Scholardo Scholardo
← 返回首页

法律条款

隐私政策

最后更新:2026 年 9 月 3 日

Scholardo 是 macOS 上的 agent 原生研究工作台,按「本地优先」原则设计。本政策说明我们如何处理你的数据——核心原则只有一句:你的资料留在你自己的机器上,我们不收集、不上传、不分析。

目录

  1. 数据存储在本地
  2. 零遥测
  3. API Key 由你自备并本地加密
  4. 我们发起的网络请求
  5. 你主动启用的第三方服务
  6. 本网站的隐私实践
  7. 数据保留与删除
  8. 未成年人
  9. 政策变更
  10. 联系我们

1. 数据存储在本地

你在 Scholardo 中产生的所有内容——文献库、PDF / EPUB / 网页、标注与高亮、笔记、会话记录、引用数据、向量索引——都仅保存在你 Mac 的本地磁盘上,默认位于用户主目录下的 ~/.scholardo/ 以及你各个项目自己的目录中,底层使用本地 SQLite(GRDB)数据库与普通文件。

这些数据不会被上传到我们的服务器,也不会同步到任何云端。我们既看不到、也无法访问你的研究内容。备份、迁移、删除完全由你掌控。

2. 零遥测

Scholardo 应用不包含任何遥测、使用统计、行为分析或崩溃数据上报。本地使用无需注册账号、无需登录。我们不追踪你打开了哪些文件、用了哪些功能、停留了多久。

3. API Key 由你自备并本地加密

Scholardo 的 AI 功能(如选区改写、订阅摘要、嵌入检索等)由你自备的第三方模型 API Key 驱动——OpenAI、Anthropic、Google Gemini、DeepSeek,或任意 OpenAI 兼容端点。核心功能(检索、标注、引用、浏览器抓取)在本地运行,无需任何 Key。

  • 本地加密存储:你填入的 API Key 保存在 macOS 钥匙串(Keychain)中,由系统加密保护,不以明文写入普通配置文件。
  • 绝不上传给我们:API Key 永远不会传输到 Scholardo 的任何服务器。
  • 请求直连提供商:当你使用 AI 功能时,请求由你的 Mac 直接发往你所配置的模型提供商,Scholardo 不充当中间代理,也不经手、不记录这些请求的内容。你与该提供商之间的数据处理,适用该提供商的隐私政策与条款。

4. 我们发起的网络请求

以下是 Scholardo 第一方向我们服务器(api.scholardo.com)发起的全部网络请求,并逐项列出各自发送的内容:

  • 许可证激活:发送激活码、你购买时使用的邮箱地址、匿名设备指纹(哈希值,绝不含硬件序列号)以及一个通用设备标签(固定为 "Mac",绝不含你的电脑名称)。之所以需要邮箱,是因为服务端要将它与购买记录比对后才签发许可。
  • 许可证刷新:定期发送激活码与同一设备指纹,使许可在你无需重新输入任何信息的情况下持续有效。
  • 免费试用:仅发送匿名设备指纹,用于保证每台机器只能获得一次试用。为防止有人不断更换指纹反复领取试用,服务端还会记录你的 IP 地址的哈希值(单向不可逆)、大致国家与最近一次访问时间。这些仅用于识别重复注册,不用于追踪你的行为,也不与你的身份或任何研究内容关联。
  • 注销设备:当你在「关于」窗口释放本机席位时,发送激活码与设备指纹。
  • 联系表单:仅当你主动在官网填写并提交「联系我们」表单时,表单内容会发送到我们的接口用于转发回复(见第 6 节)。
  • 频率限制:为防止接口被滥用,以上请求会按来源 IP 限制调用频率,为此服务端会保存你的 IP 地址与短周期内的调用次数。该记录仅用于限流,不与你的许可、试用记录或身份信息关联。

以上请求均不附带任何本地研究数据。

支付由登记商户处理,我们不接触你的银行卡信息。绝大多数国家和地区的销售由 Sold through Link, LLC(Stripe 的登记商户方案)完成;中国大陆的销售由 Armitage Labs OÜ(爱沙尼亚,注册号 16977866,即 Creem)完成——具体由哪一家,见《服务条款》第 3 节。银行卡信息在该登记商户自有的结账页面填写,绝不经过 Scholardo 的服务器;你在结账时提供的账单与税务信息,由该登记商户依其自身隐私政策、以数据控制者的身份处理。为了完成订单及后续支持,我们会从它那里获得:你购买时使用的邮箱地址、所购方案、金额与币种、订单与订阅标识,以及续费、退款或拒付的状态。上述购买记录将在许可存续期间、以及税务与会计法规要求的期限内保留。

我们与每一家登记商户就各自在支付环节中的数据处理角色均有书面约定;如你需要了解其如何处理你的个人数据,请查阅 Link 或 Creem 的隐私政策,或发邮件给我们,我们会协助你联系到正确的一方。

5. 你主动启用的第三方服务

部分功能会在你主动触发时连接第三方服务。是否使用由你决定,相关数据处理适用各自的隐私政策:

  • AI 模型 / 嵌入提供商:使用你自备的 Key,请求直连(见第 3 节)。本地 Ollama 等自托管方案则完全留在你的机器上。
  • 网页抓取:当你在内置浏览器或抓取功能中打开 / 保存网页时,会向该网址发起请求。
  • RSS 订阅:当你配置订阅源时,会拉取对应源的内容。
  • 引用样式:CSL 引用样式可能从公开样式仓库按需下载更新。
  • Hypothesis 标注同步:若你启用,会与 Hypothesis 服务通信。

6. 本网站的隐私实践

对于本营销网站(scholardo.com)本身:

  • 仅使用必要的本地存储:只记住你的主题(深 / 浅色)和语言偏好,存于浏览器 localStorage。
  • 无 Cookie、无跨站追踪:本站使用 Cloudflare Web Analytics 统计页面访问量。它不写入任何 Cookie、不读取本地存储、也不做浏览器指纹识别,无法跨站点识别你;每次访问只上报一条页面记录(页面地址、来源页、大致地理位置与设备/浏览器类型),由 Cloudflare 聚合后呈现,不保留你的 IP 地址。我们能看到的只有汇总数字,无法据此定位到具体某个人。除此之外不加载任何广告或行为分析脚本;若未来引入需要征得同意的分析工具,将仅在你明确同意后才加载。
  • 版本检查:页面会向 GitHub Releases 公共接口发起一次匿名请求,以显示最新版本与下载链接。
  • 联系表单:你提交的内容会发送到我们的接口(api.scholardo.com/contact),仅用于转发邮件给我们以便回复,不另作存储。
  • 网页字体:字体由本站自行托管,不再向 Google Fonts 或任何第三方发起请求。图标及其余静态资源同样由本站托管——页面加载过程中,你的浏览器只与本站通信。
  • 仅联系表单使用的反垃圾校验:当你打开企业咨询表单时,会加载 Cloudflare Turnstile(challenges.cloudflare.com)以确认你不是机器人。它只在你打开该表单时运行,页面加载时不会运行;Cloudflare 声明不会用它跨站点追踪用户。
  • 结账:定价按钮先经本站的 /go/checkout 跳转——它读取 Cloudflare 依你的 IP 给出的国家代码,据此把你送往对应登记商户托管的结账页面。该国家代码只用于这一次跳转,既不记录也不存储。本站不进行任何支付处理,也不加载任何支付相关脚本。

7. 数据保留与删除

因为你的研究数据从不离开你的设备,所以「删除」完全在你手中:删除项目目录或 ~/.scholardo/、或卸载应用,即可移除对应数据。我们这边没有你研究内容的副本可供保留或删除。许可记录仅包含校验授权所需的最小信息。

8. 未成年人

Scholardo 是面向研究人员的专业工具,并非面向未满 13 周岁(或你所在司法辖区规定的同等年龄)的儿童设计,我们不会有意收集其个人信息。

9. 政策变更

我们可能不时更新本政策。重大变更会更新本页顶部的「最后更新」日期;继续使用即表示你接受更新后的条款。

10. 联系我们

对本隐私政策有任何疑问,请发邮件至 support (at) scholardo.com 与我们联系。相关服务规则另见服务条款。

← Back to home

Legal

Privacy Policy

Last updated: September 3, 2026

Scholardo is the agent-native research workspace for macOS, built local-first. This policy explains how we handle your data. The principle is simple: your library stays on your own machine — we do not collect it, upload it, or analyze it.

Contents

  1. Your data is stored locally
  2. Zero telemetry
  3. API keys are yours, encrypted locally
  4. Network calls we make
  5. Third-party services you opt into
  6. This website
  7. Retention & deletion
  8. Children
  9. Changes
  10. Contact

1. Your data is stored locally

Everything you create in Scholardo — your library, PDFs / EPUBs / web pages, annotations and highlights, notes, session transcripts, citation data, and the vector index — is kept only on your Mac's local disk. By default it lives under ~/.scholardo/ in your home directory and inside each of your own project folders, stored in a local SQLite (GRDB) database and ordinary files.

This data is never uploaded to our servers and never synced to any cloud. We cannot see or access your research. Backup, migration, and deletion are entirely under your control.

2. Zero telemetry

The Scholardo app contains no telemetry, usage analytics, behavioral tracking, or crash reporting. Local use requires no account and no sign-in. We do not track which files you open, which features you use, or how long you stay.

3. API keys are yours, encrypted locally

Scholardo's AI features (selection rewriting, feed digests, embedding search, and so on) are powered by AI provider API keys that you supply yourself — OpenAI, Anthropic, Google Gemini, DeepSeek, or any OpenAI-compatible endpoint. Core features (search, annotations, citations, browser capture) run locally and need no key at all.

  • Encrypted locally: any API key you enter is stored in the macOS Keychain, protected by the operating system's encryption — never written in plaintext to ordinary config files.
  • Never sent to us: your API keys are never transmitted to any Scholardo server.
  • Requests go straight to the provider: when you use an AI feature, the request goes directly from your Mac to the model provider you configured. Scholardo is not a proxy and does not intercept, route, or log the contents of those requests. The data exchanged is governed by that provider's own privacy policy and terms.

4. Network calls we make

These are the first-party network calls Scholardo makes to our servers. Each one is listed in full, including what it sends:

  • License activation: sends your activation code, the email address you bought with, an anonymous device fingerprint (a hash — never your hardware serial), and a generic device label ("Mac", never your computer's name). The email is required because the server checks it against the purchase before issuing a licence.
  • License refresh: sends the activation code and the same device fingerprint, periodically, so a licence keeps working without you re-entering anything.
  • Free trial: sends only the anonymous device fingerprint, so a trial can be granted once per machine. To stop anyone rotating fingerprints to renew a trial indefinitely, the server also records a one-way hash of your IP address, an approximate country, and when you were last seen. These exist only to spot repeated registrations. They are not used to track what you do, and are not linked to your identity or to any of your research.
  • Deactivating a device: when you release this Mac's seat from the About window, sends the activation code and the device fingerprint.
  • Contact form: only when you choose to fill in and submit the "Contact us" form on our website does its content reach our endpoint, solely so we can reply (see Section 6).
  • Rate limiting: to keep these endpoints from being abused, the requests above are rate-limited by source IP, for which the server stores your IP address and a short-window request count. That record is used only for rate limiting and is not linked to your licence, your trial record or any identity.

No local research data is attached to any of these.

Purchases are handled by a merchant of record; we never see your card details. In most countries the sale is completed by Sold through Link, LLC (Stripe's merchant of record programme); in mainland China it is completed by Armitage Labs OÜ (Estonia, registry code 16977866), trading as Creem. Which one applies is set out in Section 3 of the Terms. Card details are entered on that merchant's own checkout pages and never reach Scholardo's servers; the billing and tax details you provide at checkout are handled by that merchant as a data controller under its own privacy policy. To fulfil an order and support it afterwards, we receive from it the email address you bought with, the plan, the amount and currency, the order and subscription identifiers, and the status of any renewal, refund or chargeback. We keep this purchase record for as long as the licence exists and for as long as tax and accounting law requires.

We have a written arrangement with each merchant of record covering our respective data-protection roles in the payment flow. For how it handles your personal data, see the Link or Creem privacy policy — or email us and we will help you reach the right party.

5. Third-party services you opt into

Some features connect to third parties only when you trigger them. Whether to use them is your choice, and the data exchanged is governed by each provider's own policy:

  • AI / embedding providers: using your own key, with requests going directly (see Section 3). Self-hosted options such as local Ollama stay entirely on your machine.
  • Web capture: when you open or save a page in the built-in browser or capture tools, a request is made to that URL.
  • RSS feeds: when you configure a feed, its source is fetched.
  • Citation styles: CSL styles may be downloaded on demand from a public style repository.
  • Hypothesis sync: if you enable it, Scholardo communicates with the Hypothesis service.

6. This website

For the marketing website (scholardo.com) itself:

  • Only essential local storage: it remembers your theme (light / dark) and language preference in your browser's localStorage.
  • No cookies, no cross-site tracking: this site uses Cloudflare Web Analytics to count page views. It sets no cookie, reads no local storage, and does not fingerprint your browser, and it cannot recognise you across sites; each visit sends a single page record (the page address, the referring page, an approximate location, and a device/browser type), which Cloudflare aggregates and reports without retaining your IP address. All we see are totals, which cannot be traced back to an individual. Nothing else is loaded — no advertising, no behavioural analytics. If a tool that does require consent is ever added, it will load only after you explicitly consent.
  • Version check: the page makes one anonymous request to the public GitHub Releases API to show the latest version and download link.
  • Contact form: anything you submit is sent to our endpoint (api.scholardo.com/contact) solely to forward it to us by email so we can reply; it is not otherwise stored.
  • Web fonts: typefaces are served from this site. They are no longer requested from Google Fonts, or from any third party. Icons and every other asset are served from here too — loading a page talks to this site and nothing else.
  • Anti-spam on the contact form only: opening the enquiry form loads Cloudflare Turnstile (challenges.cloudflare.com) to check you are not a bot. It runs only when you open that form, never on page load, and Cloudflare states it does not use it to track people across sites.
  • Checkout: the pricing buttons go through this site's /go/checkout, which reads the country code Cloudflare derives from your IP and sends you to the checkout page hosted by the merchant of record for that country. That country code is used for the redirect and is neither logged nor stored. Nothing about payment happens on this site, and no payment script is loaded here.

7. Retention & deletion

Because your research data never leaves your device, deletion is entirely in your hands: removing a project folder or ~/.scholardo/, or uninstalling the app, removes that data. We hold no copy of your research to retain or delete. Our license records contain only the minimum needed to validate your entitlement.

8. Children

Scholardo is a professional tool for researchers. It is not directed to children under 13 (or the equivalent age in your jurisdiction), and we do not knowingly collect their personal information.

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected in the "Last updated" date at the top of this page; continued use means you accept the updated terms.

10. Contact

Questions about this Privacy Policy? Email us at support (at) scholardo.com. For the rules governing the service, see the Terms of Service.

Scholardo Scholardo

The agent-native research workspace for macOS.

Product

Features Compare Pricing Download

Resources

Docs & tutorials FAQ

Company

Contact About Privacy Terms
© 2026 Scholardo · All rights reserved