Privacy Policy
隐私政策

Zero-knowledge relay. 执简_Termly is the HarmonyOS endpoint for a computer-side Termly CLI session. A public or self-hosted relay routes encrypted terminal data without receiving the content key.

执简_Termly 是电脑端 Termly CLI 会话的 HarmonyOS 控制端。公共或自托管 relay 负责转发加密终端数据,但不会获得终端正文密钥。这种设计通常称为零知识中继:中继不持有正文密钥,但仍会处理下文列出的连接元数据。

Last updated: July 24, 2026

1. Information We Collect / 我们收集的信息

执简_Termly does not collect terminal content, code, prompts, files, or AI interactions as plaintext. A relay can process IP addresses, connection timing, session IDs, payload sizes, and client-declared metadata such as project, device, and AI-tool names to route and operate encrypted sessions.

执简_Termly 不会以明文收集终端内容、代码、提示词、文件或 AI 交互。为路由和维护加密会话,relay 可以处理 IP 地址、连接时间、会话 ID、载荷大小,以及客户端声明的项目、设备和 AI 工具名称等元数据。

2. End-to-End Encryption / 端到端加密

All terminal data is encrypted with AES-256-GCM before leaving your device. Session keys are generated with Diffie-Hellman key exchange and are never sent to the relay. The relay cannot decrypt your data.

所有终端数据在离开设备前均使用 AES-256-GCM 加密。会话密钥通过 Diffie-Hellman 密钥交换生成,不会发送给中继服务器。中继无法解密您的数据。

3. Permissions / 权限

Camera permission is used only for QR-code pairing and no camera images are stored or transmitted. Internet access is used for relay communication. Biometric access is used only when you enable the local privacy lock. Notification permission is optional and requested only after you enable it in Settings.

相机权限仅用于二维码配对,不存储或传输相机图像。网络权限用于 relay 通信;生物识别权限仅在用户启用本地隐私锁时用于系统认证。通知权限为可选项,只会在设置页主动开启后请求。

4. Data Retention / 数据保留

The app stores paired-session information locally. The relay keeps resumable session metadata and may briefly retain encrypted pending input within a sliding two-day window. You can delete local sessions in the app; relay data expires under its retention policy.

App 会在本地保存已配对会话信息。relay 会在两天滑动窗口内保留可恢复会话元数据,并可能短期保存加密的待发送输入。您可以在 App 内删除本地会话;relay 数据按保留策略自动过期。

5. Website Analytics and Third-Party Services / 网站统计与第三方服务

The 执简_Termly app does not integrate third-party analytics SDKs, tracking SDKs, or advertising SDKs. The official websites for 执简_Termly and Modow use a self-hosted, first-party Umami service at stats.termlyhos.com to understand aggregate traffic. It can process page URLs and titles, referrers and UTM parameters, browser and device categories, language, coarse country or region, performance timing, and named button events. It does not receive terminal content, code, prompts, knowledge-base files, account passwords, or relay session payloads. Website analytics uses no tracking cookies or cross-site advertising identifier and honors the browser Do Not Track setting. Nginx may retain ordinary HTTPS request metadata, including IP address and user agent, in access logs that rotate after seven days. After consent, each app process requests the house-ad configuration from https://www.termlyhos.com/ads.json at most once and stores the latest valid configuration locally. Terminal sessions use either the public relay or a compatible relay selected and operated by the user.

执简_Termly App 不集成第三方分析、追踪或广告 SDK。执简_Termly 与墨斗官网使用部署在 stats.termlyhos.com 的自托管第一方 Umami 服务了解汇总访问情况。统计范围可包括页面地址与标题、来源与 UTM 参数、浏览器和设备类别、语言、粗粒度国家或地区、性能耗时以及具名按钮事件;不会接收终端正文、代码、提示词、知识库文件、账号密码或 relay 会话载荷。网站统计不使用追踪 Cookie 或跨站广告标识,并遵循浏览器的“请勿追踪(Do Not Track)”设置。Nginx 可能在访问日志中保留 IP 地址、User-Agent 等普通 HTTPS 请求元数据,日志按七天轮转。用户同意隐私政策后,每个 App 进程最多向 https://www.termlyhos.com/ads.json 请求一次自有广告配置,并仅在本机保存最近一次有效配置;该配置请求不包含终端正文、代码、提示词、会话密钥或广告画像。终端会话可以使用公共 relay,也可以使用用户选择并维护的兼容 relay。

The public relay also sends first-party operational metrics to the same private monitoring service, including aggregate connection counts, traffic volume, errors, processing latency, process load, and coarse country/region/city/ISP labels. An incoming IP address is used once for per-IP abuse limits and an offline coarse-region lookup, then discarded from the metrics path; full IP addresses, session IDs, pairing codes, public keys, and terminal payloads are not written to the relay metrics database. Minute-level relay trends are retained for up to 90 days.

公共 relay 还会向同一私有监控服务发送第一方运维指标,包括汇总连接数、流量、错误、处理延迟、进程压力,以及粗粒度国家/省市/运营商标签。连接 IP 仅在接入时用于单 IP 滥用限制和一次离线粗粒度地区查询,随后从指标链路中丢弃;Relay 指标数据库不写入完整 IP、会话 ID、配对码、公钥或终端载荷。Relay 分钟级趋势最长保留 90 天。

6. Contact / 联系我们

For privacy questions, contact: hello@termly.dev

如有隐私问题,请联系:hello@termly.dev