隐私政策
一、数据存放在哪里
- 设备本地:你的完整观展记录首先保存在设备上。
- 用户自己的 iCloud:设备启用 iCloud 且同步可用时,内容可备份到你的 CloudKit 私有数据库。记录按 iCloud 用户隔离,运营管理后台不能浏览;App 只代表当前登录的 iCloud 用户读取和写入,以完成跨设备同步。
- Aftermusée 后端:只处理账号校验、你自愿开启的分析元数据,以及艺术家公开资料缓存。
二、账号数据
使用“通过 Apple 登录”时,应用会把 Apple 身份令牌发送到 Aftermusée 后端进行校验。后端保存 Apple 用户标识符的加密哈希、内部随机账号 ID、账号创建/最近登录时间和通行证状态。应用不请求、 不保存你的姓名或邮箱地址。这些账号数据用于登录、权限、安全和账号删除。
三、可选的分析与假名化画像
“帮助改进 Aftermusée”默认关闭。只有你主动开启后,应用才会发送以下数据:
- 粗粒度资料:界面语言、系统区域中的国家/地区代码、设备类别(例如 iPhone 或 iPad);
- 作品元数据:作品名、艺术家、年代、流派、场馆、参观月份、媒介类型和你添加的标签;
- 使用数据:打开应用、创建记录、添加作品、生成展区、调整顺序、选择封面、付费墙和购买等事件;
- 处理质量:OCR/语音识别使用的引擎、语言、耗时、是否成功和字符数量,但不含识别或转写出的文字;
- 内容兴趣:查阅的艺术家标识及艺术家资料入口点击,用于了解内容偏好。
这些数据会关联到一个假名化账号,以计算留存、功能漏斗和偏好分布,因此它们不是完全匿名数据。 我们不会尝试把该账号还原成你的真实身份,也不会把它与第三方广告数据合并。
四、我们明确不收集什么
Aftermusée 后端不收集照片、视频、音频、笔记正文、OCR/语音识别正文、精确位置、通讯录、 广告标识符或跨 App 浏览活动。我们不出售数据,不投放定向广告,也不进行跨公司或跨 App 跟踪。
五、艺术家资料增强与第三方
查看艺术家资料时,应用可能把艺术家名称或 Wikidata QID 发送到 Aftermusée 后端。后端会从 Wikipedia/Wikimedia 获取公开摘要和图片并缓存;这类缓存不与账号关联。若运营者启用可选 AI 归纳,仅会把公开艺术家资料发送给配置的 AI 服务,不会发送用户照片、笔记或识别正文。
服务托管商和 Apple 可能为提供网络、计算、iCloud、登录或内购服务而处理必要的技术信息。 Aftermusée 自己的数据库不保存请求 IP 地址。
六、用途、同意与撤回
账号数据用于应用功能和安全;可选元数据用于产品分析、改进功能和理解总体内容偏好。 你可以在账号页面随时开启或关闭“帮助改进 Aftermusée”。关闭后不再发送分析数据, 本地待发送队列会被清除,服务端已保存的作品元数据、标签和使用事件也会立即删除。
七、保留、导出与删除
- 账号数据保留到你删除账号为止;可选分析数据保留到你撤回同意或删除账号为止。
- 你可以在 App 内导出本地内容,也可以查看/导出服务端持有的元数据。
- 账号页面提供“注销账户并删除云端全部数据”。操作后,Aftermusée 后端的账号及关联数据会被删除; 设备本地和你的 iCloud 私有内容不受影响,可由你在相应设备或 iCloud 中管理。
八、安全与未成年人
正式服务使用 HTTPS;会话令牌和服务端密钥应安全保存。我们采取合理措施限制数据访问, 但任何网络服务都无法保证绝对安全。本服务不以不满 14 周岁的儿童为目标。
九、政策变更与联系方式
如收集范围或用途发生实质变化,我们会更新本政策并在适当位置提示。数据控制者/运营者: Aftermusée(所见之物);联系邮箱: contactus@thefungimind.com。
Privacy Policy
1. Where data lives
Your full exhibition records are stored locally. When iCloud is enabled and sync is available, they may be backed up to your private CloudKit database. Records are isolated by iCloud user and are not browsable in the operator’s analytics backend; the app accesses them on behalf of the current iCloud user for cross-device sync. The Aftermusée backend is limited to account verification, analytics metadata you expressly opt into, and cached public artist information.
2. Account data
Sign in with Apple sends an Apple identity token to our backend for verification. We retain a cryptographic hash of the Apple user identifier, a random internal account ID, account creation and last-sign-in times, and pass status. We do not request or retain your name or email address. This data supports authentication, security, entitlements, and account deletion.
3. Optional analytics and pseudonymous profiles
“Help improve Aftermusée” is off by default. If you opt in, we collect interface language, locale country/region code, device category; artwork title, artist, date, movement, venue, visit month, media type and tags; product interaction events; OCR/speech engine, language, duration, success and character count without the recognised text; and artist lookups or artist-resource clicks. This data is linked to a pseudonymous account so we can measure retention, funnels and preference distributions. It is therefore not fully anonymous.
4. Data we do not collect
Our backend does not collect photos, videos, audio, note text, OCR or speech text, precise location, contacts, advertising identifiers, or cross-app activity. We do not sell data, serve targeted advertising, or track people across companies or apps.
5. Artist enrichment and service providers
Artist names or Wikidata QIDs may be sent to our backend, which retrieves and caches public Wikipedia/Wikimedia material without linking that cache to an account. If optional AI summarisation is enabled, only public artist material is sent to the configured AI provider. Hosting providers and Apple may process technical information necessary to provide networking, compute, iCloud, authentication, or in-app purchases. Our application database does not store request IP addresses.
6. Consent, retention, access, and deletion
You may enable or disable analytics at any time in the account screen. Disabling it clears the local queue and deletes server-side artwork metadata, tags, and usage events. Account data remains until account deletion. The app provides export tools and an in-app option to delete the backend account and all associated server data. Local and private iCloud content remains under your control.
7. Security, children, changes, and contact
Production traffic uses HTTPS and reasonable access safeguards. No network service can guarantee absolute security. The service is not directed to children under 14. Material policy changes will be disclosed in an updated policy. Controller/operator: Aftermusée; contact: contactus@thefungimind.com.