Bifrost Privacy Policy
Data Processing Instructions for Global Socialization, Language Learning, AI Companionship, Content Community, Memberships, Publishing, and Offline Activities
Initial Publication Date: July 27, 2026Effective Date of This Version: August 7, 2026Last Updated: August 8, 2026
|
Operating Entity |
Beijing Yanwan Technology Co., Ltd. |
|
Applicable Products |
Bifrost APP, website, mini-programs, client software, server-side services, AI functions, community and offline activities, and other related services |
|
Document Version |
V2026.08 |
|
Initial Publication Date |
July 27, 2026 |
|
Effective Date of This Version |
August 7, 2026 |
|
Last Updated |
August 8, 2026 |
|
Contact Email |
thebifrost@126.com |
|
Important Notice: This Policy explains how Bifrost collects, uses, saves, shares, commissions processing of, transfers, publicly discloses, provides cross-border, and protects your personal information, as well as how you can exercise your personal information rights. Please pay special attention to clauses involving sensitive personal information, minors, cross-border transfers, AI and algorithmic recommendations, third-party SDKs, system permissions, and account cancellation. Third-party SDKs, permissions, data fields, server deployments, payment links, export routes, and target country rules will be subject to actual disclosure within the product and updated versions of this Policy. |
Chapter 1 Who We Are and Scope of This Policy
1.1 Personal Information Processor. The personal information processor for Bifrost is Beijing Yanwan Technology Co., Ltd. The registered address is Room 1587, 1st Floor, Building 9, No. 18 Tianhe North Road, Huangcun Town, Daxing District, Beijing, and the contact email for personal information protection is thebifrost@126.com.
1.2 Scope of Application. This Policy applies to our personal information processing activities through the Bifrost APP, website, server-side interfaces, AI functions, community, memberships, customer service, activities, publishing, offline services, and other related products and services. Products or services independently provided by third parties are subject to their own privacy policies.
1.3 Basic Principles. We follow the principles of legality, legitimacy, necessity, good faith, clear purpose, minimum necessity, openness and transparency, accuracy and completeness, security assurance, and consistency of rights and responsibilities when processing personal information. We will not refuse to provide basic functions because you refuse to provide non-essential personal information or non-essential permissions, but we may not be able to provide extended services that rely on such information or permissions.
1.4 Important Definitions. Personal information is various information recorded electronically or otherwise related to identified or identifiable natural persons, excluding information after anonymization. Sensitive personal information refers to personal information that, once leaked or illegally used, may easily cause harm to the personal dignity of natural persons or endanger personal and property safety, such as precise location, identity documents, personal biometric information, communication content, financial accounts, whereabouts trajectories, minor personal information, specific identities, or health-related information.
Chapter 2 Information We Collect and Use
We will collect different types of information depending on the specific functions you use. The table below lists the main scenarios, potentially collected information, purposes, and whether it constitutes sensitive personal information. Specific fields are subject to product pages, permission pop-ups, SDK lists, and actual functions.
|
Scenario |
Information Possibly Processed |
Main Purpose |
Sensitivity Alert |
|
Registration and Login |
Mobile number, email, verification code, password or login credentials, third-party account IDs, Account ID, registration time, login status |
Account creation, identity verification, login, security management, account recovery |
Mobile number, login credentials may be sensitive or important security info |
|
Account Profile |
Nickname, avatar, gender, age or birthday, country or region, city, native language, target language, interest tags, learning goals, bio, milestones, social preferences |
Profile display, matching, social interaction, language learning, personalized recommendation |
Avatar photos, age, location, or specific identity tags may be sensitive info |
|
Lighting and Companionship |
Lighting records, returned light records, matching results, companionship relations, companionship days, photo blur or unlock status, interaction tasks, relation unbinding records |
Realize 7-day companionship, phased photo display, friendship relations, anti-harassment and risk control |
Social relations, avatar photos, interaction records may be relatively sensitive |
|
To-do List and Goal Growth |
To-do items, goals, tags, reminder times, completion status, check-in records, shared audiences |
Goal management, companionship supervision, growth community, reminder services |
If user fills in health, whereabouts, financial, or identity content, it may constitute sensitive info |
|
Instant Messaging |
Chat text, images, voice, video, emojis, files, translation requests, send/receive time, conversation partner, reported evidence content |
Instant messaging, translation, correction, report handling, security audit, dispute resolution |
Communication content, voice, images, and reporting materials are usually relatively sensitive |
|
AI Services |
Dialogues with AI, prompts, context, language practice audio, AI feedback, goal reminder settings, model security logs |
AI chat, language practice, translation/polishing, goal supervision, security risk control, service improvement |
Dialogues may contain sensitive info; please do not input unnecessary privacy info |
|
Content Community |
Posts, images, videos, comments, likes, favorites, reposts, follows, browsing, searches, recommendation feedback, content disposal records |
Publishing display, interaction, recommendation sorting, content governance, infringement processing |
User actively published content may contain sensitive info |
|
Location Services |
Coarse location, precise location, IP locale, post location, event location, nearby matching preference |
Local or cross-border matching, location marking, event registration, security risk control |
Precise location and whereabouts trajectories belong to sensitive personal info |
|
Memberships and Transactions |
Order number, purchased item, payment status, payment channel, invoice info, refund records, coupons, virtual items, consignee name/phone/address |
Order fulfillment, member benefits, after-sales, invoicing, logistics, anti-fraud |
Payment and logistics info may be relatively sensitive |
|
Offline Activities |
Registration info, contact details, activity records, check-in, emergency contacts, necessary health or safety reminder info |
Event organization, notifications, check-in, insurance or safety management, dispute handling |
Health, emergency contacts, and whereabouts info may belong to sensitive info |
|
Customer Service and Reporting |
Contact details, issue description, screenshots, voice recordings, chat logs, identity proof, ownership proof, processing records |
Feedback processing, identity verification, complaints/reports, infringement processing, dispute resolution |
Identity proof, communication content, reporting materials may belong to sensitive info |
|
Device and Logs |
Device model, OS, App version, network type, IP address, device identifiers, crash logs, operation logs, login logs, risk control results |
Security assurance, anti-cheating, fault troubleshooting, performance optimization, network security log retention |
Device identifiers and logs may identify individuals in specific scenarios |
|
Marketing and Notifications |
Notification tokens, contact details, subscription preferences, activity participation records, ad interaction records |
Sending lighting reminders, system notifications, activity messages, commercial info, and preference management |
Generally non-sensitive unless associated with sensitive content |
2.1 Necessary Information for Basic Functions. For basic functions like social, community, instant messaging, and language learning, necessary personal information typically includes the mobile number or email required for registration/login, account ID, basic public profile, content you actively publish or send, and device and log information necessary for service operation. If you only browse public content, we will minimize the collection of personally identifiable information.
2.2 Public and Shared Visibility. The nickname, avatar, bio, languages, interests, goals, public posts, comments, likes, follows, user works, and event registration display information you actively fill in may be displayed to other users or the public according to your settings and product rules. Please do not publicly post information you do not want others to know.
2.3 Phased Photo Display. If you participate in companionship matching, your avatar or photos may initially be displayed in a blurred, semi-transparent, or other privacy-enhanced manner, and will be clearly displayed to the other party after the companionship relationship reaches an agreed number of days or both parties meet the rules. You can read page prompts before uploading, authorizing, withdrawing, or terminating the relationship; for content that has already been viewed, screenshotted, or saved by the other party, the platform cannot fully control its subsequent use.
2.4 Boundaries of AI Data Usage. Unless we obtain your separate consent, complete de-identification or anonymization in compliance with legal requirements, or as otherwise permitted by laws and regulations, we will not use your private chats, AI dialogues, precise locations, payment information, identity documents, reporting materials, minor personal information, etc., for public model training. We may use security logs, feedback, and de-identified data to improve model safety, translation quality, and risk control effectiveness.
2.5 Information Sources. The information we process primarily comes from what you actively provide, what is generated during your use of services, what is returned by device or system permissions, what is provided by third-party account logins or payment providers, reports or interactions from other users, public channels, what is lawfully provided by partners, and what is required by regulatory and judicial authorities. We will require partners to guarantee the legality of information sources.
Chapter 3 Calling System Permissions
To realize specific functions, Bifrost may request the following system permissions. Permissions are subject to operating system pop-ups and actual product implementation. You can turn off permissions in system settings, but related functions may become unavailable after doing so.
|
Permission |
Usage Scenario |
Impact of Refusing or Turning Off |
|
Camera |
Taking avatar photos, publishing images or videos, event check-ins, identity verification |
Cannot directly shoot or complete functions relying on shooting |
|
Photo Album or Media Library |
Uploading avatars, post images/videos, chat images, saving content |
Cannot select from local device or save certain media |
|
Microphone |
Sending voice messages, spoken practice, voice recognition, AI language companionship |
Cannot record voice or use spoken practice |
|
Notifications |
Lighting reminders, returned light reminders, message notifications, event notifications, membership or security alerts |
May not receive timely reminders |
|
Location |
Local or cross-border matching, nearby events, post location marking, security risk control |
Cannot use location-based recommendations, marking, or event functions |
|
Contacts |
Inviting friends, identifying registered contacts; only called when actively authorized and used by you |
Cannot quickly invite or discover contacts via address book |
|
Calendar or Reminders |
Writing event or goal reminders to local calendar; only called when actively selected by user |
Cannot write to system calendar or reminders |
|
Clipboard |
Identifying invite codes, copying share links; generally used only when user actively pastes or copies |
Invite codes or links must be manually entered |
|
Bluetooth or Local Network |
Called if subsequent offline check-in, nearby devices, screen casting, or LAN functions require it |
Cannot use related extended functions |
|
Device Information |
Account security, anti-cheating, crash troubleshooting, push and compatibility optimization |
May affect security verification, anti-cheating, and issue locating |
Chapter 4 Third-Party SDKs, Commissioned Processing, and Sharing
4.1 Commissioned Processing. To provide cloud servers, storage, CDN, instant messaging, maps, push, payments, data statistics, content moderation, customer service, SMS, emails, risk control, logistics, invoices, event execution, etc., we may commission third parties to process necessary personal information. We will agree with the commissioned parties on the purpose, duration, method, types of personal information, protection measures, and rights and obligations of both parties, and supervise their processing activities.
4.2 Sharing Principles. Except as stated in this Policy, obtaining your separate consent, being necessary for fulfilling a contract, protecting user life and property safety, handling complaints and disputes, fulfilling legal obligations, regulatory enforcement requirements, corporate mergers/divisions/acquisitions, or other situations allowed by law, we will not share your personal information with third parties.
4.3 SDK List. Based on the SDK inspection results for the currently inspected Bifrost Android build (version_code 112), the current version integrates the following third-party SDKs for message push, device compatibility, runtime performance optimization, and stability. Actual processing may vary with device brand, operating system, SDK version, feature configuration, and user authorization. Refer to this list and each SDK's official privacy policy for details.
|
SDK Name (Package) |
Developer |
Purpose |
Processing and Information Scope |
SDK Privacy Policy |
|
vivo Push SDK (com.vivo.push) |
维沃移动通信有限公司 |
Provides system notifications, interaction alerts, and friend-message push on vivo devices, and measures SDK interface call success. |
Collected locally by the SDK and transmitted over the network: appid, appkey, app package name, app version, pushSDK version, vpush regid, device type, system type, and system version. |
https://dev.vivo.com.cn/documentCenter/doc/878 |
|
Xiaomi Push (com.xiaomi.push) |
北京小米移动软件有限公司 |
Provides system notifications, interaction alerts, and friend-message push on Xiaomi devices, supports delivery and display, and analyzes push results. |
Collected locally by the SDK and transmitted over the network: app package name, version, and running status; message creation, delivery, and click time and push-message content; device manufacturer, model, memory, system version, SDK version, device region, carrier, network type, WiFi status, and notification settings. |
https://dev.mi.com/console/doc/detail?pId=1822 |
|
Getui Message Push SDK Android (com.igexin.sdk) |
每日互动股份有限公司 |
Creates an Android message-push channel, generates push target identifiers, delivers notifications, and improves delivery rate and stability. |
Collected locally by the SDK and transmitted over the network: device platform, manufacturer, brand, model, system version, OAID, AndroidID, WiFi connection information, carrier, DHCP, SSID, and BSSID. Where compatible SDK configuration is enabled and necessary authorization is lawfully obtained, optional fields may include IMEI, MAC, GAID, Serial Number, IMSI, IP address, and base-station information. Actual optional fields depend on configuration and authorization. |
https://docs.getui.com/privacy/ |
|
Meizu Push SDK (com.meizu.cloud.pushsdk) |
珠海星纪魅族信息技术有限公司 |
Provides system notifications, interaction alerts, and friend-message push on Meizu devices, and optimizes and measures message delivery. |
Collected locally by the SDK and transmitted over the network: phone brand, model, system version, system language, push ID generated from a device identifier, tags or aliases based on push ID, push-switch status, and message display, dismissal, or click behavior. Push-message content may be processed temporarily during delivery. |
https://open.flyme.cn/docs?id=202 |
|
Performance Acceleration Library (com.huawei.hms.stats) |
华为软件技术有限公司 |
Provides multithreaded programming and system performance awareness capabilities for device compatibility, runtime performance optimization, and stability. |
The SDK's official personal-information processing list states that no personal information is collected. It may use basic capabilities such as network access and network status to provide performance acceleration. Actual processing is subject to Huawei's official privacy policy and the app's configuration. |
https://developer.huawei.com/consumer/cn/doc/development/graphics-Guides/sdk-data-security-0000001050700772 |
|
HONOR Push SDK (com.hihonor.push) |
深圳荣耀软件技术有限公司 |
Provides system notifications, interaction alerts, and friend-message push on HONOR devices, supporting timely delivery and display. |
Processed by the SDK on its servers: device and app information, including device identifiers (AAID and PushToken), APPID, and app package name. This information is used for message notifications and is deleted under HONOR's rules after the app developer requests deletion or the user uninstalls the app. |
https://developer.honor.com/cn/docs/11002/guides/sdk-data-security |
4.4 Independent Third-Party Services. After jumping to third-party websites, apps, payment pages, app stores, social platforms, logistics platforms, or offline event organizers via Bifrost, the third party may process your information as an independent personal information processor. Please read their privacy policies and authorize carefully.
4.5 Transfer and Public Disclosure. In the event of a merger, division, acquisition, asset transfer, bankruptcy liquidation, or similar transaction, your personal information may be transferred as a business asset. We will require the new holder to continue to be bound by this Policy or to obtain your consent again. Except for laws and regulations, regulatory enforcement, protecting life and property safety, public content display, or your active public disclosure, we will not publicly disclose your personal information.
Chapter 5 Sensitive Personal Information and Separate Consent
5.1 Scope of Sensitive Information. Bifrost may process sensitive personal information in specific scenarios, such as precise location, photos and voice, chat content, reporting evidence, identity documents, payment transactions, shipping addresses, minor information, emergency contacts, health or safety info, whereabouts trajectories, and social relations.
5.2 Processing Rules. We only process sensitive personal info with specific purposes, sufficient necessity, strict protection measures, and having legally obtained your separate consent or meeting statutory exceptions. Refusing to provide sensitive personal info generally won't affect basic functions, but you may be unable to use functions relying on that info like positioning, voice, payment, offline events, identity verification, publishing authorization, or security handling.
5.3 User Care Obligation. Please do not fill in identity documents, home addresses, bank cards, verification codes, passwords, precise whereabouts, medical records, minor privacy, others' personal info, or trade secrets in public profiles, posts, To-do Lists, chats, AI conversations, or comments. Info you actively publish or share may be saved, forwarded, or abused by the recipient.
Chapter 6 Algorithmic Recommendation, AI, and Automated Decision-Making
6.1 Algorithm Scenarios. We may use algorithms or automated decisions in scenarios like matching recommendation, discovery page sorting, content moderation, search ranking, ad or commercial info display, anti-cheating risk control, AI generation, translation correction, and user tag management.
6.2 Transparency and Control. We will provide necessary algorithm explanations, tag management, personalized recommendation switches, sorting options, ad preferences, AI identifiers, reporting feedback, and appeal mechanisms in the product. Users can delete or modify some profile tags; after turning off personalized recommendations, recommendation results may switch to being based on time, popularity, geographic region, language, content safety, or operational rules.
6.3 AI Safety. AI functions may simulate natural language communication, but are not real humans. We will lawfully take measures like content safety, emotional dependency risk warnings, minor protection, excessive use reminders, manual intervention, generated content identifiers, model output monitoring, training data compliance, and appeal handling.
6.4 Review of Significant Impacts. If automated decisions result in outcomes that significantly affect your rights, such as bans, transaction interception, content takedowns, functional restrictions, minor protection limits, or high-risk security alerts, you have the right to request an explanation from us and request manual review.
Chapter 7 Cross-Border Provision of Personal Information
7.1 Cross-Border Scenarios. Because Bifrost is positioned as a social and language learning platform, the following scenarios may involve cross-border provision or overseas access of personal information: you actively match, chat, share profiles or To-do Lists with overseas users; overseas users view your public profile or content; we provide servers, CDN, translation, AI, customer service, or security services for overseas users; cross-border events, publishing, gifts, payments, logistics, or partnership services.
7.2 Informing and Consent. Within the scope required by law, we will inform you of the overseas recipient's name, contact details, processing purpose, processing method, types of personal info, retention period, and methods/procedures for exercising your rights, and obtain your separate consent before providing personal info across borders.
7.3 Compliance Paths. Depending on business scale, info types, export volume, identification of important data, and regulatory requirements, we will legally choose personal info export security assessments, personal info protection certification, personal info export standard contract filing, or other paths recognized by laws and regulations. If relevant compliance procedures are not completed, we will adopt measures like localized storage, functional limits, zoned operations, de-identification, minimized transmission, or suspension of related cross-border functions.
7.4 Overseas Risks. The data protection level in the country or region of the overseas recipient may differ from mainland China. We will require the overseas recipient via contract, technical, and management measures to provide a protection level no lower than legal requirements, but cross-border networks, overseas supervision, judicial assistance, and third-party behavior may still bring additional risks.
Chapter 8 Retention Period, Storage Location, and Deletion
8.1 Retention Period Principle. We retain personal info only for the shortest period necessary to achieve the processing purposes, except where laws/regulations stipulate otherwise, users authorize otherwise, or it is necessary for dispute handling, regulatory enforcement, security auditing, transaction fulfillment, or protecting legitimate rights and interests.
8.2 Main Retention Periods. Account info is generally kept until account cancellation then lawfully deleted or anonymized; public content is kept until user deletion, account cancellation, or platform lawful disposal; chat records are kept according to user deletion, session management, reporting evidence, security auditing, and legal requirements; network logs are legally retained for no less than the statutory period; order, invoice, payment, logistics, and after-sales info are kept per financial/tax, consumer protection, e-commerce, and dispute handling requirements; reporting, infringement, account disposal, and security incident records are kept per the period necessary for processing.
8.3 Storage Location. Personal info collected and generated by us within the PRC is principally stored within the territory. Where it truly needs to be provided overseas, we will fulfill compliance obligations per Chapter 7 of this Policy.
8.4 Deletion and Anonymization. When the processing purpose is achieved, unachievable, or no longer necessary, the user withdraws consent, services terminate, retention period expires, or laws require deletion, we will legally delete or anonymize the personal info. Where the statutory retention period has not expired or it is technically difficult to delete, we will stop processing other than storage and necessary security protection.
Chapter 9 Security Protection Measures
9.1 Technical Measures. We adopt identity authentication, access control, minimum privilege, encrypted transmission, encrypted storage, desensitization, de-identification, log auditing, backup recovery, vulnerability repair, security monitoring, content safety, anti-cheating risk control, and emergency response measures to protect personal info.
9.2 Management Measures. We establish systems for data classification and grading, personal info protection impact assessments, permission approval, employee confidentiality, commissioned party management, SDK review, compliance audits, minor protection, algorithm safety, AI ethics review, and security incident disposal.
9.3 Security Incidents. If a security incident like personal info leakage, tampering, or loss occurs or may occur, we will legally launch emergency plans, take remedial measures, and report to regulatory departments according to legal requirements, informing affected users of the incident situation, impact scope, disposal measures, risk suggestions, and contact methods.
9.4 Security Limitations. The Internet environment cannot guarantee absolute security. Users should also properly keep accounts, passwords, verification codes, and devices safe, avoid disclosing sensitive info to others, avoid clicking suspicious links, and avoid unsafe transactions with strangers.
Chapter 10 Your Personal Information Rights
10.1 Query and Copy. You have the right to query and copy your personal info, except as stipulated by laws/regulations or involving others' rights, trade secrets, security risk control, or regulatory requirements. We will gradually provide query entrances in the product for personal profiles, content, orders, benefits, account security records, etc.
10.2 Correction and Supplementation. When you find personal info is inaccurate or incomplete, you can correct it within the product, or apply via customer service for supplementation/correction.
10.3 Deletion. Under statutory circumstances, you have the right to request deletion of personal info. For example, processing purpose achieved/unnecessary, we stop providing services, you withdraw consent, or we process personal info violating laws or agreements.
10.4 Withdrawal of Consent. You can withdraw consent via system settings, permission management, privacy settings, notification settings, personalized recommendation switches, account cancellation, or contacting customer service. Withdrawing consent does not affect the validity of processing activities based on consent before withdrawal, but may cause related functions to be unusable.
10.5 Account Cancellation. You can apply for cancellation via "Settings - Account Security - Cancel Account" or customer service channels. After verifying identity and handling unfinished orders, disputes, arrears, events, publishing authorizations, violation disposals, or statutory retention matters, we will complete the cancellation within the legal or reasonable period, and delete or anonymize your personal info.
10.6 Explanation and Rejecting Automated Decisions. For results made via automated decision-making that may significantly affect your rights, you have the right to request explanations, and have the right to reject us making decisions solely via automated means, except as otherwise required by law or necessary for service security.
10.7 Transfer and Portability. When conditions stipulated by the national cyberspace administration are met, you can request to transfer personal info to a personal info processor designated by you. We will legally provide the path.
10.8 Response Time. We will reply within 15 working days or the statutory period after receiving your request and completing necessary identity verification. Complex requests may require extension, and we will explain the reason. For groundless repetitions, requests exceeding reasonable scope, affecting others' rights, endangering security, or legally rejectable, we may refuse and explain the reason.
Chapter 11 Minor Protection
11.1 Principle Limitations. Bifrost involves stranger socialization, cross-border interaction, AI emotional companionship, payment, and offline activities. In principle, it does not provide core services to minors under 18. Minors must not register or use core services without guardian consent and platform permission.
11.2 Children's Information. In principle, we do not actively collect personal info of children under 14. If truly necessary to process due to guardian consent, minor mode, customer service, security protection, or legal requirements, we will obtain guardian consent according to children's personal info protection rules, take strict protective measures, and allow guardians to exercise query, correction, deletion, withdrawal, and cancellation rights.
11.3 Guardian Rights. If a guardian discovers a minor uses Bifrost, provides personal info, makes payments, is harassed, or faces safety risks without consent, they can contact us via customer service email. We will process legally after verifying identity.
11.4 AI and Minors. The platform will not provide AI anthropomorphic interactive services to minors with goals of inducing addiction, excessive pandering, emotional manipulation, or replacing true guardian companionship. If minor-applicable functions are provided later, mechanisms for age recognition, time management, content safety, consumption limits, guardian control, and complaint handling will be set up.
Bifrost Child Safety Standards (CSAE / CSAM)
11.5 Zero-Tolerance Standard. Bifrost and Beijing Yanwan Technology Co., Ltd. have zero tolerance for child sexual abuse and exploitation (CSAE) and child sexual abuse material (CSAM). No person may use Bifrost to create, upload, store, distribute, solicit, trade, direct others to, promote, or otherwise facilitate content or conduct involving the sexual abuse or exploitation of children.
11.6 Prohibited Conduct. Prohibited content and conduct include, without limitation, grooming a child for sexual exploitation; sextortion; trafficking a child for sexual purposes; sexualizing a minor; soliciting, exchanging, or distributing sexual or sexually suggestive imagery involving a minor; attempting to establish an online or offline relationship with a child for exploitation; and any conduct that endangers, exploits, or facilitates the exploitation of a child.
11.7 Reporting Channels. Users may report a child-safety concern through Bifrost's in-app reporting or feedback mechanism, or by emailing the designated child-safety contact at 205296199@qq.com. A report may include the relevant account, content link or identifier, time, and a description of the concern. Do not download, retain, or forward suspected CSAM itself by email. If a child is in immediate danger, contact local law enforcement or a child-protection organization immediately.
11.8 Review and Enforcement. When we obtain actual knowledge of suspected CSAE or CSAM, we will review it promptly under these standards and applicable law. Measures may include restricting distribution, removing content, suspending or terminating accounts, limiting product features, preserving necessary evidence, preventing re-upload, and cooperating with an investigation. We may also act against malicious reports, obstruction, or retaliation against reporters.
11.9 Legal Compliance and Reporting. We comply with applicable child-safety laws and maintain a process for reporting and cooperating on confirmed CSAM. Where required or appropriate, we may report to competent law-enforcement agencies, national or regional child-protection bodies, and applicable statutory reporting organizations, and we will respond lawfully to valid investigation, evidence-preservation, and data requests.
11.10 Child Safety Point of Contact. Bifrost's designated child-safety contact email is 205296199@qq.com. This channel receives CSAE / CSAM notices from Google Play, law-enforcement agencies, child-protection organizations, and users, and handles communications about Bifrost's prevention, review, enforcement, and compliance practices.
Chapter 12 Additional Explanations for Overseas Users
12.1 Applicable Law. If you are located in the EU, UK, US California, or other regions with specialized privacy laws, local laws may grant you rights to access, correct, delete, restrict processing, object to processing, data portability, withdraw consent, opt-out of sale/sharing of personal info, opt-out of targeted advertising, complain to supervisory authorities, etc. We will provide corresponding paths within applicable legal requirements.
12.2 Processing Basis. When applicable overseas laws apply, our basis for processing personal info may include fulfilling a contract with you, obtaining consent, complying with legal obligations, protecting your/others' vital interests, public interest, and legitimate interests like account security, service improvement, content governance, anti-fraud, and commercial operations, provided they do not override your rights.
12.3 International Transfers. If your info is transferred cross-border to other countries/regions, we will adopt standard contractual clauses, data transfer agreements, certification, encryption, minimization, access control, or other compliance measures according to applicable laws.
12.4 Localized Terms. As Bifrost enters specific countries/regions, we may publish localized privacy supplementary terms. If this Policy is inconsistent with localized supplementary terms, the terms more compliant with local mandatory legal requirements shall prevail.
Chapter 13 Policy Updates
13.1 Update Situations. We may update this Policy when laws/regulations or regulatory requirements change, product functions, personal info processing purposes, methods, info types, sharing recipients, cross-border paths, SDKs, permissions, AI or algorithm mechanisms undergo major changes, or corporate mergers/divisions/acquisitions occur.
13.2 Notification Methods. Major changes will be notified via pop-ups, announcements, site messages, push, SMS, emails, or page prompts, and consent or separate consent will be re-obtained when legally required. If you disagree with updated content, you should stop using affected functions.
13.3 Version Archiving. We recommend keeping historical versions or update summaries within the product to help users understand policy changes.
Chapter 14 Contact Us
Company Name: Beijing Yanwan Technology Co., Ltd.
Registered Address: Room 1587, 1st Floor, Building 9, No. 18 Tianhe North Road, Huangcun Town, Daxing District, Beijing
Office Address: No. 400 Wanquansi, Fengtai District, Beijing
Personal Information Protection Contact Email: thebifrost@126.com
If you have any questions, complaints, reports, rights requests, or minor protection requests regarding this Policy or personal information processing activities, please contact us via the above methods. To protect account and personal info security, we may need to verify your identity and request scope.
Appendix 1: Boundaries Between Necessary Personal Info and Extended Info
|
Function |
Necessary or Common Info |
Impact of Refusal |
|
Basic Account Services |
Mobile number or email, verification code or password, Account ID, necessary device & log info |
Refusal to provide will render registration, login, or account security impossible |
|
Public Community Browsing |
Usually no identity profile required; may generate necessary logs, IP address, browsing security records |
Refusing non-necessary authorization does not affect browsing public content |
|
Content Publishing & Interaction |
Nickname, avatar or account ID, published content, comments, likes, favorites, reporting records |
Refusal to provide will render publishing or interaction impossible |
|
Matching and Companionship |
Basic profile, language goals, interest/goal tags, matching records, companionship relations, photo display status |
Refusal to provide will render precise matching, lighting, or companionship unusable |
|
AI and Translation |
User input content, voice, context, and service logs |
Refusal to provide will render obtaining AI or translation results impossible |
|
Location Functions |
Coarse or precise location |
Refusal doesn't affect non-location functions, but nearby, location marking, or location-based events are unusable |
|
Payment and Transactions |
Orders, payment status, invoices, shipping info |
Refusal to provide will render purchase, shipping, or after-sales impossible |
Appendix 2: Main Compliance Basis Reference
This appendix is used to prompt the main laws, administrative regulations, departmental rules, and regulatory rules referenced by this document. The platform will continuously update it based on product launch regions, function implementation, user scale, qualification acquisition, SDK integration, and regulatory requirements.
|
Field |
Basis |
|
Personal Information and Data Security |
"Personal Information Protection Law of the PRC", "Data Security Law of the PRC", "Cybersecurity Law of the PRC", "Network Data Security Management Regulations", "Measures for the Management of Personal Information Protection Compliance Audits", etc. |
|
App and Permission Compliance |
"Provisions on the Scope of Necessary Personal Information for Common Types of Mobile Internet Applications" and related regulatory requirements for App personal info protection, permission calls, and SDK management. |
|
Algorithms and AI |
"Provisions on the Management of Algorithmic Recommendations in Internet Information Services", "Interim Measures for the Management of Generative Artificial Intelligence Services", "Interim Measures for the Management of AI Anthropomorphic Interactive Services" (effective July 15, 2026), etc. |
|
Content Community |
"Provisions on the Governance of the Online Information Content Ecosystem", "Provisions on the Management of Internet User Account Information", "Provisions on the Management of Internet Post Comment Services", etc. |
|
Minors |
"Regulations on the Online Protection of Minors", "Provisions on the Cyber Protection of Children's Personal Information", and related norms for minor modes and internet addiction prevention. |
|
Cross-Border and International |
Rules for personal info export security assessment, personal info protection certification, personal info export standard contract filing, as well as privacy, consumer protection, platform governance, AI, and minor protection laws applicable in target countries or regions. |