生效日期:2026 年 8 月 6 日
知己AI(以下简称"本服务")由 Siege Investment(以下简称"我们")运营。本政策说明我们收集哪些信息、如何使用,以及你如何控制自己的数据。
部分功能需要第三方 AI 或数据服务处理你主动提交的数据。首次使用任何相关功能前,应用会在独立授权页说明下列数据、接收方与用途,并提供「暂不」和「同意并继续」。只有你主动选择同意后,我们才会把个人内容发送给这些第三方服务。选择「暂不」时,相关功能不会运行,也不会向这些第三方服务发送你的个人内容。
我们仅发送完成你所请求功能所必需的数据,不会向这些服务商出售个人信息。各服务商依照其适用的商业条款和隐私条款处理数据;我们要求服务商仅为已披露的功能目的处理数据,并对个人数据提供与本政策相同或同等的保护,包括适当的保密、安全、访问控制和删除措施。
登录用户可以随时在我 → 隐私与协议 → AI 数据共享撤回同意。撤回后我们会停止今后的第三方数据传输,相关功能在你再次同意前不可用;撤回不影响此前经你同意进行的处理。你仍可删除单项内容或注销账号。
设备控制默认关闭。知己AI只有在你明确开启并授权后才能控制设备。Mac 控制需要登录同一账号,并授予 macOS「辅助功能」与「屏幕录制」权限;安卓手机可安装知己AI手机控制端、开启其手机控制(无障碍)权限并使用配对码连接。仍支持 HDC 的华为手机也可经你授权的 USB 或无线调试连接。直接手动控制时,截图和指令只经我们的账号隔离中继传输;由 AI 控制电脑或安卓手机时均适用上方 OpenAI 披露。手机锁屏只允许唤醒与滑动,禁止 AI 点击锁屏键盘或输入凭据。完成后的文字输入载荷会立即清除,完成后的命令结果和截图通常在约一小时后从活跃中继删除。你可随时在设备控制页断开手机,或从 Mac 菜单栏关闭电脑控制。
用户创建的小应用在知己AI提供的隔离环境中运行。打开每一个小应用前,平台会根据该小应用已发布的代码生成并保存独立、版本化的能力与数据清单,显示小应用名称、创建者名称和账号,并逐项说明将启用的能力、涉及的数据、用途、接收方、保留及删除方式。可能列出的能力包括:应用内存储、应用数据库、向创建者提交结果与运行错误诊断、AI 生成、联网/平台/金融数据搜索、文字转语音及自动处理。当前版本不向用户创建的小应用开放麦克风、下载、访客文件或照片的选择、拖放、粘贴、读取、上传、列表或公开访问;主聊天中的可信附件功能与小应用隔离。
小应用数据库中的访客记录只对提交者本人和该小应用创建者可见,访客不能读取其他访客的记录。创建者视图中的记录可包含一个仅在该小应用内有效的随机访客标识,以及首次访问和更新时间;不向小应用代码或创建者提供你的知己AI账号 ID 或登录凭证。如果已获授权的小应用在当次 AI 请求中使用你在小应用内创建的图片(例如画布草图),该内容会发送给 OpenAI 处理当次请求,但不会作为小应用文件持久保存或公开;OpenAI 依其安全与保留规则处理。
在原生应用中,未登录或未授权时不会装载小应用。你可以选择「暂不」或「允许」;授权只对该小应用、当前清单版本及所列能力有效。清单新增或改变能力后,旧授权自动失效并会再次询问。创建者只能通过该小应用被授权的主人视图接收清单中明确说明的数据;平台不会把你的账号 ID、登录令牌或其他应用的数据交给用户创建的代码。
小应用在全局待办中只会写入通用通知,不复制你的提交正文或自动汇总正文。你可以在该小应用右上角菜单选择「撤回此小应用授权」。撤回会立即使既有能力会话失效、停止新的存储、AI、搜索、语音等请求,并从活跃系统删除你在该小应用中的访客行、个人存储、数据库记录、提交结果,以及可能包含其内容的自动汇总和相关通知;若你是创建者,也会停止并删除该小应用的自动处理计划。受限备份、安全日志及第三方依法或依其条款保留的记录适用本政策第五节。
以下非 AI 服务商仅为账号、支付、通知、诊断和地图显示等必要功能处理相应数据:
我们要求上述处理者仅为所列目的处理数据,并对个人数据提供与本政策相同或同等的保护。
你可以在应用内查看和更正个人资料、管理或撤回 AI 数据共享同意、删除单条或全部聊天记录、删除已上传的文件与声音、注销账号。如需导出数据副本或有任何隐私问题,请通过下方邮箱联系我们,我们会在 15 个工作日内回复。
本服务不面向 17 周岁以下的未成年人;用户创建的小应用属于成人功能,访问前还要求用户明确声明已满 18 周岁。如果我们发现误收集了未成年人信息,会尽快删除。
政策更新时,我们会修改本页顶部的生效日期;重大变更会在应用内显著提示。
Effective date: August 6, 2026
GNJ AI ("the Service") is operated by Siege Investment ("we", "us"). This policy explains what we collect, how we use it, and the controls you have.
To provide core features (AI replies, voice transcription, reminders, document generation, and cross-device computer or Android-phone control that you enable), personalize your experience, run billing, keep the Service secure, and comply with legal obligations.
Some features require third-party AI or data services to process data you choose to provide. Before you first use any such feature, the app presents a separate consent screen that identifies the data, recipients, and purposes below and offers Not Now and Agree & Continue. We send personal content to these third-party services only after you affirmatively agree. If you choose Not Now, the related features do not run and your personal content is not sent to these third-party services.
We send only data necessary to perform the feature you request and never sell personal information to these providers. Each provider processes data under its applicable commercial and privacy terms. We require providers to process data only for the disclosed feature purpose and to provide the same or equivalent protection for personal data described in this policy, including appropriate confidentiality, security, access-control, and deletion safeguards.
Signed-in users may withdraw consent at any time under Me → Privacy & Terms → AI Data Sharing; anonymous agent visitors can use the withdrawal control on that page. Withdrawal stops future transfers to third-party services, and related features remain unavailable until you agree again. It does not affect processing already performed with your consent. You may still delete individual content or your account.
Device Control is off by default. GNJ AI can control a device only after you expressly enable and authorize it. Mac control requires signing in to the same account and granting macOS Accessibility and Screen Recording permission. An Android phone can connect after you install the GNJ AI Phone Agent, enable its phone-control (Accessibility) permission, and enter its pairing code. Huawei phones that still support HDC can also connect through USB or wireless debugging that you authorize. During direct manual control, screenshots and commands travel only through our account-isolated relay. AI control of either a computer or Android phone is governed by the OpenAI disclosure above. On a phone lock screen, AI is limited to wake and swipe and cannot click the lock keypad or enter credentials. Typed-text payloads are erased immediately after completion, and completed command results and screenshots are normally removed from the active relay after about one hour. You can disconnect a phone from Device Control or disable computer control from the Mac menu bar at any time.
User-created mini-apps run in an isolated environment provided by GNJ AI. Before each mini-app opens, the platform generates and stores a separate, versioned capability and data-use manifest from its published code. The screen identifies the mini-app and its creator name and account, then lists each capability, data involved, purpose, recipients, retention, and deletion. Capabilities may include in-app storage, an app database, submissions and runtime-error diagnostics sent to the creator, AI generation, web/platform/financial-data search, text-to-speech, and automatic processing. This release does not expose microphone access, downloads, visitor file or photo selection, drag/drop, paste, reading, upload, listing, or public access to user-created mini-apps; trusted main-chat attachments are isolated from mini-apps.
Visitor records in a mini-app database are visible only to the submitting visitor and that mini-app's creator; a visitor cannot read another visitor's records. Creator-view records may include a random visitor identifier valid only within that mini-app, plus first-seen and updated times. Mini-app code and creators do not receive your GNJ AI account ID or login credentials. If an authorized mini-app uses an image you create inside the mini-app for a current AI request (for example, a canvas drawing), that content is sent to OpenAI for that request but is not retained or made public as a mini-app file; OpenAI processes it under its security and retention terms.
In the native app, a mini-app is not mounted while you are signed out or before permission is granted. You may choose Not Now or Allow. A grant applies only to that mini-app, the current manifest version, and the capabilities shown. Adding or changing a capability invalidates the old grant and asks again. A creator can receive only data described in the manifest through that mini-app's authorized owner view. User-authored code does not receive your account ID, login token, or data from other apps.
Mini-apps write only generic notices to the global task list; they do not copy your submission text or automatic-summary text there. You can choose Withdraw Mini-App Access from that mini-app's menu. Withdrawal immediately invalidates existing capability sessions, blocks new storage/AI/search/speech requests, and deletes your visitor row, personal storage, database records, submissions, and automatic summaries and related notifications that may contain that content from active systems. If you are the creator, it also stops and deletes the mini-app's automatic-processing schedules. Restricted backups, security logs, and records retained by processors under law or their terms are governed by Section 5.
These non-AI providers process only the data needed for account, payment, notification, diagnostic, and map-display functions: Twilio (SMS verification), Stripe (web payments), Apple (iOS in-app purchases and push notifications), Expo (mobile push delivery), Sentry (crash, error, and performance diagnostics), OpenStreetMap map tiles and Nominatim (precise coordinates or place-search terms only when you choose to send or search for a location, to display the pin-selection map and look up a place name), and Google Maps / Amap (selected coordinates when a location card is displayed or opened, to render a map or navigation link). We require each processor to use data only for the listed purpose and to provide the same or equivalent protection for personal data described in this policy.
Data is retained while your account exists and encrypted in transit. You can delete your account at any time in Settings → Delete Account; chats, files, voice samples, agents, mini-apps, friendships, and the account are then deleted from our active systems and the account cannot be restored. Restricted encrypted backups, security logs, and records already retained by processors under law or their terms may remain for a limited period and are automatically deleted or de-identified under their configured retention schedules, except transaction or security records that law requires us or a processor to retain. Residual copies are not used to continue providing the Service. Apple auto-renewable subscriptions must be canceled separately in iOS Settings → Apple ID → Subscriptions.
You can view and correct your profile, manage or withdraw AI data-sharing consent, delete chats, files and voices, and delete your account in-app. For a data export or any privacy question, contact us at the email below; we respond within 15 business days.
The Service is not directed at anyone under 17. User-created mini-apps are an adult feature and additionally require an explicit declaration that the user is at least 18 before access. If we learn we have collected data from a minor, we will delete it promptly.
We will update the effective date above and prominently notify you in-app of material changes.
Email: [email protected]