本政策适用于本应用 iOS 客户端及配套的服务端接口。本政策遵循《中华人民共和国个人信息保护法》《中华人民共和国网络安全法》《中华人民共和国数据安全法》及 Apple App Store 审核指南 5.1 系列条款的要求。
Thank you for using QuietTalkForiphone ("the App"). The App is developed and operated by ThreeFire ("we", "us", "our"), an iOS tool that helps you keep a running diary of everyday life.
We take your privacy seriously. This policy explains what information we collect, how we use it, how we protect it, with whom we share it, and what rights you have over your data. Please read it carefully before using the App. By using the App, you acknowledge and agree to the practices described here.
This policy covers both the iOS client and the backend services. It is written to comply with China's Personal Information Protection Law (PIPL), Cybersecurity Law, Data Security Law, and the relevant Apple App Store Review Guidelines (Section 5.1 series).
二、我们收集的信息
2. Information We Collect
本应用遵循 "最小必要" 原则,只收集为实现产品功能必需的信息。具体范围如下:
We follow the principle of data minimization and only collect what is strictly necessary to operate the App:
2.1 账户信息(用于登录与凭证管理)
2.1 Account Information (for login & credential management)
Apple 账户匿名标识(sub):由 Apple 在您完成"通过 Apple 登录"时下发,用于在我们的服务端唯一识别您的账户。该标识对每个 App 是独立的、不能用于反向追踪您的真实 Apple 账户。
Anonymous Apple Account identifier (sub): issued by Apple when you complete "Sign in with Apple". It uniquely identifies your account on our backend. The identifier is app-specific and cannot be reversed to your real Apple Account.
Device UUID: derived from iOS identifierForVendor and stored in the system Keychain. Used to bind refresh tokens to a specific device.
Login credentials: Access Tokens (1-hour TTL) and Refresh Tokens (30-day TTL) are stored encrypted in the iOS Keychain on the client. On the backend, only the hash of the Refresh Token is persisted. We never store plaintext passwords.
You may choose not to share your name or email with us during Sign in with Apple. The App does not collect your real name, phone number, or email (unless you voluntarily provide them when contacting us per §11).
Text: titles, body text, and notes you enter in jottings and module forms.
Photo attachments: images you select from the system photo library (up to 4 per record in the MVP). Stored only in the iOS app sandbox at Documents/attachments/; not uploaded to the server in the MVP.
Audio attachments: AAC audio recorded via the system microphone. Stored only in the app sandbox; not uploaded to the server in the MVP.
Tags: tag strings you select or create.
Module fields: structured data like mood score, expense amount, exercise duration, book pages, event companions — populated only by what you enter.
Timestamps: occurrence time (occurred_at), creation and update time.
When you are signed in, record content is synced to our servers over an encrypted channel (HTTPS / TLS 1.3) so you can restore data after re-installing the App or switching devices. When signed out, all records remain on the device only.
2.3 订阅信息(用于权益校验)
2.3 Subscription Information (for entitlement)
Apple IAP 交易标识:original_transaction_id、transaction_id、product_id(如 top.threefire.suisuinian.monthly)、购买/到期时间、订阅状态。
App Store Server Notification(由 Apple 主动推送):用于及时同步续订、退款、撤销等状态变化。
Apple IAP transaction identifiers: original_transaction_id, transaction_id, product_id (e.g. top.threefire.suisuinian.monthly), purchase / expiration dates, and subscription status.
App Store Server Notifications: pushed by Apple to keep renewal, refund, and revocation states in sync.
我们不接触您的支付方式、银行卡或 Apple 账户余额,所有支付行为由 Apple 完成。
We never see your payment method, card details, or Apple Account balance — all payments are handled by Apple.
2.4 技术与诊断信息
2.4 Technical & Diagnostic Data
请求标识(X-Request-Id):用于排查接口问题。
IP 地址、User-Agent:仅在服务端审计日志(audit_log)中记录,用于安全审计与异常排查,保留 90 天后自动清理。
Request ID (X-Request-Id): used to trace specific API calls.
IP address & User-Agent: recorded only in the server-side audit log (audit_log) for security review and anomaly investigation. Auto-purged after 90 days.
Crash & exception events: reported via Sentry with a PII scrubber enabled — Authorization headers, cookies and Idempotency-Key are redacted; account identifiers are hashed (sha256: first 16 hex chars) before upload; 4xx business errors are not reported.
Performance metrics: aggregated in Prometheus on the server (request latency, rate-limit hits, idempotency hits, etc.) — no per-user identifiers.
三、信息使用目的
3. How We Use Your Information
我们仅在下述目的范围内使用您的信息,不会用于商业广告、用户画像售卖或与产品无关的二次用途:
We use your information only for the purposes listed below. We never use it for advertising, profile reselling, or any unrelated secondary purpose.
The App relies on the following third-party services for core functionality. Each receives only the minimum data required and is governed by its own privacy policy.
4.1 Apple 服务
4.1 Apple Services
通过 Apple 登录(Sign in with Apple):验证用户身份,仅获得匿名 sub 标识。
Important: we never send your raw record content to Tongyi Qianwen.
When you explicitly trigger the C14 "AI Summary" feature, our backend sends only aggregated metrics for the selected time range (e.g. "23 records this week, mood avg 7.2, spending total ¥412, exercise total 180 min") to Tongyi Qianwen, which returns a summary text.
Tongyi Qianwen cannot access any of your raw text, photos, audio, or tags.
On-device: photos, audio attachments, and the SQLite database live in the iOS app sandbox with file protection set to NSFileProtectionComplete; credentials live in the Keychain.
Server-side: PostgreSQL on Alibaba Cloud (Mainland China). Row-level access is enforced by account_id.
Transport: all client–server traffic is HTTPS (TLS 1.3). Plaintext HTTP is not allowed.
While we follow industry best practices, no system is 100% secure. In the event of a material data breach we will notify you within 72 hours via an in-app notice and an announcement on this page.
Access: view your account info, subscription status, and history in "Profile".
Rectify: edit, restore, or delete any record at any time; update nickname and avatar under "Profile → Settings → Profile".
Export: export all or selected records to a Markdown file via the Export feature, then share or migrate freely.
Erase:
Single record: move to trash; recoverable within 30 days, then hard-deleted.
Account deletion: "Profile → Settings → Delete Account" → cancellable during a 30-day grace period → automatic hard-delete of all associated data (records, subscriptions, tags, audit, quota) by cron.
Withdraw consent: sign out to stop data sync immediately; uninstall the App to stop all collection.
File a complaint: contact us per §11 with any questions. If unsatisfied with our response, you may file a complaint with the Cyberspace Administration of China or your local regulator.
八、对外共享、转让、公开披露
8. External Sharing, Transfer, Public Disclosure
我们不向任何第三方出售您的个人信息。仅在以下情形下可能共享:
We never sell your personal information. We may share information only in the following cases:
The App is intended for users 13 years of age and older. If you are a minor, please read this policy together with your guardian. If we learn that we have collected personal information from a minor without prior guardian consent, we will delete the data as soon as practicable.
This policy may be updated to reflect changes in law, third-party services, or product features. For material changes we will notify you via prominent in-app notice and an announcement on this page. Minor wording changes will simply update the "Last updated" date above. Please revisit this page periodically.
历史版本可在我们的代码仓库的 git log 中追溯。
Historical revisions can be traced in the git log of our repository.
十一、联系我们
11. Contact Us
若您对本政策、本应用的数据处理方式有任何疑问、投诉或权利请求,请通过以下方式联系我们:
If you have any questions, complaints, or requests regarding this policy or our data practices, please contact us: