隐私政策
MeloFlow 隐私政策
V1.12 · 更新及生效日期 2026年10月2日
MeloFlow(以下简称“我们”或“本软件”)由 贞希远 开发,是一款面向乐器教师的本地课务管理工具。我们尊重并保护你的个人信息。本政策将帮助你了解我们在你使用本软件时如何收集、使用、存储、共享和保护你的信息,以及你享有的相关权利。
1. 我们如何收集信息
1.1 你主动录入的信息
为使用课务管理功能,你可按需录入学生姓名或昵称、家长联系方式、出生日期、课程安排、财务记录、上课记录等信息;家长联系方式及出生日期等补充资料为可选。这些信息用于管理服务,默认由你在设备本地维护;可选同步和联动的处理范围分别见下文。
1.2 设备权限信息
本软件会在完成首次引导或使用对应可选功能时申请所需权限:
- 通知权限:用于上课提醒等本地通知;
- 日历权限:开启 Apple 日历同步时申请完整访问权限,用于读取和更新专用课程日历,不导入其他个人日历。
选择头像使用 Apple 系统照片选择器,不申请相机权限或完整相册访问权限;导入、导出备份使用 Apple 系统文件选择器,只能访问你主动选择的文件或位置。你可以在设备系统设置中随时开启或关闭通知权限,关闭后仅影响提醒功能,不影响本软件其他核心功能。
1.3 我们不收集的信息
基础本机功能无需注册或登录;可选 Melo 账号与联动服务见第 1.8 节。我们不会自动读取通讯录、手机号、广告标识符、精确位置或浏览历史。你主动录入的学生信息按第 1.1 节处理;购买验证和会员码服务涉及的数据见第 1.6 节。你主动联系支持时提供的信息用于处理你的请求。
1.4 iCloud 备份与同步(可选)
本软件提供两项相互独立的可选 iCloud 功能。iCloud 备份会将完整备份快照保存到你个人的 iCloud 云盘;iCloud 同步会通过 CloudKit,在登录同一 Apple 账户的兼容 Apple 设备之间同步学生、报名课程、课程、考勤、财务、待办、设置、图片及删除记录等业务数据。
iCloud 备份默认关闭,需要你主动开启。首次安装完成引导后,若确认你拥有有效的 MeloFlow Pro 权益,本软件会自动开启 iCloud 同步;其他情况保留原有设置。你可以随时在「设置」→「数据与同步」关闭同步。首次开启 iCloud 同步前,本软件会先创建并验证一份本地安全备份。开启同步后,本软件会生成一个随机同步设备标识符,仅用于区分同步变更的来源。该标识符不包含设备序列号、广告标识符、联系方式或精确位置,也不用于广告、追踪或用户画像。同步记录存储在本软件 iCloud 容器的私人数据库中,访问权限由 Apple CloudKit 控制;该个人 iCloud 同步传输不经过开发者服务器;主动选择的 Melo 联动副本另按第 1.8 节处理。
暂停 iCloud 同步只会停止后续上传和下载,不会删除设备本地或 iCloud 中已有的数据。卸载本软件或清空本机数据也不会自动删除同步数据或 iCloud 备份文件。你可以在「设置」→「数据与同步」→「iCloud 同步」中永久删除 CloudKit 同步记录;iCloud 云盘内的完整备份需要在「iCloud 备份」中另行管理。重新开启同步后,本软件会继续同步,并依据当时的本机与云端数据状态进行恢复或合并。删除本软件、清空本机数据或更换设备前,请确认同步已经完成,或另行保留一份完整备份。
1.5 Apple 日历同步(可选)
主动开启后,本软件将学生显示姓名、课程名称、上课时间、时长及地点写入你选择的 iCloud 日历账户下的专用日历。这些信息可能出现在该日历同步或共享到的设备及服务中。日历事件不包含签到、课时余额、单价、联系方式或财务记录。支持的排课字段经业务校验后可回写 MeloFlow;新日程需要选择报名课程,含义不明确的变更和缺失事件需要核对。
为避免多设备重复写入,你的私人 CloudKit 数据库还会保存随机设备标识、设备显示名称、课程与事件的关联及上次同步的排课字段。此协调机制独立于 MeloFlow 业务数据同步,不经过开发者运营的服务器。暂停会保留已有数据;Apple 日历管理菜单中的「断开同步」及其「断开并清除关联」确认操作会清除含课程内容的协调记录,并保留随机负责设备标记以阻止旧设备自动重新开始。日历已有事件可在 Apple 日历中删除。删除 MeloFlow 业务同步数据不会删除独立的课程日历及其关联记录。应用未运行或离线时更新可能延迟,你可以随时在系统设置撤销日历权限。
1.6 购买验证与终身会员码
购买和付款由 Apple App Store 处理。MeloFlow 使用 StoreKit 验证商品、交易及原始交易标识、购买环境和权益状态。需要分配或找回终身会员码时,应用会通过 HTTPS 将 Apple 签名交易发送至开发者的会员码服务;服务验证签名并向 Apple 核查当前交易状态后分配或返回编号。签名交易可能包含购买时间、商品、交易标识、商店地区及退款或撤销信息。此过程不会将学生档案、上课记录、联系方式或财务账本发送至该服务。我们不会收到你的 Apple 账户密码或完整银行卡资料。
为在恢复购买后返回同一编号并避免重复分配,会员编号数据库保存购买环境、原始交易标识、已分配会员编号及分配时间。签名交易用于验证,不作为字段保存在该编号数据库中。这些与购买关联的信息仅用于会员交付、恢复及防止欺诈,不用于广告或跨应用追踪。
该服务使用阿里云基础设施承载。请求也会产生服务器访问及错误日志,可能包含 IP 地址、请求时间、访问路径、响应状态和客户端信息,用于安全与故障排查,按服务器日志轮转策略保存,与会员编号数据库分开管理。编号数据库另有用于恢复的备份。卸载 MeloFlow、清空本机业务数据或删除 iCloud 业务同步副本,不会自动删除服务器上的会员编号对应关系及其备份。留存和请求方式见第 3.5、5.4 节。
1.7 应用锁(可选)
6 位数字密码保存在仅限本设备的钥匙串中,不纳入 MeloFlow 业务备份或 iCloud 同步。系统身份验证由 iOS 完成,MeloFlow 只接收验证结果,不获取你的生物识别模板。关闭应用数字密码会移除对应的本机钥匙串记录。换设备后需要单独设置应用锁。
1.8 Melo 账号与连接(可选)
基础本机功能无需登录。使用连接功能前,请阅读并同意本政策与《使用条款》,再通过 Apple 登录。应用向 api.melostudio.top 提交 Apple 身份令牌、一次性授权码和防重放信息;服务器向 Apple 验证后保存应用关联用户标识、随机 Melo 账号标识、应用标识、创建时间、加密授权凭据及会话校验信息,用于登录、访问控制、退出和删除账号。当前不请求 Apple 姓名或邮箱,不读取 Apple 密码,不提供手机号、微信或 Google 登录。
老师为指定学生和课程生成 8 位字母数字一次性邀请码,通常 24 小时有效。接收方填写邀请码与供老师核对的显示名(可用昵称),经老师确认后连接。服务器保存双方账号关系、学生和课程的内部标识、显示名、邀请码保护信息、有效期、连接状态和更新时间。请仅向对应学生或获授权的监护人提供邀请码。
课程共享仅包含连接显示名、授课老师名称、所选课程名称、报名及结课状态、课程时长、剩余课时、过去及未来上课时间、本人上课状态、扣除课时与更新时间。课程由老师维护,学生只读,更新受应用运行及网络情况影响。学生档案填写与资料提交不属于连接功能;头像、年龄、生日、性别、家长、电话、年级、程度、财务金额、私人笔记、内部备注和其他学生资料不进入课程共享。老师本机档案和生日提醒独立保留。显示名可使用昵称,但账号关联和课程记录仍按个人信息保护。
学生可主动选择已完成的练琴记录及已连接老师,经预览确认后分享日期、曲目和实际时长;服务器同时保存记录与连接标识、版本及更新时间以支持同步和撤回。笔记、录音、音频附件及完整练习库不上传。老师只读;本机修改不自动重新分享,学生可主动更新或撤回共享副本。
共享仅提供给对应连接的接收方,不公开展示。我们为运行和保护服务处理必要数据,阿里云提供存储与网络基础设施。账号及连接服务部署在中国大陆,其他地区用户的相关请求亦传至中国大陆;接收方可在其所在地查看共享内容。依法需要额外告知、同意或跨境程序时,应在处理前完成。本服务使用 HTTPS、服务器端加密和账号权限检查,会话保存在设备钥匙串;并非端到端加密。安全日志可能包含 IP、时间、路径、状态码及客户端信息,网关按日轮转并保留 14 份历史文件。我们不出售这些信息,不用于广告、跨应用追踪或训练通用人工智能模型。Apple 登录、购买及个人 iCloud 由 Apple 按其规则提供;Melo 连接不使用 iCloud Sharing,也不自动上传完整本机资料库。
账号和有效共享在提供服务所需期间保存。撤回练琴分享或解除连接后,停止相应访问并清除服务中的相应共享内容,保留防止旧请求恢复内容所需的最少状态和标识。双方本机原始记录及接收方已另行保存的副本不会因此自动删除。已停用的学生资料提交历史加密副本不再提供读取或处理,并按删除请求及保存规则清理;停用不表示历史副本和备份已全部删除。
你可在设置的 Melo 账号页删除账号:这会停止同一账号在 MeloFlow 和 MeloDaily 的连接访问、撤销会话并处理 Apple 授权撤销,删除关联服务器资料。授权撤销失败时账号保持停用并重试。退出、卸载或清空本机数据不等于删除账号;账号删除不删除本机原始记录、个人 iCloud 数据、会员编号登记,也不自动取消 Apple 订阅。上述内容需从各自入口管理。
账号及连接数据库的自动加密备份按 7 天周期清理,已完成删除的恢复保护记录保留 14 天;恢复时应用删除记录并使旧连接失效。删除处理期间保留必要信息,故障或部署保留的额外受限副本需一并核对;依法须保留的资料仅在必要范围和期限内受限保存。你可查看共享内容、撤回练琴分享、解除连接、删除账号,或联系 melostudio26@gmail.com 请求查阅、复制、更正、删除、撤回同意或投诉。我们核实必要身份或代理关系后处理。拒绝连接不影响无需账号的本机功能。
连接体验模式无需 Apple 登录,仅使用系统生成的虚构师生和课程。演示会话以随机临时凭据隔离,不读写你的本机档案或正式 Melo 账号;演示数据仅保存在服务器内存,退出时请求清除,网络中断等情况下最迟一小时到期清除,不进入业务备份。网络安全日志仍按本政策保存。演示不授予会员权益,也不代替正式账号的登录或删除流程。
2. 我们如何使用信息
2.1 仅用于实现本软件功能,如:
- 生成学生档案、课程表、财务统计;
- 触发本地上课提醒;
- 在你开启相应功能时,支持本地导入导出、iCloud 备份与恢复、多设备 iCloud 同步及 Apple 日历同步;
- 验证购买、交付或找回会员码,以及处理安全和支持问题。
2.2 我们不会将你的个人信息用于广告投放、用户画像或第三方营销。
3. 信息的存储与保护
3.1 你的业务数据默认存储于设备本地(App 沙盒)。如你开启 iCloud 备份或同步,备份文件或同步记录还会通过 Apple 的 iCloud 云盘或 CloudKit 服务存储在你的个人 iCloud 账户中。个人 iCloud 功能不经由我们的服务器中转;你主动启用 Melo 联动时,第 1.8 节列明的资料副本会另行发送至我们的服务器。
3.2 数据导出功能生成的 JSON 文件由你自行选择保存位置,请注意妥善保管,避免泄露。
3.3 本机数据受 iOS App 沙盒、系统数据保护及访问隔离机制保护;你仍需妥善保护设备密码、Apple 账户和导出的备份文件。
3.4 数据留存:业务数据在设备上保留至你主动清空本机数据或卸载本软件;同步记录会保留在你的 iCloud 账户中,直至你使用本软件的永久删除入口,或通过 Apple 提供的存储管理入口删除相关 MeloFlow 数据;iCloud 云盘备份文件会保留至你另行删除。暂停同步、清空本机数据、卸载本软件或失去 Pro 权益本身均不会删除云端数据。iCloud 内的数据留存与删除还受适用于你的 iCloud 服务条款及 Apple 账户设置约束。本节针对业务数据;独立会员码服务的留存规则如下。
3.5 会员数据留存:原始交易与会员编号的对应关系用于持续提供终身会员及恢复购买服务。当前编号数据库及其恢复备份没有自动到期清除机制,服务器日志另按轮转策略管理。你可以联系我们申请查阅、更正或删除。我们会核实请求,说明仍需保留的信息及原因,并在处理删除时一并核对相关备份副本。删除对应关系可能使原编号无法自动找回;这本身不会取消或退还 App Store 购买,购买记录及权益由 Apple 管理。
4. 信息的共享与披露
4.1 我们不会向任何第三方共享、转让或公开披露你的个人信息,除非:
- 获得你的明确同意;
- 根据法律法规、监管要求或司法程序必须提供。
4.2 云服务提供方:当你开启 iCloud 备份、iCloud 同步或 Apple 日历同步时,Apple Inc.(苹果公司)及适用于你所在地区的 iCloud 服务提供方,会依据适用于你 Apple 账户的 iCloud 服务条款存储和处理相关数据。对于中国大陆用户,相关 iCloud 功能可能由云上贵州(云上艾珀(贵州)技术有限公司)运营。购买验证使用 Apple 服务,会员码服务使用第 1.6 节说明的阿里云基础设施;相关提供方处理提供对应服务所需的信息。我们不出售个人信息,不集成第三方数据分析或广告 SDK。你主动分享导出文件或日历时,其内容会提供给你选择的接收方。
5. 你的权利
5.1 查阅与修改:你可以随时在本软件内查看、编辑或删除录入的学生、课程、财务等数据。
5.2 导出、撤回与删除:你可以随时导出 JSON 备份。你可以在本软件中暂停 iCloud 同步,但暂停不会删除本机或云端数据。「清空所有数据」会在先创建安全备份并暂停同步后删除本机业务数据,不会删除 iCloud 中已有的同步记录或备份文件。「iCloud 同步」页面提供独立的同步记录永久删除入口;iCloud 云盘备份文件可在「iCloud 备份」中另行删除。
5.3 权限管理:你可以在 iOS 系统设置中管理本软件使用的各项权限。
5.4 会员与支持请求:可通过 melostudio26@gmail.com 申请查阅、更正或删除会员服务信息,尽可能提供会员编号或相关购买凭据标识,请勿发送密码或完整银行卡资料。我们可能要求用于核实购买关系的必要信息,并说明处理结果及对编号恢复的影响。停止 Apple 日历同步请使用其管理菜单;已有日历事件需按第 1.5 节在 Apple 日历中另行管理。
6. 未成年人保护
未成年人应在监护人指导下使用本软件。老师录入或分享学生相关信息前,应完成必要告知并取得合法授权;涉及儿童个人信息时,应按适用法律取得监护人同意并落实相应保护要求,未满足要求前不应通过连接服务处理该类信息。老师确认连接或勾选登录协议不等于完成监护人同意核验。本软件不要求填写年龄,也不提供身份或监护关系核验。监护人可通过本政策邮箱申请查阅、更正、停止处理或删除,我们核实必要代理关系后处理。
7. 隐私政策的更新
我们可能会根据产品功能或法律法规变化更新本政策。更新后将在软件和官网公示版本与日期;涉及需要另行告知或征得同意的变更时,我们会按适用要求处理。
8. 联系我们
如你对本隐私政策有任何疑问、意见或投诉,可通过以下方式联系开发者:
- 电子邮件:melostudio26@gmail.com
- 开发者 / 处理者名称:贞希远
我们将在合理时间内予以回复。
繁體中文
MeloFlow 隱私政策
V1.12 · 更新及生效日期 2026年10月2日
MeloFlow(以下簡稱“我們”或“本軟件”)由 貞希遠 開發,是一款面向樂器教師的本地課務管理工具。我們尊重並保護你的個人信息。本政策將幫助你瞭解我們在你使用本軟件時如何收集、使用、存儲、共享和保護你的信息,以及你享有的相關權利。
1. 我們如何收集信息
1.1 你主動錄入的信息
為使用課務管理功能,你可按需輸入學生姓名或暱稱、家長聯絡方式、出生日期、課程安排、財務記錄、上課記錄等資訊;家長聯絡方式及出生日期等補充資料為可選。這些信息用於管理服務,默認由你在設備本地維護;可選同步和聯動的處理範圍分別見下文。
1.2 設備權限信息
本軟件會在完成首次引導或使用對應可選功能時申請所需權限:
- 通知權限:用於上課提醒等本地通知;
- 日曆權限:開啓 Apple 日曆同步時申請完整訪問權限,用於讀取和更新專用課程日曆,不導入其他個人日曆。
選擇頭像使用 Apple 系統照片選擇器,不申請相機權限或完整相冊訪問權限;導入、導出備份使用 Apple 系統文件選擇器,只能訪問你主動選擇的文件或位置。你可以在設備系統設置中隨時開啓或關閉通知權限,關閉後僅影響提醒功能,不影響本軟件其他核心功能。
1.3 我們不收集的信息
基礎本機功能無需註冊或登錄;可選 Melo 賬號與聯動服務見第 1.8 節。我們不會自動讀取通訊錄、手機號、廣告標識符、精確位置或瀏覽歷史。你主動錄入的學生信息按第 1.1 節處理;購買驗證和會員碼服務涉及的數據見第 1.6 節。你主動聯繫支持時提供的信息用於處理你的請求。
1.4 iCloud 備份與同步(可選)
本軟件提供兩項相互獨立的可選 iCloud 功能。iCloud 備份會將完整備份快照保存到你個人的 iCloud 雲盤;iCloud 同步會通過 CloudKit,在登錄同一 Apple 賬戶的兼容 Apple 設備之間同步學生、報名課程、課程、考勤、財務、待辦、設置、圖片及刪除記錄等業務數據。
iCloud 備份預設關閉,需要你主動開啟。首次安裝完成引導後,若確認你擁有有效的 MeloFlow Pro 權益,本軟件會自動開啟 iCloud 同步;其他情況保留原有設定。你可以隨時在「設定」→「資料與同步」關閉同步。首次開啓 iCloud 同步前,本軟件會先創建並驗證一份本地安全備份。開啓同步後,本軟件會生成一個隨機同步設備標識符,僅用於區分同步變更的來源。該標識符不包含設備序列號、廣告標識符、聯繫方式或精確位置,也不用於廣告、追蹤或用戶畫像。同步記錄存儲在本軟件 iCloud 容器的私人數據庫中,訪問權限由 Apple CloudKit 控制;該個人 iCloud 同步傳輸不經過開發者服務器;主動選擇的 Melo 聯動副本另按第 1.8 節處理。
暫停 iCloud 同步只會停止後續上傳和下載,不會刪除設備本地或 iCloud 中已有的數據。卸載本軟件或清空本機數據也不會自動刪除同步數據或 iCloud 備份文件。你可以在「設置」→「數據與同步」→「iCloud 同步」中永久刪除 CloudKit 同步記錄;iCloud 雲盤內的完整備份需要在「iCloud 備份」中另行管理。重新開啓同步後,本軟件會繼續同步,並依據當時的本機與雲端數據狀態進行恢復或合併。刪除本軟件、清空本機數據或更換設備前,請確認同步已經完成,或另行保留一份完整備份。
1.5 Apple 日曆同步(可選)
主動開啓後,本軟件將學生顯示姓名、課程名稱、上課時間、時長及地點寫入你選擇的 iCloud 日曆賬戶下的專用日曆。這些信息可能出現在該日曆同步或共享到的設備及服務中。日曆事件不包含簽到、課時餘額、單價、聯繫方式或財務記錄。支持的排課字段經業務校驗後可回寫 MeloFlow;新日程需要選擇報名課程,含義不明確的變更和缺失事件需要核對。
為避免多設備重復寫入,你的私人 CloudKit 數據庫還會保存隨機設備標識、設備顯示名稱、課程與事件的關聯及上次同步的排課字段。此協調機制獨立於 MeloFlow 業務數據同步,不經過開發者運營的服務器。暫停會保留已有數據;Apple 日曆管理菜單中的「斷開同步」及其「斷開並清除關聯」確認操作會清除含課程內容的協調記錄,並保留隨機負責設備標記以阻止舊設備自動重新開始。日曆已有事件可在 Apple 日曆中刪除。刪除 MeloFlow 業務同步數據不會刪除獨立的課程日曆及其關聯記錄。應用未運行或離線時更新可能延遲,你可以隨時在系統設置撤銷日曆權限。
1.6 購買驗證與終身會員碼
購買和付款由 Apple App Store 處理。MeloFlow 使用 StoreKit 驗證商品、交易及原始交易標識、購買環境和權益狀態。需要分配或找回終身會員碼時,應用會通過 HTTPS 將 Apple 簽名交易發送至開發者的會員碼服務;服務驗證簽名並向 Apple 核查當前交易狀態後分配或返回編號。簽名交易可能包含購買時間、商品、交易標識、商店地區及退款或撤銷信息。此過程不會將學生檔案、上課記錄、聯繫方式或財務賬本發送至該服務。我們不會收到你的 Apple 賬戶密碼或完整銀行卡資料。
為在恢復購買後返回同一編號並避免重復分配,會員編號數據庫保存購買環境、原始交易標識、已分配會員編號及分配時間。簽名交易用於驗證,不作為字段保存在該編號數據庫中。這些與購買關聯的信息僅用於會員交付、恢復及防止欺詐,不用於廣告或跨應用追蹤。
該服務使用阿里雲基礎設施承載。請求也會產生服務器訪問及錯誤日誌,可能包含 IP 地址、請求時間、訪問路徑、響應狀態和客戶端信息,用於安全與故障排查,按服務器日誌輪轉策略保存,與會員編號數據庫分開管理。編號數據庫另有用於恢復的備份。卸載 MeloFlow、清空本機業務數據或刪除 iCloud 業務同步副本,不會自動刪除服務器上的會員編號對應關係及其備份。留存和請求方式見第 3.5、5.4 節。
1.7 應用鎖(可選)
6 位數字密碼保存在僅限本設備的鑰匙串中,不納入 MeloFlow 業務備份或 iCloud 同步。系統身份驗證由 iOS 完成,MeloFlow 只接收驗證結果,不獲取你的生物識別模板。關閉應用數字密碼會移除對應的本機鑰匙串記錄。換設備後需要單獨設置應用鎖。
1.8 Melo 帳號與連接(可選)
基本本機功能無需登入。使用連接功能前,請閱讀並同意本政策與《使用條款》,再透過 Apple 登入。應用向 api.melostudio.top 提交 Apple 身分權杖、一次性授權碼和防重放資訊;伺服器向 Apple 驗證後保存應用關聯使用者識別碼、隨機 Melo 帳號識別碼、應用識別碼、建立時間、加密授權憑證及工作階段驗證資訊,用於登入、存取控制、登出和刪除帳號。目前不要求 Apple 姓名或電郵,不讀取 Apple 密碼,不提供手機號碼、微信或 Google 登入。
老師為指定學生和課程產生 8 位英數字一次性邀請碼,通常 24 小時有效。接收者填寫邀請碼與供老師核對的顯示名稱(可用暱稱),經老師確認後連接。伺服器保存雙方帳號關係、學生和課程的內部識別碼、顯示名稱、邀請碼保護資訊、有效期、連接狀態和更新時間。請僅向對應學生或獲授權的監護人提供邀請碼。
課程共享僅包含連接顯示名稱、授課老師名稱、所選課程名稱、報名及結課狀態、課程時長、剩餘課時、過去及未來上課時間、本人上課狀態、扣除課時與更新時間。課程由老師維護,學生唯讀,更新受應用執行及網路情況影響。學生檔案填寫與資料提交不屬於連接功能;頭像、年齡、生日、性別、家長、電話、年級、程度、財務金額、私人筆記、內部備註和其他學生資料不進入課程共享。老師本機檔案和生日提醒獨立保留。顯示名稱可使用暱稱,但帳號關聯和課程記錄仍按個人資料保護。
學生可主動選擇已完成的練琴記錄及已連接老師,經預覽確認後分享日期、曲目和實際時長;伺服器同時保存記錄與連接識別碼、版本及更新時間,以支援同步和撤回。筆記、錄音、音訊附件及完整練習庫不上傳。老師唯讀;本機修改不自動重新分享,學生可主動更新或撤回共享副本。
共享僅提供給對應連接的接收者,不公開展示。我們為執行和保護服務處理必要資料,阿里雲提供儲存與網路基礎設施。帳號及連接服務部署於中國大陸,其他地區使用者的相關請求亦傳至中國大陸;接收者可在其所在地查看共享內容。依法需要額外告知、同意或跨境程序時,應在處理前完成。本服務使用 HTTPS、伺服器端加密和帳號權限檢查,工作階段儲存於裝置鑰匙圈;並非端對端加密。安全日誌可能包含 IP、時間、路徑、狀態碼及用戶端資訊,閘道每日輪替並保留 14 份歷史檔案。我們不出售這些資訊,不用於廣告、跨應用追蹤或訓練通用人工智慧模型。Apple 登入、購買及個人 iCloud 由 Apple 按其規則提供;Melo 連接不使用 iCloud Sharing,也不自動上傳完整本機資料庫。
帳號和有效共享在提供服務所需期間保存。撤回練琴分享或解除連接後,停止相應存取並清除服務中的相應共享內容,保留防止舊請求恢復內容所需的最少狀態和識別碼。雙方本機原始記錄及接收者已另行保存的副本不會因此自動刪除。已停用的學生資料提交歷史加密副本不再提供讀取或處理,並按刪除請求及保存規則清理;停用不表示歷史副本和備份已全部刪除。
你可在設定的 Melo 帳號頁刪除帳號:這會停止同一帳號在 MeloFlow 和 MeloDaily 的連接存取、撤銷工作階段並處理 Apple 授權撤銷,刪除關聯伺服器資料。授權撤銷失敗時帳號保持停用並重試。登出、移除應用或清空本機資料不等於刪除帳號;帳號刪除不刪除本機原始記錄、個人 iCloud 資料、會員編號登記,也不自動取消 Apple 訂閱。上述內容需從各自入口管理。
帳號及連接資料庫的自動加密備份按 7 天週期清理,已完成刪除的恢復保護記錄保留 14 天;恢復時套用刪除記錄並使舊連接失效。刪除處理期間保留必要資訊,故障或部署保留的額外受限副本需一併核對;依法須保留的資料僅在必要範圍和期限內受限保存。你可查看共享內容、撤回練琴分享、解除連接、刪除帳號,或聯絡 melostudio26@gmail.com 請求查閱、複製、更正、刪除、撤回同意或投訴。我們核實必要身分或代理關係後處理。拒絕連接不影響無需帳號的本機功能。
連接體驗模式無需 Apple 登入,僅使用系統產生的虛構師生和課程。演示工作階段以隨機臨時憑證隔離,不讀寫你的本機檔案或正式 Melo 帳號;演示資料僅儲存於伺服器記憶體,退出時請求清除,網路中斷等情況下最遲一小時到期清除,不進入業務備份。網路安全日誌仍按本政策保存。演示不授予會員權益,也不替代正式帳號的登入或刪除流程。
2. 我們如何使用信息
2.1 僅用於實現本軟件功能,如:
- 生成學生檔案、課程表、財務統計;
- 觸發本地上課提醒;
- 在你開啓相應功能時,支持本地導入導出、iCloud 備份與恢復、多設備 iCloud 同步及 Apple 日曆同步;
- 驗證購買、交付或找回會員碼,以及處理安全和支持問題。
2.2 我們不會將你的個人信息用於廣告投放、用戶畫像或第三方營銷。
3. 信息的存儲與保護
3.1 你的業務數據默認存儲於設備本地(App 沙盒)。如你開啓 iCloud 備份或同步,備份文件或同步記錄還會通過 Apple 的 iCloud 雲盤或 CloudKit 服務存儲在你的個人 iCloud 賬戶中。個人 iCloud 功能不經由我們的服務器中轉;你主動啓用 Melo 聯動時,第 1.8 節列明的資料副本會另行發送至我們的服務器。
3.2 數據導出功能生成的 JSON 文件由你自行選擇保存位置,請注意妥善保管,避免洩露。
3.3 本機數據受 iOS App 沙盒、系統數據保護及訪問隔離機制保護;你仍需妥善保護設備密碼、Apple 賬戶和導出的備份文件。
3.4 數據留存:業務數據在設備上保留至你主動清空本機數據或卸載本軟件;同步記錄會保留在你的 iCloud 賬戶中,直至你使用本軟件的永久刪除入口,或通過 Apple 提供的存儲管理入口刪除相關 MeloFlow 數據;iCloud 雲盤備份文件會保留至你另行刪除。暫停同步、清空本機數據、卸載本軟件或失去 Pro 權益本身均不會刪除雲端數據。iCloud 內的數據留存與刪除還受適用於你的 iCloud 服務條款及 Apple 賬戶設置約束。本節針對業務數據;獨立會員碼服務的留存規則如下。
3.5 會員數據留存:原始交易與會員編號的對應關係用於持續提供終身會員及恢復購買服務。當前編號數據庫及其恢復備份沒有自動到期清除機制,服務器日誌另按輪轉策略管理。你可以聯繫我們申請查閱、更正或刪除。我們會覈實請求,說明仍需保留的信息及原因,並在處理刪除時一並核對相關備份副本。刪除對應關係可能使原編號無法自動找回;這本身不會取消或退還 App Store 購買,購買記錄及權益由 Apple 管理。
4. 信息的共享與披露
4.1 我們不會向任何第三方共享、轉讓或公開披露你的個人信息,除非:
- 獲得你的明確同意;
- 根據法律法規、監管要求或司法程序必須提供。
4.2 雲服務提供方:當你開啓 iCloud 備份、iCloud 同步或 Apple 日曆同步時,Apple Inc.(蘋果公司)及適用於你所在地區的 iCloud 服務提供方,會依據適用於你 Apple 賬戶的 iCloud 服務條款存儲和處理相關數據。對於中國大陸用戶,相關 iCloud 功能可能由雲上貴州(雲上艾珀(貴州)技術有限公司)運營。購買驗證使用 Apple 服務,會員碼服務使用第 1.6 節說明的阿里雲基礎設施;相關提供方處理提供對應服務所需的信息。我們不出售個人信息,不集成第三方數據分析或廣告 SDK。你主動分享導出文件或日曆時,其內容會提供給你選擇的接收方。
5. 你的權利
5.1 查閱與修改:你可以隨時在本軟件內查看、編輯或刪除錄入的學生、課程、財務等數據。
5.2 導出、撤回與刪除:你可以隨時導出 JSON 備份。你可以在本軟件中暫停 iCloud 同步,但暫停不會刪除本機或雲端數據。「清空所有數據」會在先創建安全備份並暫停同步後刪除本機業務數據,不會刪除 iCloud 中已有的同步記錄或備份文件。「iCloud 同步」頁面提供獨立的同步記錄永久刪除入口;iCloud 雲盤備份文件可在「iCloud 備份」中另行刪除。
5.3 權限管理:你可以在 iOS 系統設置中管理本軟件使用的各項權限。
5.4 會員與支持請求:可通過 melostudio26@gmail.com 申請查閱、更正或刪除會員服務信息,盡可能提供會員編號或相關購買憑據標識,請勿發送密碼或完整銀行卡資料。我們可能要求用於覈實購買關係的必要信息,並說明處理結果及對編號恢復的影響。停止 Apple 日曆同步請使用其管理菜單;已有日曆事件需按第 1.5 節在 Apple 日曆中另行管理。
6. 未成年人保護
未成年人應在監護人指導下使用本軟體。老師輸入或分享學生相關資訊前,應完成必要告知並取得合法授權;涉及兒童個人資料時,應按適用法律取得監護人同意並落實相應保護要求,未滿足要求前不應透過連接服務處理該類資訊。老師確認連接或勾選登入協議不等於完成監護人同意核驗。本軟體不要求填寫年齡,也不提供身分或監護關係核驗。監護人可透過本政策電郵申請查閱、更正、停止處理或刪除,我們核實必要代理關係後處理。
7. 隱私政策的更新
我們可能會根據產品功能或法律法規變化更新本政策。更新後將在軟件和官網公示版本與日期;涉及需要另行告知或徵得同意的變更時,我們會按適用要求處理。
8. 聯繫我們
如你對本隱私政策有任何疑問、意見或投訴,可通過以下方式聯繫開發者:
- 電子郵件:melostudio26@gmail.com
- 開發者 / 處理者名稱:貞希遠
我們將在合理時間內予以回復。
English
MeloFlow Privacy Policy
V1.12 · Updated and effective October 2, 2026
MeloFlow (hereinafter "we" or "the Software") is developed by Zhen Xiyuan and is a local lesson-management tool for instrument teachers. We respect and protect your personal information. This Policy explains how we collect, use, store, share, and protect your information when you use the Software, as well as the rights you enjoy.
1. How We Collect Information
1.1 Information you actively provide
For lesson management, you may enter student names or nicknames, parent contact details, birth dates, schedules, financial records and class logs as needed. Supplementary details such as parent contact information and birth dates are optional. This information provides management functions and is maintained locally by default; optional sync and connection processing are described below.
1.2 Device permission information
The Software requests the relevant permissions when you finish initial setup or use the corresponding optional features:
- Notification: for local reminders such as class alerts;
- Calendar: full access is requested when you enable Apple Calendar sync, to read and update the dedicated lesson calendar. Other personal calendars are not imported.
Avatar selection uses Apple's system photo picker and does not request camera access or broad Photo Library access. Importing and exporting a backup uses Apple's system file picker, which grants access only to files or locations you select.
You may enable or disable notification permission at any time in your device's system settings. Disabling it affects only reminders and not the Software's other core functions.
1.3 Information we do not collect
Basic local features require no registration or sign-in. Optional Melo accounts and connections are described in section 1.8. We do not automatically read contacts, phone numbers, advertising identifiers, precise location or browsing history. Information you enter about students remains subject to section 1.1. Purchase verification and membership-code service data are described in section 1.6; information you choose to send when contacting support is used to handle your request.
1.4 iCloud Backup and Sync (optional)
The Software provides two separate optional iCloud features. iCloud Backup saves complete backup snapshots to your personal iCloud Drive. iCloud Sync uses CloudKit to synchronize business records—including students, enrollments, lessons, attendance, financial entries, todos, settings, images and deletion records—between compatible Apple devices signed in to the same Apple Account.
iCloud Backup is off by default and requires you to enable it. After onboarding on a fresh installation, the Software automatically enables iCloud Sync if your active MeloFlow Pro access is verified; otherwise existing preferences are preserved. You can turn Sync off at any time in Settings → Data & Sync. Before iCloud Sync is enabled for the first time, the Software creates and verifies a local safety backup. When Sync is enabled, the Software generates a random sync-device identifier solely to distinguish the source of synchronized changes. It does not contain a device serial number, advertising identifier, contact information, or precise location, and is not used for advertising, tracking, or profiling. Synced records are stored in the private database of the Software's iCloud container. Access is controlled by Apple's CloudKit permissions, and this personal iCloud transfer is not relayed through the Developer server; separately selected Melo connection copies follow section 1.8.
Pausing iCloud Sync only stops subsequent uploads and downloads. It does not delete data already stored on your device or in iCloud. Uninstalling the Software or clearing local data also does not automatically delete synced data or iCloud backup files. You can permanently delete MeloFlow's CloudKit sync records from Settings → Data & Sync → iCloud Sync; iCloud Drive backup files are managed separately in iCloud Backup. When Sync is re-enabled, the Software resumes synchronization and may restore or merge local and cloud data according to their current state. Before deleting the Software, clearing local data, or changing devices, please verify that Sync has completed or retain a separate complete backup.
1.5 Apple Calendar sync (optional)
After you enable this feature, student display names, course names, lesson times, durations and locations are written to a dedicated calendar in the iCloud calendar account you select. They may appear on devices or services to which you synchronize or share that calendar. Attendance, credit balances, prices, contact details and financial records are not included in calendar events. Calendar changes to supported scheduling fields are validated before they update MeloFlow. New events require enrollment selection; ambiguous changes and missing events require review.
To prevent duplicate writes across devices, your private CloudKit database also stores a random device identifier, device display name, event-to-lesson links and the last synchronized scheduling fields. This coordination works separately from MeloFlow business-data sync and does not use a developer-operated server. Pausing keeps existing data. Disconnect Sync and its confirmation to clear links in Apple Calendar management removes the course-related coordination payload; a random owner marker remains to prevent an old device from silently restarting sync. Existing calendar events can be removed in Apple Calendar. Deleting MeloFlow business sync data does not delete the separate calendar or its coordination links. Updates can be delayed while the app is inactive or offline. System Calendar permission can be revoked at any time.
1.6 Purchases and lifetime membership codes
Purchases and payment are handled by Apple's App Store. MeloFlow uses StoreKit to verify the product, transaction and original transaction identifiers, purchase environment, and entitlement status. When a lifetime membership code needs to be assigned or retrieved, the app sends Apple's signed transaction over HTTPS to the Developer's membership-code service. The service verifies the signature and checks the transaction's current status with Apple before assigning or returning a code. The signed transaction may include purchase time, product, transaction identifiers, storefront, and refund or revocation information. This process does not send student profiles, lesson records, contacts, or financial ledgers to that service. We do not receive your Apple Account password or full payment-card details.
To return the same code after purchase restoration and avoid duplicate allocation, the membership registry stores the purchase environment, original transaction identifier, assigned membership number, and assignment time. The signed transaction is used for verification and is not stored as a field in that registry. This purchase-linked information is used for membership delivery, restoration, and fraud prevention, not advertising or cross-app tracking.
The service is hosted on Alibaba Cloud infrastructure. Requests also generate server access and error logs, which may contain an IP address, request time, requested path, response status, and client information. These logs support security and fault diagnosis, are subject to server log rotation, and are separate from the membership registry. Registry backups are retained for recovery. Uninstalling MeloFlow, clearing local business data, or deleting your iCloud business sync copy does not automatically delete the server-side membership mapping or its backups. See sections 3.5 and 5.4 for retention and requests.
1.7 App lock (optional)
The six-digit passcode is stored in the device-only Keychain. It is not included in MeloFlow business backups or iCloud Sync. System authentication is handled by iOS; MeloFlow receives its result, not your biometric templates. Disabling the app passcode removes its local Keychain entry. Set up locking separately on a new device.
1.8 Optional Melo Accounts and Connections
Local features do not require sign-in. Before using connections, read and agree to this policy and the Terms of Use, then sign in with Apple. The app sends an Apple identity token, one-time authorization code and replay-protection information to api.melostudio.top. After verification with Apple, the server stores the app-associated Apple user identifier, a random Melo account identifier, app identifier, creation time, encrypted authorization credentials and session verification information for authentication, access control, sign-out and deletion. We do not request Apple name or email access, read Apple passwords, or offer phone, WeChat or Google sign-in.
Teachers create an eight-character alphanumeric single-use code for a student and selected courses, normally valid for 24 hours. The recipient enters the code and a display name, which may be a nickname, for teacher confirmation. The server stores account relationships, internal student and course identifiers, display names, protected invitation information, expiry, connection status and update times. Give codes only to the intended student or an authorized guardian.
Shared courses contain only the connection display name, teacher name, selected course names, enrollment and completion status, lesson duration, remaining credits, past and future lesson times, the student's attendance, deducted credits and update times. Teachers maintain courses; students have read-only access. Updates depend on app activity and connectivity. Student profile entry and submissions are not part of connections. Avatars, age, birth dates, gender, parents, phone numbers, school grades, learning levels, financial amounts, private notes, internal remarks and other students' information are not included in course sharing. Teachers' local records and birthday reminders remain separate. Nicknames are allowed, but account relationships and course records are still protected as personal information.
Students may select completed practice records and a connected teacher, preview and share the date, piece title and actual duration. The server also stores record and connection identifiers, versions and update times to support sharing and withdrawal. Notes, recordings, audio attachments and the complete practice library are not uploaded. Teachers have read-only access. Local edits do not automatically reshare records; students can update or withdraw shared copies.
Sharing is limited to the recipient in the relevant connection and is not public. We process necessary information to operate and protect the service; Alibaba Cloud provides storage and network infrastructure. Account and connection servers are in mainland China, including for requests from users elsewhere. Recipients may access shared content in their own locations. Any legally required additional notices, consent or cross-border procedures must be completed before the relevant processing. We use HTTPS, server-side encryption and account access checks; device sessions are stored in Keychain. This is not end-to-end encryption. Security logs may contain IP addresses, times, paths, status codes and client information; gateway logs rotate daily with 14 historical files retained. We do not sell this information or use it for advertising, cross-app tracking or general-purpose AI training. Apple provides sign-in, purchases and personal iCloud under its own rules. Melo connections do not use iCloud Sharing or automatically upload the full local database.
Accounts and active shares are retained as needed to provide the service. Withdrawing a practice share or disconnecting ends the corresponding access and clears the relevant shared content, retaining minimal status and identifiers to prevent stale requests restoring it. Original local records and copies independently saved by recipients are not automatically deleted. Historical encrypted copies from the retired student profile submission feature are no longer available for access or processing and remain subject to deletion requests and retention rules; retirement does not mean every historical copy and backup has already been erased.
Delete your account from Melo Account in Settings to stop its connection access in both MeloFlow and MeloDaily, revoke sessions, process Apple authorization revocation and delete associated server data. If revocation fails, the account stays disabled while retrying. Signing out, uninstalling or clearing local data is not account deletion. Account deletion does not delete original local records, personal iCloud data or membership-number registrations, or cancel Apple subscriptions; manage those separately.
Automatic encrypted account and connection backups expire on a seven-day cycle. Completed-deletion restore-protection records are retained for 14 days; restoration applies deletion records and invalidates old connections. Necessary information remains while deletion is processed. Additional restricted troubleshooting or deployment copies must also be checked; legally required records are restricted to the necessary scope and duration. You can view shared content, withdraw practice shares, disconnect, delete your account, or contact melostudio26@gmail.com for access, copies, correction, deletion, consent withdrawal or complaints. We verify necessary identity or representative authority before responding. Declining connections does not affect local features that do not need an account.
The connection demo does not require Apple sign-in and uses only system-generated fictional people and courses. Random temporary credentials isolate each demo; it does not access your local records or production Melo account. Demo data stays in server memory, is requested to be cleared on exit, and expires within one hour if connectivity is lost. It is not included in business backups. Network security logs follow this policy. The demo does not grant membership or replace production account sign-in or deletion.
2. How We Use Information
2.1 Solely to deliver the Software's functions, such as:
- Generating student profiles, schedules, and financial statistics;
- Triggering local class reminders;
- Supporting local import and export, iCloud Backup, restore, multi-device iCloud Sync, and Apple Calendar sync when you enable them;
- Verifying purchases, delivering or restoring membership codes, and handling security or support issues.
2.2 We will not use your personal information for advertising, user profiling, or third-party marketing.
3. Storage and Protection of Information
3.1 Your business data is stored by default on your device locally (app sandbox). If you enable iCloud Backup or Sync, backup files or synchronized records are also stored in your personal iCloud account through Apple's iCloud Drive or CloudKit services. Personal iCloud traffic is not relayed through our server. If you enable Melo connections, the selected copies described in section 1.8 are separately sent to our server.
3.2 The JSON file produced by data export is saved at a location of your choice; please keep it safe to avoid leakage.
3.3 Local data is protected by the iOS app sandbox, system data protection, and access isolation. You remain responsible for your device passcode, Apple Account, and exported backup files.
3.4 Data retention: business data remains on your device until you actively clear local data or uninstall the Software. Synchronized records remain in your iCloud account until you use the permanent cloud-data deletion control in the Software or remove the relevant MeloFlow data through Apple's storage-management tools. iCloud Drive backup files remain until you delete them separately. Pausing sync, clearing local data, uninstalling the Software, or losing Pro access does not by itself delete cloud data. Retention and deletion within iCloud are also governed by the applicable iCloud terms and your Apple Account settings. This section concerns business data; the separate membership service is covered below.
3.5 Membership data retention: the original-transaction-to-code mapping is retained to support continuing lifetime membership and purchase restoration. The current registry and its recovery backups have no automatic expiry. Server logs follow a separate rotation policy. You may contact us to request access, correction, or deletion. We will verify the request, explain any information that still needs to be retained and why, and address relevant backup copies when handling deletion. Deleting the mapping may prevent automatic retrieval of the same code. It does not itself cancel or refund an App Store purchase; Apple controls the purchase record and entitlement.
4. Sharing and Disclosure of Information
4.1 We will not share, transfer, or publicly disclose your personal information to any third party, except:
- With your explicit consent;
- When required to do so by laws, regulations, supervisory requirements, or judicial procedures.
4.2 Cloud service provider: when you enable iCloud Backup, iCloud Sync, or Apple Calendar sync, Apple Inc. and the applicable regional iCloud service provider store and process the relevant data under the iCloud terms applicable to your Apple Account. For users in mainland China, applicable iCloud functions may be operated by Guizhou-Cloud Big Data Industry Development Co., Ltd. Purchase verification uses Apple services, and the membership-code service uses Alibaba Cloud infrastructure as described in section 1.6. These providers process information needed for the corresponding service. We do not sell personal information or integrate third-party analytics or advertising SDKs. When you share an exported file or calendar, its contents become available to the recipients you choose.
5. Your Rights
5.1 Access and correction: You may view, edit, or delete the student, course, and financial data you entered at any time within the Software.
5.2 Export, withdrawal and deletion: You may export a JSON backup at any time. You may pause iCloud Sync in the Software, but pausing does not delete local or cloud data. Clear All Data removes local business data after first creating a safety backup and pausing sync; it does not delete synchronized records or backup files already in iCloud. The iCloud Sync page provides a separate permanent deletion control for synchronized records. iCloud Drive backup files can be deleted separately from iCloud Backup.
5.3 Permission management: You may manage the permissions the Software uses in iOS system settings.
5.4 Membership and support requests: contact melostudio26@gmail.com to request access, correction, or deletion of membership-service information. Provide the membership code or relevant purchase reference where available; do not send passwords or full payment-card details. We may ask for the information necessary to verify the purchase relationship. We will explain the result and any effect on code restoration. To stop Apple Calendar sync, use its management menu; manage existing events separately in Apple Calendar as described in section 1.5.
6. Protection of Minors
Minors should use the app with guardian guidance. Before entering or sharing student information, teachers must provide necessary notices and have lawful authority. Processing children's personal information requires applicable parental consent and safeguards; do not process it through connections before those requirements are met. Teacher confirmation or agreement to sign-in terms is not verification of parental consent. The app does not require users to enter their age or provide identity or guardian-relationship verification. Guardians can contact the policy email to request access, correction, cessation of processing or deletion; we verify necessary representative authority before responding.
7. Updates to this Privacy Policy
We may update this Policy in line with product or legal changes. Updates will be published in the Software and on our website with a new version and date. Where a change requires notice or consent, we will provide it as applicable.
8. Contact Us
If you have any questions, comments, or complaints about this Privacy Policy, you may contact the developer via:
- Email: melostudio26@gmail.com
- Developer / data controller: Zhen Xiyuan
We will reply within a reasonable time.