隐私政策

最后更新:2026 年 7 月

西湖未来基因科技(杭州)有限公司(以下简称"我们")尊重并保护您的隐私权。本隐私政策("本政策")说明我们在您通过 FutureOS 平台("服务")使用相关功能时,如何收集、使用、存储和共享您的个人信息,以及您依法享有的相关权利。

请您在使用本服务前仔细阅读本政策。使用本服务即表示您已阅读并同意本政策。我们可能不时更新本政策,如发生重大变更将通过电子邮件或平台公告提前告知您。

1. 数据控制者

本服务的数据控制者为:

  • 公司名称:西湖未来基因科技(杭州)有限公司
  • 注册地址:杭州市西湖区三墩镇智强路428号 云创镓谷 6-806
  • 隐私联系邮箱:info@westlakefuturegene.com

2. 我们收集的个人信息

2.1 您主动提供的信息

  • 账户信息:电子邮箱地址、密码(经 Argon2 算法哈希后存储,我们无法获知您的明文密码)。
  • 支付信息:充值金额、支付状态。我们不存储您的银行卡号或支付账户密码——支付全程在支付宝或微信支付页面完成(见第 5 条),支付结果通过回调通知回传。
  • 验证信息:注册、登录、重置密码时发送至您邮箱的验证码(6 位数字),验证通过后即删除。
  • 沟通记录:您通过客服渠道(GitHub Issue、邮件等)提交的反馈与咨询内容。

2.2 我们自动收集的信息

  • 设备与网络信息:IP 地址、设备型号、操作系统版本、浏览器类型、时区。
  • 使用行为:页面访问记录、功能使用情况、会话时长。
  • API 调用日志:调用的模型名称、Token 消耗量(prompt / completion)、请求时间戳、状态码。用于计费和用量统计。
  • 服务日志:请求时间、错误日志、性能数据,用于服务监控与故障排查。

2.3 我们不收集的信息

我们不收集以下信息:真实姓名、手机号码、身份证号、通讯录、相册、位置信息、生物特征信息。

3. 我们如何使用您的个人信息

使用目的法律依据
提供和维护服务(注册、登录、API 调用)合同履行
计费与支付处理合同履行
客户支持与问题处理合同履行 / 合法利益
服务必要通知(账单提醒、安全告警、政策更新)合法利益
安全与欺诈防控合法利益
产品优化与使用统计合法利益
法律合规法律义务

我们可能对数据进行汇总或去标识化处理,用于统计分析。此类数据无法识别至具体个人。

我们目前不发送营销推广信息。未来如开展营销,将另行征得您的明确同意。

4. Cookie 和追踪技术

类型用途可关闭
严格必要型维持登录会话、核心功能正常运行
功能型语言偏好、界面个性化设置

我们不使用第三方分析工具(如 Google Analytics)或广告追踪 Cookie。本服务不包含任何广告或营销像素。

您可通过浏览器设置管理或清除 Cookie。大部分浏览器支持阻止 Cookie,但这可能影响登录等核心功能。

5. 个人信息的共享与披露

我们不出售您的个人信息,包括适用法律(如 CCPA)所定义的"出售"行为。我们不会将您的信息用于第三方广告或商业数据交换。

我们仅在以下情形共享您的信息:

  • 服务提供商:为支持服务运行,我们与以下类型的受信任合作伙伴共享必要的信息,并要求其遵守严格的保密义务:
    • 云计算服务商:提供服务器托管和基础设施服务,可能处理您的 IP 地址和日志数据。
    • 邮件发送服务商(阿里云 DirectMail):用于发送注册验证码、账户通知等邮件。我们向其提供您的邮箱地址和邮件内容。
    • 支付服务商(支付宝、微信支付):处理充值时,您将被引导至其支付页面完成交易。我们仅接收支付结果回调通知,不接触您的支付账户密码或银行卡信息。
    • AI 模型服务商:当您调用特定 AI 模型时,您的 API 请求内容(prompt)将被传输至上游模型提供商以完成推理。我们不存储您的对话内容。
  • 法律与监管要求:依据法律法规、法院命令或行政、司法机关的合法要求。
  • 商业交易:在合并、收购或资产转让等情形下,如涉及用户信息转让,我们将提前通知并确保接收方继续受本政策约束,否则将重新征得您的同意。
  • 经您同意:在获得您明确事先同意的前提下,用于其他目的。

6. 数据安全措施

  • 传输加密:全站启用 TLS / HTTPS 加密传输。
  • 密码安全:用户密码经 Argon2id 算法哈希后存储,明文密码不留存。
  • API 密钥安全:API 密钥经 SHA-256 哈希存储,仅初次创建时展示明文,之后不可检索。
  • 访问控制:数据库访问遵循最小权限原则。
  • 会话管理:登录会话令牌定期过期,支持主动登出和密码重置。

如发生可能影响您权益的安全事件,我们将在发现后 72 小时内依法通知您及相关监管机构。请妥善保管您的账户凭据和 API 密钥,切勿与他人共享。

7. 个人信息保留期限

数据类型保留期限到期处理
账户信息(邮箱、密码哈希)账户有效期内;注销后 30 天安全删除
API 调用日志36 个月(用于费用核算与争议处理)删除或归档
交易 / 充值记录依法规及税务要求保留到期安全删除
验证码验证通过后立即删除;未使用的最长 10 分钟后过期自动删除
登录会话会话有效期内;到期后自动失效自动清除
服务日志(错误日志等)90 天滚动删除

8. 您的数据权利

如需行使以下权利,请通过 info@westlakefuturegene.com 联系我们,我们将在 30 个日历日内处理您的请求。为保障安全,我们可能要求您验证身份后再处理。

权利说明
知情权了解我们收集及使用哪些数据
访问权获取您的个人信息副本
更正权纠正不准确或不完整的信息
删除权在特定条件下请求删除数据(可自行在控制台注销账户)
限制处理权在特定情形下暂停数据处理
数据可携带权以机器可读格式获取您的数据
反对权反对基于合法利益的处理
撤回同意权撤回基于同意的处理授权

如认为我们未妥善处理您的请求,您有权向所在地数据保护机构投诉。

9. 营销通信与退订

我们目前不发送营销信息。您收到的邮件仅限于:注册验证码、登录验证码、密码重置验证码,以及账户安全和服务相关的必要通知。未来如开展营销活动,我们将事先征得您的明确同意,并提供便捷的退订途径。

10. 跨境数据传输

您的个人信息存储在中华人民共和国境内的服务器上。在符合适用法律规定的情形下,如您调用的 AI 模型由境外服务商提供,您的 API 请求内容可能被传输至该服务商所在的地区(如美国、新加坡等)以完成推理。我们仅传输完成服务所必需的最小数据,并选择具有同等保护水平的服务商。

11. 未成年人保护

本服务主要面向科研机构、高校及相关行业的成年用户,最低使用年龄为 16 周岁。我们不会故意收集未满 16 周岁未成年人的个人信息。如您认为未成年子女向我们提供了信息,请立即联系我们,我们将尽快删除相关数据。

12. 第三方链接与服务

本服务可能包含第三方链接(如支付页面、模型服务商网站)。本政策仅适用于我们直接收集的信息。我们不对第三方的数据实践负责,建议您在使用前查阅其隐私政策。

13. 本政策的变更

如发生重大变更,我们将至少提前 15 天通过平台公告或您的注册邮箱通知您,并更新本页顶部的"最后更新"日期。生效日后继续使用即视为接受修订后的政策。

重大变更包括但不限于:服务模式的重大变化、用户信息共享对象的变化、您权利的重大变化等。

14. 联系我们

Westlake Future Gene Technology (Hangzhou) Co., Ltd. ("we", "us", or "our") respects and protects your privacy. This Privacy Policy explains how we collect, use, store, and share your personal information when you use the FutureOS platform (the "Service"), and the rights you have under applicable law.

Please read this Policy carefully before using the Service. By using the Service, you acknowledge that you have read and agreed to this Policy. We may update this Policy from time to time; material changes will be communicated to you in advance by email or platform announcement.

1. Data Controller

The data controller of the Service is:

  • Company: Westlake Future Gene Technology (Hangzhou) Co., Ltd.
  • Registered address: Room 6-806, Yunchuang Jiagu, No. 428 Zhiqiang Road, Sandun Town, Xihu District, Hangzhou, China
  • Privacy contact email: info@westlakefuturegene.com

2. Personal Information We Collect

2.1 Information You Provide

  • Account information: email address and password (stored as an Argon2 hash; we cannot access your plaintext password).
  • Payment information: top-up amount and payment status. We do not store your card number or payment account password — payment is completed entirely on the Alipay or WeChat Pay pages (see Section 5), and the result is returned to us via payment callback.
  • Verification information: 6-digit verification codes sent to your email for registration, sign-in, and password reset; deleted immediately after successful verification.
  • Communication records: feedback and inquiries you submit through support channels (GitHub Issue, email, etc.).

2.2 Information We Collect Automatically

  • Device and network information: IP address, device model, operating system version, browser type, and time zone.
  • Usage behavior: page visit records, feature usage, and session duration.
  • API call logs: model called, token consumption (prompt / completion), request timestamps, and status codes, used for billing and usage statistics.
  • Service logs: request times, error logs, and performance data, used for monitoring and troubleshooting.

2.3 Information We Do Not Collect

We do not collect the following: real name, phone number, national ID number, contacts, photo album, location data, or biometric information.

3. How We Use Your Personal Information

PurposeLegal Basis
Providing and maintaining the Service (registration, sign-in, API calls)Contract performance
Billing and payment processingContract performance
Customer support and issue resolutionContract performance / legitimate interest
Service-necessary notices (billing reminders, security alerts, policy updates)Legitimate interest
Security and fraud preventionLegitimate interest
Product improvement and usage statisticsLegitimate interest
Legal complianceLegal obligation

We may aggregate or de-identify data for statistical analysis. Such data cannot be linked to a specific individual.

We do not currently send marketing communications. If we launch marketing in the future, we will obtain your explicit consent first.

4. Cookies and Tracking Technologies

TypePurposeCan Be Disabled
Strictly necessaryMaintaining sign-in sessions and core functionalityNo
FunctionalLanguage preference and interface personalizationYes

We do not use third-party analytics tools (such as Google Analytics) or advertising tracking cookies. The Service contains no advertising or marketing pixels.

You can manage or clear cookies through your browser settings. Most browsers support blocking cookies, but this may affect core features such as sign-in.

5. Sharing and Disclosure of Personal Information

We do not sell your personal information, including "sales" as defined by applicable law (such as CCPA). We do not use your information for third-party advertising or commercial data exchanges.

We share your information only in the following circumstances:

  • Service providers: to support the operation of the Service, we share necessary information with the following types of trusted partners, subject to strict confidentiality obligations:
    • Cloud computing providers: host servers and infrastructure; may process your IP address and log data.
    • Email delivery provider (Alibaba Cloud DirectMail): sends registration codes and account notifications. We provide them with your email address and the email content.
    • Payment providers (Alipay, WeChat Pay): when you top up, you are directed to their payment pages to complete the transaction. We only receive payment-result callbacks and never access your payment account password or card information.
    • AI model providers: when you call a specific AI model, your API request content (prompt) is transmitted to the upstream model provider to complete inference. We do not store your conversation content.
  • Legal and regulatory requirements: in response to laws, regulations, court orders, or legitimate requests from administrative or judicial authorities.
  • Business transactions: in the event of merger, acquisition, or asset transfer involving user information, we will notify you in advance and ensure the recipient remains bound by this Policy; otherwise we will obtain your consent again.
  • With your consent: for other purposes with your explicit prior consent.

6. Data Security Measures

  • Encryption in transit: TLS / HTTPS encryption across the Service.
  • Password security: passwords are stored as Argon2id hashes; plaintext passwords are never retained.
  • API key security: API keys are stored as SHA-256 hashes; the plaintext is shown only once at creation and cannot be retrieved afterward.
  • Access control: database access follows the principle of least privilege.
  • Session management: sign-in session tokens expire periodically, with support for active sign-out and password reset.

If a security incident occurs that may affect your rights, we will notify you and the relevant authorities within 72 hours of discovery as required by law. Please safeguard your account credentials and API keys and never share them with others.

7. Retention of Personal Information

Data TypeRetention PeriodDisposal on Expiry
Account information (email, password hash)For the life of the account; 30 days after deletionSecurely deleted
API call logs36 months (for billing and dispute resolution)Deleted or archived
Transaction / top-up recordsAs required by law and tax regulationsSecurely deleted on expiry
Verification codesDeleted immediately after verification; unused codes expire after at most 10 minutesAutomatically deleted
Sign-in sessionsFor the life of the session; automatically invalidated on expiryAutomatically cleared
Service logs (error logs, etc.)90 daysRolling deletion

8. Your Data Rights

To exercise any of the following rights, contact us at info@westlakefuturegene.com; we will process your request within 30 calendar days. For security, we may ask you to verify your identity first.

RightDescription
Right to be informedKnow what data we collect and how it is used
Right of accessObtain a copy of your personal information
Right to rectificationCorrect inaccurate or incomplete information
Right to erasureRequest deletion of data under certain conditions (you may also delete your account in the console)
Right to restrict processingSuspend data processing in certain circumstances
Right to data portabilityReceive your data in a machine-readable format
Right to objectObject to processing based on legitimate interests
Right to withdraw consentWithdraw consent-based processing authorization

If you believe we have not handled your request properly, you have the right to lodge a complaint with your local data protection authority.

9. Marketing Communications and Opt-Out

We do not currently send marketing information. Emails you receive are limited to: registration codes, sign-in codes, password reset codes, and necessary account security and service notifications. If we launch marketing activities in the future, we will obtain your explicit consent in advance and provide a convenient opt-out method.

10. Cross-Border Data Transfers

Your personal information is stored on servers located in the People's Republic of China. Where permitted by applicable law, if an AI model you call is provided by an overseas provider, your API request content may be transferred to the provider's region (e.g., the United States, Singapore) to complete inference. We transfer only the minimum data necessary to provide the Service and select providers with an equivalent level of protection.

11. Protection of Minors

The Service is intended for adult users in research institutions, universities, and related industries, with a minimum age of 16. We do not knowingly collect personal information from minors under 16. If you believe a minor child has provided us with information, please contact us immediately and we will delete the relevant data as soon as possible.

12. Third-Party Links and Services

The Service may contain third-party links (e.g., payment pages, model provider websites). This Policy applies only to information we collect directly. We are not responsible for the data practices of third parties; we recommend reviewing their privacy policies before use.

13. Changes to This Policy

For material changes, we will notify you at least 15 days in advance via platform announcement or your registered email, and update the "Last updated" date at the top of this page. Continued use after the effective date constitutes acceptance of the revised Policy.

Material changes include, but are not limited to: significant changes to the Service model, changes to the parties with whom user information is shared, and significant changes to your rights.

14. Contact Us