IdeoraXM Studio

PRIVACY · 隐私

Your ideas.
Your choices.

你的灵感,
由你掌握。

Ideora Privacy Policy · Effective September 12, 2026

1. About this policy

XM Studio develops Ideora, a native app for recording ideas and organizing projects. This policy explains how the app processes information, when it leaves your device, and how to contact us. It applies to Ideora and this support website.

2. Information and how we use it

  • Content you create or import: voice recordings, transcripts, notes, project and group details, tags, progress, references, imported media, skills, and AI outputs. The app stores these to provide capture, playback, search, editing, filing, project execution and recovery from archive.
  • Settings and credentials: your selected AI provider, endpoint, model, language and consent choices. User-provided API keys are stored in the device Keychain and sent to the selected service to authenticate API requests. They are not placed in project records or sent to our support team.
  • Purchase information: Apple's StoreKit provides transaction and entitlement information so Ideora can unlock and restore Pro. Apple processes payments; Ideora does not receive your full card details. Pro is a one-time purchase, not an auto-renewing subscription.
  • Support messages: when you contact us, we receive your email address and whatever details or attachments you choose to send. We use them to answer the request, troubleshoot and handle privacy requests.

Ideora does not include advertising or third-party behavioral analytics, and we do not sell your personal data or use your project content for advertising.

3. Device storage, Apple and iCloud

Ideora stores app content on your device. Supported records, including recordings and imported attachments, may also sync through Apple's CloudKit in your private iCloud account when available. Apple processes that data to provide iCloud storage and synchronization. iCloud is not an XM Studio server. Apple Watch transfers captured ideas to your paired iPhone.

Microphone access is used for voice capture. Speech-recognition access is used to transcribe audio and interpret voice commands. The app prefers on-device recognition when enabled and supported. If it is unavailable or you turn it off, Apple's speech service may receive audio and contextual recognition hints, such as relevant titles. You control these permissions in iOS Settings. See Apple's privacy information.

4. AI data sharing and consent

Before an external AI request, Ideora shows the selected recipient and server, explains the data and purposes below, and asks you to agree or cancel. Entering an API key is not consent. Declining leaves capture, manual editing and filing available. Permission is stored per provider and endpoint; a changed recipient requires new permission.

What is sent: depending on the action, requests can contain idea text and voice transcripts; titles, tags and internal record identifiers; project and group names, descriptions, progress and updates; related ideas, reference text and earlier AI results; questions and answers; custom instructions; and enabled skill descriptions, instructions and text resources. Project context can include a list of projects for filing suggestions. Your chosen service receives the API key for authentication and standard connection metadata such as IP address, request timing and model selection.

Why: to organize, refine and merge ideas, ask follow-up questions, generate project outputs, interpret voice commands, select useful skills, list available models and test the connection. Raw recordings, photos and video files are not uploaded by the app to these AI APIs. Text transcribed or extracted from your content may be included.

Who receives it: OpenAI is the default provider. Optional providers are listed below. Requests go to the service you select, not to every provider. OpenRouter is a routing service and forwards requests to the provider serving your selected model; review its provider routing and privacy settings. An Ollama server you configure receives text even if you call it “local”; its operator and any cloud models it routes to determine subsequent processing.

On-device MLX: inference runs on your device and does not send your prompts to an AI provider. Downloading a model requires a network connection to the model host, which can receive normal connection metadata.

5. Available external AI services

Service / 服务API host / 接收地址
OpenAIapi.openai.com
Ollama Cloudollama.com
DeepSeekapi.deepseek.com
Qwen / Alibaba Cloud 通义千问dashscope.aliyuncs.com
Moonshot / Kimi 月之暗面api.moonshot.cn
Zhipu / GLM 智谱open.bigmodel.cn
Doubao / Volcano Engine 豆包 / 火山引擎ark.cn-beijing.volces.com
xAIapi.x.ai
Mistral AIapi.mistral.ai
OpenRouteropenrouter.ai + selected model provider / 所选模型服务商
Groqapi.groq.com
Perplexityapi.perplexity.ai
SiliconFlow 硅基流动api.siliconflow.cn
Ollama LocalThe server address you configure

Provider references: OpenAI privacy · OpenAI business data · Ollama privacy · OpenRouter privacy · OpenRouter provider policies. For other providers, review the privacy and data-processing terms in the provider account you use before granting access.

6. Protection, retention and international processing

We require third parties we engage to process personal data to provide the same or an equal level of protection as described in this policy, including purpose limitation, confidentiality, appropriate security and applicable deletion obligations. Standard cloud API connections use HTTPS; a user-configured Ollama HTTP endpoint does not encrypt traffic. Use only a server you trust.

Optional AI services operate under the account and terms you choose. Their retention, safety monitoring, training choices, subprocessors and processing countries can differ. We do not claim that every provider keeps zero logs or that permission withdrawal removes prior requests. Provider data may be processed outside your country. Contact us if a service's practices appear inconsistent with this policy so we can investigate and restrict the affected integration where necessary.

App content remains until you delete it or manage it through device and iCloud controls. Archiving keeps records and is not deletion. Support correspondence is kept only as needed to resolve the request and meet applicable obligations. Apple and AI providers control their own retention; use their account controls or contact them for deletion of data they already received.

7. Your controls and requests

Revoke AI sharing at Settings → About → Data & Privacy → Revoke All AI Permissions. This stops future requests until you agree again; a request already sent cannot be recalled. You can delete saved API keys in model settings, choose on-device MLX, edit or delete app content, and manage microphone, speech and iCloud access in iOS Settings. Depending on your location, you may have rights to access, correct, delete or restrict processing of personal data. Contact us using the support address below. We cannot access or erase your private iCloud account or your separate AI account on your behalf.

8. This website and policy changes

This support site does not ask for an account and has no advertising or analytics added by XM Studio. It stores only your language preference in browser local storage. The hosting provider may process IP addresses and normal request logs to deliver and secure the website. External links and email services have their own privacy policies. We will update this page and its effective date when the policy changes; material changes to AI recipients or the consent disclosure require renewed permission in the app.

9. Contact XM Studio

For support or a privacy request, tell us the relevant feature and your request. Do not send passwords, API keys or sensitive project data. Return to support.