隐私政策
一句话概括
PIXO TAP 是本地优先的软件:截图、照片、OCR 全文和剪贴板正文留在你的设备上,不会上传。只有在你自己配置了 AI 服务密钥、并主动触发分析时,本机识别出的 OCR 文字和活动时间线才会发送给该 AI 服务。账号、同步和遥测都是可选的,目前账号与同步尚未开放。
1. 留在你设备上的数据
- 截图原图、结束时拍摄的照片、原文件内容、剪贴板文字正文:始终只保存在本机,不上传。
- 项目、会话、活动时间线、OCR 全文、恢复笔记:保存在本机(macOS 的
~/Library/Application Support/PixoTap,Windows 的%LocalAppData%\PixoTap)。 - AI 服务密钥:保存在系统钥匙串(macOS)或系统凭据保护(Windows),不写入项目文件。
- 只有你明确点击开始后才会记录;每一类采集都需要你在系统或应用中授权,并可随时关闭。
2. 发送给第三方 AI 服务的数据
客户端使用你自带密钥的 AI 服务(目前为 DeepSeek)。仅当你配置了密钥并主动触发分析或对话时,才会发送:
- 本机识别出的 OCR 文字(经客户端清洗)、带时间戳的活动时间线、当前应用名称;
- 你在对话框中输入的消息。
不会发送:截图像素、照片、原文件正文、剪贴板文字正文。OCR 文字本身可能包含敏感信息,请按项目内容决定是否授权。发送后的处理受该 AI 服务自己的条款和隐私政策约束,我们无法控制。未配置密钥或断网时,客户端只在本地生成交接摘要。
网站目前不代理 AI 请求(该能力默认关闭)。
3. 账号(尚未开放)
账号是可选的,不登录也可使用客户端。账号由我们自行部署的开源 Logto 服务管理,用于将来的可选同步、数据导出与设备授权。账号服务开放后,我们会处理:
- 登录凭据与验证信息(如邮箱、手机号、验证码;登录方式以开放时为准);
- 显示名称、语言等资料,登录会话与已授权设备;
- 你对隐私政策、AI 云处理、遥测和同步的同意记录(含文档版本与时间);
- 为安全与防滥用而保留的必要日志(保留期限待法务确认)。
未成年人的使用条件与监护人同意机制待法务确认。
4. 同步(可选,尚未开放)
同步默认关闭,且必须由你主动开启。即使开启,也只同步你选择的元数据,例如项目结构、恢复笔记(四段文字)和设置;不包含截图、照片、原文件、剪贴板正文,也不包含 OCR 全文和活动时间线。目前桌面客户端不同步任何数据。
5. 遥测
使用遥测默认关闭。只有在你于账号设置中明确同意后,才可能发送匿名使用统计;你可以随时撤回。
6. 本网站
- 网站托管在 Cloudflare 上。与大多数网站一样,托管平台会处理访问日志(如 IP 地址、请求路径、时间、浏览器标识),用于提供服务、安全与排错。
- 网站没有广告和第三方跟踪脚本。下载页会通过本站接口,在必要时直接访问 GitHub 的公开发布接口以读取发布信息,此时 GitHub 会看到你的 IP 地址。
- 网站只在你的浏览器本地存储少量偏好:语言(
pixo-language)、下载页的“显示测试版”开关、首页已选择的桌宠(仅当前会话)。这些数据不会发送给我们。 - 首页的表单只在当前页面生成预览,不会提交或保存你填写的内容。
7. 你的权利
- 本机数据由你完全掌控:退出程序后删除上述目录即可清除。
- 账号服务开放后,你可以在账号中心管理各项同意、导出数据、撤销设备和会话,并申请注销账号(有宽限期,可在期内撤销;期满后账号与数据被永久删除,备份按保留期自然过期,具体期限待法务确认)。
- 依适用法律你可能享有访问、更正、删除、撤回同意等权利,具体适用与行使方式待法务确认。
8. 安全
我们采用传输加密、最小化采集与本地优先设计来降低风险,但没有任何系统绝对安全。请自行保管设备与密钥。
9. 变更与联系
政策变更时我们会更新页面日期,并在账号服务开放后要求重新同意。运营主体:待补充。联系方式:待补充。适用法律与争议解决:待法务确认。
Privacy Policy
In one paragraph
PIXO TAP is local-first: screenshots, photos, full OCR text and clipboard text stay on your device and are never uploaded. Only when you have configured your own AI service key and trigger an analysis are the OCR text recognised on your device and the activity timeline sent to that AI service. Accounts, sync and telemetry are optional; accounts and sync are not open yet.
1. Data that stays on your device
- Original screenshots, the closing photo, file contents and clipboard text are only stored locally and never uploaded.
- Projects, sessions, the activity timeline, full OCR text and recovery notes are stored locally (macOS:
~/Library/Application Support/PixoTap; Windows:%LocalAppData%\PixoTap). - Your AI service key is kept in the macOS Keychain or Windows credential protection and is not written into project files.
- Nothing is recorded until you explicitly start; each kind of collection needs your permission in the system or the app and can be turned off at any time.
2. Data sent to a third-party AI service
The client uses an AI service with your own key (currently DeepSeek). Only when you have configured a key and trigger an analysis or a chat is the following sent:
- OCR text recognised on your device (sanitised by the client), the timestamped activity timeline and the front app name;
- messages you type into the chat box.
Never sent: screenshot pixels, photos, original file contents, clipboard text. OCR text itself may contain sensitive information, so decide per project whether to allow it. What happens after it is sent is governed by that AI service's own terms and privacy policy, which we cannot control. Without a key or when offline, the client only builds a local hand-off summary.
This website does not proxy AI requests (that capability is off by default).
3. Accounts (not open yet)
Accounts are optional; the client works without signing in. Accounts are managed by an open-source Logto service that we host ourselves, and are for optional sync, data export and device authorization later. Once the account service opens we will process:
- sign-in credentials and verification data (such as email, phone number and codes; sign-in methods will be those available at launch);
- profile details such as display name and language, sign-in sessions and authorized devices;
- your consent records for the privacy policy, AI cloud processing, telemetry and sync (with document version and time);
- logs kept for security and abuse prevention (retention period pending legal review).
Conditions for minors and the guardian-consent mechanism are pending legal review.
4. Sync (optional, not open yet)
Sync is off by default and must be turned on by you. Even when on, only metadata you choose is synced, such as project structure, recovery notes (the four text parts) and settings; never screenshots, photos, original files or clipboard text, nor full OCR text or the activity timeline. The desktop clients do not sync anything today.
5. Telemetry
Usage telemetry is off by default. Anonymous usage statistics may be sent only after you explicitly agree in your account settings, and you can withdraw at any time.
6. This website
- The site is hosted on Cloudflare. As with most websites, the hosting platform processes access logs (such as IP address, request path, time and browser identifier) to provide the service, for security and for debugging.
- The site has no ads and no third-party tracking scripts. When needed, the download page reads release information directly from GitHub's public release API, in which case GitHub sees your IP address.
- The site only keeps a few preferences in your own browser: language (
pixo-language), the "Show beta builds" switch on the download page, and the companion chosen on the home page (current session only). These are never sent to us. - The form on the home page only builds a preview on that page; what you type is neither submitted nor saved.
7. Your rights
- You fully control local data: quit the app and delete the folders above to erase it.
- Once the account service opens you can manage each consent, export data, revoke devices and sessions, and request account deletion (there is a grace period you can cancel within; afterwards the account and data are permanently erased, and backups expire after their retention period; exact periods pending legal review).
- Depending on applicable law you may have rights to access, correct, delete and withdraw consent; their scope and how to exercise them are pending legal review.
8. Security
We use transport encryption, minimal collection and a local-first design to reduce risk, but no system is perfectly secure. Please safeguard your devices and keys.
9. Changes and contact
When this policy changes we will update the date on this page and, once accounts open, ask for consent again. Operator: to be added. Contact: to be added. Governing law and dispute resolution: pending legal review.
See also the Terms of Service (draft) and the documentation.