Privacy Policy

📋 Contents
This English version is a translation provided for convenience only. In case of any discrepancy or inconsistency between the English and Chinese versions, the Chinese version shall prevail.

Privacy Overview

XThinkTank values your personal information and data security. This Privacy Policy explains how we collect, use, store, entrust for processing, share, transfer, publicly disclose, and protect your personal information across our website, mobile apps, APIs, customer support, payment, and related services.

Core Principles

  • We follow the principles of lawfulness, legitimacy, necessity, good faith, and data minimization.
  • We clearly inform you of the purposes and methods of processing, the categories of information, retention periods, and your rights.
  • We will not publicly disclose your personal information without your separate consent or as permitted by laws and regulations.
  • This Policy applies to the XThinkTank website, mobile app, APIs, notifications, customer support, and related operational activities.

Information Handler

Personal Information Handler

Platform: XThinkTank
Operator and personal information handler: Hooman Biotechnology (Beijing) Co., Ltd.
Website: https://xthinktank.com
Contact for the person in charge of personal information protection: ai@xthinktank.com

XThinkTank may operate as an independent product mechanism, but for matters involving the Terms of Service, this Privacy Policy, compliance interpretation, dispute handling, and responses to user requests, the legal entity is the company named above.

Information We Store

The following information storage is necessary for XThinkTank to provide personalized services to users.

Account & Authentication

  • Email, mobile number (if enabled), username, avatar, and organization and role information.
  • The encrypted digest of your password, login status, refresh tokens, two-factor keys, and verification-code validation records.
  • Information needed for registration, login, password recovery, deregistration, security settings, and handling of abnormal logins.

Research & Content

  • Research topics, prompts, uploaded materials, conversation content, HITL feedback, and export requests you provide.
  • AI-generated plans, process events, reports, annotations, favorites, publicly published content, and related metadata.
  • Records of model calls, search calls, research depth, conversation state, error retries, and result read-backs.

Device & Log

  • IP address, browser type, operating system, device model, app version, network status, and access time.
  • Request logs, operation logs, error logs, performance data, security and risk-control records, and audit records.
  • Mobile device identifiers, push tokens, AppState, and technical information needed for crash or anomaly diagnosis.

Transaction & Support

  • Order numbers, payment channels, payment amounts, credited points, transaction status, refund requests, and billing records.
  • Support emails, issue descriptions, screenshots, device and browser information, account email, and communication records.
  • Records necessary for invoicing, taxation, anti-fraud, dispute handling, or regulatory requirements.

How We Use Information

Providing & Improving Services

  • Creating and maintaining accounts, verifying identity, and synchronizing login status between web and mobile.
  • Generating research plans, performing retrieval, calling models, saving conversations, displaying reports, and exporting files.
  • Calculating credit balances, metering and charging by actual usage in real time, and handling orders, refunds, and billing queries.
  • Troubleshooting, optimizing performance, improving product experience, and enhancing model-orchestration quality.

Security & Compliance

  • Detecting fraud, traffic inflation, attacks, unauthorized access, abnormal logins, and payment risks.
  • Fulfilling obligations for cybersecurity, personal information protection, taxation, auditing, transaction-record retention, and regulatory assistance.
  • Handling infringement complaints, content reports, dispute resolution, user appeals, and security incidents.
  • Conducting de-identification, anonymized statistics, and internal auditing within the scope permitted by laws and regulations.

AI Training & Content Use

  • We do not sell your personal information.
  • Without your separate consent, we will not use your personal conversation content to train the platform’s own foundation models.
  • To generate results, we may send necessary input content to entrusted service providers for models, search, vectors, and cloud computing.
  • We may use anonymized or de-identified statistical information to improve system quality; after such processing, no specific individual can be identified.

Entrusted Processing & Sharing

No Arbitrary Sharing

We entrust or share personal information only to the extent necessary to achieve the purposes described in this Policy, and we bind service providers through contracts, access controls, encrypted transmission, and log auditing.

Service Providers That May Be Involved

  • Providers of cloud services, databases, object storage, CDN, SMS, email, push notifications, and operations.
  • Providers of AI models, search, vector retrieval, content safety, log monitoring, and error tracking.
  • Payment or app-store providers such as WeChat Pay, Alipay, Apple, and Google Play.
  • Security-audit, legal, accounting, tax, customer-support, and compliance advisors.

Disclosure Required by Law

  • Providing necessary information as required by laws and regulations, judicial authorities, administrative authorities, regulators, or dispute handling.
  • Where necessary to protect the life, property, safety, and lawful rights and interests of users, the platform, partners, or the public.
  • In transactions such as mergers, spin-offs, asset transfers, or bankruptcy liquidation, personal information may be transferred with the business, and the recipient will be required to remain bound by this Policy.

Payment & Billing Information

Information We Process

  • Payment order numbers, payment channels, amounts, credit packages, order status, third-party transaction numbers, payment time, crediting time, and Purchase History.
  • Credit balances, real-time metered charge records, refunds, bonus credits, administrator adjustments, and related audit records including historical held balances, pre-deductions, and settlements; these records are associated with your account and used to display balances and bills and to handle re-crediting, refunds, dispute resolution, and auditing.
  • Receipts and communication records you provide during refunds, re-crediting, abnormal orders, and payment-dispute handling.

Information We Do Not Store

  • We do not store your full bank card number, payment account password, payment verification code, or full credentials of third-party payment accounts.
  • Payment information for WeChat Pay, Alipay, Apple IAP, Google Play Billing, and the like is processed by the respective institutions under their own rules.
  • Refund, billing, subscription-management, and dispute-handling entry points may differ across payment channels.

App Privacy Disclosure

  • In App Store Connect’s App Privacy section, purchase history generated by Apple IAP on mobile is disclosed as Purchase History, with a note that it is associated with the account.
  • We do not use Apple IAP purchase history, payment orders, or credit-billing records for cross-app or cross-website tracking, nor do we sell these records.
  • Purchase history and billing records are used mainly to deliver digital services, display balances and bills, process refunds/reversals, provide customer support, and meet anti-fraud, tax, audit, and compliance requirements.

Mobile Information

Information the Mobile App Processes

  • Login tokens, refresh tokens, and security state are stored in the system’s secure storage to maintain your mobile login session.
  • Push tokens, device platform, device model, app version, and notification-click information are used for message delivery, device management, and troubleshooting.
  • Selecting an avatar may invoke system photo-library permission; images are compressed locally before upload; we do not proactively access your photos when none is selected.
  • The mobile app may cache conversations, reports, the recycle bin, and a local data pool to improve the experience; you can clear such data in settings.

Mobile Payment Boundaries

In-app credit purchases, subscriptions, or external payment links are controlled by the rules of the App Store, Google Play, and the specific distribution channel. Even if the mobile app displays account balances or transaction records, this does not mean that channel offers a purchase entry or that the app store processes transactions outside its own channel.

Cross-Border & Third-Party AI

Possible Cross-Border Processing

  • When personal information is provided across borders, we will take necessary measures in accordance with China’s personal information protection laws and regulations, including notification, separate consent, contractual arrangements, security assessment, or other mechanisms prescribed by the competent authorities.
  • We minimize the scope of transferred data and may encrypt, mask, or de-identify it.

Note on Your Input

Please avoid submitting identity documents, bank accounts, medical/health information, minors’ information, trade secrets, or others’ personal information that is unrelated to your research purpose in prompts, uploaded materials, or support emails. If you genuinely need to process sensitive information, please ensure you have obtained lawful authorization and understand the associated risks.

Situations Requiring Separate Consent or Additional Notice

  • Processing sensitive personal information, such as precise location, identity documents, biometrics, medical/health data, financial accounts, or minors’ sensitive information.
  • Providing your personal information to other personal information handlers, except as otherwise provided by laws and regulations.
  • Publicly disclosing your personal information.
  • Using personal information for new purposes inconsistent with the original purpose of collection.
  • Providing personal information overseas, or other circumstances where applicable law requires separate consent.

Retention Periods

Main Retention Periods

  • Account information: retained while the account exists; deleted or anonymized within 30 calendar days after deregistration, except as otherwise provided by laws and regulations.
  • Conversations, reports, and user content: retained in sync with the account; you may delete individual conversations or request account deregistration.
  • Operation logs and security logs: typically retained for 180 days for security auditing, troubleshooting, and dispute handling.
  • Payment, invoice, tax, and billing records: retained per tax, accounting, payment, audit, and regulatory requirements, generally no less than 5 years.
  • Customer-support and complaint records: retained for the period necessary to handle requests, reviews, and disputes.

When the retention period expires or the processing purpose has been achieved, we will delete or anonymize the relevant personal information. Where continued retention is required by laws and regulations, judicial or administrative requirements, security auditing, dispute handling, or protection of lawful rights and interests, we will restrict the scope of its use.

Data Security

Technical Measures

  • Transmission encryption, access control, privilege isolation, token protection, encrypted password digests, and secure storage.
  • Log auditing, anomaly detection, backup and recovery, API authentication, CSRF/token protection, and payment-callback signature verification.
  • Monitoring and alerting for high-risk operations, abnormal logins, payment anomalies, and system errors.

Management Measures

  • Managing internal access under the principle of least privilege.
  • Establishing processes for security vulnerabilities, incidents, complaints, and data requests.
  • Conducting security assessments, vulnerability remediation, and vendor management based on risk.
  • Taking remedial measures and fulfilling notification obligations in accordance with the law in the event of a security incident.

Security Limitations

Internet services cannot guarantee absolute security. If you discover account anomalies, data-leak risks, or security vulnerabilities, please notify us immediately via ai.ts@xthinktank.com or the contact-support page.

Your Rights

Rights You May Exercise

  • Access, copy, correct, and supplement your personal information.
  • Delete personal information or request account deregistration.
  • Withdraw consent and opt out of non-essential personalized recommendations or marketing messages.
  • The right to an explanation, the right to complain and report, and other rights provided by laws and regulations.
  • Request a transfer of a copy of your personal information where the conditions are met.

How to Submit a Request

  • You may submit requests via account settings, mobile settings, or a support email.
  • Send personal-information requests to ai@xthinktank.com, stating the request type, account email, and necessary identity-verification materials.
  • We usually respond within 15 business days; for complex requests or where an extension is permitted by law, we will explain the reason.
  • To ensure security, we may verify your identity first; if verification is not possible, we may be unable to process the request.

Cookies & Local Storage

Essential Technologies

  • On the web, we use cookies, localStorage, or similar technologies to store login status, CSRF tokens, theme, language, and basic settings.
  • On mobile, we use Secure Store, caches, and a local data pool to store login tokens, preferences, temporary sessions, and data needed for the offline experience.
  • Disabling essential cookies or clearing local storage may prevent login, block task submission, or cause settings to be lost.

Analytics & Experience

  • We may use de-identified statistics to analyze access, performance, and errors.
  • If we enable non-essential analytics or marketing tools, we will provide notice and choices as required by applicable law.
  • You can manage some local storage through your browser, system settings, or app settings.

Protection of Minors

Children & Minors

  • The Service is not offered to children under the age of 14, and we do not intentionally collect children’s personal information.
  • If we find that children’s personal information has been collected inadvertently, we will delete or anonymize it as soon as possible in accordance with the law.
  • Minors aged 14 or older but under 18 should use the Service with the consent and guidance of a guardian.
  • If a guardian discovers that a minor has used the Service or made payments without consent, they may submit a request through contact support.

Policy Updates

Update Notifications

  • Material changes will be notified via website announcements, in-app messages, email, login pop-ups, or mobile on-page prompts.
  • If a change materially affects the processing purpose, categories of information, sharing recipients, cross-border provision, user rights, or contact information, we will re-notify you or obtain consent in accordance with the law.
  • If you disagree with a material change, you may stop using the relevant service and contact us to handle your account and unused entitlements.

Contact & Complaints

If you have questions, suggestions, complaints, or reports regarding this Policy, personal information processing, or security incidents, you may contact us at ai@xthinktank.com.

Legal Notice & Version

This Privacy Policy is governed by the laws of the People’s Republic of China. For disputes arising from this Policy, the parties should first negotiate in good faith; if negotiation fails, the dispute shall be submitted to the competent People’s Court at the operator’s domicile.

Current version: v1.5.1 | Effective date: September 2, 2026 | Last revised: September 2, 2026