ReadOS Privacy
Privacy Policy
隐私政策
This policy explains what ReadOS stores on your device and what happens when you choose to connect the app to websites, AI providers, document services, merchants, or other remote systems.
ReadOS primarily stores your workspace data locally. Data needed for an action is sent directly to a third party only when you visit a website, use AI, invoke MinerU, enable a merchant service, or configure another remote connection. The current app does not route those transfers through a ReadOS-operated content, advertising, or analytics backend.
ReadOS 主要在设备本地保存工作区数据。 只有当你访问网站、使用 AI、调用 MinerU、启用商家服务或配置其他远程连接时, 完成操作所需的数据才会直接发送给相应第三方。当前 App 不通过 ReadOS 运营的内容、 广告或分析后端中转这些数据。
ReadOS Privacy Policy
1. Scope and provider
This Privacy Policy applies to the ReadOS iPad app and explains the app’s current data practices. ReadOS is provided by Xiufang Wang (referred to as “ReadOS,” “we,” or “us” in this policy).
ReadOS does not require a separate developer-operated ReadOS account. Some optional features use accounts or credentials issued by Apple, ChatGPT/OpenAI, MinerU, merchants, websites, Git or SSH hosts, or other services you choose. Those providers process information under their own terms and privacy policies.
The current app code does not include developer-operated advertising, cross-app tracking, analytics, crash-report uploads, or a content backend that receives your workspace or connected-service traffic. This statement does not cover processing independently performed by Apple through the App Store or TestFlight, by the host serving these legal pages, or by a third party you choose to use.
2. Information stored on your device
Depending on the features you use, ReadOS may store locally:
- Workspace content: imported or created documents, folders, notes, PDFs, images, audio, video, Office files, generated images, downloads, extracted content, transcripts, document-analysis results, and related metadata.
- Readex content: conversations, prompts, responses, attachments, tool results, task state, conversation titles, and references to relevant workspace items or webpages.
- Preferences and history: non-secret model settings, browser history and bookmarks, start-page settings, per-site browser permissions, layout and appearance settings, and AI data-sharing consent status. These types of settings may be stored in app preferences such as UserDefaults.
- Credentials: AI API keys and secret custom headers, ChatGPT OAuth tokens, MinerU tokens, McDonald’s and Luckin MCP tokens, and configured Git or SSH credentials. Supported secrets are stored in the device Keychain using non-synchronizing, device-only accessibility settings.
- Account metadata: when you sign in with ChatGPT, non-secret metadata such as email address, account identifier, plan type, and login state may be stored in local app preferences.
- Purchase state: product, verified entitlement, expiration, grace-period, and purchase-restoration state received from StoreKit.
Most workspace and generated data is stored in the app container, including Application Support and user-visible workspace locations. ReadOS does not operate its own cloud sync service for this content.
3. When information leaves your device
ReadOS sends information off the device only as needed to perform a network action you request or enable. The destination may receive your IP address, device and network protocol information, authorization credentials for that service, and the content needed for the action.
4. AI services
ReadOS supports ChatGPT OAuth, an OpenAI API key, and custom OpenAI-compatible endpoints and headers. Before the first request to each configured AI provider, ReadOS presents an AI data-sharing disclosure. If you agree, ReadOS may send the following to the provider when relevant to your request:
- your current prompt, selected text, and relevant conversation history;
- attachments you choose, including images, audio, video, PDFs, and other files;
- task-relevant workspace context, including file names, local paths, webpage URLs, reading position, document metadata, and extracted document content;
- webpage DOM content or screenshots when a browser or visual task requires them;
- tool inputs and outputs, including clipboard text or images only when a tool is expressly asked and permitted to read the clipboard;
- the first user message in a conversation in a separate request to the same AI service when ReadOS generates a conversation title;
- image-generation prompts, and both the prompt and input image when you request an image edit.
OAuth or API credentials can allow the provider to associate requests with your provider account. Provider-specific data retention and model training rules apply. Revoking ReadOS’s local AI permission stops future requests until you agree again; it does not delete data already held by the AI provider. Contact the provider directly for its access, deletion, opt-out, or account controls.
5. Websites and browser data
When you open a website, the website and its network providers receive normal web requests and may receive your IP address, user agent, page requests, form entries, uploaded content, and other information you provide. Websites may set cookies, cache entries, and other site data in ReadOS’s persistent WebKit website data store. Each website’s privacy policy applies.
ReadOS stores its own browser history list, bookmarks, and site access permissions locally. Clearing the ReadOS history list clears that list only; it does not clear website cookies, cache, or other WebKit site storage.
For supported video inspection or playback features, ReadOS may read cookies matching the current website and write them to a temporary local file for the bundled media tool to use with that site. The temporary file is removed after the operation completes or fails. The cookies are not sent to a ReadOS-operated server, but the destination website may receive them as part of the requested connection.
Files you download are stored locally in the ReadOS workspace or download location until you delete them.
6. MinerU document processing
MinerU is optional. Only after you save a MinerU token and request MinerU processing does ReadOS send the selected PDF or PDF chunks directly to MinerU. The request may include the file name, document identifier, page range, and processing options such as OCR, formula, table, language, or model settings. ReadOS then polls MinerU for task status and downloads the result for local caching and use.
MinerU may provide a separate upload URL and may associate the request with your token or MinerU account. MinerU’s own privacy, retention, model-training, and deletion terms apply. ReadOS cannot delete a copy already retained by MinerU on your behalf.
7. McDonald’s and Luckin MCP services
The official McDonald’s and Luckin MCP integrations are off by default and are intended for supported regions. They connect only after you enable a service and add its authorization token. ReadOS then connects directly to the merchant endpoint.
Depending on the merchant operation you request, data may include:
- store, menu, product, customization, offer, coupon, and cart queries;
- pickup or delivery information, order previews, order creation, payment initiation, order status, cancellation, and order history;
- for McDonald’s address operations, recipient name, telephone number, city, street address, and unit or house number that you or the merchant account supplies;
- for Luckin operations, order location coordinates and merchant responses that may contain store, courier, or telephone information.
The merchant may associate this information with your token, merchant account, payment method, or order. Merchant and payment-provider terms apply. ReadOS does not receive complete payment-card details and does not operate the merchant ordering backend.
8. Other services you configure
ReadOS can connect to user-configured AI endpoints, Git remotes, SSH servers, webpages, and other services used by tools. When you invoke such a connection, the remote host receives the commands, files, repository data, credentials, request headers, or other information needed for the operation. You are responsible for selecting a trusted host and for understanding its terms and privacy practices.
9. Apple purchases and device permissions
Apple processes ReadOS Pro purchases, renewals, restorations, refunds, and subscription management. ReadOS receives verified transaction and entitlement information from StoreKit but does not receive your full payment-card number and does not upload StoreKit receipts to a developer-operated payment backend in the current app.
ReadOS requests add-only Photos access when you choose to save an exported image to the photo library. File and photo pickers provide only content you explicitly select. The current app does not use the camera or microphone to capture new content. Speech recognition for selected audio or video is performed locally with the bundled WhisperKit runtime.
10. Retention, deletion, and backups
- Local workspace content, conversations, downloads, browser history, bookmarks, and settings remain until you delete them using available app controls, remove the app, or iOS removes the data.
- ReadOS provides controls for ChatGPT sign-out, AI permission revocation, credential or token deletion for supported integrations, workspace deletion, and browser-history clearing.
- Uninstalling ReadOS is not a guarantee that every Keychain item is deleted. Under Apple platform behavior, Keychain entries may survive app removal. If you want to remove supported credentials, use the relevant sign-out or delete-authorization control before uninstalling when possible.
- Clearing browsing history does not clear cookies, cache, or website storage. Those are maintained separately by WebKit.
- Local app-container data may be included in Apple device or iCloud backups depending on your system settings, Apple’s backup rules, and file attributes. Some runtime artifacts are excluded from backup, but you should not assume that all ReadOS workspace data is excluded.
- Deleting local content, revoking authorization, signing out, or uninstalling ReadOS does not delete information already held by an AI provider, website, MinerU, merchant, remote host, Apple, or another third party. Use that provider’s controls or contact it directly.
11. Security and third-party responsibility
ReadOS uses platform protections such as the app sandbox and Keychain for supported secrets. No storage or transmission method is completely secure. Protect your device passcode and third-party credentials, keep iPadOS updated, and avoid sending highly sensitive information to a provider unless you understand and accept its practices.
Third-party services are independently operated. ReadOS does not control their availability, security, retention, training, account policies, or responses to privacy requests.
12. Your choices and requests
You can choose not to configure or use any optional network service.
- Manage or delete local workspace and conversation content in ReadOS.
- Revoke AI data-sharing permission from ReadOS settings.
- Sign out of ChatGPT or delete supported integration tokens.
- Disable McDonald’s or Luckin MCP services, which are off by default.
- Clear the local ReadOS browser history list separately from website data.
- Contact the relevant third party for information it holds, deletion, correction, training opt-out, or account controls.
Because ReadOS does not operate a content account or content backend, we generally cannot view or remotely delete data stored only on your device or data held by a third party. You may email us with privacy questions or requests concerning ReadOS itself.
13. Changes and contact
We may update this policy when ReadOS features or legal requirements change. The effective date at the top identifies the current version. If a material change affects the in-app AI disclosure, ReadOS may ask for AI data-sharing permission again.
ReadOS 隐私政策
1. 适用范围与提供者
本隐私政策适用于 ReadOS iPad App,并说明当前版本的数据处理方式。ReadOS 由 Xiufang Wang 提供(本政策中称为“ReadOS”或“我们”)。
ReadOS 不要求注册由开发者运营的 ReadOS 账户。部分可选功能会使用 Apple、 ChatGPT/OpenAI、MinerU、商家、网站、Git 或 SSH 主机,以及你选择的其他服务所 提供的账户或凭据。这些服务会根据其自身条款和隐私政策处理信息。
当前 App 代码中没有开发者运营的广告、跨 App 跟踪、分析、崩溃报告上传, 也没有接收工作区内容或中转第三方请求的内容后端。本说明不涵盖 Apple 通过 App Store 或 TestFlight 独立进行的处理、承载这些法律页面的托管服务,或你主动 使用的第三方服务。
2. 保存在设备上的信息
根据你使用的功能,ReadOS 可能在本地保存:
- 工作区内容:导入或创建的文档、文件夹、笔记、PDF、图片、 音视频、Office 文件、生成图片、下载内容、提取内容、转写文本、文档解析结果及 相关元数据。
- Readex 内容:对话、提示词、回复、附件、工具结果、任务状态、 对话标题,以及对相关工作区项目或网页的引用。
- 偏好与历史:非敏感模型配置、浏览历史与书签、起始页设置、 各网站浏览权限、布局和外观设置,以及 AI 数据共享授权状态。这些设置可能保存在 UserDefaults 等 App 偏好存储中。
- 凭据:AI API Key 和自定义请求头中的秘密、ChatGPT OAuth Token、 MinerU Token、麦当劳和瑞幸 MCP Token,以及你配置的 Git 或 SSH 凭据。 支持的秘密会使用不同步、仅限本设备访问级别保存在系统钥匙串中。
- 账户元数据:使用 ChatGPT 登录后,邮箱、账户标识、套餐类型和 登录状态等非敏感元数据可能保存在本地 App 偏好中。
- 购买状态:从 StoreKit 获得的商品、已验证权益、到期时间、 宽限期和恢复购买状态。
大部分工作区与生成数据位于 App 容器中,包括 Application Support 和用户可见的 工作区位置。ReadOS 不为这些内容运营自建云同步服务。
3. 信息何时离开设备
只有为了执行你主动请求或启用的网络操作,ReadOS 才会把信息发送到设备之外。 接收方可能获得你的 IP 地址、设备与网络协议信息、该服务所需的授权凭据,以及完成 操作所需的内容。
4. AI 服务
ReadOS 支持 ChatGPT OAuth、OpenAI API Key,以及自定义 OpenAI-compatible 接口 和请求头。首次向每个已配置的 AI 服务发送请求前,ReadOS 会展示 AI 数据共享说明。 你同意后,ReadOS 可能根据任务需要向该服务发送:
- 当前问题、选中的文本和相关对话历史;
- 你选择添加的附件,包括图片、音频、视频、PDF 和其他文件;
- 与任务相关的工作区上下文,包括文件名、本地路径、网页 URL、阅读位置、文档元数据 和提取出的文档内容;
- 浏览器或视觉任务所需的网页 DOM 内容或截图;
- 工具输入与输出;只有当工具被明确要求并获得许可读取剪贴板时,所读取的文本或图片 才可能进入工具结果;
- 为了生成对话标题,首条用户消息可能通过单独请求发送给同一 AI 服务;
- 图片生成提示词;编辑图片时会发送提示词与输入图片。
OAuth 或 API 凭据可能使服务商把请求与你在该服务商处的账户关联。服务商自身的数据 保留和模型训练规则适用。撤回 ReadOS 中的 AI 授权只会阻止后续请求,直到你再次同意; 它不会删除 AI 服务商已经持有的数据。如需访问、删除、退出训练或管理服务商账户, 请直接使用该服务商的控制入口或联系服务商。
5. 网站与浏览器数据
打开网站时,网站及其网络服务商会收到正常网页请求,并可能获得你的 IP 地址、 User-Agent、页面请求、表单内容、上传内容及你提供的其他信息。网站可以在 ReadOS 使用的持久 WebKit 网站数据存储中写入 Cookie、缓存和其他站点数据。各网站自身的 隐私政策适用。
ReadOS 会在本地保存自己的浏览历史列表、书签和站点访问权限。 清除 ReadOS 浏览历史只会清空该历史列表,不会清除网站 Cookie、缓存或其他 WebKit 站点存储。
对于支持的视频检查或播放功能,ReadOS 可能读取与当前网站匹配的 Cookie,并将其写入 临时本地文件,供 App 内置媒体工具连接该网站时使用。操作完成或失败后会删除该临时 文件。Cookie 不会发送到 ReadOS 运营的服务器,但目标网站可能会在你请求的连接中收到 这些 Cookie。
你下载的文件会保存在本地 ReadOS 工作区或下载位置,直至你将其删除。
6. MinerU 文档处理
MinerU 为可选功能。只有当你保存 MinerU Token 并主动请求 MinerU 处理时,ReadOS 才会把选定 PDF 或 PDF 分片直接发送给 MinerU。请求可能包含文件名、文档标识、页码 范围,以及 OCR、公式、表格、语言或模型等处理设置。随后 ReadOS 会轮询 MinerU 任务 状态,并下载结果在本地缓存和使用。
MinerU 可能返回单独的上传地址,并可能把请求与你的 Token 或 MinerU 账户关联。 MinerU 自身的隐私、保留、模型训练和删除条款适用。ReadOS 无法代你删除 MinerU 已经保留的副本。
7. 麦当劳与瑞幸 MCP 服务
麦当劳与瑞幸官方 MCP 集成默认关闭,并仅面向支持的地区。只有当你打开服务并添加 授权 Token 后,ReadOS 才会直接连接商家的接口。
根据你请求的商家操作,发送的数据可能包括:
- 门店、菜单、商品、定制项、优惠、优惠券和购物车查询;
- 自取或配送信息、订单预览、创建订单、发起支付、订单状态、取消和订单历史;
- 麦当劳地址相关操作中,由你或商家账户提供的收件人姓名、电话、城市、街道地址和 门牌号;
- 瑞幸相关操作中的订单位置坐标,以及商家返回的门店、配送员或电话等订单信息。
商家可能把这些信息与你的 Token、商家账户、支付方式或订单关联。商家和支付服务商的 条款适用。ReadOS 不接收完整银行卡信息,也不运营商家的点餐后端。
8. 你配置的其他服务
ReadOS 可以连接你配置的 AI 接口、Git 远程仓库、SSH 服务器、网页以及工具使用的其他 服务。当你调用这些连接时,远程主机将收到完成操作所需的命令、文件、仓库数据、凭据、 请求头或其他信息。你有责任选择可信主机,并了解其条款和隐私做法。
9. Apple 购买与设备权限
Apple 负责处理 ReadOS Pro 的购买、续订、恢复、退款和订阅管理。ReadOS 从 StoreKit 接收已验证的交易与权益信息,但不会收到你的完整银行卡号;当前 App 也不会把 StoreKit 收据上传到开发者运营的支付后端。
当你选择把导出图片保存到照片图库时,ReadOS 会请求仅添加照片的权限。文件和照片选择器 只会提供你明确选中的内容。当前 App 不使用相机或麦克风采集新内容。对已选音视频进行的 语音识别由 App 内置 WhisperKit 在本地完成。
10. 保留、删除与备份
- 本地工作区内容、对话、下载、浏览历史、书签和设置会保留,直至你通过 App 提供的入口 删除、移除 App,或 iOS 清除相关数据。
- ReadOS 提供 ChatGPT 登出、撤回 AI 授权、删除受支持集成的凭据或 Token、删除工作区 内容,以及清除浏览历史等控制。
- 卸载 ReadOS 并不能保证所有钥匙串项目都会被删除。根据 Apple 平台行为, 钥匙串条目可能在 App 被移除后继续保留。如需删除受支持的凭据,请尽可能在卸载前使用 相应的登出或删除授权功能。
- 清除浏览历史不会清除 Cookie、缓存或网站存储。这些数据由 WebKit 单独维护。
- 本地 App 容器数据是否进入 Apple 设备备份或 iCloud 备份,取决于你的系统设置、 Apple 的备份规则和文件属性。部分运行时资源被排除在备份外,但不应假定所有 ReadOS 工作区数据都不会被备份。
- 删除本地内容、撤回授权、登出或卸载 ReadOS,不会删除 AI 服务商、网站、MinerU、 商家、远程主机、Apple 或其他第三方已经持有的信息。请使用第三方提供的控制入口或 直接联系该第三方。
11. 安全与第三方责任
ReadOS 使用 App 沙盒、系统钥匙串等平台保护机制保存受支持的秘密,但任何存储或传输 方式都无法保证绝对安全。请保护设备密码和第三方凭据、及时更新 iPadOS,并在向服务商 发送高度敏感信息前确认你理解并接受其处理方式。
第三方服务由其独立运营。ReadOS 无法控制其可用性、安全性、数据保留、模型训练、账户 规则或对隐私请求的处理。
12. 你的选择与请求
你可以选择不配置或不使用任何可选网络服务。
- 在 ReadOS 中管理或删除本地工作区和对话内容;
- 在 ReadOS 设置中撤回 AI 数据共享授权;
- 退出 ChatGPT,或删除受支持集成的 Token;
- 关闭默认处于关闭状态的麦当劳或瑞幸 MCP 服务;
- 单独清除 ReadOS 本地浏览历史列表;网站数据不会随之清除;
- 就第三方持有的信息、删除、更正、退出训练或账户控制,直接联系相应第三方。
由于 ReadOS 不运营内容账户或内容后端,我们通常无法查看或远程删除只存在于你设备上 的数据,也无法删除第三方持有的数据。你可以通过邮件咨询与 ReadOS 本身有关的隐私问题 或请求。
13. 变更与联系
ReadOS 功能或法律要求发生变化时,我们可能更新本政策。页面顶部的生效日期标识当前 版本。如果重大变化影响 App 内 AI 数据共享说明,ReadOS 可能会重新请求你的 AI 数据 共享授权。