Private beta · 内测中

Privacy Policy · 隐私政策

Last updated: 2026-10-01 · Beta edition

Beta edition. AcrossTable is in private beta. Two administrative facts are deliberately left open below rather than filled with a guess — the formal operating entity and the governing law — and both will be stated here before paid plans open. Everything this policy says about what happens to your information has been checked against what the service actually does.

中文 本页为 beta 版。下文有两处行政信息(正式经营主体、适用法域)刻意留白而非随意填写,付费档开放前会在此补全。本政策中关于「你的信息会怎样」的每一句,都对照服务的实际行为核对过。

中文 本文英文为主文,中文为对照译文。两者含义不一致时以英文为准。

0. What this document is · 这份文件是什么

This policy describes what AcrossTable actually does with information, checked sentence by sentence against what the service actually does. Where the service does not do something, this policy does not claim it does.

中文 本政策描述 AcrossTable 对信息的实际处理方式,每一句都对照服务的实际行为逐条核对过。服务没做的事,本政策不会声称它做了。

1. Who we are · 我们是谁

AcrossTable is operated during the private beta by its builder as an individual operator. The formal operating entity will be named here before paid plans open.

Contact for anything in this policy, including a request to delete your data: hello@acrosstable.com

中文 内测期间,AcrossTable 由其开发者以个人身份运营;正式经营主体将在付费档开放前在此列明。与本政策有关的任何事项(包括删除数据的请求),请联系 hello@acrosstable.com。

2. The two kinds of people here · 两类使用者

The host is the person who starts a meeting, and the record of the meeting belongs to them. A host proves who they are by signing in to an account (§12).

A guest is anyone the host hands the meeting link or QR code to. Guests need no account, no sign-in, and install nothing. Holding the link is the entire boundary.

中文 主持人是发起会谈的人,会谈记录归他;主持人以登录账户证明身份(§12)。观看者是主持人把链接或二维码给到的人:无需账号、无需登录、无需安装,「持有链接」就是全部边界。

3. Audio is never stored · 音频从不留存

While a meeting runs, your microphone audio goes to a speech-recognition provider as you speak. It is never stored, and nothing of it is kept once it has been passed on.

Spoken translation, when a guest turns it on, is the same: the sound is sent to whoever is listening, and is not stored either.

Everything a meeting leaves behind is text — the next section says what that text is, and none of it is audio.

中文 会谈进行时,你的麦克风音频随说随走、发往语音识别厂商,从不留存;转发之后不留任何副本。观看者开启语音朗读时同理:声音送给正在收听的人,同样不保存。一场会谈留下的东西全是文字——下一节说明那是些什么文字,其中没有音频。

4. What we store · 我们存了什么

The record of a meeting. One record per meeting, holding what the meeting was: its topic and the two languages, the words as they were spoken and their translations, the speaker names the host typed, when each sentence was said, and the host's confirmation that everyone present had been told (§6). If the host asked for minutes, the minutes are in it too — never otherwise (§8). Two smaller things sit alongside: measurements of how quickly we answered, which contain no words but do show when someone spoke, and each viewer tap of "didn't catch that" — which sentence it was about, why, and when. It stays until the host deletes it, or closes their account (§9, §12); nothing else expires it. Nobody using the service can see it except the host who ran that meeting. A meeting nobody spoke in leaves no record at all.

Usage. Which host, which meeting, when it started and how many minutes of it were live — kept for billing and quota, and it only ever goes up (§9).

Your meeting link. We keep what is needed for a host's meeting link to work. It stays until the link is replaced.

The waitlist. An email address you gave us on the marketing page — see §10.

Published share pages. When a host publishes the minutes as a share link (§8), the page behind that link is kept where anyone holding the link can read it. It carries the meeting's topic, its date and the minutes, and nothing else — no transcript, no speaker names. It can be read for as long as the host chose: a day, a week, or at most 30 days, after which it stops working. Revoking the link, or deleting the meeting, takes it down — though the daily backup described in §9 may still hold what it captured before that.

Diagnostic reports. When the app breaks in front of you — a screen that will not appear, an error nothing caught, a connection that drops in a way that means something went wrong — it tells us, automatically. What it sends is what broke: the error itself, whether you were hosting or watching, your interface language, and which browser you were using. It cannot contain any part of your meeting — there is nowhere in such a report for a caption, a topic, a name or an email address to travel. These reports are kept apart from your meeting record, and nothing in them says which meeting or whose account they came from.

中文 会谈记录:每场会谈一份,装的就是这场会谈本身——主题与两种语言、说出口的原话及其译文、主持人填写的说话人姓名、每句话是什么时候说的,以及主持人「已告知在场所有人」的那次确认(§6)。主持人主动生成过纪要的,纪要也在里面,否则没有(§8)。另有两样小东西同存:我们应答快慢的测量(不含任何词句,但会显示谁在何时开口),以及观众每一次点击「没听清」——是关于哪一句、什么原因、什么时候点的。它会一直留着,直到主持人删除它、或注销账号(§9、§12),除此之外没有任何东西会让它自动过期。除举办那场会谈的主持人之外,使用本服务的任何人都看不到它。没有人开口的会谈不留任何记录。
用量:哪位主持人、哪一场会谈、何时开始、其中有多少分钟是进行中的——用于计费与配额,且只增不减(§9)。
你的会谈链接:我们保存让主持人的会谈链接得以生效所必需的东西;在链接被更换之前一直保留。
候补名单:你在落地页留给我们的邮箱地址——见 §10。
已发布的分享页:主持人把纪要发布成分享链接后(§8),链接背后的那一页会保存在持有链接者都能读到的地方。它只含会谈主题、日期与纪要正文,别的什么都没有——不含逐字记录、不含说话人姓名。它可被读取的时长由主持人当时所选:一天、一周,最长 30 天,此后即失效。撤销链接或删除该场会谈都会把它撤下——但 §9 里那份每日备份仍可能保留它在此之前捕捉到的内容。
诊断报告:应用在你面前出故障时——某个界面出不来、某个错误没人接住、或连接以「出了问题」的方式断开——它会自动告诉我们。发出去的只是「哪里坏了」:错误本身、你是主持还是观看、界面语言,以及你用的是哪种浏览器。它不可能包含你会谈的任何部分——这样一份报告里根本没有地方能装下一句字幕、会议主题、姓名或邮箱地址。这些报告与你的会谈记录分开存放,其中也没有任何东西指明它来自哪一场会谈、来自谁的账户。

5. Third parties who process your conversation · 第三方处理商

To produce captions, translation and (on request) minutes, the service sends data to three categories of outside processor.

WhoWhat they receiveWhy
Speech-recognition providersThe audio, and the glossary words the host typedProducing the captions
Language-model providersThe text of what was said, the meeting's topic, and the glossary words the host typedImproving the translation, and writing the minutes when a host asks for them
Speech-synthesis providersOnly the text to be spoken — nothing elseReading the translation aloud for a guest who turns that on

We also contact these providers in ways that carry no part of your conversation. Those exchanges carry no audio and no text of your meeting.

Put simply: the audio goes to the speech-recognition providers, and the meeting topic the host types goes to the translation and minutes providers — never to the recogniser. The table above is the whole account of who receives what.

These providers process data on infrastructure outside your country, including in the United States.

A fourth category receives something, though never your conversation: an email delivery provider. When you join the waitlist (§10), or when we invite you to the beta, your email address and the text of that one message are handed to it so the mail can be sent. It receives nothing else — no audio, no captions, no minutes. With it, the list is complete: apart from the three named elsewhere in this policy — our hosting provider (§7), the service that holds our backup (§9), and the sign-in service (§12) — nothing outside receives anything at all.

中文 为产出字幕、翻译与(按需的)纪要,服务把数据发给三类外部处理商(见上表:语音识别厂商收到音频与主持人填写的术语词,用于产出字幕;大语言模型厂商收到说话内容的文字、会议主题与主持人填写的术语词,用于改进译文、并在主持人要求时撰写纪要;语音合成厂商只收到要读出来的文字、别的什么都没有,用于在观众开启朗读时把译文读出来)。我们也会以完全不涉及你会谈内容的方式联系这些厂商,这类往来不含音频,也不含你会谈的任何文字。简单说:音频发给语音识别厂商;主持人填写的会议主题发给翻译与纪要厂商——不发给语音识别厂商。谁收到什么,以上表为准。这些厂商在你所在国境外(含美国)处理数据。还有第四类会收到东西,但从不是你的会谈内容:邮件投递服务商——你登记候补名单(§10)、或我们向你发出内测邀请时,你的邮箱地址与那一封信的正文会交给它来投递;除此之外它什么也收不到,不含音频、不含字幕、不含纪要。加上这一类,名单就穷尽了:除本政策别处点名的三方——托管平台(§7)、保管我们备份的那家服务(§9)、登录服务(§12)——之外,外部没有任何一方会收到任何东西。

6. Consent is the host's act, and the record remembers it · 同意由主持人做出,记录会记住

Before a meeting can start, the host must tick a box that reads:

我已告知所有参与者,本次会谈将被实时转写并生成双语记录 · I have told everyone present that this conversation will be transcribed into a bilingual record

The start button stays disabled until it is ticked, and the box resets for every meeting.

When the meeting starts, we record that the confirmation was given, and when. If it never happened, nothing is recorded to suggest that it did: the record says what occurred rather than what should have.

Guests see a line they cannot dismiss for the whole meeting: "This conversation is being transcribed · 本会谈正在实时转写". The same sentence is printed at the top of every exported transcript, so the notice travels with the document.

中文 会谈开始前,主持人必须勾选一条确认(原文见上);不勾则开始按钮禁用,且每场都要重勾。会谈开始时,我们记下这次确认发生过、以及发生的时刻。没有确认过,就不会有任何东西被记下来暗示它发生过:记录如实说话。观看者全程可见一行不可关闭的告知:「本会谈正在实时转写」。同一句话印在每份导出的记录顶部,告知随文档一起走。

7. What we do not do · 我们不做的事

中文 只有一个访问计数,没有任何东西给你画像(我们自己不做任何埋点:没有广告、没有追踪,也没有任何我们做的东西在度量你做了什么。我们唯一会自动收集的是故障——应用在你面前出问题时,会发送 §4 描述的那份诊断报告:它说的是哪里坏了,从不说你说了什么。托管平台会给页面加上它自己的访问计数;到我们手里的只有总数:页面被打开了多少次,而不是谁打开的,我们既拼不出一个人也不去拼。你处于登录状态时,登录服务(§12)也在页面上,而它只与自己通信);只有一个 cookie,且只用于维持登录(§12;它是服务运转的必要项,因此没有 cookie 横幅——没有可供选择的非必要项;绝无统计或广告 cookie;观看者不会收到任何 cookie);不用你的会谈训练模型——我们自己不做任何训练,也没有任何东西会把你的记录复制到 §4、§5 点名之外的地方;我们为维持服务运转而监看的东西不透露任何会议信息——它只告诉我们服务是否活着、被用掉了多少,全是数字,绝不会说出是哪一场、是谁的、关于什么、说了什么。

8. Minutes leave us — only when you press the button · 纪要会离开我们,且只在你按下按钮时

Minutes are generated only when the host presses Generate notes on a finished meeting. Nothing generates them on a schedule, and a meeting still running is refused.

When you do press it, the whole transcript is sent to a language-model provider — what was said, in the language it was said in, together with the meeting's topic. What comes back is a summary. Your record is not moved.

Minutes leave a second way, and it is also a button: a share link. From a finished meeting a host can publish the minutes as a web page at an address nobody can guess, and hand that address to someone who was not in the room. That page carries the topic, the date and the minutes — never the transcript, never speaker names. The host chooses how long it works: a day, a week, or at most 30 days. The host can revoke it sooner, and deleting the meeting takes down every link it has out (§4, §9).

中文 纪要只在主持人对一场已结束的会谈按下「生成纪要」时产生:没有定时任务会生成它,进行中的会谈会被拒绝。一旦按下,整场逐字记录会被发送到大语言模型厂商——说过的话(以说话时的语言)连同会议主题一起送出,回来的是一份摘要,你的记录不会被挪走。纪要还有第二条离开我们的路,同样由一颗按钮开启:分享链接。对一场已结束的会谈,主持人可以把纪要发布成一个网页,地址不可猜测,再把地址交给不在场的人。那一页只含主题、日期与纪要正文——不含逐字记录,也不含说话人姓名。有效期由主持人选:一天、一周,最长 30 天;主持人可以随时提前撤销,删除该场会谈会撤下它名下的全部链接(见 §4、§9)。

9. How long we keep things, and how to get rid of them · 保留多久,怎么删

Records stay until you delete them, or close your account. Nothing expires them on a timer: a meeting you do not remove stays for as long as the account does.

You can delete a meeting yourself. Deleting removes it from our service, and there is no way to undo that from inside the app. If the deletion does not fully succeed, you are told, rather than left to assume it worked.

One honest limit: a daily backup may still hold a meeting you deleted — for up to 90 days, after which it expires on its own.

You can take your data with you. Any meeting can be exported as a document you keep, in both languages or in one, whenever you like, with no request and no waiting.

Deleting a meeting does not give back the minutes it used: usage only ever counts up, and billing and quota depend on that.

You can close your account yourself. Closing it starts a 14-day wait; you can cancel at any point during it, and meanwhile meetings are off but you can still sign in. When the 14 days end, the account's meeting records, minutes and share links are deleted — with the same honest limit as above: a daily backup may still hold them for up to 90 days, after which it expires on its own. Usage records, and the few records we need for billing and security checks, are kept; the account's email address, name and country are cleared.

For anything that does not cover — a copy of everything we hold about you, for instance — write to hello@acrosstable.com saying what you want. We do it by hand and confirm when it is done.

中文 记录会一直留着,直到你删除它、或注销账号:没有定时到期这回事,你不删的会谈,只要账号在就一直在。你可以自己删除一场会谈:删除会把它从我们的服务中移除,应用内没有撤销这一操作的入口;若删除没有完全成功,我们会告诉你,而不是让你以为成功了。有一条诚实的限制:每日备份中可能仍留有你删掉的会谈,最长 90 天,之后自动过期。 你可以把数据带走:任何一场会谈都能随时导出成一份你自己保管的文档,双语或单语自选,无需申请、无需等待。删除一场会谈不会退回它用掉的分钟:用量只增不减,计费与配额依据的正是这一点。你可以自己注销账号:注销会开始一段 14 天的等待,期间随时可以取消,会议无法开始,但仍可登录;14 天结束后,该账号的会议记录、纪要与分享链接都会被删除——备份的限制同上:每日备份中可能仍留有它们,最长 90 天,之后自动过期。用量记录,以及计费与安全核对所需的少量记录会保留;账号的邮箱、名字与所在地区会被清除。以上覆盖不到的事——比如索取我们持有的与你有关的全部数据副本——请写信到 hello@acrosstable.com 说明你要什么,我们人工处理并在办完后回信确认。

10. The waitlist · 候补名单

If you enter your email on the marketing page, we store your email address, a short note of which page you signed up from, and the time. No IP address, no browser fingerprint, nothing else.

You get one email back — a short confirmation that your address is recorded — sent through the email delivery provider described in §5, which is what your address is handed to.

Reply to that email, or write to hello@acrosstable.com, and we take you off it.

中文 你在落地页留下邮箱时,我们存的是:邮箱地址、你从哪个页面提交的简短标记、提交时刻。不存 IP、不做浏览器指纹、别的都不存。你会收到一封回信——只是确认地址已登记——它经 §5 描述的那家邮件投递服务商发出,你的地址就是交给它去投递的。回复那封信,或写信到 hello@acrosstable.com,即可从名单中移除。

11. Security · 安全

中文 我们存下来的东西,其保管方式使得只有我们能读到;主持端在登录之后(§12),被篡改的身份声明一律拒绝,绝不悄悄当作他人;运营者的管理入口在一道口令之后,连续答错会被拒绝;观看者即使自称主持人,也发起不了会议、结束不了会议、也送不进任何声音。我们不做超出以上的承诺:一个密钥能与它所保护的东西分开到什么程度,是有限度的,与其暗示相反,我们宁可直说。

12. Accounts · 账号

Hosts sign in through an authentication service provider we have engaged for exactly that purpose. The sign-in page is that provider's; whatever you type or use there — an existing account you already hold, for instance — goes to the provider, not to us. What reaches us, and what we store, is only what identifies your account: the identifier the provider gives us for you, your email address, and your display name. We ask for nothing beyond basic identity — no calendar, no contacts, no files.

We also record, best effort, the country a sign-in came from, kept for the tax and regulatory questions that come with paid plans. It is recorded once and not updated as you travel, and it is not used for tracking.

The cookie described in §7 is what keeps you signed in, and it does nothing else. It is strictly necessary for the service to work, which is why there is no cookie banner: there is nothing optional to consent to.

During the invite-only beta, whether a signed-in account may start meetings is a list we maintain by hand, and you go on it when you are invited. Signing in without an invitation is possible; starting a meeting then is refused with an explanation, and watching a meeting needs no account at all (§2).

You can close your account yourself, in the app; §9 says what that does and when. If you delete your account with the provider instead, it tells us and — unless we have revoked the account or are still reviewing it — the same 14-day closure starts. You can then no longer sign in, so it runs to its end. We may also revoke an account's access ourselves — see Terms §8 for when.

If we revoke an account, the meeting records it made are kept, not deleted and not exported. Losing access is not deletion: the records stay under the retention clause in Terms §8, deleting a meeting yourself (§9) is still the way any one of them goes, and the daily backup still holds whatever it captured until it expires after 90 days. If you want the records gone, delete them yourself before you go, or write to us (§14) and we do it by hand and confirm.

中文 主持人通过我们委托的身份认证服务商登录:登录页面由该服务商提供,你在那里输入或使用的凭据(例如你已有的第三方账号)交给该服务商而非我们。我们接收并存储的只有标识账户所需的信息:服务商给我们的、代表你的那个标识,以及邮箱地址与显示名——除基础身份外我们不索取任何权限,不要日历、不要通讯录、不要文件。我们还会尽力记录首次登录来自的国家/地区,为付费档的税务与合规问题而存;只记一次、不随你的旅行更新、不用于追踪。§7 里那个 cookie 就是维持你登录状态的东西,它不做别的。它是服务运转的必要项,因此本站没有 cookie 横幅:没有可供选择的非必要项。内测期间,已登录账户能否发起会议由我们人工维护的邀请名单决定,受邀时你会被列入;未受邀也能登录,但发起会议会被拒绝并附说明,观看会议则完全无需账号(§2)。你可以自己在应用内注销账号,§9 说明这会发生什么、何时发生。你也可以直接在服务商处删除账号:服务商会通知我们,除非我们已吊销该账号、或它仍在审核中,否则同样的 14 天注销随即开始;你此后无法再登录,所以它会一直走到结束。我们也可能主动吊销某个账号的访问(何时会这样做见服务条款 §8)。若我们吊销了某个账号,该账号已生成的会谈记录会保留——不删除,也不导出。失去访问不等于删除:记录按服务条款 §8 的保留期条款留存,自己删除某一场会谈(§9)仍是让它消失的办法,那份每日备份也仍保留它捕捉到的内容、90 天后过期。想让记录消失,请在离开前自行删除,或写信给我们(§14)人工处理并回信确认。

13. Changes to this policy · 政策变更

When this policy changes in a way that affects what happens to your data, we update the date at the top and post the change on this page before it takes effect. During the beta, this page — not an email — is where changes are announced.

中文 当本政策的变更影响到你的数据处理方式时,我们会更新顶部日期,并在变更生效前在本页公布。内测期间,变更以本页公告为准而非邮件通知。

14. Contact · 联系

hello@acrosstable.com — questions, deletion requests, or a copy of what we hold about you.

中文 hello@acrosstable.com —— 咨询、删除请求,或索取我们持有的与你有关的数据副本。