跳到主要内容

法律信息

隐私政策

Last updated: August 4, 2026

1. 我们是谁以及如何联系我们

TCVoiceAI 是一款由其创作者独立运营的桌面语音翻译产品。 TCVoiceAI 的运营方是本服务所处理的账户、网站、账单、支持及服务使用数据的数据控制者。隐私问题和数据权利请求可以发送至 support@tcvoiceai.com.

如果您所在司法管辖区要求提供更多有关数据控制者、代表或数据保护官的信息,请联系我们,我们将针对您的请求提供当前适用的联系信息。

2. 我们收集哪些数据

登录时,我们会收集创建和保护账户所需的 Google 账户信息:姓名、电子邮箱地址、邮箱验证状态、Google 账户标识符、头像 URL 及相关身份验证记录。我们还会存储账户角色、您提供的语言区域、推荐信息、支持偏好、方案与订阅状态、Paddle 客户和订阅标识符、Paddle 提供的发票及交易引用信息,以及提供付费方案所需的账单状态。

为运营服务,我们会存储请求标识符、语言方向、共用的翻译及建议回复字数用量、摘要字数、额度预留、每日用量计数器、OpenAI 模型标识符、Token 数量、服务提供商的请求和响应标识符、时间戳,以及执行方案限制、防止滥用、排查可靠性问题和计算成本所需的其他元数据。此类元数据按设计不包含原始音频、转写文本、翻译文本、提示上下文、生成的回复文本或生成的摘要内容。

自动化滥用防控措施会评估服务使用元数据,例如请求数量和时间、请求类型、估算的 Token 和服务提供商用量、额度状态以及服务提供商调用次数。这些措施可能会暂时限制 AI 功能。用户可请求支持团队审核较长期的 AI 访问暂停。存储的滥用防控记录按设计不包含音频、转写内容、翻译内容、提示上下文或生成的内容。

If you explicitly connect an optional work integration, we store its provider key, account label, provider-verified scopes, token expiry, revocation state, and encrypted access and refresh credentials needed to perform the actions you approve. Connector credentials are never returned by the API. Each publication accepts only the reviewed task, note, email-draft, or calendar-event fields that you explicitly approve; raw transcripts are rejected.

如果已启用 Google Analytics 且您选择“允许分析”,Google 可能会接收并处理您的 IP 地址以推断大致地区,同时处理不含查询字符串的页面 URL、页面标题、不含查询字符串的引荐来源、浏览器和设备信息,以及基本的访问、互动和会话统计信息。Google Analytics 使用第一方分析标识符来区分访问。我们的集成不会将您的 TCVoiceAI 账户 ID、姓名、电子邮箱地址、音频、转写文本、翻译、摘要或支持内容附加到分析事件中。

如果您联系我们、创建支持工单,或发送应用反馈或评价,我们会处理回复及审核提交内容所需的姓名、电子邮箱地址、主题、类别、优先级、评分、消息内容、回复、公开评价同意状态、管理备注和时间戳。只有在您选择公开且管理员批准后,公开评价才会显示在网站上。如果 macOS 应用发送反馈或错误报告,我们可能会收到应用版本、构建版本、macOS 版本、架构、音频后端、所选设备名称、应用状态、额度计数器、方案键值、请求标识符、错误类别、错误消息及诊断元数据。反馈和报告应排除音频、转写文本、凭据及对话内容。

支持工单可能包含表单中选择的应用平台。

3. 语音、转写文本、翻译、建议及 AI 输出内容

在您主动启动翻译语音或原始音频后,macOS 应用会从您选择的麦克风及 TCVoiceAI 虚拟扬声器路径采集音频。Apple 语音识别会将语音转换为文本。翻译语音还会使用 macOS 文本转语音功能播放翻译。原始音频会保持双方真实声音实时传输,并可创建双语历史记录或同语种通话转写,还可选择翻译转写文本。

请求翻译时,我们的服务器会接收识别出的文本、语言方向、有限范围的对话上下文、可选的用户上下文备注,以及当前会话配置中仅与内容匹配的自定义词汇。仅进行同语种通话转写的会话不会发送翻译请求。配置名称、联系人标签和完整的配置库不会发送到 TCVoiceAI 服务器。会话进行期间,在您的 macOS 设置及 Apple 隐私条款约束下,识别语言的术语可能会作为上下文提示提供给 Apple 语音识别。为翻译而发送的匹配词汇会随该请求一同处理,并按设计不在请求结束后存储。当您明确请求 AI 对话输出时,应用会发送本地历史记录中的说话者原始发言及您的可选要求,以生成所请求的结果。

如果您在双语或同语种会话中启用回复建议,应用只会在对方完成一段内容足够充实的发言后才请求建议。在双语会话中,路由可以复用当前翻译响应;在同语种会话中,则会发送单独的路由请求而不请求翻译。建议请求可能包含对方刚完成的发言、最多四段近期原始发言、您有限范围的上下文备注,以及最多八组匹配词汇对。简单问候、应答和基本个人问题会被过滤。

当最新的公开信息有助于改进回复时,进入研究路径的建议可选择允许 OpenAI 使用网页搜索。如果使用搜索,来源链接会在应用中单独显示;它们不会插入建议回复,也不会由 TCVoiceAI 存储。

Translation, suggested-reply, and v1 plain-summary requests are designed not to retain raw audio, transcript text, translation text, prompt context, generated reply text, or generated summary content after the response is returned. OpenAI requests use storage disabled (store: false). We retain usage metadata such as word counts, token counts, model identifiers, and request IDs.

When the default-disabled structured Outcome recovery API is enabled, the full source transcript and optional prompt are not written as standalone records in the TCVoiceAI application database. The generated Outcome response is stored as application-encrypted replay ciphertext for up to 24 hours by default so the app can recover a lost response. That generated response can include evidence excerpts of up to 500 Unicode characters for each cited transcript turn. The ciphertext is deleted early when the app acknowledges durable local saving, or by scheduled expiry after its replay period. A content-free status tombstone may be retained for 30 days by default for idempotency and reliability handling.

The connector broker is disabled by default. When you enable a supported integration and approve a publication, TCVoiceAI sends only that approved work-result payload to the destination provider you selected. A retryable payload is application-encrypted for up to seven days by default and is removed immediately after confirmed delivery, terminal failure, cancellation, or expiry. Content-free publication receipts may remain for 30 days by default. If delivery races connection revocation, the receipt is marked delivery ambiguous rather than claiming that the remote item was cancelled.

后台辅助程序隐私说明: 当主应用处于空闲状态或已关闭时,辅助程序可以在您选择的物理设备与虚拟设备之间转发音频缓冲区,让普通通话继续进行,而无需反复更改音频设置。它仅为路由而处理这些缓冲区,不会执行语音识别、转写、翻译、文本转语音、录音、存储、内容检查或分析、上传,也不会与服务器通信。该辅助程序不会用于监听或收集您的对话。

会话配置、各配置的历史记录、导出的文字记录文件和设置文件均由您设备上的应用管理,不会存储在 TCVoiceAI 服务器数据库中。

导出文件包含配置中的语言、模式、上下文备注、词汇、当前配置、界面语言,以及兼容的历史记录、悬浮字幕和回复建议偏好设置。

导出文件不包含登录令牌、密码、音频设备选择、诊断授权、对话历史记录、摘要,以及其他敏感或设备专属数据。

请妥善保管导出的设置文件,因为配置名称、上下文备注和自定义词汇可能包含个人或机密信息。

悬浮字幕会复用 Mac 上近期的本地历史记录和当前建议回复。显示悬浮层不会创建新的音频采集、识别任务、翻译请求或服务器端转写文本。在系统支持时,应用会请求 macOS 从常规窗口捕获中排除该悬浮层;但在共享或录制包含敏感对话文字的整个显示器之前,您仍应将其隐藏。

4. 我们为何处理数据

We process account, authentication, entitlement, translation, suggested reply, summary, optional connector, quota, billing, and checkout data to perform our contract with you and provide the service you request. Connector authorization and every connector publication additionally require an explicit in-app action. We process security, abuse-prevention, logging, diagnostic, and support data for our legitimate interests in keeping the service reliable and safe. We process invoice, tax, accounting, and payment records where needed to comply with legal obligations. Optional Google Analytics processing is based on your consent. You may refuse it without losing website features and withdraw it at any time through Cookie settings in the footer.

5. 服务提供商与跨境传输

我们使用服务提供商来完成身份验证、付款、托管和基础设施、电子邮件发送、语音与 AI 处理、支持、日志记录、可靠性保障、分析及防止滥用。目前的核心提供商包括:用于登录的 Google,以及仅在启用并获得同意后使用的 Google Analytics;用于结账、订阅、税务和付款处理的 Paddle;用于翻译、回复建议和 AI 摘要的 OpenAI;macOS 应用使用的 Apple 平台服务;以及在配置后用于服务邮件的 Resend。

Google 在以下文件中说明其处理信息的方式: Google 隐私权政策. 您的分析选择决定我们的公开页面是否加载 Google Analytics 代码;它不会改变您选择登录时所请求的独立 Google 登录处理。

这些提供商可能会在您所在国家以外处理数据。在有要求时,我们会依赖适当的保障措施,例如提供商数据处理条款、标准合同条款、充分性认定或其他合法传输机制。

Optional connector providers are not contacted until you choose a supported integration. Their own privacy terms apply to the account credentials, destination identifiers, and approved work-result content that you direct TCVoiceAI to send to them. The app must show the provider and destination before each publication; TCVoiceAI does not publish an entire transcript through this interface.

6. Cookie 与会话

本网站使用必要 Cookie 和类似存储来保持登录状态、防范跨站请求伪造、记住您的 Cookie 选择、支持推荐链接,以及运行结账和账单流程。这些 Cookie 是实现所请求的网站功能及保障安全所必需的。

启用 Google Analytics 后,在您选择“允许分析”之前,不会请求加载其代码,也不会向 Google 发送任何分析数据。如果您同意,Google Analytics 可能会设置 _ga 及相关第一方 Cookie,以便我们了解访问情况并改进公开网站。我们的集成仍会禁用广告存储、广告个性化和 Google Signals。

您的 Cookie 选择最多保留六个月,分析 Cookie 也配置为相同的最长期限,且不会在每次访问时延长。您可以选择“仅必要 Cookie”,也可以稍后通过页脚中的 Cookie 设置撤回同意。撤回后,相关代码将不再于后续页面浏览时加载,并会尝试移除本网站的 Google Analytics Cookie。您也可以在浏览器中控制 Cookie,但禁用必要 Cookie 可能会导致登录、结账、账单或支持流程无法正常工作。

7. 数据保留与安全

We retain account, billing, entitlement, usage metadata, support, contact, referral, diagnostic, and administrative records for as long as needed to provide the service, comply with tax/accounting and payment obligations, resolve disputes, enforce terms, maintain security, and prevent abuse. Translation, suggested-reply, and v1 plain-summary content is designed not to be retained after the response is returned. If structured Outcome recovery is enabled, the generated Outcome, including bounded evidence excerpts for cited turns, has temporary encrypted replay retention for up to 24 hours by default; an acknowledgement deletes it early, while a content-free status tombstone may remain for 30 days by default. Connector retry payloads are encrypted for up to seven days by default and connector receipts for 30 days. On disconnect, local publishing stops immediately; encrypted credentials may be retained for up to 24 hours by default solely for bounded remote-revocation retries, then are deleted. A content-free provider/status/error audit may be retained with an account-deletion record when remote revocation could not be confirmed before deletion.

我们采取合理的技术和组织保障措施,包括身份验证、基于角色的管理员访问、CSRF 防护、请求限流、使用限制、诊断信息过滤及提供商安全控制。任何互联网服务都无法保证绝对安全。

8. 您的隐私权

根据您的居住地,您可能有权请求访问、更正、删除、限制或转移数据,反对特定处理、撤回同意,或要求审查自动化决策。欧盟、欧洲经济区及英国用户可在以下页面了解更多信息: GDPR 权利页面.

出于账单、税务、防欺诈、安全、法律主张或合规要求,某些数据可能需要保留或不予删除。在处理请求前,我们可能需要验证您的身份。

9. 儿童与敏感用途

TCVoiceAI 不面向儿童,付费账户仅应由依法能够创建账户并订阅软件服务的人士使用。除非您已确认本服务适合该用途,并拥有所有必要的权利和同意,否则请勿使用本服务处理特殊类别、高度敏感或受监管的信息。

10. 变更

我们可能会随产品、服务提供商或法律要求的变化更新本政策。如有重大变更,我们将尽合理努力通过网站、应用、电子邮件或账户通知告知用户。