Numable

隐私政策 / Privacy Policy

生效日期 / Effective: 以正式发布之日为准 / upon public release · 更新 / Updated: 2026-09-27

用户协议 / Terms隐私政策 / Privacy注销账号 / Delete account
1. 引言2. 我们收集的个人信息3. 本地优先与端上直连4. 我们如何使用信息5. 第三方 SDK 与服务清单6. 付费功能7. 存储与保护8. 我们如何共享信息9. 您的权利10. 未成年人11. 跨境传输12. 联系我们13. 政策更新

1. 引言 / Introduction

上海沐小阳网络科技有限公司(以下称"我们")开发并运营 Numable 应用及其桌面小组件(iOS、iPadOS、macOS、Android、HarmonyOS、Windows 等客户端,以下统称"本应用")。我们将按《中华人民共和国个人信息保护法》(PIPL)、《网络安全法》《数据安全法》及适用的境外法律(如欧盟 GDPR、美国加州 CCPA)保护您的个人信息。

Numable 采用"本地优先(local-first)"架构:您的仪表盘、收藏、已安装组件等使用数据默认仅保存在您的设备本地,不上传至我们的服务器;应用直接从第三方信息源获取展示数据,我们的服务器不经手、不留存这些数据(唯一例外是您主动启用的 Claude Code 用量组件,见 §3.1)。 本政策说明我们如何收集、使用、存储、共享和保护您的个人信息,以及您享有的权利。请在使用本应用前仔细阅读;继续使用即表示您认可本政策。

Shanghai Muxiaoyang Network Technology Co., Ltd. ("we", "us") develops and operates the Numable app and its home-screen widgets (iOS, iPadOS, macOS, Android, HarmonyOS, Windows; the "App"). We protect your personal information under China's PIPL, Cybersecurity Law and Data Security Law, and applicable overseas laws including the EU GDPR and California CCPA. Numable is local-first: your dashboards, favorites and installed widgets stay on your device by default and are not uploaded to our servers; the App fetches display data directly from third-party sources, which our servers never receive or retain (the one exception is the Claude Code usage widget, which you opt into — see §3.1). By using the App you acknowledge this policy.

2. 我们收集的个人信息 / Information we collect

我们坚持"最小必要"原则。

2.1 您主动提供的信息

场景收集信息是否必需
登录账号可用的登录方式:iOS / iPadOS / macOS 为 Apple、Google、GitHub;Android、HarmonyOS、Windows 为 Google、GitHub。收集第三方返回的用户唯一标识、邮箱、名称或用户名、头像 URL、登录方式,以及您自行设置的昵称(可选)登录为可选;不登录可使用浏览、安装、仪表盘、桌面小组件等功能,仅发布、举报、申诉需要登录
意见反馈反馈类别与正文、您自愿填写的联系方式;登录状态下提交时关联您的账号标识,未登录则为匿名;另附诊断信息(见下),您可在提交前关闭仅使用该功能时
举报 / 申诉被举报内容包的标识与版本、举报类别、您填写的说明及您的账号标识;发布者申诉时的申诉说明及账号标识仅使用该功能时(需登录)
发布组件(UGC)您上传的内容包及关联账号标识;发布者名称(取自您的账号名称或第三方账号用户名)会在安装面板中公开展示仅发布时
官网上线通知您在 get.numable.app 登记的邮箱与语言偏好仅登记时
多设备同步(会员功能,可选)开启后,您的仪表盘、已安装信息源清单、组件内记录的数据、提醒与信息源排序,以及您添加的第三方凭证的名称、类型、适用网站与使用它的组件(不含凭证的值),会在您的设备上加密后上传到我们的服务器,在您的其他设备间同步;我们无法解密其内容。凭证的值默认不同步,仅当您在同步中另外开启「同步密钥与凭证」时,才以同样的端到端加密方式同步(授权登录类连接除外,每台设备各自连接)。另收集:设备平台类型(如 iPhone / Mac)、最后同步时间、记录条数与大小(用于同步与配额)。不同步登录令牌、桌面小组件设置、主题与语言仅开启同步时;可随时在「我的 → 同步」关闭并删除云端数据

反馈诊断信息:服务端只接受以下 7 项,其余一律丢弃 —— App 版本、平台、系统版本、设备型号(如 "iPhone16,2")、语言、网络类型、提交时正在打开的内容包标识。各端实际附带的项可能少于 7 项;反馈界面会展示将要附带的内容,您可以关闭。反馈不支持上传截图或附件。

2.2 自动收集:登录令牌(JWT),仅保存在您的设备本地(iOS / iPadOS / macOS 存于系统钥匙串 Keychain,Android 存于加密存储 EncryptedSharedPreferences,HarmonyOS 与 Windows 存于本应用私有数据目录);下载组件包/检查更新产生的必要网络信息(如 IP、平台与版本,用于分发与安全);您提交反馈或在官网登记邮箱时,我们只保存 IP 地址的加盐哈希值(不保存原始 IP、无法还原),用于防滥用;每台登录设备的记录:平台、设备类型、设备名、App 版本、登录方式、首次登录与最近活跃时间、最近活跃时按 IP 估算的城市级位置,只用于在「我的 › 账号 › 登录设备」里展示、并让您退出某台设备的登录;不保存原始 IP,退出后 30 天删除,60 天没有活跃的设备自动删除;用已登录的手机扫码登录另一台设备(电脑、平板、手机或电视)时,我们会记录发起登录的那台设备的平台、设备类型、设备名与按 IP 估算的大致位置(城市级),只用于在您手机的确认页上显示「是哪台设备在请求登录」、帮助您识别冒用;不保存原始 IP,相关记录约 1 天后删除。

崩溃与诊断:本应用未集成任何崩溃上报、统计分析或广告 SDK,我们不另外收集崩溃日志与使用分析数据。若您在系统设置中同意与开发者共享分析数据,Apple(App Store)、Google(Google Play)等平台可能依其自身政策收集崩溃与性能统计,并以汇总形式提供给我们;这部分由平台收集和处理,您可在系统设置中随时关闭。

2.3 我们不收集:您设备的定位(GPS 等)、通讯录、麦克风;不读取您的相册(仅在您主动保存分享图时申请「仅添加」权限写入图片;在扫一扫里主动选一张图片识别二维码时,只读取您选中的那一张,在设备上识别、不上传);相机仅在您主动扫码时使用(用手机扫码登录另一台设备、添加同步设备、连接桌面端编辑器),本地网络仅在连接桌面端编辑器时使用(在同一 Wi-Fi 下把正在编辑的组件预览到本机),均不留存图像;不收集您在组件中浏览的具体数据内容;不进行用户画像或广告追踪。

(2.1) Information you provide: account identity from sign-in — Apple, Google or GitHub on iOS/iPadOS/macOS, Google or GitHub on Android, HarmonyOS and Windows (provider user id, email, name or username, avatar URL, provider, and an optional nickname you set). Sign-in is optional: browsing, installing, dashboards and home-screen widgets work signed-out; only publishing, reporting and appeals require it. Feedback: category, text and an optional contact; linked to your account id if you are signed in, anonymous otherwise; plus diagnostics you can switch off before sending — the server accepts only seven fields (app version, platform, OS version, device model, language, network type, the content pack open at the time) and discards everything else; no screenshots or attachments. Reports/appeals: the reported pack id and version, category, your note and your account id (sign-in required). Publishing: the pack you upload and its account id; the publisher name (your account name or provider username) is shown publicly in the install panel. Launch notification: the email and language you leave on get.numable.app. (2.2) Automatically collected: your login token (JWT), stored only on your device — Keychain on iOS/iPadOS/macOS, EncryptedSharedPreferences on Android, the app's private data directory on HarmonyOS and Windows; basic network data (IP, platform and version) from bundle downloads and update checks, for distribution and security; when you submit feedback or join the launch list, a salted hash of your IP (never the raw IP, not reversible) for abuse prevention; a record for each signed-in device: platform, device type, device name, app version, sign-in method, first sign-in and last active time, and the city-level location estimated from its IP when it was last active — used only to list your devices under Me › Account › Signed-in devices and let you sign any of them out; the raw IP is not stored, records are deleted 30 days after a device is signed out, and devices inactive for 60 days are removed automatically; when you sign in on another device (computer, tablet, phone or TV) by scanning with your signed-in phone, we record that device's platform, device type, device name and approximate location estimated from its IP (city level), used only to show on your phone's confirmation screen which device is asking to sign in so you can spot misuse; the raw IP is not stored and the record is deleted after about a day. Crash & diagnostics: the App integrates no crash-reporting, analytics or advertising SDK and we collect no crash logs or usage analytics ourselves. If you opt in to sharing analytics with developers in your system settings, platforms such as Apple (App Store) and Google (Google Play) may collect crash and performance statistics under their own policies and provide them to us in aggregate; you can turn this off in system settings. (2.3) We do not collect your device's location (GPS etc.), contacts or microphone; we do not read your photo library (add-only permission is requested only when you save a share image; when you pick an image in the scanner to read a QR code, only that one image is read, on the device, and never uploaded); the camera is used only when you choose to scan a code (signing in on another device with your phone, adding a sync device, or connecting the desktop editor) and the local network only when you connect the desktop editor (to preview the widget being edited over the same Wi-Fi); no image is retained; we do not collect the data you view inside widgets; and we do no profiling or advertising tracking.

3. 本地优先与端上直连 / Local-first & direct-to-source

您创建的仪表盘、收藏、已安装组件、偏好等默认仅存于设备本地(App Group / 应用私有目录),我们的服务器不保存副本。组件展示的实时数据由本应用在您的设备上直接向第三方信息源获取,数据不经过我们的服务器。

您自行提供的第三方凭证:部分组件需要您提供第三方服务的凭证(如 API Key、访问令牌)。凭证保存在设备的系统安全存储中,仅随请求发往该组件声明的域名,不会写入本地备份文件,也不会随意见反馈上传。凭证默认不上传到我们的服务器;仅当您在多设备同步中开启「同步密钥与凭证」时,凭证的值才会在您的设备上加密后同步到您的其他设备,我们的服务器只保存密文、无法解密(见下段)。您可在「我的」页的凭证管理中随时解除绑定。您导出的备份文件由您自行保管,我们不接收、不存储。

多设备同步(会员功能,默认关闭):开启同步后,上述使用数据会以端到端加密的形式上传到我们的服务器,用于在您的其他设备间同步。加密密钥只在您的设备上生成与保存(另以「恢复码」形式交由您自行保管),我们的服务器只保存密文,无法解密、不做分析;服务器能看到的只有记录条数、大小、写入时间、设备平台类型与最后同步时间。开启同步后,您添加的第三方凭证的名称、类型、适用网站及使用它的组件(不含凭证的值)也会一并同步,便于在新设备上直接补填;凭证的值默认不同步,仅在您另外开启「同步密钥与凭证」(开启前会请您确认)后才同步,同样端到端加密。通过授权登录连接的服务不同步凭证的值,每台设备需各自连接。请妥善保管恢复码:恢复码一旦泄露,已同步的凭证也会随之泄露。关闭该开关时,我们删除云端的凭证值,各设备上已保存的保留。登录令牌、桌面小组件设置、主题与语言不参与同步。您可随时在「我的 → 同步」关闭同步或删除云端数据(立即删除);会员到期后同步暂停,云端数据保留 180 天后自动删除;注销账号时一并删除。

重要:您获取的第三方数据受该第三方各自隐私政策约束,请一并阅读遵守;我们对第三方信息源的数据处理不承担责任。

3.1 例外:Claude Code 用量组件(可选) — 该组件的数据来自我们运营的投递服务 usage.numable.app,是本应用中唯一经由我们服务中转的展示数据,仅在您主动安装我们提供的 Claude Code 插件并在本应用中完成绑定后才会产生。插件只上报按日汇总的用量数字(会话数、消息数、token 数)、按小时汇总的活跃次数与模型名称,不包含对话内容、项目路径、代码、分支名或会话标识,设备只以哈希后的标识区分。数据存放在一个与您的 Numable 账号无关联的匿名空间中,凭插件生成的令牌写入与读取;连续 90 天没有新的上报,整个空间自动删除;为防滥用,相关请求按 IP 限流,限流记录约 1 天后清除。卸载插件即停止上报,在本应用中解除该凭证绑定即停止读取。

Your usage data is stored only on your device by default; our servers keep no copy. Live widget data is fetched directly from third-party sources by the App on your device and does not pass through our servers. Credentials you provide (e.g. API keys or access tokens some widgets need) are kept in the device's system secure store, sent only to the hosts the widget declares, and are never written into local backup files or attached to feedback. By default they are not uploaded to our servers; only if you turn on "Sync keys and credentials" in multi-device sync are their values encrypted on your device and synced to your other devices, and our servers hold ciphertext only and cannot decrypt it (see below). You can unbind them under "Me" at any time. Backup files you export stay with you; we never receive them. Data you obtain from a third-party source is governed by that source's own privacy policy; we are not responsible for third parties' data practices.

Multi-device sync (a paid feature, off by default). If you turn it on, the usage data above is uploaded to our servers end-to-end encrypted and synced to your other devices. The key is generated and kept only on your devices (and in a recovery code you keep yourself); our servers store ciphertext only and cannot decrypt or analyze it — they see only record counts, sizes, write times, device platform type and last-sync time. With sync on, the name, type, applicable sites and using widgets of each third-party credential you add (not its value) are synced too, so you only need to fill in the value on a new device; credential values are not synced by default — only after you separately turn on "Sync keys and credentials" (you are asked to confirm first), with the same end-to-end encryption. Services connected through sign-in authorization (OAuth) never sync their values; connect them on each device. Keep your recovery code safe: if it leaks, the synced credentials leak with it. Turning that switch off deletes the credential values from the cloud; copies already saved on your devices stay. Login tokens, home-screen widget settings, theme and language are never synced. You can turn sync off or delete the cloud copy at any time under "Me → Sync" (deleted immediately); when your subscription lapses, sync pauses and the cloud copy is deleted after 180 days; deleting your account deletes it too.

(3.1) Exception — the Claude Code usage widget (optional). Its data comes from our delivery service usage.numable.app and is the only display data that passes through a service we run. It exists only if you install our Claude Code plugin and bind it in the App. The plugin sends only daily aggregate numbers (sessions, messages, tokens), hourly activity counts and model names — never conversation content, project paths, code, branch names or session ids; devices are distinguished only by a hashed id. Data sits in an anonymous space not linked to your Numable account, written and read with plugin-generated tokens. A space with no upload for 90 consecutive days is deleted automatically; requests are rate-limited by IP and those rate-limit records are purged after about a day. Uninstall the plugin to stop uploads; unbind the credential in the App to stop reads.

4. 我们如何使用信息 / How we use information

仅用于:(a) 提供与维护账号、发布、举报/申诉、反馈等功能;(b) 分发与更新组件包并保障其完整性与来源可信(Ed25519 签名校验);(c) 安全防护、滥用与欺诈防范;(d) 履行法律义务。我们不将您的个人信息用于广告投放或出售。

We use information only to: (a) provide account, publishing, report/appeal and feedback features; (b) distribute/update bundles and verify their integrity and authenticity (Ed25519); (c) ensure security and prevent abuse/fraud; (d) meet legal obligations. We do not use your personal information for advertising, and we do not sell it.

5. 第三方 SDK 与服务清单 / Third-party SDKs & services

本应用未集成任何崩溃上报、统计分析、广告或支付 SDK。鸿蒙(HarmonyOS)客户端不集成任何第三方运行时 SDK,仅使用系统能力(Google / GitHub 登录经系统浏览器完成)。

名称提供方平台用途涉及个人信息
Sign in with AppleAppleiOS/iPadOS/macOSApple 账号登录(系统原生能力)Apple 用户标识、邮箱(可为 Apple 隐藏邮箱)、姓名(仅首次授权)
Google 账号登录GoogleiOS/iPadOS/macOS/Android/HarmonyOS/Windows系统浏览器完成 OAuth(不集成 Google SDK)由 Google 处理的登录信息;我们获得用户标识、邮箱、姓名、头像 URL
GitHub 账号登录GitHubiOS/iPadOS/macOS/Android/HarmonyOS/Windows系统浏览器完成 OAuth(不集成 GitHub SDK)由 GitHub 处理的登录信息;我们获得用户标识、用户名、邮箱、姓名、头像 URL
CloudflareCloudflare服务端组件包分发、账号与反馈等后端服务的托管(Workers / D1 / R2)见 §7
MJRefresh开源iOS/Mac下拉刷新 UI无
ZIPFoundation开源iOS/Mac组件包解压无
Kanna开源iOS/MacHTML/XML 解析(本地)无
SwiftDraw开源iOS/MacSVG 图片渲染(本地)无
Glide开源Android图片加载与磁盘缓存访问图片 URL 的网络请求
SmartRefreshLayout开源Android下拉刷新 UI无
Material Components开源(Google)AndroidUI 组件无
BouncyCastle开源Android签名/加密算法无(本地计算)
ZXing (embedded)开源Android扫码(登录电脑 / 添加同步设备 / 连接桌面端编辑器)相机画面(实时解码,不留存)
AndroidX Browser / SecurityGoogleAndroid系统浏览器登录 / 本地加密存储本地令牌加密

The App integrates the third-party components and services above. It integrates no crash-reporting, analytics, advertising or payment SDK. The HarmonyOS client integrates no third-party runtime SDK and uses only system capabilities (Google and GitHub sign-in run in the system browser). Sign in with Apple is available on iOS/iPadOS/macOS; Google and GitHub sign-in are available on all platforms through the system browser, without any provider SDK. Cloudflare hosts our backend (see §7). Open-source UI/utility libraries process no personal information. We update this list when integrations change.

6. 付费功能 / Paid features

本应用当前免费提供,不提供任何付费功能或应用内购买,我们不收集任何支付或交易信息。若将来推出付费功能,我们会在上线前更新本政策,说明相关信息的处理方式,并依法征得您的同意。

The App is currently free. It offers no paid features or in-app purchases, and we collect no payment or transaction information. If paid features are introduced in the future, we will update this policy before launch to explain how the related information is handled, and obtain your consent where required.

7. 存储与保护 / Storage & security

账号、反馈、举报、发布记录等后端数据存储于 Cloudflare(Workers / D1 / R2)。因我们以海外分发为主,数据可能存储于中国境外;如您在中国境内且涉及个人信息出境,我们将依 PIPL 履行告知—单独同意及相应合规义务(详见 §11)。登录令牌仅保存在设备本地;第三方凭证保存在设备的系统安全存储中,仅在您开启「同步密钥与凭证」时以端到端加密形式同步到您的其他设备(见 §2、§3);与我们服务之间的网络传输经 HTTPS/TLS 加密。

账号信息在您使用期间保留。注销账号时,我们立即删除账号资料(登录方式、第三方账号标识、邮箱、名称、头像、昵称),并将您提交的反馈与账号解除关联(清除账号标识与联系方式,反馈正文保留用于产品改进)。以下信息在注销后仍会保留:举报与申诉记录中的账号标识(用于防止重复举报与治理追溯);发布者封禁记录(防止通过注销后重新登录规避封禁);您已发布的内容(按《用户协议》§5.1 处理);法律法规要求留存的记录。官网上线通知邮箱可随时联系我们删除。多设备同步的云端数据(密文)在您开启同步期间保留;您在「我的 → 同步」删除云端数据或注销账号时立即删除;会员到期后保留 180 天后自动删除。

Backend data (account, feedback, reports, publishing records) is stored on Cloudflare (Workers/D1/R2) and, as we distribute primarily overseas, may be stored outside China; cross-border transfer of mainland-China users' personal information is handled under PIPL (§11). Login tokens stay on your device; third-party credentials stay in the device's secure store and are synced end-to-end encrypted to your other devices only if you turn on "Sync keys and credentials" (§2, §3); traffic to our services uses HTTPS/TLS. We retain account data while your account is active. When you delete your account we immediately delete the account profile (provider, provider id, email, name, avatar, nickname) and detach your feedback from it (account id and contact removed; the feedback text is kept for product improvement). Retained after deletion: the account id on reports and appeals (to prevent duplicate reports and keep moderation auditable); publisher-ban records (so deletion and re-login cannot evade a ban); content you published (handled under Terms §5.1); and records the law requires us to keep. Encrypted sync data is kept while sync is on, deleted immediately when you delete the cloud copy under "Me → Sync" or delete your account, and purged 180 days after your subscription lapses. Launch-list emails can be deleted on request.

8. 我们如何共享信息 / Sharing

我们不出售您的个人信息。仅在下列情形共享:(a) 经您同意;(b) 为实现功能所必需的第三方服务商(如 Cloudflare),在合同约束下按最小必要处理;(c) 法律法规或司法/行政机关依法要求。您选择用 Apple / Google / GitHub 登录时,登录过程由该服务商按其隐私政策处理。发布 UGC 内容时,您的发布者名称及所发布内容将对其他用户可见(详见《用户协议》)。

We do not sell your data. We share only: (a) with your consent; (b) with processors strictly necessary to run the service (e.g. Cloudflare) under contract and minimization; (c) as required by law or lawful authority. When you sign in with Apple, Google or GitHub, that provider handles the sign-in under its own privacy policy. When you publish UGC, your publisher name and the content become visible to other users (see the Terms).

9. 您的权利 / Your rights

您有权查阅、复制、更正、补充、删除您的个人信息;撤回同意;注销账号;获取个人信息副本(可携带)。GDPR 下您另享限制处理、反对处理、可携权及向监管机构投诉的权利;CCPA 下您享有知情、删除、以及"不出售"的权利(我们本就不出售)。行使权利请见 §12。注销账号:在任一平台的应用内进入「我的」页 → 点顶部账号行 → 在登录面板「退出登录」下方点「注销账号」,确认后立即生效;无法登录时可按 注销账号页面所述通过邮件申请。

You may access, copy, correct, supplement, delete your personal information; withdraw consent; close your account; and obtain a portable copy. GDPR additionally grants restriction, objection, portability, and the right to complain to a supervisory authority; CCPA grants rights to know, delete, and opt out of sale (we do not sell). Contact us via §12. Account deletion: in the App on any platform, open "Me" → tap the account row → tap "Delete account" below "Sign out"; it takes effect immediately. If you cannot sign in, follow the account deletion page to request deletion by email.

10. 未成年人 / Minors

本应用不面向 14 周岁以下儿童。若您为不满 14 周岁的未成年人,请在监护人同意并指导下使用;如我们发现在未获监护人有效同意下收集了儿童个人信息,将尽快删除。

The App is not directed to children under 14. Minors under 14 should use it only with guardian consent. We delete children's data collected without valid guardian consent.

11. 跨境传输 / Cross-border transfer

对于中国境内用户的个人信息出境,我们将:向您告知境外接收方信息及处理目的;取得您的单独同意;并采取 PIPL 要求的合规路径(通过安全评估、订立标准合同或通过认证之一)。

Where personal information of mainland-China users is transferred abroad, we provide notice of the overseas recipient and purpose, obtain your separate consent, and adopt a PIPL-compliant transfer mechanism (security assessment, standard contract, or certification).

12. 联系我们 / Contact

个人信息处理者:上海沐小阳网络科技有限公司,注册地址:上海市浦东新区达秀路151号1幢3层301室。隐私相关事宜:privacy@numable.app;一般客服:support@numable.app。

Controller: Shanghai Muxiaoyang Network Technology Co., Ltd., Room 301, 3rd Floor, Building 1, No. 151 Daxiu Road, Pudong New Area, Shanghai, China. Privacy contact: privacy@numable.app; general support: support@numable.app.

13. 政策更新 / Changes

我们可能适时更新本政策;重大变更将通过应用内显著方式通知,并在必要时重新征得您的同意。继续使用即表示接受更新后的政策。

We may update this policy; material changes will be notified prominently in-app and, where required, re-consented. Continued use constitutes acceptance.