关于本政策
「影子人生」(Shadow Lives,以下称「本 App」)由 待补:运营主体全称、注册地与对外通信地址(第 14 节的「运营主体与通信地址」引用此处)(以下称「我们」)开发与运营。本政策说明我们在你使用本 App 时收集哪些信息、为什么收集、交给谁处理、保留多久,以及你能怎么控制它们。
本 App 是一个虚构叙事产品:其中的「居民」全部是 AI 生成的虚构角色。为了让居民记得你、并在你不在线时继续「生活」,本 App 会在服务端保存你与居民的对话,以及由对话派生出的记忆。请在开始使用前读完本节与第 2、8 节。
本政策与 使用条款 一并适用。
About This Policy
Shadow Lives (影子人生, the "App") is developed and operated by TBD: legal entity name, place of registration, and mailing address (Section 14 refers back to this) ("we", "us"). This policy explains what information we collect, why, who processes it, how long we keep it, and what control you have over it.
The App is a work of interactive fiction: every "resident" in it is an AI-generated fictional character. So that residents can remember you and keep "living" while you are away, the App stores your conversations with residents, and the memories derived from them, on our servers. Please read this section and Sections 2 and 8 before you start.
This policy applies together with our Terms of Use.
我们收集哪些信息
A. 账号信息
- 本 App 仅支持 Google 账号登录。登录时我们向 Google 验证你的身份令牌,并保存其中的已验证邮箱地址——这是我们用来标识你账号的唯一身份信息。
- 我们不保存你的 Google 密码;也不保存你的 Google 姓名、头像或个人资料。
- 我们会保存登录会话记录,用于保持登录状态。
B. 你在 App 内主动提供的内容
- 与居民的对话:你发送的每条消息(文字、图片引用、时间戳)。
- 开场 / 初识流程中的回答:你在建立第一段关系时给出的选择与对话内容。
- 「别样人生路」入口填写的出生资料——只有当你选择这个入口时才会收集:
- 收集什么:出生年月日(必填)、出生地与成长城市(必填,城市级别的自由文本,不采集国家 / 省 / 区县,也不采集经纬度)、性别(可选)、出生时辰(可选)。同一张表单还会收集你填写的学历 / 职业 / 家庭状况、你选择的人生「分岔点」、一组情境选择题的答案,以及你可以选择粘贴的一段自述文本。
- 用来做什么:生成一段虚构的「平行人生」——如果当年做了另一个选择,另一个「你」会走出怎样的人生。出生年份用于确定故事的年代背景与那个年代真实存在的历史机会;成长城市用于确定地域背景;出生日期仅用于推算年龄;出生月份仅被转换成一句季节性的叙事措辞;性别仅用于决定角色的人称代词。出生时辰目前不参与任何计算。
- 不做现实预测:这不是算命,也不提供任何面向现实的预测或建议。生成规则明确禁止「注定 / 命里 / 一定会」这类措辞,禁止涉及灾祸、寿命与疾病,也不给出投资、置业或职业建议。
- 原始出生资料不入库:我们不保存你填写的出生年月日、出生时辰与出生地原文——它们只在处理这次请求的过程中存在于内存里,随请求结束而消失。被保存下来的只有派生结果:由出生日期推算出的年龄、由性别映射出的人称代词,以及生成出的虚构角色设定与故事线。这些派生数据会随账号删除一并删除(见第 8 节)。
- 会离开我们的服务器:为了生成故事,出生年份、出生地与成长城市、以及你粘贴的自述文本会作为提示词的一部分发送给模型供应商(默认 DeepSeek,见第 4 节)。
- 你填写的成长城市会出现在我们的服务端运行日志中。
- 加州居民请注意:出生日期与性别在 CPRA 下可能被视为敏感个人信息。我们只将它们用于上述生成用途,不出售、不共享,也不用于广告或用户画像。见第 9 节。
- 动态互动:你对居民动态的点赞与评论。
- 你写给世界的内容:你主动投入世界的自由文本(如事件线索)。
- 你讲述的「熟面孔」:你描述现实中记得的人时写下的文字、你标注的熟悉度、以及你锚定的真实地点。这些内容可能包含关于第三方的信息,请按 使用条款 第 7 条避免填写可识别真实身份的细节。此类内容默认仅你可见,跨用户可见功能当前未开启。
- 你上传的照片:仅用于把旧照片转成像素风头像。App 通过系统相册选择器读取你选中的单张图片,不获取你的相册访问权限。原图不会被保存到我们的服务器——它在内存中缩放后送交图像模型处理,我们只保留生成出的像素风成品。
C. 由你的内容派生的数据
为了实现「ta 记得你」,我们会由对话自动生成并保存:
- 记忆:从对话中提取的客观事实,以及居民视角下的主观解读;
- 记忆目录:关于你的事实、关系里程碑、你与居民之间的约定;
- 关系状态:熟悉度、关系阶段与里程碑事件;
- 向量索引:记忆文本的向量表示,用于让居民在合适的时候想起相关的事;
- 居民侧状态:居民的情绪、需求与生活事件(这部分是虚构角色的状态,但由与你的互动驱动)。
D. 设置与偏好
体验语言、通知开关、推送时段与时区、「现实交叠」开关、视觉风格与图像质量档位。
E. 位置信息
仅在你主动开启「现实交叠」后收集。详见第 5 节——这一节很重要,请读。
F. 设备与技术信息
- 推送令牌:若你允许通知,我们保存 Apple 推送服务(APNs)的设备令牌用于投递通知。
- 服务端日志:为了排障与安全,我们的服务器会记录请求元数据(时间、端点、错误信息等)。我们的应用代码不记录你的 IP 地址,也不记录经纬度,反向代理层未开启访问日志。日志以标准输出的形式由运行平台收集;我们目前没有为这些日志设定固定的保留期限。
- 生成调试快照:为排查生成质量问题,系统会临时保存单次生成的完整提示词与模型原始输出,其中可能包含你的消息内容。该快照在 14 天后自动清除(保留期不含消息内容的基础记录)。
G. 我们不收集的东西
- ❌ 没有接入任何第三方分析、广告或崩溃采集 SDK(无 Firebase / Crashlytics / Sentry / Amplitude / Mixpanel 等)。
- ❌ 不收集广告标识符(IDFA),不做广告追踪,不参与跨 App 追踪。
- ❌ 不访问你的通讯录、相机、麦克风或健康数据。
- ❌ 不收集支付信息(本 App 当前无任何付费内容)。
What We Collect
A. Account information
- The App supports Google Sign-In only. At sign-in we verify your identity token with Google and store the verified email address it contains — this is the only identity attribute we use for your account.
- We do not store your Google password, and we do not store your Google name, profile picture, or profile details.
- We store session records to keep you signed in.
B. Content you provide in the App
- Conversations with residents: every message you send (text, image references, timestamps).
- Answers during onboarding: the choices and conversation you give when forming a first relationship.
- Birth details entered in the "parallel life" entry point — collected only if you choose that entry point:
- What is collected: date of birth (required); place of birth and the city you grew up in (required, free text at city level — no country / province / district field and no coordinates); gender (optional); time of birth (optional). The same form also collects the education, occupation, and family circumstances you enter, the life "branch point" you pick, your answers to a set of situational questions, and an optional free-text passage you may paste in about yourself.
- What it is used for: to generate a fictional "parallel life" — who another version of you might have become had you chosen differently. The year of birth sets the story's era and the historical openings that genuinely existed then; the city you grew up in sets its regional backdrop; the day of birth is used only to compute an age; the month of birth is turned only into a seasonal turn of phrase; gender is used only to pick the character's pronoun. The time of birth is not used in any computation today.
- No real-world prediction: this is not fortune telling, and it offers no prediction of or advice about your actual life. The generation rules explicitly forbid wording like "destined" or "bound to happen", forbid any mention of disaster, lifespan, or illness, and give no investment, property, or career advice.
- Raw birth details are not stored: we do not keep the date of birth, time of birth, or place of birth you enter. They exist only in memory while your request is being processed and are gone when it ends. What we do keep are the derived results: the age computed from your date of birth, the pronoun mapped from gender, and the fictional character and storyline that come out of it. That derived data is deleted along with your account (see Section 8).
- What leaves our servers: to generate the story, your year of birth, place of birth, city of upbringing, and any text you paste in are sent as part of the prompt to a model provider (DeepSeek by default — see Section 4).
- The city of upbringing you enter appears in our server-side operational logs.
- For California residents: date of birth and gender may qualify as sensitive personal information under the CPRA. We use them only for the generation purposes above. We do not sell or share them, and we do not use them for advertising or profiling. See Section 9.
- Feed interactions: your likes and comments on residents' posts.
- What you write into the world: free-text you contribute to the world (such as event prompts).
- "Familiar faces" you describe: the text you write about people you remember from real life, the familiarity you assign, and the real-world place you anchor them to. This may contain information about third parties — please avoid identifying details, as required by Section 7 of the Terms of Use. This content is visible only to you by default; cross-user visibility is currently switched off.
- Photos you upload: used only to turn an old photo into a pixel-art avatar. The App reads the single image you pick through the system photo picker and does not obtain access to your photo library. The original photo is never stored on our servers — it is downscaled in memory, sent to the image model, and only the resulting pixel-art image is kept.
C. Data derived from your content
So that a resident can remember you, we automatically generate and store:
- Memories: objective facts extracted from conversation, plus the resident's subjective reading of them;
- A memory index: facts about you, relationship milestones, and commitments made between you and a resident;
- Relationship state: familiarity, relationship stage, and milestone events;
- Vector embeddings of memory text, so a resident can recall relevant things at the right moment;
- Resident-side state: a resident's mood, needs, and life events — the state of a fictional character, but driven by interaction with you.
D. Settings and preferences
Experience language, notification toggle, push hour and timezone, the "reality overlap" toggle, visual style, and image quality tier.
E. Location
Collected only if you actively enable "reality overlap". See Section 5 — it matters, please read it.
F. Device and technical information
- Push token: if you allow notifications, we store your Apple Push Notification service (APNs) device token in order to deliver them.
- Server logs: for troubleshooting and security our servers record request metadata (time, endpoint, errors, and similar). Our application code does not record your IP address and does not record coordinates, and access logging is not enabled at the reverse-proxy layer. Logs are emitted to standard output and collected by the hosting platform; we do not currently set a fixed retention period for them.
- Generation debug snapshots: to diagnose generation quality, the system temporarily stores the full prompt and raw model output for a generation, which may include your message content. These snapshots are automatically cleared after 14 days (the base record kept afterwards contains no message content).
G. What we do not collect
- ❌ No third-party analytics, advertising, or crash-reporting SDKs (no Firebase / Crashlytics / Sentry / Amplitude / Mixpanel, and so on).
- ❌ No advertising identifier (IDFA), no ad tracking, no cross-app tracking.
- ❌ No access to your contacts, camera, microphone, or health data.
- ❌ No payment information (the App currently has no paid content).
我们如何使用这些信息
- 提供核心体验:生成居民的回复、主动消息、动态与图片;让居民记得你、并延续与你的关系。
- 维持世界的连续性:即使你不在线,居民也会依据自身设定与既有记忆继续生活。
- 投递通知:把居民的主动消息推送给你(见第 6 节)。
- 安全与内容审核:自动检测并拦截违规内容;对可能与自伤 / 危机有关的表述触发安全回复(见 使用条款 第 6 节);处理举报与滥用。
- 排障与改进质量:定位生成失败、评估生成内容质量、调优提示词与参数。我们不做日常的人工内容审核——没有人会例行阅读你与居民的对话。内部的质量调优基于聚合信号与自动化评测(程序统计 + 由模型评分),而不是逐条人工阅读。App 内确实提供一个调试导出工具,但它只能导出你自己这段关系的对话上下文,无法用来读到别人的对话;管理后台没有任何读取用户对话的入口。唯一的人工复核队列是「熟面孔」角色卡片被举报后的处理,其中不含举报人身份,也不含聊天内容。保留项:若将来引入任何形式的人工抽查(哪怕只是小样本、去标识的),必须先更新本节,写明范围、是否去标识、以及用户能否拒绝。
- 履行法律义务:在法律要求时保留或披露必要信息。
如适用 GDPR,我们就上述目的所依据的法律基础为:提供核心体验与维持世界的连续性——履行合同;投递通知与「现实交叠」等位置相关功能——你的同意(可随时撤回);安全与内容审核、排障与质量改进——合法利益(维持服务的安全与可用);保留或披露必要信息——法律义务。本 App 是否面向欧盟 / 英国用户提供服务,见第 9 节。
How We Use This Information
- To provide the core experience: generate residents' replies, proactive messages, posts, and images; let a resident remember you and continue a relationship with you.
- To keep the world continuous: residents go on living according to their own persona and existing memories even while you are away.
- To deliver notifications: push a resident's proactive messages to you (see Section 6).
- For safety and moderation: automatically detect and block violating content; trigger a safety response on wording associated with self-harm or crisis (see Section 6 of the Terms of Use); handle reports and abuse.
- For troubleshooting and quality: diagnose generation failures, evaluate output quality, and tune prompts and parameters. We do not carry out routine human content review — nobody reads your conversations with residents as a matter of course. Internal quality tuning is based on aggregate signals and automated evaluation (programmatic metrics plus model-scored assessments), not on reading messages one by one. The App does include a debug export tool, but it only exports the conversation context of your own relationship and cannot be used to read anyone else's conversations; the admin backend has no endpoint that reads user conversations at all. The only human review queue is for reported "familiar face" character cards, and it contains neither the reporter's identity nor any chat content. Retained item: if we ever introduce human spot-checking in any form — even small-sample or de-identified — this section must be updated first to state the scope, whether the data is de-identified, and whether users can opt out.
- To meet legal obligations: retain or disclose information where the law requires it.
Where the GDPR applies, our legal bases for the purposes above are: providing the core experience and keeping the world continuous — performance of a contract; delivering notifications and location features such as "reality overlap" — your consent, which you may withdraw at any time; safety and moderation, troubleshooting, and quality improvement — legitimate interests in keeping the service safe and available; retaining or disclosing information where required — legal obligation. Whether the App is offered to EU / UK users is addressed in Section 9.
谁会处理你的数据
我们不出售你的个人信息,也不为了广告投放而共享它。我们只在为你提供本 App 所必需的范围内,把数据交给下列服务商处理。
| 服务商 | 用途 | 会接触到的数据 |
|---|---|---|
| Google(Sign-In) | 登录验证 | 你的 Google 身份令牌与已验证邮箱 |
| DeepSeek | 对话与内容生成(默认供应商) | 你发送的消息内容、相关记忆片段与居民人设上下文 |
| Google(AI Studio / Gemini) | 备选内容生成;记忆向量化;把你上传的照片转成像素风 | 你发送的消息内容、记忆文本、你上传的照片 |
| fal.ai | 生成图片 | 由内容派生的图像提示词(场景描述) |
| Google Maps Places | 城市地点与地点照片 | 地点查询,不含你的个人信息 |
| Open-Meteo | 天气 | 城市坐标,不含你的个人信息 |
| Apple(APNs) | 投递推送通知 | 设备令牌与通知正文(见第 6 节) |
| 我们自有服务器 | 数据库与生成图片存储 | 本政策第 2 节所列全部数据 |
- 模型供应商的数据处理条款。以下为我们在 2026-08-02 查阅各供应商公开条款所得。条款可能随时变更,最终以供应商当前条款为准。
- DeepSeek(对话生成的默认供应商):其《隐私政策》(最后更新 2026-02-10)载明,DeepSeek「直接在中华人民共和国境内收集、处理并存储」个人数据,并将「训练并改进我们的技术,例如机器学习模型与算法」列为处理目的之一;同一政策也载明用户有权拒绝将个人数据用于训练模型或优化技术。其《开放平台服务条款》(2026-04-22 发布,2026-04-29 生效)把输出内容的权利归于调用方,但没有为 API 输入另行排除训练用途,也没有公布具体的输入保留期限。所以请知悉:你与居民的对话内容会被发送到 DeepSeek;按其当前公开条款,这些内容可能被用于改进其模型,并在中国大陆境内被处理和存储。
- Google(AI Studio / Gemini API):其《Gemini API 附加服务条款》(2026-03-23 生效)对免费层与付费层规定不同。本 App 使用付费层:付费层条款载明「Google 不会使用你的提示词(包括相关的系统指令、缓存内容,以及图片、视频、文档等文件)或响应来改进我们的产品」,并且「Google 会在有限的时间内记录提示词与响应,仅用于检测和防止违反《禁止使用政策》的行为」。免费层条款则允许 Google 使用提交的内容改进其产品,且「人工审阅者可能阅读、标注并处理你的 API 输入与输出」。上述付费层的保护,以我们持续为该 API 启用计费为前提。
- fal.ai(文生图):按其官方文档《Data Retention & Storage》,请求的输入与输出(JSON 数据)默认在其平台保留 30 天,用于控制台里的请求历史;可通过请求头「X-Fal-Store-IO: 0」关闭该存储。我们目前没有设置这个请求头,因此我们发给 fal 的图像提示词(场景描述文本)适用 30 天的默认保留。我们不向 fal 发送你上传的照片,也不发送你的消息原文。待精确化:fal 的服务条款含一条范围较宽的「Usage Data」条款,其公开条款并未明确排除将标准层的输入 / 输出用于其 AI 模型的开发("never trains on your data" 的承诺见于其面向企业客户的说明)。上线前需向 fal 书面确认标准层的训练用途,并评估是否默认加上「X-Fal-Store-IO: 0」。
- 生成图片的可访问性:生成的图片存放在我们自己的服务器上,以内容哈希作为地址,通过不可枚举但无需登录的链接提供。知道确切链接的人可以打开该图片,链接本身没有有效期。
- 高德(Amap):代码中保留了面向中国大陆城市(北京 / 上海 / 广州 / 深圳)的高德地点服务。生产环境未配置高德 API key,因此当前不会调用该服务;若将来启用,这些城市的地点查询会改由高德处理,内容为地点名称与坐标,不含你的个人信息。
- 除上述服务商外,我们仅在下列情形披露信息:法律法规或主管机关要求;为保护用户或公众的人身安全;调查违规与滥用;以及在业务合并或资产转让时(届时会另行告知)。
Who Processes Your Data
We do not sell your personal information, and we do not share it for advertising. We pass data to the providers below only as needed to operate the App for you.
| Provider | Purpose | Data it can access |
|---|---|---|
| Google (Sign-In) | Authentication | Your Google identity token and verified email |
| DeepSeek | Conversation and content generation (default provider) | The messages you send, relevant memory excerpts, and resident persona context |
| Google (AI Studio / Gemini) | Alternate generation; memory embeddings; converting your uploaded photo to pixel art | The messages you send, memory text, the photo you upload |
| fal.ai | Image generation | Image prompts derived from content (scene descriptions) |
| Google Maps Places | City places and place photos | Place lookups; no personal information |
| Open-Meteo | Weather | City coordinates; no personal information |
| Apple (APNs) | Push notification delivery | Device token and notification body (see Section 6) |
| Our own servers | Database and generated-image storage | Everything listed in Section 2 |
- Model providers' data terms. The following reflects each provider's public terms as we read them on 2026-08-02. Those terms can change, and the provider's current terms govern.
- DeepSeek (default provider for conversation generation): its Privacy Policy (last updated 2026-02-10) states that DeepSeek "directly collect[s], process[es] and store[s] your Personal Data in People's Republic of China", and lists "to improve and develop the Services and to train and improve our technology, such as our machine learning models and algorithms" among its purposes; the same policy states that users have the right to opt out of the use of their personal data for training models or optimizing technologies. Its Open Platform Terms of Service (released 2026-04-22, effective 2026-04-29) assign rights in Outputs to the caller, but do not separately carve API input out of training use and do not publish a retention period for input. So please understand: your conversations with residents are sent to DeepSeek, and under its current public terms that content may be used to improve its models and is processed and stored in mainland China.
- Google (AI Studio / Gemini API): its Gemini API Additional Terms of Service (effective 2026-03-23) treat the free and paid tiers differently. This App uses the paid tier, for which the terms state that "Google doesn't use your prompts (including associated system instructions, cached content, and files such as images, videos, or documents) or responses to improve our products", and that "Google logs prompts and responses for a limited period of time, solely for detecting and preventing violations of the Prohibited Use Policy". The free-tier terms, by contrast, allow Google to use submitted content to improve its products, and state that "human reviewers may read, annotate, and process your API input and output". The paid-tier protections above hold only for as long as we keep billing enabled on that API.
- fal.ai (text-to-image): per its official documentation "Data Retention & Storage", request inputs and outputs (the JSON data) are stored on their platform for 30 days by default to power the request history in their dashboard, and that storage can be switched off with the request header "X-Fal-Store-IO: 0". We do not currently set that header, so the image prompts (scene description text) we send to fal are subject to the 30-day default. We do not send fal the photos you upload, and we do not send it your message text. TBD — needs pinning down: fal's Terms of Service contain a broadly drafted "Usage Data" clause, and their public terms do not clearly exclude standard-tier inputs and outputs from the development of their AI models (the "never trains on your data" commitment appears in their enterprise-facing material). Before launch, get written confirmation from fal about training use on the standard tier, and consider setting "X-Fal-Store-IO: 0" by default.
- Accessibility of generated images: generated images live on our own servers, addressed by content hash, served over links that are unguessable but require no sign-in. Anyone who knows the exact link can open the image, and the links do not expire.
- Amap: the codebase retains the Amap place service for mainland-China cities (Beijing, Shanghai, Guangzhou, Shenzhen). No Amap API key is configured in production, so the service is not called today. If it is enabled later, place lookups for those cities would be handled by Amap; those lookups contain place names and coordinates, not your personal information.
- Apart from these providers, we disclose information only: where required by law or a competent authority; to protect someone's physical safety; to investigate violations and abuse; and in connection with a merger or transfer of assets (we will give notice if that happens).
位置信息(「现实交叠」)
「现实交叠」默认关闭。只有你在设置中主动打开它之后,App 才会请求并使用你的位置;关闭后立即停止。
- 权限范围:仅请求「使用 App 期间」的定位权限。我们从不请求「始终允许」,App 在后台不获取你的位置。
- 精度:客户端以约 100 米级精度请求位置,并设置最小移动距离阈值,不做精细追踪。
- 手机上不留存:App 只在内存中保留最新一次坐标,不写入本地存储、不写入文件、日志中也不记录经纬度。App 关闭即消失。
- 服务器上不保存坐标:坐标发送到我们的服务器后,仅用于两项即时判断——你是否在某位居民所在的城市范围内,以及你是否走到了某个「重要地点」附近(约 100 米内)。判断完成后坐标即被丢弃,我们的数据库不存储任何经纬度。
- 会被保存下来的只有:一次交叠会话的开始 / 最后活跃 / 结束时间戳与状态;解锁事件对应的城市地点(POI)与解锁到的内容;以及「你与 ta 在同一座城市共处过」这一城市级事实。
- 撤回:随时在设置中关闭「现实交叠」,或在 iOS 系统设置中撤销定位权限。
Location ("Reality Overlap")
"Reality overlap" is off by default. The App requests and uses your location only after you switch it on in settings, and stops as soon as you switch it off.
- Permission scope: we request "while using the app" location only. We never request "always", and the App does not obtain your location in the background.
- Accuracy: the client requests roughly 100-metre accuracy with a minimum-distance threshold. There is no fine-grained tracking.
- Nothing is kept on your phone: the App holds only the latest coordinate in memory. It is never written to local storage or files, and latitude/longitude never appears in logs. It disappears when the App closes.
- No coordinates are stored on our servers: coordinates sent to us are used for two immediate checks — whether you are within the bounds of a resident's city, and whether you are near one of their meaningful places (within about 100 metres). The coordinates are discarded right after that check; our database stores no latitude or longitude.
- What is retained: the start / last-active / end timestamps and status of an overlap session; the city place (POI) an unlock is tied to and the content unlocked; and the city-level fact that you and a resident were in the same city.
- Withdrawing: switch "reality overlap" off in settings at any time, or revoke the location permission in iOS Settings.
推送通知
请注意:推送通知的正文就是居民要对你说的那句话本身,而不是「你有 1 条新消息」。这意味着对话内容会显示在你的锁屏和通知中心,旁人可能看到。
- 这是刻意的产品设计:推送就是 ta 说的那句话。如果你不希望内容出现在锁屏上,可以在 iOS 系统设置中把本 App 的通知预览改为「解锁时」或「永不」,或直接在 App 内关闭「主动消息」。
- 我们在你建立第一段关系之后才请求通知权限;你可以随时在 App 内或系统设置中关闭。
- 推送经由 Apple 的推送服务(APNs)投递,通知正文因此会经过 Apple 的服务器。
- 你可以设置希望收到主动消息的时段与时区;主动消息有频率上限。
Push Notifications
Please note: the body of a push notification is the actual thing a resident is saying to you — not "you have 1 new message". That means conversation content appears on your lock screen and in Notification Center, where others may see it.
- This is a deliberate design choice: the notification is the line they said. If you would rather that content not appear on your lock screen, set this App's notification previews to "When Unlocked" or "Never" in iOS Settings, or turn off proactive messages in the App.
- We request notification permission only after you have formed a first relationship. You can turn notifications off in the App or in system settings at any time.
- Notifications are delivered through Apple's Push Notification service, so the notification body passes through Apple's servers.
- You can choose the hours and timezone in which you would like to receive proactive messages, and proactive messages are subject to frequency caps.
我们不会做的事
- 不出售你的个人信息(包括加州法律定义下的「出售」与「共享」)。
- 不用于广告:不投放广告,不做用户画像定向,不做跨 App 跟踪,不接广告 SDK。
- 不把你的对话内容公开,不在用户之间共享你的对话或记忆。
- 不把你的数据交给数据经纪商。
What We Will Not Do
- We do not sell your personal information (including "sale" and "sharing" as defined under California law).
- No advertising: we run no ads, do no profiling for ad targeting, do no cross-app tracking, and integrate no ad SDKs.
- We do not make your conversations public, and we do not share your conversations or memories between users.
- We do not give your data to data brokers.
保留期与删除
保留多久
- 账号与对话:保留到你删除它们为止。记忆没有自动过期机制——随着时间推移它们在居民的回忆中会变得不容易被想起,但不会被自动删除。
- 生成调试快照(可能含消息内容):14 天后由每日任务自动清除(清除的是快照本身,不含消息内容的基础记录会继续保留)。
- 每日状态快照:设定的保留期为 90 天,但该定期清理目前尚未自动执行,因此实际保留时间可能更长;它们会随账号或相关关系数据的删除而删除。里程碑快照长期保留。
- 登录会话:签发后 90 天过期,过期即无法再用于访问;退出登录会立即删除该会话记录。已过期的会话行目前不会被自动物理清除,但会随账号删除一并删除。
- 位置坐标:不保留(见第 5 节)。
- 数据库备份:最多保留最近 14 份数据库转储,已删除的数据会随备份轮转而失效。
你可以删除什么
在 App 内「设置 · 隐私」中:
- 删除对话记录 —— 真实删除,不可恢复。
- 删除回忆 —— 真实删除,不可恢复。
- 结束这段关系 —— 进入告别期(期间可取消);结束后该居民不再出现,但相关故事与记忆数据仍保留在你的账号内,并有冷却期。
- 退出登录 —— 立即删除该登录会话。
删除账号
入口在 App 内:「我们」标签页 → 右上角齿轮 → 设置 → 删除账号,需要长按 3 秒确认,中途松手即取消。
删除账号是立即执行、彻底且不可撤销的。没有宽限期,也没有恢复途径。你确认之后,相关记录会立刻从数据库中被真实删除,你当前的登录令牌当场失效。
会被删除的:你的账号与已验证邮箱;全部登录会话与推送设备令牌;你的全部居民及其人设设定;你与他们的全部消息(含主动消息);全部记忆、记忆目录、向量索引与关系状态;居民侧的情绪、需求、日程与生活事件;居民的动态、足迹图文与生成图片记录;你的点赞与评论;你讲述的「熟面孔」记录;「现实交叠」的会话与解锁记录;开场 / 创建流程的会话记录(包括「别样人生路」产生的全部派生数据);以及你的后台任务记录。
关于「熟面孔」居民:只被你一个人讲述过的熟面孔居民会一并删除;如果同一位居民也被其他用户讲述过,ta 会继续留在世界里,但属于你的那份记录会被删除。
删除后仍可能残留的——我们如实告知:
- 已生成图片的文件本体:数据库中的引用会被删除,但存储中的图片文件目前不会被一并移除。这些文件以内容哈希寻址、无需登录即可访问(见第 4 节)。
- 数据库备份中的副本:最多随最近 14 份转储保留,并随备份轮转而失效。
- 一条运行日志:记录这次删除发生过,其中包含账号的内部标识符,不包含你的邮箱。
- 已经发送给模型供应商的内容:受各供应商自己的保留条款约束(见第 4 节)。删除账号不会触发供应商侧的删除。
数据导出:目前没有自助的一键导出功能。你可以通过第 14 节的邮箱向我们提出获取副本的请求,我们会以人工方式处理,并在第 9 节所述时限内回复。
此外,我们可能在法律要求的范围内、或为处理争议与滥用,在有限时间内保留必要记录。
Retention and Deletion
How long we keep things
- Account and conversations: kept until you delete them. Memories have no automatic expiry — over time they become harder for a resident to recall, but they are not deleted automatically.
- Generation debug snapshots (which may contain message content): cleared automatically after 14 days by a daily job (what is cleared is the snapshot itself; the base record, which holds no message content, remains).
- Daily state snapshots: the configured retention is 90 days, but that cleanup job is not yet running automatically, so they may in practice be kept longer; they are deleted along with your account or the related relationship data. Milestone snapshots are kept long-term.
- Sign-in sessions: expire 90 days after issue and can no longer be used once expired; signing out deletes that session record immediately. Expired session rows are not yet physically purged on a schedule, but they are deleted along with your account.
- Location coordinates: not retained (see Section 5).
- Database backups: at most the 14 most recent database dumps are kept, and deleted data ages out with that rotation.
What you can delete
Under Settings › Privacy in the App:
- Delete conversation history — a real, irreversible deletion.
- Delete memories — a real, irreversible deletion.
- End this relationship — opens a farewell period (cancellable); afterwards that resident no longer appears, but the associated story and memory data remains in your account, and a cooldown applies.
- Sign out — deletes that sign-in session immediately.
Deleting your account
In the App: the "us" tab → the gear icon in the top right → Settings → Delete account, confirmed with a three-second press and hold. Letting go before it completes cancels.
Account deletion is immediate, complete, and irreversible. There is no grace period and no way to restore it. Once you confirm, the records are genuinely deleted from the database straight away, and the sign-in token you are holding stops working on the spot.
What is deleted: your account and verified email; every sign-in session and your push device token; all of your residents and their personas; every message between you and them, proactive messages included; all memories, the memory index, vector embeddings, and relationship state; residents' moods, needs, schedules, and life events; residents' posts, footprint pieces, and generated-image records; your likes and comments; the "familiar faces" you described; your reality-overlap sessions and unlocks; your onboarding and creation conversation records, including everything derived from the "parallel life" flow; and your background job records.
About "familiar face" residents: a familiar-face resident witnessed only by you is deleted along with your account. If the same resident was also described by another user, they remain in the world, but your own record of them is deleted.
What may still remain afterwards — stated plainly:
- The image files themselves: the database references are deleted, but the generated image files in storage are not removed at the same time. Those files are addressed by content hash and readable without signing in (see Section 4).
- Copies in database backups: kept in at most the 14 most recent dumps, ageing out with the backup rotation.
- One operational log line recording that the deletion happened. It contains the account's internal identifier, not your email address.
- Content already sent to model providers: governed by each provider's own retention terms (see Section 4). Deleting your account does not trigger deletion on their side.
Data export: there is no one-tap self-service export today. You can request a copy by writing to the address in Section 14; we handle these manually and will reply within the window stated in Section 9.
Beyond that, we may retain limited records for a limited time where the law requires it, or to handle disputes and abuse.
你的权利
根据你所在地区的法律,你可能享有以下权利:访问我们持有的关于你的个人信息、更正不准确的信息、删除你的信息、获取副本 / 数据可携带、反对或限制某些处理、以及撤回同意(例如关闭「现实交叠」或通知)。
行使这些权利:请通过 teveillan@gmail.com 联系我们。我们会在 30 天内回复,并可能需要验证你的身份(通常通过你账号绑定的邮箱)。我们不会因为你行使权利而歧视性地对待你。
加州居民(CCPA / CPRA)
- 我们收集的个人信息类别见第 2 节;收集目的见第 3 节;共享给服务商的情况见第 4 节。
- 我们不出售、也不为跨情境行为广告而共享你的个人信息,过去 12 个月内亦未如此。
- 你有权知悉、访问、更正、删除,以及限制敏感个人信息的使用。我们可能收集的敏感个人信息只有一处:如果你选择「别样人生路」入口,该表单会收集你的出生日期与性别(性别为可选项)。它们只用于生成虚构的平行人生叙事(详见第 2 节 B),原始值不入库;我们不出售、不共享,也不将其用于广告或用户画像,不存在需要你另行限制的二次使用。删除账号会清除由它们派生的全部数据。
- 你可以授权代理人代为提出请求。
欧盟 / 英国用户
待确认:本 App 是否面向欧盟 / 英国用户提供服务。若是,需补齐数据控制者的身份与地址、(如适用)欧盟代表与 DPO、向监管机构投诉的途径,以及跨境传输机制(SCC 等);各处理目的对应的法律依据已写在第 3 节末尾。若不面向欧盟 / 英国,应在此写明服务的地域范围。
Your Rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct inaccurate information, delete your information, obtain a copy / port your data, object to or restrict certain processing, and withdraw consent (for example by turning off reality overlap or notifications).
To exercise these rights, contact us at teveillan@gmail.com. We will respond within 30 days and may need to verify your identity (usually via the email address on your account). We will not discriminate against you for exercising your rights.
California residents (CCPA / CPRA)
- The categories of personal information we collect are in Section 2; our purposes are in Section 3; disclosures to service providers are in Section 4.
- We do not sell your personal information and do not share it for cross-context behavioural advertising, and have not done so in the preceding 12 months.
- You have the right to know, access, correct, and delete, and to limit the use of sensitive personal information. There is only one place we may collect sensitive personal information: if you choose the "parallel life" entry point, that form collects your date of birth and gender (gender being optional). They are used solely to generate the fictional parallel-life narrative described in Section 2B, the raw values are not stored, and we neither sell nor share them nor use them for advertising or profiling — so there is no secondary use for you to limit. Deleting your account erases everything derived from them.
- You may use an authorized agent to submit a request.
EU / UK users
TBD — confirm whether the App is offered to EU / UK users. If so, add the controller's identity and address, an EU representative and DPO where applicable, the route to complain to a supervisory authority, and the transfer mechanism (SCCs, etc.); the legal bases per purpose are already stated at the end of Section 3. If the EU / UK are out of scope, state the service's geographic scope here.
数据安全
- 与我们服务器之间的全部通信经 HTTPS/TLS 加密。
- 访问 API 需要有效的登录会话;会话可随时撤销(退出登录)。
- 我们限制内部对生产数据的访问范围。
- 我们不在服务器上保存你的位置坐标,也不保存你上传的原始照片(见第 2、5 节)。
本页不就静态加密、备份的加密与存放地点、内部访问审计,以及数据泄露通知的流程与时限作出具体承诺——这些是尚待确定的运维事项,列在剩余待定条目中。
没有任何系统能保证绝对安全。请妥善保护你的 Google 账号——它是进入你账号的唯一钥匙。
Security
- All traffic to and from our servers is encrypted with HTTPS/TLS.
- API access requires a valid session, and sessions can be revoked at any time by signing out.
- We limit internal access to production data.
- We do not store your location coordinates on our servers, and we do not store the original photos you upload (see Sections 2 and 5).
This page makes no specific commitment about encryption at rest, backup encryption and location, internal access auditing, or the breach-notification process and deadline. Those are operational matters still to be settled, and they are listed under open items.
No system can be perfectly secure. Please protect your Google account — it is the only key to yours.
跨境传输
我们的服务商分布在不同国家 / 地区,因此你的信息(包括你的消息内容)可能被传输到你所在地以外的地方处理,这些地方的数据保护法律可能与你所在地不同。
按各供应商在 2026-08-02 的公开条款:DeepSeek 在中华人民共和国境内收集、处理并存储数据;Google 与 fal.ai 在美国及其全球基础设施上处理数据;推送经由 Apple 的全球基础设施投递。这意味着:如果你不在中国大陆,你与居民的对话内容仍会被传输到中国大陆处理。
待补:我们自有服务器的托管地区;以及(如面向欧盟 / 英国用户)所依赖的跨境传输机制(SCC 等)。
International Transfers
Our providers operate in different countries, so your information — including your message content — may be transferred and processed outside where you live, in places whose data protection laws differ from your own.
Per each provider's public terms as of 2026-08-02: DeepSeek collects, processes, and stores data in the People's Republic of China; Google and fal.ai process data in the United States and on their global infrastructure; notifications are delivered over Apple's global infrastructure. In practical terms: if you are outside mainland China, your conversations with residents are still transferred there for processing.
TBD: the region our own servers are hosted in, and (if EU / UK users are in scope) the cross-border transfer mechanism relied on, such as SCCs.
儿童与年龄
Children and Age
- The App is intended for people aged 16 and over and is planned for release on the App Store with a 17+ rating. The final rating must match what is entered in App Store Connect and Section 2 of the Terms of Use — see open items.
- We do not knowingly collect personal information from anyone under 16. The age restriction is enforced through the App Store rating.
- If you believe someone under 16 has given us personal information, tell us at teveillan@gmail.com and we will verify and delete it.
本政策的变更
我们可能不时更新本政策。更新后会修改本页顶部的「最后更新」日期;若变更为实质性变更(例如新增数据类别或新的处理目的),我们会通过 App 内提示或邮件方式提前告知。
Changes to This Policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date at the top of this page, and for material changes — such as a new category of data or a new purpose — we will give advance notice in the App or by email.
联系我们
关于本政策的疑问,或行使你的数据权利,请联系:teveillan@gmail.com上线前建议改用域名邮箱(如 privacy@ 自有域名);个人 Gmail 地址不适合长期作为对外法务联系方式。
运营主体与通信地址:见第 1 节(待补)。
Contact
Questions about this policy, or to exercise your data rights: teveillan@gmail.comBefore launch, switch to a domain address (for example privacy@ your own domain); a personal Gmail address is not a suitable long-term legal contact.
Operating entity and mailing address: see Section 1 (to be completed).
剩余待定条目清单
本页其余内容已逐条对照代码实现与供应商公开条款核实。下面是仍未确定的条目,按谁来定分组。定稿时删除本节。
A. 需律师 / 运营主体确定
- 页顶 · 生效日期。
- 第 1 节 · 运营主体全称、注册地与通信地址(第 14 节引用此处)。
- 第 9 节 · 是否面向欧盟 / 英国用户;若是,需补数据控制者信息、欧盟代表 / DPO、投诉途径。
- 第 11 节 · 我们自有服务器的托管地区,以及跨境传输机制(SCC 等)。
- 第 14 节 · 对外联系邮箱是否改用域名邮箱。
B. 需向供应商书面确认
- 第 4 节 · fal.ai 是否将标准层的输入 / 输出用于其 AI 模型开发;并评估是否默认加上「X-Fal-Store-IO: 0」。
C. 需 founder 补齐或拍板(本页未就此作出承诺)
- 第 10 节 · 静态加密、备份的加密与存放地点、内部访问审计、数据泄露通知流程与时限。
- 第 12 节 · App Store 年龄分级的最终档位(须与 App Store Connect 及条款第 2 条一致)。
- 第 3 节 · 若将来引入任何形式的人工抽查,必须先更新该节再上线。
D. 已在本页如实披露,但建议上线前处理的实现问题
Open Items Still to Be Decided
Everything else on this page has been checked line by line against the implementation and against each provider's public terms. Below is what remains undecided, grouped by who decides. Delete this section when the page is finalized.
A. For counsel / the operating entity
- Top of page · effective date.
- Section 1 · legal entity name, place of registration, and mailing address (Section 14 refers back to this).
- Section 9 · whether the App is offered to EU / UK users; if so, add controller details, EU representative / DPO, and the complaints route.
- Section 11 · the region our own servers are hosted in, and the cross-border transfer mechanism (SCCs, etc.).
- Section 14 · whether the public contact email moves to a domain address.
B. To confirm in writing with a provider
- Section 4 · whether fal.ai uses standard-tier inputs and outputs to develop its AI models, and whether to set "X-Fal-Store-IO: 0" by default.
C. For the founder to establish or decide (no commitment is made on this page)
- Section 10 · encryption at rest, backup encryption and location, internal access auditing, and the breach-notification process and deadline.
- Section 12 · the final App Store age rating (must match App Store Connect and Section 2 of the Terms).
- Section 3 · if human spot-checking is ever introduced in any form, this section must be updated before it ships.
D. Disclosed truthfully here, but worth fixing before launch
- Section 8 · deleting an account does not remove the generated image files from storage (only the database references).
- Section 4 · generated-image links require no sign-in and never expire.
- Section 8 · the 90-day cleanup job for daily state snapshots is not yet running automatically.
- Section 2 · the "parallel life" form invites users to enter a time of birth by suggesting it makes the reading sharper, while that field is not used in any computation — the prompt copy should be corrected before launch.