用户隐私政策声明
Privacy Policy Statement
最新更新日期:2026年9月22日
Last Updated: September 22, 2026
一、 引言
1. Introduction
本隐私政策适用于由 武汉鲸乐互娱文化传媒有限公司(以下简称“我们”)开发并运营的移动端应用 API Wallet (API 钱包),以及用于查询和同步订阅额度、统计 Codex Token 用量及提供任务完成提醒的 ModelMeter Mac 伴侣。我们非常重视您的隐私,并致力于妥善保护您的个人数据与 API 密钥资产。本声明旨在向您说明:API Wallet 采用“本地优先”的设计,默认情况下您的服务商配置、余额记录与 API 密钥主要保存在您的设备本地;当您主动开启云端余额监控、远程推送提醒或 Mac 额度同步等功能时,应用仅处理完成相应功能所必需的数据。
This Privacy Policy applies to the API Wallet mobile application developed and operated by Wuhan Jingle Huyue Culture Media Co., Ltd. (referred to as "we", "us", or "our"), as well as the ModelMeter Mac companion used to query and sync subscription quotas, summarize Codex token usage, and provide task completion alerts. We take your privacy seriously and are committed to safeguarding your personal data and API key credentials. API Wallet follows a local-first design: by default, provider settings, balance records, and API keys are mainly stored on your device. If you actively enable cloud balance monitoring, remote push alerts, or Mac quota sync, the apps process only the data needed to provide the selected feature.
二、 我们如何处理您的敏感信息(API 密钥)
2. Handling of Sensitive Information (API Keys)
API Wallet 的核心功能包括登记 API 服务商信息、保存 API 密钥或余额查询凭证,并用于查询余额与用量。以下是您输入的 API 密钥(API Keys)及相关凭证的处理规则:
API Wallet lets you save API provider settings, API keys, or balance query credentials for balance and usage checks. The details below clarify how API keys and related credentials are handled:
- 本地加密存储:您的 API 密钥在输入后,会通过 iOS 系统级安全能力存储在您设备本机的安全钥匙串(Keychain)中。
- Local encrypted storage: Once entered, your API keys are stored in your device's secure Keychain using Apple's system-level security capabilities.
- 云端监控需同步凭证:如果您主动开启云端余额监控,为了让服务器在您不打开 App 的情况下定时查询余额并发送推送提醒,我们会通过 HTTPS 将相关 API Key、余额查询 Token、用户 ID、API Base URL、服务商名称、模型名称、币种、提醒阈值等必要信息同步至我们的服务器。
- Credentials required for cloud monitoring: If you actively enable cloud balance monitoring, the app will transmit necessary information over HTTPS to our server so that balance checks and push alerts can run when the app is not open. This may include API keys, balance query tokens, user IDs, API base URLs, provider names, model names, currency codes, and alert thresholds.
- 可选启用:云端余额监控不是使用 API Wallet 的必需功能。您可以不开启该功能,仅使用本地保存、本地刷新与本地提醒能力。
- Optional feature: Cloud balance monitoring is optional. You may use API Wallet with local storage, local refreshes, and local alerts without enabling cloud monitoring.
- Mac 伴侣凭据处理:ModelMeter Mac 使用您已经登录的 Codex 或 Antigravity 本机环境查询额度。登录令牌和本机连接凭据只在 Mac 本机使用,不会保存到额度快照,不会同步到 iPhone,也不会发送至我们的业务服务器。
- Credentials used by the Mac companion: ModelMeter Mac queries quota through the Codex or Antigravity environment already signed in on your Mac. Login tokens and local connection credentials are used only on that Mac. They are not stored in quota snapshots, synced to the iPhone, or sent to our application servers.
三、 个人数据收集与使用说明
3. Data Collection and Usage
我们不会将您的数据用于广告跟踪或跨应用追踪。为提供应用核心功能,我们可能处理以下数据:
We do not use your data for advertising tracking or cross-app tracking. To provide the app's core features, we may process the following data:
- 注册信息:API Wallet 是一款免注册应用,您无须提供手机号、邮箱或任何第三方社交账户进行登录。
- Account Registration: No registration is needed. You do not need to share phone numbers, emails, or link social media profiles to use the app.
- 设备通知标识:当您允许系统通知并开启远程推送能力时,我们会保存 Apple Push Notification service(APNs)提供的 device token,用于向您的设备发送余额提醒通知。该 token 不用于广告或用户画像。
- Device notification identifier: If you allow notifications and enable remote push functionality, we store the APNs device token provided by Apple Push Notification service to send balance alerts to your device. This token is not used for advertising or profiling.
- 余额与用量数据:应用内的用量变动统计、账单流水、端点排行主要基于您的历史余额刷新记录在设备本地计算与存储。开启云端余额监控后,服务器也会保存必要的最近余额、提醒状态、检查时间、通知时间等信息,用于判断是否需要继续发送余额提醒。
- Balance and usage data: Usage statistics, billing logs, and ranking data are mainly computed and stored on-device from your historical balance refresh records. If cloud balance monitoring is enabled, our server also stores necessary recent balance values, alert status, check times, and notification times to determine whether a balance alert should be sent.
- 订阅额度数据:当您在 ModelMeter Mac 主动查询 Codex 或 Antigravity 额度时,Mac 伴侣会处理服务返回的模型或额度分组名称、额度窗口、剩余比例、重置时间和采集时间。开启 iCloud 同步后,这些额度结果会写入您 Apple 账户对应的 CloudKit 私有数据库,供 API Wallet 在 iPhone 上读取。额度快照不包含账号邮箱、登录令牌或原始接口响应。
- Subscription quota data: When you request a Codex or Antigravity quota check in ModelMeter Mac, the companion processes model or quota group names, quota windows, remaining percentages, reset times, and collection times returned by the service. If you enable iCloud sync, these quota results are written to the CloudKit private database associated with your Apple Account so API Wallet can read them on your iPhone. Quota snapshots do not contain account email addresses, login tokens, or raw service responses.
- Codex Token 统计:Mac 伴侣在查询 Codex 额度时,只读扫描本机可访问的 Codex 会话及归档记录,根据用量计数和时间信息计算今日与近 7 天 Token 用量,包含缓存输入,按 Mac 时区汇总。会话标识用于本机去重。开启额度 iCloud 同步后,上传的统计包括每日 Token 总量、对应日期、Mac 时区、采集时间,以及数据是否完整和必要的异常类别、日期与数量。不会上传聊天正文、提示词、代码、原始会话文件或本机文件路径。该统计仅反映本机可读取的记录,不代表整个账号在所有设备上的用量。
- Codex token statistics: When querying Codex quota, the Mac companion reads accessible local Codex session and archived records without modifying them. It uses usage counters and timestamps to calculate today's and the last seven days' token totals, including cached input, using the Mac time zone. Session identifiers are used locally for deduplication. If quota iCloud sync is enabled, synced statistics include daily token totals, dates, the Mac time zone, collection time, completeness status, and necessary issue categories, dates, and counts. Chat text, prompts, code, raw session files, and local file paths are not uploaded. These statistics cover readable records on this Mac, not account-wide usage across all devices.
- Codex 任务完成事件:开启 Mac 伴侣的任务监测后,伴侣只读检查本机会话记录中的完成事件。为避免重复提醒,会根据会话与轮次标识生成哈希事件标识,并将该标识、完成时间及事件类型(完成或测试)写入您自己的 CloudKit 私有数据库。此功能不上传任务标题、聊天正文、提示词、代码或原始会话文件,也不经过我们的业务服务器。
- Codex task completion events: When task monitoring is enabled in the Mac companion, it checks completion events in local session records without modifying them. To prevent duplicate alerts, it derives a hashed event identifier from session and turn identifiers and writes that identifier, completion time, and event type (completion or test) to your own CloudKit private database. This feature does not upload task titles, chat text, prompts, code, or raw session files, and does not pass through our application servers.
- 桌面小组件:iPhone 主 App 将最近同步的 Codex 额度、可用的 Token 汇总、更新时间、显示开关与语言等展示状态写入本机 App Group 共享缓存,供小组件读取。缓存不包含 API 密钥、登录凭据或账号标识。小组件不会自行查询 Codex、读取 Mac 会话记录或直接拉取 iCloud 数据;它显示主 App 最近同步的结果,刷新时间由 iOS 调度。
- Home Screen widgets: The iPhone app writes its most recently synced Codex quota, available token summaries, update times, display setting, language, and other display state to a local App Group cache for the widget to read. The cache contains no API keys, login credentials, or account identifiers. The widget does not independently query Codex, read Mac session records, or fetch iCloud data; it displays the app's last synced results, with refresh timing scheduled by iOS.
- 错误与运行状态:为排查余额查询失败、推送失败等问题,服务器可能记录有限的接口返回状态、错误信息和执行时间。我们不会将这些信息用于营销或广告。
- Error and operational status: To troubleshoot balance query failures or push delivery issues, our server may store limited response status, error messages, and execution timestamps. We do not use this information for marketing or advertising.
四、 网络访问与第三方接口连接
4. Network Access and Third-Party Connection
为了提供余额同步与云端监控功能,应用和服务器需要访问网络,并向您配置的目标接口发送请求:
To provide balance sync and cloud monitoring, the app and our server require network access and may send requests to the endpoints you configure:
- 本地刷新:当您在 App 内手动刷新余额时,网络请求通常由您的设备直接发送至您指定的官方接口或自定义中转站点。
- Local refresh: When you manually refresh balances in the app, requests are generally sent directly from your device to the official endpoint or custom gateway you configure.
- 云端监控:当您开启云端余额监控时,我们的服务器会按照计划任务定时访问您配置的余额查询接口,用于获取最新余额并判断是否发送提醒。
- Cloud monitoring: If cloud balance monitoring is enabled, our server periodically accesses the configured balance query endpoint to obtain the latest balance and decide whether to send an alert.
- Mac 本机额度查询:ModelMeter Mac 会按您的操作连接本机 Codex 提供的额度查询能力,或连接正在运行的 Antigravity 本机回环接口。为了定位 Antigravity 的本机服务,伴侣可能读取相关进程信息和本机监听端口;连接信息仅在查询期间保留在内存中。Mac 伴侣不会借此发起模型对话,也不会复制或上传第三方服务的登录凭据。
- Local quota queries on Mac: At your request, ModelMeter Mac connects to the local quota capability provided by Codex or to the loopback interface of a running Antigravity instance. To locate the Antigravity service, the companion may inspect related process information and local listening ports; connection information is retained in memory only for the duration of the query. The companion does not initiate model conversations or copy or upload credentials for either third-party service.
- 私人 iCloud 同步:订阅额度与 Token 汇总同步、任务完成事件使用 Apple CloudKit 私有数据库,不经过我们的业务服务器。这些功能可选,要求 Mac 与 iPhone 使用同一 Apple 账户。Mac 休眠或伴侣退出时不会继续采集;离线时无法上传至 iCloud,恢复连接后按各功能规则重试。
- Private iCloud sync: Subscription quota and token summary sync, and task completion events, use Apple CloudKit private databases and do not pass through our application servers. These features are optional and require the Mac and iPhone to use the same Apple Account. Collection stops while the Mac is asleep or the companion is not running. Uploads to iCloud are unavailable offline and are retried according to each feature’s rules after connectivity returns.
- 无广告与分析 SDK:应用内不集成任何可能收集您设备识别码或跟踪您广告偏好的第三方统计与广告 SDK。
- No Trackers or Ads: The app does not package advertising SDKs or tracking services that monitor hardware markers or browser behavior.
五、 通知提醒服务
5. Notification Services
当您启用低余额提醒时,应用会请求 iOS 系统通知权限。提醒方式可能包括本地通知和远程推送通知:本地通知由设备在 App 内刷新余额后触发;云端余额监控则由我们的服务器定时查询余额,并通过 Apple Push Notification service(APNs)向您的设备发送提醒。通知内容通常包含服务商名称、当前余额与提醒阈值。
When you enable low-balance alerts, the app requests iOS notification permission. Alerts may include local notifications and remote push notifications: local notifications are triggered after in-app balance refreshes, while cloud balance monitoring lets our server periodically check balances and send alerts to your device via Apple Push Notification service (APNs). Notification content typically includes the provider name, current balance, and alert threshold.
Codex 本轮完成提醒需要您在 iPhone 开启该提醒并允许系统通知,同时在 Mac 伴侣开启任务监测。iPhone 在 CloudKit 中设置通知订阅,Apple 根据新增完成事件通过推送服务发送提醒。通知使用固定完成文案,不包含任务标题或对话内容。您可以在 App 中关闭该提醒,或在 iOS 系统设置中关闭通知及锁屏预览;Mac 端监测开关与 iPhone 提醒开关分别控制事件采集与通知订阅。
Codex turn completion alerts require enabling the alert and allowing system notifications on iPhone, and enabling task monitoring in the Mac companion. The iPhone app configures a CloudKit notification subscription, and Apple sends a push alert when a new completion event is created. Alerts use fixed completion text and contain no task titles or conversation content. You can turn off this alert in the app or disable notifications and Lock Screen previews in iOS Settings. The Mac monitoring switch and iPhone alert switch separately control event collection and the notification subscription.
六、 数据保存、删除与安全
6. Data Retention, Deletion, and Security
本地数据会保存在您的设备中,您可以通过删除服务商卡片、关闭余额提醒、卸载 App 等方式移除本地数据。开启云端余额监控后,相关账户配置会保存在我们的服务器中,以便持续提供监控服务;当您删除对应账户或关闭/更新云端监控配置时,应用会向服务器同步变更。您也可以通过本政策中的联系方式要求我们协助删除服务器端保存的相关数据。
Local data is stored on your device, and you may remove it by deleting provider cards, disabling balance alerts, or uninstalling the app. If cloud balance monitoring is enabled, related account configuration is stored on our server to provide ongoing monitoring. When you delete an account or disable/update cloud monitoring settings, the app syncs those changes to the server. You may also contact us using the details in this policy to request deletion of related server-side data.
Mac 伴侣同步的订阅额度快照保存在您的 CloudKit 私有数据库中,并由您的 Apple 账户和 Apple 的 iCloud 数据管理机制控制。关闭 Mac 伴侣中的 iCloud 同步会停止后续写入;关闭 iPhone 中对应订阅来源的首页显示会停止读取和展示,但不会自动删除已存在的 CloudKit 记录。您可以通过管理或删除相应的 iCloud 数据来移除这些记录。
Subscription quota snapshots synced by the Mac companion are stored in your CloudKit private database and are governed by your Apple Account and Apple's iCloud data-management mechanisms. Disabling iCloud sync in the Mac companion stops future writes. Disabling a subscription source on the iPhone stops reading and displaying it, but does not automatically delete an existing CloudKit record. You can remove these records by managing or deleting the corresponding iCloud data.
Token 汇总随最新额度快照更新,内容覆盖最近 7 天;这不表示旧的云端快照一定会在 7 天后自动删除。关闭 Mac 额度 iCloud 同步会停止后续额度与 Token 汇总上传。关闭 iPhone 的 Codex 首页显示或 App 处理到 iCloud 账户变更时,会清除小组件缓存中的额度与 Token 数据。仅移除桌面小组件不会自动删除云端数据。
Token summaries are updated with the latest quota snapshot and cover the most recent seven days; this does not mean an existing cloud snapshot is automatically deleted after seven days. Disabling quota iCloud sync on Mac stops subsequent quota and token summary uploads. Disabling Codex display on the iPhone Home tab, or an iCloud account change handled by the app, clears quota and token data from the widget cache. Removing a Home Screen widget alone does not delete cloud data.
关闭 Mac 任务监测会停止后续完成事件采集与上传;在 iPhone 关闭完成提醒,会在成功同步设置后移除对应 CloudKit 通知订阅,但不会自动删除历史事件。伴侣运行且具备网络与 iCloud 访问条件时,会定期尝试分批清理超过 7 天的完成事件;离线、退出或清理失败可能延长保存时间。您可通过 Apple 提供的 iCloud 数据管理功能管理或删除相关应用数据。
Disabling task monitoring on Mac stops subsequent completion-event collection and uploads. Disabling completion alerts on iPhone removes the corresponding CloudKit notification subscription after the setting syncs successfully, but does not automatically delete past events. While running with network and iCloud access, the companion periodically attempts to delete completion events older than seven days in batches. Offline operation, quitting the companion, or cleanup failures may extend retention. You can manage or delete related app data using Apple's iCloud data-management features.
我们通过 HTTPS 传输云端监控数据,并采取合理的访问控制措施限制服务器数据的访问范围。请注意,API Key 本身具有调用第三方服务的能力,请您妥善设置权限和额度,并仅在信任本功能的情况下开启云端余额监控。
Cloud monitoring data is transmitted over HTTPS, and we apply reasonable access controls to limit server-side data access. Please note that API keys may grant access to third-party services. You should configure appropriate permissions and spending limits, and enable cloud balance monitoring only if you trust this feature.
七、 政策更新
7. Policy Updates
我们可能会适时修改本隐私政策的条款。如果我们将修改内容发布,这些修改将立即生效。建议您定期查看此页面以获取最新版本的隐私声明。
We may update this Privacy Policy periodically. Modifications take effect immediately upon being posted. We encourage you to review this document regularly for updates.
八、 联系我们
8. Contact Us
如果您对本隐私政策有任何疑问、意见,或发现我们的应用存在任何安全隐患,请通过以下渠道与我们取得联系:
If you have questions, comments, or report security details about this privacy policy, feel free to contact us via:
武汉鲸乐互娱文化传媒有限公司
Email: liuxin@fengjungpt.com