明日森林隐私政策 | Tomorrow Forest Privacy Policy

最后更新:2026 年 8 月 16 日 / Last updated: August 16, 2026

1. 我们处理的信息 / Information We Process

应用在你的设备本地保存你主动输入的推演内容、AI 结果与历史记录、语言/主题/触感等偏好和少量运行状态数据。历史默认仅保存在本地,你可以在应用内删除,或通过卸载应用删除本机应用数据。

The app stores on your device the reasoning content you actively enter, AI results and history, language/theme/haptics preferences, and limited operating-state data. History is local by default. You can delete it in the app or remove local app data by uninstalling the app.

Apple 登录是可选功能。服务端只保存由 Apple 稳定用户标识经单向哈希处理后的标识,以及必要的账户、使用次数和安全状态;不以明文保存该标识。对于需要服务端维护上下文的多步推演,服务端还会保存根问题、生成路径、节点和必要上下文,用于恢复、延伸和幂等;删除账户时删除这些服务端推演内容。Apple 授权返回的姓名和邮箱仅在本机用于登录展示/本地状态,公开候选服务端不把这些字段写入账户或诊断日志。设备证明和防滥用流程会保存经过单向哈希的设备/App Attest 标识;账户删除后,部分反滥用哈希可能按必要目的保留最长 180 天。

Sign in with Apple is optional. The server keeps only a one-way-hashed form of Apple's stable user identifier, plus necessary account, usage, and security state; it does not retain that identifier in plain text. For multi-step reasoning that needs server-owned context, the server also stores the root question, generated paths, nodes, and necessary context for recovery, extensions, and idempotency; this server-side reasoning content is deleted when the account is deleted. Name and email returned by Apple are used only on-device for sign-in display/local state; the public candidate server does not write them to account or diagnostic records. Device attestation and anti-abuse flows retain one-way-hashed device/App Attest identifiers; after account deletion, some anti-abuse hashes may remain for up to 180 days where necessary.

当前公开 Release 不提供手机号绑定入口,因此不会从当前公开 App 新采集手机号。服务端代码中保留的手机号绑定能力属于未暴露的历史/内部能力;如果未来重新开放,必须先同步更新隐私政策、App Privacy 标签和版本说明。对于确实存在的历史账户绑定,解绑或账户注销流程会按适用规则处理关联绑定和未完成验证码挑战记录。

The public Release does not expose phone-number binding and therefore does not newly collect phone numbers through the public app. Phone binding code retained on the server is dormant historical/internal capability; if it is reopened, the Privacy Policy, App Privacy label, and release notes must be updated first. Any historical account binding that actually exists is handled by the applicable unbinding or account-deletion process.

使用 StoreKit 购买或恢复权益时,服务端会处理经 Apple 验证的交易、订阅状态及必要交易标识,用于记录 5 次/50 次额度包、月度/年度订阅权益以及退款、撤销和账务审计结果;必要记录可能按适用义务保留,交易不会由客户端直接发放额度。

When you purchase or restore StoreKit benefits, the server processes Apple-verified transactions, subscription state, and necessary transaction identifiers to record 5-use/50-use packs, monthly/yearly subscription benefits, refunds, revocations, and accounting audit results. Necessary records may be retained where required. The client never grants these credits directly.

2. 防滥用领取记录 / Anti-Abuse Claim Record

为防止用户注销后重复注册或更换登录状态反复领取首次使用次数,并防范资源滥用和安全风险,服务端保留最小化的防滥用领取记录(anti-abuse claim tombstone):不可逆 SHA-256 处理后的设备标识和/或 Apple subject 标识、首次领取时间及领取类型。该记录不保存原始标识、AI 输入输出或账户内容,不用于画像、广告、向其他用户展示或恢复已注销账户。

To prevent repeated registration or changed sign-in states from being used to repeatedly claim first-use allowances after account closure, and to prevent resource abuse and security risks, the server keeps a minimal anti-abuse claim tombstone: an irreversible SHA-256 hash of a device identifier and/or Apple subject identifier, the first-claim time, and the claim type. It does not retain original identifiers, AI inputs or outputs, or account content, and is not used for profiling, advertising, display to other users, or restoring a closed account.

我们基于提供服务所必需的安全与防作弊目的及适用法律法规允许的其他处理依据,按必要、正当、最小范围原则处理该记录。建议常规保存期限为自注销、最后一次有效使用或最后一次风控事件(以较晚者为准)起 180 天,期满后删除或不可逆匿名化。为处理未结投诉、争议、疑似欺诈/攻击、安全事件或履行法律法规要求而确有必要时,可在必要的最短期间内例外留存;因此账户注销后不会立即删除该防滥用哈希记录。

We process this record under the necessary security and anti-cheating purpose of providing the service and other bases permitted by applicable laws and regulations, following necessity, legitimacy, and data-minimization principles. The recommended ordinary retention period is 180 days after the later of account closure, last valid use, or last risk-control event; it is then deleted or irreversibly anonymized. It may be retained exceptionally for the shortest necessary period to address an unresolved complaint, dispute, suspected fraud or attack, security incident, or a legal requirement. Therefore, account closure does not result in immediate deletion of this anti-abuse hash record.

3. AI 请求与数据流向 / AI Requests and Data Flow

你主动发起推演时,完成请求所必需的文本输入、语言和请求参数会经明日森林服务端代理发送至当前配置的阿里云百炼/DashScope Qwen 模型服务;最终公开版本的 Workspace、服务地域和 endpoint 以候选环境锁定结果为准。模型密钥只在服务端管理,应用不会要求你填写模型密钥。应用不提供用户之间的发帖、评论、私信、群组或社区功能,也不会向其他用户展示你的输入。

When you actively start a reasoning request, the text input, language, and request parameters needed to complete it are sent through Tomorrow Forest's server proxy to the configured Alibaba Cloud Model Studio/DashScope Qwen service; the final public Release's workspace, region, and endpoint will follow the locked candidate environment. Model keys are managed only on the server and are never requested in the app. The app has no posts, comments, direct messages, groups, or community features between users, and does not show your input to other users.

除上述服务端多步推演内容外,我们不将 AI 原始输入和输出作为普通请求日志的业务内容保存。为安全、限流、排障和投诉处理,服务端记录必要的安全诊断日志,例如哈希化账户标识、时间、结果、风险/错误代码、来源 IP 的必要安全信息、请求关联标识、构建/协议信息和延迟字段。安全日志保存 180 天后删除或匿名化,法律法规另有要求的除外;当前没有自有崩溃日志采集或客户端性能分析采集的证据。

Except for the server-side multi-step reasoning content described above, we do not retain raw AI inputs and outputs as business content in ordinary request logs. For security, rate limiting, troubleshooting, and complaint handling, the server records necessary diagnostic metadata, such as a hashed account identifier, time, result, risk/error codes, necessary IP-related security information, request correlation identifiers, build/protocol metadata, and latency fields. Security logs are deleted or anonymized after 180 days unless laws or regulations require otherwise; there is currently no evidence of first-party crash-log collection or client performance analytics.

阿里云百炼公开资料说明客户数据不用于模型训练,但也说明模型/应用调用产生的数据会因相关法律法规要求而存储;我们不会把 DashScope 描述为“零留存”或“请求后立即删除”。具体保留期限、产品专用处理规则和服务地域以实际使用的 Workspace、endpoint、模型产品和适用条款为准。

Alibaba Cloud Model Studio's public documentation says customer data is not used for model training, while also stating that data generated by model/application calls is stored as required by applicable laws. We do not describe DashScope as having zero retention or immediate deletion after a request. Specific retention periods, product-specific processing rules, and service region follow the actual workspace, endpoint, model product, and applicable terms.

Before a request reaches the model service, the server performs content-safety checks. If applicable laws, platform rules, or safety policies require rejection, the app will not call the model, display a reasoning result, or deduct the request allowance. The app will show: “根据相关法律法规要求,当前输入内容无法生成或显示推演结果,请修改后重试。” Security logs record only the time, request ID, account hash, risk code, policy version, and action result; they do not record the matched term or full input.

4. 免费试用与付费权益 / Trials and Purchases

当前版本提供游客最多 5 次试用、月度/年度自动续订订阅,以及 5 次和 50 次一次性额度包。月度订阅每个订阅月赠送 50 次,年度订阅每个订阅月赠送 100 次;有效订阅每日恢复 10 次,最多累计 50 次。每次新的推演消耗 1 次额度,同一推演内最多 10 次延伸不再额外扣账户额度。价格、税费、可用性、自动续订、恢复、退款和撤销以 App Store 及 Apple 条款为准。

The current version offers up to 5 guest trials, auto-renewing monthly/yearly subscriptions, and one-time 5-use and 50-use credit packs. Monthly subscriptions grant 50 credits per subscription month, yearly subscriptions grant 100 credits per subscription month, and active subscriptions restore 10 credits daily up to a cap of 50. Each new reasoning request consumes one credit; up to ten extensions within the same simulation do not consume additional account credits. Prices, taxes, availability, auto-renewal, restoration, refunds, and revocations are governed by the App Store and Apple's terms.

5. AI 标识与内容治理 / AI Labelling and Content Governance

AI 生成内容会以文字、图标或上下文提示明确作出显式标识,并按适用要求采用不影响正常使用的隐式标识;如系统基于规则作出风险提示、拦截或排序,也会在适用位置说明。请勿输入或借助本服务生成违法违规、侵权、诈骗、暴力恐怖、淫秽色情、仇恨歧视或其他有害内容。我们可拒绝处理明显有害请求、限制使用、保全必要记录、处理投诉或依法配合主管机关。

AI-generated content is clearly given an explicit label through text, an icon, or contextual notice, and uses an implicit label that does not affect normal use where required. Where the system provides a rule-based risk notice, block, or ranking, it will be indicated where applicable. Do not enter or use the service to create unlawful, infringing, fraudulent, violent or terrorist, pornographic, hateful, discriminatory, or otherwise harmful content. We may refuse clearly harmful requests, limit use, preserve necessary records, handle complaints, or cooperate with competent authorities as required by law.

6. 你的权利与联系我们 / Your Rights and Contact

你可在设置中删除本地历史、关闭触感反馈和 iCloud 同步,并删除本机 Apple 登录资料。当前公开版本没有手机号绑定入口;如账户存在历史绑定,账户页面删除服务端账户时会按适用规则处理。你也可以在账户页面直接删除服务端账户;Apple 账户删除前需要当前 Apple 账户重新授权,服务端会先撤销 Apple 授权,再使令牌失效并删除服务端推演内容、未完成验证码挑战和未使用账户额度。删除账户不会自动取消 App Store 自动续订,请在 Apple 订阅管理中单独取消。必要的购买、账务、安全、反滥用和争议审计记录可能按适用义务保留,反滥用安全哈希可能按必要期限保留。若要查询/更正个人信息、撤回同意、投诉或举报,请发送邮件至 tomorrowforest@outlook.com,并提供核验账户归属所必需的信息。

You may delete local history, turn off haptics and iCloud sync, and remove local Sign in with Apple data in Settings. The public Release has no phone-number binding entry; any historical binding is handled under the applicable account-deletion process. You can also directly delete your server account from the account page. Apple accounts must re-authorize with the current Apple account first; the server revokes the Apple authorization before invalidating the token and removing server-side reasoning content, unfinished verification challenges, and unused account credits. Account deletion does not cancel App Store auto-renewal; cancel it separately in Apple subscription settings. Necessary purchase, accounting, security, anti-abuse, and dispute-audit records may remain where required, and anti-abuse security hashes may remain for a necessary retention period. To access/correct personal information, withdraw consent, make a complaint, or report content, email tomorrowforest@outlook.com with the information needed to verify ownership.

7. 未成年人与更新 / Minors and Updates

未成年人请在监护人陪同下阅读和使用本应用,并在需要时取得监护人同意。处理目的、信息类型、保存期限、第三方接入或权利行使方式发生实质变化时,我们会通过应用内或本页面更新本政策。

Minors should read and use this app with a parent or guardian and obtain consent where required. If there is a material change to purposes, information categories, retention periods, third-party access, or how rights may be exercised, we will update this policy in the app or on this page.

官方参考:《中华人民共和国个人信息保护法》《生成式人工智能服务管理暂行办法》

Official references: Personal Information Protection Law of the PRC; Interim Measures for the Management of Generative AI Services.