Legal · 法律

隐私政策

本政策说明 PopLog 在当前 iOS 内测版本中,如何处理账号、拍摄记录、社交互动和通知相关数据。

更新日期:2026 年 8 月 26 日

适用范围与信息处理者

本政策适用于 PopLog iOS App、poplog.cn 网站及 PopLog 后端服务。当前产品处于内测阶段;在公开发布前,本页将补充运营主体的完整法定名称、注册地址和可公开联系的隐私邮箱。内测用户可通过收到测试邀请的渠道联系团队,提出隐私、导出或删除请求。

我们处理的数据及用途

账号与认证数据。包括邮箱地址、显示名称、用户名、用户 ID、头像、Apple 登录标识,以及用于维持登录和保障账号安全的会话令牌。密码不会以明文形式保存;服务端保存随机盐值及基于 PBKDF2-HMAC-SHA256 的派生值,用于验证密码。

拍摄与媒体数据。包括你拍摄或上传至 Personal Log、群组 Log、聊天或个人资料的照片、实况照片、视频,以及视频中录制的音频;还包括缩略图、媒体类型、时间戳、字幕和你选择添加的粗略地点标签。我们用这些数据存储、展示、播放、分享、导出和保护你的内容。

社交与互动数据。包括好友关系、群组成员关系与角色、邀请码、评论、回复、回应、私信、群聊消息、通知偏好、举报、屏蔽和静音设置。我们使用这些数据提供选定成员之间的分享、聊天、内容治理和通知功能。

设备与服务运行数据。包括 iOS APNs 设备令牌、App 版本、通知投递记录、未读数量、会话和必要的安全审计记录。它们用于账号运行、推送、故障排查、滥用防范和服务安全,不用于广告追踪或跨 App 追踪。

自动每日成片

当你使用 Personal Log 或群组 Log 的自动每日成片功能时,PopLog 后端会读取已上传到相应 Log 的媒体和必要的元数据,在 PopLog 服务环境中自动生成并保存一条每日成片。当前实现使用服务端媒体处理流程生成成片,不会把媒体发送给第三方生成式 AI 服务,也不会将你的媒体、音频、字幕或地点标签用于训练通用模型。生成的成片会显示在对应日期下;你可以删除账号或在适用的内容管理入口删除相关内容。群组每日成片可由该群组的活跃成员访问。

共享范围

Personal Log 中的内容仅对对应账号可见,除非你主动将内容发送到聊天或群组。群组 Log、群聊、评论和回应可被该群组的活跃成员查看;直接消息仅向参与该对话的账号显示。被举报的内容及必要上下文可能由经授权的运营人员访问,用于处理举报、审核、风控或法律义务。

第三方和服务提供方

为运行服务,我们会使用以下第三方或类别的服务提供方:Apple Sign in with Apple(处理 Apple 登录);Apple Push Notification service,APNs(投递推送);对象存储、内容分发和服务器基础设施提供方(存储、读取和分发媒体及服务数据);以及在启用密码重置邮件时的邮件投递服务提供方。若你主动使用已启用的微信相关功能,微信 SDK 也会按其自身条款处理该操作所需的数据。我们要求服务提供方仅在提供相应服务所需的范围内处理数据。当前版本未集成第三方广告 SDK、行为分析 SDK、崩溃分析 SDK 或第三方生成式 AI 服务。

权限与选择

相机权限用于拍摄;麦克风权限用于为视频录音;定位权限用于生成可选的粗略地点标签;照片库“添加”权限仅用于将你主动选择的瞬间或成片保存到系统照片;通知权限用于推送。你可以在 iOS“设置”中随时撤回相机、麦克风、定位、照片和通知权限。撤回权限不会删除已上传内容;删除内容或账号请使用 App 内相应入口。

保留、导出和删除

只要账号保持活跃,我们会保存提供服务所需的数据。你可以在 App 的 Chat → Settings 中导出账号数据,或选择 Delete Account 删除账号。删除请求会从活动服务数据中移除账号、活跃会话、设备令牌、个人日志、本人发布的内容、评论、回应、消息、通知、好友关系和屏蔽关系,并尝试删除关联媒体对象。若你是仍有其他活跃成员的群组所有者,群组会转交给最早加入的剩余活跃成员;该群组中其他成员的内容会保留。

删除后,我们保留最小化的删除审计事件,其中包含经过哈希处理的账号标识和删除计数,用于安全、滥用防范和运营合规。数据库备份按服务器配置保留;当前代码默认保留最近 14 个备份快照,删除数据可能会在这些快照到期并被轮换后才从备份中消失。上传意图和过期认证数据会由服务端清理。

安全与用户权利

我们采取访问控制、令牌哈希、传输保护和最小权限措施来保护数据。你可以通过 App 导出和删除数据,并可在 App 内更新个人资料、管理群组、删除本人可管理的内容、屏蔽用户或调整通知偏好。内测期间,如需访问、更正、删除、撤回同意或投诉,请通过测试邀请渠道联系团队。

未成年人

PopLog 不面向未达到所在地区最低数字同意年龄的儿童。未成年人应仅在其父母、监护人或适用法律允许的情况下使用服务。公开发布前将补充适用市场的年龄规则与监护人联系机制。

不用于追踪

PopLog 不出售个人信息,也不将收集的数据用于定向广告或跨 App、跨网站追踪。iOS 隐私清单与 App Store Connect 的 App Privacy 数据标签需要分别维护,并应与本政策和实际代码、SDK、服务器配置保持一致。

Privacy Notice

Scope and operator. This notice applies to the PopLog iOS app, poplog.cn and PopLog backend services. PopLog is currently in beta. Before public launch, this page will identify the legal operator, registered address and public privacy contact. Beta users can use the channel through which they received their test invitation for privacy, export and deletion requests.

Data we process. We process account data (email address, display name, handle, user ID, avatar, Apple Sign In identifier and security tokens); media data (photos, Live Photos, videos and audio recorded in videos, thumbnails, timestamps, captions and optional coarse location labels); social data (friendships, group membership and roles, invite codes, messages, comments, replies, reactions, reports, blocks and mute settings); and device and operational data (iOS APNs device token, app version, notification delivery records, unread counts, sessions and security audit records). Passwords are not stored in plaintext; the service stores a random salt and a PBKDF2-HMAC-SHA256 derived value for verification.

Automatic daily edits. When automatic daily edits are enabled for a Personal Log or group Log, PopLog's backend reads media already uploaded to that Log and necessary metadata, then creates and stores a daily video in the PopLog service environment. The current implementation uses server-side media processing. It does not send media to a third-party generative AI provider and does not use media, audio, captions or location labels to train a general-purpose model. A group daily edit is available to active members of that group.

Sharing and providers. Personal Log content is private to its account unless you actively share it. Group Logs, group chats, comments and reactions are visible to active members of that group; direct messages are visible to their participants. Authorized operators may access reported content and necessary context for moderation, security and legal obligations. Service providers may include Apple Sign in with Apple, Apple Push Notification service, object storage/CDN/server infrastructure, and an email delivery provider when password-reset email is enabled. If WeChat functionality is enabled and you choose to use it, the WeChat SDK processes data needed for that action under its own terms. The current version does not integrate third-party advertising, behavioral analytics, crash analytics or generative AI SDKs.

Permissions and choices. Camera is used to capture media; microphone records audio with video; location supplies an optional coarse label; Photos Add Only saves media you choose to export; and notifications enable push delivery. You can revoke these permissions in iOS Settings. Revoking a permission does not delete already uploaded data.

Retention, export and deletion. Data is retained while an account is active. In Chat → Settings, you may export account data or delete the account. Deletion removes active service data and attempts to delete associated media. A group with other active members is reassigned to the earliest remaining active member, and other members' group content remains. We retain a minimal deletion audit event with hashed account identifiers and deletion counts for security, abuse prevention and operational compliance. Database backups are retained under server configuration; the current code defaults to the most recent 14 snapshots, so deleted data can remain in a backup until that snapshot expires and is rotated out.

PopLog does not sell personal information or use data for targeted advertising or cross-app tracking. The iOS privacy manifest and App Store Connect App Privacy labels are maintained separately and must remain consistent with this notice, code, SDKs and server configuration.