隐私政策
生效日期:2026 年 9 月 17 日 · 最后更新:2026 年 9 月 17 日 · 版本 1.3
简要说明:OuduDesktop 主要在你的电脑上处理数据,并直接连接你选择的 Odoo 服务器和设备。桌面端不含广告、行为分析或自动崩溃上报;更新、本网站及你主动启用的增值服务会产生本政策所述的必要网络请求。
1. 适用范围与联系我们
广东欧度软件研发中心(下称“我们”)开发并提供 OuduDesktop 桌面客户端(下称“本软件”)及本网站。联系方式:desktop@oudu.top。
少数用户可另行订购可选增值服务。该服务由其运营方独立提供,并适用独立的条款与隐私政策;本政策仅说明本软件的接入边界。
2. 本机处理的数据
根据你实际使用的功能,本软件可能在本机处理:
- 你添加的服务器、数据库、账号资料与连接设置;
- 界面、窗口、语言、打印、扫描与其他设备偏好;
- 设备名称、能力、端点、网络地址及打印任务等必要元数据;
- 各账号隔离的登录会话、Cookie、缓存及其他网站数据;
- 截图、照片、录音、录像、扫描件或打印内容的临时处理结果;
- 经遮蔽的运行日志、诊断信息与数据库恢复副本。
本软件不把你的 Odoo 密码写入磁盘。登录会话在平台支持时由系统安全能力保护;部分 Linux 环境没有可用密钥环时,系统提供的静态保护可能较弱。增值服务凭据和未来设备配对凭据在安全存储不可用时不会落盘。
3. 业务内容与用户动作
Odoo 业务请求通常在你的电脑与你选择的 Odoo 服务器之间直接传输,其处理规则由该服务器运营者决定。为实现预览、打印、扫描和文件上传,本软件可能在内存、缓存或受控临时文件中短暂处理内容,但不会把正文写入普通任务历史。
网关报文调试默认关闭。你主动开启后,新请求与响应的头和正文会经过凭据遮蔽,仅在本机内存中限量、限时保留,关闭调试即清除。报文不写入普通历史或日志,不自动上传,也不纳入诊断导出;其余业务内容仍可能包含敏感信息,请仅在需要排查时开启。
你选择“复制”时,内容进入操作系统剪贴板;选择“下载”或“保存”时,内容成为你管理的文件;选择在 Odoo 中使用时,内容直接提交到你选择的 Odoo 服务器。本软件不会自动清空系统剪贴板或删除你保存的文件。
4. 联网场景
本软件只在相应功能需要时连接以下类别的目标:
- 你配置的 Odoo 服务器,用于登录和业务操作;
- 你发现、添加或使用的本机及局域网设备;
- 当前发行渠道的更新服务或应用商店;
- 你主动启用的可选增值服务;
- 你主动打开的外部链接。
网络服务通常可看到 IP 地址、请求时间、软件或浏览器版本,以及为交付请求所需的路径或设备信息。桌面端不设置广告标识,不把 Odoo 业务内容用于我们的分析,也不进行隐藏的使用情况上报。
4.1 可选增值服务
仅在你主动注册或使用时,本软件才会为该服务建立本机身份,并可能传输设备标识、设备名称、操作系统与软件版本、局域网 IP/MAC、订阅资料及设备凭据,用于登记设备、确认订阅和维持连接。设备凭据在本机加密保存;用户 API Key 仅用于当次注册,不会保存。停止订阅后本软件立即停止长连接,但会保留本机身份、设备凭据和最近订阅快照,以便你重新注册或恢复服务。
局域网共享默认关闭,按固定协议和能力启用;设备发现不等于共享。原生 Odoo 打印和客屏兼容入口在受控局域网使用 HTTP,不认证终端。客屏仅向你设置的有效默认目标展示,公开页面令牌和最新订单只在活动会话中处理;本机展示使用独立临时会话,不借账户 Cookie,也不保存令牌或订单历史。结束展示、关闭或重配网关及退出会清理会话。任何云端中继都需要另行说明并取得所需授权。
5. 保留、移除与导出
- 打印历史保留最近 90 天且最多 10,000 个请求,以先达到的上限为准;删除请求时一并删除其子记录。
- 日志按固定大小滚动;数据库恢复副本每类最多 3 份且最长 30 天。
- 在软件内移除账号、数据库或服务器会清除直接配置及相应 Chromium 网站数据。移除设备不会提前删除仍在保留期内的任务历史,历史中的设备关联会被解除。
- 如需清除本软件的全部本地数据,请先退出本软件,再删除操作系统中的应用数据目录;仅卸载程序不一定删除该目录及你另行保存的文件。
你可从软件中主动导出诊断 ZIP。它只包含应用/系统摘要及滚动日志,不包含数据库、Cookie、账号清单或 Odoo 页面内容;保存后由你决定是否以及向谁发送,本软件不会自动上传。
6. 本网站、服务提供商与跨境连接
本网站使用 Cloudflare Web Analytics 了解页面访问和性能。根据 Cloudflare 的说明,该服务不使用 Cookie 或 localStorage 采集指标,也不通过 IP、User-Agent 或其他数据对个人进行指纹识别。本网站不使用广告追踪。
Cloudflare, Inc.(美国)为本网站及部分发行渠道提供托管、分析或内容分发,会按其政策处理 IP 地址、请求标识、时间和请求路径。其联系方式及权利渠道见Cloudflare 隐私政策。应用商店、你的 Odoo 运营者、设备厂商、外部网站及可选增值服务运营方分别按其自身规则处理与你直接交互的数据。
访问境外托管的网站、更新服务或其他服务时,你的设备可能直接建立跨境连接。我们会在适用法律要求时提供额外告知、单独同意或其他必要机制。
7. 安全与未成年人
我们采用账号分区、最小化原生桥、传输校验、凭据隔离、日志遮蔽、资源预算和受控临时文件等措施。任何措施都不能保证绝对安全,你仍应保护设备、系统账号和 Odoo 服务器。本软件面向企业用户,不面向未满 14 周岁的未成年人。
8. 你的权利
你可在相应界面查看、更正或移除本机配置,并可按上文方式清除全部应用数据。对于由你的 Odoo 运营者、应用商店、外部服务或增值服务处理的数据,请向相应运营者行使权利。你也可以通过上述邮箱联系我们,我们将在适用法律规定的期限内处理。
9. 政策变更
本页始终发布最新版,并更新版本号和日期。仅纠正表述或事实的变更可直接更新;如新增重要的数据收集、上传、用途或接收方,我们会在相关行为开始前显著告知,并在法律要求或功能确有需要时取得明确同意。
Privacy Policy
Effective: 17 September 2026 · Last updated: 17 September 2026 · Version 1.3
In short: OuduDesktop processes most data on your computer and connects directly to the Odoo servers and devices you choose. The desktop app has no advertising, behavioural analytics, or automatic crash uploads. Updates, this website, and optional services you activate create the limited network requests described below.
1. Scope and contact
Guangdong Oudu Software R&D Center, China (“we”) develops and provides the OuduDesktop desktop client (the “Software”) and this website. Contact: desktop@oudu.top.
A small number of users may separately purchase optional value-added services. Those services are independently operated under separate terms and privacy policies; this policy only describes the Software’s integration boundary.
2. Data processed locally
Depending on the features you use, the Software may process locally:
- servers, databases, account details, and connection settings you add;
- interface, window, language, printing, scanning, and device preferences;
- necessary device, capability, endpoint, network, and task metadata;
- isolated sessions, cookies, cache, and other site data for each account;
- temporary captures, photos, recordings, scans, and print content; and
- redacted logs, diagnostics, and database recovery copies.
The Software never writes your Odoo password to disk. Sessions are protected by operating-system facilities when the platform supports them. On some Linux systems without an available keyring, at-rest protection supplied by the platform may be weaker. Credentials for optional services and future device pairing are not persisted when secure storage is unavailable.
3. Business content and user actions
Odoo business requests normally travel directly between your computer and the Odoo server you choose. Its operator determines how that data is processed. The Software may briefly process content in memory, cache, or controlled temporary files for previewing, printing, scanning, and uploads, but does not place content bodies in normal task history.
Gateway message debugging is off by default. When you enable it, headers and bodies of new requests and responses are redacted for credentials and kept for a limited size and duration in local memory. They are cleared when debugging is turned off, are not written to normal history or logs, are not uploaded automatically, and are excluded from diagnostic exports. Other business content may still be sensitive; enable debugging only when troubleshooting is needed.
Choosing Copy places content on the operating-system clipboard; Download or Save creates a file you control; using content in Odoo sends it directly to your selected Odoo server. The Software does not automatically clear the system clipboard or delete files you save.
4. Network connections
The Software connects only as needed to these categories:
- Odoo servers you configure, for sign-in and business operations;
- local or LAN devices you discover, add, or use;
- the update service or app store for your distribution channel;
- optional value-added services you activate; and
- external links you choose to open.
Network services can normally see an IP address, request time, software or browser version, and paths or device information needed to fulfil the request. The desktop app creates no advertising identifier, does not use Odoo business content for our analytics, and sends no hidden usage reports.
4.1 Optional value-added services
Only when you register or use such a service does the Software create a local host identity and potentially transmit a device identifier, device name, operating-system and Software versions, LAN IP/MAC addresses, subscription details, and a device credential. These are used to register the device, verify the subscription, and maintain the connection. The device credential is encrypted at rest on your computer; a user API key is used only for that registration and is not stored. When the subscription becomes inactive, the long-lived connection stops immediately, while the local identity, device credential, and latest subscription snapshot remain available for re-registration or recovery.
LAN sharing is off by default and enabled per fixed protocol and capability; discovery is not sharing. Native Odoo printing and customer display compatibility use HTTP on a controlled LAN without terminal authentication. Displays use only your valid explicit default target. Public-page tokens and the latest order are handled only during the active display session; local displays use an isolated temporary session without account cookies or token/order history. Ending the display, disabling or reconfiguring the gateway, or quitting clears the session. Any cloud relay requires separate disclosure and necessary authorisation.
5. Retention, removal, and export
- Print history retains the latest 90 days and no more than 10,000 requests, whichever limit is reached first; child records are removed with their request.
- Logs rotate at a fixed size. Each type of database recovery copy is limited to three copies and 30 days.
- Removing an account, database, or server clears its direct configuration and associated Chromium site data. Removing a device does not prematurely erase task history still within its retention period; the device reference is detached.
- To erase all local Software data, exit the Software and delete its application-data directory. Uninstalling alone may leave that directory and files you saved separately.
You can explicitly export a diagnostic ZIP. It contains only app/system metadata and rotating logs, not the database, cookies, account list, or Odoo page content. You choose whether and to whom to send the saved file; the Software never uploads it automatically.
6. Website, providers, and cross-border connections
This website uses Cloudflare Web Analytics to understand page visits and performance. Cloudflare states that it uses neither cookies nor localStorage to collect those metrics and does not fingerprint individuals through IP addresses, User-Agent strings, or other data. This website has no advertising tracking.
Cloudflare, Inc. (United States) provides hosting, analytics, or content delivery for this website and some distribution channels, and processes IP addresses, request identifiers, times, and requested paths under its policies. Contact and rights channels are available in the Cloudflare Privacy Policy. App stores, your Odoo operator, device providers, external websites, and optional-service operators each process your direct interactions under their own rules.
Visiting an overseas-hosted website, update service, or other service may cause your device to make a direct cross-border connection. Where applicable law requires it, we will provide additional notice, separate consent, or another required mechanism.
7. Security and children
We use account partitioning, narrow native bridges, transport validation, credential isolation, log redaction, resource budgets, and controlled temporary files. No measure guarantees absolute security; you remain responsible for protecting your device, system account, and Odoo server. The Software is for business users and is not directed at children under 14.
8. Your rights
You can inspect, correct, or remove local configuration through the relevant interface and erase all app data as described above. For data processed by your Odoo operator, an app store, an external provider, or an optional service, exercise your rights with that operator. You may also contact us at the address above; we will respond within the period required by applicable law.
9. Changes to this policy
This page always publishes the current version, with an updated version number and dates. Wording or factual corrections may be published directly. Before introducing material new collection, uploads, purposes, or recipients, we will give prominent notice and obtain explicit consent where required by law or by the feature.
如中英文版本存在歧义,以中文版为准。
If the Chinese and English versions differ, the Chinese version
prevails.