TimeOne Lab / 法律与隐私 Legal & Privacy / 隐私政策 Privacy Policy
隐私保护承诺 · 本地优先 (Local-First) Privacy Commitment · Local-First

时一未来科技隐私政策 TimeOne Lab Privacy Policy

生效日期:2026 年 8 月 16 日 (v1.0) Effective Date: August 16, 2026 (v1.0)
contact@timeonelab.com
1. 本地优先存储
1. Local-First Storage
PDF、手写笔迹、录音、OCR 与 AI 卡片默认完整存储于设备沙盒,绝不无感上传完整库。
PDFs, handwriting, audio, OCR, and AI cards stay in your device sandbox by default.
2. 硬件权限按需授权
2. On-Demand Permissions
仅在用户拍照、录音、转写或导出日历时申请对应权限,拒绝后不影响核心阅读与手写。
Camera, mic, and calendar permissions are only requested upon explicit user actions.
3. 严禁用于模型训练
3. Zero Model Training
仅传输用户主动圈选的局部文本片段;企业 API 隔离保障,绝不用于公有模型训练。
Only user-selected text is sent via enterprise API; never used for public model training.
4. 零广告与不追踪
4. Zero Ads & Tracking
不接入广告网络,不索取 IDFA,不出售任何学习数据,提供完整的脱敏与 Opt-Out 控制。
No third-party ad networks, no IDFA tracking, and full user-controlled opt-out switches.

01. 我们处理哪些信息与使用目的 Information We Process and Purpose

我们在提供核心研读、手写笔迹、学习资产构建及辅助功能时,按业务场景处理以下类别的信息:

1.1 文档、手写笔记与插图(完全本地优先)

您导入的 PDF 课程材料、使用 Apple Pencil 书写的手写笔迹(Ink)、选区高亮与标注、贴纸、通过相机拍摄或相册选取的插图图片、连续白板数据,均存储于设备沙盒本地安全数据库与本地文件系统中。除您主动开启 iCloud 云同步外,此类数据绝不会离开您的设备。

1.2 课堂录音与语音备注

当您使用录音功能时,音频文件保存在设备本地沙盒中。录音转写优先在 iOS 端侧系统识别引擎(On-Device Speech Framework)完成。仅在您明确选择“结合原音频生成 AI 增强摘要”时,经您主动确认后才会上传必要音频片段进行智能处理。

1.3 学习中心(Study Center)、考试与日程

本应用在本地统计您的学习时长(Study Session)、生成学习热力图与专注计时器记录。当您主动点击“导出到日历”或“导出到提醒事项”时,本应用仅执行单向事件写入,不读取或上传您的私人日程与待办。

1.4 账号与 StoreKit 订阅

当您使用 Apple 登录或邮箱注册、购买或恢复订阅时,我们处理用户标识符、邮箱、StoreKit 2 交易收据(订阅有效状态)与 AI Credits 账本余额。我们不直接收集或存储任何银行卡支付信息。

1.5 匿名应用分析与稳定性遥测

包含系统生成的匿名安装标识(anonymous_install_id)、应用崩溃堆栈、性能指标与脱敏事件(如 ai_explain_completed)。所有自动遥测严格过滤,严禁包含任何文档名、PDF 正文、手写图像、录音内容或 AI 生成正文。

Our software processes information across different feature modules in accordance with strict Local-First and data minimization principles:

1.1 Documents, Handwritten Ink, and Photos (Local-First)

Imported PDF textbooks, native Apple Pencil ink strokes, highlights, stickers, inserted photos, and continuous whiteboard data are saved locally in your device sandbox (encrypted local database and local filesystem). Unless you explicitly enable iCloud Sync, this data never leaves your device.

1.2 Voice Notes and Lecture Audio

When recording audio memos or lecture tracks, audio files are saved locally. Speech-to-text transcription prioritizes the Apple on-device speech engine. Audio is only uploaded for enhanced AI summarization if you explicitly select that option.

1.3 Study Center, Exams, and Scheduling

Study duration logs, activity heatmaps, focus timer state, and exam goals are maintained locally. Tapping "Export to Calendar" or "Export to Reminders" performs a one-way write without inspecting your private personal calendar entries.

1.4 Account and StoreKit Subscriptions

When using Sign in with Apple or email, we process anonymous user IDs, subscription entitlement status from Apple StoreKit 2, and AI credit balances. We never process or store raw payment card credentials.

1.5 Anonymized Telemetry and Stability

Includes an anonymous device ID (anonymous_install_id), crash stack traces, performance metrics, and sanitized event names. Telemetry strictly prohibits document filenames, PDF text, handwriting images, audio recordings, or AI output text.

02. 系统设备权限调用说明 Device and System Permissions Matrix

为保障完整学习体验,我们在特定功能触发时向您申请以下系统权限。所有权限均遵循“先告知、按需申请、用户可随时关闭”原则:

To provide a complete study workflow, our application requests system permissions strictly upon user action:

系统权限 Permission 对应 Key Info.plist Key 申请时机与用途 Trigger & Purpose 用户控制与替代方案 User Control & Fallback
相机 (Camera)Camera NSCameraUsageDescription 首次点击“拍照插入笔记/白板”时触发,用于拍摄课件或板书插图。 Triggered when taking a photo to insert diagrams or lecture slides into notes. 若拒绝,不影响阅读与手写;您仍可通过系统相册选择已存照片。 If denied, reading and handwriting remain active; you can still pick photos from library.
照片选取 (Photos)Photo Library PhotosPicker (PhotosUI) 点击“从相册添加插图”时调起系统原生照片选择器。 Triggered when picking photos to insert into documents or whiteboards. 采用 iOS 独立进程选择器,本应用无需且不会读取相册中的其他无关照片。 Runs out-of-process via Apple PhotosPicker; we cannot access the rest of your library.
麦克风 (Microphone)Microphone NSMicrophoneUsageDescription 首次点击“录制课堂音频”或“添加语音备注”时申请。 Requested when recording lecture tracks or attaching audio memos to notes. 若拒绝,无法录制音频,文字阅读、手写与 AI 功能不受任何影响。 If denied, recording is disabled; reading, handwriting, and AI work normally.
语音识别 (Speech)Speech Recognition NSSpeechRecognitionUsageDescription 开启语音转写时调用端侧语音引擎。 Used by iOS on-device speech engine to transcribe audio notes into text. 可随时在系统设置中禁用,禁用后录音文件仍可在本地正常回放。 Can be disabled in Settings; audio recordings can still be played back locally.
日历 (Calendar)Calendar NSCalendarsWriteOnlyAccessUsageDescription 仅在点击“导出考试目标到日历”时申请。 Requested only when tapping "Export Exam Goal to Calendar". 采用 iOS 17+ 仅写权限(Write-Only),本应用无法读取您的私人日程。 Uses iOS 17+ Write-Only permission; our app cannot read your personal calendar entries.
提醒事项 (Reminders)Reminders NSRemindersFullAccessUsageDescription 仅在点击“将今日复习同步到系统待办”时申请。 Requested only when syncing due review flashcard counts to Apple Reminders. 仅在您的提醒事项中维护专属学习列表,不读取其他个人列表。 Only manages its dedicated study list without reading other personal lists.

03. AI 学习助手与数据传输边界 AI Learning Assistant & Transmission Boundaries

我们深度融合 AI 学习能力(解释、总结、概念图、主动回忆复习卡)。我们设定了严密的数据传输边界:

✅ 显式请求白名单(仅传输必需片段):
• 用户主动圈选的文本片段 / 局部 OCR 文字;
• 必要上下文信息(文档标题、当前页码、局部坐标锚点);
• 用户选择的提示词类型(Explain / Summary / Concept Map / Flashcard)。
❌ 严禁上传项(绝对红线):
• 严禁上传整份 PDF 文件二进制内容;
• 严禁上传整本书的全量 OCR 文本;
• 严禁上传原始手写笔迹 Blob 数据;
• 严禁上传本地文件路径与未选中的无关页面。

企业免训练保障: 所有 AI 请求均通过加密 TLS 1.3 传输至 Cloudflare 后端网关,并转发给签署了商业免训练协议的模型供应商(如 DeepSeek、OpenAI 等)。供应商承诺请求数据不用于公共模型训练,处理完成后按最短保留期策略清除。

Our application provides context-aware AI learning assistance. We enforce strict transmission boundaries:

✅ Permitted Request Payload:
• Explicitly selected text fragments / bounded local OCR text;
• Minimal context (document title, page index, source coordinates);
• Selected action type (Explain / Summarize / Concept Map / Flashcard).
❌ Strictly Prohibited:
• Never uploads full PDF binary files;
• Never uploads full-document OCR dumps;
• Never uploads raw handwritten ink blobs;
• Never uploads local file storage paths.

Enterprise Zero-Training Policy: All AI requests are transmitted over encrypted TLS 1.3 to our Cloudflare gateway and processed by enterprise AI providers under zero-training agreements. Data is never used for public model training.

04. 第三方服务与数据共享清单 Third-Party Services and Subprocessors

我们绝不出售您的个人信息。为提供云端辅助功能与保障稳定性,我们仅与以下可信服务商合作:

We never sell your personal data. We work only with trusted infrastructure providers:

服务商 / SDK Provider / SDK 涉及功能 Feature 传输数据 Data Transmitted 安全措施与留存 Safeguards & Retention
AI Providers
(DeepSeek / OpenAI 等)(DeepSeek, OpenAI, etc.)
AI 解释、总结、概念图与复习卡 AI explanations & flashcards 仅限用户圈选的文本片段与上下文 User-selected text fragments only 签署免训练协议;生成后即时丢弃 Zero-training agreement; discarded post-generation
Cloudflare API 加密网关与请求路由 Encrypted API Gateway 请求元数据(IP、路由、耗时、Token 数) Request metadata (IP, route, tokens, latency) TLS 1.3 加密;脱敏日志保存 30 天 TLS 1.3; sanitized logs kept up to 30 days
PostHog 聚合功能使用分析 (海外版) Aggregated product analytics 匿名设备 ID、脱敏事件名 Anonymous ID, sanitized event names 关闭 Session Replay;可在设置中关闭 Session Replay disabled; opt-out in Settings
Firebase Crashlytics / MetricKit 崩溃监控与性能诊断 Crash & performance telemetry 匿名崩溃堆栈、设备型号、脱敏错误码 Crash stack traces, device model, error codes 严禁附带文档正文;可在设置中关闭 Prohibits user content; opt-out in Settings
Apple Inc. StoreKit 订阅、私有 CloudKit 同步 StoreKit purchases, iCloud sync 交易凭据、用户个人 iCloud 容器数据 Purchase receipts, private iCloud data 遵循 Apple 官方隐私与端到端加密 Encrypted under user's personal Apple ID

05. 数据存储安全与生命周期 Data Security, Retention, and Lifecycle

5.1 本地存储保护

本地数据库与文件受 iOS 原生沙盒与数据保护机制(NSFileProtectionCompleteUntilFirstUserAuthentication)保护。身份认证 Token 及匿名设备标识仅保存在系统安全钥匙串(Keychain)中。

5.2 废纸篓机制与彻底删除

  • 废纸篓(Trash)30 天保留:删除的文档会移入废纸篓,保留 30 天以便误删恢复;
  • 永久删除(Permanent Delete):确认永久删除或清空废纸篓后,系统将级联清除本地 PDF、笔迹、录音、OCR 缓存、AI 卡片与缩略图;
  • 一键清理缓存:在设置中提供【清理缓存】功能,可随时安全释放临时文件(Temp)与 OCR 缓存。

5.3 服务端留存期限

服务端 AI 响应缓存保留不超过 7 天(用于幂等重试);运行日志保留 30 天;订阅与计费记录依财税合规要求保留。

5.1 Local Security

Local database and files are protected by iOS sandbox isolation and NSFileProtectionCompleteUntilFirstUserAuthentication. Tokens and anonymous IDs reside in the secure iOS Keychain.

5.2 Trash and Deletion Lifecycle

  • 30-Day Trash Retention: Deleted documents move to Trash and remain recoverable for 30 days;
  • Permanent Deletion: Emptying Trash permanently erases local PDFs, ink strokes, audio recordings, OCR caches, and AI cards;
  • Clear Caches: A dedicated button in Settings safely removes temporary files and OCR caches.

5.3 Server Retention

AI response caches are kept for up to 7 days for retry handling; operational logs for 30 days; purchase receipts as required by tax regulations.

06. 您的权利与隐私控制 Your Rights and Privacy Controls

您对个人数据享有充分的知情权与控制权。我们在应用内提供了便捷的自主控制通道:

  • 数据导出与携带:支持随时将带批注的 PDF、录音文件与复习卡片导出为通用格式。
  • 分析数据选择退出(Analytics Opt-Out):在【设置】→【隐私】中可一键关闭 PostHog 数据分析。
  • 崩溃诊断选择退出(Diagnostics Opt-Out):在【设置】→【隐私】中可一键关闭崩溃诊断日志。
  • 重置匿名标识(Reset Identity):一键重新生成匿名设备 ID,切断历史诊断关联。
  • 账号注销:在【设置】→【账号】中随时注销账号,注销后即刻清空服务端关联数据。

You maintain full ownership and control over your personal data via in-app controls:

  • Export & Portability: Export annotated PDFs, audio memos, and flashcards in open standard formats.
  • Analytics Opt-Out: Toggle off PostHog product telemetry under Settings → Privacy.
  • Diagnostics Opt-Out: Toggle off crash and diagnostic reporting under Settings → Privacy.
  • Reset Anonymous Identity: Reset your anonymous ID to sever historical diagnostic links.
  • Account Deletion: Request account deletion in Settings → Account to purge server-side metadata.

07. App Store 隐私标签映射 App Store Privacy Labels Mapping

联系信息 Contact Info 已收集 · 关联 Collected · Linked

邮箱(仅用于 Apple 登录/注册账号与客服支持)。

Email address for Apple Sign In / account auth and customer support.

用户内容 User Content 已收集 · 本地/主动触发 Collected · Local/On-Demand

PDF、笔迹、录音、照片与 AI 笔记(本地存储,仅主动触发时传输)。

PDFs, handwriting, audio, photos, and AI notes (local-first; explicit trigger).

标识符 Identifiers 已收集 · 匿名化 Collected · Pseudonymous

钥匙串匿名安装 ID(anonymous_install_id)、用户 ID。

Keychain anonymous install ID and backend user identifier.

购买信息 Purchases 已收集 · 关联 Collected · Linked

StoreKit 2 交易状态与收据凭据(用于会员权益验证)。

StoreKit 2 transaction receipts for subscription entitlement.

使用与诊断 Usage & Diagnostics 已收集 · 去标识化 Collected · De-identified

聚合功能使用与崩溃堆栈(可在设置中随时关闭)。

Aggregated feature analytics and crash stack traces (can opt out in Settings).

位置、通讯录与健康数据 Location, Contacts & Health 不收集 Not Collected

我们绝不申请或收集定位、通讯录与健康数据。

We never collect location, contacts, or health information.

08. 未成年人个人信息保护 Children's Privacy Protection

我们的软件与服务面向广大学习者。若您是未满 14 周岁(或您所在国家/地区法律规定的未成年人年龄)的未成年人,请在监护人指导下阅读本协议并使用本产品。我们对未成年人执行最高标准的本地优先隐私保护,不进行任何商业画像与广告推送。

Our software and services are built for students, researchers, and lifelong learners. If you are under 14 (or the legal age of majority in your jurisdiction), please use our services with parental or guardian supervision. We enforce strict Local-First data protection and zero ad profiling across all users.

09. 政策更新与联系我们 Policy Updates and Contact Us

我们可能适时修订本隐私政策。重大变更将在 App 内显著位置公告。若您对本政策有任何疑问、意见或行使数据权利,请随时联系我们:

We may update this Privacy Policy periodically. Significant changes will be prominently announced in-app. For any inquiries or to exercise your privacy rights, please reach out to us:

时一未来科技 隐私与合规支持团队

TimeOne Lab Privacy & Compliance Team

官方联络邮箱:contact@timeonelab.com

Official Email: contact@timeonelab.com

发送邮件咨询 Contact via Email