Baixi Technology ("we," "us," or "our") understands the importance of personal information to you and is committed to protecting its security. Through this Privacy Policy ("Policy"), we explain how we collect, store, use, share, and protect your personal information when you use NetTools (the "App"), as well as the rights you have. Please read this Policy carefully and thoroughly before using the App, paying particular attention to clauses marked in bold/underlined. If you do not agree with any part of this Policy, please do not register, log in, or use the App or its related services. Your registration, login, or use of the App constitutes your acceptance of this Policy.
If you have any questions, comments, or suggestions regarding this Policy, please contact us using the details provided at the end of this document.
1. How We Collect Your Information
1.1 Information You Provide Actively
To deliver core functionality and provide continuous service, we collect information you actively provide, including but not limited to:
- Device Registration Information: When you first launch the App, we collect your device identifier (Device ID), device type (e.g., iPhone, Android, tablet), OS version, and app version to generate a unique device identity and complete account registration.
- Diagnostic Operation Inputs: When you use Ping, Port Scan, Subnet Scan, DNS Lookup, Traceroute, and other features, the target IP addresses, domains, port ranges, DNS servers, and other data you actively input.
- Feedback and Suggestions: When you submit issues through the "Feedback" feature, the text descriptions and contact information (such as email) you provide.
- Subscription and Payment Information: If you purchase a PRO membership or any paid plan, payment-related information (including order number and payment status) is processed by third-party payment channels (Apple IAP / Google Play). We only receive final payment notifications.
1.2 Information We Collect Automatically
To ensure service security and stability, we automatically collect the following information during your use of the App:
- Device Information: Device brand, model, OS type and version, screen resolution, and the App Installation ID.
- Network Status Information: Your device's network connection type (Wi-Fi / Mobile Data / No Network), IP address (only when you actively initiate a public IP query or subnet scan), and connection quality metrics.
- Diagnostic Result Data: Ping latency and packet loss rate, port scan results, local network device IP and MAC addresses (processed locally only, not uploaded to servers), DNS resolution records, traceroute hop information, and speed test rate data.
- Log Information: Brief error logs from app runtime (excluding personal sensitive data), used for troubleshooting and product improvement.
- Access Logs: Records of your API requests to our server (timestamps, endpoint paths, request parameter summaries), used for statistical analysis and service quality monitoring.
1.3 Information from Third Parties
We do not actively obtain your personal information from third parties, except in the following cases:
- Payment Result Notifications: Third-party payment platforms (Apple App Store / Google Play) send payment receipts to our server upon purchase completion, and we use them to update your subscription status. Information collected by payment platforms is governed by their respective privacy policies.
- System Announcements: If we send you important security or service announcements via push notifications, the push service is provided by a third-party platform whose data handling follows its own privacy policy.
1.4 Sensitive Permissions
To enable network diagnostic features, the App requests the following system permissions:
| Permission | Purpose | Required |
| Network Access | Required for all network diagnostic features (Ping, Port Scan, HTTP Test, Speed Test, etc.) | Yes (essential) |
| Storage (Android) | Saving diagnostic reports to local storage | No (export only) |
| Notifications (optional) | Subscription expiration reminders and important feature updates | No |
We never request access to camera, microphone, contacts, location, or any other permissions unrelated to the App's functionality.
1.5 Cases Where Consent Is Not Required
We may collect and use personal information without your consent in the following circumstances:
- Directly related to national security or defense;
- Directly related to public safety, public health, or significant public interests;
- Directly related to criminal investigation, prosecution, trial, or execution of judgments;
- Necessary to protect the life, property, or other major legitimate rights and interests of the personal information subject or other individuals, where it is difficult to obtain the subject's consent;
- The personal information collected has been publicly disclosed by the subject;
- Collecting personal information from lawful and publicly disclosed channels, such as legitimate news reports or government information disclosures;
- Necessary to maintain the safe and stable operation of the App and related services, such as detecting and handling faults;
- Other circumstances stipulated by laws and regulations.
2. How We Use Your Information
We strictly comply with applicable laws and regulations and use the collected information only for the following purposes:
2.1 Core Feature Usage
- Network Diagnostics: The IP addresses, domains, ports, and other information you input are sent to our server, which performs Ping, port scan, traceroute, and other diagnostic operations and returns results to your device. All diagnostic requests are initiated by you, and diagnostic data is not stored on the server long-term.
- Public IP Lookup: Query your device's public egress IP address and display geolocation information.
- Subnet Scan: Discover and display online devices (IP, MAC address, hostname) on your local network via ARP protocol. All scan operations are performed locally on your device and are not uploaded to any server.
- Speed Test: Measure download and upload bandwidth using the speed test nodes you select. Traffic generated during testing is used to calculate rates and the results are displayed in real time.
- DNS Lookup: Send the domain you input to the specified DNS server (or default DNS) for resolution and return the results.
2.2 Security and Operations
- Service Stability: Detect and fix server-side issues through analysis of access logs and error logs.
- Product Improvement: Continuously optimize product features and user experience through aggregated and anonymized statistical data (device type distribution, feature usage frequency). All data used for product improvement is desensitized aggregate data that does not contain any personally identifiable information.
- Security and Compliance: Monitor and restrict abnormal requests (e.g., high-frequency access, suspected attacks) as required by laws and regulations.
2.3 Subscription-Related
- Process your PRO membership subscription, including order management, subscription status verification, and feature access control.
- Send subscription expiration reminders (in-app notifications only, 3 days before expiration; no SMS or phone calls).
2.4 Notifications
- Push product update notifications and security announcements (can be disabled in Settings at any time).
2.5 No Use Beyond This Policy
Except as explicitly described in this Policy, we will not use collected personal information for any other purpose, nor will we provide it to any third-party advertisers or data brokers.
3. How We Store and Protect Your Information
3.1 Information Storage
- Storage Location: Within the People's Republic of China. We transfer data outside this jurisdiction only when:
- Required by laws or regulations;
- You provide separate, explicit consent.
- Storage Duration: We retain your personal information only for the period necessary to fulfill the purposes stated in this Policy, as follows:
- Device Registration Information: Retained for 30 days after you actively delete your account;
- Diagnostic Operation Records (server-side): Ping, port scan, traceroute, and other diagnostic data are retained for 7 days from completion, then automatically purged;
- DNS Query Records: Retained for 24 hours, then automatically purged;
- Public IP Query Logs: Retained for 30 days;
- Subscription and Order Information: Retained for 3 years after subscription expiration (financial and tax compliance requirement);
- Application Error Logs: Retained for 30 days;
- User Feedback: Retained for 90 days after the feedback is processed.
- After the above retention periods expire, we will delete or anonymize your personal information.
3.2 Information Protection
We employ the following security technologies and management measures to protect your personal information:
- Transmission Encryption: All communication between the App and our server uses HTTPS (TLS 1.2 or above) encryption to prevent data interception or tampering during transmission.
- Storage Encryption: Sensitive fields in our server database (such as device secrets) are stored using encryption.
- Access Control: Our server enforces strict permission management; only authorized personnel can access user data for work purposes, and all access is logged.
- Security Audits: Regular code security audits and penetration testing are conducted to remediate discovered vulnerabilities.
- Data Backup: Database backups are performed regularly, and backup data is also protected by encryption.
- Data Minimization: Only the minimum data necessary to provide services is collected. No personal information unrelated to diagnostic functionality is collected.
3.3 Security Incident Response
- We have established a personal information security incident response plan. In the event of a data breach or other security incident, we will immediately activate the response plan and take necessary remediation measures.
- In accordance with legal requirements, we will promptly notify you via in-app notification of: the basic situation and potential impact of the incident, the measures we have taken or will take, recommendations and remediation measures you can take to mitigate harm, and our contact information. Where it is impractical to notify each individual, we will publish announcements through reasonable and effective means.
4. How We Share, Transfer, and Disclose Your Information
4.1 Sharing
We commit to not sharing your personal information with any external party, except in the following cases:
- Sharing with Our Affiliates: Where some of our services are provided by affiliates, we sign strict confidentiality agreements requiring them to take necessary security measures as described in this Policy and to use the information solely to provide services to us.
- Sharing with Our Service Providers: Third-party service providers that provide cloud server hosting, push notifications, data analysis, and other services. We provide only the information necessary for them to deliver their services and require strict confidentiality, prohibiting any other use.
- Payment Channels: When you purchase a PRO membership, payment information is processed by Apple App Store / Google Play. We receive only the final payment notification and do not obtain your bank card number, payment password, or other sensitive information.
4.2 Transfer
We do not transfer your personal information to any third party, except in the following cases:
- With your explicit consent;
- In the event of a merger, acquisition, or bankruptcy liquidation involving personal information transfer, we will require the receiving party to continue to be bound by this Policy; otherwise we will require them to re-obtain your authorization.
4.3 Disclosure
We do not disclose your personal information, except in the following cases:
- With your explicit consent;
- When required by laws and regulations, or in response to lawful requests from judicial, administrative, or regulatory authorities.
5. Your Rights
5.1 Access and Review
You have the right to access and review the following information:
- Your device registration information (Device ID available in the Settings page);
- Your subscription status and validity (available in Settings → Subscription);
- Your feedback records (available in the Feedback History page).
5.2 Correction
If you find that the personal information we process about you is inaccurate, you have the right to request correction. You can submit a correction request by:
- Modifying the relevant settings within the App;
- Contacting us via the contact details at the end of this Policy.
5.3 Deletion
You have the right to request deletion of your personal information in the following circumstances:
- The purpose of processing has been achieved, cannot be achieved, or is no longer necessary;
- We have processed your personal information unlawfully or in violation of our agreement with you;
- We have stopped providing the relevant product or service, or the retention period has expired;
- You have deleted your account.
You may submit a deletion request via our technical support email. Please note that data subject to mandatory retention obligations under laws and regulations (e.g., financial records) is not subject to the above deletion timeframes.
5.4 Withdrawal of Consent
You have the right to withdraw any previously granted consent. You can withdraw consent by:
- Disabling specific permissions in your device settings (e.g., notifications);
- Disabling non-core feature authorizations in the App's Settings → Privacy Management;
- Contacting us to withdraw all authorizations. Please note that withdrawal of consent does not affect the legality of processing carried out before withdrawal based on consent, nor does it affect processing based on other legal grounds.
5.5 Account Deletion
You have the right to delete your account. After deletion, your device registration information and associated subscription data will be removed from our database (financial records are retained for 3 years as required by law). Please note that account deletion is irreversible.
How to Delete: Go to Settings → Account Security → Delete Account and follow the prompts.
5.6 Response to Your Requests
- We will respond to your access, correction, deletion, or withdrawal requests within 15 business days.
- To ensure security, we may require you to verify your identity before responding to your request. For reasonable requests, we generally do not charge a fee; however, for repeated requests that exceed reasonable limits, we may charge a reasonable cost-based fee.
5.7 Exceptions
In the following cases, your request may not be fulfilled, and we will provide a written explanation:
- Related to our compliance with legal obligations;
- Directly related to national security or defense;
- Directly related to public safety, public health, or significant public interests;
- Directly related to criminal investigation, prosecution, trial, or execution;
- Where there is sufficient evidence of subjective malice or abuse of rights;
- Where necessary to protect the life, property, or other major legitimate rights of you or other individuals, where authorization is difficult to obtain;
- Where responding to your request would seriously impair the legitimate rights of you or other individuals;
- Involving trade secrets.
6. How We Handle Minors' Information
6.1 Our Service Is Intended for Adults
This App is intended for adults aged 18 and over. We do not knowingly collect personal information from minors under 18. If we discover that we have inadvertently collected such information, we will promptly take measures to delete it.
6.2 Minors Using the Service
If a minor uses this App, it is presumed that their legal guardian has provided consent. If a guardian discovers that a minor has used this App and provided personal information, they should contact us using the details at the end of this Policy. We will delete the relevant personal information after verifying the guardian's identity.
7. Updates to This Policy
7.1 Change Notification
We may update this Policy from time to time. We will not reduce your rights under this Policy without your explicit consent.
We will notify you in advance of any changes through the following channels:
- Version Update Prompt: For significant changes, a prominent prompt will be displayed when the App is first launched, asking you to read and confirm the updated Policy;
- In-App Announcement: For general changes (e.g., supplementary descriptions of data processing, new service provider disclosures), an update announcement will be posted on the Settings page.
7.2 Material Changes
The following constitute material changes:
- Significant changes to our service model (e.g., the purposes of processing, types of personal information processed, or how personal information is used);
- Changes to the main objects of personal information sharing, transfer, or public disclosure;
- Significant changes to your rights regarding personal information processing and how you exercise them;
- Changes to our contact details or complaint channels.
7.3 Archive of Previous Versions
Previous versions of this Policy will be archived within the App. You may contact us to request access to historical versions.
7.4 Dispute Resolution
If you have objections to updates to this Policy or any complaints or suggestions regarding our personal information handling, please first contact us via the details below. We will respond within 15 business days. If you are dissatisfied with our response, you have the right to file a lawsuit with a court of competent jurisdiction, or to lodge a complaint with the relevant departments (e.g., cyberspace, industry and information technology, telecommunications administration, or consumer association).
8. Contact Us
8.1 Contact Information
If you have any questions, comments, or suggestions regarding this Policy, or wish to exercise any of your rights, please contact us through the following channels:
We will respond within 15 business days.
8.2 Entity Information
- App Name: NetTools - Network Toolbox
- Developer: Baixi Technology
- Operating Entity: Baixi Technology
- Registered Address: People's Republic of China
Appendix: Technical Notes on Personal Information Protection
Appendix A: Data Classification
| Data Category | Examples | Sensitivity Level | Storage Method |
| Basic Device Info | Device ID, device type, OS version | Low | Encrypted storage |
| Network Diagnostic Data | IP addresses, domains, scan results | Medium | Server temporary storage (cleared within 7 days) |
| Local Network Data | LAN IP, MAC address | Medium | Local storage only, not uploaded to server |
| Subscription and Order Info | Subscription type, order number | High | Encrypted storage, retained for 3 years |
| User Feedback | Text descriptions, contact info | Low | Standard storage, cleared within 90 days |
Appendix B: Data Transmission Security
- All client-server communication uses TLS 1.2 or above;
- API requests carry a digital signature based on the device secret to prevent tampering;
- Sensitive data (such as device secrets) is never output in logs.
Appendix C: Exercise of Data Subject Rights
| Right | How to Exercise | Response Time |
| Access / Review | In-app Settings page / Email | 15 business days |
| Correction | In-app Settings / Email | 15 business days |
| Deletion | Email (service@baixi.online) | 15 business days |
| Withdrawal of Consent | In-app Privacy Management / Email | Immediate |
| Account Deletion | In-app Settings → Account Security → Delete Account | 7 business days |
| Complaints | Email | 15 business days |
Thank you for reading this Privacy Policy. We are committed to handling your personal information with transparency and care, and to providing you with safe, reliable network diagnostic tools.
This Policy is formulated and published by Baixi Technology. Baixi Technology reserves the right to interpret this Policy.