[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"legal-privacy-en_US":3},"# MiYu Note Privacy Policy (**Last Updated: June 16, 2026**)\n\n## Important Note on End-to-End Encryption\n\nMiYu Note (hereinafter referred to as \"**we**\" or \"**the Service**\") deeply understands the importance of privacy to you. We adopt an **End-to-End Encryption (E2EE)** and **Zero-Knowledge** architecture. Any data referenced in this Policy as \"processed by us\" or \"stored by us\" is strictly distinguished between **ciphertext encrypted locally by you** and **unencrypted metadata**. Unless expressly stated otherwise in this Policy, **we are technically unable to read the body of your notes or the content of your attachments**, and no judicial or administrative authority can obtain such content in plaintext from us.\n\n---\n\n## 1. Definitions and Scope of Application\n\n### 1.1 Definitions\n\n- **\"Personal Information\"**: various information recorded in electronic or other forms that relates to an identified or identifiable natural person, **not including information after anonymization** (with reference to Article 4 of the *Personal Information Protection Law of the People's Republic of China*).\n- **\"Sensitive Personal Information\"**: personal information that, once leaked or illegally used, may easily lead to infringement of human dignity or harm to personal or property safety, including biometric identification, religious beliefs, specific identity, medical health, financial accounts, location-tracking information, and personal information of minors under fourteen years of age (with reference to Article 28 of the *Personal Information Protection Law*).\n- **\"Processing\"**: any operation performed on personal information, including collection, storage, use, processing, transmission, provision, disclosure and deletion (with reference to Article 4 of the *Personal Information Protection Law*).\n- **\"Data Controller\"** \u002F **\"Personal Information Processor\"**: the entity that determines the purposes and means of personal information processing. The operating entity of the Service is the **Personal Information Processor** of your personal information.\n- **\"E2EE Ciphertext\"**: data uploaded to our server after your note bodies and attachments have been encrypted locally with your Space Key.\n- **\"Space Key\"**: the cryptographic key generated locally on your device and used to encrypt the body of your notes.\n- **\"Space Key Password\"**: the passphrase set by you, used locally to decrypt the copy of the Space Key stored in the cloud.\n\n### 1.2 Personal Information Processor Information\n\n- **Operator**: Beijing Natural Symbol Information Technology Co., Ltd.\n- **Registered address**: Room 103-2617, 1st Floor, Building 21, Area 2, Tianzhong Yuan, Dongxiaokou Town, Changping District, Beijing\n- **Unified Social Credit Code**: 91110114MAKFN7JW4Q\n- **Legal representative \u002F Person in charge of privacy protection**: Li Chaoyang, privacy@miyunote.cn\n\n### 1.3 Scope and Territory\n\n- This Policy applies to personal-information-processing activities involved when you use the Service through the MiYu Note official website, mobile applications, desktop clients or other official channels.\n- **The Service is currently primarily offered to users in Mainland China.** Our operating entity is located in the People's Republic of China. If you access the Service from other regions, you remain bound by the general terms of this Policy, and the **mandatory laws** of your jurisdiction shall still prevail.\n\n### 1.4 Language Versions\n\n- The **Simplified Chinese** version of this Policy is the authoritative version.\n- We currently provide, without limitation, the following languages: **Simplified Chinese, Traditional Chinese, English, German and French**. The actual list of supported languages follows the language list in the application.\n- In case of any inconsistency between language versions, the **Simplified Chinese version shall prevail**.\n\n---\n\n## 2. What Information We Collect, Why and on What Legal Basis\n\nWe follow the principles of **lawfulness, legitimacy, necessity and good faith** as well as the **purpose-limitation** principle, and process personal information only to the extent necessary to provide the Service to you (with reference to Articles 5 to 9 of the *Personal Information Protection Law*).\n\n| Data Category | Specific Content | Purpose | Legal Basis (Article 13 of the *PIPL*) | Retention Period |\n|---------|---------|------|--------------------------------------|---------|\n| **Account identification** | Email address or Mainland China mobile phone number | Identity verification, login, account recovery, security notifications, orders and invoices | Necessary for conclusion\u002Fperformance of the contract | For the duration of the account + 30 days after closure |\n| **Non-encrypted business metadata** | Space name, Space background image, note title, note icon, note cover image, user nickname | Cross-device list display, client feature rendering | Necessary for conclusion\u002Fperformance of the contract | For the duration of the account; 30 days after deletion\u002Fclosure |\n| **E2EE ciphertext** | Ciphertext blocks of note bodies and attachments | Multi-device encrypted synchronization | Necessary for conclusion\u002Fperformance of the contract | For the duration of the account; immediately erased from production upon user-initiated deletion |\n| **Encrypted key copy** | Your Space Key stored in ciphertext form derived from your password | Enables multi-device login by yourself | Necessary for conclusion\u002Fperformance of the contract | Aligned with the duration of the account |\n| **Device and crash logs** | Device model, OS version, app version, crash stack (not containing personally identifiable content) | Stability troubleshooting and error repair | Legitimate interest (providing more stable service to you; data de-identified) | De-identified retention not exceeding 12 months |\n| **Transient network metadata** | IP address received by the server when you initiate a request | Country\u002Fregion compliance assessment (export control, minor protection, market access) | Legitimate interest (necessity of compliance access) | **Processed only transiently in memory; not written to persistent storage** |\n| **Subscription and payment information** | Subscription type, order number, amount, currency, payment-channel identifier | Billing, invoicing, refunds, taxation | Statutory duty \u002F Necessary for contract performance | 7 years after the transaction (accounting and tax compliance) |\n| **Customer service communications** | Inquiries and appeals initiated by you | After-sales support, dispute handling | Necessary for contract performance + legitimate interest | 24 months after handling is completed |\n\n### 2.1 Sensitive Personal Information\n\nThe Service **does not collect your Sensitive Personal Information by default** (such as biometric data, location tracking, medical health, financial accounts, etc.). Content that you input yourself into your notes and that is encrypted with E2EE is controlled by you; we neither actively identify nor actively access its plaintext.\n\n### 2.2 Legitimate-Interest Assessment\n\nWe have conducted necessity assessments for processing activities based on \"legitimate interest\":\n\n- **Device and crash logs**: Users' reasonable expectation of stable service outweighs the privacy impact of collecting a very small amount of device information, and the data has been de-identified.\n- **Transient IP processing**: The necessity of compliance access outweighs the privacy impact of brief IP processing, and the data is not retained in persistent storage.\n- **Retention of customer service communications for 24 months**: A reasonable period for traceability of disputes outweighs the impact of short-term retention.\n\nYou may at any time raise objections to our legitimate-interest assessment through the contact information in Section 13 of this Policy.\n\n### 2.13 Separate Consent\n\nYour **separate consent** is required in the following circumstances (with reference to Articles 23, 25, 26, etc. of the *Personal Information Protection Law*):\n\n- Providing your personal information abroad (currently not performed by the Service);\n- Disclosing personal information processed by us;\n- Processing specific personal information that you have voluntarily disclosed but have expressly refused;\n- Other circumstances requiring separate consent as required by laws and regulations.\n\n---\n\n## 3. End-to-End Encryption and Zero-Knowledge Architecture (Core Explanation)\n\n### 3.1 Encryption Mechanism\n\nYour note bodies and attachments are encrypted with your **Space Key** before they leave your local device. We cannot obtain the plaintext of your Space Key, nor can we decrypt the E2EE ciphertext you upload on the server.\n\n### 3.2 Storage and Decryption of the Space Key\n\nTo provide you with a multi-device synchronization experience, your Space Key is uploaded to the cloud in **ciphertext form derived from your own password**. This ciphertext can **only** be decrypted locally using the Space Key password you set. We neither collect nor store the plaintext of your Space Key password on the server, and we cannot bypass the password to access your Space Key in the cloud.\n\n### 3.3 Zero-Knowledge Boundary\n\n- **Readable**: Space name, Space background image, note title, note icon, note cover image, user nickname, email \u002F phone number.\n- **Not readable**: note bodies and attachment content.\n- Any third party, including ourselves, without your Space Key password, **cannot reconstruct** your Space Key, **nor read** the plaintext of your note bodies or attachments.\n\n### 3.4 Risk of Key Loss Is Borne by You\n\nGiven the zero-knowledge architecture, if you forget your Space Key password and have not made a local backup of your Space Key, it is **technically impossible** for us to recover, reset or restore your data. Any resulting permanent data loss is borne by you.\n\n### 3.5 Requests from Judicial Authorities\n\nWhen a judicial authority or government body makes a lawful disclosure request to us:\n\n- We **can** disclose the account metadata you have actively registered (email \u002F phone number, registration time, subscription status, login IP range, etc.).\n- With respect to your note bodies and attachments, since we do not hold your Space Key password, **we cannot and will not** provide any plaintext to any authority, nor **can we assist in decryption**.\n\n---\n\n## 4. Cookies and Tracking Technologies\n\n### 4.1 Categories of Cookies We Use\n\n| Cookie Category | Purpose | Consent Required |\n|------------|------|-------------|\n| **Strictly necessary cookies** | Session identification, CSRF protection, security tokens | No (necessary for the Service) |\n| **Preference cookies** | Remember language, region, theme | Yes (you may refuse) |\n| **Analytics cookies** (optional) | Anonymous statistics of Service usage | Yes (you may refuse) |\n\n### 4.2 Our Commitments\n\n- We **do not** use advertising-tracking cookies;\n- We **do not** share your behavioural data with third-party advertising platforms for cross-context behavioural advertising;\n- We **do not** read, analyse, profile or recommend advertisements based on the content of your notes.\n\n### 4.3 Your Choices\n\nYou can manage your cookie preferences in your browser or app settings. **Strictly necessary cookies cannot be disabled** (disabling them will render the Service unavailable). For other categories, you may withdraw your consent at any time.\n\n---\n\n## 5. Sharing and Disclosure of Data\n\n### 5.1 Basic Principles\n\n- We **do not sell** your personal information;\n- We **do not use** your personal information for cross-context behavioural advertising;\n- We **do not** discriminate against you for exercising your privacy rights.\n\n### 5.2 Parties with Whom We May Share\n\nSharing occurs only in the following circumstances, and strictly on a minimum-necessary basis:\n\n1. **After obtaining your separate consent**.\n2. **Third parties necessary for the Service**:\n\n   | Type | Purpose | Access to E2EE Ciphertext |\n   |------|------|------------------|\n   | **Cloud infrastructure provider** | Provides compute, storage and CDN | Yes (ciphertext is unreadable) |\n   | **Payment and financial infrastructure** | Processes subscriptions and refunds | No |\n   | **Email delivery service** | Sends order confirmations, refund notices and security alerts | No |\n   | **Customer service and ticketing system** | Handles your inquiries | No |\n\n3. **Required by laws and regulations or in the public interest**: including responding to lawful, valid and legally binding orders or requests from judicial authorities.\n\n### 5.3 Entrusted Processing\n\nWe may entrust third parties with proper qualifications to process your personal information (e.g., cloud services, customer service systems). We will clearly stipulate the purposes, period, methods, categories of personal information, protective measures and liability for breach through written agreements.\n\n---\n\n## 6. International Data Transfers\n\n### 6.1 Current Data Centre Regions\n\nThe Service is **deployed and operated only in the following data centre regions**:\n\n| Region Identifier | Physical Location | Cloud Service Provider |\n|---------|---------|-------------|\n| **Mainland China (Beijing)** | Beijing | Tencent Cloud Beijing node |\n\n> **Note**: The current data centre of the Service is the **Tencent Cloud Beijing node**, operated by Tencent Cloud Computing (Beijing) Co., Ltd. or its local affiliated entity, which is the sole infrastructure provider for our compute, storage and CDN. **No cross-border provision of personal information is involved.** If you access the Service from outside Mainland China, the data you transmit\u002Fstore is still placed in the Mainland China data centre; the mandatory laws of your jurisdiction still apply to some of your rights, but you bear the relevant obligations and responsibilities for any **cross-border data return**.\n\n### 6.2 Future Cross-Border Transfers\n\nOnly when we engage in cross-border transfer activities in the future will we:\n\n- Notify all Users **thirty (30) calendar days** in advance via in-app announcement and email;\n- Obtain your **separate consent** (with reference to Article 39 of the *Personal Information Protection Law*);\n- Conduct a **Personal Information Protection Impact Assessment** (with reference to Article 55 of the *Personal Information Protection Law*);\n- Execute a standard contract with the overseas recipient or pass the security assessment by the Cyberspace Administration of China and other legal mechanisms;\n- Where necessary, take additional technical measures such as encryption and pseudonymisation.\n\n### 6.3 Your Choices and Rights\n\n- Your data is **stored in Mainland China by default**;\n- The laws of your jurisdiction **still apply** to some of your rights (right of withdrawal, consumer protection, etc.), regardless of data centre location;\n- You may at any time exercise the rights set out in Section 9 of this Policy through the contact information in Section 13.\n\n---\n\n## 7. Data Retention and Destruction\n\n| Data Type | Retention Period | Destruction Method |\n|---------|---------|---------|\n| Account metadata | For the duration of the account + 30 days after closure | Logical deletion in production + overwritten in backups after 30 days |\n| E2EE ciphertext | For the duration of the account | Immediately erased from production upon user-initiated deletion or account closure |\n| Encrypted key copy | Deleted together with account closure | Same as above |\n| Device and crash logs | 12 months after de-identification | Auto-expired deletion |\n| Transaction and invoice records | 7 years (accounting and tax) | Destroyed upon expiry |\n| Customer service communications | 24 months | Destroyed upon expiry |\n\n### 7.1 Backup Retention\n\nAfter we delete your data from the production environment, **copies in backups will be overwritten within no more than ninety (90) days** as part of the backup rotation cycle, and data in backups **cannot be used for routine access** or be restored for use.\n\n---\n\n## 8. Data Security\n\nWe adopt industry-standard technical and organisational measures to protect your personal information, including without limitation:\n\n- Transport-layer encryption (TLS 1.2+)\n- End-to-end encryption (note content)\n- Access control and the principle of least privilege\n- Security audits and penetration testing\n- Employee confidentiality obligations and permission management\n- Incident-response mechanisms and regular drills\n\n### 8.1 Notification of Data Security Incidents\n\n**No system is 100% secure.** We undertake that:\n\n- Where a data security incident that may affect your rights occurs, we will notify you in a timely manner in accordance with the *Cybersecurity Law* and the *Personal Information Protection Law*;\n- Where the incident is **high-risk** and affects you, we will notify you in a timely manner via in-app notification or email;\n- The notification will include: the nature of the incident, possible impact, measures taken and recommended actions for you.\n\n---\n\n## 9. Your Rights\n\n### 9.1 Rights You Enjoy Under the Law\n\nPursuant to Chapter IV of the *Personal Information Protection Law of the People's Republic of China*, you enjoy the following rights:\n\n| Right | Legal Basis | Description |\n|------|---------|------|\n| **Right to know and to decide** | Article 44 | Realised through this Policy |\n| **Right to consult and copy** | Article 45 | Obtain a copy of your personal information held by us |\n| **Right to correct and supplement** | Article 46 | Correct inaccurate or incomplete information |\n| **Right to deletion** | Article 47 | Delete your information where the statutory conditions are met |\n| **Right to explanation** | Article 48 | Require us to explain our processing rules |\n| **Right to refuse** | Article 44 | Refuse certain processing based on \"legitimate interest\" |\n| **Right to withdraw consent** | Article 15 | Withdraw any consent you have previously given (does not affect processing prior to withdrawal based on that consent) |\n| **Rights of close relatives of the deceased** | Article 49 | Close relatives may exercise relevant rights where a natural person passes away |\n| **Right to lodge complaints** | Article 65 | Lodge complaints with the cyberspace, market regulation and other authorities |\n\n### 9.2 On Automated Decision-Making\n\n- We **do not** make any automated decision-making towards you that produces legal effects or similarly significant impacts (with reference to Article 24 of the *Personal Information Protection Law*).\n- We may make coarse-grained service-availability judgements based on **device, region and subscription status** (such as suspending the Service in certain regions for legal reasons), but we **do not** make decisions towards you personally that produce legal effects or similarly significant impacts.\n\n### 9.3 Special Notes on E2EE Data\n\nWhen you exercise the rights to consult, copy and delete:\n\n- **Accessible metadata**: email \u002F phone number, nickname, Space list, note titles, etc. — can be exported in-app.\n- **E2EE ciphertext itself**: as we do not have the plaintext, we **cannot provide a \"readable\" copy**; you can export the plaintext yourself on the client. If you request us to delete it, we will erase the ciphertext from the production environment, making the data **in fact unrecoverable**.\n- **Data portability**: we provide JSON \u002F Markdown \u002F encrypted-package format exports.\n\n### 9.4 How to Exercise Your Rights\n\n- **Email**: privacy@miyunote.cn\n- The email body must include: registered email \u002F phone number, the specific right being requested, and necessary identity-verification information.\n- You may also submit through the in-app feedback channel.\n\nWe may need additional information from you to verify your identity and prevent impersonation. **We will respond within fifteen (15) business days** of receiving your request (with reference to the requirements of the *Personal Information Protection Law*; may be extended as required by law in complex cases, with prior notice to you).\n\n### 9.5 Complaints and Remedies\n\nIf you believe that our processing of your personal information does not comply with laws and regulations, you have the right to:\n\n- Lodge complaints with the **Cyberspace Administration, market regulation department, public security authorities**, etc.;\n- Seek remedies through judicial channels such as the **National Internet Court**.\n\n---\n\n## 10. Automated Decision-Making\n\nWe **do not** engage in any:\n\n- Automatic decisions on whether to provide the Service (except for compliance-access decisions based on geographic location);\n- Automatic analysis of the content of your notes;\n- Automatic profiling and personalised recommendations;\n- Any automated processing that produces legal effects or similarly significant impacts.\n\nWe may make coarse-grained service-availability judgements based on **device, region and subscription status** (such as suspending the Service in certain regions for legal reasons), but we **do not** make decisions towards you personally that produce legal effects or similarly significant impacts.\n\n---\n\n## 11. Protection of Minors\n\n### 11.1 Minimum Age\n\n- By default, the Service is **available to Users aged fourteen (14) years and above** (with reference to Article 31 of the *Personal Information Protection Law*).\n- Minors under fourteen (14) years of age who apply to use the Service require the **express consent** of their guardian (with reference to the *Law on the Protection of Minors* and the relevant provisions of the *Personal Information Protection Law*).\n\n### 11.2 Guardian Consent\n\n- Users **under fourteen (14) years of age** who apply to use the Service must have their guardian provide verifiable consent through [mechanism].\n- Upon becoming aware of the situation, we will **proactively delete** personal information of minors collected without guardian consent.\n\n---\n\n## 12. Policy Updates\n\n| Change Type | Notification Method | Effective Method |\n|------------|--------------------|------------------|\n| **Material change** (affecting your core rights) | In-app announcement + email + re-request consent | Takes effect from the date of your **express confirmation**; you may refuse and terminate the Service under the original Policy |\n| **General change** (wording adjustments, contact-information updates) | In-app announcement | Takes effect from the effective date stated in the announcement |\n| **Driven by legal change** | In-app announcement + email | Takes effect from the effective date stated in the announcement; if the change is unfavourable to you, you may terminate the Service before the effective date |\n\nHistorical versions are kept at https:\u002F\u002Fmiyunote.cn\u002Fprivacy.\n\n---\n\n## 13. Contact Us\n\nIf you have any questions, comments or rights requests regarding this Policy, please contact us through the following channels:\n\n- **In-app feedback**: Help Center → Report a Problem or Suggestion\n- **Privacy-dedicated email**: privacy@miyunote.cn\n- **Customer service email**: contact-us@miyunote.cn\n- **Security email**: security@miyunote.cn\n\nWe commit to responding to your request **within fifteen (15) business days** of receipt.\n\n---\n\n## Appendix A: Contact Information\n\n| Purpose | Email \u002F Channel |\n|---------|-----------------|\n| **Customer service email** | contact-us@miyunote.cn |\n| **Privacy-dedicated email** | privacy@miyunote.cn |\n| **Security email** | security@miyunote.cn |\n| **In-app feedback** | Help Center → Report a Problem or Suggestion |\n\n### A.1 Response Times\n\n- **Customer service inquiries**: within fifteen (15) business days\n- **Privacy-rights requests**: within fifteen (15) business days (response within the time limit stipulated by the *Personal Information Protection Law*; may be extended as required by law in complex cases)\n- **Security vulnerability reports**: initial response within twenty-four (24) hours\n\n### A.2 On Telephone Contact\n\n- **We currently do not provide telephone-based customer service.** All matters relating to customer service, privacy and security should be addressed through the email addresses or in-app feedback channels listed above.\n- Where a regulator or judicial authority requires telephone contact, please contact security@miyunote.cn to arrange an alternative communication method.\n\n---\n\n## Appendix B: Operator Information\n\n- **Operator name**: Beijing Natural Symbol Information Technology Co., Ltd. (北京自然符号信息技术有限公司)\n- **Registered address**: Room 103-2617, 1st Floor, Building 21, Area 2, Tianzhong Yuan, Dongxiaokou Town, Changping District, Beijing\n- **Unified Social Credit Code**: 91110114MAKFN7JW4Q\n- **Legal representative**: Li Chaoyang (李超阳)\n- **Company nature**: Limited liability company (sole proprietorship by a natural person)\n- **Legal representative \u002F Person in charge of privacy protection**: Li Chaoyang, privacy@miyunote.cn",1786328451526]