Elinko App Privacy Policy

Last Updated: June 29, 2026

Effective Date: June 29, 2026

1. Introduction

Shenzhen YiWangXinKong Technology Co., Ltd. (registered address: Room 501, Building 4, Yunli Smart Park, No. 3 Changfa Middle Road, Yangmei Community, Bantian Subdistrict, Longgang District, Shenzhen, China; hereinafter “we” or “Elinko”) is the developer and operator of the Elinko App. We understand how important personal information is to you and are committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, and protect your personal information.

Scope: this policy applies to the Elinko App (iOS / Android versions) and the related cloud services.

2. Information We Collect

2.1 Information You Provide

Information TypePurpose
Phone number / emailRegistration, login, password reset
Nickname, avatarProfile display
Device nameDevice management
Customer service content (text, images)Feedback handling

2.2 Device-Related Information Collected Automatically

Information TypePurpose
Device model, operating system version, App versionCompatibility adaptation, crash analysis
Device connection status (online/offline), WiFi signal strength, battery levelDevice status display
IP address, network typeNetwork optimization, security protection
Operation logs, crash logsTroubleshooting, product improvement

2.3 Camera and Audio Data

Data TypeDescription
Real-time video streamTransmitted via P2P end-to-end direct connection; by default it does not pass through our servers
SD card recordingsStored locally on your device; we do not obtain or access them
Cloud storage recordingsUploaded to the cloud with encryption after you activate cloud storage
Event alert screenshots / short videosUploaded automatically only when an alert event you have enabled occurs (e.g., motion detection, doorbell call), for push notifications
Two-way talk audioTransmitted via P2P end-to-end direct connection, only while you press and hold to talk; not stored

2.4 Permissions We Request

PermissionPurposeRequired?When Used
BluetoothDiscover nearby Elinko devices for network configurationRequired for setupOnly during the setup process
Location (Android)Read the WiFi name to complete setup; we do not collect or store precise locationRequired for setupOnly during the setup process
CameraScan device QR code (setup / adding shared devices)NoOnly when scanning
MicrophoneTwo-way talk (press and hold to talk)NoOnly during two-way talk
Storage/PhotosSave screenshots/recording files; select a QR code from the albumNoOnly when saving/selecting
NotificationsDevice alert push, doorbell call notificationsRecommendedWhen an event occurs

2.5 Processing of Sensitive Personal Information

The following information is considered sensitive personal information. We process it only where there is a specific purpose and clear necessity, and we will obtain your separate consent in advance:

Sensitive Personal InformationProcessing PurposeProcessing MethodRequired?
Face images (video frames)Local motion detection on deviceFace detection is performed locally on your device; event screenshots/recordings that may contain faces are handled according to the cloud storage rules you enableNo
Location information (Android, used only to read the WiFi name)WiFi setupUsed only to read the WiFi name during setup; precise location is not collected or storedYes (only during setup)
Real-time camera feedRemote viewingP2P direct connection; not uploaded by defaultYes (core feature)

3. How We Use Information

  • Core services: device network configuration, real-time live preview, recording playback, push notifications, and doorbell calls
  • Product experience improvement: crash analysis, feature usage statistics, and compatibility adaptation
  • Cloud storage: after you purchase and activate it, alert recordings are stored in the cloud with encryption
  • Customer support: responding to your feedback
  • Legal compliance: fulfilling legal obligations

We promise that we will not:

  • View or monitor your real-time feed or local SD card recordings
  • Sell your personal information to third parties
  • Use video/audio data for advertising or personalized recommendations without your explicit consent
  • Turn on your camera or microphone without your knowledge
  • Include deceptive advertising, disruptive advertising, or advertising content that interferes with device functions in the App

3.1 Legal Basis for Processing

  • Contract performance: processing necessary for registration, login, and providing core services;
  • Consent: processing sensitive personal information, enabling the camera/microphone, personalized advertising, and push notifications where consent is required by law;
  • Legitimate interests: crash analysis, product improvement, and security protection;
  • Legal obligations: fulfilling statutory retention and regulatory cooperation obligations.

4. Special Notes on Video Data

Elinko is an IPC monitoring app; processing video and audio data is part of its core functionality. The following are our specific commitments regarding video data:

  • Local-first: SD card recordings are stored entirely on your device; we cannot access them
  • Encrypted cloud storage: after you activate the service, recordings are uploaded with AES-256 encryption, and you control the encryption key
  • Real-time P2P direct connection: by default, real-time video streams are transmitted through P2P end-to-end direct connections and do not pass through our servers
  • Minimal event uploads: screenshots or short video clips are uploaded only when an alert is triggered, for push notifications
  • No AI training: your video data will not be used to train artificial intelligence models

5. Data Storage and Cross-Border Transfers

User RegionData Storage LocationDescription
Mainland China usersWithin mainland ChinaComplies with the data localization requirements of the Personal Information Protection Law
Overseas usersHong Kong / SingaporeA nearby node (currently Hong Kong / Singapore) is selected based on the user's region

Cross-border transfers: when your data needs to be transferred between different jurisdictions, we will take the following safeguards:

  • Standard Contractual Clauses (SCC)
  • Encrypted data transmission (TLS 1.3)
  • Ensuring that the recipient provides an equivalent level of protection

In addition, for crash diagnosis and performance analysis, some device operating status data (not including real-time video or recordings) may be encrypted and transmitted to Sentry (Functional Software, Inc.) servers overseas. Sentry is SOC 2 certified, and we have entered into Standard Contractual Clauses (SCC) with it. See the SDK list in Section 9 for details.

Retention periods:

  • Retained normally for the duration of your account
  • After account deletion: all personal information is deleted within 30 days (except where retention is required by law)
  • Cloud storage recordings: retained according to the number of loop days you choose and automatically deleted when they expire
  • Event screenshots: retained for 3 days by default
  • If we stop operating a product or service, we will promptly stop collecting personal information, notify you, and delete or anonymize the personal information we have stored

6. Your Rights

Depending on applicable law (including China’s Personal Information Protection Law, the EU GDPR, and the California CCPA), you have the following rights:

RightDescriptionHow to Exercise
AccessObtain a copy of your personal informationApp: “Me” → “Account Security” → “Export Personal Data”
CorrectionCorrect inaccurate personal informationApp: “Me” → “Settings” → “Profile”
DeletionDelete your personal informationApp: “Me” → “Settings” → “Account & Security” → “Delete Account”
Withdraw ConsentWithdraw previously granted authorization/consentApp: “Me” → “Privacy & Authorization” → “Permission Management”
ComplaintComplain to a regulatory authorityContact us via the details below
Data PortabilityObtain a copy of your personal information in a structured, commonly used, machine-readable format, or request direct transfer to another controllerApp: “Me” → “Privacy & Authorization” → “Export Personal Data” or contact us
Restriction of Processing (GDPR)Request restriction of processing in certain circumstances (e.g., while an objection is being verified)Contact us via the details below
Objection (GDPR)Object to processing based on legitimate interests; processing for marketing will stopContact us via the details below
Automated Decision-Making (GDPR)Request human review if automated decision-making is usedContact us via the details below
Opt-Out of Sale/Sharing (CCPA)Opt out of the sale or sharing of your personal information for cross-context behavioral advertisingApp: “Me” → “Privacy & Authorization” → “Personalized Recommendations” or contact us
Limit Use of Sensitive Information (CCPA)Request limits on the disclosure and use of your sensitive personal informationContact us via the details below
Non-Discrimination (CCPA)You will not be treated differently for exercising your rightsNo action needed; applies automatically

Response time: we will respond to your request within 15 working days (mainland China) / 30 days (GDPR) / 45 days (CCPA).

7. Protection of Minors

The Elinko App is not designed for minors. Under applicable law:

  • Mainland China: the App is not directed at children under 14
  • United States (COPPA): the App is not directed at children under 13
  • European Union (GDPR): the App is not directed at children under 16

If we discover that we have inadvertently collected a minor’s personal information, we will delete it immediately. If you are a parent or guardian and discover this has occurred, please notify us through the contact details below.

8. Account Deletion

You can delete your account in the App at any time. Path: “Me” → “Settings” → “Account & Security” → “Delete Account”.

Deletion rules:

  • After you submit a deletion request, your account enters a 7-day cooling-off period
  • You can cancel the deletion request during the cooling-off period
  • After the cooling-off period ends, we will:
    • Delete your personal information (except where retention is required by law)
    • Unbind all associated devices (without affecting the continued use of the device hardware)
    • Terminate the cloud storage service
  • Local SD card recordings on your devices are not affected (they are stored on your device)

9. Third-Party SDK List

9.1 Huawei HMS Core SDK

  • Purpose and scenario: provide Huawei device manufacturer push notifications
  • Types of personal information collected: in-app identifiers (AAID, Push Token), hardware information such as device type, and basic system settings such as system type, system version, and country code; BSSID, WiFi information, and Android ID
  • Third-party organization: Huawei Software Technologies Co., Ltd.
  • Sensitive permissions: none
  • Third-party privacy policy: https://developer.huawei.com/consumer/cn/doc/development/HMSCore-Guides/sdk-data-security-0000001050042177
  • Collection method: SDK local collection

9.2 OPPO Push SDK (Local AAR: com.heytap.msp_3.4.0.aar)

  • Purpose and scenario: provide OPPO device manufacturer push notifications
  • Types of personal information collected: device identifiers that are technically accessible on your device (including, where permitted by the operating system, OAID, Serial Number, User ID, Android ID, Google Advertising ID, and device model; IMEI/IMSI are collected only where the operating system permits), system settings (region, system version, system language, battery level), app information (app package name, version number, running status), and basic network information
  • Third-party organization: Guangdong HeyTap Technology Co., Ltd.
  • Sensitive permissions: none
  • Third-party privacy policy: https://open.oppomobile.com/new/developmentDoc/info?id=10288
  • Collection method: SDK local collection

9.3 vivo Push SDK (Local AAR: vivo_pushSDK_v4.0.0.0_500.aar)

  • Purpose and scenario: provide vivo device manufacturer push notifications
  • Types of personal information collected: device identifiers that are technically accessible on your device (including, where permitted by the operating system, EmmCID, UFSID, Android ID, GUID, GAID, OPENID, VAID, OAID, RegID, and encrypted Android ID; IMEI is collected only where the operating system permits), app information (app package name, version number, APPID, installation/uninstallation/factory reset status, running status), device manufacturer, and basic network information; geofence status (device-level status used only for smart push notifications; no precise location is collected)
  • Third-party organization: vivo Mobile Communication Co., Ltd.
  • Sensitive permissions: none
  • Third-party privacy policy: https://dev.vivo.com.cn/documentCenter/doc/652#w1-12075822
  • Collection method: SDK local collection

9.4 MiPush SDK (Local AAR: MiPush_SDK_Client_6_0_1-C_3rd.aar)

  • Purpose and scenario: provide Xiaomi device manufacturer push notifications
  • Types of personal information collected: device identifier OAID, encrypted Android ID, device hardware information (manufacturer, model, memory, system version), network information, and WiFi running status
  • Third-party organization: Beijing Xiaomi Mobile Software Co., Ltd.
  • Sensitive permissions: none
  • Third-party privacy policy: https://dev.mi.com/distribute/doc/details?pId=1534
  • Collection method: SDK local collection

9.5 Honor Push SDK

  • Purpose and scenario: provide Honor device manufacturer push notifications
  • Types of personal information collected: device identifiers (AAID, PushToken), APPID, and app package name
  • Third-party organization: Shenzhen Honor Software Technologies Co., Ltd.
  • Sensitive permissions: none
  • Third-party privacy policy: https://developer.honor.com/cn/docs/11002/guides/sdk-data-security
  • Collection method: SDK local collection

9.6 Tingyun SDK (Honor Push Cooperation)

  • Purpose and scenario: monitor app performance and system failures to improve user experience
  • Types of personal information collected: network information, public IP address, Honor push app information (package name, app name, app version), distribution channel ID, and carrier code
  • Third-party organization: Beijing Diao Network Technology Co., Ltd.
  • Sensitive permissions: none
  • Third-party privacy policy: https://www.tingyun.com/legal-declaration
  • Collection method: SDK local collection

9.7 Adgo SDK - flutter_unad_ads_global

  • Purpose and scenario: overseas advertising delivery and advertising effectiveness attribution analytics
  • Types of personal information collected: device identifiers (including Google Advertising ID GAID/IDFA), IP address, location information, sensor data, and advertising interaction data; used for cross-app advertising attribution and personalized advertising
  • Third-party organization: Hangzhou Feiyu Technology Co., Ltd.
  • Sensitive permissions: location and sensor permissions
  • Third-party privacy policy: https://doc.adgo.link/Privacy/privacy-policy.html
  • Collection method: SDK local collection
  • Personalized advertising notice: before delivering personalized advertising through the Adgo SDK, we will obtain your separate consent where required by applicable law (including the GDPR and ePrivacy rules). You can withdraw consent or opt out of personalized advertising at any time via App: “Me” → “Privacy & Authorization” → “Personalized Recommendations”; opting out does not affect core features.

9.8 firebase_messaging SDK

  • Purpose and scenario: App push messages, notification delivery, and subscription to message topics
  • Types of personal information collected: device installation identifier, FCM push token, system version, app version, system language and time zone, network IP, push subscription topics, and notification delivery status; if an analytics component is integrated, user notification click behavior may be collected; push messages are temporarily relayed through Google servers during delivery and are not stored permanently
  • Third-party organization: Google LLC
  • Sensitive permissions: none
  • Third-party privacy policy: https://firebase.google.com/support/privacy
  • Collection method: SDK local collection

9.9 firebase_crashlytics SDK

  • Purpose and scenario: collect crash and exception logs, identify software defects, and improve App stability
  • Types of personal information collected: anonymous device installation identifier, device model, operating system version, app version, crash stack information, device memory/running status at the time of the crash, session duration, temporary network IP, and system language and time zone
  • Third-party organization: Google LLC
  • Sensitive permissions: none
  • Third-party privacy policy: https://firebase.google.com/support/privacy
  • Collection method: SDK local collection

9.10 firebase_analytics SDK

  • Purpose and scenario: analyze user behavior, retention and conversion, and channel effectiveness to improve product experience
  • Types of personal information collected: anonymous device identifiers, device software and hardware information, App operation behavior, network IP, and system time zone and language; iOS automatically collects IDFV; if ad attribution or advertising features are enabled, advertising identifiers (IDFA/AAID) are additionally collected
  • Third-party organization: Google LLC
  • Sensitive permissions: none
  • Third-party privacy policy: https://firebase.google.com/support/privacy
  • Collection method: SDK local collection

9.11 Sentry SDK (sentry_flutter)

  • Purpose and scenario: capture program crashes, page lag, and API exceptions, analyze performance issues, and optimize product experience; collected diagnostic data is encrypted and transmitted to Sentry servers overseas
  • Types of personal information collected: anonymous random local installation ID and session identifier; device software and hardware information, app version, system time zone and language, and network type; crash stacks, performance timings, page routes and operation traces, and basic network request chain information; all text content is redacted by default and user input is not automatically captured; user ID, custom business logs, network egress IP, and app screenshots (automatically redacted) may be additionally collected only when the developer explicitly configures this
  • Third-party organization: Functional Software, Inc. (brand name: Sentry)
  • Sensitive permissions: none
  • Third-party privacy policy: https://sentry.io/privacy/
  • Collection method: SDK local collection

10. Updates to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you through the following channels:

  • In-app pop-up notification
  • Email notification (if you have provided an email address)

For processing that requires renewed consent (e.g., sensitive personal information or personalized advertising), we will obtain your separate consent before continuing after a material change. For other changes, continued use after notification constitutes acceptance. If you do not agree, you may choose to delete your account.

11. Contact Us

  • Privacy email: wangyong@yiwangxinkong.cn
  • In the App: “Me” → “Help & Feedback”
  • Registered address: Room 501, Building 4, Yunli Smart Park, No. 3 Changfa Middle Road, Yangmei Community, Bantian Subdistrict, Longgang District, Shenzhen, Guangdong Province, China
  • EU/EEA representative: where required by applicable law, we will designate an EU/EEA representative and publish their contact details in this policy.