最后更新及生效日期:2026年8月20日
1. 适用范围与责任主体
本隐私政策说明深圳深水创新科技有限公司(英文识别名称:Shenzhen Deepwater Innovation Technology Co., Ltd.,简称"Airople"或"我们")如何通过Airople移动应用、关联云服务、客户支持及链接至本政策的页面(合称"服务")处理个人信息。我们决定本政策所述处理活动的目的和方式。
本APP用于配合包括F01T在内的兼容血压计,记录、展示、整理和导出测量结果,并可选择使用云同步及AI健康说明。我们不代表医院、医生、保险公司或雇主处理信息;对于这些消费者服务,我们不是HIPAA受规制实体或业务伙伴。
2. 简明摘要
- 进入APP必须创建账号;但您可以拒绝上传健康记录至云端,仍可配对血压计、测量并查看本地历史。
- 云同步和AI健康洞察为相互独立的选择,在您开启前均为关闭状态。
- 主要云数据库位于美国;位于中国的授权人员可能为有限运维目的远程访问云端数据。
- 我们不出售个人或健康数据,不为跨场景行为广告共享数据,APP也不含广告或分析SDK。
- 您可以访问、更正、导出和删除数据,撤回可选同意,并删除账号。
3. 我们收集的信息
3.1 账号与资料
邮箱、昵称、账号标识、密码哈希、认证状态、语言、时区、单位及偏好设置。若选择Google登录,我们会接收Google提供的身份令牌、账号标识、邮箱及资料名称。若选择Apple登录,我们会接收Apple提供的身份令牌、账号标识及您选择共享的邮箱地址(可能是Apple私密转发地址@privaterelay.appleid.com)。我们还会接收一次性授权码,仅用于获取在您删除账号时撤销Apple登录关联所需的凭证。我们不向Apple请求或接收您的姓名。我们不收集手机号。用户选择的头像保留在手机本地,不上传云端。
3.2 健康与健康管理数据
收缩压、舒张压、脉搏、测量日期和时间、时区偏移、血压计提供的不规则心跳/袖带/移动提示、手动录入测量值、体重、睡眠记录、提醒、趋势、报告及您要求导出的信息。我们不收集出生日期、性别或身高。
3.3 设备及技术数据
血压计序列号或蓝牙标识、APP生成的设备ID、平台、APP版本、语言、时区、FCM推送令牌、连接状态、服务器访问日志及IP地址。APP调试日志保留在手机本地。我们不会常规收集手机型号、精确位置、广告标识符或跨应用跟踪数据。若您在客服或反馈内容中主动提供设备或机型信息,我们仅为调查和回复该事项而处理。
3.4 客服、权利请求及AI内容
客服消息及回复、Care网站留资和问卷内容、隐私权请求、导出请求,以及验证和完成请求所需的信息。若您另行启用AI,我们会处理您选择提交的测量读数、体重或睡眠背景、问题及反馈,以及生成的回复、报告和安全标记。
4. 信息来源
信息来自您本人、通过蓝牙连接的兼容血压计、您的手机及操作系统、您选择Google登录或Apple登录时的Google或Apple,以及我们的签约服务商。我们不向数据经纪商购买健康数据。
5. 使用目的
- 创建、认证和保护账号,并隔离不同账号的数据。
- 与兼容血压计配对,并按您的指示接收、保存、去重、展示、整理、编辑、删除和导出记录。
- 提供提醒、趋势、报告、客服、隐私请求及可选云同步。
- 仅在单独选择加入后提供AI说明,并执行安全控制及滥用调查。
- 发送您要求或配置的验证邮件、服务消息、提醒通知、周报及客服回复。
- 运营、保护和排查服务故障,防止欺诈,遵守法律,执行协议,并保护用户和公众。
6. 服务商与披露
我们仅为下列目的披露合理必要的信息。处理商须依合同和我们的指示处理,采用适当保障措施,并协助履行删除和安全义务。
- Microsoft Azure(美国西部2区):应用托管、PostgreSQL数据库、服务器日志及备份。
- Microsoft Azure OpenAI(美国东部2区):在另行同意后提供可选AI说明。提交内容不用于训练Microsoft或第三方基础模型;Microsoft滥用监控副本最长可保留30天。
- Google Firebase Cloud Messaging:推送令牌和不含敏感信息的服务通知载荷;推送载荷不包含健康读数。
- Google登录:仅在您选择Google登录时处理身份令牌及基础账号信息。
- Apple Inc.(Apple登录):您选择Apple登录时的身份令牌及基础账号信息,以及您删除账号时向Apple发送的撤销请求。
- Azure Communication Services:在美国提供验证及服务邮件发送。
- 位于中国的Airople授权运维、安全及客服人员:按第9节所述进行有限远程访问。
- 在法律合规、争议、安全或公司交易合理必要时,向专业顾问、主管机关或交易相对方披露,并采取适当保护。
7. 您的选择
7.1 本地健康数据模式
APP要求创建账号,因此账号及认证数据会在线处理。若不开启云同步,血压、脉搏、体重及睡眠记录保留在APP本地SQLite数据库中;云同步、跨设备访问、服务端通知、在线导出和AI功能不可用。
7.2 云同步
云同步在您另行同意前保持关闭。您可以之后关闭以停止未来健康数据上传。已有云端数据会保留至您删除云端记录或账号。撤回后,本地待上传记录不得继续上传,除非您重新开启云同步。
7.3 AI健康洞察
AI在首次使用时另行同意前保持关闭。您可撤回同意以停止未来AI提交。已有AI报告和对话历史会保留至您删除或注销账号。您删除AI对话后,一份去标识化副本可能另行保留用于安全审查及滥用调查,直至您删除账号。AI输出仅供参考,可能不准确。
7.4 通知
您可在APP内按类别以及通过系统设置控制服务通知。我们不发送营销邮件或短信,也不使用健康数据进行广告投放。
8. 保留与删除
- 账号及云端健康记录在账号存续期间保留,或保留至您主动删除。
- 单条健康记录删除后在回收站保留30天以供恢复。期满后,该记录进入最终删除范围,并在回收站清理程序下次运行时从活动系统移除。
- AI报告及对话保留至您删除或注销账号;Microsoft滥用监控副本最长可保留30天。您删除AI对话后,一份去标识化副本可能另行保留用于安全审查及滥用调查,直至您删除账号。
- 安全、服务器及管理员审计日志、已关闭的客服与意见反馈记录,以及有限的邮箱验证码记录,最长可保留24个月。账号删除后,管理员审计日志中的操作者标识可在适当情况下解除关联。法律争议或法定义务合理需要更长期限的除外。
- 经验证的账号删除请求提交后,活动生产数据会被及时删除。隔离备份按备份周期覆盖或删除;对于消费者健康数据,最迟不超过请求验证后的180天。
- 在安全、防欺诈、法律合规或争议处理要求或允许时,我们可有限保留信息,并限制其仅用于该目的。
9. 美国存储及中国远程访问
主要生产应用及PostgreSQL数据库托管于Microsoft Azure美国西部2区;Azure OpenAI位于美国东部2区。我们不在中国常态维护生产健康数据库。位于中国的授权人员可通过加密连接远程访问美国系统,用于部署、安全、故障排查、客服、隐私请求及经批准的导出任务。
访问受到实名独立账号、基于角色的最小权限、多因素认证、审批与撤权流程及审计日志限制。除非为经批准任务所必需,否则禁止下载或本地复制至中国;确需导出时应限制范围、加密、记录并在批准期限内删除。不同国家的隐私及政府访问规则可能不同。
10. 安全与泄露通知
我们根据健康数据的敏感程度采用管理、技术及物理保障措施,包括HTTPS、访问控制、实名管理员账号、多因素认证、日志、环境隔离、数据最小化、人员保密义务及事件响应程序。任何系统均无法保证绝对安全。
若泄露事件触发FTC健康信息泄露通知规则或其他适用法律,我们将按要求及时通知受影响个人、FTC及其他主管机关或媒体。
11. 您的隐私权
根据您所在州,您可能有权确认处理、访问数据及接收方清单、更正不准确数据、取得可携带副本、删除数据、撤回同意、退出出售/定向广告/特定画像、限制敏感信息的特定使用,并对拒绝处理提出申诉。我们不出售数据,也不将其用于定向广告。
您可通过隐私中心、https://airople.com/privacy-rights或privacy@airople.com提交请求。我们可能验证您的身份。我们通常在45日内答复;合理必要时可通知后延长一次、最长45日。申诉可通过相同渠道提交。我们不会因您行使权利而歧视您。
12. 加州及其他美国州通知
在综合性州隐私法适用时,所收集类别包括标识符、账号与认证信息、设备及网络活动、通信、健康与健康管理数据,以及报告中包含的推断。来源、目的、接收方及保留规则见上文。我们不出售个人信息,也不为跨场景行为广告共享个人信息,并且不会明知而出售或共享16岁以下消费者的数据。
单独的《消费者健康数据隐私政策》位于https://airople.com/consumer-health-data。若未来实践变更为出售或为定向广告共享,我们将在开始前更新通知并提供法律要求的退出选择。
13. 年龄与儿童
本服务面向18岁及以上成年人,不针对13岁以下儿童。我们不会明知收集13岁以下儿童的个人信息。若您认为儿童向我们提供了信息,请联系我们,以便调查并删除。
14. 变更
我们可能更新本政策。我们会发布新的生效日期,并对重大变更提供显著的APP内通知或邮件通知。若新法律要求对新的健康数据类别、目的或共享接收方取得同意,我们将在变更生效前取得。
15. 联系我们
隐私:privacy@airople.com。客服:support@airople.com。公司:深圳深水创新科技有限公司(Shenzhen Deepwater Innovation Technology Co., Ltd.)。地址:中国广东省深圳市宝安区福海街道塘尾社区工业大道6号C栋607室。官网:https://airople.com。
Last Updated and Effective: August 20, 2026
1. Scope and controller
This Privacy Policy explains how Shenzhen Deepwater Innovation Technology Co., Ltd. (Chinese legal name: 深圳深水创新科技有限公司; "Airople," "we," "us" or "our") handles personal information through the Airople mobile application, connected cloud services, customer support, and pages that link to this Policy (collectively, the "Services"). We determine the purposes and means of processing described here.
The App is a companion for compatible blood-pressure monitors, including F01T. It records, displays, organizes and exports measurements and may provide optional cloud synchronization and AI health explanations. We do not act for a hospital, physician, insurer or employer, and we are not a HIPAA covered entity or business associate for these consumer Services.
2. Short summary
- An account is required to enter the App. You may decline cloud upload of health records and still pair the monitor, measure and view local history.
- Cloud Sync and AI Health Insights are separate choices and are off until you enable them.
- The primary cloud database is in the United States. Authorized personnel located in China may remotely access cloud data for limited operational purposes.
- We do not sell personal or health data, share it for cross-context behavioral advertising, or include advertising or analytics SDKs in the App.
- You can access, correct, export and delete data, withdraw optional consent, and delete your account.
3. Information we collect
3.1 Account and profile
Email address, nickname, account identifier, password hash, authentication status, language, time zone, units and preferences. If you choose Google Sign-In, we receive the identity token, Google account identifier, email and profile name made available by Google. If you choose Sign in with Apple, we receive the identity token, Apple account identifier and the email address you choose to share, which may be an Apple private-relay address (@privaterelay.appleid.com). We also receive a one-time authorization code, used only to obtain the credential needed to revoke the Apple sign-in link when you delete your account. We do not request or receive your name from Apple. We do not collect a phone number. A user-selected avatar remains on the phone and is not uploaded.
3.2 Health and wellness data
Systolic and diastolic blood pressure, pulse, measurement date and time, time-zone offset, monitor-provided irregular-heartbeat, cuff or movement indicators, manually entered measurements, weight, sleep records, reminders, trends, reports and information included in exports you request. We do not collect date of birth, sex or height.
3.3 Device and technical data
Monitor serial number or Bluetooth identifier, an App-generated device ID, platform, App version, language, time zone, FCM push token, connection status, server access logs and IP address. App debugging logs remain on the phone. We do not routinely collect the phone model, precise location, advertising identifier or cross-app tracking data. If you voluntarily include device or model information in a support or feedback submission, we process it only to investigate and respond to that submission.
3.4 Support, rights and AI content
Support messages and replies, Care website inquiry and questionnaire content, privacy-rights requests, export requests and information needed to verify and complete them. If you separately enable AI, we process the readings, weight or sleep context, questions and feedback you choose to submit, together with generated responses, reports and safety flags.
4. Sources
We obtain information from you, the compatible monitor through Bluetooth, your phone and operating system, Google or Apple if you choose Google Sign-In or Sign in with Apple, and our contracted service providers. We do not purchase health data from data brokers.
5. How we use information
- Create, authenticate and secure accounts and keep data separated between accounts.
- Pair with a compatible monitor; receive, store, de-duplicate, display, organize, edit, delete and export records at your direction.
- Provide reminders, trends, reports, support, privacy requests and optional cloud synchronization.
- Provide AI explanations only after separate opt-in; apply safety controls and investigate abuse.
- Send verification emails, service messages, reminder notifications, weekly reports and support replies that you request or configure.
- Operate, secure and troubleshoot the Services; prevent fraud; comply with law; enforce agreements; and protect users and the public.
6. Service providers and disclosures
We disclose only information reasonably necessary for the purposes below. Processors must act under contract and our instructions, use appropriate safeguards and assist with deletion and security obligations.
- Microsoft Azure (West US 2): application hosting, PostgreSQL database, server logs and backups.
- Microsoft Azure OpenAI (East US 2): optional AI explanations after separate consent. Submitted content is not used to train Microsoft or third-party foundation models; Microsoft abuse-monitoring copies may be retained for up to 30 days.
- Google Firebase Cloud Messaging: push token and non-sensitive service-notification payloads. Health readings are not included in push payloads.
- Google Sign-In: identity token and basic account information only when you choose Google login.
- Apple Inc. (Sign in with Apple): identity token and basic account information when you choose Apple login, and revocation requests sent to Apple when you delete your account.
- Azure Communication Services: verification and service email delivery in the United States.
- Authorized Airople operations, security and support personnel in China: limited remote access as described in Section 9.
- Professional advisers, authorities or transaction counterparties where reasonably necessary for legal compliance, claims, security or a corporate transaction, subject to appropriate protections.
7. Your choices
7.1 Local health-data mode
An account is required, so account and authentication data is processed online. If you do not enable Cloud Sync, blood-pressure, pulse, weight and sleep records remain in the App's local SQLite database. Cloud synchronization, cross-device access, server-generated notifications, online export and AI features are unavailable.
7.2 Cloud Sync
Cloud Sync is off until you give separate consent. You may turn it off later to stop future health-data uploads. Existing cloud data remains until you delete the cloud records or your account. Pending local records must not upload after withdrawal unless you enable Cloud Sync again.
7.3 AI Health Insights
AI is off until you give separate consent at first use. You may withdraw consent to stop future AI submissions. Existing AI reports and conversation history remain until you delete them or delete your account. When you delete an AI conversation, a de-identified copy may be retained separately for safety review and abuse investigation until you delete your account. AI output is informational and may be inaccurate.
7.4 Notifications
You may control service notifications by category in the App and through system settings. We do not send marketing email or SMS and do not use health data for advertising.
8. Retention and deletion
- Account and cloud health records are retained while the account is active or until you delete them.
- Deleted individual health records remain recoverable in the recycle bin for 30 days. After that period, they are eligible for final deletion and are removed from active systems when the recycle-bin cleanup next runs.
- AI reports and conversations are retained until you delete them or delete the account; Microsoft abuse-monitoring copies may remain for up to 30 days. When you delete an AI conversation, a de-identified copy may be retained separately for safety review and abuse investigation until you delete your account.
- Security, server and administrator-audit logs, closed support and feedback records, and limited email-verification records may be retained for up to 24 months. Operator identifiers in administrator-audit logs may be de-linked after account deletion where appropriate. A longer period may apply where reasonably necessary for a legal claim or legal obligation.
- After an authenticated account-deletion request, active production data is deleted without undue delay. Isolated backup copies are overwritten or deleted on the backup cycle and, for consumer health data, no later than 180 days after authentication of the request.
- We may retain limited information where required or permitted for security, fraud prevention, legal compliance or claims, and will restrict it to that purpose.
9. U.S. storage and access from China
The primary production application and PostgreSQL database are hosted in Microsoft Azure West US 2; Azure OpenAI is in East US 2. We do not maintain a routine production health database in China. Authorized personnel located in China may remotely access the U.S. systems through encrypted connections for deployment, security, troubleshooting, support, privacy requests and approved export tasks.
Access is limited by individually assigned accounts, role-based least privilege, multi-factor authentication, approval and revocation procedures, and audit logging. Download or local copying to China is prohibited unless necessary for an approved task, limited in scope, encrypted, logged and deleted within the approved period. Privacy and government-access rules may differ between countries.
10. Security and breach notice
We use administrative, technical and physical safeguards appropriate to the sensitivity of health data, including HTTPS, access controls, named administrator accounts, multi-factor authentication, logging, environment separation, data minimization, staff confidentiality and incident-response procedures. No system is completely secure.
If a breach triggers the FTC Health Breach Notification Rule or another applicable law, we will notify affected individuals, the FTC and other authorities or media as required, without unreasonable delay.
11. Your privacy rights
Depending on your state, you may have rights to confirm processing; access data and a list of recipients; correct inaccuracies; obtain a portable copy; delete data; withdraw consent; opt out of sale, targeted advertising or certain profiling; limit certain uses of sensitive information; and appeal a refusal. We do not sell data or use it for targeted advertising.
Submit requests in Privacy Center, at https://airople.com/privacy-rights, or to privacy@airople.com. We may verify your identity. We generally respond within 45 days and may extend once by 45 days when reasonably necessary with notice. Appeals may be submitted through the same channel. We will not discriminate against you for exercising rights.
12. California and other U.S. state notices
Where a comprehensive state privacy law applies, the categories collected include identifiers, account and authentication information, device and network activity, communications, health and wellness data, and inferences contained in reports. Sources, purposes, recipients and retention are described above. We do not sell or share personal information for cross-context behavioral advertising and do not knowingly sell or share data of consumers under 16.
Our separate Consumer Health Data Privacy Policy is available at https://airople.com/consumer-health-data. If our practices change to include sale or targeted-advertising sharing, we will update notices and provide any legally required opt-out before beginning that practice.
13. Age and children
The Services are for adults age 18 or older and are not directed to children under 13. We do not knowingly collect personal information from a child under 13. Contact us if you believe a child provided information so we can investigate and delete it.
14. Changes
We may update this Policy. We will post the new effective date and provide a prominent in-App or email notice for material changes. If a new law requires consent for a new health-data category, purpose or sharing recipient, we will obtain it before the change takes effect.
15. Contact
Privacy: privacy@airople.com. Support: support@airople.com. Company: Shenzhen Deepwater Innovation Technology Co., Ltd. (深圳深水创新科技有限公司). Address: Room 607, Building C, No. 6 Industrial Avenue, Tangwei Community, Fuhai Subdistrict, Bao'an District, Shenzhen, Guangdong, China. Website: https://airople.com.