AI Link 隐私政策
生效日期:2026 年 10 月 4 日
简要说明:AI Link 是由用户配置第三方模型与语音 API 的客户端。应用不要求注册 AI Link 账号,也不设自有聊天中转服务器。你发起请求时,必要数据会直接送至你配置的服务商。
1. 适用范围与联系
本政策说明 AI Link Android / iPhone 手机应用、Wear OS / Apple Watch 配套应用和本官方网站的数据处理。各平台公开下载与可用状态以官网发布信息为准。隐私相关问题可联系 mateolim93@gmail.com。
2. 设备上保存的数据
- 服务配置与密钥:手机将服务名称、协议、API 地址、模型 ID 等非密钥配置保存在本地 SQLite;API Key 单独保存在系统安全存储中。手机将你选择的服务配置与密钥经系统配对通道同步给手表;Wear OS 使用 Android Keystore 加密保存密钥,Apple Watch 使用 Keychain 保存密钥。
- 聊天和偏好:话题标题、消息正文、提示词、模型列表缓存和应用设置保存在手机本地 SQLite。消息正文和提示词在数据库中没有单独加密。
- 手表问答:手表可将问答先保存在应用私有存储中;重新连接后同步进手机本地聊天记录。清空手机数据不会自动删除手表上的离线问答或已同步的密钥。
- 语音文件:录音和合成音频作为请求与播放所需的临时文件使用,使用后删除。转写文本按录音松手动作直接发送或等待编辑确认;发送后会成为本地聊天记录的一部分。
- 配置导入:你通过表单、JSON 或二维码填写的服务配置会按以上方式保存;完整 JSON 文本及二维码原文不会另存。包含密钥的二维码应仅在可信场景中展示和扫描。
3. 发送给第三方服务的数据
当你获取模型列表、发送聊天内容、转写语音或合成朗读音频时,手机或手表会向你配置的 API 服务商直接发送完成请求所需的 API Key、模型 ID、对话上下文、提示词、录音或朗读文字。Wear OS 优先通过配对手机处理请求,手机不可达或出现明确网络故障时尝试手表自身网络。Apple Watch 优先直接请求,手表网络明确不可用且手机可达时尝试配对 iPhone;网络路由由 watchOS 管理。超时状态不明、服务配置错误或已有部分回答时,不自动换路重发。AI Link 不通过自有服务器中转这些请求。
第三方服务商会依照其自身政策和合同处理及保存所收到的数据,可能收取费用。请只使用你信任的 API 地址,并在发送敏感内容前阅读该服务商的隐私政策。删除设备上的数据无法撤回已发送给第三方的内容。
4. 设备权限
麦克风用于你主动按住录音的语音输入;相机用于你主动扫描服务配置或 API Key 二维码;网络访问用于连接你配置的服务、配对设备通信与同步。你可以拒绝或在系统设置中撤回相机、麦克风权限;文字聊天仍可使用。配对与同步还会使用 Android/Wear OS 的 Data Layer 或 Apple 平台的 WatchConnectivity。
5. 保存、删除与安全
本地数据保留到你删除相应话题或服务、使用“设置 → 模型设置 → 数据与隐私”清空手机数据,或卸载应用。清空手机数据会删除手机上的聊天、配置、密钥和提示词;手表数据需单独清除:Apple Watch 可在手表设置中确认「清除手表配置和问答」,删除密钥、配置及本地问答,或卸载手表应用;Wear OS 可卸载手表应用清除其本地数据。第三方服务商已收到的数据应向相应服务商申请删除。
密钥使用设备安全存储,Wear OS 密钥由 Android Keystore 加密,Apple Watch 密钥保存在 Keychain;手机数据库中的聊天正文与提示词未单独加密。请使用设备锁屏并谨慎选择第三方服务地址。
6. 应用使用统计
Android 与 iOS 正式手机版使用 Google Firebase Analytics 自动记录应用使用事件(例如首次打开、会话和使用时长)、应用实例标识及设备与应用信息。统计数据发送至 Google,用于了解应用使用情况。Android 禁用广告 ID 收集,iOS 使用不含广告 ID 支持的 Analytics 库;默认关闭广告个性化信号。调试、Profile 和测试手机版停用统计,手表应用暂未接入。
应用不主动把聊天正文、提示词、API Key、录音、合成音频或模型服务地址作为统计事件上传,也没有自定义聊天内容埋点。清空本地聊天数据不会撤回已经上报的使用统计;相关隐私问题可通过本政策的联系邮箱提出。Google 对统计数据的处理见 Google 隐私政策。
7. 儿童与政策更新
AI Link 面向一般用户,并非专为儿童设计。若功能、权限或数据处理方式发生实质变化,我们会更新本页面及生效日期,并在适当情况下通过应用更新说明提示。
8. 官方网站
本页面与 AI Link 官网不要求登录。官网将页面访问、Android / Wear OS 下载点击和隐私政策点击的事件类型发送到本站接口,汇总总次数和每日次数;此统计不设置统计 Cookie,也不发送用户标识或 App 内数据。网站托管及网络服务提供方仍可能为页面传输、安全和故障排查处理 IP 地址、浏览器信息与访问日志;点击邮件链接会由你的邮件服务处理联系内容。网站不会读取应用内的聊天、密钥或录音。
AI Link Privacy Policy
Effective date: October 4, 2026
In short: AI Link is a client for third-party text and speech APIs that you configure. It requires no AI Link account and operates no chat relay server. When you make a request, the necessary data goes directly to your selected provider.
1. Scope and contact
This policy describes data handling in the AI Link Android and iPhone apps, their Wear OS and Apple Watch companions, and this website. Public availability for each platform is listed on the product page. For privacy questions, email mateolim93@gmail.com.
2. Data stored on your devices
- Provider settings and keys: Provider names, protocols, API URLs and model IDs are stored in SQLite on the phone. API keys are stored separately in the system secure storage. Selected settings and keys are sent over the system pairing channel. Wear OS encrypts keys with Android Keystore; Apple Watch stores them in Keychain.
- Chats and preferences: Conversation titles, messages, prompts, cached model lists and settings are stored in the phone's local SQLite database. Message text and prompts are not separately encrypted in that database.
- Watch conversations: The watch can keep questions and answers in its app-private storage, then sync them into the phone's local history after reconnecting. Clearing phone data does not automatically erase offline watch conversations or keys already sent to the watch.
- Voice files: Recordings and synthesized audio are temporary files used for requests and playback, then deleted. Transcribed text is sent directly or after editing and confirmation, depending on your recording release gesture, and becomes part of local chat history.
- Configuration imports: Settings entered by form, JSON or QR code are saved as described above; the complete JSON text and raw QR contents are not stored separately. Display or scan QR codes containing keys only in trusted settings.
3. Data sent to third-party providers
When you fetch a model list, send a chat message, transcribe speech or synthesize audio, the phone or watch directly sends the required API key, model ID, conversation context, prompts, recording or speech text to the API provider you configured. Wear OS uses the paired phone first, then the watch network when the phone is unreachable or has a confirmed network failure. Apple Watch makes requests first and may use the paired iPhone when the watch network is confirmed unavailable and the phone is reachable; watchOS manages network routing. Requests are not automatically resent on an uncertain timeout, provider configuration error, or after a partial response. AI Link does not relay these requests through its own server.
Each provider handles and retains received data under its own policies and agreements and may charge fees. Use only API endpoints you trust, and read the provider's privacy policy before sharing sensitive content. Deleting on-device data does not retract information already sent to a provider.
4. Device permissions
Microphone access supports voice recording you start by holding the button. Camera access supports scanning provider settings or API key QR codes. Network access supports your configured services and communication and sync between paired devices. You can deny or revoke camera and microphone access in system settings; text chat remains available. Pairing and sync use Android/Wear OS Data Layer or Apple WatchConnectivity.
5. Retention, deletion and security
Local data remains until you delete a conversation or provider, clear phone data under Settings → Model settings → Data and privacy, or uninstall the app. Clearing phone data removes chats, settings, keys and prompts from the phone. Watch data must be cleared separately. On Apple Watch, confirm “Clear watch settings and chats” in watch settings to remove keys, configuration and local conversations, or uninstall the watch app. On Wear OS, uninstall the watch app to remove its local data. Contact the relevant provider about data it has already received.
Keys use device secure storage, Wear OS keys are encrypted with Android Keystore, and Apple Watch keys are stored in Keychain. Phone database messages and prompts are not separately encrypted. Use a device lock and choose third-party API endpoints carefully.
6. App usage analytics
Production Android and iOS phone builds use Google Firebase Analytics to automatically record app usage events (such as first open, sessions and engagement), app instance identifiers, and device and app information. Analytics data is sent to Google to understand app usage. Android disables Advertising ID collection; iOS uses Analytics without advertising ID support. Advertising personalization signals are disabled by default. Debug, Profile and test phone builds disable Analytics; watch apps are not integrated.
The app does not intentionally upload chats, prompts, API keys, recordings, synthesized audio or provider URLs as Analytics events, and has no custom chat-content events. Clearing local chat data does not retract previously reported usage analytics. Contact the email above for privacy questions. Google's handling of analytics data is described in the Google Privacy Policy.
7. Children and policy changes
AI Link is intended for a general audience and is not designed specifically for children. If features, permissions or data practices materially change, we will update this page and its effective date, and provide release notes where appropriate.
8. Official website
The AI Link website and this page require no account. The product page sends only event types for page views, Android/Wear OS download clicks and privacy-policy clicks to this site to aggregate total and daily counts. This tracking sets no analytics cookies and sends no user identifiers or in-app data. Hosting and network providers may process IP addresses, browser information and access logs for delivery, security and troubleshooting. If you use the email link, your email service processes that message. The website cannot read chats, keys or recordings inside the app.