第三方 SDK 清单

最后更新:2026年6月4日

本清单完整披露响声 Xiang 集成的全部第三方 SDK。"端"列说明哪个客户端使用:iOS(iOS 应用)、AG(Android 国际版/Google Play)、AC(Android 国内版/小米·vivo·华为等)。

1. 身份与登录

SDK提供方版本用途收集/处理信息供应商隐私政策
Sign in with AppleApple Inc.系统框架iOS / AG / ACApple 账号登录Apple ID sub、(可选)邮箱、显示名apple.com/legal/privacy
WeChat OpenSDK深圳市腾讯计算机系统有限公司iOS 2.x;Android 6.8.34iOS / AC微信登录、微信分享OpenID、UnionID、昵称、头像;分享时传输的图片/链接微信隐私政策

2. 音乐播放与目录

SDK提供方版本用途收集/处理信息隐私政策
MusicKit (iOS)Apple Inc.系统框架iOSApple Music 播放、用户曲库读取MusicKit user token、播放指令、订阅状态apple.com/legal/privacy
MusicKit Android (AAR)Apple Inc.1.1.1 / 1.1.2AG / ACApple Music 鉴权与播放同上同上
Apple Music Catalog APIApple Inc.Web API(无客户端 SDK)全部专辑/曲目/艺术家元数据storefront 标识、查询参数同上
Spotify iOS SDKSpotify ABApp RemoteiOSSpotify 播放(可选播放源)OAuth 授权码、access token、播放指令spotify.com/legal/privacy-policy
Media3 / ExoPlayerGoogle LLC(开源)1.xAG / AC本地媒体框架(不上传任何数据)

3. 推送与即时通讯

SDK提供方版本用途收集/处理信息隐私政策
Apple Push Notification service (APNs)Apple Inc.系统框架iOSiOS 推送device token、通知文案apple.com/legal/privacy
Firebase Cloud MessagingGoogle LLC33.6.0AGAndroid 国际版推送FCM token、设备指纹、通知文案policies.google.com/privacy
极光推送 JPush北京极光纵横数据技术有限公司5.3.1ACAndroid 国内版推送Registration ID、设备厂商/型号、操作系统版本、网络状态、Wi-Fi SSID、Wi-Fi BSSID、MAC 地址、地理位置(粗);用户同意隐私政策前不初始化jiguang.cn/license/privacy

4. 支付

SDK提供方版本用途收集/处理信息隐私政策
StoreKitApple Inc.系统框架iOSApp Store 应用内购买由 Apple 处理;我们仅获得交易凭证apple.com/legal/privacy
Google Play BillingGoogle LLC7.1.1AGGoogle Play 应用内购买由 Google 处理;我们仅获得 purchase tokenpolicies.google.com/privacy
支付宝 SDK支付宝(中国)网络技术有限公司15.8.14ACAndroid 国内版一次性预付(不代扣)订单号、支付状态;不接触银行卡号、CVV、密码支付宝隐私政策
微信支付(OpenSDK 内)财付通支付科技有限公司OpenSDK 6.8.34AC微信支付一次性预付预支付订单、支付结果;不接触银行卡明细微信支付协议

5. 稳定性与诊断

SDK提供方版本用途收集/处理信息隐私政策
Sentry (Android SDK)Functional Software, Inc.(Sentry)7.18.0AG / AC崩溃与错误诊断崩溃堆栈、设备型号、OS 版本、应用版本、面包屑(无用户输入内容);可关闭sentry.io/privacy
iOS 内置 Crash ReportApple Inc.系统机制iOS系统级崩溃报告(由用户在系统设置控制)由 Apple 处理同 Apple 隐私政策

6. 系统能力封装

SDK提供方版本用途收集/处理信息
CoreLocationApple Inc.系统框架iOS定位(仅"使用应用期间")经纬度(单次,即时反向地理编码后丢弃)
EventKitApple Inc.系统框架iOS写入日历事件仅写入;不读取其他事件
UserNotifications / PhotosUIApple Inc.系统框架iOS通知权限、相册写入
androidx.browser (Chrome Custom Tabs)Google LLC1.8.0AG / AC承载 Apple 网页 OAuth
androidx.security:security-cryptoGoogle LLC1.1.0-alpha06AG / AC本地令牌 AES-256-GCM 加密
CoilCoil Contributors(开源)2.7.0AG / AC图片加载
Retrofit / OkHttp / MoshiSquare, Inc.(开源)2.11.0 / 4.12.0 / 1.15.1AG / ACHTTP 与序列化

7. 应用内分析(自有)

我们使用自研的客户端埋点 + 后端聚合方案,不集成第三方分析 SDK(无 Firebase Analytics、Umeng、AppsFlyer、Mixpanel、Amplitude、神策、GrowingIO、TalkingData)。事件经批量上报到我们自有后端 POST /api/v1/track/events90 天后自动清除。详见《个人信息收集清单》

8. 服务端(后端)调用的第三方

下述第三方仅由后端调用,不向客户端集成 SDK,也不传输用户个人信息:

9. 关闭与变更

我们承诺在每次新增、移除或重大版本变更 SDK 时同步更新本清单,并在变更涉及个人信息处理时通过应用内通告告知您。

查询:privacy@bwv988.com

Third-Party SDK List

Last updated: June 4, 2026

This document lists every third-party SDK integrated into Xiang. Column "Edition" indicates which client: iOS, AG (Android Google global), AC (Android China — Xiaomi/Vivo/Huawei).

1. Identity & Login

SDKVendorVersionEditionPurposeData processedVendor policy
Sign in with AppleApple Inc.SystemiOS / AG / ACApple sign-inApple ID sub; optional email; display nameapple.com/legal/privacy
WeChat OpenSDKTencent (Shenzhen)iOS 2.x; Android 6.8.34iOS / ACWeChat login & shareOpenID, UnionID, nickname, avatar; shared image/linkWeChat privacy

2. Music Playback & Catalog

SDKVendorVersionEditionPurposeData processedVendor policy
MusicKit (iOS)Apple Inc.SystemiOSApple Music playback & libraryMusicKit user token, playback commands, subscription stateApple privacy
MusicKit Android (AAR)Apple Inc.1.1.1 / 1.1.2AG / ACApple Music auth & playbackSameApple privacy
Apple Music Catalog APIApple Inc.Web APIAllAlbum/track/artist metadataStorefront, query paramsApple privacy
Spotify iOS SDKSpotify ABApp RemoteiOSSpotify playback (optional)OAuth code, access token, playback commandsspotify.com privacy
Media3 / ExoPlayerGoogle (OSS)1.xAG / ACLocal media frameworkNone

3. Push & Messaging

SDKVendorVersionEditionPurposeData processedVendor policy
APNsApple Inc.SystemiOSiOS pushDevice token, payloadApple privacy
Firebase Cloud MessagingGoogle LLC33.6.0AGAndroid global pushFCM token, device fingerprint, payloadgoogle.com privacy
JPushJiguang (Beijing)5.3.1ACAndroid China pushRegistration ID, device model, OS version, network state, Wi-Fi SSID, Wi-Fi BSSID, MAC address, coarse location; not initialized until you accept the Policyjiguang.cn privacy

4. Payments

SDKVendorVersionEditionPurposeData processedVendor policy
StoreKitApple Inc.SystemiOSApp Store IAPApple handles; we receive receiptApple privacy
Google Play BillingGoogle LLC7.1.1AGGoogle Play IAPGoogle handles; we receive purchase tokenGoogle privacy
Alipay SDKAlipay (Hangzhou)15.8.14ACOne-time prepayment (Android China)Order ID, payment status; no card dataAlipay privacy
WeChat Pay (within OpenSDK)TenpayOpenSDK 6.8.34ACWeChat Pay one-time prepaymentPrepay order, result; no card dataWeChat Pay terms

5. Stability & Diagnostics

SDKVendorVersionEditionPurposeData processed
Sentry (Android)Functional Software, Inc. (Sentry)7.18.0AG / ACCrash & error reportingCrash stack, device model, OS, app version, breadcrumbs (no user input); user-disableable
iOS Crash ReportApple Inc.SystemiOSSystem crash reporting (user-controlled in Settings)Handled by Apple

6. System Capability Wrappers

SDKVendorVersionEditionPurpose
CoreLocationAppleSystemiOS"While in use" location (one-shot, discarded)
EventKit / UserNotifications / PhotosUIAppleSystemiOSCalendar write, notifications, photo write
androidx.browser (Custom Tabs)Google1.8.0AG / ACApple web OAuth
androidx.security:security-cryptoGoogle1.1.0-alpha06AG / ACLocal token AES-256-GCM
CoilOSS2.7.0AG / ACImage loading
Retrofit / OkHttp / MoshiSquare (OSS)2.11.0 / 4.12.0 / 1.15.1AG / ACHTTP & serialization

7. First-Party Analytics

We use our own client-side event batching with backend aggregation. No third-party analytics SDKs (no Firebase Analytics, Umeng, AppsFlyer, Mixpanel, Amplitude, Sensors, GrowingIO, TalkingData). Events go to POST /api/v1/track/events and are auto-purged after 90 days. See Data Collection Inventory.

8. Backend-Only Third Parties

The following are called only by our server; no client SDK is integrated and no end-user PII is sent:

9. Opt-Out & Changes

We update this list when any SDK is added, removed, or materially upgraded, and notify users in-app if the change affects PI processing.

Inquiries: privacy@bwv988.com