中文正文
版本:0.2
草案更新日期:2026-10-01
生效日期:【待填写:生效日期】
1. 适用范围与联系我们
本政策说明【待填写:运营者法定名称或个人姓名】(以下简称“我们”)在提供 Afterline 应用及相关服务时,如何处理你的个人信息。
隐私联系邮箱:【待填写:邮箱】;联系地址:【待填写:有效联系地址】。你可以通过该邮箱提出访问、更正、删除、撤回同意或投诉请求。
这份政策不替代微信读书、Apple 或其他独立服务的隐私政策。我们仍对自身的数据处理及依法应承担的服务商管理义务负责。
2. 先了解这几件事
- 本地阅读、关键词检索和本地关联计算,主要在你的设备上完成。 同步阅读数据、下载封面和联网 AI 是不同的联网行为。
- 联网 AI 会把本次功能涉及的书名、划线、想法和笔记标识等信息,经 Afterline 后端发送给相应模型服务商。 联网关联可能在打开笔记详情时触发,不只在点击“生成”时触发。
- 微信读书 API Key 在设备上保存,调用微信读书接口时直接发给微信读书;现有 AI 请求不包含该 Key。
- 当前没有独立的 Afterline 注册账号、应用内 iCloud 笔记同步、广告 SDK 或跨应用广告跟踪功能。系统备份与应用自身的云同步不同。
- 移除 Key、清除搜索历史、删除本机应用和删除服务端记录,是不同操作。 删除本机数据不会删除微信读书原始内容。
3. 我们处理哪些信息、为什么处理
| 使用场景 | 信息范围 | 处理方式与目的 | 不提供的影响 |
|---|---|---|---|
| 连接微信读书 | 你填写的 API Key;请求所需的书籍、笔记标识及同步参数 | 在本机保存凭证,并直接向微信读书接口发送,用于访问你获授权的阅读数据 | 无法获取或刷新相关阅读数据;已有本地内容不因此自动删除 |
| 同步与阅读回顾 | 书名、作者、封面地址、分类、章节和原文位置、划线、个人想法、时间、笔记及书籍标识、书架和阅读统计、接口返回的隐私标记 | 从微信读书获取,在本机保存、整理、展示及更新 | 无法提供依赖这些内容的同步和回顾功能 |
| 本地检索与关联 | 已同步的笔记、搜索词、搜索历史、从笔记生成的本地向量或索引 | 在设备上搜索、计算相关性和保存使用记录;搜索历史最多保存最近 50 条 | 可不使用检索;搜索历史可单独清除 |
| 联网关联判断 | 当前笔记和候选笔记的书名、文本、想法、笔记标识 | 经 Cloudflare Worker 后端交由 TypeSafe AI / Jev 判断相关性;结果可保存到本机 | 不使用该处理时,无法获得联网判断结果;本地计算与阅读功能可独立运行 |
| 阅读背景解读与 AI 洞察 | 当前笔记或本次选定笔记组的书名、文本、想法、笔记标识,以及功能类型 | 经 Afterline 后端交由 DeepSeek 生成内容;结果和相关研究记录可保存到本机 | 无法生成相应的联网内容 |
| 封面与外部链接 | 请求的图片或网页地址、IP 地址及通常的网络请求信息 | 向图片来源服务器下载封面,或在你打开链接时访问外部应用或网站 | 可能无法显示未缓存封面或打开外部内容 |
| 服务运行与排障 | IP 地址、请求时间、状态、耗时、模型、输入输出 token 用量、候选数量及请求指纹 | 用于网络服务、限流、诊断、重复请求识别和成本核算;元数据进入 D1 或托管日志,当前 Worker 的 D1 表不存笔记正文或生成结果 | 必要运行信息无法提供时,网络功能可能无法正常工作 |
| 年费 Pro 与 credit | Apple 签名购买凭据、交易及商品标识、订阅周期和状态、匿名 RevenueCat 标识、购买身份的派生标识、额度、credit 和退款记录,以及必要的设备/应用技术信息 | Apple 处理付款;RevenueCat 同步和核验权益;Cloudflare Worker 验证交易,D1 保存必要的计费记录,设备 Keychain 保存短期服务会话 | 无法验证或恢复购买、使用联网 Pro 服务及处理次数包;不要求另行注册 Afterline 账号 |
| 偏好与联系支持 | 字体、展示偏好、服务配置;你主动提供的邮箱、问题描述、附件及沟通记录 | 偏好保存在本机;支持信息用于回复、排障及处理权利请求 | 不影响无关功能;缺少必要信息时可能无法解决具体问题 |
当前版本不主动请求通讯录、精确定位、麦克风、相机或健康数据权限,也不要求提供身份证或银行卡信息。你自行写入想法或提交给支持的内容可能包含这些信息,因此请避免提交与服务无关的敏感内容或他人个人信息。
基础功能所需处理以你请求的服务及适用法律允许的依据开展;可选 AI 处理以充分告知后的有效授权为前提,依法履行义务所需处理以相应法律依据开展。我们不会把所有处理都归入一次概括同意。
4. AI 处理与第三方服务
4.1 发送范围与触发方式
AI 请求发送的是本次处理涉及的笔记内容,不是默认上传整个笔记库。联网关联会发送当前笔记和本地选出的候选笔记;背景解读发送当前笔记;AI 洞察发送本次分析的笔记组。个人想法即使没有在当前界面展开,也可能随对应笔记一并发送。
【待落实后定稿:首次发送前的明确授权,以及“设置 → AI 数据授权”中的撤回入口。】 首次授权提示应说明功能、数据种类、接收方和处理地区。你可拒绝或撤回可选 AI 授权,继续使用不依赖该处理的本地功能;已经合法完成的处理不因撤回而失效,已有记录按第 6、7 节处理。
购买 Pro 或接受用户协议不替代上述授权。未来更换服务商或实质改变处理范围时,我们会更新告知并在依法需要时重新取得同意。
4.2 服务商清单
下表按当前代码中的服务链路起草。生产发布前须核对实际接收主体、部署地区、合同角色及保存安排;品牌名称不替代必要的法定主体信息。
| 服务及接收方 | 用途与数据 | 说明与政策 |
|---|---|---|
| 微信读书/腾讯【待确认:具体运营主体及隐私联系方式】 | 接收 API Key 和接口请求,向设备提供已授权的阅读数据 | 微信读书授权入口;【待填写:适用隐私政策链接】 |
| Cloudflare(Workers 与 D1)【待确认:合同主体、处理地区及联系方式】 | 承载 AI 中转、购买鉴权、限流和计费;处理请求与响应,存储计费及必要运行元数据 | 当前默认后端使用 Cloudflare Worker;D1 不存笔记正文或生成结果,不代表请求内容不会经过 Cloudflare;Cloudflare 隐私政策 |
| RevenueCat, Inc.【待确认:适用合同及处理安排】 | 处理匿名应用用户标识、购买凭据、交易和订阅状态及必要技术信息,以验证权益、恢复购买和同步退款 | 当前 AI 请求不会把笔记正文发送给 RevenueCat;RevenueCat 隐私政策,终端用户数据还受适用的数据处理协议约束 |
| DeepSeek【待确认:实际 API 签约主体及适用数据处理条款】 | 处理阅读背景与笔记组洞察 | 接收本次相关笔记内容;DeepSeek 隐私政策;须另核对 API 合同,不将消费者产品设置视为 API 配置 |
| TypeSafe AI, Inc.(Jev)【待确认:合同主体与隐私联系渠道】 | 处理联网笔记关联判断 | 接收当前及候选笔记内容;TypeSafe AI 隐私政策 |
| 书籍封面来源服务【待确认:生产版本实际域名及主体】 | 提供封面图片,接收图片地址和必要网络请求信息 | 以微信读书返回的封面来源为准;不会为了下载封面主动发送你的想法正文 |
| Apple | 应用分发、内购付款、签名购买凭据、订阅管理与恢复,以及你选择使用的系统备份 | Apple 隐私政策;Afterline 不接收你的 Apple 账户密码或完整银行卡信息 |
我们仅为说明的功能和必要运行目的向服务商提供相关信息,并根据实际关系落实委托处理或向独立处理者提供信息的要求。依法需要单独同意的,会另行征求。我们不出售你的个人信息,不将笔记用于广告投放,也不通过广告 SDK 跨应用跟踪你。
在适用法律要求或有权机关提出合法请求时,我们可能在必要范围内披露相关信息。若发生合并、收购或业务转移而需要转移个人信息,我们会告知接收方及相关安排,并要求其继续履行适用的保护义务;变更处理目的或方式时,依法重新取得必要授权。
4.3 模型训练
Afterline 当前没有自行训练模型或建立用户笔记训练集的功能。不能据此推断所有上游服务都“零留存”或“绝不训练”。TypeSafe AI 的公开政策声明不使用输入训练或微调模型;DeepSeek API 的实际训练使用、退出选项及保存安排仍须按所用账号和合同核实。
【待确认:逐一填入生产 API 的训练用途、留存期限、人工访问范围,以及适用的退出或删除方式;核实前不得发布全链路“不用于训练”或“请求后立即删除”的承诺。】 如未来拟将内容用于超出原有目的的模型训练,我们会事先另行告知,并取得依法所需的授权。
5. 私密书籍与敏感信息
Afterline 根据微信读书接口返回的隐私标记,对识别出的私密书籍实施展示、检索及后续处理过滤。该判断依赖成功刷新后的状态,可能存在缓存和同步延迟;在来源平台修改隐私设置,不会撤回此前已经发出的请求,也不等于删除所有历史副本。
书摘和想法可能包含健康、宗教、金融或其他敏感信息。服务并不要求你提供这类信息,请在联网处理前审慎检查。若某项服务确需处理敏感个人信息,我们会说明必要性及影响,并依法取得单独同意、采取相应保护措施。普通 AI 授权不应被理解为对任何敏感信息处理的无限授权。
6. 保存地点与期限
6.1 你的设备
已同步笔记、本地索引、关联结果、生成内容及研究记录主要保存在应用的本地存储中;API Key、偏好和搜索历史也保存在本机。当前没有应用自身的 iCloud 笔记同步。你的设备或 iCloud 备份设置可能使部分本地应用数据进入系统备份,相关备份由你和 Apple 的系统设置管理。
本地笔记及生成记录通常保存至你删除相关应用数据;搜索历史最多保留最近 50 条,亦可主动删除。封面缓存按空间和使用情况更新、淘汰,不作为永久存储。应用更新、来源内容变化或系统清理也可能改变缓存。
6.2 后端与服务商
联网处理期间,Afterline 后端及模型服务商会接触本次请求和响应。当前 Cloudflare D1 保存经验证的购买映射、订阅周期和权益状态、会话 token 的哈希、请求指纹、次数预占和结算、模型用量、credit 购买及退款记录、webhook 事件标识。当前表结构不保存完整签名凭据、笔记正文或生成结果。Worker 在请求处理时仍会接触这些内容,托管平台与模型服务商的留存须另行核实。会话失效不等于历史计费记录已删除;购买与退款记录还用于避免重复发放并保留无过期 credit。
生产后端及服务商处理地区:【待确认:逐项列明国家或地区】。
D1 购买、会话及用量记录保留期限:【待确认:分类期限及清理机制】。
运行日志保留期限:【待确认:期限及自动清理方式】。
模型输入输出保留期限:【待确认:逐个服务商列明】。
支持和权利请求记录保留期限:【待确认:期限或明确的确定标准】。
备份及到期清理周期:【待确认:如无备份也须核实】。
我们仅在实现说明的目的所必需的期限内保存个人信息;到期后删除或匿名化。法律要求继续保存或技术上暂时无法删除的,限制相关处理并在条件具备时完成删除。
6.3 跨境处理
联网功能可能涉及中国大陆境外处理,不能承诺全部数据仅保存在中国大陆。 在相关跨境处理启用前,我们会明确告知境外接收方、联系渠道、处理目的和方式、信息种类、保存期限及权利行使方式,并完成依法所需的跨境手续和授权。具体安排为【待确认:实际境外接收方、地区及适用机制】。接受本政策本身不替代依法需要的跨境单独同意。
7. 你的选择与权利
- 停止同步: 在设置中移除微信读书 API Key,并可通过来源平台提供的方式撤销授权。新请求停止后,已经同步的本地数据仍可能存在;已经发出的请求无法保证即时撤回。
- 删除搜索历史: 使用搜索历史中的管理功能删除单条或清空全部历史。这不会删除笔记库。
- 删除本机数据: 当前版本没有一键清除全部数据入口。可通过 iOS 的“删除 App”移除应用及其本机容器数据;“卸载 App”保留文稿与数据,不等同于删除。系统备份需要另行管理,恢复备份可能使数据重新出现。删除 App 不会自动取消 Apple 订阅、删除 Apple/RevenueCat/D1 的购买记录,或保证清除 Keychain 项目;相关请求需分别处理。
- 撤回 AI 授权: 【待落实:应用内撤回入口及停止后续请求的机制】。撤回不等于自动删除此前生成的本地结果或服务端依法留存的记录,删除请求可另行提出。
- 访问、更正、复制或删除其他记录: 联系本政策所列邮箱,说明请求及必要的核验信息。原始阅读记录请同时在微信读书管理;当前没有独立 Afterline 账号可供注销。
我们会在适用法律要求的期限内答复,并仅要求与核验请求相称的信息。具体服务响应承诺为【待确认:可实际履行的响应期限】。如果无法满足请求,将说明理由和可用救济途径。对于仅存放在你设备上的数据,我们无法远程读取或直接替你删除,会说明可行的本地操作方式;涉及受托服务商的数据,将依法协助处理。
你有权依法投诉或向有管辖权的监管机构寻求救济。拒绝非必要处理或行使上述权利,不影响使用不依赖该处理的功能。
8. 信息安全
当前默认线上接口使用 HTTPS;本地应用数据依赖 iOS 的沙盒和设备保护。我们不将这些措施表述为端到端加密或绝对安全,处理 AI 请求的服务器及服务商仍可接触请求内容。
当前微信读书 API Key 保存在本机偏好存储中,并非 Keychain;购买验证后的短期服务会话则保存在设备 Keychain,不启用该会话的 iCloud Keychain 同步。D1 保存会话 token 的哈希,不保存原始 token。 请保护设备和授权凭证,避免在反馈中发送完整 Key。
发生个人信息安全事件时,我们会采取补救措施,并按适用法律向受影响用户和主管机关履行通知或报告义务。
9. 未成年人
本服务不面向未满十四周岁的儿童,也不主动以他们为对象收集信息。其他适用地区的儿童年龄门槛更高的,从其规定。若你认为儿童在缺乏必要监护人同意的情况下提供了个人信息,请联系我们;我们会核实并依法删除或采取其他适当措施。面向儿童提供服务前,需要另行建立相应的监护人同意和专门保护规则。
10. 政策更新
我们会在本页面列明版本和生效日期。对数据种类、用途、接收方、跨境安排或你的权利产生实质影响的变化,会通过应用内提示或其他合理方式告知,并依法重新取得必要同意。我们不会仅以你继续使用应用为由,推定你同意新增的可选或须单独授权的处理。
本政策以中文为主要文本,英文版便于阅读。在适用法律允许的范围内,内容不一致时以中文为准;该安排不减损你依法享有的权利。
English version
Version: 0.2
Draft updated: October 1, 2026
Effective date: [TO COMPLETE: effective date]
1. Scope and contact
This Policy explains how [TO COMPLETE: operator’s legal name] (“we,” “us”) processes your personal information when providing the Afterline application and related services.
Privacy email: [TO COMPLETE: email]. Contact address: [TO COMPLETE: valid contact address]. You may use this email for access, correction, deletion, withdrawal of consent, or complaints.
This Policy does not replace the policies of WeRead, Apple, or other independent services. We remain responsible for our own processing and the provider oversight required by applicable law.
2. Key points
- Local reading, keyword search, and local relevance calculations mainly take place on your device. Reading-data synchronization, cover downloads, and online AI are separate network activities.
- Online AI sends the relevant book titles, highlights, thoughts, and note identifiers through the Afterline backend to the appropriate model provider. Online note matching may be triggered when you open note details, not only when you tap a generate button.
- Your WeRead API Key is stored on your device and sent directly to WeRead when its interfaces are called. Current AI requests do not contain that Key.
- There is currently no separate Afterline registration account, in-app iCloud note synchronization, advertising SDK, or cross-app advertising tracking. System backups are different from the application’s own cloud synchronization.
- Removing a Key, clearing search history, deleting the application, and deleting server records are different actions. Deleting local data does not delete original content from WeRead.
3. Information processed and purposes
| Activity | Information | Processing and purpose | If not provided |
|---|---|---|---|
| Connecting to WeRead | Your API Key; book and note identifiers and synchronization parameters needed for requests | Store the credential locally and send it directly to WeRead to access authorized reading data | Reading data cannot be retrieved or refreshed; existing local content is not automatically deleted |
| Synchronization and reading review | Book titles, authors, cover URLs, categories, chapters and source positions, highlights, personal thoughts, dates, note and book identifiers, shelf and reading statistics, privacy flags returned by the interface | Retrieve from WeRead, then store, organize, display, and update locally | Features dependent on that data cannot operate |
| Local search and note matching | Synchronized notes, queries, search history, and locally generated vectors or indexes | Search, calculate relevance, and retain usage records on the device; search history holds up to 50 recent entries | You may choose not to search; search history can be cleared separately |
| Online note matching | Book titles, text, thoughts, and identifiers of the current note and candidate notes | Send through the Cloudflare Worker backend to TypeSafe AI / Jev to assess relationships; results may be stored locally | Online assessments are unavailable; local calculations and reading can operate independently |
| Background explanations and AI insights | Book titles, text, thoughts, and identifiers for the current note or selected group, and the requested feature type | Send through the Afterline backend to DeepSeek to generate content; results and associated research records may be stored locally | The corresponding online content cannot be generated |
| Covers and external links | Image or page URLs, IP address, and ordinary network request information | Download covers from their source servers or visit an external app or website when you open a link | Uncached covers or external content may be unavailable |
| Service operation and troubleshooting | IP address, request time, status, duration, model, input/output token usage, candidate count, and request fingerprints | Provide network services, rate limiting, diagnostics, duplicate-request detection, and cost accounting; metadata is held in D1 or hosting logs, while the current Worker D1 tables do not store note text or generated results | Network features may not work without necessary operational information |
| Annual Pro and credits | Signed Apple purchase evidence, transaction and product identifiers, subscription periods and status, anonymous RevenueCat identifiers, derived purchase identities, usage, credit and refund records, and necessary device/app technical information | Apple handles payment; RevenueCat synchronizes and verifies entitlements; Cloudflare Worker verifies transactions, D1 holds necessary billing records, and the device Keychain holds short-lived service sessions | Purchase verification, restoration, online Pro services, and credit handling are unavailable; no separate Afterline registration is required |
| Preferences and support | Font and display preferences, service settings; email, issue description, attachments, and communications you provide | Store preferences locally; use support information to respond, troubleshoot, and handle rights requests | Unrelated features are unaffected; missing essential details may prevent resolution of an issue |
The current version does not proactively request access to contacts, precise location, microphone, camera, or health data, or require identity-document or bank-card information. Your thoughts or support submissions may nevertheless contain such information. Avoid submitting unnecessary sensitive information or personal information about others.
Processing necessary for core features is based on the service you request and the grounds permitted by applicable law. Optional AI processing requires valid authorization after appropriate notice. Processing required to meet legal duties relies on the relevant legal basis. We do not treat one blanket consent as the basis for every activity.
4. AI processing and third-party services
4.1 Scope and triggers
AI requests contain notes involved in the particular operation, rather than uploading the entire library by default. Online matching sends the current note and locally selected candidates; background explanations send the current note; insights send the group being analyzed. Personal thoughts can be included with a note even if they are not expanded in the current interface.
[TO IMPLEMENT BEFORE FINALIZATION: explicit permission before the first transmission and a withdrawal control under Settings → AI data permissions.] The initial notice should explain the feature, information types, recipients, and processing locations. You may refuse or withdraw optional AI authorization while continuing to use local features that do not depend on it. Withdrawal does not invalidate lawful prior processing; existing records are handled under Sections 6 and 7.
Purchasing Pro or accepting the Terms of Use does not replace this authorization. If providers or processing scope materially change, we will update the notice and obtain renewed consent where required.
4.2 Service providers
This table reflects the service paths in the current code. Actual recipients, deployment locations, contractual roles, and retention must be checked before production publication. Brand names do not replace required legal-entity information.
| Service and recipient | Purpose and information | Details and policy |
|---|---|---|
| WeRead / Tencent [TO CONFIRM: operating entity and privacy contact] | Receives the API Key and interface requests and returns authorized reading data to the device | WeRead authorization page; [TO COMPLETE: applicable privacy policy URL] |
| Cloudflare (Workers and D1) [TO CONFIRM: contracting entity, processing locations, and contact] | Hosts AI proxying, purchase authorization, rate limiting, and billing; processes requests and responses and stores billing and necessary operational metadata | The default backend uses Cloudflare Worker; D1 does not store note text or generated results, but request content still passes through Cloudflare; Cloudflare Privacy Policy |
| RevenueCat, Inc. [TO CONFIRM: applicable contract and processing arrangements] | Processes anonymous app-user identifiers, purchase evidence, transaction and subscription status, and necessary technical information for verification, restoration, and refund synchronization | Current AI requests do not send note text to RevenueCat; RevenueCat Privacy Policy, with end-user processing also governed by applicable data-processing agreements |
| DeepSeek [TO CONFIRM: API contracting entity and applicable processing terms] | Processes background explanations and group insights | Receives the relevant note content; DeepSeek Privacy Policy; verify API terms separately rather than assuming consumer-product settings apply |
| TypeSafe AI, Inc. (Jev) [TO CONFIRM: contracting entity and privacy contact] | Processes online note relationship assessments | Receives the current and candidate notes; TypeSafe AI Privacy Policy |
| Book cover sources [TO CONFIRM: production domains and entities] | Supply cover images and receive image URLs and necessary network request information | Determined by the cover sources returned by WeRead; downloading covers does not deliberately send your thought text |
| Apple | App distribution, In-App Purchase payments, signed purchase evidence, subscription management and restoration, and optional system backups | Apple Privacy Policy; Afterline does not receive your Apple Account password or full payment-card details |
We provide relevant information only for the stated functions and necessary service operation, and apply the requirements for processors or independent recipients according to the actual relationship. Separate consent will be requested where required. We do not sell your personal information, use notes for advertising, or track you across applications through advertising SDKs.
We may disclose relevant information to the extent necessary to comply with applicable law or a lawful request from a competent authority. If a merger, acquisition, or business transfer requires personal information to be transferred, we will notify you of the recipient and arrangements and require continued compliance with applicable protections. Changes to processing purposes or methods will require renewed authorization where provided by law.
4.3 Model training
Afterline currently has no function for training its own models or building a training dataset from users’ notes. This does not establish that every upstream service has zero retention or never trains on data. TypeSafe AI’s published policy states that it does not train or fine-tune models on input. The actual training use, opt-out options, and retention for the DeepSeek API must still be verified against the account and contract used.
[TO CONFIRM: for each production API, state training uses, retention, human access, and applicable opt-out or deletion methods. Do not publish an end-to-end no-training or immediate-deletion promise before verification.] If we later propose training uses beyond the original purpose, we will provide prior notice and obtain legally required authorization.
5. Private books and sensitive information
Afterline uses privacy flags returned by WeRead to filter identified private books from display, search, and subsequent processing. This depends on successfully refreshed status and may involve caching or synchronization delays. Changing privacy settings at the source does not recall requests already sent or delete every historical copy.
Highlights and thoughts may contain health, religious, financial, or other sensitive information. The service does not require such information; review it carefully before online processing. If a service specifically requires sensitive personal information, we will explain the necessity and impact, obtain separate consent where required, and apply appropriate safeguards. Ordinary AI authorization is not unlimited permission to process any sensitive information.
6. Storage locations and retention
6.1 Your device
Synchronized notes, local indexes, relationship results, generated content, and research records are mainly held in local application storage. Your API Key, preferences, and search history are also stored locally. The application does not currently provide its own iCloud note synchronization. Device or iCloud backup settings may include some local application data in system backups, which are managed through your and Apple’s system settings.
Local notes and generated records normally remain until you delete the relevant application data. Search history holds up to 50 recent entries and may be deleted manually. Cover caches are refreshed or evicted according to space and usage and are not permanent storage. Application updates, source-content changes, and system cleanup may also affect caches.
6.2 Backend and providers
During online processing, the Afterline backend and model providers access the relevant request and response. Cloudflare D1 currently stores verified purchase mappings, subscription periods and entitlements, session-token hashes, request fingerprints, request reservations and settlements, model usage, credit purchases and refunds, and webhook event identifiers. Its current tables do not store complete signed evidence, note text, or generated results. Worker still processes that content in transit; hosting and model-provider retention require separate verification. Session expiry does not delete historical billing records, which also prevent duplicate grants and preserve non-expiring credits.
Production backend and provider processing locations: [TO CONFIRM: list countries or regions individually].
D1 purchase, session, and usage record retention: [TO CONFIRM: category-specific periods and cleanup].
Operational log retention: [TO CONFIRM: period and automated deletion process].
Model input/output retention: [TO CONFIRM: by provider].
Support and rights-request retention: [TO CONFIRM: period or specific determining criteria].
Backup and expiry-deletion cycles: [TO CONFIRM: verify even if there are no backups].
We retain personal information only as long as necessary for the stated purposes, then delete or anonymize it. Where law requires continued retention or deletion is temporarily technically unavailable, we restrict processing and complete deletion when possible.
6.3 International processing
Online features may involve processing outside mainland China; we cannot promise that all data remains in mainland China. Before enabling such transfers, we will disclose overseas recipients, contacts, purposes, processing methods, information types, retention, and rights channels, and complete the legally required transfer arrangements and permissions. Specific arrangements: [TO CONFIRM: overseas recipients, locations, and applicable mechanisms]. Accepting this Policy does not replace separate cross-border consent where required.
7. Your choices and rights
- Stop synchronization: Remove the WeRead API Key in Settings and, where available, revoke authorization through the source platform. Existing local data may remain after new requests stop. Requests already sent cannot necessarily be recalled immediately.
- Delete search history: Use search-history management to remove individual entries or clear all history. This does not delete your note library.
- Delete local data: The current version has no one-tap control to erase all data. Use iOS “Delete App” to remove the application and its local container data. “Offload App” retains documents and data and is not equivalent to deletion. Manage system backups separately; restoring a backup can restore data. Deleting the app does not automatically cancel Apple subscriptions, delete purchase records held by Apple, RevenueCat, or D1, or guarantee removal of Keychain items; these require separate handling.
- Withdraw AI permission: [TO IMPLEMENT: in-app withdrawal control and prevention of further requests]. Withdrawal does not automatically erase previously generated local results or lawfully retained server records; deletion may be requested separately.
- Access, correct, copy, or delete other records: Contact the email in this Policy with your request and necessary verification details. Manage original reading records in WeRead as well. There is currently no separate Afterline account to close.
We will respond within the time required by applicable law and request only information proportionate to verifying your request. Our specific service response commitment is [TO CONFIRM: a period we can actually meet]. If we cannot fulfill a request, we will explain why and the available remedies. We cannot remotely read or delete information held only on your device and will explain available local actions. We will assist with information held by our processors as required by law.
You may complain or seek assistance from a regulator with jurisdiction. Refusing unnecessary processing or exercising these rights does not prevent use of features that do not rely on that processing.
8. Security
Current default online interfaces use HTTPS. Local application data relies on iOS sandboxing and device protections. These measures are not end-to-end encryption or a guarantee of absolute security; servers and providers processing AI requests can still access their content.
The WeRead API Key is currently held in local preferences, not Keychain. Short-lived service sessions issued after purchase verification are held in the device Keychain without iCloud Keychain synchronization. D1 holds session-token hashes rather than raw tokens. Protect your device and credentials and avoid including complete Keys in support requests.
If a personal information security incident occurs, we will take remedial action and notify affected users and authorities as required by applicable law.
9. Minors
The service is not directed to children under fourteen, and we do not actively target them for information collection. A higher local child-age threshold applies where required. If you believe a child has provided personal information without necessary guardian consent, contact us. We will investigate and delete it or take other appropriate action under applicable law. Offering services directed to children would require appropriate guardian-consent procedures and dedicated protections first.
10. Policy updates
This page will show the version and effective date. Material changes to information types, purposes, recipients, international arrangements, or your rights will be notified in the application or through another reasonable channel, and renewed consent will be obtained where required. Continued application use alone will not be treated as consent to new optional processing or processing requiring separate authorization.
Chinese is the primary text, and English is provided for convenience. In case of inconsistency, Chinese prevails to the extent permitted by applicable law, without reducing your lawful rights.