Privacy

隐私政策

这份政策说明 TalkIME 在提供 Windows 语音输入服务时会处理哪些数据、数据流向哪里,以及你可以如何控制或删除这些数据。

生效及最后更新日期:2026 年 8 月 23 日

当前传输安全说明

当前桌面客户端连接 TalkIME 后端时使用 HTTP,尚未启用 HTTPS。Microsoft 登录令牌、应用会话令牌、语音音频和启用的上下文会经过这段连接。Microsoft 与火山引擎自身的后续连接使用 HTTPS/WSS。迁移完成前,请不要用 TalkIME 处理密码、支付信息、医疗记录等高度敏感内容。

目录

1. 适用范围

本政策适用于 TalkIME Windows 桌面应用、TalkIME 后端服务、下载页和安装包下载。TalkIME 由个人开发者 Yana Yuan 提供。

我们不出售个人数据,也不使用应用内数据投放广告。

2. 我们处理的数据

2.1 Microsoft 账号与登录

登录通过 Microsoft 身份平台完成。TalkIME 接收并保存 Microsoft 账号对象 ID、电子邮箱、显示名称、订阅或使用资格,以及 TalkIME 应用会话令牌。本地副本保存在 %LOCALAPPDATA%\TalkIME\account.json;账号资料和资格状态也保存在 TalkIME 后端数据库。

应用会话令牌目前没有自动到期时间。本地“退出登录”会删除本机保存的令牌,但不会自动删除后端账号、统计记录或备份。

2.2 语音和生成内容

只有在你主动开始一次听写或语音修改时,TalkIME 才采集麦克风音频。音频经 TalkIME 后端转发给火山引擎豆包语音识别。识别文本、候选文本、语音修改要求和待修改文本会在需要时发送给豆包大模型,以完成纠错、润色、格式整理、语音改字或个人词库生成。

TalkIME 后端数据库不保存原始音频、完整提示词或完整模型结果;这些内容会在请求期间进入服务内存并被上游服务处理。火山引擎对请求数据的处理同时受其服务条款和隐私规则约束。

2.3 光标前文、屏幕语境和本地 OCR

光标前文和屏幕语境默认开启,可以在设置中分别关闭。启用后,应用会读取当前前台窗口中的相关文字,并将其随本次识别文本发送给豆包大模型,用于同音词、专业词和语境纠错。TalkIME 不会持续后台上传屏幕;上下文读取只在一次听写触发后发生。

微信无法提供可用的界面文字时,TalkIME 可在本机截取当前微信窗口并使用 Windows OCR 或 PP-OCRv6 Tiny 识别。截图写入临时目录并在该次 OCR 完成后删除,截图本身不会上传;如果屏幕语境开启,识别出的文字仍会作为本次上下文发送给云端大模型。PowerPoint 正常编辑模式的当前幻灯片文字可通过本机 COM 接口读取。

2.4 本机个性化数据和历史

设置、表达偏好、个人词库、修改历史、候选选择历史、匿名安装 ID、待发送统计事件和诊断日志保存在 %LOCALAPPDATA%\TalkIME。修改历史和候选选择历史包含用户口述、候选或修改后的完整文字;表达偏好和个人词库会在相关云端请求中使用。

2.5 使用统计

使用统计默认开启,可在设置中关闭。统计包含随机安装 ID、每次启动生成的会话 ID、Microsoft 账号对应的 TalkIME 用户 ID、客户端版本、事件时间,以及功能状态、耗时、字符数、结果选择、失败阶段等数值或枚举字段。运营统计事件不包含转写正文、个人词条或屏幕正文。登录前的少量启动和登录事件会先与随机安装 ID 关联,登录成功后可与账号关联。

2.6 诊断日志

客户端滚动诊断日志可能包含完整的识别文本、候选文本、修改要求和修改结果。单个日志文件上限约 3 MB,并保留 3 个备份,合计约 12 MB。后端滚动日志会记录性能和错误信息,并可能包含识别结果的前 30 个字符;文件日志按 5 MB 轮转并保留 5 个备份,部分内容也可能由服务器系统日志保留。

2.7 网站和下载记录

下载页使用 Microsoft Clarity 的 consent-denied 模式记录页面访问、来源域名、UTM 参数、版本和按钮点击等交互,不设置持久 Cookie 访客标识。GitHub Pages、GitHub Releases、腾讯云 COS 和相关网络服务仍可能处理 IP 地址、浏览器信息、请求路径、来源页、响应大小和时间。TalkIME 已启用 COS 访问日志,用于下载量、安全和故障分析。

3. 使用目的

  • 验证登录并提供账号和使用资格;
  • 完成语音识别、语境纠错、润色、格式整理和语音修改;
  • 保存用户选择的设置、词库、表达偏好和修改历史;
  • 计算用量、限制滥用、排查故障并维护服务安全;
  • 分析安装、登录、听写和结果采用情况,改进产品;
  • 提供安装包、判断版本更新并分析下载可靠性。

4. 服务提供方和数据流向

  • Microsoft:账号登录;下载页上的 Microsoft Clarity 访问与交互分析。
  • 火山引擎 / 豆包:云端语音识别和大模型文本处理。
  • 腾讯云:TalkIME 后端基础设施、安装包分发和下载访问日志。
  • GitHub:公开下载页和备用安装包分发。

这些提供方会按照各自条款处理数据,处理地点可能包括中国大陆及其所使用的其他服务区域。本机 Windows OCR、PP-OCRv6 Tiny 和 PowerPoint COM 处理本身不需要把截图或 Office 文档发送给这些提供方,但随后用于云端纠错的识别文字属于云端请求内容。

5. 保存与删除

  • 本机数据:设置、历史、词库和安装 ID 当前没有自动到期时间。卸载应用后,%LOCALAPPDATA%\TalkIME 仍可能保留;可手动删除该目录。
  • 临时截图:微信 OCR 截图在单次处理结束时随临时目录删除。
  • 客户端日志:按约 12 MB 的滚动上限覆盖旧日志,也可通过删除本机数据目录立即清除。
  • 后端账号、统计和用量:当前没有自动到期或自助删除接口,会保留至不再提供服务、运营上不再需要,或完成经验证的删除请求。
  • 后端与下载访问日志:文件日志按大小轮转;服务器系统日志、COS 访问日志和备份目前没有统一的自动到期时间,可能保留到人工清理或完成适用的删除请求。
  • 云端请求:TalkIME 不在应用数据库中保存原始音频和完整模型请求;上游提供方的暂存或保留受其政策约束。

6. 你的选择

  • 在设置中分别关闭光标前文、屏幕语境、增强屏幕识别和使用统计;
  • 删除修改历史或个人词库;
  • 退出登录,删除本机保存的应用会话令牌;
  • 删除 %LOCALAPPDATA%\TalkIME,清除本机账号缓存、设置、历史、词库、安装 ID 和日志;
  • 通过本政策末尾的联系方式申请查看、更正或删除后端账号及相关记录。我们可能需要先验证账号归属,并会说明因安全、法律义务或备份限制无法立即删除的部分。

7. 安全

我们通过访问控制、请求鉴权、用量限制和日志轮转等措施降低风险。但没有任何系统可以保证绝对安全。当前桌面客户端到 TalkIME 后端仍是明文 HTTP,这是已知风险;后端到 Microsoft 和火山引擎的连接使用 HTTPS/WSS。我们建议在迁移到 HTTPS 前不要听写高度敏感内容。

8. 政策更新与联系我们

如果数据处理方式发生实质变化,我们会更新本页日期,并在合理情况下通过下载页或产品界面提示。TalkIME 不专门面向儿童;请监护人协助未成年人理解并使用本服务。

隐私问题、数据查看或删除请求:微信 reasonair,也可以从下载页的客服入口联系我们。

Privacy Policy

Effective and last updated: August 23, 2026

1. Scope

This policy applies to the TalkIME Windows application, backend service, download website, and installer downloads. TalkIME is provided by the individual developer Yana Yuan. We do not sell personal data or use in-app data for advertising.

2. Data We Process

Microsoft account

Microsoft handles sign-in. TalkIME receives and stores the Microsoft account object ID, email address, display name, entitlement information, and a TalkIME application session token. A local copy is stored in %LOCALAPPDATA%\TalkIME\account.json, while account and entitlement records are also stored in the TalkIME backend database. The application token currently has no automatic expiry. Local sign-out removes the local token but does not automatically delete backend records or backups.

Voice and generated text

Microphone audio is collected only after you start dictation or voice correction. The TalkIME backend forwards audio to Volcengine Doubao for speech recognition. Recognized text, candidate text, correction instructions, the text being corrected, glossary records, and expression preferences may be sent to Doubao language models when required for correction, rewriting, formatting, voice correction, or glossary generation.

The TalkIME application database does not store raw audio, complete prompts, or complete model responses. They pass through service memory during a request and are processed by Volcengine under its own terms and privacy practices.

Cursor and screen context

Cursor context and screen context are enabled by default and can be disabled separately in Settings. When enabled, relevant text from the foreground application is sent with the current transcript to the cloud language model. Context is read after a dictation is triggered; TalkIME does not continuously upload the screen in the background.

For WeChat, TalkIME may capture the current WeChat window and run Windows OCR or PP-OCRv6 Tiny locally. The temporary screenshot is deleted after that OCR operation and is not uploaded. If screen context is enabled, the resulting OCR text may still be included in the cloud correction request. Current-slide text in PowerPoint editing mode may be read locally through COM.

Local personalization and history

Settings, expression preferences, glossary terms, correction history, candidate-selection history, a random install ID, pending analytics events, and diagnostic logs are stored under %LOCALAPPDATA%\TalkIME. Correction and selection histories can contain complete dictated, candidate, or corrected text.

Analytics

Usage analytics are enabled by default and can be disabled in Settings. Records may include a random install ID, per-run session ID, account-linked TalkIME user ID, client version, timestamps, feature states, timing, character counts, result choices, and failure stages. Analytics events do not include transcript bodies, glossary entries, or screen text. A small set of pre-login launch and login events is first linked to the random install ID and may be linked to the account after successful sign-in.

Diagnostic logs

Local rolling logs may contain complete transcripts, candidates, correction instructions, and corrected results. Each local log is limited to about 3 MB with three backups, or about 12 MB total. Backend rolling logs may contain performance and error information plus the first 30 characters of an ASR result. Backend files rotate at 5 MB with five backups, and some entries may also remain in operating-system journals.

Website and download records

The download page uses Microsoft Clarity in consent-denied mode to measure page visits, referrer domains, UTM parameters, release version, and interactions. It does not set a persistent cookie identifier. GitHub Pages, GitHub Releases, Tencent Cloud COS, Clarity, and network providers may still process IP addresses, browser information, request paths, referrers, response sizes, and timing. TalkIME has enabled COS access logs for download measurement, security, and troubleshooting.

3. Purposes

  • Authenticate users and provide account entitlements;
  • Provide speech recognition, contextual correction, rewriting, formatting, and voice correction;
  • Save user-selected settings, glossary terms, preferences, and correction history;
  • Measure usage, prevent abuse, troubleshoot failures, and protect the service;
  • Analyze installation, login, dictation, and result adoption to improve TalkIME;
  • Deliver installers, check for updates, and measure download reliability.

4. Service Providers

  • Microsoft for identity and Microsoft Clarity website analytics;
  • Volcengine / Doubao for cloud speech recognition and language-model processing;
  • Tencent Cloud for backend infrastructure, installer delivery, and download access logs;
  • GitHub for the public download page and backup installer delivery.

These providers process data under their own terms and in their service regions, which may include mainland China and other regions they use. Local Windows OCR, PP-OCRv6 Tiny, and PowerPoint COM do not themselves send screenshots or Office documents to those providers, although extracted text may be included in a later cloud correction request.

5. Retention and Deletion

  • Local data: Settings, history, glossary data, and the install ID currently have no automatic expiry. They may remain in %LOCALAPPDATA%\TalkIME after uninstall and can be removed by deleting that directory.
  • Temporary screenshots: WeChat OCR screenshots are deleted with the temporary directory after each OCR operation.
  • Client logs: Old files are overwritten within an approximately 12 MB rolling limit and can be removed by deleting the local data directory.
  • Backend accounts, analytics, and usage: There is currently no automatic expiry or self-service deletion endpoint. Records are retained until no longer needed to provide and operate the service, the service ends, or a verified deletion request is completed.
  • Operational and download logs: File logs rotate by size. Server journals, COS access logs, and backups currently do not share a single automatic expiry and may remain until manual cleanup or an applicable deletion request is completed.
  • Cloud requests: TalkIME does not retain raw audio or complete model requests in its application database. Any provider-side temporary storage or retention is governed by the provider's policies.

6. Your Choices

  • Disable cursor context, screen context, enhanced screen recognition, or analytics in Settings;
  • Delete correction history or glossary entries;
  • Sign out to remove the locally stored application token;
  • Delete %LOCALAPPDATA%\TalkIME to remove local account cache, settings, history, glossary data, install ID, and logs;
  • Contact us to request access, correction, or deletion of backend account records. We may need to verify account ownership and will explain any portion that cannot be removed immediately because of security, legal, or backup constraints.

7. Security

We use access controls, request authentication, usage limits, and log rotation to reduce risk, but no system can be completely secure. The current desktop release connects to the TalkIME backend over unencrypted HTTP. Connections from the backend to Microsoft and Volcengine use HTTPS/WSS. Do not dictate highly sensitive information until the client-to-backend channel has been migrated to HTTPS.

8. Updates and Contact

We will update the date on this page when processing practices materially change and, where reasonable, provide notice through the download page or product. TalkIME is not specifically directed to children; guardians should help minors understand and use the service.

For privacy questions or data access and deletion requests, contact us on WeChat at reasonair, or use the support entry on the download page.