Privacy Policy

Updated September 16, 2026 · AI Data Processing Notice version: 2026-09-16

Cocoon's core services use AI. Before registration or first AI use, the app displays the data sent, processing purposes, and recipients and obtains your active consent. From version 1.0.67 (283), the registration page has two separate, unchecked options for the Terms and Privacy Policy and for the AI Data Processing Notice. The AI option is checked only after explicit confirmation on its notice page; returning or closing does not mean consent. You can also read the online AI Data Processing Notice. From version 1.0.68 (284), the in-app notice loads this online document. Consent cannot be confirmed if loading fails or the notice version does not match. Wording and layout changes do not alter existing consent; material changes to data scope, purposes, or recipients update the notice version and require renewed consent. AI services are unavailable without consent, including for signed-in accounts lacking the current record. Consent is stored per account and is not requested for every message. You may read the notice and full policy before deciding, sign out, or delete your account. These flows are provided with the corresponding app and backend updates. For questions, contact support@hicocoon.com.

Cocoon (“we”) is a personal AI app built around remembering what matters to you. This policy explains how we collect, use, store, and protect your information.

1. Information we collect

2. How we use information

3. Storage and security

Data travels between the app and our online services over encrypted HTTPS/WSS connections. Server data is protected by access controls, permission isolation, and other measures. We continuously take reasonable, practicable technical measures against unauthorized access, disclosure, and damage.

Retention and handling after deletion

4. Third-party services and AI data processing

Explicit consent: Before sending personal data to third-party AI services, we explain the data categories, purposes, and recipients in the app and obtain active consent. Opening this policy alone does not indicate consent. Material changes to purposes or recipients require renewed notice and appropriate consent.

Protection requirements for third parties: Recipients must process data only as needed for the service and provide the same or equivalent personal-information protection as this policy, including purpose limits, security measures, and restrictions on unauthorized disclosure. Services that cannot meet these requirements must not receive your personal data.

Processing purposes: Necessary content is processed by relevant third-party AI services for replies, attachment understanding, memory extraction and retrieval, personalization, and task execution. Speech recognition converts recordings to text, and speech synthesis converts text to audio.

Content sent: This includes chat content; images, videos, files, and other attachments you provide or their extracted content; relevant conversation history, memories, personal background, and other context; and authorized tool results. Voice input sends recordings and necessary request identifiers for transcription. Content may include names, contact details, or other personal information you provide and must not be treated as anonymous data.

Recipients: Depending on the model, feature, and actual service route, relevant content may be sent to the following providers. Not every message goes to every recipient:

How consent is obtained: In newer app versions, both phone registration and first-time account creation by SMS require active consent before account creation. We record the consent time and policy version. Within the disclosed processing scope, consent is not requested for every message. Opening a policy, requesting a code, or tapping Sign in does not itself constitute consent to AI processing.

Optional permissions: Registration consent does not include location, camera, microphone, notification, or advertising-tracking authorization. Relevant permissions are requested separately when needed. You can decline or manage them in system settings.

Managing system permissions: In supported mobile versions, Me → Devices and capabilities → System permission settings opens Cocoon's system settings for camera, microphone, notifications, and other permissions. You can disable or re-enable them; available options depend on the system, and unrequested permissions may be absent. On iPhone or iPad, Settings → Privacy & Security manages camera, microphone, and location; Settings → Notifications → Cocoon manages notifications. Disabling the camera prevents in-app capture; disabling the microphone prevents recording and voice calls; disabling notifications stops system notifications. Text chat remains available. The app's Location recommendations switch separately controls location-based recommendations.

Notifications and Apple push services: After you allow iOS notifications, we associate Apple's device push token with your signed-in account for reply, task, and reminder notifications. Live Activities use a separate activity token. Apple Push Notification service (APNs) processes these identifiers, generic status messages, and identifiers needed to open the relevant page. Ordinary notifications use event types and generic wording, not conversation bodies, task reports, reminder details, or personality inferences. Live Activities may display task names, execution stages, status, counts, and progress. Names and detailed progress are marked privacy-sensitive for system display or redaction under applicable settings. Full task content requires opening the app with the current account's permissions. These identifiers are not used for advertising tracking. You can disable notifications and Live Activities separately without affecting text chat.

Widgets and lock-screen display: If you add home-screen or lock-screen widgets, they can show task and reminder names, times, and counts for your account. The app and its widgets store necessary snapshots and dedicated access credentials in a system shared container for synchronization. Sensitive content is marked for iOS to hide according to your lock-screen and Always-On settings. Manage visible content for your environment or remove widgets anytime.

Signing out and switching accounts: Compatible app versions clear delivered notifications, widget caches, and old Live Activities when signing out or switching accounts, and use the previous account identity to unbind this device without affecting other devices or the new account. Offline sign-out first stops local remote-notification reception and clears displays. Server unbinding may be delayed by connectivity or expired credentials; successful registration after signing in updates the binding to the current account. Notifications already delivered or in transit may have a short processing delay. Account deletion also removes that account's server-side push tokens.

Voice call scope: From version 1.0.66 (282), mobile voice calls operate only while the app is in the foreground. Moving to the background or locking the screen stops the current recording, live audio transmission, and automatic listening. Unsent content from that turn is not sent automatically. You must restart the call after returning to the foreground. Previously sent content remains subject to this policy.

Third-party SDKs: On Android, enabling Location recommendations activates the Amap location SDK from Amap Software Co., Ltd. It collects location and device information needed for positioning, such as Wi-Fi status and lists, cell-tower information, and device identifiers. Amap handles this data under its Privacy Policy. The SDK is not initialized and collects no information while location recommendations are off. iOS uses system location services, not this SDK.

Location query services: For nearby recommendations and place resolution, the server may send necessary coordinates or place queries to Amap services to look up nearby places, resolve names, and identify frequent places. These server queries may also use Amap when iOS obtains location through system services.

5. Your rights

You may access, correct, and delete your personal information and delete your account at any time.

6. Protection of minors

Cocoon is intended for adults aged 18 or older and is rated 18+ on the App Store. We do not provide services to people under 18 or knowingly collect their personal information.

If you are a guardian and discover that a minor has used Cocoon and provided personal information without your consent, contact us using the details below. We will delete the information and close the account as soon as possible.

7. Policy updates

We will publish updated versions on this page and change the update date. Material changes will receive appropriate additional notice.

8. Contact us

The product operator and personal-information processor is Shenzhen Airuike E-commerce Co., Ltd. (深圳市埃瑞克电子商务有限公司). For questions about this policy or personal-information processing, contact us: