Privacy Policy
Last updated: August 18, 2026 (Version 2.3)
This Privacy Policy explains what personal information we collect when you use Pocket Expert AI at agentsdance.ai(the “Service”), how we use and share it, how long we keep it, and the rights you have over it. It forms part of our Terms of Service.
1. Who We Are (Data Controller)
- Controller: Beijing AgentsDance AI Technology Co., Ltd. (北京跃迁效应人工智能科技有限公司), trading as Pocket Expert AI.
- Registered address: Room 01-1922, 1/F, Building 15, East Zone, Courtyard 10, Xibeiwang East Road, Haidian District, Beijing, China
- Unified Social Credit Code: 91110108MAKL3PHR6X
- Privacy contact: [email protected]
- General support: [email protected]
- Privacy owner: Privacy requests are handled by the company through the contact address above.
2. Information We Collect
2.1 Information you provide
- Account identifier — depending on how you sign in: a username, an email address, a mobile number, or an identifier issued by WeChat or Google. We do not receive your password from these providers.
- Password — only if you use password sign-in. Stored as a salted scrypt hash; we never store or can recover your plaintext password.
- Display name — if provided by you, or a nickname returned by Google or WeChat sign-in.
- Payment records — order ID, plan, billing cycle, amount, currency, status, and timestamps. We never receive or store your card number, expiry, or CVV; those are collected directly by our payment processor (Section 5).
- Your content — the goals you give an agent, files you attach, datasets you upload, prompts, and the outputs generated for you.
- Third-party account data — only if you connect an account (e.g. Gmail, Google Drive, Calendar, GitHub, Microsoft). See Section 5.3 for exactly what we read.
- Correspondence — the content of support emails you send us.
2.2 Information collected automatically
- Network and request data — IP address, request path, HTTP status, timestamps, and error traces, recorded in operational logs.
- Approximate country — derived from your IP by our CDN, used only to choose the site language.
- IP address and IP location for community posts — when you publish a post or comment in Expert Circle, we record the client IP address and derive an IP location at province level (inside mainland China) or country level (elsewhere). The location is shown publicly next to your post, as required of account information pages in mainland China; the raw IP address is never shown to other users and is retained only as an operational record.
- Usage records — which features you used and the resulting consumption of your plan allowance, so we can show your usage and enforce plan limits.
- Rate-limiting counters — your IP is held in server memory in a short sliding window to block brute-force and abuse. These counters are never written to disk and are cleared when the service restarts.
We do not collect precise location, contacts, biometric data, or device identifiers beyond what is described above, and we do not perform advertising profiling.
3. How We Use Information & Legal Bases
| Purpose | Legal basis |
|---|---|
| Providing the Service — running agent tasks, search, recommendations, model training | Performance of a contract |
| Billing, orders, refunds, and fraud prevention on payments | Performance of a contract |
| Customer support and responding to your requests | Contract / legitimate interest |
| Service notices — receipts, security alerts, changes to the Service | Legitimate interest |
| Security, abuse prevention, rate limiting, and debugging | Legitimate interest |
| Content moderation — screening generation prompts, reviewing flagged or reported content, and enforcing our Acceptable Use Policy | Legitimate interest / legal obligation |
| Meeting tax, accounting, and other legal obligations | Legal obligation |
| Connecting a third-party account and reading data from it | Your consent (withdrawable at any time) |
We do not use your Input or Output to train our own foundation models without your explicit, separate consent. We do not send marketing email — see Section 9.
4. Cookies & Local Storage
We use no analytics, advertising, or tracking cookies, and we have not installed any third-party analytics or advertising SDK. The cookies we set are:
| Name | Purpose | Lifetime | Can you disable it? |
|---|---|---|---|
agentsdance_session | Keeps you signed in (strictly necessary) | 7 days | No — sign-in will not work |
ad_oauth_nonce | Protects third-party sign-in against CSRF (strictly necessary) | 10 minutes | No |
ad_oauth_next | Returns you to the right page after sign-in (functional) | 10 minutes | No |
site_lang | Remembers your language choice (functional) | 1 year | Yes — clear it in your browser |
The first three are httpOnly and are not readable by scripts. We also use browser local storage for interface preferences (sidebar state, workspace layout) and, in our mini program, to hold your sign-in token; these contain no tracking identifiers. Our content delivery network may set its own strictly necessary cookies to route and protect traffic.
5. How We Share Information
We do not sell your personal information, and we do not share it for advertising. We share it only in the situations below.
5.1 Payment processing
Payments are processed by Waffo Pancake, which acts as the merchant of record. When you check out we pass the order reference, plan, amount, and — if your account identifier is an email address — that email address, so a receipt can be sent. Waffo Pancake collects your card details directly on its own checkout, is PCI-DSS compliant, and card data is never transmitted to or stored on our servers.
If you purchase inside our iOS or Android app, the transaction is handled entirely by the Apple App Store or Google Play. They are the merchant, they collect the payment, and they apply their own privacy policies to the payment data. We receive only a signed transaction receipt containing the product identifier, transaction identifiers, purchase timestamp and environment — no name, no email, no payment instrument, and no App Store account identity. We link that receipt to your Pocket Expert AI account solely to deliver what you bought.
5.2 AI model providers
To carry out your requests, your Input and the context assembled for a task are sent through our model-routing gatewayto the model providers — currently including OpenAI, Anthropic, Google, DeepSeek, Alibaba Cloud (Qwen), Moonshot AI (Kimi), and BAAI — alongside models we host ourselves. If you configure private model credentials, those requests go to the provider you chose and are governed by that provider’s terms. These providers receive task content through API interfaces solely to generate the response to your task; we do not permit them to use it for advertising and we never sell it. We share task content only with providers whose API data-processing commitments provide protection equivalent to this policy, and the same requirement applies to any provider we add in the future.
5.3 Data from accounts you connect
If you connect a third-party account, we read only what the task requires, and that content becomes part of the context sent to the AI model providers described above. In particular this can include the body text of your emails (up to about 4,000 characters per message), the contents of documents and spreadsheets you ask us to open (up to about 6,000 characters), calendar events, and repository data. Do not connect an account whose contents you are not permitted to share with those providers. Access tokens are encrypted at rest and you can disconnect at any time (Section 8).
5.4 Web search
When a task searches the web, we run our own search front end, but it is a meta-search proxy: your search query is forwarded to third-party search engines and reference sources — such as general web search engines and encyclopedic sources — to obtain results. The specific providers may change over time as we tune result quality. We forward only the query itself, together with a language preference; we do not pass your account identifier, IP address, or any other identifier to them.
5.5 Communication providers
We use a third-party SMS provider to deliver login codes to mobile numbers, and a third-party email delivery provider to send login codes, receipts, and service notices. They receive only the destination address and the message content.
5.6 Legal, safety, and business transfers
We may disclose information where required by law or valid legal process, to enforce our Terms of Service, or to protect the rights, safety, and property of our users or ourselves. If the Service is involved in a merger, acquisition, or sale of assets, we will give notice before your information becomes subject to a different privacy policy.
6. Data Security
- In transit — all public traffic uses HTTPS/TLS.
- Passwords — stored only as salted scrypt hashes; never recoverable.
- Credentials — connector OAuth tokens are encrypted at rest and are refused rather than stored unprotected if encryption is unavailable. Model API keys you configure are also encrypted at rest; treat any key as sensitive.
- Isolation — every query is scoped to your tenant, and cross-tenant access is refused.
- Code execution — code produced by an agent runs in a locked-down sandbox with networking disabled, a read-only filesystem, no host mounts, an unprivileged user, and enforced memory, CPU, process, and time limits.
- Backups — encrypted with AES-256 before leaving the server.
One thing you should know: API keys you create for our own API are stored in a readable form so that you can view and copy them again from your settings page. Treat them as passwords, and revoke any key you no longer need.
No system is perfectly secure. If a breach affects your personal information, we will notify affected users and, where required, the competent regulator within 72 hours of becoming aware of it.
7. How Long We Keep Data
| Data | Retention | What happens at the end |
|---|---|---|
| Account record and sign-in identifiers | Until you delete your account | Deleted immediately on deletion |
| Tasks, outputs, and uploaded content | Until you delete them, or until account deletion | Purged within 30 days of account deletion |
| Connector authorisations (OAuth tokens) | Until you disconnect, or until account deletion | Deleted |
| Login codes (SMS / email) | 5 minutes | Expire; held in memory only |
| Rate-limiting counters (IP) | Up to 24 hours, in memory only | Discarded; cleared on restart |
| Operational logs (debugging) | Rotated automatically, capped at roughly 150 MB per service, and reset whenever a service is redeployed | Oldest entries overwritten |
| Operational records of community actions (account, time, action, source IP) | 210 days, meeting the six-month minimum required by PRC network law | Deleted automatically |
| Encrypted backups | 14 days | Deleted automatically |
| Community posts and comments (Expert Circle) | At least 6 months from publication, as required by PRC network law | Gone from every user-facing view the moment you delete them; the record itself stays in non-public storage |
| Payment and transaction records | At least 5 years after the transaction | Retained as required by tax and accounting law |
Three limits you should be aware of. First, because backups are kept for 14 days, data you delete may persist in an encrypted backup for up to 14 days after deletion. Second, if your account belongs to a team that still has other members, deleting your account removes your login and identifiers, but tasks and outputs created in that shared workspace remain available to the remaining members. Third, community posts and comments carry a statutory retention period: deleting one removes it from the timeline for everyone, including you, but we keep the record in non-public storage so that we can act on reports and disputes and answer lawful requests. It is never shown publicly again.
8. Your Rights
Subject to your local law, you have the right to:
- Know — what we collect and why (this policy).
- Access — obtain confirmation and a copy of your personal information.
- Correct — have inaccurate information rectified.
- Erase — have your personal information deleted.
- Restrict — ask us to limit processing while a request is resolved.
- Data portability — receive your information in a machine-readable format.
- Object — object to processing based on legitimate interest.
- Withdraw consent — at any time, without affecting processing already carried out.
How to exercise them:
- Delete your account — immediately, yourself, at Settings → Account → Delete account. This is irreversible.
- Withdraw consent — immediately, yourself: disconnect a connector, unbind a third-party sign-in, or revoke an API key in Settings.
- All other requests (access, correction, portability, restriction, objection) — email [email protected] from the address on your account. We respond within 30 calendar days. These requests are handled manually; there is currently no self-service export tool.
Exercising these rights is free and will not degrade your service. If you believe we have handled your information improperly, you may lodge a complaint with your local data protection authority.
9. Marketing
We do not send marketing or promotional email. The only messages we send are essential to the Service: login verification codes, payment receipts, security alerts, and notices about changes to the Service or these policies. Because these are required to operate your account, they cannot be unsubscribed from while your account is open. If we ever introduce marketing messages, we will ask for your explicit consent first and provide a one-click unsubscribe.
10. International Data Transfers
Our servers are deployed in accordance with the laws and regulations of the jurisdictions in which they are located.
Where required by law, we apply appropriate safeguards to the storage and transfer of data, including data-protection terms in our contracts with each processor, encryption in transit, and limiting each provider to the data it needs to perform its function.
11. Children
The Service is not directed to anyone under 18. By using it you represent that you are at least 18 years old. We do not knowingly collect personal information from anyone under 18, and we do not operate any age-verification mechanism, so we rely on that representation. If you believe a minor has provided us with personal information, contact [email protected] and we will delete the account and its data promptly.
12. Third-Party Links
The Service may link to, or open, websites we do not control — including results returned by web search and pages an agent visits on your behalf. This policy covers only information we collect ourselves. We are not responsible for the privacy practices of third-party sites, and we encourage you to read their policies.
13. Changes to This Policy
We may update this policy. For material changes we will post the updated version here with a new effective date and give at least 15 days’ advance notice by email or in-product notice before it takes effect. Continued use after the effective date constitutes acceptance. The current effective date is shown at the top of this page.
14. Contact Us
- Controller: Beijing AgentsDance AI Technology Co., Ltd. (北京跃迁效应人工智能科技有限公司), trading as Pocket Expert AI
- Registered address: Room 01-1922, 1/F, Building 15, East Zone, Courtyard 10, Xibeiwang East Road, Haidian District, Beijing, China
- Unified Social Credit Code: 91110108MAKL3PHR6X
- Privacy and data requests: [email protected]
- General support and billing: [email protected]
- Security reports: [email protected]
- Response time: privacy requests within 30 calendar days; billing enquiries within 2 business days