1. Scope and operator
- Operator
- Shenyang Tdx Network Technology Co., Ltd.
- Unified Social Credit Code
- 91210124088957535L
- Contact email
- tdxkefu@foxmail.com
This policy applies to the Tdx Teleprompter Android app, the official website at https://teleprompter.yiroot.com/, and account services expressly connected through them. Google and other third parties independently processing information apply their own privacy rules.
Personal information excludes anonymized information.
The app does not request all permissions at first launch. It requests access only when you start the related feature. Microphone access supports on-device AI Follow, camera access scans a Windows sign-in code, overlay access shows your prompt above other apps, and Accessibility supports Floating AI Follow. Granting access does not itself cause microphone audio, camera frames, or scripts to be uploaded. Refusing or disabling access affects only the related feature; other features remain available.
2. How we process information
We follow legality, fairness, necessity, good faith, specific purposes, transparency, and security. Basic prompting does not require registration. Google sign-in, Google Play purchases, account services, update checks, and the Countly or Microsoft Clarity SDK and analytics requests start only after Agree and Continue. If you decline, local scripts, editing, and basic Auto Scroll remain available; the privacy-consent screen is not captured by Clarity.
Script text, groups, hotwords, reading position, and settings remain in app-private storage. Images, videos, and documents are read only after you choose them through Android system pickers for import, preview, on-device recognition, or local video processing. Video Mirror saves a new result to the system gallery. Source files and processed results are not automatically uploaded as files, but after consent, visible text or images not covered by Clarity's Balanced masking may be included in interface-reconstruction data.
Google sign-in, Tdx account sign-in, the AI Follow trial, membership purchase, invitations, feedback, and updates process only what is necessary when actively used after consent, based on the service agreement, consent, or legal duties.
3. Local content and AI Follow
Scripts, hotwords, markers, prompting settings, and reading position remain in private storage. Android cloud and transfer backup are disabled. Deleting a script, clearing app data, or uninstalling may be irreversible.
The app does not request access to the whole photo library. It receives limited access to up to 10 selected images for checks, ordering, thumbnails, and bundled on-device OCR. Original images are not uploaded or retained as attachments; only recognized text you confirm is saved.
AI Follow requires an account and network access for sign-in and starting a free trial. Sherpa-ONNX then processes microphone audio, recognition, text matching, and scrolling on-device. The current session needs no continuous connection and uploads neither scripts nor audio.
Up to three recent AI evidence sets may be retained locally, up to 300 MB, and general logs for up to 14 days and 30 MB. They are automatically cleared at their limits and do not leave the device by default.
4. Feedback and diagnostic sharing
The app has two separate feedback routes. Ordinary Feedback creates a local diagnostic package. It leaves the device only after you choose a recipient in the Android share sheet and confirm sending; we do not upload it in the background.
“Earn membership by completing tasks - Submit product experience feedback” is an optional online reward task. When you enter the task, describe a genuine experience, and submit, the description and up to three selected images re-encoded without original EXIF are uploaded. A diagnostic ZIP is created and uploaded only if you separately select diagnostic sessions, read the sensitive-content notice, and confirm. It may contain full scripts, hotwords, recognized text, algorithm events, device and app information, logs, and microphone audio. Routine AI Follow remains on-device and never uploads scripts or audio automatically.
Task materials use short-lived URLs fixed to specific objects and are stored in a private Alibaba Cloud OSS bucket in China with public access disabled. Authorized support and administrators may review descriptions and images. A short-lived read-only link to a diagnostic ZIP is created only when authorized developers need it for troubleshooting. The current reward decision is made by authorized staff, not by a model, and materials are not used for advertising, profiling, or unrelated distribution.
Incomplete server drafts close and are cleaned after 24 hours. If more information is requested, the supplement window is seven days. Thirty days after a final outcome, the server deletes descriptions, appeal text, images, thumbnails, and diagnostic ZIPs; failures enter retry and backlog monitoring. Irreversible digests, material type and size, reason codes, review records, reward ledger entries, and entitlement events remain as needed to prevent duplicate rewards and preserve required audit.
5. System permissions
Camera is used only to scan a Windows sign-in code, microphone only for voice features you start, and overlay only to show Floating Prompt. Refusing or disabling access affects only its dependent feature.
Accessibility is used only when you expressly enable Floating AI Follow over the system camera or a compatible app. It hosts the prompt and lets on-device recognition receive microphone audio while another app records. It does not read or control another app's text, keystrokes, typed content, passwords, or screenshots. A separate prominent disclosure and express consent appear before system settings.
Photo and file pickers grant limited access only to selected items. Network supports sign-in, purchase verification, updates, feedback, first-party aggregate analytics, and Microsoft Clarity session reconstruction after consent. Local scripts, editing, and basic Auto Scroll remain available without it.
6. Optional account and transaction services
When you sign in, Google’s short-lived identity credential is sent to our stateless security bridge in Singapore to verify its signature, issuer, audience, nonce, and expiry. The bridge does not retain the original credential and sends only a minimized verification result to our account service in China, which stores the Tdx account, device, session, and identity binding.
If you instead choose account-ID sign-in, the public Tdx account ID and password are sent over encrypted HTTPS directly to our account service in China. The service stores the public account ID and a salted adaptive password hash needed to verify future sign-ins; it does not store a recoverable plaintext password, and credentials are excluded from logs and analytics.
When you purchase digital membership, Google Play handles product presentation and payment. The purchase token is verified through the Singapore bridge with the Google Play Developer API, after which our account service records the order and grants the shared membership entitlement. Orders, purchase tokens, and payment status are not analytics data.
Google Play Billing starts only when you view or purchase digital membership. Google processes products, payment, orders, and refunds. The app and bridge process product ID, order state, and purchase token. The app does not receive complete card details, and the final account, order, and entitlement remain on the account service.
The account service also processes installation identifier, device display name, system version, session, membership, sign-in time, and result for authentication, device management, entitlement, security, attack prevention, dispute handling, and legally required audit. Identity credentials, purchase tokens, password, session, scripts, and audio are excluded from analytics.
7. Sharing, processors, and third parties
We do not sell personal information. Google processes account selection and authorization when you sign in and product, payment, order, and refund information when you purchase. Google's independent processing is governed by its privacy rules.
The stateless Singapore bridge verifies a short-lived Google identity credential or purchase fact. It has no account or order database, does not persist the original credential, and returns only a minimized signed result to the account service in China. Network and hosting providers process only necessary connection information for limited purposes.
The bundled Google ML Kit model performs on-device OCR, Sherpa-ONNX recognizes speech on-device, and ZXing handles QR codes locally. OkHttp, AndroidX, WorkManager, and system pickers are supporting components and not independent business-data recipients.
For the product-feedback reward task, Alibaba Cloud Object Storage Service (OSS) acts as our processor and privately stores in China only the descriptions, images, and optional diagnostic ZIPs you actively submit. Processing is limited to intake, staff review, troubleshooting, and reward disputes. Alibaba Cloud may not use these materials for advertising or independent profiling; private ACLs, server-side encryption, short-lived signed URLs, least privilege, and access audit restrict access.
After consent, Microsoft Clarity acts as an independent third-party analytics service and processes app layouts, visible content after Balanced masking, taps and gestures, app errors, and limited device information to reconstruct sessions and create heatmaps. Clarity is not used for ad targeting, and we do not set a Tdx account, Google identity, email, order ID, or custom user ID in Clarity. Its processing is governed by the Microsoft Privacy Statement and Clarity terms.
8. Invitation rewards
When you use invitations, we process the code, internal account identifiers, binding time, rule version, and membership-time reward record. Scanning a poster only opens the official download page; sign-in, active code entry, and server validation are required for a relationship.
Installation identifiers and irreversible provider-subject digests support checks against duplicate rewards, self-invitation, and bulk registration. Original identifiers and risk rules are not disclosed; abnormal relationships may be restricted and reviewed.
9. Retention, security, and international transfer
Local scripts and settings remain until you delete them, clear app data, or uninstall. AI evidence, logs, ordinary-feedback image drafts, and share caches follow the limits in Sections 3 and 4. Online materials for the product-feedback reward task follow the separate periods below.
After consent, the app creates an independent random installation analytics ID and sends sessions, manual page views, fixed allowlisted events, and sanitized unhandled fatal Release Java/Kotlin exceptions to our self-hosted analytics service. This ID is not merged with a Tdx account, Google identity, order, payment identifier, or hardware identifier.
Our self-hosted Countly analytics may include app version, Google Play channel, Android major version, normalized brand and model, phone or tablet type, screen pixel resolution, app language, sign-in status, membership status, and controlled business enums. An unhandled fatal Release Java/Kotlin exception records only its type, class, method, source-file and line locations, plus limited device dimensions; exception messages, breadcrumbs, other thread stacks, custom fields, handled exceptions, and native dumps are excluded. Countly also excludes advertising ID, location, contacts, scripts, recognized text, microphone audio, images, and search terms. Linkable installation records, individual crashes, and crash groups containing sanitized stacks last up to 180 days; page, event, and crash count-only aggregates without installation IDs or stacks last up to 24 months. The crash dashboard shows only groups, counts, affected-install counts, versions, time, and sanitized stacks, never an installation ID or personal trajectory. Revoking consent stops Countly, clears its local identity, and requests anonymous deletion.
Account, sign-in audit, invitation, order, refund, and security records are retained only as needed for service, disputes, duplicate-entitlement prevention, and legal duties. We use private storage, disabled backup, HTTPS, Android Keystore, access controls, redacted logs, and permission minimization.
Account, order, and membership business records are stored in China. Only when you actively sign in or purchase is a short-lived identity credential or encrypted purchase-verification information sent to the stateless bridge in Singapore and then to Google services. The bridge stores no business database. Google may process account selection, product, payment, order, and refund data in its operating regions under its rules.
Incomplete task drafts on the server close and are cleaned after 24 hours. Thirty days after a final outcome, descriptions, appeal text, images, thumbnails, and diagnostic ZIPs are deleted. Task materials in Alibaba Cloud OSS are stored in China; deletion failures are retried and monitored. Irreversible anti-duplication digests, review decisions, reward ledger entries, entitlement events, and necessary security audit may remain only as long as needed to deliver the reward, prevent duplicate claims, resolve disputes, or meet legal duties.
Microsoft Clarity ordinarily retains session-playback data for 30 days; favorite or sampled sessions and click or heatmap data may be retained for up to nine months. Withdrawal immediately tells Clarity to deny analytics storage and pauses future collection on this device, but Microsoft currently provides no self-service API to delete existing Clarity data for an individual app user. Contact us through this policy to make a deletion or other rights request.
10. Your rights
Under applicable law, you may know, decide, restrict, or refuse processing and request access, copy, correction, supplementation, deletion, consent revocation, explanation, or account deletion. We generally respond within 15 working days after verification.
You can manage local scripts and system permissions, revoke consent under Me > Privacy & Personal Data, and manage devices, sign-out, or deletion under Account & Security. Revoking consent does not delete local scripts and is not account deletion.
If you cannot use the app, use the public deletion page or email tdxkefu@foxmail.com. Identity verification may be required to protect the account and information.
Before task submission completes, you can cancel the upload or remove the optional diagnostic ZIP. The result page provides supplement or appeal actions when applicable. You may request access, correction, deletion, or an explanation of processing through the contact route in this policy; after identity verification we respond under applicable law. An active reward dispute or legal duty may limit the deletion timing.
11. Minors
The service is not specifically directed to children under 14. A minor should use it under guardian guidance and avoid unnecessary information in scripts, images, or diagnostic packages.
Basic offline features do not require registration. Account or transaction features that upload information require guardian guidance and any legally required consent; otherwise the online feature should not be used.
12. Policy updates
We may update this policy for changes in features, purposes, information types, third parties, or law and will show a new publication date. The updated policy takes effect on that date.
A material effect on personal-information rights is announced prominently, and renewed consent is obtained where required. An update cannot reduce statutory rights without express consent.
13. Contact us
- Operator
- Shenyang Tdx Network Technology Co., Ltd.
- Unified Social Credit Code
- 91210124088957535L
- Contact email
- tdxkefu@foxmail.com
- Website
- https://teleprompter.yiroot.com/
Contact us with policy, processing, complaint, or rights questions.
Appendix 1: Personal Information Collected
1.1 Account and device
Google sign-in may provide a stable subject identifier, verified email, name, and avatar. The Tdx account service processes account ID, installation ID, device display name, session, and membership status. Email is profile and contact data, never a silent merge key.
The app does not read IMEI, IMSI, MAC address, advertising ID, contacts, or precise location. Android ID is read only on-device to derive a salted, irreversible hash as the installation identifier; the raw value is neither stored nor transmitted.
1.2 Transactions and local content
Purchases process product ID, offer, currency, order ID, purchase token, purchase state, acknowledgement or consumption state, refund, and entitlement result. Google Play handles the payment account and card details; the app does not receive full card information.
Source script and image files, microphone audio, recognition results, and prompt scrolling state are processed on-device by default and are not automatically uploaded as source files. After you consent to Clarity analytics, visible text or images on the current screen that are not covered by Balanced masking may be sent to Microsoft as interface-reconstruction data. Microphone audio and local files themselves are not sent to Clarity. Content risk checks use offline rules shipped with the app and do not upload scripts or detection content to Tdx or third-party detection servers.
1.3 Product-feedback reward task
When you actively submit the product-feedback reward task, we process internal Tdx account and device identifiers, feedback type, description, images re-encoded without original EXIF, material size and SHA-256, submission and review state, reason codes, reward records, and a device anti-abuse HMAC digest used to prevent duplicate claims.
A diagnostic ZIP is processed only after you actively select sessions and confirm again. It may contain full scripts, hotwords, recognized text, algorithm events, device and app information, logs, and microphone audio. Materials support staff review, troubleshooting, the three-day membership reward, and disputes; they are not used for advertising, profiling, or model review in the current version.
Appendix 2: Third-Party Sharing
Google services
Google processes account selection and authorization when you sign in, and product, payment, order, and refund data when you purchase.
Singapore bridge
Verifies Google credentials and sends a minimized result to the account service in China.
Self-hosted analytics
Receives only a random installation ID, controlled sessions/views/events, sanitized unhandled fatal Java/Kotlin exceptions, and limited device dimensions. Individual crashes, sanitized-stack groups, and other linkable records last up to 180 days; count-only aggregates last up to 24 months. It does not receive exception messages, a Google subject, email, Tdx account, purchase token, order ID, script, or audio.
Microsoft Clarity
After consent, receives app layouts, visible content after Balanced masking, taps and gestures, app errors, and limited device information for reconstructed sessions and heatmaps. Ordinary playback data is retained for 30 days; favorite or sampled sessions and click or heatmap data may be retained for up to nine months.
Alibaba Cloud OSS
Descriptions, images, and optional diagnostic ZIPs for the product-feedback task upload to private Alibaba Cloud OSS in China; Alibaba Cloud provides object storage, encryption, and transfer under our instructions, and authorized staff access necessary materials only through the controlled admin service or short-lived read-only links.
Appendix 3: SDKs and Open-Source Components
3.1 Feature components
Android Credential Manager
1.6.0Used only when you choose Google sign-in
Google ID components
1.1.1Used only when you choose Google sign-in
Google Play Billing
9.1.0Used only when you view or buy digital membership
Play App Update
2.1.0Obtains this app's updates only from Google Play
Google ML Kit
16.0.1Performs on-device text recognition for selected images
Sherpa-ONNX
1.13.4Provides on-device AI Follow speech recognition
ZXing
3.5.3Generates or recognizes QR codes locally
3.2 Foundation components
OkHttp
Calls account, bridge, membership, feedback, and anonymous analytics-deletion APIs
Room
Stores local scripts and settings
WorkManager
Performs bounded background tasks
First-party analytics (Countly Android SDK)
26.1.5After consent, sends fixed sessions/views/events and sanitized unhandled fatal Release Java/Kotlin exceptions; handled exceptions, breadcrumbs, other thread stacks, custom fields, and native dumps are disabled
Microsoft Clarity Compose SDK
3.9.0Developer: Microsoft Corporation Information collected: app layouts, visible text and images after Balanced masking, taps and gestures, app errors, app and device information, and country/region Purpose: reconstruct usage sessions, create heatmaps, and improve the product after consent Privacy statement: https://privacy.microsoft.com/privacystatement
Appendix 4: System Permissions
4.1 Network access (no separate system prompt)
Network access supports Google sign-in, AI Follow trials, membership purchase verification, updates, feedback, first-party aggregate analytics, and Microsoft Clarity session reconstruction after consent. Before consent, the app does not initialize the Countly or Clarity SDK or their analytics requests. Turning off network access affects only online features; local scripts, editing, and basic Auto Scroll remain available. The current version does not request notification permission.
4.2 Camera
After you open the Windows sign-in scanner, the app explains the purpose first and requests camera access only when you tap Allow Camera. Frames are processed on this device only to recognize the sign-in QR code and are neither saved nor uploaded. Declining affects only QR sign-in.
4.3 Microphone
Microphone access is requested only when you start AI Follow and is used for on-device recognition of your reading progress. Normal AI Follow does not automatically upload audio or use it for analytics. For troubleshooting, evidence from up to the three most recent sessions may store audio in the app's private directory; related diagnostic materials are uploaded only if you later select sessions, read the notice, and confirm. If you decline, Auto Scroll remains available.
4.4 Display over other apps
The app guides you to enable display-over-other-apps access only when you choose Floating Prompt. It shows your prompt above camera or streaming apps and does not read their content. Declining affects only Floating Prompt; full-screen prompting and other features remain available.
4.5 Accessibility service
Accessibility is used only when you choose Floating AI Follow. Before system settings, the app shows a separate prominent disclosure and obtains express consent. The service hosts the floating prompt and lets on-device recognition continue receiving microphone audio while another app records. It does not read or control another app's text, keystrokes, typed content, passwords, or screenshots, and does not perform taps or gestures. Granting access does not itself upload scripts or audio. You can turn the service off in system Accessibility settings at any time. If you decline, Auto Scroll remains available.
4.6 System photo and file pickers
The app does not request access to your entire photo or media library. System pickers grant limited access only to items you select, and canceling does not affect other features. Image Script accepts up to 10 images at a time for on-device file checks, ordering, thumbnails, and OCR. Video Mirror reads only the single video you select, previews and processes it on-device, and saves a new video to the system gallery. Original images, source videos, and processed results are not uploaded automatically.