隐私政策

你的素材,默认只留在你的 Mac 上。

本政策说明机灵素材(Jiling Material)如何处理与保护你在 macOS 应用和本网站中的信息。我们坚持本机优先、最少处理和明确授权。

生效日期:2026 年 7 月 31 日 · 最近更新:2026 年 7 月 31 日

默认本机处理原片、索引、OCR、语音转写、人脸特征与画面分析默认保存在你的 Mac。
不跟踪、不售卖不提供广告,不建立广告画像,不出售个人数据。
共享前先确认远端 AI、地点识别和 MCP 均需由你主动开启并可随时关闭。

1. 适用范围与处理者

本政策适用于机灵素材 macOS 应用(下称“应用”)以及 search.qushenma.com(下称“网站”)。机灵素材开发者(下称“我们”)负责本政策所述处理活动。

应用无需注册账户。我们不运营接收你的素材、索引或搜索记录的开发者服务器。应用商店购买与下载由 Apple 处理;我们不会取得你的完整 Apple ID、支付卡号或支付凭证。

2. 应用处理的数据

只有在你通过系统文件选择器授权后,应用才会访问所选文件或文件夹。为提供搜索、浏览、人物聚类、整理和本机助手连接功能,应用可能在本机处理以下信息:

  • 素材及文件信息:图片、视频、音频、GIF,以及文件名、完整路径、大小、格式、时间、尺寸、时长和素材内嵌的 GPS 坐标等元数据。
  • 本机生成的派生数据:缩略图、抽帧、OCR 文字、设备端语音转写、场景标签、画面描述、语义向量、人脸框、人脸裁剪与特征向量、人物聚类,以及你为人物指定的名称。
  • 你的操作数据:素材库配置、安全作用域书签、搜索文字、收藏、评分、标签、整理规则、功能开关和其他应用设置。
  • 你自行配置的凭证:远端 AI 服务的 API Key 保存在 macOS 系统钥匙串中;MCP 随机访问令牌保存在本机应用数据中。

人脸处理用于在你的素材库中聚类和检索同一人物,不用于身份认证,也不会默认上传给我们或第三方。

3. 数据如何流动

场景发送内容接收方与条件
默认索引与搜索原片、索引和搜索内容均在本机处理不发送给开发者服务器
远端 AI 语义复核搜索文字,以及候选素材的文件名、场景标签、OCR 文字和语音摘要;不发送原片、画面、完整路径、地点或人脸特征仅在你查看接收地址与共享范围、明确同意并开启后,发送到你配置的 OpenAI 兼容服务
地点识别素材内嵌的经纬度;不发送原片、文件名或路径仅在你主动开启后发送给 Apple 地理编码服务以取得地名
MCP 本机助手连接搜索文字,以及客户端所调用工具返回的文件名、完整路径、缩略图路径、OCR、语音转写、场景标签和地点等索引内容仅在你确认共享范围并开启后,提供给连接至 127.0.0.1 且持有随机访问令牌的客户端

语音转写仅在系统支持设备端识别时运行,并强制使用设备端识别。直连版可在你主动选择后从配置的镜像或模型托管服务下载固定版本模型,也可打开夸克网盘分享页并加载你自行下载、解压的模型文件夹。下载请求只包含模型仓库、版本和文件路径;应用会校验模型完整性。模型加载和推理在本机完成,不会上传你的素材、搜索文字、索引或本地文件路径。

4. 第三方服务

当你主动开启相应功能时,Apple 地理编码服务、你自行配置的远端 AI 服务,以及你连接到 MCP 的客户端会按照各自的隐私政策处理收到的数据。MCP 客户端可能进一步把读取的内容发送给其云端模型服务。请在启用前确认接收方、数据范围和隐私政策符合你的要求。

我们不会保存上述请求的服务器副本,也无法代表第三方承诺保留期限或删除方式。已经发送给第三方的数据,应按照该服务的隐私政策向其申请访问或删除。

5. 网站与 Cloudflare

本网站是静态网站,不提供账户、评论或联系表单。网站代码不设置用于广告或跨站跟踪的 Cookie,也未集成开发者分析、广告像素或用户画像工具。首页仅在你的浏览器本地存储中保存中英文显示偏好;该偏好不会由网站代码发送给我们。

网站通过 Cloudflare 托管并使用其内容分发与安全服务。为了传输页面、防滥用和保障安全,Cloudflare 可能处理 IP 地址、浏览器与设备信息、请求时间、访问 URL 和安全事件等标准网络日志。网站还从 Cloudflare 的 cdnjs 加载动画脚本,因此相关请求也会连接 Cloudflare。此类处理受 Cloudflare 隐私政策约束。

6. 保留、删除与撤回授权

  • 本机数据:保留在你的 Mac,直至你在应用中移除素材、删除素材库或删除应用数据。移除素材或删除素材库会删除对应索引、缩略图和人脸缓存,但不会删除原片。
  • 远端 AI:关闭“语义复核”会停止后续发送;已发送数据的保留与删除由你配置的服务决定。
  • 地点识别:关闭后会停止向 Apple 发送后续素材坐标。
  • MCP:关闭后会停止客户端的后续访问。请勿分享包含随机访问令牌的完整连接地址。
  • API Key:在应用中清空 API Key 可从系统钥匙串删除。macOS 卸载应用时可能不会自动删除钥匙串项目,建议卸载前先清空。
  • 网站日志:由 Cloudflare 按其安全与保留规则处理,我们不使用这些日志进行广告跟踪。

由于我们不持有你的应用账户、素材或索引的服务器副本,无法远程访问或删除你 Mac 上的数据。你可以直接通过应用提供的控制完成删除和撤回。

7. 安全措施

应用使用 macOS App Sandbox 和安全作用域书签限制文件访问;API Key 存储于系统钥匙串;远端 AI 地址要求使用 HTTPS(本机回环地址除外);MCP 默认关闭、仅监听 127.0.0.1,并使用随机访问令牌。任何方法都无法保证绝对安全,请妥善保护 Mac 登录凭证、API Key 与 MCP 完整连接地址。

8. 未成年人

应用并非专门面向儿童设计。我们不会故意要求儿童提交个人信息,也不运营用于收集儿童数据的账户或开发者服务器。

9. 政策更新

如应用功能或数据处理方式发生实质变化,我们会更新本页面及顶部日期。需要新的数据共享时,应用会在发送前重新说明接收方与数据范围,并在适用情况下再次征得你的同意。

10. 联系我们

如对本政策、应用隐私或数据处理有疑问,请发送邮件至 yoqulin@qq.com。请勿在邮件中附上私密素材、API Key 或 MCP 访问令牌。

Privacy Policy

Effective: July 31, 2026 · Last updated: July 31, 2026

1. Scope and Controller

This policy applies to the Jiling Material macOS application (the “App”) and search.qushenma.com (the “Website”). The developer of Jiling Material (“we,” “us,” or “our”) is responsible for the processing described here.

The App does not require an account. We do not operate developer servers that receive your media, index, or search history. App Store purchases and downloads are processed by Apple; we do not receive your full Apple ID, card number, or payment credentials.

2. Data Processed by the App

The App accesses only files or folders you authorize through the system file picker. To provide search, browsing, person clustering, organization, and local assistant features, the App may process on your Mac:

  • Your selected images, videos, audio, and GIF files, together with filenames, full paths, sizes, formats, timestamps, dimensions, duration, and embedded GPS coordinates.
  • Locally generated thumbnails, extracted frames, OCR text, on-device speech transcripts, scene labels, visual captions, semantic vectors, face boxes, face crops and embeddings, person clusters, and names you assign to people.
  • Library configuration, security-scoped bookmarks, search text, favorites, ratings, tags, organization rules, feature toggles, and other settings.
  • An API key you provide for a remote AI service, stored in macOS Keychain, and a random MCP access token stored in local App data.

Face processing is used only to cluster and find the same person within your library. It is not used for authentication and is not uploaded to us or third parties by default.

3. Data Flows and Your Choices

Default local indexing and search

Your original media, index, and searches are processed locally and are not sent to a developer server.

Optional remote AI semantic reranking

Only after you review the destination and sharing scope, expressly consent, and enable the feature, the App sends your search text and candidate filenames, scene labels, OCR text, and speech summaries to the OpenAI-compatible service you configure. It does not send original media, images, full file paths, locations, or face features.

Optional place lookup

Only when you enable place lookup, embedded coordinates from your media are sent to Apple’s geocoding service to obtain a place name. Original media, filenames, and file paths are not sent. Speech transcription runs only when on-device recognition is supported and is forced to use on-device recognition.

Optional local MCP connection

Only after you confirm the sharing scope and enable MCP may a client connected to 127.0.0.1 with the random access token read search text and indexed information returned by requested tools, including filenames, full paths, thumbnail paths, OCR, transcripts, scene labels, and places. A connected client may send that content to its cloud model under its own privacy policy.

Local semantic models

In the direct edition, you may choose to download pinned model versions from a configured mirror or model host, open the Quark Drive share page, or load a model folder you downloaded and extracted yourself. Download requests contain only the model repository, revision and file path, and the App verifies model integrity before use. Model loading and inference occur locally; your media, queries, index and local file paths are not uploaded.

4. Third Parties

If you enable the relevant features, Apple’s geocoding service, the remote AI provider you configure, and MCP clients you connect process received data under their own privacy policies. We do not retain server copies of these requests and cannot control a third party’s retention or deletion practices. Requests concerning data already sent to a third party should be directed to that provider.

5. Website and Cloudflare

The Website is static and provides no accounts, comments, or contact forms. Its code does not set cookies for advertising or cross-site tracking and does not integrate developer analytics, advertising pixels, or profiling tools. The home page stores only your Chinese or English display preference in local browser storage; the Website code does not transmit that preference to us.

The Website is hosted on Cloudflare and uses Cloudflare content delivery and security services. Cloudflare may process standard connection and security logs, such as IP address, browser and device information, request time, requested URL, and security events, to deliver and protect the Website. The Website also loads animation scripts from Cloudflare’s cdnjs. This processing is governed by the Cloudflare Privacy Policy.

6. Retention, Deletion, and Withdrawal

  • Local data remains on your Mac until you remove an item, delete a library, or delete the App’s data. Removing an item or library deletes the related index, thumbnails, and face cache without deleting the original media.
  • Turning off semantic reranking, place lookup, or MCP stops future sharing for that feature. Data already sent to a third party is retained and deleted under that provider’s policy.
  • Clearing the API key in the App removes it from Keychain. Because macOS may retain Keychain items after uninstall, clear the key before uninstalling the App.
  • Cloudflare handles Website logs under its security and retention practices. We do not use those logs for advertising tracking.

Because we do not hold server copies of your App account, media, or index, we cannot remotely access or delete data on your Mac. Use the controls in the App to delete local data and withdraw optional sharing.

7. Security

The App uses macOS App Sandbox and security-scoped bookmarks to limit file access, stores API keys in Keychain, requires HTTPS for remote AI endpoints except loopback addresses, and keeps MCP off by default, bound to 127.0.0.1, and protected by a random access token. No security method is absolute; protect your Mac credentials, API keys, and full MCP connection URL.

8. Children

The App is not specifically directed to children. We do not knowingly ask children to submit personal information and do not operate accounts or developer servers intended to collect children’s data.

9. Changes to This Policy

We will update this page and the date above if App features or data practices materially change. Before any new data sharing begins, the App will explain the recipient and scope and obtain consent again where appropriate.

10. Contact

For privacy questions, contact yoqulin@qq.com. Do not include private media, API keys, or MCP access tokens in your email.