隐私政策 / Privacy Policy
草案(Draft)· 2026-07-09 · 待法务终审(pending legal review)
本文档双语呈现:中文在前,英文在后,两版内容等同。 This document is
bilingual: Chinese first, English second; both versions are equivalent.
生效前须替换:品牌名占位(下文以”本应用”指代)、支持邮箱、托管 URL。
中文版
生效日期:(上架前填写)
本隐私政策说明本应用(一款本地优先的电子书阅读器,下称”本应用”)如何处理你的信息。一句话概括:你的数据留在你的设备上;我们没有服务器,不收集、不上传、不出售你的任何数据。
1. 我们不收集的内容
本应用没有账号体系、没有开发者运营的服务器、没有第三方分析/广告
SDK。以下数据完全保存在你的设备本地(应用沙盒):
- 你导入的书籍文件、阅读进度、书签、批注、阅读统计;
- 你自行导入或配置的书源规则、RSS 订阅、替换规则等配置;
- 应用设置(主题、字体、朗读偏好等)。
2. 设备上的数据处理
- iCloud 同步(可选):若你的设备登录了 iCloud
且系统启用了 iCloud Drive,阅读进度会通过 Apple 的 iCloud
键值存储在你自己的 iCloud
账户内跨设备同步。数据不经过开发者——Apple
是该服务的数据处理方。可在系统设置中关闭。
- WebDAV
备份(可选):你可以配置自己的 WebDAV
服务器用于备份。凭证仅保存在本机钥匙串(Keychain),备份数据直接从你的设备发送到你配置的服务器,不经过任何中间方。
- AI 功能(可选,自带密钥):若你配置了自己的 AI 服务
API
密钥(BYOK),相关文本会从你的设备直接发送到你选择的 AI
服务商以生成回顾/问答内容。密钥仅存本机钥匙串,绝不写入日志、备份或任何其他位置。你与该服务商的数据关系受其隐私政策约束。若你的设备支持
Apple 端侧模型,AI 功能可完全离线运行,内容不离开设备。
- 网络请求:仅在你主动触发时发生——导入远程文件、执行你自己配置的书源/RSS
规则、下载语音包、使用在线朗读音色。这些请求直接从你的设备发往对应站点,开发者不代理、不记录。
3.
诊断数据(默认关闭,需你主动开启并主动分享)
设置中的”帮助改进”开关(默认关闭)启用后,系统的
MetricKit
框架会在本机生成崩溃与性能诊断文件,仅保存在你的设备上。只有当你主动使用”导出诊断”分享给开发者时,这些文件才会离开设备。诊断内容为技术指标(崩溃堆栈、卡顿、CPU
用量),不含阅读内容。你可以随时关闭开关并删除本机诊断文件。
4. 内购
应用内购买由 Apple 的 StoreKit
处理。开发者不接触你的支付信息;交易凭证的验证在设备与 Apple
之间完成。
5. 权限说明
- 相机:仅用于扫描二维码导入配置,画面不保存、不上传。
- 本地网络:仅当你的书源/RSS/WiFi
传书指向局域网地址时使用。
- 面容 ID / 触控
ID:仅用于可选的应用锁,验证由系统完成,应用不接触生物特征数据。
6. 你的内容,你负责
本应用是通用工具:书籍与配置均由你自行提供。你应确保对导入内容拥有合法访问权。
7. 未成年人
本应用不面向 13 周岁以下儿童设计,且不收集任何人的个人信息。
8. 政策变更
政策更新会随应用版本发布并在本页面标注生效日期。重大变更会在应用内提示。
9. 联系我们
隐私问题或侵权投诉:octoooo@octoooo.com。我们对合规的侵权通知采取”通知—删除”(notice-and-takedown)响应。
English Version
Effective date: (to be filled before release)
This Privacy Policy explains how this app (a local-first e-book
reader, “the App”) handles your information. In one sentence:
your data stays on your device — we run no servers and do not collect,
upload, or sell any of your data.
1. What we do not collect
The App has no account system, no
developer-operated servers, and no third-party
analytics or advertising SDKs. The following data lives entirely in the
app sandbox on your device:
- Books you import, reading progress, bookmarks, annotations, and
reading statistics;
- Source rules, RSS subscriptions, replacement rules, and other
configuration you import or create;
- App settings (theme, fonts, read-aloud preferences, etc.).
2. On-device data flows
- iCloud sync (optional): if your device is signed
into iCloud, reading progress syncs across your devices through Apple’s
iCloud key-value store inside your own iCloud account.
The data never passes through the developer — Apple is the processor for
this service. You can turn it off in system settings.
- WebDAV backup (optional): you may configure
your own WebDAV server for backups. Credentials are
stored only in the local Keychain; backup data travels directly from
your device to the server you configured.
- AI features (optional, bring-your-own-key): if you
configure your own AI service API key (BYOK), the relevant text is sent
directly from your device to the AI provider you chose
to generate recaps/answers. The key is stored only in the local Keychain
and is never written to logs, backups, or anywhere else. Your
relationship with that provider is governed by their privacy policy. On
devices that support Apple’s on-device models, AI features can run fully
offline.
- Network requests happen only on your action —
importing remote files, executing source/RSS rules you configured,
downloading voice packs, or using online read-aloud voices. Requests go
directly from your device to the target site; the developer does not
proxy or log them.
3.
Diagnostics (off by default; leaves your device only when you share
it)
The “Help Improve” switch in Settings (default off)
enables Apple’s MetricKit framework to produce crash and performance
diagnostic files stored only on your device. They leave
the device only when you actively use “Export Diagnostics” to share them
with the developer. Diagnostics contain technical metrics (crash stacks,
hangs, CPU usage), never reading content. You can turn the switch off
and delete local diagnostic files at any time.
4. In-app purchases
Purchases are processed by Apple StoreKit. The developer never
touches your payment information; transaction verification happens
between your device and Apple.
5. Permissions
- Camera: only for scanning QR codes to import
configuration; frames are neither stored nor uploaded.
- Local Network: used only when your sources/RSS/WiFi
transfer point at LAN addresses.
- Face ID / Touch ID: only for the optional App Lock;
authentication is performed by the system and the App never touches
biometric data.
6. Your content, your
responsibility
The App is a general-purpose tool: books and configuration are
provided by you. You are responsible for having lawful access to the
content you import.
7. Children
The App is not designed for children under 13 and collects no
personal information from anyone.
8. Changes
Updates to this policy ship with app releases and are dated on this
page. Material changes will be announced in the app.
Privacy questions or infringement complaints: octoooo@octoooo.com. We
follow a notice-and-takedown process for valid infringement notices.