AstroBox Privacy Policy

Last Updated: July 1, 2026

AstroBox (hereinafter referred to as the “Software,” “App,” or “we”) is an open-source cross-platform wearable device management toolbox used to connect, manage, and maintain wearable devices owned by or lawfully used by users. This Privacy Policy explains how the Software processes device information, account information, logs, files, network requests, and data related to third-party services.

The source code of this Software is released under the GNU Affero General Public License v3 (AGPL v3), allowing users and the community to inspect its implementation. We do not sell user data, do not serve personalized advertisements, do not use third-party advertising SDKs, and do not use data for cross-app or cross-website tracking.

1. Data We Process

1.1 Device Information

When you voluntarily connect a wearable device via Bluetooth, the Software may read the following information from the device. This data is primarily processed locally to display device status, install resources, check firmware updates, or perform device management operations:

Such information is processed or stored locally on your device by default and is not automatically uploaded to our servers.

1.2 Account Information (Optional)

The Software supports optional sign-in to Xiaomi accounts, vivo accounts, AstroBox accounts, and BandBBS community accounts. Authentication occurs only when you voluntarily choose to use related features.

Depending on the account type, the Software may store the following data in the local WebView’s localStorage:

Account tokens are used only for operations initiated by you, such as checking firmware updates, downloading community resources, or accessing account-bound resources. We do not sell, rent, or use such data for advertising or tracking purposes.

1.3 Local Logs

The Software generates local runtime logs for diagnostics and troubleshooting. Logs typically include timestamps, log levels, module names, runtime states, and error messages.

Logs are never automatically uploaded. If you voluntarily submit logs for support, please ensure they do not contain information you do not wish to share.

1.4 User-Imported Files

The Software supports files selected by users, including:

File TypeExtensionPurpose
Mini App.rpkInstall to supported wearable devices
Watch Face.faceInstall to supported wearable devices
Binary Resource.binGeneric device resource

These files are processed locally and transferred to devices via Bluetooth. They are not automatically uploaded unless you explicitly choose to upload, share, or download resources.

2. Purpose of Data Processing

3. Network Communication and Third-Party Services

3.1 Bluetooth Communication

The Software communicates with wearable devices using Bluetooth Classic SPP or BLE. Bluetooth permission is required before use. Data transmitted may include installation packages, watch faces, device configuration commands, music files, and encrypted handshake data.

The web version of AstroBox may request Web Bluetooth API or Web Serial API permissions, limited to devices you explicitly select.

3.2 HTTPS Requests

The Software may perform network requests in the following scenarios:

ScenarioService ProviderPossible Data TransmittedTrigger
Fetch community resource indexGitHub / CDNResource index requestUser action
Download community resourcesGitHub / CDNDownload request metadataUser action
Xiaomi account login / firmware queryXiaomi official servicesOAuth info, device model, firmware versionUser action
vivo account login / firmware queryvivo official servicesCookies, device model, firmware versionUser action
AstroBox account authenticationAstroBox servicesOAuth2 tokens and auth dataUser action
BandBBS loginBandBBS servicesCookie tokens and request metadataUser action
DNS over HTTPSAliDNS / DNSPod / custom DoHDNS queriesUser-enabled

All remote requests use HTTPS or equivalent secure transport. Third-party services independently process data under their own privacy policies.

4. Data Sharing

We do not sell, rent, or trade your personal data. We only share data under the following circumstances:

5. Data Storage and Retention

Data CategoryStorage LocationRetention
Account tokens and metadataWebView / browser localStorageUntil logout, data clearance, or uninstall
Application logsOS log directoryLast 7 days by default
Downloaded resourcesApplication data directoryUntil deleted or app uninstall
User-imported filesUser-selected locationUser-managed
Network configuration (e.g. DoH)localStorageUntil modified or deleted

6. Security Measures

No transmission or storage method can guarantee absolute security. Please keep your device and accounts secure.

7. Children's Privacy

The Software is not intended for children under 13. We do not knowingly collect personal information from children under 13.

8. User Rights, Account Deletion, and Data Removal

9. App Store Privacy Disclosure

For the iOS version, App Store privacy labels are declared according to actual data handling. Most data is processed locally. When you use login, firmware queries, community downloads, DNS over HTTPS, or third-party services, necessary requests may be sent to corresponding providers. We do not use data for tracking.

10. Build Information

The Software may display build metadata such as Git commit hashes, build timestamps, and build environment usernames for version tracing and diagnostics only.

11. Open Source and Transparency

AstroBox is free and open-source software licensed under GNU AGPL v3 (with additional terms). Users may inspect source code, audit implementation, report issues, or contribute.

12. Changes to This Policy

We may update this Privacy Policy due to feature changes, legal requirements, or platform rules. Material changes will be announced through release notes, in-app notices, or our official website.

13. Contact

This Privacy Policy is written in English for international reference. In case of conflict between different language versions, the Chinese version shall prevail.