Privacy first
隐私政策
Privacy Policy
生效日期 Effective date: 2026-07-26
我们如何处理你的资料
Pluto 默认在设备上计算和生图。隐私模式、云端图谱保存和匿名产品统计默认关闭;本地历史默认开启并仅保存在本设备。隐私模式关闭时,生成的图片默认显示姓名、日期、时间和地点。本地历史开启不会导致任何云端上传。
在普通 HTTP 页面且不是 Capacitor 原生应用时,Pluto 会强制进入临时本地模式:云端保存、匿名统计、云端删除和 Supabase 匿名身份均停用。远程资料功能只在安全上下文或原生运行环境中可用。纯 JavaScript SHA-256 fallback 只用于保持本地 Hash 计算兼容,不提供传输加密,也不能替代 HTTPS。
只有在你单独、明确开启“将新生成的说明书保存到云端”后,新生成的姓名、出生资料、时区、图谱快照及版本信息才会上传。匿名统计也需要单独、明确开启“帮助我们改进 Pluto”,且只发送经白名单限制的操作事件,禁止姓名、出生资料、地点、完整图谱、自由文本和错误堆栈。
为了把你输入的出生地点转换为计算所需的坐标和时区,应用会把你主动输入的地点搜索文字发送给 Photon;服务不可用时可能使用 ArcGIS Geocoding 作为备用。我们不会随地点文字一同发送姓名、出生日期或生成结果。该文字是你手动输入的出生地点,并非你或设备的当前定位。第三方服务可能按照各自政策处理或保留网络请求;提交 App Store 前,我们仍需确认其保留政策并据此完成最终隐私分类。
设备权限
- 相册:仅在你点击“保存图片”时请求,用于把生成图片写入系统相册。
- 系统分享:仅在你主动分享时调用,由 Apple 的分享面板决定接收方。
保留与删除
本地历史默认开启,生成的说明书会保存在本设备。关闭该开关时,应用提供取消、关闭但保留已有记录、关闭并删除全部记录三种选择。选择保留时仍可打开和逐条删除旧记录,但新结果不会继续加入历史。卸载应用也会移除本地历史。“删除云端图谱与个人资料”会在同一事务中删除当前匿名身份保存的姓名、出生资料、图谱、授权记录与云端资料,不会删除本设备历史。已经记录的匿名使用事件会移除用户标识,并最多保留 180 天用于汇总统计;不含出生资料的删除收据最多保留 365 天。本地与云端删除需要分别操作。
儿童与健康声明
本应用面向 13 岁及以上用户,用于自我探索与娱乐,不提供医疗、心理、法律或财务诊断与建议。
How we handle your information
Pluto calculates and renders locally by default. Privacy mode, cloud chart saving, and anonymous product analytics are off by default. Local history is on by default and stored only on this device. With privacy mode off, generated images show the entered name, date, time, and location. Enabling local history never uploads data to the cloud.
On an ordinary HTTP page outside the Capacitor native app, Pluto enforces temporary local-only mode: cloud saving, analytics, cloud deletion, and Supabase anonymous identity are disabled. Remote data features require a secure context or the native runtime. The pure JavaScript SHA-256 fallback only preserves compatible local hashing; it does not encrypt transport and is not a substitute for HTTPS.
Only after you separately and explicitly enable Cloud Save may new names, birth details, time zones, snapshots, and versions be uploaded. Anonymous analytics also require separately enabling Help Us Improve Pluto, which sends only allowlisted action events and rejects names, birth details, locations, complete charts, free text, and raw stacks.
To convert a place you enter into coordinates and a time zone, the app sends only your place-search text to Photon and may use ArcGIS Geocoding as a fallback. We do not send your name, birth date, or generated result with that query. The text is a manually entered birth place, not the current location of you or your device. These providers may process or retain requests under their own policies; their retention behavior must still be confirmed before the final App Store privacy classification.
Device permissions
- Photos: requested only when you choose Save Image, solely to add the generated image to your library.
- System sharing: opened only when you choose Share; recipients are controlled by Apple's share sheet.
Retention and deletion
Local history is on by default, so generated Life Manuals are saved on this device. Turning it off offers three choices: cancel, stop future saves while keeping existing records, or stop and delete all records. Kept records remain available to open or delete individually, while new results are not added. Uninstalling also removes local history. Delete Cloud Charts and Personal Data atomically removes the current anonymous identity's saved name, birth details, charts, consent records, and cloud profile, but not local history. Previously recorded usage events are deidentified and retained for no more than 180 days for aggregate statistics. Birth-data-free deletion receipts are retained for no more than 365 days. Local and cloud deletion are independent.
Children and wellness disclaimer
The app is intended for ages 13 and older. It is for personal reflection and entertainment and does not provide medical, psychological, legal, or financial diagnosis or advice.
联系 / Contact
隐私问题请通过应用商店产品页中公布的开发者支持渠道联系我们。 For privacy questions, use the developer support channel listed on the app's store page.