Genie Privacy Policy

Effective date: 2026-09-12

Genie (“Genie AI”, “the App”) is operated by Maitansi Inc. (“Maitansi”, “we”, “us”), the English name of 广州麦坦思信息科技有限公司. Services are provided via domains including genie.maitansi.com. This Policy applies uniformly to Genie’s macOS, Windows, iOS, and Android clients, as well as related websites and online services (together, the “Service”). Unless a section expressly applies to one platform only, the same personal-information practices apply across clients.

1. Information we collect

1.1 Account and identity

When you register or sign in, we may collect:

  • Phone number (SMS verification)
  • Email address (registration and activation)
  • Username and password (stored using secure practices; we do not store reversible plaintext passwords)
  • Profile data you provide (such as an avatar)

1.2 Device information

To identify installations, protect accounts, and support multi-device features, we create an in-app device identifier (a UUID generated locally after install; not an IDFA), plus platform, client type, app version, and an optional device display name. These may be sent with sign-in and API requests.

1.3 User-generated content

Depending on how you use Genie, this may include:

  • Chat/conversation content and agent-related context
  • Files and content you create, import, or sync in Vault (see Section 3.1)
  • Photos/images attached to chats or feedback
  • Voice audio when you use press-to-talk speech input
  • Feedback/bug reports, replies, and screenshots

1.4 Usage and metering

When you are signed in and use cloud features, the client may report upload/download byte counts to our servers for metering, quotas, and reliability. This does not include chat message bodies.

1.5 Local diagnostic logs

The app may keep diagnostic logs on your device for troubleshooting. We do not routinely upload full local diagnostic logs as product analytics unless needed to support a request you make or with separate notice/consent where required.

2. How we use information

We use information to:

  • Provide registration, authentication, and support
  • Deliver product features (chat, sync, cloud agents, speech input, feedback)
  • Meter usage, prevent abuse, and maintain security/reliability
  • Improve the product (preferably with de-identified or aggregated data where appropriate)
  • Comply with law and lawful requests

We do not sell your personal information and do not use your data for third-party advertising tracking.

Genie itself does not use your conversations to train Genie’s own models. Whether third-party model providers may use data to improve their services is described in Section 4.1.

3. Local-first and storage

Genie is designed to be local-first: much content can remain on your device. When you enable sync, cloud chat, feedback, speech recognition, or sign in, related data is transmitted to and stored on our servers and processors (e.g. object storage, speech recognition, model inference).

You can manage sync and related privacy/proxy options in settings (as shown in the product). Turning sync off does not by itself delete data already stored on servers; contact us to request deletion or account closure.

3.1 Vault (ownership and protection of your content)

Vault is your file / knowledge space in Genie. Content you create, import, edit, or sync in Vault (“Vault Content”) belongs to you. We process it only to provide storage, multi-device sync, and related product features for you.

Our commitments regarding Vault Content:

  1. No sale; no unrelated use
    We do not sell Vault Content, use it for third-party advertising, or use it to train Genie’s own models. We do not proactively provide Vault Content to unrelated third parties for browsing or for commercial analytics unrelated to serving you.

  2. Encrypted transport (TLS/SSL)
    Vault-related control channels (authentication, metadata, sync commands, etc.) and data transfers between the client and our servers use TLS (commonly called SSL). When sync is enabled, file bytes between the client and object storage also travel over HTTPS / time-limited signed secure URLs (as implemented at the time).

  3. Authenticated access
    Access to Vault (list, download, upload, delete, sync) requires authentication via your signed-in session or equivalent credentials. The server checks your account’s permission for the relevant Vault; object-storage access uses time-limited, scoped tickets (e.g. presigned URLs). Clients do not hold permanent object-storage keys. Unauthenticated requests must not read your Vault Content.

  4. Isolation and least privilege
    Vaults of different users are logically isolated. Our operations and support staff may access related systems only when needed to troubleshoot, secure the service, or respond to your explicit request, under internal access controls and audit. We do not routinely read Vault bodies for curiosity or marketing.

  5. Relationship with AI features (important)
    Vault and AI are not fully separated: when you use chat / Agent features, the AI may read from or write to Vault as needed for the task. Portions that are read into conversation context may become “Input” under Section 4.1.
    You control access. The product provides read/write permission management for AI / Agents (including permission lists). You can scope what is allowed down to specific files and directories. Paths without the corresponding read or write grant should not be accessed or modified by the AI / Agent. You may tighten, expand, or revoke grants at any time in the permissions UI (as shown in the product).
    Enabling cloud Vault sync alone does not open your entire library to a model; what reaches a model depends on the task and on what the AI actually reads or cites within the permissions you have granted.

  6. Sync under your control
    Whether cloud Vault sync is enabled, and whether privacy/proxy sync options are used, follows product settings. With sync off, Vault Content can remain primarily on your device (still subject to the security of that device).

  7. Legal and security exceptions
    Where required by law, lawful requests by competent authorities, or necessary to respond to security incidents, we may comply or take required measures. Outside those cases, we do not disclose your Vault Content without authorization.

4. Sharing and processors

We may share data with service providers only as needed to operate the service, including:

CategoryPurposeData that may be involved
Cloud infrastructure / object storageAccounts, Vault sync files, media (accessed with auth and tickets)Account identifiers, Vault files/media
SMS providersVerification codesPhone number
Email providersActivation/notificationsEmail
Speech recognition (e.g. Tencent Cloud ASR)Speech-to-textAudio from press-to-talk
LLM / AI providersCloud chat and agentsPrompts, conversations, and necessary context (including images you attach)

Providers may process data outside your jurisdiction under appropriate safeguards.
Camera, photo library, and microphone access are requested only for the features you use (attachments and voice input).

4.1 AI / large language model processing (please read)

To provide cloud chat, agents, and related features, content you submit (prompts, conversation context, files or images you attach—“Inputs”) and model responses (“Outputs”) typically must be:

  1. transmitted over the network to our servers; and
  2. further transmitted to one or more third-party LLM providers for inference.

Providers and models may change as features, versions, and supply change. We do not sell your account information to them for advertising.

Improvement and training:

  • Genie itself does not use your conversations (Inputs/Outputs) to train Genie’s own models.
  • Testing / beta stages: we may use cloud providers’ agent or experience plans. In those stages, Inputs/Outputs may be used by the provider to improve its services (training and retention follow that provider’s then-current product terms).
  • Production commercial stages: we intend to prefer commercial inference APIs (e.g. cloud-vendor commercial tokens / DeepSeek-compatible APIs). Even then, short-term logging, abuse review, and similar practices still follow the provider’s applicable terms; this does not mean data stays only on your device.

Do not enter passwords, secrets, payment card data, government IDs, or other sensitive personal information in Inputs. Information you voluntarily include may be processed by us and these providers and may appear in Outputs.

Relationship to Vault: Sync, cloud storage, and ownership of Vault Content are governed by Section 3.1. Vault and AI are not fully separable: within the read/write permissions you grant, an AI / Agent may read or write the corresponding files and directories; content loaded into conversation context enters this LLM flow. You can refine permission lists to files and directories and change grants at any time.

We do not proactively disclose your personal information to unrelated third parties; network transmission and model inference required to fulfill your AI requests are processing necessary to provide the service, not a sale or advertising disclosure.

5. System permissions

Some features require OS permissions. Labels vary by system; typical examples include:

PermissionMain platformsPurpose
Photo libraryiOS, AndroidAttach images to chat or feedback
CameraiOS, AndroidCapture photos for chat or feedback
MicrophoneiOS, Android (and desktop if voice input is enabled)Press-to-talk and similar voice input
NetworkAll clientsSign-in, sync, cloud chat, ASR, update checks
Local files / disk accessmacOS, Windows (and on-device Vault on mobile)Read/write Vault and workspace files within your grants

We do not unreasonably keep requesting these permissions in the background when the related feature is not in use. Exact system prompts follow each OS.

6. Retention and deletion

We retain account data while your account is active, and delete or anonymize within a reasonable period after closure except where law requires retention. Vault Content synced or stored in the cloud is retained for your account/Vault while you use those features; you may delete files in the client or turn sync off. After account closure or a deletion request, we delete or anonymize cloud Vault data within a reasonable period (residual copies in backups/logs may clear on a limited cycle; legal retention excepted). Cloud chat is retained while used or until deleted upon request. Metering/security logs are kept for limited operational periods and do not include Vault file bodies.

You may request access, correction, deletion, cloud Vault deletion, or account closure via the contact below.

7. Children

The service is not directed to children under 14 (or the age defined by local law). If we learn we collected a child’s data without proper consent, we will delete it promptly.

8. Changes to this Policy

We may update this Policy from time to time. The updated version will be posted on this page with a new effective date (and a version number when useful). Continued use of the service after the effective date constitutes acknowledgment of the updated Policy, except where applicable law requires otherwise.

Your responsibility to stay informed: The current Policy is always the version on this web page (or the same page linked from the app). We encourage you to review this page periodically.

Our notice: For material changes (e.g. material changes to purposes of collection, categories of recipients, or commitments about training/cross-border processing), we will provide additional notice through reasonable channels, which may include in-app notices or dialogs, post-login prompts, in-product messages, email or SMS associated with your account, or other channels we commonly use. Non-material clarifications, formatting, or link updates may be made by updating this page only.

If you do not agree with an updated Policy, please stop using the service and contact us to request account or data deletion as described herein.

9. Contact