知在 Awareful

知在 Awareful 隐私政策 · Privacy Policy

中文

知在是一个人机信箱:你的 AI Agent 在电脑上工作时,通过 Connector 把进展、结果和需要你决定的事发送到你的 iPhone。本政策说明我们为此处理哪些信息、为什么、放在哪里、留多久,以及你能怎么做。

1. 我们处理的信息

1.1 账号信息。 创建账号时我们生成一个随机账号标识和你所选的数据区域(中国大陆或海外),并保存恢复码的哈希值。使用「通过 Apple 登录」绑定账号时,我们只保存 Apple 用户标识的哈希值;不保存你的邮箱、姓名或 Apple ID

1.2 设备信息。 每台安装知在的 iPhone 会向我们登记一把设备公钥、推送令牌(加密存储)、App 版本、系统语言、时区与最近活动时间。设备公钥用来签名你在手机上做出的回复与批准。

1.3 你的 Agent 发送的内容。 你的 Agent 通过 Connector 提交的一切都由你和你的 Agent 决定,包括:工作(Activity)的标题与状态、进展报告(Context Deposit)、向你提出的请求与你的回复、批准摘要、Source(接入的 Agent)的名称、能力声明、Connector 版本与最近联系时间。我们提供的 Agent skill 要求 Agent 不转发日志、密钥与凭据,但我们无法核验 Agent 是否遵守;请像对待任何会看到你工作内容的工具一样配置它。

1.4 订阅信息。 订阅由 Apple 处理。我们从 Apple 收到经签名的交易信息:产品、订阅状态、当前周期结束时间、原始交易号的哈希值。我们不接触你的支付卡与账单地址。

1.5 诊断信息。 只有当你在「诊断」页主动复制诊断摘要并发给我们时,我们才收到它;摘要只含连接健康状态,不含任何请求正文。

1.6 我们不收集的。 位置、通讯录、照片、广告标识符、浏览记录。知在不接入第三方分析或广告 SDK,不做用户画像,不做定向推送。

2. 我们为什么处理这些信息

我们处理这些信息的法律依据是履行与你之间的服务协议;诊断摘要基于你的主动发送。

3. 推送通知

通知经 Apple 推送服务(APNs)投递。默认推送只含最小唤醒内容(例如「你的一个 Agent 需要你」),完整内容在你打开 App 后从我们的服务器获取。你可以在「锁屏隐私」里选择锁屏上显示到什么程度:完整、仅来源、或隐藏;选择「隐藏」时通知不携带来源名。

4. 存储位置与区域

创建账号时你选择数据区域,之后不因 IP、旅行或 App Store 地区自动改变。

两个区域之间不共享用户目录,也不互相备份。我们只保留一张「账号标识 → 区域」的路由表用于账号找回和 Apple 账单通知分发,它不含任何内容数据。

5. 保留期

数据 默认保留
Activity 详情与进展报告 90 天
请求与你的回复 90 天
工作结果(Outcome) 30 天
回执 / 审计记录 180 天
推送投递日志(不含内容) 30 天
Connector 本机缓存(spool) 7 天

过了保留期的内容会被清除;时间线上会诚实地显示「这段已过保留期」的缺口,而不是假装从未存在过。当前生效的保留期在 App 内「设置 → 隐私与数据」查看。账号、设备、Source 与订阅的元数据在账号存续期间保留。

6. 我们与谁共享

我们不出售你的个人信息,也不向任何第三方提供用于广告或画像。

7. 你的权利

你可以在 App 内直接完成以下操作,无需联系我们:

订阅的取消在 iPhone「设置 → Apple 账户 → 订阅」中进行,取消订阅不会删除你的数据;账号回落到 Free 计划,历史仍可读可导出。

你也可以发邮件到 support@awareful.me 行使更正、解释说明等其他权利,我们在 15 个工作日内回复。

8. 未成年人

知在不面向不满 14 周岁的未成年人。如我们发现在未取得监护人同意的情况下收集了此类信息,会尽快删除。

9. 安全

传输全程使用 TLS;你的回复与批准由设备私钥签名,私钥不离开手机;推送令牌加密存储;Source 凭据只保存哈希;撤销设备或 Source 会立即作废未消费的批准。没有任何系统绝对安全,如发生影响你的安全事件,我们会依法及时通知你。

10. 变更

政策变更时我们更新本页并修改生效日期;重大变更会在 App 内提示。继续使用视为接受更新后的政策。


English

Awareful is a human inbox: while your AI agents work on your computer, the Connector sends progress, outcomes, and the things that need your decision to your iPhone. This policy explains what we process to do that, why, where it lives, how long it stays, and what you can do about it.

1. What we process

1.1 Account. When you create an account we generate a random account identifier, record the data region you chose (Mainland China or Global), and store a hash of your recovery code. If you bind the account with Sign in with Apple we store only a hash of the Apple user identifier; we do not store your email, name, or Apple ID.

1.2 Device. Each iPhone running Awareful registers a device public key, a push token (stored encrypted), the app version, system language, time zone, and last-seen time. The device key signs the replies and approvals you make on your phone.

1.3 Content your agents send. Everything your agents submit through the Connector is decided by you and your agents: activity titles and states, progress reports (Context Deposits), requests to you and your responses, approval summaries, the display name and declared capabilities of each Source (a connected agent), Connector version, and last contact time. The agent skill we publish instructs agents not to forward logs, secrets, or credentials, but we cannot verify that an agent complies; configure it as you would any tool that sees your work.

1.4 Subscription. Subscriptions are handled by Apple. We receive Apple-signed transaction information: product, subscription state, current period end, and a hash of the original transaction identifier. We never see your payment card or billing address.

1.5 Diagnostics. We receive a diagnostic summary only when you copy it from the Diagnostics screen and send it to us. It contains connection health only, never request content.

1.6 What we do not collect. Location, contacts, photos, advertising identifiers, browsing history. Awareful includes no third-party analytics or advertising SDKs, builds no profiles, and sends no targeted notifications.

2. Why we process it

Our legal basis is performance of our service agreement with you; diagnostic summaries are processed because you chose to send them.

3. Push notifications

Notifications are delivered through Apple Push Notification service (APNs). By default a push carries minimal wake-up content (for example, "One of your agents needs you"); the full content is fetched from our servers when you open the app. Under Lock Screen Privacy you choose how much appears on the lock screen: full, source only, or hidden. "Hidden" notifications carry no source name.

4. Where data is stored

You choose a data region when creating the account. It does not change with your IP address, travel, or App Store storefront.

The two regions share no user directory and do not back each other up. We keep only an "account identifier → region" routing table for account recovery and Apple billing notifications; it contains no content.

5. Retention

Data Default retention
Activity detail and progress reports 90 days
Requests and your responses 90 days
Outcomes 30 days
Receipts / audit records 180 days
Push delivery logs (no content) 30 days
Connector local spool 7 days

Content past its retention window is purged; the timeline shows an honest "beyond retention" gap rather than pretending nothing was there. The retention currently in effect is shown in the app under Settings → Privacy & Data. Account, device, Source, and subscription metadata are kept for the life of the account.

6. Who we share with

We do not sell your personal information and do not share it with anyone for advertising or profiling.

7. Your rights

You can do the following directly in the app without contacting us:

Cancelling a subscription is done in iPhone Settings → Apple Account → Subscriptions. Cancelling does not delete your data; the account falls back to the Free plan and history stays readable and exportable.

For correction, explanation, or other requests, email support@awareful.me; we respond within 15 business days.

8. Children

Awareful is not directed at children under 14. If we learn we have collected such information without guardian consent we will delete it promptly.

9. Security

All transport uses TLS; your replies and approvals are signed by a device private key that never leaves the phone; push tokens are stored encrypted; Source credentials are stored only as hashes; revoking a device or Source immediately voids unconsumed approvals. No system is perfectly secure; if an incident affects you we will notify you as required by law.

10. Changes

When this policy changes we update this page and its effective date; material changes are announced in the app. Continued use after a change means you accept the updated policy.