Introduction
English translation. This English version is provided so that international users can read the complete policy. If this translation is inconsistent with the Simplified Chinese original, the Simplified Chinese original prevails.
360 AI Research (the “Product”) is provided by Beijing Qihu Technology Co., Ltd. (“we,” “us,” or “360”). We understand the importance of personal information and that effective protection of it is essential to a healthy, sustainable business. We follow principles of openness and transparency, explain our personal-information processing rules, and process personal information lawfully and properly for specified, reasonable purposes. We use security safeguards required by law and mature industry standards to protect your personal information.
This Privacy Policy explains how we collect, use, store, share, transfer, and publicly disclose personal information when you use our products or services and how you may access, correct, delete, and protect that information.
Please read and understand this Privacy Policy before using the Product or services. Pay particular attention to terms shown in bold or underlined. Use the Product only after you fully understand and agree to this Policy. By starting to use the Product, you acknowledge that you understand and agree to our collection, use, storage, and sharing of information as described here. If you have a question, comment, or suggestion, contact us using the details in Section 9.
01How We Collect and Use Personal Information
We collect and use personal information lawfully, properly, and only to the extent necessary for the purposes described in this Policy. If we wish to use it for another purpose, we will notify you in a reasonable manner and obtain consent where required.
Some information is necessary for core Product functions. Other information supports optional or enhanced functions. If you decline information needed only for an optional function, that function or its intended experience may be unavailable, but core functions will remain available. If you decline all collection of personal information, we may be unable to provide any Product function that requires such information.
Personal information required for core functions
Registration and sign-in
When you register a 360 account, applicable law requires you to provide a mobile number or email address. We also collect a username and password to create the account, verify sign-in, and protect account security. If you decline, you cannot register an account, but you may still use browsing, search, or other functions that do not require one.
After registration, you may optionally provide gender, date of birth, interests, marital status, education, occupation, school, or income range to receive more personalized services. Declining to provide this optional information does not affect core Product functions.
When you close your 360 account, we stop using and delete this information or anonymize it, unless applicable law requires otherwise.
You may also sign in through a third-party account such as Weibo, WeChat, or QQ. With your affirmative authorization, we obtain the third-party-account information needed for sign-in, such as nickname, profile image, and other information you authorize.
Providing artificial-intelligence services
After signing in, you may use our artificial-intelligence (“AI”) services. We collect content that you actively select or submit, including text, images, audio, video, prompts, and voice instructions (“Input”), and analyze it to generate content that responds to your instructions. Only after applying security encryption and strict de-identification so that a particular person cannot be re-identified may we use collected data and corresponding model-generated content to improve models and service performance.
Your Input may contain another person's personal information. You must have lawful authorization before submitting it. If it concerns a minor, obtain authorization from the minor's legal guardian. Content that may be unlawful or harmful may not be displayed.
If you upload portrait material for an AI feature, we analyze key facial feature points in the original material only to provide the feature you selected and use encryption during processing. Unless we separately obtain your written consent, we do not use facial information for another purpose or share it with a third party.
Responding to feedback
You may report a problem through the Product's feedback channel. If you do not have an account, you may provide a mobile number, email address, or QQ number so that we can contact you. Registered users may also submit feedback through the 360 User Center. We analyze the information needed to identify and resolve the problem. Contact details submitted with feedback are used for customer-service communication and are not provided to a third party without your express consent, unless law requires otherwise.
Security and fraud prevention
To protect account security, transaction security, and system operations, we collect service and device information needed for security risk assessment, including IP address, device model, hardware serial number, operating-system information, service logs, and other logs related to service delivery, to prevent, detect, investigate, and address conduct that threatens system security or violates law, agreements, or rules.
We may combine account information, device information, application-use information, and information lawfully shared by affiliates or partners with your authorization to authenticate identity, identify phishing, fraud, vulnerabilities, malware, attacks, or intrusions, detect violations, and perform legally required recording, auditing, analysis, and response.
Optional and enhanced functions
VisFlow browser extension
You may choose to use the VisFlow extension in a supported third-party desktop browser. This section describes data processing for AI-powered browser automation, operation recording and replay, task storage, custom-model configuration, and issue reporting, as well as permission boundaries, prohibited collection, service providers, and user controls.
For the extension-specific explanation, read the VisFlow Privacy Policy.
(1) Core principles
| Principle | How it applies |
|---|---|
| User initiation | Webpage content, screenshots, recorded steps, and AI-execution data are processed only when you actively start the relevant function. The extension does not silently and continuously collect them in the background. |
| Purpose limitation | Data is used only to provide and improve visible VisFlow functions: AI execution, recording and replay, task saving, and debugging. |
| Sensitive-data masking | During recording, high-risk fields such as passwords, verification codes, API keys, tokens, and card security codes are automatically masked and are not stored or uploaded in plaintext. |
(2) Complete scope of data processing
The following data is processed on demand after you take an affirmative action; it is not continuously collected in the background.
| Category | Data processed | Purpose |
|---|---|---|
| Account and authentication | User ID, username, nickname, QID, bound email address, mobile number, avatar, sign-in source, access credential, and authorization status. | Sign-in verification, account identification, task ownership, service authorization, and management of user-defined model settings. |
| Instructions and tasks | Automation-task descriptions, AI conversations, prompts, AI-execution results, saved task records, submitted bad cases, notes, and runtime logs. | Generate browser actions, persist task workflows, reproduce execution paths, export workflow data, and diagnose defects. |
| Web content and browsing context | URL and title of the tab you select, summarized DOM structure, element selectors, iframe paths, browser-window dimensions, and page runtime state. | Identify page elements, support AI visual understanding, generate actions, verify replay, and execute cross-page automation. |
| Recording, replay, and form data | Clicks, text entry, scrolling, keyboard events, navigation, waits, and other steps you record; ordinary form values you enter; masking of passwords, verification codes, API keys, tokens, card security codes, and similar high-risk fields. | Create reusable replay workflows, debug automation, save user-created workflows, and reproduce recorded operations. |
| Screenshots and page images | Page screenshots, captured frames, before-and-after images, and screenshot dimensions created when you start AI execution, recording, or replay. | Visual element recognition, before-and-after comparison, step thumbnails, execution debugging, and fault diagnosis. |
| Local settings and cache | Sign-in mode, selected AI model, side-panel state, recording and replay state, temporary steps, screenshot cache, and UI state. | Restore state after restart, reduce repeated configuration, and support stable long-running recording and replay. |
| Custom-model configuration | Model name, model base URL, provider information, and an API key stored in encrypted form. | Call a third-party model service that you configure and associate that configuration with your account. |
(3) Product scenarios
| Function | Processing scenario |
|---|---|
| AI execution | Uses your instruction, target-page screenshot, page URL, window size, and DOM context to generate actions such as click, text entry, scrolling, and navigation. |
| Recording and replay | Records the browser operations that you actively initiate and creates visual, savable, exportable, reusable step data. |
| Task saving and cloud synchronization | Stores recorded steps, screenshots, DOM summaries, workflow JSON, and task descriptions so that you can later view, reuse, and debug an automation workflow. |
| Feedback and quality improvement | Receives defects, recording failures, replay deviations, and bad cases that you actively submit so that we can diagnose and fix defects and improve the Product. |
(4) Sharing and entrusted-processing providers
| Processor or service | Scope |
|---|---|
| VisFlow backend services | Sign-in verification, cloud task storage, step processing, screenshot and HTML/JSON upload, model-configuration storage, and issue-feedback intake. |
| 360 account service | Identity verification, sign-in status, and issuance of account access credentials. |
| AI execution service | Receives instructions, page screenshots, URL, window information, and page context and returns structured automation instructions. |
| User-configured third-party model service | Called only after you actively provide and enable a base URL and API key; processes the request using the external model you selected. |
| No sale or unrelated disclosure | We do not sell user data or provide it to advertising platforms, data brokers, information resellers, credit-scoring providers, or lending-risk providers. |
(5) Browser-extension permissions
Permissions are used only for user-initiated functions and are not silently invoked in the background.
| Permission | Use |
|---|---|
storage | Store settings, sign-in state, task steps, screenshot cache, and temporary runtime state locally. |
tabs / activeTab | Identify the tab you selected and read its title and URL; access page content only after you initiate a function. |
scripting | Inject scripts needed for recording, replay, element highlighting, and automation into the target page. |
sidePanel | Display the workspace for AI execution, recording, replay, runtime logs, and model settings. |
tabCapture / offscreen | Capture the page and create screenshot frames after you start recording or AI execution. |
debugger | Use the Chrome DevTools Protocol during AI execution or replay for screenshots, text entry, clicks, and dialog handling. |
windows | Locate, focus, or create a browser window required by an automation workflow. |
notifications | Notify you of long-running task, recording, replay, and execution status. |
unlimitedStorage | Cache large screenshots and long workflows; you may clear them manually, and temporary data may be cleared when a task ends. |
| Host permissions | Allow you to initiate recording, replay, and AI automation on ordinary webpages. |
(6) Storage, transmission, and retention
| Rule | Details |
|---|---|
| Local storage | Uses chrome.storage.local, extension memory, and temporary object-URL caches on your device. You may clear all local extension data. |
| Server storage | Supports cross-device task synchronization, persistent screenshots and HTML/JSON, AI-action generation, model settings, and fault diagnosis. |
| Custom credentials | A third-party-model API key is used only to call the corresponding model endpoint. You may remove or replace the model configuration at any time. |
| User-directed disposal | You may clear local extension data, delete cloud-saved task records, or request account-data deletion or export through our official contact channels. |
(7) User choice and control
| Control | How to use it |
|---|---|
| Sign-in mode | Choose a 360 account or use available core functions in guest mode. |
| Workflow control | Stop recording at any time, clear recorded data, export task JSON, or sign out. |
| Optional-function control | You decide whether to save a task to the cloud, submit issue feedback, or configure a custom-model API. |
| High-risk action confirmation | For higher-risk actions involving submission, approval, deletion, or payment, the Product requires a confirmation and returns control to you. |
(8) Information not actively collected and prohibited uses
| Category | Commitment |
|---|---|
| Not actively collected | Your complete Chrome browsing history; the extension does not call the History API to read it. |
| Not actively collected | Browser cookie data. |
| Not actively collected | Precise geolocation. |
| Not actively collected | Device contacts. |
| Not actively collected | Health information. |
| Not actively collected | Financial-account details or payment credentials; these are automatically masked during recording. |
| Prohibited use | Selling or trading users' personal information. |
| Prohibited use | Building personalized advertising or user profiles from extension data. |
| Prohibited use | Third-party credit assessment or lending-risk review. |
When consent is not required
As permitted by applicable law, we may process personal information without consent where the processing is necessary to enter into or perform a contract to which the individual is a party, or to conduct human-resources management under lawfully adopted employment rules or a lawfully concluded collective agreement; perform a statutory duty or obligation; respond to a public-health emergency or protect life, health, or property in an emergency; conduct news reporting or public-interest oversight within a reasonable scope; process personal information that an individual has made public or that has otherwise been lawfully made public within a reasonable scope; or in another circumstance provided by law or administrative regulation.
Information processed so that it cannot be restored or used to identify a particular person is not personal information under applicable law. We may receive aggregated statistics from affiliates or partners, such as counts of downloads, installations, uninstalls, requests, and errors. These non-personal statistics help us improve existing products and services and develop new ones.
02Cookies and Similar Technologies
How cookies are used
A cookie is a small text file sent by a website to your browser. It commonly contains an identifier, site name, numbers, and characters. A cookie is unique to the site that issued it and is ordinarily read only by that site's web server. Cookies can simplify repeat sign-in, remember your device and service preferences, analyze website use, make access more convenient, and support recommendations for relevant websites or services.
We do not use cookies for purposes outside this Policy. You may manage or clear cookies stored by this website. Clearing them also deletes the corresponding saved information and may affect the security or convenience of the service.
03How We Store Personal Information
Location
Personal information collected and generated within the People's Republic of China is stored within the People's Republic of China.
Retention period
We retain personal information only for the shortest period necessary for the purposes described in this Policy and for any period required by law. After that, we delete or anonymize it.
If we discontinue the Product, we will promptly stop collecting personal information, notify you individually or through a public announcement, and delete or anonymize stored personal information within a reasonable period.
04Sharing, Transfer, and Public Disclosure
(1) Sharing
We do not share personal information with a company, organization, or individual except in the following circumstances:
You have given express consent.
Sharing is necessary within the scope permitted by law to protect your, another 360 user's, or the public's lawful interests, property, or safety.
We use a third-party software development kit or service provider to keep a product or service operating reliably and share only information needed for the purpose stated in this Policy. Without your express authorization, we do not share personal information with third-party advertisers, application developers, open platforms, or other partners. We may provide aggregated, anonymized, or other information that does not identify you. Service providers may supply technical infrastructure, service analytics, measurement, customer service, payment support, academic research, surveys, or legal, financial, and technical advice.
We enter into strict data-protection agreements with recipients and require them to process personal information according to our instructions, this Policy, and applicable confidentiality and security safeguards.
(2) Transfer
We do not transfer personal information to another company, organization, or individual except where a merger, acquisition, asset transfer, or similar transaction requires it and the recipient agrees to remain bound by this Policy or obtain consent again; law, legal process, a mandatory governmental request, or a judicial decision requires it; you expressly consent; or you request transfer to a designated personal-information processor and the conditions prescribed by the national cyberspace authority are satisfied.
(3) Public disclosure
We publicly disclose personal information only with your express consent; when required by law, legal process, litigation, or a competent governmental authority; when necessary within the scope permitted by law to protect 360, an affiliate or partner, you, another user, or the public from harm to lawful interests, property, or safety; or in another circumstance provided by law.
(4) Exceptions to prior consent
Prior consent is not required where sharing, transfer, or public disclosure is directly related to a personal-information controller's statutory duties; national security or defense; public security, public health, or a major public interest; a criminal investigation, prosecution, trial, or enforcement of a judgment; protection of life, property, or another major lawful interest where obtaining consent is difficult; information the individual has made public; or information collected from a lawful public source such as lawful news reporting or governmental disclosure.
Sharing, transferring, or publicly disclosing de-identified information that a recipient cannot restore or use to re-identify an individual is not treated as an external disclosure of personal information under applicable law and does not require separate notice or consent.
05How We Protect Personal Information
We use security safeguards aligned with industry standards to prevent unauthorized access, public disclosure, use, modification, damage, or loss and take reasonable and practicable measures to protect personal information.
360 has completed the filing and testing required for China's classified cybersecurity protection system at Level 3 and has obtained ISO/IEC 27001 information-security-management certification.
We encrypt transmission and storage of identifiable information. Where a unique mobile-device identifier is processed, the Chinese policy states that the identifier is anonymized and hashed on the device using MD5 before collection and upload.
For registered accounts, we may analyze sign-in time, IP address, and sign-in frequency for risk management. Data exchanged between a mobile device and our client uses a proprietary encryption scheme together with HTTPS.
Server-side access controls apply least-privilege principles to personnel who may access personal information, and access lists and records are reviewed regularly.
Servers use security-hardened operating systems and audited, monitored administrator access. We promptly apply security upgrades when a server operating-system issue is publicly disclosed.
Personnel receive regular training on personal-information-protection law and responsibilities.
Collected personal information is managed through classification and tiered safeguards.
If a physical, technical, or administrative safeguard is compromised, we will activate an incident-response plan, contain the incident, report it to competent authorities as required, and notify you through a push message, announcement, or another appropriate method of the incident's basic circumstances, possible effects, and measures taken or planned.
06Your Personal-Information Rights
While using the Product, you may access, correct, and delete registration and other personal information through the methods below or the instructions in the relevant product or service. Available methods and scope depend on the service you use.
(1) Access and correction
Sign in to the 360 User Center to view and correct 360-account information you provided, such as your password, gender, age, date of birth, interests, and marital status.
(2) Deletion
You may request deletion if we collected personal information without required express consent; our processing violates law; we use or process the information in breach of our agreement with you; you close your account, uninstall, or stop using the Product or service; we stop providing the service; or another circumstance gives you a legal right to deletion.
Contact us under Section 9 to request deletion. After deletion from active servers, corresponding backup data may remain until the backup is updated, at which time it will be deleted.
(3) Copy of your information
You may obtain a copy of your personal information by contacting us using the details in Section 9.
(4) Account closure
You may close your 360 account through the 360 User Center account-closure page. After closure, the account cannot be used, related account information will be deleted, and you will no longer be able to use services that require that account. Functions that do not require sign-in are unaffected. Proceed carefully.
After account closure, we stop providing the corresponding product or service unless law requires us to retain relevant information.
(5) Withdrawal of consent
Each function needs certain information to operate. If you withdraw consent or authorization, we may be unable to continue the corresponding service and will stop the related processing. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
(6) Responding to requests
For security, we may require a written request or other proof of identity before processing it. Some information may not be accessible, correctable, or deletable because of legal requirements, information-security needs, or technical limitations.
07Protection of Minors
If you are under 18, obtain your parent or legal guardian's consent before using the Product.
If you are under 14, read this Policy and any product-specific privacy policy with your guardian and decide together whether to use the Product. If personal information must be submitted, obtain your guardian's consent and complete the process under the guardian's guidance.
If you are a child's guardian, carefully read this Policy and the applicable product-specific policy before helping the child register for or use a product or service. Contact us under Section 9 if you have questions about the child's personal information.
08Changes to This Policy
We may change this Policy. We will not reduce the rights you have under it without your express consent where that consent is required.
For a material change, we will provide a prominent notice, such as a pop-up when software is revised or upgraded or when you next sign in.
A material change includes a significant change to our service model, processing purposes, categories of information, or uses; a change of control such as a merger or reorganization; a change to the main recipients of sharing, transfer, or public disclosure; a change to your rights or how to exercise them; a change to the responsible security team, contact details, or complaint channel; or a personal-information-protection impact assessment indicating high risk.
09Contact Us
For a question, comment, suggestion, or complaint about this Policy or our processing of personal information, email kefu@360.cn or use the 360 feedback page.
You may also write to: 360 Data Security Committee, Electronic City International Electronics Headquarters, Courtyard 6, Jiuxianqiao Road, Chaoyang District, Beijing 100015, China.
We will ordinarily respond within 15 business days.
10Appendix 1 — Definitions
Personal information: information recorded electronically or otherwise that relates to an identified or identifiable natural person, excluding anonymized information. It may include basic details such as name, date of birth, gender, address, telephone number, and email address; identity-document information; biometric information such as voiceprint, fingerprint, and facial features; online identifiers such as account and IP address; property information such as bank accounts, transaction and consumption records, and virtual assets; communications and contacts; browsing and software-use records; device information such as hardware model, MAC address, software list, and unique device identifier; and location information such as movement, precise location, accommodation, and coordinates.
Sensitive personal information: personal information that, if leaked, unlawfully provided, or misused, may endanger personal or property safety or readily cause damage to reputation, physical or mental health, or discriminatory treatment. It includes financial-account and transaction information, biometric information, identity-document information, contacts, movement, browsing records, accommodation information, and precise location.
Unique device identifier: a string assigned by a device manufacturer that can uniquely identify the corresponding device.
De-identification: technical processing that makes it impossible to identify a personal-information subject without additional information.
Anonymization: technical processing that makes the personal-information subject unidentifiable and the processed information irreversible.
Deletion: removing personal information from systems used for ordinary business functions so that it remains irretrievable and inaccessible.
