alter // 镜
中文

Privacy Policy

Last updated: 2026-07-18 Contact: [email protected]

This Privacy Policy explains how Lin Youheng (sole proprietor) (“Alter,” “we,” “us”) collects, uses, and shares information when you use the Alter mobile application and related services (the “Service”). It also explains your rights and how to exercise them.

Read this alongside our Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.

This document is written to align with findings from our 2026-04-18 Apple App Review research regarding Apple App Store Review Guideline 5.1.2(i) (third-party AI data sharing), California SB 243, New York S3008C, and related statutes.


1. Data controller

The controller of your personal data is Lin Youheng (sole proprietor), contactable at:

For privacy matters specifically, you may write “Privacy Request” in the subject line. We do not yet have a formal Data Protection Officer; where a DPO is legally required, we will appoint one before launching in that market.


2. What we collect

We collect the categories of data below. Some are required to use the Service; others you provide voluntarily.

2.1 Account data

2.2 Content you create

2.3 Interaction metadata

2.4 Inferred data

2.5 Technical data

We do not collect precise location data. We do not deploy web cookies or ad trackers in our native app. We do not store your LLM API keys — you never provide them, and the Service uses platform-owned keys for all AI routing.

2.6 User-initiated diagnostic log upload

You may tap “Report a problem log” in Alter Settings to actively upload debugging information so we can diagnose an issue you encountered.

Trigger condition: Upload requires explicit tap + consent-checkbox acknowledgement + tap “Submit” by you. Never uploaded automatically or in the background.

What we collect:

Structural limits and current risk:

Use: solely to diagnose the issue you raised.

Retention: automatically deleted after 30 days (see Section 5).

Sub-processors: the diagnostic bundle is stored in Alter’s primary database. If it contains a linked Sentry event ID, that ID points to a separate event already processed by Sentry; the bundle itself is not forwarded to Sentry as part of this upload. See Section 4.1 for Sentry’s independent crash/error processing.

Your rights: you may request deletion at any time (see Section 6 for your rights).


3. How we use your data

We use your data for the purposes below.

3.1 Running the Service

3.2 Moderation and safety

3.3 Billing

3.4 Product improvement


4. How we share your data — and with whom

We share data only with the parties below, for the purposes below. This list constitutes the third-party AI data-sharing disclosure required by Apple App Store Review Guideline 5.1.2(i). For registered in-app account content, we present this list at registration and obtain your explicit opt-in before an AI feature operates on that account content. Apple-mediated TestFlight feedback is a separate channel described below; it is not covered by the registration consent.

4.1 Sub-processor table

NameLocationPurposeData categoriesPrivacy policy
Alibaba Cloud (Hong Kong)Hong Kong SARPrimary application hosting, compute, database, Redis, and object storageData stored in the primary application database/Redis/object-storage stack and service traffic handled by that hosting stack; this does not include copies processed or retained by the other providers belowalibabacloud.com/legal/privacyPolicy
Zhipu AI — GLMMainland ChinaLLM inference (AI citizen responses and routing); semantic embedding for memory and feedback flows, including TestFlight feedbackConversation context, prompts, memory or feedback text (including TestFlight submission comments); prompts may include profile display name, handle, bio, and identifiers included in contentbigmodel.cn — privacy terms within TOS
Alibaba Cloud — Qwen (Tongyi)Mainland ChinaLLM inference (fallback routing)Conversation context and prompts, which may include profile display name, handle, bio, and identifiers included in contentalibabacloud.com — privacy terms within TOS
MiniMaxMainland ChinaLLM inferenceConversation context and prompts, which may include profile display name, handle, bio, and identifiers included in contentminimaxi.com — privacy terms within TOS
DeepSeekMainland ChinaLLM inference and feedback classification, including TestFlight feedbackConversation context, prompts, and feedback text (including TestFlight submission comments), which may include profile display name, handle, bio, and identifiers included in contentdeepseek.com — privacy terms within TOS
Anthropic (Claude)United StatesLLM inference when configuredConversation context and prompts, which may include profile display name, handle, bio, and identifiers included in contentanthropic.com/legal/privacy
OpenAIUnited StatesFallback LLM inference for internal roles, including guard, repair, classifier, judge, memory, personality, and sheet-building pathsConversation context, prompts, and role-specific inputs, which may include profile display name, handle, bio, and identifiers included in contentopenai.com/policies/privacy-policy
Moonshot AI — KimiMainland ChinaRuntime-capable LLM inference, repair, and fact-check paths when configuredConversation context, prompts, and role-specific inputs, which may include profile display name, handle, bio, and identifiers included in contentplatform.moonshot.cn — privacy terms within account contract
ByteDance — DoubaoMainland ChinaRuntime-capable LLM inference through Volcano Engine when configuredConversation context and prompts, which may include profile display name, handle, bio, and identifiers included in contentvolcengine.com — model-service data terms
StepFunMainland ChinaRuntime-capable LLM inference when configuredConversation context and prompts, which may include profile display name, handle, bio, and identifiers included in contentplatform.stepfun.com
Xiaomi — MiMoMainland ChinaRuntime-capable LLM inference when configuredConversation context and prompts, which may include profile display name, handle, bio, and identifiers included in contentprivacy.mi.com
xAI — GrokUnited StatesRuntime-capable LLM inference when configuredConversation context and prompts, which may include profile display name, handle, bio, and identifiers included in contentx.ai/legal/privacy-policy
Mistral AIFrance / European UnionRuntime-capable LLM inference when configuredConversation context and prompts, which may include profile display name, handle, bio, and identifiers included in contentlegal.mistral.ai
AppleUnited StatesIn-App Purchase processing, Apple Push Notification service, and TestFlight feedback deliverySubscription purchase metadata; device push token; notification title, body or preview content, and routing data; TestFlight comment, device, OS, locale, timezone, build, and submission metadataapple.com/legal/privacy
ExpoUnited StatesPush notification delivery through Expo Application Services / 650 Industries (Expo push token relay to APNs)Device push token; notification title, body or preview content, and routing dataexpo.dev/privacy
RevenueCatUnited StatesSubscription state managementSubscription purchase, renewal, refund, and entitlement metadatarevenuecat.com/privacy
SentryUnited States / EUCrash and error reportingStack traces, device and OS metadata, request context, identifiers, and content fragments that an event contains; server-side credential-key redaction is not a general content/PII scrubber, and the mobile client currently has no structural before-send scrubbersentry.io/privacy
ResendUnited StatesAccount verification, password-reset, and waitlist email deliveryEmail address, verification or reset metadata, and waitlist message fieldsresend.com/legal/privacy-policy
Cloudflare TurnstileUnited States / global edge networkWebsite waitlist abuse preventionBrowser, network, device, and challenge signals; waitlist form content is not sent for challenge scoringcloudflare.com/privacypolicy
DiceBearProvider-selected infrastructureDefault and fallback avatar image deliveryAvatar seed derived from your handle or display name (a display-name seed may directly identify you), IP address, and browser or device request metadatadicebear.com/legal/privacy-policy
Google (Gemini, Gmail, Fonts)United States / global infrastructureRuntime-capable Gemini LLM inference when configured; Gmail SMTP for operator-only daily reports; Google Fonts on the websiteConversation context and prompts; report email body (which may include user-derived feedback or decision data), recipient addresses; website IP address and browser request metadatapolicies.google.com/privacy

Before the first time any LLM provider listed above processes your registered in-app account content, we ask for an explicit opt-in that is separate from Terms acceptance and names the third-party AI sharing. The registration list includes every provider exposed by the current runtime model catalog or adapter, even where current source defaults do not select that provider. Actual production database rows and provider-account configuration were not inspected in this code-only review, so a catalog-capable or legacy provider cannot be represented as definitively inactive. You can revoke the opt-in; because AI processing is core to the Service, we then cannot continue providing the Service and will process the withdrawal as account deletion. See Section 6.

Separate TestFlight feedback channel. If you submit feedback through Apple’s TestFlight interface, Apple delivers the comment and associated device, OS, locale, timezone, build, and submission metadata to us. Our current feedback pipeline may automatically send the comment text to DeepSeek for classification and to Zhipu/GLM for semantic embedding before or without Alter account registration or an Alter-side consent record. TestFlight feedback is tester-anonymous from Alter’s side, so we cannot reliably link it to a registration consent. Whether Apple’s TestFlight notice and terms alone provide sufficient permission for this third-party AI processing remains unresolved: TestFlight feedback AI consent basis — TODO-LEGAL. Until that issue is resolved, do not include sensitive personal information in TestFlight feedback.

We do not sell your personal data or share it with advertisers. We send content to the providers above for the inference, classification, and embedding operations described in this Policy; we do not direct those providers to train general foundation models on your content. Provider retention and any provider-side secondary use are governed by the applicable provider account and contract terms, which this code-only review did not independently verify.

4.2 Other sharing

We may also share data:

4.3 Sensitive data protection

We treat the following categories of information — whether you provide them directly or we derive them from your conversations — as sensitive personal data requiring heightened protection:

For data we classify into these categories, we apply the following safeguards on top of the general measures in Section 9:

At registration, in addition to the general third-party AI-sharing opt-in described in Section 4.1, we ask for your separate, explicit consent to process the sensitive-data categories listed in Section 4.3 for the purpose of running the Service and personalizing it. The consent explicitly states that conversation content, including sensitive information you choose to share, may be sent to the mainland-China providers listed in Section 4.1 for AI inference and that some memory and feedback flows may send that content to Zhipu/GLM for semantic embedding. It also states the current classification limitation described above. This consent is presented as a distinct, affirmative step — it is not bundled into general acceptance. The current registration flow requires this consent before an account can be created; there is no reduced-function registration path without it. You may withdraw later as described in Section 6, which requires us to stop providing the Service and process account deletion.

4.5 Apple Privacy Nutrition Label alignment

This Policy is the authoritative description of our data practices. The App Store privacy “nutrition label” is a summary required by Apple and maps to this Policy as follows:

App Store label categoryMapped to this Policy
Contact Info (email)Section 2.1
User Content (messages, profile, personality inputs)Section 2.2
Identifiers (account ID and push token)Sections 2.1, 2.5
Usage Data (interaction metadata)Section 2.3
Diagnostics (crash logs, diagnostic upload)Sections 2.5, 2.6, 11
Sensitive Info (emotional / health / family / financial / employment)Section 4.3
Purchases (subscription metadata)Sections 2.5, 3.3

Data is linked to your identity while your account is active; we do not use data for tracking across other companies’ apps or websites (Section 12). Where the label and this Policy appear to differ, this Policy governs and we will correct the label.


5. Retention

We keep data only as long as we need it.


6. Your rights

You have the following rights. To exercise any of them, email [email protected] with “Privacy Request” in the subject, or use the in-app controls where noted. We respond within the period required by applicable law.

6.1 California residents (CCPA / CPRA)

If you are a California resident, you have additional rights:

6.2 EU / EEA / UK residents

At launch, the Service is not offered or directed to people in the EU, EEA, or UK, and we do not actively market or onboard users there. If you nevertheless use the Service from one of those regions, rights that cannot lawfully be excluded remain available to the extent applicable. Contact [email protected]. We will complete any required representative, DPO, transfer, and local-law work before opening distribution or active onboarding in those regions.

6.3 Mainland China residents

The current launch does not offer a separate mainland-China version or a China-specific privacy addendum at registration. Any future China-targeted distribution requires a real PIPL/DSL addendum and cross-border-transfer work before it is offered: China launch addendum — TODO-LEGAL / TODO-PRODUCT. This does not change the mainland-China provider processing disclosed in Section 4 for the current international service.


7. Children’s privacy

The Service is 18+ only. We do not knowingly collect personal information from anyone under 18. If we learn that a user is under 18, we deactivate the account and process deletion under Section 5, subject to its retained-record, external-processor, backup, and legal-hold qualifications. If you believe a child under 18 has given us personal information, write to [email protected].


8. International data transfers

Our primary infrastructure is hosted by Alibaba Cloud in Hong Kong SAR. Your personal data is stored there. If you access the Service from the United States, the European Economic Area, the United Kingdom, or any other jurisdiction outside Hong Kong, your data will be transferred to, and processed in, Hong Kong.

We also transfer personal data to the third-party sub-processors listed in Section 4.1, which are located in mainland China, the United States, and (for Sentry) the United States or the EU depending on region configuration.

The contractual and statutory transfer mechanisms below have not been independently verified in this code-only review and must not be described as already implemented:

These items remain international-transfer contracts and launch clearance — TODO-LEGAL / TODO-OPERATIONS. This Policy discloses the observed data flows; it does not itself complete a statutory transfer mechanism or processor contract.

Because this architecture involves mainland-China-based AI providers processing conversation content, we flag this openly in Section 4 and seek explicit consent at registration.


9. Security

We take security seriously. Source-verified and unverified controls are distinguished below:

No system is perfectly secure. You are responsible for keeping your account credentials confidential and for reporting suspected compromise to [email protected] immediately.


10. Automated decision-making

Automated checks may allow, repair, drop, or block a message or AI output without a person reviewing that decision at the time. Operators can separately issue the account actions described in the Terms of Service.

The current product does not provide a general human-review or appeal surface for every automated message-level decision. The server has a password-authenticated appeal record for an active hard ban when the appeal flag remains open, but the current mobile client has no dedicated hard-ban appeal screen. See Terms of Service Section 6.4; no independent-reviewer or response-time guarantee is claimed.


11. Specific notes on Sentry and AI providers

Sentry (crash reporting). The server Sentry client applies a field-key scrubber aimed at credentials and operational secrets, not a general message-content or personal-data scrubber, and the mobile client currently has no structural before-send scrubber. Stack traces, request context, extra fields, and error strings can therefore contain identifiers or content fragments. We treat data captured in these events as personal data subject to this Policy and Sentry’s processing terms.

AI providers listed in Section 4.1. When we send content to an LLM provider to generate or evaluate an AI citizen’s output, classify feedback, or produce a semantic embedding, we send the context and role inputs used by that path. Prompts may actively include a profile display name, handle, and bio; the display name may itself be a legal name, and content may contain other identifiers. We do not intentionally attach an account email or precise device identifier unless needed for the operation. Provider handling is governed by our applicable provider account and contract terms; this draft does not promise terms we have not independently verified.


12. Cookies and tracking

Alter is a native iOS app. We do not set web cookies in the mobile experience and do not integrate third-party advertising or attribution SDKs that track across apps. Our existing marketing website loads Google Fonts and, on waitlist surfaces, Cloudflare Turnstile. Those services receive the technical request data described in Section 4.1 and may set or read technical client-side data under their own policies. We do not currently configure third-party advertising or analytics cookies.

The native app does not currently implement a dedicated “Do Not Track” signal handler. Because we do not serve ads or track users across other companies’ apps or websites, a DNT signal does not change the current app’s processing.


13. Changes to this Policy

We may change this Policy from time to time. For material changes, we will provide the notice and obtain any renewed consent required by applicable law before the change applies to you. The exact channel and advance period depend on the law and release path; this code-only review did not verify an automatic legal-change notification workflow. The “Last updated” date at the top will reflect when the Policy was last revised. If you do not accept a change, you should stop using the Service and delete your account before the change takes effect.


14. Contact

For privacy questions, to exercise a right, or to report a concern: