TOKENVIVE · PRIVACY POLICY
隐私政策
更新日期:2026 年 10 月 1 日
本政策适用范围
本政策说明 TokenVive 的 iPhone App、Apple Watch App 和 tokenvive.app 官网如何处理数据。TokenVive 延续原 Limit Halo 项目;更换名称和域名不会创建新的 AI 服务商账号。当前产品处于开发测试阶段。
Apple 健康与身体电量
经你在系统中授权后,App 读取睡眠、心率、心率变异性、呼吸频率、步数、活动能量、运动、站立及正念等可用记录,用于显示健康趋势和在设备端估算身体电量。健康显示数据、趋势和计算结果通过 Apple 的配对设备通信同步至你的 Apple Watch,并供本地表盘复杂功能使用;这些健康数据不上传 TokenVive 的 AI 额度服务器。休息计时和站立提醒在设备端处理。本 App 不向 Apple 健康写入数据。身体电量用于日常状态观察,不用于医疗诊断。
AI 账号与云端查询
你在 OpenAI 或 Anthropic 的官方页面登录。TokenVive 不接收你的登录密码;完成授权所需的临时代码和授权凭据会由服务端处理。为持续查询额度,服务端保留 AI 授权凭据、连接标识、自定义账号名称,以及额度、重置时间和可用的用量统计快照。消息分析处理按日期和模型汇总的数量,不查询聊天消息正文。服务端凭据及查询快照使用 AES-256-GCM 加密保存;服务在执行查询时需要解密凭据,这不是只有用户本人能解密的端到端加密。手机和手表保存本服务的连接凭据;手表使用额度查询凭据,不接收 AI 服务商的授权凭据。
用途、共享与基础设施
上述数据用于你主动连接的账号查询、设备同步、功能显示及服务维护。TokenVive 不出售健康或 AI 账号数据,不将健康数据用于广告。云端服务目前运行在 AWS 美国西部(俄勒冈),会向你选择连接的 OpenAI 或 Anthropic 发送授权请求和额度查询;这些服务商按照各自政策处理数据。域名解析由 Google Cloud DNS 提供。网络服务提供商在提供连接、运行和安全保护时可能处理 IP 地址及请求时间等技术信息。
官网与支持邮件
官网没有集成广告或分析追踪脚本,没有自行设置追踪 Cookie。语言切换在当前页面内完成。若你发送支持邮件,开发者会收到你的邮箱及你主动提供的内容,并用于处理请求。请不要发送密码、授权码、访问令牌、完整健康记录或其他不必要的敏感信息。
保留、断开与删除
AI 授权和连接数据在连接有效期间保留,用于持续查询。你可以在 App 的“账号连接”中断开单个 AI 账号;本服务停止查询该账号并移除它在运行服务中的授权数据。断开账号与删除全部服务连接数据是不同操作;需要删除全部连接数据时,可通过下方邮箱联系开发者,完成必要的身份核实后处理。第三方服务商的账号与数据需要通过服务商本身管理。你可以在 App 的健康页面停止读取,也可以在 Apple 健康或系统设置中撤销权限;停止读取不会删除 Apple 健康中的原始记录。系统、服务商及备份的保留规则可能不同,本政策不承诺它们与运行数据同步删除。
你的选择与安全
连接 AI 账号和授权健康读取均由你选择;没有相应权限时,相关数据可能无法显示。传输使用 HTTPS;设备上的正式版本连接凭据使用系统 Keychain 保存。请妥善保护设备,且不要将授权码或凭据发给支持人员。你可以联系开发者询问数据处理方式、要求更正或删除可识别的服务数据。
更新与联系
本政策随功能和数据处理方式变化而更新,页面会注明更新日期。隐私问题、数据请求和支持请联系 TokenVive 开发者:434309896@qq.com。
TOKENVIVE
Privacy Policy
Last updated: October 1, 2026
Scope
This policy describes data processing in the TokenVive iPhone app, Apple Watch app, and tokenvive.app website. TokenVive continues the former Limit Halo project. A name or domain change does not create a new account with your AI provider. The product is currently in development testing.
Apple Health and body energy
With your system permission, the app reads available sleep, heart rate, heart rate variability, respiratory rate, steps, active energy, workouts, standing, and mindful-session records to display trends and estimate body energy on device. Health display data, trends, and calculated results sync to your paired Apple Watch through Apple’s device communication and are used by local complications. These health data are not uploaded to TokenVive’s AI quota server. Rest timers and stand reminders operate on device. The app does not write to Apple Health. Body energy is for everyday awareness, not medical diagnosis.
AI accounts and cloud queries
You sign in on the official OpenAI or Anthropic page. TokenVive does not receive your login password; the server processes temporary codes and authorization credentials needed to complete the connection. To keep querying quota, the server retains AI authorization credentials, connection identifiers, custom account names, and snapshots of quota, reset times, and available usage statistics. Message analysis processes counts aggregated by date and model, without querying chat message text. Server credentials and snapshots are encrypted at rest with AES-256-GCM. The service decrypts credentials to perform queries; this is not end-to-end encryption that only the user can decrypt. The phone and watch store credentials for this service. The watch uses quota-query credentials and does not receive the AI provider’s authorization credentials.
Purpose, sharing, and infrastructure
Data are used for accounts you choose to connect, device synchronization, feature display, and service maintenance. TokenVive does not sell health or AI account data or use health data for advertising. The cloud service currently runs on AWS in US West (Oregon) and sends authorization and quota requests to the OpenAI or Anthropic service you connect. Those providers process data under their own policies. Google Cloud DNS provides domain resolution. Network providers may process technical information such as IP addresses and request times for connectivity, operations, and security.
Website and support email
The website has no advertising or analytics tracking scripts and does not set its own tracking cookies. Language selection stays within the current page. If you email support, the developer receives your email address and the content you choose to send, to handle your request. Do not send passwords, authorization codes, access tokens, full health records, or unnecessary sensitive information.
Retention, disconnection, and deletion
AI authorization and connection data are retained while a connection is active to support ongoing queries. You can disconnect an AI account in the app’s account connection screen; the service stops querying that account and removes its authorization data from the running service. Disconnecting one account differs from deleting all service connection data. To request deletion of all connection data, contact the developer below for necessary identity verification. Manage your third-party account and data with that provider. You can stop Health reading in the app or revoke permission in Apple Health or system settings. This does not delete original Apple Health records. System, provider, and backup retention may differ; this policy does not promise their deletion at the same time as running data.
Choices and security
AI connection and Health reading are optional. Related values may be unavailable without permission. Transmission uses HTTPS, and production app connection credentials are stored in the system Keychain. Protect your devices and do not send credentials or authorization codes to support. You can contact the developer about processing, correction, or deletion of identifiable service data.
Updates and contact
This policy may be updated as features and processing change. The update date is shown on this page. Contact the TokenVive developer for privacy questions, data requests, or support: 434309896@qq.com.