"WITHBOX" Privacy Policy
Effective Date: August 20, 2026
This Privacy Policy explains how AINEST TECHNOLOGY PTE. LTD. ("AINEST," "we," "us," or "our") handles personal information when you use WITHBOX applications, devices, websites, software, and related services (collectively, "WITHBOX"). It also explains the choices and rights available to you.
Please read this Policy before using WITHBOX or enabling an optional feature. Where applicable law or platform rules require consent, we will request it through a clear affirmative action. Declining an optional permission or connected service will not prevent use of unrelated core features, although the requested feature may be unavailable.
This Policy applies globally. Additional notices may be shown in context before WITHBOX accesses sensitive information, requests an operating-system permission, connects an external account, or starts an optional feature.
1. Scope, Controller & Definitions
AINEST TECHNOLOGY PTE. LTD. is responsible for the WITHBOX processing described in this Policy. This Policy covers WITHBOX applications and services on supported phones, tablets, computers, browsers, and WITHBOX storage devices. A third-party website or service remains governed by its own privacy policy, but Section 9 describes third-party SDKs and services integrated with WITHBOX.
• Sensitive information may include account credentials, precise location, private communications, payment information, contacts, and face-related information, depending on applicable law.
• Processing includes collecting, accessing, using, storing, transmitting, sharing, deleting, or otherwise handling information.
• Google user data means information obtained from Google APIs or derived from that information, including Gmail and Google Drive data.
2. Information We Process
The information processed depends on the features you use, the accounts you connect, the permissions you grant, and your device configuration.
• Device, application, network, and diagnostic information: WITHBOX device identifier and name, product model, storage and warranty status, application and operating-system version, language, IP address, network type, carrier, login user agent, push registration information, crash reports, performance information, security events, and activity or audit logs.
• Files, media, and metadata: files and folder paths; filenames, sizes, formats, timestamps, and checksums; photos, videos, music, documents, and their metadata; thumbnails; media descriptions; location metadata; playlists; and metadata generated to organize, search, back up, synchronize, or display your content.
• Face and person organization information: face groupings, face-photo associations, names, relationships, birthdays, sex, cover photos, and technical face features generated on or for the WITHBOX device when you use person-based photo organization or search. This information is used for your private media-management features and is not used for advertising.
• Contacts and schedules: contact names, phone numbers, email and postal addresses, social or messaging identifiers, organizations, job titles, birthdays, notes, avatars, calendar or plan titles, times, locations, participants, descriptions, labels, and reminders when you import, create, or manage these items.
• Email and connected-account information: email address, provider-specific authorization code or OAuth token, authorization scopes and status, mailbox folders, message and thread identifiers, senders, recipients, subjects, snippets, message bodies, attachments, timestamps, drafts, delivery information, and read, spam, sent, or deletion status.
• Cloud-storage information: connected-account identifier, access and refresh tokens, file and folder names, paths, identifiers, sizes, timestamps, metadata, and content selected for browsing, synchronization, upload, or download.
• Location and weather information: approximate or precise coordinates where permitted, manually entered places, address or place queries, and cached weather-location information.
• AI and communication information: prompts, chat messages, conversation context, requested actions, tool parameters, generated responses, summaries, action confirmations, and content you choose to submit for an AI-enabled feature.
• Payment and transaction information: order number, selected product or service, amount, currency, payment status, transaction identifier, and limited billing or fraud-prevention information returned by the payment provider. WITHBOX does not intentionally receive full payment-card or bank-account credentials from PayPal.
• Support and legal communications: messages, attachments, contact details, troubleshooting information, and records needed to respond to requests, disputes, security incidents, or legal obligations.
WITHBOX does not sell personal information. We do not use private files, emails, contacts, face-related information, or Google user data for third-party advertising.
3. How We Use Information
• Store, organize, index, search, preview, back up, restore, transfer, and manage files, media, contacts, email, schedules, and other user-directed content.
• Perform actions you request, such as sending or managing email, transferring a selected cloud file, retrieving metadata or weather, processing a payment, or generating an AI response.
• Deliver account, service, security, reminder, and device-status notifications.
• Diagnose crashes, prevent abuse, protect accounts and devices, maintain audit records, and improve reliability and performance.
• Provide customer support, enforce applicable terms, comply with law, and establish, exercise, or defend legal claims.
• Develop or improve WITHBOX using aggregated or de-identified information where reasonably possible. We do not use Google user data or private user content to train or improve a general-purpose or foundation AI model.
4. Legal Bases, Permissions & User Choice
Depending on your location and the feature involved, we process information to perform our contract with you, with your consent, to comply with legal obligations, or for legitimate interests such as security, fraud prevention, support, and service reliability where those interests are not overridden by your rights.
• Optional processing: Location, connected email or cloud accounts, online metadata, payment, and generative AI features are optional. WITHBOX will request applicable permissions or authorization in context.
• Prominent disclosure and consent: If access to personal or sensitive information would not be reasonably expected, including relevant background collection, WITHBOX will provide an in-app disclosure describing the data and purpose before collection and will request an affirmative action where required. Closing or leaving a notice is not treated as consent.
• Controls: You may change operating-system permissions, disconnect a connected account, revoke provider authorization, stop using an optional feature, or contact us. Disabling a permission may affect only the related feature. Section 9 identifies controls and limitations specific to each integration.
5. How We Share or Disclose Information
We disclose information only as reasonably necessary for the purposes described in this Policy:
• Service providers: To vendors that provide infrastructure, diagnostics, push delivery, support, security, or other processing on our behalf for non-Google data, subject to appropriate contractual and security requirements. AINEST does not provide these vendors with Gmail or Google Drive content for cloud processing.
• Legal and safety reasons: When reasonably necessary to comply with law or valid legal process, protect users, investigate abuse or security incidents, or establish or defend legal claims.
• Corporate transactions: In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable notice and consent requirements and continued protection of personal information.
• With permission: For another purpose clearly disclosed to you when you provide consent.
We do not sell personal or sensitive information. We do not share it with data brokers or use it for cross-context behavioral advertising, creditworthiness, or lending decisions.
6. Storage, Retention, Security & International Transfers
• Connected services: OAuth tokens, provider authorization codes, synchronized content, and related metadata may remain on the WITHBOX device until you clean the connected-account data, close the relevant account, delete the content, or it is no longer reasonably necessary. For Google services specifically, OAuth authorization data and synchronized Google content are stored only on the user's WITHBOX NAS/device, under the user's control, and are transmitted directly between that device/NAS and Google APIs. Disconnecting or revoking a provider account stops future authorized access but may not automatically remove copies already stored on your WITHBOX device; use the available clean-data or deletion controls or contact us if you also want those copies removed.
• Retention: We retain personal information only for as long as needed for the feature, security, dispute resolution, or legal compliance. Account deletion has a 72-hour recovery period under the current WITHBOX account process. After that period, account-linked personal information scheduled for deletion will be deleted or de-identified unless retention is required for security, fraud prevention, backup integrity, legal obligations, or the establishment or defense of claims. Residual backup copies, where applicable, are isolated from ordinary use and removed through the applicable backup cycle.
• Security: We use reasonable administrative, technical, and organizational safeguards, including access controls, authentication, transport encryption using HTTPS/TLS for personal and sensitive information transmitted over public networks, security monitoring, logging controls, and personnel restrictions. No system is completely secure, and you are responsible for protecting account credentials and physical access to your WITHBOX device.
• International transfers: WITHBOX is offered globally, and providers listed in Section 9 may process non-Google information in countries other than where you live. Google user data is transmitted directly between your device/WITHBOX NAS and Google APIs, not through AINEST cloud servers. Where required, we use legally recognized transfer mechanisms, contractual safeguards, notices, and consent. The privacy laws of another jurisdiction may differ from those in your location.
7. Your Rights & Account Deletion
Subject to applicable law, you may request access, correction, export, restriction, objection, deletion, or withdrawal of consent. You may also have the right to complain to a local data-protection authority. We may need to verify your identity before completing a request.
• Connected accounts: Disconnect the account in WITHBOX and, where applicable, revoke authorization in the provider’s account-security page. Revocation prevents future API access but does not by itself delete local copies already synchronized to your WITHBOX device.
• Account deletion: Use the account-deletion option available in WITHBOX to submit a deletion request. The current process provides a 72-hour recovery period before scheduled deletion. You may also email admin@ainest-tec.com for assistance or to request deletion when you cannot access the application.
• Deletion scope: After the recovery period, we will delete or de-identify account-linked personal information covered by the request, including stored connected-account credentials and synchronized data under our control, except information that must be retained for the limited reasons described in Section 6. Deleting data from WITHBOX does not necessarily delete the original data held by Google, an email provider, a cloud-storage provider, or another third party.
• Response: We aim to respond to verified privacy requests within 15 days, or within the period required by applicable law. If we deny or limit a request, we will explain the reason where required.
External Account-Deletion Request
If you cannot access WITHBOX, email admin@ainest-tec.com with the subject “WITHBOX Account Deletion Request” and identify the WITHBOX account and device concerned. Do not send your password, safe-box password, OAuth token, or email-provider authorization code. We may request limited additional information to verify account ownership before scheduling deletion. We will confirm the request, explain the 72-hour recovery period, and identify any information that must be retained for a legally permitted reason.
8. Children’s Privacy & Policy Updates
WITHBOX is a general-audience service and is not directed primarily to children under 13 or the minimum age required by local law. Children may use WITHBOX only with authorization from a parent or legal guardian where required. A child-directed application must not use Google Sign-In or another Google API service that accesses Google Account data. If we learn that personal information was collected from a child without required authorization, we will take reasonable steps to delete it.
We may update this Policy when products, data practices, laws, or platform rules change. We will update the date above and provide notice through the application, website, email, or another appropriate channel. Before using Google user data or other sensitive information for a materially different purpose, we will update the relevant disclosure and obtain new consent where required. The latest version will remain publicly available.
9. Third-Party SDKs and Services
WITHBOX uses a limited number of third-party software development kits (SDKs), application programming interfaces (APIs), payment services, and user-authorized connected services. Not every integration is available or active on every platform, device, region, or account. Except for components needed for functions such as crash diagnostics or push delivery, a third-party service generally receives data only when you use, enable, or authorize the corresponding feature.
FlowGate is an internal service operated by AINEST TECHNOLOGY PTE. LTD. and is not a separate third party. Where a WITHBOX AI, media-generation, or payment request is routed through FlowGate to an external provider, the relevant external provider is disclosed below.
We seek to limit information sent to each provider to what is reasonably necessary for the stated purpose. Third-party providers process information under their own privacy policies and may process it in other countries or regions. You can manage optional features through WITHBOX settings, connected-account settings, and applicable operating-system permissions. A privacy-policy disclosure does not replace an in-app prominent disclosure or affirmative consent where either is required.
AMap (AutoNavi)
Provider: AutoNavi Software Co., Ltd. and applicable affiliates.
Type / Platforms: Location, map, geocoding APIs and SDKs; used on supported mobile, web, and server-assisted features.
Purpose: Provide maps, convert coordinates and addresses, and support location-related search, weather, and photo-location features.
Data processed: Precise or approximate location where authorized, latitude and longitude, address or place queries, IP address, device model, operating-system and network information, and SDK diagnostic information where the client SDK is used.
When used / controls: Used when you invoke a location-based feature. You can deny or withdraw location permission in your device settings; some location features may then be unavailable.
Tencent Bugly
Provider: Tencent and its applicable affiliates.
Type / Platforms: Crash reporting and application diagnostics SDK on supported client applications.
Purpose: Detect crashes, diagnose faults, measure stability, and improve application performance and security.
Data processed: Crash reports, stack traces, application version, device model, operating-system version, network status, IP address, device or installation identifiers where configured, and technical diagnostic context associated with a fault.
When used / controls: Diagnostic processing may occur automatically when a supported client crashes or encounters an error. Collection varies by platform and SDK configuration.
Google Services (Sign-In, Gmail and Google Drive)
Provider: Google LLC and applicable affiliates.
Type / Platforms: OAuth authorization and user-authorized account, email, and cloud-storage APIs.
Purpose: Sign you in with Google, identify the authorized account, synchronize or manage Gmail messages, and browse, synchronize, upload, or download Google Drive files at your direction.
Data processed: Google account identifier, name and email address, OAuth access and refresh tokens, authorization scopes, Gmail message headers, senders, recipients, subjects, message content, attachments and status, and Google Drive file or folder names, metadata, and file content selected for transfer.
Direct device/NAS connection and storage: Google user data is transmitted directly between the user's device/WITHBOX NAS and Google APIs. AINEST does not receive, store, or inspect Gmail or Google Drive content on its cloud servers. OAuth authorization data and synchronized Google content are stored only on the user's WITHBOX NAS/device, under the user's control. They are retained as described in Section 6. Disconnecting the Google account stops future authorized access but does not automatically delete locally synchronized copies; use available clean-data or deletion controls, revoke access through Google, or contact us.
Google API Limited Use: WITHBOX’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide or improve prominent user-facing features requested by the user. It is not sold, used for advertising, transferred to data brokers, used for credit or lending decisions, or made available for human reading except with the user’s affirmative agreement for specific data or where permitted for security, legal compliance, or appropriately aggregated internal operations.
AI restriction: Google user data is not used to train, improve, or create a general-purpose, foundation, frontier, or shared AI model and is not stored in conjunction with such a model. Any user-directed AI processing involving Google user data must be limited to a permitted user-facing feature, use only the data needed for that request, follow Google’s applicable consent and transfer rules, and must not be retained by a general-purpose model provider for model training.
When used / controls: Used only after you complete Google authorization. You can disconnect the account in WITHBOX and revoke access through your Google Account permissions. To request removal of locally stored Google data, use the relevant WITHBOX clean-data or account-deletion control or contact us.
JPush (Jiguang Push)
Provider: Shenzhen Hexun Huagu Information Technology Co., Ltd. (Jiguang).
Type / Platforms: Push-notification SDK on supported Android and iOS applications.
Purpose: Register a device for notifications, deliver service and security messages, and measure whether a notification was delivered or opened.
Data processed: Push token or registration ID; device and installation identifiers such as Android ID, OAID, AAID, IDFA or Boot ID where available and permitted; device model and manufacturer; operating-system and app version; language; network type, carrier and IP address; and push delivery and interaction logs. Depending on the SDK version, configuration, operating system, and permissions granted, JPush may also process identifiers such as IMEI, MAC or IMSI, Wi-Fi or network details, software-list information, and approximate or precise location information.
When used / controls: In current supported mobile versions, the SDK may initialize when the application starts and may maintain a background connection for push delivery; WITHBOX does not currently provide a separate in-app switch that fully disables the JPush SDK. Disabling notifications in operating-system settings prevents visible notifications but may not by itself stop SDK registration or necessary technical communications. Because this processing may occur in the background, WITHBOX will provide a prominent in-app disclosure and request affirmative consent before collection where required by applicable law or platform rules. Depending on the device, delivery may also use Apple Push Notification service, Firebase Cloud Messaging, or a device-manufacturer push channel.
Jiguang Privacy Policy · Apple Privacy Policy · Google Privacy Policy
The Movie Database (TMDB)
Provider: The Movie Database (TMDB) and its applicable operator.
Type / Platforms: Server-side movie metadata and image API.
Purpose: Search for movie information and retrieve posters, backdrops, cast, crew, release, genre, rating, and description metadata.
Data processed: Movie-title or metadata search queries, selected TMDB identifiers, language preference, and technical request information. WITHBOX does not intentionally send the underlying video file to TMDB.
When used / controls: Used when movie metadata lookup is requested or enabled. You may choose not to use online metadata matching.
This product uses the TMDB API but is not endorsed or certified by TMDB.
QWeather
Provider: QWeather / Hefeng Internet Technology and applicable affiliates.
Type / Platforms: Server-side weather-data API.
Purpose: Provide current weather, forecasts, and weather-related information for a requested location.
Data processed: City or place name, location identifier, address or coordinates where used, language preference, IP address and technical request information.
When used / controls: Used when you request weather information. You may enter a location manually or deny device-location permission where the feature supports manual entry.
NetEase Mail
Provider: NetEase and its applicable email-service affiliates.
Type / Platforms: User-authorized IMAP and SMTP connected-email service.
Purpose: Verify an authorized mailbox, synchronize folders and messages, download attachments, change message status, and send messages at your direction.
Data processed: Email address, app-specific authorization code, mailbox folders, message identifiers, senders, recipients, subject lines, message content, attachments, timestamps, read or deletion status, and SMTP delivery information.
When used / controls: Used only after you provide a NetEase Mail address and authorization code. You can disconnect the mailbox in WITHBOX and revoke or regenerate the authorization code in NetEase Mail settings.
Sina Mail
Provider: Sina and its applicable email-service affiliates.
Type / Platforms: User-authorized IMAP and SMTP connected-email service.
Purpose: Verify an authorized mailbox, synchronize folders and messages, download attachments, change message status, and send messages at your direction.
Data processed: Email address, app-specific authorization code, mailbox folders, message identifiers, senders, recipients, subject lines, message content, attachments, timestamps, read or deletion status, and SMTP delivery information.
When used / controls: Used only after you provide a supported Sina Mail address and authorization code. You can disconnect the mailbox in WITHBOX and revoke or regenerate the authorization code in Sina Mail settings. Disconnecting without cleaning data may leave previously synchronized copies on your WITHBOX device.
QQ Mail
Provider: Tencent and its applicable email-service affiliates.
Type / Platforms: User-authorized IMAP and SMTP connected-email service.
Purpose: Verify an authorized mailbox, synchronize folders and messages, download attachments, change message status, and send messages at your direction.
Data processed: Email address, app-specific authorization code, mailbox folders, message identifiers, senders, recipients, subject lines, message content, attachments, timestamps, read or deletion status, and SMTP delivery information.
When used / controls: Used only after you provide a QQ Mail address and authorization code. You can disconnect the mailbox in WITHBOX and revoke or regenerate the authorization code in QQ Mail settings.
Baidu Netdisk
Provider: Baidu Netdisk and its applicable operating affiliates.
Type / Platforms: User-authorized OAuth and cloud-storage API.
Purpose: Connect a Baidu Netdisk account and browse, synchronize, or download cloud files at your direction.
Data processed: Baidu account identifier and profile information returned by authorization, OAuth access and refresh tokens, authorization status, file and folder names, paths, sizes, timestamps and other metadata, and file content selected for transfer.
When used / controls: Used only after you authorize the Baidu Netdisk connection. You can disconnect the account in WITHBOX and revoke authorization through Baidu Netdisk.
PayPal
Provider: PayPal, Inc. and the PayPal affiliate applicable to your region.
Type / Platforms: Payment and order-processing service on supported purchase flows.
Purpose: Create, approve, capture, verify, and reconcile payments or account recharge orders.
Data processed: Order number, amount, currency, order description, payment status, PayPal transaction identifier, and the PayPal account, billing, payment, fraud-prevention, or device information that you provide directly to PayPal. WITHBOX does not intentionally receive your full payment-card or bank-account credentials from PayPal.
When used / controls: Used only when you choose PayPal and initiate a payment. Payment credentials are entered in PayPal-controlled interfaces where applicable.
Alibaba Cloud Qwen
Provider: Alibaba Cloud and its applicable affiliates.
Type / Platforms: Generative AI model service accessed through AINEST-operated FlowGate.
Purpose: Generate chat responses, summaries, classifications, search assistance, and other AI-enabled results requested by the user.
Data processed: Prompts, chat messages and relevant conversation context, model and request parameters, generated responses, and text or other content that you choose or authorize WITHBOX to submit for the requested AI function. Depending on the feature, submitted context may contain personal information from notes, files, media descriptions, calendar items, contacts, or connected services. Google user data remains subject to the separate restrictions in the Google Services disclosure above.
When used / controls: Used when you invoke an AI feature configured to use Qwen. Avoid submitting information that is not necessary for your request. If you do not use AI features, this content is not sent to Qwen for AI processing. WITHBOX does not authorize Qwen to use Google user data or other private user content to train or improve a shared, general-purpose, or foundation model.
Volcano Engine / ByteDance (Jimeng and Seedance)
Provider: Beijing Volcano Engine Technology Co., Ltd. and applicable ByteDance affiliates.
Type / Platforms: Image- and video-generation model services accessed through AINEST-operated FlowGate.
Purpose: Generate or transform images and videos from prompts and optional reference media.
Data processed: Text prompts, selected model, generation parameters, reference-image URLs, first- or last-frame images, other media you choose to submit, task identifiers, generation status, and generated output URLs or media.
When used / controls: Used only when you start a supported image- or video-generation task. Do not submit third-party personal information or sensitive content unless you have the right and a lawful basis to do so.
MusicBrainz and Cover Art Archive
Providers: MetaBrainz Foundation and Internet Archive.
Type / Platforms: Server-side music metadata and cover-art APIs.
Purpose: Match music files with recording, artist, album, release, and cover-art metadata.
Data processed: Music title, artist and album search terms, release identifiers, language or region context where applicable, the WITHBOX account display name currently included in a technical request header, and technical request information. WITHBOX does not intentionally send the underlying audio file to these providers.
When used / controls: Used when online music metadata matching is requested or enabled. You may choose not to use online metadata matching.
MetaBrainz Privacy Policy · Internet Archive Terms and Privacy Information
10. Contact Us
Data Controller: AINEST TECHNOLOGY PTE. LTD.
Privacy and account-deletion email: admin@ainest-tec.com
Please identify the WITHBOX product, account, and device concerned, but do not send passwords, OAuth tokens, provider authorization codes, payment credentials, or unnecessary private content. We aim to respond to verified requests within 15 days or the period required by applicable law. Account-deletion instructions are provided in Section 7.