SayPilot
Home
AI reply suggestionsConversation memoryMultilingual repliesBring your own model
All use casesDating app repliesReply to friendsWorkplace repliesMultilingual chat repliesGroup chat replies
Help centerPermissions helpContact usPrivacyTermsData deletion
Get SayPilot on Google Play
EN 中文

SayPilot

SayPilot Privacy Policy

SayPilot (the "App" or "SayPilot") is operated by Wuhan Huiyu Lingxi Technology Co., Ltd. (武汉市慧语灵犀科技有限责任公司) ("we", "us", or "our"). We care about protecting your personal information and the privacy of your conversations. This Privacy Policy explains how we collect, use, store, share, transfer, disclose, delete, and protect information when we provide the SayPilot Android app, SayPilot cloud services, the management center, floating assistant, screenshot recognition, cloud reply generation, account, quota, and feedback features. It also explains how you can manage your information and permissions.

Last updated: August 31, 2026

1. Scope

This Policy applies to the SayPilot Android app and the cloud generation, account sign-in, quota/entitlement, update check, feedback, and support services we provide for it.

Third-party chat apps such as WeChat, WeCom, WhatsApp, WhatsApp Business, and Messenger are provided by their respective operators. Your accounts, chat history, contacts, payments, notifications, and platform risk controls in those third-party chat apps are handled by those third parties and are not governed by this Policy. SayPilot is not an official product of those chat apps and does not represent them or their operators.

If you use SayPilot to open a third-party website, app store, Google sign-in, Passkey, payment service, email/SMS verification service, or other third-party service, that service may be governed by its own privacy policy and terms.

2. Information We Collect and Use

We follow the principles of lawfulness, fairness, necessity, and good faith. We process information only as needed to provide product features, perform our contract with you, protect security, respond to your requests, or comply with applicable laws and regulations. Unless the law allows otherwise or the information is necessary for a core feature, you may refuse to provide certain information or disable permissions, but the related feature may not work.

2.1 Chat Recognition and Reply Assistance

SayPilot is a user-triggered chat reply assistant. When you tap the floating assistant, generate reply suggestions, view draft suggestions, or ask SayPilot to review earlier context on a supported chat conversation screen, we may process:

  • Currently visible chat text, conversation title, group title, message direction, sender display name, message-type placeholders, and timing or ordering cues.
  • Input draft text, reply style, reply intent, banned words, relationship labels you enter for the other person and yourself, group reply targets, and whether an @ mention is needed.
  • UI node text, control positions, page state, and basic screen structure, used to decide whether the current page is a supported chat conversation.
  • Additional visible messages if you actively trigger history backfill or ask SayPilot to review more context. In that case, the App may briefly scroll the current chat page.

We use this information to understand the current conversation, generate candidate replies, evaluate whether a draft is appropriate, provide conversation summaries, help infer relationship or identity context, improve candidate ranking, and reduce repeated setup.

SayPilot does not send chat messages for you, does not tap a third-party chat app's send button, and does not write generated content into a third-party chat input box on its own.

SayPilot does not obtain chat records by reading third-party chat app databases, private directories, encryption keys, non-public interfaces, hooks, injection, cracking, or protocol emulation. It does not bulk export, sell, or collect chat records for purposes unrelated to reply suggestions.

2.2 Cloud Generation and AI Processing

When you use cloud generation, SayPilot sends the minimum context needed for reply generation to the SayPilot cloud service at https://www.getsaypilot.com over HTTPS. This may include:

  • Request ID, request time, app version, request status, context source, and necessary model request metadata.
  • Currently visible chat messages, conversation title, input draft, reply settings, group reply target, and local conversation or contact profile summaries you allow for the request.
  • Screenshots or screenshot recognition results you allow for that request.
  • Generated results, including candidate replies, draft evaluation, conversation summaries, model suggestions, relationship/identity hints, and profile review results.

Before a reply-generation request is sent, SayPilot shows a Pre-send Check that summarizes the selected chat context and reply settings. You can review the selected transcript, confirm generation, or cancel. The confirmation applies only to the current request; it does not enable background chat collection or automatic message sending.

Before building a cloud generation request, SayPilot locally redacts structured text where possible. The redaction replaces high-risk items such as phone numbers, email addresses, verification codes, passwords or passphrases, government ID numbers, passport numbers, bank card numbers, API keys or tokens, payment or transfer account identifiers, and precise address fragments. Redaction does not hide ordinary nicknames, names, relationship terms, or regular chat meaning by default, and it does not change the backend request schema.

The SayPilot backend may call AI model providers enabled in the current cloud routing configuration, or other necessary service providers, to generate reply suggestions, draft evaluations, conversation summaries, and profile review results. Specific provider names, purposes, data types, and regions are described in Appendix 3 of this Policy and the public website version. Model provider secrets should not be embedded in the client app package.

Please note that redaction is not the same as anonymization, and it may not detect or replace every sensitive item. We recommend that you do not intentionally submit passwords, payment verification codes, government ID numbers, bank card numbers, precise locations, contact lists, medical records, children's sensitive information, trade secrets, or other sensitive information unrelated to reply suggestions in chats, drafts, screenshots, or feedback. If you submit another person's personal information, you must make sure you have a lawful basis or authorization to do so.

2.3 Screenshot Recognition and OCR

When you actively trigger screenshot recognition, screenshot fallback, or manual screenshot mode and approve the Android system prompt, SayPilot may process the current screenshot, OCR result, screenshot area, screenshot time, and recognition status. A screenshot may include visible chat content, draft text, or other information shown on the screen.

Screenshot recognition is mainly used when the accessibility service is unavailable, disconnected, or unable to reliably read the current chat page. SayPilot does not continuously record the screen in the background. You may refuse screen capture permission; if you do, accessibility-based text recognition and existing local context may still be available.

If you choose cloud generation and allow screenshots to be included, the original screenshot or screenshot data may be sent to SayPilot cloud services and model providers for the current request, so they can understand the chat content and generate reply suggestions.

The first version does not blur or mask the screenshot image itself. The original screenshot may be used for the current cloud screenshot recognition or multimodal understanding request. Chat text, OCR output, or structured screenshot results returned from cloud recognition are locally redacted where possible before they are used for generation, long-term local memory, or feedback diagnostic export.

2.4 Local Settings, Conversation Memory, and Contact Profiles

To reduce repeated setup and make suggestions more relevant, SayPilot may store the following information on your device:

  • Global reply preferences and default switches, plus long-term relationship, reply style, reply language, banned-word, and memory settings for eligible named direct conversations.
  • Contact notes, the other person's identity, your identity, conversation summaries, and recent chat summaries for eligible named direct conversations.
  • Long-term profile signals, preferences and taboos, interaction profiles, profile evidence, update time, confidence, and similar local profile information for eligible named direct conversations.
  • On-device generation history created after you actively trigger generation, including candidate replies from direct or group chats and related context needed to display and review that result.
  • Records showing that you acknowledged prominent permission disclosures, screenshot permission disclosures, app cache, temporary screenshot previews, and feedback export caches.

Before conversation memory, AI reply history, profile summaries, profile evidence, draft previews, and conversation previews are saved, the client locally redacts high-risk sensitive fragments where possible.

Reply intent, group reply targets, group reply scope, and whether an @ mention is needed are used only for the current runtime state or generation request. They are not stored as long-term group conversation memory or group contact profiles. Group chats do not create long-term conversation memory or contact profiles. However, group-chat candidate replies and the related context needed to review that result may be stored as separate on-device generation history until you clear local assistant data, newer history replaces the record, or you clear app data or uninstall the App. Generation history is not used as a long-term group profile.

This information is mainly stored in the App's private directory, SharedPreferences, database, or cache. You can clear local assistant data from "Management Center - Help and Feedback - Privacy and Local Data". After clearing, local profiles, conversation memory, default settings, permission confirmation records, and temporary caches will be reset.

Clearing local data does not automatically delete records that have already been sent to the cloud backend, model providers, or feedback handling systems.

2.5 Accounts, Sign-In, and Entitlements

Some cloud generation, quota sync, entitlement records, purchase records, feedback tracking, or cross-device features may require an account. Depending on server-side configuration, SayPilot may support email verification codes, phone verification codes, Google sign-in, Passkeys, or other sign-in methods. The methods actually available are those shown in the App.

When you use account features, we may process account ID, email address, phone number, verification-code request and verification status, necessary identifiers returned by Google sign-in, Passkey registration or sign-in challenges and verification results, login tokens, session status, account creation and login time, registration and sign-in IP addresses, authentication method, entitlement quota, subscription status, and risk-control status.

When an account is first created and during later sign-in or authentication requests, the server may record the public egress IP address it observes and associate the registration IP or recent sign-in IP with the account. We use this information to detect unusual registrations or sign-ins, prevent abuse, protect account security, and perform necessary security audits. The address may be affected by carrier networks, shared networks, VPNs, or proxies and does not represent a precise physical location.

We do not ask you to provide bank card passwords, payment verification codes, or third-party account passwords inside the SayPilot client. Please protect your email, phone number, Google account, Passkey, device unlock method, and other credentials.

2.6 Payments, Memberships, and Purchases

As of the last updated date of this Policy, the public SayPilot Android release offers one or more one-time credit packs and auto-renewing subscriptions through Google Play Billing. Each one-time pack grants the number of credits displayed in the App after successful verification and does not renew automatically. Subscriptions have weekly, monthly, and annual base plans: the weekly plan provides 200 credits each week, and eligible Google Play users may receive a three-day free trial that automatically converts to weekly billing; the monthly plan provides 300 credits each month; and the annual plan is charged yearly and provides 300 credits each month while active. The products actually offered, credit amounts, prices, currency, taxes, free-trial eligibility, and trial-to-paid conversion time are those displayed in the App and Google Play checkout. External payment methods and simulated or test payment features are not offered to ordinary release users.

When you buy, subscribe, restore, receive a refund, cancel, or otherwise manage a Google Play product, we may process product ID and type, base plan ID, offer or trial information, order number, purchase token, payment and acknowledgement status, subscription and auto-renewal status, current billing-period end time, credit amount, refund status, voided-purchase status, restoration result, and payment verification result. We use this information to verify purchases, grant and refresh entitlements, restore purchases, manage the subscription lifecycle, process refunds, and prevent abuse. Sensitive payment credentials such as payment card numbers are normally handled directly by Google Play and are not collected directly inside the SayPilot client.

You can manage or cancel a subscription through an in-app link or the Google Play subscription management page. After cancellation, subscription benefits generally remain available until the end of the current paid or started billing period. Uninstalling the App or deleting your SayPilot account does not automatically cancel a Google Play subscription. Refund eligibility and outcomes are determined under the applicable Google Play refund policy.

2.7 Feedback, Support, and Diagnostics

When you submit feedback, export diagnostic files, attach screenshots, or contact us, we may process the issue description, contact details, device model, system version, app version, permission status, request status, error logs, request IDs, conversation summaries, screenshots, diagnostic files, and communication records you provide.

We use this information to investigate issues, respond to you, improve the product, handle complaints, verify account or data deletion requests, and maintain service security. You may choose not to submit feedback materials, but this may limit our ability to diagnose or resolve the issue.

When you export a feedback diagnostic package or copy diagnostic information, chat text in recognition details, request log summaries, and user notes is locally redacted where possible. Contact details you actively enter are kept so we can reach you. If you choose to attach a recent screenshot, the original screenshot may still contain unredacted screen content; please review it before submission.

2.8 Device, App, and Security Logs

To keep the software and services running securely, troubleshoot issues, measure service quality, and prevent abuse, we may process app version, system version, device model, network request status, cloud API status, crash information, error logs, request latency, request success or failure status, IP address, account login status, quota usage status, and necessary security or risk-control information.

If the first-run rating prompt is configured with a country allowlist, the SayPilot backend may use the public egress IP address observed for the capabilities request to obtain an approximate country code from the configured IP-geolocation service. We use that result only to decide whether to show the first-run rating prompt in that country. This does not use GPS or precise device location, does not require an Android location permission, and does not return the IP address or resolved country to the App. The configured geolocation provider may receive the public IP address. Successful lookups may be cached in backend memory for up to six hours, while failed lookups may be cached for up to five minutes; if the country cannot be resolved, the first-run rating prompt is not shown.

Cloud requests may also carry a randomly generated installation client identifier, a one-way hash of Android ID, and a device fingerprint derived from that hash. The raw Android ID is not sent. These pseudonymous identifiers are used to bind login-verification requests, provide anonymous trials, detect multiple accounts or repeated claims on the same device, perform security and abuse prevention, associate necessary diagnostics, and measure product usage. They may be associated with a SayPilot account after sign-in.

SayPilot does not read contacts, SMS, call logs, precise location, photo library files, passwords, payment verification codes, or content unrelated to reply suggestions for the purpose of generating replies.

SayPilot also does not read third-party chat app local databases, private directories, encryption keys, or non-public interfaces for reply suggestions, and does not use hooks, injection, cracking, or protocol emulation to bypass the normal permission and security boundaries of third-party apps.

2.9 Product Analytics, Advertising Measurement, and Pseudonymous Identifiers

When the configured SayPilot cloud service is available, the Android App automatically reports a limited set of product analytics events. These include first open and app launch events; permission guide, settings-opened, permission-granted, and required-permissions-ready events; and Google Play purchase and subscription funnel events such as paywall views, product/base-plan/offer and price availability, product selection, purchase clicks, purchase-sheet opening, cancellation, errors, trial or subscription status, and verification status. This reporting happens when the App starts or when you use the relevant permission or purchase flow; it does not require a separate submission action for every event.

If you install the App through a source-tagged SayPilot website or Google Play link, the App may use Google Play Install Referrer once during its first run to read allowlisted installation-source information. This may include the source platform (for example, TikTok, YouTube, or the SayPilot website), medium, campaign and content short codes, a one-time random click identifier generated by SayPilot, and source-click and install-begin timestamps supplied by Google Play. This first-party acquisition feature itself does not read the advertising ID, store the complete raw Install Referrer string, or send in-app events back to source platforms such as TikTok or YouTube. The optional Google and Meta advertising-measurement paths described below are separate from that first-party attribution record.

Each event may contain the randomly generated installation client identifier described above, sent as anonymous_id, together with the event name, platform, app version and version code, functional channel or source, first-install source, and limited event metadata. Depending on the event, metadata may include permission type and readiness, source medium/campaign/content short codes, a one-time random click identifier, source-click and install-begin timestamps, product ID and type, base plan ID, credit amount, whether a price was available, Google Play response code, error class, or a shortened error message. The backend hashes the identifier again before storing the analytics event. The identifier is pseudonymous rather than anonymous because it remains stable in the App's private storage and is also used for some account-verification and security functions; while you are signed in, the login session may also associate the event with your SayPilot account ID.

We use these events to measure first opens, permission setup, reply generation, copying, and purchase funnels resulting from different source links; evaluate content promotion and acquisition channels, release quality, and service reliability; troubleshoot failures; and prevent abuse. First-party SayPilot analytics events are not intended to contain chat text, screenshots, contact names, advertising IDs, or precise location. We do not sell this information or use it to provide personalized advertising.

SayPilot also offers optional Firebase Analytics, Google Analytics 4 (GA4), and Google Ads measurement for a limited set of advertising conversions: first open, the first successful reply per installation, the first real paid subscription, subscription renewal, and completed purchases. The only custom business event the Android client actively sends to Firebase is first_reply_generated, at most once per installation. When supported, Firebase and Google Play automatically collect first_open, in_app_purchase, app_store_subscription_convert, and app_store_subscription_renew; the Firebase Analytics SDK may also collect its standard app-lifecycle and engagement events, such as session_start, user_engagement, app_update, and os_update. These SDK-defined lifecycle events are not additional SayPilot business-event mappings and should not be treated as the same business conversion. Permission, copy, ordinary reply, and checkout-funnel events remain in SayPilot's first-party product-analytics path and are not sent to Firebase. When enabled, Google may process a Firebase app-instance identifier; a device or advertising identifier where the device, system, and permission state allow it; app version and lifecycle or engagement state; that first-reply event; and product, price, currency, subscription, and purchase status automatically supplied through Google Play for analytics, advertising attribution, conversion measurement, and campaign optimization. Automatic Firebase screen-view reporting remains disabled. SayPilot does not put chat text, screenshots, contact or group-member names, drafts, reply content, prompts, SayPilot account identifiers, email addresses, phone numbers, stored user IP addresses or country codes, order numbers, raw purchase tokens, Android ID, device fingerprints, or raw error responses into these event parameters. Google may nevertheless process network-transport metadata, including the public IP address from which an SDK or server request connects, under its policies. Advertising personalization and remarketing signals remain disabled, and SayPilot does not display ads in the App.

After advertising measurement is allowed, the Android client may send the Firebase app-instance identifier to the SayPilot backend at low frequency; this installation-level binding does not require signing in to a SayPilot account first. The backend stores that binding in encrypted form solely to export Google Play purchase facts confirmed by backend verification to the same Firebase/GA4 app instance asynchronously. A fixed allowlist maps only paid_subscription_started (the first real paid subscription) and credit_pack_purchased (a credit-pack purchase). Only after the backend strictly matches the corresponding production Google Play order, verifies it as PROCESSED, and accepts its positive actual order total and currency may either event include that actual value and currency for conversion-value and return-on-ad-spend optimization; SayPilot does not substitute a catalog price, client display price, or backend default price. Value resolution and delivery run asynchronously in the backend and do not delay purchase verification, entitlement delivery, or App responses. The server-side event payload does not include your SayPilot account ID, email address, phone number, stored user IP address or country code, order number, purchase token, chat content, screenshot, reply content, or other personal information. The Measurement Protocol request necessarily exposes the SayPilot server's network egress IP to Google. Automatic Google Play/Firebase purchase events and these custom events may describe the same revenue, so they must not be added together or both treated as primary conversions for the same revenue goal. paid_subscription_renewed is not currently enabled; renewal measurement continues to rely on automatic events. The GA4 Measurement Protocol secret is held only on the backend and is unavailable to the client.

When the Meta destination is separately configured and ready, the same advertising-measurement setting may also enable Meta App Events through the Meta Core SDK. On the Android client, SayPilot limits this path to the SDK install ping and the installation-level first_reply_generated event; it does not manually log a Meta lifecycle-activation event. Meta automatic in-app-purchase logging, automatic App Events, codeless debugging, and SDK monitoring remain disabled. Advertiser-ID collection starts disabled and is enabled only after the updated Meta disclosure is effectively allowed and the backend Meta identity is registered, where the device and platform allow it; it is disabled again on withdrawal. Meta's event-and-data-use restriction remains enabled: SayPilot limits use to analytics and conversion measurement and does not use the data for targeting. The client does not report trial, subscription, or purchase events to Meta.

After Meta measurement is allowed, the Android client may send an installation-scoped Meta anonymous app-device GUID to the SayPilot backend at low frequency, without requiring a SayPilot account sign-in. This GUID is separate from the Firebase app-instance identifier and the first-party analytics identifier. The backend stores the GUID in encrypted form and uses an independent bounded outbox containing derived HMAC identifiers, an internal account cleanup/ownership key, allowlisted business semantics, and delivery state. The internal account key never enters Meta's HTTP payload, and the outbox contains no GUID, IP address, raw purchase token, order number, or chat content. It asynchronously maps only trusted Google Play facts to StartTrial for a verified production free-trial start, Subscribe for a verified first real paid subscription, and fb_mobile_purchase for a verified one-time credit-pack purchase. Google Play license-test purchases, one-time products carrying any non-cash purchase marker, and unknown trial/payment classifications are rejected rather than exported. StartTrial carries no monetary value. When the backend strictly matches a paid event to the exact production Google Play order, verifies that the order is PROCESSED, and accepts its positive order total, Subscribe or fb_mobile_purchase may include that actual order value and currency as Meta's _valueToSum and fb_currency parameters for conversion-value and return-on-ad-spend optimization; an unresolved or rejected order remains a count-only event. These Meta values must not be added to Google/Firebase purchase events when calculating SayPilot revenue. The Meta server access token is held only on the backend and is unavailable to the client.

The initial state of advertising measurement depends on the region where the App is used and applicable requirements. In regions where law, regulatory rules, or platform rules require prior consent, measurement remains off until you actively allow it. In other regions, measurement may be initially enabled for the purposes described in this Policy. In a consent-required or unknown region, a choice recorded by an older version whose disclosure named Google only is not valid for the expanded feature: the UI shows the switch off and both Google and Meta remain off until you make a choice under the updated disclosure. You can change the single setting at any time in "Management Center - Help and Feedback - Privacy and Local Data." Turning it off stops subsequent Firebase and Meta business-event logging, resets the local Firebase analytics state, disables the Meta measurement sink, requests deletion or tombstoning of the corresponding backend Firebase and Meta installation bindings, and cancels related server-side conversions that have not started delivery. Events occurring before consent or while measurement is off are not uploaded later. Data already transmitted to or accepted by Google or Meta, and work placed in a provider SDK's private in-memory queue before the switch changed, cannot be recalled by the switch and remains subject to the applicable provider retention, deletion, and conversion controls. SayPilot does not use Meta's lifecycle-tracking activation API; the disabled sink does not create subsequent SayPilot business or lifecycle events. Turning measurement off does not affect SayPilot's core reply features.

When the App first determines this regional initial state, it may request a coarse measurement-requirement classification from the SayPilot backend. The backend may evaluate the public IP address observed for that request. To reduce repeated external lookups, the bounded country resolver may keep an approximate country code in short-lived in-process memory, for about six hours by default, but does not persist that country code as a marketing event. The App receives only one of three states—consent-required region, other region, or unknown—not a specific IP address or country code. The IP address, country code, and three-state classification are not sent to Google or Meta as advertising-measurement event parameters. This is not continuous location or regional tracking. If the lookup fails, cannot make a determination, or returns unknown, measurement defaults to off.

2.10 Updates and Notifications

SayPilot may connect to cloud services to check the app version, update status, official update address, and forced update flags. Notification permission is used when needed to keep the floating assistant, screenshot recognition, or background tasks visibly running, or to show service-related notices.

You can disable notifications in system settings. If you do, some foreground service notices, error messages, or background task status notices may not appear.

2.11 Cases Where Separate Consent May Not Be Required

Where permitted by applicable law, we may process your personal information without separate additional consent in the following situations:

  • The processing is necessary to enter into or perform a contract with you.
  • The processing is necessary for us to perform legal duties or obligations.
  • The processing is necessary to respond to a public health emergency, or to protect an individual's life, health, or property in an emergency.
  • The processing is carried out within a reasonable scope for public-interest news reporting, public opinion supervision, or similar activities.
  • The processing concerns personal information you have made public yourself, or information that has otherwise been lawfully made public, within a reasonable scope.
  • Other situations provided by laws and regulations.

3. Cookies and Similar Technologies

The SayPilot Android app itself usually does not rely on browser cookies to provide its core chat assistance features.

If you visit the SayPilot website, data deletion page, account page, backend admin page, or another web service, we or our service providers may use cookies, LocalStorage, session tokens, or similar technologies for login sessions, security verification, request protection, preference storage, troubleshooting, and analytics. You can clear or restrict cookies through your browser settings, but some web features may be affected.

4. Service Providers, Transfers, and Public Disclosure

4.1 Service Provider Processing Principles

We do not sell your personal information. To provide SayPilot, we may provide necessary information to service providers that process data on our behalf, or allow those service providers to process necessary information, only as needed to provide the service, perform our contract, comply with law, maintain security, handle feedback, or protect users' legitimate rights and interests.

These service providers must process information according to our instructions, for the agreed purposes, within the minimum necessary scope, and with reasonable security measures. They may not use your information for their own advertising, profiling, independent commercial purposes, or purposes unrelated to providing SayPilot. Under the Google Play Data safety framework, transfers to service providers that process user data on behalf of the developer and based on the developer's instructions are generally not treated as "sharing" with third parties. If a provider processes data outside that service-provider role, we will update this Policy and the relevant app store disclosures as required.

4.2 Categories of Providers

To provide SayPilot, the following types of providers may access necessary information:

  • SayPilot cloud backend: generation requests, account login, quotas/entitlements, version updates, request status, logs, security risk control, and feedback handling.
  • AI model providers: candidate replies, draft evaluation, conversation summaries, profile review, and screenshot parsing.
  • Account verification services: Google sign-in, Passkeys, email verification codes, phone verification codes, and similar identity checks.
  • Google Play or payment providers: reading installation source written by a source-tagged link; Google Play credit-pack and auto-renewing subscription purchases; trial-eligibility decisions; renewals and cancellations; purchase restoration; refunds; voided-purchase handling; and order verification.
  • Google Firebase, Google Analytics, and Google Ads: based on the regional initial state and your later setting, for app analytics, advertising attribution, conversion measurement, and campaign optimization. This may include Firebase/Google Play automatic events, the client-side first-successful-reply event, and a limited set of purchase-semantic events asynchronously exported by the SayPilot backend from trusted Google Play verification facts while consent and the app-instance binding remain valid. Advertising personalization and remarketing signals remain disabled.
  • Meta Platforms, Meta App Events, and Meta Ads: after the current disclosure is effective for your region and the Meta destination is configured, for limited app-install, first-reply, trial, first-paid-subscription, and one-time-purchase conversion measurement and campaign optimization. Automatic in-app-purchase logging, automatic lifecycle activation, advertising personalization, and remarketing remain disabled in the App. Advertiser-ID collection starts disabled, may be enabled only after effective Meta permission and successful backend identity registration where the device and platform allow it, and is disabled again on withdrawal.
  • Cloud infrastructure, logging, monitoring, and security services: hosting, transmission, storage, troubleshooting, attack protection, and service reliability.
  • Feedback, support, or email services: issues, diagnostic materials, and contact details you submit.
  • Share targets you choose: if you send a feedback export file through the Android share sheet, the file is sent to the app or contact you select.

Specific service provider categories, processing purposes, data types, and contact information are described in Appendix 3 of this Policy and in the public website version.

4.3 Business Transfers

If personal information is transferred because of a merger, division, acquisition, asset transfer, bankruptcy, liquidation, or similar transaction, we will require the new holder to continue to follow this Policy. If the new holder changes the purposes or methods of processing, we will require it to obtain consent again as required by law.

4.4 Public Disclosure

We do not publicly disclose your personal information unless we have your separate consent, or disclosure is required by laws, courts, administrative authorities, regulators, security incident handling, or illegal-use handling.

5. How We Protect Your Information

We use reasonable technical and organizational measures to protect your information. These may include HTTPS/TLS transmission, access controls, key isolation, minimized processing, log access controls, server-side authentication, anomaly monitoring, backup and recovery, and internal permission management.

Local redaction is an additional measure to reduce the risk of sensitive information exposure. It does not mean that all sensitive information can be automatically detected or fully replaced.

Please understand that no internet service can guarantee absolute security. If a personal information security incident occurs, we will take remedial steps as required by applicable laws and regulations and notify you of the situation and suggested actions through in-app notices, announcements, email, or other reasonable methods.

6. Storage and Retention

Local data may be stored in the App's private directory, SharedPreferences, databases, or caches on your device. You can uninstall the App or clear local assistant data from "Management Center - Help and Feedback - Privacy and Local Data".

Cloud data may be stored on servers or cloud services in Singapore. If your information needs to be transferred to overseas servers or overseas model providers, we will provide notice and take necessary protections in accordance with applicable laws, regulations, and app store policies. The actual cross-border recipients, regions, and purposes are listed at https://www.getsaypilot.com/privacy/.

We retain personal information only for as long as necessary for the purposes described in this Policy. Backend request logs and model request logs are retained for 90 days. Raw registration IP addresses associated with accounts, and raw IP addresses in sign-in or authentication requests, are retained for 90 days by default. The service operator may configure the retention period for registration IP addresses and IP addresses in email or SMS verification-code records from 1 to 3,650 days. When that period expires, the raw IP address is cleared, while necessary non-IP account or security-audit metadata such as account creation time and authentication method may be retained for business or legal needs. Raw first-party product analytics events are a separate category and are automatically deleted when they are older than the configured analytics retention period. That period defaults to 400 days and can be configured by the service operator; the current implementation accepts a range of 1 to 3,650 days. The Firebase app-instance binding and Meta anonymous app-device GUID binding are encrypted on the SayPilot backend and retained only while the corresponding effective permission remains valid and low-frequency conversion export reasonably requires them. We delete or tombstone these bindings and cancel matching pending server-side conversions when you withdraw measurement permission or delete your account. Firebase Analytics, Google Analytics, Google Ads, Meta App Events, and Meta Ads data is subject to the retention, deletion, and advertising-conversion controls configured in the relevant provider consoles; we use a reasonable period needed for the stated purposes. Events already delivered to or accepted by a provider are not automatically recalled by deleting the SayPilot-side binding. Aggregated or de-identified statistics that no longer identify an account or installation may be retained longer. Feedback records, account records, order records, risk-control records, and information required by law are retained as needed for business purposes and legal requirements. After an applicable retention period expires, we delete or anonymize the information, unless laws or regulations require otherwise.

7. Your Choices and Rights

To the extent permitted by applicable law, you may request access to, a copy of, correction of, completion of, or deletion of your personal information; withdraw authorization; disable permissions; delete your account; or ask us to explain our processing rules.

You can manage information and permissions in the following ways:

  • Disable system permissions: disable SayPilot's accessibility service, display-over-other-apps permission, screen capture, notifications, background running, or other related permissions in Android system settings.
  • Clear local data: go to "Management Center - Help and Feedback - Privacy and Local Data" to clear locally stored profiles, conversation memory, generation history, default settings, permission confirmation records, screenshot caches, and feedback export caches.
  • Reset the random installation client identifier used for analytics: clear SayPilot's app storage/data in Android system settings or uninstall the App. SayPilot's Android backup and device-transfer rules exclude the account-session and analytics preference files, so this random identifier is not intended to be restored from those backups. The in-app "Privacy and Local Data" action clears the assistant data listed above, but does not by itself reset the account session or this random identifier. Clearing app data does not necessarily change platform-derived hashes or fingerprints.
  • Manage advertising measurement: go to "Management Center - Help and Feedback - Privacy and Local Data" to view and change the single Google and Meta advertising-measurement setting. Turning it off does not affect SayPilot's core reply features. It stops subsequent client business-event collection, requests deletion or tombstoning of the backend Firebase and Meta installation bindings, and cancels matching pending server-side conversions that have not started delivery, but does not automatically delete historical data already transmitted to Google or Meta.
  • Manage conversation profiles: view, edit, or delete long-term profiles for eligible named direct conversations in "Conversation Management".
  • Sign out: sign out of the current device on the account page. Signing out does not automatically delete your cloud account, logs, analytics events, orders, quotas, or feedback records.
  • Delete account: when signed in, go to "Management Center - Account - Manage Account - Delete Account" to delete the current cloud account and directly associated account data, and to sign out of the current device. Account deletion deletes first-party SayPilot analytics events directly linked to that account, pre-sign-in first-party events that share an observed install-identifier hash but are not linked to another account, the account-scoped acquisition/source record, the backend Firebase and Meta installation bindings, and matching pending server-side conversions; it does not automatically delete events already transmitted to Firebase, Google Analytics, Google Ads, Meta App Events, or Meta Ads.
  • Delete other cloud data or request manual account deletion: submit a request through https://www.getsaypilot.com/data-deletion/ or support@getsaypilot.com. You may ask us to delete or de-identify analytics records that we can reasonably locate and verify. We recommend using a subject line such as "SayPilot Data Deletion Request" or "SayPilot Account Deletion Request".

To protect account and data security, we may ask you for information needed to verify your identity and locate the relevant data. We will handle verifiable requests within 15 business days. Where information must be retained for legal compliance, dispute handling, financial audit, security risk control, backup recovery, or abuse prevention, we will restrict its use for the necessary period.

8. Children

SayPilot is mainly intended for users who have full legal capacity. If you are a minor, you should use the App only with the consent and guidance of your parent or guardian.

We do not knowingly collect children's personal information. If a parent or guardian believes that a child has used SayPilot without consent or submitted personal information that should not be processed, please contact us at support@getsaypilot.com so we can delete it or take other appropriate steps.

9. Changes to This Policy

We may update this Policy as product features, account systems, paid features, backend deployment, model providers, laws and regulations, regulatory requirements, or app store policies change. For material changes, we will notify you through in-app notices, website announcements, release notes, or another appropriate method.

If you continue to use SayPilot after the Policy is updated, you acknowledge the updated Policy. If you do not agree with the update, you should stop using the relevant features or stop using the App.

10. Contact Us

Operator: Wuhan Huiyu Lingxi Technology Co., Ltd. (武汉市慧语灵犀科技有限责任公司)

Business registration number: 91420100MAKFQF3922

Registered address: Room 2903, Unit 2, Building 1-8, Tianxiang Shangfu Phase II, No. 18 Miaoshan Middle Road, Wuhan East Lake New Technology Development Zone, Hubei Province, China

Email: support@getsaypilot.com

Website: https://www.getsaypilot.com

User Agreement: https://www.getsaypilot.com/terms/

Data deletion/account deletion: https://www.getsaypilot.com/data-deletion/

Appendix 1: Personal Information Collection List

  • Chat page information: currently visible chat text, conversation title, input draft, message direction, sender display name, message-type placeholder, UI node text, control position, and page state. Purpose: understand context and generate reply suggestions; structured text is locally redacted where possible before cloud generation, long-term local memory, or diagnostic export. Trigger: you tap the floating assistant, generate a reply, or review earlier content.
  • Screenshot/OCR information: current screenshot, OCR result, screenshot area, and recognition status. Purpose: supplement chat recognition when accessibility is unavailable or unreliable; the original screenshot may be used for the current cloud recognition request, and recognized structured text is locally redacted where possible. Trigger: you grant permission and actively trigger screenshot recognition.
  • Cloud generation information: request ID, request time, request status, model request metadata, candidate replies, draft suggestions, conversation summaries, and error logs. Purpose: generate replies, display results, troubleshoot issues, and maintain service security; except for original screenshots you allow, structured text is locally redacted where possible before the request. Trigger: you actively use cloud generation.
  • Local settings, memory, and generation history: global reply preferences and defaults; contact notes, conversation summaries, long-term profiles, and interaction profiles for eligible named direct conversations; candidate replies and related context created after you actively trigger generation in a direct or group chat; permission confirmation records; and caches. Group chats do not create long-term conversation memory or contact profiles, and group generation records are not used as long-term group profiles. Purpose: reduce repeated setup, provide result review, and improve relevance; conversation previews, draft previews, generation history, profile summaries, and profile evidence are locally redacted where possible before storage. Trigger: you enable or use related settings, actively generate replies, review generation history, use conversation management, or use profile memory.
  • Account and entitlement information: account ID, email, phone number, Google sign-in identifier, Passkey verification result, login token, account creation and sign-in time, authentication method, registration and sign-in IP addresses, quota, subscription base plan, trial/subscription and auto-renewal status, current billing-period end time, order number, and purchase verification result. Purpose: account sign-in, entitlement sync, purchase and subscription verification, detection of unusual registrations or sign-ins, account security, and risk control. Trigger: you register, sign in, or use related entitlement features.
  • Feedback and diagnostic information: issue description, contact details, diagnostic logs, screenshots, device model, system version, app version, and request ID. Purpose: support, troubleshooting, and product improvement; chat text in recognition details, request log summaries, and user notes is locally redacted where possible, except for contact details you actively enter and original screenshots you attach. Trigger: you submit feedback or export diagnostics.
  • Device and app information: app version, system version, device model, network request status, crash information, API status, IP address, an approximate country code derived from IP when the first-run rating country allowlist is enabled, a consent-required/other/unknown classification derived from IP when the App first determines the default advertising-measurement state, the random installation client identifier, a one-way hash of Android ID, a derived device fingerprint, and security-risk information. The raw Android ID is not sent. For the advertising-measurement default, the bounded backend resolver may keep the approximate country code in short-lived in-process memory, for about six hours by default, to reduce repeated lookups, but does not persist it as a marketing event. The App receives only the three-state classification, not the IP address or a specific country code; an unsuccessful lookup is treated as unknown and measurement remains off. Purpose: protect service operation, bind login verification, provide anonymous trials, detect repeated claims or multiple accounts on one device, troubleshoot issues, measure service quality, and determine the initial rating-prompt and advertising-measurement states under configured regional policies. Trigger: generated while using the App or cloud services; the advertising-measurement region classification is requested only when the App first determines its default and is not continuous location tracking.
  • Product analytics information: pseudonymous install identifier, event name, app version and version code, functional channel/source, first-install source platform, source medium/campaign/content short codes, one-time random click identifier, source-click and install-begin timestamps, permission type and readiness, product ID/type, base plan ID, offer or trial availability, credit amount, price availability, billing response code, error class, and shortened error message. Purpose: measure source-link first opens and launches, permission setup, reply generation and copying, Google Play purchase and subscription funnels, content-promotion and acquisition-channel effectiveness, release quality, reliability, and abuse prevention. Trigger: reported automatically on first run, when the App starts, or when you use the relevant permission, generation, copy, or purchase flow; while signed in, the event may also be associated with your account ID.
  • Optional advertising-measurement information: the Firebase app-instance identifier; a separate Meta anonymous app-device GUID; a device or advertising identifier when available and allowed by the effective provider permission, device, and platform; app version and Firebase/GA4 SDK-defined lifecycle, engagement, or activation state; the Meta SDK install ping; the first successful reply event per installation; and limited product, subscription, trial, purchase, actual order-value, and currency information. Purpose: Google Ads and Meta Ads attribution, conversion measurement, campaign optimization, conversion-value optimization, and return-on-ad-spend optimization, not advertising personalization or remarketing. Trigger: based on the regional initial state, the updated disclosure, and your later setting, Firebase/GA4 may process its automatic events and the first-successful-reply event, while Meta Core may process its install ping and that first-successful-reply event, without a manually logged Meta lifecycle-activation event. The two provider identifiers may be sent to the SayPilot backend at installation scope and low frequency and stored in encrypted, separate bindings, without requiring a SayPilot account sign-in first. From trusted Google Play verification facts, independent asynchronous outboxes may export Google paid_subscription_started and credit_pack_purchased, and Meta StartTrial, Subscribe, or fb_mobile_purchase. Only a strictly matched, PROCESSED production Google Play order may contribute its actual positive order value and currency to the corresponding Google or Meta paid event; test purchases, trials, unknown classifications, and facts that cannot be strictly matched receive no invented or catalog-fallback value. Automatic Google/Firebase purchase events and these custom paid events may describe the same revenue and must not be added together or both treated as primary conversions for the same revenue goal. Permission, copy, ordinary reply, paywall, and checkout-funnel events are excluded from the provider paths. SayPilot does not place chat text, screenshots, contacts, drafts, prompts, reply content, SayPilot account identifiers, email addresses, phone numbers, stored user IP addresses or country codes, order numbers, or raw purchase tokens in these advertising-measurement event parameters. Google and Meta may still process network-transport metadata, including a connecting device or SayPilot server public IP, under their policies.

Appendix 2: App Permissions

  • Accessibility service: reads visible chat text, conversation title, input draft, and UI structure to generate reply suggestions. It does not send messages automatically, tap the send button, or read passwords, payment verification codes, contacts, or SMS. You can disable it in system accessibility settings.
  • Display over other apps: shows the floating assistant and floating panel on chat pages. You can disable it in system app permission settings.
  • Screen capture/screenshot permission: used for screenshot recognition and OCR that you actively trigger. SayPilot does not continuously record the screen in the background. You can refuse permission or stop authorization in the system.
  • Network access: connects to SayPilot cloud services, account services, update services, and feedback services.
  • Notifications and foreground service: shows the floating assistant, screenshot recognition, or background task status while those features are visibly running.
  • Startup-related broadcast: restores necessary floating assistant state after device restart or app update, subject to your permissions and system settings.
  • Query installed supported apps: checks whether supported chat apps are installed so SayPilot can provide matching recognition capabilities.
  • File sharing/cache capability: creates feedback export files, temporary screenshot previews, and diagnostic materials, and passes them through system-authorized sharing when you actively share them.

Appendix 3: Service Provider and Processor List

  • SayPilot cloud backend: handles chat generation requests, account login, quotas/entitlements, version updates, request status, product analytics, logs, security risk control, and feedback. When advertising measurement is allowed, it may also store separate encrypted Firebase app-instance and Meta anonymous app-device-GUID bindings and create separate bounded, asynchronous conversion-export tasks from trusted Google Play verification facts. The Meta outbox contains derived HMAC identifiers, an internal account cleanup/ownership key, allowlisted business semantics, and delivery state; the internal account key never enters Meta's HTTP payload. Information that may be accessed or processed on our behalf includes generation context, account identifiers, pseudonymous install identifier hashes, the provider-specific installation identifiers, analytics events and metadata, request IDs, device and app version, feedback materials, and similar data; structured text is locally redacted where possible before sending, except for original screenshots. Provider installation identifiers are not used for reply generation or propagated as ordinary product-analytics parameters.
  • AI model providers: the specific provider is determined by the model routes currently enabled in the SayPilot cloud configuration. These providers process data on our behalf to generate candidate replies, draft evaluations, conversation summaries, profile reviews, and screenshot parsing. Information processed on our behalf includes the minimum context needed for the current generation, optional screenshots, and request metadata; structured text is locally redacted where possible before sending, and original screenshots may be used for the current parsing request when you allow screenshot recognition or screenshot-based generation.
  • Google sign-in, Passkey, email/SMS verification services: complete identity verification. Information that may be accessed or processed on our behalf includes account identifiers, login challenges, verification-code status, and verification results.
  • Google Play or payment providers: supply Google Play Install Referrer installation-source information and complete Google Play credit-pack and auto-renewing subscription purchases, trials, renewals, cancellation management, purchase restoration, refunds, voided-purchase handling, and order verification. Information that may be accessed or processed on our behalf includes source/medium/campaign/content short codes and a one-time random click identifier written by the source link, source-click and install-begin timestamps, product ID/type, base plan and offer information, order numbers, purchase tokens, payment and subscription status, billing-period end time, credit amounts, refund status, and verification status.
  • Google Firebase, Google Analytics, and Google Ads: based on the regional initial state and your later setting, process a Firebase app-instance identifier; a device or advertising identifier when available and allowed; SDK-defined app-lifecycle or engagement events; the first successful reply event per installation; app version; and product, base-plan, price, currency, subscription, or purchase status automatically supplied through Firebase and Google Play. While consent and the app-instance binding remain valid, they may also receive paid_subscription_started and credit_pack_purchased, which the SayPilot backend asynchronously exports from trusted verification facts. Only after the backend strictly matches and verifies the corresponding production Google Play order as PROCESSED may either paid event include that order's actual positive value and currency for analytics, advertising attribution, conversion measurement, and conversion-value optimization. Permission, copy, ordinary reply, paywall, and checkout-funnel events do not enter this path. Advertising personalization and remarketing signals remain disabled. SayPilot does not include account identifiers, stored user IP addresses or country codes, order numbers, purchase tokens, chat text, screenshots, contacts, or reply content in these events; Google may still process request-connection metadata under its policies.
  • Meta Platforms, Meta App Events, and Meta Ads: after the current disclosure is effective for your region and the Meta destination is configured, process the installation-scoped Meta anonymous app-device GUID, an advertiser identifier only where effective permission and the device/platform allow it, the SDK install ping, the first successful reply per installation, app version, and the fixed StartTrial, Subscribe, or fb_mobile_purchase events asynchronously exported from trusted production Google Play facts. StartTrial and unresolved paid events contain no monetary value; a Subscribe or fb_mobile_purchase event may include the actual positive order value and currency only after the backend strictly matches and verifies the exact production Google Play order as PROCESSED. Manually logged lifecycle activation, automatic purchase logging, codeless debugging, SDK monitoring, advertising personalization, and remarketing remain disabled in the App. Advertiser-ID collection is disabled before readiness and again on withdrawal. SayPilot does not include account identifiers, email addresses, phone numbers, stored user IP addresses or country codes, order numbers, purchase tokens, chat text, screenshots, contacts, drafts, prompts, or reply content in these events; Meta may still process request-connection metadata under its policies.
  • Cloud infrastructure, logging, monitoring, and security services: host services, transmit and store data, troubleshoot issues, defend against attacks, and maintain stability. Information that may be accessed or processed on our behalf includes service logs, API status, error information, and necessary security data.
  • Feedback, support, or email services: handle issues you submit. Information that may be accessed or processed on our behalf includes issue descriptions, contact details, diagnostic materials, screenshots, and communication records.
  • IP-geolocation service, when the first-run rating country allowlist or regional advertising-measurement default is enabled: may receive the public egress IP address observed by the SayPilot backend and return an approximate country code, which the backend may map to consent-required region, other region, or unknown. The rating feature may use the approximate country code. To reduce repeated external lookups, the bounded backend resolver may keep the approximate country code in short-lived in-process memory, for about six hours by default, but does not persist it as a marketing event. For advertising measurement, the App receives only the three-state classification, not a specific country or IP address, and an unsuccessful lookup is treated as unknown with measurement off. The default zero-configuration provider is Country (api.country.is); the service operator may instead configure a first-party or self-hosted compatible HTTPS endpoint. This is not precise device location or continuous regional tracking, and the IP address, country code, and three-state classification are not sent to Google or Meta as advertising-measurement event parameters.
↑ ↓
SayPilot

Floating AI replies for the conversations that matter.

Wuhan Huiyu Lingxi Technology Co., Ltd. Email: support@getsaypilot.com
Privacy Terms Data deletion