法律条款
隐私政策
最近更新:2026 年 8 月 1 日。适用于 Rulith Cloud(控制台)与 RULITH EARTH 两件产品,下面分开写。 数据保留那一节写的是今天真实的行为,包括还需要人工完成的部分。
一 · Rulith Cloud(控制台)
我们收什么
- 账户:用 GitHub 或 Google 登录,我们拿到的是身份提供方返回的账号标识与显示名。 我们不存密码,登录凭证由身份提供方持有。
- 客户端凭证:你接入的每个智能体客户端各持一份长期凭证,用来代表你调用。凭证可在控制台逐个撤销。
- 板上的内容:你与你的智能体写进板的材料、规则、结论与动作记录。 这些内容存在我们的服务器上;自托管部署则存在你自己的机器上。
- 运行日志:板的 journal 是这套系统的账本——每一次写入按顺序记下来,结论因此能被回放。 留痕是板的性格,不是可选项:没有 journal 就没有“可核查”。
- 模型调用:Rulith 自己不调用大模型。你的智能体客户端调哪个模型、把什么发给它, 由你和你的模型提供方决定,不经过我们。
- 统计:只有运行服务必需的聚合计数。无第三方追踪脚本、无广告 SDK (本站也一样:零外部 CDN、零字体、零统计)。
数据保留与删除
这一节按当前真实行为写。我们不写自己兑现不了的自动期限。
01你在控制台点“删除账户”,立刻发生的是
- 账户记录被删除,全部客户端凭证同时撤销——已发出的凭证即刻失效,接入的智能体当场断开;
- 你的账户从我们的账户列表中消失,智能体与板的登记、包登记、连接登记一并移除;
- 登录标识永不复用:同一个 GitHub / Google 身份重新登录,得到的是一个全新账户, 拿不回也看不到此前那块板上的任何东西。
02同时仍然留下的是
- 板上的工作记录与 journal 仍在存储中。它们已经无人可及——没有账户、没有凭证、 标识不复用,任何人(包括你自己)都无法再从产品界面读到它们——但字节还在磁盘上。
- 我们把这一点直接写出来,而不是含糊成“数据已删除”: “读不到”和“不存在”是两件事,一个讲证据链的系统没有理由把这两件事混为一谈。
03彻底物理删除:目前走人工
- 要把字节从存储中真正抹掉,请写信到 support@rulith.com, 用你删除账户前使用的登录邮箱发起,说明要删除的账户;
- 我们在收到请求后 7 个工作日内完成,并回信确认;
- 自动清理正在实现中。它落地之前,这条人工通道就是唯一真实的通道—— 当前进度见能力全景与成熟度。
04自托管部署
- 把运行时装在你自己的内网或本地时,数据、模型推理、决策记录都不出你的域: 保留与删除完全由你的运维决定,我们既接触不到、也无从删除。
为什么不给一个“30 天自动删除”的承诺? 因为今天没有任何东西会在第 30 天真的跑起来。 写一条我们兑现不了的期限,比写清“这一步现在靠人工”要糟—— 可核查的有限承诺,胜过不可核查的无限承诺,这条纪律对我们自己的隐私条款同样适用。
二 · RULITH EARTH
Privacy Policy — RULITH EARTH
Last updated: July 2026 (beta)
RULITH EARTH displays public geophysical and aviation data (earthquakes, weather, storm advisories, satellite orbits, aircraft transponder broadcasts) from public channels such as USGS, NOAA, GDACS, CelesTrak and community ADS-B networks.
- We do not require an account. Your device gets a random, client-generated anonymous id (hashed again server-side).
- Location: used only if you enable nearby alerts, guard points or sensor reporting. Coordinates are grid-rounded to ~1 km on your device before upload — precise coordinates never leave your phone. Used solely to select alerts and place anonymous readings; never sold or shared.
- Phone sensors (barometer, shake): strictly opt-in. Readings are anonymised, grid-rounded and honestly labelled as uncalibrated readings on the board.
- Push notifications: if you enable alerts, we store your push token together with your grid-rounded location to deliver nearby warnings. Disabling notifications or uninstalling stops delivery; dead tokens are purged automatically.
- Ask Earth (bring your own LLM): your API key is stored only on your device and calls your model provider directly — it never touches our servers. Ask sessions are processed in memory to orchestrate data tools and are not retained after the session ends.
- Analytics & errors: only aggregate, non-identifying counts (usage and anonymous client error reports) needed to operate the service. No third-party trackers, no ad SDKs.