EvokeMind 隐私政策
更新日期:2026 年 9 月 23 日
本政策适用于 EvokeMind iOS App、其账号服务及配套 API。EvokeMind 面向日常记忆训练,不提供医学诊断、疾病筛查或治疗建议。
我们收集什么、如何收集及用途
| 数据类别 | 来源与内容 | 使用目的 |
|---|---|---|
| 账号与认证 | 注册/登录时提供的邮箱、内部账号 ID;密码经 scrypt 加盐哈希后保存;服务端保存刷新令牌和密码重置令牌的哈希、有效期及撤销状态。密码明文不保存。 | 创建账号、登录、续期、找回密码、账号安全和阻止已删除账号恢复。 |
| 个人资料 | 你可自行填写年龄、出生年份、性别、教育、职业、兴趣、重要经历和家庭情况。 | 展示和维护个人资料,为记忆训练和个性化内容提供上下文。字段可留空;不填写不影响基本训练。 |
| 记忆相册与照片 | 你主动填写的条目类型、标题、故事、家庭情况、日期、地点,以及事实问题、答案、别名和确认状态。你选择照片时,照片原图会上传并保存在服务端;系统还保存 MIME 类型、SHA-256 摘要和字节数。应用只读取你在系统照片选择器中选中的照片,不扫描整个照片图库。照片文件可能包含拍摄设备写入的 EXIF 等内嵌信息;当前上传流程不承诺剥离这些信息。 | 创建个人记忆内容、提供可选的个人情景记忆训练题及管理相册。 |
| 训练与设备信息 | 训练/基准模式、类别、难度、题目和协议版本、开始/完成时间、答题原文、正确与否、分数、答题时长、提示/跳过/超时/中断状态及允许的任务指标;另有 App/OS 版本、设备型号或类别、输入方式和时区。部分答题内容会先保存在设备本地同步队列,待网络可用时上传。 | 完成训练、服务端复核评分、保存历史、处理离线同步、计算难度调整及生成训练报告和趋势。 |
| 报告、趋势与方案 | 各类别汇总分数、样本数、优势/待加强类别、建议、月/年趋势、难度变化历史/当前难度,以及训练方案和任务完成状态。 | 向你展示训练历史和表现趋势,并按固定规则生成难度及训练方案。它们反映训练表现,不代表医学结论。 |
| AI 设置和交互记录 | 两项 AI 用途的同意/撤回状态、告知版本和时间;请求动作、必要的记录引用 ID、模型调用状态、耗时、重试及 token 计数等运行元数据。AI 请求正文和你选择的事实原文不作为 AI 审计正文长期保存;加密的 AI 回复缓存最长 15 分钟。 | 记录并执行你的 AI 选择、复核请求是否获准、排查服务故障和限制滥用。 |
| 技术运行信息 | 服务运行和反向代理可能产生请求时间、路径、状态码、错误及安全事件等技术日志。具体字段和期限取决于实际部署配置。 | 保障服务运行、安全和故障排查。当前代码库没有为所有主机/代理日志规定统一的保留期限。 |
本版本不申请、不读取、不写入 HealthKit;没有集成广告定向或跨 App 跟踪功能。我们不会出售你的个人资料、记忆内容或训练记录。
AI 与第三方服务
AI 教练的“AI 结构化数据使用”和“AI 个人事实使用”两项同意均默认关闭,彼此独立,可在“我的资料 > AI 数据设置”随时撤回。未开启结构化数据同意时,教练使用本地/服务端固定规则回答,不向第三方 AI 发送请求。撤回后停止该用途的新请求,并清除服务端尚未过期的 AI 回复缓存;已发送给第三方的请求无法撤回,撤回也不会自动删除第三方已经收到或保留的数据。
当前仓库集成的第三方 AI API 为 DeepSeek Open Platform。获得结构化数据同意且服务端 AI 配置启用时,EvokeMind 服务端才会经 HTTPS 向 DeepSeek 发送当前动作所需的最少上下文,例如训练类别/难度/状态、报告分数与样本量、趋势摘要或方案任务,以及对应的记录引用 ID。EvokeMind 不向该 API 发送账号邮箱、密码、访问/刷新令牌、照片、故事原文、完整个人资料或逐题原始答案。选择“AI 个人事实使用”后,还必须在具体请求中由你手动选择最多 3 条已确认事实;只发送所选事实答案及事实引用,不自动沿用选择。规则解释请求可能包含你当次提交的问题(最多 500 个字符),请勿在其中输入不必要的敏感信息。
第三方服务按其自身政策处理收到的数据。DeepSeek 当前公开隐私政策说明,其服务可能在加密和去标识化处理后将输入及输出用于模型训练和服务优化,并说明在中国境内存储其服务收集的信息;该政策也没有为本 App 的 API 请求给出一个由 EvokeMind 可验证的固定删除期限。因此,EvokeMind 不承诺 DeepSeek 不会保留或用于上述用途,也无法替你删除已经发送给 DeepSeek 的数据。请阅读 DeepSeek 隐私政策;相关处理方式可能变化。若服务端更换 AI 供应商或处理用途,将更新本政策及相应告知。
密码重置时,配置的 SMTP 邮件服务会处理你的邮箱地址和一次性重置令牌,以发送重置邮件。服务端托管商、数据库/备份设施运营商也可能在提供基础设施和维护服务所必需的范围内接触系统数据;具体运营商和所在地由实际部署决定,当前仓库没有固定声明服务端基础设施的供应商或地区。你主动使用系统分享菜单发送导出文件时,所选目标 App 或服务会按其自身政策处理文件。
保护措施
正式服务器及 AI API 连接使用 HTTPS。账号数据按账号隔离;密码使用 scrypt 加盐哈希,刷新/重置令牌仅以哈希形式保存在服务端;App 会把会话令牌保存在 iOS Keychain。AI API 密钥只配置在服务端,不打包进 App;AI 请求经允许域名限制,仅包含功能所需结构化字段,模型输出经过固定文案校验。服务端的 AI 回复缓存使用加密形式保存。导出的 JSON 文件在设备本机生成,并设置 iOS 文件保护属性。
以上措施不能消除所有网络、设备或供应商风险。当前仓库没有证明服务端数据库、照片和数据库备份均启用了静态加密,也没有统一配置全部部署日志的保留周期;不要把不希望第三方处理的信息放入 AI 请求或记忆内容。
保存期限、撤回及删除
- 账号、资料、记忆内容、照片、训练记录、报告、趋势和训练方案在账号存续期间保存在服务端,以提供相应功能。你可以编辑资料;删除一条记忆会清除该条目的文字、事实和照片,并将相关历史训练来源标记为已删除,保留评分所需的汇总记录。
- App 本地数据库会保存账号邮箱、会话摘要、答题记录和待同步数据,直至你在 App 内删除账号或卸载 App。退出登录不会清除设备本地记录;设备备份是否保留本地副本由 iOS 备份设置决定。
- 你可在“我的资料”中提交“删除账号及全部数据”。服务器立即停止该账号登录和数据访问,并从主数据库删除账号关联数据。自动备份按部署策略最多保留 30 天,因此备份副本可能在删除后继续存在,直至轮换过期。设备上的账号缓存和待同步数据会随 App 内账号删除流程清理;退出登录本身不会删除服务器账号或其数据。
- 为阻止旧凭证、迟到任务或备份恢复重新启用已删除账号/已撤回用途,服务端另存最少的账号 UUID、版本、时间和撤回用途标记。当前实现没有为这些安全标记设置自动到期时间。
- AI 交互审计元数据保留 30 天,过期后由后台任务清理;AI 回复缓存加密并在 15 分钟后过期。第三方 AI 供应商对已收到输入的保存期限不受 EvokeMind 控制,适用其政策与条款。
- 服务端运行日志和反向代理日志的保存时长取决于部署配置;当前代码库未规定统一期限。运营者应在正式发布前核实并配置相关期限。
- 导出文件由你主动发起后在 App 沙盒缓存目录生成。App 不会将文件上传回 EvokeMind 服务端;iOS 可能清理缓存。若你通过系统分享将副本保存到“文件”或发送到其他服务,需在相应位置自行管理和删除该副本。
你的选择与权利
你可以在 App 内编辑个人资料、删除单条记忆、导出个人数据,或删除账号及关联数据。关闭 AI 同意会阻止后续对应用途的第三方请求;相册权限可通过 iOS 系统权限设置管理。导出文件不包含照片二进制、登录凭证、刷新令牌、逐题原始答案、AI 请求正文或内部运行日志。
隐私咨询及其他数据权利请求,请先查看 EvokeMind 支持页面,并通过 App Store 产品页列明的 App 支持联系方式联系服务运营者。提交请求时请提供足以核验账号的信息,不要发送密码、验证码或访问令牌。
EvokeMind Privacy Policy
Last updated: September 23, 2026
This policy applies to the EvokeMind iOS app, its account services, and related APIs. EvokeMind is for everyday memory training. It does not provide medical diagnosis, disease screening, or treatment advice.
What We Collect, How We Collect It, and Why
| Data category | Source and data | Purpose |
|---|---|---|
| Account and authentication | Email address and internal account ID provided at sign-up or login. Passwords are stored as salted scrypt hashes. The server stores hashes of refresh tokens and password-reset tokens, together with their expiry and revocation status. We do not store plaintext passwords. | Create and secure accounts, sign in, renew sessions, recover passwords, and prevent deleted accounts from being restored. |
| Profile | Optional details you enter, such as age, year of birth, gender, education, occupation, interests, important experiences, and family situation. | Display and maintain your profile and provide context for memory training and personalized content. You may leave these fields blank; basic training remains available. |
| Memory album and photos | Entries you create, including type, title, story, family context, date, location, factual questions, answers, aliases, and confirmation status. If you choose a photo, the original is uploaded to and stored on the server, along with its MIME type, SHA-256 digest, and byte count. The app reads only photos you select in the system photo picker; it does not scan your entire photo library. A photo may contain embedded EXIF or other metadata written by the camera. The current upload flow does not promise to remove it. | Create personal memories, provide optional personalized memory-training questions, and manage your album. |
| Training and device information | Training or benchmark mode, category, difficulty, question and protocol versions, start and completion times, submitted answers, correctness, scores, answer duration, hint/skip/timeout/interruption status, and permitted task metrics. We also process app and OS versions, device model or category, input method, and time zone. Some answers may be queued locally on your device and uploaded when the network is available. | Run training, verify scores on the server, keep history, sync offline activity, adjust difficulty, and create reports and trends. |
| Reports, trends, and plans | Category scores and sample counts, strengths and areas to improve, suggestions, monthly and yearly trends, difficulty history and current difficulty, training plans, and task completion status. | Show your training history and performance trends and generate difficulty changes and training plans using fixed rules. These reflect training performance and are not medical conclusions. |
| AI settings and interaction records | Consent and withdrawal status for each AI purpose, notice version and timestamps, request action, necessary record reference IDs, model-call status, duration, retries, and token counts. We do not retain AI request text or selected factual answers as long-term AI audit content. Encrypted AI response cache entries expire after at most 15 minutes. | Apply your AI choices, check whether requests are permitted, troubleshoot service issues, and limit abuse. |
| Technical operations information | Service and reverse-proxy logs may contain request time, path, status, errors, and security events. Exact fields and retention periods depend on deployment settings; the current codebase does not set a single retention period for every host and proxy log. | Operate and secure the service and troubleshoot failures. |
This version does not request, read, or write HealthKit data and does not include ad targeting or cross-app tracking. We do not sell your profile, memories, or training records.
AI and Third-Party Services
The AI coach has two separate settings, “AI structured data use” and “AI personal facts use.” Both are off by default and can be withdrawn at any time under “My Profile > AI Data Settings.” Without consent to structured data use, the coach relies on fixed local/server rules and sends no requests to third-party AI. After withdrawal, we stop new requests for that purpose and clear unexpired AI response cache entries on our server. A request already sent to a third party cannot be recalled, and withdrawal does not delete data the third party has received or retained.
The current codebase integrates the DeepSeek Open Platform API. Only when you consent to structured data use and the server’s AI configuration is enabled, EvokeMind sends DeepSeek the minimum context needed for the current action over HTTPS. This may include training category, difficulty or status; report scores and sample counts; a trend summary or plan task; and related record reference IDs. We do not send your account email, password, access or refresh tokens, photos, original stories, full profile, or raw per-question answers to this API. If you enable personal-facts use, you must separately select up to three confirmed facts for each request. Only the selected answers and references are sent; the selection is not carried over to later requests. A rule-explanation request may include the question you submit at that time, up to 500 characters. Do not include unnecessary sensitive information.
Third parties process received data under their own policies. DeepSeek’s current public privacy policy says that inputs and outputs may be encrypted and de-identified before being used for model training and service improvement, and that information collected by its services is stored in China. It does not provide a fixed deletion period for this app’s API requests that EvokeMind can verify. We therefore cannot promise that DeepSeek will not retain or use submitted data for those purposes, and cannot delete data already sent to DeepSeek on your behalf. Read the DeepSeek Privacy Policy. Its practices may change. We will update this policy and the related notice if the server changes AI providers or processing purposes.
When you reset your password, the configured SMTP email service processes your email address and one-time reset token to send the message. Hosting, database, and backup operators may access system data as needed to provide infrastructure and maintenance. Their identities and locations depend on the deployment; the current codebase does not specify a fixed infrastructure provider or region. If you use the system share sheet to send an export, the destination app or service handles the file under its own policy.
Safeguards
Production server and AI API connections use HTTPS. Account data is isolated by account. Passwords are stored as salted scrypt hashes; refresh and reset tokens are stored on the server as hashes; and the app stores session tokens in the iOS Keychain. AI API keys are kept on the server and are not packaged in the app. AI requests are restricted to allowed domains and contain only structured fields needed for the feature; model output is checked against fixed copy. Server-side AI response cache is encrypted. JSON exports are created on the device and use iOS file-protection attributes.
These safeguards cannot eliminate every network, device, or provider risk. The current codebase does not establish that server databases, photos, and database backups are encrypted at rest, and it does not configure one retention period for all deployment logs. Do not put information you do not want a third party to process into AI requests or memory content.
Retention, Withdrawal, and Deletion
- Account, profile, memory, photo, training, report, trend, and plan data are kept on the server while your account is active to provide the related features. You can edit your profile. Deleting a memory removes its text, facts, and photos; related historical training sources are marked as deleted, while summary data needed for scoring is retained.
- The app’s local database stores your account email, session summary, answers, and pending sync data until you delete your account in the app or uninstall it. Logging out does not clear local records. Whether device backups retain local copies depends on your iOS backup settings.
- You can submit “Delete account and all data” under “My Profile.” The server immediately stops sign-in and data access for that account and deletes account-linked data from the primary database. Automated backups may retain copies until rotation; under the deployment policy they are kept for no more than 30 days. The in-app deletion flow clears account caches and pending sync data on the device. Logging out alone does not delete your server account or its data.
- To prevent old credentials, delayed jobs, or restored backups from reactivating a deleted account or withdrawn purpose, the server retains a minimal account UUID, version, timestamp, and withdrawal-purpose marker. These security markers currently have no automatic expiry.
- AI interaction audit metadata is kept for 30 days and then removed by a background task. Encrypted AI response cache expires after 15 minutes. Retention by third-party AI providers is outside EvokeMind’s control and is governed by their policies and terms.
- Server and reverse-proxy log retention depends on deployment settings; the current codebase does not define a single period. The operator should verify and configure these periods before release.
- An export file is created in the app’s sandbox cache only after you request it. The app does not upload it back to EvokeMind, and iOS may clear the cache. If you save or send a copy through the system share sheet, you are responsible for managing and deleting that copy at its destination.
Your Choices and Rights
You can edit your profile, delete individual memories, export your data, or delete your account and associated data in the app. Turning off AI consent stops future third-party requests for that purpose. You can manage photo permissions in iOS Settings. Exports do not include photo files, login credentials, refresh tokens, raw per-question answers, AI request text, or internal operational logs.
For privacy questions or other data-rights requests, first see the EvokeMind Support page, then contact the operator using the app support contact listed on the EvokeMind App Store product page. Provide enough information to verify your account; do not send passwords, verification codes, or access tokens.