Seasonturn Privacy Policy · 时令隐私政策 · 時令隱私權政策
English
Version 1.4 · Effective date: 2026-09-11
Operator / Data controller: Seasonturn, operated by an independent developer. Privacy contact: privacy@seasonturn.com
Seasonturn (时令) helps you turn text, images, voice notes, and calendar notes into editable calendar candidates that you review before anything is saved. This policy explains what the app processes and what leaves your device.
Summary
• We do not sell personal data, and we do not use third-party advertising SDKs or cross-app tracking (no IDFA, no App Tracking Transparency prompt).
• Calendar events and app records stay on your device and in Apple Calendar/EventKit. Nothing leaves your device for AI parsing unless you explicitly allow it.
• Cloud AI parsing happens only after you allow it on first use. A disclosure card in the app tells you what is sent, to whom, and why, and you choose Allow or Don't Allow.
• You can withdraw at any time by switching to on-device-only parsing under Me › AI & Privacy. After that the app sends nothing to the cloud on any path — text, image, voice, or the share extension.
• When cloud AI parsing is used, the app sends the text you submit — typed or pasted text, on-device OCR text, or an on-device speech transcript — and, for image parsing, the image you choose. The image is re-encoded before upload with EXIF/GPS metadata removed. Audio is never sent.
• Requests go to the Seasonturn backend at api.getshiling.com (Cloudflare Workers), which forwards them through OpenRouter, Inc. (United States), an AI gateway, to the GLM model endpoint operated by Z.ai (Singapore). The app never contacts OpenRouter or Z.ai directly.
• The backend does not store your content; the AI providers state that they do not store it by default or use it to train models (see Data retention for the metadata they keep).
• All network traffic between the app and the backend is encrypted in transit (HTTPS/TLS).
Your consent to cloud AI parsing
The first time an action would send your content to the cloud, Seasonturn shows a disclosure card before anything leaves your device. The card states what is sent (the text you submit, and for image parsing the image you choose; never audio), who receives it (the Seasonturn backend, which forwards it through OpenRouter in the United States to Z.ai in Singapore), and what it is used for (generating structured calendar fields only). You choose Allow or Don't Allow.
Until you answer, every cloud path is treated as declined. If you choose Don't Allow, the app keeps working with on-device-only parsing. Your answer is stored on your device only; it is not sent to the backend and is not shared with any provider. Deleting and reinstalling the app clears the answer, and the card is shown again.
You can change your mind at any time under Me › AI & Privacy. Selecting On-Device Only takes effect immediately and applies to every path — the text field, voice capture, image parsing, and anything queued by the share extension. In on-device-only mode the app makes no network request to the backend at all.
The share extension itself never uses the network. Anything it queues is parsed inside the app, and only after you have allowed cloud parsing. If you have not answered yet, the queued item waits in your Inbox with a button that opens the disclosure card.
Information processed by the app
Calendar and event content
App records — EventKit mappings, candidate cards, settings, the activity log, and calendar sync state — are stored locally on your device and are not synced to Seasonturn servers. When you approve an event, the app writes it to Apple Calendar/EventKit; that calendar data is then handled by Apple and may sync across your devices through iCloud according to your own iCloud settings.
Text, images, and voice input
If you use text, paste, image, or voice input, Seasonturn creates editable event candidates from it. Speech transcription is performed by Apple system frameworks on your device, and raw audio is never sent anywhere. Text recognition on images can also run on your device (Apple Vision OCR), and does so whenever you are offline or have selected on-device-only parsing.
Cloud AI parsing
Once you have allowed cloud AI parsing and you request parsing, the app sends the text you submit — typed or pasted text, on-device OCR text, or an on-device speech transcript — and, on the image parsing path, the image you choose. Before an image is uploaded it is re-encoded, which removes EXIF and GPS metadata, so location and camera information contained in the original file is not transmitted. The request goes to the Seasonturn backend hosted on Cloudflare Workers at api.getshiling.com, which forwards it through OpenRouter (United States) to the GLM model endpoint operated by Z.ai (Singapore) and returns structured calendar fields to the app. The app never contacts OpenRouter or Z.ai directly.
Request metadata
Alongside your content, each parsing request carries: your locale and time zone; a reference timestamp (your device's current date and time, used to resolve relative expressions such as "next Tuesday"); your week-start preference; and an App Attest key identifier generated once per installation. The key identifier is sent in clear text and is stored by the backend together with a per-installation record and a rate-limit counter. On the voice path the request also carries your device language and internal event identifiers used by the app (identifiers only — no titles, times, or other event content).
Device integrity and security signals
For production builds, Seasonturn uses Apple App Attest to protect the backend from abuse. This involves challenge, attestation, assertion, token, and key-state data used to verify that requests come from a legitimate app instance. These signals are used only for security and abuse prevention, not to identify you personally. As the network edge, Cloudflare sees the IP address a request comes from; it is used as a rate-limiting key and is not written into our application logs.
Diagnostics and reliability data
The app receives crash, hang, and performance diagnostics through Apple MetricKit. MetricKit payloads stay on your device and are never uploaded. The app also keeps parse diagnostics on your device, which include the text you submitted for parsing. The backend logs only operational metrics — route, status, request size, latency, token/cost counters, model alias, and a hashed token identifier — which are designed not to include your content.
Purchases
Subscriptions and purchases are handled by Apple through StoreKit and the App Store. Seasonturn does not collect or process your payment card details and does not operate a separate payment processor.
Legal basis for processing (EEA/UK)
Where the EU/UK GDPR applies, we rely on:
• Your consent — for cloud AI parsing of the content you submit, including any sensitive details you choose to include. Consent is collected through the disclosure card before the first cloud request, and you can withdraw it at any time by switching to on-device-only parsing under Me › AI & Privacy.
• Our legitimate interests — for securing the backend (App Attest, rate limiting), preventing abuse, and maintaining reliability, in a way that does not store your content in backend logs.
• Performance of the service you request — for creating candidates and syncing approved events to Apple Calendar/EventKit.
How information is used
Seasonturn uses the information above to:
• create editable calendar candidates that you review before saving;
• sync approved events with Apple Calendar/EventKit;
• provide on-device parsing when you choose it, or when the network or cloud parsing is unavailable;
• secure the backend with App Attest and rate limiting;
• monitor reliability, cost, and abuse without storing your content in backend logs.
Current service providers
Seasonturn relies on:
• Apple frameworks and services — EventKit, Speech, Vision/OCR, MetricKit, App Attest, and StoreKit.
• Cloudflare Workers — hosting for the Seasonturn backend at api.getshiling.com.
• OpenRouter, Inc., located in the United States — the AI gateway that forwards cloud parsing requests to the model provider. OpenRouter states that it does not store prompts or responses by default (we have not enabled its optional logging) and does not use them to train models; it keeps per-request metadata such as token counts and latency, and may sample a small number of prompts for anonymized classification.
• Z.ai (JINGSHENG HENGXING TECHNOLOGY PTE. LTD., Singapore; an indirect wholly-owned subsidiary of Zhipu AI, Beijing) — the AI model provider whose GLM model performs cloud text and image parsing. Z.ai states that it does not store content submitted through its API, that it does not use API customers' content to develop or improve its services without their explicit consent, and that API customer data is generally processed in Singapore.
These providers process information only as needed to provide the functionality, security, and reliability described here. We may change or add AI providers; when we do, we will update this section and the effective date, and material changes are announced as described under "Changes".
Your choices and rights
• You can decline cloud AI parsing on the disclosure card, and you can switch to on-device-only parsing at any time under Me › AI & Privacy.
• You can decline Calendar, Photos, Microphone, or Speech permissions; some features may not work without the related permission.
• You can edit or reject AI-generated candidates before they are saved.
• Me › AI & Privacy › Delete AI Parsing History removes the AI-origin markers from your local events and deletes the locally stored parse diagnostics. Historical Activity Log entries are kept but stop showing AI source details; to remove them as well, delete the app. Your events themselves are not deleted.
• You can delete all local app data by deleting the app from your device. Events already saved to Apple Calendar remain in Apple Calendar unless you delete them there or through Seasonturn.
Subject to applicable law (including the GDPR and California CCPA/CPRA), you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, and to withdraw consent. California residents have the right to know, delete, and correct personal information and to opt out of "sale" or "sharing" — note that we do not sell personal information and do not share it for cross-context behavioral advertising. We do not discriminate against you for exercising these rights. To make a request, contact privacy@seasonturn.com. EEA/UK users may also lodge a complaint with their local data protection authority.
Data retention
• Local app data remains on your device until you delete it, or until you delete the app.
• Calendar data written to Apple Calendar is retained according to Apple Calendar/iCloud behavior and your own iCloud settings.
• The backend does not store the text or images you submit. OpenRouter states that it does not store prompts or responses by default (we have not enabled its logging), that it retains per-request metadata such as token counts and latency, and that it may sample a small number of prompts for anonymized classification. Z.ai states that it does not store content submitted through its API; other customer data it holds is kept temporarily without a published retention period. Both providers state that they do not use your content to train models.
• The per-installation App Attest record and its rate-limit counter are stored on the backend indefinitely; there is currently no automatic expiry, and deleting the app does not remove the backend record. After you delete and reinstall the app, a new key identifier is generated and the old record is no longer used.
• Short-lived security state, such as an App Attest challenge, expires within minutes.
• Backend operational logs contain only the metrics listed above and are kept for a limited operational period.
Sensitive information and children
Seasonturn is intended for general productivity and family calendar organization, and is not directed to children under 13 (or the minimum age in your region). You may enter family, school, health, travel, or other sensitive information into calendar text. If you have allowed cloud AI parsing, that text — including any sensitive details you include — is processed by the AI provider solely to produce calendar fields, on the basis of your explicit consent. Submit only information you are comfortable processing through the parsing mode you selected; choose on-device-only parsing for anything you prefer not to send.
International processing
Seasonturn's backend and service providers may process data in locations outside your country or region. When you have allowed cloud AI parsing, the content you submit is transferred to and processed by OpenRouter in the United States and by Z.ai, which states that it generally processes API customer data in Singapore (Z.ai's parent company is based in mainland China); this transfer is based on your consent and, where required, appropriate safeguards. Seasonturn's initial release does not include mainland China; whether and when it will be offered there is a separate decision, and if a mainland China edition is introduced, its data arrangements will be described in that edition.
Changes
We may update this policy as Seasonturn changes. We will revise the version number and effective date above, and for material changes we will provide a prominent notice in the app or on this page.
Contact
Privacy contact: privacy@seasonturn.com. Product support: support@seasonturn.com. The current version of this policy is published at https://seasonturn.com/privacy. For TestFlight builds, you can also use the TestFlight feedback channel or the support contact listed in App Store Connect.
Change log
• v1.4 — cloud AI provider changed from OpenAI (US) to Z.ai's GLM model routed through OpenRouter (US); provider, retention, and processing-location statements updated accordingly.
• v1.3 — explicit consent gate, image metadata stripping, retention wording corrected, metadata list corrected, Traditional Chinese added, domain moved to seasonturn.com.
简体中文
版本 1.4 · 生效日期:2026-09-11
运营者 / 数据控制者: Seasonturn(时令),由独立开发者运营。隐私联系方式: privacy@seasonturn.com
时令(Seasonturn)帮助你把文本、图片、语音和日历笔记转成可编辑的日历候选,你确认后才会保存。本政策说明 App 处理哪些信息,以及哪些内容会离开你的设备。
各语言版本如有歧义,以英文版为准。
摘要
• 我们不出售个人数据,不使用第三方广告 SDK,也不做跨 App 追踪(无 IDFA,不弹“App 追踪透明度”授权)。
• 日历事件与 App 记录保存在你的设备本地以及 Apple 日历/EventKit 中。除非你明确允许,任何内容都不会为了 AI 解析而离开你的设备。
• 云端 AI 解析只在你首次使用时明确允许之后才会发生。App 内的披露卡会说明发送什么、发给谁、用于什么,由你选择“允许”或“不允许”。
• 你可以随时在“我 › AI 与隐私”切换为仅设备端解析以撤回同意。此后 App 在任何路径上都不会向云端发送内容 —— 文本、图片、语音、分享扩展都不会。
• 使用云端 AI 解析时,App 会发送你提交的文本 —— 输入或粘贴的文本、设备端 OCR 文本,或设备端语音转写 —— 以及在图片解析路径上,你选择的图片。图片在上传前会重新编码,去除 EXIF/GPS 元数据。音频从不发送。
• 请求发往时令后端 api.getshiling.com(Cloudflare Workers),后端再经由 AI 网关 OpenRouter, Inc.(美国)转发给由 Z.ai(新加坡)运营的 GLM 模型端点。App 不会直接联系 OpenRouter 或 Z.ai。
• 后端不保存你的内容;AI 服务商声明默认不存储你的内容,也不用于训练模型(其保留的元数据见“数据留存”)。
• App 与后端之间的网络通信均经传输层加密(HTTPS/TLS)。
你对云端 AI 解析的同意
在某个操作首次会把你的内容发往云端之前,时令会先展示一张披露卡,此时还没有任何内容离开你的设备。卡片说明发送什么(你提交的文本,以及图片解析时你选择的图片;绝不发送音频)、谁会收到(时令后端,并由它经由位于美国的 OpenRouter 转发给位于新加坡的 Z.ai)、用于什么(仅用于生成结构化的日历字段)。你可以选择允许或不允许。
在你作出选择之前,所有云端路径都按“不允许”处理。若你选择“不允许”,App 会继续以仅设备端解析工作。你的选择只保存在你的设备上,不会发送给后端,也不会共享给任何服务商。删除并重新安装 App 会清除该选择,披露卡会再次出现。
你可以随时在“我 › AI 与隐私”改变主意。选择“仅设备端”会立即生效,并适用于所有路径 —— 文本框、语音录入、图片解析,以及分享扩展排队的内容。在仅设备端模式下,App 完全不会向后端发起网络请求。
分享扩展自身从不使用网络。它排队的内容一律在 App 内解析,且只在你已允许云端解析之后才会解析。若你尚未作出选择,排队项会停留在收件箱中,并给出打开披露卡的按钮。
App 处理的信息
日历与事件内容
App 记录 —— EventKit 映射、候选卡、设置、操作记录与日历同步状态 —— 保存在你的设备本地,不会同步到时令服务器。当你确认一个事件时,App 会将其写入 Apple 日历/EventKit;该日历数据随后由 Apple 处理,并可能依你自己的 iCloud 设置在你的设备间同步。
文本、图片与语音输入
若你使用文本、粘贴、图片或语音输入,时令会据此生成可编辑的事件候选。语音转写由 Apple 系统框架在你的设备端完成,原始音频从不发送到任何地方。图片上的文字识别也可以在你的设备端完成(Apple Vision OCR);当你处于离线或已选择仅设备端解析时,一律走设备端识别。
云端 AI 解析
在你已允许云端 AI 解析并发起解析后,App 会发送你提交的文本 —— 输入或粘贴的文本、设备端 OCR 文本,或设备端语音转写 —— 以及在图片解析路径上,你选择的图片。图片在上传前会重新编码,从而去除 EXIF 与 GPS 元数据,原始文件中包含的位置与相机信息不会被传输。请求发往托管于 Cloudflare Workers 的时令后端 api.getshiling.com,后端再经由位于美国的 OpenRouter 转发给由 Z.ai(新加坡)运营的 GLM 模型端点,并把结构化日历字段返回给 App。App 绝不会直接联系 OpenRouter 或 Z.ai。
请求元数据
除内容之外,每次解析请求还会携带:你的地区与时区;一个参考时间(你设备当前的日期与时刻,用于解析“下周二”这类相对表达);你的周起始偏好;以及一个每次安装生成一次的 App Attest 密钥标识。该密钥标识以明文发送,并由后端连同每安装记录与限流计数一起保存。在语音路径上,请求还会携带你的设备语言,以及 App 内部使用的事件标识(仅标识符 —— 不含标题、时间或其他事件内容)。
设备完整性与安全信号
对于生产版本,时令使用 Apple App Attest 保护后端免受滥用。这涉及 challenge、attestation、assertion、令牌与密钥状态等数据,用于验证请求来自合法的 App 实例。这些信号仅用于安全与防滥用,不用于识别你的个人身份。作为网络边缘节点,Cloudflare 会看到请求来源的 IP 地址;它仅用作限流键,不会写入我们的应用日志。
诊断与可靠性数据
App 通过 Apple MetricKit 接收崩溃、卡顿和性能诊断。MetricKit 数据留在你的设备上,从不上传。App 还会在你的设备上保存解析诊断,其中包含你提交解析的文本。后端只记录运营指标 —— 路由、状态、请求大小、延迟、token/成本计数、模型别名,以及一个经哈希处理的令牌标识 —— 这些指标在设计上不包含你的内容。
购买
订阅与购买由 Apple 通过 StoreKit 与 App Store 处理。时令不收集或处理你的支付卡信息,也不运营独立的支付处理方。
处理的法律依据(欧盟/英国)
在适用欧盟/英国 GDPR 的情形下,我们依据:
• 你的同意 —— 用于对你提交内容的云端 AI 解析,包括你选择纳入的任何敏感信息。同意通过首次云端请求前的披露卡取得,你可随时在“我 › AI 与隐私”切换为仅设备端解析以撤回。
• 我们的正当利益 —— 用于保护后端(App Attest、限流)、防止滥用、维持可靠性,且不在后端日志中保存你的内容。
• 履行你所请求的服务 —— 用于生成候选并把你确认的事件同步到 Apple 日历/EventKit。
信息的用途
时令使用上述信息以:
• 生成可编辑的日历候选,由你确认后才保存;
• 把你确认的事件同步到 Apple 日历/EventKit;
• 在你选择、或网络与云端解析不可用时,提供设备端解析;
• 用 App Attest 与限流保护后端;
• 监控可靠性、成本与滥用,且不在后端日志中保存你的内容。
当前服务商
时令依赖:
• Apple 框架与服务 —— EventKit、Speech、Vision/OCR、MetricKit、App Attest 与 StoreKit。
• Cloudflare Workers —— 托管位于 api.getshiling.com 的时令后端。
• OpenRouter, Inc.,位于美国 —— 把云端解析请求转发给模型服务商的 AI 网关。OpenRouter 声明默认不存储提示与回复(我们未开启其可选的日志功能),也不将其用于训练模型;它会保留每次请求的元数据(如 token 数量与延迟),并可能抽取少量提示做匿名化分类。
• Z.ai(JINGSHENG HENGXING TECHNOLOGY PTE. LTD.,新加坡;北京智谱 AI 的间接全资子公司)—— 以 GLM 模型执行云端文本与图片解析的 AI 模型服务商。Z.ai 声明不存储通过其 API 提交的内容,未经明确同意不会把 API 客户的内容用于开发或改进其服务,API 客户数据一般在新加坡处理。
这些服务商仅在为提供本政策所述功能、安全与可靠性所必需的范围内处理信息。我们可能更换或新增 AI 服务商;届时会更新本节与生效日期,重大变更按“变更”一节所述方式告知。
你的选择与权利
• 你可以在披露卡上拒绝云端 AI 解析,也可以随时在“我 › AI 与隐私”切换为仅设备端解析。
• 你可以拒绝日历、照片、麦克风或语音权限;缺少相应权限时部分功能可能无法使用。
• 你可以在保存前编辑或拒绝 AI 生成的候选。
• “我 › AI 与隐私 › 删除 AI 解析历史”会清除本地事件上的 AI 来源标记,并删除本地保存的解析诊断。历史操作记录条目会保留,但不再显示 AI 来源细节;如需一并清除,请删除 App。事件本身不会被删除。
• 你可以通过从设备删除 App 来删除全部本地 App 数据。已保存到 Apple 日历的事件会留在 Apple 日历中,除非你在那里或通过时令删除它们。
在适用法律(包括 GDPR 与加州 CCPA/CPRA)允许的范围内,你可能有权访问、更正、删除或导出你的个人数据,限制或反对某些处理,以及撤回同意。加州居民有权知悉、删除和更正个人信息,并有权选择退出“出售”或“共享”—— 请注意我们不出售个人信息,也不为跨情境行为广告而共享个人信息。你行使这些权利不会受到歧视性对待。如需提出请求,请联系 privacy@seasonturn.com。欧盟/英国用户亦可向当地数据保护监管机构投诉。
数据留存
• 本地 App 数据会保留在你的设备上,直到你将其删除或删除 App。
• 写入 Apple 日历的日历数据按 Apple 日历/iCloud 行为及你自己的 iCloud 设置留存。
• 后端不保存你提交的文本或图片。OpenRouter 声明默认不存储提示与回复(我们也未开启其日志功能),会保留每次请求的元数据(如 token 数量与延迟),并可能抽取少量提示做匿名化分类。Z.ai 声明不存储通过其 API 提交的内容;其持有的其他客户数据会临时保存,未公布保留期限。两家服务商均声明不会用你的内容训练模型。
• 每安装的 App Attest 记录及其限流计数会无限期保存在后端;目前没有自动过期机制,删除 App 也不会删除后端记录。删除并重新安装 App 后会产生新的密钥标识,旧记录不再被使用。
• 短时效的安全状态(如 App Attest challenge)会在数分钟内过期。
• 后端运营日志只包含上文列出的指标,并按有限的运营周期保留。
敏感信息与儿童
时令面向通用效率与家庭日历整理,并非面向 13 岁以下(或你所在地区最低年龄)的儿童。你可能会在日历文本中输入家庭、学校、健康、出行或其他敏感信息。若你已允许云端 AI 解析,该文本(包括你纳入的任何敏感信息)将由 AI 服务商基于你的明示同意、仅为生成日历字段而处理。请只提交你愿意经所选解析模式处理的信息;对于你不希望发送的内容,请选择仅设备端解析。
跨境处理
时令的后端与服务商可能在你所在国家或地区之外处理数据。当你已允许云端 AI 解析时,你提交的内容会被传输至位于美国的 OpenRouter,并由 Z.ai 处理(Z.ai 声明其 API 客户数据一般在新加坡处理;其母公司位于中国大陆);此传输基于你的同意,并在必要时辅以适当保障措施。时令首发不含中国大陆;是否及何时在该地区提供另行决定,若推出中国大陆版本,其数据安排将在该版本中说明。
变更
我们可能随时令的变化更新本政策。我们会更新上方的版本号与生效日期;对于重大变更,我们会在 App 内或本页提供显著提示。
联系
隐私联系方式:privacy@seasonturn.com。产品支持:support@seasonturn.com。本政策的当前版本发布于 https://seasonturn.com/privacy。对于 TestFlight 版本,你也可以使用 TestFlight 反馈渠道或 App Store Connect 中列出的支持联系方式。
变更记录
• v1.4 —— 云端 AI 服务商由 OpenAI(美国)改为经 OpenRouter(美国)路由的 Z.ai GLM 模型;服务商、留存与处理地点的表述相应更新。
• v1.3 —— 新增明示同意门、图片元数据剥除、留存措辞更正、元数据清单更正、新增繁体中文、主域迁至 seasonturn.com。
繁體中文
版本 1.4 · 生效日期:2026-09-11
營運者 / 資料控制者: Seasonturn(時令),由獨立開發者營運。隱私聯絡方式: privacy@seasonturn.com
時令(Seasonturn)協助你把文字、圖片、語音與行事曆筆記,轉成可編輯的行事曆候選項目,你確認後才會儲存。本政策說明 App 處理哪些資訊,以及哪些內容會離開你的裝置。
各語言版本如有歧義,以英文版為準。
摘要
• 我們不出售個人資料,不使用第三方廣告 SDK,也不進行跨 App 追蹤(無 IDFA,不會跳出「App 追蹤透明度」授權)。
• 行事曆事件與 App 紀錄保存在你的裝置本機以及 Apple 行事曆/EventKit 中。除非你明確允許,任何內容都不會為了 AI 解析而離開你的裝置。
• 雲端 AI 解析只在你首次使用時明確允許之後才會發生。App 內的揭露卡會說明傳送什麼、傳給誰、用於什麼,由你選擇「允許」或「不允許」。
• 你可以隨時在「我 › AI 與隱私」切換為僅限裝置端解析以撤回同意。此後 App 在任何路徑上都不會向雲端傳送內容 —— 文字、圖片、語音、分享擴充功能都不會。
• 使用雲端 AI 解析時,App 會傳送你提交的文字 —— 輸入或貼上的文字、裝置端 OCR 文字,或裝置端語音轉錄 —— 以及在圖片解析路徑上,你選擇的圖片。圖片在上傳前會重新編碼,移除 EXIF/GPS 中繼資料。音訊從不傳送。
• 請求送往時令後端 api.getshiling.com(Cloudflare Workers),後端再經由 AI 閘道 OpenRouter, Inc.(美國)轉發給由 Z.ai(新加坡)營運的 GLM 模型端點。App 不會直接聯繫 OpenRouter 或 Z.ai。
• 後端不保存你的內容;AI 服務供應商聲明預設不儲存你的內容,也不用於訓練模型(其保留的中繼資料見「資料留存」)。
• App 與後端之間的網路通訊均經傳輸層加密(HTTPS/TLS)。
你對雲端 AI 解析的同意
在某個操作首次會把你的內容送往雲端之前,時令會先顯示一張揭露卡,此時尚未有任何內容離開你的裝置。卡片說明傳送什麼(你提交的文字,以及圖片解析時你選擇的圖片;絕不傳送音訊)、誰會收到(時令後端,並由它經由位於美國的 OpenRouter 轉發給位於新加坡的 Z.ai)、用於什麼(僅用於產生結構化的行事曆欄位)。你可以選擇允許或不允許。
在你作出選擇之前,所有雲端路徑都按「不允許」處理。若你選擇「不允許」,App 會繼續以僅限裝置端解析運作。你的選擇只保存在你的裝置上,不會傳送給後端,也不會分享給任何服務供應商。刪除並重新安裝 App 會清除該選擇,揭露卡會再次出現。
你可以隨時在「我 › AI 與隱私」改變主意。選擇「僅限裝置端」會立即生效,並適用於所有路徑 —— 文字輸入欄、語音輸入、圖片解析,以及分享擴充功能排入佇列的內容。在僅限裝置端模式下,App 完全不會向後端發出網路請求。
分享擴充功能本身從不使用網路。它排入佇列的內容一律在 App 內解析,且只在你已允許雲端解析之後才會解析。若你尚未作出選擇,佇列中的項目會停留在收件匣中,並提供開啟揭露卡的按鈕。
App 處理的資訊
行事曆與事件內容
App 紀錄 —— EventKit 對應、候選卡、設定、操作記錄與行事曆同步狀態 —— 保存在你的裝置本機,不會同步到時令伺服器。當你確認一個事件時,App 會將其寫入 Apple 行事曆/EventKit;該行事曆資料隨後由 Apple 處理,並可能依你自己的 iCloud 設定在你的裝置間同步。
文字、圖片與語音輸入
若你使用文字、貼上、圖片或語音輸入,時令會據此產生可編輯的事件候選項目。語音轉錄由 Apple 系統框架在你的裝置端完成,原始音訊從不傳送到任何地方。圖片上的文字辨識也可以在你的裝置端完成(Apple Vision OCR);當你處於離線或已選擇僅限裝置端解析時,一律使用裝置端辨識。
雲端 AI 解析
在你已允許雲端 AI 解析並發起解析後,App 會傳送你提交的文字 —— 輸入或貼上的文字、裝置端 OCR 文字,或裝置端語音轉錄 —— 以及在圖片解析路徑上,你選擇的圖片。圖片在上傳前會重新編碼,從而移除 EXIF 與 GPS 中繼資料,原始檔案中包含的位置與相機資訊不會被傳輸。請求送往代管於 Cloudflare Workers 的時令後端 api.getshiling.com,後端再經由位於美國的 OpenRouter 轉發給由 Z.ai(新加坡)營運的 GLM 模型端點,並把結構化的行事曆欄位回傳給 App。App 絕不會直接聯繫 OpenRouter 或 Z.ai。
請求附帶的資料
除內容之外,每次解析請求還會攜帶:你的地區與時區;一個參考時間(你裝置目前的日期與時刻,用於解析「下週二」這類相對表達);你的每週起始日偏好;以及一個每次安裝產生一次的 App Attest 金鑰識別碼。該金鑰識別碼以明文傳送,並由後端連同每安裝紀錄與流量限制計數一起保存。在語音路徑上,請求還會攜帶你的裝置語言,以及 App 內部使用的事件識別碼(僅識別碼 —— 不含標題、時間或其他事件內容)。
裝置完整性與安全訊號
對於正式版本,時令使用 Apple App Attest 保護後端免於濫用。這涉及 challenge、attestation、assertion、權杖與金鑰狀態等資料,用於驗證請求來自合法的 App 執行個體。這些訊號僅用於安全與防止濫用,不用於識別你的個人身分。作為網路邊緣節點,Cloudflare 會看到請求來源的 IP 位址;它僅用作流量限制的索引鍵,不會寫入我們的應用程式紀錄。
診斷與可靠性資料
App 透過 Apple MetricKit 接收當機、卡頓與效能診斷。MetricKit 資料留在你的裝置上,從不上傳。App 也會在你的裝置上保存解析診斷,其中包含你提交解析的文字。後端只記錄營運指標 —— 路由、狀態、請求大小、延遲、token/成本計數、模型別名,以及一個經雜湊處理的權杖識別碼 —— 這些指標在設計上不包含你的內容。
購買
訂閱與購買由 Apple 透過 StoreKit 與 App Store 處理。時令不會收集或處理你的付款卡資訊,也不營運獨立的付款處理方。
處理的法律依據(歐盟/英國)
在適用歐盟/英國 GDPR 的情形下,我們依據:
• 你的同意 —— 用於對你提交內容的雲端 AI 解析,包括你選擇納入的任何敏感資訊。同意透過首次雲端請求前的揭露卡取得,你可隨時在「我 › AI 與隱私」切換為僅限裝置端解析以撤回。
• 我們的正當利益 —— 用於保護後端(App Attest、流量限制)、防止濫用、維持可靠性,且不在後端紀錄中保存你的內容。
• 履行你所請求的服務 —— 用於產生候選項目並把你確認的事件同步到 Apple 行事曆/EventKit。
資訊的用途
時令使用上述資訊以:
• 產生可編輯的行事曆候選項目,由你確認後才儲存;
• 把你確認的事件同步到 Apple 行事曆/EventKit;
• 在你選擇、或網路與雲端解析無法使用時,提供裝置端解析;
• 用 App Attest 與流量限制保護後端;
• 監控可靠性、成本與濫用,且不在後端紀錄中保存你的內容。
目前的服務供應商
時令依賴:
• Apple 框架與服務 —— EventKit、Speech、Vision/OCR、MetricKit、App Attest 與 StoreKit。
• Cloudflare Workers —— 代管位於 api.getshiling.com 的時令後端。
• OpenRouter, Inc.,位於美國 —— 把雲端解析請求轉發給模型服務供應商的 AI 閘道。OpenRouter 聲明預設不儲存提示與回覆(我們未開啟其可選的記錄功能),也不將其用於訓練模型;它會保留每次請求的中繼資料(如 token 數量與延遲),並可能抽取少量提示做匿名化分類。
• Z.ai(JINGSHENG HENGXING TECHNOLOGY PTE. LTD.,新加坡;北京智譜 AI 的間接全資子公司)—— 以 GLM 模型執行雲端文字與圖片解析的 AI 模型服務供應商。Z.ai 聲明不儲存透過其 API 提交的內容,未經明確同意不會把 API 客戶的內容用於開發或改進其服務,API 客戶資料一般在新加坡處理。
這些服務供應商僅在為提供本政策所述功能、安全與可靠性所必需的範圍內處理資訊。我們可能更換或新增 AI 服務供應商;屆時會更新本節與生效日期,重大變更依「變更」一節所述方式告知。
你的選擇與權利
• 你可以在揭露卡上拒絕雲端 AI 解析,也可以隨時在「我 › AI 與隱私」切換為僅限裝置端解析。
• 你可以拒絕行事曆、照片、麥克風或語音權限;缺少相應權限時部分功能可能無法使用。
• 你可以在儲存前編輯或拒絕 AI 產生的候選項目。
• 「我 › AI 與隱私 › 刪除 AI 解析歷史」會清除本機事件上的 AI 來源標記,並刪除本機保存的解析診斷。歷史操作記錄項目會保留,但不再顯示 AI 來源細節;如需一併清除,請刪除 App。事件本身不會被刪除。
• 你可以透過從裝置刪除 App 來刪除全部本機 App 資料。已儲存到 Apple 行事曆的事件會留在 Apple 行事曆中,除非你在那裡或透過時令刪除它們。
在適用法律(包括 GDPR 與加州 CCPA/CPRA)允許的範圍內,你可能有權存取、更正、刪除或匯出你的個人資料,限制或反對某些處理,以及撤回同意。加州居民有權知悉、刪除和更正個人資訊,並有權選擇退出「出售」或「共享」—— 請注意我們不出售個人資訊,也不為跨情境行為廣告而共享個人資訊。你行使這些權利不會受到差別待遇。如需提出請求,請聯絡 privacy@seasonturn.com。歐盟/英國使用者亦可向當地資料保護監管機關申訴。
資料留存
• 本機 App 資料會保留在你的裝置上,直到你將其刪除或刪除 App。
• 寫入 Apple 行事曆的資料,依 Apple 行事曆/iCloud 行為及你自己的 iCloud 設定留存。
• 後端不保存你提交的文字或圖片。OpenRouter 聲明預設不儲存提示與回覆(我們也未開啟其記錄功能),會保留每次請求的中繼資料(如 token 數量與延遲),並可能抽取少量提示做匿名化分類。Z.ai 聲明不儲存透過其 API 提交的內容;其持有的其他客戶資料會暫時保存,未公布保留期限。兩家服務供應商均聲明不會用你的內容訓練模型。
• 每安裝的 App Attest 紀錄及其流量限制計數會無限期保存在後端;目前沒有自動到期機制,刪除 App 也不會刪除後端紀錄。刪除並重新安裝 App 後會產生新的金鑰識別碼,舊紀錄不再被使用。
• 短時效的安全狀態(如 App Attest challenge)會在數分鐘內過期。
• 後端營運紀錄只包含上文列出的指標,並依有限的營運週期保留。
敏感資訊與兒童
時令面向一般效率與家庭行事曆整理,並非面向 13 歲以下(或你所在地區最低年齡)的兒童。你可能會在行事曆文字中輸入家庭、學校、健康、旅遊或其他敏感資訊。若你已允許雲端 AI 解析,該文字(包括你納入的任何敏感資訊)將由 AI 服務供應商基於你的明示同意、僅為產生行事曆欄位而處理。請只提交你願意經所選解析模式處理的資訊;對於你不希望傳送的內容,請選擇僅限裝置端解析。
跨境處理
時令的後端與服務供應商可能在你所在國家或地區之外處理資料。當你已允許雲端 AI 解析時,你提交的內容會被傳輸至位於美國的 OpenRouter,並由 Z.ai 處理(Z.ai 聲明其 API 客戶資料一般在新加坡處理;其母公司位於中國大陸);此傳輸基於你的同意,並在必要時輔以適當保障措施。時令首發不含中國大陸;是否及何時在該地區提供另行決定,若推出中國大陸版本,其資料安排將在該版本中說明。
變更
我們可能隨時令的變化更新本政策。我們會更新上方的版本號與生效日期;對於重大變更,我們會在 App 內或本頁提供顯著提示。
聯絡
隱私聯絡方式:privacy@seasonturn.com。產品支援:support@seasonturn.com。本政策的目前版本發布於 https://seasonturn.com/privacy。對於 TestFlight 版本,你也可以使用 TestFlight 意見回饋管道或 App Store Connect 中列出的支援聯絡方式。
變更記錄
• v1.4 —— 雲端 AI 服務供應商由 OpenAI(美國)改為經 OpenRouter(美國)路由的 Z.ai GLM 模型;服務供應商、留存與處理地點的表述相應更新。
• v1.3 —— 新增明示同意門、圖片中繼資料剝除、留存措辭更正、請求附帶資料清單更正、新增繁體中文、主網域遷至 seasonturn.com。
Public URL: https://seasonturn.com/privacy