Privacy隐私政策

Effective: August 2, 2026生效日期:2026 年 8 月 2 日

The short version简要说明

Your diary pages, personas, conversation history, and long-term persona memory stay on your device and are encrypted at rest. When you ask for an AI reply, Vellink sends a bounded, structured request to its gateway. The gateway is designed not to persist diary text, images, persona prompts, or AI reply bodies.你的日记页面、人物设定、对话历史和人物长期记忆保存在设备本地,并以加密形式落盘。当你请求 AI 回复时,Vellink 仅向网关发送受限长度的结构化请求。网关被设计为不持久保存日记正文、图片、人物提示词或 AI 回复正文。

Data kept on your device保存在设备上的数据

Diary pages, recognized handwriting, conversation history, persona settings and memory, snapshots, and Thinking Canvas drafts are stored in app-private files protected with AES-256-GCM. The encryption key is generated and held by Android Keystore. Existing readable files are migrated in place after a successful read; active diary content remains until you delete it or remove the app. Display preferences and short-lived service tokens remain in app-private storage.日记页面、手写识别文字、对话历史、人物设定与记忆、书写快照,以及思维画布草稿,会保存在应用私有目录,并使用 AES-256-GCM 加密;加密密钥由 Android Keystore 生成和保管。旧版可读明文会在成功读取后原地迁移,活跃日记内容会一直保留到你主动删除或卸载应用。显示偏好和短期服务令牌仍保存在应用私有存储中。

Data processed by the service服务处理的数据

For an AI request, the gateway temporarily processes the selected persona instructions, bounded memory and recent turns, your current message, and an image only when handwriting recognition needs an image fallback. The request is forwarded to the configured AI provider and is not written to the subscription database.生成 AI 回复时,网关会临时处理所选人物指令、受限长度的记忆与近期对话、当前消息,以及仅在手写识别需要时使用的图片。请求会被转发给配置的 AI 服务商,但不会写入订阅数据库。

Service metadata服务元数据

We keep a pseudonymous device identifier derived from the device public key, the public key itself, and a one-way stable-device claim used to prevent repeated trials. On Android, that claim is hashed locally from the app-scoped Android identifier and package name; the raw Android identifier is never uploaded. We also keep app platform and version, trial and subscription dates, reply counters, activation-code hashes, purchase identifiers, request identifiers, timestamps, request purposes, and success or failure status. This metadata supports authorization, fraud prevention, quotas, refunds, and service reliability.我们会保存由设备公钥派生的匿名设备标识、公钥本身,以及用于防止重复试用的单向稳定设备声明。Android 端会在本地使用应用作用域的 Android 标识与包名生成哈希,原始 Android 标识不会上传。我们还会保存应用平台与版本、试用和订阅日期、回复计数、激活码哈希、购买标识、请求标识、时间戳、请求用途以及成功或失败状态。这些元数据用于授权、防滥用、额度、退款和服务稳定性。

Web experience at vell.ink/tryvell.ink/try 网页体验

The web experience has no account or cloud sync. Its ink strokes, recent replies, and selected persona are stored in a separate IndexedDB database in your browser. Vellink's server does not store those contents. Clearing this site's browser data can remove them permanently; the page also provides a control to clear all local experience data.网页体验不提供账号或云同步。笔迹、近期回信和所选人物会保存在浏览器中独立的 IndexedDB 数据库里,Vellink 服务端不保存这些内容。清除本网站的浏览器数据可能使其永久丢失;体验页也提供一键清除全部本地体验数据的入口。

A secure first-party anonymous visitor cookie enforces the web allowance of up to ten validated successful official-model replies per Beijing calendar day, resetting at 00:00 Beijing time. A separate first-party anonymous analytics cookie measures product use. Both values are stored server-side only as keyed HMAC identifiers. The raw network IP is read at the Cloudflare edge, immediately transformed with a server secret for rate limiting, and is never written to D1 or application logs. Shared-network limits are deliberately higher than the per-visitor limit.安全的第一方匿名访客 Cookie 用于执行网页版“每个北京时间自然日最多 10 次经校验的官方模型成功回复”额度,并在北京时间 00:00 重置;另一枚相互独立的第一方匿名统计 Cookie 用于衡量产品使用。两者在服务端只以带密钥的 HMAC 标识保存。原始网络 IP 仅在 Cloudflare 边缘即时读取并以服务端密钥转换后用于限流,不写入 D1 或应用日志;共享网络限制会刻意高于单访客额度,减少误伤。

We collect only allowlisted coarse events: visits and return visits, first ink, first submission, reply success or failure category, persona selection, reaching three successful replies, invitation display and click, and categorical survey answers (a 1–5 experience score, one or more desired native focuses, one or more current drawbacks, support intent, and—only after affirmative intent—a selected plan). We also count email-signup success and Xiaohongshu-message intent separately. The survey has no free-text field. We do not collect diary text, strokes, images, handwriting transcription, prompts, model replies, email addresses, request bodies, raw visitor IDs, or raw IP addresses in analytics. Event detail is retained for 90 days; content-free daily and retention aggregates may be kept long term. The page can reset the analytics identity and delete eligible event detail without resetting anti-abuse reply quota or an email availability signup.我们只收集白名单内的粗粒度事件:访问与再次访问、首次落笔、首次提交、回复成功或失败类别、人物选择、完成三次成功回复、邀请展示与点击,以及分类问卷答案(1~5 分体验评分、一个或多个希望优先做好的原生功能、一个或多个当前主要不足、支持意愿,并且只在明确愿意了解方案后记录所选套餐)。邮箱登记成功与小红书私信意向会分开计数;问卷不提供自由文本输入。统计中不会收集日记文字、笔迹、图片、手写识别文字、提示词、模型回信、邮箱地址、请求体、原始访客标识或原始 IP。事件明细保留 90 天;不含内容的每日聚合与留存聚合可长期保存。体验页可以重置统计标识并删除符合条件的事件明细,但不会借此重置防滥用回复额度或邮箱开放通知登记。

For a handwritten web turn, the browser sends one tightly cropped PNG of the current ink (at most 768 × 768 pixels and 650 KB), up to six recent local turn pairs, a fixed persona ID, and locale. The isolated web-demo Worker sends that image to Cloudflare Workers AI only for temporary handwriting transcription; neither the image nor the transcription is written to D1 or application logs. The recognized text is then passed to the configured text-only reply-model chain for the current reply. Failed handwriting recognition, reply generation, timeouts, or browser cancellation do not consume the daily successful-reply allowance.网页版每次手写提交时,浏览器会发送一张仅包含当前笔迹的紧裁剪 PNG(不超过 768 × 768 像素、650 KB)、最多六组近期本地对话,以及固定人物 ID 和语言。隔离的网页体验 Worker 仅将该图片临时交给 Cloudflare Workers AI 抄录笔迹;图片和抄录文字都不会写入 D1 或应用日志。识别出的文字随后交给已配置的纯文本回复模型链生成当次回信;手写识别失败、回信生成失败、超时或浏览器取消都不会扣除当天的成功回复额度。

If you explicitly choose email notification for the native iPad release, we normalize the address, use a keyed HMAC only to prevent duplicates, and store the address separately from analytics using AES-GCM encryption under a dedicated server secret. It is used only to notify you when the native iPad version opens. Signup is limited by anonymous visitor, transformed network, ASN, and global thresholds. Raw IP addresses are not stored. You may withdraw from the paper menu; withdrawal immediately removes the encrypted address and its email-derived HMAC while retaining only a pseudonymous suppression marker. Contact details are kept for at most 12 months or 90 days after the native iPad release, whichever comes first. Xiaohongshu-message intent stores no Xiaohongshu account or contact detail.只有当你明确选择接收 iPad 原生版开放邮件时,我们才会规范化邮箱地址,并用带密钥的 HMAC 防止重复登记;邮箱地址使用独立服务端密钥进行 AES-GCM 加密,并与普通统计分开保存。邮箱只用于通知 iPad 原生版开放。登记接口按匿名访客、经转换的网络标识、ASN 和全局阈值限流,原始 IP 不落库。你可以从纸面菜单撤回登记;撤回后会立即删除加密邮箱及其邮箱派生 HMAC,只保留匿名的免打扰标记。联系方式最长保留 12 个月,或在 iPad 原生版正式发布后 90 天删除,以先到者为准。小红书私信意向不会保存小红书账号或联系方式。

Payments付款

Future iPad purchases will be processed by Apple. Website checkout currently uses the WeChat Pay or Alipay QR code shown on the order page. Vellink receives only the information needed to match and deliver that order: payment channel, exact amount, notification and receipt time, one-way event and monitor-device fingerprints, selected product, order status, and delivery status. We do not receive your wallet balance, password, full payment-card details, contacts, or chat history, and we do not retain the original payment-notification text in the Commerce database.未来 iPad 购买将由 Apple 处理。官网结账目前使用订单页展示的微信或支付宝收款码。Vellink 只接收完成订单匹配与发码所必需的信息:付款渠道、实付金额、通知与到账时间、单向事件与监听设备指纹、所选产品、订单状态和发码状态。我们不会获得你的钱包余额、密码、完整银行卡信息、联系人或聊天记录,也不会在收款数据库中保留原始付款通知正文。

Feedback and optional diagnostics意见反馈与可选诊断

When you submit feedback in the app, we process the feedback text and any contact details you choose to provide so we can reply, investigate a problem, and improve Vellink. You may optionally include diagnostics such as the app version, device model, system version, request identifier, and error details. Diary text and images are not attached by default. Feedback is delivered to feedback@vell.ink and may be forwarded by our mail provider to an authorised support inbox. The feedback copy in Vellink's service database is deleted after 30 days unless a longer period is required for an active dispute or legal obligation. Forwarded email copies follow the authorised mailbox provider's retention settings. You may email us to request earlier deletion, subject to records we must retain.当你在应用内提交意见反馈时,我们会处理意见正文、联系方式(由你选择是否提供),用于回复、排查问题和改进 Vellink。你可以选择附上应用版本、设备型号、系统版本、请求标识和错误信息等可选诊断;日记正文和图片不会默认附带。反馈会发送至 feedback@vell.ink,并可能由邮件服务商通过邮件转发至获授权的支持邮箱。Vellink 服务数据库中的反馈副本会在 30 天后删除;正在处理的争议或法律义务需要更长时间时除外。转发到邮箱的副本遵循获授权邮箱服务商的保存设置。你可以邮件申请提前删除,但依法必须保留的记录除外。

Retention and deletion保存与删除

Active local diary data remains until you delete it or remove the app; deleted local conversations become purge-eligible after 30 days. Completed request-usage records are retained for 90 days; web analytics event records are also retained for 90 days. Email availability contacts are kept for at most 12 months or 90 days after native iPad release (whichever is earlier), feedback records in Vellink's service database for 30 days, security alerts for 180 days, and inactive unsubscribed device records for 180 days. A pseudonymous trial claim is retained for as long as needed to prevent repeated trials. Purchase, refund, accounting, dispute, and legally required records may be retained longer. To request deletion of eligible server-side metadata, email feedback@vell.ink.活跃的本地日记数据会保留到你主动删除或卸载应用;已删除的本地对话在 30 天后进入可清理状态。已完成的请求使用记录保存 90 天;网页统计事件明细同样保存 90 天。iPad 开放通知邮箱最长保存 12 个月,或在原生 iPad 版发布后 90 天删除,以先到者为准;Vellink 服务数据库中的意见反馈记录保存 30 天,安全告警保存 180 天,未订阅且长期不活跃的设备记录保存 180 天。用于防止重复试用的匿名试用声明会在防滥用所需期间保留。购买、退款、财务、争议和法律要求的记录可能需要保存更久。如需删除符合条件的服务端元数据,请联系 feedback@vell.ink。

Contact联系我们

feedback@vell.ink