Privacy Policy · 隐私政策

你的内容,
首先属于你。

Cove 是一款本地优先的笔记应用。我们不经营广告、分析或用户画像系统,也没有用于读取你笔记内容的自建服务器。本政策说明可选的 iCloud 与外部服务在何时会处理数据。

生效日期:2026 年 8 月 7 日 版本:1.0 适用于:Cove macOS
本地优先 笔记、附件和备份默认保存在你的 Mac 或你明确选择的位置。
没有追踪 不接入广告、第三方分析、跨应用追踪或自建遥测服务。
功能才联网 只有 iCloud 同步、天气、图书来源和链接预览等明确功能需要联网。

1. 适用范围与责任主体

本政策适用于 Mac App Store 提供的 Cove macOS 应用。Cove 的个人信息处理者为 App Store 产品页面所列的开发者(下称“我们”)。

Cove 不要求注册 Cove 账号。若你选择使用 Apple iCloud、微信读书或其他第三方服务,你与相应服务提供者之间的数据处理还受其独立政策约束。

2. 我们如何处理数据

“处理”包括在设备上读取、保存、整理、加密、删除,以及为完成你请求的功能而传输。下列项目按实际代码中的功能列出。

笔记、日记、任务、标签与附件

这些内容默认保存在你的 Mac 应用容器、应用支持目录,或你通过系统文件选择器明确指定的笔记库位置。Cove 不会把这些内容上传到我们自建的服务器。

你可以粘贴文本、图片或文件;剪贴板只在你执行粘贴等相关操作时由应用读取,内容不会因剪贴板访问而发送给我们。

iCloud 同步与偏好设置

当你在设置中开启同步时,笔记、目录、附件和删除状态会通过 Apple CloudKit 写入你 iCloud 账户下的 Cove 私有数据库,用于多设备同步。Cove 开发者不运营承载这些数据的服务器。

界面语言、部分视图偏好、标签设置等有限配置可能通过 Apple 的 iCloud 键值存储同步。内容锁定使用的主密钥可能通过 iCloud 钥匙串同步,以便你的设备解密已锁定内容。

被你锁定的条目或内容块会在持久化和同步前由设备端使用 Apple CryptoKit 加密;未锁定内容不会因此自动获得端到端加密。CloudKit 与 iCloud 的底层保护以 Apple 的服务设置和政策为准。

位置、地点与天气

只有当你主动获取当前位置或天气,并同意 macOS 的定位授权后,Cove 才会请求位置。应用以城市级精度为目标,但系统返回的经纬度仍可能较精确。

经纬度会交给 Apple 的地理编码服务生成地点名称。你请求日记当天的天气时,Cove 会把经纬度和该日期交给 Apple Weather(通过 WeatherKit),并将返回的状况转换为晴、雨、雪等粗粒度标签;不保存温度、降水量或完整天气响应。

Apple 说明,WeatherKit 仅使用位置信息提供天气,不把它与个人身份信息关联,也不会在不同请求之间追踪。地点、经纬度和粗粒度天气标签可被保存到相应日记,并在你开启 iCloud 同步后随日记同步。

你可以拒绝或随后撤销定位权限;手动填写地点、手动选择天气以及其他笔记功能仍可使用。

图书搜索与微信读书连接

使用 Google Books 搜索时,搜索关键词会发送给 Google Books。Cove 不会在该流程中登录你的 Google 账号。

当你主动连接微信读书后,Cove 会把你提供的 API Key 保存在 macOS 钥匙串,并随请求发送给微信读书网关;书籍 ID、搜索关键词等请求参数也会发送。应用会读取并在本机缓存你的书架、书单、阅读进度和划线。Cove 中手写的笔记不会上传给微信读书。

断开连接会停止后续请求并删除 Cove 本地保存的凭证,但不会删除腾讯已持有的微信读书账户数据,也不会自动删除已经导入到 Cove 的内容。

链接预览与远程图片

当笔记包含网页链接并生成预览时,Cove 会直接访问该网址以读取标题、描述、图标和预览图片。打开远程图片时,应用会访问图片所在服务器或内容分发网络并在本机建立缓存。

相应网站通常能看到请求的 URL、IP 地址、时间和常规网络信息,其处理方式由该网站自己的政策决定。请勿在不希望访问的地址中嵌入敏感令牌。

备份、导入、导出与诊断

Cove 会在本地创建可验证备份。你可以通过系统选择器指定笔记库、备份和导出位置;应用仅保留访问这些位置所需的安全书签和路径信息。

Cove 没有自动上传崩溃日志、性能数据或使用统计的功能。若你主动通过邮件或 App Store 支持渠道联系我们,你选择提交的邮件地址、问题描述和附件会用于处理该次支持请求。

不用于广告或画像:上述数据不会被 Cove 用于第三方广告、开发者广告营销、数据经纪、跨应用追踪或建立用户画像。

3. 外部服务

下列服务只用于提供对应功能。它们可能根据各自政策记录请求、IP 地址或账户活动;保留期限与权利请求由相应提供者负责。

Apple

CloudKit、iCloud 键值存储、iCloud 钥匙串、定位、地理编码,以及通过 WeatherKit 提供的 Apple Weather。

Google Books

接收图书搜索关键词并返回书目资料与封面链接。

Google Books 隐私说明
微信读书(腾讯)

在你连接后处理 API Key、搜索、书架、阅读进度与划线请求。

微信读书隐私政策

Cove 使用的 GRDB 与 Highlightr 开源组件在应用内本地运行,本身不构成向其开发者传输你的内容。

4. 存储、安全与保留

本地数据

本地内容会一直保留,直到你删除内容、清空回收站、删除备份,或卸载应用并移除其数据。默认情况下,回收站中超过 30 天的条目可被自动清理;你可以在应用内关闭自动清理。备份按应用显示的轮换规则保留,也可由你直接管理。

云端数据

iCloud 数据的保存、恢复和最终删除由 Apple 及你的 iCloud 设置控制。关闭 Cove 的应用内同步会停止新的 CloudKit 同步,但不等同于立即删除已存于 iCloud 的记录。你可以通过系统 iCloud 存储管理删除相应数据。

安全措施

Mac App Store 构建启用 App Sandbox 与 Hardened Runtime;外部网络请求使用 HTTPS;微信读书凭证保存在 macOS 钥匙串;自定义目录通过系统文件选择器和安全作用域书签授权。任何技术措施都无法保证绝对安全,请同时保护好你的 Mac、iCloud 账户、内容锁定密码和第三方凭证。

5. 你的选择与权利

  • 位置:在“系统设置 → 隐私与安全性 → 定位服务”中撤销 Cove 权限。
  • iCloud:在 Cove 设置中关闭笔记同步;在 macOS 的 iCloud 设置中管理 Cove 的 iCloud 访问和存储。
  • 微信读书:在 Cove 设置中断开连接并删除本地凭证;微信读书账户中的数据应通过腾讯提供的渠道管理。
  • 本地内容:在应用内删除或清空回收站,并按需删除本地备份、导出文件和缓存。
  • 查阅、更正、删除或投诉:对于 Cove 开发者实际持有的支持通信等信息,可通过本政策末尾的联系方式提出请求。

由于我们没有 Cove 账号或集中式内容服务器,通常无法通过邮箱替你定位、导出或删除存放在你设备或个人 iCloud 账户中的笔记;这些操作需要由你在对应设备或 Apple 设置中完成。

6. 未成年人

Cove 是通用生产力工具,并非专门面向儿童设计。我们不会基于年龄投放广告,也不会有意通过自建服务收集未成年人的个人信息。未成年人应在监护人指导下使用需要位置、iCloud 或第三方账户的功能。

7. 跨境处理

取决于你的所在地和所选功能,数据可能由不同地区的服务提供者处理:Apple 按你的账户与服务区域提供 iCloud、系统服务和 Apple Weather;Google 提供全球服务;微信读书由中国境内的腾讯实体提供。

在使用相应可选功能前,请阅读提供者的政策并评估是否同意相关处理。若适用法律要求单独同意、告知或其他跨境手续,应以届时实际发行主体、服务部署和上架地区为准。

8. 政策变更与联系我们

当应用的数据处理方式发生实质变化时,我们会更新本政策、生效日期,并在适当情况下通过应用更新说明或界面提示告知。不会把已取得的数据在未告知的情况下改作与原目的不相容的用途。

隐私问题与权利请求

请发送邮件至 skyeanything@gmail.com,主题注明“Cove Privacy / Cove 隐私”。我们会在适用法律要求的期限内处理。

Privacy Policy · Cove

Your words belong to you first.

Cove is a local-first notes app. We do not operate advertising, analytics, profiling, or developer-hosted servers that read your notes. This policy explains when optional iCloud and external features process data.

Effective: August 7, 2026 Version 1.0 Applies to Cove for macOS
Local first Notes, attachments, and backups stay on your Mac or in a location you choose.
No tracking No ads, third-party analytics, cross-app tracking, or developer telemetry.
Network by feature iCloud, weather, book sources, and link previews connect only to do their stated jobs.

1. Scope and controller

This policy applies to the Cove macOS app distributed through the Mac App Store. The data controller is the developer identified on Cove’s App Store product page (“we,” “us,” or “the Cove developer”).

Cove does not require a Cove account. If you choose Apple iCloud, WeRead, or another external service, that provider separately processes data under its own policy.

2. How data is handled

“Process” includes reading, storing, organizing, encrypting, and deleting data on your device, and transmitting only what is needed to complete a feature you request.

Notes, diary entries, tasks, tags, and attachments

These stay by default in the app’s container, Application Support, or a library location you explicitly choose with the system file picker. Cove does not upload them to a server operated by us.

You may paste text, images, or files. Cove reads the pasteboard when you perform a relevant action such as Paste; pasteboard access itself does not send its contents to us.

iCloud sync and preferences

If you enable sync in Cove, notes, folders, attachments, and deletion state are stored through Apple CloudKit in Cove’s private database within your iCloud account. The Cove developer does not operate the server that hosts this data.

Limited preferences such as language, view settings, and tag options may sync using Apple’s iCloud key-value store. A master key used for Cove’s content-lock feature may sync through iCloud Keychain so your devices can decrypt locked content.

Entries or blocks you lock are encrypted on device with Apple CryptoKit before persistence and sync. Content you have not locked does not automatically gain end-to-end encryption from this feature. CloudKit and iCloud protections depend on Apple’s service and your account settings.

Location, place names, and weather

Cove requests location only when you ask for your current place or weather and grant the macOS permission. The app targets city-level accuracy, but the coordinates returned by the system can still be more precise.

Coordinates are given to Apple geocoding to produce a place name. When you request weather for a diary day, Cove gives Apple Weather, through WeatherKit, the coordinates and requested date, then converts the returned condition into a broad tag such as clear, rain, or snow. Cove does not store temperature, precipitation amounts, or the full weather response.

Apple states that WeatherKit uses location information only to provide weather, does not associate it with personally identifiable information, and does not track it between requests. A place, coordinates, and broad weather tag may be saved in the relevant diary entry and included in iCloud sync if you enable it.

You can refuse or later revoke location access. Manual place and weather entry, and the rest of Cove’s notes features, remain available.

Book search and WeRead connection

When Google Books is the selected source, Cove sends your book-search terms to Google Books. Cove does not sign you in to a Google account.

If you connect WeRead, Cove stores the API key you provide in the macOS Keychain and sends it to the WeRead gateway with requests. Book IDs, search terms, and similar request parameters are also sent. Cove receives and locally caches your shelf, lists, reading progress, and highlights. Notes you write in Cove are not uploaded to WeRead.

Disconnecting stops future requests and removes Cove’s local credential. It does not delete account data already held by Tencent or content already imported into Cove.

Link previews and remote images

To create a preview for a link in a note, Cove directly visits the URL to retrieve its title, description, icon, and preview image. To show a remote image, Cove contacts its host or content-delivery network and keeps a local cache.

The destination can normally see the requested URL, IP address, time, and standard network information. Its own policy controls that processing. Avoid embedding sensitive tokens in URLs you do not want contacted.

Backups, import, export, and diagnostics

Cove creates verified backups locally. You can choose library, backup, and export locations using system pickers; Cove retains only the path information and security-scoped bookmarks needed to use those locations.

Cove does not automatically upload crash reports, performance measurements, or usage analytics. If you contact us by email or through App Store support, we use the address, message, and attachments you choose to provide to respond to that request.

Never for advertising or profiling: Cove does not use the data above for third-party ads, developer advertising or marketing, data brokerage, cross-app tracking, or user profiles.

3. External services

Each provider is contacted only for the corresponding feature. Providers may record requests, IP addresses, or account activity under their own policies and are responsible for their retention periods and rights-request channels.

Apple

CloudKit, iCloud key-value storage, iCloud Keychain, location, geocoding, and Apple Weather through WeatherKit.

Google Books

Receives book-search terms and returns metadata and cover links.

Google Books Privacy
WeRead (Tencent)

Processes the API key, searches, shelf, progress, and highlight requests after you connect.

WeRead Privacy Policy

The open-source GRDB and Highlightr components used by Cove run locally in the app. Their inclusion does not itself transmit your content to their developers.

4. Storage, security, and retention

Local data

Local content remains until you delete it, empty Trash, remove backups, or uninstall Cove and remove its data. By default, items older than 30 days can be removed from Trash automatically; you can disable automatic removal. Backups follow the rotation shown by Cove and can also be managed directly by you.

Cloud data

Apple and your iCloud settings control the retention, recovery, and final deletion of iCloud data. Turning off Cove’s in-app sync stops new CloudKit synchronization; it does not by itself immediately delete records already stored in iCloud. You can manage the corresponding storage through system iCloud settings.

Security measures

The Mac App Store build enables App Sandbox and Hardened Runtime. External requests use HTTPS. WeRead credentials use the macOS Keychain. Custom folders use system pickers and security-scoped bookmarks. No technical measure can guarantee absolute security, so protect your Mac, iCloud account, content-lock password, and external credentials as well.

5. Your choices and rights

  • Location: revoke Cove’s access in System Settings → Privacy & Security → Location Services.
  • iCloud: disable notes sync in Cove; manage Cove’s iCloud access and storage in macOS iCloud settings.
  • WeRead: disconnect in Cove to remove the local credential; use Tencent’s channels to manage data in your WeRead account.
  • Local content: delete items or empty Trash in Cove, and remove local backups, exports, or caches when desired.
  • Access, correction, deletion, or complaints: contact us below about support communications or other information the Cove developer actually holds.

Because we do not operate Cove accounts or a centralized content server, we generally cannot locate, export, or delete by email the notes held on your Mac or in your personal iCloud account. Those actions need to be completed on your devices or through Apple’s settings.

6. Children

Cove is a general productivity tool and is not directed specifically to children. We do not serve age-based advertising or knowingly collect children’s personal information through a developer-hosted service. Minors should use features involving location, iCloud, or external accounts with a guardian’s guidance.

7. International processing

Depending on where you are and which features you choose, providers in different regions may process data. Apple provides iCloud, system services, and Apple Weather according to your account and service region; Google provides global services; and WeRead is provided by a Tencent entity in mainland China.

Review a provider’s policy before using the related optional feature. Any separate consent, notice, or transfer mechanism required by applicable law depends on the actual publishing entity, service deployment, and storefront at release.

8. Policy changes and contact

If Cove’s data practices materially change, we will update this policy and its effective date and, where appropriate, notify you in release notes or the app. We will not silently repurpose previously obtained data for an incompatible use.

Privacy questions and rights requests

Email skyeanything@gmail.com with “Cove Privacy” in the subject. We will respond within the timeframe required by applicable law.