《小转盘-做决定》隐私政策

发布日期:2026年8月3日 生效日期:2026年8月3日 最近更新日期:2026年9月9日 适用版本:Android 1.0.13 开发者:成都牧辰未来科技有限公司 联系邮箱:support@muchenweilai.com 一、我们处理哪些数据 本应用不提供账号注册、登录或支付功能。开发者不建立用户画像,也不在自有服务器分析转盘、数字、手指或正念等核心功能的使用行为。你创建的转盘名称、选项、所选图片、历史记录、偏好设置、安装时间及本地使用计数保存在设备本地,不会由我们上传至服务器。经你同意后,第三方广告 SDK 会在广告场景处理下文列明的广告交互、运行和诊断日志。 在你同意广告授权后,应用会初始化穿山甲广告 SDK 和 GroMore 融合 SDK,联网请求并展示开屏广告和页面底部 Banner 广告。广告 SDK 可能按照下述说明处理必要数据。拒绝广告授权不影响转盘、数字、手指和正念等核心功能。 设备 IP 地址与设备传感器信息处理特别说明: • 处理主体及接收方:设备 IP 地址由穿山甲广告 SDK、GroMore 融合 SDK(北京巨量引擎网络技术有限公司)处理;设备传感器信息由穿山甲广告 SDK 处理。本版本未接入腾讯优量汇 Android SDK。 • 个人信息种类:设备 IP 地址;设备传感器列表、传感器类型及可用状态,可能涉及加速度传感器、陀螺仪传感器、线性加速度传感器、磁场传感器和旋转矢量传感器。 • 处理目的:IP 地址用于建立广告网络连接、请求和展示广告、广告归因、防作弊、安全保障及故障诊断;传感器信息用于判断广告交互能力、摇一摇或扭一扭等广告投放能力及广告反作弊。 • 使用场景:仅在你点击“同意上述信息处理并启用广告”后,于广告 SDK 初始化、广告请求和广告展示期间处理。 • 处理方式:广告 SDK 通过设备网络连接自动收集设备 IP 地址,并通过后台接口传输至各 SDK 提供方服务器;穿山甲广告 SDK 通过 Android SensorManager 等系统接口自行查询或采集传感器信息,并可能按照其隐私政策处理相关结果。 • 处理范围:仅用于广告投放、广告交互能力判断、归因、防作弊、安全及稳定运行;本应用不在开发者自有服务器存储设备 IP 地址或传感器信息,也不将其用于转盘、数字、手指或正念等核心功能。当前版本已关闭摇一摇开屏按钮,并按照穿山甲官方配置禁止采集传感器运动数据;SDK 出于兼容性或能力判断仍可能查询传感器列表、类型及可用状态。拒绝或撤回广告授权后,本应用不会主动初始化广告 SDK 或发起新的广告请求。 二、使用的系统功能 • 图片选择:仅在你主动为转盘选项添加图片时调用系统图片选择器。被选图片会复制到应用私有目录。 • 转盘分享与导入:仅在你主动点击“分享”时,将当前转盘名称、选项名称和权重压缩并进行 AES-GCM 轻度加密,生成以 https://muchenweilai.com/wheel 开头的文本链接,再交由 Android 系统分享至你选择的应用。分享内容不包含选项图片、颜色、历史记录或排除状态;本应用不会把分享内容上传至开发者服务器。你选择的第三方分享应用可能按照其隐私政策处理该文本。 • 转盘链接手动导入与复制:仅当你主动进入“我的转盘”、点击右上角“导入”,并把转盘分享链接粘贴或输入到输入框后,应用才会处理该输入框中的文字,用于在设备本地识别、解密并预览转盘。应用不调用 Android ClipboardManager 读取系统剪贴板,不判断剪贴板是否有内容,也不在启动、返回前台、切换页面或使用其他功能时自动读取或监听剪贴板。解析不会访问链接网页,输入文字不会上传;只有你确认导入的转盘数据会保存在本机。点击“复制”类操作时,应用仅将你选择的内容写入系统剪贴板,不会读取已有内容。 • 文字转语音:仅在你开启结果语音后调用设备中已选择的系统语音服务,结果文字可能由该语音服务处理,其处理规则由对应提供方负责。 • 振动:用于你主动开启的触觉反馈及广告组件的必要交互。 • 桌面小组件:仅在你主动从系统桌面或应用设置添加原生 2×2 圆形转盘小组件后,Android 系统才会向小组件组件发送标准更新事件。点击小组件时,应用仅在设备本地读取当前转盘、执行随机抽取并保存结果与历史,不联网、不调用广告 SDK,也不上传小组件数据。 三、第三方广告 SDK 1. 穿山甲广告 SDK / GroMore 融合 SDK 7.7.1.6 提供方:北京巨量引擎网络技术有限公司 用途:聚合广告策略、广告请求与展示、广告交互能力判断、归因、防作弊及运行诊断。 使用场景:你同意广告授权后,在开屏广告和底部 Banner 广告初始化、请求与展示时使用。 处理方式:经你同意后,由 SDK 在广告初始化、请求和展示期间通过 Android 系统接口、设备本地接口及网络自动处理并传输。 共享个人信息名称及范围:设备 IP 地址(IP 地址);设备品牌、型号、操作系统及 API/软件版本、系统语言、时区和国家/区域、屏幕密度与分辨率、CPU、可用存储空间、磁盘和内存信息、系统启动时间;运营商、SIM 卡 MCC/MNC、网络接入方式、类型、状态、质量、信号强度及 Wi-Fi 状态;应用名称、包名、版本和前后台状态;广告展示、点击等用户操作/行为日志及崩溃、性能诊断信息;设备传感器列表、传感器类型和可用状态。可能涉及的传感器包括加速度传感器、陀螺仪传感器、线性加速度传感器、磁场传感器和旋转矢量传感器。设备 IP 地址由 SDK 通过网络连接自动收集并上传至提供方服务器;传感器信息由 SDK 通过 Android 系统接口自行查询或采集,用于广告交互能力判断及广告反作弊。当前版本按照官方配置禁止采集传感器运动数据并关闭摇一摇开屏按钮,但 SDK 出于兼容性或能力判断仍可能查询传感器列表、类型及可用状态。SDK 能力还可能涉及 MAC 地址、Wi-Fi 标识(SSID/BSSID)、设备标识符、软件安装列表或特定应用安装状态,但当前版本已通过隐私控制关闭这些非必要信息的读取。上述信息不用于本应用核心功能。具体以提供方隐私政策为准: https://www.csjplatform.com/privacy/partner https://www.csjplatform.com/terms/gromoresdk-privacy 本版本未集成腾讯优量汇 Android SDK,也未包含 GroMore-GDT 适配器。当前版本在 GroMore 初始化前,通过穿山甲隐私控制关闭传感器运动数据、定位、电话状态、MAC 地址、已安装应用列表及安装/卸载监听、Wi-Fi 标识、外部存储、麦克风、短信、Android ID、OAID、个性化广告及程序化推荐等非必要能力;不向 SDK 提供自定义 MAC 地址或自定义软件安装列表,并从应用清单中移除相应可选权限和宽泛的软件可见范围。穿山甲传感器开关严格使用官方规定的“0”值。SDK 出于兼容性或能力判断仍可能查询传感器列表或调用其他相关系统接口,但在对应数据开关关闭时不应采集传感器运动数据,或读取、上报其他已关闭信息的实际值。广告填充与收益可能因此降低。 四、权限与网络 应用使用网络访问和网络状态权限请求广告;使用振动权限提供触觉反馈;广告组件可能使用保持唤醒能力完成媒体展示。仅当你主动开启“每日提醒”时,应用才会请求通知权限,并在设备本地保存提醒开关和时间;通知由 Android 系统在本地生成,不依赖远程推送,也不会上传提醒设置。重启完成广播仅用于在设备重启后恢复你已开启的本地提醒。桌面小组件仅声明 Android 标准 APPWIDGET_UPDATE 系统事件,更新周期设置为 0,不进行定时后台刷新。该系统事件可能在系统桌面恢复用户已添加的小组件时启动小组件接收器,目的仅为恢复小组件界面;不会启动应用界面,不用于广告初始化或个人信息收集,也不会关联启动其他应用。应用不申请相册、相机、定位、通讯录、电话、麦克风或读取全部应用列表等敏感权限。Android 系统图片选择器不授予应用读取整个相册的权限。 五、同意、撤回与删除 首次启动时,我们会在任何广告 SDK 初始化前询问你的选择。你可以拒绝,之后也可在“转盘 → 设置 → 隐私与关于 → 广告与隐私授权”中同意或撤回。撤回后,应用会移除当前广告并停止新的广告请求;再次同意前不会主动初始化广告 SDK。 本地数据会保存到你主动删除相关内容或卸载应用为止。Android 备份已关闭。你可以在应用内清除历史记录、删除自建转盘,或通过 Android 系统设置清除本应用全部数据。在中华人民共和国境内运营过程中由广告 SDK 收集和产生的个人信息,由对应提供方存储在境内,仅在实现广告服务目的所必需的最短期间内保留;超过必要期限后删除或匿名化处理,法律法规另有规定的除外。各 SDK 的具体保存、删除和个人权利响应规则以其提供方隐私政策为准;你也可以通过上述邮箱联系我们协助处理。 六、未成年人 本应用不以不满 14 周岁未成年人为目标用户,也不会主动识别或收集未成年人的身份信息。不满 14 周岁的未成年人应由监护人陪同阅读本政策,并由监护人决定是否同意启用广告;未经监护人同意,请选择“暂不同意”。监护人如认为我们或广告 SDK 处理了未成年人个人信息,可以通过上述邮箱联系我们查询、更正或删除。 七、政策更新与联系 如应用功能、第三方 SDK 或数据处理方式发生变化,我们会更新本政策,并在需要时重新取得你的同意。有关隐私、数据删除或其他问题,请联系上述邮箱。

Decision Wheel Privacy Policy

Published: August 3, 2026 Effective: August 3, 2026 Last updated: September 9, 2026 Applicable version: Android 1.0.13 Developer: 成都牧辰未来科技有限公司 (Chengdu Muchen Future Technology Co., Ltd.) Contact: support@muchenweilai.com 1. Data we process The app does not provide accounts, sign-in, or payments. The developer does not build user profiles or analyze use of the Wheel, Number, Fingers, or Mindfulness features on a developer-owned server. Wheel names, options, selected images, history, preferences, installation time, and local usage counters stay on your device and are not uploaded by us. After you consent, third-party ad SDKs process the ad-interaction, operational, and diagnostic logs listed below only in advertising scenarios. With your advertising consent, the app initializes the Pangle advertising SDK and GroMore mediation SDK, connects to request and display splash and bottom banner ads, and may process the necessary data described below. Refusing ad consent does not affect the Wheel, Number, Fingers, or Mindfulness features. Specific notice about device IP address and sensor-information processing: • Processors and recipients: the device IP address is processed by the Pangle advertising SDK and GroMore mediation SDK (Beijing Ocean Engine Network Technology Co., Ltd.). Device sensor information is processed by the Pangle advertising SDK. Tencent Youlianghui is not included in this version. • Information: device IP address; and the device sensor list, sensor types, and availability, potentially involving accelerometer, gyroscope, linear-acceleration, magnetic-field, and rotation-vector sensors. • Purposes: the IP address supports ad network connections, requests, display, attribution, fraud prevention, security, and diagnostics. Sensor information supports ad-interaction capability checks, shake or twist ad capabilities, and fraud prevention. • Scenario: only after you tap “Consent to the Processing Above and Enable Ads,” during ad SDK initialization, ad requests, and ad display. • Method: the ad SDKs automatically collect the device IP address through the network connection and transmit it to their providers’ servers. The Pangle advertising SDK uses Android SensorManager and other system APIs to query or collect sensor information and may process the results under its privacy policy. • Scope: advertising, capability checks, attribution, fraud prevention, security, and stability only. The app does not store IP addresses or sensor information on a developer-owned server or use them for core features. This version disables the splash shake button and uses Pangle’s documented setting to prohibit motion-data collection; compatibility or capability checks may still query the sensor list, types, and availability. After refusal or withdrawal, the app does not proactively initialize the ad SDKs or make new ad requests. 2. System features • Image selection: The system photo picker opens only when you add an image to a wheel option. The chosen image is copied to private app storage. • Wheel sharing and import: Only after you tap Share, the app compresses and lightly encrypts the current wheel name, option names, and weights with AES-GCM, creates a text link beginning with https://muchenweilai.com/wheel, and passes it to Android for sharing through an app you choose. Images, colors, history, and exclusion state are not included, and the app does not upload the shared content to a developer-owned server. The third-party app you select may process the text under its own privacy policy. • Manual wheel-link import and copying: The app processes text from the import field only after you explicitly open My Wheels, tap Import in the top-right corner, and paste or enter a wheel-share link. This is used locally to recognize, decrypt, and preview the wheel. The app does not call Android ClipboardManager to read the system clipboard, check whether it contains data, or automatically read or monitor it at launch, on foreground return, during navigation, or while using other features. Parsing does not visit the linked webpage, and entered text is not uploaded; only wheel data you confirm for import is saved locally. Copy actions only write content you selected to the system clipboard and do not read existing content. • Text to speech: When enabled, result text may be processed by the system speech service selected on your device, under that provider's terms. • Vibration: Used for enabled haptic feedback and necessary ad component interactions. • Home-screen widget: Android sends standard widget-update events only after you actively add the native 2×2 circular-wheel widget from the system launcher or app settings. Tapping it reads the current wheel, performs the random selection, and saves the result and history only on the device. This does not use the network or advertising SDKs and does not upload widget data. 3. Third-party advertising SDKs Pangle advertising SDK / GroMore mediation SDK 7.7.1.6, provided by Beijing Ocean Engine Network Technology Co., Ltd., is used after consent during splash and bottom banner initialization, requests, and display for mediation, ad delivery, ad-interaction capability checks, attribution, fraud prevention, security, and diagnostics. Information within the active scope may include: the device IP address; device brand/model, OS and API/software version, system language, time zone and country/region, screen density/resolution, CPU, available storage, disk/memory information and system boot time; carrier, SIM MCC/MNC, network access method/type/status/quality/signal strength and Wi-Fi status; app name/package/version and foreground/background state; ad-impression/click and other user-operation/behavior logs, crash/performance diagnostics; and the device sensor list, types, and availability. Potential sensor types include accelerometer, gyroscope, linear-acceleration, magnetic-field, and rotation-vector sensors. The SDK automatically collects the IP address through the network connection and uploads it to the provider’s servers, and queries or collects sensor information through Android system APIs for ad-interaction capability checks and fraud prevention. This version uses Pangle’s documented setting to prohibit motion-data collection and disables the splash shake button, although compatibility or capability checks may still query the sensor list, types, and availability. SDK capabilities may also include MAC addresses, SSID/BSSID, device identifiers, and installed-app information, but this version disables optional access to them through privacy controls. The information is not used for core app features. See: https://www.csjplatform.com/privacy/partner https://www.csjplatform.com/terms/gromoresdk-privacy This version does not integrate the Tencent Youlianghui Android SDK or the GroMore-GDT adapter. Before GroMore initialization, it applies Pangle privacy controls to disable motion-data collection, location, phone state, MAC addresses, installed-app lists and install/uninstall listeners, Wi-Fi identifiers, external storage, microphone, messages, Android ID, OAID, personalized ads, and programmatic recommendations. We do not supply custom MAC addresses or app lists, and remove related optional permissions and broad package visibility from the manifest. Pangle’s sensor setting strictly uses its documented “0” value. SDK compatibility or capability checks may still query the sensor list or invoke other related system APIs, but disabled switches should prevent motion-data collection and prevent actual values for other disabled information from being read or reported. This may reduce ad fill and revenue. 4. Permissions and network Internet and network-state access are used to request ads; vibration supports haptics; ad components may keep the device awake during media display. The notification permission is requested only when you enable Daily Reminder. Its switch and time remain on your device; Android creates the notification locally without remote push or uploading reminder settings. The boot-completed broadcast is used only to restore an enabled local reminder after a device restart. The home-screen widget declares only Android’s standard APPWIDGET_UPDATE system event, with its periodic update interval set to 0, so it performs no scheduled background refresh. Android may start the widget receiver when restoring a widget that the user has already added; this is solely to restore that widget’s interface. It does not open the app UI, initialize advertising, collect personal information, or launch another app. The app does not request sensitive access to photos, camera, location, contacts, phone, microphone, or the full installed-app list. The Android system photo picker does not grant access to your whole library. 5. Consent, withdrawal, and deletion On first launch, the app asks before initializing any ad SDK. You may refuse, and later change your choice under Wheel → Settings → Privacy & About → Ads & Privacy Consent. Withdrawal removes the current ad and stops new requests; the ad SDK will not be proactively initialized again until you consent. Local data remains until you delete it or uninstall the app. Android backup is disabled. You can clear history, delete custom wheels, or erase all app data in Android settings. Personal information collected or generated by ad SDKs during operations in the People's Republic of China is stored in China by the corresponding provider and retained only for the shortest period necessary to provide advertising services. It is then deleted or anonymized unless law requires otherwise. Specific retention, deletion, and rights-request rules follow each provider's privacy policy; you may also contact us for assistance. 6. Children The app is not directed to minors under 14 and does not proactively identify or collect a minor's identity information. A minor under 14 should review this policy with a guardian, and the guardian should decide whether to enable advertising. Without guardian consent, choose “Not Now.” A guardian who believes that we or an ad SDK processed a minor's personal information may contact us to request access, correction, or deletion. 7. Updates and contact If functionality, third-party SDKs, or data handling changes, we will update this policy and request consent again where required. Contact us at the address above for privacy or deletion questions.