隐私政策

Privacy Policy

最后更新于:2026年6月 Last updated: June 2026

隐私核心原则

Privacy Principles

心迹(ThoughtEcho)秉承本地优先(Local-first)隐私透明的设计理念。我们的核心目标是为您提供一个纯净、安全的灵感记录空间。

ThoughtEcho adheres to the design philosophy of Local-first and Privacy Transparency. Our core mission is to provide you with a clean and secure space for capturing inspirations.

  • 不主动收集:我们不主动收集您的个人识别信息(PII)。
  • No Proactive Collection: We do not proactively collect your Personally Identifiable Information (PII).
  • 默认不进行遥测:应用默认不启用错误上报;仅在您手动开启后,才会上报崩溃诊断信息。
  • No Telemetry by Default: Crash reporting is disabled by default and only sends diagnostic crash data when you explicitly enable it.
  • 完全本地运行:应用的所有核心功能均可在无网络环境下完全本地运行。
  • Fully Local Operation: All core features of the app can operate entirely locally without an internet connection.

法律角色声明:心迹(ThoughtEcho)是一个纯粹的本地软件工具。开发者不具备访问、审查或控制您数据的技术能力,因此在适用法律下,我们不作为您数据的“数据控制者”或“数据处理者”。您对通过本软件生成、存储和传输的所有数据承担全部责任。

Legal Role Disclaimer: ThoughtEcho is purely a local software tool. The developer has no technical ability to access, review, or control your data. Therefore, under applicable laws, we act neither as a "Data Controller" nor as a "Data Processor" of your data. You assume full responsibility for all data generated, stored, and transmitted through this software.

数据存储说明

Data Storage

您的所有数据资产(笔记、图片、音视频等)默认均加密存储在您的设备本地空间中:

All your data assets (notes, images, audio, etc.) are stored locally on your device by default:

  • 数据库:使用本地 SQLite 数据库保存文本与元数据。
  • Database: Uses a local SQLite database for text and metadata.
  • 密钥安全:第三方 AI 服务的 API 密钥通过系统原生加密(如 Android KeyStore / iOS Keychain)保护。
  • Key Security: API keys for third-party AI services are protected via system-native encryption.
  • 备份控制:备份文件以 ZIP 格式导出,存储位置完全由您控制。
  • Backup Control: Backups are exported as ZIP files, with storage locations fully controlled by you.

设备权限使用说明

Device Permissions Usage

为了提供完整的功能,应用可能会在您的设备上请求以下权限。这些权限获取的数据仅用于本地处理,不会上传至我们的服务器:

To provide full functionality, the app may request the following permissions. Data accessed via these permissions is processed locally and never uploaded to our servers:

  • 相机与相册:仅用于在您的日记中插入图片或视频等多媒体内容。
  • Camera & Photos: Used solely for inserting images or multimedia into your local notes.
  • 麦克风:仅用于录制音频备忘录并本地附加到您的日记中。
  • Microphone: Used solely for recording audio memos to attach to your local notes.
  • 精准位置信息:当您主动触发时,用于获取当前经纬度,并将其仅发送给第三方天气/地理服务(如 Open-Meteo)以获取环境数据。我们不会在后台持续追踪您的位置。
  • Precise Location: When actively triggered by you, used to obtain current coordinates to request environmental data from third-party services (e.g., Open-Meteo). We do not track your location in the background.

第三方服务与数据传输

Third-Party Services & Data Transfer

应用仅在您明确触发特定功能时,才会通过加密连接与以下第三方 API 交互。请注意:当您的设备向第三方发送请求时,由于互联网协议的固有属性,第三方服务将不可避免地接收到您的公共 IP 地址及设备 User-Agent 信息。

The app interacts with the following third-party APIs via encrypted connections only when you explicitly trigger specific features. Please note: Whenever your device makes a request to a third party, inherent to internet protocols, the third-party service will inevitably receive your public IP address and device User-Agent.

1. Thoughter / AI 服务 (由用户自主配置)

1. Thoughter / AI Services (User-Configured)

本应用仅作为客户端工具,当您使用智能问答或内容分析功能时,选定的笔记上下文将直接发送至您个人配置并授权的 AI 服务商或自定义接口(如 OpenAI, DeepSeek 或其他您选择的服务)。由于服务商由您自主选择,我们强烈建议您在使用前查阅您所选服务商的隐私政策。

This app acts solely as a client tool. When using AI features, selected note contexts are sent directly to the AI provider or custom endpoint you have personally configured and authorized (such as OpenAI, DeepSeek, or any other service of your choice). Since the provider is chosen by you, we strongly recommend reviewing the privacy policy of your chosen provider before use.

此外,应用支持接入 Ollama / LMStudio 等本地大模型服务,当您使用此类本地服务时,所有数据处理均在您的设备上完成,绝对不会产生任何外部网络传输。

Additionally, the app supports local LLM services like Ollama / LMStudio. When using these local services, all data processing is done entirely on your device with no external network transmission.

数据使用声明:心迹不对您所选 AI 服务商的数据处理行为负责,也不对 AI 生成内容的准确性、完整性或合法性负责。通常,通过 API 调用的商业服务商(非网页端)不会使用您的 API 数据来训练模型,但具体条款请务必以您所选服务商的最新政策为准。

Data Usage Disclaimer: ThoughtEcho is not responsible for the data processing practices of your chosen AI provider, nor the accuracy, completeness, or legality of AI-generated content. Typically, commercial API providers (unlike web interfaces) do not use your API data for model training, but please ensure you verify this with your chosen provider's latest policy.

2. 地理环境服务

2. Environmental Services

  • Open-Meteo:发送坐标以获取当前气象信息。
  • Open-Meteo: Sends coordinates to fetch weather data.
  • Nominatim:用于地理编码解析,其服务受 OSM 隐私政策 约束。
  • Nominatim: Used for geocoding, subject to OSM Privacy Policy.

3. 每日灵感 (Daily Inspiration) API

3. Daily Inspiration API

应用首页的“每日一言”等功能会从第三方服务(如 Hitokoto 等)获取随机句子。此过程仅涉及公开内容的获取,不发送任何个人数据。

The "Daily Quote" and similar features fetch random sentences from third-party services (such as Hitokoto, etc.). This process only involves fetching public content and does not send any personal data.

内容声明:每日灵感内容由第三方 API 提供,心迹不对其内容的性质、观点或准确性负责。

Content Disclaimer: Daily inspirations are provided by third-party APIs. ThoughtEcho is not responsible for the nature, viewpoints, or accuracy of such content.

4. 内容同步 (LocalSend)

4. Sync via LocalSend

应用支持局域网内的端到端点对点同步。此过程不经过任何外部服务器,数据不会离开您的私有局域网。

The app supports end-to-end peer-to-peer sync within a local network. Data does not leave your private local network.

5. 错误日志上报 (Sentry)

5. Crash Reporting (Sentry)

应用集成了 Sentry SDK 收集崩溃堆栈和诊断信息。为了尊重您的隐私,此功能默认关闭。您可以随时手动开启。开启后上报的信息不包含您的日记内容、出处、作者或任何个人身份数据,仅包含崩溃时的异常堆栈和必要的设备元数据。

The app integrates the Sentry SDK to collect crash stack traces and diagnostic info. Respecting your privacy, this feature is disabled by default. You can enable it manually at any time. When enabled, reported info contains no note contents, authors, sources, or personal identity details, but only crash stack traces and necessary device metadata.

用户权利

User Rights

  • 权限撤回:您可以随时在系统设置中撤回位置、相机、麦克风等授权。
  • Permission Revocation: You can revoke access to location, camera, and microphone at any time.
  • 数据抹除:您可以通过卸载应用来永久删除所有本地存储的数据。
  • Data Eradication: You can permanently delete all locally stored data by uninstalling the app.

未成年人隐私 (Children's Privacy)

Children's Privacy

心迹应用不面向未满 14 周岁的未成年人。我们不会故意收集未成年人的任何个人信息。由于应用完全基于本地运行,我们无法也无意验证用户的年龄。如果您发现有未成年人在未获监护人同意的情况下向应用内输入了敏感信息,监护人可以通过直接卸载应用来彻底清除相关本地数据。

ThoughtEcho is not intended for children under 14 years of age. We do not knowingly collect any personal information from children. Because the app operates entirely locally, we cannot and do not verify user ages. If a child has entered sensitive information into the app without parental consent, parents/guardians can permanently delete all related local data by uninstalling the app.

数据保留与政策变更

Data Retention & Policy Updates

  • 数据保留:由于数据存储在本地,只要您不卸载应用或不主动清除应用数据,您的数据将永久保留在您的设备中。
  • Data Retention: Because data is stored locally, your data is retained indefinitely on your device until you uninstall the app or manually clear the app data.
  • 政策变更:我们可能会不时更新本隐私政策。任何重大更改都将通过更新本页面的“最后更新日期”来体现。对于核心机制的改变(如引入需要联网的服务),我们将会在应用更新日志中明确通知。
  • Policy Updates: We may update this privacy policy from time to time. Any material changes will be reflected by updating the "Last updated" date on this page. Changes to core mechanisms (e.g., introducing network-dependent services) will be explicitly noted in the app's release notes.

联系与反馈

Contact & Feedback

如果您对隐私保护有任何疑问,请通过以下渠道联系:
电子邮箱:shangjinyun@proton.me
开源代码仓库:GitHub Repository

If you have any questions regarding privacy, please contact us via:
Email: shangjinyun@proton.me
Repository: GitHub Repository