JUMPER Health Privacy Policy

Effective Date: June 10, 2026

1. Our Privacy Principles

Before the details, here are the principles that explain why this Policy is shorter than most privacy policies you have seen:

2. Information We Collect (by Scenario)

2.1 Guest Mode

In Guest Mode we do not ask you for any personal information. We create an anonymous account for you whose identifier is randomly generated by the Application (it is unrelated to your phone's hardware). Your measurement data is associated with that anonymous account and synchronized to our servers.

Please note: the credentials of the anonymous account are stored only on your current device. If you uninstall the Application or clear its data, you will permanently lose access to that account and its data, and no one — including us — can recover it for you. Before uninstalling, you can delete your data via the in-app "Delete Account" function, or bind an email address under "Account & Security" to convert the anonymous account into a registered account that can sign in.

2.2 Registration and Sign-In

2.3 Profile Information (All Optional)

2.4 Family Member Profiles

You may create profiles for family members under one account (same data categories as Sections 2.3 and 2.5). Before creating a profile, please ensure you have the family member's consent; where the family member is a minor or lacks legal capacity, you must be their guardian. Family member profile data is visible only to your account and is protected to the same standard as your own data.

2.5 Measurement and Health Data (Core Functionality)

When you take measurements with a connected Compatible Device or enter records manually, we collect the corresponding measurement data and synchronize it to our servers, including (depending on the devices you actually use):

Purpose: showing you results, history, and trends; synchronizing across devices; and — only if you apply for one — serving as reference for a personalized training program.

This data constitutes special categories of personal data; it is encrypted in storage and in transit. We never use it for advertising or sell it to third parties.

2.6 Additional Information Collected On Demand

The following information is collected only when you use the corresponding feature; declining only makes that feature unavailable:

Scenario Information collected Purpose
Weight measurement requiring BMI Height BMI calculation
Body composition measurement Height, gender, date of birth (to derive age) Body composition indicators (such as body fat percentage) require height, age, and gender as calculation parameters
Jaundice measurement Baby's time of birth and related details Determining age-based reference ranges for results
Before pelvic floor assessment/training Contraindication self-check questionnaire answers (with completion time) Determining, in accordance with the device's instructions for use, whether the feature can be made available to you; the answers are stored with your profile as a record of this safety feature
Applying for a personalized training program Recent symptoms, your own description, and obstetric information — which may include delivery date, delivery method, number of pregnancies, number of births, number of miscarriages/abortions, last menstrual period, number of fetuses, and due date (per the actual form) Enabling professionals to recommend a training program for you; a separate informed-confirmation page is shown before you apply
Feedback Feedback content, feedback type, contact details (optional) Handling and responding to your feedback

2.7 Device and Application Information

2.8 Usage Analytics (Can Be Turned Off at Any Time)

To improve the product, the Application records feature-usage events (such as "connected a device of a certain type", "added/deleted a record", "started/finished a measurement"). Events are associated with your account identifier for troubleshooting; event parameters contain only technical information such as duration, source, and mode, and never contain any measurement values or health content. Uploads of analytics events include the app version, phone model, operating system version, and language setting, to distinguish issues across device models and versions.

You can turn usage analytics on or off at any time in Settings; once turned off, we stop collecting new analytics events.

2.9 Crash Diagnostics

The Application does not integrate any third-party crash-collection SDK. If the Application crashes, we may receive diagnostic information processed by Google or Apple through the official developer channels of Google Play or the App Store — whether such information is shared is controlled by your device's system settings and governed by Google's/Apple's privacy policies.

3. System Permissions

The Application requests the following system permissions for the purposes described below. Each permission is requested when you first use the corresponding feature, and you can revoke it at any time in system settings (only the corresponding feature becomes unavailable):

Permission Purpose Notes
Bluetooth / Nearby devices Scanning for and connecting to your measurement devices On Android 12 and above we declare that Bluetooth scanning is "never for location"; we cannot and do not derive your location via Bluetooth
Location (Android 11 and below only) Older Android versions mandatorily require the location permission for Bluetooth scanning We do not collect, store, or upload any location information
Notifications Showing an ongoing notification while a measurement or training session runs in the background, and sounding abnormal-reading alerts
Microphone Used only to record fetal heart sounds when using the wired Fetal Doppler Recordings are stored as part of the fetal monitoring record (see Section 2.5); the Application does not otherwise use the microphone
Photos / Media Selecting an image only when you set an avatar We can only access the images you actively select

The permissions used by the iOS version (Bluetooth, microphone, photos, notifications) serve the same purposes as above.

4. How We Use Your Information

We use the information we collect only for the following purposes:

We will not: use your information for advertising or marketing profiles; sell or rent your information to third parties; or make solely automated decisions that produce legal or similarly significant effects on you.

For users in the European Economic Area (EEA) and the United Kingdom — legal bases for processing: we process your personal data under Article 6 GDPR; health data constitutes special categories of personal data and is additionally processed under Article 9:

Processing activity Legal basis (Art. 6 GDPR) Additional basis for health data (Art. 9)
Account creation, sign-in verification, cross-device sync Performance of a contract (6(1)(b))
Collection, storage, and display of health measurement data Performance of a contract (6(1)(b)) Your explicit consent (9(2)(a))
Contraindication self-check and feature availability control Performance of a contract (6(1)(b)) Your explicit consent (9(2)(a))
Personalized training program service Your consent (6(1)(a)) Your explicit consent (9(2)(a))
Usage analytics (can be turned off) Your consent (6(1)(a))
Responding to feedback; protecting service and account security Legitimate interests (6(1)(f))
Compliance with laws, regulations, and regulatory requirements Legal obligation (6(1)(c))

5. Sharing and Disclosure

We do not share your personal data with any third party, except in the following circumstances:

6. Storage Location, International Transfers, and Retention

6.1 Storage location. Your data is stored on servers located in the Hong Kong Special Administrative Region of China; an encrypted local copy is also kept on your device to support offline use.

6.2 International transfers. Because you may use the Application anywhere in the world, your data will be transferred to and stored and processed in Hong Kong. For users in the EEA, the United Kingdom, and other jurisdictions with statutory requirements for international data transfers, we protect such transfers under the Standard Contractual Clauses adopted by the European Commission (SCCs, Decision 2021/914), supplemented by technical measures such as encryption in transit and at rest (see Section 7). You may request information about these safeguards using the contact details at the end of this document. Where your jurisdiction imposes additional mandatory requirements on data exports, the supplementary terms we publish for that region prevail.

6.3 Retention periods.

7. How We Protect Your Information

Please note that no internet environment is absolutely secure; keep your account credentials safe and use a sufficiently strong password.

8. Your Rights

You have the following rights regarding your personal data:

8.1 Access and rectification: you can view and edit your profile, family member profiles, and measurement records directly in the Application;

8.2 Erasure: you can delete individual measurement records in the Application; deleting a record also deletes the corresponding data from our servers;

8.3 Obtaining a copy: you may request a copy of the personal data we hold about you using the contact details at the end of this document;

8.4 Data portability: for data you have provided that we process by automated means (such as measurement records and profile information), you may request that we provide it in a structured, commonly used, machine-readable format;

8.5 Withdrawal of consent: for processing based on your consent, you may withdraw it at any time, and withdrawing is as easy as giving consent — for example, by turning off usage analytics in Settings or revoking a permission in system settings. Withdrawing one consent affects only the corresponding feature; it does not affect your use of other features and does not require you to delete your account. If you wish to end all processing and delete your data, use the account deletion function (consequences described in Section 6.3). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal;

8.6 Account deletion: in-app via "Account & Security → Delete Account"; consequences are described in Section 6.3;

8.7 Restriction of and objection to processing (EEA/UK users): in the circumstances provided by the GDPR, you have the right to request restriction of processing or to object to processing;

8.8 Complaint: you have the right to lodge a complaint with the data protection supervisory authority of your place of residence.

You can exercise these rights through the in-app functions or by emailing the address at the end of this document. For security, we may first need to verify your identity. We will respond within one month of receiving your request; this may be extended for complex cases, in which case we will explain the reason. For manifestly unfounded or excessively repetitive requests, we may charge a reasonable fee or refuse the request, stating our reasons.

9. Children's Personal Data

The Application is intended for adults; persons under 18 years of age, or under the age of majority in their jurisdiction, may not register for or use the Application. We rely on your declaration to determine whether you meet the age requirement and do not collect additional identity documents for this purpose.

Certain features of the Application (jaundice measurement, fetal heart monitoring, etc.) process health data about fetuses, newborns, or infants. Such data is actively provided by you as a parent or guardian and is processed as part of your data (or of a family member profile you created), with all protections of this Policy applying. Beyond this, we do not knowingly collect personal data from children; if we discover that we have collected a child's personal data without verifiable guardian consent, we will endeavor to delete it promptly.

10. Updates to This Policy

We may update this Policy from time to time. Updated versions will be published within the Application; for material changes (such as changes to processing purposes, data categories, storage location, or recipients), we will notify you prominently (such as by in-app pop-up) and, where new processing of special categories of data is involved, seek your consent again.

Language versions: this Policy is executed in Chinese as the authoritative version. The English and other language versions are translations for convenience only; in the event of any inconsistency, the Chinese version prevails, except where the law of your jurisdiction mandatorily requires the local-language version to prevail.

11. Contact Us

We will respond to your request within one month of verifying your identity. If you are not satisfied with our response, you have the right to lodge a complaint with the data protection supervisory authority of your place of residence; should you wish to resolve a dispute through judicial means, the governing-law and dispute-resolution provisions of the JUMPER Health Terms of Service apply.