实际处理情况取决于你使用的功能和主动选择。未使用对应功能时,我们不会因该功能申请相应权限。
| 场景 | 信息类型 | 用途与处理方式 |
|---|---|---|
| 注册登录 | 手机号、验证码状态、账号ID、登录状态 | 身份验证、账号安全和会话维持 |
| 个人资料 | 昵称、头像、性别、生日、简介、兴趣标签 | 资料展示、个性化与匹配推荐 |
| 公开互动 | 心情文字、内容回应、画作、答案、聊天与互动记录 | 内容展示、回应、站内交流和安全审核;提交文字经本地规则和同区 AI 审核,头像、公开图片与公开画作在展示前经同区 AI 审核,失败时不发布 |
| 情侣空间 | 绑定关系、生日、纪念日、重要日、心情、愿望、计划、习惯打卡、问题答案、每周仪式、卡片、想念记录、时光信、成长记录、已解锁与正在使用的情侣主题 | 向固定绑定双方提供私密双人功能、提醒、时间线、成就和空间外观;付费主题所有权保留在购买账号 |
| 双人生活模拟 | 故事日程、双方选择、提交与揭晓时间、虚拟户型、装修、房间、家具、植物与浇水记录、水族箱生物与照料记录、共同宠物种类、昵称与照料记录、菜谱、故事数值和完成进度 | 共同经营仅绑定双方可见的虚拟小屋;双方都提交前不向对方显示一方选择 |
| 小屋真实天气 | 双方主动设置的小屋城市、城市解析后的粗略坐标、时区、当前天气、温度、昼夜状态和更新时间 | 让虚拟小屋场景与所选城市的现实天气联动;不为此持续读取设备精确位置 |
| 共同回忆 | 照片、照片说明、评论、地点、标签、语音、语音说明、发生时间和上传者 | 双人相册、检索与自动合集、语音播放、评论互动、导出和纪念视频生成;媒体采用私密存储和账号绑定访问 |
| 共同旅行 | 旅行名称、目的地、日期、票务或订单信息、路线时间节点、地点坐标、备注、日志、主动选择的旅行照片和票据截图,以及所选旅行照片中可用的拍摄时间和位置元数据 | 为绑定双方提供旅行规划、照片与行程节点匹配、按时间展开路线地图、外部导航、日志整理、旅行回忆归档和视频生成 |
| 地图展示与导航 | 路线或目的地坐标、地图加载所需的设备与网络信息 | iOS 使用 Apple MapKit;Android 中国大陆路线默认使用高德地图、其他地区默认使用 Google Maps,也可手动切换;导航时将目的地交给所选地图应用或网页 |
| 活动与实时路线 | 活动类型、开始结束时间、定位点、里程、路线、可选目的地名称与临时坐标、到达状态和最近更新时间 | 仅在主动开始后处理;完整路线仅按明确选择在活动期间向绑定伴侣近实时展示;安全到达功能在进入范围后发送一次通知,结束时清除目的地坐标 |
| 通知与小组件 | 推送令牌、通知摘要、已读状态;双方昵称、心情、相伴天数和下一计划的本机共享副本 | 发送与回看提醒;在本机 App Group 中更新 iOS 小组件 |
| 安全与运维 | 设备、系统、App版本、IP地址、访问时间、错误日志、举报和处置记录 | 安全风控、问题排查、内容治理、统计和服务稳定性 |
| 官网首页访问统计 | 浏览器中的匿名随机 Cookie、访问日期;服务端只保存哈希值和每日访问次数 | 统计首页 PV、累计 PV 和当日 UV;不用于广告或跨站识别,按日访客哈希最多保留35天 |
系统权限
| 权限 | 触发场景 | 关闭影响 |
|---|---|---|
| 相册 | 选择头像、图片、共同回忆、旅行美照或票据截图;对主动选择的旅行照片读取可用的拍摄时间和位置元数据,不会自动扫描整本相册 | 不能从相册选择对应图片或自动整理照片行程 |
| 麦克风 | 主动录制语音回忆 | 不能新录制语音,已有内容仍可按权限播放 |
| 使用期间位置/后台位置 | 主动开始通勤、运动或其他活动;后台权限用于锁屏或切换应用时继续本次记录和明确开启的路线共享;旅行节点和已选择照片地点使用一次地址解析 | 无法记录活动,或无法为旅行地点自动生成地图坐标 |
| 日历 | 主动点击把共同事项加入 Apple 日历 | 不能从 Ormo 写入系统日历,不影响 App 内共同日历 |
| 通知 | 开启情侣互动、安全到达、回复或系统提醒 | 不再收到系统推送,站内功能仍可使用 |
你的管理方式
每次共享完整精确路线、导入旅行照片的时间或地点、上传票据截图,以及进入可能涉及性取向、亲密偏好或其他敏感观点的私密问答前,App 会说明处理内容、用途和可见范围,并由你对本次操作单独选择。拒绝不影响其他基础功能。
你可以在系统设置管理权限,在 App 内修改资料、删除自己有权删除的内容、导出可用数据、关闭情侣空间或注销账号。具体权限用途见《权限与数据使用说明》,App Store 数据类别对照见《App Privacy 数据声明说明》,举报、屏蔽和注销路径见《用户控制与账号注销》。隐私请求请联系 support@ormo.app。
This list depends on the features you use and the choices you make. Permissions are not requested for features you do not use.
Account and profile
Phone number, verification status, account ID, login state, nickname, avatar, gender, birthday, bio, and interests support authentication, security, profiles, and recommendations.
Content and Couple Space
Expression content, interactions, reports, pairing, dates, moods, wishes, plans, habits, answers, rituals, cards, nudges, time capsules, photos, comments, voice memories, unlocked Couple Themes, the active Couple Theme, and related metadata support the relevant public or private features, safety review, exports, videos, and Couple Space appearance. Submitted text is reviewed by local rules and a same-region AI provider. Avatars, public images, and public drawings are reviewed by that provider before display and are blocked when review fails; private Couple Space images do not enter the public-image review flow. Paid theme ownership remains with the purchasing account.
Shared trips and maps
Trip names, destinations, dates, ticket or booking details, itinerary stops and coordinates, notes, user-selected travel photos or ticket screenshots, and available capture-time and location metadata from selected travel photos support shared planning, stop matching, chronological route maps, navigation, route PDF export, travel memories, and video generation. iOS uses Apple MapKit. Android defaults to AMap for mainland-China routes and Google Maps elsewhere, with a manual switch. The selected map provider receives the route or destination coordinates and technical data needed to load the map.
Activities
Activity type, time, location points, distance, and routes are processed only after you actively start. Precise routes are not stored on the server for private or stats-only activities. Full routes are shown only when explicitly shared.
Permissions
Photos are used only for images you select, including travel photos and ticket screenshots. Available time and location metadata is read only from travel photos you select; Ormo does not scan your whole library. The microphone is used for voice memories; location supports activities you actively start and address lookup for itinerary or selected-photo places; notifications support alerts you enable. You may disable these permissions in iOS or Android Settings.
Device and safety
Device, OS, app version, IP, access time, error logs, reports, and enforcement records support security, moderation, troubleshooting, analytics, and stability.
Website homepage analytics
A random anonymous browser cookie and visit date support homepage PV and daily UV statistics. Only a cryptographic hash and daily counts are stored by the analytics system. The hash is retained for no more than 35 days and is not used for advertising or cross-site identification.
Your controls
Before each full precise-route share, travel-photo time or location import, ticket-image upload, or entry into private questions that may concern sexual orientation, intimate preferences, or other sensitive views, the app explains the processing, purpose, and audience and asks you to choose for that action. Declining does not affect unrelated core features.
You may manage permissions, edit your profile, delete content you control, export available data, close Couple Space, or delete your account. Contact support@ormo.app.