Privacy Policy
Cocoon's core services use AI. Before registration or first AI use, the app displays the data sent, processing purposes, and recipients and obtains your active consent. From version 1.0.67 (283), the registration page has two separate, unchecked options for the Terms and Privacy Policy and for the AI Data Processing Notice. The AI option is checked only after explicit confirmation on its notice page; returning or closing does not mean consent. You can also read the online AI Data Processing Notice. From version 1.0.68 (284), the in-app notice loads this online document. Consent cannot be confirmed if loading fails or the notice version does not match. Wording and layout changes do not alter existing consent; material changes to data scope, purposes, or recipients update the notice version and require renewed consent. AI services are unavailable without consent, including for signed-in accounts lacking the current record. Consent is stored per account and is not requested for every message. You may read the notice and full policy before deciding, sign out, or delete your account. These flows are provided with the corresponding app and backend updates. For questions, contact support@hicocoon.com.
Cocoon (“we”) is a personal AI app built around remembering what matters to you. This policy explains how we collect, use, store, and protect your information.
1. Information we collect
- Account information: Basic information needed for registration and sign-in, such as your phone number or email.
- Content you provide: Your conversations, saved notes, and materials, used for memory and personalization.
- Device and log information: Device model, operating system version, and operational logs necessary for reliability and troubleshooting.
- Location (optional, off by default): If you enable Location recommendations, we collect the location you authorize while you use the app and send it with messages for nearby recommendations, location-related conversations, and analysis of frequent places. Precision depends on system permissions and may include precise location; you may authorize approximate location only. We do not request background location. You can disable the feature anytime, after which new messages no longer include location and the local cache is cleared.
2. How we use information
- To provide core features such as memory, reminders, and personalized conversations.
- Inferences from conversations and records: To personalize services, Cocoon gradually organizes and infers personality tendencies, communication preferences, people and relationships you mention, frequent places, and activity patterns from conversations, interaction times, and related records. These support You through Cocoon's eyes and the Personality, Relationships, Profile, and Rhythm sections of Memory Overview. Device-location processing requires separate location permission. This information serves you personally; it is not sold, used for advertising, or shared with other users. Third-party AI processing follows Section 4. Inferences may be inaccurate, and you may request correction or deletion. Please ensure you are entitled to provide other people's personal information and limit it to what the relevant feature requires.
- To improve product experience and service quality.
- We do not sell your personal information.
3. Storage and security
Data travels between the app and our online services over encrypted HTTPS/WSS connections. Server data is protected by access controls, permission isolation, and other measures. We continuously take reasonable, practicable technical measures against unauthorized access, disclosure, and damage.
Retention and handling after deletion
- Account and content: Account details, conversations, uploads, memories, and inferences are retained as needed for the features you use until you delete the relevant content or account. Temporary files follow the expiry specified by each feature. Account deletion removes this data from online operational systems and account-specific file directories; registering again cannot restore it.
- Operational logs: Logs support troubleshooting and security and rotate by date, file size, and retained copy count. They are not intended for long-term conversation storage. Verification codes, passwords, and login tokens should not be written to application logs. Historical logs are restricted to authorized operations staff and cleared through rotation. Necessary records retained for a specific dispute or legal obligation have restricted access and purposes and are deleted or anonymized when that reason ends.
- Isolated backups: Deleting an account does not immediately rewrite existing full-database backups. Backups are used only for disaster recovery and rotate by daily, weekly, and monthly copy counts and capacity limits. Backup interruptions may delay rotation. Copies are not used for everyday service or to restore deleted accounts. Before restoring public service, deletion requests made after the recovery point must be reapplied.
- Deletion records: To prevent deleted accounts from reappearing after recovery, we retain minimal separate records: internal account ID, creation time, and deletion-request time. They contain no conversations, attachments, contact details, or inferences and are used only for deletion and recovery verification. They may be cleared once the related backup and recovery risks are eliminated.
- Third-party processing: Necessary data sent to third parties is handled for the purposes and under recipient rules disclosed in Section 4. Deleting a Cocoon account cannot instantly erase transaction or security records held by third parties or Apple. Contact support@hicocoon.com for access or deletion requests; we will assist within our control and applicable obligations.
4. Third-party services and AI data processing
Explicit consent: Before sending personal data to third-party AI services, we explain the data categories, purposes, and recipients in the app and obtain active consent. Opening this policy alone does not indicate consent. Material changes to purposes or recipients require renewed notice and appropriate consent.
Protection requirements for third parties: Recipients must process data only as needed for the service and provide the same or equivalent personal-information protection as this policy, including purpose limits, security measures, and restrictions on unauthorized disclosure. Services that cannot meet these requirements must not receive your personal data.
Processing purposes: Necessary content is processed by relevant third-party AI services for replies, attachment understanding, memory extraction and retrieval, personalization, and task execution. Speech recognition converts recordings to text, and speech synthesis converts text to audio.
Content sent: This includes chat content; images, videos, files, and other attachments you provide or their extracted content; relevant conversation history, memories, personal background, and other context; and authorized tool results. Voice input sends recordings and necessary request identifiers for transcription. Content may include names, contact details, or other personal information you provide and must not be treated as anonymous data.
Recipients: Depending on the model, feature, and actual service route, relevant content may be sent to the following providers. Not every message goes to every recipient:
- Model services: DeepSeek, Moonshot AI (Kimi), Zhipu (BigModel), Alibaba Cloud Model Studio (Qwen), Anthropic (Claude), OpenAI (GPT / Codex), and Google (Gemini). They receive necessary content for inference, replies, attachment understanding, memory processing, and task execution.
- Model access: Some models connect directly to official services; others are provided through Alibaba Cloud Model Studio, SiliconFlow, or the National Supercomputing Internet Platform. A platform receives content needed for a request only when it is actually used.
- Speech recognition and synthesis: Depending on feature requirements and availability, we select enabled, compatible services from Volcengine, SiliconFlow, and Tencent Cloud. The applicable service may receive audio streams, recordings, video audio tracks, text to read aloud, and necessary request identifiers for transcription or speech generation. Transcripts then follow the AI conversation flow above. Tencent Cloud currently provides backup speech recognition. Service disruptions may cause a switch to an enabled backup, with the necessary audio resent to complete transcription. Only the service performing the function receives necessary content; not every message goes to all recipients.
How consent is obtained: In newer app versions, both phone registration and first-time account creation by SMS require active consent before account creation. We record the consent time and policy version. Within the disclosed processing scope, consent is not requested for every message. Opening a policy, requesting a code, or tapping Sign in does not itself constitute consent to AI processing.
Optional permissions: Registration consent does not include location, camera, microphone, notification, or advertising-tracking authorization. Relevant permissions are requested separately when needed. You can decline or manage them in system settings.
Managing system permissions: In supported mobile versions, Me → Devices and capabilities → System permission settings opens Cocoon's system settings for camera, microphone, notifications, and other permissions. You can disable or re-enable them; available options depend on the system, and unrequested permissions may be absent. On iPhone or iPad, Settings → Privacy & Security manages camera, microphone, and location; Settings → Notifications → Cocoon manages notifications. Disabling the camera prevents in-app capture; disabling the microphone prevents recording and voice calls; disabling notifications stops system notifications. Text chat remains available. The app's Location recommendations switch separately controls location-based recommendations.
Notifications and Apple push services: After you allow iOS notifications, we associate Apple's device push token with your signed-in account for reply, task, and reminder notifications. Live Activities use a separate activity token. Apple Push Notification service (APNs) processes these identifiers, generic status messages, and identifiers needed to open the relevant page. Ordinary notifications use event types and generic wording, not conversation bodies, task reports, reminder details, or personality inferences. Live Activities may display task names, execution stages, status, counts, and progress. Names and detailed progress are marked privacy-sensitive for system display or redaction under applicable settings. Full task content requires opening the app with the current account's permissions. These identifiers are not used for advertising tracking. You can disable notifications and Live Activities separately without affecting text chat.
Widgets and lock-screen display: If you add home-screen or lock-screen widgets, they can show task and reminder names, times, and counts for your account. The app and its widgets store necessary snapshots and dedicated access credentials in a system shared container for synchronization. Sensitive content is marked for iOS to hide according to your lock-screen and Always-On settings. Manage visible content for your environment or remove widgets anytime.
Signing out and switching accounts: Compatible app versions clear delivered notifications, widget caches, and old Live Activities when signing out or switching accounts, and use the previous account identity to unbind this device without affecting other devices or the new account. Offline sign-out first stops local remote-notification reception and clears displays. Server unbinding may be delayed by connectivity or expired credentials; successful registration after signing in updates the binding to the current account. Notifications already delivered or in transit may have a short processing delay. Account deletion also removes that account's server-side push tokens.
Voice call scope: From version 1.0.66 (282), mobile voice calls operate only while the app is in the foreground. Moving to the background or locking the screen stops the current recording, live audio transmission, and automatic listening. Unsent content from that turn is not sent automatically. You must restart the call after returning to the foreground. Previously sent content remains subject to this policy.
Third-party SDKs: On Android, enabling Location recommendations activates the Amap location SDK from Amap Software Co., Ltd. It collects location and device information needed for positioning, such as Wi-Fi status and lists, cell-tower information, and device identifiers. Amap handles this data under its Privacy Policy. The SDK is not initialized and collects no information while location recommendations are off. iOS uses system location services, not this SDK.
Location query services: For nearby recommendations and place resolution, the server may send necessary coordinates or place queries to Amap services to look up nearby places, resolve names, and identify frequent places. These server queries may also use Amap when iOS obtains location through system services.
5. Your rights
You may access, correct, and delete your personal information and delete your account at any time.
- View and manage memories: You can view, edit, or individually delete memories in the app.
- View and correct inferences: Open Me → Growth and Memory → You through Cocoon's eyes, or tap Cocoon's chat avatar, to see its current growth stage and understanding score. Paid members can access Personality, Relationships, Profile, and Rhythm in Me → Growth and Memory → Memory Overview. Point out mistakes and provide corrections in conversation. Corrected facts may retain older versions marked as historical and distinguished from current information; you may also request deletion. All users can use support@hicocoon.com to request access, copies, correction, or deletion, regardless of membership. Account deletion includes associated inferences within the personal-data removal scope of this policy.
- Withdraw core AI processing consent and leave the service: Cocoon's core features depend on the necessary AI processing described above. Before registration, do not consent or register if you disagree. After registration, if you no longer accept this processing, use Me → Account → Delete account and actively confirm deletion to end the service. Handling of account and data deletion is described below. Optional permissions such as location, camera, and microphone can be disabled separately without deleting your account.
- Delete account: Use Me → Account → Delete account in the app. Deletion clears all personal data associated with the account in the app's online operational systems, including but not limited to profile information, conversations, uploads, notes, memories, Knowledge Base content, projects and their materials, tasks, lessons, membership benefits, and remaining allowance. These examples do not limit the deletion scope. This action is irreversible. Isolated backups, necessary logs, and deletion records are handled under Section 3. You can also email support@hicocoon.com to request deletion.
- Apple automatically renewing memberships, if applicable: Deleting your Cocoon account does not cancel an Apple subscription with automatic renewal enabled; Apple will continue renewal under its rules. First use Manage Apple subscriptions to cancel, or go to iPhone/iPad Settings → Apple Account → Subscriptions. One-time reset products do not renew and require no cancellation. You may delete your account immediately without waiting for subscription expiry.
- Other requests: For data exports or other personal-information requests, email support@hicocoon.com. We will respond within a reasonable period.
6. Protection of minors
Cocoon is intended for adults aged 18 or older and is rated 18+ on the App Store. We do not provide services to people under 18 or knowingly collect their personal information.
If you are a guardian and discover that a minor has used Cocoon and provided personal information without your consent, contact us using the details below. We will delete the information and close the account as soon as possible.
7. Policy updates
We will publish updated versions on this page and change the update date. Material changes will receive appropriate additional notice.
8. Contact us
The product operator and personal-information processor is Shenzhen Airuike E-commerce Co., Ltd. (深圳市埃瑞克电子商务有限公司). For questions about this policy or personal-information processing, contact us:
- Email: support@hicocoon.com
- ICP registration: 粤ICP备2025381445号-8
- App registration: 粤ICP备2025381445号-10A