最后更新: May 2026 · VisionAI Workspace Beta
你的Orbit内容保存在你的Google Drive中,这是主记录。VisionAI Workspace在你使用平台期间对其进行读写,仅保留短期缓存(24小时内自动清除)以及运行服务所需的账户/使用数据。你的实际内容仍保留在你的Drive中,由你掌控。
VisionAI Workspace的设计让你拥有自己的数据。我们只收集提供服务所需的最低限度信息:
我们使用收集的数据仅用于运营VisionAI Workspace平台:
当你登录时,VisionAI Workspace请求OAuth权限代表你访问Google Sheets、Google Drive(仅文件创建)和Google Docs。此访问权限专门用于:
重要提示:如果你在任何时候撤销VisionAI Workspace的Google Drive访问权限,平台将无法访问你的工作区,并将停止运行,直到恢复访问。你在Google Drive中的数据仍然是你的,不受影响。
VisionAI Workspace使用多提供商AI架构,旨在随时间扩展。当你提交任务时,你的提示内容会由以下其中一个AI提供商临时处理以生成响应——具体使用哪一个因请求而异:
VisionAI Workspace不在你的Google Sheet之外保留你的提示或AI输出的副本。但是,每个第三方AI提供商可能会根据其自己的隐私政策临时记录或处理你的输入。如果你对他们如何处理数据有疑虑,我们建议查看这些提供商的个别隐私政策。
为了发送交易和账户电子邮件(例如等候名单确认、通知和邀请),VisionAI Workspace使用第三方电子邮件传送提供商Brevo。当我们向你发送电子邮件时,你的电子邮件地址和邮件内容仅由Brevo处理以传送该邮件。Brevo根据其自己的隐私政策处理这些数据。我们不将Brevo用于广告。
How it is protected. All traffic between your browser, this platform and Google's APIs runs over HTTPS/TLS. Your Google OAuth tokens are stored in our Supabase Postgres database, encrypted at rest, and are read only by server-side code — they are never sent to your browser and never appear in client-side JavaScript. Account records are protected by row-level security so one account cannot read another's, and the elevated key used for server-side work exists only in server environment variables, never in the app bundle.
The narrowest scopes that work. Drive access is drive.file, which reaches only files this application itself created for you — not the rest of your Drive. Calendar access is calendar.app.created, which reaches only a secondary calendar this application itself created; it cannot see your primary calendar or any event this app did not write. Either can be revoked at any time from your Google Account settings.
Limited Use. VisionAI Workspace's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
We do not train models on your data. We do not use Google user data — raw, aggregated, anonymized or derived — to create, train, or improve any machine learning or artificial intelligence model of our own, and we never sell it or transfer it for advertising.
One open question, stated plainly rather than left out. Content is processed by third-party AI providers to carry out your requests, and those providers set their own terms. Google's Gemini API states that on its free tier, submitted content may be used to improve Google's products and models. We have asked Google directly whether routing content that originated in your Google Sheet through their own Gemini API falls within the Limited Use requirements, and we will update this policy with their answer. If it does not, we will either move that integration to a paid tier — where Google states it does not use submitted content to improve its products — or remove it.
Which AI services see your content, and when. Content is sent to an AI provider only to carry out something you asked for — running a worker on a task, generating an image, summarizing or drafting an email — and only for as long as that request takes. The providers currently used are Groq, Google Gemini, Mistral AI, OpenRouter (a gateway that routes to other providers), Cloudflare Workers AI and Hugging Face. We do not operate self-hosted or offline models; each of these is reached over an API.
Gmail (development only). The Gmail integration is presently limited to the platform owner's own account — a server-side check runs before any request reaches Google, so no other user can trigger it or see its consent screen. It requests gmail.modify (reading messages and most write actions — marking read, archiving — but not permanently deleting), https://mail.google.com/ (Gmail's broadest scope, requested solely because permanent delete has no narrower scope available; everything else this integration does works under gmail.modify alone), and gmail.compose (creating, editing and deleting drafts this app itself created — no code path sends mail beyond that). Message bodies are read live from Google and are not copied to our database. An email you explicitly attach to an orbit or a task is copied into your own Google Sheet — the same file that already stores the rest of your workspace — not to our servers. Two AI-generated artifacts derived from a message you asked to summarize or suggest a task from — the summary and the suggestion — are stored in our database per message so they don't have to be regenerated on every visit; nothing else about a message's content is retained.
认证通过Google OAuth处理,由我们的认证基础设施提供商Supabase管理。Supabase安全存储你的OAuth令牌以维持会话连续性。VisionAI Workspace无法访问你的Google密码或操作工作区所需的OAuth令牌之外的任何凭证。会话与你对平台的积极使用相关联。
Cookie: VisionAI Workspace仅使用必要的会话cookie。这些cookie是认证所必需的,并在你的会话期间保持你的登录状态。我们不使用广告cookie、跟踪像素或任何第三方分析cookie。禁用必要cookie将破坏核心平台功能。
目前的VisionAI Workspace测试版免费使用,不需要任何付款信息。当推出付费Pro功能时,所有计费将由安全的第三方支付处理商处理。VisionAI Workspace绝不会直接存储你的信用卡号、银行详细信息或任何付款凭证。付款处理商的身份将在推出付费功能时公开。
由于你的工作区数据保存在你自己的Google Drive中,只要你选择保留它就会持续存在。除了账户信息(姓名、电子邮件、通过Supabase的OAuth令牌)之外,我们还会保留运行平台所需的运营数据 — 使用与可靠性日志、排期与通知记录、任何套餐购买的付款历史,以及你工作区内容的短期性能缓存(24小时内自动清除)。如果你请求删除账户,我们会从Supabase中删除这些数据。你的Google Sheet和Drive中的任何文件都是你的,必须由你直接删除。
你有权:
VisionAI Workspace面向成年人,不针对18岁以下的任何人。我们不会故意收集18岁以下人士的个人信息。如果你认为18岁以下的人向我们提供了个人数据,请联系我们,我们将采取措施将其删除。
随着VisionAI Workspace超越测试阶段,本隐私政策将更新以反映新功能、提供商和法律要求。我们将通过电子邮件或应用内通知向活跃用户通知重大变更。在更改后继续使用平台即表示接受更新后的政策。
Whose Drive shared content is written to. A workspace can have more than one person in it: an owner, and the crew they invite. The owner’s Google Drive is the system of record for the whole workspace. When a crew member uploads a file or an image to a conversation, or an AI worker produces an artifact for one of the workspace’s orbits, that content is written to the owner’s Drive under the owner’s Google account — never to the crew member’s own Drive. One consequence is worth stating plainly rather than leaving to be discovered: because attachments are stored in the owner’s Drive, a workspace owner may be able to see a file that was attached to a conversation they are not a member of, even though the conversation itself is not readable by them.
What we store for messaging. Conversation membership, message text, attachment references, emoji reactions, read state and your per-conversation notification preference are stored in our Supabase Postgres database rather than in Google Drive. Row-level security restricts reads to the members of a conversation. Typing indicators and who is currently viewing a conversation are broadcast live between connected clients and are not stored at all.
Who can see a message. An orbit’s crew room is readable by everyone the owner has granted that orbit to, and its membership is kept in step with that grant automatically. A direct message is readable only by its participants, and can only be started between people who share at least one orbit — with the exception of the workspace owner, who is reachable by anyone in their workspace and may group any of their crew together.
Notifications carry part of the message. When a message needs to reach somebody who is not looking at the app, the notification contains the sender’s name, the orbit’s name or an indication that it is a direct message, and the first 90 characters of the message body. Depending on your settings that is delivered in-app, by email through Brevo, and as a web push notification through your browser or operating system’s push service. If you would rather message content did not leave the app that way, set a conversation to Quiet or Muted using the bell in its header.
Messages are not sent to AI providers. Conversations between people in a workspace are not routed to any AI model. Content reaches an AI provider only when somebody explicitly runs a worker on a task, as described in Section 4.
Deleting, and leaving a workspace. Deleting a message clears its text and its attachment references from our database; the underlying file already written to the workspace owner’s Drive is not removed by that action and has to be deleted from Drive by its owner. If an owner withdraws your access to the last orbit you hold in their workspace — including by archiving that orbit — your membership ends and you lose access to that workspace’s orbits, rooms and message history. Messages you sent and files you uploaded stay with the workspace. Deleting your own VisionAI Workspace account removes your account data from our systems; it does not retract content you contributed to somebody else’s workspace.