DMUT Privacy Policy

Version: 2026-07-31 Effective: 31 July 2026

在地量化(温州)数据科学有限公司 (Unified Social Credit Code 91330302MAECM2C72U, “we” or “us”) is the personal information processor for DMUT account, software authorization, website, update and support services. This Policy explains what we process, why, for how long, with whom, and how you can exercise your rights.

DMUT is local-first. Project files, conversation content and model keys normally remain on your device. With a BYOK cloud model, the request normally goes directly from your device to the provider you select and does not pass through the DMUT authorization service.

1. Information and retention

Context Information Purpose Retention
Account and invitation Email, name/display name, region, invitation and account state Registration, verification, access and notices During the relationship; deleted or anonymized within 180 days after it ends unless law requires otherwise
Authorization License, plan, term, seats, irreversible device-fingerprint hash, device name/state and activation events Entitlement checks, two-device limit, abuse prevention and offline grace While valid; processed within 180 days after expiry, revocation or deletion
Quote and enterprise inquiry Contact, company, work email, region, seats, message and consent record Reply, quote and contracting 180 days after closure; transaction rules apply if an order results
Order and contract Quote, order, refund, invoice, contract and necessary payment state; no full card data Settlement, refund, accounting and disputes At least three years after completion, or longer where tax/accounting law requires
Service and security logs Time, network address, client version, result code, session/audit ID and admin action Operation, diagnostics, defence and audit Ordinary logs 30 days; security and admin audit logs 180 days
Update service Version, Global/CN channel, platform/architecture and check result Return the right update and manage rollout Ordinary logs 30 days; no Project content is collected for this purpose
Support and security Email, ticket, attachment and handling record Support, complaints, vulnerabilities and incidents 180 days after closure, longer where a dispute or law requires
Website access Network, browser/device basics, time, page and security logs Delivery, security and diagnostics Usually 30 days; security-event records may be kept for 180 days

Do not submit model API keys, passwords, state secrets or unrelated sensitive information through quote, support or authorization forms.

2. Legal bases

We process information where necessary to enter into or perform a contract with you; to fulfil legal duties or protect life, health or property in an emergency; within a reasonable scope for information lawfully made public; with consent or separate consent; or under another basis provided by law. Optional information may be refused, but the related optional function may then be unavailable. Required authorization data is necessary to issue and maintain a license.

3. Local content, models and tools

Project content, conversations, workflows, model settings and API keys are handled locally by default. Keys should be stored in the operating-system credential store or another location identified by the product. A cloud-model request sends the prompt, selected attachment, output and necessary technical information directly to the selected provider, which may be an independent processor under its policy. A local model is restricted to loopback addresses. Tools process only the objects required by your instruction and permissions.

Unless you voluntarily attach redacted material to a support ticket, the authorization service does not receive Project files, conversation content, prompts, outputs or API keys. We do not train general-purpose models on your private work.

4. Service providers and recipients

Provider Information Use and location
Vercel Website/API requests and necessary network/runtime logs Global website delivery; authorization compute in Singapore
Supabase Account, invitation, device, entitlement, consent and audit data Database region in Singapore
Resend Recipient, message, delivery state and necessary account/log metadata Sending may use Tokyo; account, email metadata, logs or API records may be processed in the United States
Model provider selected by you Prompt, attachment, output and necessary technical data Direct connection from your device; location and rules are controlled by that provider

We do not sell personal information. When law requires notice and separate consent before providing information to another processor, we will identify the recipient, contact, purpose, method and categories. A corporate transaction may transfer information only with notice and continuing protection.

5. Sensitive information and children

Routine DMUT services are not designed to collect sensitive personal information. Device names, support attachments or model inputs can nevertheless contain it; minimize such data. Where necessary, we explain necessity and impact, obtain separate consent and apply stricter protection.

We do not knowingly offer account services to children under 14. If we learn that such information was processed without guardian consent, we will delete it or take another legally required measure. Guardians can contact privacy@localqds.com.

6. Cross-border processing and separate consent

Because the current authorization, database and email infrastructure is outside mainland China, a CN user’s email, invitation/license record, device-fingerprint hash, consent record, quote/support content and necessary logs may be transferred to Singapore, Japan or the United States as described above.

Where required, the submission or activation interface records separate consent after displaying the overseas recipient, purpose, method, categories and rights channel. We conduct and retain personal-information protection impact assessments and use the legally applicable standard contract, certification, security assessment or other mechanism. You may refuse; the current online account, authorization, quote email and support functions may then be unavailable. Local offline functions depend on the product.

Selecting an overseas model or intentionally sending data to an overseas third party also invokes that provider’s rules. The CN edition lists only mainland-China endpoints and local loopback connections.

7. Cookies

The static public website does not use advertising-profile cookies. Infrastructure providers may process necessary network data for security, load and diagnostics. Non-essential analytics or marketing technologies will be separately disclosed and consented to where required.

8. Security and incidents

We use transport encryption, least privilege, key separation, device hashes, access controls, audit, backups and vulnerability response. No internet service is absolutely secure; protect your email, device and model keys and install security updates.

If personal information is or may be leaked, altered or lost, we take immediate remedial measures and provide legally required notice and reporting. Notice describes the categories, likely impact, response, recommended precautions and contact.

9. Your rights

Subject to law, you can be informed; decide, restrict or object; access and copy; correct and supplement; delete; close the account; withdraw consent; and request an explanation. If automated decision-making materially affects you, you can request an explanation and object to a solely automated decision.

Email privacy@localqds.com with the account email, request type and only the identity evidence necessary for verification. We normally respond within 15 working days and explain any justified extension. Withdrawal does not invalidate earlier consent-based processing or necessary processing based on another lawful ground. A refusal will include reasons and available complaint channels.

10. Deletion and updates

When a period expires, a purpose is fulfilled, consent is withdrawn without another basis, service ends or law requires deletion, we delete or anonymize the data. If immediate deletion is technically impracticable, processing is limited to storage and necessary security until deletion. Backups are cleared through their rotation cycle.

Material policy changes receive a new version, effective date and reasonable notice. Renewed consent is obtained where required.

11. Contact

  • Processor: 在地量化(温州)数据科学有限公司
  • Registered address: Room 105, Building 3, Area A, Wenzhou Digital Culture Industry Base, Qidu Subdistrict, Lucheng District, Wenzhou, Zhejiang, China
  • Privacy: privacy@localqds.com
  • Support: support@localqds.com
  • Website: https://dmut.localqds.com/