练境LENJO
中/EN

LEGAL / PRIVACY · 01

隐私政策

数据尽量留在设备上。发送什么、为什么发送、如何删除,在这里完整说明。

隐私政策 01 支持与联系 02 使用条款 03

CURRENT VERSION

2026-08-22

CONTACT

KmTech2026@outlook.com

练境 / Lenjo 隐私政策

最近更新日期:2026 年 9 月 8 日

感谢你使用练境 / Lenjo(以下简称“本应用”),一款健身教练与训练记录工具。我们非常重视你的隐私。本政策说明我们处理哪些信息、如何使用、与谁共享,以及你拥有的权利。

一、我们处理的数据

本应用以“数据尽量留在你设备上”为原则设计。

  • 健康与健身数据(Apple 健康 / HealthKit):在你明确授权后,读取体重、心率、HRV、睡眠、血氧、活动能量、步数等,仅用于应用内训练负荷与恢复分析、趋势展示。绝不用于广告,绝不出售或共享给第三方用于营销。
  • 你主动录入的数据:体重、训练日志、饮食记录、与 AI 教练的对话,默认存储在设备本地。
  • 照片:食物照片用于 AI 分析热量与营养;体测报告照片用于提取身体成分数据;训练器械照片用于识别器械并匹配动作库。照片存储在本地,使用对应功能时发送至 AI 服务商。
  • 购买信息:订阅通过 Apple App Store 处理。为校验和观测订阅生命周期,本应用会将 Apple 签名的购买凭证、商品与交易状态,以及不包含姓名或邮箱的随机 App 用户 ID 发送给订阅管理服务商 RevenueCat。我们不收集支付卡信息。
  • 账号、设备与用量元数据:使用 Sign in with Apple 时,本应用会把 Apple 的一次性 authorization code 和 Apple 账号标识发送给我们的服务器;服务器换取 refresh token 后仅以加密形式保存,用于删除账号时撤销 Lenjo 的 Apple 登录授权。AI 请求还会附带请求 ID、设备 ID、账号标识(如存在)、国家/市场、App 版本、用量、延迟和错误等元数据,用于 App 功能、订阅权益、防滥用、限流、成本控制和服务稳定性。
  • 使用情况分析(适用于提供该功能的版本):经你同意,我们会收集功能使用、性能及购买结果等信息,用于改进产品体验。分析事件不包含聊天正文、照片或具体健康数据。此功能默认关闭,你可在「我的」中开启或关闭;关闭后停止采集并清除本机待上传记录。
  • 意见反馈:你主动提交意见反馈时,反馈正文、选填联系方式、App 与系统版本及设备型号会发送至所选区域的反馈服务器,用于排查问题和回复。服务器加密保留正文 30 天,并经 Cloudflare 邮件服务转发至作者的 Outlook 邮箱;邮件副本及服务器备份不随在线正文到期自动删除。如需删除反馈,请通过下方邮箱联系作者。

我们不收集精确位置、通讯录、广告标识符,也不进行跨 App 跟踪。

二、数据发送给第三方服务

首次使用 AI 功能前,本应用会单独说明并请求你的同意。只有在你主动发送消息、请求分析或选择照片后,相应内容才会被发送处理:

  • AI 对话:你发送的对话内容以及必要的训练/健康摘要,会通过我们的服务器安全地发送给第三方大模型服务处理,用于生成教练回复。
  • 图片识别:你主动选择的食物、体测报告或器械照片,会通过我们的区域网关发送给第三方视觉模型服务。当前主服务为 DeepSeek 官方视觉 API;发生超时、限流、服务错误或响应异常时,会切换至阿里云百炼 DashScope。DeepSeek 官方服务会在中国大陆处理和存储提交内容;DashScope 兜底按版本分别使用北京或新加坡地域。
  • 训练同步(仅中国大陆市场可选功能,如启用):与“训记”App 接口交互,使用你自己的训记账号凭证。海外版本不提供该入口。
  • 订阅管理:Apple 签名的购买凭证、商品 ID、交易时间与订阅状态,以及随机 App 用户 ID 会发送给 RevenueCat,用于订阅校验、续费 / 到期 / 退款事件和汇总分析。RevenueCat 不会收到健康数据、训练记录、AI 对话、照片、Apple 登录标识、姓名或邮箱。

中国大陆版本的 AI 对话和图片识别均在境内处理,且相关服务已完成生成式人工智能服务备案。海外版本的 AI 对话继续由境外服务处理;图片识别使用 DeepSeek 官方 API 时,所选照片会跨境传输至中国大陆处理和存储,千问兜底使用阿里云 DashScope 新加坡地域。我们仅发送实现该功能所必需的内容。Apple 健康授权本身不等于同意把健康摘要发送给 AI 服务;发送前仍以 App 内的 AI 处理说明和你的单独确认作为前提。如未来发生处理地点或服务商的实质变化,我们会先更新本政策,并依法另行告知、取得同意或履行适用的合规程序。

三、数据存储与安全

使用分析通过随机安装标识关联,按你选择的国内或海外区域保存,不用于广告或跨 App 追踪。

你的健康数据、记录、对话、照片主要存储在设备本地;访问凭证保存在系统钥匙串(Keychain)。你选择 Apple 登录后,我们的服务器会加密保存 Apple refresh token,且仅用于删除账号时撤销 Lenjo 的 Apple 登录授权。我们采取合理措施保护数据,包括 HTTPS 传输和服务端访问控制,但互联网传输无法保证绝对安全。

四、数据保留与删除

使用分析的本机待上传记录最多保留 7 天,服务器原始事件在满 90 天后由定时任务清理,通常在一小时内完成,停机时顺延。关闭开关不会删除已上传数据;删除账号时会清除当前设备安装的分析记录。首次观察记录保留至该安装删除,必要的去标识化防重放标记继续保留。其他设备的数据可联系我们申请处理。

本地数据在你删除记录、使用 App 内账号删除流程或卸载应用时移除。App 内账号删除会删除服务器上关联的用量明细和加密的 Apple 撤销凭证;如已绑定 Apple 登录,还会撤销 Lenjo 的 Apple 登录授权,并清除本机账号身份、本地用量计数、诊断日志和重置服务器侧设备 ID。为防止通过重复删除账号或轮换设备 ID 重复领取免费或订阅额度,我们的服务器会继续保留不可逆哈希后的额度领取/计数记录;这些记录不包含原始 Apple 账号 ID、原始设备 ID、对话或照片内容,仅在防滥用和执行额度所需范围内使用。删除账号后,本应用会轮换后续发送给 RevenueCat 的随机 App 用户 ID;既有 Apple 交易记录可能由 Apple 和 RevenueCat 在履行订阅、退款、财务和适用法律义务所需期限内保留。其他服务器用量与错误元数据仅在实现订阅权益、限流、防滥用、安全审计、成本控制和服务稳定性所必需的期限内保留;不再需要时删除或匿名化。删除账号不会自动取消 App Store 订阅;你可以在 App Store 或系统设置中管理或取消订阅。你可随时在“设置 → 隐私与安全性 → 健康”撤销健康数据授权。发送给第三方的数据还受对应服务商政策约束;RevenueCat 隐私政策见 revenuecat.com/privacy。

五、儿童隐私

本应用不面向不满 14 周岁的中国大陆未成年人。未取得父母或其他监护人的有效同意前,请勿使用需要向 AI 服务发送健康、训练、对话或照片数据的功能。如果我们发现未经监护人同意处理了不满 14 周岁未成年人的个人信息,将停止相关处理并依法删除。其他国家或地区按当地适用的最低年龄和监护人同意规则执行。

六、你的权利

你可以访问、复制、更正或删除自己的数据,撤回健康授权或 AI 处理同意,注销账户,并对个人信息处理规则提出解释说明请求。撤回同意不影响撤回前基于同意已经进行的处理。大部分数据可直接在 App 内管理;如需限制处理、请求人工协助或投诉,请联系下方邮箱。我们会在适用法律规定的期限内核验身份并处理请求。

七、政策变更

我们可能不时更新本政策,重大变更将在应用内或本页面公示。

八、中国大陆备案与联系我们

开发者及个人信息处理者:KM
APP 备案号:沪ICP备2026013857号-2A
邮箱:KmTech2026@outlook.com
隐私政策 URL:https://lenjoapp.com/privacy

Lenjo 在 Apple App Store 中的开发者和交易主体以商店产品页与购买页面显示的信息为准。


Lenjo Privacy Policy (English)

Last updated: September 8, 2026

Thank you for using Lenjo (“练境” in Simplified Chinese), a fitness coaching and training-log tool. We respect your privacy.

1. Data We Process

  • Health & fitness (HealthKit): with your permission, weight, heart rate, HRV, sleep, blood oxygen, active energy, steps — used only for in-app training/recovery analysis and trends. Never used for ads; never sold or shared for marketing.
  • Data you enter: weight, training logs, meals, AI coach conversations — stored locally by default.
  • Photos: meal photos are analyzed for calories/nutrition; body assessment photos extract body-composition data; gym equipment photos identify equipment and match the exercise library. Photos are stored locally and sent to an AI provider when you use the feature.
  • Purchase info: subscriptions are handled by Apple. The App sends Apple-signed purchase data, product and transaction status, and a random App User ID containing no name or email to RevenueCat for subscription management. We do not collect payment card data.
  • Account, device, and usage metadata: With Sign in with Apple, the App sends Apple's one-time authorization code and Apple account identifier to our servers. The resulting refresh token is stored encrypted at rest solely to revoke Lenjo's Apple authorization during account deletion. AI requests also include request ID, device ID, account identifier when present, country/market, App version, usage, latency, and error metadata for App functionality, subscription entitlement, abuse prevention, rate limits, cost control, and service reliability.
  • Usage analytics (in versions offering this feature): With your consent, we collect information about feature usage, performance and purchase outcomes to improve the App. Analytics events do not include conversation text, photos or specific health data. This feature is off by default and can be enabled or disabled in My. Disabling it stops collection and clears pending records on your device.
  • Feedback: When you submit feedback, the message, optional contact details, app and OS versions, and device model are sent to the feedback server in your selected region to investigate and respond. The server retains the encrypted message for 30 days and forwards it through Cloudflare email services to the developer’s Outlook inbox. Email copies and server backups are not automatically deleted when the online message expires. Contact the developer at the email below to request deletion.

We do not collect precise location, contacts, or advertising identifiers, and do not track you across apps.

2. Data Sent to Third-Party Services

Before the first AI request, the App separately explains the processing and asks for your consent. Data is sent only after you submit a message, request an analysis, or select photos.

  • AI chat: the messages you send, together with necessary training/health summaries, are securely transmitted through our servers to third-party large-model services to generate coach replies.
  • Image recognition: meal, body-assessment, or equipment photos you actively select are sent through our regional gateway to third-party vision model services. The current primary service is DeepSeek's official vision API; Alibaba Cloud Model Studio (DashScope) is used when the primary request times out, is rate-limited, encounters a service error, or returns an invalid response. DeepSeek processes and stores submitted content in Mainland China; the DashScope fallback uses Beijing or Singapore according to the App region.
  • Training sync (optional, Mainland China only, if enabled): the “Xunji” API using your own credentials. This integration is not shown in the overseas release.
  • Subscription management: Apple-signed purchase data, product ID, transaction timestamps and subscription status, plus a random App User ID are sent to RevenueCat for subscription validation, renewal / expiration / refund events, and aggregate analytics. RevenueCat does not receive health data, workouts, AI conversations, photos, Sign in with Apple identifier, name, or email.

For the Mainland China release, AI chat and image recognition are processed within Mainland China using services filed with Chinese regulators as generative AI services. Overseas AI chat continues to use services hosted outside Mainland China. When overseas image recognition uses DeepSeek's official API, selected photos are transferred to, processed, and stored in Mainland China; the Qwen fallback uses Alibaba Cloud DashScope in Singapore. Only data necessary for the feature is sent. HealthKit permission alone does not authorize disclosure of health summaries to AI services; the in-app AI processing notice and your separate confirmation are still required. Before any material change to processing location or providers, we will update this policy and provide any notice, consent, or compliance procedure required by applicable law.

3. Storage & Security

Usage analytics is associated with a random installation identifier and stored in the mainland or overseas region you select. It is not used for advertising or cross-app tracking.

Data is stored primarily on your device (local storage and Keychain). When you choose Apple sign-in, our servers store the Apple refresh token encrypted at rest solely to revoke Lenjo's authorization during account deletion. We apply reasonable safeguards, including HTTPS transport and server-side access controls, but no internet transmission is fully secure.

4. Retention & Deletion

Pending analytics records stay on-device for up to 7 days. Raw server events are removed by scheduled cleanup after 90 days, normally within one hour; downtime may delay cleanup. Disabling analytics does not erase uploaded data. Account deletion clears analytics records for the current device installation. First-observed records remain until that installation is deleted; necessary pseudonymous replay-prevention markers remain. Contact us for requests involving other devices.

Local data is removed when you delete records, use the in-app account deletion flow, or uninstall. In-app account deletion also deletes associated server-side usage details and the encrypted Apple revocation credential, revokes Lenjo's Sign in with Apple authorization when linked, clears local account identity, local usage counters and diagnostic logs, and rotates the server-side device identifier. To prevent repeated Free or subscription quota grants through account deletion or device-ID rotation, our servers retain irreversible hashed quota grant/counter records. Account deletion also rotates the random App User ID used for future RevenueCat requests. Existing Apple transaction records may be retained by Apple and RevenueCat as needed for subscription operations, refunds, financial records, and applicable legal obligations. Other server-side usage and error metadata is retained only as long as necessary for entitlements, rate limits, abuse prevention, security, cost control, and reliability, then deleted or anonymized. Account deletion does not itself cancel an App Store subscription; manage subscriptions in the App Store or system Settings. Revoke Health access anytime in Settings → Privacy & Security → Health. Data sent to service providers is governed by their policies; see RevenueCat's privacy policy.

5. Children

Lenjo is not directed to children under 13. In Mainland China, Lenjo is not directed to children under 14, and features that send health, workout, chat, or photo data to AI services must not be used without valid consent from a parent or guardian. If we learn that such data was processed without the required guardian consent, we will stop the processing and delete it as required by law.

6. Your Rights

You may access, copy, correct, or delete your data; revoke Health permissions or AI processing consent; close your account; and request an explanation of our processing rules. Withdrawal does not affect processing lawfully completed before withdrawal. Most controls are available in the App. Contact us to restrict processing, request assistance, or submit a complaint.

7. Changes

We may update this policy; material changes will be posted in-app or here.

8. Mainland China Filing and Contact

Developer and personal information processor: KM
App filing number: 沪ICP备2026013857号-2A
Email: KmTech2026@outlook.com
Privacy Policy URL: https://lenjoapp.com/privacy

The developer and seller for Apple App Store transactions remain the parties shown on the App Store product and purchase pages.

© 2026 练境 LENJO · NEXT SESSION, DECIDED.
隐私政策 支持 使用条款