Update Date: December 2, 2025

Version Update Notification:

Welcome to StdSp! StdSp is developed, operated by HEYTAP PTE. LTD. and its affiliated companies (hereinafter referred to as "we", registered address: [138 Market Street #15-03 Capitagreen, Singapore 048946]), providing users (hereinafter referred to as "you") with functions such as app security detection and installation.

In the course of your using our accounts, websites, mobile applications, or other products and services, we may collect and use your personal information. "Personal information" or "personal data" as mentioned in the StdSp Personal Information Protection Policy (hereinafter referred to as "this Policy") refers to various types of information that can identify a natural person’s personal identity either alone or in combination with other information.

Through this Policy, we will explain to you how we process your personal information, the purposes for which we collect, use, and disclose your personal information when you use StdSp, your rights regarding your personal information, and the security protection measures we take to safeguard the security of personal information.

Please carefully read this Policy before using StdSp to understand our practices for collecting, using, and protecting your personal information. If you click "Agree" to activate StdSp, it means you fully and clearly understand the following information collection and use behaviors, as well as the rights you hold.

In principle, this Policy applies to all jurisdictions where the services provided by this app as stated herein are available. However, different jurisdictions may have different personal information protection requirements. Therefore, in addition to the general clauses, we disclose special requirements of different jurisdictions in the form of appendix-specific clauses. This appendix and the main body of this Policy together constitute the notification of our personal information processing activities in specific jurisdictions. If you are located in a region indicated in the appendix, you shall also read the content of the appendix applicable to your region. If the appendix does not specifically state otherwise, the general clauses of this Policy shall prevail. If there is any conflict or inconsistency between the content of the appendix and the main body of this Policy, the appendix shall prevail.

Regardless of where you are, the general clauses in Part A apply to you; Part B applies to users in India.

This Policy will help you understand the following:

A. General Clauses
  1. How we collect and use your personal information
  2. How we store and retain your personal information
  3. How we share, transfer, and disclose your personal information
  4. How we protect your personal information
  5. How you can exercise your rights as a data subject
  6. Third-party service providers and their services
  7. How we protect children’s personal information
  8. How this Personal Information Protection Policy is updated
  9. Contact us
B. Appendix to the Privacy Policy for India (DPDPA-Specific Clauses)
  1. The personal data we collect and the purposes of processing
  2. Your rights regarding your personal data
  3. Processing of children’s personal data

 

Text
A. General Clauses
1. How we collect and use your personal information

The information we collect depends on the functions/services you actually use, the context of your interaction with us, and the choices you make—including your privacy settings and the functions/services you use. Due to differences in the country/region of launch, system/app version, and the apps installed/downloaded on your device, the functions/services provided by this app may vary. Therefore, the actual functions/services provided by this app, as well as the corresponding personal information processing and permission request/call situations, shall be subject to the final actual product.

Please note that you are not obligated to provide us with personal information. However, if the personal information you choose not to provide is necessary for this app to provide relevant services, we may be unable to provide such services to you, nor respond to or resolve the issues you encounter. We collect personal information to operate more efficiently and provide you with the best possible user experience. Below, we detail the types of personal information we collect, as well as the reasons and purposes for collecting and using such personal information.

We collect personal information through the following channels:

For the avoidance of doubt and to transparently inform you about personal information processing, please note that if it is clearly stated below that certain personal information is only stored locally, this means such personal information will only be collected and processed locally on your device terminal and will not be uploaded to our servers, and thus is not subject to this Policy.

Please note that if you provide personal information of others, you must ensure that you have obtained authorization from the relevant data subjects.

1.1 Personal information we directly obtain from you

(1) Supporting StdSp operation and providing basic capabilities for StdSp

StdSp is a core system component in the Android system responsible for APK package installation and updates. It is also the "entry and management hub" for the entire app distribution and installation process. All installation behaviors of third-party apps must be completed through it. Its core role is to connect with the system installer, perform security detection, and process installation requests, making it a key link in the Android app security system.

To adapt StdSp to different devices and system/app versions, ensure its normal operation, and guarantee your user experience, we need to collect your Device Identifier (DUID), device MAC address, device type and model, device hardware parameters, Android system version, Android system identifier, system version and type, country/region and language settings, network operator name, mobile network status and connection type, geographic location, and StdSp version.

Malicious app interception is a service provided by StdSp to protect your device security by matching malicious apps locally/cloud, issuing interception rules. In the course of providing this service, it is necessary to obtain the app installation list locally.

(2) Product operation and maintenance, and function optimization

StdSp needs to collect buried point log information to continuously improve the stability of StdSp and optimize the service experience we provide to you. Relevant buried point information mainly includes: device identifiers, device information (brand, model, sales region, network type), system and app information (system version, app version, app package name, caller package name, etc.), and buried point data type.

(3) Personalized app recommendation services

The personalized services we provide are only launched in some countries/regions. In these regions, to provide you with personalized recommendation services and display/recommend more relevant information content to you, we will analyze your device identifiers, device information (device model, system version, network status), app usage information (e.g., app usage duration and frequency), IP address, system region, installed app list, usage information on your device, and behavioral information (including browsing and click data) to generate your personalized features and recommend content that may be of more interest to you.

1.2 Cookies and other similar tracking technologies

(1) Definition of Cookies

Cookies are small files or mechanisms stored and retrieved by website servers on your computer, mobile phone, or other local terminal devices to collect, identify, and store information about your access to and use of this product when you log on to a website or browse online content. They usually include identifiers, site names, and some numbers and characters (hereinafter referred to as "Cookies"). Our websites, online services, interactive applications, email, and advertisements may use Cookies and other similar technologies, such as pixel tags and web beacons.

(2) How we use Cookies

When you use [StdSp], we may obtain your device model, operating system, device identifier, login IP address information, etc., through Cookies or similar technologies, as well as cache your browsing information and click information to check your network environment. Through Cookies and other similar technologies, this app can identify whether you are our user each time you use it without requiring you to re-log in and verify on each page. Additionally, we can continuously optimize the user-friendliness of the website, adjust the website according to your needs, and bring you a better service experience. Please also note that Cookies may store user preferences and other information. If you choose to disable Cookies or similar technologies, this may affect your use of some functions of the website, but will not affect your use of basic and other functions.

(3) How to manage Cookies

You can manage or delete certain types of tracking technologies according to your preferences. Specifically, you can change your browser settings to prevent the browser on your device terminal from accepting Cookies from our website, thereby disabling some or all Cookies and other similar tracking technologies. In addition, you can send a "Do Not Track" request to this app through the "Do Not Track" option in your browser. For more information about Cookies, please refer to the help menu in your device’s browser, the documentation accompanying your device, or www.allaboutcookies.org.

2. How we store and retain your personal information

2.1 Storage period

We will retain your personal information for the minimum period necessary to achieve the purposes of providing products/services as required by laws and regulations. When any storage period expires or other conditions for deletion are met, we will delete or anonymize your personal information, unless otherwise specified by laws and regulations.

If we cease to operate some or all of our products or services for special reasons, we will promptly notify you, stop the personal information collection and processing activities related to such products or services, and delete or anonymize all personal information we hold related to such products or services, unless otherwise specified by laws and regulations.

Buried point log data related to product operation and maintenance and function optimization will be retained for 12 months.

StdSp has been integrated with the account service. To ensure account security and consistency of account verification, upon your successful account cancellation, we will delete or anonymize all your relevant personal information under the corresponding account system (including account information and other personal information associated with the account), unless otherwise stipulated by laws and regulations.

Please be aware that account cancellation is an irreversible action. After cancellation, we will no longer be able to provide you with account-related services.

2.2 Storage location

As a globally operating company, we provide products or services through resources and servers worldwide. To ensure service effectiveness (e.g., ensuring processing speed), we will store user personal data according to the mobile phone’s sales region and location, without violating local data protection laws. Our data centers are located in France, the United States, Singapore, India, and Indonesia. This means your personal information may be transferred to, or accessed from, jurisdictions outside the country/region where you use the products or services.

You understand that risks may vary under different data protection laws. In such cases, we will take measures to ensure that the data we collect is processed in accordance with the requirements of this Policy and applicable laws, and that your personal information receives protection equivalent to that in the country/region where you use the products or services. For example, we will request your consent for cross-border transfer of personal information, or implement security measures such as encryption, de-identification, and signing necessary data transmission/sharing agreements with data recipients before cross-border data transfer.

3. How we share, transfer, and disclose your personal information

In accordance with legal requirements, your personal information may be shared from time to time with the following companies or organizations (e.g., our affiliated companies and strategic partners to jointly provide products or services). We will require third parties to take equivalent confidentiality and security measures to process personal information through agreements or other appropriate measures.

(1) Affiliated companies: To facilitate us in providing services to you, your personal information may be shared with our affiliated companies. We will only share necessary personal information. If we or our affiliated companies change the purpose of using and processing personal information, we will seek your authorization and consent again.

(2) Authorized partners: Some of our services will be provided by authorized partners only to achieve the purposes stated in this Personal Information Protection Policy. We may share certain personal information with partners to provide you with services and enhance the user experience. We currently have no relevant partners.

Third party feature / service name: Google SDK

Partner name: Google Play

Provide service / function: personalized recommendation of advertisement

Personal information we share with third parties: gaid, duid, application installation list, region ( country ), mobile phone model, IP address

Personal information collected by the partner: gaid, duid, application installation list, region ( country ), mobile phone model and IP address

Personal information protection policy of the partner: https://policies.google.com/privacy

(3) Other organizations involved in mergers, acquisitions, or bankruptcy liquidation: In the event of a merger, acquisition, or bankruptcy liquidation involving the transfer of personal information, we will require the new company or organization that holds your personal information to continue to be bound by this Privacy Policy; otherwise, we will require the company or organization to seek your authorization and consent again. If the transfer of personal information is not involved, we will fully inform you and delete or anonymize all personal information under our control.

(4) Any entity you authorize us to disclose your personal information to;

(5) Any entity required by law to disclose your personal information to: For example, when we are required to respond to subpoenas or other legal procedures, litigation, or mandatory requests from government authorities, we may disclose your personal information if we believe such disclosure is necessary to protect our rights, ensure your safety or the safety of others, investigate fraud, or respond to government requests.

4. How we protect your personal information

The security of your personal information is very important to us. We adopt appropriate technical, administrative, and physical security measures to protect your personal information from unauthorized access, theft, disclosure, modification, or loss. We regularly review our security measures to consider available new technologies and methods.

5. How you can exercise your rights as a data subject

We respect your rights regarding your personal information and fully protect your control over your personal information. To this end, we provide you with multiple ways to conveniently and securely set your privacy and manage your personal information, ensuring the security of your personal information. Please note that operational settings may vary between different models, operating systems, and versions of product software; in addition, we may adjust operational settings to optimize your user experience. Therefore, the following management paths are for reference only. If you have any questions about the methods and channels for exercising relevant rights, you can contact us through the methods disclosed in the "Contact us" section of this Policy. Your rights regarding your personal information are as follows:

5.1 Right to be informed

We inform you how we process and protect your personal information by publishing this Policy. We are committed to ensuring transparency in the use of your information. You can understand the collection and use of your personal information by regularly reviewing this Policy, receiving emails and text messages about updates to the Personal Information Protection Policy, and contacting us through the methods disclosed in this Policy. You can view this Policy through "StdSp Settings - Personal Information Protection Policy".

5.2 Right of access

You can directly query or access your personal information in the interface of our products or services to understand the collection and use of your personal information. For example, you can view risky apps that have been disabled in this app.

5.3 Right to correction

When you find that the personal information we process about you is incorrect or incomplete, you have the right to request us to correct or supplement it. For some of your personal information, you can correct and modify it on the relevant function pages of the product or service.

5.4 Right to erasure

You can choose to delete certain personal information you provided to us. You can clear the app data and cache data stored locally on your device by selecting "App Management" in the system settings, then selecting StdSp. For example, the path to clear local data is: Settings - Apps - App Management - StdSp - Storage Usage.

5.5 Right to change authorization or withdraw consent

Each business function requires certain basic personal information to be completed (see the "How we collect and use your personal information" section of this Policy). You can change the scope of your authorization for us to continue collecting personal information or withdraw your authorization by deleting information, turning off device permission settings, changing the settings pages of relevant products or functions, or canceling your account. Specifically:

You can enable/disable this app through "Settings - Apps - App Management".

5.6 Right to obtain a copy of personal information

You have the right to request us to provide you with a copy of your personal information provided by you, or to transmit such a copy to a third party designated by you. You can contact us through the contact information listed in the "Contact us" section of this Policy. We will provide it in a timely manner in accordance with relevant laws and regulations.

5.7 Right to complain

You have the right to contact us and file a complaint through the methods disclosed in the "Contact us" section.

You have the right to file a complaint with the competent regulatory authority or initiate legal proceedings with a court of competent jurisdiction at any time regarding personal information protection issues. However, we hope to have the opportunity to resolve your concerns and issues before you contact the authorities, so please contact us directly first.

6. Third-party service providers and their services

Some of our functions/services may contain links to third-party websites, products, and services. This Policy does not apply to websites, products, and services provided by these third parties—for example, when you jump to a third-party app or website by clicking a card in this app.

Please note that before accessing these third-party website operators or using the relevant functions/services of third-party service providers through the jump function in this app, carefully read their separate personal information protection policies and related terms.

7. How we protect children’s personal information

We attach great importance to our obligations and responsibilities in protecting children’s personal information, strive to create a healthy online environment for children, and provide special protection for children. We regard anyone under the age of 18 (or the equivalent minimum age of full legal capacity in the relevant jurisdiction) as a child. Most functions and services provided by this app are mainly for adults and are not targeted at children. We do not directly provide services to children. Please note that due to objective limitations such as technical conditions, this app may not be able to actively identify the user’s age.

In accordance with applicable laws and regulations, if you are a child, you must obtain the consent of your parents or other guardians before using this app, and be sure to carefully read this Policy with your parents or other guardians. If you are a child’s guardian, you must carefully read the Children’s Privacy Statement (if any) and this Policy before helping the child use this app. Children are not allowed to use this app without the consent of their parents or other guardians.

We will not actively collect, store, use, transfer, or disclose children’s personal information, nor will we use children’s personal information for marketing purposes. If you are a child, a parent or other guardian of a child, or if you discover through other means that the information we process may include children’s personal information, please contact us through the contact information provided in this Policy, and we will take steps to delete the relevant data as soon as possible.

8. How this Personal Information Protection Policy is updated

We reserve the right to update or modify this Privacy Policy from time to time. For material changes to the Personal Information Protection Policy, we will send you a notification through an appropriate method and indicate the latest update date at the top of this Personal Information Protection Policy.

The latest version of this Personal Information Protection Policy applies to our processing activities of your personal information and shall take effect on the date of update.

9. Contact us

If you have any questions about this Policy or matters related to personal information protection, or if you have any suggestions or complaints, you can contact us or our Data Protection Officer through the following methods. We will complete identity verification and respond to your request within the time limit required by local laws and regulations. Considering the complexity and quantity of personal requests and the feasibility of technical implementation, this time limit may be extended when necessary.

If you have any questions or concerns about our Personal Information Protection Policy or practices, please contact us through the following methods:

HEYTAP PTE. LTD.

Company Address: 138 Market Street #15-03 Capitagreen, Singapore 048946

Data Subject Rights Platform: https://brand.heytap.com/en/privacy-feedback.html

Find out if there is a local data protection officer, representative or contact person in your country/region.


 

B. Appendix to the Privacy Policy for India (DPDPA-Specific Clauses)

This appendix applies only to users located in India.

You understand that this appendix is formulated in accordance with India’s Digital Personal Data Protection Act (hereinafter referred to as "DPDPA") and relevant personal data protection laws. Under the DPDPA, data processing roles are divided into Data Fiduciaries and Data Processors:

In general, we act as a Data Fiduciary in processing your personal data. However, third parties may be involved in the course of providing personalized app recommendation services. You understand that in some cases, these third parties may have independent purposes and means of processing your personal data, and such third parties will constitute independent Data Fiduciaries, processing your personal data independently.

1. The personal data we collect and the purposes of processing

In India, we provide the following functions: app security detection, app installation, personalized app recommendations, etc.

We collect your personal data only for the purpose of providing StdSp-related services and implementing relevant functions.

However, please note that we do not need to obtain your consent to process your personal data in the following circumstances:

(1) Processing personal data that you voluntarily provide to us for a specific purpose and for which you have not indicated to us that you object to processing.

(2) Providing or issuing prescribed subsidies, benefits, services, certificates, or licenses to you by the State and its institutions.

(3) The performance of functions by the State or its institutions under the laws currently in force in India, or for the protection of India’s sovereignty and integrity and national security interests.

(4) The performance of an obligation by any person under the laws currently in force in India to disclose any information to the State or its institutions.

(5) Compliance with any judgment, order, or direction issued under the laws currently in force in India, or any judgment, order, or direction relating to contractual or civil claims under the laws currently in force outside India.

(6) Taking measures to provide medical treatment or health services to any person in the event of an epidemic, disease outbreak, or other situation threatening public health.

(7) Taking measures to ensure the safety of any person, or providing assistance or services in the event of any disaster or public order disturbance.

2. Your rights regarding your personal data

Under the DPDPA, you enjoy the following rights regarding your personal data. You can exercise your rights through the methods disclosed for each specific right, or directly submit a request to us through the methods disclosed in "Contact us".

2.1 Right to information

You have the right to know:

(1) The scope of personal data we are processing and the ongoing personal data processing activities;

(2) All Data Fiduciaries and Data Processors processing your personal data, and the personal data shared;

(3) Information that needs to be disclosed in accordance with the requirements of relevant laws and regulations.

2.2 Right to correction and erasure

You have the right to (1) correct, supplement, and update your personal data; and (2) erase your personal data.

2.3 Right to appeal and redress

If you believe that we have deficiencies or omissions in fulfilling our obligations related to personal data processing, you can contact us to file an appeal and request redress. In general, we will respond within 15 working days. If you believe we cannot respond to your request, you can file a complaint with India’s Personal Data Protection Board.

2.4 Right to withdraw consent

You have the right to withdraw your consent to our processing of your personal data.

After withdrawing consent, we will no longer process your personal data accordingly. However, you understand that the withdrawal of your consent will not affect the validity of our prior processing of your personal data.

2.5 Right to appoint a representative

If you are a child or a person with a disability, you have the right to authorize your representative to exercise your rights regarding your personal data. In such cases, we will conduct necessary identity verification to confirm whether the representative is qualified to act as an agent.

3. Processing of children’s personal data

In principle, we do not provide our products and services to children.

However, please note that in India, a child is defined as a natural person under the age of 18.