隐私政策
🔒隐私政策

最后更新:2026年3月27日(新增自定义 API 条款)  ·  生效日期:2026年3月27日

本政策说明语流(WriteFlow,域名 writenow.cc)在你使用服务时收集、使用和存储哪些数据。语流承诺不过度收集,只收集服务正常运行所必须的信息。

📋语流收集哪些数据
账号信息
  • 邮箱地址:注册时填写,用于登录验证和发送邮件通知(验证邮件、密码重置)。
  • 密码:原始密码从不存储,仅在你的设备上计算 SHA-256 哈希后上传,数据库中只保留哈希值。
  • 用户名(可选):你在个人主页设置的显示名称。
  • 头像(可选):上传后以 base64 格式存储于数据库。
创作内容
  • 故事输入文本:你在「故事内容」框中提交的文字,在登录状态下保存到生成历史。
  • AI 写作结果:每次成功生成后,输入与输出一并存储至生成历史。
  • 写作记忆:你选择保存的章节摘要片段。
  • 世界观数据:你在世界观页面创建的标题、描述、角色、道具、势力等条目。
  • 生成参数:风格、体裁、长度及 Pro 高级参数(随历史记录一并保存)。
使用数据
  • 会话令牌:登录时生成的随机 UUID,存储在你的浏览器 localStorage 中,服务器保留 7 天有效期副本用于鉴权。
  • Pro 使用次数:启用世界观时,记录当前小时内的 Pro 生成次数(用于每小时 5 次限额),仅保留当前时间窗口数据。
  • 前端错误日志:当页面发生未捕获的 JavaScript 错误时,自动上报错误类型、报错信息、代码位置及页面路径,用于排查和修复 Bug。不含你的故事内容。
  • 反馈内容:你通过「反馈与建议」功能主动提交的文字。
自定义 API Key
  • 如果你使用「自定义 API」功能,API Key 仅存储在你浏览器的 localStorage 中,语流的服务器不保存、不记录该 Key。
  • 每次生成时,Key 随请求发送至语流服务器,语流仅用其转发当次请求到你指定的 API 服务商,请求结束后即丢弃。
  • 你可随时通过「清除」按钮从本地删除已填写的 Key。
不收集的内容
  • 语流不使用任何第三方广告或追踪脚本(如 Google Analytics)。
  • 语流不主动记录你的 IP 地址(Cloudflare 基础设施可能在其自身日志中短暂保留)。
  • 语流不收集你设备上的其他 App 信息,也不构建用户画像。
🗄️数据存储与安全
  • 存储位置:所有数据存储于 Cloudflare D1(SQLite),部署在 Cloudflare 全球边缘节点,物理位置包括亚太(含中国大陆境外)及欧美地区。
  • 账号有效期:账号数据(含邮箱)约 6 个月后自动失效。
  • 传输加密:所有 HTTP 传输均通过 HTTPS 加密。
  • 数据出售:语流从不向任何第三方出售你的数据。
🙋你的权利
  • 查看:你可以在「个人主页」和「生成历史」页面查看已存储的所有创作内容。
  • 删除:如需删除账号及全部数据,请通过「反馈与建议」提交申请,语流将尽快处理。
  • 更正:你可以在个人主页修改用户名、头像和邮箱。
📬联系

如对本政策有任何疑问,请通过站内「反馈与建议」功能联系语流。

本政策可能不定期更新。重大变更时将通过站内通知告知。

🔒Privacy Policy

Last updated: March 27, 2026 (added Custom API clause)  ·  Effective: March 27, 2026

This policy explains what data WriteFlow (writenow.cc) collects, uses, and stores when you use the service. WriteFlow is committed to minimal data collection — only what is necessary for the service to function.

📋What WriteFlow Collects
Account Information
  • Email address: Provided at registration; used for login, email verification, and password reset emails.
  • Password: Your raw password is never stored. Only a SHA-256 hash computed in your browser is uploaded; the database holds only the hash.
  • Username (optional): The display name you set on your profile page.
  • Avatar (optional): Stored as a base64 data URL in the database when uploaded.
Creative Content
  • Story input text: The text you submit in the story field; saved to generation history when logged in.
  • AI writing output: Each successful generation's input and output are stored together in generation history.
  • Writing memory: Chapter summary snippets you choose to save.
  • World Bible data: Titles, descriptions, characters, items, factions, and locations you create in the Worldview section.
  • Generation parameters: Style, genre, length, and Pro advanced settings (stored with each history record).
Usage Data
  • Session token: A random UUID generated at login, stored in your browser's localStorage; the server keeps a copy (7-day TTL) for authentication.
  • Pro usage count: When the World Bible is enabled, tracks how many Pro generations you've made in the current hour (5/hour limit); only the current time-window count is stored.
  • Frontend error logs: When an uncaught JavaScript error occurs, WriteFlow automatically reports the error type, message, code location, and page path to help diagnose bugs. Your story content is never included.
  • Feedback content: Text you voluntarily submit via the Feedback feature.
Custom API Key
  • If you use the Custom API feature, your API Key is stored only in your browser's localStorage. WriteFlow's servers never save or log the Key.
  • On each generation, the Key is sent with the request to WriteFlow's server solely to forward that request to your chosen API provider; it is discarded immediately after.
  • You can remove the Key from local storage at any time using the Clear button in the Custom API drawer.
What WriteFlow Does Not Collect
  • WriteFlow does not use any third-party advertising or tracking scripts (e.g. Google Analytics).
  • WriteFlow does not actively log your IP address (Cloudflare infrastructure may retain it briefly in their own logs).
  • WriteFlow does not collect information about other apps on your device and does not build behavioral profiles.
🗄️Storage & Security
  • Storage: All data is stored in Cloudflare D1 (SQLite), deployed on Cloudflare's global edge network across Asia-Pacific, Europe, and North America.
  • Account TTL: Account data (including email) expires automatically after approximately 6 months.
  • Encryption: All HTTP traffic is encrypted via HTTPS.
  • Data sales: WriteFlow never sells your data to any third party.
🙋Your Rights
  • Access: You can view all stored creative content on your Profile and Generation History pages.
  • Deletion: To delete your account and all associated data, submit a request via Feedback and it will be processed as soon as possible.
  • Correction: You can update your username, avatar, and email on the Profile page.
📬Contact

For any questions about this policy, please use the in-app Feedback feature.

This policy may be updated from time to time. You will be notified of significant changes via in-app notices.