隱私權政策
1. 個人資料之收集 (Information Collection)
當您註冊或登入本平台時,我們會收集您的「電子信箱 (Email)」或您的 Google 帳戶公開基本資料(例如名稱、頭像、內部用戶標識符)。此資料僅用於建立您的用戶身分、計算 S-Points 點數餘額、向您發送系統通知(例如臨時密碼、購買收據)以及辨識 API 呼叫擁有權,絕不用於第三方商業廣告或無關推廣。
When you register or sign in, we collect your email address or your Google account public profile. This data is used solely to authenticate your identity, track your S-Points balance, deliver transactional notices, and identify API credentials.
2. 資料儲存與去中心化特性 (Blockchain Storage Disclosure)
本平台整合區塊鏈進行永續儲存。請注意,您上傳至區塊鏈的任何「檔案內容」皆會被寫入去中心化之永久公開帳本上。本商號不擁有、亦無法控制該去中心化網路,因此無法對已發布在鏈上的檔案進行任何刪除、修改、撤銷或管理。用戶需對自行上傳之所有檔案內容、合法性、及著作權承擔完整之法律責任,本商號概不負責亦不承擔任何連帶法律責任。我們強烈建議您不要上傳任何包含個人敏感隱私資訊(例如身份證號、未加密之私鑰、病歷等)的檔案。如果您有隱私需求,請務必開啟本平台的「AES 加密上傳」功能,以確保第三方無法直接閱讀您的檔案內容。
The Platform utilizes decentralized blockchain networks for storage. Any file content uploaded will be written directly to a decentralized, permanent, and public ledger. The Company has no ownership or control over this network, and is completely unable to modify, delete, moderate, or manage files once written on-chain. Users assume absolute and sole legal liability and copyright responsibility for all submitted contents, and the Company accepts zero responsibility or liability. We advise against uploading unencrypted sensitive details. Use our AES GCM encryption mode to secure confidential documents.
3. 資訊安全與 Cookie 使用 (Security & Cookies)
我們採用業界標準之加密技術(例如 HTTPS/TLS、HttpOnly 安全 Cookie、AES-256-GCM、PBKDF2 密碼雜湊)來保護您的敏感身分資訊與傳輸通道。我們使用 HttpOnly Cookie 來儲存您的 JWT 會話資訊,這可以防止 JavaScript 惡意程式腳本(XSS 攻擊)讀取您的登入會話標記。
We implement strict industry security practices (including HTTPS, HttpOnly Session Cookies, and SHA-256 password hashes). HttpOnly cookies prevent XSS scripts from accessing your secure login session tokens.