概要:SeYx 是一款个人私密记录应用。默认情况下,您的记录保存在本机加密存储中。
仅在您主动开启「共同记录」并完成配对后,才会将选定的非自慰类记录以端到端加密形式同步至云端,供匹配对象解密查看。
未购买「去广告」时,应用会展示 Google AdMob 广告并可能使用广告标识符。
1. 适用范围与运营者
本政策适用于 Android 应用 SeYx(Google Play 包名:com.SeYx.app,以下简称「本应用」)。
本应用由 Caozhehao(以下简称「我们」)提供与运营。
使用本应用即表示您已阅读并理解本政策。若您不同意本政策,请停止使用并卸载本应用。
2. 我们处理的信息类别
2.1 始终保存在本机的信息(默认不上云)
- 您创建的亲密活动记录(时间、对象、地点、方式、备注等)
- 生理周期相关数据(若您使用周期功能)
- 自定义标签、伴侣备注、主题与语言偏好
- 可选的应用锁密码(仅存储于本机,我们无法获知)
- 生物识别解锁配置(由系统安全模块处理,我们不收集生物特征数据)
- 端到端加密所需的私钥、配对密钥(仅本机保存,不上传)
- 标记为「自慰 / 独自」或未开启「与伴侣共享」的记录
上述数据通过 Android DataStore 及 AES-GCM 等方式在本机加密存储。
卸载应用或清除应用数据将导致本机数据丢失(除非您自行导出备份)。
2.2 开启共同记录 / 配对后上传至云端的信息
仅在您完成 Firebase 匿名登录并主动匹配成功后,我们才会通过 Google Firebase 处理以下数据:
| 数据类型 | 用途 | 加密方式 |
| 匿名用户 ID(Firebase Auth UID) |
身份识别、配对与同步 |
传输加密(HTTPS/TLS) |
| 昵称、性别、性取向(配对资料) |
向匹配对象展示、完成配对握手 |
传输加密;云端为明文字段 |
| 临时 6 位匹配码及有效期 |
与伴侣建立配对关系 |
传输加密;云端为明文字段 |
| EC 公钥、Signed PreKey、一次性 PreKey |
建立端到端加密通道(X3DH / ECDH) |
传输加密;公钥为明文存储 |
| 配对关系元数据(pairId、对方 UID、本地伴侣名称等) |
维护匹配状态与同步路由 |
传输加密;云端为明文字段 |
| 共享亲密记录(非自慰且已勾选与伴侣共享) |
双方共同查看与互评 |
端到端 AES-GCM 密文;服务端无法读取明文 |
| 对共享记录的评价内容 |
伴侣互评功能 |
端到端 AES-GCM 密文 |
| 女性用户本人经期数据(匹配后自动同步) |
向匹配伴侣展示周期信息 |
传输加密;云端以明文字段存储,仅匹配双方可读 |
解除匹配后,双方不再同步新的共记内容;您可在解除时选择是否删除云端共记数据(以应用内实际选项为准)。
重装或清除本机数据会导致匿名身份与本地密钥丢失,需重新配对。
2.3 购买与广告相关
- Google Play 结算:处理「去广告」一次性内购(商品 ID:
seyx_remove_ads)。交易由 Google 处理;我们仅接收购买状态以关闭广告,不直接处理您的支付卡信息。
- Google AdMob:在未购买去广告时展示横幅与插屏广告。可能收集或处理广告 ID、设备信息、IP 地址、广告交互数据等,用于广告投放与衡量。欧盟等地区会通过 Google UMP 征求同意;您可在应用设置中使用「广告隐私设置」管理偏好(若当地法律要求)。
2.4 我们不主动收集的内容
- 真实姓名、手机号、电子邮箱(除非您主动通过下方联系方式联系我们)
- 精确 GPS 定位
- 通讯录、短信、相册(相机权限仅用于扫描配对二维码,不用于上传相册)
3. 设备权限说明
| 权限 | 用途 |
| 网络 (INTERNET) | 配对同步、广告、内购验证、Firebase 通信 |
| 通知 (POST_NOTIFICATIONS) | 伴侣新记录/评价、同步相关本地通知 |
| 相机 (CAMERA) | 扫描伴侣匹配二维码(可选功能) |
| 生物识别 (USE_BIOMETRIC) | 应用锁指纹/面容解锁(可选) |
| 广告 ID (AD_ID) | AdMob 个性化/非个性化广告(购买去广告后不再展示广告) |
您可在系统设置中撤销部分权限;撤销可能导致相关功能不可用。
4. 第三方服务
本应用集成以下第三方服务,其数据处理受其各自隐私政策约束:
5. 数据安全
- 本机数据采用加密存储;可选应用锁与「禁止截屏」进一步保护界面隐私。
- 共记内容在离开设备前由配对密钥加密;私钥与配对密钥仅存于本机。
- 云端与客户端之间使用 TLS 传输。
- 尽管如此,没有任何系统能保证绝对安全;请妥善保管设备与应用锁密码。
6. 数据保留与删除
- 本机数据:保留至您卸载应用、清除应用数据,或使用应用内「数据管理」功能清除/导出为止。
- 云端配对数据:保留至您解除匹配、删除共记或我们依法删除为止。匿名账号长期不活跃时,Firebase 数据可能按服务规则保留或清理。
- 广告与购买记录:由 Google 按其政策保留;您可通过 Google 账户管理广告与购买历史。
7. 您的权利与选择
- 不使用配对功能即可仅在本机记录,数据不上云。
- 在记录时控制是否与伴侣共享;自慰类记录不会同步。
- 随时在设置中解除匹配、清除本机数据或导出备份(以应用内功能为准)。
- 购买「去广告」以关闭 AdMob 广告。
- 在适用法律允许范围内,您可联系我们请求访问、更正或删除与您相关的信息。
8. 未成年人
本应用面向成年人,不面向未满 18 周岁(或您所在司法辖区规定的法定成年年龄)的用户。
我们不会故意收集未成年人的个人信息。若您认为未成年人向我们提供了信息,请联系我们以便删除。
9. 跨境传输
Firebase、AdMob 与 Google Play 的服务器可能位于您所在国家/地区以外。
使用本应用即表示您理解相关数据可能被传输至这些地区,并受当地法律保护框架约束。
10. 政策更新
我们可能因功能变更、法律要求或监管需要更新本政策。更新后的版本将发布于本页面并修改顶部「生效日期」。
重大变更时,我们可能通过应用内提示等方式通知您。继续使用本应用即视为接受更新后的政策。
11. 联系我们
如对本政策或数据处理有任何疑问、投诉或行使权利请求,请通过以下方式联系:
Summary: SeYx is a private journaling app. By default, your entries stay in encrypted on-device storage.
Only when you enable shared logging and complete partner matching will
selected non-solo entries be synced to the cloud as end-to-end encrypted ciphertext for your matched partner to decrypt.
If you have not purchased Remove Ads, the app shows Google AdMob ads and may use advertising identifiers.
1. Scope & Operator
This Privacy Policy applies to the Android app SeYx (Google Play package: com.SeYx.app, the “App”).
The App is provided by Caozhehao (“we”, “us”).
By using the App, you acknowledge that you have read and understood this Policy. If you do not agree, please stop using and uninstall the App.
2. Information We Process
2.1 Stored on Your Device Only (default — not uploaded)
- Intimacy activity logs you create (time, partner, location, methods, notes, etc.)
- Menstrual cycle data (if you use cycle tracking)
- Custom tags, partner notes, theme and language preferences
- Optional app passcode (stored locally only — we cannot access it)
- Biometric unlock settings (handled by the OS; we do not collect biometric templates)
- Private keys and per-pair encryption keys (device-only, never uploaded)
- Solo/masturbation entries or entries not marked for partner sharing
This data is encrypted at rest on device (e.g. DataStore + AES-GCM).
Uninstalling or clearing app data will delete local data unless you export a backup yourself.
2.2 Uploaded When Shared Logging / Matching Is Enabled
Only after anonymous Firebase sign-in and successful partner matching, we process the following via Google Firebase:
| Data | Purpose | Protection |
| Anonymous user ID (Firebase Auth UID) |
Identity, matching, sync |
TLS in transit |
| Nickname, gender, orientation (pairing profile) |
Shown to matched partner; handshake |
TLS; stored as plaintext fields in cloud |
| Temporary 6-digit match code & expiry |
Establish partner bond |
TLS; plaintext in cloud |
| EC public keys, signed prekeys, one-time prekeys |
End-to-end encryption setup (X3DH / ECDH) |
TLS; public keys stored in plaintext |
| Match metadata (pairId, partner UID, local partner name, etc.) |
Maintain match & sync routing |
TLS; plaintext in cloud |
| Shared intimacy logs (non-solo, share-with-partner enabled) |
Mutual viewing & reviews |
E2E AES-GCM ciphertext; server cannot read plaintext |
| Reviews on shared logs |
Partner review feature |
E2E AES-GCM ciphertext |
| Menstrual cycle data (female users, auto-sync when matched) |
Share cycle with matched partner |
TLS; stored as plaintext fields in cloud, readable only by matched parties |
After unmatching, new shared entries stop syncing. You may optionally purge shared cloud data when unmatching (as offered in-app).
Reinstalling or clearing local data loses your anonymous identity and local keys — rematching is required.
2.3 Purchases & Advertising
- Google Play Billing: one-time “Remove Ads” purchase (
seyx_remove_ads). Google processes payment; we only receive purchase state to disable ads.
- Google AdMob: banner and interstitial ads when ads are not removed. May process advertising ID, device info, IP address, ad interactions, etc. Google UMP may collect consent in regulated regions; you can use in-app “Ad privacy settings” when required.
2.4 What We Do Not Collect
- Real name, phone number, or email (unless you contact us voluntarily)
- Precise GPS location
- Contacts, SMS, or photo library (camera is used only for QR match scanning)
3. Device Permissions
| Permission | Purpose |
| INTERNET | Pairing sync, ads, billing, Firebase |
| POST_NOTIFICATIONS | Local notifications for partner logs/reviews & sync |
| CAMERA | Scan partner match QR code (optional) |
| USE_BIOMETRIC | Optional app lock via fingerprint/face |
| AD_ID | AdMob advertising (disabled after Remove Ads purchase) |
4. Third-Party Services
5. Security
- On-device encryption; optional passcode and screenshot blocking.
- Shared logs encrypted with pair keys before upload; private keys stay on device.
- TLS for data in transit.
- No system is 100% secure — protect your device and passcode.
6. Retention & Deletion
- Local data: until uninstall, clear data, or in-app export/delete.
- Cloud pairing data: until unmatch, purge, or legal deletion. Inactive anonymous accounts may be retained per Firebase rules.
- Ads & purchases: retained by Google per their policies.
7. Your Choices & Rights
- Use the App offline-only locally by not enabling matching.
- Control per-entry partner sharing; solo entries never sync.
- Unmatch, clear local data, or export backups in Settings (where available).
- Purchase Remove Ads to stop AdMob.
- Contact us to exercise access, correction, or deletion rights where applicable law allows.
8. Children
The App is intended for adults only (18+ or the age of majority in your jurisdiction).
We do not knowingly collect data from children. Contact us if you believe a child provided information.
9. International Transfers
Firebase, AdMob, and Google Play may process data outside your country. By using the App, you understand such transfers may occur under applicable legal frameworks.
10. Changes
We may update this Policy for feature, legal, or regulatory reasons. The effective date at the top will change when updated. Continued use constitutes acceptance.
11. Contact