小汐助手 · Xiaoxi Assistant返回官网服务条款 / Terms
中文English
LEGAL · PRIVACY

隐私政策 / Privacy Policy

生效日期 / Effective date: 2026-08-31 · 最后更新 / Last updated: 2026-09-28
中文

隐私政策

欢迎使用“小汐助手”(“本服务”)。本隐私政策说明北京汐途智观科技有限公司(TideVision Technology,“我们”)在提供小汐助手网站、移动应用及相关功能时,如何收集、使用、存储、共享和保护个人信息。

1. 我们收集的信息

根据您实际使用的功能,我们可能处理以下信息:

2. 我们如何使用信息

3. Google / Gmail 数据

只有在您主动授权后,小汐助手才会连接您的 Google / Gmail 账号。我们仅在提供您明确请求的邮件助手功能所必需的范围内访问和使用 Google 用户数据,包括读取邮件元数据和正文,以进行邮件整理、分类、翻译,以及提取课程、作业、考试、截止日期、时间、地点和日程变更等信息。

小汐助手不会使用 Gmail 权限发送、删除、修改、归档、加标签或以其他方式更改您 Gmail 账号中的邮件。我们不会出售 Google 用户数据,也不会将其用于广告、广告定向、再营销、信用评估、数据经纪或与您明确请求的功能无关的数据库构建。

Google Workspace API Limited Use:小汐助手对从 Google Workspace API 获取的信息的使用和传输将遵守 Google API Services User Data Policy,包括 Limited Use 要求。我们不会使用原始、聚合、匿名化、派生或其他形式的 Google Workspace API 数据来创建、训练或改进通用或非个性化的人工智能或机器学习模型。

您可以随时通过 Google 账号权限页面撤销小汐助手的访问权限。撤销后,我们将停止该 Google 账号的后续同步。

3.1 Microsoft / Outlook 邮箱

当您主动连接 Outlook / Microsoft 365 时,我们通过 Microsoft Graph 委托授权申请 Mail.Read(读取邮件)、User.Read(读取基本账号资料)和 offline_access(在授权有效期内刷新访问令牌)。邮件正文用于与 Gmail 相同的分类、信息提取和日程流程;我们不申请发送或修改邮件的权限。学校或组织的授权策略可能限制连接。

3.2 同步与保存

连接邮箱后,您可以手动扫描,后台任务也会定期扫描已连接邮箱,并将邮件内容交给 AI 分类和提取。保存的邮件记录可包含发件人、主题、正文、分类和提取结果;您请求翻译后,翻译结果也会保存。待确认日程需要您核对;保留或移除一组待确认日程不会删除原始邮件。

4. AI 与第三方服务提供商

在您主动使用相关功能并同意相应数据处理后,为提供您明确请求的 AI 分类、翻译、问答和信息提取等功能,我们可能将完成该请求所必需的最少内容发送给代表我们处理数据的第三方技术服务提供商。此类数据仅可用于提供相关用户请求功能,不得用于广告、数据经纪或训练通用/非个性化 AI 或机器学习模型。

目前,小汐助手的第三方 AI 服务提供商包括 OpenAI API Platform。我们通过 API 使用该服务处理用户请求所需的数据。OpenAI 的 API Platform 默认不会使用 API 输入和输出训练或改进其模型,除非 API 客户明确选择加入数据共享。小汐助手不会将 Google Workspace API 数据选择加入用于通用模型训练的数据共享机制。

我们还可能使用云托管、数据库、邮件发送、身份验证和安全服务提供商来运行本服务。目前服务基础设施主要托管于加拿大;部分服务提供商可能在其他国家或地区处理数据。

文档识别的处理路径取决于具体功能:“本地 OCR”指服务器上的 OCR,不代表文件留在手机上;相应文档会上传服务器处理。部分 AI 图片识别功能会把图片发送给 OpenAI API。文献搜索会把您输入的检索词发送给 OpenAlex。请勿在检索词中加入不必要的个人信息。

4.1 访客与系统日历

支持访客模式的移动版本允许未登录用户浏览功能框架;私人邮件、日程和资料需要登录后才能读取。执行受保护操作时才要求登录。退出或切换账号会清除当前页面的私人状态。

在提供系统日历功能的移动版本中,只有您主动添加日程时才申请日历权限。该功能手动、单向复制标题、时间和地点,不复制邮件正文;再次添加会更新已关联事件。应用在设备安全存储中按账号保存事件标识和归属标记,以便更新或移除自己创建的副本。为核对归属和恢复失败操作,应用可能读取相应日历、时间范围内的事件;这些系统日历内容不会上传到小汐服务器。所选日历可能由 Apple、Google 或其他日历服务同步,请同时查看对应服务的隐私政策。

退出登录、断开邮箱或删除小汐日程不会自动删除系统日历副本。您可在“管理已同步副本”中主动移除。卸载应用、清除设备存储或更换设备可能丢失映射,此时请在系统日历中手动处理;应用不会据此扫描并批量删除其他事件。

5. 数据存储与保留

我们仅在提供用户明确请求的功能、维持账号、履行法律义务、处理争议和保障安全所合理需要的期间保留信息。不同类型的数据可能具有不同的保留期限,我们不会为了建立独立数据库、广告或通用 AI/ML 模型训练而长期保留 Google Workspace API 数据。

如果您断开邮箱连接,我们会停止对该邮箱的后续同步。断开操作会清除该连接在服务端保存的 OAuth 凭据,但不会自动删除已经保存的邮件正文、翻译、提取结果、日程或学习事项。删除小汐内的数据不会删除 Gmail 或 Outlook 中的原始邮件。已保存内容需另行删除或提出删除请求;第三方平台上的授权可在其账号设置中撤销。

6. 数据共享

我们不会出售您的个人信息。我们仅会在以下必要情形共享信息:

对于 Google Workspace API 数据,我们仅会按照 Google API Services User Data Policy 允许的目的进行传输和处理。

7. 您的选择和权利

在适用法律允许的范围内,您可以请求访问、更正或删除与您相关的个人信息,并可以撤回某些授权。部分资料可直接在账号设置中修改;如需删除账号及关联数据,请发送请求至 info@xituzhiguan.cn,说明注册邮箱及请求范围;我们需核实账号归属。请勿发送密码或验证码。当前没有应用内一键删除整个账号的功能。具体处理范围、依法保留的例外及备份清理情况会在处理请求时说明,不承诺页面未列明的固定清理时限。

8. 安全

我们采取合理的技术和组织措施保护信息,例如身份验证、访问控制、加密传输和受控服务器环境。但任何网络或存储系统都无法保证绝对安全。

9. 未成年人

本服务主要面向高等教育阶段及具备相应民事行为能力的用户。若您所在地区要求未成年人取得监护人同意,请在获得必要同意后使用本服务。

10. 国际和跨境处理

由于我们使用跨境云服务和技术服务提供商,您的信息可能在您所在国家或地区以外被处理或存储。我们会根据适用法律采取合理措施保护这些信息。

11. 政策更新

我们可能随着功能、法律或业务变化更新本隐私政策。重大变更时,我们会通过网站、应用或其他合理方式提供通知。页面顶部的“最后更新”日期反映最新版本。

12. 联系我们

如您对本隐私政策、个人信息处理方式或权利请求有疑问,请联系 info@xituzhiguan.cn。

English

Privacy Policy

Welcome to Xiaoxi Assistant (the “Service”). This Privacy Policy explains how Beijing Xitu Zhiguan Technology Co., Ltd. (TideVision Technology, “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal information when providing the Xiaoxi Assistant website, mobile applications, and related features.

1. Information We Process

Depending on the features you use, we may process:

2. How We Use Information

3. Google / Gmail Data

Xiaoxi Assistant connects to your Google / Gmail account only after you explicitly authorize access. We access and use Google user data only to the extent necessary to provide the Email Assistant features you explicitly request, including reading message metadata and message bodies in order to organize and classify emails, translate email content, and extract academic information such as courses, assignments, exams, deadlines, times, locations, and schedule changes.

Xiaoxi Assistant does not use Gmail permissions to send, delete, modify, archive, label, or otherwise alter messages in your Gmail account. We do not sell Google user data, and we do not use it for advertising, targeted advertising, retargeting, credit evaluation, data brokerage, or creation of databases unrelated to functionality explicitly requested by the user.

Google Workspace API Limited Use: Xiaoxi Assistant's use and transfer of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use raw, aggregated, anonymized, derived, or other Google Workspace API data to create, train, or improve generalized or non-personalized artificial intelligence or machine learning models.

You may revoke Xiaoxi Assistant's access at any time through your Google Account permissions. After access is revoked, future synchronization for that Google account will stop.

3.1 Microsoft / Outlook Mail

When you connect Outlook / Microsoft 365, we request delegated Microsoft Graph permissions Mail.Read (read messages), User.Read (basic account profile), and offline_access (refresh access while authorized). Message bodies support the same classification, extraction, and calendar workflow as Gmail. We do not request permission to send or modify messages. Your school or organization may restrict consent.

3.2 Synchronization and Saved Content

After connection, you can scan manually and a background task also periodically scans connected mailboxes, sending message content for AI classification and extraction. Saved records can include sender, subject, body, classification, and extracted information. Requested translations are also saved. Review pending schedules for accuracy; keeping or removing a review group does not delete the original messages.

4. AI and Service Providers

When you actively use the relevant feature and consent to the associated data processing, we may transmit the minimum content necessary to third-party technology providers acting on our behalf in order to provide AI-powered classification, translation, question answering, and information extraction that you explicitly request. Such data may only be processed to provide the relevant user-requested functionality and may not be used for advertising, data brokerage, or generalized/non-personalized AI or machine-learning model training.

Our current third-party AI service provider includes the OpenAI API Platform. We use the API service to process data necessary to fulfill user requests. OpenAI states that API Platform inputs and outputs are not used to train or improve OpenAI models by default unless an API customer explicitly opts in to data sharing. Xiaoxi Assistant does not opt Google Workspace API data into data-sharing mechanisms for generalized model training.

We may also use cloud hosting, database, email delivery, authentication, and security providers to operate the Service. Our core infrastructure is currently hosted primarily in Canada, while some providers may process data in other jurisdictions.

Document processing depends on the feature: “local OCR” means OCR on our server, not on your phone, and documents are uploaded for processing. Some AI image-recognition features send images to OpenAI API. Literature search sends your search terms to OpenAlex; avoid including unnecessary personal information in those terms.

4.1 Guest Access and Device Calendar

Mobile versions with guest access let you browse feature frameworks without signing in. Private mail, schedules, and profiles require authentication. Protected actions prompt sign-in; signing out or switching accounts clears private page state.

In mobile versions offering device-calendar integration, calendar permission is requested only when you actively add an event. This manual, one-way feature copies the title, time, and location, not email bodies; adding again updates the linked event. Per-account event identifiers and ownership markers are kept in device secure storage to update or remove copies created by this feature. To check ownership and recover interrupted operations, the app may read events in the relevant calendar and time range; device-calendar contents are not uploaded to our server. Your selected calendar may synchronize through Apple, Google, or another calendar provider, whose privacy policy also applies.

Signing out, disconnecting email, or deleting a Xiaoxi schedule does not automatically delete device-calendar copies. Use “Manage synced copies” to remove them. Uninstalling, clearing device storage, or changing devices may lose the mapping, requiring manual removal in the system calendar; the app will not bulk-delete other events to recover it.

5. Storage and Retention

We retain information only for as long as reasonably necessary to provide user-requested functionality, maintain accounts, comply with legal obligations, resolve disputes, and protect security. Different categories of information may have different retention periods. We do not retain Google Workspace API data for the purpose of building independent databases, advertising, or generalized AI/ML model training.

If you disconnect an email account, future synchronization from that account stops. Disconnecting clears the server-side OAuth credentials for that connection, but does not automatically delete saved email bodies, translations, extracted information, schedules, or study items. Deleting data within Xiaoxi does not delete original messages in Gmail or Outlook. Saved content requires separate deletion or a deletion request; provider-side authorization can be revoked in the provider’s account settings.

6. Sharing

We do not sell your personal information. We share information only when necessary:

Google Workspace API data is transferred and processed only for purposes permitted by the Google API Services User Data Policy.

7. Your Choices and Rights

Subject to applicable law, you may request access to, correction of, or deletion of personal information associated with you, and you may withdraw certain permissions. Some profile information can be edited directly in account settings. To request deletion of your account and associated data, contact info@xituzhiguan.cn with your registered email and requested scope. We need to verify account ownership; do not send passwords or verification codes. There is currently no in-app one-click account deletion feature. The handling scope, lawful retention exceptions, and backup cleanup status will be explained when processing the request; this page does not promise a fixed cleanup deadline.

8. Security

We use reasonable technical and organizational safeguards, such as authentication, access controls, encrypted transmission, and controlled server environments. No network or storage system can be guaranteed to be completely secure.

9. Minors

The Service is primarily intended for users in higher education and users who have the legal capacity to use the Service. Where local law requires parental or guardian consent, you should obtain the required consent before using the Service.

10. International Processing

Because we use cross-border cloud and technology providers, information may be processed or stored outside your country or region. We take reasonable measures to protect information in accordance with applicable law.

11. Changes to This Policy

We may update this Privacy Policy as our features, laws, or business practices change. For material changes, we will provide notice through the website, application, or another reasonable method. The “Last updated” date at the top reflects the current version.

12. Contact

If you have questions about this Privacy Policy, our data practices, or a privacy-rights request, contact info@xituzhiguan.cn.