Ground We Share ("GWS", "the app") is built so that your data never has to leave your device to do the thing the app does. This policy explains exactly what that means.
GWS has no user accounts, no login, and no backend server. There is nothing for us to store on your behalf, because there is no "us" in the data path — the app runs entirely on your device.
Nothing. We do not collect, transmit, or have access to any of your data — not your selections, not your identity, not usage analytics, not crash reports, not advertising identifiers. The app contains no analytics SDK, no crash-reporting SDK, and no advertising SDK.
GWS helps two people find what they have in common (movies, music, or a shared list of relationship boundaries) without either person seeing the other's full private list. It does this using a cryptographic technique called private set intersection (PSI): the person who receives a reply computes the overlap locally, on their own device. The other person never sees the result. Neither side's full list is ever exposed to the other, and no list is ever exposed to us — because it never reaches us in the first place.
You share results with the other person by copying and pasting a short piece of text through whatever messaging app you already use (e.g. WeChat, iMessage). We never see that text either.
Your selections and the cryptographic keys used to compute the match are stored locally on your device using iOS's standard app-storage mechanism.
In-progress rounds. After you send an invite and before the other person replies, that round's selections and the cryptographic key material needed to compute the match are stored on your device, and may be included in your own device backup (iCloud) if you have iCloud Backup enabled. This data is never sent to any server, and never sent to the other person. You can clear it at any time by tapping "Start over" on the result screen. We made a deliberate decision not to auto-delete this data after a period of inactivity, because doing so risks silently destroying a round you are still waiting on a reply for; if you want it gone sooner, "Start over" removes it immediately.
Completed rounds. Once a round finishes, the app keeps a local history entry (what you matched on, how many items, when) so you can look back at it. It does not keep the cryptographic key material used to compute that round — that is discarded the moment the result is calculated, and cannot be recovered even by us, because we never had it.
None of this ever leaves your device except as part of your own personal iCloud backup, which is controlled by your Apple ID and Apple's own backup infrastructure, not by us.
During normal use — searching, selecting items, generating an invite, computing a result — the app makes no network requests at all. The movie, music, and other lookup lists are bundled inside the app itself.
The one exception: next to each item in your result, there's a small "↗" link. Tapping it opens that item's Wikidata page in your device's default web browser. This is a standard outbound link, not a request the app makes on your behalf — once you tap it, you've left the app, and Wikidata's own privacy policy applies to that page, not ours.
We do not share data with third parties, because we do not have any data to share. The only third party you may interact with is Wikidata, and only if you choose to tap the "↗" link described above.
The app does not collect data from anyone, of any age, so there is nothing age-specific to disclose. The app is not directed at children and contains no advertising or in-app purchases.
If this policy changes, we will update the effective date above and, for material changes, note what changed. Continued use of the app after a change means you accept the updated policy.
Questions about this policy: privacy@groundweshare.com
半分知己(Ground We Share,以下简称"本应用")的设计目标是:让你想做的事在你自己的设备上就能完成,数据完全不需要离开设备。以下逐条说明这具体意味着什么。
本应用没有用户账号、没有登录、没有后端服务器。我们没有任何"代你保存"的东西,因为数据链路里根本不存在"我们"这一环——应用完全在你自己的设备上运行。
什么都不收集。我们不收集、不传输、也无法访问你的任何数据——不管是你的选择内容、你的身份、使用行为统计、崩溃报告,还是广告标识符。应用里没有集成任何分析 SDK、崩溃上报 SDK 或广告 SDK。
本应用帮助两个人找出彼此的共同点(电影、音乐,或一份共同的关系边界清单),而不让任何一方看到对方的完整私人清单。它使用一种叫"隐私集合求交"(PSI)的密码学技术:接收回传的那一方在自己的设备上本地算出重合部分。另一方永远看不到结果。任何一方的完整清单都不会暴露给对方,也不会暴露给我们——因为它压根不会传到我们这里。
你把结果分享给对方的方式,是把一小段文字复制粘贴进你本来就在用的聊天软件(比如微信、iMessage)。那段文字我们同样看不到。
你的选择内容与用于计算匹配结果的密钥材料,会通过 iOS 标准的应用存储机制保存在你自己的设备上。
进行中的轮次。发出邀请后、对方回复之前,这一轮的选择内容和计算所需的密钥材料会保存在你的设备上,并可能进入你自己的设备备份(iCloud,若你开启了 iCloud 备份)。它不会发送到任何服务器,也不会发给对方。你可以在结果页点「重新开始」清除它。我们有意决定不做自动过期清理——自动清理有可能在你还在等对方回复时,悄悄销毁那一轮的数据;如果你想更早清除,随时可以手动点「重新开始」。
已完成的轮次。一轮结束后,应用会在本地保留一条历史记录(匹配到了什么、多少项、什么时候),方便你回顾。它不会保留那一轮用过的密钥材料——结果一算出来,密钥材料就被丢弃,我们自己也无法恢复,因为我们从未拥有过它。
以上所有数据除了作为你个人 iCloud 备份的一部分之外,永远不会离开你的设备——而 iCloud 备份由你自己的 Apple ID 与苹果自己的备份系统控制,不受我们管理。
在正常使用过程中——搜索、选择条目、生成邀请、计算结果——应用完全不发起任何网络请求。电影、音乐等词表数据已经打包在应用内部。
唯一的例外:结果页每条匹配项旁边有一个小小的"↗"链接。点它会在你手机的默认浏览器里打开该条目在 Wikidata 上的页面。这是一个普通的外部链接,不是应用替你发起的请求——点开之后你已经离开了应用,那个页面适用 Wikidata 自己的隐私政策,与我们无关。
我们不与任何第三方共享数据,因为我们本来就没有数据可共享。你唯一可能接触到的第三方是 Wikidata,且仅在你主动点击上述"↗"链接时才会发生。
本应用不向任何年龄段的用户收集数据,因此没有需要特别披露的儿童相关内容。应用不面向儿童设计,不含广告,也不含应用内购买。
如本政策发生变更,我们会更新上方的生效日期;重大变更会注明具体改了什么。变更后继续使用本应用,即表示你接受更新后的政策。
对本政策有疑问:privacy@groundweshare.com