Petta · Privacy
隐私政策Privacy Policy
简要说明:Petta 的核心功能无需登录;完成 Apple 登录后,Todo、专注记录和宠物非经济进度会同步到你自己的 iCloud 私有数据库。Screen Time 选择、当前计时、金币、食物和付费库存不会进入 iCloud。Petta 不销售个人信息,不投放第三方广告,也不使用这些数据进行跨 App 广告追踪。若启用 Pro,购买记录和订阅标识会由 Apple 与 RevenueCat 处理。
1. 适用范围与责任主体
本政策说明 待补充实际运营主体(“我们”)在你使用 Petta iOS 应用和相关页面时如何处理信息。Apple、RevenueCat 或你访问的其他第三方服务会依据其各自政策独立处理信息。
“处理”包括收集、存储、使用、传输、删除等活动。我们遵循最少必要原则,并尽可能让核心专注功能在不登录的情况下使用。
2. 我们处理的数据
Apple 将“收集”定义为数据离开设备并由开发者或第三方保留。本节特意区分“仅在设备上处理”和“发送给服务提供商”。
| 类别 | 示例与用途 | 当前位置 |
|---|---|---|
| 你创建的内容 | Todo 标题、分类、备注、安排时间、宠物名称,用于专注与陪伴功能。 | 保存在本机 SwiftData;Apple 登录后也写入你自己的 CloudKit Private Database。日历同步仅在你主动开启后写入 Apple 日历,日历事件 ID 不进入 CloudKit。 |
| 专注与成长数据 | 专注开始/结束时间、持续时长、完成状态、宠物心情、体力、亲密度、饱腹度和动作进度。 | 保存在本机;Apple 登录后同步到你的 CloudKit Private Database。当前计时、金币、食物、付费库存和小组件摘要不进入 CloudKit。 |
| Screen Time 选择 | 你选择限制的 App、类别或网站的不透明系统 Token,以及限额、禁用时段和开关。 | 仅保存在当前设备及其 App Group;我们不读取你具体的 App 使用明细,也不上传 Token。 |
| Apple 登录资料 | Apple 提供的稳定用户标识,以及你首次授权时选择提供的姓名和邮箱,用于本机登录状态与订阅恢复。 | 原始资料保存在设备 Keychain;Petta 不获取 Apple 密码。用户标识经 SHA-256 不可逆摘要后用于关联 RevenueCat 客户,姓名和邮箱不会因此发送给 RevenueCat。 |
| 订阅与购买 | 匿名 App User ID,或登录后由 Apple 用户标识生成的不可逆摘要 ID,以及商品和订阅状态、购买历史、Apple 收据、设备类型、操作系统、区域/货币等必要技术信息,用于展示权益、验证购买、恢复购买、防欺诈和订阅分析。 | 由 Apple 与 RevenueCat 处理;Petta 当前不接收支付卡号。 |
| 设备偏好与凭证 | 主题、提醒开关、调试或功能状态等偏好,以及必要的本机身份凭证。 | 保存在 UserDefaults、App Group 或 Keychain,视数据类型而定。 |
| 支持请求 | 如果你主动发邮件联系我们,我们会收到你提供的邮箱、问题描述和附件。 | 由我们的邮件服务提供商处理,并仅用于回复和解决问题。 |
Petta 当前未启用 HealthKit 步数读取。iCloud 同步只在你完成 Apple 登录后运行;离线时数据继续保存在本机,联网后自动合并,你也可以在“我的 → iCloud 同步”手动触发。请不要在自由文本 Todo 或备注中输入不必要的敏感信息。
3. iOS 系统权限
你可以拒绝或随后在 iOS 设置中撤回以下权限;拒绝只会影响对应功能,不影响无需该权限的基础专注体验。
- Screen Time / Family Controls:在你配置专注限制、每日限额或禁用时段时请求,用于按你的选择屏蔽 App、类别或网站。系统向 Petta 提供不透明 Token。
- 通知:在你启用 Todo 提醒时请求,用于发送本机通知。
- 日历:在你主动开启“同步到 Apple 日历”时请求,用于创建、更新或删除由 Petta 建立的 Todo 日历事件。
- Apple 登录:仅在你主动选择登录时发起;姓名和邮箱是否提供由你在 Apple 授权界面决定。
4. 处理目的与法律依据
我们为了以下目的处理必要数据:提供你请求的功能;保存本机进度和偏好;验证并恢复订阅;维护安全和防止欺诈;响应支持请求;履行法律义务;以及在必要时改进稳定性。
在适用法律要求说明法律依据的地区,依据可能包括履行与你的合同、你的同意、履行法定义务,以及在不损害你权利的前提下保障服务安全和运营的合法利益。你可随时撤回基于同意的授权,但不影响撤回前处理的合法性。
6. 保存期限与删除
- 本机数据:通常保存到你在 App 中删除相关内容、使用可用的重置功能,或从设备删除 Petta。请注意,删除 App 不会自动取消 Apple 订阅。
- iCloud 数据:已同步的 Todo、专注记录和宠物非经济进度保存在你的 CloudKit Private Database;在 Petta 中删除相关内容后,删除状态会在后续同步传播。删除单台设备上的 App 不等于立即删除 iCloud 副本。
- Keychain 数据:可能在卸载后仍由 iOS 保留。你可先在 Petta 内退出账号;如需协助删除,请联系我们。
- 订阅记录:由 Apple 和 RevenueCat 按提供服务、会计、争议、防欺诈及法律义务所需期限保存。部分交易记录依法可能无法立即删除。
- 支持记录:保存至问题解决及合理的后续、审计或法律期限届满,之后删除或去标识化。
Apple 登录原始资料和同步进度没有上传至 Petta 自建服务器;同步数据由 Apple 保存在你的私有 iCloud 容器中。你可在 App 中修改或删除内容并再次同步,也可通过 Apple 提供的 iCloud 管理方式管理相应数据。未来若接入 Petta 服务器账号,我们会另行提供相应的访问、导出与删除机制。
7. 你的权利与选择
你可以在 Petta 中查看、修改或删除 Todo 等内容并手动同步;也可以关闭通知和日历同步、撤回 Screen Time 授权、取消 Apple 登录授权,以及在 Apple ID 订阅设置中取消订阅。取消 Apple 登录会停止后续自动同步,但不会自动删除既有 iCloud 数据。
根据你所在地区的法律,你还可能有权请求了解、访问、更正、复制、删除或限制我们控制的个人信息,撤回同意,或反对特定处理。请通过下方邮箱提交请求。我们会验证请求者身份,并在法定期限内处理;若数据由 Apple 或 RevenueCat 独立控制,我们会指引你联系相应服务。
8. 数据安全
我们采用与风险相称的技术和组织措施,包括 iOS 沙盒、Keychain、App Group 权限隔离和传输加密等方式保护数据。但任何存储或传输方式都无法保证绝对安全。请保护设备密码和 Apple ID,并及时安装系统安全更新。
9. 未成年人
Petta 面向能够在当地法律下合法使用一般生产力应用的用户,不以儿童为主要目标,也不会明知向儿童索取超出提供功能所需的个人信息。未达到独立同意年龄的用户应在监护人同意和指导下使用。若你认为儿童在未经适当同意的情况下向我们提供了个人信息,请联系我们。
10. 跨境处理
Apple 和 RevenueCat 等服务可能在你所在国家或地区以外处理数据,包括美国。不同地区的数据保护法律可能不同。我们会在适用法律要求的范围内采用合同、同意或其他合法机制,并要求采取适当保护措施。
11. 本政策的变更
功能、合作方或法律要求变化时,我们可能更新本政策。重大变更会通过 App、此页面或其他合理方式通知,并更新生效日期;法律要求时会另行征得同意。建议你定期查看。
12. 联系我们
隐私问题、权利请求或投诉请发送至 待补充联系邮箱。运营主体:待补充实际运营主体。
中文版本与英文版本如有不一致,在适用法律允许的范围内,以中文版本为准。
In short: Petta's core features work without sign-in. After Sign in with Apple, to-dos, focus history, and non-economic pet progress sync to your private iCloud database. Screen Time selections, active timers, coins, food, and paid inventory are not synced to iCloud. We do not sell personal data, show third-party ads, or use this data for cross-app advertising. Apple and RevenueCat process purchase and subscription data if you use Pro.
1. Scope and controller
This Policy explains how Legal operator to be provided (“we,” “us,” or “our”) handles information when you use the Petta iOS app and related pages. Apple, RevenueCat, and other third-party services process some information independently under their own policies.
“Process” includes collecting, storing, using, transferring, and deleting information. We follow data-minimization principles and aim to keep core focus features usable without signing in.
2. Data we process
Apple defines “collection” as transmitting data off the device so a developer or third party can retain it. This section distinguishes on-device processing from data sent to providers.
| Category | Examples and purpose | Where it is handled |
|---|---|---|
| Content you create | To-do titles, categories, notes, scheduled times, and pet names used for focus and companionship. | Stored in local SwiftData and, after Sign in with Apple, in your CloudKit Private Database. Calendar items are written to Apple Calendar only when enabled; calendar event IDs are not sent to CloudKit. |
| Focus and progress | Start/end times, duration, completion, pet mood, energy, intimacy, fullness, and action progress. | Stored on device and, after sign-in, synced to your CloudKit Private Database. Active timers, coins, food, paid inventory, and widget summaries are not sent to CloudKit. |
| Screen Time selections | Opaque system tokens for apps, categories, or websites you restrict, plus limits, schedules, and toggles. | Only on the current device and its App Group. We do not read detailed app-usage history or upload the tokens. |
| Sign in with Apple | Apple's stable user identifier and the name or email you choose to provide on first authorization, used for local sign-in state and subscription recovery. | The original data remains in the device Keychain. Petta never receives your Apple password. A SHA-256 digest of the user identifier links the RevenueCat customer; this does not send your name or email to RevenueCat. |
| Subscriptions and purchases | An anonymous App User ID or, after sign-in, an irreversible digest ID derived from Apple's user identifier, plus product and entitlement status, purchase history, Apple receipt, device type, operating system, locale/currency, and necessary technical information used for access, validation, restoration, fraud prevention, and subscription analytics. | Processed by Apple and RevenueCat. Petta does not currently receive payment-card numbers. |
| Preferences and credentials | Theme, reminder toggles, feature state, and necessary local credentials. | UserDefaults, App Group, or Keychain, depending on the data. |
| Support requests | If you email us, we receive the address, description, and attachments you provide. | Handled by our email provider only to respond and resolve the issue. |
Petta does not currently enable HealthKit step access. iCloud sync runs only after Sign in with Apple. While offline, data remains available locally and merges automatically when connectivity returns; you can also trigger it from My → iCloud Sync. Please avoid placing unnecessary sensitive information in free-form to-dos or notes.
3. iOS permissions
You can decline or later withdraw the permissions below in iOS settings. Doing so affects only the related feature, not basic focus features that do not need it.
- Screen Time / Family Controls: requested when you configure focus restrictions, daily limits, or block schedules. iOS gives Petta opaque tokens for your selections.
- Notifications: requested when you enable to-do reminders, for local alerts.
- Calendar: requested only when you enable Apple Calendar sync, to create, update, or remove Petta-created events.
- Sign in with Apple: initiated only when you choose to sign in. You decide whether Apple provides your name and email.
4. Purposes and legal bases
We process necessary data to provide requested features, retain local progress and preferences, validate and restore subscriptions, maintain security and prevent fraud, respond to support, comply with law, and improve reliability where necessary.
Where the law requires a legal basis, these may include performing our contract with you, your consent, compliance with legal obligations, and legitimate interests in secure operation that do not override your rights. You may withdraw consent at any time without affecting processing already lawfully completed.
6. Retention and deletion
- On-device data: generally remains until you delete the related content in Petta, use an available reset, or delete Petta from the device. Deleting Petta does not cancel an Apple subscription.
- iCloud data: synced to-dos, focus history, and non-economic pet progress remain in your CloudKit Private Database. Deletions made in Petta propagate on a later sync. Deleting the app from one device does not necessarily immediately remove its iCloud copy.
- Keychain data: iOS may retain it after uninstall. Sign out in Petta first, or contact us for assistance.
- Subscription records: Apple and RevenueCat retain them as needed for service, accounting, disputes, fraud prevention, and law. Some transaction records cannot be deleted immediately.
- Support records: retained until resolution and a reasonable follow-up, audit, or legal period, then deleted or de-identified.
Original Sign in with Apple data and synced progress are not uploaded to a Petta-operated server; Apple stores synced data in your private iCloud container. You can edit or delete content in Petta and sync again, or use Apple's available iCloud data-management options. If we later add Petta server accounts, we will provide separate access, export, and deletion controls.
7. Your rights and choices
In Petta, you can review, edit, or delete content and manually sync it. You can also disable notifications and calendar sync, withdraw Screen Time permission, revoke Sign in with Apple authorization, and cancel subscriptions in Apple ID settings. Revoking sign-in stops future automatic sync but does not automatically erase existing iCloud data.
Depending on where you live, you may also ask to know, access, correct, copy, delete, or restrict personal data we control, withdraw consent, or object to certain processing. Send requests to the address below. We will verify identity and respond within applicable time limits. If Apple or RevenueCat independently controls data, we will direct you to the relevant provider.
8. Security
We use measures proportionate to risk, including the iOS sandbox, Keychain, App Group isolation, and encryption in transit. No storage or transmission method is completely secure. Protect your device passcode and Apple ID and install security updates promptly.
9. Children
Petta is intended for people legally able to use a general productivity app where they live. It is not directed primarily to children, and we do not knowingly ask children for personal data beyond what is needed to provide a feature. Users below the age of independent consent should use Petta with a guardian's approval and guidance. Contact us if you believe a child gave us personal data without appropriate consent.
10. International processing
Providers such as Apple and RevenueCat may process data outside your country, including in the United States, where privacy laws may differ. Where required, we rely on contracts, consent, or other lawful transfer mechanisms and require appropriate safeguards.
11. Changes to this Policy
We may update this Policy as features, providers, or laws change. We will give reasonable notice of material changes in the app, on this page, or by another appropriate method and update the effective date. We will obtain consent where required. Please review this page periodically.
12. Contact
Send privacy questions, rights requests, or complaints to Contact email to be provided. Operator: Legal operator to be provided.
If the Chinese and English versions differ, the Chinese version controls to the extent permitted by applicable law.