零遥测 · 零数据追踪 · 原生隐私设计

隐私政策与 安全系统架构

Velis 从芯片底层架构设计开始,便坚持零遥测、零分析追踪、设备端向量化与硬件钥匙串隔离。

生效时间:2026年10月 • 版本 2.4 • 符合 GDPR 与 CCPA/CPRA 标准

核心摘要

Velis Software does not collect, process, sell, transmit, or monetize your personal information or media playback habits. Our revenue is derived exclusively from upfront software license purchases on the Apple App Store. There are no advertising identifiers, tracking pings, or telemetry daemons inside Velis.

0
Analytics SDKs
0
Tracking Pings
100%
On-Device AI
Secure
Apple Keychain
Section 01

Zero-Telemetry & Zero-Knowledge Architecture

Velis does not embed any third-party analytics frameworks, crash log aggregators, performance monitoring daemons, or user tracking libraries (e.g., zero Firebase Analytics, zero Mixpanel, zero Google Analytics, zero Sentry, zero adjust, and zero advertising SDKs).

Section 02

Local Keychain & Credential Isolation

To aggregate your personal media sources, Velis requires authentication tokens and connection endpoints (such as Plex Auth Tokens, Jellyfin User API Keys, Emby Connect Tokens, WebDAV passwords, and SMB credentials).

Cryptographic Storage Specification:

• All server passwords and API tokens are written directly to native Apple Keychain Services.

• Encrypted with hardware-backed AES keys managed by the Apple Secure Enclave.

• Stored with access control flag: kSecAttrAccessibleAfterFirstUnlock.

• Tokens are never synced to public iCloud, never included in unredacted exports, and never accessible outside your authenticated hardware device.

Section 03

On-Device Machine Learning (Vibe Search)

Velis features "Vibe Search", a semantic discovery engine that allows you to discover media by emotional mood, color palette, pacing, and visual style.

100% Local Inference: Vibe Search executes an embedded, quantized 384-dimensional BGE-Small CoreML model running directly on your Apple device's Neural Engine (ANE) and GPU.

Zero Cloud Vector Lookups: When Velis indexes your media library, plot summaries and genres are converted into vector embeddings stored entirely in local SQLite memory. When you enter a search query, vector calculation and cosine similarity matching occur entirely offline in <18 milliseconds. Zero search terms, vectors, or media titles are ever transmitted to cloud AI services.

Section 04

Third-Party API Boundaries (Outbound Traffic Scope)

Velis communicates strictly and directly with the services you explicitly configure. Velis servers never act as a reverse proxy or intermediary for this traffic:

The Movie Database (TMDB): When indexing unorganized local media or WebDAV folders, Velis queries TMDB public endpoints directly from your device to fetch posters, backdrops, and synopsis text. Only the sanitized filename/title string is passed.
Trakt.tv: Scrobbling to Trakt is 100% optional. If enabled, your device authenticates directly with Trakt using standard OAuth PIN authorization. Scrobble timestamps and watch events are transmitted directly between your device and Trakt's API servers.
Media Servers (Plex, Jellyfin, Emby, NAS): All video streams, stream chunk requests, and metadata queries travel directly over your local home network (LAN) or direct secure remote connection (HTTPS/TLS) directly to your server.
Section 05

Apple iCloud Synchronization (CloudKit & KVS)

Velis synchronizes playback progress, favorites, and custom library tags across your macOS, iOS, iPadOS, and tvOS devices using Apple's native CloudKit Private Database and NSUbiquitousKeyValueStore (KVS).

Section 06

App Store Purchases & Payment Processing

All financial transactions for Velis Universal Purchases are executed exclusively by Apple through the official Mac App Store, iOS App Store, and tvOS App Store via StoreKit 2.

Velis Software never collects, inspects, receives, or stores credit card numbers, PayPal credentials, bank accounts, or billing addresses. All billing records and receipt validation are governed solely by Apple's Media Services Terms and Conditions.

Section 07

User Data Rights (GDPR / CCPA / CPRA Compliance)

Because Velis stores zero personal data, account databases, or playback histories on remote servers, your statutory rights under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA/CPRA) are satisfied directly on your physical hardware:

Right to Erasure ("Right to be Forgotten"): You can irrevocably delete all local database indexes, cached poster art, and Keychain credentials at any time by opening in-app Settings > Storage & Cache > Reset App Data, or by simply uninstalling the application from your Apple device.
Right to Data Portability: Your playback history and server definitions are stored in standard SQLite and JSON formats within your device's sandboxed container.
"Do Not Sell or Share My Personal Info": We do not sell, rent, or share personal data with data brokers or third parties, fully complying with CCPA/CPRA mandates.
Section 08

Operator Information & Legal Inquiries

Velis is developed and maintained by Velis Software. If you have inquiries regarding our cryptographic security design, architectural disclosures, or privacy commitments, please contact our privacy compliance team:

Velis Software Privacy & Security Team
Contact Privacy Officer
Velis Logo

预先登记 Velis

Apple 通用购买 · 即将正式上线

当 Velis 在 App Store 正式上线时,第一时间体验流畅硬件加速 4K 杜比视界、空间音频与本地语义搜索。

目标平台

零垃圾邮件。仅在 Velis 正式上线 Apple App Store 时发送一次通知。