知己AI 隐私政策

生效日期:2026 年 8 月 6 日

中文English用户协议 →

知己AI(以下简称"本服务")由 Siege Investment(以下简称"我们")运营。本政策说明我们收集哪些信息、如何使用,以及你如何控制自己的数据。

一、我们收集的信息

二、我们如何使用信息

三、第三方 AI 与数据服务、数据共享及同意

部分功能需要第三方 AI 或数据服务处理你主动提交的数据。首次使用任何相关功能前,应用会在独立授权页说明下列数据、接收方与用途,并提供「暂不」「同意并继续」。只有你主动选择同意后,我们才会把个人内容发送给这些第三方服务。选择「暂不」时,相关功能不会运行,也不会向这些第三方服务发送你的个人内容。

  • OpenAI:处理你输入的文字、为回答所必需的近期对话和记忆/知识库片段、设备语言、时区、基于 IP 的粗略地区,以及你主动选择的精确位置、图片、文件、视频或转写文本;用于生成回复、理解或生成内容、运行小应用内 AI、创建或修改小应用,以及在好友房发送前检查你选择的图片和文件是否符合社区规范。只有当你明确要求 AI 操作电脑或已连接的安卓手机时,相应设备的当前截图和操作结果也会发送给 OpenAI,用于理解画面、决定下一动作并验证请求结果。语音转文字时还会处理语音录音与语言提示并返回转写。锁屏 PIN、密码和生物识别不得交给 AI;你可在设备控制页本人接管输入,生物识别仍须在安卓手机上完成。
  • MiniMax API:仅当你主动使用声音克隆、试听或语音合成功能时,处理你提交的声音样本和需要合成的文字;用于语音合成和生成你的克隆音色。
  • Exa:处理根据你的联网搜索请求形成的搜索词,用于检索公开网页结果。
  • JustOneAPI:处理根据你的社交平台搜索请求形成的搜索词,用于检索公开社交平台内容。
  • Firecrawl:当你要求截取/读取网页时,处理你指定的网页 URL;当你要求造或修改小应用后,还会接收该小应用的一次性预览 URL 与页面内容,用于生成应用瓦片截图。
  • SerpApi:仅当你要求金融市场或其他结构化搜索数据时,处理搜索词、证券代码和查询参数,用于返回公开搜索结果与行情。

我们仅发送完成你所请求功能所必需的数据,不会向这些服务商出售个人信息。各服务商依照其适用的商业条款和隐私条款处理数据;我们要求服务商仅为已披露的功能目的处理数据,并对个人数据提供与本政策相同或同等的保护,包括适当的保密、安全、访问控制和删除措施。

登录用户可以随时在我 → 隐私与协议 → AI 数据共享撤回同意。撤回后我们会停止今后的第三方数据传输,相关功能在你再次同意前不可用;撤回不影响此前经你同意进行的处理。你仍可删除单项内容或注销账号。

电脑与安卓手机控制

设备控制默认关闭。知己AI只有在你明确开启并授权后才能控制设备。Mac 控制需要登录同一账号,并授予 macOS「辅助功能」与「屏幕录制」权限;安卓手机可安装知己AI手机控制端、开启其手机控制(无障碍)权限并使用配对码连接。仍支持 HDC 的华为手机也可经你授权的 USB 或无线调试连接。直接手动控制时,截图和指令只经我们的账号隔离中继传输;由 AI 控制电脑或安卓手机时均适用上方 OpenAI 披露。手机锁屏只允许唤醒与滑动,禁止 AI 点击锁屏键盘或输入凭据。完成后的文字输入载荷会立即清除,完成后的命令结果和截图通常在约一小时后从活跃中继删除。你可随时在设备控制页断开手机,或从 Mac 菜单栏关闭电脑控制。

用户创建的小应用

用户创建的小应用在知己AI提供的隔离环境中运行。打开每一个小应用前,平台会根据该小应用已发布的代码生成并保存独立、版本化的能力与数据清单,显示小应用名称、创建者名称和账号,并逐项说明将启用的能力、涉及的数据、用途、接收方、保留及删除方式。可能列出的能力包括:应用内存储、应用数据库、向创建者提交结果与运行错误诊断、AI 生成、联网/平台/金融数据搜索、文字转语音及自动处理。当前版本不向用户创建的小应用开放麦克风、下载、访客文件或照片的选择、拖放、粘贴、读取、上传、列表或公开访问;主聊天中的可信附件功能与小应用隔离。

小应用数据库中的访客记录只对提交者本人和该小应用创建者可见,访客不能读取其他访客的记录。创建者视图中的记录可包含一个仅在该小应用内有效的随机访客标识,以及首次访问和更新时间;不向小应用代码或创建者提供你的知己AI账号 ID 或登录凭证。如果已获授权的小应用在当次 AI 请求中使用你在小应用内创建的图片(例如画布草图),该内容会发送给 OpenAI 处理当次请求,但不会作为小应用文件持久保存或公开;OpenAI 依其安全与保留规则处理。

在原生应用中,未登录或未授权时不会装载小应用。你可以选择「暂不」「允许」;授权只对该小应用、当前清单版本及所列能力有效。清单新增或改变能力后,旧授权自动失效并会再次询问。创建者只能通过该小应用被授权的主人视图接收清单中明确说明的数据;平台不会把你的账号 ID、登录令牌或其他应用的数据交给用户创建的代码。

小应用在全局待办中只会写入通用通知,不复制你的提交正文或自动汇总正文。你可以在该小应用右上角菜单选择「撤回此小应用授权」。撤回会立即使既有能力会话失效、停止新的存储、AI、搜索、语音等请求,并从活跃系统删除你在该小应用中的访客行、个人存储、数据库记录、提交结果,以及可能包含其内容的自动汇总和相关通知;若你是创建者,也会停止并删除该小应用的自动处理计划。受限备份、安全日志及第三方依法或依其条款保留的记录适用本政策第五节。

四、其他第三方处理者

以下非 AI 服务商仅为账号、支付、通知、诊断和地图显示等必要功能处理相应数据:

  • Twilio(美国)— 短信验证码;
  • Stripe(美国)— 网页端支付;
  • Apple — iOS 应用内购买与推送通知;
  • Expo — 移动端推送通知分发。
  • Sentry — 应用崩溃、错误与性能诊断。
  • OpenStreetMap 地图瓦片与 Nominatim — 仅在你主动发送位置或搜索地点时处理经纬度或地点搜索词,用于显示选点地图并查询可读地点名称。
  • Google Maps / 高德地图(Amap) — 当应用显示或打开你选择的位置卡片时处理该位置坐标,用于渲染地图或导航链接。

我们要求上述处理者仅为所列目的处理数据,并对个人数据提供与本政策相同或同等的保护。

五、数据保留与删除

六、你的权利

你可以在应用内查看和更正个人资料、管理或撤回 AI 数据共享同意、删除单条或全部聊天记录、删除已上传的文件与声音、注销账号。如需导出数据副本或有任何隐私问题,请通过下方邮箱联系我们,我们会在 15 个工作日内回复。

七、未成年人

本服务不面向 17 周岁以下的未成年人;用户创建的小应用属于成人功能,访问前还要求用户明确声明已满 18 周岁。如果我们发现误收集了未成年人信息,会尽快删除。

八、政策变更

政策更新时,我们会修改本页顶部的生效日期;重大变更会在应用内显著提示。

九、联系我们

邮箱:[email protected]


GNJ AI Privacy Policy

Effective date: August 6, 2026

GNJ AI ("the Service") is operated by Siege Investment ("we", "us"). This policy explains what we collect, how we use it, and the controls you have.

1. Information We Collect

2. How We Use It

To provide core features (AI replies, voice transcription, reminders, document generation, and cross-device computer or Android-phone control that you enable), personalize your experience, run billing, keep the Service secure, and comply with legal obligations.

3. Third-Party AI and Data Services, Data Sharing & Consent

Some features require third-party AI or data services to process data you choose to provide. Before you first use any such feature, the app presents a separate consent screen that identifies the data, recipients, and purposes below and offers Not Now and Agree & Continue. We send personal content to these third-party services only after you affirmatively agree. If you choose Not Now, the related features do not run and your personal content is not sent to these third-party services.

  • OpenAI: text you enter; recent conversation context and relevant memory or knowledge-base excerpts needed for a response; device language, timezone, coarse IP-based region; and precise location, images, files, videos, or transcripts you choose to provide. Purposes include generating replies, understanding or generating content, running AI inside mini-apps, building or editing mini-apps, and checking selected friend-room attachments before sharing. Only when you explicitly ask AI to operate your computer or connected Android phone are that device's current screenshot and action result also sent to OpenAI to understand the screen, choose the next action, and verify the requested outcome. Speech-to-text also processes voice recordings and language hints to return a transcript. Lock-screen PINs, passwords, and biometrics are never delegated to AI; you can enter credentials yourself in device control, while biometrics remain local to the Android phone.
  • MiniMax API: only when you choose voice cloning, preview, or speech synthesis, it processes the voice sample you submit and the text to synthesize. The purposes are speech synthesis and generating your cloned voice.
  • Exa: search terms derived from your web-search request, used to retrieve public web results.
  • JustOneAPI: search terms derived from your social-platform search request, used to retrieve public social-platform content.
  • Firecrawl: when you ask to capture or read a webpage, it receives the URL you specify; after you ask to build or edit a mini-app, it also receives that mini-app's one-use preview URL and page content to create the app tile screenshot.
  • SerpApi: only when you request financial-market or other structured search data, it processes search terms, security identifiers, and query parameters used to return public search results and quotes.

We send only data necessary to perform the feature you request and never sell personal information to these providers. Each provider processes data under its applicable commercial and privacy terms. We require providers to process data only for the disclosed feature purpose and to provide the same or equivalent protection for personal data described in this policy, including appropriate confidentiality, security, access-control, and deletion safeguards.

Signed-in users may withdraw consent at any time under Me → Privacy & Terms → AI Data Sharing; anonymous agent visitors can use the withdrawal control on that page. Withdrawal stops future transfers to third-party services, and related features remain unavailable until you agree again. It does not affect processing already performed with your consent. You may still delete individual content or your account.

Computer and Android Phone Control

Device Control is off by default. GNJ AI can control a device only after you expressly enable and authorize it. Mac control requires signing in to the same account and granting macOS Accessibility and Screen Recording permission. An Android phone can connect after you install the GNJ AI Phone Agent, enable its phone-control (Accessibility) permission, and enter its pairing code. Huawei phones that still support HDC can also connect through USB or wireless debugging that you authorize. During direct manual control, screenshots and commands travel only through our account-isolated relay. AI control of either a computer or Android phone is governed by the OpenAI disclosure above. On a phone lock screen, AI is limited to wake and swipe and cannot click the lock keypad or enter credentials. Typed-text payloads are erased immediately after completion, and completed command results and screenshots are normally removed from the active relay after about one hour. You can disconnect a phone from Device Control or disable computer control from the Mac menu bar at any time.

User-Created Mini-Apps

User-created mini-apps run in an isolated environment provided by GNJ AI. Before each mini-app opens, the platform generates and stores a separate, versioned capability and data-use manifest from its published code. The screen identifies the mini-app and its creator name and account, then lists each capability, data involved, purpose, recipients, retention, and deletion. Capabilities may include in-app storage, an app database, submissions and runtime-error diagnostics sent to the creator, AI generation, web/platform/financial-data search, text-to-speech, and automatic processing. This release does not expose microphone access, downloads, visitor file or photo selection, drag/drop, paste, reading, upload, listing, or public access to user-created mini-apps; trusted main-chat attachments are isolated from mini-apps.

Visitor records in a mini-app database are visible only to the submitting visitor and that mini-app's creator; a visitor cannot read another visitor's records. Creator-view records may include a random visitor identifier valid only within that mini-app, plus first-seen and updated times. Mini-app code and creators do not receive your GNJ AI account ID or login credentials. If an authorized mini-app uses an image you create inside the mini-app for a current AI request (for example, a canvas drawing), that content is sent to OpenAI for that request but is not retained or made public as a mini-app file; OpenAI processes it under its security and retention terms.

In the native app, a mini-app is not mounted while you are signed out or before permission is granted. You may choose Not Now or Allow. A grant applies only to that mini-app, the current manifest version, and the capabilities shown. Adding or changing a capability invalidates the old grant and asks again. A creator can receive only data described in the manifest through that mini-app's authorized owner view. User-authored code does not receive your account ID, login token, or data from other apps.

Mini-apps write only generic notices to the global task list; they do not copy your submission text or automatic-summary text there. You can choose Withdraw Mini-App Access from that mini-app's menu. Withdrawal immediately invalidates existing capability sessions, blocks new storage/AI/search/speech requests, and deletes your visitor row, personal storage, database records, submissions, and automatic summaries and related notifications that may contain that content from active systems. If you are the creator, it also stops and deletes the mini-app's automatic-processing schedules. Restricted backups, security logs, and records retained by processors under law or their terms are governed by Section 5.

4. Other Third-Party Processors

These non-AI providers process only the data needed for account, payment, notification, diagnostic, and map-display functions: Twilio (SMS verification), Stripe (web payments), Apple (iOS in-app purchases and push notifications), Expo (mobile push delivery), Sentry (crash, error, and performance diagnostics), OpenStreetMap map tiles and Nominatim (precise coordinates or place-search terms only when you choose to send or search for a location, to display the pin-selection map and look up a place name), and Google Maps / Amap (selected coordinates when a location card is displayed or opened, to render a map or navigation link). We require each processor to use data only for the listed purpose and to provide the same or equivalent protection for personal data described in this policy.

5. Retention & Deletion

Data is retained while your account exists and encrypted in transit. You can delete your account at any time in Settings → Delete Account; chats, files, voice samples, agents, mini-apps, friendships, and the account are then deleted from our active systems and the account cannot be restored. Restricted encrypted backups, security logs, and records already retained by processors under law or their terms may remain for a limited period and are automatically deleted or de-identified under their configured retention schedules, except transaction or security records that law requires us or a processor to retain. Residual copies are not used to continue providing the Service. Apple auto-renewable subscriptions must be canceled separately in iOS Settings → Apple ID → Subscriptions.

6. Your Rights

You can view and correct your profile, manage or withdraw AI data-sharing consent, delete chats, files and voices, and delete your account in-app. For a data export or any privacy question, contact us at the email below; we respond within 15 business days.

7. Children

The Service is not directed at anyone under 17. User-created mini-apps are an adult feature and additionally require an explicit declaration that the user is at least 18 before access. If we learn we have collected data from a minor, we will delete it promptly.

8. Changes

We will update the effective date above and prominently notify you in-app of material changes.

9. Contact

Email: [email protected]