隐私政策
1. 产品形态与适用范围
沉淀记 Loamery 是一个本地优先的浏览器扩展,用于从受支持的 AI 对话服务中保存用户选择的回答、原文和项目上下文,并把这些内容整理为可继续推进的 Project State、Project Memory、Evidence 与 Next Action。v0.7 提供可选的 Loamery 账号与 Cloud Sync;本地保存与 BYOK 能力不依赖账号。
2. 本地处理和保存的数据
- 用户在受支持 AI 对话服务中主动选择的问题和回答文本;
- AI 生成的标题、核心观点和支持要点;
- 用户主动划选并收藏的原文;
- 项目、子项目、卡片关系、编辑历史和来源标识;
- Project State、Project Memory、Evidence、Next Action、版本与人工确认记录;
- 主题、字号、展开状态等界面设置;
- 用户自行填写的 DeepSeek、Gemini 或 OpenRouter API Key。
这些内容默认保存在浏览器扩展本地存储中,不会因为安装、升级、普通浏览或仅仅登录 Loamery 而自动上传。只有用户主动启用 Cloud Sync、创建 Public Share 或执行其他明确的云端操作时,相关功能需要的数据才会传输。
3. Loamery 账号与身份验证
本地保存和 BYOK 不要求 Loamery 账号。用户只有在使用 Cloud Sync 或其他明确标记为账号功能的能力时才需要登录。当前登录使用电子邮箱一次性验证码。身份验证服务可能处理电子邮箱、内部用户标识、认证状态、访问令牌、刷新令牌及必要的会话元数据。当前登录流程不要求用户设置固定密码。
4. Cloud Sync
Cloud Sync 是可选功能。只有用户明确启用或执行同步后,同步范围内的项目、卡片、原文摘录、Project State、Project Memory 及相关版本/组织数据才会发送到 Loamery 云端服务。同步契约明确排除 API Key、访问令牌、刷新令牌、Public Share 管理凭据和其他 secret 字段。登录本身不等同于上传全部本地内容。
5. BYOK AI 与 API Key
当用户选择 BYOK 并主动执行需要 AI 的操作时,完成该操作所需的问题、回答、提示词和相关上下文会直接从浏览器发送到用户选择的 DeepSeek、Gemini 或 OpenRouter。BYOK 请求不经过 Loamery 托管 AI 服务。
- 用户提供的 API Key 仅保存在当前浏览器扩展的受保护本地存储中;
- JSON 备份明确排除 API Key;
- API Key 只作为 BYOK 请求凭证发送给用户选择的 Provider,不上传到 Cloud Sync、商业事件或 Public Share;
- 卸载扩展或清除扩展数据可能删除本地保存的 API Key。
6. v0.7 AI 功能与 BYOK
v0.7 暂不开放 Managed AI / Trial 用户通道。需要 AI 的操作只使用用户自行配置的 DeepSeek、Gemini 或 OpenRouter API Key;如果用户没有配置 API Key,Loamery 会提示用户先完成 BYOK 设置,而不会自动切换到托管 AI 或消耗任何 Trial 额度。
BYOK 请求直接从浏览器发送到用户选择的 Provider。用户提供的 API Key 不会进入 Cloud Sync、商业事件、Public Share 或 JSON 备份。
7. 第一方产品事件
为确认账号、云同步、知识库和项目连续性是否正常工作,并诊断认证、同步和冲突错误,Loamery 可能记录与账号关联的结构化第一方事件,例如登录成功、开启云同步、首次同步成功、识别第二台设备、跨设备同步成功、打开项目工作台、看到连续性价值、开启新任务、创建分享以及后续日期回访。错误只记录粗粒度分类。事件不会记录 Prompt、Answer、卡片或摘录正文、项目名称、Project State、Project Memory、搜索词、API Key、Token、Secret、浏览历史或页面正文,也不使用第三方分析 SDK。
8. 页面与来源链接访问
Loamery 的内容脚本只运行在 Manifest 声明的受支持 AI 对话服务页面(chatgpt.com、chat.openai.com、claude.ai、gemini.google.com、chat.deepseek.com、www.doubao.com、kimi.com 和 www.kimi.com),用于识别用户问题和 AI 回答、显示沉淀入口、保存用户主动划选的原文,以及保存来源 URL 以便来源标记和用户要求时重新定位原回答。Loamery 不会因为用户访问无关网站而读取其页面内容。
9. 导出、删除、公开分享和保留
用户可以导出和导入 JSON 备份,删除卡片或原文,将内容移入回收站,从回收站恢复或永久删除,在设置中清空本地数据,或通过浏览器卸载扩展。删除内容可能在回收站中保留最多 30 天,用户也可以提前永久删除。
已登录用户可以在 Loamery 账户界面自助删除云端同步副本、设备记录、账户资料和第一方使用事件;这个操作不会删除当前设备的本地知识库,也不会删除认证账号。其他账号或隐私请求可联系 [email protected]。
当用户主动创建 Public Share 时,Loamery 只发送用户在分享界面明确选择的沉淀内容、AI 原回答和允许公开的来源字段到 https://share.loamery.com/。分享记录可设置有效期,也可由创建者使用仅保存在本机的撤销凭据主动撤销。API Key、内部卡片 ID、完整设置和撤销凭据不会作为公开快照的一部分发送给被分享者。
10. 第三方服务与 Public Share
Loamery 不向广告商、数据经纪商或第三方分析服务出售、出租或共享用户数据。BYOK 数据按用户选择直接发送给对应 AI Provider;账号和 Cloud Sync 使用 Loamery 的云端基础设施;Public Share 使用 share.loamery.com。
Public Share 是单独的数据流:只有用户主动点击生成或更新分享时,用户选定的公开快照会发送至 share.loamery.com 并保存到分享有效期结束、用户撤销或服务端清理为止。任何拿到公开链接的人都可能查看该快照,因此用户应在生成链接前确认其中不含不希望公开的信息。
v0.7 不提供用户侧付费入口,也不会要求用户输入支付信息。若未来启用真实付费,Loamery 会在功能启用前更新适用的隐私政策和商店披露。
11. 安全
Loamery 使用浏览器扩展本地存储、HTTPS、服务端 secret 与受限的认证/同步接口保护不同数据路径。API Key 不进入云同步 payload;Managed Provider Key 不进入客户端;商业事件避免记录项目正文。任何本地存储、云服务或第三方网络服务都无法保证绝对安全,用户应妥善保护设备、邮箱账号和自己的 API Key。
12. 商店数据使用与 Limited Use
Loamery 对通过浏览器扩展权限获得的信息的使用与传输,将遵守适用的商店数据使用与 Limited Use 要求,包括 Chrome Web Store User Data Policy;如果提交 Microsoft Edge Add-ons,则同时以 Microsoft Edge Partner Center 的数据使用披露和官方政策为准。Loamery 仅将用户数据用于提供或改进其公开说明的单一用途及相关用户功能,不会将这些数据用于个性化广告、数据经纪、信用评估或其他无关用途。
运营主体不会人工读取用户保存在本地的 AI 对话内容或知识卡片。只有在用户主动向支持渠道提供特定内容、法律要求或安全处理所必需的情况下,才可能处理用户明确提供的数据。
13. 政策更新
如果后续增加新的网页 Host、权限、Provider、Live Payment、广告/分析 SDK、团队功能或新的数据处理方式,本政策会在相关功能启用前更新,并在需要时提供产品内说明与用户选择。
14. 联系方式
运营主体:ChihooZeng
联系邮箱:[email protected]
产品网站:https://loamery.com/
Privacy Policy
1. Product Model and Scope
Loamery is a local-first browser extension for saving user-selected AI answers, exact excerpts, and project context from supported AI conversation services, then organizing that material into reviewable Project State, Project Memory, evidence, and next actions. v0.7 provides an optional Loamery account and Cloud Sync; local saving and BYOK do not depend on an account.
2. Data Processed and Stored Locally
Depending on the features used, Loamery may locally process or store questions and answers selected by the user, generated knowledge-card content, exact excerpts, project and card organization, source URLs and identifiers, Project State, Project Memory, evidence, next actions, revision and human-review history, interface preferences, and a user-provided API key for DeepSeek, Gemini, or OpenRouter. This data remains local by default and is not uploaded merely because Loamery is installed, updated, browsed, or signed in.
3. Loamery Account and Authentication
Local saving and BYOK do not require a Loamery account. An account is required only for features explicitly marked as account/cloud features, including Cloud Sync. The current sign-in flow uses a one-time code sent to the user's email address. Loamery's cloud authentication service may process the email address, internal user identifier, authentication state, access token, refresh token, and necessary session metadata. The current flow does not require the user to create a persistent Loamery password.
4. Cloud Sync
Cloud Sync is optional. Only after the user explicitly enables or runs sync can sync-eligible projects, cards, excerpts, Project State, Project Memory, revisions, and organization data be sent to the Loamery cloud service. The sync contract excludes API keys, access tokens, refresh tokens, Public Share management credentials, and other secret fields. Signing in alone does not mean that all existing local content is uploaded.
5. BYOK AI and API Keys
When the user chooses BYOK and explicitly requests an AI operation, the question, answer, prompt, and relevant context required for that operation are sent directly from the browser to the selected DeepSeek, Gemini, or OpenRouter service. The user-provided API key stays in protected extension-local storage, is excluded from JSON backups, is sent only to the selected provider as the BYOK request credential, and is not included in Loamery Cloud sync, commercial events, or Public Share.
6. v0.7 AI Operations and BYOK
v0.7 does not expose a Managed AI / Trial user path. AI-powered operations use the user's own DeepSeek, Gemini, or OpenRouter API key. If no API key is configured, Loamery prompts the user to complete BYOK setup instead of automatically switching to managed AI or consuming any Trial allowance.
BYOK requests go directly from the browser to the selected provider. User-provided API keys are excluded from Cloud Sync, product events, Public Share, and JSON backups.
7. First-Party Product Events
To verify that account, Cloud Sync, Library, and Project Continuity work and to diagnose authentication, sync, and conflict errors, Loamery may record structured account-linked first-party events such as successful sign-in, Cloud Sync enabled, first sync success, second-device detection, cross-device sync success, Project Workspace opened, continuity value seen, new task started, share created, and later-day return. Errors use coarse categories only. Events do not record prompts, answers, card or excerpt bodies, project names, Project State, Project Memory, search terms, API keys, tokens, secrets, browser history, or page bodies. Loamery does not use a third-party analytics SDK.
8. Page Access and Source URLs
Loamery content scripts run only on pages for the supported AI conversation services declared in the Manifest: chatgpt.com, chat.openai.com, claude.ai, gemini.google.com, chat.deepseek.com, www.doubao.com, kimi.com, and www.kimi.com. The extension can save a source URL for attribution and to reopen or locate the original answer when requested by the user. Loamery does not read unrelated websites merely because the user visits them.
9. Export, Deletion, Public Share, and Retention
Users can export and import JSON backups, delete cards and excerpts, use Trash, clear local data, or uninstall the extension. Deleted content may remain in Trash for up to 30 days unless permanently deleted earlier.
An authenticated user can delete cloud sync copies, device records, the account profile, and first-party usage events from the Loamery account interface. This does not delete the local Library on the current device or the authentication account. Other account or privacy requests can be sent to [email protected].
When a user explicitly creates a Public Share, Loamery sends only the distilled content, original answer, and allow-listed source fields the user selected in the share composer to https://share.loamery.com/. Shares may have an expiry and can be revoked using a management credential kept locally in the creator's browser. API keys, internal card IDs, full settings, and the management credential are not part of the public snapshot.
10. Third-Party Services and Public Share
Loamery does not sell, rent, or share user data with advertisers, data brokers, or third-party analytics providers. BYOK data is sent directly to the selected AI provider; account and Cloud Sync use Loamery's cloud infrastructure; and Public Share uses share.loamery.com.
Public Share is a separate developer-operated data flow. Only when the user explicitly creates or updates a share is the user-selected public snapshot sent to share.loamery.com and stored until expiry, revocation, or service cleanup. Anyone who has the public link may be able to view that snapshot.
v0.7 does not provide a user-facing payment entry and does not ask users for payment information. If real payment is enabled in the future, Loamery will update the applicable privacy policy and store disclosures before that feature is enabled.
11. Security
Loamery uses extension-local storage, HTTPS, server-side secrets, and bounded authenticated cloud interfaces for the relevant data paths. API keys are excluded from Cloud Sync payloads; the managed provider key is not sent to clients; commercial events avoid project body content. No local, cloud, or third-party system can guarantee absolute security, and users should protect their device, email account, and API keys.
12. Store Data Use and Limited Use
Loamery's use and transfer of information obtained through browser extension permissions will comply with applicable store data-use and Limited Use requirements, including the Chrome Web Store User Data Policy; an Edge submission also follows the Microsoft Edge Partner Center data-use disclosures and official policies. Loamery uses user data only to provide or improve its disclosed single purpose and related user-facing features, and does not use such data for personalized advertising, data brokerage, credit-worthiness, or unrelated purposes.
13. Policy Updates
If Loamery later adds new webpage hosts, permissions, providers, Live Payment, advertising/analytics SDKs, team features, or materially different data practices, this policy will be updated before those changes are enabled.
14. Contact
Operator: ChihooZeng
Contact: [email protected]
Website: https://loamery.com/