Fatebend Privacy Policy
Fatebend 隐私政策
Fatebend ("we", "us", "the app") is a voice-first interactive storytelling app where you intervene in unresolved moments from history, literature, and collective memory. This policy explains what data we collect, why we collect it, and what choices you have.
Fatebend(「我们」「本应用」)是一款语音优先的互动叙事应用,你可以在历史、文学与集体记忆中那些未竟的瞬间里进行干预。本政策说明我们收集哪些数据、为何收集,以及你拥有哪些选择。
1. Information We Collect
1. 我们收集的信息
We collect the minimum data needed to run live voice sessions, keep your app installation and optional account link working, maintain story balances, and diagnose service problems.
我们仅收集运行实时语音场次、维持 app 安装与可选账户关联、维护局数余额,以及诊断服务问题所必需的最少数据。
1.1 Optional Apple Account Link
1.1 可选 Apple 账户关联
- What: Only if you choose Sign in with Apple, an opaque Apple/Supabase user identifier. We do not receive your Apple ID password.
- 内容:只有你主动选择 Sign in with Apple 时,我们才会收到一个不透明的 Apple/Supabase 用户标识符。我们不会获取你的 Apple ID 密码。
- Why: To make your balance available on devices linked to the same account and establish ownership for publishing or retracting a shared public node. Registration is not required to browse, start voice, receive free stories, or buy stories.
- 原因:用于让余额可在关联到同一账户的设备上使用,并为公开或撤回共享节点建立所有权。浏览、开始语音、领取免费局数或购买局数均无需注册。
- How long: Until you delete your account in the app or request deletion by email.
- 保留时长:直到你在应用内删除账户或通过电子邮件请求删除为止。
1.2 Device Token
1.2 设备令牌
- What: A randomly generated installation token stored in Keychain/UserDefaults.
- 内容:一个随机生成的安装令牌,存储于 Keychain/UserDefaults。
- Why: To connect this app installation to the server, maintain its story balance, prevent duplicate grants, and support optional account linking.
- 原因:用于将当前 app 安装连接到服务器、维护其局数余额、防止重复发放,并支持可选账户关联。
- How long: Until you delete a linked account, uninstall/reset the app, or request deletion of an unlinked installation.
- 保留时长:直到你删除已关联账户、卸载/重置 app,或请求删除未关联安装的数据为止。
1.3 Voice Input
1.3 语音输入
- What: Audio captured from your device microphone while you speak inside a Fatebend session and text transcribed from that audio.
- 内容:你在 Fatebend 场次中说话时由设备麦克风采集的音频,以及从该音频转写出的文本。
- Why: To transcribe your speech, run the model-driven intervention engine, and play back the storyteller's response.
- 原因:用于转写你的语音、运行模型驱动的干预引擎,并播放引路人的回应。
- How long: Fatebend processes voice for the session and does not use it for advertising or to train Fatebend's own models. Apple Speech Recognition may process audio on-device or receive it through Apple's service. If Apple cannot complete transcription, Fish Audio receives the audio. Apple and Fish Audio process data under their own privacy terms.
- 保留时长:Fatebend 仅为本次场次处理语音,不会将其用于广告或训练 Fatebend 自有模型。Apple Speech Recognition 可能在设备本地处理音频,也可能通过 Apple 服务接收音频;Apple 无法完成转写时,Fish Audio 会接收音频。Apple 与 Fish Audio 按各自隐私条款处理数据。
1.4 Session Text and Runtime Logs
1.4 场次文本与运行日志
- What: Your transcript, selected scene, recent dialogue, session and node identifiers, locale, latency markers, runtime diagnostics, and de-identified learning digests. DeepInfra receives transcript/scene/recent-dialogue data to generate the next fictional response. Fish Audio receives AI-generated character text to synthesize the voice you hear. Full readable session history stays on-device by default unless you deliberately share a run for support.
- 内容:你的转写、所选场景、近期对话、场次与节点标识符、语言区域、延迟标记、运行诊断信息及去标识化学习摘要。DeepInfra 接收转写/场景/近期对话数据以生成下一段虚构回应;Fish Audio 接收 AI 生成的角色文字以合成你听到的声音。完整可读的场次历史默认留在设备本地,除非你主动分享某次运行以获得支持。
- Why: To operate the voice loop, diagnose failures, support App Store review/debugging, and improve reliability without turning your private session into shared product content.
- 原因:用于运行语音循环、诊断故障、支持 App Store 审核/调试,并在不把你的私人场次变为共享产品内容的前提下提升可靠性。
- How long: De-identified diagnostics may be retained for service improvement and abuse prevention. User-shared support or review packets are retained only as long as needed for support/debugging and can be deleted on request.
- 保留时长:去标识化的诊断信息可能为改进服务与防止滥用而保留。用户主动分享的支持或审核数据包仅在支持/调试所需的时间内保留,并可应请求删除。
1.5 Public Nodes You Publish
1.5 你公开的节点
- What: If you publish an eligible night to the public FatePool, we store the generated public node, owner mapping, source night reference, moderation/report records, locale, and open counts.
- 内容:如果你将符合条件的夜晚公开到 FatePool,我们会存储生成的公共节点、所有者映射、来源夜晚引用、审核/举报记录、语言区域与开启次数。
- Why: To show the node in the public pool, let other users open it, support report/retract/moderation controls, and prevent abuse.
- 原因:用于在公共池中展示该节点、让其他用户开启、支持举报/撤回/审核控制,并防止滥用。
- How long: Until you retract it, delete your account, or we remove it. Nodes already opened by others may leave an anonymized or retracted residue needed to preserve those users' own session records.
- 保留时长:直到你撤回、删除账户或我们移除它为止。已被其他用户开启的节点,可能留下为保留那些用户自身场次记录所需的匿名化或已撤回残留。
1.6 Onboarding Answers
1.6 引导问答
- What: Your onboarding answers and completion state.
- 内容:你的引导问答及完成状态。
- Why: To personalize the app experience and avoid repeating onboarding.
- 原因:用于个性化应用体验,并避免重复进行引导。
- How long: Stored on device unless later submitted as part of a voice session or support request.
- 保留时长:存储于设备本地,除非之后作为语音场次或支持请求的一部分被提交。
1.7 Purchases and Stories
1.7 购买与局数
- What: StoreKit transaction identifiers, product identifiers, storefront, story balance, and purchase verification payloads.
- 内容:StoreKit 交易标识符、产品标识符、商店区域、局数余额,以及购买验证数据。
- Why: To grant consumable story entries, prevent duplicate grants, and satisfy App Store purchase requirements.
- 原因:用于发放消耗型局数、防止重复发放,并满足 App Store 的购买要求。
- How long: Kept as long as necessary for accounting, fraud prevention, refunds, and legal obligations.
- 保留时长:为会计核算、欺诈防范、退款及法律义务所必需的时间内保留。
1.8 Device and App Diagnostics
1.8 设备与应用诊断
- What: App version, iOS version, locale, audio route diagnostics, latency measurements, crash information available through Apple, and server error logs.
- 内容:应用版本、iOS 版本、语言区域、音频路由诊断、延迟测量、通过 Apple 提供的崩溃信息,以及服务器错误日志。
- Why: To keep the app working across real iPhones, headphones, and network conditions.
- 原因:用于确保应用在各类真实 iPhone、耳机及网络条件下正常运行。
- How long: Retained as needed for troubleshooting and service integrity.
- 保留时长:为故障排查与服务完整性所需的时间内保留。
2. What We Do Not Collect
2. 我们不收集的信息
Fatebend does not collect contacts, photos, precise location, calendar, health data, advertising identifiers, or data used to track you across other companies' apps or websites. We do not use third-party advertising SDKs and we do not use App Tracking Transparency because we do not track users across apps or sites.
Fatebend 不收集通讯录、照片、精确位置、日历、健康数据、广告标识符,也不收集用于跨其他公司应用或网站追踪你的数据。我们不使用第三方广告 SDK,也不使用 App Tracking Transparency,因为我们不会跨应用或网站追踪用户。
3. How Your Data Is Used
3. 我们如何使用你的数据
- Your choice before sharing: Before voice-session data is sent, Fatebend presents a standalone permission screen identifying every recipient, the exact data it receives, and the purpose. Only Allow AI Data Sharing permits the listed data to be sent. Don't Share sends none of the listed voice-session data and still lets you browse and buy stories. Grant or withdraw permission through Settings > AI Data Sharing.
- 发送前由你选择:发送语音场次数据前,Fatebend 会通过独立权限页面列出每个接收方、收到的具体数据和用途。只有选择允许 AI 数据共享后才会发送所列数据;选择不共享不会发送所列语音场次数据,仍可浏览和购买。可通过设置 > AI 数据共享授权或撤回权限。
- Fatebend server: Transmits and processes the minimum voice, text, scene, and recent-dialogue data needed for the live session.
- Fatebend 服务器:传输并处理运行实时场次所需的最少语音、文本、场景与近期对话数据。
- Apple Speech Recognition (Apple Inc.): May receive microphone audio to create a transcript when recognition is not completed on-device.
- Apple Speech Recognition(Apple Inc.):在设备无法本地完成识别时,可能接收麦克风音频以生成转写。
- Fish Audio (Hanabi AI Inc.): Receives microphone audio only when fallback transcription is needed, and receives AI-generated character text to synthesize the voice you hear.
- Fish Audio(Hanabi AI Inc.):仅在需要回退转写时接收麦克风音频,并接收 AI 生成的角色文字以合成你听到的声音。
- DeepInfra: Receives your transcript, selected scene, and recent dialogue to generate the next fictional response. DeepInfra states that standard inference input/output is held in memory, not stored to disk, and not used for training, subject to its documented exceptions. Fatebend currently uses a standard non-Google/non-Anthropic text model through this path.
- DeepInfra:接收你的转写、所选场景与近期对话,以生成下一段虚构回应。DeepInfra 声明标准推理输入输出仅在内存处理、不写入磁盘且不用于训练,但以其文档列明的例外为准;Fatebend 当前通过此路径使用标准的非 Google/非 Anthropic 文本模型。
- Infrastructure: Supabase processes installation tokens, optional account identifiers, balances, purchase identifiers, and session/public-node metadata. Fly.io hosts Fatebend's encrypted-in-transit API. Apple StoreKit and the App Store handle payment and transaction verification.
- 基础设施:Supabase 处理安装令牌、可选账户标识、余额、购买标识及场次/公共节点元数据;Fly.io 托管 Fatebend 的传输加密 API;Apple StoreKit 与 App Store 处理付款和交易验证。
- Equivalent protection: Fatebend requires providers receiving user data to protect it to the same or an equivalent standard described in this policy. We review their privacy and security terms, limit the data and purpose of each transfer, use encrypted transport, and stop sharing with a provider if it cannot provide that level of protection. Fatebend remains responsible for the data it shares.
- 等同保护:Fatebend 要求每家接收用户数据的服务商提供与本政策相同或等同的保护。我们会审查其隐私与安全条款,限制每次传输的数据和用途,使用加密传输,并在服务商无法提供该等保护时停止共享。Fatebend 仍对其共享的数据负责。
- Safety and abuse prevention: Account, device, purchase, and runtime records may be used to prevent abuse, duplicate story grants, or excessive service cost.
- 安全与防止滥用:账户、设备、购买及运行记录可能被用于防止滥用、重复发放局数或过高的服务成本。
- Service improvement: Aggregated and de-identified reliability data may be used to improve latency, routing, and content quality. Full session text is not used for shared product improvement unless you choose to share a specific run.
- 服务改进:聚合且去标识化的可靠性数据可能被用于改进延迟、路由与内容质量。完整的场次文本不会用于共享性的产品改进,除非你选择分享某次具体运行。
- Public node pool: If you publish a night, its generated public node may be shown to and opened by other Fatebend users, and it may be reviewed or removed after reports or moderation.
- 公共节点池:如果你公开某个夜晚,它生成的公共节点可能会展示给其他 Fatebend 用户并被他们开启,也可能在举报或审核后被复核或移除。
4. Your Choices and Rights
4. 你的选择与权利
You can:
你可以:
- If you linked Apple, delete that account, its remaining story balance, and associated records from in-app Settings.
- 如果你关联了 Apple,可在应用内「设置」中删除该账户、其剩余局数与相关记录。
- For an unlinked installation, uninstall to clear local data and email us with the installation token shown in the app to request deletion of server-side installation data.
- 未关联账户的安装可通过卸载清除本地数据;如需删除服务器侧安装数据,请将 app 中显示的安装令牌发邮件给我们。
- Open Settings > AI Data Sharing and select Withdraw Permission to stop future AI data sharing.
- 打开设置 > AI 数据共享并选择撤回权限,可停止未来语音场次的 AI 数据共享。
- Revoke microphone permission in iOS Settings > Privacy & Security > Microphone.
- 在 iOS 系统「设置」>「隐私与安全性」>「麦克风」中撤销麦克风权限。
- Request access, correction, export, or deletion by emailing support@fatebend.com.
- 通过发送电子邮件至 support@fatebend.com 请求访问、更正、导出或删除数据。
Residents of California, the European Union, the United Kingdom, Brazil, and other jurisdictions with comprehensive privacy laws may have additional rights. Email us to exercise those rights.
加利福尼亚州、欧盟、英国、巴西及其他设有综合性隐私法律的司法管辖区的居民,可能享有额外权利。请发送电子邮件给我们以行使这些权利。
5. Security
5. 安全
We use encryption in transit, restrict server-side access to operational data, and assess providers against the same or equivalent protection standard described above. We do not store Apple ID passwords or credit card numbers; purchases are handled through Apple's StoreKit and App Store infrastructure.
我们对传输中的数据使用加密,限制服务器侧对运营数据的访问,并按上述相同或等同保护标准评估服务商。我们不存储 Apple ID 密码或信用卡号;购买通过 Apple 的 StoreKit 与 App Store 基础设施处理。
6. Adults Only
6. 仅限成年人
Fatebend is intended for adults age 18 and older. The app is gated by an age check at first launch and is not directed to children. It can touch mature themes including war, illness, loss, death, and self-harm, and it sends voice and text to third-party AI providers, so it is built and offered for adults only. We do not knowingly collect data from anyone under 18. If you believe someone under 18 has provided us with data, contact us and we will delete it.
Fatebend 仅面向 18 岁及以上成年人。应用首次启动时设有年龄确认门,且不面向儿童。它可能涉及战争、疾病、失去、死亡、自残等成熟主题,并会将语音和文本发送给第三方 AI 服务商,因此仅为成年人构建和提供。我们不会在知情的情况下收集任何 18 岁以下人士的数据。如果你认为有未成年人向我们提供了数据,请联系我们,我们会将其删除。
7. Microphone Disclosure
7. 麦克风说明
Fatebend asks for microphone access so you can speak to the storyteller. Fatebend processes voice in real time for the session and does not use it for advertising or to train Fatebend's own models. Fatebend may also request speech recognition permission so Apple Speech Recognition can transcribe your voice when available. You may revoke microphone or speech recognition permission at any time in iOS Settings.
Fatebend 请求麦克风权限,以便你能与引路人对话。Fatebend 仅为本次场次实时处理语音,不会将其用于广告或训练 Fatebend 自有模型。Fatebend 也可能请求语音识别权限,以便在可用时由 Apple Speech Recognition 转写你的语音。你可以随时在 iOS 系统「设置」中撤销麦克风或语音识别权限。
8. Safety and Crisis Resources
8. 安全与危机资源
Fatebend is not therapy, counseling, or crisis support, and it does not monitor your dramatic dialogue for risk. If you are a real person in distress, see our Safety Protocol and the 988 Suicide & Crisis Lifeline (call or text 988 in the United States).
Fatebend 不是治疗、咨询或危机支持服务,也不会把你的戏剧对白当作风险监测对象。如果你作为现实中的人正处于痛苦或危险中,请阅读我们的安全协议,并联系能立即帮助你的人;在美国可拨打或短信联系 988 Suicide & Crisis Lifeline。
9. Public Hosting
9. 公开托管
The public privacy policy URL is:
公开的隐私政策网址为:
https://fatebend.com/privacy
fatebend.com is the production host for Fatebend's public legal pages.
fatebend.com 是 Fatebend 公开法律页面的生产环境主机。
10. Changes to This Policy
10. 本政策的变更
We may update this policy when the app, providers, or data practices change. Material changes will be announced in the app or in the public policy page.
当应用、服务商或数据处理方式发生变化时,我们可能更新本政策。重大变更将在应用内或公开政策页面中公告。
Back to Fatebend返回 Fatebend