1. Scope and Controller
This policy applies to the Jiling Material macOS application (the “App”) and search.qushenma.com (the “Website”). The developer of Jiling Material (“we,” “us,” or “our”) is responsible for the processing described here.
The App does not require an account. We do not operate developer servers that receive your media, index, or search history. App Store purchases and downloads are processed by Apple; we do not receive your full Apple ID, card number, or payment credentials.
2. Data Processed by the App
The App accesses only files or folders you authorize through the system file picker. To provide search, browsing, person clustering, organization, and local assistant features, the App may process on your Mac:
- Your selected images, videos, audio, and GIF files, together with filenames, full paths, sizes, formats, timestamps, dimensions, duration, and embedded GPS coordinates.
- Locally generated thumbnails, extracted frames, OCR text, on-device speech transcripts, scene labels, visual captions, semantic vectors, face boxes, face crops and embeddings, person clusters, and names you assign to people.
- Library configuration, security-scoped bookmarks, search text, favorites, ratings, tags, organization rules, feature toggles, and other settings.
- An API key you provide for a remote AI service, stored in macOS Keychain, and a random MCP access token stored in local App data.
Face processing is used only to cluster and find the same person within your library. It is not used for authentication and is not uploaded to us or third parties by default.
3. Data Flows and Your Choices
Default local indexing and search
Your original media, index, and searches are processed locally and are not sent to a developer server.
Optional remote AI semantic reranking
Only after you review the destination and sharing scope, expressly consent, and enable the feature, the App sends your search text and candidate filenames, scene labels, OCR text, and speech summaries to the OpenAI-compatible service you configure. It does not send original media, images, full file paths, locations, or face features.
Optional place lookup
Only when you enable place lookup, embedded coordinates from your media are sent to Apple’s geocoding service to obtain a place name. Original media, filenames, and file paths are not sent. Speech transcription runs only when on-device recognition is supported and is forced to use on-device recognition.
Optional local MCP connection
Only after you confirm the sharing scope and enable MCP may a client connected to 127.0.0.1 with the random access token read search text and indexed information returned by requested tools, including filenames, full paths, thumbnail paths, OCR, transcripts, scene labels, and places. A connected client may send that content to its cloud model under its own privacy policy.
Local semantic models
In the direct edition, you may choose to download pinned model versions from a configured mirror or model host, open the Quark Drive share page, or load a model folder you downloaded and extracted yourself. Download requests contain only the model repository, revision and file path, and the App verifies model integrity before use. Model loading and inference occur locally; your media, queries, index and local file paths are not uploaded.
4. Third Parties
If you enable the relevant features, Apple’s geocoding service, the remote AI provider you configure, and MCP clients you connect process received data under their own privacy policies. We do not retain server copies of these requests and cannot control a third party’s retention or deletion practices. Requests concerning data already sent to a third party should be directed to that provider.
5. Website and Cloudflare
The Website is static and provides no accounts, comments, or contact forms. Its code does not set cookies for advertising or cross-site tracking and does not integrate developer analytics, advertising pixels, or profiling tools. The home page stores only your Chinese or English display preference in local browser storage; the Website code does not transmit that preference to us.
The Website is hosted on Cloudflare and uses Cloudflare content delivery and security services. Cloudflare may process standard connection and security logs, such as IP address, browser and device information, request time, requested URL, and security events, to deliver and protect the Website. The Website also loads animation scripts from Cloudflare’s cdnjs. This processing is governed by the Cloudflare Privacy Policy.
6. Retention, Deletion, and Withdrawal
- Local data remains on your Mac until you remove an item, delete a library, or delete the App’s data. Removing an item or library deletes the related index, thumbnails, and face cache without deleting the original media.
- Turning off semantic reranking, place lookup, or MCP stops future sharing for that feature. Data already sent to a third party is retained and deleted under that provider’s policy.
- Clearing the API key in the App removes it from Keychain. Because macOS may retain Keychain items after uninstall, clear the key before uninstalling the App.
- Cloudflare handles Website logs under its security and retention practices. We do not use those logs for advertising tracking.
Because we do not hold server copies of your App account, media, or index, we cannot remotely access or delete data on your Mac. Use the controls in the App to delete local data and withdraw optional sharing.
7. Security
The App uses macOS App Sandbox and security-scoped bookmarks to limit file access, stores API keys in Keychain, requires HTTPS for remote AI endpoints except loopback addresses, and keeps MCP off by default, bound to 127.0.0.1, and protected by a random access token. No security method is absolute; protect your Mac credentials, API keys, and full MCP connection URL.
8. Children
The App is not specifically directed to children. We do not knowingly ask children to submit personal information and do not operate accounts or developer servers intended to collect children’s data.
9. Changes to This Policy
We will update this page and the date above if App features or data practices materially change. Before any new data sharing begins, the App will explain the recipient and scope and obtain consent again where appropriate.
10. Contact
For privacy questions, contact yoqulin@qq.com. Do not include private media, API keys, or MCP access tokens in your email.