生效日期:2026 年 9 月 1 日 · Effective September 1, 2026
一句话:CanPhone 没有服务器,你的一切数据都只在你的设备上。
In one sentence: CanPhone has no servers. Everything stays on your device.
聊天记录、角色卡、世界书、你的个人设定,全部只保存在你的设备本地。 开发者不会收到这些内容,也没有任何技术途径读取它们。删除 App 即彻底删除全部数据。 生成回复时,你输入的消息与照片、角色设定与世界书、相关会话的上下文与长期记忆、 你的个人资料会有一份副本发送给你自己配置的模型服务商,用于生成那一条回复 —— 见下方「发送前告知与同意」。
Chats, character cards, world books and your profile are stored only on your device. The developer never receives them and has no way to read them. Deleting the app deletes everything. When generating a reply, a copy of your messages and photos, character sheets and lorebooks, relevant chat context and long-term memory, and your profile is sent to the model provider you configured yourself, solely to produce that reply — see "Disclosure & consent" below.
你在设置中填写的第三方模型服务密钥只保存在设备本地, 仅在你发送消息时由你的设备直接发送给你自己选择的模型服务商。 它不经过任何由开发者运营的服务器 —— 因为不存在这样的服务器。
Your API key is stored locally and sent directly from your device to the model provider you chose. It never passes through any developer-operated server — none exists.
App 只会连接你自己配置的接口 —— 聊天、以及(可选的)生图、记忆检索、语音朗读。 没有数据统计、没有崩溃上报、没有广告、没有推送服务、没有更新检查。 图片文字识别(OCR)与你说话的语音转文字都在设备本地完成,不联网。 语音朗读默认用系统自带的声音(本地);只有当你主动填写了第三方语音服务, 要朗读的那段文字才会发给你选的那家。
The app connects only to endpoints you configured yourself — chat, and optionally image generation, memory retrieval and speech. No analytics, no crash reporting, no ads, no push service, no update checks. OCR and speech-to-text of your own voice run entirely on-device. Text-to-speech uses the system voice by default; only if you fill in a third-party speech service does the text to be spoken get sent to the provider you chose.
麦克风:只在你按住「说话」录语音条时使用。录音文件保存在你的设备上, 不会上传到任何地方 —— 包括开发者、也包括你配置的模型服务商。
语音识别:把你说的话转成文字发给角色。这一步调用的是 iOS 的
设备端识别(requiresOnDeviceRecognition),音频不离开这台手机;
你的设备如果不支持离线识别,App 会明确告诉你并退回用键盘输入,绝不改走云端识别。
相册 / 相机:只在你主动选择图片时打开(导入角色卡、换壁纸、换图标、发照片)。 App 不会读取你没有选中的任何照片,也不会上传相册内容。
Microphone is used only while you hold to record a voice note;
the recording stays on your device. Speech recognition runs on-device
(requiresOnDeviceRecognition) — audio never leaves the phone, and if your device
cannot do it offline the app says so and falls back to typing rather than switching to the cloud.
Photos / camera open only when you pick an image yourself; nothing is uploaded.
首次向某家模型服务商发送内容前,App 会弹出确认卡:说明会发送什么、发给哪个域名, 经你明确同意后才发出第一个字。同意按服务商记录(换一家会重新征询,每家只问一次), 并可随时在 App 内「设置 → 隐私与数据」撤回 —— 撤回后不再向任何模型服务商发送内容, 直到你再次同意。
Before anything is sent to a given model provider for the first time, the app presents a consent card stating what will be sent and to which host; nothing leaves the device until you explicitly agree. Consent is recorded per provider (a new provider asks again; each is asked once) and can be withdrawn anytime under Settings > Privacy & data — after withdrawal nothing is sent to any provider until you agree again.
步数、睡眠、经期等健康数据(经 Apple 健康只读授权)、日历日程与「在家/在外」的粗略状态, 默认全部关闭,需要你在「设置 → 隐私数据」里逐项、逐角色打开。打开后, 相关信息会在设备上先总结成一句话,随那一轮对话发给你配置的服务商。语音只在本机转成文字, 录音本身不会离开设备。
Health data (steps, sleep, cycle — read-only via Apple Health), calendar events and a coarse home/away state are all off by default and enabled per item, per character, under Settings > Personal data. When enabled, the information is summarized into one line on device and sent with that round of conversation to the provider you configured. Voice is transcribed on device; recordings never leave the phone.
我们收集的数据:无。本页面(canphone 官网)为静态页面,仅作产品介绍与支持用途, 不设账号、不设 Cookie、不做访问统计。
Data we collect: none. This website is a static page for product information and support only — no accounts, no cookies, no analytics.
当你把消息发送给你配置的模型服务商(任何兼容通用对话接口的服务商或中转)时, 该请求受对方的隐私政策约束。请自行查阅你所选服务商的条款。
When you send messages to your chosen model provider, that request is governed by their privacy policy. Please review the terms of the provider you selected.
CanPhone 不面向 16 岁以下用户。
CanPhone is not directed at users under 16.
政策如有变更会更新本页面。由于 App 无法向你推送任何内容,重大变更只会随 App 更新说明告知。
Changes will be posted here. Since the app cannot push anything to you, material changes will be noted in App Store release notes.