OURZHAo Legal zh

OURZHAo Privacy Policy

Effective Date: April 17, 2026 Last Updated: April 17, 2026 Version: 1.0

OURZHAO LLC ("OURZHAO", "we", "us", or "our") develops and operates the OURZHAo mobile application (the "Service"). We take your privacy seriously. This Privacy Policy explains how we collect, use, store, share, protect, and delete your personal data when you use the Service, and describes the rights you have as a data subject.

This Policy is designed to comply with:

Where local law conflicts with this Policy, the mandatory provisions of the applicable jurisdiction prevail.


1. Who This Policy Applies To

The Service is available only to users aged 13 or older.


2. Data Controller and Contact

Item Details
Legal entity OURZHAO LLC
Application OURZHAo
Primary contact support@ourzhao.com
Privacy inquiries support@ourzhao.com (subject line: "Privacy")

Users in the EU/EEA, UK, and California may exercise their data subject rights via the email above. We reply within the statutory deadline applicable to your jurisdiction.


3. Personal Data We Collect

3.1 Data you provide

3.2 Data collected automatically

3.3 Data from third parties

3.4 Data we do NOT collect


4. Purposes and Legal Bases (GDPR Art. 6)

Purpose Taiwan PDPA basis GDPR basis
Creating and maintaining your account Contract necessity Art. 6(1)(b) contract
Delivering core AI-alarm features (TTS, scheduling) Contract necessity Art. 6(1)(b) contract
Processing subscriptions, billing, and refunds Contract necessity Art. 6(1)(b) contract
Error diagnosis and service stability Legitimate interest Art. 6(1)(f) legitimate interests
Fraud prevention and security incident response Legitimate interest Art. 6(1)(f) legitimate interests
Sending you service notifications Contract necessity Art. 6(1)(b) contract
Non-essential marketing communications Your consent Art. 6(1)(a) consent
Complying with legal obligations Legal obligation Art. 6(1)(c) legal obligation

If you withdraw consent, processing carried out before the withdrawal remains lawful.


5. How We Use Your Data

We use your data only to the extent necessary for the purposes described above, including:

  1. Sending your text prompts to AI providers (OpenAI, Anthropic, Google Gemini) to generate alarm scripts.
  2. Sending generated text to TTS providers (ElevenLabs, Google Cloud TTS) for voice synthesis.
  3. Uploading synthesised audio to Firebase Storage and delivering it to your device.
  4. Sending push notifications at the alarm times you configured.
  5. Sharing friend invites and monthly ring-day counts within the limits you consented to.
  6. Aggregating anonymised statistics to improve the Service.

We do not use your personal data for purposes beyond those described here, and we do not sell it.


6. Data Sharing and International Transfers

6.1 Recipients

Category Recipient Purpose Data scope
Cloud infrastructure Google Firebase (Auth, Firestore, Storage, FCM, Crashlytics, Performance, Analytics) Authentication, storage, push, error tracking Account data, audio, push tokens, error logs
AI text generation OpenAI, Anthropic, Google Gemini Generate alarm dialogue Your provided prompts (no account identifiers)
TTS synthesis ElevenLabs, Google Cloud TTS Text-to-speech Text to synthesise
Error monitoring Sentry.io Diagnostics Stack traces, de-identified device info
Payments & subscriptions Apple App Store, Google Play Billing Anonymised entitlement receipts
Email delivery SMTP providers Deliver data-export links and notifications Email address, download URL

We execute a Data Processing Agreement (DPA) with each processor, requiring them to act only on our instructions and apply security measures equivalent to or stricter than ours.

We do not "sell" or "share" your personal information as those terms are defined under CCPA/CPRA, including for cross-context behavioral advertising.

6.2 International transfers

Because the Service relies on Google Firebase and US-based AI/TTS providers, your data may be transferred to and processed in the United States, the European Union, or Asia. For users in the EEA, UK, and Switzerland, we rely on one of:


7. Retention

Category Retention
Account data (email, UID) For the life of the account
Alarms, friendships, preferences For the life of the account; deleted immediately upon account deletion
Alarm audio (generated) Tier-dependent; free-tier retained at most 7 days
Starred (permanently-saved) audio For the life of the account
Subscription & billing records 5 years (tax law)
Deletion audit log (hashed identifiers only) 2 years (anti-abuse + GDPR accountability)
Crash / error logs Up to 90 days

When your account is deleted, we remove all identifying primary data within 30 days. Backups, audit logs, and records required by law are retained for the applicable period then purged.


8. Your Rights

8.1 Taiwan PDPA rights

You may request to:

8.2 GDPR / UK GDPR rights

8.3 CCPA / CPRA rights

California residents may request:

8.4 How to exercise rights

Under CCPA §1798.130 we provide two designated methods for California residents to submit rights requests:

We acknowledge receipt within 5 business days and respond within 30 days (extendable up to 3 months under GDPR; 45 days under CCPA). You may also designate an authorised agent to make a request on your behalf; we may require reasonable proof of the agent's authority.


9. Security

Technical and organisational measures we apply:

No internet transmission or storage system is 100% secure. In case of a personal data breach, we will notify the relevant supervisory authority and affected users in accordance with Taiwan PDPA, GDPR Art. 33–34, and CCPA.


10. Cookies and Similar Technologies

The Service is a native mobile application and does not use browser cookies. We use local storage for:

You can clear local data via your OS's "Clear app data" function; signing in again will resync from the cloud.


11. Children's Privacy

The Service is not directed to children under 13 and we do not knowingly collect personal data from anyone under that age. Parents or guardians who believe their child has provided personal data to us should email support@ourzhao.com, and we will delete the data promptly.


12. Third-Party Links

The Service may contain links to third-party websites, app stores, or external resources such as YouTube. We are not responsible for their privacy practices; please review those parties' privacy notices separately.


13. Changes to this Policy

We may update this Policy to reflect legal, functional, or operational changes. For material changes we will notify you via at least one of:

For non-material changes (typographical, formatting), we will update the "Last Updated" date only.


14. Contact

For questions, complaints, or rights requests, contact:

OURZHAO LLC Email: support@ourzhao.com Subject: "Privacy" or "Data Subject Request"

We will acknowledge receipt within 5 business days and provide a substantive response within 30 days (subject to any statutory extension).