RedMate

Legal

Privacy Policy

This Policy explains how RedMate handles your personal information. We commit to keeping this Policy aligned with the app's actual behavior — please report any discrepancy to the email below.

Last updated
Important: your Xiaohongshu session cookies are stored only inside the local isolated session — never uploaded to us or to any third party.

Introduction

We respect and protect your personal information. This Policy is written in line with the PRC Personal Information Protection Law, Cybersecurity Law, Data Security Law, and is structured along the lines of GB/T 35273-2020.

1. What we collect

1.1 Registration and account

  • Email address (for registration, sign-in, receiving one-time codes and notifications).
  • Sign-in code: a short-lived 6-digit one-time code delivered by email, used solely to verify the current sign-in request; we do not retain it in cleartext.

1.2 Bound Xiaohongshu accounts

  • Xiaohongshu session cookies: stored on your machine inside an Electron isolated session — never uploaded to us or to any third party.
  • Public XHS info: nickname, avatar URL, user ID — fetched transiently by the in-app browser view only when you view your own account list.

1.3 Content you create

  • Note drafts (title, body, topics, mentions).
  • Images and videos you upload.
  • Publish-task and schedule metadata (target account, time, status).

1.4 Device and runtime

  • OS type and version (macOS).
  • App version.
  • Redacted stack traces and breadcrumbs from launch, crash, and error events.

1.5 What we do NOT collect

  • Your Xiaohongshu password.
  • Your browsing behavior on Xiaohongshu beyond what you explicitly act on.
  • Data from other apps on your device.
  • Your location.
  • Your contacts, photo library, microphone, or camera (unless you explicitly upload assets).

2. How we use the information

  • To register and authenticate your account.
  • To sync drafts and assets across the devices you authorize.
  • To schedule and execute the publish tasks and automation you trigger.
  • To provide data analytics features.
  • To diagnose crashes and errors via a crash-monitoring service — events are redacted for Bearer tokens, API keys, cookies, signed URLs, and email addresses (vendor disclosed in 3.1).
  • To send service announcements and necessary notices by email.

3. Sharing, transfer, and public disclosure

We do not sell your personal information. We do not share with third parties except:

(1) with your prior explicit consent; (2) where required by law or a valid governmental or judicial request; (3) through the third-party providers below, sharing only the minimum data required.

3.1 Third-party providers

ProviderPurposeData sharedRegion
SupabaseAuthentication; cloud storage of notes and assetsEmail, note content, assets, publish-task metadataOutside mainland China
SentryCrash and error monitoringApp version, redacted stack traces and breadcrumbsOutside mainland China
RevenueCatSubscription / entitlement management (later phase)User UUID, entitlement stateOutside mainland China
AppleApp Store in-app purchase (where applicable)Handled directly by Apple; we never see card numbers or payment credentialsAs determined by Apple

If we later enable direct payment channels (WeChat Pay, Alipay), payment information is processed by the respective platforms; we receive only order status and the minimal reconciliation data required.

4. Storage

4.1 Local storage

  • Xiaohongshu session cookies: stored by Electron's isolated session under ~/Library/Application Support/RedMate in the local Chromium database.
  • RedMate account auth tokens: encrypted via macOS Keychain through safeStorage.
  • Local draft and asset cache.
  • Uninstalling the app and clearing its application data permanently removes the local data above.

4.2 Cloud storage

  • Registration data, note content, and assets are hosted on the offshore cloud database and object storage we use (specific vendors disclosed in 3.1).
  • All data in transit uses TLS.
  • Retention: long-term while your account is active; permanently deleted within 30 days of account closure.

5. Security

  • TLS for all transport.
  • Row-level access control on the cloud database ensures users access only their own data.
  • Local sensitive credentials are encrypted with macOS safeStorage.
  • Crash-monitoring events are redacted for Bearer tokens, API keys, cookies, signed URLs, and email addresses by default (vendor disclosed in 3.1).
  • In-app logs are similarly redacted.
  • That said, transport over the public Internet cannot be made absolutely secure. Safeguard your credentials accordingly.

6. Your rights

  • Access: view all your accounts, notes, and assets in-app.
  • Correct: edit or delete your content at any time.
  • Export: request a complete machine-readable export of your account data via the email below.
  • Delete: remove individual accounts, notes, or assets from settings.
  • Close account: request account closure via the email below; cloud data is permanently deleted within 30 days.
  • Withdraw consent: opt out of crash monitoring, analytics, and other optional features at any time.
  • Complain: if you object to how this Policy is applied, you may file a complaint with the relevant regulator.

8. Minors

RedMate is intended for users 18 years or older. If you are under 18, please do not use the app or provide personal information to us. We will delete any inadvertently collected information about minors immediately.

9. Policy updates

Material changes will be announced in-app and on redmate.app, with a reasonable transition period before they take effect. Continued use after the effective date means you accept the updated Policy.

10. Contact

  • Email: ivensliao@qq.com
  • Web: redmate.app