QwenNote Privacy Policy
Welcome to QwenNote's products and services. We understand how important personal information is to you. We have prepared this QwenNote Privacy Policy (this "Policy") to help you understand how we collect, process, and protect your personal information, and how you can manage your personal information. Before using the services, please be sure to read this Policy carefully, especially the clauses highlighted in bold, and begin using the services only after you fully understand and agree to it. If you have any questions, comments, or suggestions regarding this Policy, you may contact us through the channels listed under "Contact Us" at the end of this Policy.
QwenNote is an intelligent note-taking product operated by DingTalk (Singapore) Private Limited, a company registered in Singapore ("we"). It consists of the QwenNote mobile application, the international website (qwennote.ai), and companion smart hardware devices, and provides you with services such as voice transcription, speaker differentiation, AI meeting summaries, and AI-powered Q&A.
This Policy will help you understand the following:
1.
Scope of Application
2.
Information Collection and Use
3.
Partners, Entrusted Processing, Transfer, and Disclosure of Information
4.
Your Rights
5.
Storage of Information
6.
Updates to this Policy
7.
Protection of Minors
8.
Contact Us Appendix I: Definitions Appendix II: Supplemental Disclosures for Users in Japan
1. Scope of Application
1.1 This Policy applies to your access to and use of any of the services provided by QwenNote in any manner, including hardware device binding and management, recording upload and transcription, AI summaries and Q&A, content translation, speaker identification, voice memos, account and data management, membership and customer support, and security protection.
1.2 By using the QwenNote services, you acknowledge that you have read, understood, and agree to this Policy. If you do not agree with any part of this Policy, please stop registering for or using the services.
1.4 We may publish supplementary privacy statements or appendices in local languages for users in particular countries or regions. Where a supplementary statement is inconsistent with this Policy, the supplementary statement prevails for users in that country or region.
2. Information Collection and Use
The information we collect is limited to what is necessary to deliver the service features. The types of information we collect, the means of collection, and the purposes are described below by functional scenario.
2.1 Account Registration and Management
a. Registration and sign-in: You may register and sign in using a Google account, a Microsoft account, an Apple account, or an email address. When you sign in with a third-party account, we receive the account information provided by that third party (such as your email address and nickname) within the scope of your authorization. When you register with an email address, we collect your email address and the password you set, and verify your identity using an email verification code (forgotten passwords are likewise reset via verification code).
b. Account profile: You may set or change profile information such as your avatar and nickname. When setting an avatar, we may request access to your camera or photo library, for taking a photo or selecting an image from your library; such images are used solely for avatar setup.
2.2 Recording Transcription and AI Features (Core Features)
a. Hardware device binding: Before using the core features, you must bind at least one hardware device to the product. During binding, we collect the device serial number (SN), device model, firmware version, Bluetooth connection status, and location information, for device authentication, connection management, firmware upgrades, and determination of your service region. Binding may also require you to grant camera permission (to scan the device's QR code); this permission is invoked only when you actively initiate a scan. The binding relationship between device and account is stored in the cloud to identify your device and sync settings.
b. When you use this service, we obtain the original recording files from the QwenNote smart hardware device(s) bound to you. We transfer recording files and associated metadata from the QwenNote smart hardware device to the QwenNote app via Bluetooth or high-speed transfer over Wi-Fi within the same local area network; such transfer is completed locally only. At your request, we use the above recording files for voice transcription. As the party responsible for processing the recording files and summary files you upload, you must obtain the consent of all parties recorded in advance and bear the relevant legal liability yourself.
c. Processing of audio data ("Traceless Mode"): Audio you record on the hardware device is transmitted to your phone via Bluetooth or the local network, and uploaded to the cloud solely for the purpose of that voice transcription job. Once transcription is complete, the audio file is permanently deleted from the cloud staging area, the app, and the hardware device, and cannot be recovered. The transcript and AI summaries and other content derived from it are stored normally per your instructions. This "Traceless Mode" is the default and only mode and cannot be turned off. The product does not provide storage or playback of recordings: you cannot listen to or replay recordings on any interface, and deleted recordings cannot be retrieved.
d. Hotwords: Proper nouns, names, and terms you add are stored under your account and transmitted with your transcription requests to the transcription service for transcription optimization. You may delete them at any time.
e. Tags: Tags you create for transcripts and summaries are stored with the content and used for categorization and retrieval.
f. Content translation: When you initiate a translation, the text to be translated is transmitted as input to the AI service for processing, and the translation result is stored as new text.
g. Voice memos: When you create a voice memo by recording, we transcribe it into text.
h. If you proactively enable voiceprint recognition, we will process and protect your personal information in accordance with the QwenNote Voiceprint Recognition Service Personal Information Processing Rules. If you use the annotation feature, you must obtain the consent of all parties annotated in the recording in advance and bear the relevant legal liability yourself. Recordings and transcripts may incidentally contain special-category information such as health, medical records, or criminal records; we do not collect such information as a purpose. If you proactively upload content containing such information, you are deemed to have ensured that there is a lawful basis for processing that information.
2.3 Content Publishing and Sharing
You may share files such as transcripts and summaries with third parties. Information you share may involve personal information, or even sensitive personal information, of yourself or others. You must obtain others' consent before publishing content involving their personal information, and you must ensure that the sharing does not infringe any third party's privacy or trade secrets.
Sharing is implemented via share links. Recipients can see only the shared content you selected (the summary or the transcript) together with the recording metadata necessary for that share (such as title, creation time, and duration). The original recording is not made available to recipients for playback or download. Speaker names in the transcript are labeled manually by you. You may revoke a share at any time, after which the original link becomes inaccessible. However, content already saved or forwarded by recipients cannot be retrieved by us.
2.4 Messages and Notifications
While you use the QwenNote services, we may send you service notices (such as transcription-completion reminders and account security alerts) via app push notifications, email, and other means. With your consent, we may also recommend products and information that may interest you. You may turn off push notifications in "Settings – Notifications".
2.5 Customer Support and Dispute Handling
When you contact our customer support for help, you must provide the necessary personal information to verify your identity in order to protect the security of your account and our systems.
To contact you, help resolve issues, or record the handling plan and outcome of an issue, we keep the records of your communications with us and related content (including account information, ticket information, other information you provide to prove relevant facts, and the contact details you leave).
For the reasonable needs of providing the service and improving service quality, we may use other information of yours, including information you provide when contacting customer support and your responses when participating in surveys.
2.6 Security Protection and Logs
a. To protect account and service security and to troubleshoot failures, we collect and process: device identifiers (such as device model and operating system version), app information, network environment information (such as network type and carrier), and service log information (such as access time, request records, and error information).
b. Processing of log data: Service logs are aggregated and stored in our log and diagnostics platform for troubleshooting and security auditing. User identifiers in logs are anonymized or de-identified when used. Operations and R&D personnel perform read-only troubleshooting through controlled access channels, with full audit trails.
2.7 System Permissions and Cookies
a. Additional services based on system permissions
In the course of providing services to you, we may collect and use your personal information by enabling system permissions. Turning off any permission means you withdraw the corresponding authorization; we will then stop collecting and using the related personal information based on that permission and will be unable to continue providing the service corresponding to that permission. Turning off a permission does not affect the collection and use of information that was already carried out based on your authorization before it was turned off.
We may request the following system permissions: camera (scanning QR codes to bind devices; taking photos to set an avatar), photo library (selecting avatar images from your library), Bluetooth and nearby devices (connecting hardware devices), local network (transferring audio over the local network), location (obtained only at activation and device binding, to determine the service region; not used by other features), notifications (message push and transcription-completion reminders), and storage/files (exporting and backing up content).
b. Cookies and similar technologies
Cookies and similar technologies are widely used on the internet. When you use our services, we may use such technologies to send one or more cookies or anonymous identifiers ("Cookies") to your device to collect, identify, and store information about your access to and use of the product. We commit not to use Cookies for any purpose other than those described in this Privacy Policy. We use Cookies primarily to keep the products and services running securely and efficiently, to assess the security status of your account and transactions, to diagnose anomalies such as crashes and latency, and to spare you from repeatedly filling in forms or entering search terms.
We may also use Cookies to show you information or features that may interest you. Most browsers allow you to clear cached browser data; you may delete the data accordingly or reject our Cookies. Doing so may prevent you from using services or features that rely on Cookies.
2.8 Conversational AI
When you use generative AI services (including voice transcription, AI summaries, translation, AI Q&A, voiceprint recognition, and other AI services), to provide you with conversational and interactive services we may collect the following: information you actively input (including text, voice, and other content you input) and content instructions; behavioral information when you use the model (including your clicks, browsing, edits, and other operation records); and feedback you provide (including likes, dislikes, and submitted feedback). We analyze and compute the above information to better understand your needs and context, so as to return more relevant content to you (including text, transcripts, summaries, and replies).
Feedback feature: Your likes, dislikes, or problem reports on AI outputs are used solely to help us pinpoint issues and improve service quality.
We do not use your content data, such as audio data, transcripts, summaries, or voice memos, for training or optimizing AI models.
3. Partners, Entrusted Processing, Transfer, and Disclosure of Information
We process personal information in partnership scenarios in accordance with three principles: "lawful, legitimate, and minimally necessary", "safeguarding users' right to know and to decide", and "maximizing security capabilities".
3.1 Partners involved in data use
a. Basic principles: We process personal information in partnership scenarios in accordance with the three principles stated above.
b. Entrusted processing:
To enable the service features, we may entrust partners in the following categories to process certain of your information according to our instructions. We specify by contract the processing purpose, duration, method, categories of information, protective measures, and the respective responsibilities of both parties, and we supervise the processors:
Entrustment scenario | Category of partner | Description |
Cloud infrastructure | Cloud computing providers | Data storage and computing resources |
AI transcription, translation, and generation | AI model service providers | Providing speech recognition, text translation, and text generation capabilities |
App stores and payments | Apple, Google, etc. | App distribution and subscription payments |
Security and fault diagnosis | Logging and analytics services | Log aggregation and diagnostics |
Communication services | Email and message push providers | Delivery of verification codes and service notices |
Share-page hosting | Web hosting and CDN providers | Hosting the share-link pages you generate and displaying content to recipients according to your sharing settings |
c. Third-party SDKs
To enable functions such as login, payment, push notifications, and crash and analytics reporting, we have integrated SDKs and similar technologies provided by third-party service providers. The information collected by such SDKs is limited to what is necessary for their functionality, and their processing location may be outside your country or region (for example, the United States).
3.2 Transfer
If a transfer of your personal information becomes necessary due to a merger, acquisition, asset transfer, or similar event, we will require the recipient to remain bound by this Policy and to obtain your consent again before changing the processing purpose.
3.3 Public disclosure
Except in the following cases, we will not publicly disclose your personal information: (1) with your separate consent obtained in advance; (2) as required by laws and regulations, litigation, or mandatory requirements of competent government authorities.
3.4 Cessation of operations
If we cease operating the product or service, we will promptly stop collecting your personal information, notify you by direct notice or public announcement, and delete or anonymize the relevant personal information we hold.
4. Your Rights
You may submit data rights requests to QwenNote, and you may also view and manage your information through the following means. We will respond to your requests in accordance with applicable legal requirements:
4.1 Access and copying: You may view your content data such as account profile, transcripts, summaries, and voice memos, and export them yourself.
4.2 Correction and supplementation: You may update profile information such as your nickname and avatar. You may edit and correct transcripts, summaries, and speaker names yourself.
4.3 Deletion: You may delete content data individually or in bulk at any time (including transcripts, summaries, voice memos, and translation results), and may delete the hotwords and tags you added. Deleted data cannot be recovered.
4.4 Withdrawal of consent and turning off authorizations: You may unbind hardware devices, revoke share links you created, turn off non-essential system permissions, and unsubscribe from marketing messages. Withdrawing consent does not affect the validity of processing activities already carried out based on your consent before the withdrawal.
4.5 Account deletion: You may apply to close your account. Once the closure takes effect: (1) devices bound to the account are automatically unbound and all data on the devices is erased; (2) all cloud and local files and record data under the account are deleted and cannot be recovered; (3) your membership is revoked concurrently and is not refundable; (4) share links you created become invalid. Before closing your account, please make sure you have backed up important files and cancelled your membership subscription.
4.6 Restriction on automated decision-making: Our AI features generate content only per your instructions and do not make automated decisions about you. If you believe the processing result of an AI feature materially affects your rights, you may contact us for a review.
4.7 Response time: We will respond to your request within 30 days of receipt. We may ask you to provide identity verification information where necessary. If we exceed the deadline, we will explain the reasons.
5. Storage of Information
5.1 Storage location
All users' personal information and content data are stored in a unified manner in data centers located in Singapore. Related processing for AI features and the like is also performed in Singapore. Diagnostic logs are likewise stored in our log and diagnostics platform in Singapore.
5.2 Retention period
a. We retain your information only for the period necessary to achieve the purposes described in this Policy, based on: (1) statutory retention requirements for transaction and subscription records; (2) what is needed to ensure service quality; (3) the period you agree to; (4) the needs of dispute resolution and limitation periods; and (5) other requirements of laws and regulations.
b. The foregoing retention rules do not apply to recordings (the product does not retain recordings). Transcripts and derived content are retained per the period rules in item a. of this section.
c. Upon expiry of the retention period, we will delete your personal information or anonymize it.
5.3 Storage security
a. We protect the security of your information through technical and administrative measures including encrypted transmission and encrypted storage, access control, identity authentication, and operation auditing.
b. We have established a data security management system and designated a personal information protection officer, who is responsible for coordinating personal information protection and the handling of user requests (see "Contact Us" for contact details).
c. Security incident response: In the event of a security incident such as the leakage, damage, or loss of personal information, we will immediately activate our emergency response plan, take remedial measures, and report to regulators and notify you as required by law. The specific reporting and notification deadlines are governed by the legal requirements of your country or region of residence.
d. The internet environment is not absolutely secure. We recommend that you properly safeguard your account credentials and hardware devices.
6. Updates to this Policy
6.1 We may update this Privacy Policy from time to time. After an update, we will notify you conspicuously through the app or the official website. For material changes, we will provide advance notice via a pop-up or in-app message.
6.2 Material changes include: significant changes to the service model; substantive changes to the purposes or types of information processing; changes to sharing or entrustment recipients; changes to your rights and how to exercise them; changes to the operator's contact information; changes to the responsible department and contact details; and other material matters that may affect your rights and interests.
6.3 If you disagree with the updated Policy, please stop using the services and close your account. Continued use is deemed acceptance of the updated Policy.
7. Protection of Minors
7.1 QwenNote is intended for users with the relevant capacity for civil conduct. We presume that you have reached the legal age required to use the services.
7.2 If you are under 18 years of age, please use the services under the guidance of your guardian after your guardian has read and agreed to this Policy.
7.3 If a guardian finds that a minor has used the services without consent, the guardian may contact us, and after verification we will delete the relevant information and discontinue the service.
8. Contact Us
Personal information protection officer / Data Protection Officer (DPO): We have designated a dedicated person to coordinate personal information protection and the handling of user requests under this Policy. You may contact us via the email address below.
Privacy and customer service email: support01@service.qwennote.ai
Operator name: DingTalk (Singapore) Private Limited
Registered address: 51 Bras Basah Road, #03-06 Lazada One, Singapore 189554
Official website: qwennote.ai
We will respond to your inquiries or requests within 30 days of receipt (complex matters may take longer, in which case we will explain the reasons). If you are dissatisfied with our response, you may assert your rights through the dispute resolution methods set out in the QwenNote Terms of Service.
Appendix I: Definitions
1.
QwenNote: The intelligent note-taking products and services operated by DingTalk (Singapore) Private Limited, including the app, the official website, and companion hardware devices.
2.
QwenNote smart hardware device: Recording hardware devices and accessories that can be used in conjunction with the app, including the A1 and A2 series devices of all versions sold under the QwenNote brand.
3.
Hotwords: A list of proper nouns, names, or terms you add yourself, used to improve the transcription accuracy of your content.
4.
Tags: Category labels you create for content such as transcripts and summaries, used for retrieval and management.
5.
Personal information: Various information recorded in electronic or other form that can, alone or in combination with other information, identify a specific natural person or reflect the situation of a specific natural person.
6.
Anonymization: The process of technically processing personal information so that a specific natural person cannot be identified without additional information.
7.
Service log information: Records of access, requests, errors, and the like generated to ensure service operation and security.
8.
AI features: Features provided with artificial intelligence technology, including voice transcription, AI summaries, AI Q&A, content translation, and the like.
Appendix II: Supplemental Disclosures for Users in Japan
This Appendix lists only the information that must additionally be provided to users in Japan under Japan's Act on the Protection of Personal Information (the "APPI") and that is not covered in the main body. Matters of general application already set out in the main body (operating entity, purposes of use, data subject rights, security management, etc.) are not repeated.
1.
Provision to a third party in a foreign country (transfer to Singapore): Where the business operator (i.e., DingTalk (Singapore) Private Limited identified in this Policy) is registered in Singapore, your personal information and content data will be transferred to, and stored and processed in, data centers located in Singapore, which constitutes a provision to a third party located outside Japan. Pursuant to Article 28 of the APPI, we notify you of the following with respect to this foreign provision: (1) the country where the recipient is located: Singapore; (2) an overview of Singapore's personal information protection system: Singapore's core personal information protection law is the Personal Data Protection Act 2012 (PDPA), enforced by the Personal Data Protection Commission (PDPC), which contains rules on obtaining consent, purpose limitation, protection obligations, restrictions on cross-border transfers, and individuals' rights of access and correction (Singapore has not been designated by Japan under the APPI as a country with an equivalent level of protection); (3) the measures taken by the recipient to prevent personal information from being used by an uncontrolled third party: encrypted transmission and storage, access control and identity authentication, operation audit trails, and entrustment agreements with processors that stipulate protection obligations and oversight clauses; and (4) you may request that we cease the foreign provision via the email address listed under "Contact Us" (note that after cessation, you may be unable to continue using the relevant features or services that depend on such processing). By checking to consent to this Policy, you are deemed to have given the consent required under Article 28 of the APPI to the foreign provision to Singapore described above.
2.
Breach reporting (PPC): In the event of a personal information breach or similar incident that may infringe individuals' rights and interests, we will report to the Personal Information Protection Commission (PPC) within the prescribed timeframes under PPC rules (in principle, a preliminary report within 3–5 days and a final report within 30 days) and notify you.
