DoneIt 隐私权政策

最后更新日期:2026年9月7日

生效日期:2026年9月7日

适用产品:DoneIt Web / 桌面客户端 / iOS App / Android App(以下统称「本应用」或「DoneIt」)

运营主体:DoneIt 团队(以下简称「我们」)

官方网站:https://doit.chufeng.me

联系邮箱:luckychufeng@gmail.com

DoneIt Privacy Policy

Last Updated: September 7, 2026

Effective Date: September 7, 2026

Applies to: DoneIt Web, Desktop, iOS, and Android apps (collectively, the “App” or “DoneIt”)

Operator: DoneIt Team (“we”, “us”, or “our”)

Website: https://doit.chufeng.me

Email: luckychufeng@gmail.com

重要提示:请您在使用 DoneIt 前仔细阅读并充分理解本隐私权政策。当您注册、登录或继续使用本应用,即表示您已阅读并同意我们按照本政策处理您的相关信息。若您不同意,请立即停止使用并卸载本应用。涉及敏感个人信息(如语音、图像、通讯内容、证件材料等)的处理,我们将在具体功能场景中另行征得您的同意,或仅在您主动使用相关功能时处理。

1. 我们是谁与本政策适用范围

DoneIt 是一款面向个人与团队的生产力与协作应用,提供包括但不限于:任务与清单管理、项目与版本协作、团队/公司组织、即时通讯(文字/图片/文件/语音消息、语音通话)、办公空间、智能笔记与 AI 助手、语言学习、通知提醒等功能。

本政策说明我们如何收集、使用、存储、共享与保护您的个人信息,以及您依法享有的权利。本政策适用于您通过网页、桌面端、iOS、Android 或其他我们提供的客户端访问 DoneIt 的全部场景。

本政策不适用于第三方独立运营的网站、产品或服务。若您通过本应用跳转到第三方,请另行阅读其隐私政策。

2. 我们收集的信息

我们遵循「最小必要」原则,仅在实现产品功能、保障安全与遵守法律所必需的范围内收集信息。根据您使用的功能不同,收集的信息可能包括:

2.1 账户与身份信息

  • 注册/登录信息:用户名、密码(经哈希/加密存储,我们无法获知明文密码)、登录凭证(Access Token / Refresh Token)、设备标识(用于持久登录与多端会话管理)。
  • 个人资料:昵称、头像、DoneIt 号/用户 ID、安全码(如您设置)、工作状态/在线状态等您主动填写或选择的信息。
  • 公司/组织申请材料(如您使用):公司名称及您提交的证照或证明材料。该等信息可能属于敏感个人信息,仅在您主动申请相关功能时收集。

2.2 您主动创建或上传的业务内容(用户内容)

  • 任务与协作:个人清单、团队任务、标题/描述/状态/优先级/截止日期、验收记录、备注、指派关系、项目与版本信息、流程图相关数据等。
  • 笔记与便签:标题、正文(含富文本)、标签、颜色、置顶状态、您插入的图片等。
  • 团队与公司:团队名称、成员关系、角色权限、公告、邀请记录等。
  • 即时通讯内容:私聊/群聊消息(文本、表情、图片、文件、语音)、已读回执、置顶、收藏、转发、@提醒、通话记录与通话纪要(如您使用相关功能)等。
  • 附件与媒体:您主动上传的文件名、类型、大小、上传时间及文件内容。

说明:用户内容由您或您所在团队创建。我们作为服务提供者处理这些数据,用于向您提供同步、协作、搜索与备份等功能。请勿在本应用中上传与业务无关的敏感证件、支付密码或其他您无意分享的信息。

2.3 通讯与互动数据

  • 语音消息与语音通话:在您授权麦克风并主动录音/发起或接听通话时,我们会处理音频流或音频文件,以实现发送、播放、通话连接;在您主动选择「转文字」或生成通话纪要时,才会进行语音识别与文本处理。
  • AI 对话与生成内容:当您使用智能小助手、版本日志生成、语言学习、通话纪要等 AI 功能时,我们会将您提交的提示词、相关上下文或转写文本发送至 AI 服务以生成回复(详见第 6 节)。
  • 通知与推送:任务提醒、协作通知、即时消息提醒等;在移动端可能包含推送令牌(APNs / FCM Token)。

2.4 设备、网络与诊断信息

  • 设备信息:设备型号、操作系统及版本、应用版本、语言与时区、浏览器类型(Web)、客户端类型(Web/桌面/iOS/Android)。
  • 网络与日志:IP 地址、请求时间、接口调用记录、崩溃/错误日志(用于排查故障与保障安全)。
  • 本地存储:登录状态、主题与界面偏好、草稿、缓存等存储于设备本地的数据。

2.5 我们不会主动收集的信息

  • 精确地理位置(GPS)用于广告或画像;
  • 通讯录/通讯录好友(除非未来功能明确征得同意并更新本政策);
  • 用于跨应用广告追踪的广告标识符(如 IDFA)及与广告网络共享的追踪数据;
  • 与您无关的相册内容(仅在您主动选择图片/拍照时访问所选内容)。

2.6 信息收集方式

  • 您直接提供:注册、填写资料、创建内容、上传文件、使用麦克风/相机等。
  • 使用过程中自动采集:日志、设备信息、推送令牌、安全风控所需的技术信息。
  • 他人提供:例如团队成员将任务指派给您、在群聊中提及您、向您发送消息或文件。

3. 我们如何使用信息

使用目的 典型涉及信息 说明
提供核心功能 账户、用户内容、通讯内容 任务/项目/笔记/团队协作、即时通讯、多端同步等
身份认证与会话管理 登录凭证、设备标识 登录、持久会话、退出登录、密码重置、异常登录防护
消息与提醒 通知设置、推送令牌、消息元数据 任务提醒、协作通知、IM 推送;您可在系统或应用内关闭
语音与通话 麦克风音频、通话信令 仅在您主动使用语音消息/语音通话时处理
AI 能力 您提交的文本/上下文、转写文本 助手回复、纪要整理、学习/创作类生成;按需调用第三方模型
安全与合规 日志、设备与网络信息 防欺诈、防滥用、排查故障、履行法定义务
产品改进 去标识或汇总后的使用情况 优化体验与稳定性;不以出售个人信息为目的
客户支持 您反馈的内容及相关账户信息 响应咨询、投诉与数据主体请求

4. 合法处理基础

根据适用法律(包括但不限于《中华人民共和国个人信息保护法》等),我们处理个人信息的基础通常包括:

  • 征得同意:例如开启麦克风/相机/相册/通知,或使用 AI、语音转文字等可选功能;
  • 履行合同 / 提供服务所必需:注册登录、同步您的任务与消息、团队协作等;
  • 合法利益(在适用法域):如保障服务安全、防止滥用(并兼顾您的权利与合理期待);
  • 法律义务:响应有权机关依法提出的要求,或留存特定日志。

5. 设备权限说明(含 iOS)

为提供完整功能,本应用可能请求下列系统权限。您可在设备系统设置中随时关闭;关闭后对应功能可能不可用,但不影响其他基础功能。

权限 使用场景 不授权的影响
麦克风 发送语音消息、发起/接听语音通话 无法使用语音消息与语音通话
相机 拍摄头像或笔记图片、扫描电脑登录二维码等 无法拍照上传或扫码登录
相册 / 照片 选择头像、笔记或聊天图片;保存图片到相册 无法从相册选取或保存图片
通知 任务提醒、协作与即时消息推送 无法收到系统推送(应用内通知可能仍可用)
网络 与服务器同步数据、收发消息、AI 请求 无法正常使用在线功能
后台音频(如适用) 语音通话过程中维持音频会话 切到后台时通话可能中断

我们不会在未向您告知并取得必要同意的情况下,将上述权限用于与功能无关的目的(例如广告追踪)。

6. 第三方服务与 SDK

为提供稳定服务,我们可能接入下列第三方或等效服务。它们仅在实现相应功能所需范围内处理相关数据,并受其自身隐私政策约束。我们要求服务提供方采取合理的保密与安全措施。

服务 用途 可能涉及的数据
Apple Push Notification service(APNs) iOS 远程推送 设备推送令牌、通知载荷(任务/消息提醒等)
Firebase Cloud Messaging(FCM) 移动端推送通道(视平台配置) 推送令牌、设备/应用标识、通知相关元数据
MiniMax(大模型 / TTS 等) 智能助手回复、文本生成(如版本日志、通话纪要整理)、语言学习语音合成等 您主动提交的提示与必要上下文;生成结果
语音识别(ASR,如 SenseVoice 等自建或托管推理服务) 语音消息「转文字」、通话内容转写(经您触发) 相应音频及转写文本
云服务器与对象存储 / CDN(基础设施) 托管应用、数据库、上传文件分发 账户与业务数据、日志、上传文件

关于 AI:请勿向 AI 功能提交您无意对外处理的高度敏感信息(如他人隐私、机密商业数据、支付凭证等)。AI 输出可能不准确,重要决策请您自行核实。我们不会将您的个人数据出售给广告商。

7. 信息共享、转让与公开披露

7.1 我们不会出售您的个人信息

我们不会出售、出租或以广告投放为目的向第三方提供您的个人信息。

7.2 协作场景下的可见性

  • 加入团队/公司或参与群聊后,您的昵称、头像、DoneIt 号及您发布的内容可能对授权范围内的其他成员可见;
  • 任务指派、验收、评论、已读状态等会按产品规则在相关协作方之间共享;
  • 请您审慎判断在共享空间中发布的内容。

7.3 服务提供商

我们可能委托基础设施、推送、AI、语音识别等服务商处理数据,仅限于提供服务所必需,并要求其不得将数据用于未经授权的目的。

7.4 法律与安全

在法律法规、司法或行政机关依法要求,或为保护 DoneIt、用户或公众的重大合法权益所必要的情况下,我们可能披露相关信息。

7.5 业务变更

如发生合并、分立、收购、破产等,个人信息有可能作为资产转移;我们会要求继受方继续受本政策约束,或重新征得您的授权同意。

8. 跨境传输

我们主要在中华人民共和国境内存储和处理器用户数据。若因使用境外云服务、AI 模型接口、全球推送通道等确需向境外提供个人信息,我们将依法履行评估、合同、告知与(如法律要求)单独同意等义务,并采取加密与访问控制等保护措施。

若您从中国境外访问本服务,您理解您的信息可能会被传输至并存储于中国境内的服务器。

9. 存储地点、期限与安全措施

9.1 存储地点

业务数据主要存储于我们运营的服务器及相关云基础设施,服务入口为 https://doit.chufeng.me

9.2 保存期限

  • 在您的账户存续期间,为实现服务目的持续保存必要信息;
  • 您删除的具体内容,将在系统中尽快删除或匿名化,备份中可能短期残留后清除;
  • 账户注销后,我们将在合理期限(通常为 30 日,法律法规另有规定或存在未决争议的除外)内删除或匿名化您的个人数据;
  • 安全日志、交易/审计类记录可能依法保留更长时间。

9.3 安全措施

  • 传输层加密(HTTPS / WSS 等);
  • 密码哈希存储与令牌鉴权;
  • 最小权限访问控制与服务器安全加固;
  • 备份与故障恢复机制;
  • 定期排查与漏洞修复。

请理解:任何系统都无法保证绝对安全。请您妥善保管账户与设备,不向他人透露验证码或密码,在公共设备使用后及时退出登录。

10. 您的权利

在适用法律允许的范围内,您可以:

  • 查阅、复制:在应用内查看个人资料与您创建的内容;
  • 更正、补充:修改昵称、头像等资料;
  • 删除:删除任务、笔记、消息等您有权删除的内容;
  • 撤回同意:在系统设置中关闭麦克风、相机、相册、通知等权限,或停止使用可选功能;
  • 约束自动化决策 / 获取解释(如适用):就对您有重大影响的自动化处理提出请求;
  • 注销账户:见第 11 节;
  • 导出数据:可通过联系我们申请导出您的个人数据(在技术可行与法律允许范围内)。

为保障安全,我们可能需要验证您的身份后再处理请求。我们将在法定期限内答复;情况复杂的可依法延长并告知理由。

11. 账户注销与数据删除

您可以在应用设置相关入口申请注销账户,或通过本政策载明的联系方式提交注销请求。注销后:

  • 您将无法使用该账户登录;
  • 我们将按第 9.2 节删除或匿名化与您相关的个人信息;
  • 您在团队/群聊中已产生的、对其他用户仍有意义的内容(例如您发送的消息、由他人继续引用的任务记录),可能在去标识或保留必要协作记录的前提下继续存在;
  • 法律法规要求保留或与未结争议相关的信息,将在必要期限内继续保存。

12. Cookie / 本地存储 / 追踪

  • Web / 桌面端可能使用 Cookie、localStorage 或同类技术保存登录态、主题偏好、草稿与缓存;
  • 移动端使用系统提供的本地存储与钥匙串/安全存储保存令牌与设置;
  • 上述技术不用于跨应用广告追踪,我们也不会出售追踪数据;
  • 若未来引入需 ATT(App Tracking Transparency)授权的追踪,我们将另行弹窗说明并征得同意。

13. 儿童隐私

本应用面向一般用户与职场协作场景,不面向 13 周岁以下(或您所在司法辖区规定的更高年龄)的儿童。我们不会故意收集儿童的个人信息。若您发现儿童向我们提供了个人信息,请立即联系我们,我们将尽快删除。

若您为监护人,请妥善管理未成年人设备上对本应用的使用。

14. Apple App Store / App Privacy 说明

为便于您对照 App Store「App 隐私」标签,我们声明(可能随功能更新调整,以 App Store Connect 填写及本政策最新版为准):

  • 用于应用功能的数据:联系信息(如账户标识)、用户内容(消息、照片/视频、音频、其他用户内容)、标识符(用户 ID、设备 ID)、诊断数据等;
  • 可能与用户关联:上述多数数据与您的账户关联,以便提供同步与协作;
  • 用于追踪:我们当前不将数据用于跨公司追踪广告
  • 第三方用于其目的:推送、AI、ASR 等第三方仅在您使用相关功能时按第 6 节处理必要数据。

App Store 产品页上的隐私标签是概要;本文件为完整说明。二者不一致时,以本政策及实际产品行为为准,我们也会持续校准标签披露。

15. 政策更新

我们可能适时修订本政策。更新后将在本页面发布并更新「最后更新日期」。若变更导致处理目的、方式或范围发生重大变化,我们将通过应用内通知、弹窗或其他显著方式告知,并在法律要求时重新征得同意。

16. 联系我们

如对本政策或个人信息处理有疑问、投诉、建议,或要行使法定权利,请通过以下方式联系我们:

联系邮箱:luckychufeng@gmail.com

官方网站:https://doit.chufeng.me

应用内:设置 → 关于我们 / 反馈入口

完整政策 URL(可提交至 App Store Connect):
https://doit.chufeng.me/privacy-policy.html (若您的部署路径不同,请确保该公开 URL 可长期访问)

响应时限:我们将在核实身份后,于适用法律规定的期限内(一般不超过 15 个工作日,复杂情况依法延长)予以答复。

17. 适用法律与争议解决

本政策的订立、效力、解释与争议解决,适用中华人民共和国法律(不含冲突规范)。争议应首先友好协商;协商不成的,任一方可向我们运营主体所在地有管辖权的人民法院提起诉讼。

如本政策中英文版本存在不一致,以中文版本为准(英文仅供便利阅读)。

Important: Please read this Privacy Policy carefully before using DoneIt. By registering, signing in, or continuing to use the App, you acknowledge that you have read and agree to our processing of information as described here. If you do not agree, please stop using and uninstall the App. Processing of sensitive information (such as voice, images, message content, or identity documents) occurs only when you enable or actively use the relevant features, and/or with additional consent where required.

1. Who we are & scope

DoneIt is a productivity and collaboration app offering task and list management, project/version collaboration, team/company organization, instant messaging (text/images/files/voice messages and voice calls), office space features, smart notes and AI assistance, language learning, notifications, and related services.

This Policy explains how we collect, use, store, share, and protect personal information, and the rights you may have. It applies to access via web, desktop, iOS, Android, and other clients we provide.

It does not cover third-party websites or services you may open from the App.

2. Information we collect

We follow data minimization and collect only what is needed to provide the service, keep it secure, and comply with law.

2.1 Account & identity

  • Username, password (hashed/encrypted; we cannot see your plaintext password), access/refresh tokens, and device identifiers for session persistence;
  • Profile data you provide (nickname, avatar, DoneIt ID, security code if set, work/presence status);
  • Company application materials you voluntarily submit (e.g., company name and supporting documents).

2.2 User content

  • Tasks, lists, notes, stickies, projects/versions, team/company data, diagrams, and related collaboration records;
  • IM content (text, emoji, images, files, voice), read receipts, pins, favorites, mentions, call records/summaries when used;
  • Files you upload (name, type, size, timestamps, and content).

2.3 Communications & AI

  • Microphone audio when you record voice messages or place/receive voice calls;
  • Speech-to-text / call transcripts only when you explicitly request transcription or summary features;
  • Prompts and necessary context you submit to AI features (assistant, release notes, learning TTS, summaries, etc.);
  • Push tokens (APNs/FCM) for notifications.

2.4 Device, network & diagnostics

  • Device model, OS/app version, language/timezone, client type;
  • IP address, request logs, crash/error diagnostics;
  • Local preferences, drafts, and caches stored on your device.

2.5 What we do not collect by default

  • Precise GPS for advertising/profiling;
  • Address book contacts (unless a future feature obtains consent and this Policy is updated);
  • Advertising identifiers (e.g., IDFA) for cross-app ad tracking;
  • Your entire photo library (we only access items you choose).

3. How we use information

  • Provide core product features and multi-device sync;
  • Authenticate users and manage sessions/security;
  • Deliver in-app and push notifications you enable;
  • Enable voice messaging/calls and optional ASR/AI features you trigger;
  • Prevent abuse, debug issues, and meet legal obligations;
  • Improve reliability and UX using aggregated or de-identified insights where appropriate;
  • Respond to support and privacy requests.

4. Legal bases

Depending on applicable law (including China’s PIPL and, where relevant, GDPR-like regimes), we rely on consent, performance of a contract/service necessity, legitimate interests (e.g., security), and legal obligations.

5. Device permissions (including iOS)

Permission Purpose
MicrophoneVoice messages and voice calls
CameraAvatar/note photos; scan QR for desktop login
Photo LibraryChoose/save images for avatar, notes, or chat
NotificationsTask, collaboration, and IM alerts
NetworkSync, messaging, AI requests
Background audio (if applicable)Maintain audio during calls

You may revoke permissions in system settings. We do not use these permissions for unrelated advertising tracking.

6. Third-party services & SDKs

  • Apple APNs — iOS push delivery (push token & notification payload);
  • Firebase Cloud Messaging (FCM) — mobile push where configured;
  • MiniMax — AI text generation / TTS for features you use;
  • ASR (e.g., SenseVoice-based pipeline) — speech-to-text when you request it;
  • Hosting / storage / CDN providers — infrastructure for the service.

Third parties process data only as needed for these functions and under their own policies and our contractual controls. We do not sell personal information to advertisers.

7. Sharing, transfer & disclosure

We do not sell your personal information. We may share information:

  • With teammates/group members as required for collaboration features you join;
  • With processors (hosting, push, AI, ASR) under confidentiality and purpose limits;
  • When required by law or to protect vital rights and security;
  • In connection with a merger, acquisition, or similar corporate transaction, subject to continued protections or fresh consent where required.

8. International transfers

Primary storage and processing are in the People’s Republic of China. If data is transferred abroad (e.g., certain AI or push infrastructure), we will take measures required by applicable law (contracts, security controls, and consent where mandated). If you access DoneIt from outside China, your data may be transferred to and stored on servers in China.

9. Storage, retention & security

Data is hosted in connection with https://doit.chufeng.me. We retain data while your account is active and as needed to provide the service; after account deletion we generally delete or anonymize personal data within about 30 days, except where law or unresolved disputes require longer retention. We use HTTPS/WSS, hashed passwords, token auth, access controls, backups, and ongoing hardening. No method of transmission or storage is 100% secure.

10. Your rights

Subject to applicable law, you may access, correct, delete, withdraw consent (e.g., revoke OS permissions), request export, and delete your account. We may verify your identity before fulfilling requests and will respond within statutory timelines.

11. Account deletion

You may request account deletion via in-app settings (where available) or by contacting us. After deletion, login will be disabled and personal data will be deleted or anonymized per Section 9, except collaboration records that must remain meaningful for other users (possibly de-identified) or data we must retain by law.

12. Cookies, local storage & tracking

We use cookies/local storage (web/desktop) and on-device secure storage (mobile) for login state, preferences, drafts, and cache. We do not use this for cross-app advertising tracking. If we introduce tracking that requires Apple’s App Tracking Transparency prompt, we will disclose it and request permission.

13. Children’s privacy

The App is not directed to children under 13 (or a higher age required in your jurisdiction). We do not knowingly collect children’s data. Contact us to request deletion if you believe a child has provided information.

14. Apple App Store / App Privacy

For App Store privacy labels, data collected for app functionality may include contact info (account identifiers), user content (messages, photos, audio, other content), identifiers (user/device IDs), and diagnostics, often linked to your account. We currently do not use data for cross-company tracking ads. Third parties (push/AI/ASR) receive data only as described in Section 6 when you use those features. The App Store label is a summary; this Policy is the full disclosure.

15. Changes to this policy

We may update this Policy by posting a revised version with a new “Last Updated” date. Material changes will be communicated via in-app notice or other prominent means, and we will obtain consent again when legally required.

16. Contact us

Email: luckychufeng@gmail.com

Website: https://doit.chufeng.me

In-app: Settings → About / feedback

Public policy URL for App Store Connect:
https://doit.chufeng.me/privacy-policy.html

We will respond within applicable legal timelines after identity verification.

17. Governing law

This Policy is governed by the laws of the People’s Republic of China (excluding conflict-of-law rules). Disputes should first be resolved amicably; otherwise, courts with jurisdiction over our place of operation may hear the matter.

If there is any conflict between the Chinese and English versions, the Chinese version prevails.