Horae Privacy Policy
Horae is a task planning and reminder app. We design the app so your task data stays on your device by default.
Information We Process
- Task content: titles, notes, times, steps, progress, and reminder settings you create in the app.
- Voice input: when you choose voice input, audio may be transcribed by Apple Speech Recognition.
- iCloud sync: if enabled, your data is stored in your private Apple CloudKit database. We cannot read that private database.
- AI planning: after you give in-app permission, when you use AI breakdown, AI refinement, or AI ordering, the relevant task summary is sent to Horae's AI gateway to generate a response.
- Bring Your Own AI: lifetime purchase users may configure a compatible personal AI provider. If enabled, task content is sent directly to the provider selected by the user instead of Horae's AI gateway.
- Entitlement, quota, and security data: only after you allow the in-app AI data sharing disclosure, Horae may send an Apple-signed StoreKit transaction, a randomly generated device identifier, Horae profile code (if created), platform, device model, app version, and request counters to the Horae gateway. These pseudonymous records are used for entitlement verification, quota, rate limiting, and abuse prevention. Horae does not need your Apple ID, name, address, contacts, or payment card information.
Third-Party AI Services
Horae does not register a remote Horae identity or send task content to a third-party AI service until the app first shows an AI data sharing disclosure and you choose to allow it.
- What is sent: task title, notes/details, start and end times, locale, time zone, and scheduling preferences. For AI refinement, the user's full refinement instructions and the current plan's step titles, descriptions, times, and completion status are also sent. For focus ordering, selected candidate task summaries, priority, progress, remaining steps, and local scoring reasons are sent. To verify Plus entitlement and monthly quota, Horae also sends an Apple-signed StoreKit transaction, a randomly generated device identifier, Horae profile code (if created), platform, device model, and app version to the Horae gateway. This may include personal information you type into a task. Horae does not send your Apple ID, contacts, payment card information, full photo files, or audio recordings for these requests.
- Who receives it: for Horae AI, requests are sent to Horae's gateway at
api-horae.gaimu.cn, which calls Alibaba Cloud Bailian / DashScope Qwen models. If a lifetime purchase user enables Bring Your Own AI, requests are sent to the compatible AI endpoint configured by that user. - Purpose: task content is used only to create task steps, refine an existing plan, or order the user's next-best-action recommendation. StoreKit transaction and pseudonymous identifiers are used only to verify Plus entitlement, enforce the monthly quota and rate limits, and prevent abuse.
- Protection: Horae requires third-party AI providers receiving task content to protect it to the same or an equivalent standard described in this policy. If a provider cannot provide that protection, Horae will stop sending task content to that provider. Alibaba Cloud states that model-call data is encrypted, is not used to train its models, and may be stored as required by applicable law. Its processing is governed by the Model Studio privacy notice and Bailian Privacy Policy. Bring Your Own AI requests are governed by the privacy terms of the provider selected by the user.
- Control: you can revoke AI data sharing permission in the app settings. If permission is not granted or is revoked, Horae uses local planning and local ordering instead.
How We Use Information
We use information to create reminders, split tasks into steps, rank focus recommendations, sync data through Apple services when enabled, protect the gateway from abuse, and provide support.
Storage and Retention
- Task content on Horae's gateway: task titles, notes, steps, refinement instructions, and focus summaries are processed in memory for the active AI request. Horae's gateway does not write this task content to its own persistent data files after returning the response. Gateway operational logs record only HTTP status and public error codes; they do not record request bodies, task content, or model-response bodies. Alibaba Cloud may retain model-call data as described in its policies linked above.
- Monthly quota records: Horae stores a one-way hashed purchase identifier, the number and type of counted AI requests, and the last update time. These records are kept for the current calendar month and the previous two calendar months, then automatically deleted.
- Horae identity record: only after in-app consent, if the app registers a Horae profile code, the gateway stores a one-way hash of the app-generated random device identifier, profile code, registration time, platform, device model, and app version. Horae does not send the device name or Apple's Identifier for Vendor for this registration. This record is kept until you request deletion or the service is discontinued.
- Rate-limit data: daily counters may temporarily use a one-way hashed purchase identifier and network IP address in server memory. They are not written to persistent files, expire after the current UTC day, and are also cleared whenever the gateway restarts.
- Local and iCloud data: local task data remains until you delete it or remove the app. If iCloud sync is enabled, deletion and retention are also governed by your Apple account and CloudKit settings.
Your Choices and Deletion Requests
You can revoke AI data sharing permission at any time in Horae Settings. This stops future Horae AI requests but does not affect processing completed before withdrawal. To request access to or deletion of a Horae identity or quota record, email mrdxi0717@gmail.com and include the Horae profile code shown in the app. We may ask for reasonable verification and will complete a verified request within 30 days unless retention is required by law. Task content stored locally can be deleted inside the app; private iCloud data is managed through your Apple account.
Subscriptions and Purchases
All payments are processed by Apple In-App Purchase. Horae does not receive or store your payment card information. After you allow AI data sharing, an Apple-signed StoreKit transaction is sent to Horae's gateway only to verify Plus entitlement and AI quota; it is not sent to the AI model as task content.
Contact
Questions or requests: mrdxi0717@gmail.com
Horae 隐私政策
Horae 是一款任务规划和提醒工具。默认情况下,你的任务数据只保存在你的设备上。
我们处理的信息
- 任务内容:你在 App 中创建的标题、备注、时间、步骤、进度和提醒设置。
- 语音输入:当你主动使用语音输入时,音频可能由 Apple 语音识别服务转写。
- iCloud 同步:开启后,数据存储在你本人的 Apple CloudKit 私有数据库中,我们无法读取。
- AI 规划:在你于 App 内同意后,当你使用 AI 拆解、AI 优化或 AI 排序时,相关任务摘要会发送到 Horae AI 网关生成结果。
- 自接入 AI:买断用户可以配置自己的兼容 AI 服务。启用后,任务内容会发送给用户选择的服务商,而不是 Horae AI 网关。
- 权益、额度与安全数据:只有在你同意 App 内的 AI 数据共享说明后,Horae 才可能向网关发送 Apple 签名的 StoreKit 交易凭证、随机生成的设备标识、Horae 身份编号(如已生成)、平台、设备型号、App 版本及请求计数。这些假名化记录仅用于权益验证、额度、限流与防滥用。Horae 不需要你的 Apple ID、姓名、地址、通讯录或银行卡信息。
第三方 AI 服务
Horae 不会在未取得你同意的情况下注册远程 Horae 身份,也不会把任务内容发送给第三方 AI 服务。首次发送前,App 会显示 AI 数据共享说明,并由你选择是否同意。
- 发送的数据:任务标题、备注/详情、开始和结束时间、语言地区、时区和排程偏好。进行 AI 优化时,还会发送用户完整的优化要求,以及当前方案中步骤的标题、说明、时间和完成状态;进行“现在最该做”AI 排序时,还会发送候选任务摘要、优先级、进度、剩余步骤和本地评分原因。为验证 Plus 权益和月度额度,Horae 还会向网关发送 Apple 签名的 StoreKit 交易凭证、随机生成的设备标识、Horae 身份编号(如已生成)、平台、设备型号和 App 版本。这些内容可能包含你写入任务的个人信息。Horae 不会发送你的 Apple ID、通讯录、银行卡信息、完整照片文件或录音文件。
- 接收方:使用 Horae AI 时,请求会发送到 Horae 网关
api-horae.gaimu.cn,并由网关调用阿里云百炼 / DashScope 的千问模型。买断用户启用自接入 AI 时,请求会发送到用户自行配置的兼容 AI 接口。 - 用途:任务内容仅用于生成任务步骤、优化已有计划,或为用户排序“现在最该做”的推荐;StoreKit 交易凭证和假名化标识仅用于验证 Plus 权益、执行月度额度和限流以及防止滥用。
- 保护措施:Horae 要求接收任务内容的第三方 AI 服务商按照本政策所述的相同或同等标准保护这些数据;如果服务商无法提供相同或同等保护,Horae 将停止向其发送任务内容。阿里云声明模型调用数据会被加密、不用于模型训练,并可能根据适用法律要求进行存储。具体处理规则以大模型服务平台百炼隐私说明和阿里云百炼隐私政策为准。自接入 AI 请求则适用用户所选服务商的隐私条款。
- 控制方式:你可以在 App 设置中撤回 AI 数据共享授权。未授权或撤回后,Horae 会改用本地规划和本地排序。
信息用途
我们使用这些信息来创建提醒、拆分任务、生成焦点推荐、通过 Apple 服务同步数据、保护网关安全并提供支持。
存储与保留期限
- Horae 网关处理的任务内容:任务标题、备注、步骤、优化要求和焦点摘要只在当前 AI 请求期间于内存中处理。Horae 网关返回结果后,不会把这些任务内容写入自己的持久化数据文件。网关运行日志只记录 HTTP 状态与公开错误代码,不记录请求正文、任务内容或模型响应正文。阿里云可能按照上方链接所列政策保留模型调用数据。
- 月度额度记录:Horae 会保存单向哈希处理的购买标识、计入额度的 AI 请求次数和类型,以及最后更新时间。记录仅保留当前自然月及此前两个自然月,之后自动删除。
- Horae 身份记录:只有在 App 内取得同意后,如果 App 注册了 Horae 身份编号,网关才会保存经过单向哈希处理的 App 随机设备标识、身份编号、注册时间、平台、设备型号和 App 版本。注册过程不会发送设备名称或 Apple 的供应商设备标识符,记录会保留至你申请删除或服务停止运营。
- 限流数据:每日限流计数可能在服务器内存中临时使用单向哈希处理的购买标识及网络 IP 地址。这些内容不会写入持久化文件,会在当前 UTC 自然日结束后失效,并在网关重启时清除。
- 本地与 iCloud 数据:本地任务数据会保留到你主动删除或卸载 App。开启 iCloud 同步后,相关删除和保留还受你的 Apple 账户及 CloudKit 设置控制。
你的选择与删除请求
你可以随时在 Horae 设置中撤回 AI 数据共享授权,撤回后不再发起新的 Horae AI 请求,但不会影响撤回前已经完成的处理。如需查询或删除 Horae 身份记录或额度记录,请发送邮件至 mrdxi0717@gmail.com,并附上 App 中显示的 Horae 身份编号。为保障安全,我们可能要求进行合理验证;除法律要求继续保留的情况外,会在验证完成后 30 天内处理。保存在本地的任务内容可直接在 App 内删除;iCloud 私有数据由你的 Apple 账户管理。
订阅与购买
所有付款均通过 Apple App 内购买处理。Horae 不接收也不保存你的银行卡信息。在你同意 AI 数据共享后,Horae 仅会把 Apple 签名的 StoreKit 交易凭证发送到 Horae 网关,用于验证 Plus 权益和 AI 额度;该凭证不会作为任务内容发送给 AI 模型。
联系我们
问题或请求:mrdxi0717@gmail.com