南京老法师 · Nanjing Laofashi

南京老法师隐私政策 / Nanjing Laofashi Privacy Policy

生效及最后更新 / Effective and last updated: 2026-09-14
Contact / 联系: [email protected]
Privacy / 隐私: nanjinglaofashi.com/privacy.html
Terms / 条款: nanjinglaofashi.com/terms.html
Support / 支持: nanjinglaofashi.com/support.html

中文

1. 适用范围

本政策适用于“南京老法师”首版原生 iOS App(下称“App”)、nanjinglaofashi.com 网站(下称“网站”)及其后端。App 和网站的功能不同,请以相应章节为准。

首版 App 拟在中国大陆以外的 App Store 免费提供,无广告、无 App 内购买。我们不出售个人信息,也不为广告目的进行跨 App 跟踪。

2. 首版原生 App

2.1 首版明确不提供的功能

App 不提供注册、登录或账户;不接入网站公开留言板;不生成法律文书;不提供语音录入、不录音,也不请求麦克风或定位权限。App 不调用网站的 /api/hit,不会把 App 访问事件写入网站 visits 统计表。

因此,网站账户、留言、语音转写、文书生成、Nominatim 地址反查及网站访问统计不属于首版 App 的数据流。

2.2 法律库、收藏、缓存与期限提醒

随 App 提供的法律资料可离线浏览;联网时,App 可从南京老法师服务器检查并缓存公开资料更新。联网资料缓存、收藏、用户填写的期限日期/备注、AI 同意记录和本地通知计划保存在设备上,不上传至南京老法师后端,也不用于广告或用户画像。

删除 App 或清除 App 数据通常会删除这些内容,但仍受 iOS 备份和设备设置影响。期限提醒只是便利工具,用户必须独立核对法定、合同、签证、仲裁和诉讼期限。

2.3 110/120/119/122 拨号与双语播报

App 可启动 110、120、119 或 122 的系统拨号确认界面。App 不自动拨出、不替用户联系机构,也不收集通话内容或通话记录。

双语求助信息由 Apple 的 AVSpeechSynthesizer 系统框架播报。App 代码不把播报文字或音频上传至南京老法师后端。App 不是警察、医疗、消防或其他紧急服务;现实危险中请直接联系所在地适用的紧急机构。

2.4 首版不使用定位

首版 App 不请求或使用定位权限,不读取精确经纬度,也不调用 Nominatim 或其他地址反查服务。文字 AI 网络请求可能由 Cloudflare 派生粗略国家、地区或城市;该数据流见下文 2.5。

2.5 文字 AI 问答

文字 AI 是首版 App 唯一会把用户主动输入发送到南京老法师后端的功能。我们可能处理:

首版 App 无账户,因此 App AI 请求不含 App 账户编号或账户邮箱。法律问题可能主动包含家庭、雇佣、健康、刑事、财务或其他敏感事实。请仅输入获得一般信息所必需的内容,不要输入无关的证件号码、银行卡资料、密码、完整住址或第三人的非必要信息。

虽然首版 App 无账户,但上述自由文本、粗略地区、IP 指纹、user-agent、模型与耗时会按同一请求共同保存;因此 App Store 隐私披露按保守口径将相关数据视为与用户设备或请求关联,但不用于广告跟踪。

问题由 Cloudflare Worker 发送至 Cloudflare Workers AI;问题、答复及关联技术日志可能写入 Cloudflare D1,最长保存 30 天。原始 IP 限流记录最长保存 24 小时。AI 可能不完整、过时或错误,不构成正式法律意见。

我们执行上述保存期限,并在相应期限届满后删除数据或进行去标识化,但法律、安全或争议处理确有必要时除外。

2.6 支持邮件

用户点按 App 的邮件联系入口时,由用户选择的系统邮件客户端打开;App 不会自动发送邮件。用户确认发送后,我们可能收到发件邮箱地址、主题、正文、附件、邮件头,以及用户主动写入的 App/设备信息。我们仅用于响应支持、隐私请求、安全调查或履行法律义务,并在处理和必要后续完成后删除或去标识,但法律、安全或争议处理确有必要时可保留更长时间。用户可通过同一邮箱请求删除。

3. 独立网站

网站可能提供比首版 App 更多的功能。仅在使用相应网站功能时,网站可能处理以下数据:

3.1 网站账户与留言板

网站注册可能处理姓名、邮箱、密码的加盐哈希值、内部用户编号、注册时间、最近登录时间和会话状态。网站公开咨询留言板可能保存标题、问题、帖子、回复和时间;公开页面会部分隐藏账户姓名,不显示账户联系方式,但运营后台可访问账户资料和内容。请勿在帖子正文自行填写私人联系方式或敏感资料。

网站账户可通过网站删除入口或发送邮件至 [email protected] 申请删除。经认证和明确确认的账户删除流程会在同一 D1 批处理中删除账户、用户帖子及其回复、按用户编号或邮箱关联的 AI 日志,并注销会话。

假名化访问统计、短期限流记录及未登录时产生且无法可靠关联到账户的 AI 活动,分别按 365 天、24 小时和 30 天期限到期,不一定能在账户删除时单独定位。

3.2 网站语音、AI 与文书

网站可能在用户主动授权后录制一次语音输入,上传至 Cloudflare Workers AI 转写。当前应用代码不把原始音频写入 D1;转写文字继续用于 AI 时可能进入 30 天 AI 日志。Cloudflare 基础设施层面的临时请求处理须以发布时合同和配置为准。

网站还可能处理文字法律问题、文书事实、修改指示、生成答复和文书草稿,以及关联技术信息。网站已登录请求可能与用户编号和邮箱关联;这些 AI 日志最长保存 30 天,账户删除时会删除可关联日志。

这些网站专属的语音和文书功能不在首版原生 App 中。

3.3 网站定位与 Nominatim

仅当网站用户主动请求地址转换并授权时,网站可能把经纬度发送至 Cloudflare Worker,并转发给 OpenStreetMap Nominatim 反向地理编码。网站应用代码不把精确坐标写入 D1,但 Cloudflare 和 Nominatim 可能按其规则处理请求 IP、坐标和时间。

首版 App 不使用此数据流,也不请求定位权限。

3.4 网站访问统计

网站 /api/hit 可能保存访问时间、随机假名访客标识、来源类别/域名、国家、设备类别和浏览器类别,最长 365 天。网站访问表不写入原始 IP,但服务器和 Cloudflare 仍会在网络与安全层处理 IP。首版 App 不调用 /api/hit

4. 处理目的和服务提供者

我们仅为提供用户主动请求的功能、维护安全、限制滥用、排查故障、形成必要统计、响应支持请求和履行法律义务处理数据。根据功能,接收者可能包括:

我们要求代表我们处理 App 用户数据的服务商提供与本政策及 Apple 要求相同或同等程度的保护,并只按约定目的处理数据。服务商可能在用户所在地区以外处理数据;在适用法律要求时,我们采用相应合同或其他跨境保护机制。

5. 保存期限

数据最长期限或状态
App 文字 AI 问题、答复和关联技术日志30 天
AI 限流原始 IP 小时记录24 小时
App 收藏、缓存、期限和通知设备本地,至用户清除或删除 App
用户主动发送的支持/隐私邮件至处理和必要后续完成;法律、安全或争议处理确有必要时可更久
网站账户至用户删除账户或提出有效删除申请
网站帖子和回复至用户/运营者删除或账户删除
网站 AI/文书日志30 天;可关联日志也随账户删除
网站明细访问统计365 天
网站原始语音应用层不持久保存,仅完成本次转写所需时间
网站精确坐标应用数据库不持久保存,仅用于本次 Nominatim 请求
备份、安全或争议记录仅在实现安全、解决争议或履行法律义务所需期间保留;目的完成后删除或去标识

我们执行上述保存期限,并在相应期限届满后删除数据或进行去标识化,但法律、安全或争议处理确有必要时除外。

6. 用户选择和权利

用户可以关闭 App 通知权限、不使用文字 AI、清除设备本地数据,并根据适用法律请求查阅、更正或删除服务器数据。网站账户用户可通过网站删除入口或 [email protected] 申请删除。普通隐私或数据请求也可发送至该邮箱,主题注明“Data Request / 数据请求”。

我们可能进行必要的身份核验。目标是在 30 天内完成有效删除请求,或在法律允许延长时说明理由。删除 App 本身不会删除独立网站账户。

7. 安全、未成年人及法律提示

我们采用传输加密、加盐密码哈希、受保护会话、访问控制和限流等措施,但任何系统均不能保证绝对安全。本服务并非专门面向儿童;未成年人应在监护人指导下使用并避免提交无关信息。

App 和网站提供一般法律信息,使用服务不自动形成律师—客户关系、正式委托、保密义务或法律特权。AI 结果必须核实。App 和网站均不是紧急服务。

8. 政策变更和联系

功能、服务商或法律变化时,我们可能更新本政策,并在适用时提供显著通知或重新取得许可。联系邮箱:[email protected]

1. Scope

This Policy covers the first native Nanjing Laofashi iOS app (the “App”), the separate nanjinglaofashi.com website (the “Website”), and their backend. The App and Website have different features; the sections below distinguish them.

The first App release is planned as a free product outside the mainland China App Store, with no advertising or in-app purchases. We do not sell personal data or track users across apps for advertising.

2. First native App release

2.1 Features not present

The App has no registration, login, or account; no public board; no document generation; and no voice input, recording, microphone permission, or location permission. It does not call the Website’s /api/hit endpoint or write App visits to the Website visits table.

Website accounts, board posts, transcription, document drafting, Nominatim reverse geocoding, and Website visit analytics are therefore not App data flows.

2.2 Library, bookmarks, cache, and deadlines

The law library bundled with the App is available offline; when online, the App may check the Nanjing Laofashi server for public-content updates and cache them. Online-content cache, bookmarks, deadline dates/notes, AI-consent records, and local notification schedules remain on the device. They are not sent to our backend or used for advertising or profiling.

Removing the App or clearing App data normally removes them, subject to ordinary iOS backup settings. Reminders are only a convenience; users must independently verify every legal, contractual, visa, arbitration, and litigation deadline.

2.3 Calling and bilingual playback

The App can open the standard iOS call-confirmation flow for 110, 120, 119, or 122. It does not call automatically or collect call content or call history.

Bilingual help messages are played by Apple’s AVSpeechSynthesizer system framework. App code does not upload playback text or audio to our backend. The App is not a police, medical, fire, or other emergency service. Contact the appropriate local authority in a real emergency.

2.4 No location access in the first release

The first App release does not request or use location permission, read precise coordinates, or call Nominatim or another reverse-geocoding service. Cloudflare may derive an approximate country, region, or city from text-AI network requests; that flow is described in Section 2.5.

2.5 Text AI Q&A

Text AI is the only first-release App feature that sends user-entered content to our backend. We may process:

The first App release has no account, so App AI requests contain no App account ID or account email. A legal question may voluntarily reveal sensitive family, employment, health, criminal, or financial facts. Submit only what is necessary and do not include unrelated identity numbers, payment-card data, passwords, full home addresses, or unnecessary third-party information.

Although the first App release has no account, free text, coarse region, IP fingerprint, user-agent, model, and timing are stored together for the same request. App Store disclosures therefore conservatively treat the relevant data as linked to a device or request, while confirming it is not used for advertising tracking.

Questions pass through a Cloudflare Worker to Cloudflare Workers AI. Questions, answers, and related technical logs may be stored in Cloudflare D1 for up to 30 days. Raw-IP rate-limit records are retained for up to 24 hours. AI may be incomplete, outdated, or wrong and is not formal legal advice.

We apply these retention periods and delete or de-identify the data when the applicable period expires, except where longer retention is necessary for law, security, or dispute handling.

2.6 Support email

Tapping the App’s email contact opens the user-selected system mail client; the App does not send email automatically. If the user confirms sending, we may receive the sender’s email address, subject, body, attachments, message headers, and any App/device information the user chooses to include. We use these only to respond to support or privacy requests, investigate security, or comply with law. We delete or de-identify them after the request and necessary follow-up are complete, unless a longer period is needed for law, security, or dispute handling. Users may request deletion through the same address.

3. Separate Website

The Website may offer features not present in the first App release.

3.1 Website accounts and public board

Website registration may process name, email, salted password hash, internal user ID, registration time, last-login time, and session state. Its public consultation board may store titles, questions, posts, replies, and timestamps. Public pages partially mask account names and do not display account contact details, while the operator’s admin view can access account information and content. Do not put private contact details or sensitive information in the text of a public post.

A Website account may be deleted through the Website deletion control or by emailing [email protected]. The authenticated, explicitly confirmed deletion flow deletes the account, that user’s posts and replies, and AI logs linked by user ID or email in one D1 batch, then clears the session.

Pseudonymous visit events, short-lived rate-limit rows, and signed-out AI activity that cannot reliably be linked to the account expire under their respective 365-day, 24-hour, and 30-day policies and may not be individually locatable during account deletion.

3.2 Website voice, AI, and documents

After the Website user grants permission and starts voice input, the Website may record one input and send it to Cloudflare Workers AI for transcription. Current application code does not write raw audio to D1; a transcript used for AI can enter the 30-day AI log. Processor-level temporary request handling depends on the current Cloudflare contract and configuration.

The Website may also process text questions, document facts, revision instructions, generated answers and drafts, and related technical data. Signed-in Website requests may be linked to user ID and email. These AI logs are retained for up to 30 days, and linkable logs are deleted with the account.

These Website-only voice and document features are not in the first native App release.

3.3 Website location and Nominatim

Only when a Website user requests address conversion and grants permission may the Website send coordinates through a Cloudflare Worker to OpenStreetMap Nominatim for reverse geocoding. Website application code does not write precise coordinates to D1, but Cloudflare and Nominatim may process request IP, coordinates, and time under their own rules.

The first App release does not use this flow or request location permission.

3.4 Website visit analytics

The Website’s /api/hit may store visit time, a random pseudonymous visitor ID, referring category/domain, country, device class, and browser class for up to 365 days. The visit table does not store raw IP, although servers and Cloudflare process IP at the network/security layer. The App does not call /api/hit.

4. Purposes and providers

We process data only to provide requested functions, secure the service, limit abuse, troubleshoot, produce necessary statistics, respond to support requests, and comply with law. Depending on the feature, recipients may include:

We require providers processing App user data on our behalf to provide the same or equivalent protection described by this Policy and required by Apple, and to process the data only for agreed purposes. Providers may process data outside the user’s region; where applicable law requires, we use relevant contractual or other transfer safeguards.

5. Retention

DataMaximum period or status
App text AI questions, answers, and related technical logs30 days
Raw-IP AI rate-limit hour records24 hours
App cache, bookmarks, deadlines, and notificationsOn device until cleared or App deletion
Support/privacy emails the user chooses to sendUntil the request and necessary follow-up are complete; longer only where needed for law, security, or dispute handling
Website accountUntil the user deletes the account or makes a valid deletion request
Website posts and repliesUntil user/operator deletion or account deletion
Website AI/document logs30 days; linkable logs also deleted with the account
Detailed Website visit analytics365 days
Raw Website voice inputNot persisted at the application layer; only as needed for the current transcription
Precise Website coordinatesNot persisted in the application database; used only for the current Nominatim request
Backup, security, or dispute recordsOnly as long as needed for security, dispute resolution, or legal duties; then deleted or de-identified

We apply the periods above and delete or de-identify data when the applicable period expires, except where longer retention is necessary for law, security, or dispute handling.

6. Choices and rights

Users can disable App notifications, avoid text AI, clear local App data, and exercise access, correction, or deletion rights under applicable law. Website account users can use the Website deletion control or email [email protected]. Other privacy requests can be sent to the same address with “Data Request” in the subject.

We may reasonably verify identity. Our target is to complete a valid deletion request within 30 days or explain a legally permitted extension. Removing the App does not delete a separate Website account.

7. Security, children, and legal notice

We use encrypted transport, salted password hashing for Website accounts, protected sessions, access controls, and rate limiting, but no system is absolutely secure. The service is not specifically directed to children; minors should use it with a guardian and avoid irrelevant submissions.

The App and Website provide general legal information. Use does not automatically create an attorney-client relationship, formal engagement, confidentiality duty, or privilege. AI results must be verified. Neither the App nor Website is an emergency service.

8. Changes and contact

We may update this Policy when features, providers, or laws change and provide prominent notice or renewed permission where required. Contact: [email protected].