Overview
- Personal Information We Collect
- How We Use Your Information
- How We Use Cookies and Similar Technologies
- How We Share Your Personal Information
- How We Transfer Your Data Around the World
- How We Secure Your Information
- How We Retain Your Personal Information
- Your Rights and Choices
- Use by Minors
- Changes to This Privacy Policy
- Contact Us
- Legal Bases for Processing
- Additional U.S. State Disclosures
1. Personal Information We Collect
For the purpose of this Policy, “personal information” means any information relating to an identified or identifiable individual. In certain jurisdictions, this may be referred to as “personal data”. For consistency, this Policy uses the term “personal information” throughout.1.1 Information You Provide
Through your use of the Services, you may provide us with the following information:a. Account Information
This includes your email address or Google Account, verification code, and password. When you use our Services, you may create an account with your email address or Google Account to complete registration and become our user. We may verify your identity by sending a verification code. If you refuse to provide Account Information for registration and login, we may be unable to create an account or offer you our Services.b. Information Required for Trial Service Application
This includes developer type (enterprise or individual), business scenario, and contact name. If you are an enterprise developer, you also need to provide your company name and company size. This information is required to apply for an API service trial. We collect it to verify your identity, review your application, and determine your eligibility for access. Except for optional items, these details are necessary; if you do not provide them, you may be unable to apply for the trial.c. Payment Information
This includes the record of your payment status. Some of our Services may require payment before use, and the specific payment requirements are shown on the relevant platform pages. This information is necessary to record your payment and enable access to the corresponding services based on your payment status. If you refuse to provide this information, you may be unable to use the related paid services.d. Feedback Information
This includes your communications or call records with our customer service representatives, including your account information, feedback, additional information provided to verify facts, and contact details. This information is used to communicate with you effectively, resolve your issues promptly, and document solutions. The above information is necessary for us to provide customer support; however, refusing to provide it will not affect your ability to use our other Services.1.2 Information We Collect Automatically
e. Usage Data
We collect your API usage information associated with your account, including your API key information, its creation time, latest call time, and usage records such as consumed interfaces, models, consumption amount, and consumption time. This information is necessary to help you manage and monitor your API service usage.f. Device and Network Data
This includes your device and log information, including:- hardware model
- operating system version
- device identifier
- IP address
- WLAN access points such as SSID and BSSID
- base station
- software version
- network access method, type, and status
- network quality data
- network source and destination addresses
- network source port
- operation time and operation type
- usage and service logs
- device sensor data such as accelerometer
- overall usage statistics
- performance data
1.3 Information Processed by Us as a Data Processor
When we act as a data processor and process personal data on behalf of our commercial customers using our Services, for example when an end user’s employer has provisioned a StepFun account or when an end user uses an application powered by StepFun on the back end, the commercial customer serves as the data controller. The commercial customer is responsible for providing its own privacy policy to explain how it handles personal data. Commercial customers may refer to this Policy when developing their own policies. Information we may process as a data processor includes:a. End Users’ Account Information
This includes end users’ mobile phone number.b. End Users’ Interaction Information
When an end user uses the AI-powered function, we collect input data such as text, images, and voice messages. These inputs are analyzed to enhance our understanding of the inquiry and context, enabling us to provide responses tailored to the specific need.c. Device and Network Data
This includes end users’ device and log information, including hardware model, operating system version, device identifier, IP address, WLAN access points such as SSID and BSSID, base station, software version, network access method, type, status, network quality data, network source and destination addresses, network source port, operation time and operation type, usage and service logs, device sensor data such as accelerometer, overall usage statistics, and performance data.d. Usage Data
This includes end users’ behavior information while using the Services, including click, browsing, and editing activity records.2. How We Use Your Information
We use your personal information for the following purposes. You can find more detail in Legal Bases for Processing.- To provide user account management functions, such as account registration, login, and deletion.
- To offer trial services, verify identity, review applications, and determine eligibility for access.
- To facilitate payments for the Services we provide.
- To send notifications, such as reminders about service usage.
- To analyze user behavior in order to optimize and improve the Services.
- To monitor and protect the Services, ensuring normal operation and preventing fraud, criminal activity, or misuse.
- To respond to inquiries, comments, feedback, or questions.
- To comply with legal obligations and defend against legal claims or disputes.
3. How We Use Cookies and Similar Technologies
Cookies and similar technologies are common technologies used on the internet. When you use our Services, we may send one or more cookies or anonymous identifiers to your device to collect, identify, and store information about your access to and use of the Services. We do not use cookies for any purposes other than those described in this Policy. We primarily use cookies and similar technologies for the following purposes:a. Ensuring Secure and Efficient Operation
We may set authentication and security-related cookies or anonymous identifiers to verify whether you have securely logged into the platform or encountered unauthorized use, fraud, or other illegal activities. These technologies also help us improve service efficiency and enhance login and response speed.b. Improving Access Experience
Using such technologies can help you avoid repeating steps and procedures for re-entering your personal information.c. Clearing Cookies
Most browsers provide users with the ability to clear browser cache data. You can perform data clearing operations through browser settings. If you clear the data, you may no longer be able to use services or features provided by us that rely on cookies due to these changes.4. How We Share Your Personal Information
In order to provide you with more comprehensive and higher-quality Services, we may authorize commercial partners to provide certain services to you. In such cases, we may share some of your personal information with our partners. We only share personal information for lawful, legitimate, necessary, specific, and explicit purposes, and only to the extent required to provide the Services. We require our partners, through agreements, to retain data only for the necessary period and to implement adequate security measures. We may disclose personal information to the following categories of third parties:Affiliates and Corporate Partners
We disclose the categories of personal information described above between and among our affiliates and related entities for legitimate business purposes and operation of the Services, in accordance with applicable laws.Service Providers and Business Partners
Third-party service providers who provide technology services such as server deployment and database storage, and business support such as SMS sending services, may need to process your data. These third parties process personal information on our behalf under relevant contracts.Law Enforcement Agencies and Public Authorities
We disclose information if we are legally required to do so, or if we have a good-faith belief that such use is reasonably necessary to comply with a legal obligation, process, or request; enforce our Terms of Service and other terms, policies, and standards; detect, prevent, or otherwise address security, fraud, or technical issues; or protect the rights, property, or safety of us, our users, third parties, or the public, as required or permitted by law.Change of Corporate Ownership
If we are involved in a merger, acquisition, bankruptcy, reorganization, partnership, asset sale, or other transaction, we may disclose your information as part of that transaction.5. How We Transfer Your Data Around the World
Our servers are located in the United States. Due to the international nature of our business, your personal information may also be accessed by our affiliates or transferred to third-party service providers and business partners in connection with the purposes set out in this Policy. For this reason, we may transfer personal information to jurisdictions that have different laws and data protection requirements from those in your location. If you would like more information regarding cross-border data transfers, please contact us through the details provided in Contact Us. Where required by applicable laws, we will provide an adequate level of protection for your personal information using various means, including implementing Standard Contractual Clauses or other lawful data transfer mechanisms.6. How We Secure Your Information
- We take the security of your personal information seriously and implement reasonable security measures, including technical and managerial safeguards, to prevent improper use, unauthorized access, disclosure, use, modification, damage, loss, or leakage.
- We use encryption technologies, anonymization techniques, and other reasonably feasible methods no less secure than those used by industry peers to protect personal information and prevent malicious attacks.
- We maintain a dedicated security team, security management policies, and data security procedures. We enforce strict data usage and access policies so that only authorized personnel can access personal information, and we conduct security audits where appropriate.
- Despite these efforts, no internet-based service can guarantee absolute security. We will do our best to ensure the security of the personal information you provide to us.
- The systems and communication networks used to access our services may encounter issues beyond our control. You should take proactive measures to protect your personal information, including not disclosing account information to others.
- We maintain incident response plans and will activate them promptly in the event of a user information security incident. Where required by law, we will notify you of the incident, its likely impact, the measures taken or proposed, recommendations for mitigating risk, and any remedies available.
- Once you leave the StepFun platform and browse or use other websites, services, or content resources, we have no direct obligation to protect personal information you submit outside the platform.
7. How We Retain Your Personal Information
We retain personal information only as long as necessary for the intended purpose, for example:- Phone number: retained as needed to provide normal services, respond to inquiries or complaints, and ensure account and system security.
- IP addresses: retained for 3 years.
- to comply with legal requirements
- for financial, audit, dispute resolution, or other legitimate purposes
8. Your Rights and Choices
Subject to applicable law and depending on where you reside, you may have rights regarding your personal information.8.1 Data Access
You may have the right to know what personal information we process about you, including categories of personal information, business or commercial purposes for collection, categories of third parties to whom we disclose it, and other information required by applicable law. You may also have the right to access and obtain a copy of your personal information. Where applicable, we will provide the information in a portable, machine-readable, readily usable format. You can view your phone number information and access API key information, account creation time, last call time, and usage records on the StepFun platform page. If you wish to access other personal information generated during your use of the platform, you may contact us through the contact details provided in this Policy.8.2 Data Correction
You may have the right to request correction of inaccurate personal information that we retain about you, subject to applicable exceptions.8.3 Data Deletion
You have the right to delete your account and erase your personal information. Upon deleting your account, all your personal information will be deleted. You may also request deletion of the personal information you provide by contacting us. If some personal information cannot be deleted, we will inform you of the reasons. We reserve the right to retain some personal information where there are valid grounds for us to do so under applicable laws.8.4 Withdrawal of Consent
Where we process your personal information on the basis of your consent, you may withdraw consent by contacting us. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.8.5 Objection to Processing
Subject to applicable laws, you may object to processing based on our legitimate interests where there are grounds relating to your particular situation. We may have overriding legitimate interests to continue processing, and we will let you know where that is the case.8.6 Restriction of Processing
If you would like to restrict our processing of your personal information, you may contact us. You may have the right to restrict processing where:- the processing is unlawful and you oppose erasure
- you need us to retain personal information for establishment, exercise, or defense of legal claims
- your objection regarding the accuracy of personal information is pending verification
- your objection to processing is pending verification
8.7 Lodge a Complaint
Subject to applicable data protection laws, you may have the right to submit a complaint to the local data protection authority where you reside if you consider that our processing infringes applicable data protection laws. A full list of EU supervisory authorities’ contact details is available here. If you live or work in the UK, you have the right to lodge a complaint with the UK Information Commissioner’s Office.8.8 Other Rights
Depending on your jurisdiction, you may be entitled to additional rights in relation to your personal information. To exercise rights, ask questions about this Policy, or file a complaint about how we process your personal information, use the contact details provided in Contact Us. When submitting a rights request, please specify the scope and basis of your request and provide information necessary to verify your identity. We may contact you to confirm your identity. We will typically respond within 7 days after verifying your identity and no later than the timeframe required by applicable laws.9. Use by Minors
If you are considered a minor under the laws of the applicable jurisdiction, consent to the processing of your personal information must be given by your parent or legal guardian before using the Services. Our Services are not directed toward, and we do not knowingly collect, sell, or share information about individuals under 18. If you become aware that a child under 18 has provided personal information to us while using our Services, please contact us using the details in Contact Us, and we will investigate and, if appropriate, delete the personal information.10. Changes to This Privacy Policy
The Services and our business may change from time to time. As a result, it may be necessary for us to make changes to this Policy. We recommend that you regularly check the latest version of this Policy on the StepFun platform. If there are any substantial changes, depending on the nature of those changes, we will notify you in advance through pop-ups, push notifications, or other appropriate means.11. Contact Us
For more information about your data subject rights, or how we process your personal information, please contact us using the information below.- Controller: SPARKLING AI PTE. LTD.
- Contact Person: StepFun Privacy Team
- Contact Details: platform@stepfun.com
12. Legal Bases for Processing
Account Management
- Purpose: To provide user account management functions, such as account registration, login, and deletion
- Type of personal information: Account Information; Device and Network Data
- Legal basis: Performance of contract
Trial Services
- Purpose: To offer trial services, verify identity, review applications, and determine eligibility for access
- Type of personal information: Account Information; Information Required for Trial Service Application; Usage Data; Device and Network Data
- Legal basis: Performance of contract
Notifications
- Purpose: To send notifications, such as reminders about service usage
- Type of personal information: Account Information; Usage Data; Device and Network Data
- Legal basis: Performance of contract and consent where required by applicable laws
Payments
- Purpose: To facilitate payments for the Services we provide
- Type of personal information: Payment Information; Device and Network Data
- Legal basis: Performance of contract
Service Improvement
- Purpose: To analyze user behavior in order to optimize and improve the Services
- Type of personal information: Device and Network Data; Usage Data
- Legal basis: Legitimate interests in identifying and resolving issues with the platform and enhancing its functionality
Service Protection
- Purpose: To monitor and protect the Services, ensuring normal operation and preventing fraud, criminal activity, or misuse
- Type of personal information: Account Information; Device and Network Data; Usage Data
- Legal basis: Performance of contract and legitimate interests in ensuring that the platform is safe and secure
Support and Communications
- Purpose: To respond to inquiries, comments, feedback, or questions
- Type of personal information: Account Information; Payment Information; Feedback Information
- Legal basis: Performance of contract
Legal Compliance
- Purpose: To comply with legal obligations and defend against legal claims or disputes
- Type of personal information: Account Information; Information Required for Trial Service Application; Payment Information; Feedback Information; Device and Network Data; Usage Data
- Legal basis: Legal obligations, legitimate interests, and consent where required by applicable laws
13. Additional U.S. State Disclosures
We collected personal information from and about you in the preceding 12 months as described in Personal Information We Collect. We disclosed personal information with third parties for business purposes in the preceding 12 months as follows:- All categories detailed in Section 1 above: disclosed to server deployment and database storage service providers and our affiliates
- Account Information: disclosed to SMS sending service providers
- Limit the use of sensitive personal information. If you would like to limit the use of your sensitive personal information, please contact us using the details in Contact Us.
- Do not sell or share my personal information. Based on applicable state-law definitions, we do not believe we engage in such activity and have not engaged in such activity in the preceding 12 months from the effective date of this Policy.
- Appeal. You may appeal our refusal to take action on a request by contacting us using the details in Contact Us.
- Direct marketing. We do not disclose personal information to third parties for their direct marketing purposes.
- Non-discrimination. You have the right not to be discriminated against for exercising any of your rights.