Horae Privacy Policy
Horae is a task planning and reminder app. We design the app so your task data stays on your device by default.
Information We Process
- Task content: titles, notes, times, steps, progress, and reminder settings you create in the app.
- Voice input: when you choose voice input, audio may be transcribed by Apple Speech Recognition.
- iCloud sync: if enabled, your data is stored in your private Apple CloudKit database. We cannot read that private database.
- AI intent parsing and planning: after you give in-app permission, when you use AI intent parsing, breakdown, refinement, or ordering, the text you typed or the transcript produced by Apple Speech Recognition and the relevant task summary are sent to Horae's AI gateway to generate a response. Audio recordings are not sent to the gateway for intent parsing.
- Bring Your Own AI: lifetime purchase users may configure a compatible personal AI provider. If enabled, task content is sent directly to the provider selected by the user instead of Horae's AI gateway.
- Entitlement, quota, and security data: only after you allow the in-app AI data sharing disclosure, Horae may send an Apple-signed StoreKit transaction, a randomly generated device identifier, Horae profile code (if created), platform, device model, app version, and request counters to the Horae gateway. These pseudonymous records are used for entitlement verification, quota, rate limiting, and abuse prevention. Horae does not need your Apple ID, name, address, contacts, or payment card information.
Third-Party AI Services
Horae does not register a remote Horae identity or send task content to a third-party AI service until the app first shows an AI data sharing disclosure and you choose to allow it.
- What is sent: for AI intent parsing, the text you type or the transcript produced by Apple Speech Recognition, the current date and time, locale, and time zone are sent. Task title, notes/details, start and end times, locale, time zone, and scheduling preferences may also be sent for planning. For AI refinement, the user's full refinement instructions and the current plan's step titles, descriptions, times, and completion status are also sent. For focus ordering, selected candidate task summaries, priority, progress, remaining steps, and local scoring reasons are sent. To verify Plus entitlement, quotas, and rate limits, Horae also sends an Apple-signed StoreKit transaction, a randomly generated device identifier, Horae profile code (if created), platform, device model, and app version to the Horae gateway. This may include personal information you type into a task. Horae does not send your Apple ID, contacts, payment card information, full photo files, or audio recordings for these requests.
- Who receives it: for Horae AI, requests are sent to Horae's gateway at
api-horae.gaimu.cn, which calls DeepSeek models. If a lifetime purchase user enables Bring Your Own AI, requests are sent to the compatible AI endpoint configured by that user. - Purpose: Horae sends input text and task content to parse task intent and time, create task steps, refine an existing plan, or order the user's next-best-action recommendation. The Horae gateway uses the StoreKit transaction and pseudonymous identifiers only to verify Plus entitlement, enforce quotas and rate limits, and prevent abuse. DeepSeek and Bring Your Own AI providers may also process model-call data as described under “Protection and applicable terms” below.
- Protection and applicable terms: For Horae AI, DeepSeek's processing, storage, and use of model-call data are governed by the applicable DeepSeek Open Platform Terms of Service and any other effective agreements governing Horae's use of the service. DeepSeek's public Open Platform terms require Horae, as the downstream app developer, to disclose this processing and obtain the required consent. DeepSeek's general Privacy Policy describes possible use of personal data, including user input, to improve and train its technology, but also states that the policy does not cover personal data collected from end users of downstream apps. Horae therefore does not promise that DeepSeek will never retain model-call data or use it to improve or train models. For Bring Your Own AI, the provider you select processes, stores, and uses data under its own terms and privacy policy; review them before enabling the provider.
- Control: you can revoke AI data sharing permission in the app settings. If permission is not granted or is revoked, Horae uses local planning and local ordering instead.
How We Use Information
We use information to understand task intent and time, create reminders, split tasks into steps, rank focus recommendations, sync data through Apple services when enabled, protect the gateway from abuse, and provide support.
Storage and Retention
- Task content on Horae's gateway: intent input, task titles, notes, steps, refinement instructions, and focus summaries are processed in memory for the AI request. For intent parsing retries, the gateway may retain only a one-way hash of the input and the parsed intent result in a bounded, volatile memory cache for up to 24 hours; it does not retain the raw intent input in that cache, and the cache is cleared when the gateway process restarts. Horae's gateway does not write task content or parsed intent results to its own persistent data files. Gateway operational logs record only HTTP status and public error codes; they do not record request bodies, task content, or model-response bodies. DeepSeek's processing, storage, and use of Horae AI model-call data are governed by the applicable Open Platform terms and effective agreements described above. For Bring Your Own AI, the provider you select determines its retention practices under its own terms and privacy policy.
- Monthly quota records: Horae stores a one-way hashed purchase identifier, the number and type of counted AI requests, and the last update time. These records are kept for the current calendar month and the previous two calendar months, then automatically deleted.
- Horae identity record: only after in-app consent, if the app registers a Horae profile code, the gateway stores a one-way hash of the app-generated random device identifier, profile code, registration time, platform, device model, and app version. Horae does not send the device name or Apple's Identifier for Vendor for this registration. This record is kept until you request deletion or the service is discontinued.
- Rate-limit data: daily counters may temporarily process a one-way hashed purchase identifier and the request's network IP address. Before an IP rate-limit key is created or persisted, Horae's gateway converts the IP address to a keyed, one-way HMAC-SHA256 digest. Only the digest, counter, and expiry time are written to the rate-limit file; the raw IP address is not written to persistent files. The record expires at the end of the current UTC day and is removed during the next rate-limit store update.
- Local and iCloud data: local task data remains until you delete it or remove the app. If iCloud sync is enabled, deletion and retention are also governed by your Apple account and CloudKit settings.
Your Choices and Deletion Requests
You can revoke AI data sharing permission at any time in Horae Settings. This stops future Horae AI requests but does not affect processing completed before withdrawal. To request access to or deletion of a Horae identity or quota record, email mrdxi0717@gmail.com and include the Horae profile code shown in the app. We may ask for reasonable verification and will complete a verified request within 30 days unless retention is required by law. Task content stored locally can be deleted inside the app; private iCloud data is managed through your Apple account.
Subscriptions and Purchases
All payments are processed by Apple In-App Purchase. Horae does not receive or store your payment card information. After you allow AI data sharing, an Apple-signed StoreKit transaction is sent to Horae's gateway only to verify Plus entitlement and AI quota; it is not sent to the AI model as task content.
Contact
Questions or requests: mrdxi0717@gmail.com
Horae 隐私政策
Horae 是一款任务规划和提醒工具。默认情况下,你的任务数据只保存在你的设备上。
我们处理的信息
- 任务内容:你在 App 中创建的标题、备注、时间、步骤、进度和提醒设置。
- 语音输入:当你主动使用语音输入时,音频可能由 Apple 语音识别服务转写。
- iCloud 同步:开启后,数据存储在你本人的 Apple CloudKit 私有数据库中,我们无法读取。
- AI 意图识别与规划:在你于 App 内同意后,当你使用 AI 意图识别、AI 拆解、AI 优化或 AI 排序时,你输入的文字或 Apple 语音识别生成的转写文本及相关任务摘要会发送到 Horae AI 网关生成结果。意图识别不会向网关发送录音文件。
- 自接入 AI:买断用户可以配置自己的兼容 AI 服务。启用后,任务内容会发送给用户选择的服务商,而不是 Horae AI 网关。
- 权益、额度与安全数据:只有在你同意 App 内的 AI 数据共享说明后,Horae 才可能向网关发送 Apple 签名的 StoreKit 交易凭证、随机生成的设备标识、Horae 身份编号(如已生成)、平台、设备型号、App 版本及请求计数。这些假名化记录仅用于权益验证、额度、限流与防滥用。Horae 不需要你的 Apple ID、姓名、地址、通讯录或银行卡信息。
第三方 AI 服务
Horae 不会在未取得你同意的情况下注册远程 Horae 身份,也不会把任务内容发送给第三方 AI 服务。首次发送前,App 会显示 AI 数据共享说明,并由你选择是否同意。
- 发送的数据:进行 AI 意图识别时,会发送你输入的文字或 Apple 语音识别生成的转写文本,以及当前日期时间、语言地区和时区。进行规划时,还可能发送任务标题、备注/详情、开始和结束时间、语言地区、时区和排程偏好。进行 AI 优化时,还会发送用户完整的优化要求,以及当前方案中步骤的标题、说明、时间和完成状态;进行“现在最该做”AI 排序时,还会发送候选任务摘要、优先级、进度、剩余步骤和本地评分原因。为验证 Plus 权益、额度和限流,Horae 还会向网关发送 Apple 签名的 StoreKit 交易凭证、随机生成的设备标识、Horae 身份编号(如已生成)、平台、设备型号和 App 版本。这些内容可能包含你写入任务的个人信息。Horae 不会发送你的 Apple ID、通讯录、银行卡信息、完整照片文件或录音文件。
- 接收方:使用 Horae AI 时,请求会发送到 Horae 网关
api-horae.gaimu.cn,并由网关调用 DeepSeek 模型。买断用户启用自接入 AI 时,请求会发送到用户自行配置的兼容 AI 接口。 - 用途:Horae 发送输入文本和任务内容,用于识别任务意图与时间、生成任务步骤、优化已有计划,或为用户排序“现在最该做”的推荐;Horae 网关仅将 StoreKit 交易凭证和假名化标识用于验证 Plus 权益、执行额度和限流以及防止滥用。DeepSeek 和自接入 AI 服务商还可能按照下方“保护措施与适用条款”处理模型调用数据。
- 保护措施与适用条款:使用 Horae AI 时,DeepSeek 对模型调用数据的处理、保存和使用受适用的《DeepSeek 开放平台服务协议》及其他约束 Horae 使用该服务的有效协议约束。DeepSeek 公开的开放平台协议要求 Horae 作为下游应用开发者披露相关处理并取得所需同意。DeepSeek 的通用《隐私政策》说明其可能使用包括用户输入在内的个人信息来改进和训练技术,同时也说明该政策不涵盖下游应用终端用户个人信息的处理规则。因此,Horae 不承诺 DeepSeek 绝不保留模型调用数据,也不承诺其绝不将这些数据用于模型改进或训练。使用自接入 AI 时,数据如何处理、保存和使用由你选择的服务商依据其自身条款与隐私政策决定;启用前请查阅这些条款。
- 控制方式:你可以在 App 设置中撤回 AI 数据共享授权。未授权或撤回后,Horae 会改用本地规划和本地排序。
信息用途
我们使用这些信息来识别任务意图与时间、创建提醒、拆分任务、生成焦点推荐、通过 Apple 服务同步数据、保护网关安全并提供支持。
存储与保留期限
- Horae 网关处理的任务内容:意图输入、任务标题、备注、步骤、优化要求和焦点摘要会在 AI 请求期间于内存中处理。为支持意图识别重试,网关可能在有界的易失内存缓存中保留输入的单向哈希和解析结果,最长 24 小时;该缓存不保留原始意图输入,并会在网关进程重启时清空。Horae 网关不会把任务内容或意图解析结果写入自己的持久化数据文件。网关运行日志只记录 HTTP 状态与公开错误代码,不记录请求正文、任务内容或模型响应正文。DeepSeek 对 Horae AI 模型调用数据的处理、保存和使用受上文所述的适用开放平台条款及有效协议约束。使用自接入 AI 时,数据保留方式由你选择的服务商依据其自身条款与隐私政策决定。
- 月度额度记录:Horae 会保存单向哈希处理的购买标识、计入额度的 AI 请求次数和类型,以及最后更新时间。记录仅保留当前自然月及此前两个自然月,之后自动删除。
- Horae 身份记录:只有在 App 内取得同意后,如果 App 注册了 Horae 身份编号,网关才会保存经过单向哈希处理的 App 随机设备标识、身份编号、注册时间、平台、设备型号和 App 版本。注册过程不会发送设备名称或 Apple 的供应商设备标识符,记录会保留至你申请删除或服务停止运营。
- 限流数据:每日限流计数可能临时处理单向哈希后的购买标识及请求的网络 IP 地址。在创建或持久化 IP 限流键之前,Horae 网关会先把 IP 地址转换为带密钥、不可逆的 HMAC-SHA256 摘要。限流文件只保存摘要、计数和到期时间,不会写入原始 IP;记录会在当前 UTC 自然日结束时失效,并在下一次更新限流存储时删除。
- 本地与 iCloud 数据:本地任务数据会保留到你主动删除或卸载 App。开启 iCloud 同步后,相关删除和保留还受你的 Apple 账户及 CloudKit 设置控制。
你的选择与删除请求
你可以随时在 Horae 设置中撤回 AI 数据共享授权,撤回后不再发起新的 Horae AI 请求,但不会影响撤回前已经完成的处理。如需查询或删除 Horae 身份记录或额度记录,请发送邮件至 mrdxi0717@gmail.com,并附上 App 中显示的 Horae 身份编号。为保障安全,我们可能要求进行合理验证;除法律要求继续保留的情况外,会在验证完成后 30 天内处理。保存在本地的任务内容可直接在 App 内删除;iCloud 私有数据由你的 Apple 账户管理。
订阅与购买
所有付款均通过 Apple App 内购买处理。Horae 不接收也不保存你的银行卡信息。在你同意 AI 数据共享后,Horae 仅会把 Apple 签名的 StoreKit 交易凭证发送到 Horae 网关,用于验证 Plus 权益和 AI 额度;该凭证不会作为任务内容发送给 AI 模型。
联系我们
问题或请求:mrdxi0717@gmail.com