一、适用范围与运营者
本政策说明 Ormo 在提供 App、网站及相关服务时如何收集、使用、保存、共享和保护个人信息,以及你如何访问、更正、删除、导出、撤回授权或注销账号。Ormo 由个人开发者运营,法定身份以 App Store 产品页展示的开发者信息及中国区 APP 备案主体为准。隐私、账号或投诉事项可通过 support@ormo.app 联系。
二、我们处理的信息
1. 账号与资料
手机号或登录标识、在用户主动绑定 Apple 登录后由 Apple 提供或隐藏的邮箱、验证码状态、账号ID、昵称、头像、性别、生日、个人简介、兴趣标签、登录状态和账号安全信息。Apple 登录不用于创建独立账号。
2. 公开或互动内容
你主动提交的心情文字、内容回应、画作、答案、聊天、反馈、举报和相关互动记录,以及内容审核和违规处理所需记录。
3. 情侣空间内容与可能的敏感信息
绑定关系和邀请码状态、双方生日、纪念日和重要日、每日心情、愿望、计划、共同习惯和打卡、主题问答及关系趋势、结构化和好记录与共同约定、双人小游戏答案、每周仪式回答、想念互动、互动卡片、时光信、双人故事进度与选择、虚拟小屋的户型、装修、房间、家具、植物与浇水记录、水族箱生物与照料记录、共同宠物种类、昵称与照料记录、菜谱及故事数值、成长记录,以及共同照片、照片评论、地点标签、语音回忆、说明和对应时间信息。你自愿参与的私密情侣问答可能涉及关系、性取向、亲密偏好、宗教或其他敏感观点;这些回答仅用于你选择的情侣互动,不用于广告画像。旅行功能还会处理你主动填写的旅行名称、目的地、日期、票务或订单信息、路线时间节点、地点坐标、备注,以及你从相册主动选择的旅行照片和票据截图;在你选择旅行照片后,系统会读取其中可用的拍摄时间和位置元数据,用于按时间和地点匹配行程节点并展示路线。需要双方共同揭晓的答案在双方都提交前不向对方展示。
4. 活动、目的地与位置
仅在你主动开始通勤、运动或其他活动并授权后处理定位点、活动类型、时间、里程和路线。选择“仅自己”或“只分享统计”时,精确轨迹不会上传到服务器,本地临时轨迹会在结束或取消后删除;选择“分享完整路线”时,活动期间路线会近实时向绑定伴侣展示。你主动开启“到达后自动报平安”时,我们还会在本次活动中处理你填写的目的地名称和经系统解析的坐标,以判断是否进入提示范围;到达通知只发送一次,目的地坐标在活动结束时清除。结束或取消后停止定位和实时更新。
5. 设备、通知与日志
设备型号、操作系统、App版本、IP地址、访问时间、错误与安全日志、推送设备令牌、通知摘要、目标页面和已读状态,用于稳定性、安全、通知和故障处理。你使用好友推荐码注册时,App 会在安全存储中生成一个随机、App 范围的匿名安装标识,并仅将其哈希值保存到当前数据服务区,用于防止同一安装重复领取好友邀请奖励。该标识不用于广告追踪、跨 App 识别或跨区域传输。
6. 官网首页访问统计
当你访问官网首页时,我们设置一个一年期、HttpOnly、同站限制的匿名 Cookie,用于区分当天是否为同一访客,并统计首页打开次数(PV)和当日匿名访客数(UV)。Cookie 中的随机标识保留在浏览器内,服务端只保存加密哈希后的按日标识;本项统计不用于广告追踪、跨站识别或用户画像,也不把完整 IP 写入访问统计记录。基础设施可能仍按安全与故障排查需要处理必要的网络日志。
三、系统权限
- 相册:在你选择头像、图片、共同回忆、旅行美照或票据截图时使用;对你主动选择的旅行照片,会读取其中可用的拍摄时间和位置元数据进行行程整理,Ormo 不会自动扫描整本相册;
- 麦克风:仅在你主动录制语音回忆时使用,最长录制时间以页面提示为准;
- 位置与后台位置:仅用于你主动开始的活动;后台权限允许切换应用或锁屏期间继续本次记录和你明确开启的路线共享,结束或取消后停止;旅行地点仅在你添加节点或整理已选择照片的地点时用于地址解析;
- 日历:仅在你点击加入系统日历后,用于把所选共同事项写入设备日历;
- 通知:用于你选择接收的情侣互动、回复、安全到达和系统提醒。
你可以在 iOS 或 Android 系统设置中关闭权限,关闭后只影响对应功能。在每次开启完整路线共享、导入带时间或地点的旅行照片、上传票据截图,或进入可能涉及敏感观点的私密问答前,Ormo 会再次说明处理内容、用途和可见范围,由你单独选择是否继续。拒绝不影响其他基础功能。
四、使用目的
我们将信息用于注册登录、账号保护、资料展示、内容互动、固定双人空间、所选城市的真实天气联动、旅行计划与日志、照片与语音存储、运动统计和路线分享、桌面小组件同步、通知、数据导出、纪念日与旅行视频生成、内容安全审核、反作弊、投诉客服、统计分析和服务改进。
五、委托处理、共享与公开
我们不会出售个人信息。为实现必要功能,信息可能由云存储、短信、推送、地图、天气、内容安全、支付和基础设施服务商在必要范围内处理数据,例如腾讯云、阿里云、Apple、Expo、Open-Meteo 以及已配置的区域合规内容审核服务。
必要第三方处理:远程推送仅向推送服务发送设备令牌、通用提示和粗粒度事件类型,不发送私密正文、精确轨迹或数据库标识。天气查询仅发送用户主动设置的城市名称或降低精度后的城市级坐标,不附带账号身份。用户提交的文字会先经 Ormo 本地风险规则处理,再发送给数据处理区域与当前 Ormo 服务区一致的 HTTPS AI 内容安全服务审核;审核失败或服务不可用时不发布。用户主动设置的头像、公开图片和公开画作会在展示前发送给同区 AI 内容安全服务,界面会在发送前明确告知;情侣空间私密图片不进入这条公开图片审核链路。审核服务仅接收完成本次判断所需的内容和技术请求信息。短信服务处理手机号和验证所需信息;Apple 处理绑定登录或交易凭证;地图服务处理加载地图所必需的设备、网络和坐标信息。具体处理地点、保存期限和独立处理行为以相应服务商的合同与隐私规则为准。
数据存储区域与基础设施:中国大陆用户的核心业务数据存储于中国服务区,主要服务节点在北京,数据库、对象存储和备份位于中国境内。其他国家和地区用户的核心业务数据存储于海外服务区,主要服务节点在美国加利福尼亚州圣克拉拉地区,数据库、对象存储和备份位于美国或明确标识的海外区域。
Ormo 中国服务区与海外服务区不传递核心业务数据:不双写、不整库复制、不跨区查询、不跨区故障切换,也不建立跨区情侣空间。这项区域隔离不等于功能所必需的独立第三方服务商不会处理有限信息。如核心存储区域或第三方处理方式发生实质变化,我们将更新本政策并履行适用的告知、评估和同意义务。
中国服务区为 ormo.com.cn,海外服务区为 ormo.app。隐私请求可联系 support@ormo.app。为保护系统安全,本政策不公开服务器 IP、端口、访问凭证或精确机房位置。地图展示会使用设备平台和地区对应的服务:iOS 使用 Apple MapKit;Android 中国大陆路线默认使用高德地图 SDK,其他地区默认使用 Google Maps SDK,且用户可以手动切换。打开地图时,相应地图服务商可能接收为加载地图所必需的设备、网络及路线坐标信息,并按其隐私规则处理;Ormo 不会因地图展示额外开启定位。点击导航后会打开你选择的第三方地图应用或网页。
情侣空间内容仅向同一区域内绑定的双方提供。私密照片和语音通过短时、账号绑定的凭证读取;时光信正文使用认证加密保存;完整路线仅在你明确选择时向伴侣分享。因法律义务、监管司法要求或保护人身与服务安全而必须提供的情况除外。
六、导出、生成与第三方分享
你可以主动导出结构化数据、可阅读档案、纪念长图和旅行路线 PDF,或根据共同照片生成纪念日及旅行视频。服务端临时视频和中间文件在响应完成后删除;照片与语音原件不会自动嵌入结构化或网页档案。通过系统分享面板保存或发送的副本由你选择的设备位置或第三方应用继续保管。未共同揭晓的对方答案、未开启时光信正文和对方仅自己可见的运动不会进入你的导出内容。
七、保存与保护
个人信息原则上在实现目的所需的最短期限内保存,法律法规另有要求的除外。情侣通知摘要和已读状态最多保留180天。好友邀请记录及匿名安装标识的哈希值在账号和相关奖励记录存续期间保存,用于防止重复奖励、处理申诉和财务核对,之后按适用规则删除或匿名化。官网访问统计的按日访客哈希最多保留35天,匿名每日 PV 汇总可长期保留用于运营趋势分析。我们采用访问控制、加密、签名访问、日志与备份等措施保护数据。互联网服务无法保证绝对安全,请妥善保护账号和导出文件。
八、你的权利
你可以查看、更正资料,管理权限,删除自己有权删除的照片、语音、评论和发布内容,关闭情侣空间,导出部分数据,或通过“我的-设置-账户-注销账号”永久删除账号。举报、屏蔽、内容管理、无法登录时的注销申请及订阅注意事项,详见《用户控制与账号注销》。注销或关闭空间后,相关数据将按页面提示删除或匿名化,法律要求保留或处理安全投诉所必需的信息除外。
九、未成年人
Ormo 当前仅面向年满18周岁的用户。我们不面向未成年人提供注册服务;如发现未成年人信息被不当提交,请联系我们处理。
十、更新与联系
重大变更时我们会通过页面、App提示或其他合理方式通知。隐私请求请联系 support@ormo.app,我们通常在15个工作日内回复。
This English version is for convenience. The Chinese version prevails if there is any inconsistency.
1. Scope and operator
This Policy explains how Ormo collects, uses, stores, shares, and protects personal information and how you may exercise your rights. Ormo is operated by an individual developer whose legal identity is shown on the App Store product page and, for the China service region, in the applicable app filing. Contact support@ormo.app for privacy, account, or complaint matters.
2. Information processed
We may process phone or login identifiers; an email supplied or hidden by Apple after a user actively links Apple Sign In; account and profile information; content, interactions, reports, and moderation records; Couple Space pairing, dates, moods, wishes, plans, habits, answers, rituals, nudges, cards, time capsules, photos, comments, voice memories, and metadata. Apple Sign In does not create a standalone account. Optional private couple answers may concern relationships, sexual orientation, intimate preferences, religion, or other sensitive views; they are used only for the couple interaction the user chooses and not for advertising profiles. We may also process travel names, destinations, dates, ticket or booking details, itinerary stops and coordinates, notes, user-selected travel photos or ticket screenshots, and available capture-time and location metadata from selected travel photos; activity location after you actively start and grant permission; and device, notification, log, IP, and security information. When you register with a friend referral code, the App creates a random app-scoped anonymous installation identifier in secure storage and stores only its hash in the current data service region to prevent duplicate referral rewards. It is not used for advertising tracking, cross-app identification, or cross-region transfer.
When you open the website homepage, Ormo sets a one-year, HttpOnly, same-site anonymous cookie to count homepage views (PV) and deduplicate daily anonymous visitors (UV). The random identifier remains in the browser and only a cryptographic daily hash is stored by the analytics system. This statistic is not used for advertising, cross-site identification, or profiling, and full IP addresses are not written to the visit-statistics records. Infrastructure may still process necessary network logs for security and troubleshooting.
3. Permissions
- Photos are used only when you select an avatar, image, shared memory, travel photo, or ticket screenshot. Available capture-time and location metadata is read only from travel photos you select to match itinerary stops and display the route. Ormo does not automatically scan your library.
- The microphone is used only when you actively record a voice memory.
- Location and background location are used only for an activity you actively start and stop after finishing or cancelling; itinerary places and selected-photo places may use address lookup.
- Notifications are used for alerts you choose to receive.
Before each full-route sharing session, selected-photo metadata import, ticket-image upload, or entry into private questions that may involve sensitive views, Ormo provides a specific notice and asks whether you want to continue. Declining does not disable unrelated core features.
4. Purposes
Information is used for accounts, security, profiles, interactions, Couple Space, travel planning and route PDFs, media storage, activity records, widgets, notifications, exports, anniversary and travel video generation, moderation, fraud prevention, support, analytics, and improvement.
5. Service providers and sharing
We do not sell personal information. Cloud storage, SMS, push, maps, weather, content-safety, payment, and infrastructure providers may process limited data needed for their functions, including Tencent Cloud, Alibaba Cloud, Apple, Expo, Open-Meteo, and a configured region-compliant moderation provider.
Necessary third-party processing: Remote push providers receive only a device token, generic notice, and coarse event type—not private message text, precise routes, or database identifiers. Weather requests use a city name or reduced-precision city-level coordinates without account identity. Submitted text is checked by local Ormo rules and then sent to an HTTPS AI content-safety provider whose processing region matches the current Ormo service region; publication is blocked if review fails or is unavailable. Avatars, public images, and public drawings that a user chooses to post are sent to the same-region AI safety provider before display, with notice shown before sending. Private Couple Space images do not enter this public-image review flow. The provider receives only the content and technical request information needed for that decision. SMS providers process the phone number and verification data, Apple processes linked sign-in or transaction credentials, and map providers process technical and coordinate data needed to load maps. Provider locations, retention, and independent processing are governed by their contracts and privacy terms.
Core data storage: Mainland-China users' core business data is stored in the China service region, whose primary nodes are in Beijing and whose database, object storage, and backups are in China. Other users' core business data is stored in the overseas service region, whose primary nodes are in the Santa Clara, California area and whose database, object storage, and backups are in the United States or another expressly identified overseas region.
Ormo does not transfer core business data between its China and overseas regions: there are no dual writes, full-database copies, cross-region queries, cross-region failover, or cross-region Couple Spaces. This regional isolation does not mean that independent providers never process the limited data needed for a feature. If core storage or third-party processing materially changes, we will update this Policy and complete applicable notice, assessment, and consent requirements.
The China service region is ormo.com.cn, the overseas service region is ormo.app, and privacy requests may be sent to support@ormo.app. To protect system security, this Policy does not publish server IP addresses, ports, credentials, or exact data-center locations. Map display uses Apple MapKit on iOS; Android defaults to AMap for mainland-China routes and Google Maps elsewhere, with a manual switch. Opening navigation transfers the destination to the selected map app or website. Couple Space content is available only to paired members in the same service region. Private media uses short-lived account-bound access, time-capsule text is encrypted, and full routes are shown near real time during an active session only when explicitly shared.
6. Exports
You may actively create data exports, readable archives, keepsakes, trip route PDFs, or anniversary and travel videos. Temporary server video files are deleted after delivery. Copies saved or shared through the system share sheet are handled by the destination you choose. Unrevealed partner answers, unopened partner capsule text, and partner-private activities are excluded.
7. Retention and security
Information is retained only as long as needed unless law requires otherwise. Couple notification summaries and read status are retained for up to 180 days. Referral records and anonymous installation identifier hashes are retained while the account and related reward record remain necessary for duplicate prevention, disputes, and financial reconciliation, then deleted or anonymized as applicable. Daily website visitor hashes are retained for no more than 35 days; anonymous daily PV totals may be retained for long-term operational trend analysis. We use access control, encryption, signed access, logging, and backups, but no internet service can guarantee absolute security.
8. Your rights
You may access or correct your profile, manage permissions, delete content you control, close Couple Space, export available data, or delete your account in Settings. Data is then deleted or anonymized except where retention is legally required or necessary for safety complaints.
9. Adults only
Ormo is intended only for users aged 18 or above.
10. Contact
Contact support@ormo.app. We generally respond within 15 business days.