保安同私隱Security & privacy
Cantalkie Meetings · 最後更新 2026 年 8 月 29 日 Cantalkie Meetings · last updated 29 August 2026
會議錄音、逐字稿同會議紀錄,由頭到尾淨係喺你部 Mac 度處理, 一次都冇送去 Ajuby 或者任何其他地方。唔係「預設熄咗」,係個 App 根本冇呢條路。 Meeting audio, transcripts and minutes are processed entirely on your own Mac and are never sent to Ajuby or anyone else. Not a setting that defaults to off — there is no such feature in the app at all.
呢一頁係寫俾對方公司 IT 或者合規同事睇嘅。下面每一項我哋都寫埋你點樣自己驗證, 因為驗得到嘅講法先至有用。 This page is written to be handed to somebody else's IT or compliance team. Every claim below comes with the way to check it yourself, because a claim you can verify is worth more than one you have to trust.
我哋實際做咗啲乜What we have actually done
-
全部喺你部機處理Everything runs on your Mac
語音辨識、講者分辨同紀錄撰寫全部係本機模型。個 App 得三樣嘢會用網絡: 第一次下載模型、每日一次查有冇新版本、以及你撳「啟用授權」嗰陣。 Speech recognition, speaker separation and minute-writing are all local models. Three things use the network at all: the first-run model download, a once-a-day version check, and licence activation.
點驗證How to check 錄完會議之後熄咗 Wi-Fi,個 App 一樣寫得晒份紀錄出嚟。 Turn Wi-Fi off after recording. The app still writes the full minutes.
-
Apple 簽署同公證Signed and notarised by Apple
每一個版本都用 Developer ID 簽署、開啟 hardened runtime、 送交 Apple 公證並釘上票據。Team ID 係 7527DB46R4。 Every release is signed with a Developer ID, built with the hardened runtime, submitted to Apple for notarisation and stapled. Team ID 7527DB46R4.
點驗證How to check 喺 Terminal 執行,應該見到 source=Notarized Developer ID: Run this in Terminal. It should say source=Notarized Developer ID:
spctl --assess --type execute -vv \ "/Applications/Cantalkie Meetings.app" -
呢個網站冇追蹤No tracking on this website
冇 Google Analytics,冇任何第三方分析工具,冇廣告像素,冇追蹤 cookie。 瀏覽器只會記住你揀嘅語言,用嘅係 sessionStorage,閂咗個分頁就冇。 No Google Analytics, no third-party analytics of any kind, no advertising pixels, no tracking cookies. The only thing stored in your browser is which language you picked, in sessionStorage, and it is gone when you close the tab.
點驗證How to check 開瀏覽器嘅開發者工具,睇 Network 同 Application → Cookies。 Open your browser's developer tools and look at Network, then Application → Cookies.
-
問題報告:你撳咗 Send 先會寄Problem reports go only when you press Send
個 App 唔會自己寄任何嘢。你會見到一模一樣嘅內容先至決定寄唔寄。 會議標題、出席者姓名、你自己個名同資料夾路徑都會喺寄之前換走。報告 90 日後自動刪除。 Nothing is ever sent by itself. You see character-for-character what leaves before deciding. Meeting titles, attendee names, your own name and your folder path are all replaced first. Reports are deleted automatically after 90 days.
點驗證How to check 「說明」→「回報問題…」,睇晒全部內容,然後唔寄都得。90 日刪除係 Cloudflare R2 上一條 物件生命週期規則,唔係靠人手。 Help ▸ Report a problem… — read all of it and close without sending. The 90-day deletion is an object lifecycle rule on the storage bucket, not a manual process.
-
唔使開戶口No account, ever
冇註冊、冇密碼、冇用戶檔案。個 App 唔會知你係邊個。 買咗授權之後你有一條 licence key,就係咁多。 No sign-up, no password, no user profile. The app does not know who you are. Buying a licence gives you a key, and that is the whole of it.
點驗證How to check 由下載到寫完第一份會議紀錄,全程冇一個畫面問你攞電郵。 Download, install and write your first minutes. Nothing asks for an email address.
-
你張卡我哋掂唔到We never touch your card
付款全部經 Polar 處理,佢係 merchant of record。信用卡資料由頭到尾冇經過 Ajuby 嘅系統,亦冇儲喺我哋度。 Payment is handled entirely by Polar as merchant of record. Card details never pass through, and are never stored on, any Ajuby system.
點驗證How to check 結帳頁係 buy.polar.sh,唔係 cantalkie.com。 The checkout page is on buy.polar.sh, not cantalkie.com.
我哋未有嘅嘢What we do not have
市面上好多網站會貼一堆保安徽章,但當中好多係自己貼、冇人審核嘅。 我哋覺得講清楚未有乜,先至令上面嗰啲講法信得過。 Plenty of sites display security badges that nobody audited. We think saying plainly what we do not have is what makes the rest of this page worth believing.
- 冇 SOC 2、冇 ISO 27001、冇 Cyber Essentials。 呢三個都係自願性認證,唔係法例要求。我哋而家一個都未攞。 如果你嘅採購程序指名要邊一個,請直接同我哋講 —— 有真實需求我哋先去做, 唔會為咗擺個徽章而買。 No SOC 2, no ISO 27001, no Cyber Essentials. All three are voluntary, none is required by law, and we hold none of them today. If your procurement process names one, tell us — we would rather pursue it for a real requirement than buy a badge.
- 「GDPR 認證」係唔存在嘅。 任何網站貼住個「GDPR compliant」徽章都係自己講嘅。GDPR 係一套法律責任,唔係一張證書。 我哋喺私隱頁逐項寫清楚我哋持有乜、點解持有、留幾耐。 There is no such thing as GDPR certification. Any "GDPR compliant" badge is self-asserted. GDPR is a set of obligations, not a certificate. What we hold, why, and for how long is set out item by item on the privacy page instead.
- 冇獨立滲透測試報告。 個 App 冇後台伺服器儲存會議內容,所以一般 SaaS 嗰種滲透測試對佢意義不大, 但我哋唔會扮做過。 No independent penetration-test report. There is no backend holding meeting content for one to test, which is rather the point — but we are not going to pretend we have one.
如果你要做盡職審查If you are running due diligence
- 邊個係資料控制者? 會議內容嘅控制者係你嘅機構,唔係 Ajuby —— 因為啲內容由頭到尾冇離開過你部機。 Ajuby 淨係就自己持有嘅嘢(帳單、授權紀錄、你主動寄嘅問題報告)做控制者。 Who is the controller? For meeting content, your organisation is — not Ajuby — because that content never leaves your machine. Ajuby is controller only for what it actually holds: billing, licence records, and problem reports you chose to send.
- 資料存喺邊個國家? 會議內容存喺你部 Mac,你揀邊個資料夾就邊個資料夾。Ajuby 唔持有副本,所以「資料落地」呢個問題 喺會議內容上面唔適用。 Where is data held? Meeting content is on your Mac, in the folder you chose. Ajuby holds no copy, so data-residency questions do not arise for it.
- 如果出咗資料外洩點算? Ajuby 一份會議錄音、逐字稿或者紀錄都冇持有,所以我哋呢邊冇可能洩漏到會議內容。 What about a breach at your end? Ajuby holds no recording, transcript or set of minutes, so meeting content cannot be exposed from our side.
- 錄音要通知與會者? 係你機構嘅責任,唔係我哋。不過個 App 每次開始錄音都會提你,並且提供中英文講稿,撳一下就 copy 到。 Telling participants they are recorded? That obligation is your organisation's, not ours. The app does prompt at the start of every recording and offers wording to say, in English and Chinese, one click to copy.
搵我哋Getting in touch
保安或者合規上嘅問題,電郵 hello@cantalkie.com。 如果你手上有一份供應商問卷要填,寄埋俾我哋,我哋會照實填。 Security or compliance questions: hello@cantalkie.com. If you have a vendor questionnaire to fill in, send it and we will answer it straight.