狗运极佳 隐私政策
更新日期:2026年8月23日
本隐私政策适用于 iOS 应用「狗运极佳」(以下简称「本应用」)。我们深知隐私对您的重要性。本应用遵循「隐私设计」原则:无需注册;除每日签到、以及您主动使用「狗运通天」中转服务所必需的有限数据外,不在开发者服务器上收集或存储您的案例、札记、聊天内容等隐私数据;仅在功能必要时请求最少系统权限。
1. 本地优先与必要的数据处理
本应用采用本地优先、最少必要和用户控制的设计,不建立开发者侧用户身份档案,不使用广告或行为追踪服务。案例、札记和对话历史默认保存在本地;当您主动启用 iCloud、AI、语音、面相分析等联网功能时,相应数据会按本政策说明发送至 Apple 或您选择的服务商。
- 无需注册: 您下载本应用后即可直接使用,无需创建账户或提供任何个人信息。
- 无数据追踪: 我们不使用任何分析工具、广告SDK或追踪器来监控您的行为。
- 无广告: 本应用不包含任何广告内容,不会向您展示任何第三方广告。
- 有限网络请求: 除可选的 iCloud 同步、AI 对话(含狗运通天中转)、语音识别、语音合成朗读、面相量化分析、每日签到同步及算力包购买验证外,本应用不会主动发起其他网络请求。
2. 您自行产生和存储的数据
本应用是一个适用于宠物和人类的娱乐工具,您在使用过程中输入或创建的所有信息(例如:头像、名称、生日、品种、札记等案例信息)完全由您自己控制。您可以选择是否以及如何存储这些信息。
2.1 本地存储
如果您选择保存案例信息,默认情况下,这些数据将仅存储在您设备的本地应用沙盒中。这意味着:
- 未启用 iCloud、AI、语音识别等联网功能时,案例数据保留在本地;您主动使用联网功能时,相关必要数据将按本政策传输。
- 只有您自己可以通过设备访问这些数据。
- 当您卸载本应用时,这些本地数据将被系统完全删除。
- 数据受到iOS系统级别的沙盒保护,其他应用无法访问。
2.2 iCloud云同步(可选功能)
为了方便您在多个设备间同步数据,我们提供了基于Apple iCloud的云同步选项。这是一个完全可选的功能,开启或关闭的权利完全在您手中。
- 用户控制: 您可以选择是否开启iCloud同步。
- 数据归属: 当您开启同步时,您的数据会被加密并存储在您自己的个人iCloud账户中。数据的所有权和控制权仍然属于您。
- 访问与用途限制: 数据存放在与您 Apple 账户关联的私人 CloudKit 数据库或 iCloud 钥匙串中。开发者不将案例、札记、对话等内容复制到自建服务器,不将其用于广告、画像或与应用功能无关的用途;数据访问仍受 Apple 平台权限、应用功能和适用法律约束。
- 管理与删除: 您可以随时在设备的"设置"中管理或删除存储在iCloud上的应用数据。
- 安全保护: 数据传输与存储由 Apple 平台提供相应的加密和访问控制保护,具体安全机制以 Apple 当前说明为准。
- AI 配置与 API Key 同步: 为便于您在自己的 Apple 设备间恢复模型配置,所选 AI 服务商及您主动填写的自定义 API Key 可能通过 iCloud Keychain 和您的私有 CloudKit 数据库同步。API Key 不会公开展示,也不会用于您所选服务商之外的用途;您可以在应用模型设置中清除 Key,并可通过 Apple 的 iCloud 设置管理相关云端数据。
2.3 每日签到数据(开发者服务器)
为恢复签到功能并提高数据稳定性,每日签到状态已迁移至开发者管理的 PostgreSQL 服务器。
服务器仅保存实现每日签到所必需的有限数据,包括:
- App 专属 iCloud 用户标识
- 免费真气余额
- 连续签到天数
- 签到及补签日期
- 补签卡数量
- 防止补签卡重复发放所需的 StoreKit 交易编号
订阅真气、购买真气、案例、札记、聊天内容及其他用户数据均不迁移至签到服务器,仍保存在您的设备或 Private CloudKit 中。上述签到数据仅用于提供签到与补签功能,不用于广告、营销或追踪。
2.4 狗运通天算力包与 AI 中转服务(开发者服务器)
当您主动选择并使用「狗运通天」模型时,本应用会通过开发者运营的 PostgreSQL 服务器临时中转 AI 请求,以便支持后台或锁屏等待回复、算力包余额计量、流式任务恢复,以及将请求转发至上游 AI 服务商(如 DeepSeek、通义千问、小米 MiMo 等)。狗运通天不消耗本地「真气」,而使用单独购买的算力包额度。
为此,服务器会处理以下有限且必要的数据:
- 用户标识: 与每日签到相同,使用您 iCloud 账户的 CloudKit 用户 recordName(通过请求头
X-User-Id 传递),用于关联算力余额、任务与防重复入账;我们不会要求您额外注册账号或提供手机号、邮箱。
- 购买与余额: App Store 交易凭证(JWS)、交易编号、算力包授予/剩余额度、到期时间,以及可选的 App Account Token 绑定信息,用于验证「狗运通天算力包」(消耗型内购,当前定价 68 元人民币)并入账。
- 任务中转(临时): 创建 AI 任务时,服务器会临时保存对话标识、所选模型、以及生成回答所需的请求内容(可能包括您发送的文字、图片及案例资料、排盘信息、札记、相关对话和长期记忆等组合后的 prompt);在流式生成过程中,可能临时缓存回复片段。
- 用量计量: 与任务相关的 token/字符估算、扣费流水及任务状态,用于结算算力包消耗。
我们不会长期保存您的 AI 对话内容。 当 App 确认已完整收取回复(ack)后,服务器会自动清除该任务中的对话正文(response_text、reasoning_text)与请求内容(prompt_json);任务元数据(如任务 ID、状态、用量)最长保留 7 天后自动删除。算力包余额与交易去重记录会保留至包过期或依 Apple 退款/撤销通知处理,不包含对话正文。
上述数据仅用于提供狗运通天服务、计量算力、运维排错与合规处理,不用于广告、用户画像或与该功能无关的用途。
3. AI对话功能的数据处理
本应用中的 AI 功能严格定位为娱乐类、工具型的传统命理理论分析工具,用于整理、解释用户主动提交的案例与命理资料。本应用不提供拟人化情感陪伴、虚拟亲密关系、心理治疗或真人专业服务,不以替代现实社会交往、诱导依赖或控制用户心理为目标。
3.1 AI服务提供方
- 两种传输路径:
- 狗运极佳默认模型与自定义 API: 应用通过 HTTPS 从您的设备直连当前所选 AI 服务商官方 API,不经开发者服务器中转。
- 狗运通天模型: 同类数据会经开发者服务器(见上文第 2.4 节)临时中转至上游 AI 服务商,以便后台回复与算力计量;确认收取完整回复后会自动清除对话正文与请求内容。
- 支持的第三方 AI 服务: 应用提供狗运极佳内置模型与自定义 API,并可接入 DeepSeek、Kimi、阿里通义千问(Qwen)、小米 MiMo、MiniMax、智谱 GLM 等;狗运通天还可通过服务器路由上述等上游模型。在相关功能和地区可用时,还可能提供 OpenAI、Anthropic Claude 和 Google Gemini。实际接收方以应用发送前显示的当前所选服务商为准。
- 内置模式: 应用内置官方 API 密钥,您无需任何配置即可直接使用狗运极佳内置模型。
- 自定义 API Key 模式: 您可以在设置中输入当前版本所列服务商的自有 API Key,以使用自己的账户额度。Key 会保存在系统 Keychain,并可能按上文说明同步至您的 iCloud Keychain 与私有 CloudKit 数据库,而非“仅保存在单台本地设备”。
- 官方端点: 使用狗运极佳默认模型或自定义 API Key 时,应用从您的设备连接当前所选服务商的官方 API。使用狗运通天时,请求先到达开发者服务器再转发至上游官方 API。网络传输和服务商系统仍可能存在其固有风险。
- 传输内容: 当您使用 AI 功能时,您主动输入或确认发送的内容,以及生成回答所需的案例资料、排盘信息、札记、相关对话和长期记忆,可能被组合后发送至所选 AI 服务商处理。这些内容可能包含您填写的姓名、性别、生日、出生地等信息。
- 用户主动传输: 我们不会在开发者服务器上另外收集或建立您的身份档案;但您主动提交发送给 AI 的内容可能包含您自行填写的个人信息,其后续处理受所选 AI 服务商政策约束。
服务商官方政策入口:DeepSeek、Kimi、阿里云百炼 / Qwen、小米 MiMo、MiniMax、智谱 GLM、OpenAI、Anthropic、Google Gemini。服务商可能更新政策或链接,请以其官方页面当时展示内容为准。
3.2 AI数据保护措施
- 无开发者侧身份档案: 我们不运营传统意义上的用户账户体系,不在开发者服务器上建立您的案例或札记档案。发送至 AI 服务商(或经狗运通天临时中转)的数据由您在使用功能时主动触发。
- 服务商政策: AI 服务商可能按照其当时有效的条款和隐私政策处理、记录、保存或使用请求数据,包括用于安全审查、服务改进或模型训练。具体保存期限、退出机制和用户权利以所选服务商政策为准;使用自定义 API Key 时,您与相应服务商之间的协议亦同时适用。
- 加密传输: 数据通过 HTTPS 加密通道传输,以降低传输过程中的风险;任何网络或云服务均无法保证绝对安全。
- 开发者对话存储边界: 我们不在开发者服务器上长期保存完整 AI 对话库。狗运极佳默认/自定义 API 路径下,对话不经开发者服务器;狗运通天路径下,对话正文与请求内容仅在任务进行及恢复期间临时保存,并在您确认收取完整回复后自动清除(详见第 2.4 节)。
- 开发者处理边界: 开发者不将 AI 对话用于广告或用户画像;数据到达所选 AI 服务商(或经中转后到达上游服务商)后,由该服务商依其政策和适用法律处理。
3.3 您的控制权
- 自愿使用: AI对话功能完全由您自愿选择使用。
- 本地历史: 对话历史记录仅保存在您的本地设备或个人 iCloud 账户中,开关完全由您自主控制,我们不会在服务器端存储任何聊天记录。
- 随时删除: 您可以随时在应用内删除对话历史记录。
- 选择退出: 您可以随时选择不使用AI对话功能,仅使用本地功能,数据不会发生任何网络传输。
3.4 知情同意与透明说明
- 主动确认: 首次发送 AI 消息前,应用会展示数据处理方式、当前所选 AI 服务商以及用户协议和隐私政策链接。只有在您主动勾选并点击“同意并继续”后,应用才会发送请求;选择“暂不使用”不会发送 AI 请求。
- 持续透明: 应用在 API 配置页面显著位置说明当前所连接的 AI 服务商及其官方端点,确保您随时了解数据流向。
3.5 AI 生成内容标识
- 显式标识: AI 回复界面及导出的分享图片会显示“AI生成,毫无科学依据,仅供娱乐参考”等可见提示;复制的完整 AI 文本会附带相应声明。
- 文件隐式标识: 应用导出的 AI 分享 PNG 会按照适用的人工智能生成合成内容标识要求,在文件元数据中写入包含 AIGC 属性、内容制作方及唯一内容编号等信息的隐式标识。
- 用户义务: 您对外发布或传播 AI 生成内容时,应主动声明其 AI 生成属性,不得恶意删除、篡改、伪造或隐匿应用添加的标识。
4. 系统权限说明
本应用遵循最小权限原则,仅在您使用相关功能时才会请求对应权限。以下权限不会请求:
- 通讯录权限
- 日历或提醒事项权限
- 健康数据权限
- 蓝牙权限
- Face ID或Touch ID权限
以下权限仅在您主动使用对应功能时才会请求,均为可选,拒绝授权不影响其他功能:
- 位置权限: 用于札记或出生地等场景的自动定位,仅在您触发相关功能时请求。
- 相机或相册权限: 用于札记上传图片,以及您主动使用面相量化分析时选择或拍摄照片;仅在您触发相关功能时请求。
- 通知权限: 用于事件提醒等功能,您可在系统设置中随时关闭。
4.1 麦克风权限(语音输入功能)
本应用提供可选的语音转文字功能,仅在您主动点击语音输入按钮时才会申请麦克风权限。语音数据通过腾讯云「一句话识别」接口进行实时转录。关于该权限的使用,我们做出如下承诺:
- 用途单一:麦克风权限仅用于将您的语音实时转录为文字,方便您输入对话内容,不用于任何其他目的。
- 不存储语音:您的语音内容经腾讯云接口实时转录后即丢弃,我们不存储任何语音录音。
- 第三方处理:语音转录由腾讯云提供,音频数据会发送至腾讯云服务器处理,具体规则请参阅腾讯云相关服务条款与隐私政策。
- 不用于追踪或训练:我们不对语音数据用于用户追踪或行为画像。
- 您可随时关闭:您可在设备的"设置"中随时撤销麦克风权限,不影响应用的其他功能使用。
4.2 语音合成朗读(可选)
洞见页等场景可提供可选的 AI 回复朗读。若您选择使用系统自带朗读,文字通常在设备本地合成,不额外发送至腾讯云。若您配置并选用腾讯云音色,应用会将待朗读的文字通过 HTTPS 发送至腾讯云语音合成(TTS)接口生成音频;我们不因此在自建服务器保存朗读文本或音频。具体处理规则以腾讯云当时有效的服务条款与隐私政策为准。您可随时改用系统朗读或关闭朗读功能。
4.3 面相量化分析(可选)
当您在典籍等模块主动使用面相量化功能时,您选择或拍摄的人脸图像会通过 HTTPS 发送至百度智能云人脸检测接口,用于提取量化特征以供后续文化/命理框架下的娱乐化参考分析。关于该功能:
- 主动触发:仅在您主动选择图片或拍照并确认分析时才会上传,不会在后台静默采集人脸。
- 传输内容:主要为您提交的人脸图像及完成检测所需的技术参数;开发者不将人脸图复制到自建服务器用于广告或画像。
- 第三方处理:检测由百度智能云处理,后续保存期限与使用规则以百度当时有效的服务条款与隐私政策为准。
- 本地结果:分析过程中产生的结构化结果与您关联的案例资料,默认保存在本地设备,并可按您的设置同步至私人 iCloud。
- 可选择退出:您可以不使用面相功能;拒绝相机或相册权限不影响排盘、签到等其他功能。
5. 订阅服务与内购支付
本应用提供订阅制及消耗型内购选项。订阅与内购的购买、支付及续订均由 Apple App Store 处理,我们不会直接处理或存储您的支付信息(如信用卡号、银行账户等)。
5.1 订阅选项
- 基础年度订阅: 年度自动续订,价格以 App Store 页面显示为准。解锁本应用全部功能(含会员差异化能力),不包含无限真气;AI 仍可通过每日签到获得的免费真气(狗运极佳默认模型等)或使用狗运通天算力包。
- 周订阅(PRO): 18元人民币/周,无限使用所有功能,无限真气
- 月度订阅(PRO): 36元人民币/月(在本价格调整生效前已开通且保持不间断自动续订的月度订阅用户,续订价格仍为30元人民币/月)
- 年度订阅(PRO): 298元人民币/年,无限使用所有功能,无限真气
- 终身会员(PRO): 888元人民币,一次性购买,永久无限使用所有功能,无限真气
5.2 消耗型内购
- 补签卡: 一次性消耗品,通过 Apple App Store 购买;使用后可以且仅可补签昨日缺失的签到。
- 狗运通天算力包: 一次性消耗型内购,当前定价 68 元人民币;购买后 30 天内有效,用于「狗运通天」模型的云端算力额度,不消耗本地真气,不可转让、不可兑换现金。余额通过 iCloud 用户标识与 App Store 交易凭证关联至服务器。
5.3 支付与订阅数据
- Apple 处理:所有订阅及内购的支付均由 Apple 完成,我们不会获取您的个人支付信息。
- 订阅管理:您可随时在 iOS「设置 > Apple ID > 订阅」中管理或取消订阅。
- 自动续订:订阅将自动续订,除非您在当前订阅期结束前至少 24 小时取消。
- 状态验证:我们仅通过 Apple 提供的匿名订阅状态验证确认权益是否有效,验证在您的设备上本地进行。
6. 数据安全
我们通过本地沙盒、Keychain、Apple 私有 CloudKit 数据库及 HTTPS 等措施降低数据风险。任何网络与云服务均无法承诺绝对安全;AI 与语音数据到达相应服务商后,由该服务商依其政策和适用法律处理。
- 本地加密: 数据存储在您的设备上时,受iOS系统级加密的保护。
- 有限服务器存储: 开发者服务器保存:(1)第 2.3 节所述每日签到数据;(2)第 2.4 节所述狗运通天算力包、余额、交易去重及 AI 任务临时中转数据。我们不在服务器上长期保存案例、札记或完整 AI 对话库。
- Apple安全保障: 如果您使用iCloud同步,数据安全由Apple的CloudKit服务保障。
- 传输加密: AI对话数据传输使用行业标准的HTTPS加密协议。
7. 第三方服务
本应用使用以下第三方服务:
- Apple App Store:用于处理订阅、终身会员及消耗型内购的购买与支付,我们不会获取您的支付信息。
- Apple iCloud(CloudKit 与 iCloud Keychain): 用于您选择的案例、对话等数据同步,并可能用于模型选择及自定义 API Key 的跨设备同步。
- 官方 AI 服务商(DeepSeek、Kimi、阿里通义千问、小米 MiMo、MiniMax、智谱 GLM 等): 仅在您启用并使用 AI 功能时调用。传输内容可能包括您主动提交的文字,以及生成回答所需的案例资料、排盘信息、札记、相关对话和长期记忆;具体处理规则以您实际选择的服务商政策为准。
- 腾讯云(语音识别): 仅在您使用语音输入功能时调用,通过「一句话识别」接口将语音实时转录为文字。
- 腾讯云(语音合成 TTS): 仅在您配置并选用腾讯云音色朗读 AI 回复时调用;待朗读文字发送至腾讯云合成接口。
- 百度智能云(人脸检测): 仅在您主动使用面相量化分析时调用;人脸图像发送至百度检测接口以提取量化特征。
- 开发者 PostgreSQL 服务器(每日签到): 用于每日签到状态同步,保存第 2.3 节所列有限数据。
- 开发者 PostgreSQL 服务器(狗运通天): 仅在您使用狗运通天模型或购买/恢复算力包时调用;处理第 2.4 节所列数据,并在任务完成后自动清除对话正文与请求内容。
除此之外,我们不集成任何第三方分析、广告、社交分享或其他可能收集您数据的SDK或服务。
- 无第三方追踪: 不集成Google Analytics、Facebook SDK等任何第三方追踪服务。
- 无广告网络: 不集成任何广告网络或广告SDK。
- 透明使用: 所有第三方服务的使用都是透明的,并在本政策中明确说明。
8. 儿童隐私
除每日签到所必需的有限数据外,本应用不在开发者服务器上收集隐私数据,也不会故意收集儿童的隐私数据。我们鼓励家长和监护人监督孩子的在线活动。
- 适合全年龄: 本应用内容适合13岁及以上用户使用。
- 无额外隐私数据收集: 除签到功能所必需的有限数据外,我们不会主动收集隐私数据。
- 家长监督: 建议未成年人在家长监督下使用本应用,特别是使用AI对话功能时。
- 教育性质: 本应用旨在提供命理学生活哲学方面的娱乐与参考内容,适合作为个人思考与学习的辅助工具。
9. 您的权利
对于保存在本地设备或个人 iCloud 账户中的应用数据,您拥有直接控制权;签到数据及已发送至第三方服务商的数据分别按本政策相关章节处理:
- 访问、修改和删除权: 您可以随时在应用内直接查看、修改或删除您保存的任何案例信息和对话记录。
- 数据可携带权: 您可以通过应用内的功能(如截图、导出)或iCloud来管理您的数据。
- 控制权: 您可以随时决定是否使用存储功能、是否开启iCloud同步、是否使用AI对话功能。
- 完全删除权: 您可以随时删除应用内的所有数据,或通过卸载应用来完全清除数据。
- 选择退出权: 您可以选择不使用任何涉及数据传输的功能(如AI对话),仅使用本地功能。
10. 数据保留
除第 2.3、2.4 节所述服务器数据外,开发者不在其他服务器上长期存储您的隐私数据。各类数据的保留方式如下:
- 本地数据: 保留在您的设备上,直到您主动删除或卸载应用。
- iCloud数据: 保留在您的个人iCloud账户中,由您自己管理。
- 签到数据: 保存在开发者 PostgreSQL 服务器,仅用于签到与补签功能;您可通过卸载应用或联系我们请求删除相关记录。
- 狗运通天任务数据: 任务进行期间临时保存请求与回复片段;App 确认收取完整回复后自动清除对话正文与请求内容;任务元数据最长 7 天后自动删除。算力包余额与交易记录保留至包过期或依 Apple 退款/撤销处理。
- AI对话数据: 应用内完整对话历史保存在本地或您的 iCloud;经狗运通天中转的内容不在开发者服务器长期保留(见第 2.4 节);到达 AI 服务商后的保存期限以该服务商政策为准。
- 无自动删除: 除签到功能所需数据外,我们不会自动删除您设备或 iCloud 中的其他数据。
11. 政策更新
我们可能会更新本隐私政策以反映我们服务的变化。如果发生任何重大变更,我们将通过以下方式通知您:
- 在应用更新说明中通知
- 在官方网站发布公告
- 应用内弹窗提醒(如有重大变更)
我们建议您定期查看本政策以了解最新信息。特别是涉及 AI 功能、订阅服务、内购项目和数据处理方式的变更,我们会提前至少 30 天通知。
12. 相关协议
本隐私政策与我们的用户协议共同构成您使用本应用的完整法律框架。请您同时阅读并遵守用户协议的相关条款。
13. 联系我们
如果您对本隐私政策有任何疑问、建议或需要任何澄清,请通过以下方式联系我们。特别是Apple审核团队的成员,如果您需要进一步了解隐私实现细节或AI数据处理方式,我们非常乐意提供协助。
感谢您信任狗运极佳,我们将继续致力于保护您的隐私。
Furud Privacy Policy
Updated: August 23, 2026
This Privacy Policy applies to the iOS application "Furud" (hereinafter referred to as "the App"). We understand the importance of privacy. The App follows Privacy by Design: no registration required; except for the limited data necessary for daily check-in and for the Sirius (Tongtian) relay service when you actively use it, we do not collect or store your private data (such as cases, journals, or chat content) on developer-operated servers; and we request only the minimum permissions necessary for App functionality.
1. Local-First and Necessary Data Processing
The App follows a local-first, data-minimization, and user-control approach. We do not build developer-side identity profiles or use advertising or behavioral tracking. Cases, journals, and chat history are stored locally by default. When you actively use iCloud, AI, speech features, or facial analysis, the necessary data is sent to Apple or the provider you select as described below.
- No Registration Required: You can use the App directly after downloading without creating an account or providing any personal information.
- No Data Tracking: We do not use any analytics tools, advertising SDKs, or trackers to monitor your behavior.
- No Advertisements: The App does not contain any advertising content and will not display any third-party advertisements.
- Limited Network Requests: Except for optional iCloud sync, AI conversation (including Sirius/Tongtian relay), speech recognition, optional speech synthesis (TTS), optional facial analysis, daily check-in sync, and compute-pack purchase verification, the App does not initiate other network requests.
2. Data You Generate and Store
This App is an entertainment tool for pets and humans. All information you input or create during use (such as: avatars, names, birthdays, breeds, journal notes, and other case information) is completely under your control. You can choose whether and how to store this information.
2.1 Local Storage
If you choose to save case information, by default, this data will only be stored in the local app sandbox on your device. This means:
- Case data remains local unless you actively use an iCloud, AI, speech-recognition, or other network feature described in this policy.
- Only you can access this data through your device.
- When you uninstall the App, this local data will be completely deleted by the system.
- Data is protected by iOS system-level sandboxing, and other apps cannot access it.
2.2 iCloud Cloud Sync (Optional Feature)
To facilitate syncing data across multiple devices, we provide an Apple iCloud-based cloud sync option. This is a completely optional feature, and you have full control over enabling or disabling it.
- User Control: You can choose whether to enable iCloud sync.
- Data Ownership: When you enable sync, your data will be encrypted and stored in your personal iCloud account. Ownership and control of the data remain with you.
- Access and Purpose Restrictions: Data is stored in a private CloudKit database or iCloud Keychain associated with your Apple Account. The developer does not copy cases, journals, conversations, or similar content to developer-operated servers or use it for advertising, profiling, or purposes unrelated to App functionality. Access remains subject to Apple platform permissions, App functionality, and applicable law.
- Management and Deletion: You can manage or delete app data stored on iCloud at any time in your device's "Settings".
- Security Protections: Apple platform encryption and access controls protect data in transit and at rest, subject to Apple’s current documentation.
- AI Configuration and API Key Sync: To restore model settings across your Apple devices, the selected provider and custom API Keys you enter may sync through iCloud Keychain and your private CloudKit database. Keys are not publicly displayed or used with providers other than the one you select. You can clear them in model settings and manage related cloud data through Apple’s iCloud settings.
2.3 Daily Check-in Data (Developer Server)
To restore check-in functionality and improve data stability, daily check-in status has been migrated to a developer-managed PostgreSQL server.
The server stores only the limited data necessary for daily check-in, including:
- App-specific iCloud user identifier
- Free Qi balance
- Consecutive check-in days
- Check-in and makeup check-in dates
- Makeup check-in card count
- StoreKit transaction IDs needed to prevent duplicate makeup card grants
Subscription Qi, purchased Qi, cases, journals, chat content, and other user data are not migrated to the check-in server and remain on your device or in Private CloudKit. Check-in data is used only to provide check-in and makeup check-in features, not for advertising, marketing, or tracking.
2.4 Sirius Compute Pack and AI Relay Service (Developer Server)
When you actively choose and use the Sirius (Tongtian) model, the App temporarily relays AI requests through a developer-operated PostgreSQL server so replies can continue in the background or on the lock screen, compute packs can be metered, streaming jobs can be recovered, and requests can be forwarded to upstream AI providers (such as DeepSeek, Qwen, and Xiaomi MiMo). Sirius does not consume local “Qi.” It uses separately purchased compute packs.
The server processes the following limited and necessary data:
- User identifier: The same CloudKit user recordName used for daily check-in (sent as
X-User-Id) to link compute balance, jobs, and anti-duplicate crediting. We do not ask for a separate account, phone number, or email.
- Purchase and balance: App Store transaction receipts (JWS), transaction IDs, granted/remaining compute, expiration time, and optional App Account Token binding to verify the Sirius Compute Pack (consumable IAP, currently ¥68 RMB) and credit balance.
- Temporary job relay: When creating an AI job, the server temporarily stores conversation identifiers, the selected model, and the request payload needed to generate a reply (which may include your text, images, and combined case data, charts, journal entries, related conversations, and long-term memory). Streaming reply fragments may be cached temporarily during generation.
- Usage metering: Token/character estimates, billing ledger entries, and job status related to compute-pack settlement.
We do not long-term store your AI conversation content. After the App confirms receipt of the full reply (ack), the server automatically clears message bodies (response_text, reasoning_text) and request payloads (prompt_json) for that job. Job metadata (such as job ID, status, and usage) is deleted within up to 7 days. Compute balance and transaction deduplication records are retained until packs expire or are handled per Apple refund/revocation notices and do not include conversation bodies.
This data is used only to provide Sirius/Tongtian, meter compute, operate the service, troubleshoot, and meet compliance obligations—not for advertising, profiling, or unrelated purposes.
3. AI Conversation Feature Data Processing
AI features are strictly positioned as an entertainment-oriented tool for analyzing traditional Chinese metaphysics theories. They organize and explain case and chart information voluntarily submitted by users. The App does not provide anthropomorphic emotional companionship, virtual intimate relationships, psychotherapy, or human professional services, and is not designed to replace real-world social relationships or induce dependency.
3.1 AI Service Providers
- Two transmission paths:
- Furud default or custom API: The App connects directly from your device to the selected provider's official API over HTTPS without routing through developer-operated servers.
- Sirius (Tongtian) model: The same categories of data are temporarily relayed through developer servers (Section 2.4) to upstream AI providers for background replies and compute metering; message bodies and request payloads are cleared after you confirm receipt of the full reply.
- Supported AI Services: The App provides a Furud built-in model path and custom API options, and may connect to DeepSeek, Kimi, Alibaba Qwen, Xiaomi MiMo, MiniMax, Zhipu GLM, and others. Sirius may also route to upstream providers such as these. OpenAI, Anthropic Claude, and Google Gemini may also be available where supported by the feature and region. The actual recipient is the provider shown as selected before a request is sent.
- Built-in Mode: The App includes official API credentials so you can use the Furud built-in model without configuration.
- Custom API Key Mode: You may enter your own Key for a provider listed in the current version. It is stored in Keychain and may sync through iCloud Keychain and your private CloudKit database as described above; it is not represented as being stored only on one local device.
- Official endpoints: With the Furud default model or a custom API Key, the App connects from your device to the selected provider's official API. With Sirius, requests reach developer servers first and are then forwarded to upstream official APIs. Network transmission and provider systems still carry inherent risks.
- What Is Transmitted: When you use an AI feature, your submitted content and the case data, charts, journal entries, related conversations, and long-term memory needed to generate a response may be combined and sent to the selected provider. This may include information you entered such as a name, gender, birthday, or birthplace.
- User-Initiated Transmission: We do not separately collect or maintain identity profiles on developer servers; however, content you submit to AI may include personal information you entered yourself, and its subsequent processing is governed by the selected AI provider's policies.
Official provider policies: DeepSeek, Kimi, Alibaba Cloud Model Studio / Qwen, Xiaomi MiMo, MiniMax, Zhipu GLM, OpenAI, Anthropic, and Google Gemini. Providers may update their policies or links; their then-current official pages control.
3.2 AI Data Protection Measures
- No Developer-Side Identity Database: We do not operate a user account system and do not persistently store your cases or conversations on developer servers. Data sent to AI providers is triggered only when you use the feature.
- Provider Policies: AI providers may process, log, retain, or use request data under their then-current terms and privacy policies, including for safety review, service improvement, or model training. Retention periods, opt-out mechanisms, and user rights depend on the selected provider. Your agreement with that provider also applies when you use a custom API Key.
- Encrypted Transmission: Data is transmitted over HTTPS to reduce risks in transit. No network or cloud service can guarantee absolute security.
- Developer conversation storage boundary: We do not long-term store a full AI conversation database on developer servers. On the Furud default/custom API path, conversations do not pass through developer servers. On the Sirius path, message bodies and request payloads are stored only while a job is running or being recovered and are cleared after you confirm receipt of the full reply (see Section 2.4).
- Developer processing boundary: The developer does not use AI conversations for advertising or profiling. Once data reaches the selected AI provider (or an upstream provider after relay), that provider processes it under its policies and applicable law.
3.3 Your Control
- Voluntary Use: The AI conversation feature is entirely voluntary for you to use.
- Local History: Conversation history is saved only on your local device or in your personal iCloud account; the sync toggle is entirely under your control. We do not store any chat records on our servers.
- Delete Anytime: You can delete conversation history within the App at any time.
- Opt-Out: You may choose not to use the AI conversation feature at any time and use only local features, with no network data transmission occurring.
3.4 Informed Consent and Transparency
- Affirmative Confirmation: Before the first AI message is sent, the App presents the data flow, current AI provider, and links to the User Agreement and Privacy Policy. A request is sent only after you actively select the checkbox and tap “Agree and Continue.” Choosing “Not Now” sends no AI request.
- Ongoing Transparency: The App prominently displays the currently connected AI service provider and its official endpoint on the API configuration page, so you are always informed of where your data goes.
3.5 AI-Generated Content Labels
- Visible Labels: AI replies and exported share images display a visible AI-generated entertainment notice; full copied AI text includes the corresponding notice.
- File Metadata: Exported AI share PNG files include AIGC metadata identifying the AI-generated attribute, content producer, and unique content ID as required by applicable labeling rules.
- User Responsibility: When publishing or distributing AI-generated content, you must disclose its AI-generated nature and must not maliciously remove, alter, forge, or conceal labels added by the App.
4. System Permissions
The App follows a minimum-permission principle and requests permissions only when you use related features. The following permissions will never be requested:
- Contacts permissions
- Calendar or reminder permissions
- Health data permissions
- Bluetooth permissions
- Face ID or Touch ID permissions
The following permissions are requested only when you actively use the corresponding feature. All are optional; denying permission does not affect other features:
- Location: Used for auto-location in journal notes or birthplace fields, requested only when you trigger the feature.
- Camera or Photo Library: Used when you upload images in journals, and when you actively choose or take a photo for optional facial analysis.
- Notifications: Used for event reminders; you can disable them in system Settings at any time.
4.1 Microphone Permission (Voice Input Feature)
The App offers an optional voice-to-text feature. Microphone permission is only requested when you actively tap the voice input button. Voice data is transcribed in real time via Tencent Cloud's "One Sentence Recognition" API. We make the following commitments regarding this permission:
- Single Purpose: Microphone access is used solely to transcribe your speech into text for conversation input, and for no other purpose.
- No Audio Storage: Voice input is processed via Tencent Cloud and discarded after transcription; we do not store any voice recordings.
- Third-Party Processing: Transcription is provided by Tencent Cloud; audio is sent to Tencent Cloud servers. Please refer to Tencent Cloud's terms and privacy policy for details.
- Not Used for Tracking: We do not use voice data for user tracking or behavioral profiling.
- Revocable Anytime: You may revoke microphone permission at any time in your device Settings without affecting any other App functionality.
4.2 Optional Speech Synthesis (TTS)
Insight and similar screens may offer optional read-aloud for AI replies. If you use the system voice, synthesis usually stays on-device and is not sent to Tencent Cloud. If you configure and select a Tencent Cloud voice, the text to be spoken is sent over HTTPS to Tencent Cloud TTS to generate audio. We do not store that text or audio on developer-operated servers. Processing follows Tencent Cloud's then-current terms and privacy policy. You may switch back to the system voice or turn read-aloud off at any time.
4.3 Optional Facial Analysis
When you actively use facial analysis in Classics or similar modules, the face image you choose or capture is sent over HTTPS to Baidu AI Cloud face detection to extract quantitative features for entertainment-oriented cultural/metaphysics reference. Regarding this feature:
- User-initiated only: Images are uploaded only after you select a photo or take a picture and confirm analysis; faces are not collected in the background.
- What is transmitted: Primarily the face image you submit and technical parameters needed for detection. The developer does not copy face images to developer-operated servers for advertising or profiling.
- Third-party processing: Detection is performed by Baidu AI Cloud; retention and use follow Baidu's then-current terms and privacy policy.
- Local results: Structured results associated with your case are stored locally by default and may sync to your private iCloud if you enable sync.
- Opt out: You may skip facial analysis; denying camera or photo library access does not affect charting, check-in, or other features.
5. Subscription Services and In-App Purchases
The App offers subscription plans and consumable in-app purchases. All purchases, payments, and renewals are processed by the Apple App Store. We do not directly process or store your payment information (such as credit card numbers or bank accounts).
5.1 Subscription Options
- Basic Annual Subscription: Auto-renewing annually; price shown in the App Store. Unlocks all app features (including member-only capabilities) but does not include unlimited Qi. AI may still use free Qi from daily check-in (Furud default model, etc.) or Sirius compute packs.
- Weekly Subscription (PRO): ¥18 RMB/week, unlimited access to all features, unlimited Qi
- Monthly Subscription (PRO): ¥36 RMB/month (users who had an active monthly subscription with uninterrupted auto-renewal before this price change will continue to be charged ¥30 RMB/month)
- Annual Subscription (PRO): ¥298 RMB/year, unlimited access to all features, unlimited Qi
- Lifetime Membership (PRO): ¥888 RMB, one-time purchase, permanent unlimited access to all features, unlimited Qi
5.2 Consumable In-App Purchases
- Makeup Check-in Card: A one-time consumable item purchased through the Apple App Store; once used, it can and may only make up for yesterday's missed check-in.
- Sirius Compute Pack: A one-time consumable IAP currently priced at ¥68 RMB; valid for 30 days after purchase and used for Sirius/Tongtian cloud compute. It does not consume local Qi, is non-transferable, and cannot be exchanged for cash. Balance is linked on the server through your iCloud user identifier and App Store transaction receipts.
5.3 Payment and Subscription Data
- Apple Processing: All subscription and in-app purchase payments are completed by Apple; we do not obtain your personal payment information.
- Subscription Management: You can manage or cancel subscriptions at any time in iOS Settings > Apple ID > Subscriptions.
- Auto-Renewal: Subscriptions automatically renew unless canceled at least 24 hours before the end of the current period.
- Status Verification: We only use anonymous subscription status verification provided by Apple to confirm entitlements, performed locally on your device.
6. Data Security
We reduce risk through the local sandbox, Keychain, Apple private CloudKit databases, and HTTPS. No network or cloud service can guarantee absolute security; after AI or speech data reaches the relevant provider, it is processed under that provider’s policy and applicable law.
- Local Encryption: When data is stored on your device, it is protected by iOS system-level encryption.
- Limited Server Storage: Developer servers store: (1) daily check-in data in Section 2.3; (2) Sirius compute packs, balance, transaction deduplication, and temporary AI job relay data in Section 2.4. We do not long-term store cases, journals, or a full AI conversation database on servers.
- Apple Platform Protection: If you use iCloud sync, transmission, storage, and access controls are provided under Apple's current CloudKit security model.
- Transmission Encryption: AI conversation data transmission uses industry-standard HTTPS encryption protocols.
7. Third-Party Services
The App uses the following third-party services:
- Apple App Store: Used to process subscription, lifetime membership, and consumable in-app purchases; we do not obtain your payment information.
- Apple iCloud (CloudKit and iCloud Keychain): Used for the case/chat synchronization you choose and may also synchronize model selection and custom API Keys across your devices.
- Official AI Providers (DeepSeek, Kimi, Alibaba Qwen, Xiaomi MiMo, MiniMax, Zhipu GLM, etc.): Used only when you activate an AI feature. Transmitted data may include text you submit and the case data, charts, journals, related conversations, and long-term memory needed to generate a response.
- Tencent Cloud (Speech Recognition): Only called when you use voice input, via the "One Sentence Recognition" API to transcribe speech to text in real time.
- Tencent Cloud (TTS): Only called when you configure and select a Tencent Cloud voice to read AI replies aloud; the text to be spoken is sent to Tencent Cloud TTS.
- Baidu AI Cloud (Face Detection): Only called when you actively use facial analysis; face images are sent to Baidu's detection API to extract quantitative features.
- Developer PostgreSQL Server (daily check-in): Used for daily check-in status sync, storing the limited data listed in Section 2.3.
- Developer PostgreSQL Server (Sirius/Tongtian): Called when you use Sirius or purchase/restore compute packs; processes the data listed in Section 2.4 and clears message bodies and request payloads after you confirm receipt of the full reply.
Apart from this, we do not integrate any third-party analytics, advertising, social sharing, or other SDKs or services that may collect your data.
- No Third-Party Tracking: No integration of Google Analytics, Facebook SDK, or any other third-party tracking services.
- No Ad Networks: No integration of any ad networks or advertising SDKs.
- Transparent Use: All use of third-party services is transparent and clearly stated in this policy.
8. Children's Privacy
Except for the limited data necessary for daily check-in, the App does not collect private data on developer servers and does not intentionally collect children's private data. We encourage parents and guardians to supervise their children's online activities.
- Suitable for All Ages: The App content is suitable for users aged 13 and above.
- No Additional Private Data Collection: Except for the limited data required for check-in, we do not actively collect private data.
- Parental Supervision: It is recommended that minors use the App under parental supervision, especially when using the AI conversation feature.
- Educational Nature: The App provides entertainment and reference content related to metaphysics as life philosophy, suitable as a personal thinking and learning aid.
9. Your Rights
You directly control App data stored on your device or in your personal iCloud account. Check-in data and data already sent to third-party providers are handled under the relevant sections of this policy:
- Access, Modify, and Delete Rights: You can view, modify, or delete any case information and conversation records you have saved within the App at any time.
- Data Portability: You can manage your data through in-app features (such as screenshots, exports) or iCloud.
- Control: You can decide at any time whether to use storage features, whether to enable iCloud sync, and whether to use AI conversation features.
- Complete Deletion Rights: You can delete all data within the App at any time, or completely clear data by uninstalling the App.
- Opt-Out Rights: You can choose not to use any features involving data transmission (such as AI conversations) and only use local features.
10. Data Retention
Except for the server data described in Sections 2.3 and 2.4, we do not long-term store your private data on other developer servers. Retention for each category is as follows:
- Local Data: Retained on your device until you actively delete it or uninstall the App.
- iCloud Data: Retained in your personal iCloud account and managed by you.
- Check-in Data: Retained on the developer server only as long as needed to provide check-in and makeup check-in features.
- Sirius/Tongtian Job Data: Request and reply fragments are stored temporarily while a job runs; message bodies and request payloads are cleared after you confirm receipt of the full reply; job metadata is deleted within up to 7 days.
- AI Conversation Data: Full in-app history is stored locally or in your iCloud. Content relayed through Sirius is not long-term stored on developer servers (Section 2.4). Provider-side request logs, retention, and model-training practices are governed by the provider's then-current terms and privacy policy.
- No Automatic Deletion: Except as otherwise stated in this policy, the App does not automatically delete data stored on your device or in your iCloud account.
11. Policy Updates
We may update this Privacy Policy to reflect changes in our services. If any significant changes occur, we will notify you through the following methods:
- Notification in app update notes
- Announcement on the official website
- In-app pop-up reminders (if there are significant changes)
We recommend that you regularly review this policy to stay informed of the latest information. Especially regarding changes to AI features, subscription services, in-app purchases, and data processing methods, we will notify you at least 30 days in advance.
12. Related Agreements
This Privacy Policy, together with our Terms of Use, constitutes the complete legal framework for your use of the App. Please read and comply with the relevant terms of the Terms of Use as well.
13. Contact Us
If you have any questions, suggestions, or need any clarification about this Privacy Policy, please contact us through the following methods. Especially for Apple review team members, if you need further information about privacy implementation details or AI data processing methods, we are very happy to assist.
Thank you for trusting Furud. We will continue to be committed to protecting your privacy.