Movira 隐私政策
本政策仅适用于 Movira 移动应用程序(iOS),不适用于 StepBeat 官方网站。StepBeat 官方网站的隐私政策为 stepbeattech.com/privacy.html。
引言
Movira(以下称“本应用”)是一款跑步训练管理工具,由StepBeat Tech(以下称“我们”)开发和运营。
我们深知个人信息对您的重要性。本政策说明我们收集哪些信息、为什么收集、如何使用和保护,以及您对这些信息拥有哪些权利。请您在使用本应用前完整阅读本政策。
本政策依据用户所在国家或地区适用的个人信息保护、数据安全和网络安全法律法规及相关标准制定。
本政策对应当前版本的功能范围:训练计划管理、配速计算器、账号管理。若后续版本新增功能并涉及新的信息收集,我们会先更新本政策。
一、我们收集的信息
我们遵循最小必要原则:只收集实现具体功能所必需的信息。以下是完整清单。
表中标注 † 的项,是服务器在通信过程中自动获得的,不由应用主动采集上报。
1.1 您主动提供的信息
| 信息类型 | 具体内容 | 收集场景 | 为什么需要 |
|---|---|---|---|
| 电子邮箱 | 邮箱地址 | 注册 / 登录 | 本应用的唯一登录凭证。我们不设置密码,通过向您的邮箱发送验证码完成身份验证 |
| 账号资料 | 用户名(昵称)、国家/地区、个人简介 | 注册时填写;用户名与个人简介可在“我的 → 编辑资料”中修改 | 用户名与个人简介用于账号展示;国家/地区记录为您的账号归属地区(后端账号必填属性) |
| 头像图片 | 您选择上传的头像 | 注册时,或在“我的 → 编辑资料”中更换 | 账号展示 |
| 训练数据 | 训练计划、课表安排、训练阶段类型 | 使用“训练”功能 | 本应用的核心功能。用于生成、保存和同步您的训练安排 |
| 偏好设置 | 距离/身高/体重/温度四项单位、界面语言 | 在“我的 → 设置”中调整 | 使您的偏好在更换设备或重装后仍然保留 |
| 意见反馈 | 反馈正文、联系方式(自由文本)、截图 | 主动提交反馈时 | 处理并回复您的问题 |
关于“联系方式”:反馈表单中的联系方式是一个自由文本框,可以留空。我们不强制要求,也不将其作为手机号单独采集或结构化存储。
关于账号资料的修改:注册后,您可在应用内修改头像、用户名、个人简介。国家/地区在注册时选择,注册后不可自行修改,如需变更请通过下方联系方式联系我们。
1.2 自动收集的信息
| 信息类型 | 具体内容 | 为什么需要 |
|---|---|---|
| 账号标识 | 系统为您生成的用户 ID | 关联您的数据;所有需登录的接口凭此识别账号 |
| 设备标识 | 应用生成的设备标识符 | 用于建立加密通信通道、识别登录设备 |
| 设备诊断信息 | 设备型号、操作系统版本 | 随每次网络请求上报,用于排查兼容性问题与故障定位 |
| IP 地址 † | 访问来源 IP | 用于服务端限流防刷、安全审计与故障排查。我们可能对 IP 地址进行粗略地域解析,以识别用户所在的国家或地区;仅在适用法律允许且相关功能启用的地区显示粗略地域信息,其他地区不显示。非显示地区的解析结果不用于用户画像或广告投放,并不长期保存。 |
设备诊断信息的使用边界:这两项目前仅用于功能实现与故障排查,不用于任何统计分析或用户画像。若未来我们要将其用于统计,会先更新本政策并同步更新 App Store 隐私声明。
二、我们不收集的信息
以下内容我们明确不收集。这不是承诺性表述,而是可以通过应用行为验证的事实:
- 设备定位数据。本应用未申请任何定位权限,代码中不包含设备定位能力,不会读取您设备的 GPS 或系统定位。您在训练信息中填写的地点是您手动输入的文本,不是设备定位的产物。服务器对 IP 地址进行的粗略地域解析不等同于读取设备定位,也不会用于精确定位、用户画像或广告投放。
- 运动轨迹、心率等体征数据。目前本应用不提供跑步实时记录功能,不采集、不上传任何 GPS 轨迹或心率数据。
- 手机号码。本应用的资料页没有手机号输入项,也不会向服务端发送手机号。
- 身份证件信息。目前本应用不提供实名认证功能。
- 健康 App / HealthKit 数据。本应用未接入 HealthKit。
- 通讯录、日历、麦克风、摄像头。本应用未申请上述任何权限。
- 用于广告或跨应用追踪的任何数据。本应用不含任何广告 SDK、不做用户追踪,未申请 App 跟踪透明度(ATT)授权。
三、系统权限说明
| 权限 | 何时申请 | 用途 | 拒绝的后果 |
|---|---|---|---|
| 照片图库(读取) | 您主动点击“更换头像”“添加反馈截图”时 | 让您从相册中挑选图片 | 无法通过相册选图,其他功能不受影响 |
| 照片图库(写入) | 您主动保存图片时 | 将图片保存到您的相册 | 无法保存图片,其他功能不受影响 |
我们不会在启动时申请任何权限,所有权限都由您的具体操作触发,且拒绝后可继续使用应用的其余功能。
四、我们如何使用这些信息
我们仅将收集的信息用于以下目的:
- 提供核心功能:账号登录、训练计划管理、配速计算;
- 保障账号与服务安全:验证码校验、登录频率限制、防止账号被暴力破解;
- 处理您的反馈:回复您通过反馈功能提交的问题;
- 履行法定义务:按照法律法规要求保存必要的日志记录。
我们不会将您的信息用于自动化决策、用户画像、精准营销或广告投放。
五、信息的存储
- 存储地点:您的个人信息可能存储和处理于多个国家或地区的服务器及服务设施中。为提供和维护服务,您的个人信息可能在不同国家或地区之间传输。我们将根据适用法律采取必要的安全措施,并履行适用的跨境数据传输义务。
- 本地存储:为支持部分功能和提升使用体验,部分数据可能会暂存在您的设备上。我们会采取适当的技术和管理措施保护本地缓存及登录凭证,防止未经授权的访问、使用或披露。
- 保存期限:在您的账号存续期间,我们持续保存您的信息以提供服务。您注销账号后按第七条处理。服务器访问日志采用按文件大小滚动覆盖的方式保存(单个日志文件上限 5MB,仅保留最近 5 个文件,写满后自动覆盖最旧的一个),不设固定保存天数;实际留存时长取决于访问量,访问量越大覆盖越快。
六、信息的对外提供
我们不出售、不出租您的个人信息。
我们仅在以下必要情形下委托第三方处理部分信息,且已与其签订数据处理协议、要求其按本政策约定处理:
| 受托方 | 处理的信息 | 目的 |
|---|---|---|
| 阿里云计算有限公司 | 您上传的图片(头像、反馈截图) | 对象存储服务(OSS) |
| 阿里云邮件推送(DirectMail) | 您的邮箱地址、验证码内容 | 发送登录验证码邮件 |
| 阿里云计算有限公司 | 全部服务端数据 | 云服务器托管 |
除上述情形外,我们仅在下列情况下对外提供信息:
- 事先获得您的单独同意;
- 依据法律法规、司法机关或行政机关的强制性要求;
- 为维护您或社会公众的重大合法权益且难以事先取得您同意的紧急情况。
七、您的权利
依据用户所在国家或地区适用的数据保护法律,您可能对自己的个人信息享有以下权利:
| 权利 | 如何行使 |
|---|---|
| 查阅 | 在“我的”页面查看您的账号资料与训练数据 |
| 更正 | 头像 / 用户名 / 个人简介可在“我的 → 编辑资料”中直接修改;其余资料请联系我们 |
| 删除 / 注销账号 | 在“我的 → 设置 → 删除账号”中操作,见下方说明 |
| 撤回同意 | 在 iOS 系统设置中撤回已授予的相册权限;或注销账号 |
| 获取副本 / 转移 | 通过下方联系方式向我们提出 |
| 投诉 | 通过下方联系方式向我们提出;您也有权向网信部门等监管机构投诉 |
关于账号注销(请务必阅读)
注销是立即、彻底、不可撤销的。
- 为确认是本人操作,注销需要通过邮箱验证码二次验证;
- 验证通过后,您的账号及关联数据将被立即物理删除,没有冷静期或宽限期;
- 删除后无法恢复,我们也无法为您找回;
- 您上传的图片文件(头像、反馈截图)会在账号删除时一并进入清除队列,由后台任务从对象存储中删除。该清除是异步执行的,通常在短时间内完成。
请在操作前确认您已备份需要保留的内容。
服务器日志的例外(请一并了解)
上述“彻底删除”针对的是您的账号与业务数据。第五条提到的服务器访问日志是按访问流水逐条记录、按文件大小滚动覆盖的,其中可能包含您过往请求的 IP、设备型号与系统版本,不随账号删除而即时清除,而是随日志轮转被自动覆盖。这部分记录不与您已删除的账号关联,也不用于任何用户画像。
八、信息安全
我们采取合理的技术和管理措施保护您的个人信息,包括:
- 加密保护:对个人信息的传输和存储采取适当的加密措施;
- 访问控制与审计:按照最小权限原则控制信息访问,并对重要操作进行记录和审计;
- 账户安全:通过验证码有效期、尝试次数和访问频率限制等措施保护账户安全;
- 日志保护:采取措施避免在日志中记录密码、验证码、访问令牌等敏感凭证。
尽管如此,请理解互联网环境不存在绝对安全。如发生个人信息泄露等安全事件,我们将按法律法规要求及时向您和监管部门告知。
九、未成年人保护
本应用面向年满 16 周岁的用户。注册时,您需要确认自己已年满 16 周岁;未满 16 周岁的用户不得注册或使用本应用。本应用不会要求您上传身份证件或进行生物识别年龄认证。
- 对于 16 至 17 周岁的用户,如其所在国家或地区的法律要求取得监护人同意,应在取得相应同意后使用本应用。
- 如我们发现未满 16 周岁的用户注册或使用本应用,将尽快删除相关信息并注销对应账号。
监护人如对儿童个人信息有疑问,或希望查阅、更正、删除被监护人的个人信息,可通过下方方式联系我们。
十、本政策的变更
我们可能适时修订本政策。变更涉及您的重要权利时(如收集范围扩大、使用目的变更),我们会在应用内以显著方式通知您,并在必要时重新征得您的同意。
十一、联系我们
如您对本政策有任何疑问、意见或投诉,或希望行使上述权利,可通过以下方式联系:
- 电子邮箱:support@stepbeattech.com
- 运营主体:深圳市步频共振科技有限公司
- 应用内路径:我的 → 意见反馈
我们将在收到您的请求后 15 个工作日内予以答复。
Movira · 备案号:粤ICP备2026103885号-3A
Movira Privacy Policy
This policy applies only to the Movira mobile application (iOS), not to the StepBeat corporate website. The website's privacy policy is at stepbeattech.com/privacy.html.
Introduction
Movira (the “App”) is a running training management tool developed and operated by StepBeat Tech (“we”, “us”, “our”).
We understand how important your personal information is. This policy explains what we collect, why we collect it, how we use and protect it, and what rights you have over it. Please read this policy in full before using the App.
This policy is prepared in accordance with the personal information protection, data security and cybersecurity laws, regulations and relevant standards applicable in the user’s country or region.
This policy describes the features currently provided by the App: training plan management, a pace calculator, and account management. If a future version adds features that involve collecting new information, we will update this policy first.
1. Information We Collect
We follow the principle of data minimization: we collect only what a specific feature actually requires. The list below is complete.
Items marked † are observed automatically by the server during communication; they are not actively collected and sent by the App.
1.1 Information You Provide
| Type | What exactly | When collected | Why we need it |
|---|---|---|---|
| Email address | Your email address | Sign-up / sign-in | The App's only login credential. There is no password; we verify your identity by emailing you a one-time code |
| Profile data | Username (display name), country/region, bio | Entered at sign-up; username and bio can be changed under “Profile → Edit Profile” | Username and bio are for account display; country/region is recorded as a required attribute of your account (your account region) |
| Profile photo | The avatar image you choose to upload | At sign-up, or when you change it under “Profile → Edit Profile” | Account display |
| Training data | Training plans, session schedules, workout phase types | When you use the “Training” feature | The App's core feature. Used to generate, store and sync your training schedule |
| Preferences | Your four unit settings (distance, height, weight, temperature) and interface language | When you adjust them under “Profile → Settings” | So your preferences survive a device change or reinstall |
| Feedback | Feedback text, contact details (free text), screenshots | When you submit feedback | To process and respond to your issue |
About the “contact details” field: the contact field in the feedback form is free text and may be left blank. We do not require it, and we do not collect or store it as a structured phone number.
About editing your profile: after sign-up you can change your avatar, username and bio in the App. Country/region is chosen at sign-up and cannot be changed after registration; to change it, please contact us using the details below.
1.2 Information Collected Automatically
| Type | What exactly | Why we need it |
|---|---|---|
| Account identifier | A user ID generated for you by the system | To associate your data; every authenticated endpoint identifies your account by it |
| Device identifier | An identifier generated by the App | To establish the encrypted communication channel and to recognise your signed-in devices |
| Device diagnostics | Device model, operating system version | Sent with each network request, used for compatibility troubleshooting and fault diagnosis |
| IP address † | The IP address a request comes from | Server-side rate limiting, security auditing and troubleshooting. We may perform approximate geolocation processing to identify the user’s country or region. Approximate regional information is displayed only where permitted by applicable law and where the relevant feature is enabled; it is not displayed in other regions. Results for regions where the information is not displayed are not used for profiling or advertising and are not retained long-term. |
Boundaries on device diagnostics: these two values are currently used only for functionality and troubleshooting — never for analytics, statistics or profiling. If we ever want to use them for statistics, we will update this policy and the App Store privacy disclosure first.
2. Information We Do Not Collect
We explicitly do not collect the following. These are not aspirational promises — each can be verified from the App's behaviour:
- Device location data. The App requests no location permission and contains no device-location capability; it never reads your device's GPS or system location. Any place name you enter in training information is text you typed yourself, not a product of device positioning. Approximate IP geolocation performed by our servers is not device location and is not used for precise location tracking, profiling or advertising.
- Running routes, heart rate or other biometric data. The App currently has no live run-recording feature; it does not collect or upload any GPS track or heart rate data.
- Phone numbers. The profile screen has no phone number field, and the App never sends a phone number to the server.
- Identity document information. The App currently has no real-name verification feature.
- Apple Health / HealthKit data. The App does not integrate with HealthKit.
- Contacts, calendar, microphone or camera. The App requests none of these permissions.
- Any data used for advertising or cross-app tracking. The App contains no advertising SDK and performs no user tracking; it does not request App Tracking Transparency (ATT) authorisation.
3. System Permissions
| Permission | When requested | Purpose | If you decline |
|---|---|---|---|
| Photo library (read) | Only when you tap “Change avatar” or “Attach a screenshot” | To let you pick an image from your library | You cannot pick images from the library; everything else works normally |
| Photo library (add) | Only when you actively save an image | To save an image to your library | You cannot save images; everything else works normally |
We never request permissions at launch. Every permission is triggered by a specific action of yours, and declining any of them still leaves the rest of the App usable.
4. How We Use This Information
We use the information we collect only to:
- Provide core features: sign-in, training plan management, pace calculation;
- Keep your account and our service secure: verification code checking, sign-in rate limiting, preventing brute-force attacks on accounts;
- Handle your feedback: responding to issues you submit through the feedback feature;
- Meet legal obligations: retaining the log records required by applicable law.
We do not use your information for automated decision-making, user profiling, targeted marketing or advertising.
5. Where Your Information Is Stored
- Storage location: your personal information may be stored and processed in servers and service facilities across multiple countries or regions. To provide and maintain the App, your personal information may be transferred between different countries or regions. We will implement appropriate security measures and comply with applicable requirements for cross-border data transfers.
- On-device storage: to support certain features and improve the user experience, some data may be temporarily stored on your device. We use appropriate technical and organisational measures to protect locally cached data and sign-in credentials against unauthorised access, use or disclosure.
- Retention: while your account exists, we retain your information in order to provide the service. After you delete your account, section 7 applies. Server access logs are kept on a size-based rolling basis (each log file is capped at 5 MB and only the 5 most recent files are kept; the oldest is overwritten automatically), with no fixed retention period in days — how long a given entry survives depends on traffic volume.
6. Disclosure to Third Parties
We do not sell or rent your personal information.
We entrust parts of the processing to the following service providers only where necessary. We have data processing agreements in place with each and require them to handle information in line with this policy:
| Recipient | Information processed | Purpose |
|---|---|---|
| Alibaba Cloud Computing Ltd. | Images you upload (avatar, feedback screenshots) | Object storage (OSS) |
| Alibaba Cloud DirectMail | Your email address and verification code content | Sending sign-in verification emails |
| Alibaba Cloud Computing Ltd. | All server-side data | Cloud server hosting |
Beyond the above, we disclose information only when:
- we have your separate, explicit consent;
- disclosure is mandated by law, or by a judicial or administrative authority;
- it is necessary in an emergency to protect the vital lawful interests of you or the public and consent cannot reasonably be obtained beforehand.
7. Your Rights
Under the data protection laws applicable in your country or region, you may have the following rights over your personal information:
| Right | How to exercise it |
|---|---|
| Access | View your profile and training data on the “Profile” screen |
| Correction | Avatar / username / bio can be edited directly under “Profile → Edit Profile”; for the rest, contact us |
| Deletion / account closure | Use “Profile → Settings → Delete Account” — see the note below |
| Withdraw consent | Revoke the photo library permission in iOS Settings, or delete your account |
| Obtain a copy / portability | Request it from us using the contact details below |
| Complain | Contact us using the details below; you may also complain to the competent regulator |
About Account Deletion (please read)
Deletion is immediate, complete and irreversible.
- To confirm it is really you, deletion requires a second verification via an emailed code;
- once verified, your account and its associated data are physically deleted immediately — there is no cooling-off or grace period;
- deleted data cannot be restored, not even by us;
- images you uploaded (avatar, feedback screenshots) are queued for removal from object storage when your account is deleted, and removed by a background job. That removal runs asynchronously and normally completes shortly afterwards.
Please make sure you have backed up anything you want to keep before proceeding.
One exception: server logs
The “complete deletion” above covers your account and business data. The server access logs described in section 5 are written per request and rotate on a size basis. They may contain the IP address, device model and OS version from your past requests, and are not erased immediately when you delete your account — they are overwritten automatically as logs rotate. Those records are not linked to your deleted account and are not used for profiling.
8. Information Security
We use reasonable technical and organisational measures to protect your personal information, including:
- Encryption: we use appropriate encryption measures for data transmission and storage;
- Access control and auditing: access is controlled according to the principle of least privilege, and important operations are logged and audited;
- Account security: measures such as verification-code expiry, attempt limits and request-rate controls help protect accounts;
- Log protection: we take measures to avoid recording passwords, verification codes, access tokens and similar credentials in logs.
However, no system connected to the Internet can be guaranteed to be completely secure. If a personal information security incident occurs, we will take appropriate measures in accordance with applicable law and notify you and the relevant authorities where required.
9. Minors
The App is intended for users aged 16 and above. During registration, you must confirm that you are at least 16 years old. Users under the age of 16 may not register for or use the App. The App does not require identity documents or biometric age verification.
- Users aged 16 or 17 must obtain parental or guardian consent where required by the laws of their country or region.
- If we discover that a user under 16 has registered for or used the App, we will delete the relevant information and close the account as soon as possible.
Guardians with questions about a child's personal information — or who wish to access, correct or delete it — can contact us using the details below.
10. Changes to This Policy
We may revise this policy from time to time. Where a change materially affects your rights (for example, an expansion of what we collect or a change of purpose), we will notify you prominently within the App and, where required, seek your consent again.
11. Contact Us
If you have any question, comment or complaint about this policy, or wish to exercise any of the rights above:
- Email: support@stepbeattech.com
- Operating entity: Shenzhen StepBeat Technology Co., Ltd.
- In the App: Profile → Feedback
We will respond within 15 working days of receiving your request.
Movira · ICP filing no.: 粤ICP备2026103885号-3A