SayPilot
Home
AI reply suggestionsConversation memoryMultilingual repliesBring your own model
All use casesDating app repliesReply to friendsWorkplace repliesMultilingual chat repliesGroup chat replies
Help centerPermissions helpContact usPrivacyTermsData deletion
Get SayPilot on Google Play
EN 中文

SayPilot

SayPilot Privacy Policy

SayPilot (the "App" or "SayPilot") is operated by Wuhan Huiyu Lingxi Technology Co., Ltd. (武汉市慧语灵犀科技有限责任公司) ("we", "us", or "our"). We care about protecting your personal information and the privacy of your conversations. This Privacy Policy explains how we collect, use, store, share, transfer, disclose, delete, and protect information when we provide the SayPilot Android app, SayPilot cloud services, the management center, floating assistant, screenshot recognition, cloud reply generation, account, quota, and feedback features. It also explains how you can manage your information and permissions.

Last updated: July 17, 2026

1. Scope

This Policy applies to the SayPilot Android app and the cloud generation, account sign-in, quota/entitlement, update check, feedback, and support services we provide for it.

Third-party chat apps such as WeChat, WeCom, WhatsApp, WhatsApp Business, and Messenger are provided by their respective operators. Your accounts, chat history, contacts, payments, notifications, and platform risk controls in those third-party chat apps are handled by those third parties and are not governed by this Policy. SayPilot is not an official product of those chat apps and does not represent them or their operators.

If you use SayPilot to open a third-party website, app store, Google sign-in, Passkey, payment service, email/SMS verification service, or other third-party service, that service may be governed by its own privacy policy and terms.

2. Information We Collect and Use

We follow the principles of lawfulness, fairness, necessity, and good faith. We process information only as needed to provide product features, perform our contract with you, protect security, respond to your requests, or comply with applicable laws and regulations. Unless the law allows otherwise or the information is necessary for a core feature, you may refuse to provide certain information or disable permissions, but the related feature may not work.

2.1 Chat Recognition and Reply Assistance

SayPilot is a user-triggered chat reply assistant. When you tap the floating assistant, generate reply suggestions, view draft suggestions, or ask SayPilot to review earlier context on a supported chat conversation screen, we may process:

  • Currently visible chat text, conversation title, group title, message direction, sender display name, message-type placeholders, and timing or ordering cues.
  • Input draft text, reply style, reply intent, banned words, relationship labels you enter for the other person and yourself, group reply targets, and whether an @ mention is needed.
  • UI node text, control positions, page state, and basic screen structure, used to decide whether the current page is a supported chat conversation.
  • Additional visible messages if you actively trigger history backfill or ask SayPilot to review more context. In that case, the App may briefly scroll the current chat page.

We use this information to understand the current conversation, generate candidate replies, evaluate whether a draft is appropriate, provide conversation summaries, help infer relationship or identity context, improve candidate ranking, and reduce repeated setup.

SayPilot does not send chat messages for you, does not tap a third-party chat app's send button, and does not write generated content into a third-party chat input box on its own.

SayPilot does not obtain chat records by reading third-party chat app databases, private directories, encryption keys, non-public interfaces, hooks, injection, cracking, or protocol emulation. It does not bulk export, sell, or collect chat records for purposes unrelated to reply suggestions.

2.2 Cloud Generation and AI Processing

When you use cloud generation, SayPilot sends the minimum context needed for reply generation to the SayPilot cloud service at https://www.getsaypilot.com over HTTPS. This may include:

  • Request ID, request time, app version, request status, context source, and necessary model request metadata.
  • Currently visible chat messages, conversation title, input draft, reply settings, group reply target, and local conversation or contact profile summaries you allow for the request.
  • Screenshots or screenshot recognition results you allow for that request.
  • Generated results, including candidate replies, draft evaluation, conversation summaries, model suggestions, relationship/identity hints, and profile review results.

Before a reply-generation request is sent, SayPilot shows a Pre-send Check that summarizes the selected chat context and reply settings. You can review the selected transcript, confirm generation, or cancel. The confirmation applies only to the current request; it does not enable background chat collection or automatic message sending.

Before building a cloud generation request, SayPilot locally redacts structured text where possible. The redaction replaces high-risk items such as phone numbers, email addresses, verification codes, passwords or passphrases, government ID numbers, passport numbers, bank card numbers, API keys or tokens, payment or transfer account identifiers, and precise address fragments. Redaction does not hide ordinary nicknames, names, relationship terms, or regular chat meaning by default, and it does not change the backend request schema.

The SayPilot backend may call AI model providers enabled in the current cloud routing configuration, or other necessary service providers, to generate reply suggestions, draft evaluations, conversation summaries, and profile review results. Specific provider names, purposes, data types, and regions are described in Appendix 3 of this Policy and the public website version. Model provider secrets should not be embedded in the client app package.

Please note that redaction is not the same as anonymization, and it may not detect or replace every sensitive item. We recommend that you do not intentionally submit passwords, payment verification codes, government ID numbers, bank card numbers, precise locations, contact lists, medical records, children's sensitive information, trade secrets, or other sensitive information unrelated to reply suggestions in chats, drafts, screenshots, or feedback. If you submit another person's personal information, you must make sure you have a lawful basis or authorization to do so.

2.3 Screenshot Recognition and OCR

When you actively trigger screenshot recognition, screenshot fallback, or manual screenshot mode and approve the Android system prompt, SayPilot may process the current screenshot, OCR result, screenshot area, screenshot time, and recognition status. A screenshot may include visible chat content, draft text, or other information shown on the screen.

Screenshot recognition is mainly used when the accessibility service is unavailable, disconnected, or unable to reliably read the current chat page. SayPilot does not continuously record the screen in the background. You may refuse screen capture permission; if you do, accessibility-based text recognition and existing local context may still be available.

If you choose cloud generation and allow screenshots to be included, the original screenshot or screenshot data may be sent to SayPilot cloud services and model providers for the current request, so they can understand the chat content and generate reply suggestions.

The first version does not blur or mask the screenshot image itself. The original screenshot may be used for the current cloud screenshot recognition or multimodal understanding request. Chat text, OCR output, or structured screenshot results returned from cloud recognition are locally redacted where possible before they are used for generation, long-term local memory, or feedback diagnostic export.

2.4 Local Settings, Conversation Memory, and Contact Profiles

To reduce repeated setup and make suggestions more relevant, SayPilot may store the following information on your device:

  • Global reply preferences and default switches, plus long-term relationship, reply style, reply language, banned-word, and memory settings for eligible named direct conversations.
  • Contact notes, the other person's identity, your identity, conversation summaries, and recent chat summaries for eligible named direct conversations.
  • Long-term profile signals, preferences and taboos, interaction profiles, profile evidence, update time, confidence, and similar local profile information for eligible named direct conversations.
  • On-device generation history created after you actively trigger generation, including candidate replies from direct or group chats and related context needed to display and review that result.
  • Records showing that you acknowledged prominent permission disclosures, screenshot permission disclosures, app cache, temporary screenshot previews, and feedback export caches.

Before conversation memory, AI reply history, profile summaries, profile evidence, draft previews, and conversation previews are saved, the client locally redacts high-risk sensitive fragments where possible.

Reply intent, group reply targets, group reply scope, and whether an @ mention is needed are used only for the current runtime state or generation request. They are not stored as long-term group conversation memory or group contact profiles. Group chats do not create long-term conversation memory or contact profiles. However, group-chat candidate replies and the related context needed to review that result may be stored as separate on-device generation history until you clear local assistant data, newer history replaces the record, or you clear app data or uninstall the App. Generation history is not used as a long-term group profile.

This information is mainly stored in the App's private directory, SharedPreferences, database, or cache. You can clear local assistant data from "Management Center - Help and Feedback - Privacy and Local Data". After clearing, local profiles, conversation memory, default settings, permission confirmation records, and temporary caches will be reset.

Clearing local data does not automatically delete records that have already been sent to the cloud backend, model providers, or feedback handling systems.

2.5 Accounts, Sign-In, and Entitlements

Some cloud generation, quota sync, entitlement records, purchase records, feedback tracking, or cross-device features may require an account. Depending on server-side configuration, SayPilot may support email verification codes, phone verification codes, Google sign-in, Passkeys, or other sign-in methods. The methods actually available are those shown in the App.

When you use account features, we may process account ID, email address, phone number, verification-code request and verification status, necessary identifiers returned by Google sign-in, Passkey registration or sign-in challenges and verification results, login tokens, session status, account creation and login time, registration and sign-in IP addresses, authentication method, entitlement quota, subscription status, and risk-control status.

When an account is first created and during later sign-in or authentication requests, the server may record the public egress IP address it observes and associate the registration IP or recent sign-in IP with the account. We use this information to detect unusual registrations or sign-ins, prevent abuse, protect account security, and perform necessary security audits. The address may be affected by carrier networks, shared networks, VPNs, or proxies and does not represent a precise physical location.

We do not ask you to provide bank card passwords, payment verification codes, or third-party account passwords inside the SayPilot client. Please protect your email, phone number, Google account, Passkey, device unlock method, and other credentials.

2.6 Payments, Memberships, and Purchases

As of the last updated date of this Policy, SayPilot offers Google Play Billing one-time credit packs in the public Android release. The App may show the credits_30, credits_100, and credits_300 product IDs, prices supplied by Google Play, purchase status, and restore-purchase status. Subscriptions, external payment methods, simulated payments, and test payment features are not offered to ordinary release users in this release.

When you buy, restore, receive a refund for, or otherwise manage a Google Play credit pack, we may process product IDs, order numbers, purchase tokens, payment status, credit amounts, refund status, voided-purchase status, purchase restoration results, and payment verification results. Sensitive payment credentials such as payment card numbers are normally handled directly by Google Play or the relevant payment provider, and should not be collected directly inside the SayPilot client.

2.7 Feedback, Support, and Diagnostics

When you submit feedback, export diagnostic files, attach screenshots, or contact us, we may process the issue description, contact details, device model, system version, app version, permission status, request status, error logs, request IDs, conversation summaries, screenshots, diagnostic files, and communication records you provide.

We use this information to investigate issues, respond to you, improve the product, handle complaints, verify account or data deletion requests, and maintain service security. You may choose not to submit feedback materials, but this may limit our ability to diagnose or resolve the issue.

When you export a feedback diagnostic package or copy diagnostic information, chat text in recognition details, request log summaries, and user notes is locally redacted where possible. Contact details you actively enter are kept so we can reach you. If you choose to attach a recent screenshot, the original screenshot may still contain unredacted screen content; please review it before submission.

2.8 Device, App, and Security Logs

To keep the software and services running securely, troubleshoot issues, measure service quality, and prevent abuse, we may process app version, system version, device model, network request status, cloud API status, crash information, error logs, request latency, request success or failure status, IP address, account login status, quota usage status, and necessary security or risk-control information.

Cloud requests may also carry a randomly generated installation client identifier, a one-way hash of Android ID, and a device fingerprint derived from that hash. The raw Android ID is not sent. These pseudonymous identifiers are used to bind login-verification requests, provide anonymous trials, detect multiple accounts or repeated claims on the same device, perform security and abuse prevention, associate necessary diagnostics, and measure product usage. They may be associated with a SayPilot account after sign-in.

SayPilot does not read contacts, SMS, call logs, precise location, photo library files, passwords, payment verification codes, or content unrelated to reply suggestions for the purpose of generating replies.

SayPilot also does not read third-party chat app local databases, private directories, encryption keys, or non-public interfaces for reply suggestions, and does not use hooks, injection, cracking, or protocol emulation to bypass the normal permission and security boundaries of third-party apps.

2.9 Product Analytics and Pseudonymous Identifiers

When the configured SayPilot cloud service is available, the Android App automatically reports a limited set of product analytics events. These include first open and app launch events; permission guide, settings-opened, permission-granted, and required-permissions-ready events; and Google Play credit-pack funnel events such as membership-page views, product and price availability, product selection, purchase clicks, purchase-sheet opening, cancellation, errors, and verification status. This reporting happens when the App starts or when you use the relevant permission or purchase flow; it does not require a separate submission action for every event.

Each event may contain the randomly generated installation client identifier described above, sent as anonymous_id, together with the event name, platform, app version and version code, channel or source, and limited event metadata. Depending on the event, metadata may include permission type and readiness, product ID and type, base plan ID, credit amount, whether a price was available, Google Play response code, error class, or a shortened error message. The backend hashes the identifier again before storing the analytics event. The identifier is pseudonymous rather than anonymous because it remains stable in the App's private storage and is also used for some account-verification and security functions; while you are signed in, the login session may also associate the event with your SayPilot account ID.

We use these events to measure installation and feature adoption, understand permission setup and purchase funnels, assess release quality and service reliability, troubleshoot failures, and prevent abuse. First-party SayPilot analytics events are not intended to contain chat text, screenshots, contact names, advertising IDs, or precise location, and we do not sell this information.

2.10 Updates and Notifications

SayPilot may connect to cloud services to check the app version, update status, official update address, and forced update flags. Notification permission is used when needed to keep the floating assistant, screenshot recognition, or background tasks visibly running, or to show service-related notices.

You can disable notifications in system settings. If you do, some foreground service notices, error messages, or background task status notices may not appear.

2.11 Cases Where Separate Consent May Not Be Required

Where permitted by applicable law, we may process your personal information without separate additional consent in the following situations:

  • The processing is necessary to enter into or perform a contract with you.
  • The processing is necessary for us to perform legal duties or obligations.
  • The processing is necessary to respond to a public health emergency, or to protect an individual's life, health, or property in an emergency.
  • The processing is carried out within a reasonable scope for public-interest news reporting, public opinion supervision, or similar activities.
  • The processing concerns personal information you have made public yourself, or information that has otherwise been lawfully made public, within a reasonable scope.
  • Other situations provided by laws and regulations.

3. Cookies and Similar Technologies

The SayPilot Android app itself usually does not rely on browser cookies to provide its core chat assistance features.

If you visit the SayPilot website, data deletion page, account page, backend admin page, or another web service, we or our service providers may use cookies, LocalStorage, session tokens, or similar technologies for login sessions, security verification, request protection, preference storage, troubleshooting, and analytics. You can clear or restrict cookies through your browser settings, but some web features may be affected.

4. Service Providers, Transfers, and Public Disclosure

4.1 Service Provider Processing Principles

We do not sell your personal information. To provide SayPilot, we may provide necessary information to service providers that process data on our behalf, or allow those service providers to process necessary information, only as needed to provide the service, perform our contract, comply with law, maintain security, handle feedback, or protect users' legitimate rights and interests.

These service providers must process information according to our instructions, for the agreed purposes, within the minimum necessary scope, and with reasonable security measures. They may not use your information for their own advertising, profiling, independent commercial purposes, or purposes unrelated to providing SayPilot. Under the Google Play Data safety framework, transfers to service providers that process user data on behalf of the developer and based on the developer's instructions are generally not treated as "sharing" with third parties. If a provider processes data outside that service-provider role, we will update this Policy and the relevant app store disclosures as required.

4.2 Categories of Providers

To provide SayPilot, the following types of providers may access necessary information:

  • SayPilot cloud backend: generation requests, account login, quotas/entitlements, version updates, request status, logs, security risk control, and feedback handling.
  • AI model providers: candidate replies, draft evaluation, conversation summaries, profile review, and screenshot parsing.
  • Account verification services: Google sign-in, Passkeys, email verification codes, phone verification codes, and similar identity checks.
  • Google Play or payment providers: Google Play credit-pack purchases, purchase restoration, refunds, voided-purchase handling, and order verification.
  • Cloud infrastructure, logging, monitoring, and security services: hosting, transmission, storage, troubleshooting, attack protection, and service reliability.
  • Feedback, support, or email services: issues, diagnostic materials, and contact details you submit.
  • Share targets you choose: if you send a feedback export file through the Android share sheet, the file is sent to the app or contact you select.

Specific service provider categories, processing purposes, data types, and contact information are described in Appendix 3 of this Policy and in the public website version.

4.3 Business Transfers

If personal information is transferred because of a merger, division, acquisition, asset transfer, bankruptcy, liquidation, or similar transaction, we will require the new holder to continue to follow this Policy. If the new holder changes the purposes or methods of processing, we will require it to obtain consent again as required by law.

4.4 Public Disclosure

We do not publicly disclose your personal information unless we have your separate consent, or disclosure is required by laws, courts, administrative authorities, regulators, security incident handling, or illegal-use handling.

5. How We Protect Your Information

We use reasonable technical and organizational measures to protect your information. These may include HTTPS/TLS transmission, access controls, key isolation, minimized processing, log access controls, server-side authentication, anomaly monitoring, backup and recovery, and internal permission management.

Local redaction is an additional measure to reduce the risk of sensitive information exposure. It does not mean that all sensitive information can be automatically detected or fully replaced.

Please understand that no internet service can guarantee absolute security. If a personal information security incident occurs, we will take remedial steps as required by applicable laws and regulations and notify you of the situation and suggested actions through in-app notices, announcements, email, or other reasonable methods.

6. Storage and Retention

Local data may be stored in the App's private directory, SharedPreferences, databases, or caches on your device. You can uninstall the App or clear local assistant data from "Management Center - Help and Feedback - Privacy and Local Data".

Cloud data may be stored on servers or cloud services in Singapore. If your information needs to be transferred to overseas servers or overseas model providers, we will provide notice and take necessary protections in accordance with applicable laws, regulations, and app store policies. The actual cross-border recipients, regions, and purposes are listed at https://www.getsaypilot.com/privacy/.

We retain personal information only for as long as necessary for the purposes described in this Policy. Backend request logs and model request logs are retained for 90 days. Raw registration IP addresses associated with accounts, and raw IP addresses in sign-in or authentication requests, are retained for 90 days by default. The service operator may configure the retention period for registration IP addresses and IP addresses in email or SMS verification-code records from 1 to 3,650 days. When that period expires, the raw IP address is cleared, while necessary non-IP account or security-audit metadata such as account creation time and authentication method may be retained for business or legal needs. Raw first-party product analytics events are a separate category and are automatically deleted when they are older than the configured analytics retention period. That period defaults to 400 days and can be configured by the service operator; the current implementation accepts a range of 1 to 3,650 days. Aggregated or de-identified statistics that no longer identify an account or installation may be retained longer. Feedback records, account records, order records, risk-control records, and information required by law are retained as needed for business purposes and legal requirements. After an applicable retention period expires, we delete or anonymize the information, unless laws or regulations require otherwise.

7. Your Choices and Rights

To the extent permitted by applicable law, you may request access to, a copy of, correction of, completion of, or deletion of your personal information; withdraw authorization; disable permissions; delete your account; or ask us to explain our processing rules.

You can manage information and permissions in the following ways:

  • Disable system permissions: disable SayPilot's accessibility service, display-over-other-apps permission, screen capture, notifications, background running, or other related permissions in Android system settings.
  • Clear local data: go to "Management Center - Help and Feedback - Privacy and Local Data" to clear locally stored profiles, conversation memory, generation history, default settings, permission confirmation records, screenshot caches, and feedback export caches.
  • Reset the random installation client identifier used for analytics: clear SayPilot's app storage/data in Android system settings or uninstall the App. SayPilot's Android backup and device-transfer rules exclude the account-session and analytics preference files, so this random identifier is not intended to be restored from those backups. The in-app "Privacy and Local Data" action clears the assistant data listed above, but does not by itself reset the account session or this random identifier. Clearing app data does not necessarily change platform-derived hashes or fingerprints.
  • Manage conversation profiles: view, edit, or delete long-term profiles for eligible named direct conversations in "Conversation Management".
  • Sign out: sign out of the current device on the account page. Signing out does not automatically delete your cloud account, logs, analytics events, orders, quotas, or feedback records.
  • Delete account: when signed in, go to "Management Center - Account - Manage Account - Delete Account" to delete the current cloud account and directly associated account data, and to sign out of the current device. Account deletion deletes first-party SayPilot analytics events directly linked to that account, pre-sign-in first-party events that share an observed install-identifier hash but are not linked to another account, and the account-scoped acquisition/source record.
  • Delete other cloud data or request manual account deletion: submit a request through https://www.getsaypilot.com/data-deletion/ or support@getsaypilot.com. You may ask us to delete or de-identify analytics records that we can reasonably locate and verify. We recommend using a subject line such as "SayPilot Data Deletion Request" or "SayPilot Account Deletion Request".

To protect account and data security, we may ask you for information needed to verify your identity and locate the relevant data. We will handle verifiable requests within 15 business days. Where information must be retained for legal compliance, dispute handling, financial audit, security risk control, backup recovery, or abuse prevention, we will restrict its use for the necessary period.

8. Children

SayPilot is mainly intended for users who have full legal capacity. If you are a minor, you should use the App only with the consent and guidance of your parent or guardian.

We do not knowingly collect children's personal information. If a parent or guardian believes that a child has used SayPilot without consent or submitted personal information that should not be processed, please contact us at support@getsaypilot.com so we can delete it or take other appropriate steps.

9. Changes to This Policy

We may update this Policy as product features, account systems, paid features, backend deployment, model providers, laws and regulations, regulatory requirements, or app store policies change. For material changes, we will notify you through in-app notices, website announcements, release notes, or another appropriate method.

If you continue to use SayPilot after the Policy is updated, you acknowledge the updated Policy. If you do not agree with the update, you should stop using the relevant features or stop using the App.

10. Contact Us

Operator: Wuhan Huiyu Lingxi Technology Co., Ltd. (武汉市慧语灵犀科技有限责任公司)

Business registration number: 91420100MAKFQF3922

Registered address: Room 2903, Unit 2, Building 1-8, Tianxiang Shangfu Phase II, No. 18 Miaoshan Middle Road, Wuhan East Lake New Technology Development Zone, Hubei Province, China

Email: support@getsaypilot.com

Website: https://www.getsaypilot.com

User Agreement: https://www.getsaypilot.com/terms/

Data deletion/account deletion: https://www.getsaypilot.com/data-deletion/

Appendix 1: Personal Information Collection List

  • Chat page information: currently visible chat text, conversation title, input draft, message direction, sender display name, message-type placeholder, UI node text, control position, and page state. Purpose: understand context and generate reply suggestions; structured text is locally redacted where possible before cloud generation, long-term local memory, or diagnostic export. Trigger: you tap the floating assistant, generate a reply, or review earlier content.
  • Screenshot/OCR information: current screenshot, OCR result, screenshot area, and recognition status. Purpose: supplement chat recognition when accessibility is unavailable or unreliable; the original screenshot may be used for the current cloud recognition request, and recognized structured text is locally redacted where possible. Trigger: you grant permission and actively trigger screenshot recognition.
  • Cloud generation information: request ID, request time, request status, model request metadata, candidate replies, draft suggestions, conversation summaries, and error logs. Purpose: generate replies, display results, troubleshoot issues, and maintain service security; except for original screenshots you allow, structured text is locally redacted where possible before the request. Trigger: you actively use cloud generation.
  • Local settings, memory, and generation history: global reply preferences and defaults; contact notes, conversation summaries, long-term profiles, and interaction profiles for eligible named direct conversations; candidate replies and related context created after you actively trigger generation in a direct or group chat; permission confirmation records; and caches. Group chats do not create long-term conversation memory or contact profiles, and group generation records are not used as long-term group profiles. Purpose: reduce repeated setup, provide result review, and improve relevance; conversation previews, draft previews, generation history, profile summaries, and profile evidence are locally redacted where possible before storage. Trigger: you enable or use related settings, actively generate replies, review generation history, use conversation management, or use profile memory.
  • Account and entitlement information: account ID, email, phone number, Google sign-in identifier, Passkey verification result, login token, account creation and sign-in time, authentication method, registration and sign-in IP addresses, quota, subscription status, order number, and purchase verification result. Purpose: account sign-in, entitlement sync, purchase verification, detection of unusual registrations or sign-ins, account security, and risk control. Trigger: you register, sign in, or use related entitlement features.
  • Feedback and diagnostic information: issue description, contact details, diagnostic logs, screenshots, device model, system version, app version, and request ID. Purpose: support, troubleshooting, and product improvement; chat text in recognition details, request log summaries, and user notes is locally redacted where possible, except for contact details you actively enter and original screenshots you attach. Trigger: you submit feedback or export diagnostics.
  • Device and app information: app version, system version, device model, network request status, crash information, API status, IP address, the random installation client identifier, a one-way hash of Android ID, a derived device fingerprint, and security risk-control information. The raw Android ID is not sent. Purpose: protect service operation, bind login verification, provide anonymous trials, detect repeated claims or multiple accounts on one device, troubleshoot issues, and measure service quality. Trigger: generated while using the App or cloud services.
  • Product analytics information: pseudonymous install identifier, event name, app version and version code, channel/source, permission type and readiness, product ID/type, base plan ID, credit amount, price availability, billing response code, error class, and shortened error message. Purpose: measure first open and launch, permission setup, Google Play credit-pack funnels, release quality, reliability, and abuse prevention. Trigger: reported automatically when the App starts or when you use the relevant permission or purchase flow; while signed in, the event may also be associated with your account ID.

Appendix 2: App Permissions

  • Accessibility service: reads visible chat text, conversation title, input draft, and UI structure to generate reply suggestions. It does not send messages automatically, tap the send button, or read passwords, payment verification codes, contacts, or SMS. You can disable it in system accessibility settings.
  • Display over other apps: shows the floating assistant and floating panel on chat pages. You can disable it in system app permission settings.
  • Screen capture/screenshot permission: used for screenshot recognition and OCR that you actively trigger. SayPilot does not continuously record the screen in the background. You can refuse permission or stop authorization in the system.
  • Network access: connects to SayPilot cloud services, account services, update services, and feedback services.
  • Notifications and foreground service: shows the floating assistant, screenshot recognition, or background task status while those features are visibly running.
  • Startup-related broadcast: restores necessary floating assistant state after device restart or app update, subject to your permissions and system settings.
  • Query installed supported apps: checks whether supported chat apps are installed so SayPilot can provide matching recognition capabilities.
  • File sharing/cache capability: creates feedback export files, temporary screenshot previews, and diagnostic materials, and passes them through system-authorized sharing when you actively share them.

Appendix 3: Service Provider and Processor List

  • SayPilot cloud backend: handles chat generation requests, account login, quotas/entitlements, version updates, request status, product analytics, logs, security risk control, and feedback. Information that may be accessed or processed on our behalf includes generation context, account identifiers, pseudonymous install identifier hashes, analytics events and metadata, request IDs, device and app version, feedback materials, and similar data; structured text is locally redacted where possible before sending, except for original screenshots.
  • AI model providers: the specific provider is determined by the model routes currently enabled in the SayPilot cloud configuration. These providers process data on our behalf to generate candidate replies, draft evaluations, conversation summaries, profile reviews, and screenshot parsing. Information processed on our behalf includes the minimum context needed for the current generation, optional screenshots, and request metadata; structured text is locally redacted where possible before sending, and original screenshots may be used for the current parsing request when you allow screenshot recognition or screenshot-based generation.
  • Google sign-in, Passkey, email/SMS verification services: complete identity verification. Information that may be accessed or processed on our behalf includes account identifiers, login challenges, verification-code status, and verification results.
  • Google Play or payment providers: complete Google Play credit-pack purchases, purchase restoration, refunds, voided-purchase handling, and order verification. Information that may be accessed or processed on our behalf includes product IDs, order numbers, purchase tokens, payment status, credit amounts, refund status, and verification status.
  • Cloud infrastructure, logging, monitoring, and security services: host services, transmit and store data, troubleshoot issues, defend against attacks, and maintain stability. Information that may be accessed or processed on our behalf includes service logs, API status, error information, and necessary security data.
  • Feedback, support, or email services: handle issues you submit. Information that may be accessed or processed on our behalf includes issue descriptions, contact details, diagnostic materials, screenshots, and communication records.
↑ ↓
SayPilot

Floating AI replies for the conversations that matter.

Wuhan Huiyu Lingxi Technology Co., Ltd. Email: support@getsaypilot.com
Privacy Terms Data deletion