简体中文 繁體中文 English

Effective date: August 12, 2026 · Version 1.0

Privacy Policy — 年轮日记

年轮日记 is local-first. Your journal lives on your device and, if you turn on sync, in your own iCloud. The operator does not run a server that stores your diary. The App contains no third-party analytics, advertising, or tracking SDKs.

This Policy explains what data the App ("年轮日记", bundle identifier cn.rtool.nianlun, operated by developer sanmiao li, domain rtool.cn) handles, why, where it goes, and your choices. It is read together with the Terms of Service.

1. What We Collect and Where It Goes

"We" = the operator. Most data never reaches us. The table summarises each category:

DataOn deviceYour iCloud (private)Operator backend (rtool.cn)
Journal text, datesYesYes (if sync on)Only transiently when you use the Agent; not retained
Photos & thumbnailsYesYes (if sync on)Never
Weather text (your editable free text)YesYes (if sync on)Never
"Understanding about you" (Agent memory, versioned)YesYes (private CloudKit)Only transiently during an Agent request; not retained
Apple identity (Sign in with Apple)An opaque account token + membership state + monthly Agent usage counters only
Push token & reminder scheduleOnly if you enable writing reminders; used solely to deliver your reminders
Analytics / crash / ad dataNot collected at all — no such SDK is included

2. Local-First Storage and iCloud Sync

2.1 Journal entries, photos, and weather text are stored on your device using SwiftData (a local SQLite database in the App's sandbox).

2.2 If you enable iCloud sync, the App mirrors this data to your own iCloud account using a CloudKit private database (container iCloud.cn.rtool.nianlun). The operator cannot read this data. Sync requires that you are signed into iCloud and is optional; the App works fully offline.

2.3 The "understanding about you" maintained by the Agent is stored locally and synced as a single private CloudKit record — not shared, not public.

3. The Agent (AI Companion)

3.1 When you use an Agent feature (an observation, a structured chat, or an update to "understanding about you"), the App sends the current entry's text and the relevant "understanding about you" context to the operator's backend (https://rtool.cn/api/nianlun/v1) to generate a response.

3.2 Photos and weather are never sent.

3.3 After the request completes, the backend does not retain the journal, chat, or understanding content. Only aggregated usage counters (needed for the quota) are kept.

3.4 Agent outputs are generated by an AI model and may be incorrect. They are not stored permanently by the backend.

4. Accounts and Sign in with Apple

Core journaling needs no account. The App uses Sign in with Apple only when you actively enable the Agent or open the membership page. The App does not request your email, real name, or password. The backend stores only an opaque account token, membership state, and monthly Agent usage counters.

5. Location

Location is used only when you enable the weather feature, and only transiently (low accuracy, ~3 km) to fetch weather from Apple WeatherKit. Coordinates are not saved and are not uploaded to the backend. The weather field stored on the entry is editable free text you control.

6. Push Notifications

Push notifications are used only if you enable writing reminders, and solely to deliver your chosen reminders (and Agent-related sync). The App never sends marketing notifications. A push token is sent to the backend only when reminders are enabled.

7. No Third-Party Tracking

The App includes no third-party analytics, advertising, attribution, or tracking SDKs. No ATT (App Tracking Transparency) prompt is therefore triggered. The only external services used are Apple's own: iCloud/CloudKit, Sign in with Apple, WeatherKit, StoreKit, and Apple Push Notification service.

8. Permissions the App May Request

Each permission is requested only when the relevant feature is used and can be refused at any time in iOS Settings.

9. Data Retention and Deletion

9.1 Content stays on your device / your iCloud until you delete it. You can delete individual entries, or use Settings → Clear all data (requires typing a confirmation), which also removes the iCloud copy.

9.2 Backend usage counters and the account token are retained while your account is active and may be deleted on request (see Contact).

10. Children

The App is not directed at children under 13 and does not knowingly collect their personal information. The App does not knowingly process special categories of personal data.

11. Your Rights

Because your journal content lives on your own device and your own iCloud, you control it directly — including viewing, correcting, exporting-by-hand, and deleting it. For the limited account data held by the backend, you may request access or deletion by contacting us.

12. Changes to This Policy

We may update this Policy as the product evolves. Material changes will be reflected here and noted in the App where appropriate, with the updated effective date above.

13. Contact

Operator: sanmiao li (rtool.cn)

Customer service: service@rtool.cn

Hours: Mon–Fri, 9:00–18:00 (GMT+8)