隐私工具箱隐私政策

支持邮箱:support@tjmlai.com

本政策说明“隐私工具箱”(Privacy Toolbox,桌面名称“工具箱”)在你使用应用管理、工具外层、笔记、记账、自动化和购买功能时如何处理信息。

1. App 不向开发者上传业务数据

当前版本无需开发者账号,不含广告、行为分析或追踪 SDK,没有开发者云同步服务。我们不会通过 App 将你的所选 App、秘密口令、笔记、账目、隐私组或使用行为上传到开发者服务器。

系统授权、生物识别和购买由 Apple 服务处理。“不上传给开发者”不表示所有 Apple 系统服务都不联网。

2. 设备上的存储

App 在设备上保存隐私组、系统选择令牌、保护规则、语言与工具外层偏好。秘密口令和笔记使用仅限本设备、解锁时可访问的 Keychain 存储;账目使用受 iOS 文件保护的本地文件。

为了让系统后台扩展执行你的规则,主 App 与 Device Activity Monitor 扩展通过本机 App Group 共享所选令牌、组标识、时间窗、临时恢复期限、保护状态和已验证权益的截止时间,不共享笔记或秘密口令。自动化文件允许在设备重启后首次解锁后供后台使用。

账目与自动化配置文件设置了排除系统备份。App 不提供云同步,但部分系统偏好仍可能随设备备份保留;我们不承诺所有本地数据都不会被系统备份。

3. 屏幕时间和身份验证

App 通过 Family Controls 请求设备所有者的个人授权,由你通过 Apple 系统选择器逐个选择 App,再通过 ManagedSettings 应用隐藏、访问限制或恢复规则。DeviceActivity 用于你设置的时间安排。App 不请求完整安装列表,不把所选令牌用于广告、画像或上传。你可以在 iOS 系统设置中撤销授权。

身份验证使用 Apple LocalAuthentication。App 接收认证结果,不读取或保存人脸、指纹等生物特征模板。秘密数字口令用于计算器入口,不能替代生物识别或解锁其他 App。

4. 外层可见性和保护边界

记事本和记账本外层显示对应的真实内容,不是独立的假数据空间。进入隐私控制台需要验证,不代表每条笔记或账目都单独上锁。选择外层前,请考虑他人可能看到的内容。

系统 Shield 不等于在每个目标 App 内加入 Face ID。可管理范围和后台执行受 iOS 限制;本工具不能抹去系统记录,也不能保证对知道设备密码或能修改系统设置的人隐藏信息。任何技术都不能保证绝对安全。

5. 购买和订阅

购买通过 Apple App Store 和 StoreKit 处理。App 读取验证后的交易权益来判断可用功能,开发者不接收银行卡号等支付凭证。Apple 对其交易及账户数据的处理适用 Apple 隐私政策。订阅管理见 Apple Account 的“订阅”设置。

6. 保留、删除与撤销

你可删除单条笔记,或进入控制台的“设置”页面,选择“清除全部本地数据”并再次验证身份。该操作先停止自动化、恢复所管理 App,再清空笔记和账目、删除秘密口令、隐私组与选择令牌,并重置语言和外层。成功后可能保留空数据容器和默认空组;不是对设备存储进行不可恢复的取证擦除。

清除操作可能因系统授权或存储错误失败,并可能已完成部分步骤。看到失败提示时请检查状态并重试,必要时联系支持,不要假定已经全部删除。它不会取消 Apple 订阅、自动撤销系统授权,也不会重置所有非敏感偏好或桌面图标。

卸载前建议先恢复全部 App、清除需要删除的数据,再在系统设置中撤销屏幕时间权限。卸载会删除 App 沙盒中的内容,但 iOS 可能保留 Keychain 项;仅卸载不能保证笔记和口令全部清除。我们无法远程读取或代你删除设备中的本地内容。

7. 支持邮件和网页访问

如果你主动联系支持,我们及邮件服务提供方会处理你的联系信息、问题描述和你自愿提供的附件,用于回复与解决问题。请勿发送秘密口令、Apple Account 密码、银行卡信息或不必要的私密内容。

8. 儿童和政策变更

本 App 面向设备所有者的个人管理,不是专为儿童制作的产品,也不建立儿童账户或提供远程家长管理。若功能、服务商或数据处理方式变化,我们会更新本政策和生效日期,并按需要在 App 内作出提示。

9. 联系我们

有关隐私、支持邮件的访问/更正/删除或其他请求,请联系 support@tjmlai.com。我们会在适用法律要求的范围内处理;本机内容请使用 App 内删除功能。

Privacy Toolbox Privacy Policy


Email: support@tjmlai.com

This policy explains information handling in Privacy Toolbox (Home Screen name: 工具箱), including app-access management, tool facades, notes, ledger, automation and purchases.

1. No app business data uploaded to the developer

The current app requires no developer account, includes no advertising, behavioral analytics or tracking SDK, and has no developer cloud-sync service. The app does not upload selected apps, codes, notes, ledger entries, groups or usage behavior to a developer server.

Apple handles system authorization, biometrics and purchases. No developer upload does not mean that Apple system services never connect to the internet.

2. On-device storage

Groups, selection tokens, rules, language and facade preferences are stored locally. Codes and notes use this-device-only Keychain storage accessible while unlocked. Ledger entries use an iOS-protected local file.

The app and its Device Activity Monitor extension share local rule configuration through an App Group: selected tokens, group identifier, schedules, temporary-restore deadline, protection status and the verified entitlement expiry. Notes and codes are not shared with the extension. Automation files remain available for background use after the first device unlock following a restart.

Ledger and automation configuration files are marked as excluded from backup. The app does not provide cloud sync, but some system preferences may be included in device backups. We do not claim that every local setting is excluded from all system backups.

3. Screen Time and authentication

The app requests individual authorization through Family Controls. You select individual apps in Apple's picker. ManagedSettings applies hiding, access restrictions or restoration; DeviceActivity handles your schedules. The app does not request a complete installed-app list or use selected tokens for advertising, profiling or developer upload. Revoke authorization in iOS Settings.

Apple LocalAuthentication provides authentication results. The app does not read or store face or fingerprint templates. Your numeric code is an entry mechanism for the calculator facade, not a replacement for biometrics or a code that unlocks other apps.

4. Facade visibility and limits

Notes and ledger facades display their corresponding real content. They are not separate decoy stores. Console authentication does not individually lock each note or entry. Consider who can see the facade before selecting it.

The system Shield is not a Face ID login inside each selected app. Supported apps and background actions depend on iOS. This app does not erase system records or guarantee protection from someone with the device passcode or system-settings access. No technology can guarantee absolute security.

5. Purchases

Apple App Store and StoreKit process purchases. The app checks verified transaction entitlements; the developer does not receive payment-card credentials. Apple's account and transaction handling is governed by the Apple Privacy Policy. Manage subscriptions in your Apple Account subscription settings.

6. Retention, deletion and revocation

Delete individual notes or open the console's Settings, choose Clear All Local Data and authenticate again. Clearing first stops automation and restores managed apps, then clears notes and ledger entries, deletes the code, groups and selection tokens, and resets language and facade. Empty containers and a default empty group may remain. This is not a forensic secure-erasure feature.

System or storage errors can interrupt clearing after some steps have completed. If an error appears, check the state and retry or contact support; do not assume all data has been removed. Clearing does not cancel Apple subscriptions, revoke system authorization, or reset every non-sensitive preference or Home Screen icon.

Before uninstalling, restore all apps, clear the data you want removed, and revoke Screen Time authorization in iOS Settings. Uninstalling removes the app sandbox, but iOS may retain Keychain items. Uninstalling alone does not guarantee removal of all notes or codes. We cannot remotely read or delete your local app content.

7. Support messages and website visits

If you contact support, we and our email provider process your contact details, question and voluntary attachments to respond and resolve the issue. Do not send codes, Apple Account passwords, card details or unnecessary private content.

8. Children and changes

The app is intended for the device owner's personal management, is not specifically designed for children, and does not create child accounts or provide remote parental management. We update this policy and its effective date when features, providers or practices change, with in-app notice where appropriate.

9. Contact

For privacy questions or requests about support correspondence, contact support@tjmlai.com. We handle requests as required by applicable law. Use the app's deletion controls for on-device content.