夥計Hooji
← 回首頁

隱私權政策

最後更新:2026 年 7 月 31 日

一句話總結:夥計沒有帳號系統,也沒有伺服器資料庫。你的支出紀錄只存在你的裝置與你自己的 iCloud,我們沒有副本、也無從讀取。唯一會離開裝置的,是你在使用 AI 記帳時說(或打)的那一句話——語音記帳時送出的是那一小段錄音,只用於當次辨識、用完即丟;iPhone 上可改成只用裝置端辨識(限 Apple 離線辨識支援的語言)。

一、適用範圍

本政策適用於 iPhone 與 Apple Watch 上的「夥計(Hooji)」App,以及本網站。夥計由位於台灣的個人開發者開發與維運,聯絡方式為 hooji.app@gmail.com

二、我們不收集什麼

  • 沒有註冊、沒有登入、沒有使用者帳號或密碼。
  • 不使用任何廣告、行為分析或使用者追蹤 SDK;App 的隱私清單中「追蹤」一欄為否。
  • 不收集你的姓名、Email、電話、聯絡人、位置、相簿、通訊錄或廣告識別碼。
  • 不收集你的支出紀錄——包含金額、商家、分類與備註。

三、留在你裝置上的資料

  • 支出紀錄(金額、幣別、內容、商家、分類、時間、備註、付款方式)儲存在你裝置的本機資料庫。
  • 若你的裝置已登入 iCloud,這些紀錄會透過 Apple 的 CloudKit 私有資料庫你自己的裝置之間同步。該資料位於你的 Apple 帳號底下,我們沒有存取權限。
  • 訂閱狀態由 Apple 的 StoreKit 提供與驗證;試用起始日期存放在你的 iCloud 鍵值儲存與本機 Keychain,用來判斷 7 天試用是否已使用過。這兩者都不會傳送給我們。
  • 配對的 Apple Watch 上的副本:手錶本身不保存完整帳目,但為了讓你抬腕就看到數字,iPhone 會把本月/今日的合計與最近 10 筆紀錄傳到手錶上顯示。這是你的兩台裝置之間由 Apple 的 WatchConnectivity 直接傳送,不經過我們的伺服器;iPhone 上的資料一有變動,就會推一份新的過去整包覆蓋。

四、使用 AI 記帳時,會送出什麼

只有在你使用 AI 一句話記帳(語音或文字)時,才會有資料離開你的裝置。每一次請求包含:

送出的內容說明
你說(或打)的那一句話長度上限 200 字。文字記帳、以及 iPhone 選擇「只用裝置端辨識」時,送出的就是這一行文字。
語音記帳時的那一小段錄音你說那一句話時錄下的短音檔(通常約 5 秒),送去轉成文字後接著解析。只用於當次辨識,辨識完就丟,我們不保存、不建立索引,也不與你的任何資料關聯。錄音何時開始、何時停止,見下方兩段說明。
送出時間與時區用來把「昨天午餐」這類說法換算成正確的日期。
一次性請求識別碼隨機產生,用來避免同一句話被重複記成兩筆;不對應到任何人。
來源(語音/文字)僅供解析使用。
你的記帳幣別例如 TWD。你沒說幣別時用它當預設,否則所有非台灣使用者的第一筆帳都會被記成台幣。
你的語系代碼例如 zh-Hant-TW。決定 AI 需要追問時用哪一種語言問你。

不會送出:你的姓名、Email、裝置識別碼、廣告識別碼、位置,以及你既有的任何一筆支出紀錄。若你只使用手動記帳,則不會有任何內容離開你的裝置。免費層在 iPhone 上不會呼叫 AI;Apple Watch 在尚未收到 iPhone 推來的方案狀態前,可能仍會送出一次——這是刻意的取捨,寧可讓付費使用者不被誤擋。

語音辨識在哪裡做:iPhone 押住金幣時,App 會同時做兩件事——用 Apple 的裝置端語音辨識即時把文字顯示在畫面上,以及把同一段麥克風音訊錄成音檔。放開後預設把音檔送去雲端辨識;上傳失敗或沒有網路時,改用裝置端已經聽到的文字送出。之所以預設走雲端,是因為 Apple 的裝置端辨識一次只能綁定一種語言、沒有自動偵測語言的模式,雙語使用者、或一句話裡夾雜不同語言的說法必然有一邊聽不準;雲端模型會自動判斷語言並處理語言切換。你可以在 App 內「設定 → 語音辨識 → 只用裝置端辨識」關掉雲端,錄音就完全不會離開你的手機(可用的語言以 Apple 的離線辨識涵蓋範圍為限,辨識品質也受上述限制)。

Apple Watch:watchOS 沒有提供任何語音轉文字的 API,因此手錶上的語音記帳一律是把錄音送去雲端辨識。手錶會自己連線,不經過 iPhone。沒有網路時,錄音會暫存在手錶本機的待送佇列(最多 20 筆、保留 7 天),回到線上後自動送出;未送出前不會被記成一筆帳。

手錶會在你打開 App 時主動開始錄音:這是為了讓你抬起手腕、講一句、放下就好,全程不必碰螢幕(點 Smart Stack 卡片進來也一樣)。三件事值得你知道:每次打開只會自動錄第一次,之後要再記一筆仍是押住金幣;你說完停下來它就結束錄音,如果從頭到尾沒聽到人聲,那段錄音會直接在手錶上丟掉,不會被上傳;以及你可以在 iPhone 的「設定 → Apple Watch → 手錶開啟就自動錄音」關掉它,關掉後一律改用押住金幣。手錶未取得麥克風權限時不會自動錄音,也不會為此主動跳出權限請求。

五、誰會處理這句話(與那段錄音)

  • Cloudflare, Inc.(Cloudflare Workers)——我們的無狀態中繼,用途是代為保管 AI 服務金鑰並轉送請求。它不寫入任何資料庫、不保存請求內容:音檔在它手上只是一段轉手的串流,不會寫進任何儲存服務(沒有 R2/KV/D1)。作為基礎設施供應商,Cloudflare 可能產生短暫的營運層級日誌。
  • OpenAI, L.L.C.——實際執行語音轉錄與語意解析。語音轉錄使用 OpenAI 的音訊轉錄端點,該端點的資料保留政策為不用於訓練模型(training = No),且不為濫用偵測保留(abuse monitoring = None)語意解析則呼叫對話模型,我們已設定關閉對話保存;依 OpenAI 的 API 資料使用政策,透過 API 傳送的內容預設不會用於訓練模型,但 OpenAI 仍可能為濫用偵測目的短暫保留。
  • Apple Inc.——iCloud 同步與訂閱交易,適用 Apple 自己的隱私權政策。

正因為第三方可能為濫用偵測短暫保留該段文字,我們在 App 的隱私清單中誠實申報這項為「其他使用者內容」;語音記帳送出的那段錄音則申報為「音訊資料」,用途皆為 App 功能。兩者都標示為未與你的身分連結、且不用於追蹤——請求本身不帶任何使用者識別碼。

六、我們保存多久

我們沒有資料庫,因此沒有可保存的內容。中繼在轉送完該次請求後即結束,不留下副本。語音記帳的錄音只在該次請求中被轉成文字,之後即消失,我們手上沒有任何錄音檔。

七、你的權利與控制

  • 刪除全部資料:App 內「設定 → 刪除所有資料」,經兩次確認後永久刪除本機與 iCloud 上的所有支出,無法復原。
  • 沒有帳號要刪:因為沒有帳號系統,也就沒有需要另行刪除的伺服器資料。
  • 不想讓錄音離開手機:iPhone 上到「設定 → 語音辨識」開啟「只用裝置端辨識」,語音就改由裝置端處理,只送出辨識後的文字(限 Apple 離線辨識支援的語言;不支援的語言開啟後語音記帳會停用)。
  • 不想用 AI:只使用手動記帳,就不會有任何內容離開裝置。
  • 法定權利:你在個人資料保護法、GDPR 等法規下的查詢、更正與刪除權,因資料就在你手上,可直接於 App 內完成;需要協助請來信。

八、兒童

夥計並非針對 13 歲以下兒童設計,也不會刻意收集兒童的個人資料。

九、安全

  • App 與中繼之間一律使用 HTTPS 加密連線。
  • AI 服務金鑰只存在中繼的加密環境變數中,絕不隨 App 散佈;App 內不含任何 AI 服務金鑰。
  • 正式環境不記錄完整的語音或文字內容,音檔也不會被寫入任何儲存服務。

十、政策變更

本政策若有實質變更,會更新本頁的「最後更新」日期;重大變更會另於 App 內告知。

十一、聯絡我們

對隱私有任何疑問,請寄信到 hooji.app@gmail.com

Privacy Policy

Last updated: 31 July 2026

In one sentence: Hooji has no accounts and no server database. Your expenses exist only on your device and in your own iCloud — we hold no copy and cannot read them. The only thing that ever leaves your device is the single sentence you say or type when you use AI logging — for voice entries, the short clip of you saying it, used for that one transcription and then discarded. On iPhone you can switch to on-device recognition only, and then even that stays on your phone — for the languages Apple covers offline.

1. Scope

This policy covers the Hooji app for iPhone and Apple Watch, and this website. Hooji is built and operated by an independent developer based in Taiwan. Contact: hooji.app@gmail.com.

2. What we do not collect

  • No sign-up, no sign-in, no user account or password.
  • No advertising, behavioural analytics or tracking SDKs of any kind. The app's privacy manifest declares tracking as false.
  • No name, email, phone number, contacts, location, photos or advertising identifiers.
  • No expense records — not the amounts, merchants, categories or notes.

3. Data that stays on your device

  • Expenses (amount, currency, description, merchant, category, time, note, payment method) are stored in a local database on your device.
  • If your device is signed in to iCloud, those records sync between your own devices through Apple's CloudKit private database. That data sits under your Apple account and we have no access to it.
  • Subscription status comes from Apple's StoreKit. The trial start date is stored in your iCloud key-value store and in the device Keychain so we can tell whether the 7-day trial has been used. Neither is ever sent to us.
  • A copy on your paired Apple Watch: the watch keeps no full ledger of its own, but so that the numbers are there when you raise your wrist, your iPhone sends it the month and today totals along with your last 10 entries to display. That travels directly between your two devices over Apple's WatchConnectivity and never through our servers; whenever the data on your iPhone changes, a fresh copy is pushed over that replaces the previous one wholesale.

4. What is sent when you use AI logging

Data leaves your device only when you use AI one-sentence logging (by voice or text). Each request contains:

What is sentWhy
The sentence you said or typedUp to 200 characters. This is what is sent for typed entries, and on iPhone when you choose “On-device recognition only”.
The short clip of speech, for voice entriesThe audio recorded while you say the sentence (usually about 5 seconds), sent to be turned into text and then parsed. Used for that one transcription and then discarded — we do not store it, index it, or associate it with anything about you. When recording starts and stops is described in the two paragraphs below.
Time of sending and time zoneSo that phrasings like “yesterday's lunch” resolve to the right date.
A one-off request identifierRandomly generated, used to stop the same sentence being logged twice. It maps to no person.
Source (voice or text)Used for parsing only.
Your logging currencyFor example TWD. Used as the default when you do not say a currency — without it every first entry outside Taiwan would be recorded in New Taiwan dollars.
Your locale codeFor example en-US. Decides which language the AI uses if it needs to ask you a follow-up question.

Not sent: your name, email, device identifiers, advertising identifiers, location, or any of your existing expenses. If you only log manually, nothing leaves your device at all. On the free tier your iPhone does not call the AI; an Apple Watch may still send one request before it has received the plan status pushed from your iPhone — a deliberate trade-off, so that paying users are never wrongly blocked.

Where speech is recognised: while you hold the coin on iPhone, the app does two things at once — it runs Apple's on-device speech recognition so you can watch the words appear, and it records the same microphone input to an audio file. When you release, the clip is sent for cloud transcription by default; if the upload fails or you have no connection, the text heard on device is sent instead. Cloud transcription is the default because Apple's on-device recogniser can only be bound to one language at a time and has no automatic language detection, so bilingual speech — or a sentence that switches languages halfway — is always misheard in one direction. The cloud model works out the language itself and handles the switching. You can turn the cloud off under Settings → Speech recognition → On-device recognition only, after which no audio leaves your phone (only for the languages Apple covers offline, and with the language limitation above).

Apple Watch: watchOS offers no speech-to-text API at all, so voice logging on the watch always sends the clip for cloud transcription. The watch connects on its own and does not go through your iPhone. With no connection the clip waits in a queue on the watch itself (up to 20 clips, kept for 7 days) and is sent automatically once you are back online; nothing is logged as an expense until it has been sent.

The watch starts listening when you open the app: this is so you can raise your wrist, say one sentence and lower it again without touching the screen (the same happens when you tap the Smart Stack card). Three things worth knowing: it does this only once per launch — after that you press and hold the coin as usual; it stops recording when you stop speaking, and if it never hears any speech the clip is discarded on the watch and is never uploaded; and you can turn it off under Settings → Apple Watch → Auto-record on Apple Watch on your iPhone, after which press-and-hold is the only way to record. The watch will not auto-record without microphone permission, and never raises a permission prompt on its own to get it.

5. Who processes that sentence (and that clip)

  • Cloudflare, Inc. (Cloudflare Workers) — our stateless relay, whose only job is to hold the AI service key and forward the request. It writes to no database and stores no request content: an audio clip is only a stream passing through it and is never written to any storage service (no R2, KV or D1). As an infrastructure provider, Cloudflare may produce short-lived operational logs.
  • OpenAI, L.L.C. — performs both the speech-to-text and the parsing. We call it with conversation storage disabled. Under OpenAI's API data usage policy, content sent through the API is not used to train their models by default. Speech-to-text runs on a different endpoint whose policy is no training and no abuse-monitoring retention — meaning the audio clip is not kept at all. The text may still be retained briefly for abuse monitoring.
  • Apple Inc. — iCloud sync and subscription transactions, governed by Apple's own privacy policy.

Because a third party may briefly retain that text for abuse monitoring, we declare it honestly in the app's privacy manifest as “other user content”; the clip sent for voice entries is declared as “audio data”. Both are declared for app functionality and marked as not linked to your identity and not used for tracking — the request carries no user identifier of any kind.

6. How long we keep things

We have no database, so there is nothing for us to keep. The relay finishes when it has forwarded the request and retains no copy; for voice entries the audio clip is discarded once it has been turned into text, and is never written to storage.

7. Your rights and controls

  • Delete everything: Settings → Delete all data. After two confirmations it permanently erases every expense on the device and in iCloud. This cannot be undone.
  • No account to delete: there is no account system, so there is no server-side data left to remove.
  • Keep recordings on your phone: on iPhone, turn on Settings → Speech recognition → On-device recognition only. Speech is then handled on the device and only the recognised text is sent. This covers the languages Apple supports offline; for a language it does not support, voice logging is disabled while the setting is on.
  • Prefer no AI: use manual logging only and nothing ever leaves your device.
  • Legal rights: rights of access, rectification and erasure under GDPR, Taiwan's Personal Data Protection Act and similar laws can be exercised directly in the app, because the data is in your hands. Email us if you would like help.

8. Children

Hooji is not directed at children under 13 and does not knowingly collect personal data from them.

9. Security

  • All traffic between the app and the relay uses HTTPS.
  • The AI service key lives only in the relay's encrypted environment variables and is never shipped inside the app.
  • Production systems do not log the full contents of what you said or typed, and audio is never written to any storage service.

10. Changes to this policy

If this policy changes materially we update the “Last updated” date on this page, and significant changes are also surfaced in the app.

11. Contact

Questions about privacy? Email hooji.app@gmail.com.

プライバシーポリシー

最終更新:2026 年 7 月 31 日

ひと言で:Hooji にはアカウント機能もサーバーデータベースもありません。あなたの支出はお使いのデバイスとご自身の iCloud にのみ存在し、私たちに複製はなく、読み取ることもできません。デバイスから出るのは、AI で記録するときに話した(または入力した)そのひと言だけです。音声で記録する場合は、それを話している短い録音が送られ、その一回の認識にだけ使われたあと破棄されます。iPhone では「デバイス上の認識のみ」に切り替えることもできます(Apple がオフライン認識に対応している言語に限ります)。

1. 適用範囲

本ポリシーは、iPhone および Apple Watch 向けアプリ「Hooji」と、本ウェブサイトに適用されます。Hooji は台湾を拠点とする個人開発者が開発・運営しています。連絡先:hooji.app@gmail.com

2. 収集しないもの

  • 会員登録もサインインもなく、ユーザーアカウントもパスワードもありません。
  • 広告・行動分析・トラッキングの SDK は一切使用していません。アプリのプライバシーマニフェストでも、トラッキングは「なし」と申告しています。
  • 氏名、メールアドレス、電話番号、連絡先、位置情報、写真、広告識別子は収集しません。
  • 支出の記録そのもの——金額・店舗・カテゴリ・メモ——も収集しません。

3. デバイスに残るデータ

  • 支出(金額、通貨、内容、店舗、カテゴリ、日時、メモ、支払い方法)は、デバイス内のローカルデータベースに保存されます。
  • デバイスが iCloud にサインインしている場合、これらの記録は Apple の CloudKit プライベートデータベースを通じてあなた自身のデバイス間で同期されます。そのデータはあなたの Apple アカウントの下にあり、私たちにアクセス権はありません。
  • サブスクリプションの状態は Apple の StoreKit から取得します。お試しの開始日は、7 日間のお試しをすでに使ったかどうかを判断するために、ご自身の iCloud キーバリューストアとデバイスのキーチェーンに保存されます。どちらも私たちに送信されることはありません。
  • ペアリング済みの Apple Watch にある複製:Apple Watch 自身は帳簿全体を持ちませんが、腕を上げたときにすぐ数字が見えるように、iPhone が今月・今日の合計と直近 10 件の記録を Apple Watch に送って表示します。これはあなたの 2 つのデバイスのあいだで Apple の WatchConnectivity によって直接やり取りされ、私たちのサーバーを経由しません。iPhone 側のデータが変わるたびに新しい一式が送られ、前の内容はまとめて置き換わります。

4. AI で記録するときに送信されるもの

データがデバイスから出るのは、AI のひと言記録(音声または文字)を使うときだけです。各リクエストに含まれるのは次のとおりです。

送信されるもの理由
話した(または入力した)そのひと言最大 200 文字。文字で記録する場合、および iPhone で「デバイス上の認識のみ」を選んでいる場合は、この 1 行のテキストが送られます。
音声で記録する場合の短い録音そのひと言を話しているあいだに録音された短い音声(通常 5 秒程度)で、文字に変換したうえで解析されます。その一回の認識にだけ使い、終わったら破棄します。保存も、索引付けも、あなたに関する情報との紐付けも行いません。録音がいつ始まり、いつ止まるかは下の 2 段落で説明しています。
送信時刻とタイムゾーン「昨日のランチ」のような言い方を正しい日付に解決するために使います。
1 回限りのリクエスト識別子ランダムに生成され、同じひと言が 2 件として記録されるのを防ぎます。個人には対応しません。
入力方法(音声/文字)解析にのみ使用します。
記録に使う通貨例:JPY。通貨を言わなかったときの既定値として使います。これがないと、台湾以外の利用者の最初の 1 件がすべて台湾ドルとして記録されてしまいます。
ロケールコード例:ja-JP。AI が聞き返す必要があるとき、どの言語で尋ねるかを決めます。

送信されないもの:氏名、メールアドレス、デバイス識別子、広告識別子、位置情報、そしてこれまでに記録した支出。手動での記録だけを使う場合は、何もデバイスの外に出ません。無料プランでは iPhone から AI を呼び出しません。ただし Apple Watch は、iPhone から送られるプランの状態をまだ受け取っていない段階では 1 回だけ送信することがあります——これは意図的な判断で、有料の利用者を誤って止めないことを優先しています。

音声認識をどこで行うか:iPhone でコインを長押ししているあいだ、アプリは 2 つのことを同時に行います。Apple のデバイス上の音声認識で聞き取った文字をその場に表示することと、同じマイク入力を音声ファイルに録音することです。指を離すと、既定ではその録音をクラウドの音声認識に送ります。アップロードに失敗した場合や接続がない場合は、デバイス上で聞き取ったテキストを代わりに送ります。既定でクラウドを使うのは、Apple のデバイス上の認識が一度に 1 つの言語しか設定できず、言語の自動判別もないためです。複数の言語を使う人、あるいは 1 つの文の途中で言語が切り替わる話し方では、どちらかが必ず正しく聞き取れません。クラウドのモデルは言語を自分で判別し、切り替わりにも対応します。アプリ内の「設定 → 音声認識 → デバイス上の認識のみ」でクラウドをオフにでき、その場合は音声が一切 iPhone の外に出ません(対応できるのは Apple のオフライン認識がカバーしている言語に限られ、認識の品質も上記の制約を受けます)。

Apple Watch:watchOS には音声を文字に変換する API がまったく提供されていないため、Apple Watch での音声記録は常に録音をクラウドの音声認識に送ります。Apple Watch は自分で通信し、iPhone を経由しません。接続がないときは、録音は Apple Watch 内の送信待ちキューに一時保存され(最大 20 件、7 日間)、オンラインに戻ると自動的に送信されます。送信されるまで、支出として記録されることはありません。

Apple Watch はアプリを開いたときに自分から録音を始めます:腕を上げて、ひと言話して、下ろすだけで済むようにするためです(Smart Stack のカードから開いたときも同じです)。知っておいていただきたいことが 3 つあります。自動で録音するのは起動ごとに一度だけで、続けてもう 1 件記録するときはこれまでどおりコインを長押しします。話し終えて止まると録音も終わり、最初から最後まで人の声が聞こえなかった場合、その録音は Apple Watch 上で破棄され、アップロードされません。そして iPhone の「設定 → Apple Watch → Apple Watch で自動録音」からオフにでき、オフにすると常に長押しでの録音になります。マイクの許可が得られていない場合、Apple Watch は自動録音を行わず、そのために許可のダイアログを自分から出すこともありません。

5. そのひと言(とその録音)を処理する事業者

  • Cloudflare, Inc.(Cloudflare Workers)——ステートレスな中継です。役割は AI サービスのキーを預かってリクエストを転送することだけで、データベースへの書き込みもリクエスト内容の保存も行いません。音声は中継を通り抜けるストリームにすぎず、いかなるストレージにも書き込まれません(R2・KV・D1 は使っていません)。インフラ事業者として、Cloudflare が短期間の運用ログを生成することはあります。
  • OpenAI, L.L.C.——音声からテキストへの変換と、意味の解析を実際に行います。音声認識には OpenAI の音声文字起こしエンドポイントを使用しており、このエンドポイントのデータ保持方針はモデルの学習に使用しない(training = No)、不正利用の監視のためにも保持しない(abuse monitoring = None)です。意味の解析では対話モデルを呼び出し、会話の保存を無効に設定しています。OpenAI の API データ利用ポリシーによれば、API 経由で送信された内容は既定ではモデルの学習に使用されませんが、不正利用の監視のために短期間保持される場合があります。
  • Apple Inc.——iCloud 同期とサブスクリプションの取引。Apple 自身のプライバシーポリシーが適用されます。

第三者が不正利用の監視のためにそのテキストを短期間保持する可能性があるため、アプリのプライバシーマニフェストではこれを「その他のユーザーコンテンツ」として正直に申告しています。音声で記録するときに送られる録音は「音声データ」として申告しており、いずれも用途はアプリの機能です。どちらもあなたの身元と紐付けられておらず、トラッキングにも使用しないと申告しています——リクエストにはいかなる利用者識別子も含まれません。

6. 保持期間

私たちにはデータベースがないため、保持するものがありません。中継はそのリクエストを転送し終えた時点で終了し、複製を残しません。音声で記録した録音はそのリクエストのなかで文字に変換されたあと消え、私たちの手元に音声ファイルは一切残りません。

7. あなたの権利と操作

  • すべてのデータを削除する:アプリ内の「設定 → すべてのデータを削除」。2 回の確認を経て、このデバイスと iCloud にあるすべての支出を完全に削除します。取り消せません。
  • 削除すべきアカウントはありません:アカウント機能がないため、別途削除が必要なサーバー側のデータもありません。
  • 録音を iPhone の外に出したくないとき:iPhone の「設定 → 音声認識」で「デバイス上の認識のみ」をオンにすると、音声はデバイス上で処理され、認識後のテキストだけが送信されます(Apple のオフライン認識が対応している言語に限ります。対応していない言語では音声での記録が無効になります)。
  • AI を使いたくないとき:手動での記録だけを使えば、何もデバイスの外に出ません。
  • 法令上の権利:個人情報保護法や GDPR などに基づく開示・訂正・削除の権利は、データがあなたの手元にあるため、アプリ内で直接行使できます。サポートが必要な場合はメールでご連絡ください。

8. お子様について

Hooji は 13 歳未満のお子様を対象としておらず、お子様の個人データを意図的に収集することもありません。

9. セキュリティ

  • アプリと中継のあいだの通信は、すべて HTTPS で暗号化されています。
  • AI サービスのキーは中継の暗号化された環境変数にのみ存在し、アプリに同梱して配布することは決してありません。アプリに AI サービスのキーは含まれていません。
  • 本番環境では、話した内容や入力した内容の全文を記録せず、音声もいかなるストレージにも書き込みません。

10. 本ポリシーの変更

本ポリシーに実質的な変更があった場合は、このページの「最終更新」の日付を更新します。重要な変更についてはアプリ内でもお知らせします。

11. お問い合わせ

プライバシーに関するご質問は hooji.app@gmail.com までメールでお願いします。