Privacy Policy / 隐私政策

Last updated: 2026-09-20 · 最后更新:2026 年 9 月 20 日

English

1. Who we are

Natively (“we”, “us”, “the app”) is an iOS custom keyboard plus a companion app that helps you write and speak more natural English. The keyboard rewrites your English to sound like a native speaker; the app also includes an AI chat feature where you practice with conversational personas and can get your own messages coached. Natively is built and operated by Natively Lab, Inc., a Delaware corporation with its principal place of business in Irvine, California, USA.

If you have any questions about this policy, contact us at legal@trynatively.app.

2. What this policy covers

This policy explains what information Natively collects, how it’s used, and what your rights are. Because Natively is a keyboard, we want to be especially clear about what we can and cannot see when you type.

3. What we collect

Text you type while using Natively as your active keyboard. When you tap the “rewrite” button, the text you’ve entered is sent to our servers to be rewritten by an AI model.

Messages you send in the in-app AI chat, and any message you ask us to “coach” (analyze), along with the recent conversation needed to respond. These are sent to our servers to generate the reply, its Chinese annotations, or coaching feedback.

A photo you explicitly choose or capture in AI chat is sent with that message so your AI friend can respond. When you capture a video, the raw video stays on your device and only one preview frame is sent. Camera and microphone access occur only after you start a capture or recording.

When you start a voice call with an AI friend, the app sends a bounded continuity snapshot: up to the eight most recent successfully delivered, text-only turns in that friend’s thread. Our backend combines that snapshot with the non-sensitive memory profile the friend already keeps about you. Failed sends and photo, video, or voice-message items are excluded. During the call, the realtime voice service returns a text transcript to the app. If a speaking report is generated, that transcript is sent to our backend and the AI provider used by your build to grade your spoken English.

Voice routing depends on the build. In the overseas build, audio streams directly between your device and OpenAI over WebRTC and does not pass through our backend. In the mainland-China build, audio travels from your device to Natively’s domestic gateway and then to Doubao’s realtime voice service; the gateway necessarily relays the live audio and transcript events, but does not record, persist, or log their contents.

Subscription and purchase information for supported purchases. Mainland-China iOS uses our first-party StoreKit verification. Overseas iOS uses RevenueCat for purchases and restoration, as described in Section 6.6; Android checkout is not enabled. Purchases are processed by the Apple App Store — not by us — so we never see or receive your card number or billing details. On mainland-China iOS, Apple determines introductory-offer eligibility and provides signed transaction information to the app. To unlock premium features and keep your subscription in sync across your devices, the app sends that signed transaction information to our backend, and Apple may send signed subscription-status notifications directly to our backend. This information includes, for example, the plan, whether a trial is active, and the renewal or expiry date.

We do not collect:

3.1 Accepted keyboard rewrite capture

If you separately enable “Bring accepted keyboard rewrites here” (off by default), a rewrite’s before/after text enters an on-device App Group confirmation queue only after you accept it and the keyboard verifies it was inserted. The queue is limited to 20 items, is never uploaded, and is not written merely because an API request succeeds or a suggestion is shown.

3.2 Mainland-China keyboard membership

In the mainland-China build, the signed-in companion app sends the keyboard’s random installation UUID to our domestic backend to obtain a narrowly scoped, revocable keyboard credential. Each credential issue or revoke request also sends a non-secret, monotonically increasing binding value so the server can reject delayed older changes without relying on device time. This lets the server apply your current Natively Pro status to that keyboard. Free usage remains attached to the installation; a purchased N-key balance is attached to both the purchasing account and that installation, so changing accounts on the same keyboard does not transfer either account’s balance. The credential and binding value contain no text you type and cannot be used as your general account session or as proof of Natively Pro status.

3.3 Mainland-China Deck/Slang usage information

In the mainland-China build, when you are signed in and the Deck/Slang comparison is enabled, we record whether the learning entry was shown, a reading session started or ended, a card was viewed, you changed mode, you explicitly saved an expression, or audio playback began manually or automatically. These records contain your account ID, a stable comparison group derived from that account, the experiment ID, event name and ID, Deck/Slang mode, a reading-session ID, event and server-receipt timestamps, and, when applicable, the expression/card ID and session duration. These are account-linked usage records, not anonymous statistics. They do not contain your typed text, search queries, custom expression text, chat messages, audio recordings, email address or keyboard installation ID.

We use these records to compare the two learning entry experiences, calculate return visits and reading, saving, playback and switching rates, and improve the feature. Automatic playback is recorded separately from manual playback. These records are sent to our domestic backend and are not synchronized to the overseas data plane. Retention and deletion are described in Section 6.3.

4. Full Access

To use the AI rewrite feature, you must enable “Allow Full Access” for Natively in iOS Settings → General → Keyboard → Keyboards → Natively. This permission is required by iOS to allow the keyboard extension to communicate with our server.

Without Full Access enabled, Natively works as a standard input keyboard, AI features are unavailable, and no text leaves your device.

5. How we process your text

When you trigger an AI rewrite:

When you use the in-app AI chat, or tap one of your messages to “coach” it:

When you make a voice call with an AI friend:

Mainland-China iOS verifies StoreKit purchases on the domestic backend. Overseas iOS uses RevenueCat for subscription and consumable verification, restoration and status updates (Section 6.6). For supported purchases:

5.1 Accepted rewrite processing

The optional capture setting is a local App-to-keyboard instruction. When you turn it off, the keyboard purges its pending queue. The app reads pending pairs with a non-destructive peek, displays them only in memory for your decision, and acknowledges each pair only after you save or ignore it.

5.2 Mainland-China consumable refunds

In mainland China, the purchase-history screen has a separate consent switch for each consumable purchase, off by default. If you enable it and Apple requests information to review a refund, our domestic server sends Apple the transaction identifier, delivery status, used percentage, refund recommendation and confirmation that consent was granted and no sample content was provided. It does not send your account ID, email, keyboard text, chat messages or recordings. Apple makes the refund decision. You may turn the switch off at any time; refusal or withdrawal does not prevent a refund request. Withdrawal stops future sends but cannot recall data already delivered to Apple. General privacy acceptance does not enable this switch.

We store purchase usage counters and the consent version/time (and withdrawal time if applicable) on our domestic server. We also keep request deadlines, the sent-field snapshot, send attempts/results and signed-payload digests for refund handling, duplicate prevention and reconciliation; we do not store raw signed payloads in this ledger. Consent records are deleted with your account. Limited transaction-linked refund evidence remains after account linkage is removed, with no shorter automatic deletion period currently configured. Backups follow Section 9.1. Apple retains received information under its own privacy policy for refund processing; access or deletion requests for Apple's copy can be made at privacy.apple.com.

6. What we store

On your device:

On our servers:

We do not persist your rewrite text, chat photos or video preview frames, voice-call audio or raw report transcript, or your full chat transcript on our servers. Temporary call-context and report-result storage is described above and in Section 6.5 for overseas calls.

6.1 Accepted rewrite retention

If you opt in, up to 20 accepted keyboard before/after pairs stay in local App Group confirmation storage. The staging files use iOS file protection and are excluded from backups. Each pair expires after 24 hours and is deleted the next time the queue is accessed. Ignoring a pair, turning the setting off, or clearing local data also deletes it. A pair you explicitly save moves to your on-device Saved expressions bank and remains there until you delete that expression or clear local data; it is not uploaded.

6.2 Mainland-China keyboard credential retention

On your device, the mainland-China build keeps one atomic bundle containing a narrowly scoped keyboard credential, its account owner, the keyboard installation UUID, and its expiry in protected shared Keychain storage. The bundle contains only those four fields. The raw credential is never written to MMKV, logs, files, or App Group UserDefaults; App Group UserDefaults stores only a fail-closed disabled flag and independent SHA-256 invalidation markers. On logout or account switch, the app disables credential reads before attempting to delete the Keychain bundle. Even if iOS cannot delete the bytes, neither the app nor keyboard can use them. The credential expires within 30 days and can be revoked by our backend; the keyboard never receives your normal account access or refresh token. Separately, the companion app persistently reserves the next positive safe-integer value of a non-secret, per-keyboard monotonic binding counter before each issue or revoke request. That counter is stored in host-private iOS Keychain storage protected as WhenUnlockedThisDeviceOnly, is not shared with the keyboard, and is not authentication, authorization, or evidence of Natively Pro status. On our server, domestic Postgres stores the current credential’s keyboard UUID, account ID, expiry timestamps, and only a SHA-256 hash of the credential — never the raw value. Revocation deletes that credential and immediately ends its authority; an expired credential is deleted when presented or when the same account later requests another credential. A minimal last-authenticated account-to-installation association can remain after revocation for balance attribution and account-lifecycle cleanup. A later authenticated binding replaces it, and account deletion removes it. Free limits and rate limits remain keyed to the keyboard UUID; purchased N-key balances are keyed to both account and keyboard UUID, so another account on the same installation cannot inherit them. A separate account-free fence stores only the random keyboard UUID, the last accepted counter value, and an update timestamp. It contains no account ID, credential or token, token hash, typed text, or subscription status. We keep the fence long-term and accept a credential mutation only when its counter is strictly greater than the stored value, preventing delayed old requests from reviving revoked access or replacing a newer binding. The fence is covered by your deletion rights; after account-linked data is deleted, any retained fence is only unlinkable random-device ordering metadata.

6.3 Mainland-China Deck/Slang retention

On your device, the reading-mode preference, reading position, automatic-playback preference, and up to 1,000 unsent usage events are stored under your account. Events older than 29 days are not uploaded and are removed when the app next processes the queue; a closed app cannot remove local bytes at a deadline. Events acknowledged by the server are removed from the local queue.

On our domestic servers, the usage records remain linked to your account until account deletion; there is currently no shorter automatic deletion schedule. Account deletion removes them from the active database and the app clears the corresponding account-owned local state. Historical backups follow Section 9.1.

6.4 Mainland-China purchase verification records

For mainland-China App Store subscriptions, we process Apple-signed transaction and notification payloads (JWS) to verify purchases and reconcile entitlements. In addition to subscription status, our domestic backend stores account-linked verification records: transaction and original-transaction IDs, product, purchase/expiry/revocation/signing times, production or sandbox environment, offer and ownership information, notification and processing status, error codes where applicable, and a SHA-256 digest of the signed payload. The original JWS is not retained in this ledger. These records support purchase verification, duplicate-credit prevention, refunds and reconciliation; they contain no payment card data. Account deletion removes account-linked entitlement snapshots and balances, while limited purchase evidence is retained with the account linkage removed as described in Section 9.1.

6.5 Overseas account, voice and keyboard data

Overseas accounts store email addresses and password hashes (never plain-text passwords), linked sign-in identifiers, hashed refresh credentials and subscription status in Neon. Signing out revokes the current refresh-token family when the request reaches our server; local sign-out clears the device session even offline. Previously issued access tokens can remain valid for up to one hour unless the account is deleted. Password recovery sends a one-time code through Cloudflare Email to the account email address. Only a hash is stored; it expires after 15 minutes and expired rows are removed by hourly cleanup. Successful reset changes the password, invalidates outstanding reset codes and revokes refresh sessions; existing access tokens retain the same short expiry.

Personalized spoken chat replies are cached for up to seven days in a private Cloudflare R2 bucket, partitioned by account. Playback requires the same signed-in account and is not publicly cacheable. Generated speech contains the reply, which can reflect your conversation. Audio is inaccessible after seven days; physical deletion follows the configured bucket lifecycle. Account deletion removes private audio and blocks late background writes. This is separate from live call audio.

Our server exchanges the overseas WebRTC session description with OpenAI and retains a call ID and an enforced termination deadline. No reusable OpenAI credential goes to the phone. Bounded persona memory and recent delivered text are held until termination, then erased; a minimal receipt remains for ten minutes. If provider termination fails, the server retries and retains session state until it confirms termination. Audio still travels directly between your device and OpenAI. Overseas rate-limit counters stop affecting requests after their UTC day ends. Automatic cleanup is scheduled within 48 hours; delayed platform alarms can delay physical deletion.

The overseas iOS keyboard receives a revocable, account-bound, rewrite-only credential, valid for at most 30 days. The backend stores its hash, account and random installation ID, expiry and a non-secret ordering counter. It checks current Premium entitlement on the server. It is stored in protected shared Keychain on iOS. Local sign-out immediately disables the credential; successful server revocation ends its authority. These records contain no typed text, and the keyboard never receives your account access or refresh token. Overseas iOS purchase and restore now use the separate RevenueCat integration described in Section 6.6.

6.6 Overseas iOS RevenueCat billing

Overseas iOS purchases are paid through Apple and managed with RevenueCat (revenuecat.com). We provide RevenueCat with your random Natively account identifier, App Store purchase receipts and transaction information, and technical app/device information collected by its purchasing SDK. We do not provide your chat messages, keyboard text, audio, email or password to RevenueCat. We never receive your payment card number. RevenueCat processes purchase data outside mainland China under its privacy policy (https://www.revenuecat.com/privacy). The mainland-China app does not initialize or link this SDK and continues to use the domestic StoreKit verification service.

Our overseas backend verifies subscription and one-time purchase records with RevenueCat and keeps an account-linked subscription snapshot, transaction identifiers, product and environment, purchase times, credited and used balances, refunds and temporary voice reservations in Neon. Voice reservations are settled using server-measured usage. Account deletion removes access to balances and detaches raw account identifiers from purchase and reservation records; limited transaction evidence and a one-way account identifier hash remain to prevent the same purchase being credited again. There is currently no automatic expiry for this payment anti-replay evidence. RevenueCat and Apple may retain purchase records under their own policies and obligations. Deleting Natively does not cancel an Apple subscription. Manage or cancel it in App Store settings.

6.7 Optional product usage analytics

Optional product usage analytics is off until you separately choose Allow. We collect account-linked action names, timing, app/build/update versions, distribution channel, random event/session identifiers, content identifiers, durations and allowlisted outcomes to understand usage and failures and exclude internal testing. We never include typed text, chat content, recordings or advertising identifiers in these events. Mainland-China events stay on the domestic server; overseas events stay on the overseas plane. You can turn this off in Privacy & subscriptions: local collection stops and pending app/keyboard events are cleared immediately; the account setting syncs when online. Other devices learn the change when they reconnect. Uploaded event details and classification audit entries expire after 90 days (hourly cleanup); account preferences, classification and first-observed time remain until account deletion. Events are deleted with the account. The app queue holds up to 1,000 events; the iOS keyboard holds up to 200 content-free events and sends them through the companion app when it next opens. Events aged 7 days or more are not uploaded and are removed when the app next processes the queue; closed apps cannot erase local bytes at a deadline. Backups follow Section 9.1. Declining does not restrict any feature.

7. Third-party services

Natively uses the following third parties to operate:

We do not share your data with any other third parties. We do not sell your data, ever.

8. Children’s privacy

Natively is intended for users 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has used Natively, please contact us and we will take appropriate action.

9. Your rights

You have the right to:

9.1 Mainland-China account deletion

Account deletion is available without requiring a support call or email. It is irreversible. If your account is linked to Sign in with Apple, the app first asks you for a fresh Apple authorization; our domestic backend verifies that it belongs to the linked Apple account and asks Apple to revoke the app’s token before erasing the account.

After the domestic backend confirms deletion, it removes your login record (including email/password hash, where applicable), linked sign-in identifiers, refresh sessions, chat memories, learning and practice records, feedback and reports, subscription-entitlement snapshot, account-linked keyboard credential and installation association, and voice, N-key, and learning balances. The app then signs out and clears app-managed local state belonging to that account, including chat/progress references, the shared keyboard credential and accepted-rewrite queue, its account-owned daily reminder, and app-owned cache copies created for cropped avatars or compressed chat images. Cleanup is restricted to Natively’s own cache directory; original photos or videos in your Photos library or saved outside Natively remain under your control and are never deleted by this process.

Deleting Natively does not cancel an App Store subscription. You can continue deletion without cancelling, but to prevent future Apple charges you must manage or cancel the subscription separately in App Store subscriptions. Deletion removes account-linked purchased balances and history. An App Store subscription tied to the deleted account is not transferred to a new Natively account and cannot be restored there; deleted history and consumable balances are not restored.

We retain only the following limited records after deletion:

9.2 Overseas account deletion

Permanently delete your account in Settings → Account & data → Delete account. Linked Apple sign-in requires fresh Apple authorization and server-side revocation first. A deletion marker blocks account access and delayed writes. The backend removes account/sign-in records, refresh sessions, persona memories, server learning/practice records, feedback/reports, subscription records, keyboard credentials, private synthesized audio and call quota/report state. Active calls must terminate before completion is acknowledged. The app clears its managed local account data after confirmation; your original system-library photos and videos are untouched.

Failed external cleanup leaves the account blocked and is retried. A minimal cleanup queue holds the account ID only while cleanup is pending. A one-way SHA-256 marker of the deleted random user ID protects against replay and restored data for 366 days. After completed deletion, expired markers are removed by hourly cleanup; outages can delay physical cleanup. Incomplete deletion remains blocked until cleanup succeeds, even beyond that period. Voice objects retain content-free deletion fences against late requests. Non-account-linked keyboard ordering fences can remain. Provider-managed historical backups follow configured provider retention; deletion does not imply instant erasure of every backup byte. Deletion protection must be reapplied before service resumes from a restored backup.

Account deletion does not automatically cancel a previously purchased app-store subscription; manage it with the store to prevent future charges.

10. California Privacy Rights

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the following rights regarding your personal information:

To exercise these rights, email us at the address in Section 15 (Contact). We verify requests using the random user ID stored on your device.

11. EEA, UK, and Switzerland Privacy Rights

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent laws apply to our processing of your personal data.

12. Data location

The overseas build uses Cloudflare for the API edge, Neon for relational data, and OpenAI for AI processing; OpenAI’s servers are located in the United States. The mainland-China build uses a separate Natively backend, Postgres, Redis, and contracted AI services hosted inside mainland China. Its user text, continuity context, memory profile, report transcript, and voice-call audio are not synchronized to the overseas plane; domestic voice follows device → Natively domestic gateway → Doubao inside mainland China.

13. Security

Data in transit is encrypted using HTTPS/TLS, encrypted WebRTC, or WSS as appropriate. Our backend uses authenticated, short-lived request or call-session tokens to prevent unauthorized access. The mainland-China keyboard uses a separate time-limited, revocable credential with only rewrite scope; our server stores only its SHA-256 hash, and invalid, expired, revoked, mismatched, or stale-generation operations fail closed. The binding counter orders credential changes but does not authenticate them. Permanent provider credentials are never shipped in the app.

14. Changes to this policy

We may update this policy from time to time. When we do, we’ll update the “Last updated” date at the top. For significant changes, Natively will ask you to re-confirm acceptance on next launch, and we’ll notify users via the app or email (if you’ve joined our waitlist).

15. Contact

If you have questions, concerns, or requests related to this policy, please email us at legal@trynatively.app. We read every message.


中文

1. 我们是谁

Natively(“我们”、“本应用”)是一款 iOS 自定义键盘,外加一个配套应用,帮你写出、说出更地道的英语。键盘会把你的英语改写得像母语者一样;应用还包含一个 AI 聊天功能,你可以和对话角色练习,并让我们点评(coach)你自己发的消息。Natively 由 Natively Lab, Inc.(一家特拉华州公司,主要办公地点位于美国加州尔湾)开发和运营。

如对本政策有任何疑问,请联系我们:legal@trynatively.app

2. 本政策的范围

本政策解释了 Natively 收集哪些信息、如何使用,以及你的权利。由于 Natively 是一个键盘,我们希望特别清楚地说明:你输入文字时,我们能看到什么、不能看到什么。

3. 我们收集的内容

你在使用 Natively 作为当前键盘时输入的文字。当你点击“改写”按钮时,你输入的文字会被发送到我们的服务器,由 AI 模型改写。

你在应用内 AI 聊天里发送的消息,以及你让我们“点评”(分析)的消息,连同生成回复所需的近期对话内容。这些会被发送到我们的服务器,用于生成回复、中文标注或点评反馈。

你在 AI 聊天中主动选择或拍摄的照片会随消息发送,让 AI 朋友可以回应。拍摄视频时,原视频保留在设备上,只发送一张预览帧。只有在你主动开始拍摄或录音后,应用才会访问相机或麦克风。

当你开始与 AI 朋友语音通话时,App 会携带一份有限的连续上下文:该角色线程里最近最多 8 条已成功送达的纯文字消息,以及该角色已保存的非敏感人物记忆。发送失败的消息、照片、视频和语音消息不会带入。通话时,实时语音服务会把文字转录返回给 App;如果生成口语报告,该转录会发送给我们的后端及当前版本使用的 AI 服务商来评估口语。

通话音频路由版本决定。海外版通过 WebRTC 在你的设备与 OpenAI 之间直接传输,不经过我们的后端。中国大陆版的路径是「你的设备 → Natively 国内网关 → 豆包实时语音服务」;网关为完成通话必须实时转发音频和转录事件,但不会录音、持久化存储或记录其内容。

如你购买海外版 Natively Premium 或中国大陆版 Natively Pro 订阅,相关的订阅与购买信息。付款由 Apple App Store 或 Google Play 处理,而非我们 —— 我们绝不会看到或收到你的卡号或账单信息。在 iOS 上,Apple 判断新订阅优惠资格,并向 App 提供经过签名的交易信息。为了解锁高级功能并在你的多台设备间同步订阅,App 会把该签名交易信息发送给我们的后端;Apple 也可能把经过签名的订阅状态通知直接发送给我们的后端。这些信息包括例如套餐、试用是否生效,以及续订或到期日期。

我们不会收集以下内容:

3.1 已接受键盘改写的暂存

如果你单独开启「将已接受的键盘改写带到这里」(默认关闭),一条改写的前后文本只有在你接受且键盘确认已成功插入后,才会进入设备本地的 App Group 待确认队列。该队列最多 20 条,绝不上传;仅 API 成功或只展示建议都不会写入。

3.2 中国大陆版键盘会员

在中国大陆版中,已登录的配套 App 会把键盘随机安装 UUID 发送给我们的国内后端,以领取一枚权限严格受限、可撤销的键盘凭证。每次签发或撤销请求还会发送一个非秘密、单调递增的绑定值,让服务器无需信任设备时间也能拒绝延迟到达的旧变更。这会让服务器把你当前的 Natively Pro 状态应用到这台键盘。免费次数归属于该键盘安装;已购 N 键余额则同时绑定购买账号与该安装,因此同一键盘切换账号不会转移任一账号的余额。凭证和绑定值都不包含你输入的文字,不能作为通用账号会话,也不能证明 Natively Pro 权益。

3.3 中国大陆版 Deck/Slang 使用信息

在中国大陆版中,当你已登录且 Deck/Slang 体验比较启用时,我们会记录学习入口是否展示、阅读会话开始或结束、卡片浏览、模式切换、主动收藏表达,以及手动或自动播放是否开始。记录包括你的账号 ID、由该账号决定的固定比较分组、实验 ID、事件名称及 ID、Deck/Slang 模式、阅读会话 ID、事件发生和服务器接收时间;适用时还包括表达/卡片 ID 和会话时长。这些是与账号关联的使用记录,不是匿名统计。其中不含你输入的正文、搜索词、自定义表达正文、聊天消息、录音、邮箱或键盘安装 ID。

我们用这些记录比较两种学习入口体验,计算回访、阅读、收藏、播放及切换情况,并改进该功能。自动播放与手动播放分开记录。这些记录发送至国内后端,不同步到海外数据平面。保留与删除方式见第 6.3 节。

4. 关于 Full Access(完全访问)

使用 AI 改写功能时,你必须在 iOS 设置 → 通用 → 键盘 → 键盘 → Natively 中开启“允许完全访问”。这是 iOS 系统要求,用于允许键盘扩展与我们的服务器通信。

未开启 Full Access 时,Natively 作为普通输入键盘工作,AI 功能不可用,任何文字都不会离开你的设备。

5. 我们如何处理你的文字

当你触发 AI 改写时:

当你使用应用内 AI 聊天,或点按你自己的某条消息进行“点评”时:

当你和 AI 朋友进行语音通话时:

中国大陆 iOS 通过国内后端验证 StoreKit 购买;海外 iOS 通过 RevenueCat 验证订阅及消耗型购买、恢复并同步状态(见第 6.6 节)。对于支持的购买:

5.1 已接受改写的处理

可选的暂存开关是 App 发给键盘的本地指令。关闭时键盘会清除待确认队列。App 通过非破坏性 peek 读取待确认项,只在内存中展示供你决定,并且只会在你收藏或忽略后逐条确认(ACK)。

5.2 中国大陆版消耗型购买退款

中国大陆版「购买记录」中,每笔消耗型购买都有一个独立、默认关闭的同意开关。你开启后,若 Apple 为审核退款请求信息,我们的国内服务器会向 Apple 提供该笔交易标识、交付状态、已使用比例、退款建议,以及已取得同意和未提供试用内容的标记。不发送你的账号 ID、邮箱、键盘文字、聊天正文或录音。退款结果由 Apple 决定。你可随时关闭开关;不同意或撤回不影响申请退款。撤回会停止后续发送,但无法收回 Apple 已收到的数据。接受一般隐私政策不会自动打开此开关。

国内服务器保存购买使用计数、同意版本和时间,以及适用时的撤回时间;另保存请求截止时间、发送字段快照、发送尝试和结果、签名载荷摘要,用于退款处理、防重复及对账,不在此记录表保存原始签名载荷。删号会删除同意记录;移除账号关联后的有限交易退款凭证仍保留,目前没有更短的自动删除期限。备份按第 9.1 节处理。Apple 按其隐私政策为退款处理保留已接收的信息;对 Apple 所持副本的访问或删除请求可前往 privacy.apple.com 提交。

6. 我们存储的内容

在你的设备上:

在我们的服务器上:

我们不会在服务器上持久化存储你的改写文字、聊天照片或视频预览帧、语音通话音频或原始报告转录,也不保存你的完整聊天记录。临时通话上下文和报告结果存储如上所述;海外通话另见第 6.5 节。

6.1 已接受改写的保留

如你选择开启,最多 20 条已接受的键盘改写前后内容会存放在本地 App Group 待确认存储中。暂存文件使用 iOS 文件保护且不进入备份。每条会在 24 小时后失效,并在下次访问队列时删除;忽略、关闭开关或清除本机数据也会删除。你明确收藏的一条会转存到设备本地「我的表达」,保留至你删除该表达或清除本机数据,绝不上传。

6.2 中国大陆版键盘凭证保留

在你的设备上,中国大陆版会把权限严格受限的键盘凭证、所属账号、键盘安装 UUID 和到期时间作为一个原子 bundle,保存在受保护的共享 Keychain 中;bundle 仍只含这四个字段。raw 凭证绝不会写入 MMKV、日志、文件或 App Group UserDefaults;App Group UserDefaults 只保存 fail-closed 的 disabled 标记和彼此独立的 SHA-256 失效标记。退出登录或切换账号时,App 会先禁止读取凭证,再尝试删除 Keychain bundle;即使 iOS 未能删除其中字节,App 和键盘也都不能继续使用。凭证最长 30 天过期,也可由我们的后端撤销;键盘不会收到你的普通账号 access token 或 refresh token。另外,配套 App 会在宿主私有、WhenUnlockedThisDeviceOnly 的 iOS Keychain 中,为每个键盘安装保存一个非秘密、持久单调递增的绑定 counter;每次签发或撤销网络请求前先持久预留下一个正的安全整数。该 counter 不与键盘共享,也不是认证、授权或 Natively Pro 权益证明。在服务器上,国内 Postgres 会为当前凭证保存键盘 UUID、账号 ID、到期时间以及凭证的 SHA-256 hash,绝不存 raw 值。撤销会删除该凭证并立即终止其权限;过期凭证会在被呈现,或同一账号之后申请新凭证时删除。为了余额归属和账号生命周期清理,一份最小化的“最后认证账号↔键盘安装”关联可在撤销凭证后继续保留;后续通过认证的绑定会覆盖它,删除账号时会将它删除。免费次数和限流仍以键盘 UUID 为 key;已购 N 键余额同时以账号和键盘 UUID 为 key,因此同一安装上的其他账号不能继承。另一份不含账号的 fence 只保存随机键盘 UUID、最后接受的 counter 和更新时间,不含账号 ID、credential/token、token hash、输入文字或订阅状态。只有严格大于已存值的 counter 才能改变绑定;该 fence 会长期保留,防止延迟旧请求复活已撤销访问或覆盖更新绑定。它受你的删除权覆盖;账号关联数据删除后,任何仍保留的 fence 只是不再可关联账号的随机设备排序元数据。

6.3 中国大陆版 Deck/Slang 数据保留

本机按账号保存阅读模式偏好、阅读位置、自动朗读偏好,以及最多 1,000 条待上传的交互事件。超过 29 天的事件不再上传,并在 App 下次处理队列时删除;App 关闭时无法到点删除本地字节。服务器确认接收的事件会从本机队列移除。

在国内服务器上,这些使用记录会保持账号关联,保留至删除账号;目前没有更短的自动清理期限。删号会从在线数据库移除这些记录,App 同时清理对应的账号本机状态。历史备份按第 9.1 节处理。

6.4 中国大陆版购买验证记录

对于中国大陆版 App Store 订阅,我们处理 Apple 签名交易和通知载荷(JWS),用于验证购买及核对权益。除订阅状态外,国内后端还保存与账号关联的验证记录:交易及原始交易 ID、商品、购买/到期/撤销/签名时间、正式或沙盒环境、优惠与购买归属信息、通知及处理状态、适用时的错误代码,以及签名载荷的 SHA-256 摘要。该记录表不保存原始 JWS。这些记录用于购买验证、防止重复入账、退款与对账,不含支付卡数据。删号会删除账号关联的权益快照和余额;有限购买凭证在移除账号关联后,按第 9.1 节保留。

6.5 海外版账号、语音与键盘数据

海外版在 Neon 保存邮箱和密码 hash(绝不保存明文密码)、关联登录标识、refresh 凭证 hash 和订阅状态。退出请求到达服务器后会撤销当前 refresh token 家族;即使断网,本机退出也会清除设备会话。除删号外,已签发的 access token 最长一小时内可能继续有效。找回密码通过 Cloudflare Email 向账号邮箱发送一次性重置码;服务器只存 hash,十五分钟后失效,过期记录由每小时清理任务移除。重置成功会更新密码、废止未用重置码并撤销 refresh 会话;已有 access token 仍按上述短期到期规则处理。

个性化聊天朗读音频在 Cloudflare R2 私有桶按账号分区,最长缓存七天;播放须验证同一登录账号,禁止公共缓存。合成语音包含回复正文,可能涉及聊天内容,与实时通话音频不同。七天后音频不再可访问,物理清理由配置的桶生命周期执行。删号会清理账号私有音频,并阻止延迟后台写入。

海外通话由服务器向 OpenAI 交换 WebRTC 会话描述,保留通话 ID 并执行挂断截止时间;手机不再收到可复用的 OpenAI 凭证。有上限的角色记忆和近期已送达文字暂存至通话终止,终止时清除;最小化回执再保留十分钟。若服务商挂断失败,服务器会重试并保留会话状态至确认终止。音频仍在设备与 OpenAI 之间直传。海外限流计数在其 UTC 日结束后不再影响请求,并在 48 小时内调度自动清理;平台 alarm 延迟可能使物理删除稍晚完成。

海外 iOS 键盘使用绑定账号、可撤销且仅限改写的凭证,最长三十天有效;后端保存其 hash、账号和随机安装 ID、到期时间和非秘密排序 counter,并在服务端核对当前 Premium 权益。iOS 使用受保护的共享 Keychain 保存。本机退出立即停用凭证,成功的服务端撤销会终止其权限。这些记录不含输入正文,键盘不会收到普通账号 access token 或 refresh token。海外 iOS 通过 RevenueCat 处理购买和恢复,详见第 6.6 节;Android 购买尚未开放。

6.6 海外 iOS RevenueCat 支付

海外 iOS 购买由 Apple 收款,通过 RevenueCat(revenuecat.com)管理。我们向 RevenueCat 提供随机的 Natively 账号标识、App Store 购买收据及交易信息,以及其支付 SDK 收集的应用和设备技术信息;不向 RevenueCat 提供聊天消息、键盘正文、音频、邮箱或密码。我们不会收到支付卡号。RevenueCat 按其隐私政策(https://www.revenuecat.com/privacy)在中国大陆以外处理购买数据。中国大陆版不初始化或链接该 SDK,继续使用国内 StoreKit 验证服务。

海外后端向 RevenueCat 核对订阅和单次购买,在 Neon 保存账号关联的订阅快照、交易标识、商品及环境、购买时间、入账和使用余额、退款及临时语音预留。语音预留按服务器测得的使用时长结算。删号会移除余额访问权限,并从购买及预留记录解除原始账号标识;为防止同一购买重复入账,有限交易凭证和账号标识的单向 hash 会继续保留,目前没有自动到期清理期限。RevenueCat 和 Apple 可能按各自政策及义务保留购买记录。删除 Natively 账号不会取消 Apple 订阅,请在 App Store 设置中另行管理或取消。

6.7 可选的产品使用统计

可选的产品使用统计在你单独选择「允许统计」之前不会开启。我们记录与你账号关联的操作名称、时间、App/构建/更新版本、安装渠道、随机事件和会话标识、内容条目标识、时长及限定的结果类型,用于了解使用和失败情况并排除内部测试。这些事件不包含输入正文、聊天内容、录音或广告标识。中国大陆版数据保存在国内,海外版保存在海外数据面。你可在「隐私与订阅」中关闭:立即停止本机采集并清空 App 和键盘待上传事件,联网后同步账号设置;其他设备联网后同步变化。已上传事件明细和分类审计记录保留 90 天,由每小时清理任务删除;账号选择、分类和首次被观测时间保留至删号。删号会删除关联事件。本机 App 队列最多 1000 条;iOS 键盘独立队列最多 200 条不含正文的事件,在下次打开主 App 时上传。满 7 天的事件不再上传,会在 App 下次处理队列时删除;关闭的 App 无法在到期瞬间清除本机文件。备份按第 9.1 节处理。拒绝统计不影响任何功能。

7. 第三方服务

Natively 使用以下第三方服务运行:

我们不会与任何其他第三方共享你的数据。我们永远不会出售你的数据。

8. 儿童隐私

Natively 面向 13 岁及以上用户,不针对 13 岁以下儿童。我们不会有意收集 13 岁以下儿童的个人信息。如果你认为有 13 岁以下儿童使用了 Natively,请联系我们,我们将采取适当措施。

9. 你的权利

你有权:

9.1 中国大陆版账号删除

删除账号不要求拨打客服或发送邮件,且不可撤销。如果账号关联了「通过 Apple 登录」,App 会先要求一次新的 Apple 授权;国内后端确认它属于当前关联的 Apple 账号,并请求 Apple 撤销本 App 的 token,然后才删除账号。

国内后端确认删除后,会移除登录记录(如适用,包括邮箱与密码 hash)、关联登录标识、refresh session、聊天记忆、学习与练习记录、反馈和举报、订阅权益快照、账号关联的键盘凭证和安装关联,以及语音、N 键和学习余额。随后 App 会退出登录,并清除属于该账号、由 App 管理的本机状态,包括聊天/进度引用、共享键盘凭证、已接受改写队列、该账号的每日本地提醒,以及裁剪头像或压缩聊天图片时由 App 生成的缓存副本。清理范围严格限制在 Natively 自有缓存目录;系统相册原件或你保存在 Natively 之外的照片、视频仍由你自行管理,删号流程绝不会删除它们。

删除 Natively 账号不会自动取消 App Store 订阅。你无需先取消即可继续删号;但若要避免 Apple 后续扣费,必须另行前往 App Store 订阅管理页管理或取消。删号会移除账号关联的已购余额和历史。绑定已删除账号的 App Store 订阅不会转移给新的 Natively 账号,也无法在新账号中恢复;已删除的历史和消耗型余额同样不会恢复。

删号后仅保留以下有限记录:

9.2 海外版账号删除

你可以在「设置 → 账号与数据 → 删除账号」永久删号。已关联 Apple 登录的账号需要重新授权 Apple 并先由服务器撤销授权。删除标记会阻断账号访问和延迟写入。后端移除账号与登录记录、refresh 会话、角色记忆、服务端学习与练习记录、反馈举报、订阅记录、键盘凭证、私有合成音频和通话额度/报告状态;正在进行的通话须先终止才能确认完成。服务器确认后 App 清理管理的本机账号数据,不触及系统相册原件。

外部清理失败时账号继续被禁用,服务器重试清理;最小清理队列仅在待清理期间保存账号 ID。已删除随机用户 ID 的单向 SHA-256 标记用于 366 天内拒绝重放及恢复后的删除核对。删号完成后,过期标记由每小时任务移除;故障可能延迟物理清理。尚未完成的删号会持续阻断至清理成功,即使超过上述期限。语音对象保留不含内容的删除 fence 以阻止延迟请求,不含账号的键盘排序 fence 可继续保留。服务商历史备份按配置的期限保留;删号不代表所有备份字节立即擦除,恢复服务前必须重新应用删除保护。

删号不会自动取消此前通过应用商店购买的订阅;要防止后续扣费,请到对应商店管理。

10. 加州隐私权(California Privacy Rights)

如你是加州居民,《加州消费者隐私法》(CCPA)及其修订法案《加州隐私权法案》(CPRA)赋予你以下与个人信息相关的权利:

如需行使上述权利,请发邮件至第 15 节(联系我们)所列地址。我们将使用你设备上存储的随机用户 ID 验证请求。

11. 欧洲经济区、英国及瑞士隐私权

如你位于欧洲经济区(EEA)、英国或瑞士,《通用数据保护条例》(GDPR)及同等法律适用于我们对你个人数据的处理。

12. 数据位置

海外版使用 Cloudflare 作为 API edge、Neon 作为关系数据库,并使用 OpenAI 进行 AI 处理;OpenAI 的服务器位于美国。中国大陆版使用独立的 Natively 国内后端、Postgres、Redis 和中国大陆境内的签约 AI 服务。该版本的用户文字、连续上下文、记忆档案、报告转录和通话音频不会同步到海外数据平面;国内语音路径为「设备 → Natively 国内网关 → 豆包」,并全程留在中国大陆境内。

13. 安全性

传输中的数据会按路径使用 HTTPS/TLS、加密 WebRTC 或 WSS。我们的后端使用已认证的短期请求或通话会话令牌防止未授权访问;中国大陆版键盘另用一枚仅限改写 scope、限时且可撤销的凭证;服务器只存其 SHA-256 hash,无效、过期、已撤销、与 keyboard UUID 不匹配或 generation 过旧时一律 fail-closed。绑定 counter 只负责排序凭证变更,不承担认证。永久服务商凭证永不下发到 App。

14. 政策变更

我们可能会不时更新本政策。更新时,我们会修改顶部的“最后更新”日期。对于重大变更,Natively 会在下次启动时请你重新确认接受,并通过应用内提示或邮件(如果你加入了候补名单)通知用户。

15. 联系我们

如对本政策有任何问题、顾虑或请求,请发邮件至 legal@trynatively.app。我们会阅读每一条消息。

← Back to home