Privacy Policy
Last updated: June 17, 2026
Suyzeko ("we", "our", or "us") provides a mobile application used to create an account, connect supported hardware devices through Bluetooth, manage device presets, and synchronize selected data with our server. This Privacy Policy explains what information we collect, how we use it, how it is protected, and how you can delete your account.
We do not sell your personal data. We collect only the data needed to provide account login, device connection, avatar upload, preset synchronization, account security, and support for the Suyzeko App.
1. Information We Collect
1.1 Account and Profile Information
- Email address / username: used to register, log in, identify your account, and send verification codes.
- Password: stored on our server as a password hash. We do not store plaintext passwords.
- User ID, account status, and creation time: used to manage your account and account security.
- Nickname and gender: optional profile fields shown in your account profile.
- Profile picture URL: stored when you upload or update an avatar.
1.2 Avatar Images
If you choose to set a profile picture, the App lets you select an image and upload it to our cloud storage provider, Alibaba Cloud Object Storage Service (OSS). The uploaded object path is associated with your user ID so that the App can display your avatar.
1.3 Device and Bluetooth Information
- Device MAC address: used to identify and manage supported hardware devices linked to your account.
- Bluetooth device name: used to show the device in the App and help you recognize it.
- Device type code: used to identify the type of supported hardware device.
- Connection status, last seen time, and RSSI signal strength: used locally to show device connection state and scanning results.
Bluetooth scanning may require Nearby Devices permissions on newer Android versions. On Android 11 and earlier, Android may require location-related permission for Bluetooth scanning. Suyzeko uses these permissions only to discover and connect supported hardware devices. We do not use Bluetooth scanning to track your physical location.
1.4 Preset, Protocol, and Device Configuration Data
- Protocol and preset records: protocol names, icons, protocol type, version, and update time.
- Protocol step data: step number, duration, enabled state, and channel parameter values such as frequency, percentage, and related device control settings.
- Device settings: device MAC address, user ID, mode, manual settings, preset settings, total session duration, selected preset name, and icon resource.
This data is used to control supported devices, restore your settings, and synchronize your presets between the App and our server.
1.5 Authentication and Security Data
- Access tokens and refresh tokens: used to keep you signed in and protect authenticated API requests.
- Email verification codes and temporary password reset tokens: used for account registration and password reset.
- Failed login or verification counters and temporary lock records: used to protect accounts from brute-force attempts.
- Protocol edit authorization state: used to temporarily allow authorized editing of protected preset parameters.
On the device, access tokens and refresh tokens are encrypted using Android Keystore before being stored in app-private SharedPreferences. We do not store plaintext passwords on the device.
1.6 Logs and Diagnostics
Our server and App may generate operational logs needed for security, troubleshooting, and service reliability. These logs may include request metadata, error information, timestamps, account identifiers, device identifiers, or synchronization status. Production systems are configured not to intentionally log plaintext passwords, verification codes, access tokens, refresh tokens, or OSS security tokens.
2. How We Use Your Information
- To create, authenticate, and manage your account.
- To send email verification codes and support password reset.
- To discover, connect, and communicate with supported Bluetooth hardware devices.
- To save, restore, and synchronize device presets, protocols, and configuration data.
- To upload, display, and delete your avatar image.
- To protect accounts, prevent abuse, enforce single-device session controls, and improve security.
- To troubleshoot errors, maintain service reliability, and comply with legal obligations.
3. Permissions Used by the App
- Internet and network access: used to communicate with our server, synchronize settings, send account requests, and upload avatar images.
- Bluetooth / Nearby Devices: used to scan for and connect to supported hardware devices.
- Location permission on older Android versions: may be required by Android for Bluetooth scanning, but is not used for location tracking.
- Notifications: used on Android 13 and later to show Bluetooth connection status and the ongoing foreground service notification. If you deny notification permission, Bluetooth connection features can continue to work, but connection status may not appear in the notification area.
- Photo selection: used only when you choose an avatar image. The App uses Android's system photo picker for this flow and does not request Camera or broad photo library/storage permissions.
4. Data Storage and Security
- Data transmitted between the App and our server is sent over HTTPS in production.
- Passwords are stored as password hashes, not plaintext.
- Tokens and saved credentials on the device are encrypted with Android Keystore before local storage.
- Access to server-side data is restricted to authorized systems and personnel.
- Temporary security data, such as verification codes and reset tokens, is stored with expiration times.
5. Third-Party Service Providers
We use service providers only to operate the App and related services:
- Alibaba Cloud OSS: stores avatar images and provides temporary upload credentials.
- Email delivery service: sends verification and security codes to your email address.
- Cloud hosting and database services: store account, device, preset, and configuration data required by the App.
These providers process data on our behalf and are not permitted by us to sell your personal data.
6. Data Sharing
We do not sell, rent, or trade your personal data. We may disclose data only in the following circumstances:
- To service providers that help us operate the App and server infrastructure.
- When required by law, regulation, legal process, or enforceable government request.
- To protect the security, rights, property, or safety of users, Suyzeko, or the public.
7. Data Retention and Deletion
We retain account data while your account is active or as needed to provide the App. When you delete your account, we delete account profile data, device records, protocol records, protocol steps, device configuration data, active session data, and uploaded avatar files associated with the account from active systems where applicable.
Some limited records may be retained only if required for security, fraud prevention, legal compliance, dispute resolution, backup recovery, or audit purposes. Such records are limited to what is necessary and retained only for the required period.
8. Your Choices and Rights
- You can update your nickname, gender, and avatar in the App.
- You can remove locally saved login credentials by signing out or clearing App data.
- You can delete your account in the App through Settings > Account Security > Delete Account.
- If you cannot access the App, you can follow the instructions on our Account Deletion page.
9. Children's Privacy
Suyzeko is not intended for children under 13 years of age. We do not knowingly collect personal information from children. If you believe that a child has provided us with personal data, please contact us so we can take appropriate action.
10. International Data Processing
Your information may be processed and stored in countries or regions where our servers or service providers operate. We take steps designed to protect your information in accordance with this Privacy Policy.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date at the top of this page when changes are made. Continued use of the App after changes means you accept the updated policy.
12. Contact Us
If you have any questions or requests about this Privacy Policy, contact us at: