PRIVACY

kirakira 隐私政策

更新日期:2026-08-18 · 生效日期:2026-08-18

English ↓
当前发布版本的核心剪辑、人脸贴纸与普通导出均在设备本地完成。 kirakira 不会把视频或人脸数据发送给开发者或第三方。

1. 适用范围与基本原则

本政策说明 kirakira 当前发布版本如何处理本地视频剪辑、人脸贴纸、可选产品分析、随机积分账号和 Apple App 内购买。 我们不接入广告或跨 App 跟踪 SDK,不出售个人信息,不使用人脸数据进行广告、画像或模型训练。

2. 照片和视频的本地处理

当你使用系统照片选择器时,App 只会获得你明确选中的视频。人物检测、跟踪、画面构图、剪辑、贴纸、滤镜与普通导出均在设备本地完成。

App 会在沙盒中保存当前草稿的视频工作副本与编辑数据,供中断后恢复。该草稿排除在系统备份之外。 App 还会在本机沙盒的 Documents/Exports 中保留生成的导出文件;这些文件只包含视频画面与最终视觉效果,不包含内部人脸框、轨迹 ID、特征表示或描述向量元数据。

3. 面部数据(仅在设备上处理):范围、用途、共享、存储、留存与删除

当你主动通过系统照片选择器选择一个视频,并打开“人脸贴纸”或“遮脸”功能时,kirakira 会在你的设备上分析该视频中可见的人脸。 就本政策而言,“面部数据”包括:(1)用户所选视频中含有人脸的图像帧;(2)检测到的人脸位置和大小(边界框)、检测置信度及对应的视频时间点; (3)在普通人脸检测不足时,为估算人脸位置而临时使用的姿态点,例如眼睛、鼻子和耳朵;(4)从人脸区域临时生成的图像特征描述和颜色描述, 用于在同一视频的连续画面中匹配同一张脸;(5)为供你选择需要遮盖的人而在内存中生成的面部缩略图;以及(6)你选择的人脸轨迹、贴纸样式、大小和逐帧位置调整。 每个数字轨迹 ID 仅在当前视频草稿内有效,不代表该人的真实身份。

普通舞者跟踪也可能在设备上生成姿态推导的人脸或头部框、置信度、颈部与肩部坐标、紧凑的头部/上身颜色描述向量, 以及可能包含脸部画面的全身外观向量。这些数据只用于在当前视频草稿内稳定跟踪匿名舞者;全身外观模型不是人脸识别模型, App 不会把这些数据与其他视频、其他用户或现实身份进行比较。

所有面部分析均使用 Apple 提供的设备端 Vision 和 AVFoundation 技术在本机完成。面部数据仅用于检测视频中可见的人脸、 在同一视频内维持逐帧位置、显示缩略图供你选择、在选定的人脸上渲染贴纸或柔化遮罩、保存可恢复的本地草稿,以及导出你主动创建的视频。 kirakira 不使用面部数据进行身份验证、现实身份识别、跨视频或跨会话识别、广告、营销、用户画像、敏感属性推断或机器学习模型训练。 App 不访问 Face ID 数据、TrueDepth 数据或面部深度图,也不建立可用于识别现实人物的面部数据库。

kirakira 不会把用户选择的视频、面部图像或缩略图、人脸框或轨迹、姿态点、图像特征描述、人物外观向量或贴纸选择发送到开发者服务器、 积分服务器、产品分析服务器、任何云端 AI 服务或任何第三方,也不会出售或出租这些数据。如果你主动同意可选产品分析,App 可能仅记录 “人脸贴纸工具被点击”这一预先定义的功能事件;该事件不包含视频、面部图像、人脸数量、位置、轨迹、所选人物、特征描述、缩略图或贴纸内容, 因此不是面部数据。

在人脸贴纸分析期间,姿态点、Vision 图像特征表示及用于该功能的脸部/肩部颜色描述仅临时保存在内存中,并在该次分析完成后释放, 不会写入文件。面部缩略图仅在当前项目打开时保存在内存中,不会作为独立图片文件保存;重新打开草稿时,缩略图会从本机草稿视频重新生成。

为便于恢复未完成的编辑,kirakira 会将当前草稿的源视频副本、人脸轨迹数据(视频时间点、边界框和置信度)、贴纸设置, 以及普通舞者跟踪所需的上述头部/身体姿态与外观向量,保存在设备上的 App 沙盒 Application Support 目录中,并将该草稿排除在系统备份之外。 kirakira 的服务器不会保存任何面部数据。你主动导出的成片只会在获得授权后保存到系统“照片”App;其留存和任何 iCloud 照片同步由你的系统设置控制。

临时图像特征描述和姿态点仅保留至当前人脸分析结束;内存中的缩略图保留至项目关闭或 App 进程结束。可恢复草稿没有固定的日历留存期限, 而是保留到你关闭当前视频并重新开始、成功用另一个视频替换当前草稿,或在 iOS 中选择“删除 App”为止。上述操作会删除 kirakira 沙盒中的 草稿源视频副本、人脸轨迹和相关编辑设置。iOS 的“卸载 App”功能可能保留 App 文稿与数据,因此若希望一并删除本地草稿,应选择“删除 App”。 kirakira 沙盒 Documents/Exports 中的本地导出文件保留到你删除 App;删除草稿或 App 不会删除系统“照片”App 中的原始视频或已保存成片, 这些内容需要由你在“照片”App 中单独删除。由于 kirakira 从未接收面部数据,开发者无法从服务器访问或远程删除这些仅存于设备上的数据。

4. 第三方与共享

kirakira 不向分析服务商、广告服务商、数据经纪商或其他第三方共享、出售或出租面部数据。Apple Vision 与随 App 提供的本地人物外观模型均在设备上运行, 其提供方不会收到你的媒体或派生数据。如果你启用了 iCloud 照片,Apple 可能按你的系统和 Apple 账号设置同步“照片”App 中的原始或已保存视频; kirakira 不发起、控制或接收该同步。

5. 可选产品分析

仅在你单独同意后,App 才发送白名单事件、时间、App 版本/构建号、受控结果类别及每日轮换随机标识。 事件不包含媒体、文件名、人脸图像、人脸数量、人物轨迹、面部位置、特征表示、积分账号、购买交易或自由文本。 本机队列最长保留 72 小时,服务端原始事件最长保留 45 天;关闭后 App 停止新采集并清除本机队列。

6. 随机积分账号与 Apple App 内购买

积分功能使用随机账号标识,不要求姓名、邮箱或手机号。购买由 Apple StoreKit 处理;kirakira 处理商品 ID、Apple 签名交易、交易 ID 与入账结果, 用于验签、入账、防重放、退款和恢复。我们不会收到完整银行卡信息或 Apple ID 密码。这些账号与购买数据不包含面部数据。

7. 你的选择、删除与联系

你可以不启用人脸贴纸、在系统“设置”中撤销照片权限、点按编辑页的关闭按钮删除当前草稿、导入新视频替换旧草稿、 在“照片”App 中管理原始和已保存视频,或选择“删除 App”移除 kirakira 沙盒数据。撤销照片权限会阻止 App 继续读取你未重新授权选择的内容。

数据控制者与开发者:Yiming Chen
联系邮箱:lucky20000406@icloud.com
kirakira App 备案号:桂ICP备2026003159号-2A

ENGLISH PRIVACY POLICY

kirakira Privacy Policy

Last updated and effective: August 18, 2026.

1. Scope and principle

This policy describes how the currently distributed version of kirakira handles local video editing, Face Stickers, optional product analytics, a random credits account, and Apple in-app purchases. We do not use advertising or cross-app tracking SDKs, sell personal information, or use face data for advertising, profiling, or model training.

2. Local photo and video processing

The system Photos picker gives the app only the video you intentionally select. Person detection and tracking, reframing, editing, stickers, filters, and standard export are performed on the device. A working video copy and editing data are kept in the app sandbox for draft recovery and excluded from system backups. Rendered exports may also remain in the app sandbox; they contain the resulting video pixels, not internal face coordinates, track IDs, feature representations, or descriptor metadata.

3. Face Data (Processed Only on the Device): Scope, Use, Sharing, Storage, Retention, and Deletion

When you intentionally select a video through the system Photos picker and open the Face Stickers or Face Cover feature, kirakira analyzes visible faces in that video on your device. For purposes of this policy, “face data” includes: (1) image frames containing faces in the video you selected; (2) detected face location and size (bounding boxes), detection confidence, and corresponding video timestamps; (3) pose points, such as the eyes, nose, and ears, that may be used temporarily to estimate a face location when ordinary face detection is insufficient; (4) image-feature and color descriptors generated temporarily from face regions to match the same face across consecutive frames of that video; (5) face thumbnails generated in memory so that you can choose which people to cover; and (6) the face tracks, sticker style, size, and frame-by-frame position adjustments that you select. Each numeric track ID is meaningful only within the current video draft and does not identify a person in the real world.

Ordinary dancer tracking may also generate, on the device, a pose-derived face or head box, confidence value, neck and shoulder coordinates, a compact head/upper-body color-appearance vector, and a full-body appearance vector whose image region may include the face. These values are used only to keep an anonymous dancer track stable within the current video draft. The full-body appearance model is not a face-recognition model, and the app does not compare this data with another video, another user, or a real-world identity.

All face analysis is performed on the device using Apple’s on-device Vision and AVFoundation technologies. Face data is used only to detect visible faces in the video, maintain their frame-by-frame positions within that same video, display thumbnails for your selection, render a sticker or soft blur over selected faces, save a recoverable local draft, and export the video that you choose to create. kirakira does not use face data for authentication, real-world identity recognition, recognition across videos or sessions, advertising, marketing, profiling, sensitive-attribute inference, or machine-learning model training. The app does not access Face ID data, TrueDepth data, or facial depth maps, and it does not create a face database capable of identifying real people.

kirakira does not transmit the selected video, face images or thumbnails, face boxes or tracks, pose points, image-feature descriptors, person-appearance vectors, or sticker selections to the developer’s servers, the credits server, the product-analytics server, any cloud AI service, or any third party, and it does not sell or rent this data. If you expressly enable optional product analytics, the app may record only the allow-listed event that the Face Stickers tool was tapped. That event contains no video, face image, face count, location, track, selected person, feature descriptor, thumbnail, or sticker content and therefore is not face data.

During Face Stickers analysis, pose points, Vision image-feature representations, and the face/shoulder color descriptors used by that feature exist temporarily in memory and are released when that analysis finishes; they are not written to a file. Face thumbnails are held in memory only while the current project is open and are not stored as separate image files. If a draft is reopened, the thumbnails are regenerated from the draft video stored locally on the device.

To restore unfinished editing, kirakira stores the current draft’s local source-video copy, face-track data (video timestamps, bounding boxes, and confidence values), sticker settings, and the head/body pose and appearance vectors described above in the app’s sandboxed Application Support directory on the device. The draft is excluded from system backups. No face data is stored on kirakira’s servers. A finished video is saved to the system Photos app only when you request it and grant permission; its retention and any iCloud Photos synchronization are controlled by your system settings.

Temporary image-feature descriptors and pose points are retained only until the current face-analysis operation ends. In-memory thumbnails are retained until the project is closed or the app process ends. A recoverable local draft has no fixed calendar retention period. It remains until you close the current video and start over, successfully replace it with another video, or choose Delete App in iOS. Those actions remove the draft’s local source-video copy, face tracks, and associated editing settings from kirakira’s sandbox. The iOS Offload App feature may preserve documents and data, so choose Delete App if you want the local draft removed with the app. Local rendered exports in kirakira’s sandbox remain until you delete the app. Deleting a draft or the app does not delete the original or exported videos in the system Photos app; you must delete those separately in Photos. Because kirakira never receives face data, the developer cannot access or remotely delete this device-only data from a server.

4. Third parties and sharing

kirakira does not share, sell, or rent face data to analytics providers, advertising providers, data brokers, or any other third party. Apple Vision and the local person-appearance model bundled with the app run on the device; their providers do not receive your media or derived data. If you enable iCloud Photos, Apple may sync original or saved videos under your system and Apple account settings. kirakira does not initiate, control, or receive that synchronization.

5. Optional product analytics

Only after separate consent, the app sends allow-listed events, time, app version/build, controlled result categories, and a daily rotating random identifier. Events contain no media, filename, face image, face count, person track, face location, feature representation, credits account, purchase transaction, or free text. The on-device queue is retained for no longer than 72 hours and raw server events for no longer than 45 days. Turning analytics off stops new collection and clears the local queue.

6. Random credits account and Apple in-app purchases

Credits use a random account identifier and do not require a name, email address, or phone number. Purchases are processed by Apple StoreKit. kirakira processes the product ID, Apple-signed transaction, transaction ID, and crediting result for verification, crediting, replay prevention, refunds, and recovery. We do not receive full payment-card information or an Apple ID password. These account and purchase records contain no face data.

7. Your choices, deletion, and contact

You may decline to use Face Stickers, revoke Photos access in iOS Settings, close the current video to delete its draft, import a replacement video, manage original and saved videos in Photos, or choose Delete App to remove kirakira’s sandbox data. Revoking Photos access prevents further access to content unless you select and authorize it again.

Data controller and developer: Yiming Chen
Contact: lucky20000406@icloud.com
App filing number: 桂ICP备2026003159号-2A