Nomily AI
隐私政策
最后更新:2026-09-15
Nomily AI 没有账号系统,我们也没有为它运行任何接收你内容的服务器。录音、转写、摘要和 API Key 全都保存在你自己的设备上。数据离开设备的唯一情形,是你自己配置的第三方转写 / AI 服务商。
一、适用范围
本政策适用于 Nomily AI 手机 App(iOS 与 Apple Watch、Android)、命令行工具、可选的自建转写服务,以及本网站。
App 的源码在 nomily-ios 与 nomily-android 两个仓库公开,按 Nomily Small Team License 1.0.0 授权。本政策里的每一条说法,你都可以对着源码自己核实——这是我们选择公开源码的原因之一。
你通过 App 或本网站跳转到的第三方页面与服务(如 Azure、OpenAI、OpenRouter、应用商店、社区平台),适用它们各自的隐私政策。
二、我们不收集什么
- 没有账号、没有注册和登录,我们不持有可以指向你的身份信息。
- 你的录音、转写文本、摘要不会上传给我们——我们没有运行接收这些内容的服务器。
- App 内不含第三方统计、广告或崩溃分析 SDK,不做用户画像、不做跨应用追踪。
- 我们不出售、不交易任何用户数据。没有收集,也就没有可卖的东西。
三、你的数据存在哪里
- 录音、转写、摘要、模板与设置:保存在手机(或电脑)上 App 的私有存储区,随 App 卸载一并删除。
- 服务商 API Key:保存在设备本地。Android 上经系统 Keystore 加密后存放,并排除在云备份之外;密钥不会发给我们,只会随你发起的请求发给对应服务商。
- 设备录音加密口令:口令本身不被保存;由它派生出的密钥存在 iOS Keychain / Android Keystore 中,只对本机有效。口令遗失时加密录音无法恢复,这是加密本身的性质,我们没有后门也无法代为解密。
四、数据什么时候会离开你的设备
只有一种情形:你在设置里配置了云端服务商,并触发了转写或摘要。此时音频或文本会从你的设备直接发送给你选定的服务商,使用你自己的 API Key,不经过我们的任何中转。
App 在首次要把数据发往云端服务商前会弹窗提示并要求确认。你可以选择本地转写服务加本地模型(如自建 faster-whisper 与 Ollama),此时数据完全不出你的设备或局域网。
这些服务商如何存储和使用收到的数据,由你与它们之间的协议和它们的隐私政策决定,我们无法代为约束。是否开启服务商侧的数据保留或训练选项,请到各自的控制台确认。
五、设备连接与本地网络
App 通过蓝牙(BLE)与录音设备通信;快速传输时设备会开启自己的 Wi-Fi 热点,手机直连后走局域网 TCP 取文件。这两条链路都在你身边完成,不经互联网,也不经我们。
Android 上扫描蓝牙设备与发现设备热点需要位置权限,这是 Android 系统的要求。App 在清单里已声明 neverForLocation,不采集、不推断、不使用你的地理位置。
六、权限用途
| 权限 | 用来做什么 |
| 蓝牙 | 发现、连接录音设备,读取设备状态与录音列表 |
| 本地网络 / Wi-Fi(iOS、Android) | 快速传输时直连设备热点下载录音 |
| 麦克风 | 实时转写时与设备的音频流协同;Apple Watch 上录制语音笔记 |
| 位置(仅 Android) | 系统要求:蓝牙扫描与设备热点发现的前置条件,不用于定位 |
| 通知 | 提示传输、转写等后台任务的完成状态 |
七、日志与诊断
App 的运行日志写入操作系统的日志系统,留在你的设备上,不会自动发送出去。只有你主动导出日志并发给我们(例如附在反馈邮件里)时,我们才会看到其中的内容。
通过 App Store 或 Google Play 安装、更新时,商店自身会收集下载与崩溃统计,这部分适用苹果、谷歌各自的隐私政策,我们无法关闭,也不会因此拿到你的录音内容。
八、儿童
本产品不面向 13 周岁以下的儿童(当地法律规定更高年龄的,以当地规定为准)。
九、你的权利
你的数据在你自己手里:在 App 内可以随时查看、导出、删除录音与转写内容;卸载 App 即删除本地全部内容。由于我们不持有账号,也就没有需要向我们申请的数据导出或账号注销。
若你就本政策有任何请求或投诉,可以通过下方邮箱联系我们。对于存放在第三方服务商处的数据,请直接向对应服务商行使权利。
十、关于本网站
本网站是纯静态页面:不设置 Cookie、不做统计分析、不做广告跟踪,只用浏览器的本地存储记住你选的语言。页面中的部分图标来自公共 CDN(jsdelivr),加载这些资源时你的 IP 地址对该 CDN 可见,适用其自身政策。
十一、政策变更与联系方式
政策更新后我们会修改本页内容与上方的更新日期;涉及重大变更时会在 App 内另行提示。
联系邮箱:[email protected]。
Nomily AI
Privacy Policy
Last updated: 2026-09-15
Nomily AI has no accounts, and we run no server that receives your content. Recordings, transcripts, summaries and API keys stay on your own device. The only time data leaves it is when you send it to a third-party transcription or AI provider you configured yourself.
1. Scope
This policy covers the Nomily AI mobile app (iOS and Apple Watch, Android), the command-line tool, the optional self-hosted transcription server, and this website.
The app's source code is published in two repositories, nomily-ios and nomily-android, under the Nomily Small Team License 1.0.0. Every claim in this policy can be checked against that source, which is part of why we publish it.
Third-party pages and services you reach from the app or this site (Azure, OpenAI, OpenRouter, app stores, community platforms) are governed by their own policies.
2. What we do not collect
- No accounts, no sign-up, no sign-in. We hold no identifier that points back to you.
- Your recordings, transcripts and summaries are never uploaded to us. We operate no server that receives them.
- The app contains no third-party analytics, advertising or crash-reporting SDK. No profiling, no cross-app tracking.
- We do not sell or trade user data. Nothing is collected, so there is nothing to sell.
3. Where your data lives
- Recordings, transcripts, summaries, templates and settings: in the app's private storage on your phone or computer, removed when you uninstall the app.
- Provider API keys: stored locally on the device. On Android they are encrypted through the system Keystore and excluded from cloud backup. Keys are never sent to us; they travel only with the requests you make to the provider they belong to.
- Device recording passphrase: the passphrase itself is not stored. The key derived from it lives in the iOS Keychain or the Android Keystore and is valid on that device only. If the passphrase is lost, encrypted recordings cannot be recovered — there is no backdoor and we cannot decrypt them for you.
4. When data leaves your device
One case only: you configured a cloud provider in settings and triggered transcription or summarisation. The audio or text then goes directly from your device to the provider you chose, authenticated with your own API key. It does not pass through anything of ours.
Before the first upload to a cloud provider the app shows a consent prompt. You can instead run a local transcription server and a local model (for example self-hosted faster-whisper with Ollama), in which case nothing leaves your device or your LAN.
How those providers store and use what they receive is governed by your agreement with them and by their privacy policies; we cannot bind them on your behalf. Check their consoles for data-retention and training settings.
5. Device connection and local network
The app talks to the recorder over Bluetooth Low Energy. For fast transfer, the device opens its own Wi-Fi access point and your phone connects to it directly over TCP. Both paths are local; neither goes over the internet or through us.
On Android, scanning for Bluetooth devices and discovering the device hotspot require location permission — that is an Android platform requirement. The app declares neverForLocation and does not collect, infer or use your geographic location.
6. Permissions
| Permission | What it is used for |
| Bluetooth | Discover and connect to the recorder, read device state and the recording list |
| Local network / Wi-Fi (iOS, Android) | Connect straight to the device hotspot during fast transfer |
| Microphone | Coordinate with the device's audio stream during live transcription; record voice notes on Apple Watch |
| Location (Android only) | Platform prerequisite for BLE scanning and hotspot discovery; not used for positioning |
| Notifications | Report completion of background transfers and transcription jobs |
7. Logs and diagnostics
Runtime logs are written to the operating system's log facility and stay on your device. They are not sent anywhere automatically. We see them only if you export the log yourself and send it to us, for example attached to a support email.
When you install or update through the App Store or Google Play, those stores collect their own download and crash statistics under Apple's and Google's privacy policies. We cannot turn that off, and it never gives us the content of your recordings.
8. Children
The product is not directed at children under 13, or under the higher age set by local law where that applies.
9. Your rights
Your data is in your own hands: view, export or delete recordings and transcripts in the app at any time, and uninstalling removes everything local. Because we hold no account, there is no data export or account deletion to request from us.
For requests or complaints about this policy, email us at the address below. For data held by a third-party provider, exercise your rights directly with that provider.
10. About this website
This site is static: no cookies, no advertising trackers, and no first-party analytics. A footer page-view counter loads a public SVG from visitor-badge.laobi.icu; that service receives your IP address and increments an aggregate page-view count under its own policy. Browser local storage is used only to remember your language choice. Some icons load from a public CDN (jsdelivr), which also sees your IP address when they are fetched, under its own policy.
11. Changes and contact
When this policy changes we update this page and the date above; significant changes are also announced in the app.
Contact: [email protected].