Privacy Policy
This policy explains how the Noesis iOS app and supporting service handle information. Noesis is local-first: assessment and training activity is stored on your device unless you enable sync or request a network feature.
1. Who operates Noesis and how to contact us
Noesis is operated by 史成良, at 江苏省苏州市工业园区八达街99号 (“Noesis”, “we”, “us”). These operator details must be completed and approved before production release.
Privacy and data requests: support@noesis.dsysonshi.com. If local law requires another representative or contact, it will be added after legal review.
2. Scope and product status
This policy covers the Noesis iOS app, noesis.dsysonshi.com pages, and the Noesis API. The product provides cognitive exercise, strategy reflection, and training feedback. It is not a medical device, clinical assessment, diagnosis, treatment, therapy, IQ test, or substitute for professional advice.
3. Information processed on your device
Core starter exercises can be used without Sign in with Apple. Local records remain on the device until you delete them, delete the app in accordance with iOS behavior, or use the in-app deletion controls.
- Assessment and training records: item and version identifiers, selected answers, correctness, hint use, task/session identifiers, timestamps, time to first interaction, and time from interaction to submission.
- Strategy reflections, transfer reflections, checkpoints, progress, local profile estimates, confidence indicators, training history, and selected goals or preferences.
- App settings such as language, appearance, reminder preferences, and sync state.
- A random installation identifier and random profile identifier. Installation credentials are kept in the iOS Keychain; activity and profile records are kept in the app’s local data store.
4. Optional sync and anonymous identity
Sync is off until you enable it or link Sign in with Apple. When sync starts, the service creates an anonymous profile and installation record using random UUIDs, your app language, hashed installation credentials, and expiring API-session credentials. No Noesis password is created.
Sync uploads the response and training fields described above so the service can acknowledge events, restore progress, replay profile calculations, and make records available across supported devices. Turning sync off stops future uploads but does not delete information already synchronized.
5. Sign in with Apple
If you choose Sign in with Apple, Apple supplies an identity token, authorization code, and a stable Apple subject identifier. Noesis asks Apple for email scope, but the current server stores the verified Apple subject—not your email—and links or merges it with your Noesis profile. Apple processes sign-in data under Apple’s own terms and privacy policy.
6. Strategy feedback in version 1.0.0
Version 1.0.0 provides deterministic strategy explanations. It does not enable AI-provider feedback and does not send training evidence to an AI processor.
A future AI feature would require a separate product update, explicit consent, updated disclosures, and approval of the processor, region, retention, subprocessors, model-training terms, and international transfer safeguards before activation.
7. Subscriptions and Apple
Purchases are made through Apple StoreKit. Apple handles payment credentials and billing. Noesis receives and verifies signed transaction and App Store Server Notification data, including product, transaction-chain and transaction identifiers, purchase/expiry/signing dates, environment, renewal or grace-period status, and revocation information. We use it to bind a subscription to a profile, prevent conflicting claims, provide Pro access, restore purchases, and handle renewals, expiry, refunds, and revocation.
8. Operational data, telemetry, and website
The current API produces server logs for requests and errors and in-memory aggregate metrics by route, method, and status for reliability and security. Request identifiers, network metadata normally received by an internet service (such as IP address), and error context may appear in infrastructure logs. The app privacy manifest declares linked user ID, purchase history, product interaction, and other user content, plus unlinked diagnostic data, for app functionality and declares no tracking.
The current codebase contains no advertising tracker and does not sell personal information. Public website pages do not currently set advertising cookies or embed behavioral analytics. We do not use cognitive profiles for targeted advertising.
9. Why we process information
The applicable legal basis varies by location and must be confirmed by counsel. Depending on the feature, processing may be necessary to provide the service you request, based on consent, or necessary for legitimate operational and security interests.
- Provide local exercises, save progress, calculate limited profile observations, and personalize training.
- Provide optional sync, account recovery, multi-device continuity, exports, and deletion.
- Provide deterministic strategy explanations and verify Pro eligibility.
- Process and reconcile App Store subscriptions and protect against fraud or conflicting claims.
- Operate, secure, debug, measure reliability, respond to support requests, and comply with applicable obligations.
10. Sharing and international processing
Information is disclosed only as needed to service providers acting for Noesis, including hosting, database, and backup operators, and to Apple for identity and subscriptions; to professional advisers under confidentiality; during a properly structured business transaction; or when required to protect users, the service, or comply with law. Version 1.0.0 does not disclose training evidence to an AI processor.
Noesis may be available internationally. Configured primary hosting provider: Microsoft Azure. Configured primary hosting region: Japan East. Information from launch markets may therefore be processed in Japan. The applicable transfer notices, contractual safeguards, and user rights remain subject to legal approval; this draft does not claim that any particular transfer mechanism has been approved.
11. Retention
Current implementation retains synchronized response events, profile snapshots, identity/link records, and linked subscription records until account deletion; it does not yet enforce a general automated expiry period. API sessions expire after 30 days, although expired session rows may remain until deletion or operational cleanup. Local data remains while you keep it on the device.
Production values awaiting verification are: application logs 30 days; backups 30 days. Version 1.0.0 sends no request content to an AI processor. These schedules must be configured, verified, and approved before this draft can become effective. Some records may be preserved when law requires it or to establish, exercise, or defend legal claims, subject to an approved schedule.
12. Export and deletion
In Profile → Data & Privacy, you can export synchronized server data as JSON. The server export currently includes profile identity mode and locale, response events and payloads, profile snapshots, App Store transactions, entitlement state, and linked notification history. If no server identity is available, the current local-only export is a JSON summary of record counts rather than a complete record-level export.
Delete account and data first deletes server profile data, response events, snapshots, installations, sessions, and profile-linked subscription records, then clears local Noesis records, Keychain credentials, preferences, and pending reminders. If server deletion fails, the app keeps local data so it does not falsely report success. Deletion is intended to be immediate for the current online database, but residual infrastructure logs and rolling backups require an approved production schedule.
Deleting Noesis data does not cancel an App Store subscription. Manage or cancel it separately in Apple ID subscription settings. Apple may retain transaction records under its own obligations.
13. Security
Noesis uses random identifiers, hashed installation secrets on the server, iOS Keychain storage for device credentials, expiring bearer sessions, authorization checks, and Apple-signed transaction verification. Access should be limited to personnel and providers who need it. No system is completely secure; production encryption, access control, incident response, backup, and deletion evidence remain release-gate items.
14. Children and age scope
Noesis is not directed to children and the production minimum age has not been legally approved. Do not use Noesis if you are under 18 or under the age at which you can consent to this processing where you live, unless and until an approved age and parental-consent flow is published. We do not knowingly seek children’s personal information; contact us to request deletion if you believe a child provided it.
15. Your choices and rights
You can keep core activity local, turn sync off, manage Apple permissions and subscriptions, export available data, and delete Noesis data. Depending on where you live, you may also have rights to access, correct, delete, restrict, object, port, or complain to a regulator. Contact us to exercise a right; we may need to verify the request and may lawfully limit it.
16. Changes
We will publish material changes with a new version and effective date and provide additional notice or obtain consent where required. This draft is not approved for production reliance.