Msats Privacy Policy

Last updated: October 1, 2026 · v2.3

Information we collect and use

How you sign in

Sign in with Apple

We receive the anonymous Apple user identifier and, if you allow it, your name. Msats requests only your name, not your email address. If Apple includes an email address in the sign-in credential (for example because you shared it earlier), our servers do not store it.

Sign in with WeChat

WeChat sign-in is not offered in this version. If we enable it, we would receive the openid and unionid issued by WeChat plus the nickname and avatar you authorize, stored on Msats servers so we can recognize you at the next sign-in. We would not receive your WeChat password, contact list, chat history or moments.

Phone number sign-in

Msats does not currently offer phone-number/SMS sign-in, and we do not collect your phone number. If we enable it in a future version, your phone number would be sent to Alibaba Cloud SMS solely to deliver the verification code, and this policy would be updated first.

Location data and Footprint Run

Location is sensitive personal information. We collect it only while you have actively started a run, while you are in a Buddy Run room, at the moment you create or search for nearby clubs, and when you set a private zone. The app does not track your location in the background outside of an active run.

What we collect

During a run (including while the app is backgrounded after you press Start) we record track points containing longitude, latitude, timestamp, location accuracy and instantaneous speed. Highest system accuracy is used, roughly one point every 5 metres, so distance and pace are correct. Altitude is not recorded in the track. The city used for city leaderboards is worked out by our server from the midpoint of your submitted track, using an offline administrative-area database.

Why it is uploaded, and what is actually sent

Footprint Run awards you the hexagonal cells enclosed by your route. That has to be computed on the server — otherwise anyone could fabricate a result locally. Only after you have agreed to the Footprint explanation is each outdoor run submitted for a claim when it ends, together with your nickname and membership tier. If you have not agreed, your runs are never submitted and the track never leaves your phone.

The track is simplified on your device before it is sent, not uploaded raw: redundant points are removed with a Ramer-Douglas-Peucker pass at a 12-metre tolerance, the result is capped at 600 points, and every coordinate is rounded to 4 decimal places (roughly 11 metres). What reaches our server is therefore a coarse outline of your route, accurate enough to decide which hexagons it encloses and nothing more.

What the server keeps, and for how long

Who can see your footprints

Cells you claim are shown on every user's footprint map, labelled with your nickname and avatar, and your cell count appears on city leaderboards. That is the core of the game, and we want you to understand it before you start. Under Profile → Settings → Social & Visibility you can turn on Map anonymity, so that the map shows only your colour, without your nickname or avatar.

Private zone

Under Footprint → Mine → Private zone you can define a circle of 100–2000 m (for example around your home or workplace). Cells inside it are filtered out by the server before sending — other users' devices never receive that data, rather than merely hiding it in the interface. A private zone does not affect your claims or your ranking. We prompt you to set one after your first successful claim. To do the filtering, the server stores the zone's centre (to about 1 metre) and its radius; turning the zone off or deleting your account deletes them.

Other uses of location

You can decline

You may deny location permission, or revoke it at any time in iOS Settings → Privacy & Security → Location Services. Run tracking and Footprint Run will not work, but the rest of the app is unaffected.

Device integrity check (App Attest)

What we collect

Only when a Footprint claim is submitted, the app asks Apple's App Attest service to certify that the request really comes from an unmodified copy of Msats on a genuine Apple device. We store the resulting device public key and a monotonic counter.

Why

Footprints are a competitive feature. Without this check, a modified client or a script could mint territory that nobody ran. The attestation is checked only at claim time.

What it is not

The App Attest key is not a device identifier. Apple derives it per app and per device, it cannot be correlated with any other app or with advertising identifiers, and we do not use it for profiling, analytics or advertising. It is never shared with third parties.

How long we keep it

The key and counter are kept while your account exists and are deleted when you delete your account.

Buddy Run

What we collect

When you and your partner are close together, the two phones exchange position and distance directly over Bluetooth and Ultra Wideband; this does not go through our servers. In remote mode (a membership feature), your real-time position, speed, heading and cumulative distance — plus, if you use "Listen together", the title and artist of the song you are playing — are sent to our server and relayed to the other people in the same room (up to four in total), so that you can see each other on the mini-map and see the distance between you.

What the server keeps

The server holds only the most recent position packet, in memory. It is overwritten by the next packet, and cleared automatically after 90 seconds without an update. It is never written to disk, to the database or to a backup, and it is not used to build a track.

How to turn it off

Leave the room, or simply do not start a Buddy Run. Your partner in the room can see your live position while the session lasts — that is the purpose of the feature, so only pair with people you trust.

Social square and clubs

What we collect

Who can see it, and for how long

Each post can be set to Everyone or Only me. Posts you set to Everyone are visible to all Msats users, and content you post inside a club is visible to that club's members. Posts are kept indefinitely until you delete them or delete your account.

Images and videos are served from a public URL. The address is hard to guess, but it is not access-controlled: anyone who obtains the link — for example because someone re-shared it — can open it without being logged in. Please do not post images or videos you would not want seen outside the app.

Reports

When you report a post, a comment or a user, we record who filed the report, along with the target and your reason. We do this to detect and stop malicious mass-reporting. Reporter identity is visible only to our content-moderation staff, and is never shown to the person you reported.

How to turn it off

Posting is entirely optional. Under Profile → Settings → Social & Visibility you can set the default audience, switch off attaching running routes, and turn on Map anonymity. You can delete any post or comment you made at any time, which removes it from our servers.

Share links and plan QR codes

Workout share links

When you create a share link for a workout, the following is stored on our servers and shown on a public web page that anyone with the link can open without signing in: your nickname, the title and time, distance, duration, pace, average and maximum heart rate, steps, cadence, splits, exercises with sets and weights, up to six song titles, and the shape of your route with all latitude and longitude removed. Share pages are kept for 180 days. To take one down earlier, contact us at the address below; deleting your account deletes all share pages you created.

Plan QR codes

When you share a training plan by QR code, the plan name, exercises, sets and reps, and its compressed background image are stored on our servers for 7 days so that the person scanning the code can import the plan. This package is not linked to your account.

Gym membership cards

If a gym issues you a membership card through Msats and you claim it, that gym can see your Msats nickname and your check-in history at that gym. The cardholder name and phone number on the card are entered by the gym, which is responsible for them; we store them on the gym's behalf. When you add a card to Apple Wallet, Wallet registers a device library identifier and a push token with our server so that the card can be updated. Deleting your account unlinks and cancels your cards; a gym's own business records about its members remain with that gym.

Sign in with Msats (sharing with other apps)

Msats can act as a sign-in provider for other apps we publish. Today the only integrated app is Pace Go. Nothing is shared until you complete the authorization screen, and the screen lists exactly what is being requested. In this version you cannot authorize new apps; you can view and revoke existing authorizations.

What the other app can receive

What is stored on Msats servers

Run records synced through this feature are stored on Msats servers, not only on your device. Each record may contain the start and end time, distance, duration, calories, average and maximum heart rate, per-kilometre splits and an optional note. This is a deliberate exception to "health data stays on your device", because both apps need one shared, de-duplicated copy.

How long, and how to revoke

Records are kept until you delete your account. You can revoke an app's access at any time under Profile → Settings → Authorized Apps; the app immediately loses the ability to read or write anything. Revoking does not by itself delete records already synced — deleting your Msats account does.

Food and nutrition data

Kept on your device by default

Your food, water, caffeine, fasting and carb-cycling logs, your calorie and nutrient goals, and the food cut-out images created from your photos are stored on your device and synced to your Apple Watch and widgets. If you turn on iCloud Sync (a membership feature), they are mirrored to your own iCloud Drive, which Msats cannot access.

Apple Health

With your permission, Msats writes the calories, protein, carbohydrates, fat, fiber (with the food name) and water you log to Apple Health, and reads the same dietary types from Apple Health to show daily totals on your device. Dietary data read from Apple Health is never uploaded to Msats servers or written to iCloud backups, and is not shared with anyone except as described under "AI meal plans, AI coach and analysis" below.

Food photo recognition

When you take or choose a photo to estimate calories, we send the compressed photo (longest side up to 1,024 pixels), any voice or text note you add (up to 200 characters; voice is transcribed on your device where supported) and your app language to the Msats server, which forwards them to ByteDance Doubao (Volcano Ark, primary) or Alibaba Cloud Qwen (fallback) to identify the food and estimate the portion and nutrients. If our built-in nutrition database has no match, the server may send only the recognized food name — never the photo or anything about you — to Bocha AI web search to calibrate calories per 100 g. In "Packaged food" mode the nutrition label is read on your device first; the photo is sent only if that fails. Photos are discarded after processing, never written to our database or disk, and never used by us to train models. We record only the time, the model and the usage of each request — against your account when you are signed in, or your IP address when you are not — for quota management and abuse prevention (see "AI usage records").

"Calories from my latest screenshot" Shortcut

When you run this Shortcut, Msats reads the most recent screenshot in your photo library and sends it for recognition as described above. Screenshots of delivery orders may show a name, address or phone number — please check before running it.

AI meal plans, AI coach and analysis

When you ask AI to create or adjust a meal or fat-loss plan, ask the AI coach about food, or run data insights or deep analysis, we send your height, weight, target weight, age, sex, training frequency, the preferences you type, and summaries of your food logs over the last 7–90 days (average daily calories, macronutrients and water, your goals, and the number of days logged). The one-time "what AI knows about you" profile created after you connect Apple Health also includes your Apple Health dietary averages. Individual meals and food photos are not sent unless you attach a photo in the chat. This content is used only to produce the result and is not stored on our servers.

Sharing

Only when you post a meal card to the social square are its calories and three macronutrients stored on our servers and visible to others.

Deletion

You can delete any food entry at any time; the matching samples Msats wrote to Apple Health are deleted with it. Deleting your account erases food data on your device; backups in your own iCloud Drive and data in Apple Health are managed by you in iOS Settings and the Health app.

Third-party AI processing

Msats uses ByteDance Doubao (Volcano Ark) as its primary AI provider — in this version the AI coach uses the doubao-seed-2-1-turbo model — with Alibaba Cloud Qwen (Model Studio/DashScope) as a fallback. Both providers' servers are located in mainland China. The app explains what will be sent and asks for your separate consent before sending photos or text to AI processing; photos you attach in the AI coach are downscaled to 1,024 pixels on the longest side. The AI coach can read your calendar (event titles, times and locations, without notes or attendees) and your open reminders (titles and due times) only after you give a further, separate permission. You can withdraw consent at any time under Profile → Settings → Privacy → Allow AI to process my data; doing so also withdraws the photo and calendar permissions.

The data sent for AI features is used only to generate the requested result. It is not used by Msats for advertising, identity recognition, or model training. We do not permit the AI provider to use this content for advertising or model training, and the provider is expected to protect the data with safeguards comparable to those used for the Msats service.

AI deep analysis in Data archive

What is sent

Data archive → AI deep analysis is a paid feature. When you start it, we send a statistical summary of your data to the third-party AI provider. The summary contains: your weekly training volume for the last 8 weeks, the distribution of volume across muscle groups, your most-trained exercises and personal records, your average daily calories and water intake over the last 30 days, your first and last body weight in the period, and how many days you checked in.

It does not contain individual entries — no single meal, set or run — and no photos. The analysis runs as three consecutive rounds, so the summary is sent up to three times in one session.

How long is it kept

The summary is not stored: it exists only in the request path. The report you get back is stored on your device.

How to turn it off

Do not start the analysis, or switch off "Allow AI to process my data" under Profile → Settings → Privacy, which disables this feature along with all other AI features.

Voice input

When you use voice commands or voice input, your speech is transcribed by Apple's speech recognition — on your device whenever your iPhone supports it; only if it does not is the audio sent to Apple's servers for processing. Msats receives only the resulting text; we do not store the audio. You can avoid speech recognition entirely by typing instead, or by revoking microphone and speech-recognition permission in iOS Settings → Privacy & Security.

Notifications

Push notifications from our servers

This version of Msats does not register for push notifications from our servers, so we do not collect a push token for the app and do not send you server push alerts. Gym membership cards in Apple Wallet are refreshed through Wallet's own push mechanism. If we enable server push in a future version (for example "someone commented on your post" or "your footprint cells were taken"), we will update this policy first; such alerts would never contain your health data or location.

Notifications created on your device

AI health insight, rest-timer and reminder notifications are generated by the app on your device and do not go through our servers. AI health insights may show figures such as your active calories or how far your resting heart rate is above your usual level, and these can appear on your lock screen. You can turn each type off under Profile → Settings → Reminders, or turn all notifications off in iOS Settings → Notifications → Msats.

Server access logs

What is recorded

Every request to our servers is written to a technical access log containing the timestamp, the IP address, the request path (with any coordinates stripped out of the query string), a masked user identifier and the HTTP status code.

Request bodies are never logged. Tracks, photos, post text, chat content and AI prompts do not appear in the log.

The server process also writes a runtime log for troubleshooting, which likewise contains IP addresses and request paths and is rotated and deleted automatically. When food recognition fails, this log may record the recognized food name or an excerpt of up to 220 characters of the model's reply. Photos, tracks, post text, chat content and AI prompts are never written to it.

Why, and for how long

Article 21 of the Cybersecurity Law of the PRC requires network operators to retain relevant logs for no less than six months. We keep one access-log file per day and delete files automatically after 200 days. The logs are used only for security auditing and fault diagnosis; they are not used for profiling, recommendation or advertising.

Note on deletion

Because this retention is a legal obligation, deleting your account does not delete these logs. They age out on their normal schedule like everyone else's.

Data recipients

When you use the corresponding feature, the app or our server interacts with the following parties. Where your device connects to a party directly, that party can see your IP address; where our server connects on your behalf, the party sees only our server.

Except as described above for AI features, gyms, Buddy Run partners and apps you authorize through Sign in with Msats, your location data, footprint data and health data are not provided to any of these parties.

Discontinued features

Friends and chat were removed from Msats on August 11, 2026. The friend list, friend requests and the encrypted messaging feature no longer exist in the app; all related code and interfaces have been deleted from the client.

Undelivered encrypted messages held on our servers are deleted automatically after 14 days. Existing friend relationships, together with the public keys and push tokens used by that feature, are no longer served to any client and are deleted when you delete your account. Leftover local settings from the feature are cleaned up automatically the next time you launch the app.

As a consequence, the post audience option "Friends only" is no longer available; existing posts that used it are treated as "Only me". If you have questions about data from the discontinued feature, contact us at the address below.

Features processed only on your device

Camera-based jump-rope rep counting, cycle tracking, and caffeine, fasting and carb-cycling logs are processed only on your device (and in your iCloud if sync is on). Data from your Apple Watch is sent only to your iPhone; it leaves your iPhone only in the cases listed under "Health and fitness data".

Storage and security

Local data is protected by the iOS sandbox. iCloud sync (a membership feature) uses your own private iCloud account, which Msats cannot access. Before anything is copied to iCloud, heart-rate fields and health-sample identifiers obtained from Apple Health are removed, and runs and workouts imported from Apple Health are not copied at all; they remain in Apple Health.

Where data is stored: Msats servers are located in mainland China (Alibaba Cloud, Hangzhou). Your location data, footprint data, social content and account information are stored there and are not transferred abroad. If you use Msats outside mainland China, your data is transferred to and processed on these servers in mainland China.

In transit: all communication between the app and our servers uses HTTPS.

Image metadata: photos, the video part of Live Photos and avatars you upload have their metadata — including capture location, device model and timestamp — stripped before they are stored, so that an image you post cannot reveal where it was taken.

Internal access control

Only a small number of authorized staff can access production data, and only when handling a cheating appeal or a content report. In those cases the location data they see is blurred: the precise-coordinate mode of our moderation console is disabled by default in production. Access to that console is password-protected and every use is recorded in the access log described above.

Subscriptions and payments

Memberships are purchased and billed through the Apple App Store; we never receive your card number or any payment credentials. To verify your membership on our servers, handle renewals and refunds, and provide support, the app uploads the Apple-signed transaction receipt to our server when you purchase or restore, and we also receive subscription status notifications from Apple. From these we store: transaction IDs, the product (membership tier and period), purchase and expiration dates, trial status, auto-renew status, billing grace-period and refund/revocation status and a short history of status changes, environment (production/sandbox), storefront region, price and currency, and a random account token (appAccountToken) used to match the subscription to your Msats account. This information is used only for entitlement checks, customer support and aggregate business statistics, and is not shared with third parties. When you delete your account, these subscription records are deleted as well (Apple retains its own purchase records under its policies).

Your choices and rights

For help exercising any of these rights, or any privacy question, contact frankdoug87@gmail.com.

Minors

Msats is designed for adults. If you are under 18, please use it with the consent and guidance of a parent or guardian. If you are under 14, please have a guardian read this policy and consent before use. If we learn we have collected personal information from a child under 14 without guardian consent, we will delete it promptly. Guardians may contact us at the address above to review or delete such information.


Msats 隐私政策

更新日期:2026 年 10 月 1 日 · 版本 v2.3

我们收集和使用的信息

登录方式

Apple 登录

我们接收 Apple 签发的匿名用户标识,以及你允许提供的姓名。Msats 只请求姓名,不请求邮箱地址;即使 Apple 在登录凭证中附带了邮箱(例如你此前授权过),我们的服务器也不会保存它。

微信登录

当前版本未提供微信登录。如果未来开启,我们将接收微信签发的 openid 与 unionid,以及你授权的昵称和头像,保存在 Msats 服务器,用于下次登录时识别你的账号;我们不会获取你的微信密码、通讯录、聊天记录或朋友圈。

手机号登录

当前版本的 Msats 未提供手机号短信登录,我们不收集你的手机号。如果未来版本开启该方式,你的手机号将仅发送给阿里云短信服务用于下发验证码,并且我们会先更新本政策。

位置信息与「足迹跑」

位置信息属于敏感个人信息。我们只在你主动开始一次跑步、你处于「并肩跑」房间中、你创建俱乐部与搜索附近俱乐部、以及你设置隐私区的那一刻采集,App 不在跑步之外的后台长期跟踪你的位置。

采集什么

跑步过程中(包括你按下开始后 App 退到后台时)记录轨迹点,每个点包含:经度、纬度、时间戳、定位精度、瞬时速度。为保证距离与配速准确,记录时使用系统最高定位精度,约每 5 米记一个点。海拔不进入轨迹记录。同城排行榜所用的城市名,由服务器根据你提交轨迹的中点、使用离线行政区划库计算得出。

为什么要上传,实际上传的是什么

「足迹跑」的规则是:跑出的闭合路线所围住的六边形格子归你所有。这个判定必须在服务器完成,否则任何人都可以在本机伪造成绩。只有在你同意足迹说明之后,每次户外跑步结束时,App 才会提交本次轨迹进行结算,并一并上传你的昵称和会员档位。如果你没有同意,跑步不会被提交,轨迹不会离开你的手机。

轨迹在你的手机上先做抽稀再上传,不是原样上传:先用 Ramer-Douglas-Peucker 算法以 12 米容差剔除冗余点,再限制最多 600 个点,最后把每个坐标四舍五入到小数点后 4 位(约 11 米)。因此到达服务器的只是一条粗略的路线轮廓,刚好够判定它围住了哪些六边形,不够更多。

服务器保存什么、保存多久

谁能看到你的足迹

被占领的格子会显示在所有用户的足迹地图上,并标注你的昵称和头像;你的格数会进入同城排行榜。这是这个玩法的核心机制,我们希望你在开始前就清楚这一点。你可以在「自己 → 设置 → 社交与可见性」中打开「地图隐身」,地图上只显示你的足迹颜色,不显示你的昵称和头像。

隐私区

你可以在「足迹 → 我的 → 隐私区」圈定一块半径 100–2000 米的区域(例如家或公司附近)。该区域内的格子由服务器在下发时直接过滤掉,其他用户的手机根本收不到这些数据,不是仅在界面上隐藏。隐私区不影响你的占地和排名。首次占领成功后我们会主动提醒你设置。为了完成过滤,服务器会保存隐私区的圆心坐标(精确到约 1 米)和半径;关闭隐私区或注销账号即删除。

位置的其他用途

你可以拒绝

你可以不授予定位权限、或随时在系统「设置 → 隐私与安全 → 定位服务」中关闭。关闭后跑步记录与足迹跑不可用,App 的其他功能不受影响。

设备完整性校验(App Attest)

采集什么

仅在提交足迹结算时,App 会请求 Apple 的 App Attest 服务证明这次请求确实来自一台真实 Apple 设备上未被修改的 Msats。我们保存由此得到的设备公钥和一个单调递增的计数器。

为什么

足迹是一个竞争性玩法。没有这道校验,被改装的客户端或脚本就能凭空造出没人跑过的足迹。该校验只在提交结算时进行。

它不是什么

App Attest 公钥不是设备识别码:它由 Apple 针对「这个 App + 这台设备」单独派生,无法与其他 App 或广告标识符关联,不能用于跨 App 追踪。我们不会用它做用户画像、统计分析或广告投放,也不会提供给任何第三方。

保存多久

公钥与计数器在你的账号存续期间保存,注销账号时一并删除。

并肩跑

采集什么

你和伙伴距离较近时,两台手机通过蓝牙和超宽带(UWB)直接交换位置与距离,不经过我们的服务器。在远距模式(会员功能)下,你的实时位置、速度、航向和累计距离——以及使用「一起听」时你正在播放的歌名和歌手——会发送到我们的服务器,并转发给同一房间里的伙伴(每个房间最多 4 人),用于在小地图上互相显示位置和彼此距离。

服务器保存什么

服务器只在内存中保留最后一个位置数据包,下一个包到达即覆盖,超过 90 秒没有更新就自动清除。它不写入磁盘、不写入数据库、不进备份,也不会被拼接成轨迹。

怎么关掉

退出房间,或者不发起并肩跑即可。请注意:在会话进行期间,同房间的伙伴可以看到你的实时位置——这正是该功能的用途,因此请只和你信任的人组队。

社交广场与俱乐部

采集什么

谁能看到、保存多久

每条动态你都可以设置为「所有人可见」或「仅自己」。设为所有人可见的动态,全体 Msats 用户都能看到;发布在俱乐部内的内容,该俱乐部成员可以看到。动态会一直保存,直到你删除它或注销账号。

图片和视频通过公开链接提供。该地址很难被猜到,但没有访问控制:任何拿到链接的人(例如有人把链接转发出去)无需登录即可打开。请不要发布你不希望在 App 之外被看到的图片或视频。

举报记录

当你举报动态、评论或用户时,我们会记录举报人是谁,连同被举报对象和你填写的理由一并保存。这样做是为了识别和阻止恶意批量举报。举报人身份仅内容审核人员可见,绝不会展示给被举报的人。

怎么关掉

发布内容完全是可选的。你可以在「自己 → 设置 → 社交与可见性」中设置动态的默认可见范围、是否附带跑步路线,以及打开「地图隐身」;你也可以随时删除自己发布的任何动态或评论,删除后即从服务器移除。

分享链接与计划二维码

训练分享链接

当你为一次训练生成分享链接时,以下内容会保存在我们的服务器,并展示在一个公开网页上,任何拿到链接的人无需登录即可打开:你的昵称、标题与时间、距离、时长、配速、平均与最高心率、步数、步频、分段、动作与各组重量、最多 6 首歌名,以及去掉所有经纬度后的路线形状。分享页保存 180 天;如需提前撤下,请通过下方邮箱联系我们;注销账号会一并删除你创建的全部分享页。

计划二维码

当你用二维码分享训练计划时,计划名称、动作、组数次数和压缩后的背景图会在服务器暂存 7 天,供扫码的人导入。该内容不关联你的账号。

健身房会员卡

如果健身房通过 Msats 向你发放会员卡并由你领取,该健身房可以看到你的 Msats 昵称以及你在该店的到店记录。卡上的持卡人姓名和手机号由健身房录入并由其负责,我们代健身房保存。你把会员卡加入 Apple 钱包时,钱包会向我们的服务器登记设备库标识和推送令牌,用于更新卡片。注销账号会解除绑定并作废你的会员卡;健身房自己的会员经营记录由健身房保留。

Sign in with Msats(授权其它 App 登录)

Msats 可以作为我们旗下其它 App 的登录提供方,目前唯一接入的 App 是 Pace Go。在你完成授权页面上的确认之前,不会共享任何数据;授权页面会逐条列出对方申请的权限。当前版本不能发起新的授权,只能查看和解除已有授权。

对方能拿到什么

哪些数据保存在 Msats 服务器

通过该功能同步的跑步记录保存在 Msats 服务器,不再只保存在你的设备上。每条记录可能包含:起止时间、距离、时长、消耗热量、平均心率与最大心率、分段配速,以及一条可选备注。这是对「健康数据只留在你设备上」的一个刻意例外——因为两个 App 需要共用同一份去重后的记录。

保存多久、如何撤销

这些记录保存到你注销账号为止。你可以随时在「自己 → 设置 → 已授权的应用」中解除某个 App 的授权,解除后对方立即失去读写任何数据的能力。解除授权本身不会删除已经同步过来的记录——注销 Msats 账号才会删除。

饮食与营养数据

默认保存在你的设备上

你记录的饮食、饮水、咖啡因、轻断食、碳循环、热量与营养目标,以及由照片生成的食物贴纸,保存在你的设备上,并同步到你的 Apple Watch 和桌面小组件。开启「iCloud 同步」(会员功能)后会镜像到你本人的 iCloud Drive,Msats 无法访问。

Apple 健康

经你授权,Msats 会把记录的热量、蛋白质、碳水、脂肪、膳食纤维(附食物名称)和饮水写入「健康」,并读取「健康」中的同类饮食数据,在本机按天汇总。从「健康」读取的数据不会上传到 Msats 服务器,也不会写入 iCloud 备份;除下文「AI 饮食计划、AI 教练与分析」所述情形外,不会提供给任何第三方。

拍照识别热量

你主动拍照或选图识别时,我们把压缩后的照片(长边不超过 1024 像素)、你补充的语音或文字说明(不超过 200 字,语音优先在设备上转写)和界面语言发送到 Msats 服务器,再转发给火山方舟豆包(主用)或阿里云通义千问(备用)识别食物、估算份量与营养。本地营养库未收录时,服务器可能把识别出的食物名称(不含照片和任何个人信息)发送给博查 AI 搜索,用来校准每 100 克热量。「包装食品」模式先在设备上读取营养成分表,读不出才发送照片。照片处理完即丢弃,不写入数据库或磁盘,也不会被我们用于训练模型;服务器只记录这次调用的时间、模型和用量(登录时记在你的账号名下,未登录时按 IP 地址记录),用于额度管理与防滥用(见「AI 调用记录」)。

快捷指令「识别截屏里的食物热量」

运行该指令时,App 会读取你相册中最新的一张截图,并按上述方式识别。外卖订单截图可能包含姓名、地址或电话,请在运行前确认。

AI 饮食计划、AI 教练与分析

当你让 AI 生成或调整饮食、减脂计划,在 AI 教练中询问饮食,或使用数据洞察与深度分析时,我们会发送身高、体重、目标体重、年龄、性别、训练频率、你输入的偏好,以及近 7~90 天的饮食统计(日均热量、三大营养素、饮水、目标值、记录天数)。首次授权「健康」后生成的「AI 初识画像」还会包含「健康」中的饮食日均值。我们不发送单条饮食明细,也不发送食物照片(你在聊天中主动附加的除外)。这些内容仅用于生成本次结果,服务器不保存。

公开分享

只有当你在广场发布饮食卡片时,卡片上的热量与三大营养素才会保存在服务器并对他人可见。

删除

你可以随时删除任意饮食记录,Msats 写入「健康」的对应样本会一并删除。注销账号会清除设备上的饮食数据;你 iCloud Drive 中的备份和「健康」中的数据,请在系统设置和「健康」App 中自行管理。

第三方 AI 处理

Msats 以字节跳动豆包(火山方舟)为主要 AI 服务商——本版本 AI 教练使用 doubao-seed-2-1-turbo 模型——阿里云通义千问(阿里云百炼/DashScope)作为备用,两者服务器均在中国境内。App 会在发送照片或文字进行 AI 处理前,说明将发送的数据并征求你的单独同意;在 AI 教练中附加的照片会压缩到长边 1024 像素。AI 教练只有在你另行同意后,才能读取你的日历(日程标题、时间、地点,不含备注与参会人)和未完成的提醒事项(标题与截止时间)。你可以随时在「自己 → 设置 → 隐私 → 允许 AI 处理我的数据」中撤回,撤回时照片与日程的许可一并撤回。

发送给 AI 的数据仅用于生成你请求的结果。Msats 不会将这些内容用于广告、身份识别或模型训练。我们不允许 AI 服务商将这些内容用于广告或模型训练,并要求其按照与 Msats 服务相当的安全保护措施处理数据。

数据档案中的 AI 深度分析

会发送什么

「数据档案 → AI 深度分析」是一项付费功能。当你启动它时,我们会把你数据的一份统计摘要发送给第三方 AI 服务商。该摘要包含:近 8 周的逐周训练量、各肌群的容量分布、你最常练的动作与个人纪录、近 30 天的日均摄入热量与饮水量、期间体重的首末两个数值、以及你打卡的活跃天数。

摘要中不包含任何单条明细——没有单餐、单组、单次跑步的记录——也不包含任何照片。该分析会连续进行三轮,因此一次分析中摘要最多被发送三次。

保存多久

该摘要不保存,只存在于请求处理链路中。返回给你的分析报告保存在你的设备本地。

怎么关掉

不启动该分析即可;或在「自己 → 设置 → 隐私」中关闭「允许 AI 处理我的数据」,关闭后该功能连同其他全部 AI 功能一并停用。

语音输入

当你使用语音指令或语音输入时,语音由 Apple 的语音识别转写成文字:只要你的设备支持,就在设备上完成;设备不支持时,音频才会发送给 Apple 服务器处理。Msats 只接收转写后的文字,不保存音频。你可以改用键盘输入,或在系统「设置 → 隐私与安全」中撤回麦克风与语音识别权限,从而完全避免语音识别。

通知

我们服务器发送的推送

当前版本的 Msats 不会为接收我们服务器的推送而注册,因此不收集 App 的推送令牌,也不会向你发送服务器推送。加入 Apple 钱包的健身房会员卡通过钱包自己的推送机制更新。如果未来版本开启服务器推送(例如「有人评论了你的动态」「你的足迹被抢了」),我们会先更新本政策;这类推送不会包含你的健康数据或位置。

在你设备上生成的通知

AI 健康洞察、组间休息和提醒事项等通知由 App 在你的设备上生成,不经过我们的服务器。其中 AI 健康洞察可能显示活动热量、静息心率比平时高多少等数值,并可能出现在锁屏上。你可以在「自己 → 设置 → 提醒」中逐类关闭,或在系统「设置 → 通知 → Msats」中全部关闭。

服务器访问日志

记录什么

对服务器的每次请求都会写入一条技术访问日志,内容包括:时间、IP 地址、请求路径(其中查询参数里的坐标已被去除)、脱敏后的用户标识、HTTP 状态码。

不记录请求体。轨迹、照片、动态正文、聊天内容、AI 提示词等内容都不会进入日志。

服务进程另有一份用于故障排查的运行日志,同样包含 IP 地址与请求路径,并会自动轮转清除。食物识别失败时,该日志可能记录识别出的食物名称,或不超过 220 字的模型回复片段;照片、轨迹、动态正文、聊天内容和 AI 提示词不会写入。

为什么记录、保存多久

《中华人民共和国网络安全法》第二十一条要求网络运营者留存相关网络日志不少于六个月。我们按天分文件保存访问日志,200 天后自动删除。这些日志仅用于安全审计和故障排查,不用于用户画像、推荐或广告。

关于删除的说明

由于这项留存是法定义务,注销账号不会删除这些日志,它们会和其他人的日志一样按正常周期自然到期删除。

数据接收方清单

在你使用对应功能时,App 或我们的服务器会与以下各方交互。由你的设备直接连接的一方可以看到你的 IP 地址;由我们的服务器代为连接的一方只能看到我们的服务器。

除上文所述的 AI 功能、健身房、并肩跑伙伴以及你通过 Sign in with Msats 授权的 App 外,你的位置信息、足迹数据和健康数据不会提供给上述任何一方。

已下线功能的数据处理

好友与聊天功能已于 2026 年 8 月 11 日整体下线。好友列表、好友申请与加密聊天在 App 中均已不存在,相关代码与界面已从客户端彻底删除。

服务器上尚未送达的加密消息会在 14 天后自动删除。历史好友关系,以及该功能使用的公钥和推送令牌,已不再向任何客户端提供,并会在你注销账号时删除。该功能遗留在本机的设置项会在你下次启动 App 时自动清理。

相应地,动态可见范围中的「仅好友可见」选项已不再可用;此前使用该选项发布的动态按「仅自己」处理。如果你对已下线功能涉及的数据有任何疑问,请通过下方邮箱联系我们。

仅在你设备上处理的功能

跳绳视觉计数(摄像头)、经期记录,以及咖啡因、轻断食、碳循环记录,只在你的设备上处理(开启 iCloud 同步时也会存入你的 iCloud),不会上传到我们的服务器。Apple Watch 上的数据只发送到你的 iPhone;只有在「健康与运动数据」中列出的情形下才会离开你的 iPhone。

数据存储与安全

本地数据由 iOS 沙盒保护;iCloud 同步(会员功能)经由你本人的 iCloud 私有账户完成,Msats 无法访问。复制到 iCloud 之前,会移除从 Apple 健康获得的心率字段与健康样本标识;从 Apple 健康导入的跑步与训练记录整条不上传到 iCloud,它们仍保留在「健康」中。

存储地点:Msats 服务器位于中国境内(阿里云杭州)。你的位置信息、足迹数据、社交内容与账号信息均存储在中国境内,不出境。如果你在中国大陆以外使用 Msats,你的数据会传输至位于中国大陆的上述服务器处理。

传输:App 与服务器之间的通信全程使用 HTTPS 加密。

图片元数据:你上传的照片、实况照片中的视频部分以及头像,会在保存前去除元数据(包括拍摄位置、设备型号与拍摄时间),使你发布的图片不会泄露拍摄地点。

内部访问控制

只有少数经授权的人员可以访问生产数据,且仅限处理作弊申诉与违规内容举报时。在这类场景中,他们看到的位置数据是经过模糊处理的:我们后台管理工具的精确坐标模式在生产环境默认不开启。该后台需口令鉴权,且每次使用都会记入上文所述的访问日志。

订阅与支付

会员订阅通过 Apple App Store 购买和扣费,我们不会获取你的支付卡号或任何支付凭证。为了在服务器端核对会员权益、处理续费/退款并提供客服支持,你购买或恢复购买时,App 会把 Apple 签名的交易凭证上传到我们的服务器;我们也会接收 Apple 发来的订阅状态通知。我们据此保存:交易编号、商品(会员档位与周期)、购买与到期时间、是否试用、自动续订状态、扣费宽限期与退款/撤销状态及最近的状态变更记录、交易环境(正式/沙盒)、店面地区、价格与币种,以及一个用于把订阅与你的 Msats 账号对应起来的随机账号令牌(appAccountToken)。这些信息仅用于会员权益核对、客服和汇总经营统计,不与第三方共享。注销账号时,这些订阅记录会一并删除(Apple 那边的购买记录由 Apple 按其政策保存)。

你的选择和权利

如需协助、行使上述权利或有任何隐私问题,请联系:frankdoug87@gmail.com。

未成年人

Msats 面向成年用户设计。如果你未满 18 周岁,请在监护人同意并指导下使用;如果你未满 14 周岁,请在监护人阅读本政策并同意后再使用。如果我们发现在未取得监护人同意的情况下收集了不满 14 周岁儿童的个人信息,会尽快删除。监护人如需查阅或删除相关信息,请通过上方邮箱联系我们。