Public summary · United States and Canada, including Quebec

Privacy Governance and Request Handling

This page explains in plain language how YiTu assigns privacy responsibility, manages the information lifecycle, and handles requests and complaints. Please also read the full Privacy Policy.

Responsibility and administration location

YiTu is currently operated by the individual HAICHUAN ZHANG, who is also the Privacy Officer. A registered company is not YiTu’s current operator. Operational administration and privacy requests are handled from Canada. This is separate from the user service region and does not mean providers process data only in Canada.

Contact: privacy@yituapp.com. The mailbox supports external receiving, sending, and direct replies in Chinese, English, and French.

Information lifecycle

We collect only what is needed for speech recognition, translation, speech generation, connection security, troubleshooting, and request handling. We do not create user accounts or use data for ads, sale, cross-context targeting, or profiling.

Captions, translation history, and returned speech primarily remain in runtime memory. Temporary recordings are deleted on a best-effort basis across cleanup paths. Data we control is deleted or de-identified when its purpose or retention period ends and no legal hold applies.

Providers and cross-border processing

We review the purpose, data, written arrangements, subprocessors, locations, retention, deletion, and incident boundaries for OpenAI, Cloudflare (including the Worker used by voice features and Pages used by the static privacy site), and Google/Gmail. We select only providers that, under applicable terms, data processing addenda, or other written arrangements, give the same or equivalent protection required by our policy and applicable law.

Using providers does not relieve HAICHUAN ZHANG of responsibility for protecting data or for provider selection and oversight. Data may be processed in the United States and other locations published by providers, where lawful government-access requirements may apply.

Access, correction, withdrawal, and deletion

You may send access, correction, consent-withdrawal, deletion, portability, or other privacy requests in Chinese, English, or French to privacy@yituapp.com. We request only identity-verification information proportionate to the request’s risk and aim to provide a substantive response within 30 days.

The App has no accounts, so we generally cannot find an anonymous voice session using a name or email. Providers may also be unable to isolate a default log entry. We will explain our search, technical limits, referrals, and available recourse rather than claim deletion we cannot verify.

Complaints and incidents

The Privacy Officer reviews complaints first. Canadian users may also contact the Office of the Privacy Commissioner of Canada (OPC); Quebec users may also contact the Commission d’accès à l’information du Québec (CAI).

We contain, assess, remedy, and record privacy incidents. When an applicable reporting threshold is met, we notify the competent authority and affected individuals as soon as required. Incident records are kept for at least five years without copying unnecessary speech, email content, or credentials.

Review and policy changes

At least every 12 months, and after a material product, provider, law, or incident change, we review governance, privacy impact assessments, providers, retention, requests, and safeguards. Material processing changes trigger new App consent where required; old consent is not silently carried forward.