit card information, bank account number, other financial information
Service providers.

Legally Protected Classification Characteristics
Age, race and ethnic origin, and gender or gender identity

[ ]

Internet, Application, and Network Activity
Call logs; text messages or emails (content); browsing history; search history; clickstream/online websites tracking information; data related to user activity, e.g., browser visits; Cookies or other similar technologies, which is typically collected automatically
[ ]

Inferences Drawn from Data
Profile reflecting a person's preferences, characteristics, behavior, and attitudes
[ ]
Some of the Data we collect is considered sensitive data under applicable U.S. laws (and GDPR), including health and fitness data (such as heart rate, calorie consumption, and physical exertion levels), and biometric information (specifically, body pose and skeleton keypoints extracted via AI analysis).
We collect this data solely when you:
  • Authorize synchronization with third-party health platforms (e.g., Apple HealthKit, Google Fit);
  • Use the AI Motion Analysis feature; or
  • Voluntarily provide it in your User Profile.
This information is used solely to:
  • Analyze your sports performance (e.g., swing speed, ball rotation);
  • Provide technical coaching and correction suggestions; and
  • Track your workout intensity.
Specific Notice Regarding HealthKit Data: To the extent we collect your health data via Apple HealthKit or similar APIs, we strictly adhere to the following principles:
  • We do not use HealthKit data for advertising, marketing, or data mining purposes.
  • We do not sell HealthKit data to third parties.
  • We only share HealthKit data with third parties for medical research (with your explicit consent) or as required by law.
Health data may also be referred to as “consumer health data” under certain U.S. data privacy laws. As described above, this information is only shared internally within us and with our service providers. We do not share this data with other third parties.
  1. When/How Do We Collect Data?
We collect Data from the following categories of sources:
  • From you or a member of your household;
  • From other individuals acting on your behalf, such as personal shoppers or assistants;
  • From devices associated with you or a member of your household, including through Cookies, web beacons or similar technologies when you visit our websites or online applications or open our emails;
  • Through technology we use in our apps;
  • From third-party partners.
  1. How Do We “Share” or “Sell” Your Data as Defined under Applicable Law?
We share certain categories of Data, collected through Cookies on the U.S. Digital Properties in a way that may be considered a “sale” or “sharing” of Data for targeted advertising under the applicable data privacy laws.
The following are the categories of data we sell/share/disclose Data for targeted advertising:(i)Device and Online Identifiers;(ii)Internet, Application, and Network Activity data.
Below are the categories of third parties to whom we sell/share/disclose Data for targeted advertising: Digital Partners (which include social media companies and advertising technology providers).
If you would like to opt-out of this activity please see Your Choices And Rights below.
  1. Your Choices and Rights
Please refer to section 6 of the Privacy Policy. We also include the following as relevant to our practices and rights that may apply under some U.S. state or federal laws.
  • Opt out of Sale/Share/Disclose for Targeted Advertising:
As described above, we work with Digital Partners that collect Data via cookies on our U.S. Digital Services in a manner which may be considered a “sale” or sharing/disclosure of Data for cross-contextual/targeted advertising.
Residents of certain states within the U.S., have the right to opt out of this activity.
You may opt out of “sale” or “sharing” of your Data through our use of targeting Cookies by disabling Cookies through your web browser.
  • Targeted Advertising. As further discussed above you may opt-out of our use of Cookies and similar technologies for targeted advertising purposes by adjusting your "Privacy Settings" within our App.
  • Marketing Communications. You may choose to stop receiving our newsletter or marketing emails by following the unsubscribe instructions included in these emails or contacting us at support@lumistar.ai.
  • Your Legal Rights. Some consumers (including job applicants located in California) may have additional rights with respect to their Data under applicable law, such as:
    • Right to access Data. You have the right to request that we disclose to you the categories of Data that we have collected about you, the categories of sources from which we collected your Data, the business or commercial purposes for collecting or “selling” or “sharing” your Data and the categories of third parties with whom we shared your Data. You may be entitled to receive the specific pieces of your Data we hold. In some jurisdictions you may also be entitled to receive a list of the specific third parties with whom we share Data.
    • Right to disclosure. You may be entitled to receive information regarding the categories of Data we collected, the sources from which we collected Data, the purposes for which we collected and shared Data, the categories of Data that we sold or shared and the categories of third parties to whom the Data was sold or shared, and the categories of Data that we disclosed for a business purpose in the 12 months preceding your request.
    • Right to correct Data. You have the right to request in certain circumstances that we correct any personal information that we, our vendors or service providers on our behalf, have collected directly from you.
    • Right to deletion. You may be entitled to request that we delete the Data that we have collected from you. We will use commercially reasonable efforts to honor your request, in compliance with applicable laws. Please note, however, that we may need or be required to keep certain information, such as for our legitimate business purposes or to comply with applicable law.
    • Right to opt-out of sales or sharing of Data to third parties. You have the right to opt out of sales of your Data, as defined under applicable state privacy laws.   In addition, you have the right to opt of the sharing of Data for cross-contextual behavior advertising / targeted advertising purposes. The definitions of “sale” under applicable state privacy law is very broad and may include certain activities, including the use of website Cookies and similar tracking technologies for analytics and advertising purposes.
    • Right to use an authorized agent. You can designate an authorized agent to submit requests on your behalf. However, to protect your Data and in accordance with applicable state privacy laws, we will require written proof of the agent’s permission to do so and we will need to verify your identity directly.
    • Right to appeal. You have a right to appeal decisions concerning your ability to exercise your consumer rights.
    Please note that these rights may be limited under applicable laws. For example, we may need to retain certain Data for business purposes, to complete transactions you have requested, to comply with our legal obligations, or for other purposes as required or permitted by applicable law.
    If you wish to exercise your rights under applicable law, please contact us by [privacy@lumistar.ai ].
    Please note that we may require additional information from you in order to verify your identity and process your request. we will not discriminate against you because you exercise any of the consumer rights described in this section.
Your California Privacy Rights. Under California's "Shine the Light" law, California residents who provide Data to us in obtaining products or services for personal, family or household use are entitled to request and obtain from us once a calendar year information about the customer information that we disclosed, if any, to other businesses for their own marketing purposes in the immediately prior calendar year. This request may be sent by [privacy@lumistar.ai ]. We will respond to these requests within 30 days. Please be aware that not all information sharing is covered by the "Shine the Light" requirements and only information on covered sharing will be included in our response.
  1. Contact Us
If you have any questions or concerns about the handling of your Data by us, please contact us online at lumistar.ai (by postal mail at: privacy@lumistar.ai).
PART B: Australia
If you visit us via any of our websites, mobile apps or in our points of sales within or from Australia, each processing of your Data is based on your consent or in compliance with applicable laws and regulations, not on the basis of necessity to carry out a contract with you, a legal obligation /or our overriding legitimate interest.
PART C: Canada
If you visit us via any of our websites, mobile apps or in our points of sales within or from Canada, the processing of your Data is based on your consent or in compliance with applicable laws and regulations.
In addition to the rights listed in section 6 of this policy, the rights below will apply:
  1. You may vary or withdraw your consent to the processing of your Data, or opt-out of certain uses and disclosures, subject to legal and contractual restrictions. Such withdrawal will not affect the lawfulness of the processing prior to consent being withdrawn.
  2. You also have the right to object at any time to the processing of your Data for marketing purposes. To unsubscribe from our marketing communications, you may also use the above channels or click the "Unsubscribe" link included at the bottom of any marketing email we send to you.To stop receiving “LUMISTAR Product & Service Recommendations,” you can switch off the “LUMISTAR Product & Service Recommendations” toggle in Settings > Message Center.
PART D: Japan
  1. Provision to Third Parties
We may provide your Data to third parties such as data analysis companies and advertising companies, including social networking service providers, for the purpose of conducting research, analysis, and targeted advertising distribution, etc. Such third parties may use your Data provided by us, such as e-mail addresses, in conjunction with the Data relating to you held by such third parties for our research, analysis, and delivery of advertisements, etc.
  1. Provision to Foreign Third Parties
We may transfer your personal data to a location that is outside Japan, under the following circumstances:
  • when we have your consent;
  • when the third party is located in a member state of the European Economic Area or in the UK; or
  • when the third party has established a system necessary to continuously implement measures comparable to the measures that a personal information handling business operator in Japan should take.
  1. Managing Your Privacy Rights and Choices
For disclosure (including disclosure of records of provision to third parties), correction, addition, deletion, suspension of use, elimination, suspension of provision to third parties, etc. of your data in accordance with Japanese Act on the Protection of Personal Information, please contact us using the contact information in Art.4 below.
  1. Contact US
If you have any questions or concerns about the handling of your Data by us, please contact us online at lumistar.ai (by postal mail at: privacy@lumistar.ai).
PART E: South Korea
If you visit and use our websites / mobile apps while in South Korea, or if you are purchasing our products via our websites / mobile apps to be shipped to South Korea, please read and agree this additional specific provision:
  1. What Data Do We Collect and How?
In addition to the matters provided in Section 1 of the Privacy Policy, Data that we process, purposes of collection, and the retention period thereof are as follows:
  • Customer Registration (retention period: one (1) month upon membership unsubscription): (i) Purpose: Member identification, membership management, and service provision; (ii) Mandatory Items: Name; phone number; email address; password; (iii) Optional Items:[Profile picture, gender, date of birth, height, weight, sports preferences.]
  • Mobile App: (i) Registration:[Device Information (UUID, OS version, device model), IP address, Service usage logs]; (ii) Location-based Push Messaging (upon consent of access to location data): Mandatory Items: Location data (retention period: immediately deleted without storage).
  1. For How Long Do We Keep Your Data?
We subject to the following retention periods.
Customer Inquiries through email or customer support channels: three (3) years.
Regardless of the designated retention period, certain Data may still be retained if required by applicable laws. Some major periods of retention are as follows:
  • Commercial books and records (e.g., accounting books and balance sheets); material documents regarding business (including any agreements): (i)Legal ground: Commercial Code; (ii) Retention period: ten (10) years.
  • Books, evidentiary documents, tax invoices or receipts regarding transactions: (i)Legal ground: Framework Act on National Taxes, Corporate Tax Act, Value-Added Tax Act; (ii)Retention period: five (5) years.
  • Records on agreement or withdrawal of subscription; records on payment and supply of goods: (i)Legal ground: Act on the Consumer Protection in Electronic Commerce, Etc. (“E-Commerce Consumer Protection Act”); (ii)Retention period five (5) years.
  • Records on consumer complaints or dispute resolution: (i)Legal ground: E-Commerce Consumer Protection Act; (ii)Retention period: three (3) years.
  • Records on website visits: (i)Legal ground: Protection of Communications Secrets Act; (ii)Retention period: three (3) months.
In addition to the foregoing, we implement deactivation system of personal information pursuant to the Personal Information Protection Act of Korea. With respect to customers registered as members through online channels such as websites and apps, customers who have not used the relevant service for at least one (1) year will be converted to dormant customers:
  • Online customers may freely choose a period of service validity for either one (1) year or until withdrawal from membership; and if they do not specify their choice, the one-year period will be automatically selected.
  • The period of validity is counted from the date on which online customers use the service; and if the customer does not use the service over the period selected pursuant to the preceding paragraph, Data of such customers will be stored and managed separately from that of other customers.
  • At least thirty (30) days prior to converting to dormancy, we will notify applicable customers of related Data by email or other communication channels.
  1. What Are the Grounds for Processing Your Data?
We lawfully process Data in accordance with the Korean law, specifically the Personal Information Protection Act, by obtaining express prior consent from data subjects in relation to the processing of Data.
  1. To Whom Do We Share Your Data with?
Please see Section 3 above. Please refer to the Third Party Information Sharing List for details.
Meanwhile, the processing of customer Data is delegated overseas as follows: [ ]: (i) Purpose of transfer:[ ]; (ii) Types of information transferred:[ ]; (iii) Period of retention:[ ]; (iv) Date/time and method of transfer:[ ].
  1. How Do We Destroy Your Data?
The procedures and methods of destroying Data are as follows:
Destruction procedures: we identify Data regarding which reasons for destruction arise, such as expiry of the period of retention, and destroy such Data upon approval of [Data Protection Officer].
Destruction methods: we irreversibly destroy Data recorded and stored in electronic files to prevent their recovery, and shreds or incinerate any Data recorded and stored by paper-based means.
  1. What Safety Measures are Taken to Protect Data?
The measures that we take to protect Data are as follows:
  • Managerial Measures to Protect Data: [].
  • Technical Measures to Protect Data: [].
  • Physical Measures to Protect Data: [].
  1. Contact for Data Privacy
You may reach our [Privacy Department] and our [Data Protection Officer] at [ ].
To report other infringements of personal data or request consultation, please contact the institutions below:
Personal Data Infringement Call Center (operated by the Korea Internet & Security Agency (“KISA”))
Website:http://privacy.kisa.or.kr
Telephone: 118
Personal Information Dispute Mediation Committee
Website:https://www.privacy.go.kr/front/reqDis/reqDisStep1.do
Telephone: 1833-6972
National Police Agency Cyber Safety Bureau
Website:ecrm.cyber.go.kr
Telephone: 182
Supreme Prosecutor’s Office Cyber Safety Bureau
Website:www.spo.go.kr
Telephone: 1301
  1. Processing of Personal Location Information
Purpose of Processing Personal Location Information and Retention Period:
We retain your location information to provide our location-based services and to comply with relevant laws and regulations, and for the purposes to which the personal location data subjects consented.
We use such personal location information only for the periods as necessary to achieve the purposes described above. Where it is required to retain certain location information under relevant laws and regulations, we retain the information for the periods prescribed under the law and never uses such information for any purposes other than the purposes described above.
Basis for Retaining Records Verifying Collection, Use, and Provision of Personal Location Information and Retention Period:
Pursuant to Article 16(2) of the Act on the Protection and Use of Location Information, we automatically record data verifying collection, use, and provision of your location information on the location information system, and retains such records for at least six months. However, where a personal location data subject withdraws his/her consent for use or provision of his/her personal location information, the records verifying the collection, use, and provision of the relevant personal location information shall be destroyed.
Destruction Procedures and Methods for Personal Location Information:
We irreversibly destroy Data recorded and stored in electronic files to prevent their recovery, and shreds or incinerate any Data recorded and stored by paper-based means.
Matters Regarding Third Party Provision of Personal Location Information and Notification Thereof:
Where we provide personal location information of personal location data subjects to a third party designated by the personal location data subjects, we shall immediately notify the personal location data subjects of the recipient, the date and time, and purpose of the provision every time we provide personal location information of personal location data subjects to the third party, or collect such information on a certain number of such provisions and then notify the personal location data subjects with the data subjects’ consent.
  1. Data Subjects’ Rights
The data subject may access, modify or delete his/her personal information on “My Information” available on [ LUMISTAR mobile app (My > My Information / Settings )] or [ LUMISTAR ] mobile app at any time. The data subject may also contact the department in charge of protecting personal information and request for access of his/her personal information.
How to reject Cookies by Browser:
Internet Explorer: Select “Tools” menu on top of the web browser > Internet Option > Privacy > Advanced > Choose whether to allow Cookies
Chrome: Select “Settings” on the menu icon (upper-right corner) > Privacy and security > Cookies and other site data > Choose whether to allow Cookies
Microsoft Edge: Select “Settings” on the upper-right corner > Cookies and Site permissions > Manage and delete Cookies and site data > Choose whether to allow Cookies
PART F: EEA+
If you visit and use our websites / mobile apps while in the European Economic Area (EEA), the United Kingdom (collectively, the “EEA+”) or if you are purchasing our products via our websites / mobile apps to be shipped to the EEA+, please read this additional specific provision:
If you are located in the EEA, the EU General Data Protection Regulation applies to our processing of your personal data, as well as local data protection laws, as the case may be. If you are located in the UK, the UK General Data Protection Regulation applies to our processing of your personal data. References to the “GDPR” are references to the General Data Protection Regulation as it applies in the country where you are located.
  1. Who Is the Data Controller?
The data controller is Lumistar (Shanghai) Robotics Technology Co., Ltd., registered address at
Room 340, Building 1, No. 299 Zhongchen Road, Songjiang District, Shanghai, P.R. China. To contact us, please contact [ ]
  1. What Lawful Bases of Processing and Legitimate Interests Do We Rely On?
If we have entered a contract with you and the processing is necessary for us to perform our contract with you or take steps at your request prior to entering the contract, the lawful basis is that it is necessary per Article 6(1)(b) GDPR.
If the processing is necessary for us to comply with an applicable legal obligation under EEA or UK laws, the lawful basis is that it is necessary per Article 6(1)(c) GDPR.
In some cases, the processing is necessary for us to realize a legitimate interest based on an assessment of that interest and your privacy and other fundamental interests, including where we endeavor to provide you with a positive user experience, seek to comply with the laws or regulations outside of the EEA or UK, to maintain the security and integrity of our products and/or services and related platforms and systems, operate and optimize our business, improve our Products and/or Services, develop new services, and manage our relationships with users. In these cases, the lawful basis is that it is necessary per Article 6(1)(f) GDPR. More information on our assessments of legitimate interests balanced against privacy and other fundamental interests is available on request.
In some cases, we rely on your consent to process your personal data, per Article 6(1)(a) GDPR, including when we use non-essential cookies or other technologies to process your data. In these cases, you can withdraw your consent at any time with future effect by using the consent settings on our products and/or services with a description of what data processing activities of ours you would like to withdraw your consent from.
  1. What Categories of Recipients Receive Personal Data From Us?
Please see Section 3 above. Please refer to the Third Party Information Sharing List for details.
  1. Where Is Your Personal Data Processed and On What Basis Do We Transfer Personal Data Across Borders?
The personal information that you provide us is stored and processed on servers owned by us and other companies in the United States, the People's Republic of China, including locations outside of the country or jurisdiction where you are located. We take measures to ensure that our processors provide an adequate level of data protection by ensuring appropriate safeguards are in place and performing data transfer arrangements as appropriate. If you have any questions or would like more information, you can contact us by [ ].
  1. How Long Do We Process Personal Data?
We retain your personal data only as necessary for the purposes for which the personal data is processed or for legal requirements. The length of time for which we retain personal data depends on the purposes for which we collect and use it and how long we need to retain it to comply with applicable laws (including for the purpose of satisfying any legal, regulatory, tax, accounting or reporting requirements). If we retain the personal data solely to satisfy legal requirements, we will implement measures to prevent the data's processing. Once the personal data is no longer necessary for the purposes for which we collected it, we will delete it.
  1. What Data Protection Rights Do You Have?
In the EEA and the UK you have the following rights, subject to the conditions under the GDPR and/or local data protection law:
  • To object, on grounds relating to your particular situation, to the processing of your personal data by us. This includes the right to object to our processing of your personal data for direct marketing and the right to object to our processing of our personal data where we are performing a task in the public interest or pursuing our legitimate interests or those of a third party. If we process your personal data based on our legitimate interests or those of a third party, or in the public interest, you can object to this processing, and we will cease processing your personal data, unless the processing is based on compelling legitimate grounds or is needed for legal reasons. Where we use your personal data for direct marketing for our own products and services, you can always object and opt out of future marketing messages using the unsubscribe link in such communications or through other means.
  • To obtain from us confirmation as to whether your personal data is being processed, and, where that is the case, to request access to details about how we process your personal data and copies of the personal data.
  • To obtain from us the rectification of inaccurate personal data concerning you.
  • To ask us to erase your personal data to the extent it is not required for legally required purposes or necessary for security and integrity purposes.
  • To request restriction of processing of your personal data, in which case, it would be marked and processed by us only for certain purposes.
  • To receive your personal data which you have provided to us in a structured, commonly used and machine-readable format and you have the right to transmit the personal data to another entity without hindrance from us.
  • To withdraw your consent at any time. This will not affect the lawfulness of our use of your personal data before your withdrawal.
  • To lodge a complaint with a supervisory authority.
  • In some jurisdictions such as France and Portugal, you also have the right to provide us with guidelines as to the processing of your personal data after your death.
You may view a list of supervisory authorities in the EEA and UK and their respective contact information here:
To submit a request to exercise your privacy rights, you can contact us by [ ]. In your request, please describe what rights you are exercising and how you would like us to assist. We may need to request specific information from you to help us verify your identity and that you have the right to request what you are requesting. These are security measures to ensure that we do not disclose personal data to any person who has no right to receive it, or otherwise process the data in unauthorized ways. We may also contact you to ask for further information about your request to clarify the scope of your request and speed up our response. We will respond to requests to exercise privacy rights according to applicable laws.
  1. Children’s Privacy
We do not intend for our websites or app services to be used by, and do not knowingly collect information from, anyone under the age of 16. If you are a parent or guardian and believe we may have collected information about your child, please contact us immediately as described in this Policy.
  1. Are You Required to Provide Us with Your Personal Data?
You are not legally required to provide personal data to us, but we cannot provide our products and/or services without receiving some personal data from you.

Appendix A: Data Collection Inventory (by Feature)

To help you understand more clearly how we process your personal information across various functions, and in accordance with the requirements of the Personal Information Protection Law of the People's Republic of China and relevant national standards, we have specially formulated this list of personal information collection, itemized by function and scenario.
Core Principle: We adhere to the principles of legality, legitimacy, necessity, and good faith, processing only the minimum scope of personal information necessary to achieve the product's functions. For scenarios not covered in this list, we will not proactively collect your personal information.
1. Account Registration & Login
Collection Scenario
Types of Personal Information
Purpose of Collection
Method of Processing
Required Information?
Storage Duration
One-Click Login via Local Number
Mobile phone number, Device identification codes (IMEI/IMSI), Network IP address
To verify your identity and create/log into your account
Login is completed locally after verification via the carrier (Mobile/Unicom/Telecom) gateway.
Yes
Stored for the duration of your account use. Deleted according to law after you deactivate your account.
SMS Verification Code Login
Mobile phone number
To send you a dynamic verification code for identity verification and login
SMS is sent via partnered SMS service providers.
Yes
The verification code becomes invalid immediately. The mobile number is stored while you use the account.
WeChat / Apple ID Login
Unique identifier provided by the third-party platform, Nickname, Avatar (WeChat only, requires your authorization)
To associate the third-party account for quick creation or login of a local account
Authorization is obtained from WeChat/Apple to associate the account locally.
Yes
The unique identifier is stored while you use the account. Nickname and avatar are only used for initial profile setup.
Password Login
Mobile phone number, Password (encrypted storage)
To verify account credentials and complete login
Locally verifies the encrypted password.
Yes
The password is stored with irreversible encryption.
Password Recovery
Mobile phone number, New password (encrypted storage)
To verify identity and reset the account password
Identity is verified via SMS, then the password is reset locally.
Yes
The new password is stored with irreversible encryption.
2. Device Connection & Training
Collection Scenario
Types of Personal Information
Purpose of Collection
Method of Processing
Required Information?
Storage Duration
Adding & Connecting Devices
Device identifier (Bluetooth MAC address, Device SN), Wi-Fi name (SSID), Device location permission (for Bluetooth scanning)
To discover, pair, and connect your smart ball machine or accessories
Completed locally via the phone's Bluetooth and Wi-Fi modules.
Yes
Device identifiers are stored while the device is bound, and deleted after unbinding. Wi-Fi info is used only for network configuration and is not stored.
Conducting Ball Machine Training
Training parameter settings (e.g., speed, placement), Training duration, Number of shots, Device status data
To control the ball machine and generate your personal training records
Commands are set via the App and sent to the device. Training records are saved under your account.
Yes
Training records are stored long-term to generate your sports reports. You can manually delete them.
Generating & Sharing Training Reports
Summarized training data, Poster images you choose to generate
To visually analyze your training results and allow you to share posters to the community
Reports and posters are generated locally based on your training data.
Generating reports: Yes. Sharing to community: No.
Reports are stored under your account. Content shared to the community is made public per community rules.
3. Community Interaction
Collection Scenario
Types of Personal Information
Purpose of Collection
Method of Processing
Required Information?
Storage Duration
Posting Notes/Updates
User-uploaded text, images, or videos; Location information (requires your authorization); Mood and tags added
For you to share training insights, match arrangement info in the community
Content is published to the community (public or visible to selected friends) after your confirmation.
Posting content: Yes. Location: No.
Content you publish is saved in the community. You can edit or delete it at any time.
Browsing & Interaction
Browsing history, Likes, Favorites, Comments
To recommend content of interest and record your interaction preferences
Your actions are recorded to optimize content recommendations.
Yes
Browsing history is stored short-term. Interaction records are stored long-term until you delete them.
Private Messaging
Chat history with other players/coaches
To provide an in-app communication tool
Messages are encrypted during transmission and storage via instant messaging services.
Yes
Chat history is stored under your account. You can clear conversations.
Using the "Find a Match" Map
Your location information (requires your authorization, optional for map/list mode)
To show nearby players and venues
Location is used for map display upon acquisition; no continuous background tracking.
Yes
Used during the single session; precise location is not persistently stored.
Participating in Leaderboards
Sports data (e.g., cumulative training time, number of shots, distance covered, forehand/backhand counts, deep shots in, etc.)
To generate personal and global rankings based on your sports performance, providing motivation and reference
After you explicitly consent and enable "Sync to Leaderboards," your selected period's sports data is used for ranking calculation.
No (you can choose whether to sync)
Stored during the leaderboard display period (e.g., daily, monthly). After you disable sync, data is removed from subsequent rankings.
Viewing Leaderboards
Rankings, nicknames, avatars, and brief data of other users you browse
For you to understand the sports levels of other users in the community
The system publicly displays a de-identified leaderboard (showing only nickname and avatar) to all users.
Browsing function: Yes. Others' info: Made public per their authorization.
Storage of others' information follows their personal settings.
Sharing My Parameters
Your custom or saved training parameter sets (e.g., "My Special Drills," "My Combos," including speed, spin, placement, frequency, etc.)
To allow you to generate a QR code for your training plans or upload them to the Parameter Leaderboard for other users to learn from
After your active operation, the parameter sets you choose are generated into a shareable QR code or listed on the public "Parameter Leaderboard" by the system.
No (shared by your initiative)
Shared parameters remain public until you delete the share within this feature.
Importing Others' Parameters
You scanning a shared parameter QR code, or selecting from the Parameter Leaderboard

To enable you to quickly use training plans recommended by other users or celebrities
After you scan the QR code or click "One-Click Import," the parameters are saved to your "Custom Training" list.
Yes (necessary to implement the import function)
Imported parameters are saved as your personal settings in your account.
4. AI Analysis & Smart Editing
Collection Scenario
Types of Personal Information
Purpose of Collection
Method of Processing
Required Information?
Storage Duration
Uploading Video for AI Analysis
Training or match videos you upload
To provide motion analysis, generate sports reports, or highlight reels
Videos are uploaded to the cloud for AI algorithm analysis to generate structured reports.
Yes
Original videos are deleted by default after analysis; only the generated report data is retained. You can choose to save the video.
Using Voice Control for Device
Voice commands recorded by the device (only after you wake it)
To recognize your voice commands for controlling the ball machine
Voice recognition is performed on the device or locally. Command text is uploaded for execution; recordings are not saved.
Yes
Voice recordings are processed in real-time and not stored.
Highlight Reel Editing
Original match or training videos you upload, Video metadata (duration, resolution, etc.)
To automatically identify and edit highlight moments (e.g., long rallies, winning shots) from your video via AI, generating short video reels for you

1. Upload: You manually select and upload videos to the cloud processing queue. 2. Analysis: AI algorithms analyze video content to identify highlight segment boundaries. 3. Generation: Automatically synthesizes and edits the video, adding optional effects or tags. 4. Delivery: The generated highlight video is returned for your preview and saving.
Yes (necessary for the core editing function)
1. Original Videos: Automatically deleted from the cloud within 7 days after processing, unless you manually select "Keep original footage." 2. Highlight Videos: Saved under your account after generation. You can keep them permanently or delete them anytime. 3. Control: You have full control over each step (upload, generation, saving, deletion).
6. Personal Center & System Security
Collection Scenario
Types of Personal Information
Purpose of Collection
Method of Processing
Required Information?
Storage Duration
Completing Personal Profile
Avatar, Nickname, Years playing, Personal bio, Skill level, etc.
To personalize your community profile and recommend matching players or content
Actively filled in and uploaded by you on the profile page.
Avatar & Nickname: Yes. Others: No.
Stored while you use the account. You can modify them anytime.
Feedback & Customer Service
Your contact details (phone/email), Feedback content, Device logs (optional upload)
To contact you and resolve issues you encounter
Used for customer service personnel to communicate with you. Device logs are for technical troubleshooting only.
Yes
Communication records are saved until a reasonable period after the issue is closed.
App Stability & Security Control
Device information (model, OS version), Application logs, Operation logs, Network IP address
To ensure stable App operation, troubleshoot crashes, and prevent security risks
Automated collection and analysis.
Yes
Application logs are stored short-term. Security logs are stored for a period as required by law.
Important Notes:
  1. Sharing Principles: We only share information necessary to enable specific functions. We enter into data protection agreements with our partners, requiring them to protect user information in accordance with the law.
  2. User Authorization: Before you first use a function that involves sharing information, we will obtain your consent via a pop-up window or user agreement.
  3. User Rights: You can view and manage your authorizations through "My Profile > Settings > Account & Security," or contact our customer service to withdraw your consent.
  4. Policy Updates: This list may be updated as business adjustments are made. The updated version will be published within the App, and users will be notified accordingly.

Appendix B: Third‑Party Sharing (SDK/Partners)

To ensure the normal operation of the App's features, enhance user experience, and fulfill specific service purposes, we may share necessary information with third-party service providers. This list details the third-party SDKs currently integrated or potentially invoked by the App, as well as partner information, including the types of personal information they collect, the purposes of use, and links to their official privacy policies.
Mainland China
Third-Party Company Name
Product / Type
Information Shared
Purpose of Use
Usage Scenario
Sharing Method
Third-Party Privacy Policy
Shenzhen Tencent Computer Systems Company Limited
MyApp SDK (Tencent YSDK)
QQ account, phone number, ID number, IP address, Android ID, device model, Wi-Fi parameters, etc.
Developer registration, login, payment, real-name verification, account security, risk control
When users log in, make payments, or undergo real-name verification via the MyApp channel
SDK integration
Tencent MyApp Privacy Protection Guidelines
Huawei Device Co., Ltd. / Huawei Software Technologies Co., Ltd.
Huawei Push SDK
App basic info (AppID, package name), device identifiers (AAID, Push Token), device model, OS version, country code, etc.
To push messages to Huawei phone users
When pushing any system or activity notifications to Huawei device users
SDK local collection
Huawei Push SDK Privacy Statement
Beijing Xiaomi Mobile Software Co., Ltd.
Xiaomi Push SDK
Device identifiers (OAID, Android ID), app info (package name, version), device info (manufacturer, model, region), network type, etc.
To push messages to Xiaomi phone users
When pushing any system or activity notifications to Xiaomi device users
SDK local collection
Xiaomi Push Privacy Policy
China Mobile Communications Group Co., Ltd.
China Mobile Authentication SDK
Phone number, device identifier, network status
To enable one-click login with the local number
When user selects "One-Click Login with Local Number"
SDK integration
China Mobile Authentication Service Privacy Policy
China United Network Communications Group Co., Ltd.
China Unicom Authentication SDK
Phone number, device identifier, network status
To enable one-click login with the local number
When user selects "One-Click Login with Local Number"
SDK integration
China Unicom Authentication Service Privacy Policy
China Telecom Group Co., Ltd.
China Telecom Authentication SDK
Phone number, device identifier, network status
To enable one-click login with the local number
When user selects "One-Click Login with Local Number"
SDK integration
China Telecom Authentication Service Privacy Policy
Shenzhen Tencent Computer Systems Company Limited
WeChat Open Platform SDK
Device identifier, WeChat account information
To support WeChat quick login
When user selects "Login with WeChat"
SDK integration
WeChat Open Platform Privacy Protection Guidelines
Apple Inc.
Apple Sign-in SDK
Device identifier, Apple account information (email optional)
To support Apple account login
When user selects "Login with Apple"
SDK integration
Apple Privacy Policy
Shanghai Yongyun Network Technology Co., Ltd. (SMS Bao)
SMS Bao SDK/API
Phone number, SMS verification code content, sending status
To send SMS verification codes
When user registers, logs in, or recovers password via SMS
API call
SMS Bao Privacy Agreement
Shenzhen Tencent Computer Systems Company Limited
Tencent Cloud Instant Messaging (IM) SDK
Device identifier, User ID, message content, network status
To provide in-app private messaging function
When user sends and receives in-app private messages
SDK integration
Tencent Cloud IM Privacy Agreement
Shenzhen Hexun Huagu Information Technology Co., Ltd.
JPush SDK
Device identifier, push records, network status
To implement message push service
When pushing system messages or private message notifications to users
SDK integration
JPush Privacy Policy
Gaode Software Co., Ltd.
AMap SDK
Device identifier, location information, network status
To provide map, positioning, and venue navigation functions
When user views nearby venues or uses the "Find a Match" map
SDK integration
AMap Open Platform Privacy Policy
Shanghai Qiniu Information Technology Co., Ltd.
Qiniu Cloud Object Storage SDK
Device identifier, uploaded files (images/videos)
To provide storage and distribution services for user content (e.g., images, videos)
When user uploads avatar, posts community images/videos, or uploads training videos
SDK integration
Qiniu Cloud Privacy Policy
Umeng Tongxin (Beijing) Technology Co., Ltd., Beijing Ruixun Lingtong Technology Co., Ltd.
Umeng Analytics SDK
Device info, network info, location, permissions to read storage (photos, media, other files)
To statistically analyze user behavior and optimize product functions
When collecting data on user's usage of various App functions for analysis
SDK local collection
Umeng+ Privacy Policy
Shenzhen Tencent Computer Systems Company Limited
Tencent Bugly SDK
Device identifier, log information, exception stack trace
To collect App crash logs and improve stability
When monitoring App operation status and collecting crash info for fixes
SDK local collection
Bugly User Agreement
Amazon Web Services, Inc.
AWS S3 SDK
Device identifier, uploaded files (images/videos)
To provide storage services for user content
When user uploads avatar or posts community images/videos
SDK integration
AWS Privacy Policy
European Union (EU)
Third-Party Company Name
Product / Type
Information Shared
Purpose of Use
Usage Scenario
Sharing Method
Third-Party Privacy Policy
Google LLC
Google Sign-in SDK
Device identifier, Google account information, email
To support Google account login
When user selects "Login with Google"
SDK integration
Google Privacy Policy
Apple Inc.
Apple Sign-in SDK
Device identifier, Apple account identifier, email (optional)
To support Apple account login
When user selects "Login with Apple"
SDK integration
Apple Privacy Policy
Tencent Cloud Europe B.V.
Tencent Cloud Instant Messaging (IM) SDK (International)
Device identifier, User ID, chat content
To provide in-app private messaging function
When user sends in-app private messages to other players or coaches
SDK integration
Tencent Cloud International Privacy Policy
Aurora Mobile Limited
JPush SDK (International)
Device identifier, push token
To implement message push service
When pushing private message reminders or activity notifications to users
SDK integration
JPush International Privacy Policy
Google LLC
Google Maps SDK
Device identifier, location information
To provide map and location services
When user uses the "Find a Match" map or searches for venues
SDK integration
Google Maps Platform Terms of Service
Adjust GmbH
Adjust SDK
Device identifier, advertising identifier (IDFA), in-app events
To statistically analyze user behavior and measure advertising effectiveness
Records anonymized behavioral data from the moment user installs the App
SDK integration
Adjust Privacy Policy
Google LLC
Firebase Crashlytics SDK
Device identifier, crash logs, stack trace
To collect crash information and monitor application stability
When the App crashes or experiences unexpected errors
SDK integration
Firebase Terms of Service
Alibaba Cloud
Object Storage Service (OSS) SDK
User-uploaded files (images/videos), stored by default in the Germany (Frankfurt) region.
To provide storage services for user-generated content (UGC)
When user uploads avatar, posts community images/videos, or uploads training videos
SDK integration
Alibaba Cloud Compliance Center
Amazon Web Services, Inc.
AWS S3 SDK
User-uploaded files (images/videos)
To provide core data storage services
When user uploads large files such as training videos
SDK integration
AWS Privacy Policy
United States (US)
Third-Party Company Name
Product / Type
Information Shared
Purpose of Use
Usage Scenario
Sharing Method
Third-Party Privacy Policy
Google LLC
Google Sign-in SDK
Device identifier, Google account information, email
To support Google account login
When user selects "Login with Google"
SDK integration
Google Privacy Policy
Apple Inc.
Apple Sign-in SDK
Device identifier, Apple account identifier, email (optional)
To support Apple account login
When user selects "Login with Apple"
SDK integration
Apple Privacy Policy
Tencent Cloud Europe B.V.
Tencent Cloud Instant Messaging (IM) SDK (International)
Device identifier, User ID, chat content
To provide in-app private messaging function
When user sends in-app private messages to other players or coaches
SDK integration
Tencent Cloud International Privacy Policy
Aurora Mobile Limited
JPush SDK (International)
Device identifier, push token
To implement message push service
When pushing private message reminders or activity notifications to users
SDK integration
JPush International Privacy Policy
Google LLC
Google Maps SDK
Device identifier, location information
To provide map and location services
When user uses the "Find a Match" map or searches for venues
SDK integration
Google Maps Platform Terms of Service
Adjust GmbH
Adjust SDK
Device identifier, advertising identifier (IDFA), in-app events
To statistically analyze user behavior and measure advertising effectiveness
Records anonymized behavioral data from the moment user installs the App
SDK integration
Adjust Privacy Policy
Google LLC
Firebase Crashlytics SDK
Device identifier, crash logs, stack trace
To collect crash information and monitor application stability
When the App crashes or experiences unexpected errors
SDK integration
Firebase Terms of Service
Alibaba Cloud
Object Storage Service (OSS) SDK
User-uploaded files (images/videos), stored by default in the US (Silicon Valley/Virginia) region.
To provide storage services for user-generated content (UGC)
When user uploads avatar, posts community images/videos, or uploads training videos
SDK integration
Alibaba Cloud Compliance Center
Amazon Web Services, Inc.
AWS S3 SDK
User-uploaded files (images/videos)
To provide core data storage services
When user uploads large files such as training videos
SDK integration
AWS Privacy Policy

Appendix C: Permissions & Invocation (iOS/Android)

To ensure the implementation of relevant features within this application and its secure and stable operation, we may need to request your authorization to access the following system permissions. Please be aware that these permissions are not enabled by default. We will only process your information within the scope of the authorized permissions after you actively confirm or grant access based on prompts in specific scenarios.
Permission Name
Corresponding Function Module
Invocation Scenario & Purpose
Platform Differences & Explanation
Required?
Bluetooth
Device Connection & Control
1. To scan for and connect to smart ball machines and accessories. 2. To send control commands (e.g., start training, adjust parameters) to connected devices.
Universal: Requested when clicking "Add" or "Connect" on the "Devices" page. For Android, location permission may be required to scan for Bluetooth devices, which is a system limitation.
Yes (Core function for connecting and controlling physical devices)
Location
Find a Match Map, Venue Navigation, Nearby Players/Venues Recommendation
1.Using the "Find a Match" map: To display courts and players around you, facilitating match arrangements. 2. Finding/navigating to a venue: For route planning and estimated time of arrival. 3. Posting updates (optional): To add a location tag.
iOS: May differentiate between "While Using the App" or "Precise Location". Android: May differentiate between "Precise" or "Approximate" location. Explanation: We only request permission when the relevant feature is actively used in the foreground and do not continuously track your location in the background.
Yes (Core function for maps and match-making features)
Camera
Scan-to-Pair when Connecting Devices
Scanning device or parameter QR codes: For quickly adding devices or importing training parameters.
Universal: Requested when you tap the scan, capture, or upload button.
Yes (Core interaction for device pairing via scanning)
Photo Library / Photos
Avatar/Image/Video Upload, Sharing, Saving
1.Uploading existing photos/videos: For posting community updates, uploading content for AI analysis, setting avatars. 2. Saving content locally: For saving training report posters, highlight videos, etc.
iOS: "Photos" permission. Android: "Photo Gallery" or "Storage" permission. Explanation: We only access files you actively select.
Yes (For content upload and saving functions)
Wi-Fi
Device Network Configuration
When configuring the network for Wi-Fi-enabled ball machines, used for the phone to connect to the device's hotspot and transmit home Wi-Fi credentials.
Universal: Only invoked during the device network configuration process. Does not collect information about other Wi-Fi networks.
Yes (For initial setup of network-connected devices)
Notifications
Message Center
To receive push notifications for completed training reports, device messages, community interactions (likes, comments, private messages), activity reminders, etc.
Universal: Typically requested upon first App launch. You can disable them anytime in your system settings.
No (However, disabling will prevent all in-app message alerts)
App List (may involve on Android)
Third-party Login & Sharing
To detect if apps like WeChat are installed, enabling quick login redirects or sharing.
Android-specific: On some systems or device models, integrating third-party SDKs may involve this permission for functionality availability checks.
No (Used to optimize interaction experience)
Important Notes:
  1. Permission Management: You can review the status of the permissions mentioned above on your device via Settings > Privacy > Permission Management (or a similar path), and turn them off or back on at any time. Disabling a permission will only affect the corresponding function and will not impact the use of other features.
  2. Permissions & Information: Some permissions themselves do not directly collect personal information but may enable its acquisition when combined with other actions. For example, after granting "Camera" permission, we only access photo information when you actively take a picture.
  3. Children's Privacy: We place great importance on the protection of minors' personal information. If you are a child under the age of 14, please use our services under the guidance of your parent or other guardian.
  4. Policy Updates: This list may be adjusted as features are updated. In the event of significant changes, we will notify you through prominent means within the application.
If you have questions about the invocation of a specific permission or require more detailed explanations, please contact us via Profile > Settings > Help & Feedback.

Appendix D: Retention & Deletion Matrix (Examples)

To safeguard your information rights and interests, we have established clear data retention periods and deletion rules. This matrix specifies the duration for which different types of data will be retained after fulfilling specific purposes, as well as the methods for their deletion.
Data Category
Typical Data Content
Retention Period / Deletion Trigger
Deletion Mechanism & Explanation
1. Account & Identity Information
Phone number, third-party login identifiers, encrypted passwords, nickname, avatar.
Retained until you deactivate your account.
Upon receiving your account deactivation request, we will initiate the deletion process. Core identity information will be anonymized or permanently deleted within 15 working days.
2. Profile & Settings
Gender, date of birth, personal bio, NTRP rating, list of ball machine devices, training preference parameters.
Retained until you delete or modify the information, or deactivate your account.
You can edit or delete this information within the App at any time, with changes taking effect immediately. It will be deleted upon account deactivation.
3. User-Generated Content & Records
Training Records
Detailed data from individual training sessions (duration, number of balls, placement, etc.).
Retained until you manually delete the record, or deactivate your account.
You can delete individual training records at any time in "Training Reports" or "My Profile - Activity".
Community Content
Published posts, comments, shared images/videos, private message chat history.
Retained until you manually delete the content, or deactivate your account.
You can delete your own published content at any time. Private messages become invisible after both parties delete them. After account deactivation, your community content will be anonymized (displayed as "Deactivated User").
AI-Generated Content
AI motion analysis reports, generated "Highlight Moment" videos.
Reports retained until manually deleted or account deactivation. Original videos are deleted by default from the cloud 7 days after processing.
You have full control over AI-generated reports. Uploaded original videos are for temporary processing and will be automatically cleaned up by the system unless you explicitly choose to retain them.
4. Operational & Log Information
Device Logs
App crash logs, performance data used for fault diagnosis.
No more than 30 days.
To ensure application stability, log information will be automatically anonymized within 30 days of collection, removing parts that can identify individuals.

Appendix E: Data Subject Request Templates (Summary)

  • Access/Copy: Provide account identifier, scope, and preferred delivery format.
  • Rectify/Supplement: Specify fields and reasons.
  • Erasure: Specify feature/data types to erase.
  • Restrict/Object: Explain scope and reasons.
  • Portability: Indicate recipient and format (e.g., JSON/CSV/ZIP).
  • Withdraw Consent: Identify the permission (e.g., Location/Health/Camera).
  • Account Deletion: Unbind devices and close orders, then submit the deletion request.
After identity verification, we aim to process requests within 15 business days, or within 30 days/statutory timeframes where permitted. If we cannot fulfill a request, we will provide reasons and available remedies (regulator complaint/judicial relief).