跳至主要內容
HoMade Works Logo
HoMade Works
← 回到拾讀|LeafTrove
拾讀|LeafTrove・隱私與資料 預發布草案

拾讀|LeafTrove 隱私政策

版本草案 0.2 · 最後更新:2026 年 9 月 15 日

本頁依目前測試版的實際資料流整理。營運者與聯絡信箱已沿用注音小學堂 iOS 版的公開資料;法定公開地址、供應商方案細節、各地代表與申訴方式仍須在全球上架前補齊並完成法律審閱。

繁體中文

English ↓
定稿前提醒:法定公開地址、供應商方案/跨境安排、各地資料保護聯絡方式與生效日尚待法律定稿。這些欄位完成前,本頁是預發布說明,不是完整法律通知。

1. 誰負責處理資料

拾讀由 HSIHSUN HO(HoMade Works)獨立開發與維護,與注音小學堂 iOS 版使用同一公開開發者資料。隱私與客服信箱為 [email protected]。注音小學堂的 App Store 公開頁沒有列出法定服務地址,因此拾讀不自行推定地址;正式全球政策會補上可公開的法定地址或法律顧問確認的替代聯絡方式。

2. 我們處理哪些資料

  • Apple 登入所需的使用者識別資料、短效工作階段與更新用憑證;憑證保存在裝置 Keychain。
  • 書籍識別碼、書名、作者、畫線、心得、來源修改時間、收藏、封存、回顧排除、回顧選文、同步游標與配對狀態。
  • 通知、小工具、回顧來源與提醒時間等裝置設定。
  • 帳號刪除申請的請求識別碼、收據與處理狀態。
  • 連線所需的 IP、請求時間、裝置/作業系統資訊與固定錯誤紀錄。同步報告以版本、批數與筆數為主,不把筆記原文寫入應用程式日誌。

拾讀不要求你提供 Kobo 帳號密碼;目前版本不提供廣告個人化、AI 摘要、公開排行榜或跨帳號社交功能。

3. 使用目的

資料用於建立及恢復帳號、取得你授權的 Kobo 同步內容、在裝置間更新書庫、提供搜尋/今日拾讀/收藏/匯出/帳號刪除、維持同步續作、排程通知,以及偵測安全性與服務故障。

4. Kobo 封面請求

有可用封面識別碼時,App 會直接向 cdn.kobo.com 請求圖片。App 傳送封面識別碼,不傳送筆記文字、收藏狀態或 Apple 登入憑證;圖片服務仍可能取得 IP、時間、User-Agent 與一般技術紀錄。拾讀目前沒有自有伺服器封面代理或 R2 快取;圖片主機的所在地、保存期限、服務條款與封面展示/商用權利仍須另行確認。

5. 接收者與跨境處理

目前實際資料流涉及 Apple Sign in with Apple、Cloudflare Workers(kobonotes-p2-api)、Cloudflare D1(kobonotes-p2-data,目前讀取區域為 APAC、未啟用讀取複本)及 cdn.kobo.com。Cloudflare Pages 另託管本網站的靜態政策頁。正式版本會逐項列出處理者、目的、所在地、契約依據、跨境傳輸機制與子處理者;拾讀不會把帳號憑證提供給 Kobo,也不會把筆記內容交給廣告服務。

6. 保存、匯出與刪除

書庫資料保存在 App 私有儲存空間,工作階段憑證保存在 Keychain。活躍帳號的雲端書籍、畫線、心得、偏好、同步批次與變更會保留至你刪除帳號或法律要求較早刪除;目前沒有閒置自動刪除。配對終止資料只為支援與重送排查短暫保留:已過期/撤銷及已確認配對,會在 pairing 到期後保留 30 天再由排程清除;裝置 credential 依自己的期限與撤銷狀態保存,清理不會撤銷仍在生命週期內的裝置。這項清理已在 build 21 程式與測試完成,production D1 套用 migration 0007 後生效。`changes` feed 歷史目前沒有固定 TTL。登出會清除目前裝置的書庫、收藏與回顧狀態;雲端資料需使用帳號刪除流程處理。刪除受理交易會移除目前可查詢的雲端內容,完成收據雜湊保留 30 天,防止刪除前登入重建的雜湊屏障約保留 24 小時;Apple 撤銷所需的加密憑證只保留到撤銷完成。Cloudflare D1 的災難復原歷史依方案可能另保留 7 或 30 天,這是供應商控制的備份期限,不是拾讀可在 App 內立即刪除的資料。

7. 你的選擇與權利

你可以關閉每日拾讀提醒與小工具、登出、匯出資料、解除 Kobo 連結或提出帳號刪除申請。正式政策會依所在地說明查閱、更正、刪除、限制處理、反對處理、資料可攜、撤回同意與向主管機關申訴的方式。

8. 安全、兒童與變更

App 使用 HTTPS、裝置 Keychain 與系統資料保護功能,但任何網路服務都不能保證絕對安全。拾讀不是以兒童為主要對象;未成年人使用時,請由家長或監護人依所在地法律判斷並陪同。正式政策會補充安全事件流程、跨境傳輸、兒童規則、生效日及變更通知。

English summary

繁體中文 ↑
Pre-launch draft: The operator and support email follow the public information used by the Zhuyin Academy iOS app. The final policy still needs the legal address, provider-plan and transfer details, regional contacts, and effective date after legal review.

LeafTrove (拾讀) is operated by HSIHSUN HO (HoMade Works). Privacy and support contact: [email protected]. The Zhuyin Academy iOS store page identifies the same developer but does not publish a legal service address; that address and any regional representative will be added after review.

Current production test services are Apple Sign in with Apple, Cloudflare Workers (kobonotes-p2-api), Cloudflare D1 (kobonotes-p2-data, APAC primary, no read replicas), Cloudflare Pages for homadeworks.com, and Kobo’s cdn.kobo.com for cover requests. The app has no cover proxy or R2 cache and no advertising or analytics SDK.

Depending on the features you use, the app may process Apple sign-in identifiers and session credentials, book and note content, favorites and review preferences, paired-device status, local reminder and widget settings, deletion receipts, and ordinary connection diagnostics. Sign-in credentials are stored in the device Keychain. The app does not ask for a Kobo account password and the current build does not provide advertising personalization, AI summaries, public rankings, or cross-account social features.

When a cover identifier is available, the app requests an image from cdn.kobo.com. It sends the cover identifier, not note text, favorite state, or Apple credentials. The image service may still receive ordinary technical request data such as IP address, time, and User-Agent.

Signing out clears the current device’s private library state. Active cloud content remains while the account is active. Terminal pairing metadata is purged 30 days after the pairing expires for expired, revoked, or confirmed jobs; device credentials follow their own expiry and revocation lifecycle, and this cleanup does not revoke a live device. The build 21 code and tests are complete, and production takes effect after migration 0007 is applied. The account deletion flow removes queryable cloud content when accepted; a completion receipt hash is kept for 30 days, a deletion-login barrier for about 24 hours, and encrypted Apple refresh material only until revocation completes. The changes feed has no fixed TTL yet. D1 disaster-recovery history may remain for Cloudflare’s plan-dependent 7- or 30-day window. You can export books and notes before submitting a request.

For pre-launch support or privacy questions, email [email protected]. This summary is not a complete legal notice until the missing operator details are filled and reviewed.