订阅更新

Vibe Coding 实践

谷唧(Guji)隐私政策 / Privacy Policy

小余学长VibeCoding 浏览量 381

谷唧(Guji,以下简称“本 App”)由 Xiaoyang Zheng(以下简称“我们”)开发和运营。本政策说明本 App 如何处理你的数据。谷唧采用本地优先设计:收藏资料和图片默认仅保存在你的设备上;只有当你主动使用云端功能,或明确允许可选的使用情况分析时,相关数据才会离开设备。

Guji (the “App”) is developed and operated by Xiaoyang Zheng (“we,” “us,” or “our”). This policy explains how the App processes your data. Guji is local-first: collection records and images are stored on your device by default. Data leaves your device only when you choose to use a cloud feature or expressly enable optional usage analytics.

1. 我们处理的数据 / Data We Process

1.1 本地收藏数据 / Local collection data

你创建的收藏名称、作品或 IP、角色、品类、价格、数量、订单信息、备注、标签和图片默认存储在设备本地。我们不会仅因你使用本地收藏功能而把这些内容上传到我们的服务器。

Collection names, works or IPs, characters, categories, prices, quantities, order information, notes, tags, and images that you create are stored locally by default. We do not upload this content to our servers merely because you use the local collection features.

1.2 匿名账号与安装信息 / Anonymous account and installation information

当你使用需要连接谷唧服务器的功能时,我们会生成随机的谷账号、安装编号和安全令牌,并处理 App 版本、构建版本、iOS 主版本、分发渠道以及最近在线时间。这些数据用于身份验证、服务安全、功能开关、额度和账号状态管理。安全令牌保存在设备钥匙串中。我们不使用 IDFA,也不以这些信息进行跨 App 或跨网站跟踪。

When you use features that connect to Guji servers, we generate a random Guji account ID, installation ID, and security token, and process the App version, build number, major iOS version, distribution channel, and last-seen time. We use this information for authentication, security, feature availability, quota management, and account status. The security token is stored in the device Keychain. We do not use IDFA or use this information to track you across apps or websites.

1.3 iCloud 同步 / iCloud sync

如果你主动开启 iCloud 同步,本 App 会把包含收藏资料和图片的完整备份存入你的 Apple 私有 iCloud Documents 容器,并在你的设备间合并和更新备份。iCloud 由 Apple 提供并受 Apple 的条款与隐私政策约束。关闭同步后,本 App 停止新的同步操作;已存在于 iCloud 的备份可由你通过 Apple 提供的方式管理。

If you enable iCloud sync, the App stores a complete backup, including collection data and images, in your private Apple iCloud Documents container and merges or updates that backup across your devices. iCloud is provided by Apple and governed by Apple’s terms and privacy policy. Turning sync off stops new sync operations; existing iCloud backups can be managed through Apple-provided controls.

1.4 Guji.AI 智能识别 / Guji.AI recognition

只有在你明确同意并主动选择或拍摄图片、发起识别后,本 App 才会将该图片通过加密连接发送到谷唧服务器。发送前,图片会被缩放并重新编码;服务器还会再次解码和重新编码,以移除 EXIF、GPS、ICC 等附加元数据。谷唧服务器仅在内存中实时处理并转发净化后的图片,不会把用户上传的识别图片持久保存到谷唧平台。图片内容随后发送给当前启用的第三方视觉模型服务商,用于识别商品名称、作品、角色、品类、数量和价格,并生成供你确认的结构化草稿。第三方服务商不会收到你的谷账号、邮箱或长期设备标识。

Only after you expressly consent, select or capture an image, and start recognition does the App send that image to Guji servers over an encrypted connection. The image is resized and re-encoded before transmission. The server decodes and re-encodes it again to remove auxiliary metadata such as EXIF, GPS, and ICC data. Guji processes and relays the sanitized image only in memory and does not persistently store the user-uploaded recognition image on the Guji platform. The image content is then sent to the currently enabled third-party vision model provider solely to identify merchandise details and create a structured draft for your review. The third-party provider does not receive your Guji account ID, email address, or long-term device identifier.

我们只保存固定结构化结果和稳定错误状态,不保存 OCR 全文、模型的原始响应、访问密钥或内部错误堆栈。识别结果不会自动写入正式收藏,只有你确认后才会保存。第三方模型服务商也会按照其自身隐私政策处理本次请求;如需查询当前服务商及其政策,请通过本政策末尾的联系方式联系我们。

We retain only fixed structured results and stable error states, not full OCR text, raw model responses, access keys, or internal stack traces. Recognition results are not automatically added to your collection and are saved only after your confirmation. The third-party model provider also processes the request under its own privacy policy. Contact us using the details below if you need the identity and policy of the provider currently in use.

1.5 可选使用情况分析 / Optional usage analytics

只有在你主动开启“使用情况分析”后,我们才会接收白名单内的产品交互事件,例如打开 App、完成入库、开始识别,以及识别成功或失败。事件可能包含随机账号或安装编号、App 与系统主版本、功能入口、是否包含图片、结果码、耗时区间和项目数量等有限信息。

Only if you enable Usage Analytics do we receive allow-listed product interaction events, such as opening the App, creating a collection item, starting recognition, and recognition success or failure. Events may contain a random account or installation ID, App and major OS version, feature entry point, whether an image was used, a result code, a duration range, and item count.

分析事件不包含收藏名称、图片、OCR 全文、搜索词、备注、订单号、精确位置、通讯录或剪贴板内容。关闭分析后,本 App 停止上传新的可选分析事件,服务器会删除与你关联的已有分析事件。

Analytics events do not contain collection names, images, full OCR text, search terms, notes, order numbers, precise location, contacts, or clipboard content. If you disable analytics, the App stops sending new optional analytics events and the server deletes existing analytics events associated with you.

1.6 相机与照片权限 / Camera and photo permissions

相机权限仅用于拍摄你要添加或识别的图片。照片选择器仅向本 App 提供你明确选择的照片;保存分享图时,本 App 可能请求仅添加照片的权限。我们不会读取你的完整照片图库。

Camera access is used only to capture an image you want to add or recognize. The system photo picker gives the App access only to photos you select. The App may request add-only photo access when you save a share image. We do not read your entire photo library.

2. 数据用途 / How We Use Data

我们仅将数据用于提供和改进本 App 的功能,包括本地收藏管理、iCloud 同步、AI 识别、账号与额度管理、故障排查、安全防护,以及在你同意后的产品分析。我们不会出售你的个人数据,不会将数据用于广告定向、数据经纪、跨产品画像或跨 App/网站跟踪,也不会要求访问通讯录、精确位置、其他 App 列表或完整相册。

We use data only to provide and improve the App, including local collection management, iCloud sync, AI recognition, account and quota management, troubleshooting, security, and consent-based product analytics. We do not sell personal data or use it for targeted advertising, data brokerage, cross-product profiling, or cross-app or cross-website tracking. We do not request access to your contacts, precise location, list of installed apps, or entire photo library.

3. 数据共享 / Data Sharing

我们仅在实现你主动选择的功能所必需时与服务提供方共享最少数据:

  • Apple:在你开启 iCloud 同步时处理你的私有 iCloud 备份;
  • 云基础设施服务商:托管谷唧 API、数据库和必要的安全服务;
  • 第三方视觉模型服务商:仅在你发起 Guji.AI 识别时处理净化后的图片内容。

我们可能在法律要求、保护用户或服务安全所必要时披露最少数据。如果业务发生合并、收购或资产转让,我们会按照适用法律提供通知并继续保护相关数据。

We share the minimum data necessary with service providers only to deliver a feature you choose:

  • Apple processes your private iCloud backup when you enable iCloud sync;
  • cloud infrastructure providers host the Guji API, database, and necessary security services; and
  • a third-party vision model provider processes sanitized image content only when you start Guji.AI recognition.

We may disclose the minimum necessary data when required by law or to protect users and service security. If the business is involved in a merger, acquisition, or asset transfer, we will provide notice as required by applicable law and continue to protect the relevant data.

4. 保存期限与删除 / Retention and Deletion

  • 设备本地数据:保留至你在 App 内删除、清除本地数据或卸载 App;
  • iCloud 备份:保留至你删除或通过 Apple 的 iCloud 管理方式移除;
  • 匿名账号、安装信息和必要的同意记录:在账号存续期间保留,删除账号时删除或去标识,法律要求保留的最小记录除外;
  • 可选分析事件:最长保留 90 天;你撤回分析同意后会提前删除;
  • AI 识别图片:谷唧平台仅在内存中实时处理和转发,不持久保存用户上传的识别图片;第三方 AI 服务商可能依据其自身政策进行短期请求处理或日志保存;
  • 管理员安全审计记录:最长保留 365 天,并执行最小化和访问控制。
  • Local device data is retained until you delete it in the App, clear local data, or uninstall the App.
  • iCloud backups are retained until you remove them or manage them using Apple’s iCloud controls.
  • Anonymous account and installation information and necessary consent records are retained while the account exists, then deleted or de-identified upon account deletion, except for minimal records required by law.
  • Optional analytics events are retained for up to 90 days and are deleted earlier if you withdraw analytics consent.
  • AI recognition images are processed and relayed in memory and are not persistently stored on the Guji platform. The third-party AI provider may perform short-term request processing or log retention under its own policy.
  • Administrator security audit records are retained for up to 365 days under data-minimization and access-control safeguards.

第三方服务商可能依据其自身条款采用不同的短期处理或日志保存期限。我们会限制其处理目的,并仅选择具备隐私政策和安全措施的服务商。

Third-party providers may apply different short-term processing or log-retention periods under their own terms. We restrict their processing purpose and select only providers with privacy policies and security safeguards.

5. 你的选择和权利 / Your Choices and Rights

你可以:

  • 不开启 AI 识别、iCloud 同步或可选分析,并继续使用手动录入等核心功能;
  • 在 App 的隐私设置中查看或撤回相关授权;
  • 查看、修改、导出或删除本地收藏;
  • 在 App 内申请删除谷账号和相关云端数据。删除申请设有 7 天撤销期,之后执行删除;
  • 通过下方联系方式申请访问、更正、删除或限制处理你的数据。

You may:

  • decline AI recognition, iCloud sync, or optional analytics and continue using core features such as manual entry;
  • review or withdraw relevant permissions in the App’s privacy settings;
  • view, edit, export, or delete local collection data;
  • request deletion of your Guji account and related cloud data in the App. A 7-day cancellation period applies before deletion is carried out; and
  • contact us to request access, correction, deletion, or restriction of processing, subject to applicable law.

撤回同意不会影响撤回前处理行为的合法性。部分必要数据用于提供你主动请求的服务、安全和防欺诈,因此在你使用相关服务期间无法关闭。

Withdrawing consent does not affect the lawfulness of processing before withdrawal. Some necessary data is required to provide services you request and to maintain security and prevent abuse, and therefore cannot be disabled while you use those services.

6. 儿童隐私 / Children’s Privacy

本 App 不面向未满 13 周岁的儿童,也不会有意收集其个人数据。如果你认为儿童在未经适当监护人同意的情况下向我们提供了数据,请联系我们,我们会采取适当措施删除相关数据。

The App is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided data without appropriate parental or guardian consent, contact us and we will take appropriate steps to delete it.

7. 安全 / Security

我们采用 HTTPS 传输、访问控制、设备钥匙串、安全令牌摘要、图片元数据清理、服务端字段白名单和定期数据清理等措施保护数据。任何系统都无法保证绝对安全;如发生可能显著影响你的安全事件,我们会依据适用法律通知你。

We use safeguards including HTTPS transport, access controls, device Keychain storage, security-token hashing, image metadata sanitization, server-side field allow-lists, and scheduled deletion. No system can guarantee absolute security. If an incident is likely to materially affect you, we will notify you as required by applicable law.

8. 跨境处理 / International Processing

根据你所在地区以及所选云服务和 AI 服务商的位置,你的数据可能在你所在国家或地区之外处理。我们会通过数据最小化、用途限制、加密传输和服务商审查来保护相关数据,并在适用法律要求时采取必要的跨境传输保障措施。

Depending on your location and the locations of selected cloud and AI providers, data may be processed outside your country or region. We protect such data through minimization, purpose limitation, encrypted transport, and provider review, and use required cross-border transfer safeguards where applicable.

9. 政策更新 / Changes to This Policy

如果本政策发生重要变化,我们会更新生效日期,并在 App 内展示新版本或重新请求你的确认。建议你定期查看本页面。

If we make material changes, we will update the effective date and show the new version in the App or request your confirmation again. We encourage you to review this page periodically.

10. 联系我们 / Contact Us

开发者及数据控制者 / Developer and data controller:Xiaoyang Zheng 联系邮箱 / Email:xiax43025@gmail.com

如对本政策或数据处理有任何问题,请通过上述邮箱联系我们。我们会在合理期限内回复。

If you have questions about this policy or our data practices, contact us at the email address above. We will respond within a reasonable period.

小余学长VibeCoding AI 产品观察 · Vibe Coding 实践 · 内容实验室 RSS / 公众号 / 小红书 / X / 邮件