命FateOS命运实验室
返回应用 / Back to app

数据边界 · 01

隐私政策

FateOS 只处理提供记录、AR 掌相和你主动请求的 AI 自我反思所需的数据。观察事实、传统象征解读和情景假设会分开呈现。

正在核对发布资料

运营主体与生产处理商从 FateOS 法务发布清单读取。

运营主体处理的数据相机与掌纹AI 处理保存期限你的权利

1. 适用范围与运营主体

本政策适用于 FateOS 网页、海外 iOS 应用和 Android 应用。FateOS 是生活方式与自我反思工具,不提供医疗或心理诊断、法律或投资建议、生育或寿命预测,也不承诺必然结果。

数据控制者/运营主体未配置
注册地址未配置
隐私联系邮箱未配置
生效日期未配置

2. 我们处理的数据

  • 你主动填写的称呼、出生城市、当地出生日期与时间、IANA 时区及时间准确程度。
  • 你保存的精力、进展、情绪记录、现实事件和行动复盘。
  • 你明确确认的掌纹文字特征,例如长度、清晰度、连续性和弯曲度。
  • 你主动提交的问题、生成的中英双语 AI 解读、证据引用、行动建议和历史报告。
  • 目的明确的同意与撤回记录,以及服务器验证的订阅权益;外部交易标识只保存不可逆摘要。
  • 任务类型、状态、耗时、Token 数、质量结果和随机追踪标识等假名化运行信息。运行日志不保存用户问题正文、模型回答正文、API 密钥或原始掌纹图像。

3. 相机与掌纹

相机只用于设备端手部定位、拍摄引导和实时 AR 图层。相机帧不上传、不写入 FateOS 服务,也不保留原始图像。手部关键点不等于掌纹识别;只有你主动确认的文字特征可以进入 AI 解读。

FateOS 不进行身份识别、生物特征模板建立、掌纹变化判断或社交匹配。你可拒绝或撤回系统相机权限,并继续使用不依赖相机的功能。

4. AI 处理

每次个性化结论都由管理员配置的模型服务实时生成;本地模板不会冒充 AI 结果。只有在 `ai_guidance` 同意有效且你主动发起功能时,FateOS 才发送完成当前任务所需的档案、记录、问题和已确认掌纹描述。相机画面、管理员 API 密钥和模型配置不会发送给用户端或写入用户导出。

模型输出会经过结构、证据、安全和双语质量校验。证据不足、验证失败或模型不可用时,应用显示不可用状态,不补造结论。生产处理商与处理地区如下:

生产处理商尚未配置。

5. 处理目的与依据

  • 提供档案、趋势、AR 掌相与 AI 反思:履行你主动请求的服务,并在适用时取得目的明确的同意。
  • 出生资料保存与时间换算:仅在 `birth_data_processing` 同意有效时进行。
  • 相机访问:需要应用内说明以及 iOS/Android 系统权限。
  • 防滥用、稳定性和故障排查:基于提供安全服务的合法利益,并采用最少化运行日志。
  • 订阅验证:履行购买、恢复购买及防止交易滥用所必需。

6. 服务商与跨境处理

数据只交由提供托管、数据库、AI 推理和商店交易验证所必需的服务商处理。FateOS 不出售个人数据,不用于第三方定向广告或数据经纪。每个生产处理商的地区与跨境保障会在上方清单中公开。

7. 保存期限

非活跃账号730 天后删除或匿名化,并在到期前按适用规则通知。
运行日志最多 30 天。
加密备份最多 35 天后随轮换失效。
交易验证记录最多 2555 天,或依法需要的更短/更长期限。

账号永久删除会移除在线主库中的档案、记录、解读、权益及可关联审计。备份中的数据会在上述轮换周期内失效。

8. 你的选择与权利

你可以在应用内撤回相机、出生资料和 AI 资料使用同意,导出机器可读档案,并永久删除账号与数据。也可联系运营主体请求访问、更正、限制、反对、数据可携带或投诉。撤回不影响撤回前已经合法完成的处理。

删除服务暂时不可用时,客户端先清除本地资料并保存待删除标记,联网后自动重试;完成前不会发送新的个性化资料。

9. 安全

生产环境使用 HTTPS、受控管理员密钥、最小权限访问、PostgreSQL 持久化、交易服务端验签、删除审计及经过验证的备份恢复。任何系统都无法保证绝对安全;依法需要通知的数据事件将按适用法律处理。

10. 未成年人

最低使用年龄为 18 岁。FateOS 不以儿童为目标;若发现不符合年龄要求的数据,将采取删除和限制措施。

11. 政策变更、法律与联系

重大变更会在应用或网站显著通知,并在需要时重新征求同意。适用法律与争议管辖:未配置。隐私问题请联系 未配置。

Data boundary · 01

Privacy Policy

FateOS processes only the data needed for records, AR palm reflection, and AI self-reflection you explicitly request. Observations, traditional symbolic interpretations, and scenario assumptions remain separate.

Checking release details

Operator and production processor details are loaded from the FateOS legal release manifest.

ControllerData processedCamera & palmAI processingRetentionYour rights

1. Scope & Controller

This policy applies to the FateOS web app, overseas iOS app, and Android app. FateOS is a lifestyle and self-reflection tool. It does not provide medical or psychological diagnosis, legal or investment advice, fertility or mortality predictions, or guaranteed outcomes.

Data controller/operatorNot configured
Registered addressNot configured
Privacy contactNot configured
Effective dateNot configured

2. Data We Process

  • Your chosen name, birth city, local birth date and time, IANA time zone, and time-confidence level.
  • Energy, progress, and mood check-ins, observed events, and action reviews you save.
  • Palm descriptors you explicitly confirm, such as length, clarity, continuity, and curve.
  • Questions you submit, bilingual AI readings, cited evidence, actions, and reading history.
  • Purpose-specific consent and withdrawal records, plus server-verified subscription entitlement; external transaction identifiers are retained only as irreversible hashes.
  • Pseudonymous operational data such as task, status, latency, token count, quality outcome, and random trace ID. Logs exclude user question bodies, model response bodies, API credentials, and original palm images.

3. Camera & Palm Data

The camera is used only for on-device hand positioning, capture guidance, and live AR overlays. Frames are not uploaded, written to the FateOS service, or retained. Hand landmarks are not palm-line recognition; only descriptors you explicitly confirm can enter an AI reading.

FateOS does not perform identity recognition, biometric-template creation, palm-change detection, or social matching. You can deny or revoke system camera permission and continue using features that do not require it.

4. AI Processing

Every personalized conclusion is generated live by the administrator-configured model service; local templates are never presented as AI output. Only while `ai_guidance` consent is current and you actively request a feature does FateOS send the profile, records, question, and confirmed palm descriptors needed for that task. Camera frames, administrator API credentials, and model configuration are not sent to user clients or written to user exports.

Output passes schema, evidence, safety, and bilingual quality checks. Insufficient evidence, failed validation, or model unavailability produces an unavailable state rather than a fabricated conclusion. Production processors and regions:

Production processors are not configured.

5. Purposes & Legal Bases

  • Profile, trend, AR palm, and AI reflection features: performance of the service you request and purpose-specific consent where applicable.
  • Birth-data storage and time normalization: only while `birth_data_processing` consent is current.
  • Camera access: an in-app explanation plus iOS or Android system permission.
  • Abuse prevention, reliability, and troubleshooting: legitimate interests in secure service delivery using minimized logs.
  • Subscription verification: necessary to fulfill purchases, restore purchases, and prevent transaction abuse.

6. Processors & International Transfers

Data is disclosed only to processors needed for hosting, databases, AI inference, and store transaction verification. FateOS does not sell personal data or use it for third-party targeted advertising or data brokerage. Each production processor's region and transfer safeguard is disclosed above.

7. Retention

Inactive accountsDeleted or anonymized after 730 days, with notice where required.
Operational logsUp to 30 days.
Encrypted backupsExpire through rotation within 35 days.
Purchase verificationUp to 2555 days, or a shorter/longer period required by law.

Permanent account deletion removes profiles, records, readings, entitlements, and linkable audits from the active database. Backup copies expire within the rotation period above.

8. Your Choices & Rights

You can withdraw camera, birth-data, and AI-data consent in the app, export a machine-readable archive, and permanently delete your account and data. You may also contact the operator to request access, correction, restriction, objection, portability, or complaint. Withdrawal does not affect processing lawfully completed before withdrawal.

If deletion is temporarily unavailable, the client clears local data, retains a deletion marker, retries when connectivity returns, and blocks new personalized uploads until completion.

9. Security

Production uses HTTPS, protected administrator secrets, least-privilege access, PostgreSQL persistence, server-side transaction verification, deletion auditing, and verified backup restoration. No system can guarantee absolute security; legally notifiable incidents will be handled under applicable law.

10. Children

The minimum age is 18. FateOS is not directed to children. Data discovered to fall below the applicable age threshold will be deleted or restricted.

11. Changes, Law & Contact

Material changes will be disclosed in the app or website and renewed consent requested where required. Governing law and jurisdiction: Not configured. Privacy questions: Not configured.

FateOS · Updated 2026-08-04
支持 / Support账号删除 / Account deletion