Privacy Policy

隱私權政策

Mosaic 以資料最小化、裝置端優先與明確同意為設計原則。

生效日期:2026 年 10 月 6 日

1. Mosaic 處理的資料

當你主動使用功能時,Mosaic 可能處理你建立或選取的文字、連結、照片、文件、掃描結果、語音筆記、分類標籤、搜尋內容、AI 指令與行動草稿。這些資料用於提供你要求的擷取、整理、搜尋、生成、同步、行事曆或提醒事項功能。

Mosaic 不包含第三方廣告、跨 App 追蹤或第三方分析 SDK,也不建立廣告識別資料。

2. 裝置端處理與保護

資料預設保存在你的裝置,並使用 iOS Complete Protection、App 沙箱與受保護的 App Group 儲存。支援的分類、Vision 掃描、Natural Language 分析、Speech 轉錄、搜尋與 Foundation Models 工作會優先在裝置端執行。受限制內容不能送往 PCC、CloudKit、Spotlight 或系統捐贈。

3. Private Cloud Compute

當裝置與所在地區支援、工作需要較大模型,而且政策允許時,Mosaic 可使用 Apple 的 Private Cloud Compute。對個人內容,App 會先顯示傳送範圍並要求明確確認;允許的內容會先經過最小化與遮蔽。敏感內容留在裝置端,受限制資料不會送到 PCC。

只有目前助理範圍內、由你明確選取且分類為公開低風險的原始圖片,才可供支援視覺能力的 PCC 模型分析。個人圖片只提供遮蔽後文字;敏感與受限制圖片不會送到 PCC。Mosaic 的助理回覆只由 Apple Foundation Models 產生,不使用第三方生成式 AI 模型。

PCC 的技術與服務處理由 Apple 依其適用條款與隱私政策提供。網路、配額或服務不可用時,Mosaic 會顯示狀態並使用可行的裝置端替代方式。

4. 選用的公開網路搜尋

只有在你開啟「網路搜尋」並提出可安全公開的問題時,Mosaic 才會將你本次輸入中的公開查詢詞送至 Mosaic 的 Cloudflare Web Search 閘道與其 Ceramic 搜尋供應商。Mosaic 擷取的內容、先前的助理訊息、私人識別碼、個人、敏感或受限制資料不會成為網路搜尋查詢。

搜尋結果會回傳給 Apple 模型作為引用來源;搜尋供應商不是回覆模型。Mosaic 閘道不會在請求完成後儲存查詢或搜尋結果。為防止濫用與限制速率,隨機安裝識別碼和網路 IP 位址只在處理請求所需期間暫時使用。你可隨時關閉網路搜尋,並繼續使用本機資料搜尋。

5. iCloud 與 CloudKit

若你啟用同步,Mosaic 會使用 Apple CloudKit private database 儲存經你允許的安全投影,例如最小化且已遮蔽的文字與同步中繼資料。原始附件、本機主資料庫與受限制內容不直接加入 CloudKit。資料與你的 iCloud 帳號相關聯,並由 Apple 的 CloudKit 服務處理。

6. 系統權限與 Apple 服務

相機、照片、檔案、麥克風、語音辨識、Face ID、行事曆與提醒事項只會在你使用對應功能時啟動,並依 iOS 權限介面控制。Mosaic 使用 Share Extension、Widget、Spotlight、Shortcuts、Siri、Visual Intelligence、Image Playground、Translation 與 Writing Tools 等 Apple 原生介面;是否可用取決於裝置與系統設定。

在建立行事曆事件或提醒事項前,Mosaic 會顯示可編輯草稿並要求你確認。Share sheet 只在你選擇目的地後傳送內容。

7. 保存、匯出與刪除

資料會保留到你刪除內容、刪除工作空間、執行 App 內完整刪除,或移除 App。你可以匯出自己的資料。完整刪除會清除本機資料庫、受保護附件、Share inbox、本機索引與相關偏好;若啟用同步,刪除標記會用於防止較舊資料復原已刪除內容。

8. 兒童、變更與聯絡方式

Mosaic 不是專為兒童設計,也不會明知而收集兒童資料作廣告或剖析。本政策若有重大變更,會在本頁更新生效日期。

隱私或支援問題請聯絡 support@claude-world.com。請勿在郵件中附上密碼、驗證碼、健康資料或私密內容。

English Summary

Privacy summary

Mosaic is designed around data minimization, on-device processing, and explicit consent. Content is stored locally with iOS Complete Protection by default. Supported Vision, Natural Language, Speech, search, and Foundation Models operations run on device where available.

When an eligible task uses Apple Private Cloud Compute, Mosaic shows the scope for personal content and requires confirmation. Allowed content is minimized and redacted first. Only explicitly scoped images classified as public low-risk may be analyzed directly by a vision-capable PCC model. Personal images provide redacted text only; sensitive content remains on device, and restricted content is never eligible for PCC, CloudKit, Spotlight, or system donation. Assistant responses are generated only by Apple Foundation Models.

Optional web search sends only public query terms authored in your current message to Mosaic's Cloudflare Web Search gateway and its Ceramic search provider. Captured content, previous assistant messages, private identifiers, and personal, sensitive, or restricted data are never used as search queries. Results return as sources for the Apple model; the gateway does not retain queries or results after the request. A random install identifier and network IP address are used transiently for abuse prevention and rate limiting.

Optional CloudKit sync stores only approved safe projections in the user's private database; raw attachments and the primary local database are not synced directly. Mosaic includes no third-party ads, cross-app tracking, or third-party analytics SDK.

You may export or delete your data in the App. Questions: support@claude-world.com.