iGulu App Privacy Policy

How This Policy Applies
This Privacy Policy explains how iGulu collects, uses, shares, and protects your personal information when you use the iGulu smart brewing machine application and related services (the "App").

The App is intended for use in multiple regions, and the data controller responsible for your information depends on where you are located: Your personal information is stored and processed within your own region. We do not transfer your personal information across these regions. Where any limited cross-border processing is unavoidable, we rely on appropriate legal safeguards (such as the EU Standard Contractual Clauses) as described in Section 7.

Effective Date: 2026-05-29

Last Updated: 2026-05-29

Part 1: Privacy Policy (EEA, United States, Canada & other non-Chinese regions)

1. Age Restriction

1.1 The App is associated with an alcoholic-beverage brewing product. You must be at least 21 years of age to create an account or use the App. The App is not directed to, and we do not knowingly collect personal information from, anyone under 21.

1.2 If we learn that we have collected personal information from a person under 21, we will delete that information promptly. If you believe a minor has provided us with personal information, please contact us using the details in Section 12.

2. Scope and Acceptance

2.1 This Policy applies to personal information we process about you in connection with the App. By creating an account or using the App, you acknowledge that you have read this Policy. Where the law requires consent (for example, for certain processing under the GDPR), we will ask for it separately and you may withdraw it at any time.

2.2 This Policy should be read together with the iGulu App User Agreement.

3. Personal Information We Collect

We collect the following categories of information:

CategoryExamplesSource
Account & identity dataEmail address and unique identifier shared by your third-party login provider (Apple, Google, etc.); optional profile details (display name, avatar) where you choose to provide themYou / third-party login provider
Device control & usage dataBrewing settings and changes you make, brewing history and logs, configuration and status information published by your connected brewing machineYou / your connected device
Technical & diagnostic dataPhone brand, model, operating system version, app version, crash and performance logs, network statusAutomatically collected
Optional feature dataLocation, camera/photos, and media you upload — only where you grant the relevant permission for a specific featureYou (with permission)
Support dataContact details and the content of communications when you contact customer supportYou

3.1 You can use the core functions of the App without granting optional permissions (location, camera, photos). Declining these permissions only disables the specific features that depend on them.

3.2 We do not currently use advertising or third-party advertising technologies, and we do not sell or "share" your personal information for cross-context behavioral advertising. If this changes in the future, we will update this Policy, notify you in advance, and — where required by law — obtain your consent before any such processing begins.

4. How We Use Your Information and Our Legal Bases

For users in the EEA, we process personal information only where we have a legal basis to do so under the GDPR. The table below explains our purposes and the corresponding legal basis.

PurposeLegal basis (GDPR)
Create and manage your account; provide core App and device-control functionsPerformance of a contract
Maintain security, prevent fraud, and verify identityLegitimate interests / legal obligation
Diagnose problems, improve and develop the AppLegitimate interests
Provide customer supportPerformance of a contract / legitimate interests
Use optional features requiring device permissions (location, camera, media)Consent
Comply with legal and regulatory obligationsLegal obligation

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

5. How We Share Your Information

5.1 We do not sell your personal information. We share it only as follows:

5.2 We do not transfer your personal information between the regional controllers identified above.

6. Third-Party SDKs

To deliver push notifications, the App may integrate third-party push SDKs. These SDKs may collect limited technical information (such as network status, device identifiers, and, for certain providers, approximate location) solely to deliver notifications. The relevant providers and their privacy policies are listed in the regional/store-specific disclosures within the App. Where these SDKs are active in your region, we request the permissions they require and you may disable notifications at any time in your device settings.

7. International Transfers

We store and process your personal information within your region (EEA, United States, or Canada respectively). Where any transfer of personal information outside the EEA is necessary, we implement an appropriate safeguard recognised under the GDPR, such as the European Commission's Standard Contractual Clauses (SCCs), and we take steps to ensure your information continues to receive an adequate level of protection. You may request a copy of the relevant safeguard using the contact details in Section 12.

8. Data Retention

8.1 We retain your personal information for as long as your account is active and as needed to provide the App.

8.2 If your account is inactive for a continuous period of twelve (12) months, we treat it as dormant. We will delete or anonymise your login and related account data within ninety (90) days after the dormancy period begins, unless a longer retention period is required by law (for example, for tax, accounting, or legal-compliance purposes).

8.3 When you delete your account, we delete or anonymise your personal information except where retention is legally required.

9. Your Privacy Rights

9.1 EEA (GDPR)

You have the right to: access your personal information; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent. You also have the right to lodge a complaint with your local data protection authority.

9.2 United States (including California — CCPA/CPRA)

Depending on your state of residence, you may have the right to: know what personal information we collect and how we use it; access and obtain a copy of your personal information; correct inaccurate information; and delete your personal information. We do not sell or share your personal information for cross-context behavioral advertising, and we do not use or disclose sensitive personal information beyond the purposes permitted by law. We will not discriminate against you for exercising these rights.

9.3 Canada (PIPEDA)

You have the right to access the personal information we hold about you, to request correction, and to withdraw consent (subject to legal or contractual restrictions and reasonable notice).

9.4 Exercising your rights

To exercise any of these rights, contact us using the details in Section 12. We will verify your request and respond within the timeframe required by applicable law (generally within 30 days, extendable where permitted). We do not charge a fee for reasonable requests but may decline requests that are manifestly unfounded, excessive, or repetitive.

10. How We Protect Your Information

10.1 We use technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS) and at rest, access controls, data minimisation, and security monitoring and auditing. We require our employees and processors to maintain confidentiality.

10.2 No method of transmission or storage is completely secure. While we work to protect your information, we cannot guarantee absolute security.

10.3 If a personal data breach occurs, we will notify affected users and the relevant authorities where and within the time periods required by applicable law.

11. Cookies and Similar Technologies

The App is a mobile application and does not rely on browser cookies for its core functions. We may use limited local storage and device identifiers for authentication, security, and diagnostics. We do not currently use cookies or similar technologies for advertising. If we introduce any analytics or advertising technologies in the future, we will update this Policy and, where required, obtain your consent.

12. Changes to This Policy

We may update this Policy from time to time. For material changes, we will provide prominent notice (for example, an in-app notice) before the changes take effect and, where required by law, obtain your consent. Previous versions will be archived and available on request.

13. How to Contact Us

For privacy questions or to exercise your rights, contact the controller for your region:

第二部分:中华人民共和国(中国大陆)地区适用条款

制定主体:爱咕噜(上海)智能科技有限公司

更新日期:2026年05月29日

生效日期:2026年05月29日

特别提示
本部分仅适用于在中国大陆地区使用本 App 的用户。我们遵循合法、正当、必要和诚信原则,依据《个人信息保护法》(PIPL)等中国法律法规处理您的个人信息。本 App 与酒精饮品相关,仅向 21 周岁以上人士开放,请您在使用前仔细阅读并自主选择。

一、年龄限制

本 App 与酒精饮品酿造产品相关,仅向 21 周岁以上人士开放。我们不会故意收集 21 周岁以下人士的个人信息。如发现相关情形,我们将尽快删除。

二、我们如何收集和使用您的个人信息

2.1 核心定义

个人信息是以电子或其他方式记录的与已识别或可识别自然人有关的各种信息,不包括匿名化处理后的信息。敏感个人信息是一旦泄露或非法使用,容易导致自然人人格尊严受到侵害或人身、财产安全受到危害的个人信息,包括生物识别、宗教信仰、特定身份、医疗健康、金融账户、行踪轨迹等信息。

2.2 我们收集的信息

2.3 必须授权收集的情形(核心功能)

2.4 自主选择提供的情形(扩展功能)

不提供以下信息不影响核心功能:基于位置/相机/相册/图片视频上传的功能,需您单独授权;补充账户信息(生日、性别等)。

2.5 关于广告

我们目前使用广告或第三方广告技术,也不会将您的个人信息用于广告目的。未来如引入相关功能,我们将更新本政策、事先告知,并在法律要求时另行取得您的同意。

2.6 数据存储与处理

中国大陆用户的个人信息存储和处理于中国境内服务器。我们不会将该等信息跨区域传输至境外控制主体。

2.7 数据保留

您账户处于活跃状态期间,我们将保留相关数据。连续 12 个月未登录的账户视为休眠;休眠满 90 天后,我们将删除或匿名化您的登录及相关账户数据,但法律另有要求的除外。

三、我们如何共享、转让、公开披露您的个人信息

3.1 我们遵循「合法正当、最小必要、目的明确」原则,仅在您明确同意、法定要求、实现核心服务等情形下共享,受托方无权将信息用于其他用途。

3.2 原则上不向第三方转让,仅在您明确同意或企业合并、收购、破产清算时转让,并要求受让方继续遵守本政策。

3.3 仅在法律法规要求、诉讼/争议解决需要,或您明确同意时公开披露。

四、我们如何保护您的个人信息

互联网环境并非绝对安全。发生个人信息安全事件后,我们将按法律法规要求告知您并向监管部门报告。

五、您如何管理您的个人信息

您依法享有访问、更正、删除个人信息,改变/撤回同意及注销账户的权利。您可随时操作账户信息,或联系我们处理。撤回同意后,我们将无法继续提供对应服务。账户注销后信息将被删除或匿名化(法定情形除外),且无法恢复。我们将在 30 天内回复您的请求。

六、我们如何处理未成年人的个人信息

本 App 仅向 21 周岁以上人士开放,我们不主动收集未成年人个人信息。如发现未成年人在未获监护人同意情况下提供个人信息,我们将尽快删除。对不满 14 周岁儿童的信息,严格遵循《儿童个人信息网络保护规定》处理。

七、第三方 SDK

为实现消息推送功能,本 App 可能接入第三方推送 SDK,其可能收集网络状态、设备标识符等有限技术信息用于推送。具体 SDK 名称及其隐私政策以 App 内相应说明为准。您可随时在设备设置中关闭通知。

八、本政策如何更新

本政策可能适时更新。重大变更将通过显著方式(如 App 内特别提示)在生效前通知您;未经您明确同意,不会削减您的权利。旧版本将存档供查阅。

九、如何联系我们

我们将在 30 天内回复并协助解决问题。若您对回复不满意,可向爱咕噜(上海)智能科技有限公司所在地人民法院提起诉讼,或向网信、市场监管、公安等部门投诉举报。

附件:核心术语定义

1. 匿名化:通过技术处理使个人信息主体无法被识别,且信息无法复原的过程。

2. 去标识化:个人信息经处理后,不借助额外信息无法识别特定自然人的过程。

3. 设备信息:包括设备标识符、设备型号、系统信息、网络环境信息等。

4. 儿童:指未满十四周岁的未成年人。