PRIVACY POLICY / 2026-08-01
Privacy Policy
We process personal information for clear and specific purposes, limit processing to what is necessary, provide transparency and maintain appropriate safeguards. Refusing an optional permission will not affect basic features unrelated to that permission.
1. Who we are
WALI AI Interpretation is developed and operated by Shenzhen Baiyi Business Co., Ltd. Official website: www.abcfanyi.com. You may submit requests to access, correct, delete or copy personal information, withdraw consent, close an account or make a complaint through your organization administrator or the service channels published on the website.
2. Account, identity and service information
To support sign-in, account administration and security checks, we process username, nickname or display name, organization, optional email address and phone number, login IP address, login time, device information, login result and account status. Individual identity verification processes a name, national identification number and a live face image, which is automatically compared by an entrusted identity-verification service. The face image is used only for that verification and is not stored by our platform; we retain only the result, necessary score and log information. Organization verification processes the company name, unified social credit code, representative’s name, identification information and supporting materials, which are manually reviewed by authorized staff and stored in access-controlled private object storage. Some of this information is, or may be, sensitive personal information. We explain why it is necessary and the possible impact and obtain separate consent before submission. We also process room titles, language settings, terminology, captions, translations, participation status, usage duration and billing records.
3. Microphone, audio and captions
The client collects audio only after you actively start interpretation, voice input or an audio or video call and grant microphone permission. Online audio is sent to the speech-recognition service configured for your organization. Recognized text may then be sent to text translation or AI-assisted translation services. Captions and translations are used according to room rules for real-time display, correction, archiving and export. Your audio, captions and translations are not used to train general-purpose models unless we separately explain this and obtain the authorization required by law. Supported offline processing takes place on your device. Only while you actively keep an interpretation or call task running may a foreground service with an ongoing notification continue processing audio as a live stream after the screen is locked or the app moves to the background. Processing stops when you stop the task, leave the room or end host control. When no task is running, the client and related media SDKs do not collect microphone, camera or media content while idle or in the background.
4. Audio and video calls and public invitations
Permission to start a call is jointly checked against enterprise membership status, approved organization verification, approved individual identity verification for the initiating account, and the organization-level call switch. For access control and compliance auditing, we process organization and account identifiers, verification results, and call-room and invitation status; identification numbers and face images are not shown to other participants. When you actively start or join a room, we also process your nickname, room title, participant status, microphone and camera state, selected input devices, necessary device and network status, and the media streams required for live transmission. Media streams are used by default only during the call and are not retained as a long-term call recording. If the host enables shared captions, the web host mixes currently published room audio locally into one recognition stream and recognized text may be sent to the selected translation service. Residual queued audio is cleared after processing stops, while captions, translations, participation status, usage duration and billing records follow the applicable archive rules. When joining through a public invitation, the browser accesses selected devices only after you actively accept the notice and grant system permission. Your nickname, image, voice and captions may be visible to other participants. You may turn off the microphone or camera, leave the call, or revoke device access in browser settings.
5. Device information, application status and permissions
Necessary device information. To secure accounts and services, complete online authentication, adapt media processing and diagnose faults, the client or media SDK automatically processes limited device information only when you sign in, start online interpretation, or actively start or join a call: device brand and model, operating-system and API versions, CPU and memory status, screen resolution, battery level, network connection type, IP address, Android ID, this application’s package name and process information, application version, and the device-MAC-address value returned by the system during media-component compatibility checks. On restricted Android versions, that value may be masked or fixed. This information is used only for online authentication, anti-fraud and security, media transmission adaptation, service-quality statistics and troubleshooting. It is normally processed once during relevant feature initialization and updated during use only after a network or device-state change or when genuinely needed for quality diagnosis. Processing does not continue after the feature is closed.
Specific application installation status. The client does not read or upload a complete software installation list. When you actively choose WeChat Pay, it queries only whether the WeChat client is installed so it can determine whether payment can be opened, normally once per payment attempt. When you actively enable on-device speech output and choose a speech service, Android may return services capable of handling that request so you can make a selection. This is not used to compile or upload a complete software installation list. The client does not read usage records of other applications or a list of other running processes.
Clipboard. When you tap a button such as “Copy invitation link,” the client writes only the link or text you selected to the system clipboard. It does not read, scan or upload existing clipboard content.
Permission requests. Network status helps select an online or offline route. Microphone permission is requested only when you start interpretation, conversation translation, voice input or a call; camera permission only when you start video or take a photo; Bluetooth access only when you select a paired headset; notifications show active tasks; display-over-other-apps is used only for floating captions you enable; and screen capture is used only when you select device audio and confirm the system prompt. Administrators can choose app-market or in-app updates. Store builds do not request unknown-app installation permission. An official direct-distribution build requests it only after you confirm an in-app update and the APK size and SHA256 have been verified; Android's system installer still requires your confirmation and the app never installs silently. You can decline and use the app market without affecting unrelated features.
Information not processed. The client does not request phone-state, location, contacts, SMS or broad-storage permission and does not actively read an IMEI, IMSI, MEID, device serial number, SIM serial number, phone number, contacts, messages, precise location, external-storage files or a complete software installation list. Real-time media uses only coarse Wi-Fi, Ethernet, cellular or offline state and does not read the carrier network subtype.
6. Camera, photos and image translation
Camera translation uses the system camera to create a photo that you actively take. Importing from photos uses the system photo picker to read the single image you expressly select and does not request broad access to your entire photo library. For online image translation, the selected image and language settings are sent to the configured image-translation service. The original image is kept in a temporary cache and cleared when the page is closed. A translated image is written to the system media library or a location you select only when you explicitly save it.
7. Storage on your device
The client stores sign-in tokens, remembered account details, preferences, downloaded offline models and translated-speech cache on your device. You can clear cache, delete offline models and sign out through the account area, or clear application data through system settings. Uninstalling the application normally deletes data held in its private application directory.
8. Entrusted services and third-party SDKs
Depending on organization settings and the mode you select, online features may use entrusted services. Principal embedded SDKs are: (1) WeChat OpenSDK Android, developed by Shenzhen Tencent Computer Systems Co., Ltd., activated only when you choose WeChat Pay to process the application identifier, payment request parameters, whether WeChat is installed, payment status and payment callback result for registering the payment application, determining whether WeChat can be opened and receiving the result. The SDK queries that specific application status through a system interface and transmits payment results over an encrypted network, normally once per payment attempt; see the WeChat OpenSDK Android Privacy Policy; (2) veRTC, developed by Beijing Volcano Engine Technology Co., Ltd., activated only when you start or join a call to process device brand and model, operating-system and API versions, CPU and memory status, screen resolution, battery level, network type, IP address, Android ID, this application’s package name and process information, the device-MAC-address value returned by the system, microphone and camera status, media-device information, live audio and video streams, accelerometer information and call-quality data. These data support online authentication, call establishment and transmission, orientation adaptation, security, quality statistics and troubleshooting. The SDK automatically obtains necessary data through system interfaces during media-feature initialization and use and transmits them over encrypted links; see the veRTC SDK Privacy Policy; and (3) Microsoft Azure AI Speech SDK, developed by Microsoft, activated only when that online recognition capability is configured and you start online interpretation to process language settings and live audio and return recognized text; see Microsoft Speech data and privacy guidance. Offline recognition, translation and inference components process content only on the device and do not send it to their open-source project providers. These SDKs do not process corresponding business data merely because you accept this Policy; the relevant feature and required authorization must first be activated. We provide only data necessary for the feature, contractually define the purpose, duration, method, information categories and security responsibilities, and supervise entrusted processing.
9. Retention and security
Account information is retained while the account remains active and for the minimum period required to satisfy legal obligations. Live media streams are processed only during the call and in necessary short-lived technical queues. Caption history, bills, login records and operational records are retained according to administrative settings, contracts and legal requirements, and are deleted or anonymized when the applicable period ends or deletion is legally required. When a specific date cannot be determined in advance, we use the minimum necessary period based on whether the service purpose has been completed, whether you continue to retain a record and any legal obligation. Safeguards include access control, encryption in transit, permission isolation, security auditing and oversight of entrusted processors.
10. Your rights and account closure
You can view account and usage records, change your password and clear local cache. You may also request access to, correction, copying or deletion of personal information, withdraw consent and request account closure. After phone verification and administrative review, an approved closure request signs the account out of logged-in devices. Billing, security or audit records that must be retained by law are deleted or anonymized when the required period ends. Withdrawal of consent does not affect processing that lawfully occurred before withdrawal.
11. Sensitive personal information
National identification numbers, face images, identification-document images and organization-verification materials, as well as audio or video that may reveal identity, voiceprints, likeness or private activities in a particular context, may be sensitive personal information. A face image for individual verification is used only for the current automated check and is not stored by our platform. Organization materials are available only to authorized reviewers. If you do not consent to the sensitive information needed for identity verification, you may continue using basic features that do not require verification, but you cannot use features such as audio and video calls that require verified identity.
12. Children, cross-border processing and updates
The product is primarily intended for organizations and is not offered to children under 14. Resources located in mainland China should be used by default. If an organization selects a service that may involve processing outside mainland China, the required notice, assessment and consent must be completed separately in accordance with law. If material changes are made to processing purposes, methods, information categories or retention rules, we will update this Policy and request confirmation again. We regularly conduct personal information protection compliance audits.