明日森林隐私政策 | Tomorrow Forest Privacy Policy
最后更新:2026 年 7 月 24 日 / Last updated: July 24, 2026
1. 我们处理的信息 / Information We Process
应用在你的设备本地保存你主动输入的推演内容、AI 结果与历史记录、语言/主题/触感等偏好和少量运行状态数据。历史默认仅保存在本地,你可以在应用内删除,或通过卸载应用删除本机应用数据。
The app stores on your device the reasoning content you actively enter, AI results and history, language/theme/haptics preferences, and limited operating-state data. History is local by default. You can delete it in the app or remove local app data by uninstalling the app.
Apple 登录是可选功能。服务端只保存由 Apple 稳定用户标识经单向哈希处理后的标识,以及必要的账户、使用次数和安全状态;不以明文保存该标识。姓名和邮箱不是提供本服务的必需信息,不用于建立公开个人资料。
Sign in with Apple is optional. The server keeps only a one-way-hashed form of Apple's stable user identifier, plus necessary account, usage, and security state; it does not retain that identifier in plain text. Name and email are not necessary to provide this service and are not used to create a public profile.
你可以在已有游客或 Apple 服务端账户中自愿绑定中国大陆手机号,用于账户追溯、申诉核验和安全风控。手机号不是登录或使用基础功能的必要条件。绑定前需要短信验证码验证;服务端不保存验证码明文,并以查找哈希和加密密文保存手机号,管理后台仅展示脱敏号码。你可在应用内申请解绑,账户注销后会删除关联的手机号绑定和未完成验证码挑战。
You may voluntarily bind a mainland China mobile number to an existing guest or Apple server account for account traceability, appeal verification, and security risk control. A phone number is not required for sign-in or basic use. SMS verification is required before binding; the server does not retain plaintext verification codes and stores the number as a lookup hash plus encrypted ciphertext. Only a masked number is shown in the admin console. You may request unbinding in the app, and account closure removes the associated binding and unfinished verification challenges.
2. 防滥用领取记录 / Anti-Abuse Claim Record
为防止用户注销后重复注册或更换登录状态反复领取首次使用次数,并防范资源滥用和安全风险,服务端保留最小化的防滥用领取记录(anti-abuse claim tombstone):不可逆 SHA-256 处理后的设备标识和/或 Apple subject 标识、首次领取时间及领取类型。该记录不保存原始标识、AI 输入输出或账户内容,不用于画像、广告、向其他用户展示或恢复已注销账户。
To prevent repeated registration or changed sign-in states from being used to repeatedly claim first-use allowances after account closure, and to prevent resource abuse and security risks, the server keeps a minimal anti-abuse claim tombstone: an irreversible SHA-256 hash of a device identifier and/or Apple subject identifier, the first-claim time, and the claim type. It does not retain original identifiers, AI inputs or outputs, or account content, and is not used for profiling, advertising, display to other users, or restoring a closed account.
我们基于提供服务所必需的安全与防作弊目的及适用法律法规允许的其他处理依据,按必要、正当、最小范围原则处理该记录。建议常规保存期限为自注销、最后一次有效使用或最后一次风控事件(以较晚者为准)起 180 天,期满后删除或不可逆匿名化。为处理未结投诉、争议、疑似欺诈/攻击、安全事件或履行法律法规要求而确有必要时,可在必要的最短期间内例外留存;因此账户注销后不会立即删除该防滥用哈希记录。
We process this record under the necessary security and anti-cheating purpose of providing the service and other bases permitted by applicable laws and regulations, following necessity, legitimacy, and data-minimization principles. The recommended ordinary retention period is 180 days after the later of account closure, last valid use, or last risk-control event; it is then deleted or irreversibly anonymized. It may be retained exceptionally for the shortest necessary period to address an unresolved complaint, dispute, suspected fraud or attack, security incident, or a legal requirement. Therefore, account closure does not result in immediate deletion of this anti-abuse hash record.
3. AI 请求与数据流向 / AI Requests and Data Flow
你主动发起推演时,完成请求所必需的文本输入、语言和请求参数会经部署在中国境内的服务端代理发送至单一通义模型服务。模型密钥只在服务端管理,应用不会要求你填写模型密钥。应用不提供用户之间的发帖、评论、私信、群组或社区功能,也不会向其他用户展示你的输入。
When you actively start a reasoning request, the text input, language, and request parameters needed to complete it are sent through a server-side proxy deployed in mainland China to one Tongyi model service. Model keys are managed only on the server and are never requested in the app. The app has no posts, comments, direct messages, groups, or community features between users, and does not show your input to other users.
我们默认不将 AI 原始输入和输出作为业务内容保存。为安全、限流、排障和投诉处理,服务端记录必要的安全日志,例如哈希化账户标识、时间、结果、风险/错误代码、来源 IP 的必要安全信息和操作记录。安全日志保存 180 天后删除或匿名化,法律法规另有要求的除外。
We do not retain raw AI inputs and outputs as business content by default. For security, rate limiting, troubleshooting, and complaint handling, the server records necessary security logs, such as a hashed account identifier, time, result, risk/error codes, necessary IP-related security information, and operation records. Security logs are deleted or anonymized after 180 days unless laws or regulations require otherwise.
Before a request reaches the model service, the server performs content-safety checks. If applicable laws, platform rules, or safety policies require rejection, the app will not call the model, display a reasoning result, or deduct the request allowance. The app will show: “根据相关法律法规要求,当前输入内容无法生成或显示推演结果,请修改后重试。” Security logs record only the time, request ID, account hash, risk code, policy version, and action result; they do not record the matched term or full input.
4. 免费使用规则 / Free-Use Rules
1.0 版本完全免费,不提供订阅、应用内购买或付费余额。游客最多可使用 5 次;首次 Apple 登录后余额为 20 次;其后按北京时间每日增加 5 次,余额上限为 20 次。使用次数只用于防滥用和资源管理,不是货币、储值或可交易权益。
Version 1.0 is completely free and has no subscriptions, in-app purchases, or paid balance. Guests may use the service up to 5 times. On first Sign in with Apple, the balance is 20 uses; afterwards it increases by 5 uses per day in Beijing time, up to a balance cap of 20. Uses are solely for abuse prevention and resource management; they are not money, stored value, or transferable rights.
5. AI 标识与内容治理 / AI Labelling and Content Governance
AI 生成内容会以文字、图标或上下文提示明确作出显式标识,并按适用要求采用不影响正常使用的隐式标识;如系统基于规则作出风险提示、拦截或排序,也会在适用位置说明。请勿输入或借助本服务生成违法违规、侵权、诈骗、暴力恐怖、淫秽色情、仇恨歧视或其他有害内容。我们可拒绝处理明显有害请求、限制使用、保全必要记录、处理投诉或依法配合主管机关。
AI-generated content is clearly given an explicit label through text, an icon, or contextual notice, and uses an implicit label that does not affect normal use where required. Where the system provides a rule-based risk notice, block, or ranking, it will be indicated where applicable. Do not enter or use the service to create unlawful, infringing, fraudulent, violent or terrorist, pornographic, hateful, discriminatory, or otherwise harmful content. We may refuse clearly harmful requests, limit use, preserve necessary records, handle complaints, or cooperate with competent authorities as required by law.
6. 你的权利与联系我们 / Your Rights and Contact
你可在设置中删除本地历史、关闭触感反馈和 iCloud 同步、解绑手机号,并删除本机 Apple 登录资料。若要注销服务端账户、删除/查询/更正个人信息、撤回同意、投诉或举报,请发送邮件至 tomorrowforest@outlook.com,并提供核验账户归属所必需的信息。核验后我们将按适用法律法规处理。
You may delete local history, turn off haptics and iCloud sync, unbind a phone number, and remove local Sign in with Apple data in Settings. To close a server account, delete/access/correct personal information, withdraw consent, make a complaint, or report content, email tomorrowforest@outlook.com and provide the information necessary to verify account ownership. We will handle the request after verification in accordance with applicable laws and regulations.
7. 未成年人与更新 / Minors and Updates
未成年人请在监护人陪同下阅读和使用本应用,并在需要时取得监护人同意。处理目的、信息类型、保存期限、第三方接入或权利行使方式发生实质变化时,我们会通过应用内或本页面更新本政策。
Minors should read and use this app with a parent or guardian and obtain consent where required. If there is a material change to purposes, information categories, retention periods, third-party access, or how rights may be exercised, we will update this policy in the app or on this page.
官方参考:《中华人民共和国个人信息保护法》;《生成式人工智能服务管理暂行办法》。
Official references: Personal Information Protection Law of the PRC; Interim Measures for the Management of Generative AI Services.