1概述
Enso 排班(以下简称"本应用")是一款专为排班管理设计的 iOS / iPadOS 应用。我们的核心理念很简单:您的数据属于您自己。
本隐私政策说明在您使用本应用时,我们对数据的处理方式。默认情况下,我们不收集任何数据;您也可以选择开启匿名诊断数据共享,帮助我们改进排班算法。
1Overview
Enso Shift (the "App") is an iOS and iPadOS application designed for shift scheduling. Our principle is simple: your data belongs to you.
This Privacy Policy explains how we handle data when you use the App. By default, we collect no data. You may also opt in to share anonymous diagnostics to help us improve scheduling algorithms.
2数据收集概览
默认不收集任何数据。所有数据收集功能均为可选,由您手动开启。
本应用的数据处理分为两种模式:
- 默认模式:所有数据仅保存在设备本地,不上传至任何服务器
- 可选诊断模式:开启后,会匿名上传求解性能数据用于算法改进(详见第 6 节)
无论哪种模式,我们都不会收集以下信息:
- 个人身份信息(姓名、邮箱、电话号码等),本应用无需注册或登录
- 排班具体内容(人员姓名、班次名称、具体日期、可用性设置)
- 设备标识符(IDFA、UDID、IMEI 等)
- 地理位置或网络信息
2Data Collection Overview
No data is collected by default. All data collection features are optional and must be enabled by you.
The App operates in two modes:
- Default mode: all data stays local on your device, never uploaded
- Optional diagnostics mode: when enabled, anonymous solver performance data is uploaded for algorithm improvement (see Section 6)
In either mode, we do not collect:
- Personal information (name, email, phone, etc.) — no account or sign-in required
- Scheduling content (staff names, shift names, specific dates, availability settings)
- Device identifiers (IDFA, UDID, IMEI, etc.)
- Location or network information
3本地数据存储
您在使用过程中创建的所有信息——员工档案、班次配置、排班结果等——均通过 Apple 提供的本地存储机制保存在您的设备上。这些数据在默认情况下不会发送至我们或任何第三方。
本地存储的内容包括:
- 员工信息(姓名、备注、个性化配置)
- 班次类型与时段定义
- 排班计划、约束规则与历史结果
- 应用偏好设置
如何删除:卸载应用即可完全清除设备上的所有本地数据。
3Local Data Storage
Everything you create in the App — staff profiles, shift configurations, generated schedules — is stored locally on your device through Apple's standard storage mechanisms. By default, none of it is ever sent to us or any third party.
Locally stored data includes:
- Staff information (names, notes, personal configurations)
- Shift type and time-window definitions
- Schedules, constraint rules, and history
- App preferences
How to remove: Deleting the App removes all local data from your device.
4网络与服务器
所有核心功能——包括排班引擎的求解计算、PDF 导出——均在您的设备本地完成。在不开启 iCloud 同步或诊断数据共享的情况下,本应用可在完全无网络的环境下正常使用全部功能。
应用内可能发起网络请求的场景包括:
- App Store 订阅校验:在您购买、恢复或验证 Enso Pro 订阅时由系统发起,仅与 Apple App Store 通信。
- iCloud 同步(可选,默认关闭):详见第 5 节。
- 诊断数据上传(可选,默认关闭):详见第 6 节。仅在 Wi-Fi 环境下上传,数据经过匿名化和加密处理。
4Network & Servers
All core functionality — including the scheduling solver and PDF export — runs locally on your device. With iCloud sync and diagnostics sharing turned off, the App works fully offline.
Network requests the App can initiate include:
- App Store subscription verification: triggered by the system when you purchase, restore, or verify an Enso Pro subscription. Talks only to the Apple App Store.
- iCloud sync (optional, off by default): see Section 5.
- Diagnostics upload (optional, off by default): see Section 6. Only over Wi-Fi, with anonymization and encryption.
5可选 iCloud 同步
iCloud 同步默认关闭,需由您手动开启;数据只进入您自己的 Apple 账户。
您可以在「设置」中开启 iCloud 同步,让多台登录同一 Apple ID 的设备共享排班数据。开启后:
- 同步通道:由 Apple 的 iCloud Drive 提供。数据存储在您自己的 iCloud 账户中,开发者无法读取、访问或导出。
- 同步内容:排班设置、当前正在编辑的草稿,以及所有已保存的排班(包含其中的人员、班次与分配信息)。
- 不包含身份信息:我们不会因此获得您的 Apple ID、姓名、邮箱或任何账户信息。
- 仅限同一 Apple ID:数据只在您本人登录同一 Apple ID 的设备之间同步,不会共享给其他用户。
- 可随时关闭:关闭开关即停止同步;本机已有数据保留。如需删除已保存到 iCloud 的数据,请前往「设置 → Apple ID → iCloud → 管理账户存储 → Enso → 删除数据」。
iCloud 中数据的处理受 Apple 隐私政策约束。
5Optional iCloud Sync
iCloud sync is off by default and must be enabled by you. Data stays inside your own Apple account.
You can enable iCloud sync in Settings to share scheduling data across devices signed in to the same Apple ID. When enabled:
- Transport: handled by Apple's iCloud Drive. Data is stored inside your own iCloud account; the developer cannot read, access, or export it.
- What is synced: scheduling settings, the current in-progress draft, and all saved schedules (including the staff, shifts, and assignments inside them).
- No identity information: we do not receive your Apple ID, name, email, or any account information as part of this.
- Same Apple ID only: data syncs only between devices signed in to your own Apple ID. It is never shared with other users.
- Can be turned off at any time: disabling the toggle stops syncing while keeping your local data. To remove data already saved to iCloud, go to Settings → Apple ID → iCloud → Manage Account Storage → Enso → Delete Data.
Apple's handling of iCloud data is governed by the Apple Privacy Policy.
6可选诊断数据
诊断数据共享默认关闭,需由您手动开启。数据完全匿名,无法关联到您或您的设备。
您可以选择开启「共享诊断数据」,帮助我们改进排班算法。开启后,应用会在每次排班求解后匿名上传以下信息:
会收集(匿名) Collected (anonymous)
- 求解性能(总耗时、各阶段用时、求解状态)
- 问题规模(人员数、班次数、天数、约束数量)
- 求解配置(生成策略、worker 数量、时间上限)
- 设备型号与系统版本(用于性能归一化分析)
- 求解复杂度指标(变量数、约束数、目标项数等)
不会收集 Not collected
- 个人身份信息(姓名、邮箱、电话)
- 人员或班次名称
- 具体日期或可用性设置
- 排班结果内容
- 稳定的设备标识符
数据匿名化措施:
- 每次上传使用随机生成的标识符,无法跨上传关联
- 所有可能包含身份信息的字段在设备端即被移除或转换为匿名类别码
- 假日地区信息仅保留国家/地区级代码,去掉细分区域
- 不可行原因仅记录约束类型类别,不包含具体人员或班次信息
数据传输与存储:
- 仅在 Wi-Fi 环境下上传,不消耗蜂窝数据
- 数据在传输前经过加密和压缩处理
- 使用 Apple 的后台传输机制,不影响应用正常使用
- 数据存储在安全的云存储中,90 天后自动删除
- 通过 Apple App Attest 技术防止滥用
数据用途:
- 优化排班算法的求解时间预算估算
- 分析不同规模和配置下的求解质量
- 改进求解策略和预设配置
- 识别和解决不可行排班的常见原因
如何控制:
- 在「设置 → 数据与隐私」中可随时开启或关闭
- 关闭后,本地缓存的诊断数据会立即清除
- 已上传的数据将在 90 天后自动过期删除
6Optional Diagnostics Data
Diagnostics sharing is off by default and must be enabled by you. Data is fully anonymous and cannot be linked to you or your device.
You can opt in to "Share Diagnostics" to help us improve scheduling algorithms. When enabled, the app anonymously uploads the following after each schedule solve:
Collected (anonymous) Collected (anonymous)
- Solve performance (total time, per-stage timing, solve status)
- Problem scale (staff count, shift count, days, constraint count)
- Solver configuration (strategy, worker count, time limit)
- Device model and OS version (for performance normalization)
- Complexity metrics (variable count, constraint count, objective terms)
Not collected Not collected
- Personal identity information (name, email, phone)
- Staff or shift names
- Specific dates or availability settings
- Schedule content or results
- Stable device identifiers
Anonymization measures:
- Each upload uses a randomly generated identifier — no cross-upload linking
- All fields that could contain identity information are removed or converted to anonymous category codes on-device
- Holiday region data retains only country/region-level codes, with sub-regions removed
- Infeasible reasons record only constraint type categories, not specific staff or shift information
Data transmission & storage:
- Uploaded only over Wi-Fi — no cellular data consumed
- Data is encrypted and compressed before transmission
- Uses Apple's background transfer mechanism —不影响 app usage
- Stored in secure cloud storage with automatic 90-day expiration
- Protected against abuse via Apple App Attest technology
Data usage:
- Optimizing solve time budget estimation for scheduling algorithms
- Analyzing solve quality across different scales and configurations
- Improving solver strategies and preset configurations
- Identifying and addressing common causes of infeasible schedules
How to control:
- Toggle on/off anytime in Settings → Data & Privacy
- Turning off immediately clears locally cached diagnostics
- Previously uploaded data expires and is automatically deleted after 90 days
7第三方服务
本应用不集成任何第三方分析、广告、推送、崩溃上报或追踪 SDK。不使用 Firebase、Google Analytics、Facebook SDK、AppsFlyer、Sentry、Crashlytics 或类似的任何第三方服务。
本应用依赖的网络服务仅包括:
- Apple 提供的系统级 App Store 与 iCloud 服务
- 用于诊断数据上传的安全云存储服务(仅在用户开启时使用)
7Third-Party Services
The App integrates no third-party analytics, advertising, push, crash-reporting, or tracking SDKs. There is no Firebase, Google Analytics, Facebook SDK, AppsFlyer, Sentry, Crashlytics, or any similar service.
The network services the App relies on include only:
- Apple's system-provided App Store and iCloud services
- Secure cloud storage for diagnostics upload (only when enabled by the user)
8设备权限
本应用不请求以下任何系统权限:
- 位置(精确或模糊)
- 相机或照片库
- 麦克风
- 通讯录或日历
- 推送通知
- 蓝牙或本地网络
8Device Permissions
The App does not request any of the following system permissions:
- Location (precise or approximate)
- Camera or Photo Library
- Microphone
- Contacts or Calendar
- Push Notifications
- Bluetooth or Local Network
9儿童隐私
本应用面向工作场景中的排班管理用户,不针对 13 岁以下儿童。即使开启诊断数据共享,收集的数据也不包含任何可识别儿童个人信息的内容。
9Children's Privacy
The App is intended for workplace scheduling and is not directed at children under 13. Even with diagnostics enabled, collected data does not contain any information that could identify children.
10政策变更
我们可能会不时更新本隐私政策。任何变更将在本页面发布,并相应更新顶部的"最后更新"日期。重大变更将在应用内显著告知。
10Policy Changes
We may update this Privacy Policy from time to time. Any changes will be posted on this page and the "Last updated" date at the top will be revised accordingly. Material changes will be noted within the App.
11联系我们
11Contact
有问题想要联系?
对本隐私政策有任何疑问,欢迎随时与我们联系。
Questions or feedback?
If you have any questions about this Privacy Policy, please reach out.