隐私政策

Privacy Policy

This policy explains how Deepspace collects, uses, stores, shares and protects your personal information, and the rights you have over it.

Deepspace has not been released yet. This policy describes the current development build and will be reviewed against the final features, third-party services and release regions before launch. The updated version on this page will then apply.

1. Scope

Deepspace (深空放映 in Chinese, “the app”) is a video player developed and operated by Guizhou Redshift Deep Space Technology Co., Ltd. (贵州红移深空科技有限公司, “we”, “us”) for iPhone, iPad, Mac, Apple TV and Apple Vision Pro. This policy covers the app and its related account, membership, AI and diagnostic services.

2. Use it without signing in

Your local library and playback don’t require registering or signing in. The sources you add, your library, watch progress and playback history are stored on your device. We only create an account and process the account information described below if you choose to sign in.

3. Information we collect and how we use it

3.1 Accounts and sign-in (optional)

  • Phone number sign-in: The mainland China phone number you submit is passed to Alibaba Cloud’s number verification service and to carriers to send and check a verification code. The number is stored encrypted on our servers and shown masked in the app.
  • WeChat, Apple and Google sign-in: We only receive and verify the authorization result returned by the provider. WeChat sign-in uses the UnionID only. Apple and Google sign-in request email access; we store only an email the provider marks as verified, encrypt it, and record whether it is an Apple private relay address. We don’t collect nicknames or profile photos.
  • Sign-in devices and security records: To keep accounts secure, we record sign-in device identifiers, authentication times and results, session state, and authentication-related security events with source IP addresses. Security events and source IPs are kept for 30 days, used only for rate limiting and security auditing, and never for location profiling.
  • Syncing sources to your account: After signing in, you can choose to save the public settings of your sources to your account so they sync across devices: name, type, public address and folders, username, authentication method, scan scope, enabled state and order. Passwords and authorizations for your sources are never uploaded.

3.2 Install statistics

To understand which versions and environments are in use, the app generates a random install identifier that isn’t linked to your account and reports the device model, platform, OS and app version and build, interface language, region format, time zone, network type, and the public IP address seen by our servers. For each install we keep only the first record and the nine most recent changes. Reports are sent at most once every six hours, or sooner when the OS or app version changes. Region format does not indicate where you are.

3.3 Memberships and AI features

  • Memberships: We store your membership tier, billing period start, and the source, expiry and use time of quota reset coupons in order to provide membership benefits and quotas.
  • AI subtitle translation and AI Q&A: When you use these features, the app sends what is needed for the request to our servers, which then call a third-party large language model service. Subtitle translation sends the subtitle text to translate, the title and the languages; AI Q&A sends the title, playback position, audio and subtitle track names, interface language and your question. This content is processed in memory only and cleared after about 30 minutes. We don’t store subtitles, conversations or prompts.
  • AI usage: We aggregate model usage per billing period (such as cache hits and misses, output tokens and the resulting upstream cost) only for membership quotas and pricing. The app shows it to you as a percentage.
  • On-device processing: Recognition of image-based subtitles and subtitle language detection happen on your device. Voice questions use the system’s speech recognition; whether it runs on device depends on system support for the selected language.

3.4 Film and TV information

To organize your library, the app uses search terms recognized from file names, such as titles and years, to look up posters, stills and details from the TMDB film database. TMDB receives these search terms and your IP address.

3.5 Activity records and remote diagnostics

  • Activity records: The app keeps key operations, warnings, errors and aggregated performance data on your device for troubleshooting. These records don’t contain authentication data, credentials, raw addresses, media titles or other sensitive dynamic text, and they only leave your device when collected through remote diagnostics.
  • Remote diagnostics: When the app connects to our service, it automatically registers a random device identity; no sign-in is required. Authenticated support staff can use an administrative console to operate the app on your device, capture diagnostics and collect diagnostic records, which may include the app’s screen and audio. Settings shows whether diagnostics are enabled, connected, operable and capturing.
  • Stop anytime: Choose Stop Remote Connection under Me → Remote Diagnostics. We then refuse to operate or collect from your device and cancel related capture and transfers; restarting the app won’t turn it back on. Diagnostic records collected before you stopped are kept to finish the investigation. Our servers only keep the device identity, the stopped state and request metadata, and diagnostic records are only relayed temporarily.

3.6 Device permissions

  • Local network: to access SMB, FTP, NFS and WebDAV libraries on your local network.
  • Microphone and speech recognition: only when you ask the AI assistant a question by voice.
  • Face ID, Touch ID or device passcode: to verify it’s you before showing Recently Deleted and Hidden items.

You can turn these permissions off in system settings at any time. The related feature stops working, and nothing else is affected.

4. Information we don’t collect

  • Your media files. Videos are read and played directly from your sources and are never uploaded to our servers.
  • Passwords, tokens, bookmarks, local absolute paths and authentication headers for your sources. They stay on the device, and a new device needs to be authorized again.
  • Your library contents and what you watch. Your library and playback history stay on your device.
  • Device MAC addresses, IDFA/IDFV, unique hardware fingerprints, your full language list, contacts, precise location, or the list of other apps.

5. Third-party services

Service Purpose Information involved
Alibaba Cloud number verification Phone number sign-in Phone number
WeChat Open Platform WeChat sign-in UnionID from the authorization result; on iPhone and iPad the WeChat SDK may read the data WeChat returns for that sign-in through the system clipboard
Apple Sign in with Apple Authorization result, verified email
Google Google sign-in Authorization result, verified email
DeepSeek AI subtitle translation and AI Q&A See section 3.3
TMDB Film and TV information and images Search terms, IP address
Alibaba Cloud Object Storage Encrypted server backups Encrypted backups of our server database

6. Where and how long we keep information

  • Our services run on Alibaba Cloud, and encrypted backups of server data are kept in Alibaba Cloud Object Storage in the Hangzhou region.
  • When you sign in with Apple or Google, and when the app looks up film information from TMDB, the related information goes directly to these providers outside mainland China.
  • Retention:
    • Account information: until you delete your account.
    • Authentication security events and source IPs: 30 days.
    • Temporary phone numbers and device details from verification: cleared within 24 hours after they expire; sign-in receipts are kept for at most 24 hours.
    • AI request content: processed in memory only and cleared after about 30 minutes.
    • Membership tier and AI usage: deleted when you delete your account.
    • Install statistics: the first record and the nine most recent changes for each install.
    • Encrypted backups: up to 56 days.
    • Deletion records: only the user identifier and the fact of deletion, so that a deleted account can’t come back when a backup is restored.

7. Your rights

  • View: On iPhone, iPad or Mac, see your account details and sign-in methods under Me → Account.
  • Delete your account: Go to Me → Account → Delete account, verify your identity and confirm. Your account is deleted immediately: your cloud identity and sign-in methods are removed, every session is signed out, and Sign in with Apple authorization is revoked. Your local library stays on your device.
  • Withdraw consent: Sign out, turn off permissions in system settings, or stop remote diagnostics.
  • Other requests: For other requests such as accessing, correcting or copying your personal information, contact us as described in section 10.

8. Minors

The app is intended mainly for adults. If you are under 14, please use the app and its account services only with the consent and guidance of a parent or guardian.

9. Security

We encrypt data in transit. Fields such as phone numbers and email addresses are stored encrypted and looked up through one-way indexes. Access tokens are valid for 15 minutes and refresh tokens for 30 days, rotating on every use. Session and runtime credentials are kept out of ordinary logs, and server backups are encrypted.

10. Changes and contact

If this policy changes materially, we will let you know on this page and in the app.

For questions, comments or requests about this policy or your personal information, email contact@deepredshift.com. We will verify your identity, handle your request and reply within the period required by law.