翻谱器隐私政策
翻谱器(FanPuQi)是一款用于阅读相册乐谱与 PDF、通过触摸或歪头动作翻页的应用。本政策说明应用处理的数据、用途、存储、保留、共享和删除方式,以及你的选择。以下人脸数据说明适用于 1.0 版本,并说明 build 2 与 build 3 的差异;开发者联系方式见本页末尾。
1. 摄像头、TrueDepth/ARKit 与人脸数据
1.1 处理哪些数据
进入乐谱阅读界面或校准功能时,应用会请求相机权限。获得许可后,应用在受支持的设备上使用 Apple ARKit 人脸追踪(ARFaceTrackingConfiguration,属于 TrueDepth 相关 API);不支持时使用 Apple Vision 通过前置摄像头估算头部姿态。
应用在设备上实时处理相机画面、人脸是否处于追踪状态,以及人脸相对于相机的位置和方向信息,由此计算头部角度(roll、pitch、yaw)。应用同时使用时间戳判断歪头动作的保持时间。实时相机预览用于帮助你调整坐姿并让面部保持在取景范围内。
1.0 的 build 2 曾由 ARKit 适配层读取 4 项表情系数:左眼眨眼(eyeBlinkLeft)、右眼眨眼(eyeBlinkRight)、眉毛内侧抬起(browInnerUp)和吐舌(tongueOut),放入内存中的姿态结果,但未用于翻页、诊断文件或传输。1.0 的 build 3 已移除这 4 项读取,不再访问 ARKit 表情系数,只提取翻谱所需的头部姿态与追踪状态。
1.2 用途与共享
头部角度、人脸可见状态和时间信息用于歪头翻页、中位校准、追踪反馈,以及用户主动开启的本机诊断。1.0 版本的翻页功能仅使用歪头动作;build 3 不读取表情系数。
应用不使用人脸数据识别个人身份、建立人脸身份档案,或进行广告、营销、用户画像、使用行为挖掘或模型训练。应用不会自动向开发者或第三方上传、披露或分享相机画面、人脸追踪数据、表情系数或诊断记录。ARKit 和 Vision 是应用调用的 Apple 设备端系统框架;应用没有将人脸数据发送到开发者运营的云端服务进行处理。
1.3 实时数据的存储与保留
相机画面和当前人脸追踪结果在设备内存中实时处理。build 2 的表情系数也仅在内存中处理;build 3 不读取这些系数。应用不把相机图像或视频、完整人脸变换矩阵、人脸网格或表情系数保存到文件。停止追踪后,应用停止相机追踪并清除当前姿态和预览引用;相关内存会随对象释放或应用进程结束而释放。停止追踪不代表所有内存缓冲都被立即安全擦除。
1.4 可选本机诊断:存储、保留与删除
诊断录制默认关闭。只有你主动点击校准页高级诊断中的“录制数据”后,应用才在内存中记录相对时间、头部角度(roll、pitch、yaw)和人脸是否可见。点击“停止记录”后,结果以 CSV 文件保存到应用的本机 Documents 目录,供你排查追踪或角度问题、调整翻页灵敏度。
诊断 CSV 只包含相对时间、3 个头部角度和人脸可见状态,不包含相机图像、视频、表情系数、人脸网格、完整人脸变换矩阵或身份模板。未手动开启诊断录制时,应用不写入这些 CSV;应用没有自动上传或自动分享诊断文件的功能。
已保存的诊断 CSV 没有自动过期或自动删除期限,会保留在本机应用容器中,直到本机应用数据被删除。点击“停止记录”不会删除已生成的文件;诊断样本也可能继续留在内存中,直到再次开始录制时被清空、对应对象被释放或应用进程结束。删除本机数据和管理备份的方法见第 4 节。
2. 相册与 PDF 乐谱
相册权限用于读取授权范围内的相簿、图片和相关信息,显示封面、缩略图与乐谱页面。应用不修改或删除系统照片,不向开发者上传相册内容。
应用仅访问你通过系统文件选择器选取的 PDF,在设备上渲染。为便于下次打开,应用会在本机保存文件名和文件访问书签,不会把 PDF 上传给开发者。
若照片原图在 iCloud,或 PDF 来自 iCloud Drive 等文件提供商,系统可能需要联网取得文件。相关云端储存和传输由你选择的系统或文件服务管理,适用其隐私政策。
3. 本机设置、账户、跟踪与系统备份
翻页灵敏度和校准角度等参数保存在应用的本机偏好设置中,用于按你的坐姿和选择运行翻页功能。这些设置持续保留,直到你更改它们或删除本机应用数据;它们不包含照片、录像或人脸身份模板。应用无需注册或登录,没有开发者运营的用户数据后端,也未集成第三方广告、分析或跟踪 SDK。
应用不会主动向开发者传输你的乐谱、头部动作记录或使用行为。设备的系统备份及系统诊断共享可能依照你的 Apple 设置运行;本机应用数据可能包含在你启用的系统备份中。本政策不代替 Apple 的相关政策,备份副本需在相应的 Apple 设置中单独管理。
4. 你的选择、撤回权限与删除
你可以在系统“设置”中关闭翻谱器的相机权限,或调整、撤销照片访问。撤销相机权限后,应用不能继续使用该权限进行相机追踪;你仍可使用触摸翻页。打开 PDF 不需要照片权限。
在应用中移除 PDF 条目会删除其本机访问书签,不会删除原文件。选择“删除 App”会移除本机应用容器中的设置、书签和诊断 CSV;选择保留文稿和数据的“卸载 App”不会产生相同的数据删除效果。相册及原始 PDF 不会因删除应用而被删除。
删除本机应用数据不会自动删除已存在的系统或云端备份。若你启用了相关备份,请通过 Apple 或相应文件服务的设置管理、删除备份副本。应用没有供开发者远程删除的自动上传人脸数据库。
5. 主动联系支持
如果你通过邮件联系开发者,我们会收到你主动发送的邮箱、文字与附件,并仅将其用于理解、处理和回复你的问题。应用不会自动附加或发送人脸数据、相机画面或诊断 CSV。请不要发送与问题无关的私人照片、乐谱或诊断记录。你可以通过同一邮箱请求删除你主动提供的支持资料。
6. 未成年人使用
应用不要求未成年人提供姓名、账号或联系方式。未成年人需要授权照片、摄像头或向支持邮箱发送资料时,建议由监护人协助决定。
7. 政策更新与联系方式
本政策描述当前版本的数据处理方式。如未来版本改变人脸数据的用途、采集范围、共享或存储方式,我们会在相应功能发布时更新本政策和对应的商店隐私信息,并按适用要求取得许可;本页顶部显示最近更新日期。
联系人:梁斯理
邮箱:178272907@qq.com
技术支持与常见问题
English privacy policy
FanPuQi reads photo and PDF scores and supports touch-based and hands-free head-tilt page turning. This policy explains the data the app processes, its purposes, storage, retention, sharing and deletion, and your choices. The face-data practices below describe version 1.0 and distinguish build 2 from build 3.
1. Camera, TrueDepth/ARKit and face data
1.1 Data processed
The app requests Camera permission when you enter the score reader or calibration feature. With your permission, it uses Apple ARKit face tracking (ARFaceTrackingConfiguration, a TrueDepth-related API) on supported devices. Otherwise, it uses Apple Vision to estimate head pose from the front camera.
The app processes camera frames, face-tracking visibility and the face position and orientation relative to the camera on the device. It derives head angles (roll, pitch and yaw) and uses timestamps to measure how long a head tilt is held. The live camera preview helps you position yourself and keep your face in view.
In version 1.0 build 2, the ARKit adapter read four expression coefficients: left-eye blink (eyeBlinkLeft), right-eye blink (eyeBlinkRight), inner-brow raise (browInnerUp) and tongue out (tongueOut). These were included in the in-memory pose result but were not used for page turning, diagnostic files or transmission. Version 1.0 build 3 removes these four reads. It does not access ARKit expression coefficients and extracts only the head pose and tracking state needed for score page turning.
1.2 Purposes and sharing
Head angles, face visibility and timing are used for head-tilt page turning, neutral-position calibration, tracking feedback and user-enabled local diagnostics. Version 1.0 supports only head-tilt gesture page turning; build 3 does not read expression coefficients.
The app does not use face data to identify individuals, create facial identity profiles, or perform advertising, marketing, profiling, use-based data mining or model training. The app does not automatically upload, disclose or share camera frames, face-tracking data, expression coefficients or diagnostic records with the developer or third parties. ARKit and Vision are Apple on-device system frameworks used by the app; the app does not send face data to a developer-operated cloud service for processing.
1.3 Storage and retention of real-time data
Camera frames and the current face-tracking result are processed in device memory. Build 2 expression coefficients were also processed only in memory; build 3 does not read them. The app does not save camera images or video, complete face-transform matrices, face meshes or expression coefficients to files. Stopping tracking stops camera tracking and clears the app's current pose and preview references. Related memory is released when objects are released or the app process ends; stopping tracking does not imply that every memory buffer is immediately securely erased.
1.4 Optional local diagnostics: storage, retention and deletion
Diagnostic recording is disabled by default. Only after you tap the recording control in the calibration page's advanced diagnostics does the app record relative timestamps, head angles (roll, pitch and yaw) and face visibility in memory. Tapping Stop saves a CSV in the app's local Documents directory so you can investigate tracking or angle issues and adjust page-turning sensitivity.
The diagnostic CSV contains only relative timestamps, three head angles and face visibility. It contains no camera images, video, expression coefficients, face meshes, complete face-transform matrices or identity templates. Without manual diagnostic recording, the app does not write these CSV files. The app has no automatic upload or automatic sharing feature for diagnostic files.
Saved diagnostic CSVs have no automatic expiry or scheduled deletion. They remain in the local app container until its data is deleted. Tapping Stop does not delete files already saved. Diagnostic samples may also remain in memory until a new recording clears them, the recording object is released, or the app process ends. Section 4 explains deleting local data and managing backups.
2. Photo and PDF scores
Photo permission allows the app to read albums, images and related information within the scope you authorize, to display covers, thumbnails and score pages. The app does not modify or delete system photos or upload your photo-library content to the developer.
The app accesses only PDFs you select through the system file picker and renders them on the device. File names and access bookmarks are stored locally so you can reopen the files. The app does not upload the PDFs to the developer.
iCloud Photos and cloud file providers, such as iCloud Drive, may need a network connection to retrieve content you select. Those services manage their own cloud storage and transmission under their respective policies.
3. Local settings, accounts, tracking and system backups
Page-turning sensitivity and calibration angles are stored in local preferences to apply your posture and choices. These settings remain until you change them or delete the local app data; they contain no photos, video or facial identity templates. No account or login is required. The app has no developer-operated user-data backend and no integrated third-party advertising, analytics or tracking SDK.
The app does not proactively transmit your scores, head-movement records or usage behavior to the developer. System backups and system diagnostic sharing may operate according to your Apple settings. Local app data may be included in system backups you enable. This policy does not replace Apple's policies; backup copies must be managed separately through the relevant Apple settings.
4. Your choices, permission withdrawal and deletion
You can revoke the app's Camera permission or change or revoke photo access in system Settings. After Camera permission is revoked, the app cannot continue camera tracking using that permission. Touch-based page turning remains available. Opening PDFs does not require photo permission.
Removing a PDF entry in the app deletes its local access bookmark, not the original file. Selecting Delete App removes the local app container, including settings, bookmarks and diagnostic CSVs. Offload App, which preserves documents and data, does not have the same deletion effect. Deleting the app does not delete your photo library or original PDFs.
Deleting local app data does not automatically delete existing system or cloud backups. If you enabled backups, manage or delete backup copies through Apple or the relevant file provider's settings. The app has no automatically uploaded face-data database for the developer to delete remotely.
5. Contacting support voluntarily
If you email the developer, we receive the email address, text and attachments you choose to send and use them only to understand, handle and reply to your request. The app does not automatically attach or send face data, camera frames or diagnostic CSVs. Please avoid sending private photos, scores or diagnostic records unrelated to your request. You can request deletion of support materials you provided by contacting the same email address.
6. Use by minors
The app does not require minors to provide their name, an account or contact details. A parent or guardian should help decide whether to grant photo or Camera access or send material to support.
7. Policy updates and contact
This policy describes the current version's data practices. If a future version changes the purposes, scope, sharing or storage of face data, we will update this policy and the corresponding App Store privacy information when that feature is released, and obtain permission as applicable. The date at the top identifies the latest update.
Contact: Liang Sili
Email: 178272907@qq.com
Technical support