隱私政策
最後更新:2026 年 9 月 6 日
本隱私政策依據中華民國《個人資料保護法》及相關法令訂定,說明 Tentory 露營記(以下稱「本 App」)如何蒐集、使用、儲存與保護你的個人資料。使用本 App 前請詳閱本政策。
資料控制者(蒐集者):Yan-Che, Lin(營運 Tentory)
聯絡信箱:support@tentory.app
1. 我們蒐集的資料
- 帳號資料:電子郵件(以 Email 註冊時);或 Apple、Google 登入所提供的帳號識別碼;暱稱、頭像與自訂稱謂。
- 露營紀錄:營地名稱與地區、入營日期、七項星等評比、優點標籤、心得文字、天氣與脈絡、以及你上傳的照片。這些內容依你為該筆紀錄選擇的可見性(私人/限露友/公開)分享,詳見第 5 節。
- 衍生的彙總資料:由你的紀錄計算出的統計(露營次數、縣市足跡)、等級與徽章。你開啟公開個人頁時,依你的逐項隱私開關,這些彙總資料可能顯示於公開個人頁。
- 裝備資料:你建立的裝備清單、告示牌求售/求購貼文。
- 社群資料:追蹤關係、封鎖與檢舉紀錄;你發表的留言,以及市集一對一詢問訊息。
- 技術資料:為維運與安全所必要的一般性紀錄(如錯誤與存取記錄),由 Google Firebase 產生;以及本 App 發生當機時的診斷資料(當機堆疊、App 版本、裝置機型與作業系統版本)。當機診斷資料不包含你的心得、照片或帳號識別資訊。
裝置權限:本 App 僅在你上傳照片時請求「相機」與「照片圖庫」權限。我們不索取定位、通訊錄與麥克風權限,也沒有推播通知;營地與縣市都由你自己選擇,足跡地圖是從你的紀錄累積出來的,不使用衛星定位。
我們不做的事:我們不出售你的個人資料;不投放個人化廣告、不使用廣告識別碼、不安裝任何行銷或行為分析 SDK;除本政策第 4 節所列的服務供應商外,不與任何資料仲介或第三方分享你的資料。
2. 蒐集之特定目的與利用依據
- 提供並維護本 App 功能(紀錄、統計、徽章、社群動態、市集)——履行你與我們間的服務契約(特定目的參考代號:069 契約與類似契約關係管理、090 消費者與客戶管理)。
- 依你設定的可見性(公開/限露友/私人)顯示內容——依你的主動選擇。
- 維護社群安全:對公開或限露友分享的照片與文字進行自動內容審核,處理檢舉與封鎖——為維持服務安全所必要。
- 彙整不含個人識別的統計(例如營地的正向數字)——157 調查、統計與研究分析。
- 與你就服務相關事項聯繫(客服回覆、重大變更通知)。我們不會將你的聯絡方式用於行銷。
不提供資料之影響:若你不提供註冊所需的帳號資料,將無法建立帳號與使用本 App。其餘欄位(照片、心得、裝備等)皆為選填,不提供不影響基本功能。
3. 利用之期間、地區、對象與方式
- 期間:你的帳號存續期間;刪帳後之處理詳見第 7 節。
- 地區:主要儲存於 Google Cloud
asia-east1(台灣)。為提供第三方登入、內容審核、AI 起草與當機診斷,相關處理可能發生於服務供應商所在地(含台灣以外地區),詳見第 4 節。
- 對象:我們;第 4 節所列受委託處理的服務供應商(Google、Apple);以及依你設定的可見性而能看到你分享內容的其他使用者。
- 方式:以自動化系統於前述目的範圍內蒐集、處理及利用(含網路傳輸、儲存、顯示與自動內容審核)。
4. 資料儲存與第三方服務
本 App 的後端建置於 Google Firebase(Authentication、Cloud Firestore、Cloud Storage),資料儲存於 asia-east1(台灣)區域。我們使用下列第三方服務:
- Google Firebase / Google Cloud:帳號驗證、資料庫與檔案儲存(asia-east1)。
- Sign in with Apple、Google 登入:第三方登入(僅取得完成登入所需的識別資訊);驗證程序由 Apple/Google 於其服務所在地處理。
- Google Cloud Vision(SafeSearch):對公開或分享給露友的照片進行自動審核,以偵測並過濾冒犯性內容;將照片設為公開或限露友,即會送交此項審核。私人照片不送審。
- Firebase Crashlytics:蒐集本 App 當機時的診斷資料以修復問題;僅於正式版本蒐集。我們不以帳號 ID 標註當機報告,報告不含你的心得、照片或帳號識別資訊(Crashlytics 本身會產生與裝置安裝相關的識別碼)。
- Google Cloud Vertex AI(Gemini):當你主動使用「AI 幫我起草/潤飾」時,該筆紀錄的結構化欄位(營地名稱、日期與泊數、天氣、營位型態、露營風格、評分、優點、亮點)與你已寫的心得文字會傳送至 Vertex AI 以產生心得草稿;此項處理可能於台灣以外的 Google 資料中心進行。僅傳送產生草稿所必要的欄位,不含帳號識別資訊(如 email、使用者 ID);惟營地名稱與日期可能間接反映你的行程,送出前請自行斟酌。依 Google Cloud 服務條款,該資料不會被用於訓練模型。不使用此功能就不會傳送任何資料。另為控管每月使用額度,我們會在自有資料庫保存與你的帳號連結的每月使用次數;該計數僅為次數,不保存心得或草稿內容。
這些服務各自的資料處理受其隱私政策規範。
5. 公開與私密
- 紀錄預設為私人;是否公開由你逐筆主動選擇。
- 公開層只顯示正向的絕對數(例如「幾人願意再訪」),不顯示比例、分母或排名。
- 當你把一筆紀錄設為「限露友」或「公開」時,該筆紀錄的內容——包括七項星等評比、優點標籤、心得文字與照片——會依你選擇的可見層整筆分享;沒有逐欄位的私密設定。分享的照片會送交第 4 節所述的自動審核。
- 照片、入營日期、營地名稱與心得文字可能間接揭露你的行程與位置,屬敏感資訊,請於分享前自行斟酌。
6. 你的權利與行使方式
依《個人資料保護法》第 3 條,你就自己的個人資料享有下列權利,且這些權利不因你使用本 App 而預先拋棄:
- 查詢、閱覽與製給複製本:你可在 App 內檢視自己的所有資料;如需資料複製本(匯出),請來信申請,我們會於 15 日內提供。
- 補充或更正:你可隨時在 App 內編輯自己的紀錄、裝備與個人資料。
- 停止蒐集、處理或利用:你可將紀錄改回私人、關閉公開個人頁、不使用 AI 起草功能;如需其他停止利用之申請(不以刪除帳號為前提),請來信提出。
- 刪除:你可逐筆刪除內容,或於「設定 → 刪除帳號」自助刪除帳號;若已無法使用 App,可依刪除帳號說明頁以電子郵件提出申請。刪除帳號後,你的帳號、露營紀錄、裝備、照片、追蹤關係、市集貼文、留言與詢問訊息將被永久移除且無法復原;你與他人的詢問對話串會整串移除(對方端亦同),你留在他人貼文下的留言與他人留在你貼文下的留言也會一併移除。基於社群安全與稽核需要,檢舉處理與管理稽核紀錄可能以去識別化形式保留(不含你的帳號識別)。
- 封鎖與檢舉:你可封鎖濫用者、檢舉冒犯內容。
行使方式:請寄信至 support@tentory.app,主旨註明「個人資料申請」;我們會於收到申請後 15 日內回覆,必要時得延長 15 日並通知你。
7. 資料保存期間
我們在你的帳號存續期間保存你的資料。當你刪除帳號,系統會立即清除你的個人資料與上傳檔案;殘留於服務供應商之備份與維運日誌(如資料庫時間點備份、當機診斷)會依各服務之保存週期自動汰除,一般不超過 90 日。
8. 資料安全
所有傳輸均採 TLS 加密;資料庫與檔案儲存受 Firebase 安全規則與最小權限存取控制保護;密碼由 Firebase Authentication 以雜湊形式保存,我們不以明文儲存、也不會要求你提供密碼或身分證件;後端另有自動內容審核、頻率限制與稽核紀錄等防護機制。
9. 兒童與家庭
- 本服務不以未滿 18 歲者為主要對象;未滿 18 歲者應在法定代理人同意及陪同下使用。
- 露營內容可能包含家庭與兒童影像。上傳含兒童影像的照片前,請確認已取得其法定代理人同意;設為公開或限露友的照片會送交第 4 節所述的自動審核(即會傳送至 Google 處理),請一併斟酌。
- 若我們發現在未經法定代理人同意下蒐集了未成年人的個人資料,會儘速刪除;如你發現此類情形,請來信告知。
10. 官方網站
官方網站(tentory.app)不使用任何分析工具、Cookie 或外部字型;僅有網站代管服務(Firebase Hosting)產生之營運必要連線紀錄。
11. 政策變更
我們可能不時更新本政策,並於本頁公告更新日期。重大變更時會於 App 內另行提示,必要時並以電子郵件通知。
12. 聯絡我們
如對本政策或你的資料有任何疑問,或欲行使第 6 節之權利,請聯絡:support@tentory.app(行使權利請於主旨註明「個人資料申請」)。
Privacy Policy
Last updated: September 6, 2026
This Privacy Policy is established in accordance with Taiwan's Personal Data Protection Act (PDPA) and related regulations. It explains how Tentory (the "App") collects, uses, stores, and protects your personal data. Please read it before using the App.
Data controller: Yan-Che, Lin (operator of Tentory)
Email: support@tentory.app
1. Data we collect
- Account: email (for email sign-up), or the account identifier provided by Apple or Google sign-in; display name, avatar, and custom title.
- Camping records: campground name and region, dates, seven-dimension star ratings, advantage tags, journal text, weather/context, and photos you upload. This content is shared according to the visibility you choose for each record (private / friends / public) — see Section 5.
- Derived aggregates: statistics computed from your records (camp counts, region footprint), levels, and badges. If you enable your public profile, these aggregates may appear on it according to your per-item privacy toggles.
- Gear: your gear list and marketplace (sale/wanted) posts.
- Social: follow relationships, blocks, and reports; comments you post and one-to-one marketplace inquiry messages.
- Technical: standard operational and security logs generated by Google Firebase, plus diagnostic data when the App crashes (crash stack, App version, device model and OS version). Crash diagnostics contain none of your notes, photos, or account identifiers.
Device permissions: the App requests only Camera and Photo Library access, and only when you upload photos. We do not request location, contacts, or microphone permissions, and we send no push notifications. Campgrounds and regions are chosen by you; the footprint map is built from your records, not from GPS.
What we don't do: we do not sell your personal data; we serve no personalized ads, use no advertising identifiers, and embed no marketing or behavioral-analytics SDKs; beyond the service providers listed in Section 4, we share your data with no data brokers or other third parties.
2. Purposes and basis of collection
- To provide and maintain App features (records, stats, badges, social feed, marketplace) — performance of our service contract with you.
- To display content according to your chosen visibility (public / friends / private) — based on your active choice.
- To keep the community safe: automated moderation of photos and text shared publicly or with friends, and handling of reports and blocks — necessary for service security.
- To compile non-identifying statistics (e.g. positive counts per campground).
- To contact you about the service (support replies, notices of material changes). We do not use your contact details for marketing.
If you do not provide data: without the account data needed for registration, you cannot create an account or use the App. All other fields (photos, journals, gear, etc.) are optional; leaving them out does not affect core functionality.
3. Period, territory, recipients, and means of use
- Period: for as long as your account exists; see Section 7 for what happens after deletion.
- Territory: primarily stored in Google Cloud
asia-east1 (Taiwan). To provide third-party sign-in, content moderation, AI drafting, and crash diagnostics, related processing may occur where our service providers operate, including outside Taiwan — see Section 4.
- Recipients: us; the service providers listed in Section 4 processing data on our behalf (Google, Apple); and other users who can see content you share, according to your visibility settings.
- Means: automated collection, processing, and use within the purposes above (including network transmission, storage, display, and automated content moderation).
4. Storage & third-party services
The App's backend runs on Google Firebase (Authentication, Cloud Firestore, Cloud Storage), stored in the asia-east1 (Taiwan) region. We use:
- Google Firebase / Google Cloud — authentication, database, and file storage (asia-east1).
- Sign in with Apple, Google Sign-In — third-party login (only the identifiers needed to complete sign-in); verification is processed by Apple/Google where their services operate.
- Google Cloud Vision (SafeSearch) — automated moderation of photos that are public or shared with friends to detect and filter objectionable content; setting a photo to public or friends submits it for this review. Private photos are not scanned.
- Firebase Crashlytics — collects diagnostic data when the App crashes so we can fix it; collected in release builds only. We do not tag crash reports with your account ID; reports contain none of your notes, photos, or account identifiers (Crashlytics itself generates installation-related identifiers).
- Google Cloud Vertex AI (Gemini) — when you actively use the "AI draft / polish" feature, that record's structured fields (campground name, dates and nights, weather, site type, camping style, ratings, advantages, highlights) and any note you have written are sent to Vertex AI to generate a draft; this processing may take place in Google data centers outside Taiwan. Only the fields needed for drafting are sent, with no account identifiers (such as email or user ID); note that campground names and dates may indirectly reveal your itinerary — please consider before sending. Under Google Cloud's terms, this data is not used to train models. Nothing is sent unless you use the feature. To enforce the monthly usage quota, we keep a monthly usage count linked to your account in our own database; this count is a number only and stores no journal or draft content.
Each of these services processes data under its own privacy policy.
5. Public vs. private
- Records are private by default; you choose per record whether to make them public.
- The public layer shows only positive absolute counts — never ratios, denominators, or rankings.
- When you set a record to "friends" or "public", that record's content — including all seven star ratings, advantage tags, journal text, and photos — is shared as a whole at that visibility level; there are no per-field privacy settings. Shared photos are submitted to the automated review described in Section 4.
- Photos, dates, campground names, and journal text may indirectly reveal your itinerary and location — please consider carefully before sharing.
6. Your rights and how to exercise them
Under Article 3 of the PDPA you have the following rights over your personal data, and you do not waive them by using the App:
- Access, review, and copies: you can view all of your data in the App; to request a copy (export), email us and we will provide it within 15 days.
- Supplement or correction: you can edit your records, gear, and profile in the App at any time.
- Cease collection, processing, or use: you can set records back to private, disable your public profile, or simply not use the AI drafting feature; for other cessation requests (without deleting your account), email us.
- Deletion: you can delete individual content, or delete your account under Settings → Delete account; if you can no longer use the App, request deletion by email as described on the account deletion page. Deleting your account permanently removes your account, camping records, gear, photos, follow relationships, marketplace posts, comments, and inquiry messages; inquiry threads between you and others are removed in full on both sides, as are comments you left on others' posts and comments others left on yours. For community-safety and audit purposes, moderation and admin audit records may be retained in de-identified form (without your account identifiers).
- Block & report: you can block abusive users and report objectionable content.
How to exercise these rights: email support@tentory.app with the subject "Personal data request"; we will respond within 15 days of receiving your request, extendable by another 15 days with notice where necessary.
7. Retention
We retain your data while your account exists. When you delete your account, your personal data and uploaded files are erased immediately; residual copies in provider-side backups and operational logs (such as database point-in-time backups and crash diagnostics) are purged automatically per each service's retention cycle, generally within 90 days.
8. Security
All transmission is TLS-encrypted; the database and file storage are protected by Firebase security rules and least-privilege access control; passwords are stored as hashes by Firebase Authentication — we never store them in plaintext and will never ask you for your password or ID documents; the backend additionally runs automated content moderation, rate limiting, and audit logging.
9. Children and families
- The service is not primarily directed at persons under 18; users under 18 should use it with the consent and guidance of a legal guardian.
- Camping content may include images of families and children. Before uploading photos containing children, please ensure you have their guardian's consent; photos set to public or friends are submitted to the automated review described in Section 4 (i.e. transmitted to Google for processing) — please take this into account.
- If we learn that we have collected a minor's personal data without guardian consent, we will delete it promptly; please email us if you become aware of such a case.
10. Our website
The official website (tentory.app) uses no analytics, cookies, or external fonts; only the connection logs necessarily generated by our hosting provider (Firebase Hosting) exist.
11. Changes
We may update this policy from time to time and will post the updated date on this page. We will notify you in-app of material changes, and by email where necessary.
12. Contact
Questions about this policy or your data, or to exercise the rights in Section 6: support@tentory.app (please use the subject "Personal data request" for rights requests).