MIUI 13 Security White Paper - Xiaomi

4.3 Privacy protection

4.3.1 System permissions management*

MIUI provides applications with a dynamic permissions management mechanism, aiming to limit sensitive operations and protect personal user data. The application requests in the form of pop-up windows before obtaining permission, prompting the user to decide whether or not to grant authorization.

  • Sensitive permission management and control: Permission for "Location", "Camera" and "Microphone" can be set to "while using the app" or "only this time". When the user sets the permission to "while using the app", the application cannot use the related permissions when the application is not in use or is running in the background. When the user sets the permission to "only this time", the application can only use the permission during the current process, and when the application is started again, the application needs to ask the user for permission again.

  • "Camera" is disabled in the background: No application is permitted to invoke the "Camera" permission from the background to take a picture or video.

  • High-risk permission management and control: When the application requests high-risk permissions, such as permission to send you push notifications, MIUI will notify the user of any possible risks associated with the granting of authorization through a full-screen reminder.

*Note: The above permission management mechanism is supported by versions newer than Android R.

4.3.2 Differential Privacy

MIUI uses differential privacy technology to protect the user's privacy. When the user agrees to share data with Xiaomi, MIUI will upload and analyze such data after adding random interference information. This technology ensures that Xiaomi can only use the data provided by the user to study the overall trend and cannot obtain accurate information of the user. For example, the MIUI User Experience Program uses differential privacy technology to collect the operating status and the user traffic statistics of the user's phone. MIUI will upload and analyze such data after adding interference information at random. While ensuring the availability of data, this technology ensures that no one can obtain the user's accurate information from the data, thereby protecting user privacy to the greatest extent.

4.3.3 Log Privacy Mask

MIUI uses "*" to partially mask private information involved in Android native logs (such as base station location, IP address and device identifier) to further protect the private information.

4.3.4 Private Space

MIUI provides users with a series of private space functions such as private text messages, private photo albums, private folders and private notes.

Users can set this through the "Settings"-"Password & security"-"Privacy protection password" menu, and get access to exclusive space for private items by way of privacy passwords or fingerprint passwords. In this space, users can manage their private contacts, album pictures, files and notes. In addition, text messages to or from private contacts, as well as private pictures, private files and private notes will only be displayed in the private space, thus enhancing the protection of user private information.

Users can also use settings to decide whether to display notifications for private text messages on the conventional interface.

If users clone this feature to their mobile phones, the above functions will be linked to display private content in the cloned space and regular content in the primary space.