隐私政策 / Privacy Policy
核心承诺:「无极开物」采用零知识端到端加密架构。您的编程对话、终端输入与代码片段在离开发送设备前已完成端到端加密,我们的服务器与中继节点无私钥,无法也绝不解密您的私有内容。
一、适用范围
本隐私政策适用于乾元执中(南京)科技有限公司(以下简称“乾元执中”或“我们”)运营的公司官方网站,以及由我们开发、运营的移动客户端应用程序「无极开物」(以下简称“App”或“本应用”,英文代称:Kaiwu / Wuji Kaiwu)。
本政策旨在向您清晰说明我们如何收集、使用、存储、共享您的个人信息,以及您所享有的查阅、更正、删除个人信息与注销账号的权利。若您在自托管(Self-Hosted)环境中部署并运行服务端,您的数据将由该服务器的运营者管理,我们不触碰亦不承担该自建节点的管理责任。
二、我们收集与处理的信息
我们严格遵循“合法、正当、必要和诚信”原则,仅收集实现软件功能所必需的信息:
1. 端到端加密数据(服务器不可解密)
- 会话消息与代码内容:您在「无极开物」中与 AI 智能体之间的所有对话、指令输入、终端操作记录及代码片段,在传输前均在您的设备本地完成高强度端到端加密(E2EE)。
- 加密密钥:当您在多台设备间进行配对授权时,加密密钥仅以密文形式在设备之间传输。我们的服务器仅负责加密数据的安全中继与暂存,无权也无法获取私钥进行解密。
2. 元数据(用于通信路由与同步)
- 会话与消息标识符:用于维持会话生命周期与消息正确定序的随机 ID(Message ID、Session ID)。
- 时间戳:消息生成与设备同步的时间戳记。
- 匿名设备标识符:用于保障设备间安全配对绑定的匿名化标识符(Device ID)。
- 推送通知令牌(Push Token):用于向系统通知服务(如 Apple APNs、Google FCM 及 Expo 推送服务)发送消息提醒凭证。
3. 账户信息
本应用基于密码学公私钥对生成数字身份标识符(公钥 ID 及认证令牌)。您无需提供真实姓名、手机号码或身份证件即可使用基础功能。若您主动设置公开昵称(Username),我们将保存该字符用于展示。
4. 我们明确不收集的信息
- 绝不收集或查看您的明文代码、会话内容或私有开发资产;
- 不收集您的手机通讯录、短信、通话记录及社交好友信息;
- 不强制收集个人面部识别、指纹等生物识别敏感数据;
- 不主动追踪未经授权的连续精确定位数据。
三、设备权限调用与用途
为了实现各项核心产品功能,App 可能会在您主动触发相关功能时,向操作系统申请以下设备权限。我们绝不超出所述范围使用权限:
| 操作系统 | 权限名称 / 配置项 | 调用目的与具体业务场景 |
|---|---|---|
| iOS | NSMicrophoneUsageDescription麦克风权限 |
用于与 AI 进行实时语音对话、语音指令输入以及音频交互。仅在您主动点击麦克风时录制。 |
| iOS | NSSpeechRecognitionUsageDescription语音识别权限 |
用于将用户输入的语音转换为文本,以实现端侧语音转写与对话输入。 |
| iOS | NSPhotoLibraryUsageDescription相册读取权限 |
用于用户在会话中主动选取图片、截图或照片发送给 AI 进行多模态代码分析与视觉交互。 |
| iOS | NSPhotoLibraryAddUsageDescription相册保存/添加权限 |
用于用户主动将生成的图片、图表或导出的会话内容保存到系统相册。 |
| iOS | NSLocationWhenInUseUsageDescription使用期间位置权限 |
仅在用户主动授权时使用,用于辅助 AI 根据粗略地理上下文提供精准的本地化开发辅助与回答。 |
| iOS | NSLocalNetworkUsageDescription本地网络权限 |
用于在同一局域网(LAN)内发现、直连本地开发机、个人服务器及终端守护进程。 |
| iOS / Android | expo-camera相机权限 |
用于扫描二维码快速完成设备配对授权,以及拍照上传供 AI 进行代码分析。 |
| Android | android.permission.RECORD_AUDIO麦克风录音权限 |
用于语音输入、实时语音通话与 AI 语音交互。 |
| Android | android.permission.MODIFY_AUDIO_SETTINGS修改音频设置权限 |
用于控制扬声器播放、实时音频流控制及切换通话音频路由。 |
| Android | android.permission.ACCESS_NETWORK_STATE访问网络状态权限 |
用于检测网络连接与切换状态,确保中继同步通道能够及时重连。 |
| Android | android.permission.POST_NOTIFICATIONS发送通知权限 |
用于在后台向用户发送会话任务完成、长耗时任务状态更新的推送提醒。 |
| Android | android.permission.ACTIVITY_RECOGNITION身体活动识别权限 |
明确禁用/拦截:本应用已在配置中显式拦截(blocked)该权限,绝不获取用户的身体活动信息。 |
四、数据存储与跨境传输
1. 存储地点与中继服务
本服务官方默认的云端中继中转域名为 https://kaiwu.chengqiyun.com(应用 Deep Link 域名为 app.chengqiyun.com)。同时,我们支持高级用户自行配置自建服务器(Self-Hosted Relay)。
2. 跨境传输说明
为了保障产品的高可用性、崩溃诊断与基础运维服务,部分非敏感数据可能传输至境外服务节点:
- 数据分析(PostHog):服务运行于 PostHog 的欧盟区域(德国法兰克福)。我们仅上传匿名应用生命周期与使用事件,所有事件均通过机密密钥派生的匿名化 ID 发送,绝不包含用户会话、代码或可识别个人身份的信息。
- 崩溃排查(Sentry):仅在应用发生运行时崩溃或严重异常时,向 Sentry 服务上报调用堆栈与环境诊断参数,代码内容与敏感会话在此过程中均做脱敏过滤。
- 订阅管理(RevenueCat):仅用于处理 App Store 购买凭证校验与订阅状态同步,处理数据仅限匿名账户 ID。
特别说明:由于端到端加密机制,您的对话、代码及终端数据全程处于密文状态,无论通过何种境内外网络节点传输,均无法被解密。
3. 数据保留期限
- 端到端加密消息在服务器端保留至用户主动删除或申请注销;
- 元数据保留期限严格限制在提供网络同步所必需的最短时间内;
- 当收到用户明确的数据删除或注销申请并核验无误后,相关数据将在 30 个自然日内从生产服务器中永久删除。
五、信息共享与第三方 SDK
乾元执中承诺:我们绝不向任何第三方出售、出租或出借您的个人信息。本应用的部分版本可能集成以下服务,具体以所发布版本为准:
| 第三方 SDK 名称 | 服务机构 / 提供方 | 收集数据类型与用途 | 退出 / 控制途径 |
|---|---|---|---|
| PostHog (posthog-react-native) | PostHog, Inc. (欧盟节点) | 匿名应用交互事件、设备型号、系统版本(用于优化产品交互,不含对话与代码内容) | App「设置 - 隐私」中提供开关,可随时一键完全关闭(Opt-out) |
| Sentry (@sentry/react-native) | Functional Software, Inc. | 应用崩溃堆栈、异常诊断日志、设备运行时环境参数 | App「设置 - 隐私」中提供开关,可随时关闭崩溃报告(crashReportsOptOut) |
| RevenueCat (react-native-purchases) | RevenueCat, Inc. | 匿名账户 ID、应用内购买收据、订阅状态 | 遵循 App Store 系统内购管理规则,购买数据与分析数据严格隔离 |
| Expo Notifications | 650 Industries, Inc. (Expo) | 设备推送 Token,用于实现角标更新及系统通知推送。内容在设备本地生成,后端不拼接明文消息 | 可在系统设置中随时关闭应用的系统通知权限 |
| ElevenLabs | ElevenLabs, Inc. | 语音音频流(仅在用户主动发起 ElevenLabs 实时语音会话时调用) | 不主动开启实时语音通话时不传输任何语音数据 |
未启用与澄清项
- LiveKit:工程配置中虽存在插件声明,但在生产环境核心业务中未实际启用,不收集任何用户数据。
- Firebase:本应用未接入 Firebase 运行时统计与分析 SDK。
六、用户权利保障与账号注销途径
根据《中华人民共和国个人信息保护法》等法律法规,您对您的个人信息享有充分的控制权:
- 查阅与复制:您可在 App 内查看您的设备绑定状态、公钥标识及同步数据。
- 更正信息:您可随时在 App「设置 - 账户」中更新您的个人公开昵称。
- 删除数据与注销账号的专门途径: 由于「无极开物」采用基于公私钥对的匿名与去中心化安全架构,为防止误操作并确保请求系由资产拥有者本人发起,用户如需删除服务器存储的全部历史同步数据、重置身份凭据或彻底注销账号,请发送电子邮件至官方联系邮箱:wuji@wujilabs.cn。 请在邮件中提供您的公钥标识(Public ID)或认证凭据辅助验证,我们将在核验您的身份后 15 个工作日内完成注销与数据物理清除,并向您反馈处理结果。
- 自主退出与授权撤回:您可随时在 App 危险区(Danger Zone)点击“退出登录(Logout)”切断当前设备关联;并可在 App 内随时开关数据分析及崩溃收集选项。
七、未成年人信息保护
我们的产品与服务主要面向成年软件工程师、开发者及技术专业人员,我们不以 14 周岁以下未成年人为目标用户群体,亦不会主动收集未成年人的个人信息。若父母或监护人发现未成年人未经同意使用了我们的服务,请通过联系邮箱与我们取得联系,我们将在核实后立即删除相关数据。
八、政策更新与通知
我们可能会根据法律法规变化、产品功能升级适时修订本隐私政策。若发生重大变更,我们将在 App 客户端内推送通知或在官方网站主页显著位置公示。若您在修订政策生效后继续使用本服务,即表示您已充分阅读并同意受更新后的政策约束。
九、联系方式与主体信息
如您对本隐私政策有任何疑问、意见、建议或需要进行权利投诉,请通过以下途径联系我们:
- 企业名称:乾元执中(南京)科技有限公司
- 英文名称:Qianyuan Zhizhong (Nanjing) Technology Co., Ltd.
- 统一社会信用代码:91320191MAKGB4A45F
- 注册地址:江苏省南京市江北新区研创园华创路73号韦恩大厦C座983-4室
- 官方联系邮箱:wuji@wujilabs.cn
我们将尽快审核您的问题,并在验证身份后的 15 个工作日内予以答复与处理。
Privacy Policy (English Translation)
Core Commitment: "Kaiwu" (Wuji Kaiwu) is built on a zero-knowledge, end-to-end encrypted architecture. Your AI conversations, terminal commands, and code snippets are encrypted on your device before transmission. Our relay servers do not hold private keys and cannot decrypt your confidential data.
1. Scope
This Privacy Policy applies to the official website and the mobile application "Kaiwu" (also referred to as "Wuji Kaiwu" or the "App") operated and maintained by Qianyuan Zhizhong (Nanjing) Technology Co., Ltd. ("Qianyuan Zhizhong", "we", "us", or "our").
This Policy explains how we collect, use, store, and share information, as well as your rights to access, correct, delete your data, and terminate your account. If you choose to run a self-hosted relay server, your data is governed by the operator of that infrastructure, and we have no access to or liability for self-hosted instances.
2. Information We Collect and Process
We adhere to the principles of data minimization, lawfulness, and fairness:
- End-to-End Encrypted Data: All programming conversations, prompts, terminal outputs, and code files are encrypted locally on your client device using AES-256-GCM. Session keys are secured via X25519 key exchange, and account settings are ciphered via Libsodium SecretBox (XSalsa20-Poly1305). We store only encrypted ciphertexts and have no ability to decrypt them.
- Metadata: To facilitate routing, sync, and ordering, we process anonymous identifiers including Message IDs, Session IDs, timestamps, anonymous Device IDs, and push notification tokens.
- Account Data: Accounts are identified by cryptographic key pairs and authorization tokens. You can use the core software without providing your real name, phone number, or government identification. Optional public display names (usernames) may be stored if explicitly configured.
- What We Do NOT Collect: We never collect plaintext code or conversation contents, address books, SMS logs, biometric identifiers, or unauthorized continuous fine location data.
3. Device Permissions and Purposes
When required to perform user-initiated operations, the App may request specific system permissions:
- iOS - NSMicrophoneUsageDescription: Microphones are used for voice-based conversations and audio interaction with AI agents.
- iOS - NSSpeechRecognitionUsageDescription: Converts spoken speech into text on-device for transcription and prompt drafting.
- iOS - NSPhotoLibraryUsageDescription & NSPhotoLibraryAddUsageDescription: Allows users to attach images for multimodal analysis and save exported artifacts or charts into the system photo library.
- iOS - NSLocationWhenInUseUsageDescription: Used only when explicitly allowed to provide localized context for AI suggestions.
- iOS - NSLocalNetworkUsageDescription: Discovers and connects to local development machines and daemon sessions within the same local network.
- iOS & Android - Camera (expo-camera): Scans QR codes for instant device pairing and captures images for code analysis.
- Android - RECORD_AUDIO & MODIFY_AUDIO_SETTINGS: Records user voice input and manages audio stream routing for calls.
- Android - ACCESS_NETWORK_STATE: Monitors network availability to maintain reliable relay reconnection.
- Android - POST_NOTIFICATIONS: Displays background completion updates and push alerts for long-running workflows.
- Android - ACTIVITY_RECOGNITION: Explicitly blocked and disabled in the App build configuration.
4. Data Storage and Cross-Border Transfers
Our canonical relay server is hosted at https://kaiwu.chengqiyun.com (mobile deep link host: app.chengqiyun.com). Users may also configure private self-hosted relay instances.
For telemetry and infrastructure stability, certain non-sensitive operational data is processed through international endpoints:
- PostHog Analytics: Hosted in PostHog's EU region (Frankfurt, Germany). Collects basic anonymized application usage events using anonymized IDs derived from private seeds. No code, message content, or personal identifiers are ever sent. Can be disabled at any time.
- Sentry Crash Diagnostics: Gathers technical crash logs and stack traces upon uncaught exceptions. Stripped of user secrets and code. Can be disabled in app settings.
- RevenueCat: Validates App Store subscription receipts and manages entitlement statuses based on anonymous account IDs.
Because all messages and code are end-to-end encrypted, intermediate relay nodes and overseas network routes can never read your plaintext data.
5. Third-Party SDK Integrations
Qianyuan Zhizhong commits: We never sell, rent, or lease your personal information. Certain versions of the App may integrate the following services, subject to the specific released build:
| SDK / Library | Provider | Data Processed & Purpose | Opt-Out / Control |
|---|---|---|---|
| PostHog | PostHog, Inc. (EU Region) | Anonymized usage telemetry to improve app usability. No message or code content. | Toggle off under Settings > Privacy > Analytics. |
| Sentry | Functional Software, Inc. | Stack traces and runtime diagnostics for crash investigation. | Toggle off under Settings > Privacy > Crash Reports. |
| RevenueCat | RevenueCat, Inc. | Anonymous account ID and in-app purchase receipts. | Managed via Apple ID / App Store subscription settings. |
| Expo Notifications | 650 Industries, Inc. (Expo) | Device push tokens. Content is constructed locally on device; backend sends badge refreshes. | Disable notification permissions in OS settings. |
| ElevenLabs | ElevenLabs, Inc. | Realtime audio stream during user-initiated voice calls. | Inactive unless user initiates a voice session. |
Clarification: LiveKit is declared as a dependency but not activated in production flows; Firebase SDK is not included in the runtime app bundle.
6. User Rights and Account Deletion Procedures
You have full rights to access, update, export, and delete your information under applicable data protection laws:
- In-App Controls: You can edit your display name, toggle analytics and crash reporting, and disconnect devices via "Logout" in Settings.
- Account Deletion & Data Erasure: Because our architecture relies on cryptographic keys and tokens rather than centralized passwords, requests to completely purge your server-side synchronized records, delete stored metadata, or terminate an account must be submitted by emailing our designated privacy team at wuji@wujilabs.cn. Please provide your Public ID to verify ownership. We will verify and permanently delete your server-side records within 15 business days.
7. Children's Privacy
Our services are geared towards software developers and technical professionals. We do not knowingly solicit or collect data from children under the age of 14 (or the legal age of majority in your jurisdiction). If you believe a minor has provided us with personal information, please contact us immediately for prompt deletion.
8. Changes to this Policy
We may revise this Privacy Policy periodically. Significant changes will be announced within the App or on our website. Continued use of our App after updates signifies your acceptance of the revised terms.
9. Contact Information
- Company: Qianyuan Zhizhong (Nanjing) Technology Co., Ltd.
- Chinese Entity: 乾元执中(南京)科技有限公司
- Unified Social Credit Code: 91320191MAKGB4A45F
- Address: Room 983-4, Block C, Wayne Building, No. 73 Huachuang Road, Yanchuang Park, Jiangbei New District, Nanjing, Jiangsu 210000, China
- Contact Email: wuji@wujilabs.cn