栖记 Terria 隐私政策

最后更新日期:2026 年 10 月 1 日

栖记(Terria)是一款面向爬宠饲养者的本地数据优先 iOS 应用。本政策说明当前版本如何处理你在应用中创建的记录、照片、权限和导出文件。

我们不要求注册或登录,也不运营用于集中保存你的宠物资料和照料记录的自建服务器。个人 iCloud 同步由你主动开启,默认关闭。


1. 适用范围

本政策适用于栖记 iOS 应用及其当前公开版本提供的相关功能,包括宠物档案、照料记录、环境读数、医疗与检疫记录、繁育资料、耗材、提醒、报告和备份。

本政策不适用于 Apple、GitHub、邮件、云盘或其他由你主动选择的外部服务。你将文件发送给这些服务后,应同时查看相应服务自己的隐私政策和服务条款。


2. 你在应用中创建的信息

根据你使用的功能,你可以主动录入或添加以下内容:

  • 宠物名称、物种、品系、来源、状态和照片;
  • 喂食、称重、蜕皮、排泄、换水、清洁等照料记录;
  • 箱体、温度、湿度、环境维护和其他环境读数;
  • 就诊、用药、检疫、繁育、窝蛋和出壳等专业记录;
  • 食品、药品、垫材、设备、数量、价格和消耗流水;
  • 提醒时间、单位、外观、通知开关和其他应用偏好。

这些信息用于在设备上展示、搜索、统计、生成提醒、生成报告、创建备份以及完成你主动发起的编辑或删除操作。


3. 本地存储与使用方式

当前版本的宠物档案、照料记录、环境数据、专业记录、耗材、照片和应用设置默认保存在你的设备本地应用空间中。若你在“设置 → 数据管理 → iCloud 同步”中主动开启个人同步,档案、记录与宠物当前头像缩略图会保存到当前 Apple 账户的 iCloud 私有数据库,以便在你的设备间同步;个人同步不会上传记录附件与照片原图。

当前公开版本不提供共同照料空间。

应用会在本地使用这些信息来维护数据关系、生成趋势和统计、安排本地通知,以及生成 CSV、PDF、JSON 或 ZIP 文件。栖记不会把这些内容上传到栖记运营的服务器。

当前版本不使用你的记录建立广告画像、出售记录或建立跨应用用户画像。


4. 照片、相机与系统权限

相机

只有当你主动选择拍照或打开应用内的扫一扫时,应用才会使用相机,用于给宠物档案或照料记录添加照片,或识别宠物二维码。应用不会在后台持续使用相机。

照片

只有当你主动选择照片时,应用才会访问你选中的内容。选中的照片会按记录需要保存在本机应用空间中,不会上传到栖记服务器。使用应用内相机拍照后,应用会请求系统照片权限,并尝试在系统“照片”App 的“栖记”或“Terria”相簿中另存一份;拒绝该权限不影响将照片添加到应用内记录。当前个人 iCloud 同步仅同步宠物当前头像的轻量缩略图,不再上传记录附件或照片原图;独立的照片同步开关已移除。若旧版本曾上传附件,升级后的同步会尝试清理这些旧云端文件;在同步完成前,旧副本可能仍留在你的 iCloud 私有空间。

宠物二维码

相机扫码和你选取的二维码图片均在设备上识别,不会上传用于识别。二维码仅包含格式标识和宠物档案的唯一标识,不包含档案内容,也不授予其他设备访问权限;应用仅查找本机已有的对应档案。你主动导出的二维码标签图片或 PDF 可包含所选的宠物名称、物种和饲养箱名称,并通过系统分享菜单按你的选择保存或发送。

通知

通知权限用于在设备上安排照料、给药或复诊等本地提醒。当前版本不依赖栖记的远程推送服务器。

当前版本不会主动请求通讯录、位置、健康数据或麦克风权限。你可以随时在 iOS“设置”中管理已授予的权限。


5. 备份、导出与分享

当你主动创建完整备份时,应用会在设备上生成 ZIP 文件。备份可能包含宠物档案、照料和专业记录、照片以及用于恢复数据的清单。

在提供“设置 → 数据管理 → 导出诊断信息”功能的版本中,应用会在本机记录预定义的记录详情、编辑、照片导入及应用前后台事件,普通日志最多保留最近 500 条。为帮助排查编辑页意外关闭,还会独立保留最多 5 段疑似异常退出事件片段;这些片段只是排查线索,不代表已确认发生崩溃。事件可包含时间、记录类型、页面来源、随机页面/编辑会话/进程标识、App 与 iOS 版本,以及照片导入的数量、字节数、格式、像素尺寸、耗时和限定的错误代码等技术信息。诊断信息不包含宠物名称、记录正文、照片内容、文件名、路径或业务记录 ID,也不是系统控制台日志或崩溃堆栈。你主动导出的 JSON 还会包含导出时间、设备类别、物理内存大小和错误代码汇总。栖记不会自动上传诊断信息;只有你主动保存或分享该文件时,它才会进入你选择的系统文件位置或分享目标。

CSV 明细、PDF 报告、JSON 或 ZIP 备份会先在本机生成。只有当你通过系统文件选择器保存文件,或通过系统分享面板选择邮件、云盘、隔空投送、文件 App 等目标时,文件才会按照你的选择离开应用。

一旦文件被发送到外部服务,栖记无法控制该服务如何保存或处理文件。分享前请确认文件内容和接收方,并妥善保管导出的备份。


6. 保存、删除与保留

当前版本没有栖记服务器上的用户档案,因此没有需要由开发者替你从服务器删除的账号数据。

  • 你可以在应用内删除宠物、记录、照片或其他本机内容;
  • 删除应用内记录或应用本身,不会删除此前已另存到系统“照片”App 的照片;如需移除这份副本,请在系统“照片”App 中自行删除;
  • 删除应用会移除其应用空间中的本地数据,但不会自动保证删除此前已同步到 iCloud 私有数据库或已导出到其他位置的副本;
  • 若你曾通过测试版创建共同照料空间,当前版本暂停共享入口并不会自动撤销旧共享区域或收回其他成员此前保存的副本;
  • 你之前导出的 ZIP、JSON、CSV 或 PDF 文件可能仍存在于文件 App、云盘或其他分享目标中,需要你自行删除;
  • 恢复备份前,应用会按现有流程创建安全回退副本,回退副本也属于本机数据。

本机数据的最终保留时间取决于你的编辑、删除、备份和设备管理操作。


7. 第三方服务、广告与跟踪

截至本政策生效日期,当前版本:

  • 没有接入广告 SDK、行为分析 SDK 或崩溃上报 SDK;
  • 没有栖记账号服务或栖记自建用户数据服务器;可选的个人同步使用 Apple 提供的 CloudKit 私有数据库;
  • 不使用广告标识符,不请求跨 App 跟踪权限;
  • 不把宠物档案、照料记录或照片发送给第三方用于分析或广告。

应用使用 Apple 提供的系统能力,例如 iCloud、照片选择器、相机、通知和系统分享面板。个人同步由你主动开启;你选择的文件分享目标会影响谁能够访问导出内容。

在提供自动检查更新的版本中,这项功能默认开启,你可以在设置中关闭。开启时,应用进入前台会在距上次成功检查至少 6 小时后,向 Apple 的公开应用信息接口查询栖记的 App Store 版本。一次检查失败时最多再重试两次;失败不会更新成功检查时间,因此后续进入前台可能再次发起检查。请求只指定应用的公开 App Store ID,不包含宠物档案、照料记录、照片或诊断信息;Apple 可能按其自身政策处理提供网络服务所需的技术信息,例如 IP 地址。检查失败时应用会继续正常运行,也不会将查询结果发送给栖记服务器。

使用周报海报功能时,你可以主动下载所需字体。应用从 jsDelivr 下载字体,失败时可尝试 GitHub 的原始文件服务;请求不包含宠物档案、照料记录或照片。这些服务提供方可能按其自身政策处理传输所需的技术信息,例如 IP 地址。下载的字体缓存在应用本机空间,仅供应用使用,不安装为系统字体;你可以在周报海报页面删除已下载字体。


8. 本隐私政策网页

本页面是一个公开的静态网页,托管在 GitHub Pages。页面本身不设置栖记账号、不使用自定义 Cookie、不嵌入广告或行为分析脚本。

GitHub 作为网页托管和网络服务提供方,可能按照其自身政策接收处理网页请求所需的常规技术信息,例如 IP 地址、浏览器类型和请求时间。相关处理不由栖记控制,请同时参阅 GitHub 的隐私政策。


9. 你的选择

你可以通过栖记和 iOS 提供的功能:

  • 查看、修改或删除本机宠物和照料记录;
  • 开启或关闭相机、照片和通知权限;
  • 创建、导出、恢复或自行删除备份文件;
  • 在支持该功能的版本中,主动导出本机诊断信息,并决定是否保存或分享;
  • 开启或关闭个人 iCloud 同步;
  • 通过系统分享面板决定是否以及向谁发送导出文件;
  • 删除应用及其本机数据。

由于栖记当前没有独立账号和开发者服务器,开发者无法远程访问、修改或删除仅保存在你设备、个人云盘或你自行选择的外部服务中的数据。


10. 政策更新

如果应用的数据处理方式、联网能力、第三方服务或权限用途发生变化,我们会更新本页面的内容和生效日期,并在适用时同步更新 App Store Connect 中的 App 隐私信息。

建议你在升级应用后重新查看本页面。页面顶部的日期表示当前公开版本适用的政策版本。


11. 联系开发者

如果你对本政策或栖记的隐私处理有疑问,可以通过 GitHub Issues 联系开发者。

请不要在公开 Issue 中提交宠物照片、备份文件、姓名、邮箱或其他个人信息。与本机数据相关的删除操作可以直接在应用内完成。

Terria Privacy Policy

Last updated: October 1, 2026

Terria is a local-first iOS app for reptile keepers. This policy explains how the current version handles records, photos, permissions, and exported files created while you use the app.

Terria does not require an account or sign-in and does not operate its own server for centrally storing pet profiles or care records. Personal iCloud Sync is opt-in and off by default.


1. Scope

This policy applies to the Terria iOS app and its current public features, including pet profiles, care records, environment readings, medical and quarantine records, breeding information, supplies, reminders, reports, and backups.

This policy does not apply to Apple, GitHub, email, cloud storage, or another external service that you choose to use. When you send a file to one of those services, please review that service’s own privacy policy and terms.


2. Information You Create in the App

Depending on the features you use, you may choose to enter or add:

  • pet names, species, morphs, sources, statuses, and photos;
  • feeding, weighing, shedding, waste, water-change, and cleaning records;
  • enclosures, temperature, humidity, maintenance, and other environment readings;
  • veterinary, medication, quarantine, breeding, clutch, and hatchling records;
  • food, medication, substrate, equipment, quantities, prices, and inventory activity;
  • reminder times, units, appearance, notification settings, and other preferences.

Terria uses this information on your device to display, search, summarize, and maintain records; schedule local reminders; generate reports; create backups; and complete edits or deletions that you request.


3. Local Storage and Use

In the current version, pet profiles, care records, environment data, professional records, supplies, photos, and app settings are stored in the app’s local storage by default. If you enable personal sync under Settings → Data Management → iCloud Sync, profiles, records, and current pet-avatar thumbnails are also stored in the private iCloud database of the current Apple Account for synchronization across your devices. Personal sync does not upload record attachments or original photos.

Shared Care spaces are not available in the current public release.

The app uses this information locally to maintain relationships between records, calculate trends and summaries, schedule local notifications, and generate CSV, PDF, JSON, or ZIP files. Terria does not upload this content to a server operated by Terria.

The current version does not use your records to build advertising profiles, sell your records, or create a cross-app user profile.


4. Photos, Camera, and System Permissions

Camera

The app uses the camera only when you choose to take a photo for a pet profile or care record, or open the in-app scanner to read a pet QR code. It does not continuously use the camera in the background.

Photos

The app accesses existing photos only when you choose them. Selected photos are stored in the app's local space as needed for your records and are not uploaded to a Terria server. After you take a photo with the in-app camera, Terria requests access to your photo library and attempts to save a separate copy in a “栖记” or “Terria” album in Apple's Photos app. Declining that permission does not prevent you from adding the photo to an in-app record. Current personal iCloud Sync includes only lightweight thumbnails of current pet avatars; it no longer uploads record attachments or original photos. The separate photo-sync switch has been removed. If an older version uploaded attachments, the app attempts to remove those older cloud files when it next syncs; copies may remain in your private iCloud space until that sync completes.

Pet QR Codes

Camera scans and QR images you select are decoded on your device, without uploading them for recognition. A QR code contains only a format identifier and a unique pet-profile identifier, not profile contents or permission to access data on another device. The app looks up the corresponding profile only among those already on the current device. QR label images or PDFs you export may include the pet name, species, and enclosure name you choose to display. They are saved or sent through the system share sheet at your direction.

Notifications

Notification permission is used to schedule local care, medication, or appointment reminders on your device. The current version does not rely on a Terria remote push server.

The current version does not actively request access to contacts, location, health data, or the microphone. You can manage granted permissions at any time in iOS Settings.


5. Backups, Exports, and Sharing

When you actively create a complete backup, the app generates a ZIP file on your device. It may contain pet profiles, care and professional records, photos, and the manifest needed to restore the data.

In versions that offer Settings → Data Management → Export Diagnostics, the app records predefined events from record details, editing, photo imports, and app foreground or background transitions on your device. The regular log retains up to 500 recent events. Up to five separate event excerpts may also be kept to help investigate a suspected unexpected exit from an edit page; these are diagnostic clues, not confirmation of a crash. Events may include timestamps, record type, page origin, random page, edit-session and process identifiers, app and iOS versions, and technical photo-import details such as count, byte size, format, pixel dimensions, duration, and limited error codes. Diagnostics do not contain pet names, record text, photo contents, file names, paths, or business record IDs; they are not system console logs or crash stacks. A JSON file you choose to export also includes the export time, device category, physical memory size, and an error-code summary. Terria does not upload diagnostics automatically. The file goes to a system file location or sharing destination only when you choose to save or share it.

CSV details, PDF reports, JSON files, and ZIP backups are generated locally first. A file leaves the app only when you save it through the system file picker or choose a destination such as Mail, cloud storage, AirDrop, or Files through the system share sheet.

After a file is sent to an external service, Terria cannot control how that service stores or handles it. Please review the file and recipient before sharing and keep exported backups secure.


6. Retention and Deletion

The current version has no user profiles stored on Terria servers, so there is no server account data for the developer to delete on your behalf.

  • You can delete pets, records, photos, and other local content in the app;
  • Deleting an in-app record or uninstalling Terria does not remove a photo already saved in Apple's Photos app; delete that separate copy in Photos if you no longer want it;
  • Deleting the app removes data in its local app space, but does not guarantee deletion of copies previously synced to the private iCloud database or exported elsewhere;
  • If you created a Shared Care space in a test build, the current release's paused sharing controls do not automatically revoke that older shared zone or retrieve copies previously saved by other members;
  • Previously exported ZIP, JSON, CSV, or PDF files may remain in Files, cloud storage, or another sharing destination and must be deleted by you;
  • Before a restore, the app creates a safety rollback copy under its existing workflow; that copy is also local device data.

How long local data remains depends on how you edit, delete, back up, and manage the app on your device.


7. Third-Party Services, Advertising, and Tracking

As of the effective date of this policy, the current version:

  • does not include advertising, behavioral analytics, or crash-reporting SDKs;
  • does not include a Terria account service or Terria-operated user-data server; optional personal sync uses Apple’s private CloudKit database;
  • does not use an advertising identifier or request cross-app tracking permission;
  • does not send pet profiles, care records, or photos to a third party for analytics or advertising.

The app uses Apple system capabilities such as iCloud, the photo picker, camera, notifications, and the system sharing interface. Personal sync is opt-in. The file-sharing destinations you choose affect who can access exported content.

In versions that offer automatic update checks, this feature is on by default and can be turned off in Settings. While it is on, entering the foreground triggers a query to Apple’s public app-information service for Terria’s App Store version when at least six hours have passed since the last successful check. A failed check can be retried up to twice. Failure does not update the time of the last successful check, so a later foreground session may trigger another check. The request specifies only the app’s public App Store ID; it does not include pet profiles, care records, photos, or diagnostic information. Apple may process technical information needed to provide the network service, such as an IP address, under its own policy. A failed check does not interrupt the app, and the lookup result is not sent to a Terria server.

When using weekly posters, you can choose to download the required font. The app downloads it from jsDelivr and may try GitHub’s raw-file service if that fails. These requests do not include pet profiles, care records, or photos. The providers may process technical information needed for the transfer, such as an IP address, under their own policies. Downloaded fonts are cached in the app’s local storage for use within the app, not installed as system fonts. You can delete a downloaded font from the weekly poster screen.


8. This Privacy Policy Website

This page is a public static website hosted on GitHub Pages. It does not set a Terria account, use custom cookies, embed advertising, or include behavioral analytics scripts.

As the hosting and network provider, GitHub may receive ordinary technical information needed to serve a web request, such as an IP address, browser type, and request time. That processing is governed by GitHub’s own policies and is not controlled by Terria.


9. Your Choices

Using Terria and iOS features, you can:

  • view, edit, or delete local pet and care records;
  • turn camera, photo, and notification permissions on or off;
  • create, export, restore, or delete backup files yourself;
  • in versions that support it, export local diagnostics and choose whether to save or share the file;
  • enable or disable personal iCloud Sync;
  • decide whether and to whom an exported file is sent through the system share sheet;
  • delete the app and its local data.

Because Terria currently has no independent account system or developer-operated data server, the developer cannot remotely access, change, or delete data stored only on your device, in your personal cloud storage, or with an external service you choose.


10. Changes to This Policy

If the app’s data practices, network capabilities, third-party services, or permission purposes change, we will update this page and its effective date, and update App Store Connect privacy information when applicable.

We recommend reviewing this page after updating the app. The date at the top identifies the policy version for the current public release.


11. Contact

If you have questions about this policy or Terria’s privacy practices, contact the developer through GitHub Issues.

Please do not post pet photos, backup files, names, email addresses, or other personal information in a public issue. Local data can be deleted directly in the app.