苔光 Daymoss

苔光 Daymoss

隐私政策
Privacy Policy

中文

1. 适用范围与联系方式

本政策适用于苔光 Daymoss、支持网站,以及你主动向我们发送的支持邮件。1.0(Build 2)是本地记录版,不包含云端餐食识别。下述可选 AI 处理仅适用于带有“自动识别餐食”功能的新版本;该功能目前尝试中,需完成服务配置和验证后才能使用。开发者及运营者为 Hai Cheng Huang。隐私或支持问题请联系 daymoss@charlex.me

生效及最后更新日期:2026 年 9 月 22 日。

2. 你在 App 中记录的内容

餐食、手动运动、习惯、照片、时间、备注、数量、目标及相关历史保存在你设备的应用空间。无需账号。App 没有账号或记录同步服务器,没有广告或第三方行为分析 SDK。本地记录版不上传记录。支持自动识别的新版本仅在你明确同意后发送所分析餐食的照片副本和可选说明,具体见第 3 节;不会上传整个记录库。我们不出售这些内容,也不将其用于广告或模型训练。

App 使用本机偏好保存单位、首页顺序、显示方式、提醒设置和是否曾请求健康访问等选项。核心本地记录不要求连接 Apple 健康或开启通知。

3. 照片、相机与贴纸

拍照时才请求相机权限;使用系统照片选择器时,App 仅接收你选择的照片。保存的照片副本可能经过缩放、压缩及方向调整,不是原文件的无损存档。新导入照片经过重新绘制,不保留原文件的相机及位置元数据。

照片习惯使用设备上的 Apple Vision 生成贴纸;处理失败不会删除已保存的照片。这项处理始终在设备上完成。1.0(Build 2)的餐食热量需手动填写,不发送给 AI 服务。

在支持自动识别的新版本中,首次发送前会说明用途和服务方,由你选择是否开启。开启后,新保存的餐食照片会用于识别;历史餐食不会因开启而批量上传,需由你逐条主动分析。发送内容仅为压缩、重新编码且移除相机及位置元数据的照片副本,以及你提供的可选食物说明;照片画面本身仍可能包含个人信息,请避免拍入无关人物、文件或私密内容。健康数据、习惯照片和其他记录不会随餐食请求上传。

照片和说明经苔光在 Cloudflare 上的代理发送到 OpenRouter,再路由至运行 DeepSeek V4.1 Flash 的推理服务方,用于识别食物、估计份量和热量。数据会离开设备,可能在你所在地区之外处理;我们不承诺固定的处理地区。OpenRouter 密钥仅保存在服务端,不放入 App。分析结果保存于本机,失败也保留原记录;估算可能不准确,你可更正食物、份量或热量,也可完全手动记录。

苔光代理不持久保存照片、说明或模型输出,不缓存识别响应。请求只允许路由至 OpenRouter 标记为符合零数据保留(ZDR)及不收集内容用于训练要求的端点;无符合要求的可用端点时返回失败,不自动放宽要求。我们不启用 OpenRouter 的输入输出内容日志或内容用于产品改进选项。ZDR 不是“所有服务均无日志”:OpenRouter 可保留用量、耗时等请求元数据,其 ZDR 定义也允许端点的隐式内存缓存。具体见 OpenRouter ZDR 说明数据处理说明隐私政策

为提供免费识别配额和防止滥用,App 在钥匙串保存一个随机安装标识,不使用广告标识。Cloudflare 接收请求 IP;代理将安装标识和 IP 分别转换为按日变化的带密钥摘要,仅在活动数据中保留这些摘要对应的配额计数、请求标识和处理状态,最长 48 小时。Cloudflare 的数据库恢复副本可能保留更久,其时间点恢复窗口为过去 30 天;这些副本同样不包含照片、说明或识别结果。Cloudflare 为基础设施运行和安全处理技术信息的做法另见其隐私政策。这些信息不用于广告跟踪。

你可在 App 设置中关闭自动识别。关闭后不再开始新请求,并取消 App 中尚未完成的识别;已经发出的内容无法从上游的处理中撤回。拒绝或撤销同意不影响保存照片、已有本地结果或手动记录。钥匙串中的安装标识可能在删除 App 后继续保留;关闭识别后不会再随识别请求发送,清除本地记录不会自动清除服务器尚未过期的防滥用计数。

4. Apple 健康

你主动连接后,App 请求读取体重、静息心率、睡眠、训练,以及相关活动能量和步行跑步、骑行、游泳距离。读取结果仅用于设备上的展示、历史回看及汇总。App 不上传 HealthKit 数据,不写入或删除 Apple 健康原始样本,也不使用健康数据进行广告、营销或数据挖掘。

原始健康测量值使用可重新读取的内存缓存,不写入苔光的导出备份,不复制到小组件。为避免重复计算运动,App 保存你确认的来源选择及关联样本标识。手动记录上的关联标识与选择随该记录保存在本机,也包含在记录备份中;健康来源之间的选择保存在本机偏好,不包含在手动导出备份中。

你可以在 Apple 健康中管理访问权限,并在苔光“设置 → 健康数据”清除本机健康缓存。没有显示样本可能有多种原因,App 不会仅凭无数据判断你拒绝了读取权限。

5. 主屏幕、锁定屏幕小组件与提醒

小组件启用内容显示时,主 App 向同一设备上自己的扩展共享当天本地餐食及手动运动记录摘要、习惯名称与进度、适用的照片缩略图。不会共享 Apple 健康指标、完整原图或备注。组件配置列表可能显示习惯名称。

你可以在“设置 → 小组件”关闭内容显示。App 会清理共享内容并请求系统刷新,刷新可能有延迟。屏幕上的内容可能被他人看见,锁屏显示也受系统设置控制。

习惯提醒默认关闭,主动开启时才请求通知权限。提醒在 iPhone 本地安排,不使用开发者的远程推送服务器;标题可包含习惯名称。你可以关闭提醒或通过系统设置管理通知预览。

6. 备份、分享与系统服务

手动导出备份包括记录、习惯、目标历史、关联照片和贴纸,以及手动运动上的健康关联标识与来源选择。不包含 Apple 健康原始测量值、健康来源之间的选择、提醒或显示偏好。备份没有额外的密码加密,请选择可信的保存位置与接收人。恢复备份前会校验内容并请求确认,确认后替换当前本地记录、习惯和照片。

“本地保存”不表示数据绝不会离开设备。iCloud 或电脑的设备备份、系统文件服务,以及你主动导出或分享的内容,都可能在其他位置保存副本,具体取决于系统设置及你选择的服务。App 本身不提供自动跨设备同步。Apple 提供的设备、商店及诊断服务依其规则处理相关信息。

7. 保留、删除与控制

本地记录保留至你删除它们或移除相应应用数据。你可在 App 删除单条记录,或通过“设置 → 数据与隐私”清除本地记录、习惯和照片。照片文件清理失败时,App 会显示提示;请根据提示处理,而不要将部分清理视为全部删除。

删除苔光记录不会删除 Apple 健康原始数据、系统照片图库、已经导出或分享的文件及设备备份副本;请在相应位置另行管理。显示偏好和曾请求权限的标记可能继续保留,清除记录不等于撤销系统授权。开发者无法远程访问或找回你未备份的本地记录。

8. 你主动联系支持时

发送邮件后,我们及提供邮件投递和存储的服务商会处理你的邮箱地址、邮件内容和你主动附上的附件,仅用于答复、排查问题及处理你的请求。App 的反馈诊断文本包含应用版本、系统版本和你填写的说明,不会自动附上个人记录、健康数据或照片。打开邮件草稿或系统分享面板不等于已经发送。

请勿发送完整备份、健康信息或私密照片,除非你主动决定这些内容确有必要;发送前可以删去无关信息。支持信息仅在处理请求、必要的后续支持、安全或法律需要期间保留。你可以通过支持邮箱请求查阅、更正或删除已发送给我们的信息;当地法律要求保留的部分除外。

9. 访问本网站时

支持与隐私页面通过 Cloudflare 提供。为传送页面、维护安全及可靠性,托管服务可能处理 IP 地址、请求时间、浏览器信息和访问路径等技术信息,具体按其服务与隐私政策处理。网页不会接收你 App 内的记录或健康数据。

本网站不设置自有分析或广告脚本,不使用跟踪 Cookie,也没有在线表单或文件上传入口。点击邮件链接会打开你选择的邮件应用;发送的内容按上面的支持邮件说明处理。

10. 政策变更

若功能或数据处理方式改变,我们会更新本页及适用的 App 内说明。需要新增授权或云端处理的功能会在使用前给出相应说明与选择。有关本政策或你的隐私请求,请联系 daymoss@charlex.me

English

1. Scope and contact

This policy covers Daymoss, its support website, and support emails you choose to send. Version 1.0 (Build 2) is a local journaling edition without cloud meal recognition. The optional AI processing below applies only to newer versions offering automatic meal recognition. This feature is in development and requires service configuration and verification before use. The developer and operator is Hai Cheng Huang. Contact daymoss@charlex.me for privacy or support requests.

Effective and last updated: September 22, 2026.

2. Content you record in the app

Meals, manually entered workouts, habits, photos, dates, notes, quantities, goals, and related history are stored in the app’s space on your device. No account is required. The app has no account or journal-sync server, advertising, or third-party behavioral analytics SDK. The local edition does not upload records. New versions offering recognition send only the selected meal photo copy and optional description after explicit consent, as described in section 3; they do not upload your record library. We do not sell this content or use it for advertising or model training.

Local preferences store options such as units, home card order, display settings, reminders, and whether Health access has been requested. Core local journaling does not require Apple Health access or notifications.

3. Photos, camera, and stickers

Camera permission is requested when you take a photo. When you use the system photo picker, the app receives only the photos you select. Saved copies may be resized, compressed, and orientation-corrected; they are not lossless archives of the original files. Newly imported photos are redrawn without retaining the original camera or location metadata.

Photo habits use Apple Vision on the device to create stickers; failure does not delete a saved photo. This processing stays on the device. Version 1.0 (Build 2) supports manually entered meal calories and does not send photos to AI services.

In newer versions that support recognition, you choose whether to enable it after seeing the purpose and providers, before anything is sent. Once enabled, newly saved meal photos are analyzed. Enabling it does not upload historical meals in bulk; you must start their analysis individually. The request contains a compressed, re-encoded photo copy with camera and location metadata removed, plus your optional food description. The visible image may still contain personal information; avoid including unrelated people, documents, or private content. Health data, habit photos, and other records are not included.

A Daymoss proxy hosted on Cloudflare sends the photo and description to OpenRouter, which routes them to an inference provider running DeepSeek V4.1 Flash to identify food and estimate portions and calories. Data leaves your device and may be processed outside your region; no fixed processing region is promised. The OpenRouter key stays on the server and is not included in the app. Results are saved on your device, and failure preserves the record. Estimates may be inaccurate; you can correct food, portions, and calories, or record them manually.

The Daymoss proxy does not persist photos, descriptions, or model output, and does not cache recognition responses. Requests are restricted to endpoints OpenRouter classifies as meeting zero data retention (ZDR) and no content collection for training requirements. If no eligible endpoint is available, the request fails without relaxing those requirements. We do not enable OpenRouter input/output content logging or its content-use opt-in. ZDR does not mean every service keeps no logs: OpenRouter may retain request metadata such as usage and latency, and its ZDR definition permits implicit in-memory endpoint caching. See OpenRouter ZDR, data collection, and its privacy policy.

To provide a free recognition allowance and prevent abuse, the app keeps a random installation identifier in the device Keychain; it is not an advertising identifier. Cloudflare receives the request IP address. The proxy converts the installation identifier and IP separately into keyed digests that change daily, retaining only associated quota counts, request identifiers, and processing status in active storage for up to 48 hours. Cloudflare database recovery copies may persist longer, with a point-in-time recovery window covering the past 30 days. These copies likewise contain no photos, descriptions, or recognition results. Cloudflare separately handles infrastructure and security information under its privacy policy. This information is not used for advertising tracking.

Turn off automatic recognition in the app settings to prevent new requests and cancel unfinished recognition in the app. Content already sent cannot be recalled from upstream processing. Declining or withdrawing consent does not prevent photo storage, access to existing local results, or manual recording. The installation identifier in Keychain may survive app removal. Disabling recognition stops sending it with recognition requests; clearing local records does not immediately remove unexpired server abuse-prevention counters.

4. Apple Health

After you choose to connect, the app requests read access to body mass, resting heart rate, sleep, workouts, and related active energy and walking/running, cycling, and swimming distances. Results are used only for on-device display, history, and summaries. The app does not upload HealthKit data, write or delete original Apple Health samples, or use health data for advertising, marketing, or data mining.

Original health measurements use a refreshable in-memory cache. They are not written to Daymoss export files or shared with widgets. To avoid counting a workout twice, the app stores your confirmed source choices and linked sample identifiers. Links and choices attached to a manual workout are stored with that record locally and included in its backup. Choices between Health sources are stored in local preferences and excluded from manual exports.

You can manage permissions in Apple Health and clear the local health cache under Settings → Health Data in Daymoss. Missing samples may have several causes; the app does not infer a denied read permission from an empty result.

5. Home Screen and Lock Screen widgets and reminders

When widget content is enabled, the app shares today’s local meal and manual workout summaries, habit names and progress, and applicable photo thumbnails with its own extension on the same device. It does not share Apple Health measurements, full original photos, or notes. Widget configuration may display habit names.

You can disable content under Settings → Widgets. The app clears shared content and asks the system to refresh; the refresh may be delayed. Other people who can see your screen may see widget content. Lock Screen visibility also depends on system settings.

Habit reminders are off by default. Notification permission is requested when you choose to enable them. Reminders are scheduled locally on the iPhone, without a developer-operated remote push server. Titles may contain habit names. You can turn off reminders or manage notification previews in system settings.

6. Backups, sharing, and system services

Manual exports include records, habits, goal history, related photos and stickers, and Health links and source choices attached to manual workouts. They exclude original Apple Health measurements, choices between Health sources, reminders, and display preferences. Backup files have no additional password encryption; choose trusted storage and recipients. Restore validates the file and asks for confirmation before replacing current local records, habits, and photos.

“Stored locally” does not mean data can never leave your device. iCloud or computer device backups, system file services, and files you export or share may create copies elsewhere, depending on your settings and chosen services. The app itself does not provide automatic cross-device sync. Apple’s device, store, and diagnostic services handle applicable information under their own rules.

7. Retention, deletion, and your controls

Local records remain until you delete them or remove the relevant app data. Delete individual records in the app, or clear local records, habits, and photos under Settings → Data & Privacy. If photo-file cleanup fails, the app displays a message; follow that message rather than treating partial cleanup as complete deletion.

Deleting Daymoss records does not delete original Apple Health data, items in your system photo library, previously exported or shared files, or device backup copies. Manage these separately in their respective locations. Display preferences and permission-request markers may remain; clearing records does not revoke system permissions. The developer cannot remotely access or recover local records you have not backed up.

8. When you contact support

If you send an email, we and the services that deliver and store email process your email address, message, and attachments you choose to provide, only to reply, troubleshoot, and handle your request. The app’s feedback text includes the app version, operating system version, and your description. It does not automatically attach personal records, health data, or photos. Opening an email draft or a share sheet does not send a message by itself.

Avoid sending a complete backup, health information, or private photos unless you decide it is necessary; remove unrelated details before sending. Support information is retained only as needed to handle the request, necessary follow-up support, security, or legal obligations. Email us to request access, correction, or deletion of information you have sent, subject to any legally required retention.

9. When you visit this website

Cloudflare serves the support and privacy pages. To deliver pages and maintain security and reliability, the hosting service may process technical information such as IP addresses, request times, browser information, and requested paths, under its services and privacy policy. These pages do not receive records or health data from your app.

This website has no first-party analytics or advertising scripts, tracking cookies, online forms, or file upload feature. Email links open your chosen mail app. Messages you send are handled as described in the support-email section above.

10. Changes to this policy

If features or data practices change, we will update this page and the relevant in-app information. Features requiring new permissions or cloud processing will provide appropriate information and choices before use. Contact daymoss@charlex.me about this policy or your privacy requests.