English 中文

NextDo Privacy Policy

Last updated: 2026-10-10 · Developer: rongcai · Contact: micarfield@gmail.com

NextDo (“the App”) is a free, single-user iOS productivity app with three tabs — 今天 (Today), 统计 (Stats), and 设置 (Settings). Today has two modes: Zen, which recommends one task based on your current energy, and a regular checklist. There is no account, no sign-in, no ads, no in-app purchases, and no third-party analytics, tracking, or crash-reporting SDKs.

Most of what the App does happens entirely on your device. The App also offers optional AI features that, depending on your device and a setting you control, may send limited text to the developer's own server to generate a result. This policy explains exactly what is stored locally, what the voice and AI features do, and when (if ever) anything leaves your device.

1. What the App stores locally

The SwiftData store lives in a shared App Group container (group.com.rongcai.NextDo) so the iOS Home Screen widget can read the same task list on the same device. The App Group is a local container shared only between NextDo and the NextDo widget — it does not leave your device.

You can delete completed tasks at any time from Settings → 数据管理. Deleting the App removes every byte listed above.

2. Voice capture and speech recognition

If you use voice capture, the App requests access to the microphone and uses Apple's Speech framework (SFSpeechRecognizer) to turn your speech into text. On devices that support on-device speech recognition, the App requires on-device recognition, so your audio never leaves the device. On devices that don't support on-device recognition, Apple's speech recognition service processes the audio instead, under Apple's own privacy policy. NextDo itself never stores or uploads the audio. The relevant system permissions are NSMicrophoneUsageDescription and NSSpeechRecognitionUsageDescription.

3. AI features and network behaviour

NextDo uses AI for two things: splitting spoken or typed text into separate todos, and picking which task to suggest in Zen mode. The App tries each option in order and stops at the first one that is available:

  1. On-device (preferred). When Apple's on-device Foundation Models (Apple Intelligence) are available on your device, processing happens entirely on-device. Nothing leaves your device.
  2. Developer's cloud AI (optional, your choice). If on-device AI is not available, and the Settings toggle “允许云端 AI” (Allow cloud AI, on by default) is enabled, the App sends the text of what you said or typed (for splitting into todos), or your task titles, energy tags, and deadlines (for picking a Zen recommendation), together with the current time and locale, over HTTPS to the developer's own Cloudflare Worker (nextdo-ai.micarfield.workers.dev), which runs Cloudflare Workers AI. The Worker processes the request in memory and returns a result; it does not log, store, or retain the content of your request, has no database or KV storage attached, and has observability logging disabled. No account, device identifier, or other identifying information is sent with the request — only a fixed app key header used to authorize calls to the Worker. Cloudflare acts purely as the infrastructure provider that runs this Worker; see Cloudflare's privacy policy at https://www.cloudflare.com/privacypolicy/.
  3. On-device fallback. If cloud AI is turned off or unreachable, a built-in rule-based splitter runs the task entirely on your device instead.

Turning the “允许云端 AI” toggle off means no task content is ever sent off your device for any reason — the App will only use on-device AI or the on-device rule-based fallback.

The only other outgoing link the App produces is a mailto: URL: when you tap Settings → 反馈这个推荐准不准 the system Mail composer opens with a pre-filled subject and body addressed to micarfield@gmail.com. You can edit or cancel the draft before sending. Nothing is transmitted unless you tap Send in Mail.

4. What the App does NOT do

5. Permissions the App may request

NextDo may request microphone and speech recognition access for voice capture (see Section 2). It does not request location, camera, photo library, contacts, calendar, reminders, health, motion, notifications, or Bluetooth. The only other system feature it asks the OS for is the App Group container described above (granted automatically by the entitlement).

6. App Store privacy label

NextDo's App Store privacy label is “Data Not Collected.” When the optional cloud AI fallback is used, task-related text is sent to the developer's Cloudflare Worker only to generate the requested result, is processed transiently in memory, and is not stored, linked to you, or used for tracking or advertising — so it does not count as “collection” under Apple's definitions.

7. Children's privacy

The App is rated 4+ in the App Store. We do not knowingly collect any personal information from anyone, including children.

8. Data retention and deletion

All task data lives on your device. To delete it: use the 清除已完成任务 action in Settings → 数据管理, or delete the App entirely. iOS removes the local sandbox and the App Group container together with the App. When cloud AI is used, the text sent to the Cloudflare Worker is processed in memory and discarded immediately after the response is returned — it is not retained on the server.

Because we hold no persistent user data on any server, there is nothing for you to request from us under GDPR, CCPA, or similar regimes. For questions, write to the contact email above.

9. Changes to this policy

If the App's data practices change in a future release, this page will be updated and the “Last updated” date above will change. Material changes will also be noted in the App Store “What's New” text for that release.


NextDo 隐私政策(中文版)

更新日期:2026-10-10 · 开发者:rongcai · 联系邮箱:micarfield@gmail.com

NextDo 是一个免费的单机 iOS 效率工具,包含三个标签页: 今天、统计、设置。 「今天」页有两种模式:Zen(根据你当前的精力推荐一个 任务)和普通的清单模式。App 没有账号、不需要登录、 没有广告,也不集成任何第三方分析、追踪或崩溃上报 SDK。

App 的大部分功能完全在你的设备本地完成。App 还提供可选的 AI 功能, 根据你的设备情况和你自己设置的开关,可能会把有限的文本发送到开发者 自建的服务器以生成结果。本政策详细说明本地保存了什么、语音与 AI 功能 具体做了什么,以及在什么情况下(如果有)数据会离开你的设备。

1. 本地保存的数据

SwiftData 存储位于 App Group 共享容器 (group.com.rongcai.NextDo),用于让 iOS 主屏 小组件在同一设备上读取同一份任务列表。该容器只在本机 的 NextDo 主 App 与其小组件之间共享,不会离开你的设备。

你可以随时在「设置 → 数据管理」里删除已完成任务。卸载 App 即可 彻底清除上述全部数据。

2. 语音输入与语音识别

如果你使用语音输入,App 会请求麦克风权限,并使用 Apple 的语音识别框架(SFSpeechRecognizer) 把你说的话转成文字。在支持本机语音识别的设备上, App 会强制要求使用本机识别,音频不会离开设备。在不支持本机识别的设备 上,则由 Apple 自己的语音识别服务处理音频,遵循 Apple 自身的隐私政策。 NextDo 本身不会存储或上传这段音频。涉及的系统权限是 NSMicrophoneUsageDescription 和 NSSpeechRecognitionUsageDescription。

3. AI 功能与联网行为

NextDo 在两个场景使用 AI:把你说的或打的一段话拆分成多条待办,以及 在 Zen 模式里挑选要推荐的任务。App 会按以下顺序依次尝试,一旦有可用的 就停止:

  1. 本机 AI(优先)。当你的设备支持 Apple 的本机 Foundation Models(Apple Intelligence)时,处理完全在设备本地完成, 不会有任何内容离开你的设备。
  2. 开发者的云端 AI(可选,由你决定)。如果本机 AI 不可用,且「设置」里的「允许云端 AI」开关(默认开启)处于开启状态, App 会把你说的或打的文字(用于拆分待办),或者你的任务标题、精力 标签、截止时间(用于挑选 Zen 推荐),连同当前时间与语言区域,通过 HTTPS 发送到开发者自己的 Cloudflare Worker (nextdo-ai.micarfield.workers.dev),由它调用 Cloudflare Workers AI 处理。该 Worker 只在内存中处理这次请求并返回 结果,不记录、不保存、不留存请求内容,没有连接任何数据库或 KV 存储,也关闭了可观测性日志。请求中不会附带账号、设备标识或其他 身份信息——只有一个用于鉴权调用的固定 App key。Cloudflare 在这里 只是运行该 Worker 的基础设施提供方,其隐私政策见 https://www.cloudflare.com/privacypolicy/。
  3. 本机兜底方案。如果云端 AI 被关闭或无法访问, App 会改用内置的、完全在设备本地运行的规则拆分逻辑。

关闭「允许云端 AI」开关意味着任何任务内容都不会以任何理由离开你的 设备——App 只会使用本机 AI 或本机的规则兜底方案。

App 产生的另一个(也是唯一的)对外链接是 mailto::在 「设置 → 反馈这个推荐准不准」处点击会调起系统邮件,预填好主题与正文, 收件人是 micarfield@gmail.com。你可以在邮件 App 里修改或 取消该草稿——只有在你按下「发送」之后才会真正发出。

4. 我们不做的事

5. 权限

为了支持语音输入,NextDo 可能会请求麦克风和 语音识别权限(见第 2 节)。它不会 请求位置、相机、相册、通讯录、日历、提醒事项、健康、运动、通知、蓝牙 等权限。它向系统申请的另一项只是上述 App Group 容器(由 entitlement 自动授予)。

6. App Store 隐私标签

NextDo 在 App Store 上的隐私标签是「不收集数据」(Data Not Collected)。在使用可选的云端 AI 兜底方案时,与任务相关的文本 只会被发送到开发者的 Cloudflare Worker 用于生成当次请求的结果,处理 过程只在内存中短暂进行,不会被存储、不会与你的身份关联,也不会用于 追踪或广告——因此按 Apple 的定义,这不构成「收集」。

7. 儿童隐私

App Store 评级为 4+。我们不会知情地收集任何人(包括儿童)的个人 信息。

8. 数据保留与删除

所有任务数据都保存在你的设备上。删除方式:在「设置 → 数据管理」 里使用清除已完成任务,或直接卸载 App——iOS 会一并 删除沙盒与 App Group 容器。使用云端 AI 时,发送给 Cloudflare Worker 的文本只在内存中处理,返回结果后即被丢弃,不会留存在服务器上。

因为我们没有在任何服务器上保存持久的用户数据,所以 GDPR / CCPA 等法规所规定的可向我们提出的请求并不适用。如有疑问,请发邮件至上方 邮箱。

9. 政策更新

未来版本若改变数据使用方式,本页面会更新,「更新日期」也会同步 刷新;重大变化会在该版本的 App Store「新内容」中一并注明。