DouOS Privacy Policy

Effective and last updated: September 1, 2026

DouOS is a native iOS and macOS AI companion app centered on Xiaodou. This policy explains what data DouOS processes, how it is collected and used, and which service providers receive it. API keys you add yourself are stored locally in Apple Keychain and are not uploaded to DouOS servers.

DouOS(小豆)是一款 iOS 与 macOS 原生 AI 朋友 App。本政策说明 DouOS 处理哪些数据、如何收集和使用,以及哪些服务方会接收数据。你自行添加的模型 API Key 仅保存在 Apple Keychain 中,不会上传到 DouOS 服务器。

Data we process / 我们处理的数据

Device storage and Mac file access / 设备存储与 Mac 文件访问

DouOS stores local app data and caches inside its app sandbox or an authorized Apple app-group container used by a feature you choose, such as LifeLogs integration. On macOS, images and supported documents enter the app only when you select or drop them. Pending imports are listed and can be removed before sending, and security-scoped file access ends when the import finishes. The floating companion stores only whether it is shown, its size, and its screen position; it does not store conversations, imported files, account identifiers, or credentials.

DouOS 会把本机 App 数据与缓存保存在 App 沙盒内,或保存在你所选功能使用的 Apple 授权 App Group 容器中,例如 LifeLogs 集成。在 macOS 上,只有你主动选择或拖入的图片与受支持文档才会进入 App;发送前会列出待发送项目并可移除,导入完成后会结束对该文件的安全作用域访问。小豆浮窗只保存显示状态、大小和屏幕位置,不保存对话、导入文件、账号标识或凭据。

Mac permissions and notifications / Mac 权限与通知

Calendar and Reminders access is optional and requested only after you choose to connect it. DouOS uses Apple EventKit on your device to show the permission status and, only when you explicitly choose the matching action, read upcoming items or add selected summaries to Box. A summary added to Box follows the same storage and AI-sharing rules as other content you provide. You can change access at any time in System Settings.

日历与提醒事项权限均为可选,只有你主动连接相应功能时才会请求。DouOS 通过设备上的 Apple EventKit 显示权限状态,并且只在你明确选择对应操作时读取近期项目或把所选摘要加入盒子;加入盒子的摘要与其他由你提供的内容适用相同的存储和 AI 共享规则。你可以随时在“系统设置”中更改权限。

System notifications are optional. When you enable them, DouOS registers the app/device identifier, app version, notification preference, and Apple Push Notification service (APNs) device token with the DouOS service so alerts can be delivered. On macOS, a completed reply may also create a local notification. Disabling notifications unregisters the app and updates the service preference; notification access can also be revoked in System Settings.

系统通知为可选功能。开启后,DouOS 会向服务端登记 App/设备标识、App 版本、通知偏好以及 Apple 推送通知服务(APNs)设备令牌,以便发送提醒;在 macOS 上,回复完成后也可能生成本地通知。关闭通知时,App 会取消系统注册并更新服务端偏好;你也可以在“系统设置”中撤回通知权限。

AI data sharing and consent / AI 数据共享与同意

Before DouOS sends personal data to an AI service for the first time, the app separately explains what will be sent, identifies the recipient and purpose, and asks for your affirmative permission. If you choose “Not Now,” the content is not sent and AI generation remains unavailable until you grant permission.

在首次把个人数据发送给 AI 服务前,App 会单独说明发送内容、接收方和用途,并取得你的明确允许。选择“暂不允许”时,内容不会发送,AI 生成功能会保持关闭,直到你主动允许。

With permission, DouOS sends only the content needed to provide the requested reply or related AI feature: the current text, selected attachment content, necessary recent conversation, profile context, and relevant confirmed memories. This may be used to generate chat replies, Inner OS, Xiaodou activity content, and memory suggestions. Apple credentials and user-supplied model API keys are never included in AI model requests.

Recipients / 接收方

DouOS uses encrypted transport, limits data to the requested purpose, does not sell chat content, and does not use chat content for advertising. We require service providers that process data for DouOS to provide privacy and security protection no less protective than this policy.

Your choices and controls / 你的选择与控制

You can review or withdraw AI data-sharing permission in Profile > Advanced & Privacy > AI Data Use. Withdrawal stops future AI requests but does not prevent you from viewing content already stored on your device. You can also edit or delete memories, export supported data, configure your own provider, restore purchases, or request account deletion.

你可以在“我的 > 高级与隐私 > AI 数据使用”查看或撤回允许。撤回会停止新的 AI 请求,但不影响查看已保存在设备上的内容。你也可以编辑或删除记忆、导出支持的数据、自行配置模型服务、恢复购买或申请删除账号。

Retention and deletion

Functionality data is retained while your account remains active. When you delete your account in the app, DouOS deletes the account and associated primary-database records. Encrypted operational backups and security logs, when required for recovery or abuse prevention, are retained for no longer than 30 days before deletion.

功能数据会在账号存续期间保留。你在 App 内删除账号后,DouOS 会删除账号及主数据库中的关联记录。仅为故障恢复或防止滥用所必需的加密运维备份和安全日志,最长保留 30 天后删除。

Contact

Email: isdou.exe@gmail.com