Effective Date: 2026.8.11
Last Updated: 2026.8.11
Suzhou AIDomex Intelligent Technology Co., Ltd. ("Dome X", "we", "us", or "our") develops and operates the Dome X App and the Dome X smart helmet. We are committed to protecting your privacy and handling your personal information with transparency and care.
This Privacy Policy explains what information we collect when you use the Dome X App and connected helmet, why we collect it, how we use and share it, how long we keep it, and the choices you have. It applies to all users of the Dome X App worldwide.
Contact us at any time: service@neoaitek.com
Suzhou AIDomex Intelligent Technology Co., Ltd. , B422,18th.Zhanye RD. SIP. Suzhou China
We collect different types of information depending on how you use the Dome X App and helmet. We collect only what we need to provide and improve our services.
When you log in to the Dome X App, we collect the following data:
Username: Account identity authentication; allows you to log in and use the App.
Password: Account identity verification. Stored using one-way cryptographic hashing only; never stored in readable form.
Google / Apple account (third-party login): Third-party OAuth authorisation login via Google or Apple account, simplifying the registration and login process.
Phone number: Account identity verification and SMS verification code delivery; ensuring account security.
Email address: Account identity verification and account-related notifications.
Account ID: Identifying and associating your account when logging in via third-party OAuth authorisation.
To personalise your experience and provide core app features, we collect the following profile data:
Nickname: Displaying your identity within the App and in cycling groups.
Date of birth: Calculating your age for cycling health data analysis.
Gender: Personalised exercise data analysis (e.g., calorie estimation) and group profile display.
Height/Weight: Used together with weight to calculate calorie expenditure and other health metrics.
Fitness plan / exercise goal: Recording your cycling exercise target to provide personalised activity tracking and progress feedback.
Habitual cycling distance: Recording your typical daily cycling distance to support App exercise planning and recommendations.
Planned pace: Recording your target cycling pace to support the exercise planning feature.
Health data is sensitive information and we handle it with the highest level of care. The Dome X smart helmet collects the following data via its built-in sensors during active cycling, only when you have enabled health monitoring:
Heart rate: Real-time collection via helmet sensor during cycling; provides in-ride health monitoring and exercise analysis functionality.
Important Disclaimer: Dome X helmet sensors are consumer-grade devices, not medical-grade instruments. All health metrics are estimates only and must NOT be used for medical diagnosis or treatment. Always consult a qualified healthcare professional for medical advice.
Health monitoring is:
Off by default – you must explicitly enable it.
Independently controlled – you can disable health monitoring without affecting other App features.
Revocable at any time – via App Settings Profile > Privacy settings > Allow Health Monitoring.
When you use the voice assistant feature of the Dome X smart helmet, the following data is involved:
Voice wake word: When you speak the designated wake phrase, the helmet's built-in chip uses a lightweight, locally-executed algorithm to detect whether the specific phrase has been spoken and, if so, activates the voice assistant. We do not collect, record, or transmit your voice audio or any acoustic / sound-wave data. The algorithm does not capture raw audio input — it only recognises whether the predefined phrase pattern has been matched. No audio data leaves the helmet device during this process.
How it works: The wake-word detection runs entirely on-device using a basic pattern-matching algorithm. Only the trigger signal (i.e., "wake word detected: yes / no") is passed to the App to initiate voice assistant activation. No voice recordings, no sound waves, and no audio files are stored or transmitted at any point during wake-word detection.
When you record a cycling session, we collect the following data. GPS data is sampled approximately every 5 seconds during active sessions authorised by you:
GPS location (latitude, longitude, altitude, speed): Recording your cycling route track; providing route playback, mileage, and exercise data statistics.
Cycling time: Recording the start and end time of your cycling session; used for exercise duration statistics.
Cycling distance (algorithmically derived): Calculated from GPS track data; displaying total mileage.
Pace (algorithmically derived): Calculated from GPS data; providing average pace and real-time speed metrics.
Elevation gain (algorithmically derived): Calculated from GPS altitude data; providing complete exercise data.
Estimated calorie burn (algorithmically derived): Calculated using your body weight, heart rate, and cycling data to estimate energy expenditure. As this derivation involves health data, it is treated as health-related data.
Start and end location names (algorithmically derived via reverse geocoding): GPS coordinates resolved to location names for cycling record review.
GPS coordinates are collected only during active cycling sessions. Route summary waypoints are stored as part of your cycling record; real-time streaming GPS data is not retained beyond the session.
When you connect and manage your Dome X smart helmet via the App, we collect the following data:
Device ID: Auto-generated by the App on first device connection; uniquely identifies and links your Dome X helmet to your App account for binding management.
Bluetooth MAC address: Transmitted via Bluetooth broadcast during pairing; identifies and pairs the smart helmet device to complete the device connection.
GPS (Android 11 and below, Bluetooth scanning only): On Android 11 and earlier, BLE scanning for helmet pairing requires the Precise Location (ACCESS_FINE_LOCATION) permission as mandated by the Android OS. We do not read or store GPS coordinates for location tracking. This data is processed only in real-time during Bluetooth scanning and is not persistently stored. On Android 12+, we use BLUETOOTH_SCAN with the [neverForLocation] flag.
Auto-answer call setting: Synchronising the helmet's auto-answer call configuration to the App, enabling coordinated Bluetooth call management between the helmet and your phone.
SN number (Serial Number): Uniquely identifying the smart helmet hardware device; used for device management and firmware upgrade delivery.
The following device configuration settings and consent records are stored solely to maintain your device binding, synchronise your preferences, and to retain verifiable records of your consent as required by applicable data protection law. They are not used for any analytics, profiling, or marketing purposes.
Collision detection permission switch: Recording whether you have enabled the helmet's collision detection and SOS function; serving as a consent record to ensure this feature is only activated upon your explicit authorisation.
Health data collection authorisation: Recording whether you have authorised the helmet to collect heart rate, and other biometric data; serving as the consent record for health data processing.
Health monitoring setting switch: Recording whether you have enabled the ongoing health monitoring function; serving as the consent record for continuous health data processing. This is maintained separately from the initial health data collection authorisation above.
When you participate in cycling groups, we collect the following data:
GPS (resolved to city level): Matching you with local cycling groups based on your city. GPS coordinates are resolved to city level; precise coordinates are deleted immediately after the city-level extraction is complete. Only the city-level information is stored.
Nickname: Displaying your identity within cycling groups.
Profile avatar / photo: Displaying your profile image within cycling groups. Note: if your avatar contains your facial image, this constitutes personal data and is processed accordingly.
Phone number: Used for internal group member identity association; not publicly displayed to other group members.
Gender: Displaying your basic profile information in cycling groups.
Age: Displaying your age information in cycling groups.
Region / area: Displaying your location information in cycling groups.
Group friend location (opt-in): Sharing your real-time cycling GPS location with group members. This data is sensitive and must be actively enabled by you; it must not be set as the default. You can stop sharing at any time via App Settings > Profile > Privacy settings > Share My Location Mode. Real-time location is processed only during the authorised sharing session and is not persistently stored.
When you use the SNS community features to publish, interact with, and browse content, we collect the following data:
User-generated text content:The text posts (up to 200 characters) you voluntarily submit for public display within the SNS feed.
Post timestamp:The date and time of publication; displayed alongside your post in the feed.
IP address (resolved to province / city):Your IP address is resolved to province- and city-level location (e.g., "Jiangsu · Nanjing") to support the City Topic filter. The original IP address is not persistently stored; only the extracted province/city information is retained.
Like record:Recording which users have liked which posts, enabling the like count display.
Favourite / bookmark record:Records which user saved which post, enabling the favourite count display.
Blocked author list:Records user IDs you have blocked so that their content is filtered from your feed.
Report record:Includes the Report Type you select from the dropdown, the Report Content text you enter, and the reported post / user identifier. Used for content moderation, community safety, and — where required by law — disclosure to regulatory or law-enforcement authorities.
Topic participation tag:Indicates whether your post appears under Hot Topic (default) or City Topic (based on IP-derived city).
The Dome X smart helmet includes automatic collision detection and emergency SOS functionality. When this feature is enabled and a collision event is detected, the following data is processed:
Emergency contact phone number: When SOS is triggered, your phone automatically dials your emergency contact's number to notify them of the emergency situation. The call is placed directly from your own device via the auto-dial function; we do not receive or record the content of this call.
Emergency contact name: Displayed in the App interface to identify and label the emergency contact, enabling you to manage your contacts.
Bluetooth auto-dial permission (system permission): The App requires Bluetooth auto-dial system permission to enable automatic emergency dialling from your phone when a collision is detected. This system-level permission is used solely to trigger the SOS call function.
GPS (at SOS trigger): When SOS is triggered, your real-time GPS location is sent to your emergency contact to enable rapid location by emergency responders.
Important – Third-Party Notice: Your emergency contacts are third parties whose personal data is processed by us solely for the SOS feature. Please inform your emergency contacts that their contact details will be stored in the Dome X App for this safety purpose, and ensure you have their agreement before adding their details.
When you use the voice assistant and AI features of the Dome X App, the following data is processed:
Voice control system: Your voice commands are captured by the microphone, converted to text, and semantically parsed to control App functions including navigation, calling, and music playback, and to provide intelligent Q&A services via a third-party AI model (currently Alibaba Cloud). Raw audio data is processed in real time only and is NOT persistently stored. Converted text command logs are retained for up to 90 days.
We do not store raw audio. We do not use your personal data to train AI models. All AI-generated outputs are for informational purposes only.
To identify your device's current firmware and software version, determine whether an upgrade package needs to be pushed, and deliver targeted upgrades, we collect the following data:
Version number: The current App version installed on your device; used together with the device number to identify the applicable upgrade package.
Device number: Identifying the specific device's current firmware / software version; determining whether an upgrade package needs to be pushed and completing targeted upgrade delivery.
Current version: The current firmware version on your helmet; used to determine whether a firmware upgrade is required.
To maintain App stability and security:
Device model and operating system version: For compatibility checks and diagnostics.
Crash logs and error reports: To identify and fix application issues.
App usage analytics: Aggregated feature usage and session data for product improvement.
Server logs: Network security, fraud detection, and abuse prevention.
When you contact our support team:
Support messages and requests: The content of your enquiry to us.
Bug reports and feedback: Voluntarily submitted information about App or device issues.
Account identifier: To link your request to your account.
Advertising identifiers (IDFA / GAID) – we do not track you for advertising.
Browsing history outside the App.
Payment or financial information – no in-app purchases.
Raw audio recordings – voice commands are transcribed in real time; audio is not stored.
Face recognition or biometric identification beyond health monitoring.
Blood pressure, ECG, or advanced clinical health metrics not supported by the helmet hardware.
We use the information we collect for the following purposes:
Account, Login & Device Management
Creating and managing your account; authenticating your login.
Pairing and managing your Dome X smart cycling helmet via Bluetooth.
Delivering firmware and software upgrades to your device.
Health & Performance
Real-time heart rate monitoring during cycling.
Calculating personalised health metrics: BMI, calorie burn, fitness trends.
Providing cycling performance analytics and ride history.
Voice & AI
Converting voice commands to control App functions (navigation, calling, music playback).
Providing AI-powered intelligent Q&A services via the voice assistant.
Social & Community
Enabling you to create and join local cycling groups (matched by city).
Displaying your profile and activity within groups.
Sharing real-time location with group members (opt-in only).
Enabling you to publish, browse, and interact with text posts in the SNS community feed.
Supporting like, favourite, block, and report functions for community content moderation and user experience.
Filtering and displaying posts under Hot Topic and City Topic based on IP-derived city information.
Safety
Detecting helmet collisions and triggering automatic SOS calls and GPS location alerts to emergency contacts.
App Stability, Security & Improvement
Diagnosing crashes and fixing technical issues.
Detecting and preventing fraud, abuse, and unauthorised access.
Analysing aggregated usage to improve features and performance.
Customer Support
Responding to support requests, bug reports, and feedback.
Legal & Compliance
Responding to lawful requests from public authorities.
Enforcing our Terms of Service and protecting user safety.
We do not use your information for advertising, marketing profiling, or sale to third parties.
The Dome X App requests the following device permissions. You can manage all permissions at any time via your device system settings (Profile > System Settings > Permission Setting > Camera, GPS, File Storage, Bluetooth, Notifications, Battery optimizations).
| Permission | Why We Need It |
|---|---|
| Bluetooth | To connect and communicate with your Dome X smart helmet for data sync, health monitoring, settings management, and auto-answer call coordination. |
| Location / GPS | To record your cycling route; match you with local groups (city-level only); transmit location during SOS events; and enable BLE scanning on Android 11 and below (see Section 2.7). |
| Microphone | To capture voice commands for the voice assistant. Audio is processed in real time only; not stored. |
| Phone / Call | To enable automatic SOS emergency dialling to your nominated contact when a collision is detected. |
| Bluetooth auto-dial (system) | To enable the SOS function's automatic calling capability directly from your phone when a collision event is triggered. |
| Notifications / App Access | To relay phone notifications (calls) to your helmet as audio or vibration alerts. Used only for notification forwarding; not shared externally. |
| Network | To sync data, deliver App and firmware updates, and enable connected features. |
Background location (during active cycling sessions only): When GPS recording is enabled, location data may be processed while the App runs in the background to ensure a complete cycling route record. This is strictly limited to active cycling sessions.
We do not sell your personal information. We share it only in the following limited circumstances:
Service Providers as data processors acting on our instructions
Alibaba Cloud Computing Co., Ltd: Cloud infrastructure; all user data hosted on encrypted servers (Frankfurt, Germany for EU users). Also provides AI services (Qwen) for voice assistant text transcript processing.
Agora Inc.: Real-time voice communication processing for group riding voice chat features.
Third-Party Services (for specific features)
Google Maps API: GPS route data shared for map display and route visualisation. Governed by Google's data processing terms.
Legal Requirements We may disclose your information to law enforcement or regulatory authorities when required by applicable law, court order, or government request. Where permitted, we will notify you in advance.
Business Transfers If Dome X undergoes a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. You will be notified before such a transfer.
We DO NOT: sell your data / share health data with insurers, employers, or advertisers / use advertising networks or retargeting services
Dome X is operated by Suzhou AIDomex Intelligent Technology Co., Ltd., based in Suzhou, Jiangsu Province, China. To provide our services, your personal information will be transferred to and processed in China.
For users in the European Economic Area (EEA), we take the following steps:
EU data hosting: Your data is stored in Alibaba Cloud's Frankfurt, Germany datacenter in the first instance.
Data minimisation: Only the minimum data necessary for service provision is processed at our China-based facilities.
Security controls: Strict encryption and access controls applied to all data accessed from China.
Data transferred to and processed in China is subject to Chinese law, including the Personal Information Protection Law (PIPL). In certain circumstances, Chinese authorities may access data under Chinese law. EEA residents retain the right to lodge a complaint with their national data protection authority.
We implement industry-standard technical and organisational measures to protect your personal information:
| Measure | Details |
|---|---|
| Encryption in transit | TLS 1.3 (minimum TLS 1.2). Bluetooth communications use paired device authentication and encryption. |
| Encryption at rest | AES-256 (or equivalent) for stored personal data. Server disks encrypted at disk level. |
| Password security | Stored as salted cryptographic hashes; never in readable form. |
| Access controls | Role-based access with least-privilege principle. Only authorised staff access personal data. |
| Multi-factor authentication | Required for all administrative access to production systems. |
| EU data isolation | EU user data physically and logically isolated in the Frankfurt datacenter. |
| Security audits | Regular vulnerability scans, penetration testing, and access logging (minimum 6-month log retention). |
| Processor oversight | All third-party processors bound by data protection agreements with equivalent security requirements. |
We keep your data only as long as necessary for the purpose it was collected or as required by law.
| Data Type | Retention Period |
|---|---|
| Account login data (username, password, Google/Apple login, phone number, email, OAuth Account ID) | Duration of active account. Deleted within 30 days of account deletion. |
| User profile information (nickname, date of birth, gender, height, fitness plan, habitual distance, planned pace) | Duration of active account. Deleted within 30 days of account deletion. |
| Body weight | Duration of active account or until consent withdrawn, whichever is earlier. Deleted within 30 days of deletion request or consent withdrawal. |
| Health data (heart rate) | Up to 12 months from collection date. Raw real-time data aggregated at end of session; not stored per-second. Deleted within 30 days of account deletion or consent withdrawal. |
| Voice wake word | Processed locally on device in real time; not persistently stored by us. |
| Cycling records (GPS route, time, distance, pace, elevation, calorie burn, start/end locations) | Duration of active account; individual records up to 3 years from activity date. Deleted within 30 days of account deletion. |
| Device connection & management data (Device ID, MAC, GPS-BLE, auto-answer setting, collision detection switch, health data authorisation record, SN number, health monitoring setting switch) | Duration of active device binding. Deleted within 30 days of device unbinding or account deletion. GPS during Android 11 BLE scanning: not persistently stored. |
| Group features data (city-level GPS, nickname, profile photo, phone, gender, age, region) | Group profile data: duration of group membership; deleted within 30 days of leaving group or account deletion. Precise GPS for city extraction: deleted immediately after extraction. Real-time group GPS location: not stored; processed only during active sharing session. |
| Community content & interaction data | Post text and interaction records: Deleted upon user deletion/cancellation; deleted within 30 days after account deactivation.Blocked author list: Deleted within 30 days after unblocking or account deactivation.Topic tags: Retained with the post.Original IP addresses: Not persistently stored. |
| SOS data (emergency contact phone number, emergency contact name) | Duration of active account. Deleted within 30 days of account deletion or manual removal. |
| SOS GPS location | Processed in real time during SOS event only. Deleted within 30 days of the event. |
| Voice control data (text transcript logs) | Raw audio not stored. Text transcripts up to 90 days. Deleted within 30 days of account deletion. |
| Software/hardware upgrade data (version number, device number, current version) | Version number and current version: deleted upon completion of upgrade task. Device number: deleted upon device unbinding or account deletion (within 30 days). |
| Technical logs, crash reports, server logs | Maximum 90 days. |
| Support & feedback records | Up to 3 years from date of resolution. |
Exceptions: We may retain data beyond these periods where required by law, needed for fraud prevention or security, or where immediate technical deletion is not feasible (in which case processing ceases and data is secured pending deletion). Backup purges occur on a rolling schedule within 12 months.
We will respond to all requests within 30 days (extensions may apply for complex requests).
For All Users
Access – request a copy of the personal data we hold about you.
Correction – ask us to correct inaccurate or incomplete information. Update most details directly in Profile > Click User Icon > enter Personal Information Page > edit user's properties, or by emailing service@neoaitek.com.
Deletion – request deletion of your account and data via Profile > Click User Icon > enter Personal Information Page > click "Delete Account" or by https://help.neoaitek.com/user-account-data-delete.html or by emailing service@neoaitek.com.
Data portability – download your data in a structured format by emailing service@neoaitek.com.
Withdraw consent – revoke consent for health monitoring, group location sharing, or other consent-based features at any time in Profile > Click User Icon > enter Personal Information Page > click "Delete Account" or by https://help.neoaitek.com/user-account-data-delete.html or by emailing service@neoaitek.com.
Restrict processing – ask us to limit how we use your data in certain circumstances by emailing service@neoaitek.com.
Object – object to processing based on our legitimate interests. You have an unconditional right to object to direct marketing at any time.
Additional Rights for EEA Residents
If you are in the EEA: You have the rights above and additionally the right to lodge a complaint with your national data protection supervisory authority: https://edpb.europa.eu/about-edpb/board/members_en. We process EEA user data under: contract performance (Art. 6(1)(b)), consent (Art. 6(1)(a)), legitimate interests (Art. 6(1)(f)), and vital interests (Art. 6(1)(d)). Health and weight data are processed under explicit consent (Art. 9(2)(a)). Contact us or our EU Representative for our full records of processing activities (ROPA) on request.
How to Exercise Your Rights
| Method | Details |
|---|---|
| In-App (fastest) | Most requests processed real-time or within 48 hours. |
| service@neoaitek.com. Response within 30 days. | |
| Post | Suzhou AIDomex Intelligent Technology Co., Ltd., B422,18th.Zhanye RD. SIP. Suzhou China |
Dome X is intended for users aged 16 and above. In regions where a lower minimum age applies under local law (but no lower than 13), the local minimum age applies.
We do not knowingly collect personal data from children below the applicable minimum age. Parents or guardians who believe their child's data has been collected should contact us immediately at service@neoaitek.com.
Our mobile application does not currently use cookies directly. However, certain third-party services integrated into the App (such as mapping and analytics services) may use cookies or similar technologies within their own platforms.
A cookie is a small text file stored on your device by a web server. Cookies allow services to remember your preferences and recognise you across sessions. Cookies may be session-based (deleted when you close the app) or persistent (retained across sessions).
We do not use cookies for purposes other than those described in this Notice. Where third-party cookies apply, they are governed by those third parties' own privacy policies.
To provide Dome X's features, we integrate the following third-party components. We do not control their privacy practices; their own policies apply to data they independently collect.
| SDK / Service | Purpose & Data |
|---|---|
| Alibaba Cloud (Aliyun) https://www.aliyun.com/privacy | Cloud infrastructure: hosts all user data (encrypted) in Frankfurt (EU users). AI Services (Qwen): processes voice assistant text transcripts for AI-powered voice control and Q&A. |
| Agora RTC Engine https://www.agora.io/en/privacy/ | Real-time voice communication for group riding features. Processes: encrypted voice data; not stored long-term. |
| Google Maps API https://policies.google.com/privacy | Map display and cycling route visualisation. Processes: GPS coordinates and route data for map rendering. |
| flutter_blue_plus (open-source library) | Bluetooth Low Energy communication between the App and your Dome X helmet. Processes: Bluetooth device identifiers during pairing. |
In the event of a personal data breach, we will:
Immediately contain the breach and preserve evidence for investigation.
Within 72 hours notify the relevant data protection authority (where required by law).
As soon as possible notify affected users where the breach poses a high risk to your rights, via email and/or in-app notification.
We may update this Privacy Policy to reflect changes in our practices, new features, or legal requirements. When we make material changes, we will update the "Last Updated" date and notify you via in-app notification or email. Previous versions are available on request at service@neoaitek.com.
| Contact Type | Details |
|---|---|
| Privacy enquiries & data requests | service@neoaitek.com |
| General support | service@neoaitek.com |
| Company address | B422,18th.Zhanye RD. SIP. Suzhou China |