Skip to content

AIY 隐私政策 / Privacy Policy

生效日期:2026 年 8 月 15 日
Effective date: August 15, 2026

开发者 / Developer:Gantrol
联系邮箱 / Contact:[email protected]

本政策适用于 AIY 桌面应用。访问本页面时,网站本身对访问日志、分析数据和 Cookie 的处理另见 AI能做.XYZ 隐私政策

This policy applies to the AIY desktop application. When you visit this page, the website's separate handling of access logs, analytics, and cookies is described in the AI Can Do website privacy policy.

中文

1. 概述

AIY 是一款用于整理 AI 辅助创作工作的本地优先桌面应用。AIY 不要求注册 AIY 账号。空间元数据、受管媒体、提示词、生成记录、词典、笔记和设置默认保存在用户设备上。

AIY 0.3.2 不提供由开发者运营的云同步、广告或产品分析数据收集服务。只有在用户启用并使用相应功能时,AIY 才会连接用户选择的第三方模型服务或本地运行环境。

2. 本地保存的数据

根据用户使用的功能,AIY 可能在设备上保存:

  • 本地空间数据库、空间注册信息和应用设置;
  • 提示词、模型设置、生成历史、用量记录和错误诊断;
  • 图片、视频、音频分块、字幕、笔记、文章、缩略图及相关元数据;
  • 导入的内容包、词典、配方、标签、图集和来源关系;
  • 经操作系统安全存储能力加密的服务凭据,以及不含秘密的连接设置;
  • 用户主动导出的空间归档。

这些数据会保留在设备上,直到用户编辑或删除内容、移除相应本地空间、清除凭据,或卸载应用。Windows 自身的数据保留行为可能影响卸载后的数据状态。导出的归档是独立副本,需要单独删除。

3. 发送给第三方服务的数据

AIY 支持由用户选择并配置的模型服务与集成。当用户主动发起 AI 请求时,AIY 仅向所选服务发送完成该请求所需的信息,可能包括:

  • 提示词、指令、模型与生成参数;
  • 为该请求选择的图片、蒙版、视频、音频、字幕片段或其他参考素材;
  • 服务商完成请求所需的技术元数据;
  • 已配置服务商的身份验证凭据。

接收方会依据其自身条款、隐私政策、安全措施、地区可用性和计费规则处理与保留这些信息。随着扩展被添加、移除、启用或停用,可用集成可能变化。发送个人、机密或受许可限制的内容前,用户应先阅读所配置服务的政策。

仅仅配置服务商不会让 AIY 上传整个本地空间。除用户主动执行的连接测试和服务能力发现外,只有在用户调用相应功能时才会发起网络请求。

4. 本地集成

部分功能使用同一设备上的软件,例如已登录的 Codex 运行环境、本地命令行工具、FFmpeg,或可选的基于 WSL 的语音识别服务。完全由本地运行环境处理的数据不会通过 AIY 离开设备。本地工具自身可能具有网络行为或账号配置,其处理方式由该工具的服务商与设置决定。

当用户要求 AIY 发现或导入本地 Codex 生成图片时,AIY 只会为该导入流程读取用户选择或配置的本地记录与媒体。

5. 凭据与安全

AIY 保存的服务商 API 凭据会在可用时使用操作系统安全存储能力保护。AIY 不会在应用安装包或生成历史载荷中附带服务商凭据。

任何存储或传输方式都无法保证绝对安全。用户应妥善保护自己的 Windows 账号、本地空间目录、导出归档、服务商账号与 API 凭据。请勿在公开 Issue 中提交凭据、个人数据或私有空间内容。

6. 导入、导出与迁移

导出的 AIY 空间归档可能包含空间数据库、提示词、媒体、历史、笔记,以及其他由用户创建或导入的内容。请将归档视为私密数据,仅通过合适的安全渠道分享给预期接收者。

导入归档或旧版空间时,AIY 会复制并校验用户选择的数据,不会自动删除原始来源。

7. 生成式 AI 输出与内容举报

AI 生成内容可能不准确、不符合预期或不适当。用户应在使用、发布或分发前检查输出。

如需举报不适当的 AI 生成内容,请发送邮件至 [email protected],并在主题中注明“AIY 内容举报”。首次联系时请说明使用的功能、服务商、发生时间和问题类型;除非调查确有必要,请勿附加 API 凭据、完整空间归档或未经脱敏的个人数据。

开发者仅在调查举报及履行法律或平台义务所合理需要的期限内保留来信。第三方模型服务对请求和输出的保留期限由其自身政策决定。

8. 未成年人

AIY 是通用创作工具,不面向所在地区低于数字同意年龄的儿童。未成年人使用第三方 AI 服务时,应由家长或监护人监督,并遵守相应服务商的年龄要求。

9. 用户选择

用户可以:

  • 不配置远程 AI 服务,仅使用本地整理、浏览、导入和导出功能;
  • 自行选择要配置的服务商或本地运行环境;
  • 在应用中清除已保存的服务商凭据;
  • 删除由自己控制的内容或本地空间;
  • 在迁移或删除本地空间前先导出归档。

有关本政策或个人信息处理的请求,可以发送至上述联系邮箱。首次联系时请勿发送凭据或未经脱敏的私有空间归档。

10. 政策变更

如果 AIY 新增服务商、云功能、诊断、账号功能或其他数据处理行为,本政策可能更新。重大变更会通过更新生效日期和本页面予以体现。

English

1. Overview

AIY is a local-first desktop application for organizing AI-assisted creative work. AIY does not require an AIY account. Workspace metadata, managed media, prompts, generation records, dictionaries, notes, and settings are stored on the user's device by default.

AIY 0.3.2 does not provide a developer-operated cloud-sync, advertising, or product-analytics collection service. AIY connects to third-party model services or local runtimes only when the user enables and uses the corresponding feature.

2. Data stored locally

Depending on the features used, AIY may store the following data on the user's device:

  • local-space databases, registries, and application settings;
  • prompts, model settings, generation history, usage records, and error diagnostics;
  • images, videos, audio chunks, transcripts, notes, articles, thumbnails, and related metadata;
  • imported content packs, dictionaries, recipes, tags, albums, and source relationships;
  • provider credentials protected with operating-system secure storage and non-secret connection settings; and
  • archives explicitly exported by the user.

This data remains on the device until the user edits or deletes it, removes the corresponding local space, clears credentials, or uninstalls the application. Windows data-retention behavior may affect what remains after uninstall. Exported archives are independent copies and must be deleted separately.

3. Data sent to third-party services

AIY supports model services and integrations selected and configured by the user. When the user initiates an AI request, AIY sends only the information needed for that request to the selected service. This may include:

  • prompts, instructions, model and generation parameters;
  • images, masks, videos, audio, transcript excerpts, or other reference material selected for the request;
  • technical request metadata required by the provider; and
  • authentication credentials for the configured provider.

The receiving service processes and retains that information under its own terms, privacy policy, security practices, regional availability, and billing rules. Available integrations can change as extensions are added, removed, enabled, or disabled. Users should review the policy of each configured service before sending personal, confidential, or licensed content.

AIY does not upload an entire local space merely because a provider is configured. A network request is made only for a feature the user invokes, except for user-initiated connection checks and provider capability discovery.

4. Local integrations

Some features use software running on the same device, such as an authenticated Codex runtime, local command-line tools, FFmpeg, or an optional WSL-based speech-recognition service. Data processed entirely by a local runtime does not leave the device through AIY. A local tool may have its own network behavior or account configuration, governed by that tool's provider and settings.

When the user asks AIY to discover or import local Codex-generated images, AIY reads the selected or configured local records and media only for that import workflow.

5. Credentials and security

Provider API credentials saved by AIY are protected using the operating system's secure-storage facilities when available. AIY does not include provider credentials in the application package or generation-history payloads.

No storage or transmission method is completely secure. Users are responsible for protecting their Windows account, local-space folders, exported archives, provider accounts, and API credentials. Do not include credentials, personal data, or private workspace contents in public issues.

6. Import, export, and migration

An exported AIY space archive may contain workspace databases, prompts, media, histories, notes, and other user-created or imported content. Treat an export as private data. Share it only with intended recipients through an appropriate secure channel.

When an archive or legacy space is imported, AIY copies and validates data selected by the user. The original source is not deleted automatically.

7. Generative AI output and content reports

AI-generated content may be inaccurate, unexpected, or inappropriate. Users should review output before using, publishing, or distributing it.

To report inappropriate AI-generated content, email [email protected] with “AIY Content Report” in the subject. In the initial message, identify the feature, provider, approximate time, and type of issue. Do not attach API credentials, a complete workspace archive, or unredacted personal data unless it is genuinely required for the investigation.

The developer retains a report only as long as reasonably necessary to investigate it and meet legal or platform obligations. Retention of requests and outputs by a third-party model service is governed by that service's own policy.

8. Children

AIY is a general-purpose creative tool and is not directed to children under the minimum digital-consent age that applies in their region. A parent or guardian should supervise a minor's use of third-party AI services and review the provider's age requirements.

9. User choices

Users can:

  • use local organization, browsing, import, and export features without configuring a remote AI provider;
  • choose which provider or local runtime to configure;
  • clear stored provider credentials in the application;
  • delete content or local spaces under their control; and
  • export a local space before moving or deleting it.

Requests concerning this policy or personal-information processing can be sent to the contact address above. Do not send credentials or unredacted private workspace archives in an initial message.

10. Changes

This policy may be updated when AIY adds providers, cloud features, diagnostics, account functionality, or other data practices. Material changes will be reflected by updating the effective date and this page.