隐私政策 / Privacy Policy

应用 / App: Grader
生效日期 / Effective date: 2026-07-03 · 更新日期 / Updated: 2026-08-24
开发者 / Developer: 蔡东鹏 (Cai Dongpeng)
联系方式 / Contact: andy.cai.work@gmail.com


中文

一句话总结

本 App 默认把你的课程、成绩、任务等数据保存在你自己的设备上。首次启动时你需要阅读并点击同意本政策后才能使用。首次使用时,App 会随机生成一个安装 USER ID并登记到 Supabase,用于连接本设备与服务器;它不是硬件序列号,也不包含姓名或邮箱。你可以另行登录 Apple / 邮箱账号开启账号云同步与 AI 功能,或开启 iCloud 同步。

1. 我们收集哪些数据

默认情况下,你创建的课程信息、成绩与任务(含导入的评分规则原文)及个人设置保存在本地。

任何用户首次使用 App 时,App 会随机生成安装 UUID 和设备密钥。UUID 会上传作为服务器 USER ID;设备密钥原文仅保存在本机 Keychain,服务器只保存 SHA-256 哈希。它们不包含姓名、邮箱或硬件序列号。Supabase 可能保留请求所需的网络与安全日志;登录后,敏感连接信息改存到正式账号 USER ID 名下。

当你登录账号时,会额外涉及:

不含任何广告或第三方分析 SDK,不做用户行为追踪。

2. 数据存储在哪里

3. 网络请求

App 内不含广告网络、不做用户行为追踪。除上述情况外,不上传任何数据——其中「自动服务器身份」「自动化失败诊断」「WAM 算法反馈」可能在你未登录时自动发生。

4. 系统权限

你可随时在「设置 → 隐私与安全性」中撤销上述权限。

5. 数据共享

我们不会出售、出租你的数据,也不会用于广告或追踪。涉及的第三方仅有:Supabase(云数据库/存储/边缘函数托管)、Apple(Sign in with Apple 与 iCloud),以及仅当你使用 AI 功能时Groq / Google Gemini(处理学业数据,不含姓名或账号身份)。

即使你不登录、也不使用 AI,仍有少量数据会离开设备:公开大纲抓取、首次使用时的设备身份登记,以及自动化失败诊断与 WAM 算法反馈(均见第 3 节)。

6. 数据删除

7. 儿童隐私

本 App 面向高校学生,不针对 13 岁以下儿童,也不会有意收集儿童信息。

8. 政策变更

如本政策有重大变更,我们会在 App 或本页面更新生效日期。

9. 联系我们

有任何隐私相关问题,请联系:andy.cai.work@gmail.com


English

In one sentence

By default, your courses, grades, and tasks stay on your device. On first launch you must read and tap to agree to this policy before using the app. On first use, the app generates a random installation user ID and registers it with Supabase. It is not a hardware serial number and contains no name or email.

1. Data we collect

By default, the course info, grades & tasks (including imported grading-rule text), and preferences you create stay on your device.

For every user on first use, the app generates a random installation UUID and device secret. The UUID is uploaded as the server user ID. The plaintext secret stays in Keychain; the server stores only its SHA-256 hash. Neither contains a name, email, or hardware serial number.

When you sign in, the following applies:

There are no ads, no third-party analytics SDKs, and no behavioral tracking.

2. Where data is stored

3. Network requests

No ad networks, no tracking. Beyond the cases above nothing is uploaded — and automatic server identity, automation failure diagnostics, and WAM algorithm feedback can occur while you are signed out.

4. System permissions

Calendar (write your due dates, read back your edits) · Reminders (mirror due dates if enabled) · Notifications (local only) · Photos (only when picking an avatar or attaching a file) · Camera (only when you scan an MFA setup QR code; the frames themselves are processed on-device and never stored or uploaded, and codes are generated entirely on-device — but the resulting MFA secret is stored in the local Keychain and, if you are signed in to a permanent account and Credential cloud backup is on, is also synced to the cloud in plaintext as described above). Revocable anytime in Settings → Privacy & Security.

5. Data sharing

We do not sell or rent your data, and never use it for ads or tracking. Third parties: Supabase (cloud database/storage/edge functions), Apple (Sign in with Apple, iCloud), and — only when you use AI featuresGroq / Google Gemini (academic data only, no name or account identity).

Even if you never sign in and never use AI, a small amount of data still leaves your device: public outline fetches, the first-use device identity registration, and automation failure diagnostics plus WAM algorithm feedback (all described in §3).

6. Data deletion

7. Children's privacy

Intended for university students; not directed at children under 13.

8. Changes

Material changes update the effective date here and in the app.

9. Contact

andy.cai.work@gmail.com