Etono Privacy Policy — International

Version 2026-10-07.1 · 草案 / Draft

About this policy

Etono is operated by xiaojun zhang, an individual. Etono helps you develop and run applications on your phone through chat. Contact: privacy@etonoai.com. This is a pre-publication draft. Its effective date will be stated after publication checks are complete.

1. Information and purposes

Account information includes your phone number or email, the identifier and verified email returned by Apple or Google, and account creation time. We use it for registration and authentication. Security information includes session credentials, verification-code digests, puzzle state, request IP addresses and rate-limit records to protect the service.
Development information includes conversations and relevant history, project names and icons, tasks, events, model usage, tool arguments and results. Tool results may contain code, file content or command output. We use this information to provide development, screen for abuse, maintain task history, recover interrupted work and calculate usage. Do not submit credentials, unnecessary sensitive information, or other people's information without authority.
Subscription information includes store transaction identifiers, purchase credentials, products, status and expiry to verify benefits and prevent duplicate claims. Stores process payments; this feature does not provide us with your full payment-card details. Privacy correspondence includes your contact details, request and verification records.

2. Local storage and network requests

Project files, application databases and the Linux runtime disk are mainly stored on your phone. We do not currently provide full project cloud synchronization. The phone also caches project catalogs and chat. Uninstallation or deletion can cause local data loss. Deleting an Etono account does not cancel a store subscription.
Our backend stores conversations, tasks and tool results. When you authorize an AI provider, task-related conversations, history, code, file content and runtime output may be sent through the backend to that provider. Local execution does not mean all information stays on your phone.
Necessary disclosed account, security and service requests may run on an appropriate legal basis. Reading this notice or accepting our Terms does not provide consent for every purpose. Processing that requires consent starts only after that consent.

3. Providers and international processing

Our backend is hosted on Tencent Cloud in mainland China. Our verification-email server and independent privacy-contact mailbox are in Hong Kong. AI recipients are listed in the in-app Provider List; The list includes MiniMax and DeepSeek; the recipient depends on the provider actually enabled by the backend. Other providers may be added. Before sharing content, we identify the actual recipient, purpose, data scope and verified processing locations. Permission is recorded for each provider and notice version. A new recipient requires the applicable notice and authorization.
Apple and Google process the sign-in or store-payment features you choose under their own policies. We request only information needed for those features. Provider roles, locations and safeguards must be verified before public release; we do not claim that a provider never retains or trains on data without a verified commitment. Sending a privacy request to our mailbox involves processing that correspondence in Hong Kong.

4. Retention and deletion

Account, conversation and task records are retained while the account exists and they are needed to provide the service. Project deletion or account deletion removes associated service records; the client also removes projects on that phone after account deletion. Necessary transaction and anti-replay records may be retained for security, fraud prevention or legal obligations, without continued use for personalized development.
Verification codes are valid for five minutes. Puzzle credentials and pending third-party sign-in attempts are short-lived. Expired authentication and sending-limit records are removed during cleanup. Expiry does not necessarily mean immediate physical deletion. Backup, security-log and provider-copy retention must match verified operational policies; this draft does not promise immediate deletion from every backup or third-party system.

5. Security and permissions

We use HTTPS for backend connections, protected session storage, access controls and verification-code digests. Android may request notification permission for background operation. You can manage permissions in system settings. Applications you develop may access network resources they use. No system can guarantee absolute security.

6. Rights and controls

Settings provides policies, AI permission controls and account deletion. You may contact privacy@etonoai.com to request access, correction, a copy or deletion of your information, or withdraw consent where processing relies on consent. We verify identity using proportionate information and respond within applicable legal deadlines.
For people in the EEA or UK, applicable rights may also include restriction, objection, portability and a complaint to a supervisory authority. Core account and requested development processing may rely on contractual necessity, security on a properly assessed legitimate interest, legally required records on legal obligations, and specific sharing on consent where required. These bases are assessed for the actual processing; acceptance of terms is not blanket consent. Transfers from the EEA or UK require an applicable lawful mechanism verified before those markets are opened.
California rights and disclosures apply where the relevant law applies to this operator and processing. We do not currently integrate advertising or advertising-tracking SDKs; any future sale, sharing for advertising or optional tracking requires a separate assessment, notice and applicable controls.
Withdrawing AI permission stops future sharing and cancels related active tasks. It cannot recall content already sent or undo earlier lawful processing. Your existing local data is not deleted merely because you refuse optional processing.

7. Young users

The international minimum age is generally 13, subject to stricter local requirements. Mainland China registration starts at 14. Users under 18 require an independent parent or guardian email confirmation before an active account can be created. A checkbox claiming parental permission is insufficient. Where law requires further age or parental-authorization checks, registration remains unavailable until those checks are completed. Parents may contact our privacy mailbox to exercise applicable rights.

8. Changes and contact

Version: 2026-10-07.1. We notify you of material changes in purposes, data, recipients or handling and obtain renewed permission where required before the new processing. Operator: xiaojun zhang. Privacy contact: privacy@etonoai.com.

第三方 AI 服务商 / AI providers

MiniMax

上海稀宇科技有限公司 / Shanghai Xiyu Technology Co., Ltd.
AI 开发与安全检查:理解请求、生成代码、检查运行结果及识别滥用 / AI application development and abuse screening
对话及相关历史、任务所需代码、文件内容、工具参数和运行输出 / Conversations, relevant history, code, file content and tool results needed for your task
MiniMax 开放平台公开政策称在中国境内收集的个人信息存储在中国境内;当前后台使用 api.minimaxi.com。下游 API 条款与具体保存安排仍需核验 / Public platform policy states PRC-collected personal information is stored in the PRC. Current endpoint: api.minimaxi.com. Downstream API terms and retention arrangements require verification.
服务商公开政策采用实现目的所必需期限及法定例外;不作固定期限或“不用于训练”承诺 / Purpose-based retention with legal exceptions; no unverified fixed retention or no-training claim.
contact@minimaxi.com

服务商隐私政策 / Provider policy

DeepSeek

杭州深度求索人工智能有限公司 / Hangzhou DeepSeek Artificial Intelligence Co., Ltd.
AI 开发与安全检查:理解请求、生成代码、检查运行结果及识别滥用 / AI application development and abuse screening
对话及相关历史、任务所需代码、文件内容、工具参数和运行输出 / Conversations, relevant history, code, file content and tool results needed for your task
公开资料列示主体为杭州深度求索人工智能有限公司;API 接收主体、处理地点和保存规则须按开发者协议核验 / Publicly named entity: Hangzhou DeepSeek Artificial Intelligence Co., Ltd.; API recipient, location and retention require developer-contract verification
公开消费者政策不直接适用于下游 API 应用;开发者合同需另行核验 / Consumer policy excludes downstream API applications; developer terms require separate verification.
privacy@deepseek.com

服务商隐私政策 / Provider policy