本政策謹以一語概括:使用者之收藏資料,預設僅儲存於使用者自身之裝置;倘使用者選擇登入,則另備份於使用者自有之 Google 雲端硬碟。本應用程式不含廣告,亦無任何分析或追蹤工具。惟有二事應予敘明:擷取網頁預覽或全文時,使用者所收藏之網址會傳送予第三方服務(第四條);使用者主動啟用社群或「聯繫我們」功能時,相關資料會儲存於開發者所管理之雲端資料庫(第五條)。
本隱私權政策(下稱「本政策」)旨在說明「社群收藏管理器」(Social Collector,下稱「本應用程式」)如何處理使用者之資料。茲分述如次。
一、資料之蒐集
本應用程式之核心功能不需登入,亦無須提供任何個人資料。謹說明如下:
(一)使用者所新增之收藏(包含網址、標題、標籤、備註等),於預設情形下,僅儲存於使用者裝置瀏覽器之本機儲存空間(localStorage)之內。
(二)本應用程式不含任何廣告,亦不使用任何分析或追蹤工具。
(三)惟下列二種情形,資料將離開使用者之裝置,詳如各該條所述:其一,擷取網頁預覽與全文時,使用者所收藏之「網址」會傳送予第三方服務(詳見第四條);其二,使用者主動啟用「社群」或「聯繫我們」功能時,相關資料會儲存於開發者所管理之雲端資料庫(詳見第五條)。
二、Google 登入與雲端備份(選用功能)
使用者得自行選擇以 Google 帳號登入,將其收藏備份至自有之 Google 雲端硬碟。相關事項,說明如下:
(一)本應用程式僅請求 drive.file 此一最小範圍之權限,其效力僅及於「由本應用程式自身所建立之備份檔案」之讀寫;對於使用者雲端硬碟內之其他任何檔案,均無從讀取。
(二)備份內容為一 JSON 檔案(檔名為 社群收藏管理器-backup.json),存放於使用者自有之雲端硬碟中,開發者無從存取。
(三)登入時所取得之使用者名稱、電子郵件位址及大頭貼,僅用於本應用程式介面之顯示,概不傳送至其他任何處所。
(四)縱不登入,使用者仍得使用本應用程式之全部核心功能。
(五)為使登入得以持久、免除每小時重新授權之煩,使用者登入後,Google 所核發之長期授權憑證(refresh token)會加密後保存於開發者所管理之後端伺服器(Cloudflare Workers 及其 D1 資料庫,詳見第六條)。該伺服器所保存者僅有:Google 帳號識別碼、電子郵件位址、加密後之憑證,及建立與使用之時間戳記;不會讀取、亦不會保存任何收藏內容。備份檔案仍僅存於使用者自有之雲端硬碟,其內容不經過該伺服器。
三、Google 使用者資料之使用(有限使用聲明)
本應用程式對於經由 Google API 所取得之使用者資料,其存取、使用、儲存及分享,均遵循《Google API 服務使用者資料政策》(Google API Services User Data Policy),並符合其中之「有限使用」(Limited Use)要求。準此:
(一)前條所述之名稱、電子郵件位址及大頭貼,僅供介面顯示之用,別無他途,亦不移轉予任何第三人。
(二)drive.file 權限所及之備份檔案,僅限本應用程式自身所建立者,開發者並無存取之途徑。
(三)本應用程式不將前述資料用於任何廣告用途,亦不販售或以其他方式移轉予第三方。
四、第三方服務
(一)Microlink(api.microlink.io):當使用者貼上或分享網址時,本應用程式將該網址傳送至 Microlink,藉以擷取標題、縮圖等預覽資訊。此項請求係由使用者之瀏覽器逕行發出;除網址本身外,本應用程式不另附加使用者之任何個人資料。惟一如任何網路請求,Microlink 於接收之際,仍將取得使用者之 IP 位址及瀏覽器基本資訊(例如 User-Agent 字串)。Microlink 對前述資料之處理,適用其 隱私權政策。
(二)Jina AI Reader(r.jina.ai):當使用者開啟「全文閱讀」或新增收藏時,本應用程式將該網址傳送至 Jina AI Reader,藉以擷取該頁面之完整內文,供使用者於本應用程式內閱讀。此項請求係由使用者之瀏覽器逕行發出;除網址本身外,本應用程式不另附加使用者之任何個人資料。惟一如任何網路請求,Jina AI 於接收之際,仍將取得使用者之 IP 位址及瀏覽器基本資訊。Jina AI 對前述資料之處理,適用其 相關條款與隱私權政策。
(三)Google Identity Services 與 Google Drive API:僅於使用者主動使用 Google 登入功能時方予載入,並適用 Google 隱私權政策。
五、社群功能與雲端資料庫(選用功能)
本應用程式設有「社群」功能(好友分享、共同編輯、留言、按讚、私訊),及「聯繫我們」之訊息功能。使用者一旦啟用前述任一功能,相關資料即須儲存於開發者所管理之 Google Firebase/Cloud Firestore 資料庫(專案代號 social-collector-47ad0),俾能於使用者之間傳遞。茲說明如下:
(一)未使用社群功能者,不受本條影響。使用者之收藏資料,仍僅存於其裝置本機及(於選用備份時)其自有之 Google 雲端硬碟;開發者之資料庫內不會有其任何資料。
(二)啟用社群功能後,儲存於前述資料庫者,包括下列各項:
1. 會員資料:使用者之電子郵件位址、顯示名稱、方案別(Light/Pro)、方案到期日及試用狀態。
2. 個人檔案:顯示名稱、大頭貼、帳號代號(@handle)及好友人數。其中個人頁面係屬公開,任何取得該頁面連結者均得瀏覽。
3. 分享之收藏:使用者主動設為「好友可見」或「共同編輯」之收藏,其標題、網址、預覽圖、作者、摘要、筆記及劃線內容,均會上傳。未經分享之收藏不會上傳。
4. 社交關係與互動:好友名單、留言(含姓名、大頭貼及留言文字)及按讚紀錄。
5. 私訊:對話雙方之識別碼及訊息內容。
6. 「聯繫我們」之對話:使用者之顯示名稱、電子郵件位址及訊息內容。
7. 邀請碼:邀請碼本身、發送者及兌換者之識別碼。
(三)存取權限之控制:前述資料之讀寫權限,係由 Firestore 安全規則(Security Rules)於伺服器端強制執行。私訊僅限對話雙方讀取;好友限定之收藏及其留言,僅限擁有者與其好友讀取;會員資料僅限本人與管理員讀取。
(四)開發者之存取:開發者為維運之必要,得經由 Firebase 主控台存取上開資料庫之內容,並得讀取會員資料及「聯繫我們」之對話。除為排除故障、處理使用者所提出之請求,或依法令規定應予配合者外,開發者不會主動查閱使用者之私訊或分享內容,亦不將之用於任何廣告用途,更不販售或移轉予任何第三人。
(五)資料之所在地:前述資料存放於 Google Cloud Platform 之伺服器,並適用 Firebase 隱私權與安全性說明。
六、資料之保存與安全
(一)本應用程式之收藏資料,存放於使用者得自行掌控之處所——即其裝置之本機儲存空間,及(於選用備份時)其自有之 Google 雲端硬碟。惟使用者主動啟用社群或「聯繫我們」功能者,第五條所列之資料另存於開發者所管理之 Firestore 資料庫。
(二)Google 登入所生之短期存取權杖(access token)僅存於使用者瀏覽器之記憶體內,不寫入裝置之儲存空間。長期授權憑證(refresh token)則依第二條第(五)項,加密後保存於開發者所管理之後端(Cloudflare Workers/D1,位於 Cloudflare 之全球網路),僅用於替使用者換發短期權杖;後端須同時驗證使用者之 Firebase 登入身分與 App Check 憑證,始予換發。
(三)資料之保存期間,全由使用者自行決定;使用者得依第七條所載方式,隨時刪除之。
七、資料之刪除
(一)裝置上之資料:於瀏覽器中清除本網站之資料,或解除安裝本應用程式即可。
(二)雲端備份與授權憑證:請至使用者之 Google 雲端硬碟刪除 社群收藏管理器-backup.json 檔案。於本應用程式內按「登出」,後端所保存之授權憑證即會被刪除,並向 Google 撤銷;亦得至 Google 帳戶之第三方存取權設定,撤銷本應用程式之授權。
(三)社群資料:於本應用程式內,得自行刪除已分享之資料夾、留言及私訊。至於會員資料、個人檔案及「聯繫我們」之對話,因涉及帳號本身,請依第十一條所載方式來信,開發者將於合理期間內自資料庫中刪除之。
八、兒童隱私
本應用程式係一般用途之書籤整理工具,並非以兒童為對象而設計,亦未以兒童為訴求而行銷。開發者不會在知情之情形下,蒐集未滿十三歲兒童之個人資料。倘家長或監護人發現有此情事,請依第十一條所載方式來信,開發者將儘速刪除之。
九、使用者權利
鑑於開發者並不蒐集、保存或處理任何使用者之個人資料,本應用程式就使用者之個人資料,並不居於資料控管者之地位。使用者對其自有之資料,本即擁有完全之掌控權,並得依第七條所載方式,隨時查閱、匯出或刪除之。倘依當地法令(如歐盟《一般資料保護規則》〔GDPR〕或美國加州《消費者隱私法》〔CCPA〕)另有相關權利,使用者亦得逕向前述第三方服務(Google、Microlink)主張之。
十、政策之變更
本政策倘有重大變更,將更新本頁面之內容,並一併修正頁首所載之「最後更新日期」。
In brief: your collection data is by default stored only on your own device and, should you choose to sign in, additionally backed up to your own Google Drive. The Application contains no advertising and employs no analytics or tracking tools. Two matters warrant mention, however: when a page preview or full text is retrieved, the URL you have saved is transmitted to third-party services (Section 4); and when you actively enable the Community or “Contact Us” features, the relevant data is stored in a cloud database managed by the developer (Section 5).
This Privacy Policy (the “Policy”) explains how Social Collector (the “Application”) handles user data. The provisions below apply.
1.Collection of Data
The Application’s core features require no sign-in and no personal data. Specifically:
(a) The collections you add (including URLs, titles, tags, and notes) are, by default, stored only within your device browser’s local storage (localStorage).
(b) The Application contains no advertising and employs no analytics or tracking tools of any kind.
(c) There are, however, two circumstances in which data leaves your device, each described in the section indicated: first, when retrieving a page preview or full text, the URL you have saved is transmitted to third-party services (see Section 4); second, when you actively enable the “Community” or “Contact Us” features, the relevant data is stored in a cloud database managed by the developer (see Section 5).
2.Google Sign-In and Cloud Backup (Optional)
You may choose to sign in with a Google account and back up your collections to your own Google Drive. The following provisions apply:
(a) The Application requests only the minimal drive.file scope, the effect of which extends solely to reading and writing files that the Application itself has created; it cannot access any other file in your Google Drive.
(b) The backup consists of a single JSON file (named 社群收藏管理器-backup.json) stored in your own Google Drive, to which the developer has no access.
(c) The name, email address, and profile picture obtained upon sign-in are used solely for display within the Application’s interface and are transmitted nowhere else.
(d) All core features of the Application remain available without signing in.
(e) So that you need not re-authorize every hour, the long-lived authorization credential (refresh token) issued by Google upon sign-in is stored, encrypted, on a backend server managed by the developer (Cloudflare Workers and its D1 database; see Section 6). That server holds only: your Google account identifier, your email address, the encrypted credential, and creation/usage timestamps. It neither reads nor stores any of your collection content; the backup file continues to reside solely in your own Google Drive and does not pass through that server.
3.Use of Google User Data (Limited Use)
The Application’s access to, and use, storage, and sharing of, any user data obtained through Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Accordingly:
(a) The name, email address, and profile picture described above are used solely for interface display, for no other purpose, and are transferred to no third party.
(b) The backup file accessible under the drive.file scope is limited to files the Application itself has created, and the developer has no means of access.
(c) The Application uses none of the foregoing data for any advertising purpose, and neither sells nor otherwise transfers it to any third party.
4.Third-Party Services
(a) Microlink (api.microlink.io): When you paste or share a URL, the Application transmits that URL to Microlink in order to retrieve preview information such as the title and thumbnail. This request is issued directly by your browser; apart from the URL itself, the Application appends none of your personal data. However, as with any network request, Microlink will upon receipt necessarily obtain your IP address and basic browser information (such as the User-Agent string). Microlink’s handling of such data is governed by its Privacy Policy.
(b) Jina AI Reader (r.jina.ai): When you open the “full-text reading” feature or add an item, the Application transmits that URL to Jina AI Reader to retrieve the full text of the page for in-app reading. This request is issued directly by your browser; apart from the URL itself, the Application appends none of your personal data. However, as with any network request, Jina AI will upon receipt necessarily obtain your IP address and basic browser information. Jina AI’s handling of such data is governed by its terms and privacy policy.
(c) Google Identity Services and the Google Drive API: These are loaded only when you actively use the Google Sign-In feature and are governed by the Google Privacy Policy.
5.Community Features and Cloud Database (Optional)
The Application provides “Community” features (sharing with friends, co-editing, comments, likes, and direct messages) and a “Contact Us” messaging feature. Once you enable any of these, the relevant data must be stored in a Google Firebase / Cloud Firestore database managed by the developer (project social-collector-47ad0) in order to be delivered between users. The following provisions apply:
(a) If you do not use the Community features, this Section does not affect you. Your collections remain solely on your device and, where backup is used, in your own Google Drive; the developer’s database will hold no data of yours.
(b) Once the Community features are enabled, the database stores the following:
1. Membership data: your email address, display name, plan (Light / Pro), plan expiry, and trial status.
2. Profile: display name, avatar, account handle (@handle), and friend count. Your profile page is public and may be viewed by anyone holding its link.
3. Shared collections: for collections you have actively set to “visible to friends” or “co-edited”, the title, URL, preview image, author, summary, notes, and highlights are uploaded. Collections you have not shared are not uploaded.
4. Social graph and interactions: your friend list, comments (including name, avatar, and comment text), and likes.
5. Direct messages: the identifiers of both parties and the message content.
6. “Contact Us” conversations: your display name, email address, and message content.
7. Invitation codes: the code itself and the identifiers of the issuer and the redeemer.
(c) Access control: read and write permissions for the foregoing are enforced server-side by Firestore Security Rules. Direct messages are readable only by the two parties; friends-only collections and their comments only by the owner and their friends; membership data only by the member and the administrator.
(d) Developer access: as necessary for operation and maintenance, the developer may access the contents of the database through the Firebase console, and may read membership data and “Contact Us” conversations. Save where required to diagnose faults, to act upon a request made by a user, or to comply with applicable law, the developer does not review users’ direct messages or shared content, uses none of it for any advertising purpose, and neither sells nor transfers it to any third party.
(e) Location of data: the foregoing data is stored on Google Cloud Platform servers and is subject to Firebase’s privacy and security documentation.
6.Data Retention and Security
(a) Your collection data resides in locations within your control — namely your device’s local storage and, where backup is used, your own Google Drive. Where you have actively enabled the Community or “Contact Us” features, however, the data listed in Section 5 is additionally stored in a Firestore database managed by the developer.
(b) The short-lived access token arising from Google Sign-In is held solely in your browser’s memory and is not written to device storage. The long-lived credential (refresh token) is, as described in Section 2(e), stored encrypted on a backend managed by the developer (Cloudflare Workers / D1, hosted on Cloudflare’s global network) and used solely to issue short-lived tokens to you; the backend verifies both your Firebase sign-in identity and an App Check attestation before doing so.
(c) The retention period is determined entirely by you; you may delete the data at any time by the means set out in Section 7.
7.Deletion of Data
(a) Data on your device: clear this site’s data in your browser, or uninstall the Application.
(b) Cloud backup and authorization credential: delete the 社群收藏管理器-backup.json file from your Google Drive. Signing out within the Application causes the backend to delete the stored credential and revoke it with Google; you may also revoke the Application’s authorization via your Google account’s third-party access settings.
(c) Community data: within the Application you may delete your shared folders, comments, and direct messages yourself. As for membership data, your profile, and “Contact Us” conversations — which pertain to the account itself — please write to the developer by the means set out in Section 11, and they will be deleted from the database within a reasonable period.
8.Children’s Privacy
The Application is a general-purpose bookmark-organizing tool. It is neither designed for nor marketed to children. The developer does not knowingly collect personal data from children under 13. Should a parent or guardian become aware that this has occurred, please write to the developer by the means set out in Section 11 and the data will be deleted promptly.
9.Your Rights
As the developer collects, retains, and processes no user personal data, the Application does not act as a data controller with respect to your personal data. You retain full control over your own data and may access, export, or delete it at any time by the means set out in Section 7. To the extent applicable law (such as the EU General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA)) confers further rights, you may also assert those rights directly with the third-party services named above (Google and Microlink).
10.Changes to this Policy
Should this Policy undergo material change, the content of this page will be updated and the “Last updated” date at the top revised accordingly.
11.Developer Information and Contact
The Application is developed and maintained by 哩賣亂工作室. If you have any questions regarding this Policy, please write to: [email protected].
Note: The Chinese version of this Policy governs; the English version is provided for reference only. In the event of any discrepancy between the two, the Chinese version shall prevail.