乔木剪藏隐私说明 / Privacy

更新日期:2026-10-08。适用于乔木剪藏 Chrome 扩展。

剪藏功能读取用户打开的网页、链接、标题、元数据及选中文字,用于提取 Markdown、预览和保存。模板、设置、历史记录、待保存内容及预览草稿存储在浏览器扩展存储中;部分模板和设置通过浏览器同步存储同步。预览草稿最多读取 24 小时,在下次创建预览时清理过期草稿;待重试内容保留到成功或用户清理扩展数据。扩展代码不提供访问统计上传功能。

安装可选本地助手后,扩展通过 Chrome Native Messaging 将笔记内容和相对位置传给本机助手。助手在用户选定的 Obsidian 库内写入 Markdown;库的绝对路径只在本机配置。未安装助手时使用 Obsidian URI 和上游剪贴板保存流程。学习笔记的草稿、视频笔记标记仅保存在扩展本机存储,正文只在你点击保存后发送给本机助手,追加到所选库的今日日记;AI 回答只有你明确点击「加入日记」才会写入。B 站字幕请求在你已登录的 B 站标签页里发出,不会把登录信息交给扩展以外的服务。

勾选“分享到乔木 RSS”(默认不勾选)并点击剪藏后,链接、标题、剪藏 Markdown 和可选封面地址通过 HTTPS 发送到 rss.qiaomu.ai,收录后网站和 RSS 订阅者可以公开读取。请求还包含本地生成的匿名设备编号,用于识别客户端和限流;服务端也可获得正常网络请求的 IP 地址等连接信息。此编号不包含电脑名或笔记库路径。公开提交不会因卸载扩展自动撤回;如需删除已提交内容,请通过维护者联系渠道提出请求,已经被第三方订阅的副本可能无法撤回。

可选的本机字幕生成:当视频没有字幕且用户在字幕条中点击「生成字幕」并确认后,本机助手用 yt-dlp 从视频平台下载这条视频的音频到助手目录的临时文件夹,在本机用语音识别模型识别,任务结束即删除音频;首次使用某个本机引擎时,经你确认后助手会从 PyPI(Python 包)和 Hugging Face(识别模型)下载并装进助手目录下的私有文件夹,只下载、不上传任何你的内容;可在设置里卸载。对小宇宙节目,助手只访问该节目页面和它指向的小宇宙媒体域名来下载音频;对你选择的本地文件,扩展只把文件交给本机助手(不经过任何服务器),助手在自己的目录里保留一份副本最多 3 天用于避免重复转写,随后清理。若你选了云端识别,音频才会发给你所选的服务。识别时,视频或节目页面上公开的标题、作者、简介会作为背景交给识别以减少人名和术语的错误(设置里可关闭);用云端服务时,这段公开文字会随音频一起发给该服务。识别出的文字保存在扩展本地存储和助手的缓存中(助手缓存最多保留 60 天),作为字幕返回扩展,不会由扩展自动上传;使用云端识别时音频及公开背景文字会发送到所选服务。若平台要求登录状态才能下载,用户可在设置中开启使用浏览器登录状态,或选择“用浏览器登录状态重试”。商店版的 cookies 是可选权限,首次开启需浏览器授权;用户可在设置中关闭自动使用。扩展只读取目标网站相关的 Cookie(YouTube 包括 youtube.com 及其登录所依赖的 google.com),通过 Native Messaging 交给本机助手;本机助手将其写入临时 Cookie 文件,供 yt-dlp 向原平台验证身份并下载音频,任务完成、失败或取消后删除。Cookie 不发送给 RSS、AI 或云端识别服务,不用于其他网站或广告。扩展无法提供 Cookie 时,助手可按用户选择尝试从所选浏览器读取登录状态。

可选的云端语音识别:用户也可以在设置里选择自己的云端语音识别服务(如硅基流动、豆包语音、智谱、阶跃星辰、小米 MiMo、Groq、OpenAI 或自定义地址)。此时在用户确认后,本机助手把这条视频的音频切成数十秒到数分钟的片段,上传到用户所选的服务,由该服务识别并按其规则计费;界面在上传前会写明服务名称。API Key 只保存在这个浏览器的本地存储里(不随浏览器同步),由扩展后台读取,只在启动任务时通过环境变量交给本机识别进程,不写入磁盘,网页和页面脚本读不到。若服务地址指向本机(如 127.0.0.1),音频不会离开这台电脑。

预览本身不上传草稿。取消 RSS 选项后,剪藏不向 RSS 接口提交正文;阅读网页仍可能从原站获取网页和图片。可选 AI 解释器会将所需网页内容、提示词及用户配置的凭证发送到用户选择的服务商端点,适用该服务商的隐私与收费规则。

AI 问题与对话上下文也会发送到用户选择的服务商;用户输入的 API 凭证存储在扩展设置中,可能随浏览器设置同步,仅用于请求对应服务商。

可选账号登录:用户可在设置中选择 ChatGPT、Codex 或词元跳动登录,授权页面由对应服务提供。扩展接收授权结果,并与对应服务交换或刷新访问凭证;返回的账号邮箱、账号标识、套餐信息及访问/刷新令牌保存在服务商设置中,可能随浏览器设置同步。词元跳动返回的 API Key 按 AI 服务商凭证保存。相关凭证仅用于所选服务的模型请求,网页脚本无法直接读取;删除该服务商可移除扩展中的凭证,撤销服务端授权需到对应服务操作。ChatGPT 登录使用本机生成的随机主机标识联系认证服务。登录不会让扩展读取用户的密码。

AI 对话的文章地址、标题、问题、所选片段和模型回答保存在本机浏览器存储中,最多保留 40 篇文章、每篇 15 段对话,每段最多 40 条消息。用户可以删除对话记录。三连击快捷键只在本机判断配置的按键序列,输入框内不触发,不上传原始按键记录。

用户数据仅用于用户选择的剪藏、阅读、编辑、问答和分享功能,不出售用户数据,不用于广告投放、信用评估或与这些功能无关的用途。扩展对用户数据的使用遵循 Chrome Web Store User Data Policy,包括 Limited Use 要求。

用户可修改模板、保存位置及 RSS 选项;清理扩展存储或卸载可移除本机扩展数据(会丢失模板和待重试内容)。本地 Markdown、助手配置及已公开提交的内容需要分别处理。隐私问题可通过 维护者 GitHub 联系;不要在公开 Issue 中附上私人正文、凭证或完整日志。

English

The extension reads the active web page, metadata and selected text to extract, preview and save Markdown. Templates, settings, history, pending clips and draft previews are stored in browser extension storage; some settings and templates use browser sync storage. Preview drafts are readable for up to 24 hours and expired drafts are removed when a new preview is created. Pending retries remain until success or local data clearing.

The optional Native Messaging helper receives note content and a relative path to write Markdown inside your selected local Obsidian vault. Absolute vault paths are configured locally. Without the helper, saving uses the inherited Obsidian URI and clipboard flow. Learning-note drafts and the small index of where you took notes in a video stay in local extension storage; a note is sent to the helper only when you press save and is appended to today's daily note in your vault. An AI answer is included only if you explicitly add it. Bilibili subtitle requests run inside your own signed-in Bilibili tab.

When the RSS checkbox is enabled (off by default) and you click Clip, the URL, title, clipped Markdown and optional image URL are sent over HTTPS to rss.qiaomu.ai for public publication. Requests include a locally generated anonymous device ID used for client identification and rate limiting; the server can also receive normal network connection metadata such as the IP address. The ID does not include your computer name or vault path. Uninstalling does not retract public submissions; contact the maintainer for removal requests. Third-party RSS copies may persist.

Optional on-device subtitle generation: when a video has no subtitles and you press "Generate subtitles" and confirm, the local helper downloads the video's audio from the platform with yt-dlp into a temporary folder, recognises it on this computer with a speech model, and deletes the audio when the job ends. The first time you use a local engine, and after you confirm, the helper downloads it from PyPI (the Python packages) and Hugging Face (the model) into a private folder under its own directory; it only downloads, nothing of yours is uploaded, and the engine can be uninstalled in the settings. For Xiaoyuzhou episodes the helper only contacts the episode page and the platform's media domain it points to, to download the audio. A local file you choose is handed by the extension to the local helper only (it never touches a server); the helper keeps a copy in its own folder for up to 3 days to avoid transcribing it twice, then cleans it up. Audio is sent anywhere only if you chose a cloud recognition service. While recognising, the title, author and description that the video or episode page shows publicly are given to the recogniser as background to reduce name and term errors (it can be turned off in the settings); with a cloud service that public text is sent along with the audio. The recognised text is kept in extension storage and in the helper's cache (up to 60 days); it is returned to the extension as subtitles and is not automatically uploaded by the extension; cloud recognition sends audio and public background text to the selected service. If the platform requires login to download audio, you may enable use of the browser login in settings or choose "Retry with my browser login". The store edition declares cookies as an optional permission and requests browser approval when first enabled; automatic use can be turned off in settings. The extension reads only cookies related to the target site (for YouTube, youtube.com and the google.com login it relies on) and passes them to the local helper through Native Messaging. The helper writes a temporary cookie file so yt-dlp can authenticate with the original platform and download audio, then deletes it on completion, failure or cancellation. Cookies are not sent to RSS, AI or cloud recognition services and are not used for other websites or advertising. If the extension cannot provide cookies, the helper may try the user-selected browser login instead.

Optional cloud speech recognition: you can instead choose your own cloud recognition service in the settings (SiliconFlow, Doubao, Zhipu GLM, StepFun, Xiaomi MiMo, Groq, OpenAI or a custom address). After you confirm, the local helper cuts the video's audio into pieces of tens of seconds to a few minutes and uploads them to the chosen service, which recognises them and bills you under its own terms; the interface names the service before anything is uploaded. The API key is kept only in this browser's local storage (not synced), read by the extension's background worker, handed to the local recognition process through its environment when a job starts, never written to disk and never visible to web pages or page scripts. If the address points to this computer (for example 127.0.0.1), the audio does not leave it.

Previewing alone does not submit content. Original sites may receive page and image requests. Optional AI interpretation sends relevant content, prompts and configured credentials to your chosen provider endpoint under its own terms. Clearing extension data removes local extension data, but vault notes, helper configuration and public submissions require separate handling. Contact the maintainer through GitHub without posting private content or credentials in public issues.

AI questions and conversation context are also sent to the chosen provider. User-entered API credentials are stored in extension settings, may sync with browser settings, and are used only with the configured provider.

Optional account sign-in: users may choose ChatGPT, Codex or TokenDance in settings. The provider hosts the authorization page. The extension receives the authorization result and exchanges or refreshes credentials with that provider. Returned email, account identifier, plan information and access/refresh tokens are stored in provider settings and may sync through browser settings. TokenDance API keys are stored as AI provider credentials. Credentials are used only for requests to the selected service and are not directly readable by website scripts. Removing a provider removes its saved credentials from extension settings; revoke server-side authorization through the provider. ChatGPT sign-in sends a locally generated random host identifier to its authentication service. The extension does not read user passwords.

AI chat history (article URL/title, questions, selected passages and model answers) stays in local browser storage, limited to 40 articles, 15 conversations per article and 40 messages per conversation. Users can delete conversations. Triple-press shortcuts inspect configured key sequences locally, ignore typing in editable fields, and do not upload raw keystroke logs. User data is used only for the clipping, reading, editing, AI and sharing features the user chooses; it is not sold or used for advertising, creditworthiness or unrelated purposes. Use of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements.