ranu · 隐私说明
Nate Gu & Co LLC · 更新于 2026-10-03
联系:developer@nateguco.com
相册里的照片在这台手机上整理成手帐。ranu 的服务器不接收照片原片或完整路线;地图、地名、可选路标以及你主动分享或导出的内容,各有下面的边界。
相册与手帐
- ranu 读取相册里照片的拍摄时间和位置,用来找出你出门的日子、画路线。
- 照片内容识别、抠图、手帐生成和整理记录在手机上处理。原片由系统相册管理;iCloud 照片是否同步或下载,遵循你的 Apple 设置。
- 仅从手帐移除照片不删除原片。从相册删除则先征求你的确认;开启 iCloud 照片时,系统会把删除同步到同一账户的设备。
地图与地名
- 手绘底图使用 OpenStreetMap 数据,按约 5 公里的格子从我们的地图服务下载;覆盖区外的格子由服务器向公共地图服务查询并缓存。
- 地名和拍摄地时区通过 Apple 的系统地理服务查询坐标,结果缓存在手机上。因此,并非所有位置查询都只发生在本机。
- 地图格子和公开路标查询不带 ranu 的设备身份,但服务仍会收到格子编号和 IP 地址等一般网络元信息。「不带 App 身份」不代表绝对无法关联请求。
路标和家人朋友(可选)
- 不需要手机号或邮箱。手机生成随机设备密钥;需认证的请求通过加密连接发送该密钥,服务器保存单向摘要、可选称呼、朋友关系及邀请码。
- 主动留路标会上传该站坐标、日期和图形,并绑定设备身份的摘要。可以选择一条预设的固定短提醒和 7、30 或 90 天有效期,不接受自由文字。路标在 24 小时后公开:返回的位置约到 10 米、拍摄日期只显示月份,提醒和有效期也会公开,到期时间只精确到 UTC 日期,不公开精确发布时刻。不带照片或完整路线,也不显示发布者身份。相册识别的常待地点附近不能留路标。
- 新版路标从公开时刻起计算所选有效期,向上取整至 UTC 日期边界。过期后不再公开,也不再接受新的盖章或路过反馈;作者仍能查看自己的过期路标和已有计数,并可拿掉它。旧版留下的图形路标没有自动有效期,仍可由作者拿掉。
- 保存结果不确定时,App 可带身份发送请求编号来关闭这次尝试并确认结果,不重新发送位置或提醒内容。服务器保存已闭合的请求编号及设备身份摘要用于恢复,防止迟到请求重新创建路标;这份闭合记录不含位置或提醒内容,也不对其他人公开。
- 「ranu 宇宙」默认关闭;开启后,即使没有连接朋友,也会查询自己手帐附近的陌生路标。关闭只影响你看到什么,不会把已经留下的路标改为私密或取消公开;可以在 App 里拿掉自己的路标。
- 朋友路标编号通过带身份的请求取得,该请求不带附近位置;App 在手机上比对编号并标记朋友的路标。
- 「盖章」「路过」不带设备身份,发送路标编号和按路标、操作生成的去重令牌。一般网络元信息仍会到达服务。
- 邀请码一次性或限次使用,会过期;连接前先确认,可以随时断开朋友。
分享、导出与备份
- 分享卡可能包含你选的照片、地名、日期、标题和短话;邀请二维码默认关闭。由你确认内容,并在系统分享面板选择发送去处,或保存到相册。
- 主动导出的出门记录含照片位置等个人记录。整理备份包含文字、选图引用、贴纸选择、排版及分组,不含照片原片、设备密钥或朋友配置。
- 文件由你选择存到本机、iCloud Drive 或其他文件服务;ranu 不自动把手帐上传到自己的服务器。接收方或文件服务如何处理内容,遵循你选择的服务。
通知和统计
- "画好了"的提醒是手机本地通知,不经过服务器。
- 使用次数(打开了几页、存了几张卡等)只记在你的手机上,不上传。没有广告,没有第三方统计或追踪。
删除
- 删除 App 会移除其本机整理与缓存,不会删除系统相册里的原片和已保存的分享卡、你另存的导出或备份文件,也不会自动删除服务器上的路标和朋友关系。随机设备密钥可能由系统钥匙串保留。
- 可以在 App 里拿掉自己的路标、断开朋友。服务器数据的删除请求或隐私问题请联系 developer@nateguco.com。
English summary
ranu processes photos and journals on your phone; our servers do not receive original photos or full routes. Apple system geocoding receives coordinates to look up place names and time zones. Map and public-sign requests omit ranu device identity but send roughly 5 km cell IDs and normal network metadata, including IP addresses. Map services supply the base map. iCloud Photos follows your Apple settings.
Authenticated requests send a random device secret over TLS; the server stores its digest, optional name, connections and invites. When you choose to leave a sign, its coordinates, date and pictogram are uploaded with that identity. You may choose one fixed preset reminder and a 7, 30 or 90 day lifetime; free-form text is not accepted. After 24 hours it becomes public, with rounded coordinates, the photo month only and no author identity, photos or full route. The reminder and lifetime are public too; expiry is rounded up to a UTC date boundary, without an exact publication time. New signs count their lifetime from publication. Expired signs are no longer public and cannot receive new stamps or passes; their owner can still read existing counts and remove them. Legacy pictograms do not automatically expire. The stranger-sign setting is off by default; enabling it can query signs without connected friends. Turning it off does not make your own published signs private. You can remove your signs. Stamp and pass requests omit device identity and carry sign IDs and deduplication tokens; network metadata still reaches the service.
If a save result is uncertain, the app can send an authenticated request ID to close that attempt and recover its result, without resending locations or reminder content. The server retains closed request IDs with the device-identity digest to prevent late requests from creating signs again. These recovery markers contain no location or reminder content and are not public.
You choose where to share cards or save exports and backups. Cards can include photos and places; exports contain locations. Journal backups contain edits and references, not original photos, device secrets or friend settings. Deleting the app does not delete system-library photos, saved cards, exports, backups or server records; the device secret may remain in the system Keychain. Remove signs and disconnect friends in the app, or contact developer@nateguco.com about server data. Usage counts and notifications stay local. No ads or third-party analytics.