隐私政策
最后更新:2026 年 4 月 28 日
1. 我们收集的信息
Fiva AI(以下简称"本应用")在提供服务过程中可能收集以下类型的信息:
- 账号信息:注册时提供的电子邮件地址、用户名等。
- 训练数据:您的运动记录、姿态分析结果、评分历史等。
- 摄像头数据:姿态识别功能需要访问摄像头。摄像头画面仅在设备本地处理,不会上传至服务器。
- 设备信息:设备型号、操作系统版本、应用版本,用于调试和改善服务。
- 使用数据:功能使用频率、崩溃报告等匿名统计数据。
2. 信息的使用方式
我们使用收集的信息用于:
- 提供、维护和改进本应用的功能;
- 个性化训练建议和 AI 教练反馈;
- 发送服务通知(如订阅到期提醒);
- 防止欺诈和保障账号安全;
- 匿名化的产品分析以改善用户体验。
3. 信息共享
我们不会出售、出租或以其他商业目的分享您的个人信息。以下情况除外:
- 服务提供商:我们可能与处理支付、云存储、数据分析的第三方服务商共享必要信息,这些服务商受保密协议约束。
- 法律要求:在法律、监管机构或司法程序要求时,我们可能披露相关信息。
- 业务转让:若发生合并、收购或资产出售,用户信息可能作为资产转让,届时将提前告知。
4. 数据安全
我们采用行业标准的安全措施保护您的数据,包括 HTTPS 加密传输、数据库加密存储以及定期安全审计。但请注意,没有任何网络传输或存储系统能做到完全无风险。
5. 摄像头与设备本地姿态识别(含面部区域关键点)
本应用的核心功能(姿态识别和动作计数)需要访问摄像头。我们郑重承诺:
- 摄像头画面仅在您的设备上本地处理,不会上传至任何服务器;
- 不录制、不截图、不上传任何摄像头画面;
- 您可随时在系统设置中撤销摄像头权限(撤销后相关功能将无法使用)。
本应用使用 Google ML Kit Pose Detection(端侧推理)从摄像头帧中实时计算 33 个全身关键点骨架。其中 11 个关键点落在用户面部区域(鼻尖、左/右眼内/中/外角、左/右耳、嘴左/右角),它们仅作为骨架的位置坐标用于以下用途:
- 实时姿态追踪(判断用户是否进入画面、起始姿势是否就绪);
- 需要头部/上半身参与的动作(如仰卧起坐)的次数计数;
- 本地绘制骨架叠加层提供视觉反馈。
本应用不进行人脸识别、人脸认证或任何生物特征识别,不建立 face print / face template,不提取年龄、性别、情绪等个人属性。所有面部区域关键点仅在设备内存中临时存在,单帧处理结束或相机会话结束时立即丢弃,从不写入磁盘、从不上传服务器、从不与任何第三方共享。保留时长:零。
6. 数据保留与删除
您可以随时在应用设置中申请删除账号。账号删除后,我们将在 30 天内删除您的个人数据(法律要求保留的除外)。匿名化的统计数据可能继续保留用于产品改进。
7. 儿童隐私
本应用不面向 13 岁以下儿童(在欧盟为 16 岁以下)。如果您发现未成年人在未经监护人同意的情况下使用本应用,请联系我们,我们将立即删除相关账号。
8. 第三方服务与 AI 处理
本应用使用以下第三方服务。除用户主动发起的 AI 教练上传外,不会向任何第三方传输个人数据。我们也不集成任何第三方分析、广告或追踪 SDK(无 Firebase Analytics、Sentry、AppsFlyer 等)。
- 豆包大模型(Doubao LLM AI,字节跳动 火山引擎):用于两类场景。
(a)运动总结:运动结束后,应用会将匿名的统计数据(运动名称、次数、时长、平均评分、卡路里估算)发送至我们的后台,再转发至豆包大模型生成总结文案。不发送任何画面、骨架、面部关键点或用户标识。
(b)AI 教练:用户主动上传的图片、视频或文字会经我们的后台转发给豆包大模型进行内容分析。每次发送都由用户在 UI 上明确触发。 - 腾讯云对象存储(COS):作为 AI 教练上传的暂存。用户上传的图片/视频会存放在 COS 上以便豆包大模型 API 拉取,24 小时后自动删除。
- Apple StoreKit / Google Play Billing:应用内购买的收据校验。除 Apple/Google 自身收到的信息外,不传输额外个人数据。
- 微信支付 / 支付宝(仅 Android 渠道):订阅支付通道。
- Apple App Store / Google Play:应用分发。
所有端侧 ML 推理(姿态检测)均在设备本地运行,从不离开设备。
我们已与上述每一家第三方服务核对其公开发布的隐私与数据保护条款,确认其对用户数据提供与本应用同等或更强的保护标准;任何向第三方发送数据的操作仅在用户在 App 内显式同意「AI 数据共享」之后才会发生,用户随时可在「设置 → AI 数据共享」内撤回同意。
9. 隐私政策变更
我们可能不时更新本隐私政策。重大变更将通过应用内通知或电子邮件告知您。继续使用本应用表示您同意更新后的政策。
10. 联系我们
如有隐私相关问题,请联系:privacy@fiwaai.com
1. Information We Collect
Fiva AI ("the App") may collect the following types of information in the course of providing its services:
- Account Information: Email address, username, and other details provided during registration.
- Workout Data: Exercise logs, pose analysis results, form scores, and session history.
- Camera Data: Pose detection requires camera access. Camera frames are processed locally on your device only — nothing is uploaded to our servers.
- Device Information: Device model, OS version, and app version, used for debugging and service improvement.
- Usage Data: Anonymous statistics such as feature usage frequency and crash reports.
2. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the App's features;
- Personalize training suggestions and AI coach feedback;
- Send service notifications (e.g., subscription renewal reminders);
- Prevent fraud and protect account security;
- Conduct anonymized product analytics to improve user experience.
3. Information Sharing
We do not sell, rent, or share your personal information for commercial purposes. Exceptions include:
- Service Providers: We may share necessary data with third-party vendors handling payments, cloud storage, or analytics, bound by confidentiality agreements.
- Legal Requirements: We may disclose information when required by law, regulation, or judicial process.
- Business Transfers: In the event of a merger, acquisition, or asset sale, user information may be transferred as an asset, with prior notice provided.
4. Data Security
We employ industry-standard security measures including HTTPS encrypted transmission, encrypted database storage, and regular security audits. Please note that no network transmission or storage system can be guaranteed completely risk-free.
5. Camera and On-Device Pose Detection (Including Face-Region Landmarks)
The App's core features (pose detection and rep counting) require camera access. We commit to the following:
- Camera frames are processed locally on your device only — nothing is uploaded to any server;
- We do not record, screenshot, or upload any camera footage;
- You may revoke camera permission at any time in system settings (doing so will disable related features).
The App uses Google ML Kit Pose Detection (running entirely on-device) to compute a full-body skeleton of 33 anatomical landmarks from camera frames in real time. 11 of these landmarks fall on the user's face region — specifically: nose tip, left/right eye (inner, center, outer), left/right ear, and mouth corners (left, right). These are positional coordinates only and are used solely for:
- Real-time pose tracking — detecting whether the user is in frame and ready to start;
- Exercise rep counting for movements that involve head/upper-body motion (e.g., crunches);
- Drawing the local skeleton overlay for user feedback.
The App does not perform face recognition, face authentication, or any biometric identification. No face prints or face templates are created. No age, gender, or emotion inference is performed. All face-region landmarks exist only in volatile device memory during an active camera session and are discarded immediately after each frame is processed. They are never written to disk, never transmitted off the device, and never shared with any third party. Retention duration: zero.
6. Data Retention & Deletion
You may request account deletion at any time in the App settings. Following deletion, we will remove your personal data within 30 days (except where retention is required by law). Anonymized statistics may be retained for product improvement.
7. Children's Privacy
The App is not directed at children under 13 (or under 16 in the EU). If you believe a minor has used the App without guardian consent, please contact us and we will promptly delete the account.
8. Third-Party Services and AI Processing
The App uses the third-party services listed below. Outside of explicitly user-initiated AI Coach uploads, no personal data is shared with any third party. We do not integrate any third-party analytics, advertising, or tracking SDKs (no Firebase Analytics, Sentry, AppsFlyer, etc.).
- Doubao LLM AI (ByteDance Volcano Engine) — used in two scenarios.
(a) Workout Summary: After a workout, the App sends anonymous aggregate statistics (exercise name, rep count, duration, average form score, calorie estimate) to our backend, which forwards them to Doubao to generate a summary. No camera frames, no skeletons, no face landmarks, and no user identifiers are sent.
(b) AI Coach: When the user explicitly uploads a photo, video, or text question, the upload is forwarded by our backend to Doubao for analysis. Every transmission is initiated by the user via a clear UI action. - Tencent Cloud Object Storage (COS) — transient storage for AI Coach uploads only. User-uploaded photos/videos are placed on COS so that Doubao's API can fetch them, and are auto-deleted after 24 hours.
- Apple StoreKit / Google Play Billing — In-App Purchase receipt validation. No personal data beyond what Apple/Google themselves receive is shared.
- WeChat Pay / Alipay (Android only) — subscription payment channels.
- Apple App Store / Google Play — app distribution.
All on-device ML inference (pose detection) runs locally and never leaves the device.
We have reviewed each third party listed above against their publicly available privacy and data-protection terms and confirm that they provide protection of user data equivalent to or stronger than this policy. No data is sent to any third party until the user has explicitly granted "AI Data Sharing" consent in the app, and the user can revoke this consent at any time from Settings → AI Data Sharing.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notifications or email. Continued use of the App constitutes acceptance of the updated policy.
10. Contact Us
For privacy-related inquiries, please contact: privacy@fiwaai.com