Privacy Policy

VibeNote Privacy Policy

Welcome to VibeNote (the “Product”). We, Whale Cloud Technology Co., Ltd. (“we” or “us”), understand the importance of personal privacy and information security, and we are committed to protecting your personal information.

This Privacy Policy explains how we collect, use, manage, share, transfer, disclose, protect, and retain your personal information when providing products or services, and explains your rights to access, correct, delete, or otherwise manage your information.

This Policy applies to all VibeNote products and services, including the VibeNote app, web version, WeChat mini program, and other related services. By using our products or services, you acknowledge that you have read, understood, and agreed to this Policy.

1. Definitions

  1. Personal information: information recorded electronically or otherwise that relates to an identified or identifiable natural person, excluding anonymized information.
  2. Sensitive personal information: personal information that may easily cause harm to personal dignity or personal and property safety if leaked or illegally used.
  3. VibeNote: all platforms operated by Whale Cloud Technology Co., Ltd., including the VibeNote app, web version, WeChat mini program, and related applications or websites.
  4. Affiliates: entities that control, are controlled by, or are under common control with a party.
  5. Anonymization: processing personal information so that a specific natural person cannot be identified and the information cannot be restored.

2. How We Collect and Use Your Personal Information

We follow the principles of legality, legitimacy, necessity, and transparency. We collect and use your personal information only for the purposes described in this Policy and will request your consent where required by law.

Account registration, login, and core features

  1. Registration and login: when you register a VibeNote account, we collect your mobile phone number to create your account and verify login through SMS verification codes.
  2. Note features: when you use note synchronization, recording, optimization, query, or search features, we collect text, images, audio, and related information that you actively submit or generate.

Paid services and order management

  1. Virtual goods and payment: if you purchase membership or other paid virtual goods, we collect account and order information and share necessary order details with payment service providers.
  2. Service delivery: after payment is completed, we activate the corresponding paid service. When third-party assistance is required, we share only the necessary order information.

Customer support

When you contact customer service, submit feedback, or request dispute handling, we may collect account information, order information, contact information, and support communication records for identity verification and follow-up.

Security and service improvement

  1. Security: we may use account information, device information, software usage records, and IP addresses to identify risks, prevent fraud, protect account security, and respond to attacks.
  2. Optimization: we may collect device information and usage records to analyze feature usage, improve product functionality, and enhance user experience.

Device permissions

We request device permissions only when needed for product features, and you can enable or disable them in your device settings.

PermissionFeaturePurpose
PhotosImage notes, avatar editing, image savingUpload note images, modify avatars, and save images.
MicrophoneVoice input and speech-to-textRecord voice notes or convert audio to text.
ClipboardCopy and pasteRead local clipboard content to quickly fill note information. Clipboard content is not uploaded to the server.
LocationBLE device scanningScan and connect to BLE devices.

Exceptions where consent may not be required

We may collect and use personal information without consent where permitted by law, including situations involving legal obligations, public security, public health, criminal investigation, protection of vital interests, publicly disclosed information, or secure operation of products and services.

3. Cookies and Similar Technologies

We may use cookies and similar technologies to simplify login, identify account status, and protect account security. You can manage or delete cookies through your browser or device settings.

4. Sharing, Transfer, and Public Disclosure

We do not arbitrarily share, transfer, or publicly disclose your personal information. We may share information with your consent, with affiliates under this Policy, or with partners such as payment providers, security verification providers, and analytics service providers where necessary to provide services.

We transfer personal information only with your consent, as part of mergers, acquisitions, or asset transfers where the recipient remains bound by this Policy, or as required by law. Public disclosure occurs only with your consent or as required by competent authorities after legal review.

5. How We Protect and Retain Your Information

Security measures

  1. We use SSL transmission encryption, asymmetric encryption for sensitive information, and access control mechanisms.
  2. We maintain information security teams, management systems, emergency plans, security checks, and training.
  3. If a personal information security incident occurs, we will activate emergency procedures, take remedial measures, notify you as required by law, and report to regulators where necessary.

Retention

  1. Personal information collected by us is stored within the territory of the People’s Republic of China unless otherwise required by law or with your consent.
  2. We retain personal information only for the period necessary to achieve the purposes described in this Policy or for the period required by law.
  3. After your account cancellation is approved, we delete or anonymize your personal information within the time required by applicable laws and regulations.

6. Your Rights

You have rights to access, correct, supplement, delete, and request account cancellation for your personal information.

Access

You can access account information, order information, and note content through the “Me” page in the VibeNote app or the avatar icon in the lower-left corner of the web version.

Correction and supplementation

If your personal information is inaccurate or incomplete, you may correct or supplement it through the above paths or contact customer service. We will respond within 15 business days.

Deletion

You may request deletion where our processing violates laws, lacks your consent, violates our agreement with you, you no longer use the service, you cancel your account, or we stop providing products or services.

Account cancellation

You can request account cancellation through the VibeNote app “Me” page, the web avatar icon, or manual customer service. We will verify your identity and respond within 15 business days.

Exceptions

We may be unable to respond to requests related to national security, public security, criminal investigation, malicious abuse of rights, damage to lawful rights of others, trade secrets, or legal obligations.

7. Protection of Minors

  1. This Product is mainly intended for adults. Minors under 18 must obtain guardian consent before use; minors under 14 must have their guardian read and agree to this Policy on their behalf.
  2. We collect and use minors’ personal information only as permitted by law, with guardian consent, or where necessary to protect minors. If we discover that minors’ information was collected without guardian consent, we will delete it promptly.
  3. Guardians may contact us through the methods listed in “Contact Us” for questions about minors’ personal information.

8. Updates and Notices

  1. We may update this Policy as products, services, or laws change. Updated versions will be posted prominently in the VibeNote app, web version, or other platforms for no less than seven days.
  2. For major changes, we may notify you through pop-ups, push notifications, emails, or other methods. Continued use means you agree to the updated Policy. If you disagree, you may stop using VibeNote and request account cancellation.

9. Contact Us

  1. For questions, comments, or complaints about this Policy or personal information protection, contact us at vibenote@iwhalecloud.com. We will respond and handle the matter within three business days.
  2. For further communication with our personal information protection officer, please email vibenote@iwhalecloud.com.

Publication date: October 17, 2025

Appendix 1: Operating System Device Permission List

iOS permissions

PermissionFeaturePurpose
NSMicrophoneUsageDescriptionMicrophoneVoice input and speech-to-text.
NSCameraUsageDescriptionCameraTake photos as note content, recording attachments, or feedback screenshots.
NSPhotoLibraryUsageDescriptionPhotosUpload note images, modify avatars, and save images.
NSContactsUsageDescriptionContactsImport phone contacts and create contact groups for sharing notes or managing recipients.
NSBluetoothAlwaysUsageDescription
NSBluetoothPeripheralUsageDescription
BluetoothConnect recorder devices and synchronize audio files.

Android permissions

PermissionFeaturePurpose
android.permission.WRITE_EXTERNAL_STORAGE
android.permission.READ_EXTERNAL_STORAGE
External storageSave images to the device.
android.permission.INTERNET
android.permission.ACCESS_WIFI_STATE
android.permission.ACCESS_NETWORK_STATE
android.permission.CHANGE_WIFI_STATE
NetworkDetermine network status and maintain service connectivity.
android.permission.WAKE_LOCKWake lockKeep the screen awake during audio recording.
android.permission.RECORD_AUDIO
android.permission.MODIFY_AUDIO_SETTINGS
RecordingVoice input and speech-to-text.
android.permission.BLUETOOTH_ADMINBluetoothConnect Bluetooth headsets and support voice recording or playback.
android.permission.READ_CONTACTSContactsOpen local contacts from My Contacts.
android.permission.ACCESS_FINE_LOCATIONLocationScan BLE devices.
android.permission.READ_PHONE_STATEPhone statusDetect phone-call status to pause recording automatically during calls and resume recording after calls end.

Appendix 2: Third-Party SDK Sharing List

1. JPush SDK

OrganizationShenzhen Hexun Huagu Information Technology Co., Ltd.
Product / TypeJPush SDK
Information UsedDevice identifiers including Android ID, GAID, OAID, UAID, IDFA, AAID; device hardware information including model, screen resolution, manufacturer, product name, and storage; operating system information including version, name, and language; network information including network type, carrier, IP address, and Wi-Fi status; push message logs.
Information TypeCommon device information and network identity information
PurposeMessage push
ScenarioUsed for task messages and alert notifications.
PermissionNotification permission (POST_NOTIFICATIONS)
Sharing MethodThe app initializes the SDK, and the SDK obtains information through its own system API logic.
Official Linkhttps://docs.jiguang.cn/jpush/client/Android/android_sdk
Privacy Policyhttps://www.jiguang.cn/license/privacy

2. Umeng+ SDK

OrganizationUmeng Tongxin (Beijing) Technology Co., Ltd. (Alibaba Group)
Product / TypeUmeng+ Analytics and Social Sharing SDK
Information UsedDevice identifiers including IMEI, Android ID, OAID, MAC address, and IDFA; device hardware information including model, operating system version, and screen resolution; network information including network type, carrier, and IP address; app usage data including page visits, event tracking, sharing behavior, and other user operation records.
Information TypeCommon device information, network identity information, and browsing/usage records
PurposeApp analytics and social sharing
ScenarioUsed to analyze app usage data and share content to WeChat or DingTalk.
PermissionNetwork permissions (INTERNET, ACCESS_NETWORK_STATE)
Sharing MethodThe app initializes the SDK, and the SDK obtains information through its own system API logic.
Official Linkhttps://developer.umeng.com/
Privacy Policyhttps://www.umeng.com/policy

3. Tencent Bugly SDK

OrganizationShenzhen Tencent Computer Systems Co., Ltd.
Product / TypeTencent Bugly Crash Analytics SDK
Information UsedDevice hardware information including model, manufacturer, and operating system version; network information including Wi-Fi status, network type, and carrier; app crash logs including crash stack and error logs; user identifiers including user ID, phone number, and nickname.
Information TypeCommon device information and network identity information
PurposeCrash monitoring and analysis
ScenarioUsed to monitor app crashes and troubleshoot errors.
PermissionNetwork permissions (INTERNET, ACCESS_NETWORK_STATE, ACCESS_WIFI_STATE)
Sharing MethodThe app initializes the SDK, and the SDK obtains information through its own system API logic.
Official Linkhttps://bugly.qq.com/
Privacy Policyhttps://privacy.qq.com/

4. Tencent Browser Service SDK (TBS / X5)

OrganizationShenzhen Tencent Computer Systems Co., Ltd.
Product / TypeTencent Browser Service SDK (TBS File SDK)
Information UsedDevice hardware information including model and operating system version; app process information; document file paths.
Information TypeCommon device information
PurposeIn-app document preview
ScenarioUsed to preview Office files, PDFs, and other documents in the app.
PermissionNetwork permission (INTERNET)
Sharing MethodThe app initializes the SDK, and the SDK obtains information through its own system API logic.
Official Linkhttps://x5.tencent.com/
Privacy Policyhttps://privacy.qq.com/

5. Alipay SDK

OrganizationAlipay (China) Network Technology Co., Ltd. (Ant Group)
Product / TypeAlipay Payment SDK
Information UsedDevice identifiers including IMEI, IMSI, MAC address, and Android ID; device hardware information including model and operating system version; network information including network type, carrier, and IP address; order information including payment amount and merchant ID.
Information TypeCommon device information, network identity information, and personal transaction information
PurposeIn-app payment
ScenarioUsed for membership purchases and value-added service payments.
PermissionNetwork permissions (INTERNET, ACCESS_NETWORK_STATE)
Sharing MethodThe app calls the SDK to initiate payment, and the SDK obtains device information through its own logic.
Official Linkhttps://open.alipay.com/
Privacy Policyhttps://opendocs.alipay.com/open/54/01g6qm

6. WeChat Open Platform SDK

OrganizationShenzhen Tencent Computer Systems Co., Ltd.
Product / TypeWeChat Open Platform SDK
Information UsedDevice hardware information including model and operating system version; network information including network type and IP address; WeChat installation status; payment order information.
Information TypeCommon device information, network identity information, and personal transaction information
PurposeWeChat Pay and WeChat sharing
ScenarioUsed for WeChat payments and sharing content to WeChat chats or Moments.
PermissionNetwork permission (INTERNET)
Sharing MethodThe app calls the SDK to initiate payment or sharing, and the SDK obtains necessary device information through its own logic.
Official Linkhttps://open.weixin.qq.com/
Privacy Policyhttps://weixin.qq.com/cgi-bin/readtemplate?lang=zh_CN&t=weixin_agreement&s=privacy

7. DingTalk Sharing SDK

OrganizationAlibaba (China) Co., Ltd.
Product / TypeDingTalk Sharing SDK
Information UsedShared content information including links, images, and text.
Information TypeBrowsing/usage records
PurposeShare content to DingTalk
ScenarioUsed to share app content to DingTalk conversations.
PermissionNetwork permission (INTERNET)
Sharing MethodThe app calls the SDK to initiate sharing, and sharing is completed through the DingTalk client.
Official Linkhttps://open.dingtalk.com/
Privacy Policyhttps://terms.alicdn.com/legal-agreement/terms/suit_bu1_dingtalk/suit_bu1_dingtalk20201007094649608.html

8. Huawei AppGallery Connect SDK

OrganizationHuawei Technologies Co., Ltd.
Product / TypeHuawei AppGallery Connect SDK
Information UsedDevice identifiers including Huawei ID and push token; device hardware information including model, operating system version, and HMS Core version; network information including network type and IP address.
Information TypeCommon device information and network identity information
PurposeHuawei device push channel
ScenarioUsed to receive push messages on Huawei devices as a JPush vendor channel.
PermissionNetwork permission (INTERNET)
Sharing MethodWhen the app initializes JPush, the Huawei push plugin indirectly calls Huawei AGC SDK to obtain the push token.
Official Linkhttps://developer.huawei.com/consumer/cn/agconnect/
Privacy Policyhttps://consumer.huawei.com/minisite/cloudservice/legal/privacy-statement.htm

9. Xiaomi Push SDK

OrganizationBeijing Xiaomi Mobile Software Co., Ltd.
Product / TypeXiaomi Push SDK
Information UsedDevice information including manufacturer, model, region, carrier name, memory, operating system version, Xiaomi Push SDK version, push message content, notification settings, network type, and Wi-Fi status.
Information TypeCommon device information and network identity information
PurposeMessage push
ScenarioUsed to receive push messages on Xiaomi devices as a JPush vendor channel.
PermissionNetwork permission (INTERNET)
Sharing MethodWhen the app initializes JPush, the Xiaomi push plugin indirectly calls Xiaomi Push SDK to obtain the push token.
Official Linkhttps://dev.mi.com/console/appservice/push.html
Privacy Policyhttps://dev.mi.com/xiaomihyperos/documentation/detail?pId=1534

10. Honor Push SDK

OrganizationShenzhen Honor Software Technology Co., Ltd.
Product / TypeHonor Push SDK
Information UsedDevice identifiers including AAID and PushToken, APPID, and app package name.
Information TypeNetwork identity information
PurposeMessage push
ScenarioUsed to receive push messages on Honor devices as a JPush vendor channel.
PermissionNetwork permission (INTERNET)
Sharing MethodWhen the app initializes JPush, the Honor push plugin indirectly calls Honor Push SDK to obtain the push token.
Official Linkhttps://developer.hihonor.com/cn/
Privacy Policyhttps://developer.hihonor.com/cn/kitdoc/?category=%E5%9F%BA%E7%A1%80%E6%9C%8D%E5%8A%A1&kitId=11002&navigation=guides&docId=sdk-data-security.md

11. OPPO Push SDK

OrganizationGuangdong Huantai Technology Co., Ltd.
Product / TypeOPPO Push SDK
Information UsedBasic app information including MCS package name, app version, OPUSH SDK version, and in-app device identifiers including RegistraterID, appKey, and appSecret.
Information TypeNetwork identity information
PurposeMessage push
ScenarioUsed to receive push messages on OPPO devices as a JPush vendor channel.
PermissionNetwork permission (INTERNET)
Sharing MethodWhen the app initializes JPush, the OPPO push plugin indirectly calls OPPO Push SDK to obtain the push token.
Official Linkhttps://open.oppomobile.com/
Privacy Policyhttps://open.oppomobile.com/new/developmentDoc/info?id=11228

12. vivo Push SDK

OrganizationVivo Mobile Communication Co., Ltd.
Product / Typevivo Push SDK
Information UsedBasic app information including appid, appkey, package name, app version, pushSDK version; in-app device identifier regid; device hardware information including device type; basic system information including system type and version.
Information TypeCommon device information and network identity information
PurposeProvide push message services and collect push SDK API success-rate statistics
ScenarioUsed to receive push messages on vivo devices as a JPush vendor channel.
PermissionNetwork permission (INTERNET)
Sharing MethodWhen the app initializes JPush, the vivo push plugin indirectly calls vivo Push SDK to obtain the push token.
Official Linkhttps://dev.vivo.com.cn/promote/pushNews
Privacy Policyhttps://dev.vivo.com.cn/documentCenter/doc/652#w1-12075822

13. Meizu Push SDK

OrganizationZhuhai Xingji Meizu Information Technology Co., Ltd.
Product / TypeMeizu Push SDK
Information UsedDevice-related information including phone brand, model, system version, system language, PUSHID device identifier, app information, and push status.
Information TypeCommon device information and network identity information
PurposeProvide real-time message push on Meizu phones and optimize push experience and analytics
ScenarioUsed to receive push messages on Meizu devices as a JPush vendor channel.
PermissionNetwork permission (INTERNET)
Sharing MethodWhen the app initializes JPush, the Meizu push plugin indirectly calls Meizu Push SDK to obtain the push token.
Official Linkhttps://open.flyme.cn/service?type=push
Privacy Policyhttps://open.flyme.cn/docs?id=202