SAUNA CONTROLLER

Privacy Policy

For Android and iOS

Product: Sauna Controller (Android and iOS)

Operator: 无锡朗特电子科技有限公司 (Wuxi Langte Electronic Technology Co., Ltd.)

Effective date: August 4, 2026

Contents

Contents

  1. 1. Scope and Core Principles
  2. 2. Personal Information We Process
  3. 2.1 Account Registration, Sign-In, and Profile
  4. 2.2 Device Binding, Management, and Sharing
  5. 2.3 Bluetooth and Nearby Devices
  6. 2.4 Wi-Fi Provisioning, Local Network, and Network Information
  7. 2.5 Camera, Photos / Media, and QR-Code Recognition
  8. 2.6 Device Controls, Timers, and Usage Records
  9. 2.7 Logs, Diagnostics, and Security Data
  10. 2.8 Support, Complaints, and Rights Requests
  11. 2.9 Processing Without Consent Where Permitted
  12. 3. System Permissions
  13. 4. Sensitive Personal Information and Enhanced Protection
  14. 5. Local Storage and On-Device Processing
  15. 6. Third-Party SDKs and External Services
  16. 7. Processors, Disclosures, Transfers, and Publication
  17. 7.1 Service Providers
  18. 7.2 Sharing You Initiate
  19. 7.3 Other Disclosures, Business Transfers, and Publication
  20. 8. Storage Location and Retention
  21. 9. International Transfers
  22. 10. How We Protect Personal Information
  23. 11. Your Privacy Rights
  24. 12. Children and Minors
  25. 13. Policy Updates and Notices
  26. 14. Contact Us
  27. 15. Effective Date and Languages

无锡朗特电子科技有限公司 (Wuxi Langte Electronic Technology Co., Ltd.) ("we," "us," or "our") values your privacy and the security of your personal information. This Policy explains how we collect, use, store, disclose, and protect personal information when you use the Android or iOS version of Sauna Controller, compatible smart sauna equipment, and related services, and how you may exercise your rights.

Please read this Policy before registering, signing in, or using the service. You may refuse optional processing and continue to use features that do not depend on it. If information is necessary for a feature you request, refusing it may make that feature unavailable.

1. Scope and Core Principles

This Policy applies to the Android and iOS versions of Sauna Controller, including account services, device binding and sharing, Bluetooth and local-network control, Wi-Fi provisioning, QR-code recognition, sauna controls, timers, and related services. Separate policies may apply to companion hardware, websites, or future services.

We process personal information lawfully, fairly, transparently, and only for specified and necessary purposes. We seek to minimize collection and maintain safeguards appropriate to the risk.

2. Personal Information We Process

2.1 Account Registration, Sign-In, and Profile

Information: Username, password, user ID, authentication tokens, and optional phone number and email address.

Purpose: Create and manage accounts, authenticate users, reset passwords, display profile information, maintain sessions, and protect account security.

Necessity: A username and password are generally required for account features. Optional contact details may be omitted, although this may affect account recovery, notices, or support verification.

Processing location: Account and authentication information is sent to the business server. Session state, account identifiers, and necessary credentials may also be stored on your mobile device.

2.2 Device Binding, Management, and Sharing

Information: Sauna-device serial number (SN), device identifier or name, online status, bound account, owner or shared-user role, and binding or unbinding records.

Purpose: Identify and bind devices, prevent unauthorized control, share access between accounts, switch devices, remove shared users, and restore ownership.

Visibility: When an owner shares a device, authorized users may see its name, a serial-number suffix, online status, and the usernames or roles needed to manage sharing.

2.3 Bluetooth and Nearby Devices

Information: Bluetooth state, nearby device names and identifiers, signal strength, connection state, services and characteristics, and control or provisioning data exchanged with a selected sauna device.

Purpose: Discover, connect to, and control sauna equipment; deliver Wi-Fi provisioning parameters; and diagnose connection failures.

Effect of refusal: Device scanning, connection, binding, and Bluetooth provisioning will be unavailable. Features that do not rely on Bluetooth remain available.

2.4 Wi-Fi Provisioning, Local Network, and Network Information

Information: Wi-Fi network name (SSID), Wi-Fi password, nearby access-point information where permitted, network state, local-network addresses and messages, and MQTT connection parameters needed to configure the device.

Purpose: Provision a selected network to a sauna controller, connect the device to the internet or local network, communicate with it, test connectivity, and reconnect automatically.

Processing: During connection and provisioning, the connection data described above is stored locally in the app and is sent to the selected device over Bluetooth or the local network. To support automatic reconnection, the app retains the necessary connection records locally on the mobile device. These records remain only in the app sandbox and are deleted with the app data when the app is uninstalled.

Risk: A Wi-Fi password is a high-risk credential. Only provision networks you are authorized to use, and clear network configuration before transferring or selling hardware.

2.5 Camera, Photos / Media, and QR-Code Recognition

Information: Camera frames you actively capture, an image you actively select, and QR-code content decoded from that image, typically a device serial number.

Purpose: Scan a device QR code, read its serial number, and complete binding with less manual entry.

Processing: QR-code recognition occurs on the device. The business feature needs the decoded result rather than the full image. Images are not uploaded to the server. Google components may process diagnostics not directly tied to the Sauna account as described in Section 6.

2.6 Device Controls, Timers, and Usage Records

Information: Device online status, temperature, duration, power and timer settings, power level, lighting and color, negative ions, ozone disinfection, music selection, commands and responses, timestamps, and faults.

Purpose: Perform local or remote control, synchronize status, create or cancel cloud timers, display records or trends, troubleshoot faults, and prevent conflicting control by multiple users.

Processing location: Some commands remain between the app and hardware over Bluetooth or the local network. Account binding, online status, MQTT configuration, and cloud timers are processed through the business server or MQTT service.

2.7 Logs, Diagnostics, and Security Data

Information: IP address generated when accessing the server, app version, operating system and basic device information, network type and state, request time and result, errors, and performance diagnostics. Google Data Transport may process component operation, error, and performance diagnostics.

Purpose: Maintain security and reliability, detect abnormal access or misuse, diagnose compatibility issues or failures, and evaluate barcode-component performance.

Advertising and tracking: We do not use this information for personalized advertising or cross-app tracking.

2.8 Support, Complaints, and Rights Requests

Information: Contact details, account or device identifiers, issue description, communications, and the minimum evidence needed to verify identity and resolve a request.

Purpose: Respond to questions, troubleshoot faults, process account deletion and privacy-rights requests, and resolve disputes.

2.9 Processing Without Consent Where Permitted

Where applicable law permits, we may process personal information when necessary to enter into or perform a contract, comply with legal duties, respond to public emergencies, protect life or property in an emergency, or reasonably process information you have made public or that was otherwise lawfully disclosed. We continue to apply data-minimization and security requirements.

3. System Permissions

Permission names and authorization flows differ between Android and iOS and may vary by operating-system version. You may manage permissions in your mobile device settings. Turning off a permission stops future access through it but does not affect processing lawfully completed before withdrawal.

Permission Purpose Information If Refused
Bluetooth / Nearby Devices Discover and connect to sauna equipment; transfer control and provisioning information. Nearby-device names and identifiers, signal, connection state, and exchanged data. Scanning, connection, binding, and Bluetooth provisioning will be unavailable.
Camera Scan a device QR code and read its serial number in real time. Camera frames and the decoded QR result. Live scanning is unavailable; manual entry or a selected image may be used.
Photos / Media Read a QR-code image you actively select. The selected image and decoded result; unselected content is not read. QR recognition from the photo or media library is unavailable.
Location, only where required On some OS versions, support Bluetooth scanning, read the current Wi-Fi name, or recognize nearby networks. Permission state, SSID, and nearby-network information; not used for continuous location or route history. Some scanning or automatic network-name functions may be unavailable.
Local / Nearby Network Discover and communicate with a sauna controller on the same LAN. Local addresses, device responses, and control commands. Local control and provisioning tests may be unavailable.

4. Sensitive Personal Information and Enhanced Protection

Account passwords, authentication tokens, Wi-Fi passwords, and precise location in some circumstances may be sensitive or high-risk information. We process them only where necessary for a specific feature, use encrypted storage, least privilege, access controls, limited retention, and segregation, and obtain separate consent where required by law.

5. Local Storage and On-Device Processing

To improve availability, the app may store session state, authentication tokens, account identifiers, the last connected device serial number, device history, and preferences on an Android or iOS device. To support automatic reconnection, the app also stores the necessary connection records locally on the mobile device. These records remain only in the app sandbox and are deleted with the app data when the app is uninstalled.

You may manage some local information through clear-record, unbind, and sign-out functions. Uninstalling generally removes app-sandbox data but does not automatically delete information already synchronized to a server, hardware device, or third-party service. Contact us under Section 14 for complete deletion.

6. Third-Party SDKs and External Services

To provide barcode scanning, the applicable platform may use Google ML Kit Barcode Scanning and related components to recognize QR codes on the device and, under Google's rules, process necessary app, device, and diagnostic information. To provide accounts, device binding, remote control, and timers, we may also use cloud hosting and MQTT messaging services. We permit each provider to process information only as necessary for the stated service; where required by applicable law, we identify the actual provider, information categories, and its privacy policy in this Policy, an in-app notice, or a separately published third-party information-sharing list.

7. Processors, Disclosures, Transfers, and Publication

7.1 Service Providers

We may engage cloud hosting, messaging, support, operations, and security providers to process necessary information. Contracts specify purpose, duration, method, data categories, safeguards, and each party's duties, and we supervise their processing.

7.2 Sharing You Initiate

7.3 Other Disclosures, Business Transfers, and Publication

Except with required consent, to comply with law, to protect significant lawful interests, or as otherwise permitted, we do not provide personal information to another controller. If a merger, reorganization, acquisition, asset transfer, or insolvency transfers personal information, we will identify the recipient and require continued protection. We do not publicly disclose personal information unless legally permitted and appropriately authorized, and we do not sell personal information.

8. Storage Location and Retention

We retain personal information only for the shortest period necessary for the purposes described here. Account information is generally retained until account deletion; device binding, sharing, and timer data until unbinding, revocation, or deletion of the relevant record; and session state, device configuration, and preferences on a mobile device until you clear them, sign out, or uninstall the app. After the applicable period, we delete or anonymize the information unless law requires longer retention. Server-side information is stored in Hong Kong, China. Specific retention periods and log-retention rules must be consistent with the production database and operations configuration.

9. International Transfers

Server-side information is stored in Hong Kong, China. Depending on where you use the service, this may constitute an international or cross-border transfer of personal information. Google components may also involve overseas diagnostic processing. Where a cross-border transfer occurs, we provide legally required information about the overseas recipient, purposes, methods, categories, retention, and rights channel; complete applicable assessments, certifications, or contractual safeguards; and obtain separate consent where required.

10. How We Protect Personal Information

We implement technical and organizational safeguards appropriate to the type, purpose, method, and risk of processing, including classification, least privilege, access control, authentication, audit logs, backup and recovery, workforce training, vendor management, and incident response.

Use the service only on trusted networks and devices, and do not disclose account, Wi-Fi, or sharing credentials.

If personal information is or may be compromised, altered, or lost, we will take corrective action and make legally required regulatory and user notifications describing the event, likely impact, response, risk-reduction steps, and contact channel.

11. Your Privacy Rights

Subject to applicable law, you may be entitled to be informed, decide, restrict or refuse processing, access, copy, correct, complete, delete, withdraw consent, close your account, request an explanation, and, where statutory conditions are met, request transfer of personal information.

Right How to Exercise It
Manage permissions In Android or iOS device settings, find Sauna Controller and turn off Bluetooth or Nearby Devices, Camera, Photos or Media, Location, or Local Network permissions.
Clear local records Use the available clear function on the relevant page, or uninstall the app to remove app-sandbox data.
Unbind or revoke sharing Use device settings or the shared-user page. Unbinding a device does not close the account.
Correct profile Edit available fields under Settings > Profile, or contact us under Section 14.
Close account and delete cloud data Use the in-app account-deletion path, if provided, or submit a request under Section 14. We verify identity and process it within the required or promised period.
Withdraw consent Turn off permission, stop the feature, or contact us. Withdrawal does not affect the lawfulness of earlier processing.

We may request information necessary to verify identity and protect account or device security. We aim to respond within 15 business days unless applicable law requires another period. We may refuse requests that are repetitive, manifestly unreasonable, affect others' lawful rights, or are exempt under law, and will explain the reason where required.

12. Children and Minors

The service is intended for users with legal capacity to operate smart sauna equipment and is not directed primarily to children under 14. Minors should use it only with guardian consent and supervision. We do not knowingly collect personal information from a child under 14 without guardian consent. If we learn that we have done so, we will delete it or take another lawful measure. Guardians may contact us under Section 14.

13. Policy Updates and Notices

We may update this Policy when features, processing, third-party components, or law changes. Material changes include significant changes to purpose, method, categories, recipients, international transfers, rights, or risk. We will provide notice through an in-app dialog, prominent page, message notice, or another reasonable method and obtain renewed consent where required.

14. Contact Us

Personal information controller: 无锡朗特电子科技有限公司 (Wuxi Langte Electronic Technology Co., Ltd.)

Registered / principal business address: Dize Bridge, Ehu Village, Ehu Town, Xishan District, Wuxi, Jiangsu, China (中国江苏无锡锡山区鹅湖镇鹅湖村荻泽桥)

Privacy contact or officer: zhuhongjie

Email: wuxisaunapro@saunaprem.com

Telephone: +8619906246189

After verifying identity, we respond as soon as practical and generally within 15 business days. If you are dissatisfied, you may complain to a competent privacy, cybersecurity, consumer-protection, or other authority, or pursue available legal remedies.

15. Effective Date and Languages

This Policy takes effect on August 4, 2026. If it is offered in more than one language and the versions differ, the English version prevails, without reducing rights granted by applicable law.