JotMind 隐私政策
本隐私政策说明三比一特科技(北京)有限公司(“三比一特”“我们”)在你使用 JotMind iOS App 或其发布网站时如何处理信息。
1. 网站与发布候补名单
sanbit.ai 不使用 Cookie,不加载第三方分析、广告脚本、第三方字体或 CDN 资源。除非你自己 填写候补名单表单,浏览这个网站不需要向我们提交任何信息。
如果你主动加入发布候补名单,我们只保存你填的那个邮箱地址——记录里就这 一个字段,没有 IP 地址、浏览器信息或访问来源。表单托管在 Cloudflare Pages,地址由 Cloudflare KV 代我们保存。作为网站托管商,Cloudflare 会在自己的访问日志里短暂保留 IP 等常规信息,用于送达 页面和抵御攻击,这些不会进入候补名单。
我们仅用这个地址发送一次 JotMind 发布通知,并在发送后 30 天内删除候补名单。你也可以随时 发送邮件至 jotmind-support@sanbit.ai 要求提前删除。
2. 留在设备上的内容
JotMind 只在你的设备上保存和处理以下内容:
- 麦克风录音;
- 转写和你输入的文字;
- 笔记内容、标题、整理后的 Markdown 及你的编辑;
- 临时搜索词和本地关键词搜索索引。
我们不会收到这些内容。JotMind 没有用户账号、内容服务器、云同步或远程 AI 总结。你的笔记会 不会随 iPhone 备份进 iCloud 或电脑,取决于你自己的系统备份设置;JotMind 只把体积大、可以重新 取得的 AI 模型文件排除在备份之外,免得白占你的备份空间。
3. 有限的使用与可靠性数据
JotMind 使用 Firebase Analytics 了解基础功能和端侧处理是否可靠。这项收集从你开始使用 App 时生效,并且对所有用户一视同仁——我们不会按你所在的国家或 App Store 商店地区区别对待。
分析数据可能包括:
- 一个随机、假名化的 App 安装标识;JotMind 没有账号,它也不与任何账号绑定;
- App 生命周期、引导、Capture、端侧处理、关键词搜索、Markdown 导出、条目删除与恢复、 付费墙、购买和恢复购买事件;
- 语音或文字、新建或追加 Capture、预定义处理阶段、端侧整理用的是内置模型还是规则回退, 以及预定义结果或错误码等固定值;
- 每段录音的时长,以及端侧转写、整理各自花了多少秒;
- 基础环境信息,用于判断问题出在哪种机型或哪个系统版本上:事件时间、App 版本、平台、 操作系统版本、设备类型或型号、设备语言、屏幕尺寸,以及 Firebase 根据网络请求推断的国家或 地区(不精确到城市,也不使用 GPS);
- 发生 App Store 购买时,Firebase 可能自动接收产品标识及名称、价格与币种、数量、 订阅或试用状态。
这些数据里没有你的任何内容——录音、转写、笔记内容和标题、搜索词都不会出现,也没有任何 可以自由填写的文字栏位:每个字段都是我们预先定好的选项之一。
在 Firebase 中,我们还关闭了广告标识符、供应商标识符收集、Google Signals、个性化广告、 广告网络归因、自动页面报告和精确位置报告,也不设置 Firebase User ID,不把分析数据与 RevenueCat 关联。App 里没有集成任何崩溃上报或会话回放 SDK。
这个安装标识是随机生成的,只用来区分不同的安装,不含你的姓名、邮箱或设备序列号。部分隐私 法律仍把这类标识归为个人数据,所以我们按个人数据的标准对待它。我们用这些数据运行并改进 JotMind。Firebase 的分析事件与用户级数据保留两个月;我们不启用 BigQuery 导出。Google 依据 适用的数据保护条款作为我们的服务提供商处理 Firebase Analytics 数据。
4. 购买与订阅
iOS 上的付款、退款和订阅都由 Apple 处理,我们看不到你的支付方式或账单信息。
JotMind 用 RevenueCat 判断这台设备是否有有效订阅。App 启动和回到前台时会向 RevenueCat 查一次 订阅状态,所以即使你从未订阅,RevenueCat 也会收到这次查询。它收到的是:RevenueCat 自己随机生成 的匿名标识、Apple 给出的权益是否有效、商店交易状态,以及 iOS 提供给我们的设备标识(供应商标识, 同一开发者的 App 共用,把这些 App 全部卸载后重置)和你的 App Store 商店地区。付费墙和订阅管理 界面也由 RevenueCat 提供。
RevenueCat 不会收到你的录音、转写或笔记内容。统计数据和购买数据是两套我们从不打通的标识, 具体见第 3 节。RevenueCat 作为我们的服务提供商处理上述数据,并按与我们之间的协议提供与本政策 同等的保护,保留期限适用该协议;Apple 按其自身隐私政策处理你的购买。
5. 导出、分享与支持
当你主动导出 Markdown、分享 Note、使用系统分享面板或联系支持时,只有你选择的信息 会前往你选择的目的地,并由该目的地按其隐私规则处理。如果你给我们发邮件,我们会收到 你的邮箱地址和邮件内容,并仅在处理你的请求或留存必要记录所需的期间内保存。App 内的隐私支持 操作只会打开给我们的邮件;JotMind 不会自动附上录音、转写、Note 内容、分析标识或其他 App 数据。
6. 权限
- 麦克风:仅在你前台录音时使用。
- 网络访问:用于上述有限分析和 iOS 订阅服务。除此之外,只有你点击时才会 打开网页——我们的网站与法律页面、App Store 商品页与订阅管理页、开源致谢里的项目来源链接, 以及你主动发起的支持邮件。打开哪个网页,对方就会看到你的 IP 地址。
JotMind 不请求日历、提醒事项、通讯录、照片、通知、后台音频、本地网络或广告权限。
7. 法律依据与跨境处理
候补名单邮箱基于你的同意处理。在法律允许的地区,我们基于了解功能可靠性并改进 JotMind 的 合法利益处理上述有限分析数据,同时以严格排除用户内容来平衡你的权益。购买和权益信息、导出、 分享及支持通信会在提供你请求的功能或履行与你的约定所必需时处理。我们也可能基于服务安全、 防欺诈以及响应支持或法律请求的合法利益处理必要信息,但前提是这些利益不凌驾于你的权利。
Google、Apple 和 RevenueCat 可能在你所在国家或地区之外处理有限数据。需要时,我们 会采用适用的合同或法律保障措施,包括标准合同条款。你可以联系我们了解适用保障。
8. 你的选择和权利
你在 JotMind 里删除的条目会先进入「最近删除」并保留 30 天,到期自动清除(连同该条的录音); 你也可以在「最近删除」里立即永久删除。你还可以导出所选内容,或卸载 App 以删除本地数据并停止 该次安装之后的分析收集。
JotMind 目前没有 App 内的分析开关。你可以随时通过 App 内的隐私支持操作或发送邮件,要求我们 停止、限制或删除该次安装的分析数据。由于 JotMind 没有账号,也不把分析标识与联系方式关联,我们 可能无法只凭一封邮件识别特定安装;届时会说明能够验证和完成的事项。
我们不出售个人信息,不为跨情境行为广告而共享信息,不做定向广告,也不会用你的内容 对你画像。根据所在地不同,你还可能享有访问、删除、更正、限制或反对处理以及在适用时获取 可携带数据的权利。欧盟用户还可向其居住、工作或认为发生侵权所在地的数据保护机构投诉。 我们通常会在一个月内回复经验证的请求,并履行适用于你的权利。
9. 儿童
JotMind 不面向 13 岁以下儿童,我们不会有意收集儿童个人信息。如果你认为儿童向我们 提供了信息,请联系我们。
10. 安全与变更
JotMind 的数据默认只存放在 iOS 为 App 划分的私有存储区;所有对外请求走 HTTPS;App 能上报的 分析事件由代码里一份固定白名单限定;App 经 App Store 签名分发。我们另有内部的隐私事件处理流程。 任何存储或传输方式都无法保证绝对安全。JotMind 发生变化时,我们可能更新本政策;页面顶部日期会 显示最新修订时间。
11. 联系我们
三比一特科技(北京)有限公司
隐私联系人
jotmind-support@sanbit.ai
通信地址
北京经济技术开发区永昌北路 9 号 1 幢 4 层 491-31 号
JotMind Privacy Policy
This Privacy Policy explains how Sanbit Technology (Beijing) Co., Ltd (“Sanbit,” “we,” “us,” or “our”) handles information when you use the JotMind iOS app or its launch website.
1. Website launch waitlist
sanbit.ai sets no cookies and loads no third-party analytics, advertising scripts, fonts, or CDN resources. Unless you fill in the waitlist form yourself, browsing the site sends us nothing.
If you join the launch waitlist, we store only the email address you type — that one field, with no IP address, browser information, or referring page. The form is hosted on Cloudflare Pages and the address is stored in Cloudflare KV on our behalf. As our website host, Cloudflare briefly keeps ordinary access logs such as IP addresses to deliver the page and fend off attacks; those never enter the waitlist.
We use the address only to send one JotMind launch notice, and we delete the waitlist within 30 days after sending it. You may ask us to remove your address sooner by emailing jotmind-support@sanbit.ai.
2. Content that stays on your device
JotMind stores and processes the following content only on your device:
- microphone recordings;
- transcripts and text you enter;
- Notes, titles, organized Markdown, and your edits; and
- temporary search queries and the local keyword-search index.
We do not receive this content. JotMind has no user account, content server, cloud sync, or remote AI summarization. Whether your notes are included in an iPhone or computer backup is determined by your own system backup settings; JotMind excludes only the large AI model files it can obtain again, so they do not take up your backup space.
3. Limited usage and reliability data
JotMind uses Firebase Analytics to understand whether its basic features and on-device processing work reliably. Collection starts when you begin using the app, and it is the same for everyone — we do not treat you differently based on your country or App Store storefront.
Analytics may include:
- a random, pseudonymous app-installation identifier; JotMind has no accounts, so it is not tied to one;
- app lifecycle, onboarding, Capture, on-device processing, keyword search, Markdown export, item delete and restore, paywall, purchase, and restore-purchase events;
- fixed values such as voice or text, new or appended Capture, predefined processing stage, whether on-device processing used the bundled model or the rule-based fallback, and predefined result or error code;
- how long each recording was, and how many seconds on-device transcription and organizing each took;
- basic environment information, so we can tell which hardware or system version a problem happens on: event time, app version, platform, operating-system version, device type or model, device language, screen dimensions, and the country or region Firebase infers from the network request (no city-level precision, and no GPS); and
- for an App Store purchase, Firebase may automatically receive the product identifier and name, price and currency, quantity, and subscription or trial status.
None of your content is in this data — no recordings, transcripts, Note text, titles, or search terms, and no free-text field of any kind: every field is one of a fixed set of values we define in advance.
In Firebase we also disable advertising identifiers, vendor-identifier collection, Google Signals, personalized advertising, ad-network attribution, automatic screen reporting, and precise location reporting; we set no Firebase User ID and do not link analytics to RevenueCat. The app ships with no crash-reporting or session-replay SDK at all.
The installation identifier is generated at random and only tells one installation apart from another; it carries no name, email address, or device serial number. Some privacy laws still treat such an identifier as personal data, so we handle it to that standard. We use this data to operate and improve JotMind. Firebase event and user-level data is retained for two months. We do not enable BigQuery export. Google processes Firebase Analytics data as our service provider under its applicable data-protection terms.
4. Purchases and subscriptions
Apple handles payment, refunds, and subscriptions on iOS. We never see your payment method or billing details.
JotMind uses RevenueCat to tell whether this device has an active subscription. The app asks RevenueCat for that status at launch and when it returns to the foreground, so RevenueCat receives the check even if you never subscribe. What it receives is the random anonymous identifier RevenueCat generates itself, whether Apple reports an active entitlement, store transaction status, the device identifier iOS provides to us (the identifier for vendor, which is shared by this developer's apps and resets once they are all removed), and your App Store storefront country. RevenueCat also provides the paywall and subscription-management screens.
RevenueCat never receives your recordings, transcripts, or Notes. Analytics and purchase data use separate identifiers that we never join; see Section 3. RevenueCat processes this data as our service provider and, under our agreement with it, provides protection equivalent to this policy; that agreement governs how long it is kept. Apple processes your purchase under its own privacy policy.
5. Exports, sharing, and support
When you deliberately export Markdown, share a Note, use the system share sheet, or contact support, the information you select goes to the destination you choose. That destination handles it under its own privacy practices. If you email us, we receive your email address and message, and we keep them only as long as we need them for your request or our records. The in-app privacy-support action opens a message to us; JotMind does not automatically include recordings, transcripts, Note content, analytics identifiers, or other app data.
6. Permissions
- Microphone: used only while you record in the foreground.
- Internet access: used for the limited analytics above and for iOS subscription services. Beyond that, a web page opens only when you tap one — our website and legal pages, the App Store product and subscription-management pages, the project links in our open-source acknowledgements, and support email you start yourself. Whichever page you open sees your IP address.
JotMind does not request Calendar, Reminders, Contacts, Photos, notification, background audio, local-network, or advertising permissions.
7. Legal bases and international processing
We process the waitlist email address with your consent. Where permitted, we rely on our legitimate interests in understanding feature reliability and improving JotMind for the limited analytics described above, balanced against the strict exclusion of user content. We process purchase and entitlement information, exports, sharing, and support communications as needed to provide the feature you request or perform our agreement with you. We may also rely on legitimate interests for service security, fraud prevention, and responding to support or legal requests where those interests are not overridden by your rights.
Google, Apple, and RevenueCat may process limited data in countries other than yours. Where required, we rely on applicable contractual or legal safeguards, including standard contractual clauses. You may contact us for information about applicable safeguards.
8. Your choices and rights
Items you delete in JotMind move to Recently Deleted for 30 days and then clear automatically, together with that item's audio; you can also delete them permanently right away from Recently Deleted. You can export selected content, or uninstall the app to remove its local data and stop future analytics from that installation.
JotMind currently has no in-app analytics switch. You can ask us at any time — through the privacy-support action in the app or by email — to stop, restrict, or delete the analytics data for your installation. Because JotMind has no account and does not link analytics to contact information, we may be unable to identify a particular installation from an email alone; we will explain what can be verified and completed.
We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or profile you using your content. Depending on where you live, you may have additional rights to access, delete, correct, restrict or object to processing, and to receive portable data where applicable. EU users may also complain to the data-protection authority where they live, work, or believe an infringement occurred. We normally respond to verified requests within one month and will honor rights that apply to you.
9. Children
JotMind is not directed to children under 13, and we do not knowingly collect personal information from children. Please contact us if you believe a child has provided information to us.
10. Security and changes
JotMind's data is stored by default only in the private storage area iOS assigns to the app; all outbound requests use HTTPS; the analytics events the app can send are limited by a fixed allowlist in code; and the app is distributed signed through the App Store. We also keep an internal procedure for handling privacy incidents. No method of storage or transmission is completely secure. We may update this policy as JotMind changes; the date above will show the latest revision.
11. Contact
Sanbit Technology (Beijing) Co., Ltd
Privacy Contact
jotmind-support@sanbit.ai
Mailing address
Room 491-31, 4th Floor, Building 1, No. 9 Yongchang North Road,
Beijing Economic and Technological Development Zone