PRIVACY_PROTOCOL

TOP SECRET // CLASSIFIED

Sano Live Official Website privacy policy for Sano Live, also known as Sano. Official contact: sanoofficialcontact@gmail.com

01. THIS PRIVACY POLICY WILL HELP YOU UNDERSTAND

The Sano Live application (also referred to as Sano), its affiliates ("we"), are well aware of the importance of personal information to you. We will protect your personal information and privacy in accordance with laws and regulations. We have formulated this "Privacy Policy" with a special reminder: we hope you read and understand this privacy policy carefully before using Sano Live and related services, so that you can make an appropriate choice.

• We will collect and use your information in accordance with the privacy policy, but we will not collect personal information in a mandatory bundle just because you agree to this privacy policy.

• When you use or turn on related functions or services, we will collect and use relevant information in order to realize the necessary functions and services. Unless it is necessary for basic business functions or required by laws and regulations, you can refuse to provide it without affecting other functions or services.

• If you are not logged in to your account, we will use the identifier information corresponding to the device to ensure the basic functions of information push. If you log in to your account, we will push information based on your account information.

• The camera, microphone, and album permissions will not be turned on by default. Only after your express authorization can they be used for specific functions or services, and you can also withdraw the authorization.

• This privacy policy applies to your access and use of our products and services through the Sano Live application, Sano software development kit (SDK), and application programming interface (API) for third-party websites and applications.

02. TABLE OF CONTENTS

The following will help you understand in detail how we collect, use, store, transfer, share (if applicable), and protect personal information; and how to query, access, delete, correct, and withdraw authorized personal information.

1. How we collect and use personal information

2. How we share, transfer, and publicly disclose personal information

3. How we store personal information

4. How we protect the security of personal information

5. Manage your personal information

6. Minor Clause

7. How to delete personal information

8. Revision and notice of privacy policy

9. Contact us

03. 1. HOW WE COLLECT AND USE PERSONAL INFORMATION

We will collect information that you proactively provide when you use the service, and collect information generated during your use of functions or services through automated means.

1.1 Registration, login, authentication

1.1.1 Register and log in to your account

a. When you register and log in to Sano and related services, you can create an account and complete network identification information (avatar, nickname, password). You can also choose to fill in gender, birthday, region, and personal introduction to improve your profile.

b. When you log in through a third-party account, you need to authorize us to obtain public information of that account (such as avatar, nickname, gender, and other authorized information). If you refuse this authorization, you cannot log in through a third-party account, but this will not affect your use of other functions.

1.2 Release and interaction

1.2.1 Information release

a. When you post audio, video, pictures, and other content, we will collect the information you post and display your nickname, avatar, and posted content.

b. When you use live broadcast, audio, and video functions, we will ask for camera, photo, and microphone permissions. If you refuse authorization, you will not be able to use these functions, but this will not affect other functions.

c. When you use live broadcast components on iOS or Android, we may use third-party SDK capabilities for image processing and beauty effects. Required information may include device model and unique device number. Facial data is not used to identify users. Recognition is done locally and facial feature values are not uploaded or stored.

When you use filters, beauty, and related tools to shoot and publish content, we may process live video data and facial feature data locally on your device for visual effects only.

1.2.2 Interactive communication

a. When you follow accounts, browse, or chat, we will collect related interaction information and display corresponding content.

b. To support following/unfollowing friends, we will create follow and follower lists, which are necessary for relationship management.

c. When you comment on live streams or moments, we collect your comment content and may notify the user you commented on.

d. When you use virtual property to reward other users, we collect your avatar, nickname, and reward data and display it to other users.

1.3 Recharge and query virtual property

When you enter the Wallet function, we collect your balance information and display it in the Wallet page. Payment-related functions are completed through third-party payment institutions, which may use biometric information for verification.

1.4 Safe operation

1.4.1 Security function

To provide a safe and reliable service environment, information collected for security functions is necessary information.

1.4.2 Device Information and Log Information

a. To ensure safe software and service operation, we may collect operating system version, device identifier, IP address, software version, operator information, network access mode/type/status/quality, and service logs.

b. To prevent malicious programs and ensure operation safety, we may collect installed application information or running process information, app crashes, performance data, and related usage frequency data.

c. We may use account information, device information, and service logs to determine account security, perform identity verification, and detect/prevent security incidents.

1.5 Changes to the purpose of collecting and using personal information

As business develops, the functions and services of Sano may be adjusted. For scenarios not directly or reasonably related to original purposes, we will notify you and obtain consent before new collection/usage.

1.6 Collection and use exempt from consent in accordance with law

In the following circumstances, we do not need your authorization: a. national security and defense security; b. public safety/public health/major public interests; c. criminal investigation/prosecution/trial/judgment execution; d. protecting major legal rights where consent is difficult to obtain; e. information made public by yourself; f. lawfully public information channels; g. contract signing/performance necessity; h. safe and stable operation maintenance; i. legal news reporting; j. other circumstances stipulated by laws and regulations.

If information cannot identify your personal identity alone or in combination with other information, it does not belong to personal information in the legal sense. If combined usage enables identification, it will be treated and protected as personal information under this policy.

04. 2. HOW WE SHARE, TRANSFER, AND PUBLICLY DISCLOSE PERSONAL INFORMATION

2.1 Sharing

2.1.1 Sharing principles

a. Authorization and consent principle: without your consent, we will not share your personal information unless it is de-identified and cannot re-identify natural persons.

b. Legality and minimum necessity principle: shared data must have legitimate purpose and stay within necessary scope.

c. Security prudence principle: we will evaluate third-party data usage purposes, assess security capability, and require compliance with legal agreements.

Access to third-party SDK directory: in order to ensure realization of relevant functions and stable operation of the Sano application, we may access third-party SDKs.

We conduct strict security monitoring on partner SDKs used to obtain information, in order to protect data security. The relevant third-party SDKs are listed below.

2.1.2 Realization of shared information for security analysis and statistics

a. Safe use: to protect account, service, and content security, and protect legitimate rights and interests, we and our affiliates/service providers may share necessary device/account/log information.

b. Product usage analysis: to analyze service usage and improve user experience, we may share statistical data (such as crash statistics) that is difficult to identify personal identity when combined with other information.

2.2 Assignment

a. We will not transfer your personal information to any third party unless you give explicit consent.

b. With business development, mergers/acquisitions/asset transfers may occur. If personal information is transferred, we will require successors to protect it under standards not lower than this policy, otherwise they must re-obtain authorization and consent.

2.3 Public display

a. We will not publicly disclose your information unless required by laws/regulations or with your consent. Where public disclosure is needed, we use industry-standard security measures.

b. We may disclose relevant account information when announcing penalties for illegal accounts and fraudulent acts.

2.4 Legal exemptions for sharing/transfer/public disclosure

In the following circumstances, we do not need your authorization to share, transfer, or publicly disclose personal information: a. national security and defense security; b. public safety/public health/major public interests; c. criminal investigation/prosecution/trial/judgment execution; d. protecting life/property/major legal rights where consent is difficult to obtain; e. your personal information disclosed to the public by yourself; f. lawfully public information channels.

> SDK: PAG SDK

Affiliated Company:Tencent Cloud Computing (Beijing) Co., Ltd.

Collected Data:Animation rendering logs, device model, GPU information.

SDK Usage:Used for playing vector and Lottie-like animations for UI and live scenes.

Privacy Policy:PAG SDK Privacy Policy

> SDK: Zego SDK

Affiliated Company:Shenzhen Jigo Technology Co., Ltd.

Collected Data:Network status, read/write storage permission, camera, microphone, album access.

SDK Usage:Provides real-time audio and video communication, low-latency live streaming, multi-user interaction.

Privacy Policy:ZEGO Privacy Policy

> SDK: Alibaba Cloud OSS SDK

Affiliated Company:Alibaba Cloud Computing Co., Ltd.

Collected Data:File names, upload/download logs, device IP, network information.

SDK Usage:Used for cloud storage of user-uploaded images, videos, and media files.

Privacy Policy:Alibaba Cloud Privacy Policy

> SDK: MMKV SDK

Affiliated Company:Tencent Technology (Shenzhen) Co., Ltd.

Collected Data:Local key-value data storage (no network data collection).

SDK Usage:Used for high-performance local data caching and configuration storage.

Privacy Policy:MMKV

> SDK: Tencent IM SDK

Affiliated Company:Tencent Cloud Computing (Beijing) Co., Ltd.

Collected Data:User ID, chat content (for message delivery), device model, network status, IP.

SDK Usage:Enables instant messaging, friend lists, chat synchronization, push notifications.

Privacy Policy:Tencent Privacy Policy

> SDK: Google Play Services

Company:Google Inc.

Collected Data:User ID.

SDK Usage:Authentication, Google Sign-in, and Google account-related features.

Privacy Policy:Google Privacy Policy

> SDK: Firebase SDK

Company:Google Inc.

Collected Data:Network status, storage access permission.

SDK Usage:Log collection and upload.

Privacy Policy:Google Privacy Policy

> SDK: SoftSugar Effects Studio SDK

Scope of Data:Camera video frames and facial landmarks (eyes, nose, mouth) used for AR effects rendering.

Processing Method:All processing is performed locally on-device.

Storage and Sharing:No face data is collected, stored, uploaded, or shared with third parties.

Privacy Policy:SoftSugar Privacy Policy

> SDK: FileDownloader

Usage Statement:Only connects when user explicitly starts downloading files via HTTPS; no personal data collection.

Privacy Policy:FileDownloader

> SDK: PictureSelector

Use of SDK:Used for selecting, previewing, editing, and compressing user media before upload.

Security Statement:Permissions are requested only during user-triggered upload actions, with explicit consent.

Privacy Policy:PictureSelector

05. 3. HOW WE STORE PERSONAL INFORMATION

3.1 Storage period

We only keep your personal information for the period necessary for providing Sano and related services. During the period when you have not withdrawn, deleted, or canceled your account, relevant information will be retained. After the necessary period, we will delete or anonymize personal information, except where otherwise provided by laws and regulations.

06. 4. HOW WE PROTECT THE SECURITY OF PERSONAL INFORMATION

a. We attach great importance to personal information security and will use reasonable security measures (technical and management) to prevent unauthorized access, disclosure, use, modification, damage, loss, or leakage.

b. We will use encryption, anonymization, and feasible measures not lower than industry standards, and deploy protection mechanisms against malicious attacks.

c. We establish dedicated security teams, management systems, and data security processes, and enforce strict data access controls with timely security audits.

d. Please understand that due to technical limitations and malicious attack methods, absolute information security cannot be guaranteed in any internet scenario.

e. We strongly recommend you actively protect your information security, including but not limited to using complex passwords, changing passwords regularly, and avoiding sharing account credentials.

f. We will formulate emergency response plans and activate them immediately in case of user information security incidents. We will notify you in a timely manner according to laws and regulations regarding incident details, impact, disposal measures, risk reduction suggestions, and remedial measures.

> INITIATING FIREWALL... [OK]
> MASKING IP ADDRESS... [OK]
> SECURING USER TOKEN... [OK]

07. 5. MANAGE YOUR PERSONAL INFORMATION

We attach great importance to your personal information rights, including inquiry, access, modification, deletion, withdrawal of authorization, complaints, and reports, and provide related privacy capabilities.

5.1 Change or withdraw authorization scope

5.1.1 Change or withdraw sensitive permission settings

a. You can turn off camera, microphone, and album permissions in your operating system settings. After withdrawal, we will no longer collect information related to those permissions.

b. The software does not enable auto-start by default, and you can change settings on your phone.

5.1.2 Information processing after authorization withdrawal

Some services require specific information. After you withdraw authorization, we cannot continue to provide related functions/services and will stop processing corresponding data. Your withdrawal does not affect prior processing already based on your authorization.

5.2 Complaints and reports

If you believe your personal information rights are infringed, you can contact us via email: sanoofficialcontact@gmail.com. We will handle complaints within 30 days after verification.

5.3 Access to privacy policy

You can view this policy on the registration page, or after login via [Me]-[Settings]-[About Us]-[Privacy Policy].

5.4 Notice of service suspension

If we cease operations, we will stop collecting personal information in a timely manner, notify you via appropriate channels, and delete or anonymize retained personal information.

08. 6. MINOR CLAUSE

6.1 General terms for minors

a. If you are a minor under 18, you should read and agree to this policy under the supervision and guidance of your parents or guardians before using Sano and related services.

b. We protect minors' personal information according to applicable laws and regulations, and will only process minors' data where legally permitted, expressly consented by guardians, or necessary for minor protection. If data is collected without verifiable guardian consent, we will delete it as soon as possible.

c. If you are a guardian and have questions about a minor's personal information, please contact us via this policy's contact information.

09. 7. HOW TO DELETE PERSONAL INFORMATION

The Sano Live application provides account deletion functionality. You can apply for account deletion by emailing customer service or by using [My]-[Settings]-[About Us]-[Delete Account] in the app.

Please make sure account-related information and services are handled properly before deletion. We provide a 15-day appeal period during which users can revoke deletion requests.

At the end of the appeal period, account information will be automatically cleared and cannot be recovered. Deleted information may include device information (including mobile phone model and unique device number), account information, personal data, account assets, member benefits, and chat records.

10. 8. REVISION AND NOTICE OF PRIVACY POLICY

To provide better services, Sano and related services may be updated from time to time. We will revise this policy accordingly. These revisions form part of this policy and have the same effect. We will not reduce your rights under the currently effective privacy policy without lawful basis.

11. 9. CONTACT US

If you have complaints, suggestions, or questions about personal information protection, please contact us via email: sanoofficialcontact@gmail.com.

We will review and handle your request within fifteen working days after verifying your identity.

AUTHORIZED BY: Sendal Technology Limited

Document Version: 2.0