Msats Privacy Policy
Last updated: August 10, 2026 · v2.0
Information we collect and use
- Account information: when you sign in with Apple, we receive only the anonymous Apple user identifier and the nickname you authorize. We never receive your password.
- Health and fitness data: workouts, runs, heart-rate readings received from Apple Watch, weight, diet, water logs and HealthKit data stay on your device and in your own private iCloud database by default. We never sell it or use it for advertising.
Exception: when you submit a Territory Run claim, a summary of that run's HealthKit data (distance, duration, average heart rate, whether it was manually entered) and motion-sensor data (cadence, vertical oscillation, pedometer step count, and CoreMotion time spent stationary/walking/running/cycling/driving) is uploaded together with the claim. This is used solely to verify the run is genuine and to prevent claiming territory from a vehicle. If you do not use Territory Run, none of this is uploaded.
- Food AI content: when you choose food photo recognition, we send the compressed food photo and optional voice-note text you provide to the Msats backend, then to our AI service provider, Alibaba Cloud DashScope/Qwen, to estimate calories and macronutrients.
- Posture and face/body data: when you choose AI posture analysis, we send the body photos you select and an on-device Vision skeleton-angle summary to the Msats backend, then to Alibaba Cloud DashScope/Qwen to generate a posture report. These photos may include your face or body features.
- AI plan and chat text: when you ask Msats to generate or revise a meal plan, training plan, or chat response, the text you enter and the current plan context are sent to the Msats backend and then to Alibaba Cloud DashScope/Qwen to generate the requested result.
- Usage counters: our backend stores anonymous user identifiers and product-interaction counters, such as AI quota usage, for abuse prevention, subscription entitlement checks and quota management.
Location data and Territory Run
Location is sensitive personal information. We collect it only while you have actively started a run. The app does not track your location in the background outside of an active run.
What we collect
During a run (including while the app is backgrounded after you press Start) we record track points containing longitude, latitude, timestamp, location accuracy and instantaneous speed. Highest system accuracy is used, roughly one point every 5 metres, so distance and pace are correct. Altitude is not recorded in the track. Your location is also reverse-geocoded on-device into a city name for city leaderboards.
Why it is uploaded
Territory Run awards you the hexagonal cells enclosed by your route. That has to be computed on the server — otherwise anyone could fabricate a result locally. So when you actively submit a territory claim, that run's full track is uploaded for computation. If you simply record a normal run and do not submit a claim, the track never leaves your phone.
What the server keeps, and for how long
- The raw track is not retained. It is discarded after the calculation; it is never written to the database, to disk, or to a backup.
- Results are kept: the hex cell identifiers you own, ownership timestamps, shield and expiry windows.
- One summary record per claim: the midpoint coordinate (rounded to 5 decimal places), coverage radius, distance and whether the loop closed. Only the 40 most recent per user are kept.
- An irreversible fingerprint (hash) of the track, used only to detect the same track being submitted twice. It cannot be reversed into a route.
- Cells expire automatically after 30–45 days without activity depending on your plan. All territory data is kept per season, and only the two most recent seasons are retained; older seasons are deleted in full.
Who can see your territory
Cells you claim are shown on every user's territory map, labelled with your nickname and avatar, and your cell count appears on city leaderboards. That is the core of the game, and we want you to understand it before you start.
Private zone
Under Territory → Mine → Private zone you can define a circle of 100–2000 m (for example around your home or workplace). Cells inside it are filtered out by the server before sending — other users' devices never receive that data, rather than merely hiding it in the interface. A private zone does not affect your claims or your ranking. We prompt you to set one after your first successful claim.
You can decline
You may deny location permission, or revoke it at any time in iOS Settings → Privacy & Security → Location Services. Run tracking and Territory Run will not work, but the rest of the app is unaffected.
Social feed, clubs and friend chat
- Content you post — text, images and any workout cards you attach — is stored on Msats servers. Every post can be set to Everyone / Friends only / Only me.
- Route maps in posts: if you choose to attach your running route, it is downsampled to at most 140 points and rounded to 5 decimal places before upload. You can turn this off entirely under Settings → Social privacy → Include running route.
- Friend chat is end-to-end encrypted: messages are encrypted on your device with a key only you and the recipient hold. The server relays ciphertext only and we cannot read your messages. Your private key lives in your device keychain and is not synced to iCloud, so history does not follow you to a new phone. Messages are deleted from the server as soon as they are delivered; undelivered messages are purged after 14 days. Note that the server still knows the metadata — who messaged whom, and when.
- Strangers cannot message you: both sides must accept a friend request first. You can turn off "findable by ID" under Settings → Social privacy.
Third-party AI processing
Msats uses Alibaba Cloud DashScope/Qwen as a third-party AI service provider. The app explains what will be sent and asks for permission before sending photos or text to AI processing.
The data sent for AI features is used only to generate the requested result. It is not used by Msats for advertising, identity recognition, or model training. We do not permit the AI provider to use this content for advertising or model training, and the provider is expected to protect the data with safeguards comparable to those used for the Msats service.
Face/body data details
What face or body data is collected?
Only the body photos that you actively select for posture analysis are sent. These images may incidentally contain your face. Msats also sends an on-device Vision skeleton-angle summary such as shoulder, hip or side-view posture angles.
How is it used?
The photos and angle summary are used only to generate a posture assessment, corrective exercise suggestions and a posture score. Msats does not use this data to identify you, authenticate you, build a biometric profile, track you, advertise to you, or train AI models.
Is it shared with third parties?
Yes, only for the AI feature you request: the data is sent through the Msats backend to Alibaba Cloud DashScope/Qwen for processing. It is not shared with advertisers, data brokers, social networks or analytics providers.
Where is it stored and how long is it retained?
The original photos are processed transiently in the request path and are not saved to the Msats server database or file storage. After the AI provider returns the result, Msats does not retain the submitted photos or text. The generated posture report is stored locally on your device unless you delete app data or delete your account.
Storage and security
Local data is protected by the iOS sandbox. iCloud sync uses your own private iCloud account, which Msats cannot access.
Where data is stored: Msats servers are located in mainland China (Alibaba Cloud, Hangzhou). Your location data, territory data, social content and account information are stored there and are not transferred abroad.
In transit: all communication between the app and our servers uses HTTPS.
Subscriptions and payments
Subscriptions are processed and billed by the Apple App Store. Msats does not receive or store your payment card information.
Your choices and rights
- Access and export: Profile → Settings → Data archive exports all of your detailed data; Data transfer produces an encrypted backup package.
- Withdraw consent: AI processing can be switched off at any time under Profile → Settings. Location, health, photo and microphone permissions can be revoked at any time in iOS Settings → Privacy & Security.
- Correct: nickname, avatar, height and weight can be edited under Profile → Edit profile; territory names can be changed by long-pressing the territory on the map.
- Delete: Profile → Settings → Delete account erases all local data. To also delete your account, territory and social content from our servers, email us at the address below; we will complete the deletion and reply within 15 working days.
- Private zone: see "Location data and Territory Run" above.
- Social visibility: Profile → Settings → Social privacy controls your default post audience, whether routes are attached, and whether strangers can find you by ID.
For help exercising any of these rights, or any privacy question, contact frankdoug87@gmail.com.
Minors
Msats is designed for adults. If you are under 18, please use it with the consent and guidance of a parent or guardian. If you are under 14, please have a guardian read this policy and consent before use. If we learn we have collected personal information from a child under 14 without guardian consent, we will delete it promptly. Guardians may contact us at the address above to review or delete such information.
Msats 隐私政策
更新日期:2026 年 8 月 10 日 · 版本 v2.0
我们收集和使用的信息
- 账号信息:你使用 Apple 登录时,我们仅接收 Apple 签发的匿名用户标识,以及你授权的昵称。我们不会获取你的密码。
- 健康与运动数据:训练记录、跑步数据、Apple Watch 回传的心率、体重、饮食饮水和 HealthKit 数据默认只保存在你的设备本地及你本人的 iCloud 私有数据库,我们不会出售或用于广告。
例外:当你使用「领地跑」并提交一次占领结算时,App 会随该次结算一并上传本次跑步的 HealthKit 摘要(距离、时长、平均心率、是否为手动录入)与运动传感器摘要(步频、垂直振幅、系统计步数、CoreMotion 判定的静止/步行/跑步/骑行/驾车各时长)。这些数据仅用于校验该次成绩是否真实、防止乘车刷地,不用于其他目的。如果你不使用领地跑,这些数据不会上传。
- 食物 AI 内容:当你主动使用食物拍照识别时,我们会把压缩后的食物照片和你主动提供的语音说明文字发送到 Msats 后端,再转发给 AI 服务商阿里云通义千问(DashScope/Qwen),用于估算热量和营养素。
- 体态与脸部/身体数据:当你主动使用 AI 体态分析时,我们会把你选择的身体照片和本机 Vision 计算出的骨骼角度摘要发送到 Msats 后端,再转发给阿里云通义千问(DashScope/Qwen)生成体态报告。这些照片可能包含你的脸部或身体特征。
- AI 计划与聊天文字:当你要求 Msats 生成或修改饮食计划、训练计划或聊天回复时,你输入的文字和当前计划上下文会发送到 Msats 后端,再转发给阿里云通义千问(DashScope/Qwen)生成结果。
- 用量计数:服务器会保存匿名用户标识和产品交互计数,例如 AI 调用额度,用于防滥用、订阅权益校验和额度管理。
位置信息与「领地跑」
位置信息属于敏感个人信息。我们只在你主动开始一次跑步或领地跑时采集,App 不在后台长期跟踪你的位置。
采集什么
跑步过程中(包括你按下开始后 App 退到后台时)记录轨迹点,每个点包含:经度、纬度、时间戳、定位精度、瞬时速度。为保证距离与配速准确,记录时使用系统最高定位精度,约每 5 米记一个点。海拔不进入轨迹记录。此外会在本机把你的位置反查成城市名(如「贵阳市」),用于同城排行榜。
为什么要上传
「领地跑」的规则是:跑出的闭合路线所围住的六边形格子归你所有。这个判定必须在服务器完成,否则任何人都可以在本机伪造成绩。因此当你主动提交一次领地结算时,本次完整轨迹会上传到 Msats 服务器用于计算。如果你只是普通跑步、不提交领地结算,轨迹不会离开你的手机。
服务器保存什么、保存多久
- 不保存原始轨迹。轨迹用于计算后即丢弃,不写入数据库、不落盘、不做备份。
- 保存计算结果:属于你的六边形格子编号、归属时间、保护期与有效期。
- 保存每次占领的一条摘要记录:轨迹中点坐标(精确到小数点后 5 位)、覆盖半径、距离、是否闭环。每位用户只保留最近 40 条,更早的自动覆盖。
- 保存一个不可逆的轨迹指纹(哈希值),仅用于识别重复提交同一条轨迹。该指纹无法还原出轨迹。
- 格子按会员档在 30–45 天无新活动后自动失效清除;全部领地数据按赛季保存,仅保留最近两个赛季,更早的赛季整体删除。
谁能看到你的领地
被占领的格子会显示在所有用户的领地地图上,并标注你的昵称和头像;你的格数会进入同城排行榜。这是这个玩法的核心机制,我们希望你在开始前就清楚这一点。
隐私区
你可以在「领地 → 我的 → 隐私区」圈定一块半径 100–2000 米的区域(例如家或公司附近)。该区域内的格子由服务器在下发时直接过滤掉,其他用户的手机根本收不到这些数据,不是仅在界面上隐藏。隐私区不影响你的占地和排名。首次占领成功后我们会主动提醒你设置。
你可以拒绝
你可以不授予定位权限、或随时在系统「设置 → 隐私与安全 → 定位服务」中关闭。关闭后跑步记录与领地跑不可用,App 的其他功能不受影响。
社交广场、俱乐部与好友聊天
- 你发布的内容:动态正文、图片、以及你选择附带的运动数据卡片,保存在 Msats 服务器。每条动态你都可以设置为「所有人可见 / 仅好友 / 仅自己」。
- 动态中的路线图:如果你选择在动态里附带跑步路线,路线会被抽稀到不超过 140 个点、坐标精度降到小数点后 5 位后再上传。你可以在「设置 → 社交隐私 → 附上跑步路线」中关闭,关闭后动态不再包含任何地图。
- 好友聊天是端到端加密的:消息在你的手机上用只有你和对方持有的密钥加密,服务器只中转密文,我们无法读取聊天内容。私钥保存在你手机的钥匙串中,不同步到 iCloud,因此换手机后历史消息不会跟随。对方收到后服务器立即删除该消息;14 天内未被取走的消息自动清除。请注意:服务器仍然知道「谁在什么时间给谁发过消息」这一元数据。
- 陌生人无法直接私聊你:必须双方确认成为好友后才能发送消息。你可以在「设置 → 社交隐私」中关闭「允许通过 ID 找到我」。
第三方 AI 处理
Msats 使用阿里云通义千问(DashScope/Qwen)与字节跳动豆包(火山方舟)作为第三方 AI 服务商,两者服务器均在中国境内。App 会在发送照片或文字进行 AI 处理前,说明将发送的数据并征求你的单独同意;你可以随时在「自己 → 设置 → 允许 AI 处理我的数据」中撤回。
发送给 AI 的数据仅用于生成你请求的结果。Msats 不会将这些内容用于广告、身份识别或模型训练。我们不允许 AI 服务商将这些内容用于广告或模型训练,并要求其按照与 Msats 服务相当的安全保护措施处理数据。
数据接收方清单
除上述 AI 服务商外,App 在你使用对应功能时还会与以下方交互:
- Apple:Apple 登录(获取匿名用户标识)、Apple 地图(显示底图与搜索附近场地)、Apple Music(你连接后播放音乐)、Apple 推送服务。
- 阿里云:Msats 服务器托管(中国杭州)、短信服务。
- Spotify、网易云音乐:仅在你主动连接并使用对应音乐服务时。
- 歌词服务(lrclib.net、api.lrc.cx):仅在播放音乐并开启歌词时,按歌名查询歌词,不发送你的个人信息。
你的位置信息、领地数据、健康数据和聊天内容不会提供给上述任何一方。
脸部/身体数据说明
收集什么脸部或身体数据?
仅收集你主动选择用于体态分析的身体照片。这些图片可能附带包含你的脸部。Msats 还会发送本机 Vision 计算出的骨骼角度摘要,例如肩部、髋部或侧面体态角度。
用途是什么?
照片和角度摘要仅用于生成体态评估、矫正训练建议和体态评分。Msats 不会用这些数据识别身份、认证身份、建立生物识别档案、追踪你、投放广告或训练 AI 模型。
是否会分享给第三方?
会,但仅限你请求的 AI 功能:数据会经由 Msats 后端发送给阿里云通义千问(DashScope/Qwen)处理。我们不会将这些数据分享给广告商、数据经纪商、社交网络或分析服务商。
存储在哪里,保留多久?
原始照片只在请求处理链路中短暂处理,不会保存到 Msats 服务器数据库或文件存储中。AI 服务返回结果后,Msats 不保留你提交的照片或文字。生成的体态报告保存在你的设备本地,除非你删除 App 数据或注销账号。
数据存储与安全
本地数据由 iOS 沙盒保护;iCloud 同步经由你本人的 iCloud 私有账户完成,Msats 无法访问。
存储地点:Msats 服务器位于中国境内(阿里云杭州)。你的位置信息、领地数据、社交内容与账号信息均存储在中国境内,不出境。
传输:App 与服务器之间的通信全程使用 HTTPS 加密。
订阅与支付
会员订阅由 Apple App Store 处理与扣费,Msats 不接收或保存你的银行卡信息。
你的选择和权利
- 查阅与复制:「自己 → 设置 → 数据档案」可导出你的全部明细数据;「数据传输」可生成加密备份包。
- 撤回同意:AI 处理可在「自己 → 设置」中随时关闭;定位、健康、相册、麦克风等系统权限可在 iOS「设置 → 隐私与安全」中随时撤回。
- 更正:昵称、头像、身高体重等资料可在「自己 → 编辑资料」中修改;领地名称可长按地图上的领地修改。
- 删除:「自己 → 设置 → 注销账号」会清除本机全部数据。如需同时删除服务器上的账号、领地与社交内容,请发送邮件至下方地址,我们将在 15 个工作日内处理完成并回复。
- 隐私区:见上文「位置信息与领地跑」。
- 社交可见性:「自己 → 设置 → 社交隐私」可设置动态默认可见范围、是否附带路线、是否允许陌生人通过 ID 找到你。
如需协助、行使上述权利或有任何隐私问题,请联系:frankdoug87@gmail.com。
未成年人
Msats 面向成年用户设计。如果你未满 18 周岁,请在监护人同意并指导下使用;如果你未满 14 周岁,请在监护人阅读本政策并同意后再使用。如果我们发现在未取得监护人同意的情况下收集了不满 14 周岁儿童的个人信息,会尽快删除。监护人如需查阅或删除相关信息,请通过上方邮箱联系我们。