Privacy Policy / 隐私政策
Version prepared: 14 September 2026. This page applies when published; paid licensing applies only when purchases open.
VerbaTap is provided by Zhongfei Liu, an individual operator based in Beijing, China. Privacy contact: zhongfeihit@gmail.com.
中文说明
VerbaTap 由中国北京的个人经营者 Zhongfei Liu 提供。本说明涵盖应用、本网站和授权服务。当前下载和购买尚未开放,以下付费服务说明供上线前了解。
- 输入与权限: 功能开启且试用或授权有效时,辅助功能读取光标附近文本并插入你接受的建议,输入监控识别触发键。会跳过系统安全输入、已识别的密码框、无法验证的焦点和已屏蔽应用;但自定义控件可能无法正确报告密码属性。建议在密码管理器、敏感业务应用中禁用功能。
- 本地模型与学习: 本地模式在 Mac 上推理。启用学习后,可能保存词汇、短风格样本、应用/语言标签及最多 200 组有界上下文与已接受续写;采集组合由独立开关控制。剪贴板学习、自由输入学习及语料收集默认关闭,除非设置页另有明确说明。剪贴板风格样本最长 160 字符;同时开启语料收集时可能保留更长文本。已识别的 Command-V 和 VerbaTap 自己插入的文字会从自由输入学习排除,但系统不能可靠区分所有菜单粘贴、拖放、听写或其他应用写入。严格要求不采集时应关闭自由输入学习。关闭开关不删除旧数据,可在设置中查看、编辑或清除学习数据。
- 可选实时上下文: 剪贴板上下文和屏幕 OCR 默认关闭、仅用于本地推理。剪贴板上下文只读取开启后新出现的合格纯文本;OCR 需要你另行授予屏幕录制权限,仅识别焦点窗口附近的有界区域。其内容不会由该功能单独持久化、用于学习或发送给云端 API,但会进入本地模型提示;本地引擎诊断信息仍可能包含提示相关内容。OCR 可能读到光标附近敏感信息,应在敏感应用中关闭。
- 你选择的云端模型: Cloud API 模式会发送光标附近文本、补全指令、可选的后文和模型配置到你指定的服务商。学习词汇、风格及上下文样本只有另行同意后才加入请求。该同意绑定服务商、地址及有效凭据,切换后需重新授权;当前 Keychain 凭据不可读时会中止请求。云服务商可能有自己的留存规则和费用,请先查看其政策。不要把“本地模式”理解为云端模式也绝不传输文本。
- 授权与支付: 随机安装 ID、应用版本、粗粒度语言地区信息和授权状态用于激活、校验和设备限制。Paddle 处理结账身份、付款、税务、发票和退款;授权服务接收客户、订阅、交易标识及状态,不接收完整银行卡信息。API 密钥与授权凭据保存在 macOS Keychain。
- 存储与保留: 设置保存在 UserDefaults,模型和学习数据主要位于本机 Application Support。升级会按固定顺序迁移旧 CoType/LocalTypist 本地数据,不因此上传。正式版不持久化自由文本应用日志;本地引擎可能生成仅本机可访问、截断的当前运行诊断日志。本地数据保留至你清除;卸载不一定清除 Keychain。服务端付费授权记录目前没有固定自动删除期限,按提供权益、争议/退款、防欺诈及法律义务的必要范围保留,可邮件申请人工核查、访问、更正或删除。必要法律记录可能不能立即删除。
- 托管与共享: 授权服务使用 Cloudflare,本网站由 Cloudflare Pages 托管。托管和支付服务商可能处理 IP、时间及安全日志;应用没有广告、跨应用跟踪或产品分析 SDK。目前授权 Worker 关闭应用可观测性日志/追踪,预发布服务尚未启用定时清理;平台自身的安全日志由平台政策管理。Paddle、托管平台及你选择的 AI 服务商可能在其他国家处理数据。我们不出售个人数据。
- 你的选择: 可暂停应用、屏蔽应用、关闭学习和云个性化、清除本地学习与语料、移除 API 密钥、停用设备或取消订阅。服务端数据请求请联系上方邮箱;我们可能先核验身份。请勿发送密码、完整许可证、银行卡或包含敏感内容的日志。Paddle 付款数据请求也可直接通过其客户支持提出。
Detailed English policy
1. What the app processes / 应用处理什么数据
- Accessibility and keystroke triggers. While your trial or subscription grants access and VerbaTap is enabled, macOS Accessibility APIs read text near the focused caret and insert accepted completions. Input Monitoring detects trigger keys. The app skips macOS Secure Input, recognized password fields, unverifiable focus and apps you blocklist. Custom controls may fail to report password metadata; users should blocklist password managers and sensitive apps.
- Local inference and learning. With a local model, prompts, accepted completions, vocabulary, style samples, up to 200 bounded cursor-prefix/accepted-continuation pairs, and optional fine-tuning corpus remain on this Mac. A pair is retained only when both accepted-completion and free-typing learning are enabled. Saved style samples and context/continuation pairs may include an inferred application bundle identifier and language label for retrieval. Clipboard learning, free-typing learning and corpus collection are off by default unless the settings screen says otherwise. When clipboard learning is enabled, an eligible copied text item contributes extracted vocabulary and may be retained as a style sample of up to 160 characters; if corpus collection is also enabled, the copied text may additionally be retained as a longer local training sample. Observed Command-V operations and text inserted by VerbaTap through accepted completions, snippets, or replacements mark the current sentence so it is skipped by the free-typing collector. macOS does not always let the app distinguish menu paste, drag-and-drop, dictation, or edits made programmatically by another app; users requiring strict non-collection should leave free-typing learning disabled. Disabling a source stops future collection but does not erase previously learned data. Learning counts can be reviewed, vocabulary and style samples can be edited, and all learned data can be cleared. The clipboard-learning monitor does not read or backfill clipboard text while paused or disabled; user-triggered clipboard snippets and safe paste recovery remain separate clipboard-accessing features. macOS provides no reliable clipboard owner, so attribution of background clipboard changes may be incomplete.
- Optional live context. Recent clipboard context and bounded on-screen OCR are off by default and operate only with local inference. Enabling clipboard context establishes a new pasteboard generation baseline, then reads only newer eligible plain-text items into short-lived memory; confidential/transient types are skipped. Screen OCR requires a separate user-initiated Screen Recording grant, captures only a bounded region of the focused app window, and uses on-device macOS Vision. These sources are marked as untrusted autocomplete reference data, are not learned from, separately persisted by the live-context feature, or included in Cloud API requests. They do become part of the local model prompt. The Release app's free-form logger does not persist that content, but the local model process writes a private, truncated diagnostic log that may contain prompt-adjacent diagnostic information, as described under Storage and retention. OCR may still observe sensitive information visible near the focused field; users should keep it off in sensitive apps and use the application blocklist where strict exclusion is required.
- Cloud inference chosen by you. In Cloud API mode, text near the caret, completion instructions, optional text after the caret and provider/model settings are sent to the provider endpoint you select. Bounded vocabulary, short style samples, and context/continuation examples selected for the request are added only after a separate opt-in. Retrieval prioritizes app-, language-, and context-matched examples, while learned vocabulary is global and migrated or otherwise untagged examples may be reused across apps. VerbaTap does not control a custom provider’s retention; review that provider’s policy before enabling it. API keys are stored in macOS Keychain. Learned-data permission is bound to a digest of the selected provider, endpoint, and effective request credential (never the plaintext key). Switching any of them revokes permission and requires a new opt-in; an unreadable current Keychain item aborts the request rather than falling back to a possibly stale legacy key or making an anonymous request.
- Licensing and billing. A random installation identifier, app version and coarse locale are sent to our entitlement service. License and device tokens are stored in Keychain. Paddle, our Merchant of Record, processes checkout identity, payment, invoices, taxes, refunds and subscription status under Paddle’s own privacy policy. Our service receives Paddle customer/subscription/transaction identifiers and entitlement status, but never receives full card details.
- Operational metadata. Hosting and payment providers may process IP address, request time, security/rate-limit signals and ordinary server logs. VerbaTap includes no advertising SDK, cross-app tracker or product analytics SDK.
中文概要:在授权有效且功能开启时,VerbaTap 使用辅助功能读取光标附近文本、使用输入 监控识别触发键;本地模式的数据留在本机。云端模式会把当前上下文和补全指令发送到你 选择的服务商,个性化数据需另行同意。随机安装 ID 和授权状态发送到授权服务;Paddle 作为记录商户处理支付、税务和订阅,我们不接触完整银行卡信息。应用不含广告或跨应用 跟踪 SDK。
2. Storage and retention / 存储与保留
- Preferences are stored in UserDefaults; API and license credentials in Keychain; models, learned data and debug files under
~/Library/Application Support/VerbaTap/. - On the first eligible launch, local Application Support data is migrated in the fixed compatibility order
VerbaTap <- CoType <- LocalTypist; the app does not upload that legacy data. Verify the new directory before manually deleting either legacy directory. - Release builds do not persist free-form application logs. On upgrade, the commercial build removes legacy
app.log/backup files and the previous engine log. Local llama.cpp may then write a private, truncated diagnostic log for the current engine run. - Local models and learned data remain until you remove them using the app or delete the relevant local files. Turning off collection is not deletion. Keychain items may remain after uninstalling; remove saved credentials separately if you no longer need them.
- Server-side license, subscription and transaction identifiers are kept only as needed to supply access, resolve refunds or disputes, prevent fraud, and meet applicable legal obligations. There is currently no fixed automatic deletion period for paid-customer records. You can request a review, access, correction or deletion by email; records still required for these purposes may need to be retained. We do not promise immediate or unconditional deletion of legally required records.
- Our entitlement Worker's application observability logs and traces are disabled. Hosting providers may still process their own security, network and operational logs under their policies; their retention is not controlled by this app. Our current prelaunch service has no scheduled cleanup enabled. Retention practices will be reviewed before paid access opens; any changed practices will be reflected here.
3. Sharing and processors / 共享对象
We share data only with services needed for a user-selected feature: Paddle for billing; Cloudflare for entitlement delivery and the hosting infrastructure of this support site; the AI provider explicitly selected by the user; and authorities where legally required. We do not sell personal data.
4. Your controls / 你的控制权
You can pause VerbaTap, blocklist apps, disable each learning source, disable cloud personalization, remove API keys, clear all learned data and corpus, deactivate a Mac, cancel through the customer portal, and uninstall the app. For access, correction, deletion or export requests concerning server-side billing/license data, contact zhongfeihit@gmail.com. Paddle account/payment requests may also be handled in Paddle’s customer portal. Identity verification may be required before fulfilling a request.
5. Security, transfers, children and changes / 安全、跨境、未成年人及变更
We use HTTPS, HMAC-verified Paddle webhooks, hashed bearer credentials, Keychain and short-lived Ed25519-signed offline leases. No system is perfectly secure. Paddle, Cloudflare and a user-selected AI provider may process data in other countries. VerbaTap is not directed to children under the minimum digital-consent age in their location. Material policy changes will be posted at this website with a new effective date.
Paddle privacy policy: Paddle Privacy. This website is hosted on Cloudflare Pages. Hosting privacy policy: Cloudflare Privacy.