Cadence 隐私政策
最后更新日期:2026 年 10 月 | 适用版本:Cadence for iOS
核心承诺:Cadence 是一款本地优先 (Local-First) 应用。您的日程、习惯打卡、计划备注等所有核心数据仅保存在您的个人设备上。我们不设置用户账户、不收集个人数据、不包含任何第三方追踪或广告 SDK。
1. 数据存储与本地优先架构
Cadence 在设计之初即贯彻“数据所有权归于用户”的原生设计理念:
- 本地数据库:所有提醒事项 (Reminders)、计划 (Plans)、阶段打卡记录 (Cadence Chains & Check-Ins) 均直接存储于您设备本地的 SwiftData / CoreData 数据库中。
- 无远程服务器:我们不运营任何存储您个人日程或任务的云端数据库,您无需注册账户,亦无需提供手机号、邮箱或任何身份凭据。
2. 零数据收集与无追踪声明 (No Tracking)
根据 Apple 隐私清单规范 (Privacy Manifest, PrivacyInfo.xcprivacy):
- 不进行跨应用追踪 (NSPrivacyTracking: false):Cadence 绝不追踪用户行为,不使用广告标识符 (IDFA),亦不与任何数据经纪商共享信息。
- 零收集数据类型 (NSPrivacyCollectedDataTypes 为空):我们不会收集或向任何外部服务器上传您的姓名、通讯录、位置、设备标识、网络浏览记录或待办内容。
3. iOS 系统权限与 API 使用规范
为了在 iOS 系统上提供流畅的提醒体验,Cadence 会请求以下系统能力:
- 本地通知 (Local Notifications):应用通过系统
UNUserNotificationCenter 在设备本地排程并投递提醒。所有通知标题和正文均在设备内部生成并由 iOS SpringBoard 调度,不通过任何第三方远程推送服务 (APNs) 服务器转发。
- 小组件与 App Group (UserDefaults):为在桌面及锁屏小组件 (Widget) 中显示当日待办计数和语言偏好,应用使用苹果授权的 App Group (
group.jzhone.Cadence)。根据 Apple 隐私理由规范:
CA92.1:仅用于记录主应用的语言、新手引导等基础界面偏好。
1C8F.1:仅用于将语言和设置同步至同套件的小组件扩展。数据绝不离开设备。
- 实时活动 (Live Activities):仅在本地 ActivityKit 框架内渲染您正在进行的阶段习惯状态,无需任何外部网络支持。
4. 本地加密备份与导出
Cadence 支持离线备份与迁移功能:
- 高强度本地加密:导出的备份文件采用行业标准 AES-GCM-256 算法加密,密钥由用户自行输入的密码通过安全密钥派生算法派生。
- 密码自持原则:开发者无法获知、存储或恢复您的解密密码。若您遗忘密码,数据将无法恢复,请妥善保管。
5. 端侧自然语言解析
Cadence 提供的多活动自然语言计划解析功能完全在您的设备本地通过高效规则语法引擎运行,绝不会将您的文本发送至云端大语言模型 (LLM) 或第三方 AI 服务。
6. 应用内购买与订阅 (StoreKit 2)
Cadence Pro 的高级订阅服务由 Apple StoreKit 2 官方系统提供支持:
- 所有支付交易、信用卡信息与扣费均由 Apple 直接处理,并遵循 Apple 隐私政策。
- 开发者仅接收 Apple 返回的经加密签名的匿名交易凭证以解锁功能,无法获取您的任何财务或银行信息。
7. 诊断日志脱敏 (Privacy-Safe Diagnostics)
在用户主动导出系统排程诊断信息时,内置的脱敏引擎 (Privacy Scrubber) 会默认过滤掉所有待办标题、备注、解析器文本及备份密码,仅保留底层的结构化错误码(如系统排程上限或时钟状态),确保您的个人生活轨迹绝不外泄。
8. 政策更新与联系方式
如本隐私政策有任何调整,我们将在应用内及本页面公布最新版本。如您对本政策有任何疑问,请通过以下方式联系开发者:
开发者联系支持:jzhone@gmail.com
Cadence Privacy Policy
Last Updated: October 2026 | Effective for: Cadence iOS Application
Core Principle: Cadence is built on a strict local-first architecture. All your habits, reminders, and plan notes reside exclusively on your personal device. We require no user accounts, perform zero data collection, and include zero third-party tracking or analytics SDKs.
1. Local-First Architecture & Data Storage
- On-Device Storage: All reminders, Cadence Chains, check-ins, and notes are stored strictly in the local SwiftData / CoreData database on your device.
- No Central Cloud Database: We do not operate cloud servers to store your personal schedule or habits. You are never required to sign up or provide email, phone, or identity credentials.
2. Zero Data Collection & No Tracking
In accordance with Apple's Privacy Manifest (PrivacyInfo.xcprivacy):
- No Tracking (
NSPrivacyTracking: false): Cadence never tracks you across apps or websites, does not use advertising identifiers (IDFA), and never shares information with data brokers.
- No Data Collected: We do not collect or upload names, contacts, precise locations, device IDs, or schedule contents to remote servers.
3. Apple System Permissions & APIs
- Local Notifications: Scheduled strictly via the iOS
UNUserNotificationCenter framework. Notifications are created and fired locally by iOS SpringBoard without relaying through remote APNs servers.
- Widgets & App Group (UserDefaults): Shared via App Group (
group.jzhone.Cadence) to render widget counts and sync language preferences:
- Reason
CA92.1: App-only interface and onboarding preferences.
- Reason
1C8F.1: Synchronizing settings with the bundled widget extension.
- Live Activities: Managed locally via ActivityKit to present ongoing timers and routines on the Lock Screen and Dynamic Island.
4. Encrypted Backups & Export
Exported backups are encrypted locally using AES-GCM-256 with a key derived from your user passphrase. The developer has no access to your passphrase and cannot restore forgotten keys.
5. On-Device Natural Language Parser
Natural language parsing is executed entirely on-device using structured syntactic algorithms, without sending user input to cloud LLMs or remote APIs.
6. In-App Purchases & Subscriptions (StoreKit 2)
Cadence Pro subscriptions are processed securely by Apple's StoreKit 2. All billing and card information is handled directly by Apple under its privacy policy. The developer only receives anonymous cryptographic receipts to unlock Pro features.
7. Privacy-Safe Diagnostics
When generating diagnostic logs, sensitive task titles, notes, and passphrases are automatically redacted by the on-device privacy scrubber.
8. Contact Us
For questions regarding this Privacy Policy, please contact: jzhone@gmail.com