DMUT Privacy Policy
Version: 2026-07-31 Effective: 31 July 2026
在地量化(温州)数据科学有限公司 (Unified Social Credit Code 91330302MAECM2C72U, “we” or “us”) is the personal information processor for DMUT account, software authorization, website, update and support services. This Policy explains what we process, why, for how long, with whom, and how you can exercise your rights.
DMUT is local-first. Project files, conversation content and model keys normally remain on your device. With a BYOK cloud model, the request normally goes directly from your device to the provider you select and does not pass through the DMUT authorization service.
1. Information and retention
| Context | Information | Purpose | Retention |
|---|---|---|---|
| Account and invitation | Email, name/display name, region, invitation and account state | Registration, verification, access and notices | During the relationship; deleted or anonymized within 180 days after it ends unless law requires otherwise |
| Authorization | License, plan, term, seats, irreversible device-fingerprint hash, device name/state and activation events | Entitlement checks, two-device limit, abuse prevention and offline grace | While valid; processed within 180 days after expiry, revocation or deletion |
| Quote and enterprise inquiry | Contact, company, work email, region, seats, message and consent record | Reply, quote and contracting | 180 days after closure; transaction rules apply if an order results |
| Order and contract | Quote, order, refund, invoice, contract and necessary payment state; no full card data | Settlement, refund, accounting and disputes | At least three years after completion, or longer where tax/accounting law requires |
| Service and security logs | Time, network address, client version, result code, session/audit ID and admin action | Operation, diagnostics, defence and audit | Ordinary logs 30 days; security and admin audit logs 180 days |
| Update service | Version, Global/CN channel, platform/architecture and check result | Return the right update and manage rollout | Ordinary logs 30 days; no Project content is collected for this purpose |
| Support and security | Email, ticket, attachment and handling record | Support, complaints, vulnerabilities and incidents | 180 days after closure, longer where a dispute or law requires |
| Website access | Network, browser/device basics, time, page and security logs | Delivery, security and diagnostics | Usually 30 days; security-event records may be kept for 180 days |
Do not submit model API keys, passwords, state secrets or unrelated sensitive information through quote, support or authorization forms.
2. Legal bases
We process information where necessary to enter into or perform a contract with you; to fulfil legal duties or protect life, health or property in an emergency; within a reasonable scope for information lawfully made public; with consent or separate consent; or under another basis provided by law. Optional information may be refused, but the related optional function may then be unavailable. Required authorization data is necessary to issue and maintain a license.
3. Local content, models and tools
Project content, conversations, workflows, model settings and API keys are handled locally by default. Keys should be stored in the operating-system credential store or another location identified by the product. A cloud-model request sends the prompt, selected attachment, output and necessary technical information directly to the selected provider, which may be an independent processor under its policy. A local model is restricted to loopback addresses. Tools process only the objects required by your instruction and permissions.
Unless you voluntarily attach redacted material to a support ticket, the authorization service does not receive Project files, conversation content, prompts, outputs or API keys. We do not train general-purpose models on your private work.
4. Service providers and recipients
| Provider | Information | Use and location |
|---|---|---|
| Vercel | Website/API requests and necessary network/runtime logs | Global website delivery; authorization compute in Singapore |
| Supabase | Account, invitation, device, entitlement, consent and audit data | Database region in Singapore |
| Resend | Recipient, message, delivery state and necessary account/log metadata | Sending may use Tokyo; account, email metadata, logs or API records may be processed in the United States |
| Model provider selected by you | Prompt, attachment, output and necessary technical data | Direct connection from your device; location and rules are controlled by that provider |
We do not sell personal information. When law requires notice and separate consent before providing information to another processor, we will identify the recipient, contact, purpose, method and categories. A corporate transaction may transfer information only with notice and continuing protection.
5. Sensitive information and children
Routine DMUT services are not designed to collect sensitive personal information. Device names, support attachments or model inputs can nevertheless contain it; minimize such data. Where necessary, we explain necessity and impact, obtain separate consent and apply stricter protection.
We do not knowingly offer account services to children under 14. If we learn that such information was processed without guardian consent, we will delete it or take another legally required measure. Guardians can contact privacy@localqds.com.
6. Cross-border processing and separate consent
Because the current authorization, database and email infrastructure is outside mainland China, a CN user’s email, invitation/license record, device-fingerprint hash, consent record, quote/support content and necessary logs may be transferred to Singapore, Japan or the United States as described above.
Where required, the submission or activation interface records separate consent after displaying the overseas recipient, purpose, method, categories and rights channel. We conduct and retain personal-information protection impact assessments and use the legally applicable standard contract, certification, security assessment or other mechanism. You may refuse; the current online account, authorization, quote email and support functions may then be unavailable. Local offline functions depend on the product.
Selecting an overseas model or intentionally sending data to an overseas third party also invokes that provider’s rules. The CN edition lists only mainland-China endpoints and local loopback connections.
7. Cookies
The static public website does not use advertising-profile cookies. Infrastructure providers may process necessary network data for security, load and diagnostics. Non-essential analytics or marketing technologies will be separately disclosed and consented to where required.
8. Security and incidents
We use transport encryption, least privilege, key separation, device hashes, access controls, audit, backups and vulnerability response. No internet service is absolutely secure; protect your email, device and model keys and install security updates.
If personal information is or may be leaked, altered or lost, we take immediate remedial measures and provide legally required notice and reporting. Notice describes the categories, likely impact, response, recommended precautions and contact.
9. Your rights
Subject to law, you can be informed; decide, restrict or object; access and copy; correct and supplement; delete; close the account; withdraw consent; and request an explanation. If automated decision-making materially affects you, you can request an explanation and object to a solely automated decision.
Email privacy@localqds.com with the account email, request type and only the identity evidence necessary for verification. We normally respond within 15 working days and explain any justified extension. Withdrawal does not invalidate earlier consent-based processing or necessary processing based on another lawful ground. A refusal will include reasons and available complaint channels.
10. Deletion and updates
When a period expires, a purpose is fulfilled, consent is withdrawn without another basis, service ends or law requires deletion, we delete or anonymize the data. If immediate deletion is technically impracticable, processing is limited to storage and necessary security until deletion. Backups are cleared through their rotation cycle.
Material policy changes receive a new version, effective date and reasonable notice. Renewed consent is obtained where required.
11. Contact
- Processor: 在地量化(温州)数据科学有限公司
- Registered address: Room 105, Building 3, Area A, Wenzhou Digital Culture Industry Base, Qidu Subdistrict, Lucheng District, Wenzhou, Zhejiang, China
- Privacy:
privacy@localqds.com - Support:
support@localqds.com - Website: https://dmut.localqds.com/