Second AI Brain Privacy Policy

Effective date: September 26, 2026

Second Brain is designed to keep your personal memory and knowledge under your control. This policy explains what the app processes and when information may leave your device.

Version boundary: Version 1.0.5 is available on the App Store. The hosted-AI disclosures below apply to 1.0.5 and later. Devices still running version 1.0.4 have different AI and Gmail behavior, described under Version 1.0.4. Features and data practices depend on the version installed on your device.

Version 1.0.5 and later: data stored on your device

Memories, knowledge items, attachments, local indexes, retrieval data, preferences, and task state are stored on your device, except for any selected data you choose to synchronize through your private iCloud account. The app does not contain or ask you to supply a model-provider API key. Your complete local library is not uploaded to the developer.

Hosted AI and its precise privacy boundary

Before any hosted AI content is sent, the app asks for separate, explicit permission. If you decline or withdraw it, local features remain available and hosted AI content requests are blocked. Depending on the task you choose, the content sent can include entered text, voice transcripts, selected knowledge documents, and relevant excerpts from memories, reminders, or context sources you enabled, such as calendar events, location, photo descriptions, or health summaries. The app does not upload your entire library or Contacts address book for AI processing.

When you request an AI feature, the text needed for that operation is sent over TLS to a separately deployed Cloudflare relay operated for Second Brain, then to MiniMax's China-region API for inference. The relay necessarily processes the request and response in memory; it is not end-to-end encrypted from the phone to MiniMax and cannot honestly be described as unable to see plaintext. The relay does not save prompts, answers, or uploaded documents in its database or content logs, and does not offer a human content-review dashboard. MiniMax receives the inference content. Its API Privacy Policy governs its processing and retention; we cannot promise zero retention by MiniMax. Do not submit information that must never leave your device.

The relay checks subscription status with Apple using the original subscription transaction identifier and a random app-account token. Its quota store retains the transaction identifier as a storage key, random operation/document/request identifiers, document character counts, plan periods, and usage counters needed to enforce limits; it does not retain the app-account token. It does not forward your app-account token, subscription identifier, email address, or other account identity to MiniMax. Cloudflare and Apple may process service metadata under their own terms. The model credential is held as a Cloudflare secret and can be rotated without an app update. AI access requires an active trial or subscription; expiry does not remove your existing local data.

Email features discontinued

Version 1.0.5 and later do not offer Gmail or IMAP account connection, mailbox refresh, mail suggestions, reply drafts, or mail AI processing, and do not request new Gmail data. Previously connected accounts, credentials, and mail-derived records may remain locally on devices upgraded from an older release, but are inactive: the app cancels scheduled mail tasks and does not send that legacy content to the hosted model. Items identified as email messages by the share extension, and legacy mail-share queue items, are not processed by the mail AI feature; a failed import may remain locally. If you deliberately share plain text from another app, the app treats it as an ordinary text import. You can revoke the old app authorization in your Google Account. The developer cannot remotely access or remove old device-local records or Keychain items.

Data protection and security controls

Network connections to the hosted relay use HTTPS/TLS; credential-bearing requests do not follow redirects. Legacy mail credentials, if present after an upgrade, remain in device Keychain storage but are not used by the discontinued feature. Legacy mail records remain in the app sandbox and are not synchronized by this app's private iCloud feature.

Apple services and permissions

When you enable a related feature, the app may use Apple services and permission-controlled data such as iCloud/CloudKit, Calendar, Notifications, Location, Microphone, Speech Recognition, Camera, Contacts, Health, Weather, App Intents, widgets, and Spotlight. Permissions can be reviewed or revoked in system Settings. Health data is read-only; the app does not write Health data.

Contacts access is used only after you choose a contact action: the app looks up a named contact and phone number on your device so you can confirm a call. It does not upload the address book, the lookup result, or the selected phone number to our relay or MiniMax. Revoking Contacts access does not prevent use of local memories or knowledge.

Imported content and external websites

If you ask the app to import a link or media, it connects to that website to retrieve the content you selected. Network requests reveal ordinary connection information, such as your IP address, to the destination website. Weather alerts may be retrieved from Apple Weather and public weather sources.

Cross-device sync

If you enable iCloud synchronization, selected app data is stored in your private iCloud container and handled according to Apple's iCloud terms. Cross-device sync is optional.

Data collection by the developer

The developer does not use Second Brain data for advertising, tracking, data brokerage, or developer analytics. The app does not contain third-party advertising SDKs. Subscription identifiers and usage counters are collected to provide and protect the hosted service; model content passes transiently through the relay as described above.

Retention and deletion

You can delete memories and knowledge inside the app. You can also remove the app and its local data through iOS. Data synchronized through iCloud can be managed through your Apple account and the app's synchronization features. The relay does not retain model content; MiniMax's processing and retention are governed by its own terms. Subscription usage records remain for service operation and abuse prevention; contact us to request access or deletion where applicable.

Version 1.0.4: user-configured AI and Gmail

Version 1.0.4 does not use the developer's hosted AI relay or collect subscription identifiers and usage counters. It ships without a model provider, endpoint, or API key. If you configure an AI service, the API key is kept in the device Keychain and bounded content needed for a requested memory, knowledge, context, or planning operation is sent directly to your configured endpoint, subject to that provider's privacy terms.

If you explicitly connect Gmail in version 1.0.4, the app requests gmail.readonly and reads inbox sender and recipient fields, subject, Gmail-produced snippet, message and thread identifiers, dates, and attachment metadata; it does not download full message bodies or modify, delete, or send email. OAuth tokens are stored in the device Keychain. Mail evidence, suggestions, and reply drafts are stored in the app's local database, not its memory or knowledge libraries, and are not synchronized through the app's private iCloud feature. After in-app disclosure and consent, only the subject and bounded snippet needed for requested mail understanding are sent directly to the LLM endpoint you configured. The full body, OAuth token, sender and recipient fields, and attachments are not sent to that model. The developer does not receive Gmail content or offer human access to it.

Google user data is not sold, used for advertising, credit decisions, data brokerage, or training general-purpose AI models. You can disconnect Gmail and delete local tokens and imported mail records in version 1.0.4, revoke access in your Google Account, or remove the app and its local data. Second Brain's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Children

Second Brain is a general productivity app and is not directed specifically to children.

Contact

Privacy questions: support@prismsai.org


第二大脑隐私政策

生效日期:2026 年 9 月 26 日

第二大脑以用户掌控个人记忆和知识为设计前提。本政策说明 App 会处理哪些信息,以及信息可能在何时离开设备。

版本边界:1.0.5 已在 App Store 上架。下述托管 AI 披露适用于 1.0.5 及后续版本。仍在使用 1.0.4 的设备,其不同的 AI 与 Gmail 行为见1.0.4 版本说明。实际处理方式取决于设备安装的版本。

1.0.5 及后续版本:设备本地数据

记忆、知识、附件、本地索引、检索数据、偏好和任务状态保存在设备上;你选择通过私人 iCloud 同步的数据除外。App 不包含或要求用户提供模型服务商 API Key,也不会将完整本地资料库上传给开发者。

托管 AI 与准确的隐私边界

发送任何托管 AI 内容前,App 会单独、明确征求你的同意。拒绝或撤回后,本地功能仍可使用,托管 AI 内容请求会被阻止。视你选择的任务而定,发送内容可能包括输入文字、语音转写、选定的知识资料,以及相关记忆、提醒或你启用的情境来源片段,例如日历事项、位置、照片描述或健康汇总。App 不会为 AI 处理上传完整资料库或通讯录。

使用 AI 功能时,完成该次操作所需的文本经 TLS 发送到第二大脑独立部署的 Cloudflare 转发服务,再交由 MiniMax 中国区 API 推理。转发服务必须在内存中处理请求和响应,因此不能声称它完全看不到明文,也不是手机到 MiniMax 的端到端加密。转发服务不将提示词、回答或导入文档存入数据库或内容日志,也不提供人工查看内容的后台。MiniMax 会收到推理所需内容;其API 隐私政策约束其处理和保留,我们不能承诺 MiniMax 零保留。不得提交必须完全留在设备上的信息。

转发服务使用原始订阅交易标识及随机 App 账户令牌向 Apple 核验订阅。配额库仅保留作为存储键的交易标识、随机操作/文档/请求标识、文档字符数、套餐周期与用量计数,不保留 App 账户令牌。它不会将 App 账户令牌、订阅标识、邮箱或其他账户身份转发给 MiniMax。Cloudflare 与 Apple 可能依据各自条款处理服务元数据。模型密钥作为 Cloudflare 机密保存,可在不更新 App 的情况下轮换。AI 功能需要有效试用或订阅;到期不会删除已有本地资料。

邮箱功能已取消

1.0.5 及后续版本不提供 Gmail 或 IMAP 账户连接、邮箱刷新、邮件建议、回复草稿或邮件 AI 处理,也不再请求新的 Gmail 数据。旧版升级设备上此前连接的账户、凭据和邮件衍生记录可能仍保留在本机,但处于停用状态:App 会取消待运行的邮件后台任务,不会将这些旧内容发送至托管模型。分享扩展识别出的邮件文件以及旧邮件分享队列项目不会由邮件 AI 功能处理;失败的导入可能留在本机。如果你主动从其他 App 分享普通文本,App 会将其作为普通文本导入。你可以在 Google 账户中撤销旧版授权。开发者无法远程读取或删除设备上的旧记录或 Keychain 项目。

数据保护与安全控制

与托管转发服务的连接使用 HTTPS/TLS;携带凭据的请求不会跟随重定向。升级后如仍存在旧邮件凭据,它们保存在设备 Keychain 中,但取消的邮件功能不再使用。旧邮件记录留在 App 沙盒内,也不会由本 App 的私人 iCloud 功能同步。

Apple 服务与系统权限

当你启用相关功能时,App 可能使用 iCloud/CloudKit、日历、通知、位置、麦克风、语音识别、相机、联系人、健康、天气、App Intents、Widget 和 Spotlight。你可以随时在系统设置中查看或撤销权限。健康数据仅只读,App 不会写入健康数据。

通讯录仅在你选择联系动作后用于本机查找指定联系人的号码,以便你再次确认拨号。App 不会将通讯录、查询结果或所选号发送至转发服务或 MiniMax。撤销通讯录权限不影响本地记忆或知识功能。

导入内容与外部网站

当你要求 App 导入链接或媒体时,App 会连接相应网站以读取你选择的内容。目标网站会获得网络连接通常包含的信息,例如 IP 地址。天气预警可能来自 Apple 天气和公开天气来源。

跨设备同步

如果你开启 iCloud 同步,所选 App 数据会存储在你的私人 iCloud 容器中,并受 Apple 的 iCloud 条款约束。跨设备同步为可选功能。

开发者的数据收集

开发者不会把第二大脑数据用于广告、跟踪、数据交易或开发者分析。App 不包含第三方广告 SDK。订阅标识与用量计数用于提供和保护托管服务;模型内容仅如上所述短暂经过转发服务。

保留与删除

你可以在 App 内删除记忆和知识,也可以通过 iOS 删除 App 及其本地数据。iCloud 同步数据可通过 Apple 账户和 App 同步功能管理。转发服务不保留模型内容;MiniMax 的处理和保留遵循其自身条款。订阅用量记录用于服务运行与防滥用;如适用可联系我们请求访问或删除。

1.0.4 版本:自选 AI 服务与 Gmail

1.0.4 不使用开发者的托管 AI 转发服务,也不收集订阅标识与用量计数。App 不预置模型服务商、接口或 API Key。用户配置 AI 服务后,密钥保存在设备 Keychain;所请求记忆、知识、情境或规划操作所需的有界内容直接发送到用户配置的地址,并受该服务商隐私条款约束。

用户明确连接 Gmail 后,1.0.4 申请 gmail.readonly,读取收件箱的发件人、收件人、主题、Gmail 生成的摘要、邮件与会话标识、日期及附件元数据;不下载完整正文,也不能修改、删除或发送邮件。OAuth 令牌保存在设备 Keychain;邮件证据、建议和回复草稿仅保存在本机数据库,不进入记忆库或知识库,也不会通过本 App 的私人 iCloud 功能同步。经 App 内披露和同意后,仅将请求邮件理解所需的主题及有界摘要直接发送至用户配置的 LLM 地址;完整正文、OAuth 令牌、收发件人字段及附件不发送给模型。开发者不接收 Gmail 内容,也不提供人工访问渠道。

Google 用户数据不会被出售,或用于广告、信用决策、数据交易及训练通用 AI 模型。用户可在 1.0.4 中断开 Gmail 并删除本机令牌和导入邮件记录、在 Google 账户撤销授权,或删除 App 及其本机数据。第二大脑对从 Google API 获得的信息的使用与传输遵守 Google API Services User Data Policy,包括 Limited Use 要求。

联系

隐私问题:support@prismsai.org