Drivo · 车记

隐私政策

适用于 Drivo · 车记(应用标识 com.drivo.carji,支持 macOS 与 iOS / iPadOS)

生效日期:2026年6月8日

地图显示方式说明更新:2026年9月7日;应用的数据处理方式未变更。

一句话总结:Drivo · 车记 是一款本地优先的特斯拉行车记录仪(TeslaCam / 哨兵 / 遥测)视频编辑工具。开发者不会收集、上传或追踪你的数据;本应用不集成任何第三方广告 / 分析 / 崩溃上报 SDK。本应用确实会使用 Apple 的系统服务(如相册、地图、内购),并且——仅当你主动配置时——会与你自己搭建的 TeslaMate 服务器通信。你的视频文件不会上传给开发者,也不会发送到 CarJi 运营的服务器;地图、相册写入与内购会通过 Apple 系统服务完成,TeslaMate 仅在你主动配置时连接你自己的服务器。

1. 我们收集什么

开发者不收集你的任何数据。本应用不含任何第三方分析(analytics)、遥测(telemetry)、崩溃上报、广告或追踪类 SDK,不使用广告标识符(IDFA),也没有用户账号或登录系统。开发者没有运营任何服务器,因此你的任何信息都不会被发送给开发者。应用也不会自动检查更新。本应用使用的对外通信仅限于:Apple 的系统服务(相册写入、地图瓦片、内购),以及——仅当你主动配置时——你自己搭建的 TeslaMate 服务器(详见以下各节)。

2. 本地优先:你的数据存在哪里

你导入的 TeslaCam 视频文件夹是由你自己选择的,应用只读取、从不写回该文件夹。扫描得到的事件列表、缩略图、逐帧遥测(SEI)等元数据仅在本地内存与设备上处理。导出的 MP4 写入你自己指定的磁盘位置(保存面板默认 ~/Movies)或你选择的相册。应用在本地保存的内容仅包括:

3. 相册(仅写入)

当你把导出的视频保存到相册时,本应用会向系统申请「仅添加」(add-only)的相册权限,用于把这一个视频文件写入你的相册。本应用不会读取你的相册内容。若你在编辑器中使用系统 PhotosPicker 选择图片,CarJi 仅会获得你明确选择的那一张图片,无法浏览整个相册,也无法访问未选择的项目。

4. 可选的 TeslaMate 连接(默认关闭)

TeslaMate 是一个由你自行搭建(self-hosted)的开源行程记录服务。API 地址与访问令牌均由你自己在「设置」中填入;本应用仅在你主动配置后才会与之通信。全新安装从不调用 TeslaMate。

启用后,应用会向你自己的服务器发起带时间范围的请求,以获取所选行车片段对应的 GPS 轨迹(服务器返回轨迹数据),用于在「小地图」组件中绘制路线。令牌存于系统钥匙串(Keychain);服务器地址(非机密)存于偏好设置。这些数据只在你的设备与你自己的 TeslaMate 服务器之间往返——绝不发送给本应用的开发者,绝不发送给任何第三方。你可随时在「设置」中清空地址与令牌,请求即不再发出。

5. 地图(Apple MapKit)

当首页预览、编辑画布中的地图格、导出小地图组件或地图快照启用时,地图底图、路线折线和当前位置显示会通过 Apple MapKit / MKMapSnapshotter 加载;Apple 可能依其隐私政策处理 IP 地址、地图请求等信息。(与系统「地图」App 使用同一套地图服务,由操作系统解析;在中国大陆,Apple 地图瓦片由高德基础设施按 Apple 的协议提供。该请求会向 Apple 透露所记录行程的大致地理范围。)此过程适用 Apple 的隐私条款,本应用不会持久化任何瓦片缓存。

地图样式与路名:画布角落的小地图组件使用标准矢量地图,可能显示道路名称;其设置可调整大小与视野,不提供「隐藏路名」开关。布局中的整格地图可独立选择「标准」「卫星」或「混合」样式,默认「混合」(.hybrid),即带道路名称的卫星图。上述样式在编辑器预览与导出中保持一致。

商户 / 兴趣点(POI)标签在所选 MapKit 样式支持时被排除,但这不等于隐藏道路名称,也不保证地图中没有可识别位置的信息。若不希望整格地图叠加路名,可选择「卫星」样式,并检查预览与导出结果;部分地区或设备的卫星底图可能显示异常或空白。若不希望分享地点或路线,请在导出前关闭小地图组件,并将布局中的地图格改为摄像头画面;分享前仍应检查原视频及其他叠层是否透露位置。

6. 导出的视频

如果你为视频叠加了地图 / 轨迹 / 遥测 / 水印等图层,然后把导出的视频分享出去,那么该视频文件本身就可能内嵌了地理位置、时间与车速等信息。这是你叠加内容的直接结果,请据此谨慎处理分享:发布到公开平台前,请确认你愿意公开这些信息。如果你导出遥测 CSV 或其他诊断/分析文件,这些文件也可能包含车速、时间、加速度、GPS 或车辆状态等信息。此类文件只在你主动导出时生成,请谨慎分享。

7. 内购与付费

Pro 高级功能通过 Apple 的「应用内购买」/ StoreKit 解锁。付款全程由 Apple 处理;本应用只会收到购买状态(是否已购),绝不会接触任何支付卡信息(卡号、账单地址等一概不经手)。

8. 第三方与品牌说明

本应用不集成任何第三方广告 / 分析 / 崩溃上报 SDK。涉及的外部方仅为:Apple 的系统服务(相册、地图 MapKit、内购 StoreKit,均适用 Apple 隐私条款),以及——仅当你主动配置时——你自己搭建的 TeslaMate 服务器(由你掌控)。本应用与 Tesla, Inc. 无任何隶属、赞助或背书关系;文中对「Tesla」「特斯拉摄像头」等的提及仅为描述用途。

9. 诊断日志

可选的诊断日志文件 carji-diag.txt 写在本地的应用沙盒内(位于应用的「文档」目录下,即 <Documents>/carji-diag.txt),仅含应用 / 设备的技术性诊断信息(状态切换、计数、耗时毫秒数、设备机型与系统版本等),不含任何个人内容(无定位 / GPS 坐标、无文件路径、无用户文本)。它被标记为「排除备份」,绝不会自动上传;只有当你在「设置 → 诊断」中主动点按「导出诊断日志」时,才会经系统分享面板离开设备。你也可随时在同一处点按「清除诊断日志」将其删除。

10. 数据保留与删除

由于所有数据都只存在于本地,数据保留与删除完全由你掌控:删除导出的 MP4、清除诊断日志、在「设置」中清空 TeslaMate 地址与令牌,或直接卸载应用,即可移除相应数据。在 iOS / iPadOS 上,卸载应用通常会移除其应用容器与偏好设置;在 macOS 上,删除应用并不保证会移除其沙盒容器。无论平台,系统钥匙串中的项目均不保证随之移除;如需确保删除 TeslaMate 令牌,请先在「设置」中清空该令牌。

11. 儿童隐私

本应用并非专为儿童设计。开发者不收集任何用户(包括儿童)的个人信息。若儿童使用本应用,父母或监护人应监督其使用及任何购买决定。

12. 你的权利

因为开发者不持有你的任何数据,所以无需向开发者提出访问、更正或删除请求——这些操作你都可以在自己的设备上直接完成(见第 10 条)。若你对本政策有疑问,可通过下方邮箱联系我们。

13. 政策变更

若本应用未来新增任何涉及数据的行为,我们会在更新前修订本政策,并更新页面顶部的「生效日期」。重大变更将通过本页面公示。

14. 联系我们

如对本隐私政策有任何疑问,请联系:[email protected]

Privacy Policy

For Drivo · 车记 (bundle com.drivo.carji, available on macOS and iOS / iPadOS)

Effective date: June 8, 2026

Map-display clarification: September 7, 2026; no change to how the app handles data.

In one sentence: Drivo · 车记 is a local-first editor for Tesla dashcam footage (TeslaCam / Sentry / Telemetry). The developer does not collect, upload, or track your data; CarJi uses no third-party advertising / analytics / crash-reporting SDKs. CarJi does use Apple system services (Photos, Maps, In-App Purchase) and — only if you configure it — your own TeslaMate server. Your video files are never uploaded to the developer or to any CarJi-operated server; maps, photo-library writes, and in-app purchases go through Apple system services, and TeslaMate connects only to your own server when you choose to configure it.

1. What we collect

The developer collects none of your data. The app contains no third-party analytics, telemetry, crash reporters, advertising, or tracking SDKs of any kind. It uses no advertising identifier (IDFA) and has no user account or login. The developer operates no server, so none of your information is ever sent to the developer. The app also never checks for updates automatically. The only outbound communication CarJi performs is to Apple's system services (writing to Photos, map tiles, In-App Purchase) and — only if you configure it — your own TeslaMate server (detailed in the sections below).

2. Local-first: where your data lives

The TeslaCam folder you import is one you choose yourself; the app only reads it and never writes back into it. The event list, thumbnails, and per-frame telemetry (SEI) it derives are processed locally on your device. Exported MP4s are written to a disk location you choose (the save panel defaults to ~/Movies) or to a photo library you select. The only things the app stores locally are:

3. Photos (add-only)

When you save an exported video to your photo library, CarJi requests add-only Photos permission to write that file. CarJi does not read your photo library. If you use the system PhotosPicker in the editor to choose an image, CarJi receives only the image you explicitly select; it cannot browse your whole library or access unselected items.

4. Optional TeslaMate connection (off by default)

TeslaMate is an open-source, self-hosted trip-logging service that you run yourself. The API URL (TM_API_URL) and access token are entered by you in Settings; the app communicates with TeslaMate only after you configure it. A fresh install never calls TeslaMate.

Once enabled, the app sends requests that include a time range to your own server and receives GPS tracks back, used to draw the route in the Mini Map widget. The token is stored in the system Keychain; the server URL (not a secret) is kept in preferences. This data goes only between your device and your own TeslaMate server — it is never sent to CarJi's developer and never to any third party. You can clear the URL and token in Settings at any time, after which no such request is made.

5. Maps (Apple MapKit)

When the home preview, the editor-canvas map cell, the export mini-map widget, or a map snapshot is enabled, the base map, route polylines, and current-location indicator load via Apple MapKit / MKMapSnapshotter; Apple may process IP address and map-request data under its own privacy policy. (This is the same map service used by the system Maps app, resolved by the operating system; in mainland China, Apple Maps tiles are served from AutoNavi infrastructure under Apple's contract. The request discloses the rough geographic bounding box of the recorded drive.) Apple's privacy terms apply to this; the app persists no tile cache of its own.

Map styles and road names: the corner Mini Map widget uses a standard vector map that may show road names. Its settings adjust size and viewing range; there is no "Hide road names" switch. A layout's full-cell map separately offers Standard, Satellite, and Hybrid styles. The default is Hybrid (.hybrid): satellite imagery with road-name labels. These styles are consistent between the editor preview and export.

Business / points-of-interest (POI) labels are excluded where the selected MapKit style supports that filter, but this does not hide road names or guarantee that a map contains no identifiable location information. To avoid added road-name labels on a full-cell map, select Satellite and inspect both the preview and the exported result; satellite imagery may appear incorrectly or blank in some regions or on some devices. If you do not want to share a location or route, disable the Mini Map widget and replace layout map cells with camera views before exporting. Still check the original footage and other overlays for location information before sharing.

6. Exported video

If you add map / track / telemetry / watermark overlays and then share the exported video, the file itself may embed location, time, and speed. This is a direct result of the overlays you chose to add, so handle sharing accordingly — before posting to any public platform, make sure you are comfortable disclosing that information. If you export a telemetry CSV or other diagnostic/analysis file, it too may contain speed, time, acceleration, GPS, or vehicle-state data. Such files are produced only when you actively export them — share them with care.

7. Purchases

Pro / in-app purchases are processed by Apple's In-App Purchase / StoreKit. Payment is handled entirely by Apple; CarJi only receives purchase status (whether you have purchased) and never sees payment-card information (no card numbers, no billing address — none of it passes through us).

8. Third parties & brand notice

The app integrates no third-party advertising / analytics / crash-reporting SDKs. The only external parties involved are: Apple's system services (Photos, Maps / MapKit, In-App Purchase / StoreKit — Apple's privacy terms apply), and — only if you configure it — your own self-hosted TeslaMate server (under your control). The app is not affiliated with, sponsored by, or endorsed by Tesla, Inc.; references to "Tesla" / "Tesla camera" are descriptive only.

9. Diagnostic log

The optional diagnostic log file carji-diag.txt is written locally inside the app sandbox (in the app's Documents directory, i.e. <Documents>/carji-diag.txt) and holds app / device diagnostics only (state transitions, counts, millisecond durations, device model and OS version) — it contains no personal content (no location / GPS coordinates, no file paths, no user text). It is marked "excluded from backup," is never uploaded automatically, and leaves the device only if you tap "Export Diagnostic Log" in Settings → Diagnostics (via the system share sheet). You can also clear it any time with "Clear Diagnostic Log" in the same place.

10. Data retention & deletion

Because all data lives only on your device, retention and deletion are entirely under your control: delete the exported MP4s, clear the diagnostic log, clear the TeslaMate URL and token in Settings, or uninstall the app to remove the corresponding data. On iOS and iPadOS, deleting the app normally removes its app container and preferences; on macOS, deleting the app does not guarantee removal of its sandbox container. On any platform, system Keychain items are not guaranteed to be removed; to ensure the TeslaMate token is removed, clear it in Settings before uninstalling.

11. Children's privacy

The app is not designed specifically for children. The developer collects no personal information from any user, including children. If a child uses the app, a parent or guardian should supervise that use and any purchase decision.

12. Your rights

Because the developer holds none of your data, there is no access, correction, or deletion request to make to the developer — you can perform all of these directly on your own device (see section 10). If you have questions about this policy, contact us at the email below.

13. Changes to this policy

If the app ever introduces any new data-related behavior, we will revise this policy before that change ships and update the "Effective date" at the top of this page. Material changes will be announced on this page.

14. Contact

For any questions about this Privacy Policy, contact: [email protected]