隐私政策
生效日期:2026 年 7 月 1 日
我们收集哪些数据
Self Researcher 会在用户通过 Apple Health 授权后读取与健康和健身功能相关的数据,例如步数、心率、静息心率、心率变异性(HRV)、睡眠、活动能量、锻炼时间、锻炼记录、步行跑步距离、呼吸频率和血氧等。用户还可以在 App 的“健康数据授权”页面选择开启心率恢复、有氧适能、体力负荷、日照时间、睡眠腕温、正念时间,以及 iOS 18 及以上系统提供的心境愉悦度等进阶数据。应用只使用心境记录的日期和愉悦度数值进行日级摘要,不读取心境标签、关联项目或备注。运动恢复功能还会读取训练内心率和锻炼结束后 3 分钟内的短时心率窗口。应用只读取用户在 Apple Health 中授权且在 App 内启用的 HealthKit 数据。
应用还会在设备本机保存用户主动选择填写的资料卡信息(例如年龄和性别)、训练复盘补充问卷(例如训练目标、训练类型或部位、主观强度、身体感受和后续计划)、每日感受问卷(心情、精力、压力和身体疲劳,均为 1-5 分)、AI 模型配置、自动分析设置、分析历史、锻炼 AI 复盘和订阅状态。年龄、性别及两类补充问卷均为可选项;用户可以跳过,之后也可以在设置或分析流程中补充、修改或删除。每日感受记录默认只保存在本机。这些数据用于本机趋势展示、生成用户主动请求或明确开启的自动 AI 分析、保存分析记录,以及解锁订阅功能。HealthKit 中的锻炼与心率样本不会作为副本长期保存在应用中,每次展示时从 Apple Health 重新读取。
运动恢复只读取 Apple Health 中已经存在的锻炼记录。Self Researcher 不会创建、修改或删除 Apple Health 中的锻炼;Apple Watch 端也不会启动额外的临时 Workout。
进阶数据默认不在 App 内启用。用户开启某一进阶项后,iOS 会显示由 Apple 管理的授权页面;用户可以在 App 内停止加载该项,也可以随时在 Apple Health 或系统设置中撤销读取权限。Apple 不向第三方 App 返回每一项只读权限的精确授权状态,因此没有授权或没有样本的指标会保持为空。
我们如何使用数据
HealthKit 数据和用户资料会用于生成健康趋势、个人基线、长期统计特征、今日活动节奏、恢复和睡眠参考,以及用户主动发起的 AI 分析。订阅版可以在设备本机比较每日感受或心境日级摘要与睡眠、活动、日照和正念等日级摘要,并只生成压缩后的个人模式候选。应用不会仅根据 HRV、心率或睡眠推断用户真实的心情、压力或疲劳。Self Researcher 的分析结果仅供健康管理和生活方式参考,不构成医疗诊断、治疗建议、疾病监测或紧急医疗服务。
Self Researcher 不会将 HealthKit 数据、AI 分析内容或用户资料用于广告、营销、跨 App 跟踪或出售。应用不读取 Apple ID、通讯录或精确定位,也不会发送未经授权的数据。
自动分析与通知
用户可以选择开启自动分析功能,例如每天在指定时间进行一次深度分析,或在检测到 Apple Fitness/Apple Health 中新增且时长超过用户设定阈值的锻炼记录后生成运动恢复分析。自动分析默认关闭;只有用户在 App 内主动开启相应开关后才会运行。用户可以随时在设置中关闭自动分析、调整每日分析时间、调整新运动最短时长阈值,或关闭分析完成通知。
自动分析触发时,App 只发送该次分析需要的健康摘要和上下文:每日深度分析会使用所选范围的健康摘要、资料卡、关注方向、个人模式证据、用户主动填写的每日感受摘要(如有)和必要的历史分析摘要;新运动自动分析会使用该次锻炼摘要、压缩心率趋势、运动后恢复窗口、训练前身体信号、近期或同类型训练背景、资料卡,以及用户在训练复盘补充中主动填写的内容。App 不会因为开启自动分析而发送 Apple ID、通讯录、精确位置、HealthKit 全量原始记录或未授权数据。
iOS 不保证第三方 App 精确后台准点执行,因此每日自动分析可能在 App 打开或回到前台时补跑。通知权限仅用于提醒用户分析已完成或提醒用户打开 App 补跑到期分析;通知内容只包含分析完成或打开 App 的提示,不包含完整健康数据。若用户拒绝通知权限,分析结果仍会保存在 App 内。
AI Token 与第三方 AI 服务
App 支持用户自行选择第三方 AI 服务商并填写 API Token,例如 DeepSeek、通义千问、智谱 GLM、Moonshot、硅基流动、兼容 API 接口或用户自定义服务。Token 保存在用户设备本机 Keychain,仅用于向用户选择的 AI 服务商发起请求。
AI 请求会携带用户配置的 API Token。第三方 AI 服务商可能依据其隐私政策和账户体系,将收到的请求及其中的数据关联到该 Token 所属的服务商账户。用户应查看所选服务商的隐私政策、数据保留规则和服务条款。
当用户主动发起 AI 分析时,只有在应用内确认“Agree and Send to Third-Party AI”或同等含义的发送确认按钮后,应用才会把本次 AI 分析所需的数据发送给用户选择的第三方 AI 服务商。用户可以在发送前取消;如果用户取消,应用不会向第三方 AI 服务发送本次健康数据。自动分析默认关闭;开启任一自动分析前,App 会显示独立确认页,明确接收方、触发条件、发送内容、用途和关闭方式。只有用户点击“同意并开启自动分析”后,该自动化才会启用,并在对应触发条件满足时自动发送该次分析所需的数据摘要。用户可以随时关闭自动分析。
发送前的确认界面会显示接收方(AI 服务商、模型和 API 主机)、发送的数据类别、用途,以及不会发送的数据。可能发送的数据包括:所选 HealthKit 指标的摘要、长期统计特征、近期日级证据、分段趋势、跨指标个人模式证据矩阵和候选、用户主动填写的每日感受摘要及由设备本机生成的压缩主观模式候选、今日小时级节奏、锻炼摘要、压缩心率趋势、运动后恢复窗口、训练前 72 小时身体信号、近期或同类型训练背景、用户资料卡信息、用户在训练复盘补充中主动填写的内容、分析侧重点和上一条 AI 分析的压缩摘要。应用不会发送 Apple ID、通讯录、精确定位、HealthKit 全量原始记录、Apple Health 心境标签/关联项目/备注或用户未授权的数据。
第三方 AI 服务仅用于生成用户本次请求的 AI 分析。Self Researcher 要求第三方 AI 服务对接收到的数据提供与本政策相同或同等水平的保护,不得将这些数据用于广告、营销或跨 App 跟踪。用户配置自定义接口时,应确认该接口由自己控制或由自己信任的服务商提供,并阅读对应服务商的隐私政策和服务条款。
数据存储
健康趋势、分析记录、运动复盘、自动分析设置、AI 配置、API Token、用户资料、每日感受和用户主动填写的训练复盘补充主要保存在设备本机。API Token 保存在 Keychain 中。我们不运营独立服务器来集中存储用户健康数据。
第三方 AI 服务对其接收到的数据的处理和保留受其自身隐私政策和服务条款约束。Self Researcher 不会从第三方 AI 服务处取回并集中保存用户健康数据。
用户控制与删除
用户可以在 Apple Health 中管理或撤销 HealthKit 授权,也可以在 App 内关闭某项进阶读取、修改 AI 模型配置、停止发起 AI 分析、关闭自动分析、关闭通知、调整自动分析触发条件,或删除本机保存的每日感受、分析记录和运动复盘。删除每日感受后,后续 AI 请求将不再包含该记录。删除 App 通常会移除设备上的 App 本地数据;HealthKit 中原有的 Apple Health 数据仍由 Apple Health 管理。
如需协助删除本机数据、反馈隐私问题或咨询数据使用方式,可以通过本政策底部的联系方式联系我们。
订阅与付款
订阅购买、续订、退款和取消由 Apple App Store 处理。App 仅通过 StoreKit 读取订阅状态,用于解锁全部可用历史特征萃取和高阶统计。
English Summary for App Review
Self Researcher reads user-authorized Apple Health data such as steps, heart rate, resting heart rate, HRV, sleep, active energy, exercise minutes, workout records, walking/running distance, respiratory rate, and oxygen saturation for health and fitness features. Users may also optionally enable heart-rate recovery, cardio fitness, physical effort, time in daylight, sleeping wrist temperature, mindful minutes, and State of Mind valence on iOS 18 or later in the app’s Health Data Access screen. For State of Mind, the app uses only the date and valence value for daily summaries; it does not read labels, associations, or notes. Workout recovery also reads in-workout heart rate and a short heart-rate window within 3 minutes after the workout ends. The app stores optional user-entered profile details, optional workout review supplement answers, optional daily check-ins for mood, energy, stress, and physical fatigue, AI model configuration, automation settings, analysis history, workout AI reviews, and subscription status on the user’s device. Age, gender, and both questionnaires are optional. HealthKit workout and heart-rate samples are re-read from Apple Health rather than retained as a long-term duplicate.
Advanced data types are disabled in the app by default. Enabling one opens Apple’s authorization sheet. Users can stop the app from loading an advanced type at any time and can revoke read access in Apple Health or Settings. Apple does not disclose the precise read-authorization status of each data type to third-party apps, so a metric remains empty when access or samples are unavailable.
The app uses this data for on-device trend display, personal baselines, long-range statistical features, workout recovery and sleep references, and AI analysis that the user manually requests. Workout recovery only reads workouts that already exist in Apple Health; the app does not create, modify, or delete Apple Health workouts, and the Apple Watch app does not start an additional temporary workout. Health data is not used for advertising, marketing, cross-app tracking, or sale.
The app supports user-selected third-party AI providers, including DeepSeek, Qwen, Zhipu GLM, Moonshot, SiliconFlow, compatible API endpoints, or a custom endpoint. API tokens are stored locally in the device Keychain and are used only for requests to the provider selected by the user.
The app also supports optional automations. Users may enable a daily deep analysis at a selected time or enable new-workout analysis when a newly detected Apple Fitness/Apple Health workout exceeds the user-selected minimum duration. Automations are off by default and can be turned off or adjusted at any time. When an automation is triggered, the app sends only the data summary needed for that specific analysis to the user-selected AI provider. A daily deep analysis may include voluntary daily check-in summaries when available; a workout analysis may include voluntary workout supplement answers. iOS may run due automations when the app opens or returns to the foreground. Notification permission is used only to notify that an analysis is complete or to remind the user to open the app for a due analysis; notifications do not contain full health data.
AI requests use the API token configured by the user. Under the selected provider’s privacy policy and account system, the provider may associate a request and its data with the provider account represented by that token. Users should review the selected provider’s privacy policy, retention practices, and terms.
When the user manually starts an AI analysis, the app sends summarized health data to a third-party AI service only after the user explicitly taps “Agree and Send to Third-Party AI” or an equivalent consent button in the app. Automations are off by default. Before enabling any automation, the app presents a separate consent screen that identifies the recipient, trigger, data categories, purpose, and how to turn the automation off. The automation is enabled only after the user taps “Agree and Enable Automatic Analysis”; it may then send the data summary needed for the corresponding analysis when its trigger condition is met. Before manual sending, the app identifies the recipient, including the AI provider, model, and API host, explains the data categories sent, states the purpose, and identifies data that is not sent. If the user cancels a manual request, the app does not send the health data to the third-party AI service.
Data that may be sent includes selected HealthKit metric summaries, long-range statistical features, recent daily evidence, segmented trends, cross-metric personal pattern evidence matrices and candidates, voluntary daily check-in summaries and compressed subjective-pattern candidates generated on device, today’s hourly rhythm, a workout summary, a compressed heart-rate trend, post-workout recovery windows, pre-workout 72-hour body signals, recent or same-activity workout context, user profile details, optional workout review supplement answers, selected analysis focus areas, and a compact summary of the previous AI analysis when used for comparison. The app does not send Apple ID, contacts, precise location, full raw HealthKit records, State of Mind labels/associations/notes, or unauthorized data.
The third-party AI service is used only to generate the user-requested AI analysis. Self Researcher requires third-party AI services that receive this data to provide the same or equal privacy and security protection as described in this policy and not to use the data for advertising, marketing, or cross-app tracking. If the user configures a custom endpoint, the user should confirm that the endpoint is controlled by them or provided by a trusted service provider and review that provider’s privacy policy and terms.
Self Researcher does not operate a server that centrally stores user health data. Health trends, analysis history, workout reviews, automation settings, AI configuration, API tokens, user profile details, daily check-ins, and optional workout supplement answers are primarily stored on the user’s device. Premium analysis may compare daily check-ins or State of Mind daily summaries with daily sleep and activity summaries on device and send only compressed pattern candidates. The app does not treat HRV or heart rate as the user’s actual emotion. AI results are for wellness and lifestyle reference only and are not medical diagnosis, treatment advice, disease monitoring, or emergency medical service.
联系我们
如需删除本机数据、反馈隐私问题或咨询 App 使用问题,请发送邮件至 2716288374@qq.com。