Airople

Airople隐私政策Airople Privacy Policy

文档版本 2026-08-20 Document version 2026-08-20

最后更新及生效日期:2026年8月20日

1. 适用范围与责任主体

本隐私政策说明深圳深水创新科技有限公司(英文识别名称:Shenzhen Deepwater Innovation Technology Co., Ltd.,简称"Airople"或"我们")如何通过Airople移动应用、关联云服务、客户支持及链接至本政策的页面(合称"服务")处理个人信息。我们决定本政策所述处理活动的目的和方式。

本APP用于配合包括F01T在内的兼容血压计,记录、展示、整理和导出测量结果,并可选择使用云同步及AI健康说明。我们不代表医院、医生、保险公司或雇主处理信息;对于这些消费者服务,我们不是HIPAA受规制实体或业务伙伴。

2. 简明摘要

3. 我们收集的信息

3.1 账号与资料

邮箱、昵称、账号标识、密码哈希、认证状态、语言、时区、单位及偏好设置。若选择Google登录,我们会接收Google提供的身份令牌、账号标识、邮箱及资料名称。若选择Apple登录,我们会接收Apple提供的身份令牌、账号标识及您选择共享的邮箱地址(可能是Apple私密转发地址@privaterelay.appleid.com)。我们还会接收一次性授权码,仅用于获取在您删除账号时撤销Apple登录关联所需的凭证。我们不向Apple请求或接收您的姓名。我们不收集手机号。用户选择的头像保留在手机本地,不上传云端。

3.2 健康与健康管理数据

收缩压、舒张压、脉搏、测量日期和时间、时区偏移、血压计提供的不规则心跳/袖带/移动提示、手动录入测量值、体重、睡眠记录、提醒、趋势、报告及您要求导出的信息。我们不收集出生日期、性别或身高。

3.3 设备及技术数据

血压计序列号或蓝牙标识、APP生成的设备ID、平台、APP版本、语言、时区、FCM推送令牌、连接状态、服务器访问日志及IP地址。APP调试日志保留在手机本地。我们不会常规收集手机型号、精确位置、广告标识符或跨应用跟踪数据。若您在客服或反馈内容中主动提供设备或机型信息,我们仅为调查和回复该事项而处理。

3.4 客服、权利请求及AI内容

客服消息及回复、Care网站留资和问卷内容、隐私权请求、导出请求,以及验证和完成请求所需的信息。若您另行启用AI,我们会处理您选择提交的测量读数、体重或睡眠背景、问题及反馈,以及生成的回复、报告和安全标记。

4. 信息来源

信息来自您本人、通过蓝牙连接的兼容血压计、您的手机及操作系统、您选择Google登录或Apple登录时的Google或Apple,以及我们的签约服务商。我们不向数据经纪商购买健康数据。

5. 使用目的

6. 服务商与披露

我们仅为下列目的披露合理必要的信息。处理商须依合同和我们的指示处理,采用适当保障措施,并协助履行删除和安全义务。

7. 您的选择

7.1 本地健康数据模式

APP要求创建账号,因此账号及认证数据会在线处理。若不开启云同步,血压、脉搏、体重及睡眠记录保留在APP本地SQLite数据库中;云同步、跨设备访问、服务端通知、在线导出和AI功能不可用。

7.2 云同步

云同步在您另行同意前保持关闭。您可以之后关闭以停止未来健康数据上传。已有云端数据会保留至您删除云端记录或账号。撤回后,本地待上传记录不得继续上传,除非您重新开启云同步。

7.3 AI健康洞察

AI在首次使用时另行同意前保持关闭。您可撤回同意以停止未来AI提交。已有AI报告和对话历史会保留至您删除或注销账号。您删除AI对话后,一份去标识化副本可能另行保留用于安全审查及滥用调查,直至您删除账号。AI输出仅供参考,可能不准确。

7.4 通知

您可在APP内按类别以及通过系统设置控制服务通知。我们不发送营销邮件或短信,也不使用健康数据进行广告投放。

8. 保留与删除

9. 美国存储及中国远程访问

主要生产应用及PostgreSQL数据库托管于Microsoft Azure美国西部2区;Azure OpenAI位于美国东部2区。我们不在中国常态维护生产健康数据库。位于中国的授权人员可通过加密连接远程访问美国系统,用于部署、安全、故障排查、客服、隐私请求及经批准的导出任务。

访问受到实名独立账号、基于角色的最小权限、多因素认证、审批与撤权流程及审计日志限制。除非为经批准任务所必需,否则禁止下载或本地复制至中国;确需导出时应限制范围、加密、记录并在批准期限内删除。不同国家的隐私及政府访问规则可能不同。

10. 安全与泄露通知

我们根据健康数据的敏感程度采用管理、技术及物理保障措施,包括HTTPS、访问控制、实名管理员账号、多因素认证、日志、环境隔离、数据最小化、人员保密义务及事件响应程序。任何系统均无法保证绝对安全。

若泄露事件触发FTC健康信息泄露通知规则或其他适用法律,我们将按要求及时通知受影响个人、FTC及其他主管机关或媒体。

11. 您的隐私权

根据您所在州,您可能有权确认处理、访问数据及接收方清单、更正不准确数据、取得可携带副本、删除数据、撤回同意、退出出售/定向广告/特定画像、限制敏感信息的特定使用,并对拒绝处理提出申诉。我们不出售数据,也不将其用于定向广告。

您可通过隐私中心、https://airople.com/privacy-rights或privacy@airople.com提交请求。我们可能验证您的身份。我们通常在45日内答复;合理必要时可通知后延长一次、最长45日。申诉可通过相同渠道提交。我们不会因您行使权利而歧视您。

12. 加州及其他美国州通知

在综合性州隐私法适用时,所收集类别包括标识符、账号与认证信息、设备及网络活动、通信、健康与健康管理数据,以及报告中包含的推断。来源、目的、接收方及保留规则见上文。我们不出售个人信息,也不为跨场景行为广告共享个人信息,并且不会明知而出售或共享16岁以下消费者的数据。

单独的《消费者健康数据隐私政策》位于https://airople.com/consumer-health-data。若未来实践变更为出售或为定向广告共享,我们将在开始前更新通知并提供法律要求的退出选择。

13. 年龄与儿童

本服务面向18岁及以上成年人,不针对13岁以下儿童。我们不会明知收集13岁以下儿童的个人信息。若您认为儿童向我们提供了信息,请联系我们,以便调查并删除。

14. 变更

我们可能更新本政策。我们会发布新的生效日期,并对重大变更提供显著的APP内通知或邮件通知。若新法律要求对新的健康数据类别、目的或共享接收方取得同意,我们将在变更生效前取得。

15. 联系我们

隐私:privacy@airople.com。客服:support@airople.com。公司:深圳深水创新科技有限公司(Shenzhen Deepwater Innovation Technology Co., Ltd.)。地址:中国广东省深圳市宝安区福海街道塘尾社区工业大道6号C栋607室。官网:https://airople.com。

Last Updated and Effective: August 20, 2026

1. Scope and controller

This Privacy Policy explains how Shenzhen Deepwater Innovation Technology Co., Ltd. (Chinese legal name: 深圳深水创新科技有限公司; "Airople," "we," "us" or "our") handles personal information through the Airople mobile application, connected cloud services, customer support, and pages that link to this Policy (collectively, the "Services"). We determine the purposes and means of processing described here.

The App is a companion for compatible blood-pressure monitors, including F01T. It records, displays, organizes and exports measurements and may provide optional cloud synchronization and AI health explanations. We do not act for a hospital, physician, insurer or employer, and we are not a HIPAA covered entity or business associate for these consumer Services.

2. Short summary

3. Information we collect

3.1 Account and profile

Email address, nickname, account identifier, password hash, authentication status, language, time zone, units and preferences. If you choose Google Sign-In, we receive the identity token, Google account identifier, email and profile name made available by Google. If you choose Sign in with Apple, we receive the identity token, Apple account identifier and the email address you choose to share, which may be an Apple private-relay address (@privaterelay.appleid.com). We also receive a one-time authorization code, used only to obtain the credential needed to revoke the Apple sign-in link when you delete your account. We do not request or receive your name from Apple. We do not collect a phone number. A user-selected avatar remains on the phone and is not uploaded.

3.2 Health and wellness data

Systolic and diastolic blood pressure, pulse, measurement date and time, time-zone offset, monitor-provided irregular-heartbeat, cuff or movement indicators, manually entered measurements, weight, sleep records, reminders, trends, reports and information included in exports you request. We do not collect date of birth, sex or height.

3.3 Device and technical data

Monitor serial number or Bluetooth identifier, an App-generated device ID, platform, App version, language, time zone, FCM push token, connection status, server access logs and IP address. App debugging logs remain on the phone. We do not routinely collect the phone model, precise location, advertising identifier or cross-app tracking data. If you voluntarily include device or model information in a support or feedback submission, we process it only to investigate and respond to that submission.

3.4 Support, rights and AI content

Support messages and replies, Care website inquiry and questionnaire content, privacy-rights requests, export requests and information needed to verify and complete them. If you separately enable AI, we process the readings, weight or sleep context, questions and feedback you choose to submit, together with generated responses, reports and safety flags.

4. Sources

We obtain information from you, the compatible monitor through Bluetooth, your phone and operating system, Google or Apple if you choose Google Sign-In or Sign in with Apple, and our contracted service providers. We do not purchase health data from data brokers.

5. How we use information

6. Service providers and disclosures

We disclose only information reasonably necessary for the purposes below. Processors must act under contract and our instructions, use appropriate safeguards and assist with deletion and security obligations.

7. Your choices

7.1 Local health-data mode

An account is required, so account and authentication data is processed online. If you do not enable Cloud Sync, blood-pressure, pulse, weight and sleep records remain in the App's local SQLite database. Cloud synchronization, cross-device access, server-generated notifications, online export and AI features are unavailable.

7.2 Cloud Sync

Cloud Sync is off until you give separate consent. You may turn it off later to stop future health-data uploads. Existing cloud data remains until you delete the cloud records or your account. Pending local records must not upload after withdrawal unless you enable Cloud Sync again.

7.3 AI Health Insights

AI is off until you give separate consent at first use. You may withdraw consent to stop future AI submissions. Existing AI reports and conversation history remain until you delete them or delete your account. When you delete an AI conversation, a de-identified copy may be retained separately for safety review and abuse investigation until you delete your account. AI output is informational and may be inaccurate.

7.4 Notifications

You may control service notifications by category in the App and through system settings. We do not send marketing email or SMS and do not use health data for advertising.

8. Retention and deletion

9. U.S. storage and access from China

The primary production application and PostgreSQL database are hosted in Microsoft Azure West US 2; Azure OpenAI is in East US 2. We do not maintain a routine production health database in China. Authorized personnel located in China may remotely access the U.S. systems through encrypted connections for deployment, security, troubleshooting, support, privacy requests and approved export tasks.

Access is limited by individually assigned accounts, role-based least privilege, multi-factor authentication, approval and revocation procedures, and audit logging. Download or local copying to China is prohibited unless necessary for an approved task, limited in scope, encrypted, logged and deleted within the approved period. Privacy and government-access rules may differ between countries.

10. Security and breach notice

We use administrative, technical and physical safeguards appropriate to the sensitivity of health data, including HTTPS, access controls, named administrator accounts, multi-factor authentication, logging, environment separation, data minimization, staff confidentiality and incident-response procedures. No system is completely secure.

If a breach triggers the FTC Health Breach Notification Rule or another applicable law, we will notify affected individuals, the FTC and other authorities or media as required, without unreasonable delay.

11. Your privacy rights

Depending on your state, you may have rights to confirm processing; access data and a list of recipients; correct inaccuracies; obtain a portable copy; delete data; withdraw consent; opt out of sale, targeted advertising or certain profiling; limit certain uses of sensitive information; and appeal a refusal. We do not sell data or use it for targeted advertising.

Submit requests in Privacy Center, at https://airople.com/privacy-rights, or to privacy@airople.com. We may verify your identity. We generally respond within 45 days and may extend once by 45 days when reasonably necessary with notice. Appeals may be submitted through the same channel. We will not discriminate against you for exercising rights.

12. California and other U.S. state notices

Where a comprehensive state privacy law applies, the categories collected include identifiers, account and authentication information, device and network activity, communications, health and wellness data, and inferences contained in reports. Sources, purposes, recipients and retention are described above. We do not sell or share personal information for cross-context behavioral advertising and do not knowingly sell or share data of consumers under 16.

Our separate Consumer Health Data Privacy Policy is available at https://airople.com/consumer-health-data. If our practices change to include sale or targeted-advertising sharing, we will update notices and provide any legally required opt-out before beginning that practice.

13. Age and children

The Services are for adults age 18 or older and are not directed to children under 13. We do not knowingly collect personal information from a child under 13. Contact us if you believe a child provided information so we can investigate and delete it.

14. Changes

We may update this Policy. We will post the new effective date and provide a prominent in-App or email notice for material changes. If a new law requires consent for a new health-data category, purpose or sharing recipient, we will obtain it before the change takes effect.

15. Contact

Privacy: privacy@airople.com. Support: support@airople.com. Company: Shenzhen Deepwater Innovation Technology Co., Ltd. (深圳深水创新科技有限公司). Address: Room 607, Building C, No. 6 Industrial Avenue, Tangwei Community, Fuhai Subdistrict, Bao'an District, Shenzhen, Guangdong, China. Website: https://airople.com.