隐私政策 / Privacy Policy

Aurmo · 个人开发者周德建 / Individual developer Dejian Zhou
最后更新 / Last updated:2026-08-13
生效日期 / Effective:2026-08-13

中文English

核心要点 / Highlights

Aurmo 无账号体系,不含第三方广告、第三方行为分析或崩溃统计 SDK,不进行跨 App 追踪。录音不会进入 Aurmo backend 或大模型服务;录音和其他指定内容会通过你的 CloudKit private database 同步。插嘴录音的转写文字会短暂经过 Aurmo backend 和配置的大模型服务做自动纠错,但 Aurmo PostgreSQL 不保存该正文。

Aurmo has no account system, third-party advertising, third-party behavioral analytics, or crash-reporting SDKs, and does not track you across apps. Recording files never enter Aurmo's backend or an LLM provider. Specified content, including recordings, syncs through your CloudKit private database and, only after you connect Notion, may also sync directly from the App to your authorized Notion workspace. Interject transcript text temporarily passes through Aurmo's backend and the configured LLM provider for automatic correction, but its body is not stored in Aurmo's PostgreSQL database.

中文

欢迎使用 Aurmo(以下简称“本应用”或“我们”)。本应用由个人开发者周德建开发并运营。我们按照最小必要原则处理信息,并通过本政策说明数据的真实去向和你的选择。

本应用没有用户注册或登录体系,不要求你提供姓名、手机号、电子邮箱或身份证件等身份信息。

一、我们处理的信息

信息场景与用途实际去向
随机设备标识符(UUID)区分设备、统计每日活跃、计算免费用量、关联 Premium 状态、响应删除请求Keychain;随业务请求进入 Aurmo 境内 backend,并写入设备维度记录
Apple 交易凭证与购买状态验证和恢复购买;分析会员续订状态与产品价值采用情况StoreKit;交易 JWS 和 Apple Server Notifications 发送至 Aurmo backend 验签,保存当前状态、到期时间、续订开关、原始交易 ID,以及功能上线后捕获的续订开关变化。Admin 可按随机 device ID 将这些事实与下述匿名日使用聚合关联;不保存节目、单集、播放位置、搜索词、文字、录音或逐步使用轨迹,不用于广告或跨 App 追踪
公开播客信息与全文转写你主动触发全集转写公开 RSS 信息与 device ID 进入 Aurmo backend;公开音频由服务端获取,转写作为共享播客内容保存在境内 PG
公开播客文字上下文生成火花 AI 摘要经 Aurmo backend 发送给当前配置的大模型服务
插嘴录音的转写文字自动纠正同音字、专名和口语转写经 Aurmo backend 发送给当前配置的大模型服务;Aurmo PG 不保存输入或输出正文
可选 Notion 同步内容你主动连接 Notion 后,手动或自动同步内容到自己的 workspaceApp 直接向 Notion API 写入公开播客元数据、用户笔记、AI 摘要、Topic、收听历史和 Spark 录音。OAuth access token 通过 Aurmo backend 的临时 ticket 交接:最长保留 10 分钟,匹配 device ID 领取后立即删除,随后保存在 App Keychain
分享图片与分享文案你主动使用火花或整集分享时生成分享卡片。火花分享可由你选择是否包含“我的想法”;整集分享仅包含节目和单集的公开信息。分享网页链接不包含“我的想法”或用户录音分享图片在设备端生成;仅在你确认分享后交给 iOS 系统分享面板或微信 OpenSDK。创建短分享时,backend 可能短暂读取公开 RSS 并核对单集元数据;静态分享网页最长 180 天保存公开播客与单集标题、仅火花分享包含的时间点和 AI 摘要、以及经验证的封面 URL,不保存或返回 Feed URL、音频 URL、节目来源 URL、分享图片或与设备 ID 的长期关联,也不提供网页音频播放
每日活跃、聚合时长与功能使用次数统计有效使用、核心功能采用率、执行免费配额、结合 Premium 状态做匿名设备分群与维持服务运行App 前台连续使用至少 2 秒或成功保存标记 / 插嘴后,backend 按 device ID 和北京时间日期保存日活、首次见到与最近活跃时间;另按日累计前台使用秒数、实际播放秒数、每日标记、插嘴、转写、摘要和标注次数。核心行为与时长记录不含 Feed、单集、播放位置、文字或录音
有限产品交互事件分析从启动、首次引导、关注播客、有效播放、插嘴 / 摘要、分享选择到付费结果的使用路径,定位版本问题并改进留存仅在你同意本政策后,Aurmo backend 按 device ID 保存会话开始、onboarding 步骤结果、关注状态变化、同一次播放累计达到 30 秒、插嘴和摘要流程的开始 / 结束 / 固定结果、成功保存 Mark / Interject、整集分享的入口 / 去向 / 固定结果、付费墙展示、开始结账和固定购买结果等有限事件及发生 / 接收时间。事件可包含随机 session / flow / playback context ID、App 版本与 build、系统版本、语言地区、会员分群、入口、固定时长区间和结果;购买事件可包含固定 Apple 产品 ID,但不包含价格、交易凭证或错误原文。所有事件均不包含 Feed、节目、单集、分享链接、播放位置、搜索词、文字、录音、IDFA 或 IDFV。原始事件保留 90 天,不接入第三方分析 SDK,不用于广告或跨 App 追踪
播客热度、单集热度与预转写 / 推荐信号发现页热度榜、按真实使用情况选择预转写候选、了解用户更偏好的播客和单集类型订阅 / 取消订阅按 device ID + Feed URL 保存当前订阅状态;插嘴 / 打点按 device ID + Feed URL 汇总次数。单集有效播放设备、Mark、Interject、加入列表、标记播完行为和实际播放秒数按 device ID + canonical show episode 汇总,并保留最近一次事件对应的 Feed URL、原始 episode ID 和公开 RSS 单集元数据用于跨 Feed 合并。不保存播放位置、文字、录音或逐条事件时间线;旧客户端事件可能仅保留 Feed 级匿名计数,单集收听时长从支持版本上线后开始积累且不回填历史
新单集通知偏好、APNs token 与通知效果计数你选择“关注并提醒”或开启小铃铛后发送新单集通知,并评估提醒是否帮助用户回来收听Aurmo backend 按 device ID 保存 APNs token、环境、Feed URL、播客标题和通知开关;轮询状态保存 Feed URL、ETag / Last-Modified、最新公开 guid 和发送去重记录。CTA 选择、系统授权、开关、发送、点击 / 关闭及点击后 30 秒有效播放只按北京时间日期保存匿名总次数,不附带 device ID、Feed 或单集。点击后设备本地临时保存对应 Feed / 单集标识,仅用于 24 小时有效匹配窗口;匹配后删除,超期记录在下次读取或 App 启动时清理。不保存逐设备通知打开历史、播放位置、文字或录音
反馈、删除请求与审计记录处理反馈、执行并证明删除境内 backend;删除请求与必要审计记录会保留
网络信息安全、限流和基础设施运行IP 可能短暂用于限流并出现在安全 / 访问日志中,不用于广告、画像或位置推断

随机设备标识符不是 IDFA 或 IDFV,不用于广告或跨 App 追踪。它保存在 iOS Keychain 中,可能在卸载重装后继续存在。“重置应用数据”会保留该标识符,以便恢复购买和维持设备维度服务。

二、你的创作数据与 iCloud

Aurmo 使用一个 ModelContainer 和两个存储配置:

CloudKit private database 默认仅当前 iCloud 用户可访问,内容归该用户所有,生产 private records 不会在开发者门户中显示。Aurmo backend 不接收或读取这些 CloudKit records。CloudKit 由 Apple 运营;中国大陆 iCloud 由云上贵州(GCBD)运营,适用相应 iCloud 条款。

三、第三方服务

四、存储、安全与保留

五、你的权利与当前能力边界

六、未成年人保护

本应用不专门面向不满 14 周岁的儿童。未满 14 周岁者请在监护人指导和同意下使用。

七、政策更新与联系

重大变更会通过 App 内提示或本页面公布等方式告知,并在需要时重新征求同意。隐私问题或 backend 数据查询 / 删除请求请联系 support@aurmoapp.com

English

Welcome to Aurmo (the “App,” “Aurmo,” or “we”), developed and operated by individual developer Dejian Zhou. We process information only when reasonably necessary and explain its actual destination and your choices below.

Aurmo has no account registration or login system and does not require your name, phone number, email address, or government ID.

1. Information We Process

InformationScenario and purposeActual destination
Random device identifier (UUID)Distinguish a device, measure daily activity, calculate free quotas, associate Premium status, and respond to deletion requestsKeychain; sent with business requests to Aurmo's China-mainland backend and stored in device-scoped records
Apple transaction receipt and purchase statusVerify and restore purchases; analyze subscription-renewal status and observed product-value adoptionStoreKit transaction JWS and App Store Server Notifications are verified by Aurmo's backend, which stores current status, expiration, auto-renew setting, original transaction ID, and auto-renew changes captured after this feature launches. Admin may associate these facts with the anonymous daily aggregates below by random device ID. This does not store shows, episodes, playback positions, search queries, text, recordings, or step-by-step usage trails, and is never used for advertising or cross-app tracking
Public podcast information and full transcriptsProcess a full-episode transcription you requestPublic RSS information and device ID go to Aurmo's backend; the server fetches public audio and stores the shared transcript in a China-mainland PostgreSQL database
Public podcast text contextGenerate an AI summary for a SparkSent through Aurmo's backend to the currently configured LLM provider
Transcript of your interject recordingAutomatically correct homophones, names, and speech-recognition errorsSent through Aurmo's backend to the configured LLM provider; Aurmo's PostgreSQL database stores neither input nor output body
Optional Notion sync contentManually or automatically sync content to your own workspace after you connect NotionThe App writes public podcast metadata, your notes, AI summaries, Topics, listening history, and Spark recordings directly to the Notion API. The OAuth access token passes through a temporary Aurmo-backend ticket retained for at most 10 minutes and deleted immediately after a matching device ID claims it; the App then stores it in Keychain
Share image and share messageGenerate a share card when you actively use Spark or whole-episode sharing. Spark sharing can include “My Thought” when you choose; whole-episode sharing contains only public show and episode information. Share webpage links contain neither “My Thought” nor user recordingsShare images are generated on device and handed to the iOS share sheet or WeChat OpenSDK only after you confirm sharing. When a short share is created, the backend may briefly read public RSS to verify episode metadata. For up to 180 days, the static webpage stores public podcast and episode titles, a timestamp and AI summary for Spark shares only, and verified artwork URL. It does not store or return Feed, audio, or source URLs, does not store the share image or a long-term device ID association, and does not offer webpage audio playback
Daily activity, aggregate duration, and feature usage countsMeasure effective usage and core-feature adoption, enforce free quotas, combine with Premium status for anonymous device cohorts, and operate the serviceAfter at least two foreground seconds or a successfully saved mark / interject, daily activity, first-seen time, and latest-active time are stored by device and Beijing-calendar day, plus daily aggregate foreground seconds, actual playback seconds, mark, interject, transcription, summary, and annotation counts. Core-action and duration records contain no feed, episode, playback position, text, or recording
Limited product-interaction eventsAnalyze journeys from launch, onboarding, following a podcast, effective playback, interject / summary flows, sharing choices, and paywall outcomes; identify version-specific problems; and improve retentionOnly after you consent to this policy, Aurmo's backend stores a limited set of events by device ID: session start, onboarding-step outcome, subscription-state change, reaching 30 seconds of cumulative listening in one playback context, interject and summary start / end with fixed outcomes, successfully saving a Mark / Interject, whole-episode share entry / destination / fixed result, paywall view, checkout start, and fixed purchase outcome, together with occurrence and receipt times. Events may include random session / flow / playback-context IDs, App version and build, OS version, locale, membership cohort, entry source, fixed duration buckets, and result. Purchase events may include a fixed Apple product ID but no price, transaction receipt, or raw error. No event contains a feed, show, episode, share URL, playback position, search query, text, recording, IDFA, or IDFV. Raw events are retained for 90 days, use no third-party analytics SDK, and are never used for advertising or cross-app tracking
Podcast popularity, episode popularity, and pre-transcription / recommendation signalsDiscovery rankings, pre-transcription candidate selection from real usage, and understanding which podcast and episode types users preferSubscribe / unsubscribe events store current subscription state by device ID and feed URL; interject / mark events are aggregated by device ID and feed URL. Episode-level effective-play devices, mark, interject, queue, marked-played actions, and actual playback seconds are aggregated by device ID and canonical show episode, with the latest feed URL, raw episode ID, and public RSS episode metadata retained for cross-feed merging. No playback position, text, recording, or per-event timeline is stored; legacy-client events may remain as feed-level anonymous counters, and episode listening duration begins accumulating only in supported versions without historical backfill
New-episode notification preferences, APNs token, and effect countersSend a new-episode notification after you choose “Follow & Notify” or enable the bell, and assess whether reminders help listeners returnAurmo backend stores the APNs token, environment, Feed URL, podcast title, and notification preference by device ID. Feed polling stores the Feed URL, ETag / Last-Modified, latest public guid, and send-deduplication records. CTA choice, system authorization, toggle, send, tap / dismiss, and 30-second effective play after a tap are stored only as anonymous totals by Beijing-calendar day, without device ID, Feed, or episode. The device temporarily keeps matching Feed / episode identifiers solely for a 24-hour attribution window; it deletes them after a match and clears an expired record on the next read or App launch. No per-device notification-open history, playback position, text, or recording is stored
Feedback, deletion requests, and audit recordsProcess feedback and perform and demonstrate deletionChina-mainland backend; deletion requests and necessary audit records are retained
Network informationSecurity, rate limiting, and infrastructure operationIP may be used temporarily for rate limiting and appear in security / access logs; never used for advertising, profiling, or location inference

The random device identifier is not IDFA or IDFV and is never used for advertising or cross-app tracking. Because it is stored in iOS Keychain, it may survive app deletion and reinstallation. “Reset App Data” keeps it so purchases can be restored and device-scoped services can continue.

2. Your Content and iCloud

Aurmo uses one ModelContainer with two storage configurations:

By default, a CloudKit private database is accessible only to the current iCloud user, its content is owned by that user, and production private records are not visible in the developer portal. Aurmo's backend does not receive or read those records. CloudKit is operated by Apple; iCloud in China mainland is operated by GCBD under the applicable iCloud terms.

3. Third-Party Services

4. Storage, Security, and Retention

5. Your Rights and Current Product Limits

6. Children

Aurmo is not specifically directed to children under 14. If you are under 14, use Aurmo only with your guardian's guidance and consent.

7. Updates and Contact

We will announce material changes in the App or on this page and request renewed consent when required. For privacy questions or backend data access / deletion requests, email support@aurmoapp.com.