Privacy Policy
隐私政策
Toti 开发者通过银杏 Ginkgo 提供笔记、任务、项目与协作功能。本政策说明我们如何处理你使用这些功能时提供的信息。隐私问题与数据请求请联系 [email protected]。
1. 我们处理哪些信息
- 账户与身份信息:你提供的邮箱或手机号、账户标识、昵称、头像及验证状态。邮箱密码与手机验证由 Google Firebase Authentication / Identity Platform 处理;业务后端接收验证后的身份凭据并创建应用会话,不接收你的 Firebase 登录密码。
- 你主动创建或提交的内容:笔记、任务、项目、讨论消息、协作关系以及上传的文件和图片。不同功能可能只在本地保存,也可能在使用在线功能时提交到服务器。
- 设置与服务配置:应用偏好,以及你主动填写的第三方 AI 服务地址、模型偏好和访问凭据等配置(如使用该功能)。
- 运行与安全信息:设备或会话标识、网络请求的必要 IP 信息、时间与错误信息,用于身份保护、访问控制和故障排查。
- 支持邮件:你发送给开发者的联系方式、问题描述及主动附上的资料。
2. 信息的用途
我们使用这些信息提供登录、内容保存与同步、项目协作、附件访问、设置管理和用户支持,并保护账户与服务安全。我们不出售个人信息,也不为跨应用广告追踪使用这些信息。
3. 数据分享与服务供应商
当你共享项目、文件或发送消息时,相关内容会按你的操作与访问权限提供给其他参与者。在线服务使用 Google Cloud 提供计算与存储,身份验证使用 Firebase Authentication / Identity Platform,附件保存在 Google Cloud Storage。供应商为运行这些服务处理必要信息,其处理也受各自条款与隐私政策约束。可参阅 Firebase 隐私与安全说明和 Google Cloud 隐私声明。
若你启用或调用自行配置的第三方 AI 服务,相关服务配置或请求内容可能由你选择的供应商处理。请在使用前了解该供应商的隐私政策。
4. 存储地区与安全
目前在线业务的主服务器位于比利时,附件存储位于 Google Cloud 的欧洲区域。Google 身份验证及其他供应商服务可能按其服务安排在其他地区处理必要信息。我们采用 HTTPS、会话保护和访问权限控制等安全措施;任何网络传输或存储方式都无法保证绝对安全。
5. 离线与设备数据
访客探索和离线测试内容可保存在设备上。应用也可能在设备上缓存已授权的在线内容,并在系统 Keychain 中保存登录会话。离线内容不会因为切换到在线模式而自动作为协作数据上传。卸载应用可能移除部分本地内容,但不会自动删除服务器账户,也不保证清除系统 Keychain 中保留的凭据。
6. 保留与删除
账户和在线内容在提供服务所需期间保留。你可以使用应用中提供的编辑、删除、退出和权限设置,或通过上述邮箱请求访问、更正、导出或删除个人信息及账户。为保护账户,我们可能需要核实请求者身份。
为灾难恢复、安全或履行适用义务,部分副本可能延后清理。当前日常数据库备份保留 30 天,云服务软删除保护另保留 7 天;备份不作为正常业务内容展示。迁移、恢复或其他供应商保留机制的实际清理情况,可通过联系邮箱查询。
7. 未成年人、网站与政策更新
本服务用于一般生产力和协作场景。若监护人认为未成年人提供了需要处理的个人信息,请联系我们。本介绍网站不使用广告、第三方分析脚本或追踪 Cookie。发送支持邮件时,邮件服务商会处理投递所需的信息。
我们会根据功能与服务变化更新本政策,并在此页面标明更新日期。对数据处理有任何疑问,请联系 [email protected]。
English version
Privacy Policy
This policy covers the Toti / Ginkgo iPhone and iPad app and this website. The Toti developer provides notes, tasks, projects and collaboration features. Contact [email protected] for privacy questions or data requests.
Information we process
We process the email address or phone number, account identifier, profile and verification status you provide; notes, tasks, projects, messages, sharing relationships and files you create or submit; preferences and any third-party AI service configuration or credentials you choose to enter; necessary device/session identifiers, request IP information, timestamps and errors for operation and security; and information you include in support emails. Firebase Authentication / Identity Platform handles email/password and phone verification. Our business backend receives verified identity credentials and creates app sessions; it does not receive your Firebase sign-in password.
Use and sharing
Information is used to provide authentication, content storage and synchronization, collaboration, file access, settings and support, and to protect the service. We do not sell personal information or use it for cross-app advertising tracking. Content you share is made available to other participants according to your actions and access permissions.
Google Cloud provides online computing and storage, Firebase Authentication / Identity Platform provides identity verification, and Google Cloud Storage stores attachments. Providers process necessary information under their own terms and policies: Firebase privacy and security and the Google Cloud Privacy Notice. If you enable or call a third-party AI service you configure, its provider may process the relevant configuration or request content. Review that provider's policy before use.
Storage and security
The current main business server is in Belgium and attachments are stored in Google Cloud's European region. Identity and other provider services may process necessary information in other locations under their service arrangements. We use HTTPS, session protection and access controls. No transmission or storage method can guarantee absolute security.
Device and offline data
Guest exploration and offline test content may remain on your device. The app may cache authorized online content and save session credentials in the system Keychain. Changing to online mode does not automatically upload offline content as collaboration data. Uninstalling may remove some local content, but does not automatically delete the server account or guarantee removal of Keychain credentials.
Retention and your requests
Accounts and online content are retained as needed to provide the service. Use available app controls or contact us to request access, correction, export, or deletion of your personal information and account. We may verify your identity. Copies may take longer to remove for disaster recovery, security or applicable obligations. Daily database backups currently have a 30-day retention period, followed by 7 days of cloud soft-delete protection. Backups are not displayed as normal service content. Contact us for the applicable cleanup status of migration, recovery or other provider-held copies.
Other information
The service is intended for general productivity and collaboration. Guardians may contact us concerning a minor's personal information. This website does not use advertising, third-party analytics scripts or tracking cookies. Email providers process information needed to deliver support messages. We may update this policy as features and services change and will show the update date on this page.