This policy explains what personal information First Bird (the "app") collects, why we collect it, how we use and store it, and what rights you have over it.
This is a voice-only social app: the messages you record go into a public pool where strangers can listen to them. Please read section 4 carefully before using it.
1. Who we are
The app is independently developed and operated by [TO FILL: developer name], who is the controller of your personal information under this policy.
- Operator: [TO FILL: developer name]
- Location: [TO FILL: country or region]
- Contact email: privacy@yuxiaohei.com
You can reach us at that address with any question about privacy, your data rights, or this policy.
2. What we collect
We collect only what the app needs to work. Specifically:
Account information. The app signs you in with your email address and a one-time code — there is no password. We store:
- Your email address (the unique identifier for your account)
- The display name you choose
- Your chosen avatar symbol and colour
- Gender (optional, "unspecified" by default)
- Last active time
- Your notification preference
Voice content. The messages you record and send, plus related technical details:
- The audio file itself
- Duration, file size, and audio format
- Sender, recipient (public voice messages have no specified recipient), and time sent
- Which public voice messages you have received, so the same one never reaches you twice
Reports and feedback. When you report a message or send feedback, we record:
- The reporter, the reported message, the reason category, and any details you write
- The content of feedback you choose to submit
Technical and device information. To keep accounts secure, diagnose problems, and notify you about updates, we record:
- App version, operating system version, and platform (iOS or Android)
- Device model and brand
- A device identifier stored in the system keychain, used to recognise sign-ins from the same device
- Session information: sign-in tokens, IP address, client identifier (User-Agent), and session expiry
3. Why we process this information
If you are in the European Economic Area, the United Kingdom, or another region where the GDPR applies, these are our purposes and the legal bases for each:
- Creating and maintaining your account, sending and receiving voice messages, keeping your chats — basis: performance of our contract with you (Article 6(1)(b)).
- Handling reports, removing violating content, banning abusive accounts, and preventing spam and attacks — basis: our and other users’ legitimate interest in a safe community (Article 6(1)(f)).
- Diagnosing crashes and improving stability — basis: our legitimate interest in improving the service (Article 6(1)(f)).
- Sending you push notifications — basis: your consent (Article 6(1)(a)), which you can withdraw at any time in system or app settings.
- Retaining or disclosing information where the law requires it — basis: compliance with a legal obligation (Article 6(1)(c)).
4. Public voice messages: who can hear your voice
When you send a public voice message, that recording enters the public pool. Any other registered user may randomly receive it and listen to it. You cannot choose who receives it, and you cannot find out afterwards who has heard it.
A private one-to-one chat exists only after someone replies to you with their voice. Messages inside a private chat can be heard only by you and that person.
So please do not say your real name, address, phone number, social media handles, employer, financial details, or anything else you would not want a stranger to know. Anything you say in a public voice message is something you have chosen to make public.
5. What we do not do
- We do not sell or rent your personal information, and we do not hand it to third parties for advertising.
- We do not perform voiceprint recognition. Your recordings are stored and played back as audio only; we do not extract biometric features that could uniquely identify you, so they are not biometric data under Article 9 of the GDPR.
- We do not show third-party ads in the app or embed advertising trackers.
- This website sets no cookies and does no cross-site tracking. Visits are counted with Cloudflare Web Analytics, which does not identify individual visitors.
6. Who else handles your data
We share some data with the following categories of service provider, who process it only on our instructions and never for their own purposes:
- Object storage provider (Cloudflare R2) — stores the audio files. The bucket is not publicly accessible; playback uses temporary links valid for about 15 minutes.
- Email delivery provider — sends sign-in codes and account emails.
- Website analytics (Cloudflare Web Analytics) — counts page views on this website, such as which pages are visited, the referring site, and the browser and country. It sets no cookies, does not store your IP address, and does not follow you across other websites. It covers this website only, not the app.
- Server and database hosting provider — runs the app’s backend.
We may also disclose necessary information where the law requires it, where legal process compels it, or where it is necessary to protect someone’s safety.
7. Where your data is stored
Our servers and storage are located in [TO FILL: country or region where data is stored]. If you use the app from another country, your personal information will be transferred there and processed locally.
For transfers of data out of the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism. You can request details at the address above.
8. How long we keep it
- Voice content: automatically cleaned up after [TO FILL] days.
- Account information: kept for as long as your account exists.
- Sessions: expire and are cleaned up automatically; you can also sign out at any time.
- Reports: kept for a period after they are resolved, to prevent repeat abuse and support follow-up.
- After account deletion: see the next section.
9. What happens when you delete your account
You can delete your account at any time from within the app (see section 11). When you do:
- Your email address is anonymised and your profile is no longer usable.
- You can no longer sign in, and your chats are no longer visible to you.
- We keep one string derived from your email address using an irreversible keyed hash (HMAC-SHA256).
The only purpose of keeping that hash is to stop a deleted email address from registering again, which prevents people from evading bans by repeatedly deleting and recreating accounts. The string cannot be reversed into your email address, and we cannot use it to work out who you are.
10. Your rights
To the extent applicable law provides them, you have the right to:
- Access the personal information we hold about you and receive a copy.
- Correct information that is inaccurate or incomplete.
- Erase your personal information (the "right to be forgotten").
- Restrict our processing of your information.
- Object to processing based on legitimate interests.
- Receive a portable copy of the information you gave us.
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint with your local data protection authority.
To exercise any of these, email privacy@yuxiaohei.com. We will respond within one month of receiving your request; if it is complex we may extend that, and we will tell you in advance. To protect your account we may need to verify your identity first.
Exercising these rights is free, and we will not treat you differently for doing so.
11. How to delete your account
In the app, go to Settings > Account Actions > Delete Account and enter the code sent to your email address. This cannot be undone.
If you can no longer sign in, email privacy@yuxiaohei.com from the address you registered with, asking us to delete the account, and we will do it for you.
12. Children
The app is intended for people aged 16 and over. We do not knowingly collect personal information from anyone younger.
The app lets strangers exchange voice messages, which we do not consider suitable for children. If you are a parent or guardian and believe a child under 16 has given us personal information without your consent, contact privacy@yuxiaohei.com and we will delete the information and close the account.
13. Security
- Audio files are stored in a bucket that is not publicly accessible, so they cannot be reached by guessing a URL.
- Playback uses temporary links valid for about 15 minutes, which stop working once they expire.
- All traffic between the app and our servers is encrypted in transit.
- Sign-in uses short-lived access tokens plus refresh tokens, which are rotated; once a refresh token expires you must sign in again.
- The deletion blocklist stores only irreversible email hashes, never plain addresses.
That said, no method of transmission over the internet or electronic storage is completely secure. We take reasonable technical and organisational measures to protect your information, but we cannot guarantee absolute security.
14. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the date on this page and notify you in the app where appropriate. We encourage you to review this page periodically.
15. Region-specific terms
European Economic Area and United Kingdom (GDPR / UK GDPR). Section 3 sets out the legal basis for each purpose. You have the right to complain to the data protection authority where you live, where you work, or where the alleged infringement took place.
Japan (Act on the Protection of Personal Information, APPI). The business operator handling personal information is the operator named in section 1. The purposes of use are those set out in section 3. We do not provide your personal information to third parties without your consent, except to the processors described in section 6, which is entrustment of processing and does not require separate consent. For disclosure, correction, or suspension of use, contact us at the address in section 1.
South Korea (Personal Information Protection Act, PIPA). The personal information protection officer is the operator named in section 1, reachable at the same address. The categories collected, the purposes, and the retention periods are set out in sections 2, 3, and 8. You may refuse to provide personal information, but since an email address is required to sign in, refusing means you cannot use the app. Personal information is destroyed once the retention period ends or the purpose is fulfilled.
California (CCPA / CPRA). In the past 12 months we have not sold personal information and have not shared it for cross-context behavioural advertising, and we do not intend to. We will not discriminate against you for exercising your privacy rights. California residents can exercise the rights to know, delete, and correct by contacting us at the address in section 1.