Privacy Policy / 隐私政策
English1. Who we are
Natively (“we”, “us”, “the app”) is an iOS custom keyboard plus a companion app that helps you write and speak more natural English. The keyboard rewrites your English to sound like a native speaker; the app also includes an AI chat feature where you practice with conversational personas and can get your own messages coached. Natively is built and operated by Natively Lab, Inc., a Delaware corporation with its principal place of business in Irvine, California, USA.
If you have any questions about this policy, contact us at legal@trynatively.app.
2. What this policy covers
This policy explains what information Natively collects, how it’s used, and what your rights are. Because Natively is a keyboard, we want to be especially clear about what we can and cannot see when you type.
3. What we collect
Text you type while using Natively as your active keyboard. When you tap the “rewrite” button, the text you’ve entered is sent to our servers to be rewritten by an AI model.
Messages you send in the in-app AI chat, and any message you ask us to “coach” (analyze), along with the recent conversation needed to respond. These are sent to our servers to generate the reply, its Chinese annotations, or coaching feedback.
A photo you explicitly choose or capture in AI chat is sent with that message so your AI friend can respond. When you capture a video, the raw video stays on your device and only one preview frame is sent. Camera and microphone access occur only after you start a capture or recording.
When you start a voice call with an AI friend, the app sends a bounded continuity snapshot: up to the eight most recent successfully delivered, text-only turns in that friend’s thread. Our backend combines that snapshot with the non-sensitive memory profile the friend already keeps about you. Failed sends and photo, video, or voice-message items are excluded. During the call, the realtime voice service returns a text transcript to the app. If a speaking report is generated, that transcript is sent to our backend and the AI provider used by your build to grade your spoken English.
Voice routing depends on the build. In the overseas build, audio streams directly between your device and OpenAI over WebRTC and does not pass through our backend. In the mainland-China build, audio travels from your device to Natively’s domestic gateway and then to Doubao’s realtime voice service; the gateway necessarily relays the live audio and transcript events, but does not record, persist, or log their contents.
Subscription and purchase information for supported purchases. Mainland-China iOS uses our first-party StoreKit verification. Overseas iOS uses RevenueCat for purchases and restoration, as described in Section 6.6; Android checkout is not enabled. Purchases are processed by the Apple App Store — not by us — so we never see or receive your card number or billing details. On mainland-China iOS, Apple determines introductory-offer eligibility and provides signed transaction information to the app. To unlock premium features and keep your subscription in sync across your devices, the app sends that signed transaction information to our backend, and Apple may send signed subscription-status notifications directly to our backend. This information includes, for example, the plan, whether a trial is active, and the renewal or expiry date.
We do not collect:
- Anything you type in password fields. Natively detects secure text fields (password inputs) and completely disables AI processing in those contexts. No data leaves your device.
- Anything you type while another keyboard (e.g. the system keyboard) is active.
- Your contacts, precise location, or other device data unrelated to a feature you explicitly start.
- Your name or other identifying information unless you voluntarily provide it (for example in chat, your profile, or support). If you create an email account, we necessarily collect that email address for sign-in; social sign-in provides the identifier required to authenticate that account.
3.1 Accepted keyboard rewrite capture
If you separately enable “Bring accepted keyboard rewrites here” (off by default), a rewrite’s before/after text enters an on-device App Group confirmation queue only after you accept it and the keyboard verifies it was inserted. The queue is limited to 20 items, is never uploaded, and is not written merely because an API request succeeds or a suggestion is shown.
3.2 Mainland-China keyboard membership
In the mainland-China build, the signed-in companion app sends the keyboard’s random installation UUID to our domestic backend to obtain a narrowly scoped, revocable keyboard credential. Each credential issue or revoke request also sends a non-secret, monotonically increasing binding value so the server can reject delayed older changes without relying on device time. This lets the server apply your current Natively Pro status to that keyboard. Free usage remains attached to the installation; a purchased N-key balance is attached to both the purchasing account and that installation, so changing accounts on the same keyboard does not transfer either account’s balance. The credential and binding value contain no text you type and cannot be used as your general account session or as proof of Natively Pro status.
3.3 Mainland-China Deck/Slang usage information
In the mainland-China build, when you are signed in and the Deck/Slang comparison is enabled, we record whether the learning entry was shown, a reading session started or ended, a card was viewed, you changed mode, you explicitly saved an expression, or audio playback began manually or automatically. These records contain your account ID, a stable comparison group derived from that account, the experiment ID, event name and ID, Deck/Slang mode, a reading-session ID, event and server-receipt timestamps, and, when applicable, the expression/card ID and session duration. These are account-linked usage records, not anonymous statistics. They do not contain your typed text, search queries, custom expression text, chat messages, audio recordings, email address or keyboard installation ID.
We use these records to compare the two learning entry experiences, calculate return visits and reading, saving, playback and switching rates, and improve the feature. Automatic playback is recorded separately from manual playback. These records are sent to our domestic backend and are not synchronized to the overseas data plane. Retention and deletion are described in Section 6.3.
4. Full Access
To use the AI rewrite feature, you must enable “Allow Full Access” for Natively in iOS Settings → General → Keyboard → Keyboards → Natively. This permission is required by iOS to allow the keyboard extension to communicate with our server.
Without Full Access enabled, Natively works as a standard input keyboard, AI features are unavailable, and no text leaves your device.
5. How we process your text
When you trigger an AI rewrite:
- The text is sent over an encrypted HTTPS connection to the backend for your build. The overseas backend runs on Cloudflare Workers and forwards it to OpenAI; the mainland-China backend forwards it only to a contracted AI provider inside mainland China.
- The rewrite result is returned to your device. Natively does not persist the rewrite text on its servers; the provider processes it under its API data-use terms.
When you use the in-app AI chat, or tap one of your messages to “coach” it:
- Before your first chat, we ask for your explicit permission to share your messages with our AI provider. Nothing is sent until you agree.
- Your message, the recent conversation, and a short memory profile (see Section 6) are sent over HTTPS to the AI provider for your build to generate the reply, its Chinese annotations, or coaching feedback. The overseas build uses OpenAI; the mainland-China build uses a contracted provider inside mainland China. A photo you explicitly choose or capture may be included. For a video, only one preview frame is included; the raw video is not uploaded.
- We instruct the system not to extract or store sensitive information (such as health, sexual, religious, political, or financial details). Providers process API inputs under their applicable data-use terms.
When you make a voice call with an AI friend:
- When dialing, the app sends up to eight recent successfully delivered text-only turns from that AI friend’s thread and the friend’s existing non-sensitive memory profile so the call can continue the conversation. Failed messages and media or voice-message items are not included. This call-specific copy is used only to initialize the session; it is not added to a server-side full-chat-history table. In the mainland-China stack, the gateway handoff is kept in Redis for at most 150 seconds and is atomically deleted when the WebSocket claims it, or expires unused. The underlying memory profile remains stored as described in Section 6 until you clear it.
- The AI friend speaks first with a brief server-authored welcome. In the overseas build, encrypted audio streams directly between your device and OpenAI. In the mainland-China build, encrypted audio follows device → Natively domestic gateway → Doubao realtime voice service. The domestic gateway relays audio and transcript events in memory so the call works, but does not record, persist, or content-log them.
- To create a speaking report, the app sends the captured text transcript over HTTPS to our backend and the AI provider for your build. Temporary network or upstream failures get at most two automatic retries (1 and 2 seconds). If the same stable report job is still running, the app may make up to five additional idempotent checks over a bounded 46-second window; those checks cannot start a second AI generation while the server claim is live. After a final failure, you may choose a manual retry. Every server request drops the raw transcript after processing: Natively does not cache or content-log it. To make a timed-out request return the same report instead of invoking the AI again, the schema-validated report result is available for replay for five minutes and may contain short speech quotes shown in the report.
Mainland-China iOS verifies StoreKit purchases on the domestic backend. Overseas iOS uses RevenueCat for subscription and consumable verification, restoration and status updates (Section 6.6). For supported purchases:
- Supported iOS payments are handled entirely by the Apple App Store. Your card and billing details go to Apple — never to us. Android checkout is not enabled.
- In mainland-China iOS, StoreKit returns Apple-signed transaction information to the app, which sends it to our domestic backend. Our backend validates Apple’s signature, stores the resulting subscription status and, in the mainland-China build, keeps the verification records described in Section 6.4; Apple also sends signed server notifications when that status changes. This lets premium features stay in sync across your devices. No payment card data reaches our servers.
5.1 Accepted rewrite processing
The optional capture setting is a local App-to-keyboard instruction. When you turn it off, the keyboard purges its pending queue. The app reads pending pairs with a non-destructive peek, displays them only in memory for your decision, and acknowledges each pair only after you save or ignore it.
5.2 Mainland-China consumable refunds
In mainland China, the purchase-history screen has a separate consent switch for each consumable purchase, off by default. If you enable it and Apple requests information to review a refund, our domestic server sends Apple the transaction identifier, delivery status, used percentage, refund recommendation and confirmation that consent was granted and no sample content was provided. It does not send your account ID, email, keyboard text, chat messages or recordings. Apple makes the refund decision. You may turn the switch off at any time; refusal or withdrawal does not prevent a refund request. Withdrawal stops future sends but cannot recall data already delivered to Apple. General privacy acceptance does not enable this switch.
We store purchase usage counters and the consent version/time (and withdrawal time if applicable) on our domestic server. We also keep request deadlines, the sent-field snapshot, send attempts/results and signed-payload digests for refund handling, duplicate prevention and reconciliation; we do not store raw signed payloads in this ledger. Consent records are deleted with your account. Limited transaction-linked refund evidence remains after account linkage is removed, with no shorter automatic deletion period currently configured. Backups follow Section 9.1. Apple retains received information under its own privacy policy for refund processing; access or deletion requests for Apple's copy can be made at privacy.apple.com.
6. What we store
On your device:
- A randomly generated keyboard installation ID (UUID). It is used for rate limiting and the installation’s free-use counter. In the mainland-China build, it also selects the purchased N-key balance owned jointly by the signed-in account and that installation, and is linked as described in Section 6.2; it is not your account ID.
- Your app preferences, chat conversation history, completed-call cards, and generated speaking reports. The chat transcript and local media URIs stay on your device — we do not store them as a full chat transcript on our servers. Captured raw videos remain on your device.
- If report generation is pending or ultimately fails, the call transcript is retained only in local retry storage. It is available for retry for no more than 24 hours and is deleted immediately after a report succeeds. At the 24-hour boundary it can no longer be retried; a global sweep removes expired retry transcripts the next time the app loads its chat/report feature (a closed app cannot delete local bytes until it runs again).
On our servers:
- Your random keyboard installation ID and daily request counters (Cloudflare Durable Objects overseas or Redis in mainland China), plus short-lived client-IP counters used to limit credential issuance and protect accounts from abuse. These frequency-limit records expire automatically within 48 hours.
- A small chat “memory profile” (our relational database in the build’s own data plane): a few non-sensitive facts an AI persona remembers about you to keep the conversation continuous — for example a name you give it, a city you mention, or interests you bring up. We instruct the extractor to skip sensitive categories (health, sexual, religious, political, financial, precise location). This is kept until you delete it: you can clear what any persona remembers at any time in Settings → Chat memory, or from that persona’s profile inside the chat.
- For a mainland-China call only, one call-specific copy of the bounded recent-text snapshot and memory context may be held in Redis for up to 150 seconds while the HTTP token request hands the session to the WebSocket gateway. It is consumed and deleted on first successful claim, or expires unused; it is not a permanent chat record.
- For report retry idempotency, a completed, schema-validated report result is available for replay for five minutes under opaque user and report IDs. The raw call transcript is not cached. This short window prevents a lost HTTP response from charging for or generating a different second report; the result may include the short speech quotes shown in the report. At five minutes it becomes inaccessible. Mainland-China Redis enforces key expiry; the overseas Cloudflare Durable Object schedules physical deletion at the deadline, although platform alarm retry may briefly delay that cleanup.
- If you join our waitlist, your email address (voluntarily provided) is stored in a separate namespace, used only to send Natively launch and product updates. You can request deletion at any time by emailing us.
- If you subscribe, your subscription status (for example: active, in trial, or expired; the plan; and the renewal or expiry date), keyed to your user ID. We derive it from Apple-signed transaction information sent by the app and update it from Apple’s signed server notifications so premium features work across your devices. It contains no payment card data.
We do not persist your rewrite text, chat photos or video preview frames, voice-call audio or raw report transcript, or your full chat transcript on our servers. Temporary call-context and report-result storage is described above and in Section 6.5 for overseas calls.
6.1 Accepted rewrite retention
If you opt in, up to 20 accepted keyboard before/after pairs stay in local App Group confirmation storage. The staging files use iOS file protection and are excluded from backups. Each pair expires after 24 hours and is deleted the next time the queue is accessed. Ignoring a pair, turning the setting off, or clearing local data also deletes it. A pair you explicitly save moves to your on-device Saved expressions bank and remains there until you delete that expression or clear local data; it is not uploaded.
6.2 Mainland-China keyboard credential retention
On your device, the mainland-China build keeps one atomic bundle containing a narrowly scoped keyboard credential, its account owner, the keyboard installation UUID, and its expiry in protected shared Keychain storage. The bundle contains only those four fields. The raw credential is never written to MMKV, logs, files, or App Group UserDefaults; App Group UserDefaults stores only a fail-closed disabled flag and independent SHA-256 invalidation markers. On logout or account switch, the app disables credential reads before attempting to delete the Keychain bundle. Even if iOS cannot delete the bytes, neither the app nor keyboard can use them. The credential expires within 30 days and can be revoked by our backend; the keyboard never receives your normal account access or refresh token. Separately, the companion app persistently reserves the next positive safe-integer value of a non-secret, per-keyboard monotonic binding counter before each issue or revoke request. That counter is stored in host-private iOS Keychain storage protected as WhenUnlockedThisDeviceOnly, is not shared with the keyboard, and is not authentication, authorization, or evidence of Natively Pro status. On our server, domestic Postgres stores the current credential’s keyboard UUID, account ID, expiry timestamps, and only a SHA-256 hash of the credential — never the raw value. Revocation deletes that credential and immediately ends its authority; an expired credential is deleted when presented or when the same account later requests another credential. A minimal last-authenticated account-to-installation association can remain after revocation for balance attribution and account-lifecycle cleanup. A later authenticated binding replaces it, and account deletion removes it. Free limits and rate limits remain keyed to the keyboard UUID; purchased N-key balances are keyed to both account and keyboard UUID, so another account on the same installation cannot inherit them. A separate account-free fence stores only the random keyboard UUID, the last accepted counter value, and an update timestamp. It contains no account ID, credential or token, token hash, typed text, or subscription status. We keep the fence long-term and accept a credential mutation only when its counter is strictly greater than the stored value, preventing delayed old requests from reviving revoked access or replacing a newer binding. The fence is covered by your deletion rights; after account-linked data is deleted, any retained fence is only unlinkable random-device ordering metadata.
6.3 Mainland-China Deck/Slang retention
On your device, the reading-mode preference, reading position, automatic-playback preference, and up to 1,000 unsent usage events are stored under your account. Events older than 29 days are not uploaded and are removed when the app next processes the queue; a closed app cannot remove local bytes at a deadline. Events acknowledged by the server are removed from the local queue.
On our domestic servers, the usage records remain linked to your account until account deletion; there is currently no shorter automatic deletion schedule. Account deletion removes them from the active database and the app clears the corresponding account-owned local state. Historical backups follow Section 9.1.
6.4 Mainland-China purchase verification records
For mainland-China App Store subscriptions, we process Apple-signed transaction and notification payloads (JWS) to verify purchases and reconcile entitlements. In addition to subscription status, our domestic backend stores account-linked verification records: transaction and original-transaction IDs, product, purchase/expiry/revocation/signing times, production or sandbox environment, offer and ownership information, notification and processing status, error codes where applicable, and a SHA-256 digest of the signed payload. The original JWS is not retained in this ledger. These records support purchase verification, duplicate-credit prevention, refunds and reconciliation; they contain no payment card data. Account deletion removes account-linked entitlement snapshots and balances, while limited purchase evidence is retained with the account linkage removed as described in Section 9.1.
6.5 Overseas account, voice and keyboard data
Overseas accounts store email addresses and password hashes (never plain-text passwords), linked sign-in identifiers, hashed refresh credentials and subscription status in Neon. Signing out revokes the current refresh-token family when the request reaches our server; local sign-out clears the device session even offline. Previously issued access tokens can remain valid for up to one hour unless the account is deleted. Password recovery sends a one-time code through Cloudflare Email to the account email address. Only a hash is stored; it expires after 15 minutes and expired rows are removed by hourly cleanup. Successful reset changes the password, invalidates outstanding reset codes and revokes refresh sessions; existing access tokens retain the same short expiry.
Personalized spoken chat replies are cached for up to seven days in a private Cloudflare R2 bucket, partitioned by account. Playback requires the same signed-in account and is not publicly cacheable. Generated speech contains the reply, which can reflect your conversation. Audio is inaccessible after seven days; physical deletion follows the configured bucket lifecycle. Account deletion removes private audio and blocks late background writes. This is separate from live call audio.
Our server exchanges the overseas WebRTC session description with OpenAI and retains a call ID and an enforced termination deadline. No reusable OpenAI credential goes to the phone. Bounded persona memory and recent delivered text are held until termination, then erased; a minimal receipt remains for ten minutes. If provider termination fails, the server retries and retains session state until it confirms termination. Audio still travels directly between your device and OpenAI. Overseas rate-limit counters stop affecting requests after their UTC day ends. Automatic cleanup is scheduled within 48 hours; delayed platform alarms can delay physical deletion.
The overseas iOS keyboard receives a revocable, account-bound, rewrite-only credential, valid for at most 30 days. The backend stores its hash, account and random installation ID, expiry and a non-secret ordering counter. It checks current Premium entitlement on the server. It is stored in protected shared Keychain on iOS. Local sign-out immediately disables the credential; successful server revocation ends its authority. These records contain no typed text, and the keyboard never receives your account access or refresh token. Overseas iOS purchase and restore now use the separate RevenueCat integration described in Section 6.6.
6.6 Overseas iOS RevenueCat billing
Overseas iOS purchases are paid through Apple and managed with RevenueCat (revenuecat.com). We provide RevenueCat with your random Natively account identifier, App Store purchase receipts and transaction information, and technical app/device information collected by its purchasing SDK. We do not provide your chat messages, keyboard text, audio, email or password to RevenueCat. We never receive your payment card number. RevenueCat processes purchase data outside mainland China under its privacy policy (https://www.revenuecat.com/privacy). The mainland-China app does not initialize or link this SDK and continues to use the domestic StoreKit verification service.
Our overseas backend verifies subscription and one-time purchase records with RevenueCat and keeps an account-linked subscription snapshot, transaction identifiers, product and environment, purchase times, credited and used balances, refunds and temporary voice reservations in Neon. Voice reservations are settled using server-measured usage. Account deletion removes access to balances and detaches raw account identifiers from purchase and reservation records; limited transaction evidence and a one-way account identifier hash remain to prevent the same purchase being credited again. There is currently no automatic expiry for this payment anti-replay evidence. RevenueCat and Apple may retain purchase records under their own policies and obligations. Deleting Natively does not cancel an Apple subscription. Manage or cancel it in App Store settings.
6.7 Optional product usage analytics
Optional product usage analytics is off until you separately choose Allow. We collect account-linked action names, timing, app/build/update versions, distribution channel, random event/session identifiers, content identifiers, durations and allowlisted outcomes to understand usage and failures and exclude internal testing. We never include typed text, chat content, recordings or advertising identifiers in these events. Mainland-China events stay on the domestic server; overseas events stay on the overseas plane. You can turn this off in Privacy & subscriptions: local collection stops and pending app/keyboard events are cleared immediately; the account setting syncs when online. Other devices learn the change when they reconnect. Uploaded event details and classification audit entries expire after 90 days (hourly cleanup); account preferences, classification and first-observed time remain until account deletion. Events are deleted with the account. The app queue holds up to 1,000 events; the iOS keyboard holds up to 200 content-free events and sends them through the companion app when it next opens. Events aged 7 days or more are not uploaded and are removed when the app next processes the queue; closed apps cannot erase local bytes at a deadline. Backups follow Section 9.1. Declining does not restrict any feature.
7. Third-party services
Natively uses the following third parties to operate:
- RevenueCat (revenuecat.com) — overseas iOS purchase and subscription management only; receives the purchase/account information described in Section 6.6. It is not used by the mainland-China build.
- OpenAI (api.openai.com) — the AI provider for rewriting, chat, coaching, speaking reports, and direct WebRTC voice calls in the overseas build. Your text and audio are processed under OpenAI’s API data-use terms.
- Cloudflare (cloudflare.com) — hosts the overseas API edge, private generated-audio storage, rate limits and password-recovery email delivery. Cloudflare may log standard request metadata (such as IP address and request timestamp) under its privacy policy.
- Neon (neon.tech) — hosts the overseas relational database, including account data and the non-sensitive chat memory profile described in Section 6.
- Alibaba Cloud / Aliyun (aliyun.com) — hosts the mainland-China Natively API, Postgres, and Redis data plane and may provide the contracted Bailian text-AI service for that build.
- Volcengine Ark and Doubao (volcengine.com) — may provide mainland-China text AI; Doubao provides the mainland-China realtime voice service and receives the live call audio, bounded continuity context, and transcript needed to conduct the call.
- Apple — provides the iOS platform, App Store, StoreKit, and TestFlight; processes App Store subscription payments; determines introductory-offer eligibility; signs transaction information returned to the app; and sends subscription-status notifications to our backend. Apple’s data practices are governed by Apple’s privacy policy.
- Google — provides the Android platform and Google Play, and processes Google Play subscription payments. Google’s data practices are governed by Google’s privacy policy.
We do not share your data with any other third parties. We do not sell your data, ever.
8. Children’s privacy
Natively is intended for users 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has used Natively, please contact us and we will take appropriate action.
9. Your rights
You have the right to:
- Stop using Natively at any time. Simply uninstall the app or disable the keyboard in iOS Settings → General → Keyboards.
- Clear what any AI chat persona remembers about you at any time, from Settings → Chat memory or that persona’s profile inside the chat.
- In the mainland-China build, initiate permanent account deletion inside the app at Settings → Account & data → Delete account. You may also contact legal@trynatively.app about deletion or another privacy-rights request.
- Ask questions about how your data is handled at legal@trynatively.app.
9.1 Mainland-China account deletion
Account deletion is available without requiring a support call or email. It is irreversible. If your account is linked to Sign in with Apple, the app first asks you for a fresh Apple authorization; our domestic backend verifies that it belongs to the linked Apple account and asks Apple to revoke the app’s token before erasing the account.
After the domestic backend confirms deletion, it removes your login record (including email/password hash, where applicable), linked sign-in identifiers, refresh sessions, chat memories, learning and practice records, feedback and reports, subscription-entitlement snapshot, account-linked keyboard credential and installation association, and voice, N-key, and learning balances. The app then signs out and clears app-managed local state belonging to that account, including chat/progress references, the shared keyboard credential and accepted-rewrite queue, its account-owned daily reminder, and app-owned cache copies created for cropped avatars or compressed chat images. Cleanup is restricted to Natively’s own cache directory; original photos or videos in your Photos library or saved outside Natively remain under your control and are never deleted by this process.
Deleting Natively does not cancel an App Store subscription. You can continue deletion without cancelling, but to prevent future Apple charges you must manage or cancel the subscription separately in App Store subscriptions. Deletion removes account-linked purchased balances and history. An App Store subscription tied to the deleted account is not transferred to a new Natively account and cannot be restored there; deleted history and consumable balances are not restored.
We retain only the following limited records after deletion:
- De-identified Apple transaction and top-up evidence needed to reject duplicate credit, reconcile payments, process refunds or fraud, and meet financial obligations. It may include transaction or purchase IDs, product, amount/currency, dates, balance-after values, and a signed-payload digest, but no account ID, email, or linked sign-in identifier.
- The account-free keyboard generation fence described in Section 6.2, which remains unlinkable random-device ordering metadata.
- A one-way SHA-256 marker of the deleted random user ID for no more than 366 days, used only to reject already-issued or concurrently rotated credentials, make a retried deletion safe, and enforce deletion safeguards whenever a retained database backup is restored.
- Account-related transient Redis state is removed during successful completion; independently bounded entries also expire under their normal limits, including five-minute report replay and rate-limit records of no more than 48 hours.
- Historical encrypted database backups can still contain pre-deletion data until they expire under the backup lifecycle, currently no more than 365 days. They are isolated from the live service, are not used to provide or personalize the product, and any disaster restoration must reapply deletion safeguards before serving traffic.
9.2 Overseas account deletion
Permanently delete your account in Settings → Account & data → Delete account. Linked Apple sign-in requires fresh Apple authorization and server-side revocation first. A deletion marker blocks account access and delayed writes. The backend removes account/sign-in records, refresh sessions, persona memories, server learning/practice records, feedback/reports, subscription records, keyboard credentials, private synthesized audio and call quota/report state. Active calls must terminate before completion is acknowledged. The app clears its managed local account data after confirmation; your original system-library photos and videos are untouched.
Failed external cleanup leaves the account blocked and is retried. A minimal cleanup queue holds the account ID only while cleanup is pending. A one-way SHA-256 marker of the deleted random user ID protects against replay and restored data for 366 days. After completed deletion, expired markers are removed by hourly cleanup; outages can delay physical cleanup. Incomplete deletion remains blocked until cleanup succeeds, even beyond that period. Voice objects retain content-free deletion fences against late requests. Non-account-linked keyboard ordering fences can remain. Provider-managed historical backups follow configured provider retention; deletion does not imply instant erasure of every backup byte. Deletion protection must be reapplied before service resumes from a restored backup.
Account deletion does not automatically cancel a previously purchased app-store subscription; manage it with the store to prevent future charges.
10. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the following rights regarding your personal information:
- Right to know the categories of personal information we collect and how we use them (described throughout this policy).
- Right to delete the personal information we hold about you.
- Right to correct inaccurate personal information.
- Right to opt out of the “sale” or “sharing” of personal information for cross-context behavioral advertising. Natively does not sell or share personal information for these purposes.
- Right to non-discrimination — we will not deny service, charge different prices, or provide different quality of service if you exercise any of these rights.
To exercise these rights, email us at the address in Section 15 (Contact). We verify requests using the random user ID stored on your device.
11. EEA, UK, and Switzerland Privacy Rights
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation (GDPR) and equivalent laws apply to our processing of your personal data.
- Data Controller: Natively Lab, Inc. Contact details are in Section 15.
- Legal basis for processing: We process the text you submit for rewriting or chatting on the basis of contract performance under Article 6(1)(b) GDPR — to provide the service you have requested. If you join our waitlist, we process your email address on the basis of your consent under Article 6(1)(a) GDPR, which you can withdraw at any time.
- International data transfers: When you use Natively from the EEA, UK, or Switzerland, your text is transferred to the United States for processing by OpenAI and may transit Cloudflare’s global edge network. These transfers are protected by the Standard Contractual Clauses (SCCs) approved by the European Commission, and equivalent UK and Swiss addenda.
- Your rights: In addition to the rights listed in Section 9, you have the right to data portability, the right to object to processing, and the right to lodge a complaint with your local data protection supervisory authority.
- Retention: We do not retain your rewrite text or your chat transcript on our servers. Your chat memory profile (Section 6) is retained until you delete it. Rate-limit data expires after 48 hours. A mainland-China keyboard credential can authorize requests for at most 30 days and stops authorizing immediately when revoked; its credential row and token hash are deleted on revocation. The minimal last-authenticated account-to-installation association described in Section 6.2 may remain until a later authenticated rebind or account deletion, when it is removed. The account-free keyboard generation fence described in Section 6 is retained long-term to stop delayed requests from restoring old access; it is also covered by your deletion rights and, after account deletion, is unlinkable random-device ordering metadata. The limited deletion records and historical-backup lifecycle are described in Section 9.1. Waitlist email addresses are retained until you request deletion or until Natively ceases operation.
12. Data location
The overseas build uses Cloudflare for the API edge, Neon for relational data, and OpenAI for AI processing; OpenAI’s servers are located in the United States. The mainland-China build uses a separate Natively backend, Postgres, Redis, and contracted AI services hosted inside mainland China. Its user text, continuity context, memory profile, report transcript, and voice-call audio are not synchronized to the overseas plane; domestic voice follows device → Natively domestic gateway → Doubao inside mainland China.
13. Security
Data in transit is encrypted using HTTPS/TLS, encrypted WebRTC, or WSS as appropriate. Our backend uses authenticated, short-lived request or call-session tokens to prevent unauthorized access. The mainland-China keyboard uses a separate time-limited, revocable credential with only rewrite scope; our server stores only its SHA-256 hash, and invalid, expired, revoked, mismatched, or stale-generation operations fail closed. The binding counter orders credential changes but does not authenticate them. Permanent provider credentials are never shipped in the app.
14. Changes to this policy
We may update this policy from time to time. When we do, we’ll update the “Last updated” date at the top. For significant changes, Natively will ask you to re-confirm acceptance on next launch, and we’ll notify users via the app or email (if you’ve joined our waitlist).
15. Contact
If you have questions, concerns, or requests related to this policy, please email us at legal@trynatively.app. We read every message.
中文
1. 我们是谁
Natively(“我们”、“本应用”)是一款 iOS 自定义键盘,外加一个配套应用,帮你写出、说出更地道的英语。键盘会把你的英语改写得像母语者一样;应用还包含一个 AI 聊天功能,你可以和对话角色练习,并让我们点评(coach)你自己发的消息。Natively 由 Natively Lab, Inc.(一家特拉华州公司,主要办公地点位于美国加州尔湾)开发和运营。
如对本政策有任何疑问,请联系我们:legal@trynatively.app
2. 本政策的范围
本政策解释了 Natively 收集哪些信息、如何使用,以及你的权利。由于 Natively 是一个键盘,我们希望特别清楚地说明:你输入文字时,我们能看到什么、不能看到什么。
3. 我们收集的内容
你在使用 Natively 作为当前键盘时输入的文字。当你点击“改写”按钮时,你输入的文字会被发送到我们的服务器,由 AI 模型改写。
你在应用内 AI 聊天里发送的消息,以及你让我们“点评”(分析)的消息,连同生成回复所需的近期对话内容。这些会被发送到我们的服务器,用于生成回复、中文标注或点评反馈。
你在 AI 聊天中主动选择或拍摄的照片会随消息发送,让 AI 朋友可以回应。拍摄视频时,原视频保留在设备上,只发送一张预览帧。只有在你主动开始拍摄或录音后,应用才会访问相机或麦克风。
当你开始与 AI 朋友语音通话时,App 会携带一份有限的连续上下文:该角色线程里最近最多 8 条已成功送达的纯文字消息,以及该角色已保存的非敏感人物记忆。发送失败的消息、照片、视频和语音消息不会带入。通话时,实时语音服务会把文字转录返回给 App;如果生成口语报告,该转录会发送给我们的后端及当前版本使用的 AI 服务商来评估口语。
通话音频路由版本决定。海外版通过 WebRTC 在你的设备与 OpenAI 之间直接传输,不经过我们的后端。中国大陆版的路径是「你的设备 → Natively 国内网关 → 豆包实时语音服务」;网关为完成通话必须实时转发音频和转录事件,但不会录音、持久化存储或记录其内容。
如你购买海外版 Natively Premium 或中国大陆版 Natively Pro 订阅,相关的订阅与购买信息。付款由 Apple App Store 或 Google Play 处理,而非我们 —— 我们绝不会看到或收到你的卡号或账单信息。在 iOS 上,Apple 判断新订阅优惠资格,并向 App 提供经过签名的交易信息。为了解锁高级功能并在你的多台设备间同步订阅,App 会把该签名交易信息发送给我们的后端;Apple 也可能把经过签名的订阅状态通知直接发送给我们的后端。这些信息包括例如套餐、试用是否生效,以及续订或到期日期。
我们不会收集以下内容:
- 你在密码框中输入的任何内容。Natively 会检测密码输入框(secure text field),并在这些场景下完全禁用 AI 处理。任何数据都不会离开你的设备。
- 你在使用其他键盘(如系统键盘)时输入的内容。
- 你的通讯录、精确位置,或与你主动使用的功能无关的其他设备数据。
- 你的姓名或其他身份识别信息,除非你主动提供(例如在聊天、个人资料或支持请求中)。如你创建邮箱账号,我们必然会收集该邮箱用于登录;社交登录则会提供验证该账号所必需的标识符。
3.1 已接受键盘改写的暂存
如果你单独开启「将已接受的键盘改写带到这里」(默认关闭),一条改写的前后文本只有在你接受且键盘确认已成功插入后,才会进入设备本地的 App Group 待确认队列。该队列最多 20 条,绝不上传;仅 API 成功或只展示建议都不会写入。
3.2 中国大陆版键盘会员
在中国大陆版中,已登录的配套 App 会把键盘随机安装 UUID 发送给我们的国内后端,以领取一枚权限严格受限、可撤销的键盘凭证。每次签发或撤销请求还会发送一个非秘密、单调递增的绑定值,让服务器无需信任设备时间也能拒绝延迟到达的旧变更。这会让服务器把你当前的 Natively Pro 状态应用到这台键盘。免费次数归属于该键盘安装;已购 N 键余额则同时绑定购买账号与该安装,因此同一键盘切换账号不会转移任一账号的余额。凭证和绑定值都不包含你输入的文字,不能作为通用账号会话,也不能证明 Natively Pro 权益。
3.3 中国大陆版 Deck/Slang 使用信息
在中国大陆版中,当你已登录且 Deck/Slang 体验比较启用时,我们会记录学习入口是否展示、阅读会话开始或结束、卡片浏览、模式切换、主动收藏表达,以及手动或自动播放是否开始。记录包括你的账号 ID、由该账号决定的固定比较分组、实验 ID、事件名称及 ID、Deck/Slang 模式、阅读会话 ID、事件发生和服务器接收时间;适用时还包括表达/卡片 ID 和会话时长。这些是与账号关联的使用记录,不是匿名统计。其中不含你输入的正文、搜索词、自定义表达正文、聊天消息、录音、邮箱或键盘安装 ID。
我们用这些记录比较两种学习入口体验,计算回访、阅读、收藏、播放及切换情况,并改进该功能。自动播放与手动播放分开记录。这些记录发送至国内后端,不同步到海外数据平面。保留与删除方式见第 6.3 节。
4. 关于 Full Access(完全访问)
使用 AI 改写功能时,你必须在 iOS 设置 → 通用 → 键盘 → 键盘 → Natively 中开启“允许完全访问”。这是 iOS 系统要求,用于允许键盘扩展与我们的服务器通信。
未开启 Full Access 时,Natively 作为普通输入键盘工作,AI 功能不可用,任何文字都不会离开你的设备。
5. 我们如何处理你的文字
当你触发 AI 改写时:
- 文字通过加密 HTTPS 连接发送给当前版本的后端。海外后端运行在 Cloudflare Workers 上并转发给 OpenAI;中国大陆后端只转发给中国大陆境内签约的 AI 服务商。
- 改写结果会返回你的设备。Natively 不会在自有服务器上持久化保存改写文字;服务商根据其 API 数据使用条款处理。
当你使用应用内 AI 聊天,或点按你自己的某条消息进行“点评”时:
- 在你首次聊天前,我们会请求你的明确同意,把你的消息共享给我们的 AI 服务商。在你同意之前,不会发送任何内容。
- 你的消息、近期对话,以及一份简短的记忆档案(见第 6 节)会通过 HTTPS 发送给当前版本的 AI 服务商,用于生成回复、中文标注或点评反馈。海外版使用 OpenAI;中国大陆版使用中国大陆境内的签约服务商。你主动选择或拍摄的照片也可能随消息发送;视频只发送一张预览帧,原视频不会上传。
- 我们会指示系统不要抽取或存储敏感信息(如健康、性、宗教、政治或财务细节)。服务商依其适用的 API 数据使用条款处理输入。
当你和 AI 朋友进行语音通话时:
- 拨号时,App 会发送该 AI 朋友线程里最近最多 8 条已成功送达的纯文字消息,以及该角色已有的非敏感记忆档案,让通话能承接文字对话。发送失败的消息、媒体和语音消息不会带入。这份通话专用副本只用于初始化当前会话,不会写入服务器的完整聊天历史表。在中国大陆 stack 中,网关交接数据最多在 Redis 保留 150 秒,WebSocket 取走时原子删除,未取走则自动过期。原始记忆档案仍按第 6 节保留,直到你主动清除。
- AI 朋友会先说一句由服务器生成的简短欢迎语。海外版的加密音频在你的设备与 OpenAI 之间直连。中国大陆版的加密音频路径是「设备 → Natively 国内网关 → 豆包实时语音服务」。国内网关只在内存中转发通话所需的音频和转录事件,不会录音、持久化存储或记录内容。
- 生成口语报告时,App 会通过 HTTPS 把捕获的文字转录发送给我们的后端及当前版本使用的 AI 服务商。网络或上游短暂故障最多自动重试 2 次(等待 1 秒、2 秒);如果同一稳定报告任务仍在服务器生成中,App 可在最长 46 秒的有限窗口内再做最多 5 次幂等状态检查,存活的服务器 claim 会阻止这些检查启动第二次 AI 生成。最终失败后,你可以主动点击手动重试。服务器每次处理后都会丢弃原始转录;Natively 不缓存、不记录其内容。为了让超时请求返回同一份报告,而不是再调用一次 AI,通过 schema 验证的报告结果可在 5 分钟内回放,其中可能含有用于反馈的短句引用。
中国大陆 iOS 通过国内后端验证 StoreKit 购买;海外 iOS 通过 RevenueCat 验证订阅及消耗型购买、恢复并同步状态(见第 6.6 节)。对于支持的购买:
- 付款本身完全由 Apple App Store 或 Google Play 处理。你的卡号和账单信息发给 Apple 或 Google —— 绝不发给我们。
- 在中国大陆 iOS 版,StoreKit 会把 Apple 签名的交易信息返回给 App,再由 App 发送给我们的国内后端。后端验证 Apple 签名并保存由此产生的订阅状态;中国大陆版还保存第 6.4 节所述的验证记录;状态变化时,Apple 也会发送经过签名的服务器通知。这样高级功能就能在你的多台设备间保持同步。没有任何支付卡数据会到达我们的服务器。
5.1 已接受改写的处理
可选的暂存开关是 App 发给键盘的本地指令。关闭时键盘会清除待确认队列。App 通过非破坏性 peek 读取待确认项,只在内存中展示供你决定,并且只会在你收藏或忽略后逐条确认(ACK)。
5.2 中国大陆版消耗型购买退款
中国大陆版「购买记录」中,每笔消耗型购买都有一个独立、默认关闭的同意开关。你开启后,若 Apple 为审核退款请求信息,我们的国内服务器会向 Apple 提供该笔交易标识、交付状态、已使用比例、退款建议,以及已取得同意和未提供试用内容的标记。不发送你的账号 ID、邮箱、键盘文字、聊天正文或录音。退款结果由 Apple 决定。你可随时关闭开关;不同意或撤回不影响申请退款。撤回会停止后续发送,但无法收回 Apple 已收到的数据。接受一般隐私政策不会自动打开此开关。
国内服务器保存购买使用计数、同意版本和时间,以及适用时的撤回时间;另保存请求截止时间、发送字段快照、发送尝试和结果、签名载荷摘要,用于退款处理、防重复及对账,不在此记录表保存原始签名载荷。删号会删除同意记录;移除账号关联后的有限交易退款凭证仍保留,目前没有更短的自动删除期限。备份按第 9.1 节处理。Apple 按其隐私政策为退款处理保留已接收的信息;对 Apple 所持副本的访问或删除请求可前往 privacy.apple.com 提交。
6. 我们存储的内容
在你的设备上:
- 一个随机生成的键盘安装 ID(UUID)。它用于使用频率限制和该安装的免费次数。在中国大陆版中,它还会选中由当前账号与该安装共同拥有的已购 N 键余额,并按第 6.2 节所述关联;它不是你的账号 ID。
- 你的应用偏好设置、聊天对话历史、本地媒体 URI、已完成通话卡片和已生成的口语报告。聊天记录与拍摄的原视频保留在设备上;我们不会在服务器上保存一份完整聊天历史。
- 如果报告仍在生成或最终失败,通话转录只保留在本地重试存储中。它最多只能用于重试 24 小时,报告成功后立即删除。到达 24 小时后将无法重试;App 下次加载聊天/报告功能时会全局扫描并删除过期重试转录(App 关闭时无法在后台到点删除本地字节)。
在我们的服务器上:
- 你的随机键盘安装 ID 和每日请求计数(海外使用 Cloudflare Durable Objects,中国大陆使用 Redis),以及用于限制键盘凭证签发、保护账号免受滥用的短期客户端 IP 计数。这些频率限制记录会在 48 小时内自动过期。
- 一份简短的聊天“记忆档案”(保存在当前版本独立数据平面的关系数据库中):AI 角色记住的少量关于你的非敏感信息,用于保持对话连贯 —— 例如你告诉它的名字、你提到的城市,或你聊到的兴趣。我们会指示抽取程序跳过敏感类别(健康、性、宗教、政治、财务、精确位置)。这些会一直保留,直到你删除:你可以随时在「设置 → 聊天记忆」,或在聊天里该角色的资料页,清除任意角色记住的内容。
- 仅在中国大陆通话中,最近文字快照和记忆上下文的一份通话专用副本可能在 Redis 中保留最多 150 秒,用于从 HTTP token 请求交接给 WebSocket 网关。首次成功取走时即删除,或在未使用时自动过期;它不是永久聊天记录。
- 为确保报告重试幂等,已完成且通过 schema 验证的报告结果可以匿名用户 ID 和报告 ID 为 key 在 5 分钟内回放;原始通话转录不会被缓存。这个短暂窗口避免 HTTP 响应丢失后重复扣费或生成不同报告;结果可能含报告中展示的短句引用。满 5 分钟后结果不可再访问;国内 Redis 由 key TTL 强制过期,海外 Cloudflare Durable Object 会在截止时间调度物理删除,但平台重试 alarm 时,物理清理可能有短暂延迟。
- 如你加入候补名单,你主动提供的邮箱地址会存储在一个独立命名空间,仅用于发送 Natively 上线及产品更新通知。你可随时发邮件请求删除。
- 如你订阅,则存储你的订阅状态(例如:生效中、试用中或已过期;套餐;以及续订或到期日期),以你的用户 ID 关联。我们根据 App 发送的 Apple 签名交易信息得出该状态,并通过 Apple 的签名服务器通知更新状态,以便在你的多台设备上使用高级功能。其中不含任何支付卡数据。
我们不会在服务器上持久化存储你的改写文字、聊天照片或视频预览帧、语音通话音频或原始报告转录,也不保存你的完整聊天记录。临时通话上下文和报告结果存储如上所述;海外通话另见第 6.5 节。
6.1 已接受改写的保留
如你选择开启,最多 20 条已接受的键盘改写前后内容会存放在本地 App Group 待确认存储中。暂存文件使用 iOS 文件保护且不进入备份。每条会在 24 小时后失效,并在下次访问队列时删除;忽略、关闭开关或清除本机数据也会删除。你明确收藏的一条会转存到设备本地「我的表达」,保留至你删除该表达或清除本机数据,绝不上传。
6.2 中国大陆版键盘凭证保留
在你的设备上,中国大陆版会把权限严格受限的键盘凭证、所属账号、键盘安装 UUID 和到期时间作为一个原子 bundle,保存在受保护的共享 Keychain 中;bundle 仍只含这四个字段。raw 凭证绝不会写入 MMKV、日志、文件或 App Group UserDefaults;App Group UserDefaults 只保存 fail-closed 的 disabled 标记和彼此独立的 SHA-256 失效标记。退出登录或切换账号时,App 会先禁止读取凭证,再尝试删除 Keychain bundle;即使 iOS 未能删除其中字节,App 和键盘也都不能继续使用。凭证最长 30 天过期,也可由我们的后端撤销;键盘不会收到你的普通账号 access token 或 refresh token。另外,配套 App 会在宿主私有、WhenUnlockedThisDeviceOnly 的 iOS Keychain 中,为每个键盘安装保存一个非秘密、持久单调递增的绑定 counter;每次签发或撤销网络请求前先持久预留下一个正的安全整数。该 counter 不与键盘共享,也不是认证、授权或 Natively Pro 权益证明。在服务器上,国内 Postgres 会为当前凭证保存键盘 UUID、账号 ID、到期时间以及凭证的 SHA-256 hash,绝不存 raw 值。撤销会删除该凭证并立即终止其权限;过期凭证会在被呈现,或同一账号之后申请新凭证时删除。为了余额归属和账号生命周期清理,一份最小化的“最后认证账号↔键盘安装”关联可在撤销凭证后继续保留;后续通过认证的绑定会覆盖它,删除账号时会将它删除。免费次数和限流仍以键盘 UUID 为 key;已购 N 键余额同时以账号和键盘 UUID 为 key,因此同一安装上的其他账号不能继承。另一份不含账号的 fence 只保存随机键盘 UUID、最后接受的 counter 和更新时间,不含账号 ID、credential/token、token hash、输入文字或订阅状态。只有严格大于已存值的 counter 才能改变绑定;该 fence 会长期保留,防止延迟旧请求复活已撤销访问或覆盖更新绑定。它受你的删除权覆盖;账号关联数据删除后,任何仍保留的 fence 只是不再可关联账号的随机设备排序元数据。
6.3 中国大陆版 Deck/Slang 数据保留
本机按账号保存阅读模式偏好、阅读位置、自动朗读偏好,以及最多 1,000 条待上传的交互事件。超过 29 天的事件不再上传,并在 App 下次处理队列时删除;App 关闭时无法到点删除本地字节。服务器确认接收的事件会从本机队列移除。
在国内服务器上,这些使用记录会保持账号关联,保留至删除账号;目前没有更短的自动清理期限。删号会从在线数据库移除这些记录,App 同时清理对应的账号本机状态。历史备份按第 9.1 节处理。
6.4 中国大陆版购买验证记录
对于中国大陆版 App Store 订阅,我们处理 Apple 签名交易和通知载荷(JWS),用于验证购买及核对权益。除订阅状态外,国内后端还保存与账号关联的验证记录:交易及原始交易 ID、商品、购买/到期/撤销/签名时间、正式或沙盒环境、优惠与购买归属信息、通知及处理状态、适用时的错误代码,以及签名载荷的 SHA-256 摘要。该记录表不保存原始 JWS。这些记录用于购买验证、防止重复入账、退款与对账,不含支付卡数据。删号会删除账号关联的权益快照和余额;有限购买凭证在移除账号关联后,按第 9.1 节保留。
6.5 海外版账号、语音与键盘数据
海外版在 Neon 保存邮箱和密码 hash(绝不保存明文密码)、关联登录标识、refresh 凭证 hash 和订阅状态。退出请求到达服务器后会撤销当前 refresh token 家族;即使断网,本机退出也会清除设备会话。除删号外,已签发的 access token 最长一小时内可能继续有效。找回密码通过 Cloudflare Email 向账号邮箱发送一次性重置码;服务器只存 hash,十五分钟后失效,过期记录由每小时清理任务移除。重置成功会更新密码、废止未用重置码并撤销 refresh 会话;已有 access token 仍按上述短期到期规则处理。
个性化聊天朗读音频在 Cloudflare R2 私有桶按账号分区,最长缓存七天;播放须验证同一登录账号,禁止公共缓存。合成语音包含回复正文,可能涉及聊天内容,与实时通话音频不同。七天后音频不再可访问,物理清理由配置的桶生命周期执行。删号会清理账号私有音频,并阻止延迟后台写入。
海外通话由服务器向 OpenAI 交换 WebRTC 会话描述,保留通话 ID 并执行挂断截止时间;手机不再收到可复用的 OpenAI 凭证。有上限的角色记忆和近期已送达文字暂存至通话终止,终止时清除;最小化回执再保留十分钟。若服务商挂断失败,服务器会重试并保留会话状态至确认终止。音频仍在设备与 OpenAI 之间直传。海外限流计数在其 UTC 日结束后不再影响请求,并在 48 小时内调度自动清理;平台 alarm 延迟可能使物理删除稍晚完成。
海外 iOS 键盘使用绑定账号、可撤销且仅限改写的凭证,最长三十天有效;后端保存其 hash、账号和随机安装 ID、到期时间和非秘密排序 counter,并在服务端核对当前 Premium 权益。iOS 使用受保护的共享 Keychain 保存。本机退出立即停用凭证,成功的服务端撤销会终止其权限。这些记录不含输入正文,键盘不会收到普通账号 access token 或 refresh token。海外 iOS 通过 RevenueCat 处理购买和恢复,详见第 6.6 节;Android 购买尚未开放。
6.6 海外 iOS RevenueCat 支付
海外 iOS 购买由 Apple 收款,通过 RevenueCat(revenuecat.com)管理。我们向 RevenueCat 提供随机的 Natively 账号标识、App Store 购买收据及交易信息,以及其支付 SDK 收集的应用和设备技术信息;不向 RevenueCat 提供聊天消息、键盘正文、音频、邮箱或密码。我们不会收到支付卡号。RevenueCat 按其隐私政策(https://www.revenuecat.com/privacy)在中国大陆以外处理购买数据。中国大陆版不初始化或链接该 SDK,继续使用国内 StoreKit 验证服务。
海外后端向 RevenueCat 核对订阅和单次购买,在 Neon 保存账号关联的订阅快照、交易标识、商品及环境、购买时间、入账和使用余额、退款及临时语音预留。语音预留按服务器测得的使用时长结算。删号会移除余额访问权限,并从购买及预留记录解除原始账号标识;为防止同一购买重复入账,有限交易凭证和账号标识的单向 hash 会继续保留,目前没有自动到期清理期限。RevenueCat 和 Apple 可能按各自政策及义务保留购买记录。删除 Natively 账号不会取消 Apple 订阅,请在 App Store 设置中另行管理或取消。
6.7 可选的产品使用统计
可选的产品使用统计在你单独选择「允许统计」之前不会开启。我们记录与你账号关联的操作名称、时间、App/构建/更新版本、安装渠道、随机事件和会话标识、内容条目标识、时长及限定的结果类型,用于了解使用和失败情况并排除内部测试。这些事件不包含输入正文、聊天内容、录音或广告标识。中国大陆版数据保存在国内,海外版保存在海外数据面。你可在「隐私与订阅」中关闭:立即停止本机采集并清空 App 和键盘待上传事件,联网后同步账号设置;其他设备联网后同步变化。已上传事件明细和分类审计记录保留 90 天,由每小时清理任务删除;账号选择、分类和首次被观测时间保留至删号。删号会删除关联事件。本机 App 队列最多 1000 条;iOS 键盘独立队列最多 200 条不含正文的事件,在下次打开主 App 时上传。满 7 天的事件不再上传,会在 App 下次处理队列时删除;关闭的 App 无法在到期瞬间清除本机文件。备份按第 9.1 节处理。拒绝统计不影响任何功能。
7. 第三方服务
Natively 使用以下第三方服务运行:
- RevenueCat(revenuecat.com)—— 仅用于海外 iOS 购买和订阅管理,处理第 6.6 节说明的购买和账号信息;中国大陆版不使用。
- OpenAI(api.openai.com)—— 海外版的改写、聊天、点评、口语报告和直连 WebRTC 语音通话服务商。你的文字和音频按 OpenAI 的 API 数据使用条款处理。
- Cloudflare(cloudflare.com)—— 托管海外 API edge、私有合成音频、限流及找回密码邮件发送。Cloudflare 可能按其隐私政策记录标准请求元数据(如 IP 地址、请求时间戳)。
- Neon(neon.tech)—— 托管海外关系数据库,包括账号数据和第 6 节所述的非敏感聊天记忆档案。
- 阿里云 / Aliyun(aliyun.com)—— 托管中国大陆的 Natively API、Postgres 和 Redis 数据平面,并可能为该版本提供签约的百炼文字 AI 服务。
- 火山方舟与豆包(volcengine.com)—— 可能提供中国大陆文字 AI;豆包提供中国大陆实时语音服务,会接收进行通话所需的实时音频、有限连续上下文和转录。
- Apple —— 提供 iOS 平台、App Store、StoreKit 和 TestFlight 服务;处理 App Store 订阅付款;判断新订阅优惠资格;对返回给 App 的交易信息签名;并向我们的后端发送订阅状态通知。Apple 的数据处理由 Apple 隐私政策管理。
- Google —— 提供 Android 平台和 Google Play 服务,并处理 Google Play 订阅付款。Google 的数据处理由 Google 隐私政策管理。
我们不会与任何其他第三方共享你的数据。我们永远不会出售你的数据。
8. 儿童隐私
Natively 面向 13 岁及以上用户,不针对 13 岁以下儿童。我们不会有意收集 13 岁以下儿童的个人信息。如果你认为有 13 岁以下儿童使用了 Natively,请联系我们,我们将采取适当措施。
9. 你的权利
你有权:
- 随时停止使用 Natively。直接卸载应用,或在 iOS 设置 → 通用 → 键盘 中禁用本键盘即可。
- 随时清除任意 AI 聊天角色记住的关于你的内容,入口在「设置 → 聊天记忆」或聊天里该角色的资料页。
- 在中国大陆版中,通过「设置 → 账号与数据 → 删除账号」直接发起永久删除;有关删除或其他隐私权请求,也可以联系 legal@trynatively.app。
- 询问有关数据处理的任何问题,邮件至 legal@trynatively.app。
9.1 中国大陆版账号删除
删除账号不要求拨打客服或发送邮件,且不可撤销。如果账号关联了「通过 Apple 登录」,App 会先要求一次新的 Apple 授权;国内后端确认它属于当前关联的 Apple 账号,并请求 Apple 撤销本 App 的 token,然后才删除账号。
国内后端确认删除后,会移除登录记录(如适用,包括邮箱与密码 hash)、关联登录标识、refresh session、聊天记忆、学习与练习记录、反馈和举报、订阅权益快照、账号关联的键盘凭证和安装关联,以及语音、N 键和学习余额。随后 App 会退出登录,并清除属于该账号、由 App 管理的本机状态,包括聊天/进度引用、共享键盘凭证、已接受改写队列、该账号的每日本地提醒,以及裁剪头像或压缩聊天图片时由 App 生成的缓存副本。清理范围严格限制在 Natively 自有缓存目录;系统相册原件或你保存在 Natively 之外的照片、视频仍由你自行管理,删号流程绝不会删除它们。
删除 Natively 账号不会自动取消 App Store 订阅。你无需先取消即可继续删号;但若要避免 Apple 后续扣费,必须另行前往 App Store 订阅管理页管理或取消。删号会移除账号关联的已购余额和历史。绑定已删除账号的 App Store 订阅不会转移给新的 Natively 账号,也无法在新账号中恢复;已删除的历史和消耗型余额同样不会恢复。
删号后仅保留以下有限记录:
- 为防止重复入账、支付对账、退款/反欺诈及履行财务义务所需的去标识化 Apple 交易与加购凭证。其可能包括交易或购买 ID、商品、金额/币种、日期、入账后余额和签名载荷摘要,但不含账号 ID、邮箱或关联登录标识。
- 第 6.2 节所述、不含账号的 keyboard generation fence;它仍只是不可关联账号的随机设备排序元数据。
- 已删除随机用户 ID 的单向 SHA-256 标记,最长保留 366 天,仅用于拒绝已经签发或并发轮换出的凭证、让重复提交删除请求保持安全,并在恢复保留期内的数据库备份时执行删除保护。
- 成功完成删除时会清理账号相关的临时 Redis 状态;本身有期限的记录也会按原期限过期,包括 5 分钟报告回放和最长 48 小时的限流记录。
- 历史加密数据库备份在备份生命周期到期前仍可能含删号前数据,目前最长不超过 365 天。它们与在线服务隔离,不用于提供或个性化产品;灾难恢复时必须先重新应用删除保护,才能对外提供服务。
9.2 海外版账号删除
你可以在「设置 → 账号与数据 → 删除账号」永久删号。已关联 Apple 登录的账号需要重新授权 Apple 并先由服务器撤销授权。删除标记会阻断账号访问和延迟写入。后端移除账号与登录记录、refresh 会话、角色记忆、服务端学习与练习记录、反馈举报、订阅记录、键盘凭证、私有合成音频和通话额度/报告状态;正在进行的通话须先终止才能确认完成。服务器确认后 App 清理管理的本机账号数据,不触及系统相册原件。
外部清理失败时账号继续被禁用,服务器重试清理;最小清理队列仅在待清理期间保存账号 ID。已删除随机用户 ID 的单向 SHA-256 标记用于 366 天内拒绝重放及恢复后的删除核对。删号完成后,过期标记由每小时任务移除;故障可能延迟物理清理。尚未完成的删号会持续阻断至清理成功,即使超过上述期限。语音对象保留不含内容的删除 fence 以阻止延迟请求,不含账号的键盘排序 fence 可继续保留。服务商历史备份按配置的期限保留;删号不代表所有备份字节立即擦除,恢复服务前必须重新应用删除保护。
删号不会自动取消此前通过应用商店购买的订阅;要防止后续扣费,请到对应商店管理。
10. 加州隐私权(California Privacy Rights)
如你是加州居民,《加州消费者隐私法》(CCPA)及其修订法案《加州隐私权法案》(CPRA)赋予你以下与个人信息相关的权利:
- 知情权:知悉我们收集的个人信息类别及使用方式(本政策已全文说明)。
- 删除权:要求删除我们持有的关于你的个人信息。
- 更正权:要求更正不准确的个人信息。
- 选择退出权:选择退出为跨情境行为广告而进行的个人信息“出售”或“共享”。Natively 不为上述目的出售或共享个人信息。
- 反歧视权:你行使上述任何权利时,我们不会拒绝服务、收取不同价格或提供不同质量的服务。
如需行使上述权利,请发邮件至第 15 节(联系我们)所列地址。我们将使用你设备上存储的随机用户 ID 验证请求。
11. 欧洲经济区、英国及瑞士隐私权
如你位于欧洲经济区(EEA)、英国或瑞士,《通用数据保护条例》(GDPR)及同等法律适用于我们对你个人数据的处理。
- 数据控制者:Natively Lab, Inc.,联系方式见第 15 节。
- 处理的法律依据:我们处理你提交的待改写或聊天文字,依据是 GDPR 第 6 条第 1 款 (b) 项的合同履行——为你提供你所请求的服务。如你加入候补名单,我们处理你的邮箱地址依据是 GDPR 第 6 条第 1 款 (a) 项的同意,你可随时撤回同意。
- 跨境数据传输:当你在 EEA、英国或瑞士使用 Natively,你的文字会传输至美国由 OpenAI 处理,并可能经过 Cloudflare 的全球边缘网络。此类传输受欧盟委员会批准的标准合同条款(SCCs)及英国、瑞士相应附录保护。
- 你的权利:除第 9 节所列权利外,你还享有数据可携带权、反对处理权,以及向当地数据保护监管机构投诉的权利。
- 数据保留:我们不会在服务器上保留你的改写文字或聊天记录。你的聊天记忆档案(第 6 节)会保留至你删除为止。频率限制数据 48 小时后过期。中国大陆版键盘凭证最多授权 30 天,撤销后立即停止授权;凭证 row 与 token hash 会在撤销时删除。第 6.2 节所述、最小化的最后认证账号与键盘安装关联可保留至后续通过认证的重绑,或在删除账号时移除。不含账号的 keyboard generation fence 会长期保留,以阻止延迟旧请求恢复旧访问;它同样受删除权覆盖,账号删除后只是不再可关联账号的随机设备排序元数据。第 9.1 节说明了删号后有限记录及历史备份的保留期限。候补名单邮箱保留至你请求删除或 Natively 停止运营。
12. 数据位置
海外版使用 Cloudflare 作为 API edge、Neon 作为关系数据库,并使用 OpenAI 进行 AI 处理;OpenAI 的服务器位于美国。中国大陆版使用独立的 Natively 国内后端、Postgres、Redis 和中国大陆境内的签约 AI 服务。该版本的用户文字、连续上下文、记忆档案、报告转录和通话音频不会同步到海外数据平面;国内语音路径为「设备 → Natively 国内网关 → 豆包」,并全程留在中国大陆境内。
13. 安全性
传输中的数据会按路径使用 HTTPS/TLS、加密 WebRTC 或 WSS。我们的后端使用已认证的短期请求或通话会话令牌防止未授权访问;中国大陆版键盘另用一枚仅限改写 scope、限时且可撤销的凭证;服务器只存其 SHA-256 hash,无效、过期、已撤销、与 keyboard UUID 不匹配或 generation 过旧时一律 fail-closed。绑定 counter 只负责排序凭证变更,不承担认证。永久服务商凭证永不下发到 App。
14. 政策变更
我们可能会不时更新本政策。更新时,我们会修改顶部的“最后更新”日期。对于重大变更,Natively 会在下次启动时请你重新确认接受,并通过应用内提示或邮件(如果你加入了候补名单)通知用户。
15. 联系我们
如对本政策有任何问题、顾虑或请求,请发邮件至 legal@trynatively.app。我们会阅读每一条消息。
← Back to home