PRIVACY · 隐私
Your ideas.
Your choices.
你的灵感,
由你掌握。
Ideora Privacy Policy · Effective September 12, 2026
Ideora 隐私政策 · 生效日期:2026 年 9 月 12 日
1. About this policy
1. 关于本政策
XM Studio develops Ideora, a native app for recording ideas and organizing projects. This policy explains how the app processes information, when it leaves your device, and how to contact us. It applies to Ideora and this support website.
XM Studio 开发 Ideora,这是一款用于记录灵感和管理项目的原生应用。本政策说明信息如何被处理、何时离开设备,以及如何联系我们,适用于 Ideora 和本支持网站。
2. Information and how we use it
2. 数据来源与用途
- Content you create or import: voice recordings, transcripts, notes, project and group details, tags, progress, references, imported media, skills, and AI outputs. The app stores these to provide capture, playback, search, editing, filing, project execution and recovery from archive.
- 你创建或导入的内容:录音、转写、笔记、项目和分组信息、标签、进度、参考资料、导入媒体、技能及 AI 产出。应用存储这些内容,用于记录、播放、搜索、编辑、归档、项目执行和归档恢复。
- Settings and credentials: your selected AI provider, endpoint, model, language and consent choices. User-provided API keys are stored in the device Keychain and sent to the selected service to authenticate API requests. They are not placed in project records or sent to our support team.
- 设置与凭据:所选 AI 服务、地址、模型、语言和授权选择。你提供的 API 密钥保存在设备钥匙串中,仅用于向所选服务验证 API 请求,不写入项目记录,也不发送给支持团队。
- Purchase information: Apple's StoreKit provides transaction and entitlement information so Ideora can unlock and restore Pro. Apple processes payments; Ideora does not receive your full card details. Pro is a one-time purchase, not an auto-renewing subscription.
- 购买信息:Apple StoreKit 提供交易及权益信息,用于解锁和恢复 Pro。付款由 Apple 处理,Ideora 不获取完整银行卡信息。Pro 为一次性买断,不是自动续费订阅。
- Support messages: when you contact us, we receive your email address and whatever details or attachments you choose to send. We use them to answer the request, troubleshoot and handle privacy requests.
- 支持邮件:你联系我们时,我们会收到你的邮箱及你主动提供的信息、附件,用于回复、排查问题和处理隐私请求。
Ideora does not include advertising or third-party behavioral analytics, and we do not sell your personal data or use your project content for advertising.
Ideora 不包含广告或第三方行为分析,我们不出售个人数据,也不将项目内容用于广告。
3. Device storage, Apple and iCloud
3. 设备存储、Apple 与 iCloud
Ideora stores app content on your device. Supported records, including recordings and imported attachments, may also sync through Apple's CloudKit in your private iCloud account when available. Apple processes that data to provide iCloud storage and synchronization. iCloud is not an XM Studio server. Apple Watch transfers captured ideas to your paired iPhone.
Ideora 在设备上存储内容。在 iCloud 可用时,支持的记录(包括录音和导入附件)还可能通过 Apple CloudKit 同步到你的私人 iCloud 账户。Apple 为提供云端存储和同步处理这些数据;iCloud 并非 XM Studio 的服务器。Apple Watch 记录的灵感会传输到配对的 iPhone。
Microphone access is used for voice capture. Speech-recognition access is used to transcribe audio and interpret voice commands. The app prefers on-device recognition when enabled and supported. If it is unavailable or you turn it off, Apple's speech service may receive audio and contextual recognition hints, such as relevant titles. You control these permissions in iOS Settings. See Apple's privacy information.
麦克风权限用于录音;语音识别权限用于转写及语音指令。在设置开启且设备支持时,应用优先使用设备端识别。若设备端识别不可用或被关闭,Apple 语音服务可能收到音频及相关标题等识别提示。你可以在系统设置中管理权限。参阅 Apple 隐私说明。
4. AI data sharing and consent
4. AI 数据共享与授权
Before an external AI request, Ideora shows the selected recipient and server, explains the data and purposes below, and asks you to agree or cancel. Entering an API key is not consent. Declining leaves capture, manual editing and filing available. Permission is stored per provider and endpoint; a changed recipient requires new permission.
向外部 AI 发送请求前,Ideora 会展示所选接收方和服务器,解释以下数据范围与用途,并提供同意或取消选项。输入 API 密钥不等于同意共享数据。拒绝后仍可记录、手动编辑和归档。授权按服务商及地址分别保存,更换接收方需重新授权。
What is sent: depending on the action, requests can contain idea text and voice transcripts; titles, tags and internal record identifiers; project and group names, descriptions, progress and updates; related ideas, reference text and earlier AI results; questions and answers; custom instructions; and enabled skill descriptions, instructions and text resources. Project context can include a list of projects for filing suggestions. Your chosen service receives the API key for authentication and standard connection metadata such as IP address, request timing and model selection.
发送内容:根据操作,请求可能包含灵感文本和语音转写、标题、标签和内部记录标识;项目或分组名称、说明、进度和更新;相关灵感、参考文本和历史 AI 结果;提问及回答;自定义指令;已启用技能的说明、指令和文本资源。为建议归档位置,上下文可能包含多个项目的列表。所选服务还会收到用于身份验证的 API 密钥,以及 IP 地址、请求时间、所选模型等标准连接信息。
Why: to organize, refine and merge ideas, ask follow-up questions, generate project outputs, interpret voice commands, select useful skills, list available models and test the connection. Raw recordings, photos and video files are not uploaded by the app to these AI APIs. Text transcribed or extracted from your content may be included.
用途:整理、优化和合并灵感,生成追问和项目产出,理解语音指令,选择相关技能,获取模型列表及测试连接。应用不会向这些 AI API 上传原始录音、照片或视频文件;转写或提取后的文本可能包含在请求中。
Who receives it: OpenAI is the default provider. Optional providers are listed below. Requests go to the service you select, not to every provider. OpenRouter is a routing service and forwards requests to the provider serving your selected model; review its provider routing and privacy settings. An Ollama server you configure receives text even if you call it “local”; its operator and any cloud models it routes to determine subsequent processing.
接收方:默认服务商为 OpenAI,可选服务见下表。请求仅发送给你选择的服务,而非所有服务商。OpenRouter 是路由服务,会将请求转发到所选模型的服务商,请查看其路由与隐私设置。你配置的 Ollama 服务器会收到文本,即使它被称为“本地”;服务器运营者及其调用的云端模型决定后续处理方式。
On-device MLX: inference runs on your device and does not send your prompts to an AI provider. Downloading a model requires a network connection to the model host, which can receive normal connection metadata.
设备端 MLX:推理在设备内运行,不向 AI 服务商发送提示内容。模型下载需要连接模型托管服务,该服务可能收到标准连接信息。
5. Available external AI services
5. 可选外部 AI 服务
| Service / 服务 | API host / 接收地址 | |
|---|---|---|
| OpenAI | api.openai.com | |
| Ollama Cloud | ollama.com | |
| DeepSeek | api.deepseek.com | |
| Qwen / Alibaba Cloud 通义千问 | dashscope.aliyuncs.com | |
| Moonshot / Kimi 月之暗面 | api.moonshot.cn | |
| Zhipu / GLM 智谱 | open.bigmodel.cn | |
| Doubao / Volcano Engine 豆包 / 火山引擎 | ark.cn-beijing.volces.com | |
| xAI | api.x.ai | |
| Mistral AI | api.mistral.ai | |
| OpenRouter | openrouter.ai + selected model provider / 所选模型服务商 | |
| Groq | api.groq.com | |
| Perplexity | api.perplexity.ai | |
| SiliconFlow 硅基流动 | api.siliconflow.cn | |
| Ollama Local | The server address you configure | 你配置的服务器地址 |
Provider references: OpenAI privacy · OpenAI business data · Ollama privacy · OpenRouter privacy · OpenRouter provider policies. For other providers, review the privacy and data-processing terms in the provider account you use before granting access.
服务商说明:OpenAI 隐私政策 · OpenAI 企业数据说明 · Ollama 隐私政策 · OpenRouter 隐私政策 · OpenRouter 模型服务商政策。使用其他服务前,请在对应账号中查阅其隐私政策和数据处理条款。
6. Protection, retention and international processing
6. 保护、保存与跨境处理
We require third parties we engage to process personal data to provide the same or an equal level of protection as described in this policy, including purpose limitation, confidentiality, appropriate security and applicable deletion obligations. Standard cloud API connections use HTTPS; a user-configured Ollama HTTP endpoint does not encrypt traffic. Use only a server you trust.
我们要求受我们委托处理个人数据的第三方提供与本政策相同或同等程度的保护,包括用途限制、保密、适当安全措施及适用的删除义务。标准云端 API 使用 HTTPS;用户自行配置的 Ollama HTTP 地址不加密传输,请仅使用可信服务器。
Optional AI services operate under the account and terms you choose. Their retention, safety monitoring, training choices, subprocessors and processing countries can differ. We do not claim that every provider keeps zero logs or that permission withdrawal removes prior requests. Provider data may be processed outside your country. Contact us if a service's practices appear inconsistent with this policy so we can investigate and restrict the affected integration where necessary.
可选 AI 服务依据你选择的账号及条款运行,其保存期限、安全监测、训练选项、分包处理方和处理地区可能不同。我们不承诺所有服务都不留日志,也不承诺撤回授权会删除已经发送的请求。服务商可能在你所在国家或地区之外处理数据。如发现某服务的做法与本政策不一致,请联系我们,以便调查并在必要时限制相关集成。
App content remains until you delete it or manage it through device and iCloud controls. Archiving keeps records and is not deletion. Support correspondence is kept only as needed to resolve the request and meet applicable obligations. Apple and AI providers control their own retention; use their account controls or contact them for deletion of data they already received.
应用内容将保留至你删除,或通过设备及 iCloud 管理。归档会保留记录,不等于删除。支持邮件仅在解决请求及履行适用义务所需期间保存。Apple 和 AI 服务商自行管理其保存期限;对其已收到的数据,请使用对应账号的管理工具或联系服务商申请删除。
7. Your controls and requests
7. 你的选择与请求
Revoke AI sharing at Settings → About → Data & Privacy → Revoke All AI Permissions. This stops future requests until you agree again; a request already sent cannot be recalled. You can delete saved API keys in model settings, choose on-device MLX, edit or delete app content, and manage microphone, speech and iCloud access in iOS Settings. Depending on your location, you may have rights to access, correct, delete or restrict processing of personal data. Contact us using the support address below. We cannot access or erase your private iCloud account or your separate AI account on your behalf.
在「设置 → 关于 → 数据与隐私 → 撤回全部 AI 授权」撤回授权,后续请求将暂停至你再次同意;已发送的请求无法撤回。你可以在模型设置删除 API 密钥、选择设备端 MLX、编辑或删除内容,并在系统设置管理麦克风、语音识别和 iCloud 权限。依所在地区,你可能享有访问、更正、删除或限制处理个人数据的权利,请通过下方支持邮箱联系我们。我们无法代你访问或清除私人 iCloud 账户或独立 AI 账号。
8. This website and policy changes
8. 本网站及政策变更
This support site does not ask for an account and has no advertising or analytics added by XM Studio. It stores only your language preference in browser local storage. The hosting provider may process IP addresses and normal request logs to deliver and secure the website. External links and email services have their own privacy policies. We will update this page and its effective date when the policy changes; material changes to AI recipients or the consent disclosure require renewed permission in the app.
本支持站不要求注册账号,XM Studio 未添加广告或分析脚本,仅在浏览器本地存储语言偏好。托管服务商可能为交付和保护网站处理 IP 地址及标准请求日志。外部链接和邮件服务适用各自隐私政策。政策变更时,我们会更新此页及生效日期;AI 接收方或授权说明发生重大变化时,应用内需重新取得授权。
9. Contact XM Studio
9. 联系 XM Studio
For support or a privacy request, tell us the relevant feature and your request. Do not send passwords, API keys or sensitive project data. Return to support.
如需支持或提出隐私请求,请说明涉及的功能与诉求。请勿发送密码、API 密钥或敏感项目数据。返回支持页面。