Last updated: September 15, 2025
Effective date: September 15, 2025
Tuya Smart Inc. and its affiliated companies (hereinafter collectively referred to as "we" or "Tuya") are committed to protecting your personal privacy.
"SmartLife App SDK Privacy Policy" (hereinafter referred to as "this policy") applies to the products or services provided by Smart Life App SDK. When you use our services, we will collect and process your relevant information*, so please read this policy carefully and make sure you understand our rules for collecting and processing your personal information (including how to collect, use, save, and share this information), and provide you with ways to access, update, delete and protect this information.*
This policy mainly explains to you:
What personal information we collect
Who we share your personal information with
Transfer of collected information
Rights related to personal information
Information security measures
Information retention period
Statement regarding policy changes
Contact us
Definition
In this policy,
Affiliated companies: companies directly or indirectly controlled by Tuya; or companies that control Tuya directly or indirectly; or jointly control the same company with Tuya; or companies that are directly or indirectly controlled by the same company as Tuya, including but not limited to parent companies and subsidiaries ; Subsidiaries controlled by the same parent company as Tuya, etc.
Personal information: Various information recorded electronically or by other means that can be used alone or in combination with other information to identify an individual or reflect the activities of a specific individual.
Smart devices: refer to non-standard computing devices produced or manufactured by hardware manufacturers that have human-machine interfaces and can transmit information through wireless networks, including smart home appliances, smart wearable devices, smart air purification equipment, etc.
Application: refers to a mobile application developed by a developer.
1. What personal information do we collect?
In order to provide you with our services, we will ask you to provide the personal information necessary for such services. If you do not provide personal information, we cannot provide you with corresponding products or services. Based on different devices and systems (Android/IOS) and system versions, as well as the scope decided by developers when integrating and using our SDK products, the information collected will be different. Therefore, developers should inform users of the personal information actually collected. illustrate.
In order to ensure that you can normally use the corresponding functions and services of the Smart Life App SDK product, the developer application may apply for the following permissions from your device system. The authorization method is determined by the device system developer and the developer application. Please know that even if you have agreed to enable permission, we will only collect relevant information to a minimum extent. You can cancel authorization in the system at any time. Once you cancel authorization, we will no longer continue to collect and use relevant personal information based on the corresponding permissions, and we will not be able to provide you with services corresponding to this permission. However, your decision to turn off permissions will not affect the previous collection and use of information based on your authorization.
Special reminder: Because we provide you with many types of products or services, and the scope of specific products or services that different developers choose to use is different, the type and scope of personal information collected and used by different products or services will be different. Please use Specific product or service functions shall prevail.
- Smart Life SDK
(1) When you use functions and services integrated with Smart Life SDK products, we may collect the following personal information from you:
Personal information type | Personal information description | Collection purpose | Applicable sdk type |
---|
Basic information | It may include the mobile phone number, email, login password, and nickname you entered. | The developer application collects your basic information to help the developer provide you with registration, login, account information and feedback functions. | Android SDKIOS SDK |
User Feedback | Your email address, mobile phone number, and feedback content (attached pictures or videos) | Developers use the app to collect your user feedback information so that we can promptly handle your application issues and smart device-related failures. | Android SDKIOS SDK |
location information | May include rough positioning information, background location information, region, time zone, city, latitude and longitude, home address, country | Developer applications collect your location information to help developers provide you with registration, login, account information, family management, smart scenes and device distribution functional services. | Android SDKIOS SDK |
Network information | Wi-Fi name (SSID), gateway ID | Developer applications collect your network information to help developers provide you with device network configuration services. | Android SDKIOS SDK |
Mobile device information | Device model, operating system type and version, app version number, push notification identifier (Android SDK only), log files, system locale, and app installation list | In order to ensure your normal use of our services, maintain the normal operation of our services, improve and optimize our service experience, we will automatically collect your mobile device information | Android SDKIOS SDK |
Smart device information | Device name, device ID, online status, activation time, firmware version, upgrade information, MAC address, Wi-Fi information (SSID, BSSID, Wi-Fi MAC address, Wi-Fi password), device MAC address, device ID, device IP, device Bluetooth MAC address, information reported by smart devices | In order to ensure your normal use of smart devices, maintain the normal operation of functional devices, improve and optimize the service experience of smart devices, we will automatically collect your smart device information | Android SDKIOS SDK |
media information | photos, videos | Developer applications collect your media information, and SDK helps developers provide you with user feedback and IPC device capture function services. | Android SDKIOS SDK |
health information | Height, weight, body fat mass (bfm), body mass index (bmi) and skeletal muscle mass (smm), body fat rate, muscle mass, body fat index, obesity level, ideal weight, weight control, visceral fat index, net weight , body water, bone mass, protein rate, bmr, metabolic age, body score, body shape, subcutaneous fat rate, subcutaneous fat mass, heart rate, number of steps, calories, mileage, sleep records, training records, body temperature, blood oxygen, systolic blood pressure , diastolic blood pressure, pressure, start time, jump pattern, number of jump ropes, exercise duration, calories burned, maximum number of jumps to maintain, average speed, maximum speed | When you connect a smart body fat scale, fitness tracker, bracelet, or smart skipping smart device through a developer application, the developer application collects the health data collected by the device (the specific data fields received depend on the fields collected by the developer's business), sdk help Developers provide you with smart device usage function services | Android SDKIOS SDK |
(2) The permissions involved in the Smart Life SDK are as follows. Specific permissions are applied by developers themselves. The Smart Life App SDK does not participate in any permission applications:
Permission type | Purpose of use | Applicable sdk type |
---|
Positioning | In order to provide you with setting home location; automatically obtain Wi-Fi name (IOS 13 and above); automatically discover surrounding Bluetooth devices (Android 6.0 and above) | Android SDKIOS SDK |
Background positioning | To provide you with geofencing functionality | Android SDKIOS SDK |
microphone | To provide you with camera device intercom and the ability to control your device using voice | Android SDKIOS SDK |
External storage reading and writing | In order to provide you with the functionality of camera devices to capture screenshots, save and read videos | Android SDK |
Read phone status | In order to provide you with automatic filling in mobile phone numbers and realize one-click login function | Android SDKIOS SDK |
camera | In order to provide you with the function of scanning QR codes to add special types of equipment | Android SDKIOS SDK |
photo album | In order to provide you with user feedback services, you can upload photos or videos to facilitate locating your problems; in order to save photos or videos captured by IPC devices | Android SDKIOS SDK |
Bluetooth | In order to provide you with Bluetooth device network distribution and communication functions | Android SDKIOS SDK |
Message notification | In order to push you notifications about products or services, especially when you purchase relevant services, we need to send you alerts so that you can capture real-time status. | Android SDKIOS SDK |
floating window | In order to show you the real-time camera footage in a floating window | Android SDK |
HomeKit | You can use the Home Kit to use device discovery, device network configuration, device status and device control functions, and exchange data with the IOS built-in [Home] App through Home Kit. | IOS SDK |
HealthKit | You can use the Health Kit to count weight, height data, running, and swimming statistics, and exchange data with the IOS built-in [Health] App through the Health Kit. This will only be done when using a body fat scale, bracelet, or watch device. data exchange | IOS SDK |
face id | In order to provide you with facial recognition verification for safe and convenient account password-free login. | IOS SDK |
fingerprint | In order to provide you with fingerprint ID password-free login | Android SDK |
2. Who do we share your personal information with?
Tuya only shares your personal information in ways known to you. We will share your personal information with the following parties:
- Disclose your personal information to third-party service providers who provide certain business-related services to us, including data analysis, infrastructure provision and other similar services, to ensure that they can provide services to us.
- Disclose your personal information to customers and other business partners who directly or indirectly provide you with smart devices.
- In the event of a reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or a portion of our business, assets or stock (including, but not limited to, the foregoing in connection with any bankruptcy or similar proceeding), to an affiliate or Disclosure of your personal information by other third parties. In such event, you will receive clear notice via email and/or on our website of the change in ownership, incompatible new uses of your personal information, and your choices regarding your personal information.
- Disclose your personal information to our subsidiaries or affiliates for the purpose of conducting business activities on a regular basis.
- We will share your personal information reasonably and lawfully under the following necessary or appropriate circumstances:
- Comply with applicable laws, regulations, legal procedures, policies and/or standards, or requirements of appropriate public agencies and governmental authorities;
- Enforce our Terms of Use and other agreements, policies and standards, including investigating any potential violations;
- protect our operations, business and systems;
- Protect our and/or other users’ rights, privacy, safety or property, including you; and
- Risk management, detection and identification of illegal, fraudulent, deceptive or malicious activities.
3. Transfer of collected information
Tuya operates globally, and Personal Data may be transferred, stored and processed outside of the country or region where it was initially collected. Also, the applicable laws in the countries and regions where we operate may differ from the laws applicable to your country of residence (please kindly check Tuya Global Data Center accordingly). Under the Personal Data protection framework and in order to facilitate our operation, we may transfer, store and process your Personal Data in jurisdictions other than where you live. We protect Personal Data in accordance with this Policy wherever it is processed and take appropriate contractual or other steps to protect it under applicable laws.
The European Commission has determined that certain countries outside of the European Economic Area (EEA), the UK or Switzerland can provide adequate protection of Personal Data. Where Personal Data of users in the EEA, Switzerland, or the UK is being transferred to a recipient located in a country outside the EEA, Switzerland, or the UK which has not been recognized as having an adequate level of data protection, we ensure that the transfer is governed by the European Commission’s standard contractual clauses. You can review the agreement on the basis of approved EU standard contractual clauses per GDPR Art. 46. For more information, see here. If you would like further details on the safeguards we have in place under the data transfer, such as a copy of the Standard Contractual Clauses concluded between us and our affiliate recipient that Personal Data may be transferred to, you can contact us directly as described in this Privacy Policy.
Also, when we transfer data to our processors, the data may be transferred outside the EEA, For details on such third parties information sharing, please see "List of Third-party Information Sharing*".* 4. Rights related to personal information
In view of your use of SDK products and services through developer applications, in order to protect your rights to view, copy, correct, supplement, withdraw consent to personal information and cancel developer application accounts, we have agreed with developers in this privacy policy to require developers Promise to provide an easy-to-operate implementation. If you want to check, correct, supplement, copy personal information or cancel the developer's application account, you should use the above rights implementation methods provided by the developer. If the developer fails to provide it as promised, you can use the methods listed in Article 9 of this Privacy Policy Contact us using the contact information and we will try our best to coordinate, support and ensure the realization of your above rights. 5. Information security measures
We maintain commercially reasonable physical, administrative and technical safeguards to maintain the integrity and security of your personal information. Tuya provides a variety of security strategies to effectively ensure the information security of users and devices.
In terms of device access, we use Tuya's proprietary algorithms to ensure data isolation, access authentication and authorization applications.
In terms of data communication, communication using security algorithms and transport encryption protocols as well as commercial-grade information encrypted transmission based on dynamic keys is supported.
In terms of data processing, strict data filtering and verification and a complete data review process are adopted.
In terms of data storage, all confidential information of users will be securely encrypted for storage.
In addition to the above-mentioned technical security guarantees, Tuya has also formulated a series of security guarantees at the institutional and management control levels, including assigning positions and responsibilities, holding security and privacy protection training courses, strengthening employee data protection awareness, controlling access rights and other measures. To prevent data loss, illegal use, unauthorized access or leakage, tampering or damage.
If you believe for any reason that your interaction with us is no longer secure (for example, if you believe the security of your Tuya account has been compromised), please inform us immediately by sending an email to privacy@tuya.com as described below. If a security incident occurs that affects the security of your personal information, we will notify you as soon as possible through your reserved email address, phone number, message center push, etc., and inform you of suggestions and other information to reduce or prevent related risks. . When necessary, we will take corresponding remedial measures in a timely manner in accordance with the internal security incident emergency plan, and report to the relevant competent authorities in accordance with regulations.
We have obtained corporate privacy certification. For more information about EPC, please click here to view. 6. Information retention period
We will process your personal information within the shortest period required to achieve the purposes stated in this policy or as required by laws and regulations, unless a longer period of time is required based on specific legal requirements. We will determine the appropriate retention period based on the amount, nature and sensitivity of the personal information, and after the retention period, we will destroy your personal information. When you explicitly request to delete your personal information, we will set this as a task and no longer retain your personal information.
After we confirm your deletion or cancellation request, or after we terminate the operation of the corresponding products or services, we will stop retaining and delete your personal information. Generally, we will no longer retain your personal information once the specified information retention period is reached. If we are unable to destroy the information for technical reasons, resulting in the retention of personal information beyond the storage period, we will take appropriate measures to prevent further use of your personal information, including anonymization.
7. Protection of children’s personal information
We do not provide services directly to children, nor do we use children's personal information for marketing purposes. If you are a parent or guardian and you believe that a minor has submitted personal information to Tuya, you may contact us at privacy@tuya.com to ensure that such personal information is promptly deleted. 8. Statement on policy changes
We will update this policy at least annually as our information practices change. If we make any material changes, we will notify you via email (sent to the email address specified in your account) or post a notice within the App before the changes take effect. We recommend that you periodically browse the Application to obtain the latest information on our privacy practices.
9. Contact us
If you have any questions about our practices or this Policy, please contact us as follows:
Tuya Smart Inc.
Postal Mailing Address: 333 West San Carlos Street Suite 600 San Jose, CA 95110
For European Union or United Kingdom data subjects, you have the right to lodge a complaint with a supervisory authority concerning Tuya’s data processing activities. For questions, or to exercise your rights as an EU or UK data subject, please contact our DPO here:
If you are in India:
Our Consent Manager is Will Yu, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform. You may contact him via email:privacy@tuya.com. If you have any grievance regarding the processing of your personal data by Tuya, you may submit your grievance to our designated Grievance Officer or Data Protection Officer (DPO). We will endeavor to acknowledge and address your grievance within 15 working days from the date of receipt. Contact for Grievance Redressal: Grievance Officer: Mr. Will Yu Email:privacy@tuya.comSubject line: “DPDP Grievance – [Your Issue]” If you are not satisfied with the response or have not received a response within the specified timeframe, you have the right to escalate the matter to the Data Protection Board of India (DPB) in accordance with the Digital Personal Data Protection Act, 2023.