DouOS Privacy Policy
Effective and last updated: July 22, 2026
DouOS is an iOS AI companion app centered on Xiaodou. This policy explains what data DouOS processes, how it is collected and used, and which service providers receive it. API keys you add yourself are stored locally in the iOS Keychain and are not uploaded to DouOS servers.
DouOS(小豆)是一款 iOS 原生 AI 朋友 App。本政策说明 DouOS 处理哪些数据、如何收集和使用,以及哪些服务方会接收数据。你自行添加的模型 API Key 仅保存在 iOS Keychain 中,不会上传到 DouOS 服务器。
Data we process / 我们处理的数据
- Apple account identifier and any name or relay email you choose to share, used for sign-in, account continuity, and subscription entitlement.
- Content you actively provide, including messages and selected images, audio, files, notes, profile details, confirmed memories, and Box content.
- App and device identifiers, purchase status, request identifiers, usage counts, and reliability or abuse-prevention records needed to operate and secure the service.
- 你的 Apple 账号标识及你选择提供的姓名或中继邮箱;你主动提供的消息、选中的图片、语音、文件、资料、已确认记忆和盒子内容;以及运行订阅、服务可靠性和防滥用所必需的 App/设备标识与使用记录。
AI data sharing and consent / AI 数据共享与同意
Before DouOS sends personal data to an AI service for the first time, the app separately explains what will be sent, identifies the recipient and purpose, and asks for your affirmative permission. If you choose “Not Now,” the content is not sent and AI generation remains unavailable until you grant permission.
在首次把个人数据发送给 AI 服务前,App 会单独说明发送内容、接收方和用途,并取得你的明确允许。选择“暂不允许”时,内容不会发送,AI 生成功能会保持关闭,直到你主动允许。
With permission, DouOS sends only the content needed to provide the requested reply or related AI feature: the current text, selected attachment content, necessary recent conversation, profile context, and relevant confirmed memories. This may be used to generate chat replies, Inner OS, Xiaodou activity content, and memory suggestions. Apple credentials and user-supplied model API keys are never included in AI model requests.
Recipients / 接收方
- DouOS service: authenticates the account, routes requests, applies entitlement and safety controls, and returns results.
- Xiaomi MiMo (Xiaomi): the default platform AI service that receives the minimum request content needed to generate a result. See Xiaomi MiMo Privacy Policy.
- A provider you explicitly choose: if you switch to “My Model,” request content goes directly to the configured provider or self-hosted endpoint, such as OpenAI, Anthropic Claude, Google Gemini, DeepSeek, or OpenRouter, under that provider’s privacy policy.
- Optional tools you enable: a search query or selected content may be sent to the named search, webpage, or connector service only when required for the feature you request. Sensitive write actions require preview and confirmation.
DouOS uses encrypted transport, limits data to the requested purpose, does not sell chat content, and does not use chat content for advertising. We require service providers that process data for DouOS to provide privacy and security protection no less protective than this policy.
Your choices and controls / 你的选择与控制
You can review or withdraw AI data-sharing permission in Profile > Advanced & Privacy > AI Data Use. Withdrawal stops future AI requests but does not prevent you from viewing content already stored on your device. You can also edit or delete memories, export supported data, configure your own provider, restore purchases, or request account deletion.
你可以在“我的 > 高级与隐私 > AI 数据使用”查看或撤回允许。撤回会停止新的 AI 请求,但不影响查看已保存在设备上的内容。你也可以编辑或删除记忆、导出支持的数据、自行配置模型服务、恢复购买或申请删除账号。
Retention and deletion
Functionality data is retained while your account remains active. When you delete your account in the app, DouOS deletes the account and associated primary-database records. Encrypted operational backups and security logs, when required for recovery or abuse prevention, are retained for no longer than 30 days before deletion.
功能数据会在账号存续期间保留。你在 App 内删除账号后,DouOS 会删除账号及主数据库中的关联记录。仅为故障恢复或防止滥用所必需的加密运维备份和安全日志,最长保留 30 天后删除。
Contact
Email: isdou.exe@gmail.com