Skip to content
Doraemon Studio
Doraemon Schedule Terms of Use
EN / 中文

Doraemon Schedule

Privacy Policy

Updated and effective: October 9, 2026

This policy explains how Doraemon Schedule Development Team (“we”) processes information when providing the Doraemon Schedule iOS app and related services, and how you can manage it. Please pay particular attention to cloud AI, subscription verification, and system permissions.

On this page

  1. Schedules, conversations, and materials
  2. Device accounts, authentication, and security
  3. Apple purchases and subscription verification
  4. When you choose cloud AI
  5. Microphone and speech recognition
  6. Location and maps
  7. System calendar, reminders, and widgets
  8. Email feedback
  9. Storage, protection, and third parties
  10. Your choices and information rights
  11. Children
  12. Policy changes and contact

1. Schedules, conversations, and materials

Schedule titles, dates and times, notes, locations, and tags that you create or import, together with conversations and the names, types, extracted text, references, and summaries of selected materials, are primarily stored on your device to record, display, find, and organize your plans. We do not proactively read files you have not selected.

Ordinary local creation, editing, and viewing do not upload your entire schedule or materials library to our servers. We currently provide neither our own schedule cloud sync nor in-app iCloud schedule sync. Content sent when you choose cloud AI is described in section 4; system calendar account sync is described in section 7.

Daily and weekly free schedule creation allowances and usage counts are recorded locally and are not uploaded to our servers. The allowance rules are described in the Terms of Use.

2. Device accounts, authentication, and security

The app generates a random 40-character hexadecimal CUID to identify a service account, authenticate requests, and provide membership or allowlist access. This is a device account identifier for our service, not an advertising identifier. The app also generates a device authentication credential, deviceSecret, and stores it in the iOS Keychain. It is not used for advertising tracking or attached to feedback emails. Keychain items may remain after the app is uninstalled.

Our servers process the CUID, account UUID, device authentication information, and session verification information. During authentication, the device credential is transmitted over HTTPS. The server stores only hashes of the device credential and session token, not their original values. Sessions last no more than one hour. Requests may also include common parameters such as system language, together with a signature, timestamp, and random nonce, for authentication, replay protection, and appropriate responses.

Network providers such as Cloudflare process IP addresses and necessary network information when establishing connections. We use necessary request status, rate-limit, and security records to prevent abuse, diagnose failures, and protect the service. We do not put schedule content, chat bodies, materials, or authentication secrets in business logs.

3. Apple purchases and subscription verification

Purchases are handled by Apple through the App Store and StoreKit. We do not read your bank card details, payment passwords, or Apple Account password. To verify purchase ownership and provide access, the app sends our Cloudflare service the product identifier, transaction identifier, original transaction identifier, expiration date, revocation status, appAccountToken, and Apple-signed transaction evidence (JWS).

Our servers verify transactions through Apple’s verification mechanisms and receive Apple subscription status notifications, with production and sandbox handled separately. Cloudflare D1 stores the minimum account records, subscription and transaction status, allowlist status and expiration, and necessary security or audit records needed for account and subscription services.

The app keeps different layers of UserInfo and entitlement cache in memory, UserDefaults, and the Keychain, separated by account owner and service environment. Persisted entitlement caches are encrypted with AES-GCM using a key derived from the device credential in the Keychain. If a network request fails, verified local access that has not expired can support the applicable local features. A purchase awaiting verification is not an active membership. Cloud AI access must still be checked by the server at the time of use.

4. When you choose cloud AI

When you choose to send a cloud AI request, the text you enter, extracted text from selected documents used in the request, and conversation context necessary for the task are forwarded through our Cloudflare Worker to DeepSeek to interpret content, generate a response, and help organize schedules. This may include schedules, locations, other people’s personal information, or sensitive materials. Review the content and remove unnecessary information before sending, and obtain any necessary authorization to process other people’s information.

This feature requires a network connection and eligible access. You can choose not to send a request and continue using available local schedule features. Speech recognition text first appears in the input area for you to decide whether to send it. Selecting a file or editing a local schedule does not itself sync your entire library to the cloud.

Our servers do not save chat bodies, attachments, or summaries to D1, and do not log request bodies. Cloudflare and DeepSeek still process request data to transmit it and perform inference. These restrictions do not mean the providers retain no data. Their processing, retention, and regional rules are described in the Cloudflare Privacy Policy and DeepSeek Privacy Policy.

Our Cloudflare service runs on its global network; a .cn domain does not mean the service is hosted in mainland China. Using cloud AI, account, or subscription services may involve transmission or processing outside your country or region. DeepSeek processes inference requests under its own policy. We do not promise that all network data is processed within China. Where separate notice or consent is required by applicable law, we will follow those requirements.

5. Microphone and speech recognition

For voice input, the app requests microphone and speech recognition permissions and uses Apple’s on-device speech recognition to convert speech into text, without falling back to cloud speech recognition. Voice input may be unavailable if your device or language does not support on-device recognition.

The app does not save this recording as a materials attachment. Recognized text first appears in the input area, where you may edit it, delete it, or decide whether to send it to cloud AI. Denying or disabling these permissions affects voice input; text input remains available.

6. Location and maps

When you use a feature that needs your current location, the app requests location access while in use to help select or search for a schedule location. It does not continuously collect location in the background or build a background movement history. You can also enter a location manually.

Place search and map display use Apple Maps. Search terms, the map area you view, authorized coordinates, and necessary device and network information may be processed by Apple and its mapping partners. Apple Maps in China uses Amap’s mapping service. See Apple Maps & Privacy and Apple Location Services & Privacy for details.

7. System calendar, reminders, and widgets

Connecting the system calendar requires full calendar access to read information needed for calendar integration. The current reading window covers one year in the past through one year in the future. Event fields may include titles, start and end times, notes, locations, links, time zones, recurrence, alerts, and participants. The app creates, updates, or deletes system calendar events after you authorize access and perform the corresponding action.

System calendar accounts such as iCloud, Google, and Exchange, and their synchronization, are managed by iOS and the account providers you choose according to your system settings and their privacy rules. They are separate from a schedule cloud sync service provided by us.

Notification permission and, on supported system versions, AlarmKit permission are used only for the schedule reminders you set. Delivery depends on permissions and system settings. Schedule widgets and Live Activities display relevant titles, times, and similar information that may be seen by others who can view your Home Screen or Lock Screen. Use available app and system options to show, hide, or remove these displays. Local data needed by widgets is shared with the app through an App Group.

You can manage or revoke calendar, location, microphone, speech recognition, notification, and other permissions in iOS Settings. Disabling a permission affects its corresponding feature without affecting available features that do not depend on it.

8. Email feedback

When you choose to send feedback, an email draft may include your CUID, device model, iOS version, and app version to help diagnose the problem. You may review, edit, or remove them before sending through your email app. We do not automatically attach schedules, materials, authentication secrets, or purchase evidence.

We process the email address, description, and attachments you choose to send to respond and resolve the issue. Remove unnecessary personal information from screenshots or attachments first. Email services may involve international transfers and are subject to the privacy rules of your email provider and our receiving email provider. Contact: wecopilot.alpha@gmail.com.

9. Storage, protection, and third parties

Local files use iOS file protection, authentication credentials use the Keychain, and network services use HTTPS. We apply security measures appropriate to the processing purpose, but cannot guarantee absolute security for any device, network, or storage. The app does not track users for advertising, read advertising identifiers for ad delivery, or build advertising profiles.

Local schedules, conversations, and materials remain until you delete the relevant content or app data. Server records are retained only as needed for account, subscription, security, and support services and legal requirements. When no longer needed, we delete them or handle them appropriately; we do not promise an unverified fixed retention period. Purchase ownership records and legally necessary transaction or security audit information may need to be retained.

The main third parties involved are Apple (purchases, speech, calendar, maps, notifications, and other system capabilities; see the Apple Privacy Policy), Cloudflare (network access, server execution, and D1 storage; see the Cloudflare Privacy Policy), and DeepSeek (cloud inference you choose to use; see the DeepSeek Privacy Policy). Relevant information is processed for the corresponding feature or necessary service, and each provider’s own services are also governed by its rules.

10. Your choices and information rights

You can view, edit, or delete relevant schedules and conversations in the app and use the existing attachment cleanup option. Removing attachment files does not necessarily delete extracted text, references, or summaries; manage those within the corresponding records. There is currently no option to clear the entire workspace in one step.

Uninstalling the app does not automatically delete events already written to the system calendar, system or account backups, or Keychain information that may remain. It also does not cancel an Apple subscription. Manage calendars and backups in the relevant services and subscriptions in your Apple Account.

You may email wecopilot.alpha@gmail.com to request access to, copies of, correction of, or deletion of account-related information we process, withdraw consent, or ask us to explain our processing rules. You may also use this address to exercise other rights under applicable law. We will conduct necessary identity and account ownership checks to avoid deleting the wrong account or disclosing information to another person. Do not send device secrets, session tokens, Apple passwords, or bank card details.

The app currently has no one-step interface for deleting a server account. Please request account deletion by email. We will handle the request under applicable law. Minimum records that must remain for legal requirements, purchase ownership, security, or dispute handling will have restricted purposes and appropriate protection. Deleting an account does not replace canceling an Apple subscription.

11. Children

Minors should use the service with a guardian’s guidance and obtain guardian consent as required by applicable law. Where such consent is required for processing the personal information of children under 14, we will process it after obtaining that consent. If a guardian believes a child has provided information without necessary consent, please contact wecopilot.alpha@gmail.com so we can address it.

12. Policy changes and contact

This policy may change as features or legal requirements change. We will display the updated and effective dates on this page. Material changes to information processing will be communicated through an in-app notice or another appropriate channel, and we will obtain renewed consent where legally required.

Operator: Doraemon Schedule Development Team. For privacy, permissions, or information rights questions, contact wecopilot.alpha@gmail.com.

哆啦日程

隐私政策

更新及生效日期:2026 年 10 月 9 日

本政策说明哆啦日程开发团队(以下简称“我们”)在提供哆啦日程 iOS 应用及相关服务时,如何处理信息,以及你可以如何管理这些信息。请特别留意云端 AI、订阅验证和系统权限涉及的数据处理。

本页目录

  1. 日程、对话与材料
  2. 设备账户、认证与安全
  3. Apple 购买与订阅验证
  4. 你主动使用云端 AI 时
  5. 麦克风与语音识别
  6. 定位与地图
  7. 系统日历、提醒与小组件
  8. 邮件反馈
  9. 保存、保护与第三方
  10. 你的选择与信息权利
  11. 未成年人
  12. 政策更新与联系

1. 日程、对话与材料

你在应用中创建或导入的日程标题、日期与时间、备注、地点、标签,以及对话内容、所选材料的文件名称和类型、提取文字、引用与摘要,主要保存在设备本地,用于记录、展示、检索和整理安排。我们不会主动读取你没有选择的文件。

普通的本地创建、编辑和查看,不会把整个日程库或材料库上传到我们的服务器。目前没有自有日程云同步或应用内 iCloud 日程同步功能。你主动使用云端 AI 时,需要发送的内容见第 4 节;系统日历账户的同步见第 7 节。

免费新增日程的每日、每周额度及使用计数记录在设备本地,不上传到我们的服务器。额度规则见 使用条款。

2. 设备账户、认证与安全

为了识别服务账户、验证请求和提供会员或白名单权益,应用生成随机的 40 位十六进制 CUID。它是本服务的设备账户标识,不是广告标识符。应用还生成设备认证凭据 deviceSecret,保存在 iOS 钥匙串,不用于广告跟踪,也不作为反馈邮件附件发送。钥匙串项目可能在卸载应用后仍然保留。

服务器处理 CUID、账户 UUID、设备认证信息和会话验证信息。认证时设备凭据通过 HTTPS 传输;服务端仅保存设备凭据和会话令牌的哈希,不保存这些凭据的原文。会话最长有效 1 小时。请求还可能包含系统语言等公共参数,以及签名、时间戳和随机 nonce,用于认证、防重放和正确返回内容。

Cloudflare 等网络服务在连接过程中会处理 IP 地址及必要的网络信息。我们使用必要的请求状态、限流和安全记录来防止滥用、排查故障和维护服务安全,不把日程、聊天正文、材料内容或认证密钥写入业务日志。

3. Apple 购买与订阅验证

购买由 Apple 的 App Store 和 StoreKit 处理。我们不读取你的银行卡信息、支付密码或 Apple 账户密码。为核对购买归属和提供权益,应用会向我们的 Cloudflare 服务发送产品标识、交易标识、原始交易标识、有效期、撤销状态、appAccountToken,以及 Apple 签名的交易凭证(JWS)。

服务器通过 Apple 的验证机制核验交易,并接收 Apple 的订阅状态通知;生产与沙盒环境分别处理。Cloudflare D1 保存提供账户与订阅服务所必需的最小账户记录、订阅和交易状态、白名单及有效期、必要的安全或审计记录。

应用在内存、UserDefaults 和钥匙串中保存不同层级的 UserInfo 与权益缓存,按账户所有者及服务环境区分。持久化权益缓存使用 AES-GCM 加密,密钥由钥匙串中的设备凭据派生。网络失败时,已验证且未到期的本地权益可用于相应本地功能;待验证购买不等于已生效会员。云端 AI 权限仍须由服务器实时校验。

4. 你主动使用云端 AI 时

当你选择发送云端 AI 请求时,你输入的文字、所选文档中用于本次请求的提取文字,以及完成任务所需的对话上下文,会通过我们的 Cloudflare Worker 转发给 DeepSeek,用于理解内容、生成回复和协助整理日程。这些内容可能包含日程、地点、他人的个人信息或敏感材料;请在发送前核对并移除不必要的信息,处理他人信息时取得必要授权。

该功能需要联网及有效使用资格。你可以选择不发送,继续使用可用的本地日程功能。语音识别产生的文字先进入输入区,由你决定是否发送;选择文件或在本地编辑日程本身,不会触发整个资料库的云端同步。

我们的服务器不把聊天正文、附件或摘要保存到 D1,也不记录请求正文日志。完成传输和推理时,Cloudflare 与 DeepSeek 仍需要处理请求数据;上述限制不代表供应商不保存任何数据。供应商的处理、留存和适用地域规则见 Cloudflare 隐私政策、DeepSeek 隐私政策。

我们的 Cloudflare 服务运行在全球网络,.cn 域名不表示在中国大陆托管。使用云端 AI、账户和订阅服务,数据可能在你所在国家或地区以外传输或处理;DeepSeek 按其自身政策处理推理请求。我们不承诺全部网络数据均在中国境内处理。依法需要另行告知或取得同意时,将按适用法律办理。

5. 麦克风与语音识别

使用语音输入时,应用请求麦克风与语音识别权限,使用 Apple 的设备端语音识别能力将语音转换为文字,不回退到云端语音识别。设备或语言不支持设备端识别时,相关语音功能可能不可用。

应用不把这段录音保存为材料附件。识别文字先显示在输入区,你可以修改、删除或决定是否发送给云端 AI。拒绝或关闭相应权限会影响语音输入,你仍可使用文字输入。

6. 定位与地图

你使用需要当前位置的功能时,应用请求“使用期间”定位权限,以协助选择或搜索日程地点。应用不持续在后台采集位置,也不建立后台行踪轨迹;你也可以手动填写地点。

地点搜索和地图展示由 Apple 地图提供。搜索词、所查看的地图区域、经授权的坐标,以及必要的设备、网络等信息,可能由 Apple 及其地图合作方处理;Apple 地图在中国使用高德的地图服务。具体规则见 Apple 地图与隐私、Apple 定位服务与隐私。

7. 系统日历、提醒与小组件

连接系统日历时,应用请求日历完整访问权限,读取与同步所需的事件信息。当前日历读取范围为过去一年至未来一年,可能涉及事件标题、起止时间、备注、地点、链接、时区、重复规则、提醒和参与者等字段;应用会在你授权并执行对应操作后新增、更新或删除系统日历事件。

系统日历中的 iCloud、Google、Exchange 等账户及其同步由 iOS 和你选择的账户服务提供方管理,取决于系统设置,适用各自的隐私规则。它们不等于我们提供日程云同步。

通知权限及适用系统版本中的 AlarmKit 权限,仅用于你设置的日程提醒。是否送达取决于权限和系统设置。日程小组件与实时活动会显示相应标题、时间等信息,可能被能看到主屏幕或锁定屏幕的人看见;你可以通过应用和系统提供的显示、隐藏或移除选项管理。小组件所需的本地数据通过 App Group 与应用共享。

你可以在 iOS 设置中管理或撤回日历、定位、麦克风、语音识别、通知等权限。关闭权限会影响对应功能,不影响不依赖该权限的其他可用功能。

8. 邮件反馈

你主动使用反馈功能时,邮件草稿可预填 CUID、设备型号、iOS 版本和应用版本,以便排查问题。你可以在发送前查看、修改或删除这些内容。发送由你使用的邮件应用完成;我们不会自动附上日程、材料、认证密钥或购买凭证。

我们处理你主动发送的邮件地址、问题说明和附件,以回复并解决问题。请先移除截图或附件中不必要的个人信息。邮件服务可能涉及跨境传输,适用你使用的邮件服务商及我们的收件服务商的隐私规则。联系邮箱:wecopilot.alpha@gmail.com。

9. 保存、保护与第三方

本地文件使用 iOS 提供的文件保护机制,认证凭据使用钥匙串保护,网络服务使用 HTTPS。我们采取与处理目的相适应的安全措施,但不能保证任何设备、网络或存储绝对安全。应用没有广告跟踪,不读取广告标识用于投放,也不建立广告画像。

本地日程、对话和材料会保留到你删除对应内容或应用数据;服务器记录仅在提供账户、订阅、安全和支持服务所需的期间,以及法律要求的期间保存。无需继续保存时,我们会删除或作适当处理,不承诺未经核实的固定留存天数。购买归属、依法必要的交易或安全审计信息可能需要继续保留。

与功能有关的第三方主要包括:Apple(购买、语音、日历、地图、通知等系统能力,见 Apple 隐私政策)、Cloudflare(网络入口、服务器运行与 D1 存储,见 Cloudflare 隐私政策)、DeepSeek(你主动使用的云端推理,见 DeepSeek 隐私政策)。仅在对应功能或必要服务场景中处理相关信息,供应商各自的服务还适用其自身规则。

10. 你的选择与信息权利

你可以在应用中查看、编辑或删除对应日程与对话,并使用现有的附件清理入口。清理附件文件不必然删除已提取的文字、引用或摘要;这些内容需要在对应记录中管理。目前没有一键清空整个工作区的功能。

卸载应用不会自动删除已写入的系统日历事件、系统或账户备份、可能保留的钥匙串信息,也不会取消 Apple 订阅。系统日历与备份须在相应服务中管理,订阅须在 Apple 账户中管理。

你可以通过 wecopilot.alpha@gmail.com 申请查阅、复制、更正或删除我们处理的账户相关信息,撤回同意,或要求说明处理规则;其他适用法律赋予的信息权利也可通过该邮箱提出。为防止误删或向他人泄露信息,我们会进行必要的身份与账户归属核实。请勿发送设备密钥、会话令牌、Apple 密码或银行卡信息。

目前应用没有一键删除服务器账户的界面入口,请通过邮箱提出账户删除申请。我们将按适用法律处理;依法或为购买归属、安全及争议处理必须保留的最小记录,会限制用途并采取保护措施。删除账户不替代取消 Apple 订阅。

11. 未成年人

未成年人应在监护人的指导下使用,并按照适用法律取得监护人同意。对未满 14 周岁儿童的个人信息,依法需要取得监护人同意的,我们将在获得该同意后处理。若监护人认为儿童在未取得必要同意的情况下提供了信息,请通过 wecopilot.alpha@gmail.com 联系我们处理。

12. 政策更新与联系

本政策可能随功能或法律要求更新。我们会在本页注明更新及生效日期;对信息处理有实质影响的重要变化,会通过应用内提示或其他适当方式通知,并在依法需要时重新取得同意。

运营主体:哆啦日程开发团队。有关隐私、权限或信息权利的问题,请联系 wecopilot.alpha@gmail.com。

© 2026 Doraemon Studio
Privacy Policy Terms of Use Email support