隐私政策
ZovaX AI Inc.(「我们」)运营 ZovaX IDE 及相关服务。本政策说明我们如何收集、使用、存储、共享与删除您的个人信息及与产品使用相关的数据。
部署前请由执业律师审阅;下文已按当前产品实现列出主要数据类型。英文完整版亦见安装包 Privacy-Policy.txt。
1. 我们收集哪些信息
| 类别 | 内容示例 | 目的 |
|---|---|---|
| 账号与身份 | 邮箱、用户名、OAuth 标识、登录时间与 IP、会话令牌 | 注册、登录、安全风控 |
| 设备与授权 | 设备指纹哈希、机器 ID、操作系统概要、应用版本、心跳 | 设备绑定、订阅校验、更新与反欺诈 |
| 订阅与支付 | 套餐、订阅状态、订单号;支付由 Stripe 等处理者完成(我们不存储完整卡号) | 计费、权益同步、退款与合规 |
| 产品遥测(可选) | 事件类型/名称、会话 ID、非敏感属性 JSON | 统计、稳定性、反滥用 |
| 行为风控遥测(可选,默认关闭) | 打字间隔、粘贴比例、会话时长等聚合指标;禁止含密码/源码 | 反机器人/滥用检测 |
| 云端 AI(仅开启时) | 选中代码片段、对话输入等必要上下文 | 补全与对话;不用于模型训练(除非您单独同意) |
我们不收集:GPS/精确定位、通讯录、生物识别。 我们不出于训练目的批量采集您的仓库源码,也不要求您上交 BYOK 的明文密钥到遥测。 禁止在遥测字段中上传密码、API 密钥或完整仓库源码。
2. 本地模式、BYOK 与云端模式
- 本地 / BYOK:工作区源码默认不上传用于我方训练;您的模型 Key 保存在本机或由您指定的密钥库管理,调用直达对应模型服务商。
- 本地模式:仍可能有账号校验、订阅心跳与最小必要运维数据(设备 ID、版本)。
- 云端模式:为提供 AI 能力,必要上下文经 TLS 加密传输至我方及受托模型服务商;范围以您选择的上下文为限。
3. 订阅到期与数据
订阅到期后高级 Agent/MCP 功能锁定,但不因此删除您的本地工程文件。账号与设备绑定记录按保留政策处理;您可随时申请注销。
4. 保留期限
- 账号数据:账号存续期间;注销后 15 个工作日内删除或匿名化(法律要求保留的除外)。
- 产品遥测:约 180 天,届满删除或聚合统计。
- 云端 AI 技术缓存:约 30 天(运维脱敏日志另按内部策略)。
- 支付与账务记录:按适用财税法律保留。
5. 第三方共享
我们可能委托云主机、身份认证(Casdoor)、支付(Stripe)、模型 API、对象存储(如用于安装包分发的 R2)等处理者;其仅按合同处理数据。依法要求的披露除外。
6. 您的权利
- 访问、更正、删除、复制(可携)您的个人信息
- 限制或反对特定处理、撤回同意
- 注销账号:见 隐私中心 或邮件 privacy@zovax.ai
- 关闭可选遥测:隐私中心或 IDE 设置(若已登录)
- 我们不出售您的个人信息;加州用户如需「Do Not Sell/Share」说明,请联系 privacy@zovax.ai
7. 跨境传输
若数据传至境外,我们将采取适用法律要求的标准合同条款或等效机制,并在必要时征得同意。
8. Cookie
网站使用 Cookie/本地存储维护登录态与偏好;您可通过浏览器管理。
9. 未成年人
服务面向成年人;未成年人须在监护人同意下使用。
10. 政策更新
重大变更将通过网站或产品内提示。更新日期见文首或安装包文件。
Privacy Policy
ZovaX AI Inc. (“we”) operates ZovaX IDE and related services. This policy explains how we collect, use, store, share, and delete personal data and product-usage data.
Have counsel review before production reliance. The summary below mirrors current product behavior. The installer also ships Privacy-Policy.txt.
1. What we collect
| Category | Examples | Purpose |
|---|---|---|
| Account & identity | Email, username, OAuth IDs, login time/IP, session tokens | Sign-up, login, security |
| Device & entitlement | Device fingerprint hash, machine ID, OS summary, app version, heartbeat | Device binding, subscription checks, updates, anti-fraud |
| Subscription & payment | Plan, status, order IDs; payments via Stripe etc. (we do not store full card numbers) | Billing, entitlements, refunds, compliance |
| Product telemetry (optional) | Event type/name, session ID, non-sensitive JSON attributes | Analytics, stability, abuse prevention |
| Behavioral risk telemetry (optional, off by default) | Aggregates such as typing intervals, paste ratio, session length; no passwords/source | Bot/abuse detection |
| Cloud AI (only when enabled) | Selected snippets, chat inputs, necessary context | Completions & chat; not used for model training unless you separately consent |
We do not collect: precise GPS, contacts, or biometrics. We do not bulk-harvest your repo for training, and we do not require plaintext BYOK secrets in telemetry. Never put passwords, API keys, or full repositories in telemetry fields.
2. Local, BYOK, and cloud modes
- Local / BYOK: workspace source is not uploaded for our training by default; keys stay on your machine or vault; calls go to the model provider.
- Local mode: account checks, subscription heartbeats, and minimal ops data (device id, version) may still apply.
- Cloud mode: necessary context is sent over TLS to us and entrusted model providers, limited to what you choose.
3. After subscription expiry
Advanced Agent/MCP features lock when a subscription ends; we do not delete your local project files for that reason. Account and device records follow retention rules; you may request deletion anytime.
4. Retention
- Account data: while the account exists; within 15 business days after deletion request (except legal retention).
- Product telemetry: about 180 days, then delete or aggregate.
- Cloud AI technical caches: about 30 days (ops logs may follow separate redaction policy).
- Payment/accounting records: as required by tax/finance law.
5. Processors
We may use cloud hosting, identity (Casdoor), payments (Stripe), model APIs, and object storage (e.g. R2 for installers) as processors under contract. Lawful disclosures excepted.
6. Your rights
- Access, correct, delete, or port your personal data
- Restrict or object to certain processing; withdraw consent
- Delete account: Privacy center or privacy@zovax.ai
- Turn off optional telemetry in the privacy center or IDE settings when signed in
- We do not sell personal information; California users may contact privacy@zovax.ai about Do Not Sell/Share
7. International transfers
Where data leaves your region, we use SCC or equivalent safeguards and consent when required.
8. Cookies
The site uses cookies/local storage for session and preferences; manage them in your browser.
9. Children
The service is intended for adults; minors need guardian consent.
10. Updates
Material changes will be announced on the website or in-product. See the header dates or installer file.
Privacy questions: privacy@zovax.ai (Data protection contact: {dpo})