Privacy Policy隐私政策
U.S. & International · Windows美国与国际 · Windows
1. Information we collect
1.1 You provide
- Account: email address, third-party account identifier, and auth tokens used at sign-in.
- Connector authorization: OAuth tokens and connection status when you connect Gmail, Slack, and similar channels.
- Payment: transaction information handled by our payment processor when you buy or subscribe (we do not store full card numbers).
- Feedback you submit: your optional note, a bounded structured diagnostic timeline, and any generated reply, conversation excerpt, transcript, counterpart information, or screenshot that you separately preview and choose to include.
1.2 Processed transiently to draft a reply
- Conversation context: conversation text visible in the current window on your trigger, your instruction, and the local tone/profile memory needed for the reply.
- Screenshots (fallback): an in-memory, cropped image of the current conversation area when Accessibility can't read it (discarded after local OCR).
- Voice: audio while you hold to talk, streamed for cloud speech recognition (see Section 4; the raw recording is not kept by TONEBIRD).
1.3 Collected automatically
Anonymous product metrics: event names, enums, counts, app version, OS version, an anonymous install id, and an optional signed-in user id. Excludes message bodies, drafts, recipient names, screenshots, and raw audio.
2. What stays on your device
TONEBIRD's live read starts locally: Windows accessibility interfaces (UI Automation) read the current window's visible text; screenshots are handled in memory; OCR runs first on-device via a bundled local OCR model. Your tone profile, personal profile, person cards, reply events, learned corrections, and usage counts are stored locally in the app's data folder. You can view them, open the data folder, or clear them any time in Settings. Diagnostic traces also stay on your device unless you actively submit a feedback report; the submission screen shows the exact structured diagnostics and optional content you selected to send.
3. How we use information
- Provide and operate TONEBIRD — read the current conversation on your trigger and draft replies in your voice.
- Authenticate you, meter usage, and enforce quotas.
- Maintain security, prevent abuse and fraud, and debug technical issues.
- Improve the product using anonymous metrics.
- Investigate a problem you deliberately report and track its resolution in our internal issue system.
We do not train foundation models on your conversations, and TONEBIRD's product metrics never include message content. When you use a model (managed or your own key), the model provider processes the content under its own policy.
4. Screenshots, OCR & voice
Screenshots are only for apps accessibility interfaces can't read; TONEBIRD crops to the conversation area, runs OCR on-device first, and discards the image. Only if OCR is insufficient may a vision-capable model receive it for transcription. Raw hold-to-talk audio is not stored by TONEBIRD; on Windows, dictation uses cloud speech recognition — audio is streamed through our relay to the speech provider selected in Settings (Volcengine “Doubao” or Alibaba Cloud), which returns the transcript and processes the audio under its own policy.
5. Service providers we share with
We share only what is necessary, with providers acting as our processors or as independent controllers you direct data to:
| Provider | Purpose | Data involved |
|---|---|---|
| Clerk, Inc. | Sign-in & authentication | Email, login identifier, auth tokens |
| Cloudflare / Vercel | Hosting & the model proxy (stateless forwarding) | Conversation context & instruction (not logged by design) |
| Anthropic, Google (Gemini), OpenRouter, and any provider you choose | Draft / rewrite replies, distill memory, vision transcription | Conversation context & instruction needed for the task |
| Composio, Inc. | Managed connectors (Gmail / Slack / Google Chat) auth, status & read/write | Connector OAuth tokens, message payload you asked to process |
| Volcengine (Doubao) / Alibaba Cloud | Cloud speech recognition for hold-to-talk dictation | Voice audio (not retained by TONEBIRD) |
| Analytics backend | Anonymous product metrics | Event names, enums, counts, versions, anonymous install id |
| Meta Platforms, Inc. | Ad measurement on the tonebird.ai marketing site only (Meta Pixel; never inside the app) | Page views, download clicks, ad click id, cookie identifiers set by Meta |
| Google LLC | Traffic measurement on the tonebird.ai marketing site only (Google Analytics 4; never inside the app) | Page views, referrer, approximate location, device and browser, cookie identifiers set by Google |
| Linear | Internal triage of feedback you actively submit | Issue category, your note, app/system metadata, bounded diagnostic timeline, and a protected report link |
| Supabase | Access-controlled, short-term feedback delivery and private review storage | Your feedback note, bounded structured diagnostics, selected generated reply or conversation/transcript excerpt, counterpart information, and screenshot |
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We may disclose information if required by law or to protect rights and safety.
Google user data (Limited Use). TONEBIRD's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Chat data you authorize (spaces, messages, and memberships) is used only to provide the features you enabled — surfacing conversations awaiting your reply and learning your own writing tone to draft replies for you. We do not sell it, use it for advertising, or transfer it to others except as needed to provide the feature (e.g. the managed connector above), to comply with law, or in a merger. No human reads your Google data except with your consent, for security, to comply with law, or in aggregated or anonymized form.
6. Your choices & controls
- Use your own model key so requests never pass through our servers.
- Turn off learning from your sent messages; opt out of anonymous product metrics.
- Open your local data folder; clear reply history and learned memory in Settings.
- Before sending feedback, review and remove every optional content attachment. Feedback is never submitted automatically.
7. U.S. state privacy rights (incl. California)
Depending on your state (e.g. California/CCPA, and similar laws in Virginia, Colorado, Connecticut, Utah, and others), you may have the right to: know/access the personal information we hold; delete it; correct it; obtain a portable copy; and opt out of sale/sharing or targeted advertising. As noted above, we do not sell or share personal information for cross-context behavioral advertising.
We honor opt-out preference signals such as Global Privacy Control (GPC) where applicable. You will not be discriminated against for exercising your rights. To make a request, contact support@amplift.ai; we may need to verify your identity.
8. International users & transfers
TONEBIRD is operated from the United States, and our providers are largely U.S.-based; using TONEBIRD involves transferring your information to the United States and other countries. Where required (e.g. for EEA/UK users), we rely on appropriate safeguards such as Standard Contractual Clauses. Payment for some regions may be processed by an affiliated entity; where that applies, the payment page will identify the processing entity.
9. Retention & security
Local data stays on your device until you delete it or uninstall. A submitted feedback report may remain in an encrypted local outbox for up to seven days while delivery is retried. The complete live Supabase feedback record, including its copy of your note, bounded structured diagnostics, and any selected private content, becomes inaccessible after 14 days and is scrubbed from live storage within 24 hours; encrypted provider backups may remain recoverable for up to seven additional days. The full delivery row is removed by 30 days. A minimal, long-lived anti-duplicate record retains only the random report ID, account-bound owner, terminal result or error, and any Linear receipt; it contains no note, diagnostics, environment data, or attachment reference and exists only to prevent report-ID takeover and duplicate Linear issues. The safe Linear issue summary is retained for support, security, and product-quality records until it is no longer needed or you request deletion where applicable. Account and connection status are kept while you use TONEBIRD and deleted or anonymized within a reasonable period after account closure, unless the law requires otherwise. We use transport encryption, access controls, encryption at rest, and encrypted token storage (Windows DPAPI). No assistant that must send context to an external AI model can claim 100% local privacy.
10. Children
TONEBIRD is not intended for anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe a child provided us information, contact us and we will delete it.
11. Changes & contact
We may update this policy periodically; material changes will be notified in-app or on the website. This policy is part of, and subject to, the TONEBIRD Terms of Service for Windows (U.S. & International); if they conflict, the Terms control.
Controller: Ampliftai Inc.
Privacy requests: support@amplift.ai · Support: support@amplift.ai
© 2026 Ampliftai Inc. · Last updated July 27, 2026.
1. 我们收集的信息
1.1 你提供的
- 账户:登录时的邮箱、第三方账号标识与鉴权令牌。
- 连接器授权:连接 Gmail、Slack 等渠道时的 OAuth 令牌与连接状态。
- 付款:购买或订阅时由支付服务商处理的交易信息(我们不存储完整卡号)。
- 你主动提交的问题反馈:可选说明、有限的结构化诊断时间线,以及你在提交页分别预览并主动勾选的生成回复、对话片段、转写片段、对方信息或截图。
1.2 为生成回复而临时处理的
- 对话上下文:你触发时当前窗口可见的对话文字、你的指令,以及本地语气与档案记忆。
- 截图(兜底):辅助功能读不到时在内存中裁剪的会话区域图像(本机 OCR 后丢弃)。
- 语音:按住说话的音频(用于云端语音识别,见第 4 节;TONEBIRD 不保存原始录音)。
1.3 自动采集的
匿名产品指标:事件名、枚举、计数、应用与系统版本、匿名安装标识、可选登录标识。不含消息正文、草稿、收件人姓名、截图或原始音频。
2. 哪些留在你的本机
实时读取从本机开始:Windows 辅助功能接口(UI Automation)读当前窗口可见文字;截图在内存中处理;OCR 优先用内置的本地 OCR 模型识别。你的语气档案、个人资料、人物卡、回复事件、学习到的修正与用量计数保存在应用的本地数据文件夹,可随时查看、打开数据文件夹或清空。诊断 trace 也默认只留在本机;只有你主动提交问题反馈时,提交页展示的诊断与所选内容才会离开设备。
3. 我们如何使用信息
- 提供与运行 TONEBIRD——在你触发时读取当前对话并用你的语气起草回复。
- 身份认证、用量计量与额度控制。
- 保障安全、防止滥用与欺诈、排查技术问题。
- 用匿名指标改进产品。
- 调查你主动报告的问题,并在内部 issue 系统中跟踪处理。
我们不会用你的对话训练基础模型,TONEBIRD 的产品指标也从不包含消息内容。当你使用模型(托管或自带 Key)时,模型服务商会按其自身政策处理相关内容。
4. 截图、OCR 与语音
截图仅用于辅助功能读不到的应用;TONEBIRD 裁剪到会话区域、优先本机 OCR 并丢弃图像。仅当 OCR 不足时,视觉模型才可能收到该截图用于转写。按住说话的原始音频不被 TONEBIRD 保存;Windows 上的听写使用云端语音识别——音频经我们的中转发送至你在设置中选择的语音服务商(火山引擎「豆包」或阿里云),由其返回转写文本并按其自身政策处理音频。
5. 我们共享的服务商
我们仅共享必要信息,服务商作为我们的处理者或你主动指向的独立控制者:
| 服务商 | 目的 | 涉及信息 |
|---|---|---|
| Clerk, Inc. | 登录与身份认证 | 邮箱、登录标识、鉴权令牌 |
| Cloudflare / Vercel | 托管与模型代理(无状态转发) | 对话上下文与指令(按设计不记录) |
| Anthropic、Google(Gemini)、OpenRouter 及你选择的服务商 | 生成 / 改写回复、蒸馏记忆、视觉转写 | 完成任务所需的对话上下文与指令 |
| Composio, Inc. | 托管连接器(Gmail / Slack / Google Chat)授权、状态与读写 | 连接器 OAuth 令牌、你请求处理的消息载荷 |
| 火山引擎(豆包)/ 阿里云 | 按住说话的云端语音识别 | 语音音频(TONEBIRD 不留存) |
| 匿名指标后端 | 匿名产品统计 | 事件名、枚举、计数、版本、匿名安装 id |
| Meta Platforms, Inc. | 仅在 tonebird.ai 官网上的广告效果统计(Meta Pixel;绝不进入应用内) | 页面浏览、下载点击、广告点击 id、Meta 设置的 cookie 标识 |
| Google LLC | 仅在 tonebird.ai 官网上的访问量统计(Google Analytics 4;绝不进入应用内) | 页面浏览、来源页、大致地理位置、设备与浏览器、Google 设置的 cookie 标识 |
| Linear | 处理你主动提交的问题反馈 | 问题类别、你的说明、应用/系统元数据、有限诊断时间线与受保护的报告链接 |
| Supabase | 访问受控的短期反馈投递与私有审阅存储 | 反馈说明、有限结构化诊断、所选生成回复或对话/转写片段、对方信息与截图 |
我们不出售你的个人信息,也不为跨情境行为广告而共享。在法律要求或为保护权利与安全时,我们可能披露信息。
Google 用户数据(Limited Use 限制性使用)。TONEBIRD 对通过 Google API 获取并向任何其他应用传输的信息,遵守 Google API 服务用户数据政策,包括其 Limited Use(限制性使用)要求。你授权的 Google Chat 数据(会话空间、消息与成员关系)仅用于你启用的功能——标出等待你回复的会话、并学习你自己的写作语气以为你拟稿。我们不出售该数据、不用于广告,也不向他人传输,除非为实现该功能所必需(如上表的托管连接器)、法律要求、或公司并购。任何人都不会阅读你的 Google 数据,除非经你同意、出于安全、法律要求、或已聚合匿名化。
6. 你的选择与控制
- 使用自己的模型 Key,让请求完全不经我们服务器。
- 关闭从已发消息中学习;退出匿名产品指标。
- 打开本地数据文件夹;在设置中清空回复历史与学到的记忆。
- 提交反馈前逐项预览并移除任何可选内容;TONEBIRD 不会自动提交反馈。
7. 美国各州隐私权利(含加州)
视你所在州(如加州 CCPA,以及弗吉尼亚、科罗拉多、康涅狄格、犹他等州的类似法律),你可能有权:知悉/查阅我们持有的个人信息;删除;更正;获取可携副本;退出「出售/共享」或定向广告。如上所述,我们不出售个人信息,也不为跨情境行为广告而共享。
在适用情形下,我们尊重 Global Privacy Control(GPC)等退出偏好信号。你不会因行使权利而受到歧视性对待。提交请求请联系 support@amplift.ai,我们可能需要核验你的身份。
8. 国际用户与跨境传输
TONEBIRD 由美国运营,服务商多位于美国;使用 TONEBIRD 会将你的信息传输至美国及其他国家。在需要时(如 EEA/UK 用户),我们采用标准合同条款等适当保障措施。部分地区的收款可能由关联实体处理;适用时,付款页面会标明处理实体。
9. 保存期限与安全
本机数据保存在你的设备上,直至你删除或卸载。已提交但尚未送达的反馈可在加密本地 outbox 中保留最多 7 天。完整的 Supabase 在线反馈记录(包括其中的反馈说明副本、有限结构化诊断和你选择的私有内容)在 14 天后停止访问,并在 24 小时内从在线存储清除;加密备份最多可能再恢复 7 天。完整投递行会在 30 天内删除。系统会长期保留一条最小防重复记录,仅含随机 report ID、账户绑定的归属、终态结果或错误及可选 Linear 回执;它不含说明、诊断、环境数据或附件引用,只用于防止 report ID 被接管和重复创建 Linear 问题。Linear 中不含私聊正文的安全摘要会为支持、安全与产品质量记录保留至不再需要,或在适用情况下按你的删除请求处理。账户与连接状态在你使用期间保存,注销后在合理期限内删除或匿名化,法律另有要求的除外。我们采用传输加密、访问控制、静态加密与令牌加密存储(Windows DPAPI)。任何须向外部 AI 模型发送上下文的助手都无法声称 100% 本地隐私。
10. 未成年人
TONEBIRD 不面向未满 18 周岁者,我们不会在明知的情况下收集 13 岁以下儿童的个人信息。若你认为有儿童向我们提供了信息,请联系我们删除。
11. 更新与联系
我们可能不时更新本政策,重大变更将在应用内或官网通知。本政策是《TONEBIRD Windows 版用户协议(美国与国际)》的一部分并受其约束;如有冲突,以用户协议为准。
控制者:Ampliftai Inc.
隐私请求:support@amplift.ai · 支持:support@amplift.ai
© 2026 Ampliftai Inc. · 本政策最后更新于 2026 年 7 月 27 日。