UniMobile Privacy Policy

Last Updated: March 19, 2026

Effective Date: March 19, 2026

Version: V1.0

Summary

UniMobile fully understands the importance of personal information to you. We will process your personal information in accordance with laws and regulations, based on the principles of legality, legitimacy, necessity, and good faith, and will take appropriate security measures to protect your information.

To help you quickly understand the core content of this policy, the summary is provided as follows:

I. What Information We Process

No. Information Type Specific Information Purpose of Use Applicable Scenario
1 Account Information Enterprise domain, username, password Complete account login and identity authentication User login
2 Single Sign-On Information Authorization result, access token Complete enterprise single sign-on User chooses SSO account login
3 Device Identifier ANDROID_ID, identifierForVendor, device_uuid Device identification, configuration sync, security verification Domain recognition, configuration fetch, update check, connection control
4 Application & Configuration Information Platform type Determine updates, incremental configuration delivery Configuration sync, update check
5 Network & Connection Information Interface information, local IP Establish and maintain VPN connection, troubleshooting and security audit Network access, VPN connection
6 Local Storage Information Saved domain, username, encrypted password, routing settings, agreement consent records Improve continuity of use, save user preferences, remember login status When the user actively chooses to save information

II. How We Request Permissions

The current version primarily involves the following permissions or system authorizations:

  1. VPN authorization: used to establish a VPN tunnel;
  2. Install update package authorization: used for users to actively install updated versions;
  3. Network access and network state reading: used for service communication and connection status determination.

We will not enable non-essential permissions by default and will only request them when you trigger the relevant features.

III. Whether We Share with Third Parties

The current version does not integrate any third-party SDKs for advertising, analytics, push notifications, maps, or payments. Under the current default deployment model, the authentication service, controller service, configuration sync service, and update service are typically built, deployed, or operated by ourselves, and they belong to our own service nodes used to provide this service, which generally does not constitute sharing with external third parties. For details, please refer to the chapter "How We Share, Transfer, and Publicly Disclose Your Personal Information" in this policy.

IV. What Rights You Have

You may exercise your legal rights of query, copy, correction, deletion, withdrawal of consent, and account deregistration, etc. If you cannot exercise these rights through the product features, you may contact us via the contact information at the end of this policy.


Preamble

Anxindaohe (Beijing) Technology Development Co., Ltd. (hereinafter referred to as "we") provides you with services including enterprise domain recognition, account login, configuration sync, VPN connection, routing settings, log viewing, and version updates through the UniMobile client. This UniMobile Privacy Policy (hereinafter referred to as "this Policy") aims to explain how we collect, use, store, share, and protect your personal information, as well as the rights you enjoy.

Please read and fully understand the content of this Policy carefully before using this software. We will highlight clauses involving your important rights in bold, lists, or other reasonable ways.

By clicking "Agree and Continue" or continuing to use this software, you indicate that you have read and understood this Policy and agree to our processing of your personal information in accordance with this Policy.

1. How We Collect and Use Your Personal Information

We will follow the principles of legality, legitimacy, minimum necessity, and openness and transparency when processing your personal information in the following scenarios.

1.1 Account Login and Identity Authentication

When you log in to UniMobile, we will process the following information:

Processing purposes:

1.2 Device Identification and Configuration Sync

To enable domain recognition, authentication configuration fetching, update checking, incremental configuration sync, and security control, we will process the following device identifier information:

Processing purposes:

1.3 Network Access and VPN Connection

When you use VPN connection, routing settings, status viewing, and other features, we will process the following information:

Processing purposes:

1.4 Application Version and Configuration Version Management

When you use configuration sync or update check capabilities, we will process the following information:

Processing purposes:

1.5 Local Storage Information

To improve user experience and enable necessary features, we may store the following on your local device:

Processing purposes:

1.6 Processing Boundary Before First Consent

On the Android platform, before you click "Agree" on the homepage popup, we will only read local static resources and agreement status configuration, and will not:

2. How We Request and Use System Permissions

To implement specific features, we may need to request or use relevant system permissions or system capabilities. The current version primarily involves the following:

2.1 VPN Authorization

Item Description
Permission/Capability Name VPN Authorization / VPN Configuration Authorization
Applicable Platform Android, iOS
Purpose Establish an enterprise VPN tunnel to enable secure network access
Trigger Timing When you actively initiate a VPN connection
Required Yes
Impact of Refusal Unable to establish a VPN connection; post-login network access features will be unavailable

Notes:

2.2 Install Update Package Authorization

Item Description
Permission/Capability Name Install Unknown Source Apps / Install Package Authorization
Applicable Platform Android
Purpose Install the new version package when you actively perform an application update
Trigger Timing When you actively click update and confirm installation
Required Only required for the in-app update installation feature
Impact of Refusal Unable to complete installation within the app; you may still manually update through other legitimate means

2.3 Network Access, Network State, and Foreground Service

The following permissions are primarily used to enable network connectivity and service operation. They generally do not require a separate popup confirmation like VPN authorization, but take effect through the system installation and runtime mechanisms.

Permission Name Applicable Platform Purpose
INTERNET Android Access enterprise services, update services, agreement links, and other network resources
ACCESS_NETWORK_STATE Android Determine network status, handle connection logic
CHANGE_NETWORK_STATE Android Coordinate connection and network state management
FOREGROUND_SERVICE Android Run as a foreground service during VPN connection
FOREGROUND_SERVICE_SPECIAL_USE Android Support VPN special-use foreground service scenarios
WAKE_LOCK Android Reduce the impact of device sleep on connections in certain scenarios

2.4 Permissions Not Used in the Current Version

As of the current version, UniMobile has not requested or actually used the following capabilities:

If related permissions or capabilities are added in future versions, we will:

  1. Separately inform you of the purpose before triggering the feature;
  2. Update this policy again when necessary;
  3. Re-obtain your consent as required by laws and regulations.

Please note:

3. How We Store Your Personal Information

3.1 Storage Location

We process and store your personal information within the People's Republic of China. The current version does not have any regular business scenario for transmitting personal information overseas.

3.2 Storage Period

We will retain your personal information for the shortest period necessary to achieve the processing purposes. After the retention period, we will delete or anonymize the information in accordance with the law, unless otherwise required by laws and regulations.

The retention period of locally cached information depends on:

4. How We Share, Transfer, and Publicly Disclose Your Personal Information

4.1 Sharing

We will not sell or rent your personal information to unrelated third parties.

Under the current default deployment model, the authentication service, controller service, configuration sync service, and update service are typically built, deployed, or operated by ourselves. Therefore, the aforementioned business requests are usually sent to our own or controlled service nodes, and do not constitute sharing with external third parties.

If subsequent versions or specific deployment scenarios integrate with the following external recipients, we will disclose them separately based on the actual situation and obtain your consent when necessary:

  1. Customer self-built controllers or customer-designated controller services;
  2. Customer-designated or external identity providers;
  3. Other external update service recipients.

The current default deployment model is described as follows:

Scenario Current Default Recipient Constitutes External Third-party Sharing
Account Authentication Our self-operated authentication service No
Controller Configuration Fetch / Configuration Sync Our self-operated controller or configuration service No
Application Update Check and Installation Package Distribution Our self-operated update service No
OIDC Single Sign-On Currently typically provided by our self-operated identity service; if integrated with an external identity source, it will be disclosed separately Default: No

4.2 Description of Third-party SDKs and Basic Components in the Current Version

The current version uses a number of basic open-source components or system capability plugins to implement local authentication, system capability calls, local storage, opening external links, and other features. They mainly serve as local runtime dependencies and do not constitute a commercial data cooperation involving sharing personal information with their operators.

Basic components identifiable in the current codebase include but are not limited to:

Component / Capability Primary Use Third-party Commercial Sharing Party
flutter_appauth / AppAuth Implement OIDC login capability No
device_info_plus Obtain platform device identifier capabilities No
android_id Obtain Android ANDROID_ID No
shared_preferences Local storage for configuration and consent status No
flutter_secure_storage Local secure storage for tokens / sensitive information No
url_launcher Open agreement and official website links No

4.3 Transfer

Unless your explicit consent is obtained, or personal information needs to be transferred due to legal reasons such as mergers, divisions, reorganizations, or bankruptcy, we will not transfer your personal information to other companies, organizations, or individuals.

4.4 Public Disclosure

Unless your separate consent is obtained, or otherwise required by laws and regulations, we will not publicly disclose your personal information.

5. How We Protect Your Personal Information

We will take reasonable and necessary technical and management measures to protect the security of your personal information, including but not limited to:

Nevertheless, the Internet environment is not absolutely secure. Please safeguard sensitive information such as account passwords and tokens to avoid disclosure.

6. Your Rights

Within the scope prescribed by laws and regulations, you have the following rights regarding your personal information:

  1. Query and access
  2. Copy
  3. Correct and supplement
  4. Delete
  5. Withdraw consent
  6. Deregister account
  7. Obtain explanations
  8. File complaints and reports

If you withdraw your authorization for the processing of necessary information or for necessary permissions, it may result in the corresponding features being unavailable, but it will not affect the processing that has been conducted based on your prior consent.

7. Policy Changes

We may revise this policy from time to time based on changes in product features, legal and regulatory requirements, or business operation needs.

If significant changes occur to this policy, we will provide prominent notice through popups, page prompts, re-confirmation of the agreement, etc. Significant changes include but are not limited to:

  1. Changes in the purpose, method, or type of personal information processing;
  2. Changes in information sharing recipients;
  3. Significant changes in the manner or procedures for exercising your rights;
  4. Changes in operating entity, contact information, or dispute resolution rules.

If the revised policy requires re-obtaining your consent, we will solicit your consent again in the relevant scenarios.

8. Protection of Minors

We attach great importance to the protection of minors' personal information. If you are a minor under the age of 18, please read this policy accompanied by your legal guardian and use this software and services only after obtaining your guardian's consent.

If you or your guardian have any questions regarding the protection of minors' personal information, please contact us via the contact information at the end of this policy.

9. Contact Us

If you have any questions, comments, or suggestions regarding this policy, personal information protection matters, or your personal information rights, please contact us via the following:

We will process your request as soon as possible upon receipt and respond to you within the time limit prescribed by laws and regulations.

Anxindaohe (Beijing) Technology Development Co., Ltd.