隱私權政策
Read in English ↓生活筆記與車廂配置主要保存在你的裝置;登入後的探險進度與社交資料保存在伺服器。用生活記錄參與雲端任務或選擇旅伴同行時,會送出必要的活動摘要;每日移動同行也會送出你填的步數或樓層數值。
1. 適用範圍與聯絡方式
本政策說明慢慢號 App 及公開網站的資料處理。營運者為 Velox Data Consulting Limited。資料或隱私問題請寄至 dev@loomory.co。
2. 登入與雲端遊戲資料
使用 Google 或 Apple 登入時,我們驗證登入憑證,保存登入供應商、該供應商的帳號識別碼(subject ID)、慢慢號玩家識別碼及建立/連結時間。目前 Google 僅請求 OpenID 登入識別,Apple 不請求姓名或電子郵件權限;我們不將 Google/Apple 的姓名或電子郵件保存為帳號資料。你自行設定的社交暱稱則會保存。
我們也保存 App 安裝識別碼、登入工作階段、存取/更新憑證的雜湊、到期及撤銷時間,用來驗證帳號與裝置、維持登入及防止未授權操作。登入流程會短期處理驗證狀態、nonce、授權碼及一次性兌換票券。原生裝置的登入憑證透過系統安全儲存保存;Web 的登入憑證只留在記憶體。
雲端遊戲資料包括探險與戰鬥進度、隊伍/角色/技能、收藏與物品、資源與使用紀錄、抽取紀錄、任務及登入日期、離線結算,以及操作回執與來源識別資料。這些資料用來保存進度、跨裝置取得雲端遊戲狀態、確認獎勵資格及避免重複操作。
3. 生活記錄、本機資料與備份
你的生活設定、活動與課程/練習紀錄、安排、日期、時間或時長、筆記、建議、手填週移動紀錄、車廂及家具配置,保存在本機資料庫(原生 App 使用 SQLite,Web 使用 IndexedDB)。裝置也會保存遊戲快取、待送出的操作與顯示/帶玩偏好。完整生活紀錄與房間配置目前不提供自動雲端備份。
但生活記錄並非所有欄位都只留在本機:登入後,符合雲端生活任務的活動確認可能送出活動識別碼、日期及活動名稱;選擇旅伴同行時,會送出活動識別碼、類型、日期、確認時間、來源、同行角色及相關任務識別碼。每日移動同行另會送出手填的步數或樓層數值,用來確認資格與記錄同行結果。這些摘要不包含完整自由筆記、老師建議或房間配置。更正或刪除活動可能另送撤銷紀錄;原遊戲回執不會因本機刪除而消失。
你可以自行產生完整 JSON 備份、研究匯出或原始存檔診斷檔。完整備份未加密,可能含私人筆記、研究回答及遊戲資料;請存放在信任的位置。還原會依確認內容取代本機資料,雲端遊戲帳本仍以伺服器為準。下載、系統分享或行事曆匯出由你選擇交付對象;已交出的檔案不會因 App 清除資料而自動刪除。
4. 運動與健康相關資料
目前 HealthKit/Health Connect 尚未連接,App 不會自動讀取這些服務的每日健康紀錄。健康回顧呈現你自行填寫的週步數、樓層、填報範圍、來源及備註;這些週紀錄保存在本機,不會當成即時感測資料。若你另在每日移動選擇雲端旅伴同行,手填數值會依上一節傳送。
活動及移動數值用於生活回顧與遊戲功能,不作醫療用途。本政策不將尚未啟用的健康資料讀取描述為已提供的功能。
5. 自願研究與回饋
研究由你另外自願同意。拒絕、略過或撤回不影響遊戲參與與獎勵。啟用後,本機會保存參與代碼、基線練習次數、同意範圍內的安排與參與事件、抽樣問卷、展示/略過紀錄、固定選項回答及選填補充。「自願回饋」中的送出按鈕保存到本機,不會直接傳送給研究者。
研究匯出由你自行下載或分享,包含參與代碼、基線、授權活動與安排的識別碼/日期/狀態、固定回答、事件與週統計;排除暱稱、自由名稱、筆記、老師建議、選填補充、步數、樓層及時長。完整備份則可能包含這些私人資料。撤回同意會停止新增研究事件與問卷;清除既有研究資料須在資料管理另行確認。已分享給研究者的檔案,請聯絡我們申請處理。
6. 社交資料與其他使用者
使用社交功能時,我們保存你設定的暱稱、頭像、好友碼、展示角色與技能/等級、好友請求、邀請、好友與封鎖關係、借用旅伴設定及紀錄、點讚與站內通知。依好友碼/邀請查找及社交功能,其他使用者可能看到你的簡要個人檔案;好友及支援功能也會呈現你選擇展示的角色資訊。請勿在暱稱中放入不想公開的個人資訊。
7. 第三方服務與網站
Google 與 Apple 提供登入驗證;App 後端使用 Google Cloud(台灣 asia-east1 區域)與 PostgreSQL,公開網站使用 Cloudflare Pages。登入供應商及主機服務商會依各自政策處理其提供服務所需的資料;資料處理地點可能因供應商服務而異。
目前 App 未加入第三方分析、廣告或崩潰回報 SDK,本網站不載入外部字型、CDN 資源或追蹤碼。App 的 API 關閉應用層請求記錄;這不代表主機服務商完全不處理網路連線資訊。
8. 保存、安全與你的選擇
本機資料會保留到你清除、移除 App 或瀏覽器/系統移除資料;請自行備份。雲端帳號及遊戲資料用於持續提供帳號、進度與操作核對,不會因登出或清除本機資料而自動刪除。我們以登入驗證、憑證雜湊及裝置安全儲存等措施保護資料,但無法保證任何儲存或傳輸方式絕對安全。
App 的「資料管理」提供備份與還原、研究同意管理、預覽並確認清除研究資料,以及清除全部本機資料。清除全部本機資料會清除正式存檔並登出,但不會刪除雲端帳號或你已下載的檔案。部分 Web 顯示偏好及舊原型配置可能仍保留,可另在瀏覽器設定清除此網站資料。
目前沒有 App 內的線上刪除帳號功能。若要刪除帳號及相關雲端資料,請來信 dev@loomory.co 申請,我們會在 30 天內處理;為避免誤刪他人資料,可能需要確認帳號歸屬。你也可以來信申請查詢、閱覽、取得副本、補充或更正、停止蒐集/處理/利用及刪除個人資料。如依法需保留特定資料,我們會說明範圍與原因。未提供登入及必要雲端資料時,將無法使用相應帳號與雲端功能。
9. 政策更新
若資料處理方式改變,我們會在此頁更新內容與生效日期;需要額外權限或同意的功能,會在使用前另行說明。
Privacy Policy — English
1. Scope and contact
This policy covers the Manmanhao (慢慢號) app and public website. Contact us at dev@loomory.co about personal data or privacy.
2. Sign-in and cloud game data
For Google or Apple sign-in, we verify authentication credentials and store the provider, its account subject ID, our player ID, and creation/linking timestamps. Google requests only OpenID identification; Apple does not request name or email permissions. We do not store Google/Apple names or email addresses as account data. A social nickname you choose is stored separately.
We store an app installation ID, sessions, access/refresh token hashes, expiry and revocation timestamps for authentication and device authorization. OAuth temporarily processes state, nonce, authorization codes and one-use redemption tickets. Native credentials use system secure storage; web session credentials remain in memory.
Cloud data includes expedition/battle progress, teams, characters and skills, collections, items, resources and spending, draws, tasks and login dates, offline settlements, command receipts and source identifiers. We use it to preserve cloud game progress across devices, validate rewards and prevent duplicate operations.
3. Local records, limited cloud summaries and files
Life settings, activity/class/practice records, schedules, dates, times or durations, notes, advice, manual weekly movement records, and carriage/furniture layouts are stored locally in SQLite on native devices or IndexedDB on the web. Devices also store game caches, pending operations and display/tutorial preferences. Full life records and room layouts are not automatically backed up to the cloud.
Some life data is sent to cloud game features. When signed in, eligible activity confirmation can send its canonical ID, date and activity name for cloud tasks. Choosing a companion sends activity identifiers, type, date, confirmation time, source, companion and task identifiers. Daily movement companionship additionally sends manually entered step or floor counts to check eligibility and record results. These summaries exclude full free-text notes, teacher advice and room layouts. Corrections or deletions can send revocation records; deleting local activity data does not erase original game receipts.
You may create full JSON backups, research exports or diagnostic files. Full backups are unencrypted and may contain private notes, research answers and game data. Store them securely. Restore replaces local data after confirmation and does not roll back the server ledger. You choose recipients for downloads, system sharing or calendar exports. Clearing app data does not remove files already delivered.
4. Movement and health-related data
HealthKit and Health Connect are not currently connected; the app does not automatically read their daily health records. The health review displays manually entered weekly steps, floors, reporting ranges, sources and notes, stored locally and not represented as live sensor data. Daily movement counts are transmitted if you separately choose cloud companionship as described above. Activity and movement data support life review and gameplay, not medical use.
5. Optional research and feedback
Research requires separate voluntary consent. Declining, skipping or withdrawing does not affect gameplay or rewards. Local research data includes a participant code, baseline practice counts, consent-authorized schedule/participation events, sampled questions, display/skip records, fixed-choice answers and optional comments. Submitting optional feedback saves it locally and does not directly send it to researchers.
You choose whether to download or share a research export. It includes participant code, baseline, authorized activity/schedule IDs, dates and statuses, fixed answers, events and weekly statistics. It excludes nicknames, custom names, notes, teacher advice, optional comments, steps, floors and durations. Full backups may still contain private fields. Withdrawing consent stops new research events/questions; clearing existing research data requires a separate confirmation. Contact us about research files already shared.
6. Social features
We store your chosen nickname, avatar, friend code, showcased characters and skills/levels, friend requests, invitations, friend/block relationships, borrowing settings and records, likes and in-app notifications. Other users may see your basic profile through code/invitation lookup and social features, and displayed character information through friend/support features. Avoid putting sensitive personal information in your nickname.
7. Service providers and website
Google and Apple provide sign-in verification. The app backend uses Google Cloud and PostgreSQL; the public website uses Cloudflare Pages. Providers process data needed for their services under their own policies, and processing locations may vary.
The current app includes no third-party analytics, advertising or crash-reporting SDKs. This website loads no external fonts, CDN assets or tracking code. API application-level request logging is disabled; this does not mean hosting providers process no network connection information.
8. Retention, security and controls
Local data remains until you clear it, uninstall the app, or your browser/system removes it. Keep your own backups. Cloud account/game data supports account continuity, progress and operation verification and is not automatically removed by logout or local clearing. We use authentication, token hashing and device secure storage, but cannot guarantee absolute security.
In-app Data Management offers backup/restore, research consent controls, confirmed research deletion and confirmed clearing of all local data. Clearing all local data removes the main local save and logs you out but does not delete your cloud account or downloaded files. Some web display preferences and legacy prototype layouts may remain; you can separately clear site data in your browser settings.
There is currently no in-app online account deletion feature. Email dev@loomory.co to request account and related cloud data deletion; we will process the request within 30 days and may verify account ownership. You may also request access, copies, correction, cessation of collection/processing/use, and deletion of personal data. If legal retention is required, we will explain its scope and reason. Without necessary sign-in/cloud data, related account and cloud features cannot be provided.
9. Updates
We will update this page and its effective date when data practices change. Features requiring additional permissions or consent will explain them before use.