影伴隐私说明
影伴面向家庭和未成年学习者,默认遵循数据最小化原则。本说明描述当前 Dogfooding 和小规模内测版本的技术行为。
我们收集和保存什么
家长账号与家庭基本配置信息
家长用于登录的邮箱由 Supabase Auth 处理,系统记录家庭空间基础信息用于档案管理。
日常学习打卡与成长积分记录
记录学习者年级、打卡、积分、书架与练习状态。不要求提供未成年人真实姓名、精确位置或照片。
- 家长用于登录的邮箱,由 Supabase Auth 处理。
- 家庭空间名称。
- 学习者显示名称和年级。建议使用昵称,不填写真实姓名。
- 打卡、积分、书架和阅读日志等学习状态。
当前版本不要求儿童提供邮箱、手机号、生日、学校、地址、精确位置或照片,也不包含广告。
分析服务和朗读功能
应用通过 Vercel Web Analytics 记录匿名、聚合的页面访问数据,以及以下不带自定义属性的最小事件:首次激活、首次打卡、达到连续 3 天打卡、用户可见的学习记录同步失败和用户可见的 TTS 失败。事件不会发送学习状态、邮箱、家庭/孩子 ID、儿童显示名称、错误文本或语音文本;首次和连续使用事件只在本机用标记去重。页面访问和自定义事件可能包含时间、页面 URL、来源、设备、浏览器、操作系统和粗略地理位置。详情见 Vercel Web Analytics Privacy and Compliance。
正式站点配置 VibeCafé 作品统计后,打开影伴即加载其页面浏览脚本,用于公开作品榜单的 UV/PV。当前脚本会在本站浏览器存储中保存随机访客标识,同一浏览器后续访问可被识别,并向 VibeCafé 发送该标识及页面浏览事件。普通网络连接还会向该服务暴露 IP 和浏览器等连接信息。当前脚本不会在事件正文中发送学习状态、账号邮箱、家庭/孩子 ID、儿童名称或页面 URL;本站设置 Referrer-Policy: no-referrer。启用 Do Not Track 或 Global Privacy Control 时,当前脚本不创建访客标识,也不上报事件。清除本站浏览器数据可移除访客标识;应用内“清除本机数据”不会清除它。VibeCafé 的数据处理和保留期限以该服务的实际政策为准。
固定课程文字会在发布准备阶段发送给腾讯云语音合成,生成后的 MP3 保存在项目自己的 COS/CDN 中供所有用户复用。用户点击播放时不会把文字、学习记录、账号信息或儿童资料发送给腾讯云,也不会触发新的付费合成。浏览器可能按标准 HTTP 规则缓存这些音频。影伴不采集麦克风录音。
家长同意和学习者档案
学习者不是独立登录账号。创建第一个学习者或添加学习者前,登录用户必须确认自己是家长或监护人,并阅读本隐私说明。系统会在 Supabase 数据库记录家庭 ID、认证用户 ID、同意类型 learner_data_processing、隐私说明版本 privacy-v1 和数据库生成的同意时间。客户端不能修改同意时间戳,也不能在没有同意记录的情况下通过公开 API 创建新的学习者档案。
数据存放和访问
- 离线学习状态保存在当前设备的浏览器存储中。
- 登录后,家庭和学习状态同步到项目配置的 Supabase 数据库。
- 登录会话保存在当前设备的浏览器本地持久存储中,支持长期免重复登录;退出登录或清除本机数据时会一并清除。
- 学习数据按家庭隔离,登录用户仍必须通过家庭成员关系和 RLS 才能读取或修改记录。
本机缓存通常会在关闭浏览器后继续保留,直到用户清除该网站的浏览器数据、使用隐私/无痕窗口、浏览器或系统自动清理,或更换访问域名。登录并同步后,云端家庭记录才是跨设备恢复来源。
删除、导出和保留
- “清除本机数据”只删除当前设备的离线学习记录并退出登录,不删除云端记录。
- 家庭所有者可以从账号面板导出完整家庭 JSON 数据,也可以使用“删除全部家庭数据”删除当前家庭的云端记录、清理本机数据并退出登录。
- 共享 Supabase 项目中的家庭数据删除不会删除 Supabase Auth 身份;用户仍可使用同一邮箱重新登录。
- 删除学习者或家庭时,同意记录随家庭或学习者所属家庭级联删除。
当前没有独立的“撤回同意但保留家庭”的自助流程。数据保留期限、删除、导出、更正和撤回请求会根据产品运营地区和适用法律持续更新。
安全问题
请不要在公开 Issue 中提交个人数据或安全漏洞。安全问题请通过仓库的私密漏洞报告功能提交。
Shadow Mate Privacy Policy
Shadow Mate is designed for families and learners who may be minors. We follow data minimization by default. This policy describes the technical behavior of the current Dogfooding and small-scale beta version.
What We Collect and Store
Parent Account and Household Configuration
The parent's email address used to sign in is handled by Supabase Auth, and the family space name organizes household settings.
Daily Learning Progress and Points Records
Includes learner display names, grade levels, check-ins, points balances, bookshelf records, and handwriting progress. We do not collect phone numbers, exact locations, or photos.
- The parent's email address used to sign in, handled by Supabase Auth.
- The family space name.
- The learner's display name and grade. We recommend using a nickname instead of a real name.
- Learning activity such as check-ins, points, bookshelf items, and reading logs.
The current version does not require a child to provide an email address, phone number, birthday, school, address, precise location, or photo. It does not contain advertising.
Analytics and Reading Aloud
The app uses Vercel Web Analytics for anonymous, aggregated page-visit data and a minimal set of custom events without custom properties: first activation, first check-in, reaching a three-day check-in streak, user-visible learning-record sync failures, and user-visible TTS failures. Events do not send learning state, email addresses, household/learner IDs, learner display names, error text, or speech text. First-use and streak events are deduplicated with local browser flags. Page views and custom events may include the time, page URL, referrer, device, browser, operating system, and approximate location. See Vercel Web Analytics Privacy and Compliance for details.
When VibeCafé work statistics are configured on the production site, Shadow Mate loads its pageview script as soon as the site opens so the work can participate in public UV/PV rankings. The current script stores a random visitor identifier in this site's browser storage, recognizes later visits from the same browser, and sends that identifier with a pageview event to VibeCafé. Normal network requests also expose connection information such as IP address and browser details to the service. The current event body does not include learning state, account email, household/learner IDs, learner names, or the page URL; this site sets Referrer-Policy: no-referrer. With Do Not Track or Global Privacy Control enabled, the current script neither creates the identifier nor sends events. Clearing this site's browser data removes the identifier; the in-app “Clear local data” action does not. VibeCafé's own data handling and retention follow its current policies.
Fixed public curriculum text is sent to Tencent Cloud TTS during release preparation. Generated MP3 files are stored in the project's COS/CDN for shared reuse. Playback does not send curriculum text, learning history, account data, or child profile data to Tencent and does not trigger paid synthesis. Browsers may cache these files under standard HTTP rules. Shadow Mate does not record microphone audio.
Parental Consent and Learner Profiles
A learner is not an independent login account. Before creating or adding a learner, the signed-in user must confirm that they are the child's parent or guardian and read this policy. Supabase stores the household ID, authenticated user ID, consent type learner_data_processing, policy version privacy-v1, and a database-generated consent timestamp. The client cannot change the timestamp, and the public API cannot create a new learner profile without a consent record.
Where Data Is Stored and Who Can Access It
- Offline learning state is stored in the browser storage on the current device.
- After sign-in, household and learning state sync to the Supabase database configured for the project.
- The sign-in session is stored in the browser's local persistent storage on the current device to support long-lived logins; it is cleared upon sign-out or clearing local data.
- Learning data is isolated by household. Signed-in users must still pass household membership checks and Row Level Security (RLS) to read or change records.
Local cache normally remains after the browser closes until the site's browser data is cleared, a private/incognito session is used, the browser or operating system cleans it up, or the site domain changes. After synchronization, the cloud household record is the source for cross-device recovery.
Deletion, Export, and Retention
- “Clear local data” removes only offline learning records from the current device and signs the user out; it does not delete cloud records.
- The household owner can export the full household data as JSON or use “Delete all household data” to remove the current household's cloud records, clear local data, and sign out.
- Deleting household data in the shared Supabase project does not delete the Supabase Auth identity; the user can sign in again with the same email.
- When a learner or household is deleted, its consent record is deleted through the household-level cascade.
There is currently no self-service flow to withdraw consent while keeping the household. Data retention periods and requests for deletion, export, correction, or withdrawal will be updated as the operating region and applicable laws require.
Security Issues
Do not submit personal data or security vulnerabilities in public issues. Please use the repository's private vulnerability reporting process for security issues.