隐私政策
欢迎使用「好事来」App(以下简称「本应用」)。我们非常重视您的隐私保护,本隐私政策旨在说明本应用如何收集、使用、存储和保护您的个人信息。
1. 信息收集
本应用不收集任何用于追踪用户的个人身份信息,也不进行任何跨应用追踪。为了实现 App 核心功能,本应用会在设备本地处理以下类型的数据(与 PrivacyInfo.xcprivacy 中 NSPrivacyCollectedDataTypes 声明一致):用户创建的记录内容(文字、心情、标签)、用于分享与保存的相片/视频、通知偏好设置,以及产品交互数据(如 IAP 购买状态)。上述数据仅用于 App 功能本身,不与用户身份关联,不上传至开发者运营的服务器,不用于追踪。所有数据均仅存储在您的设备本地或您的个人 iCloud 容器中,您可以随时查看、修改或删除这些数据。
- 记录数据:您创建的「好事」记录(包括文字内容、心情标签、日期等)仅存储在您的设备上,不会上传至任何由开发者运营的服务器。
- iCloud 同步(可选):如果您开启了 iCloud 同步功能,您的记录数据会通过 Apple 的 iCloud 服务同步到您的其他设备。此过程由 Apple 处理,我们无法访问您的 iCloud 数据。
2. 权限与能力说明
本应用在以下场景中请求或使用系统权限与能力,所有权限均仅在用户主动调用相关功能时启用,您可在系统设置中随时撤回授权。
- Face ID / Touch ID(生物识别):用于解锁本应用,确保只有您本人可查看记录。生物特征数据由 iOS Secure Enclave 加密保护,仅保存在设备本地,不离开设备,也不被本应用读取或上传。
- 麦克风:用于语音输入记录功能,仅在您主动调用语音输入时启用。音频数据不会被保存或上传,仅在当前会话中处理。
- 语音识别:用于将语音转换为文字,仅在您主动调用语音转文字功能时启用。识别请求由 Apple Speech 框架处理,本应用不接触原始音频数据。
- 本地通知:用于每日提醒、周报、月报、纪念日提醒、回收站过期提醒等通知场景。所有通知均为本地通知,不涉及推送服务器,不收集任何推送 token。
- StoreKit 内购:订阅与一次性购买均通过 Apple StoreKit 2 处理,交易由 Apple 完成并加密,开发者不接触任何支付卡或账单信息。订阅状态通过 App Group 同步至 Widget,仅用于显示是否为 Pro 用户。
- App Group 共享:本应用使用 App Group(
group.com.goodthingapp.GoodThingApp)在主 App 与 Widget 之间共享 Pro 状态和记录数据。该共享容器仅由本应用的两个组件访问,不向第三方开放。
- URL Scheme:本应用注册了 URL Scheme
goodthing://,用于从其他 App 或网页跳转至本应用的特定页面。该 Scheme 不传输任何个人信息。
- Widget Extension:桌面小组件(Widget)通过 App Group 共享容器读取记录数据和 Pro 状态,仅读取,不写入,不会修改任何数据。
- iCloud 同步:Pro 用户可开启 iCloud 同步,使用 iCloud 容器
iCloud.com.goodthingapp.GoodThingApp 在您的多个设备间同步记录数据。该容器为您的个人 iCloud 私有空间,共享范围仅限您登录同一 Apple ID 的设备。开发者无法访问容器内容,您可在 iOS「设置 - Apple ID - iCloud - 管理账户存储」中查看或删除同步数据。
- 相册:用于将分享卡片保存到您的相册,仅具有写入权限,不读取相册中的任何内容。
3. 第三方 SDK
本应用不使用任何第三方分析、广告或追踪 SDK,不进行任何跨应用追踪或用户画像。本应用仅使用 Apple 原生框架,包括但不限于:
- StoreKit(内购与订阅管理)
- CloudKit(iCloud 同步)
- WidgetKit(桌面小组件)
- UserNotifications(本地通知)
- Speech(语音识别)
- LocalAuthentication(Face ID / Touch ID)
- Photos(保存到相册)
上述框架均由 Apple 提供并在系统层面运行,相关数据处理遵循 Apple 的隐私规范。
4. 信息使用
本应用所处理的任何数据仅用于以下目的:
- 提供和维护应用的核心功能(记录、提醒、统计、同步等)
- 响应您的主动操作(语音输入、保存卡片、订阅 Pro 等)
- 通过 Widget 与 App 间共享数据以提供桌面小组件体验
5. 信息共享
本应用不会向任何第三方分享、出售或出租您的个人信息。所有数据始终归您所有。iCloud 同步仅在您个人的 Apple ID 范围内进行,不涉及任何第三方。
6. 数据安全
我们采用行业标准的安全措施来保护您的数据:
- 本地数据加密存储
- iCloud 同步通过 Apple 端到端加密传输
- App Group 共享容器受 iOS 沙盒保护
- 生物特征数据由 Secure Enclave 硬件加密保护
7. 数据保留与删除
您对自己的数据拥有完全控制权:
- App 内删除:您可在应用内随时删除单条记录、清空回收站或删除全部记录,操作不可恢复。
- 卸载 App:卸载本应用将删除存储在设备本地的所有数据。
- iCloud 数据管理:已同步至 iCloud 的记录数据可在 iOS「设置 - Apple ID - iCloud - 管理账户存储 - 好事来」中查看和删除,或通过关闭 iCloud 同步功能停止后续同步。
- 撤回权限:您可在 iOS「设置 - 好事来」中随时关闭麦克风、语音识别、通知、相册、Face ID 等权限,撤回后相关功能将不可用,但不影响其他功能。
8. 隐私政策变更
我们可能会不时更新本隐私政策。每次更新会递增版本号(见文末「隐私政策版本」)。当有重大变更时,我们会通过应用内通知或其他适当方式通知您。继续使用本应用即表示您同意更新后的隐私政策。
9. 联系我们
如果您对本隐私政策有任何疑问或建议,请通过以下方式联系我们:
邮箱:pangtong@qq.com
隐私政策版本:v1.0
最后更新:2026年7月18日
Privacy Policy
Welcome to Good Things (the "App"). We take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information.
1. Information Collection
The App does not collect any personally identifiable information for tracking purposes, nor does it perform any cross-app tracking. To deliver core app functionality, the App processes the following data types locally on the device (consistent with the NSPrivacyCollectedDataTypes declaration in PrivacyInfo.xcprivacy): user-created record content (text, mood, tags), photos/videos used for sharing and saving, notification preference settings, and product interaction data (such as IAP purchase status). This data is used solely for app functionality, is not linked to user identity, is not uploaded to any developer-operated server, and is not used for tracking. All data is stored only on your device or in your personal iCloud container, and you can view, modify, or delete it at any time.
- Record Data: The "good things" entries you create (including text content, mood tags, dates, etc.) are stored only on your device and are never uploaded to any developer-operated server.
- iCloud Sync (Optional): If you enable iCloud sync, your records are synced to your other devices via Apple's iCloud service. This process is handled by Apple, and we cannot access your iCloud data.
2. Permissions & Capabilities
The App requests or uses system permissions and capabilities only in the following scenarios, and only when you actively invoke the relevant features. You may revoke any permission at any time in system Settings.
- Face ID / Touch ID (Biometrics): Used to unlock the App so that only you can view your records. Biometric data is encrypted and protected by the iOS Secure Enclave. It is stored only on-device, never leaves the device, and is never read or uploaded by the App.
- Microphone: Used for voice input when composing a record. It is enabled only when you actively invoke voice input. Audio data is not saved or uploaded; it is processed only within the current session.
- Speech Recognition: Used to convert speech to text, enabled only when you actively invoke the speech-to-text feature. Recognition requests are handled by the Apple Speech framework, and the App does not access the raw audio data.
- Local Notifications: Used for daily reminders, weekly reports, monthly reports, anniversary reminders, and trash-bin expiration reminders. All notifications are local. No push server is involved, and no push tokens are collected.
- StoreKit In-App Purchase: Subscriptions and one-time purchases are processed via Apple StoreKit 2. Transactions are completed and encrypted by Apple. The developer never touches any payment card or billing information. Subscription status is synced to the Widget via App Group only to determine whether you are a Pro user.
- App Group Sharing: The App uses an App Group (
group.com.goodthingapp.GoodThingApp) to share Pro status and record data between the main App and the Widget. This shared container is accessed only by these two components of the App and is not exposed to any third party.
- URL Scheme: The App registers the URL Scheme
goodthing:// for launching specific pages from other apps or web pages. This scheme does not transmit any personal information.
- Widget Extension: The home-screen Widget reads record data and Pro status from the App Group shared container. It is read-only and never writes data.
- iCloud Sync: Pro users may enable iCloud sync, which uses the iCloud container
iCloud.com.goodthingapp.GoodThingApp to sync records across your devices. The container is your personal private iCloud space, and the sync scope is limited to devices signed in with the same Apple ID. The developer cannot access the container contents. You can view or delete synced data in iOS Settings > Apple ID > iCloud > Manage Account Storage.
- Photos: Used to save sharing cards to your photo library. It has write-only access and does not read any content from your photo library.
3. Third-Party SDKs
The App does not use any third-party analytics, advertising, or tracking SDKs, and does not perform any cross-app tracking or user profiling. The App only uses Apple-native frameworks, including but not limited to:
- StoreKit (in-app purchase and subscription management)
- CloudKit (iCloud sync)
- WidgetKit (home-screen widgets)
- UserNotifications (local notifications)
- Speech (speech recognition)
- LocalAuthentication (Face ID / Touch ID)
- Photos (saving to photo library)
These frameworks are provided by Apple and operate at the system level. Their data processing follows Apple's privacy specifications.
4. Information Use
Any data processed by the App is used solely for the following purposes:
- Providing and maintaining core app functionality (recording, reminders, statistics, sync, etc.)
- Responding to your active actions (voice input, saving cards, subscribing to Pro, etc.)
- Sharing data between the App and the Widget to provide the home-screen widget experience
5. Information Sharing
The App does not share, sell, or rent your personal information to any third party. All data belongs to you. iCloud sync takes place only within your personal Apple ID and does not involve any third party.
6. Data Security
We employ industry-standard security measures to protect your data:
- Encrypted local data storage
- iCloud sync via Apple's end-to-end encryption
- App Group shared containers protected by the iOS sandbox
- Biometric data protected by Secure Enclave hardware encryption
7. Data Retention & Deletion
You have full control over your data:
- In-App Deletion: You can delete individual records, empty the trash bin, or delete all records at any time within the App. These actions are irreversible.
- Uninstalling the App: Uninstalling the App will delete all data stored locally on the device.
- iCloud Data Management: Records synced to iCloud can be viewed and deleted in iOS Settings > Apple ID > iCloud > Manage Account Storage > Good Things, or you can turn off iCloud sync to stop further syncing.
- Revoking Permissions: You can revoke permissions such as Microphone, Speech Recognition, Notifications, Photos, and Face ID at any time in iOS Settings > Good Things. Revoking a permission disables the related feature but does not affect other features.
8. Privacy Policy Changes
We may update this Privacy Policy from time to time. Each update will increment the version number (see "Privacy Policy Version" at the bottom). When significant changes occur, we will notify you via in-app notifications or other appropriate means. Continued use of the App constitutes your agreement to the updated Privacy Policy.
9. Contact Us
If you have any questions or suggestions about this Privacy Policy, please contact us at:
Email: pangtong@qq.com
Privacy Policy Version: v1.0
Last updated: July 18, 2026