生效日期 / Effective date: 2026-08-21
联系方式 / Contact: support@taolab.dev
本页地址 / Canonical URL: https://moqi.taolab.dev/privacy
最后更新 / Last updated: 2026-08-24
---
MOQI 把会话中的语音实时转成文字并翻译;在「线上会议」模式下,它还会在对方说完一段话后
自动生成一张提示卡。
MOQI transcribes and translates speech in real time. In online meeting mode it also generates
a prompt card after the other party finishes speaking.
---
设备麦克风采集的音频以加密连接直接发送给 Soniox(转写与翻译服务商)。
MOQI 的服务器只向设备签发一把有效期 60 秒、仅可使用一次的临时凭据,随后不参与这条连接。
⚠️ 麦克风会采到你身边所有人的声音,包括通话对方(免提时)或面对面的对话者。
Audio captured by the device microphone is sent directly to Soniox over an encrypted
connection. MOQI's server only issues the device a single-use credential valid for 60 seconds
and takes no further part in that connection.
⚠️ The microphone picks up everyone around you, including the other party on speakerphone or
the person you are talking to face to face.
生成提示卡时,最近若干段已定稿的转写文字(包含对方说过的话)以及你会前自行提供的资料,
会发送到 MOQI 的服务器,再由它转给模型厂商(OpenAI / DeepSeek / Anthropic 之一,
具体哪一家在 app 的同意书里逐字点名)。
🔴 数据在传输中经过我们的服务器 —— 我们技术上看得见它。我们不会说"我们看不见你的会话"。
但我们不存储它:服务器的数据库共三张表(订阅与配额、token 计数、临时凭据签发记录),
没有任何一列能容纳消息正文。这一点由一条逐表逐列扫描的自动化测试钉住
(m4/relay/test/unit/schemaAudit.test.ts),不是一句承诺。
When a prompt card is generated, the most recent finalized transcript segments (including what
the other party said) and any materials you provided beforehand are sent to MOQI's server, which
forwards them to a model vendor (OpenAI, DeepSeek or Anthropic — named verbatim in the in-app
consent text).
🔴 **The data passes through our server in transit — we can technically see it. We will not claim
"we cannot see your session."**
We do not store it. The server's database has three tables (subscription and quota, token
counts, credential-issuance records) and no column capable of holding message content. That is
enforced by an automated per-table, per-column test, not by a promise.
如果你打开「把这次会话记到本机」,字幕原文与译文、提示卡内容与失败原因会写进你设备上的一个文件。
它不会上传到任何地方。 位置:iOS 的「文件」App →「我的 iPhone」→ MOQI → logs。
你可以随时打开、导出或删除。
⚠️ 这个文件里含对方说过的话。
If you enable "Save this session on this device", the transcript, its translation, prompt-card
content and any failures are written to a file on your device. It is never uploaded.
You can open, export or delete it at any time. ⚠️ That file contains what the other party said.
我们不收集设备标识符、位置、通讯录、广告标识,也不做用户画像或定向广告。
我们不出售任何数据。
We do not collect device identifiers, location, contacts or advertising identifiers, and we do not
build profiles or serve targeted advertising. We do not sell data.
---
| 数据 | 存在哪 | 留多久 |
|---|---|---|
| 音频 | 只在传输中(设备 → Soniox) | 按 Soniox 文档,实时流默认不留存、不用于训练 |
| 转写文字 | 传输中经过我们的服务器 | 我们不存(见 2.2 的 schema 判据);模型厂商按其自身政策留存 |
| 用量计数(token 数、时长、时间戳、模型名) | 我们的服务器 | 用于配额与计费 |
| 本机会话记录 | 只在你的设备上 | 由你控制,随时可删 |
⚠️ 模型厂商的留存不由我们决定。 在没有零留存协议的默认情况下,
主要厂商通常最长保留输入输出约 30 天用于滥用监测,默认不用于训练。
这是厂商的政策,可能随时变化 —— 以其官方文档为准。
Vendor retention is not ours to decide. Absent a zero-retention agreement, major vendors
typically keep inputs and outputs for up to ~30 days for abuse monitoring and do not train on them
by default. That is the vendor's policy and may change — their documentation governs.
---
这是本产品最需要你注意的一点。
MOQI 会采集并实时转写麦克风范围内所有人的声音,其中大多数人并不是 MOQI 的用户,
也没有机会向我们表达同意。
准确地说,MOQI 做的是实时字幕,不是录音(与第三节一致):
线上会议模式下,转写会发给第三方模型厂商生成提示卡,
那边可能按其自身政策保留一段时间(见第三节)——
其中包含对方说过的话;
由你随时删除。
这一点不改变下面那条责任归属,但它是理解下面那些规则时的前提。
我们无法核实它是否属实。
MOQI 不做地区化的法律强制校验。
这件事在澳大利亚由各州与领地各自立法,没有一条全国统一的规则。
这一点最容易被误解 —— 不要因为"在澳洲可以"就假设换个州也一样。
能不能录取决于是否落进一个范围有限的例外(各地的例外条件互不相同)。
而且往往更严格。
⚠️ 以上是一般性说明,不是法律意见。你的具体情况(在哪个州、对方是谁、
用途是什么)会改变结论 —— 需要确定时请咨询执业律师。
**In Australia this is governed by each state and territory separately — there is no single
national rule.** In some states and territories, recording a conversation you are part of is not
an offence; in others it may be unlawful even for a participant, unless a narrow exception
applies, and those exceptions differ between jurisdictions. Even where making the recording is
lawful, sharing or publishing it is usually governed separately and more strictly.
⚠️ This is general information, not legal advice. Your situation — which state you are in,
who the other people are, what you use it for — changes the answer. Get your own advice if you
need certainty.
MOQI captures and transcribes in real time everyone within microphone range, most of whom are
not MOQI users and have no opportunity to give us their consent.
To be precise, MOQI produces live captions rather than a recording (consistent with section 3):
the audio is not retained — it passes through in transit and we never write it to disk; we do
not store the transcript either — but "we do not store it" is not the same as "it is gone": in
online-meeting mode the transcript goes to a third-party model service to generate prompt cards,
and that service may retain it for a period under its own policy (see section 3), **including
what the other party said. Finally, only if you turn on** "save this session on this device"
does the text (not the audio) stay on your device, deletable by you at any time.
That does not change the responsibility stated below, but it is the premise for understanding it.
your declaration; we cannot verify it.
participants to agree. MOQI performs no region-specific legal check.
---
要删除请联系下方邮箱。
is made afterwards.
below to have them deleted.
---
MOQI 不面向 13 岁以下儿童,也不会有意收集他们的信息。
MOQI is not directed to children under 13 and does not knowingly collect their information.
---
数据流发生实质变化时,app 内的同意书会强制你重新同意一次 ——
那不是提示,是机制:同意记录绑定的是那份披露文本的哈希,文本一改,旧同意即失效。
When the data flow materially changes, the in-app consent screen requires you to consent again.
That is a mechanism, not a notice: a consent record is bound to the hash of the disclosure text, so
changing the text invalidates the previous consent.
---
隐私相关的问题,以及第五节说的删除服务端数据请求,请发到 support@taolab.dev。
Privacy questions — and the deletion requests described in section 5 — go to
support@taolab.dev.
---