Mi Account Privacy Policy

Our Privacy Policy was updated on September 24, 2019.

Please take a moment to familiarize yourself with our privacy practices and let us know if you have any questions.

Introduction

Mi Account related services (including account creation, sign-in and management) are provided by Xiaomi and its affiliated companies (hereinafter refer to as "Xiaomi", "we", "our" or "us").

We are committed to protecting your privacy. This Privacy Policy sets out the principles on which Mi Account operates, and constitutes an important part of Xiaomi Privacy Policy. In the event of inconsistency between this Privacy Policy and Xiaomi Privacy Policy with respect to Mi Account, the former shall prevail. For the terms and conditions not stipulated in this Privacy Policy, Xiaomi Privacy Policy shall prevail. Terms and conditions regarding the protection of minors, security measures, and cross-border data transmission can be found in Xiaomi Privacy Policy.

This Privacy Policy is designed with your needs in mind, and it is important that you have a comprehensive understanding of our personal information collection and usage practices, while ensuring that ultimately, you have control of your personal information provided to us, which is crucial. This Privacy Policy sets out how we collect, use, disclose, process and store any information that you give us when you use our Mi Account. Please note that you can refer to the privacy policy for the service for rules of collection and use of personal information for your use of the corresponding service. For the purpose of this Privacy Policy, "personal information" refers to data that can help identify a specific person through the information itself or after linked with other information. We will use such information in strict accordance with this Privacy Policy.

Ultimately, what we want is the best for all our users. Should you have any concerns with our data handling practice as summarized in this Privacy Policy, please contact privacy@xiaomi.com to address your specific concerns. We will appreciate your feedback. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.

1. What information is collected by us and how do we use it?

1.1 Personal information that we collect and use with your authorization

The purpose of collecting personal information is to provide you with products and/or services and to ensure that we comply with applicable laws, regulations, and other regulatory requirements. You have the right to choose whether or not to provide the information we have requested, but in most cases, if you do not provide your personal information, we may not be able to provide you with our services or respond to your queries. The related features include:

1.1.1 Basic functions

(1) Creating accounts and signing in

At the time of account creation, you need to provide us with your mobile phone number or email address as your Mi Account name. Meanwhile, you can set a password for your Mi Account. Your account number and password will be encrypted and saved on our server. It is suggested that you should properly keep your password to prevent your Mi Account from embezzlement by others.

If you are a user from the Chinese Mainland, we will automatically obtain your mobile phone number and fill in it for you at the time of account creation and sign-in to avoid your manual input. For that, we need to obtain your IMSI of SIM card, ICCID or Line1Number.

(2) Complete account information

While using different services provided by Xiaomi, you may obtain better services and experience by completing basic information including profile photo, nickname, gender, country or region and encryption settings. If you don't provide such information, you may also get access to basic functions of the Mi Account.

1.1.2 Functions necessary for guaranteeing account creation and sign-in security

With the view of enhancing system safety at the time of your use of our products and/or services, better preventing phishing website fraud and protecting account safety, we will verify your identity by SMS messages and the second verification (if necessary). In that light, we will need to collect your SMS and the second verification code.

Besides, we will collect your account creation/sign-in time, device related information (e.g. device IMEI/OAID (on Android Q), device model and the version of operating system), device sensor information (e.g. angular velocity and accelerated velocity of mobile phone) as well as network information (e.g. the generally used IP address of sign-in) so as to judge whether current account creation and sign-in environment is safe or not.

1.2 You are fully informed that we may collect and use personal information without your consent if:

  • 1.2.1 The personal information is vital to national security and defense;
  • 1.2.2 The personal information is vital to public safety, public health, and major public interests;
  • 1.2.3 The personal information is related to criminal investigations, prosecutions, trials, or execution of judgments;
  • 1.2.4 The personal information is essential for protecting major legitimate rights (including life and property) and interests of the personal information subject or other people, but it is hard to obtain the subject's consent;
  • 1.2.5 The personal information collected is made public by the subject at their own discretion;
  • 1.2.6 The personal information is collected from public sources, such as news reports or government announcements;
  • 1.2.7 The personal information is necessary for us to sign the contract as required by you;
  • 1.2.8 The personal information is necessary to maintain the safe and steady operation of products and/or services provided, such as for discovering and handling faults of products and/or services;
  • 1.2.9 The personal information is required for legal news releases; and
  • 1.2.10 The personal information is de-identified in the results of statistical or academic research based on public interest.

1.3 Collection of the personal information from third-party sources

When permitted by law, we will collect information about you from third-party sources. For example, you authorize the pairing of a third-party account with Mi Account, and sign in the former to use Xiaomi's services or authorize the import of your profile photo, nickname and other information on the third-party platform; for the purpose of risk control, we will learn about whether your current account creation/sign-in environment is safe via a third party (such as the risk grade library of mobile phone numbers).

1.4 Non-personally identifiable information

We may also collect other types of information which are not directly or indirectly linked to an individual (i.e. the information other than the personal information), for example, statistical data generated during your use of any specific service, and the sign-in/exit records, interaction records and error records during your use of services of Mi Account. The purpose of such collection is to improve the services we provide to you. The type and amount of information collected depends on how you use our products and/or services. We aggregate such information. Such aggregated data is not personal information as it cannot be used to identify you. However, if we combine non-personal information with personal information, such information will be treated as personal information.

2. Sharing of your personal information with any third party

When you sign in with Mi Account on a third-party website/app, we will, upon authorization and approval by you, transmit your nickname, avatar and other information (depending on the nature of the third party's services and products) to the said third party. If you disagree about the third party's acquisition of your personal information, please do not agree about authorization.

Please note that we will guarantee the security of your information by such means as of encryption. However, your personal information at a third party shall be subject to the privacy policy of the said third party. It's suggested that you should carefully read the third party's privacy policy, just as you read this Privacy Policy. You can sign in https://account.xiaomi.com/ at any time, and click "Accounts & permissions" to cancel your authorization of the said third party.

3. Retention policy

We retain personal information for the period necessary for the purpose of the information collection described in this Privacy Policy or as required by applicable laws. We will cease to retain and delete or anonymize personal information once the purpose of collection is fulfilled, or after we confirm your request for erasure, or after we terminate the operation of the corresponding product or service. An exception to this is personal information that we are processing for public interest, scientific, historical research or statistical purposes. We will continue to retain this type of information for longer than its standard retention period, where permitted based on applicable laws, even if further data processing is not related to the original purpose of collection.

4. Your rights

4.1 Controlling settings

We recognize that privacy concerns differ from person to person. Therefore, we provide examples of ways Mi Account makes available for you to restrict the collection, use, disclosure or processing of your personal information and control your privacy settings:

• Go to https://account.xiaomi.com, or Settings > Mi Account on your mobile phone to check and change account security information, personal information, pairing authorization and device management; and

• Sign in or out of the Mi Account.

If you have previously agreed to us using your personal information for the aforementioned purposes, you may change your mind at any time by writing or emailing us at privacy@xiaomi.com .

4.2 Your rights to your personal information

Depending on applicable laws and regulations, you have the right to access, rectification, and erasure of any other personal information that we hold about you (hereinafter referred to as the request).

You may also access and update the details relating to the personal information in your Mi Account at https://account.xiaomi.com or by signing into your account on your device. For additional information, please write to us or contact us at the email address below. Email: privacy@xiaomi.com.

Most laws require that the request made by the personal information subject follows specific requirements, and this Privacy Policy requires that your request satisfies the following conditions:

• Through our exclusive access of request and for the protection of your information security, your request should be in writing (unless the local law explicitly recognizes the oral request);

• Provide sufficient information to enable us to verify your identity and ensure that the applicant is the subject or legally authorized person of the requested information.

Once we obtain sufficient information to confirm that your request can be processed, we shall proceed to respond to your request within any timeframe set out under your applicable data protection laws. In detail:

• Based on the requirements of applicable laws, a copy of your personal data collected and processed by us will be provided to you upon your request free of charge. For any extra requests for relevant information, we may charge a reasonable fee based on actual administrative costs according to the applicable laws.

• If any information we are holding on you is incorrect or incomplete, you are entitled to have your personal information corrected or completed based on the purpose of use.

• Based on the requirements of applicable laws, you have the right to request the deletion or removal of your personal information. We shall consider the grounds regarding your erasure request and take reasonable steps, including technical measures. If the right is upheld, we may not be able to immediately remove the information from the backup system due to applicable legal and security technologies. In that case, we will securely store your personal information and isolate it from any further processing until the backup can be cleared or be made anonymous.

We have the right to refuse to process requests that are not meaningful/entangled, requests that damage others' right of privacy, extremely unrealistic requests, requests that require disproportionate technical work, and requests not required under local law, information that have been made public, information given under confidential conditions. If we believe that certain aspects of the request to delete or access the information may result in our inability to legally use the information for the aforementioned anti-fraud and security purposes, it may also be rejected.

4.3 Withdrawal of consent

• You may withdraw your consent by submitting a request, including collecting, using, and/or disclosing your personal information in our possession or control. The withdrawal of your consent is equal to the deletion of your Mi Account. You can send an email to privacy@xiaomi.com. We will process your request within a reasonable time from when the request was made, and thereafter not collect, use and/or disclose your personal information as per your request.

• Attention: Your withdrawal of consent may result in some legal consequences. You may not be able to continue receiving the full benefit of Xiaomi’s products and services depending on the extent of our processing of information upon your authorization. The withdrawal of your consent or authorization won't affect the validity of our processing carried out upon your authorization up until the point of withdrawal.

4.4 Cancelling a service or account

If you wish to cancel Mi Account, you can send an email to privacy@xiaomi.com. Please note that the cancellation will prevent you from using the full range of Xiaomi products and services. In order to protect your or others' legitimate rights and interests, we will judge whether to approve your request of account cancellation in combination with your use conditions of all Xiaomi's products and services. For example, if there still exists monies outstanding, we cannot immediately support your request.

5. Contact us

If you have any comments or questions about this Privacy Policy or any questions relating to our collection, use or disclosure of your personal information, please contact us at the address below referencing “Privacy Policy”. When we receive privacy or personal information questions about access/download requests, we have a professional team to solve your problems. If your question itself involves a significant issue, we may ask you for more information. If you are not satisfied with the response you received, you can hand over the complaint to the relevant regulatory authority in your jurisdiction. If you consult us, we will provide information on the relevant complaint channels that may be applicable based on your actual situation.

Mailing address:

  • #006, 6th Floor, Building 6, 33 Xi'erqi Middle Road, Haidian District, Beijing
  • China 100085
  • Xiaomi Singapore Pte. Ltd.
  • 20 Cross Street, China Court #02-12
  • Singapore 048422
  • For users in the European Economic Area (EEA):
  • Xiaomi Technology Netherlands B.V.
  • Room 04-106, Wework Strawinskylaan 4117 4th Floor, Atrium North Tower Amsterdam, 1017XD

Email: