Privacy Policy — DrLock

Effective Date: April 22, 2026  |  Last Updated: April 22, 2026


1. Introduction

Welcome to DrLock ("App", "we", "us", or "our"). This Privacy Policy explains how Shenzhen Lanxin Zhilian Technology Co., Ltd. , a company registered in Shenzhen, Guangdong, China, collects, uses, shares, and protects your personal information when you use the Dr. Lock mobile application.

By using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree to this policy, please do not use the App.

Contact us regarding privacy matters:
Email: drlock@skychip.top


2. Information We Collect

2.1 Information You Provide to Us

CategoryData ItemsPurpose
AccountEmail address, password (hashed)Account registration and login
ProfileDisplay name, profile photoPersonalization
Lock sharingRecipient email address or phone numberSharing lock access with others

2.2 Information Collected Automatically

CategoryData ItemsPurpose
Device informationDevice model, operating system version, device identifierService compatibility, crash diagnosis
Usage analyticsApp feature usage, session duration, event logsProduct improvement
Crash reportsStack traces, device state at time of crashBug fixing and stability
Push notification tokenFirebase registration tokenSending push notifications
Door lock event logsUnlock records, alarm events, doorbell events, video eventsLock activity history shown to you

2.3 Information Collected via Device Permissions

We request the following device permissions only when needed for specific features. You may deny any permission; however, the corresponding feature will be unavailable.

PermissionWhen RequestedWhy
BluetoothAlways — core featureCommunicating with smart lock hardware via BLE
Location (while using app)When scanning for nearby locksBluetooth device scanning requires location permission on iOS and Android
CameraWhen scanning QR codes or uploading profile photoQR code device pairing; avatar upload
MicrophoneWhen using the video doorbell intercomTwo-way voice communication with the doorbell
ContactsWhen sharing lock accessSelecting a contact as the lock access recipient
Photo Library (read)When uploading profile photoSelecting an existing photo for your avatar
Photo Library (add only)When saving captured imagesSaving doorbell snapshots to your photo album
NotificationsOn first launchReceiving lock alerts, doorbell rings, and system notices

We do not collect raw microphone audio beyond the live intercom session. No audio is recorded or transmitted to our servers.


3. How We Use Your Information

We use your information for the following purposes, each supported by a legal basis under applicable law:

PurposeLegal Basis (GDPR)CCPA Category
Providing and operating the App's core featuresPerformance of contractService providers
Sending push notifications for lock events and alertsLegitimate interests / ConsentIdentifiers
Sending access-sharing emails or SMS on your behalfPerformance of contractIdentifiers
Diagnosing crashes and improving App stabilityLegitimate interestsInternet/network activity
Analyzing aggregate feature usage to improve the AppLegitimate interestsInternet/network activity
Complying with legal obligationsLegal obligation
Processing in-app subscription purchasesPerformance of contractCommercial information

We do not use your information for advertising, marketing profiling, or selling to third parties.


4. Information Sharing and Disclosure

We do not sell your personal information. We share information only in the following limited circumstances:

4.1 Service Providers (Sub-processors)

We engage the following third-party service providers who process data on our behalf:

ProviderServiceData ProcessedPrivacy Policy
Google LLC (Firebase Analytics)Usage analyticsAnonymous usage events, device type, OS versionpolicies.google.com/privacy
Google LLC (Firebase Crashlytics)Crash reportingCrash stack traces, device model, OS versionpolicies.google.com/privacy
Google LLC (Firebase Cloud Messaging)Push notificationsPush notification token, device identifierpolicies.google.com/privacy
Apple Inc.In-app purchases (iOS)Transaction identifier, subscription statusapple.com/legal/privacy
Google LLC (Google Play)In-app purchases (Android)Transaction identifier, subscription statuspolicies.google.com/privacy
Email service providerTransactional emailsRecipient email address, email contentPer provider privacy policy

All service providers are contractually bound to process your data only for the purposes specified by us.

4.2 Lock Access Sharing

When you choose to share lock access with another person via email or SMS, we transmit the recipient's email address or phone number to our backend server solely to send the access notification. This information is not used for any other purpose.

4.3 Legal Disclosure

We may disclose your personal information if required to do so by law or in response to valid legal requests (e.g., court orders, government requests), or to protect the rights, property, or safety of our users, ourselves, or others.

4.4 Business Transfer

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your personal information may be transferred to the acquiring entity. We will notify you of any such change via email or a prominent in-app notice.


5. Data Retention

Data TypeRetention Period
Account informationUntil account deletion, plus 30 days for recovery
Door lock event logs90 days rolling window (configurable)
Video recordingsDependent on your subscription plan; deleted after plan expiry
Crash reports90 days
Analytics data14 months (Firebase default)
Purchase recordsAs required by applicable tax and accounting laws (typically 5–7 years)

When you delete your account, we delete or anonymize all personal data associated with your account within 30 days, unless retention is required by law.


6. Data Security

We implement industry-standard security measures to protect your personal information:

Despite our efforts, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.


7. International Data Transfers

Our servers are located in the People's Republic of China. If you access the App from the European Economic Area (EEA), United Kingdom, or Switzerland, your personal data is transferred to and processed in China.

China is not recognized by the European Commission as providing an adequate level of data protection equivalent to the EEA. We rely on the EU Standard Contractual Clauses (SCCs) as the legal mechanism for transferring personal data from the EEA to China. You may request a copy of the applicable SCCs by contacting us at drlock@skychip.top.


8. Your Privacy Rights

8.1 Rights for All Users

Regardless of your location, you may:

8.2 Additional Rights for EEA / UK / Swiss Users (GDPR)

If you are located in the EEA, UK, or Switzerland, you have the following additional rights under the GDPR:

To exercise your GDPR rights, contact us at drlock@skychip.top. We will respond within 30 days.

EU Representative: We are in the process of appointing an EU representative as required by Article 27 of the GDPR. Contact details will be updated in this policy once appointed. In the meantime, please contact us directly at drlock@skychip.top.

8.3 Additional Rights for California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) grant you the following rights:

Categories of personal information collected:

CCPA CategoryCollectedExamples
Identifiers✅ YesEmail address, device ID, push token
Personal information (Cal. Civ. Code §1798.80)✅ YesName
Commercial information✅ YesSubscription purchase records
Internet/network activity✅ YesApp usage analytics, crash logs
Geolocation data✅ Yes (approximate, BLE scanning only)Location while scanning for nearby locks
Sensory/audio data❌ NoMicrophone used for live intercom only, not recorded
Inferences❌ NoWe do not build consumer profiles

To exercise your CCPA rights, contact us at drlock@skychip.top. We will respond within 45 days, with one possible 45-day extension if needed.

8.4 CalOPPA Disclosure

We comply with the California Online Privacy Protection Act (CalOPPA):


9. Children's Privacy

The App is not directed to children under the age of 13 (or under 16 for users in the EEA). We do not knowingly collect personal information from children under these ages. If you become aware that a child has provided us with personal information without parental consent, please contact us at drlock@skychip.top. We will promptly delete such information.


10. Third-Party Links and Services

The App may contain links to third-party websites or services (e.g., our in-app purchase pages managed by Apple or Google). These third parties have their own privacy policies. We are not responsible for the privacy practices of third-party sites or services and encourage you to review their policies.


11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:

The "Last Updated" date at the top of this policy reflects the most recent revision. Your continued use of the App after any changes indicates your acceptance of the updated policy.


12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Shenzhen Lanxin Zhilian Technology Co., Ltd.

Email: drlock@skychip.top

We aim to respond to all privacy-related inquiries within 30 days.