SelfVersePRIVACY
PRIVACY POLICY

SelfVerse
隱私權政策

清楚說明資料如何留下、
何時離開裝置,以及為什麼。

SelfVerse 保存的是高度私密的生命記錄。我們只會為提供你主動使用的功能、維護服務與履行必要法律義務而處理資料。

我們不出售你的個人資料,也不使用你的生命內容進行跨 App 或跨網站的廣告追蹤。任何網路傳輸或儲存方式都無法保證絕對安全;以下說明 SelfVerse v1.5 實際使用的資料流程與邊界。

01

裝置上的生命記錄

SelfVerse 的主要生命記錄預設保存在你的裝置本機資料庫,包含生活故事、今日的我、人生回應、願景、感悟、念頭、人生事件、旅程資料,以及已生成的生命回望等。

這些本機內容是你的主要生命記錄。SelfVerse 不會因為安裝 App,就把全部本機資料永久上傳到 AI 或 SelfVerse Server。

你可在 App 中新增、修改或刪除適用的本機內容。刪除 App、本機資料或裝置備份後能否復原,取決於你的裝置與備份狀態。

02

匿名使用者識別

SelfVerse 使用 Firebase Anonymous Authentication 建立匿名使用者識別碼(UID)。這不是以姓名、電子郵件或社群帳號建立的個人檔案,但它仍是可持續辨識同一位 Server 使用者的識別碼。

UID 用於:

  • 驗證並保護送往 SelfVerse Server 的請求
  • 讓 Life Memory 與生命回望資料依使用者隔離
  • 維持功能與訂閱權益的連續性
  • 將必要的 Server 記錄與正確使用者關聯

不同使用者的 Server 資料以經驗證的 UID 分隔;App 不會把 UID 當作你的真實姓名帳號公開。

03

使用狀況與 Firebase Analytics

SelfVerse 使用 Firebase Analytics 記錄基本產品使用事件,例如 App 開啟、頁面瀏覽、功能操作與互動結果,以了解功能使用狀況、改善產品體驗並分析整體使用趨勢。

Firebase Analytics 可能使用與 App 安裝或執行個體相關的識別資訊來整理事件。SelfVerse 目前未在 Analytics 中主動設定 Firebase 使用者 ID,也未發現使用 IDFA、廣告個人化、廣告投放或跨 App 追蹤的實作。

Analytics 資料不應包含你書寫的完整生命內容;我們會以事件名稱、狀態與必要的非內容型參數進行產品分析。

04

AI 與 SelfVerse Server

當你主動使用需要整理或生成的功能,例如旅人之詩、Life Memory、生命回望或分享前的隱私檢查,App 可能選取完成該次功能所必要的內容,傳送至 SelfVerse Server 處理。

資料流程通常是:

  • App 選取該功能所需的生命內容與脈絡
  • Google Cloud Run 上的 SelfVerse Server 驗證匿名 UID 並控制請求
  • Server 視功能需要透過 OpenAI API 進行摘要、向量化或文字生成
  • 結果回傳 App;部分衍生資料與生成階段會保存於 Firestore

這些功能不是人格測驗,也不是由 AI 判定你的個性。SelfVerse 的用途是整理你主動留下的內容,讓你重新閱讀;理解與選擇仍由你決定。

05

Life Memory、向量與生命回望

為了跨時間找回相關生命片段,SelfVerse Server 可能為被選取的生命記錄建立摘要、向量(embedding)、來源類型、時間與關聯中繼資料、版本/指紋及衍生索引。

Life Memory 的原始來源文字會在建立摘要與向量時被處理,但目前的 Life Memory 索引文件主要保存衍生摘要、向量與相關中繼資料,不把完整原始來源文字當作索引內容永久保存。

生命回望的規劃、整理與輸出階段會處理所選取的當期與歷史內容。為了避免重複計費、支援生成流程、錯誤重試與回傳既有結果,Server 會保存各階段狀態與回應(包含最終輸出)、生成識別、用量/配額及時間等必要資料。

上述衍生資料與匿名 UID 關聯,並依 UID 隔離。它們不是對你人格或人生價值的判決。

06

OpenAI API

OpenAI API 只在需要 AI 功能時,依 SelfVerse Server 的請求處理必要的輸入與生成內容。OpenAI 不會從 SelfVerse 取得你的 Apple ID 密碼或信用卡資料;SelfVerse 也不會把你的全部本機資料自動提供給 OpenAI。

SelfVerse 不會為訓練 SelfVerse 自有模型而使用你的生命內容。OpenAI 對 API 資料的處理、濫用監控與保存則適用其 API 資料控制政策;除非相關帳戶控制已被正式核准並啟用,我們不承諾 OpenAI 為零資料保存。

OpenAI API 資料控制說明 ↗
07

訂閱與 Apple

SelfVerse 使用 StoreKit 處理購買與恢復購買,並由 SelfVerse Server 使用 App Store Server API 驗證訂閱權益。

為提供與維持訂閱功能,App 會以 Firebase 身分驗證傳送 Apple 原始交易識別碼;Server 可能保存與匿名 UID 關聯的產品識別、訂閱狀態、到期/檢查時間,以及交易識別碼或其衍生值。

付款由 Apple 處理。SelfVerse 不會取得或保存你的信用卡號、Apple ID 密碼或完整付款憑證。

08

Memory Backup 與分享

Memory Backup v4

你可以主動匯出與匯入 SelfVerse Memory Backup。App 會建立備份檔,交由系統檔案匯出器保存至你選擇的位置,例如裝置檔案、iCloud Drive 或其他檔案服務。

SelfVerse 目前不會把 Memory Backup 自動上傳到 SelfVerse Server,也不提供 SelfVerse Server Cloud Backup。你選擇的儲存位置可能依 Apple 或該第三方檔案服務的政策處理備份。

主動分享

人生章節卡、文字摘要或完整回望等分享,都必須由你主動觸發。SelfVerse 不會自動公開生命內容;你應自行確認分享內容與對象。部分回望分享流程可能先將草稿傳送至 SelfVerse Server/OpenAI 進行隱私提示,再由 App 產生可分享內容。

09

資料保存、刪除與安全

本機資料通常保留於你的裝置,直到你在 App 中刪除、清除 App 資料或移除 App;系統備份仍可能依你的裝置設定保留副本。

Firestore 中的 Life Memory 衍生索引、生命回望生成階段/輸出、訂閱權益與必要的用量/服務資料,會在提供功能、維護服務、安全防濫用與履行法律義務所必要的期間保存。目前沒有對所有 Server 資料適用的單一固定保存天數,因此我們不承諾 30 天或 90 天等未經實作確認的期限。

目前 App 尚未提供一個可一次刪除所有 Server-side Life Memory、生命回望生成狀態與訂閱資料的使用者按鈕。若你希望查詢或刪除與匿名 UID 關聯的 Server 資料,請透過本頁聯絡方式提出請求。我們會依適用法律、身分確認與技術可行性處理。備份、服務記錄或供應商系統中的副本,可能依正常覆寫、保存週期或法律要求延後移除。

我們採取合理的技術與組織措施保護資料,包括驗證 Server request、依 UID 隔離資料,以及避免在正常診斷記錄中寫入原始生命內容;但任何網路傳輸或儲存系統都無法保證絕對安全。

10

第三方服務

SelfVerse v1.5 目前使用下列服務:

  • Apple StoreKit/App Store Server API:付款、購買恢復與訂閱驗證
  • Firebase Authentication:匿名 UID 與請求驗證
  • Firebase Analytics:產品使用事件與趨勢分析
  • Google Cloud Run:執行 SelfVerse Server 與必要的 AI/訂閱流程
  • Google Cloud Firestore:保存依 UID 隔離的衍生資料、生成狀態與權益資料
  • OpenAI API:必要的摘要、向量化、生成與分享隱私處理

現行第三方服務以本節列出的服務為準;第三方服務會依各自條款與隱私政策處理其所接收的資料。若日後新增會處理個人資料的第三方服務,我們會先更新本政策。

Firebase 隱私與安全資訊 ↗
Google Cloud 隱私權聲明 ↗
Apple 隱私權政策 ↗

11

你的權利

依所在地適用法律,你可以就與你相關的資料提出查詢、更正、刪除、限制處理或停止使用等請求。你也可以刪除 App 內適用的本機資料、停止使用 App,或主動管理匯出的備份與分享檔案。

Server 資料請求可能需要你提供可核對的匿名 UID 或其他必要資訊,以避免刪除錯誤使用者的資料。請勿透過電子郵件傳送完整生命內容、Apple ID 密碼或付款資料。

12

兒童隱私

SelfVerse 不以 13 歲以下兒童為主要使用對象。若你認為兒童在未獲適當同意下提供了資料,請聯絡我們。

13

政策更新與聯絡方式

我們可能因產品、Server 架構、法規或第三方服務變更而更新本政策。重大更新會在本頁公布,並更新頁面上方日期。

若你對本政策或資料請求有任何問題,請聯絡:

selfverse.dev@gmail.com ↗

ENGLISH VERSION

SelfVerse stores deeply personal life records. We process data only to provide features you choose to use, maintain the service, protect it from abuse, and meet applicable legal obligations.

We do not sell personal information or use life content for cross-app or cross-website advertising tracking. No transmission or storage system can be guaranteed to be completely secure. This policy describes the actual data boundaries in SelfVerse v1.5.

01

Life Records on Your Device

Your primary SelfVerse life records are stored by default in the local database on your device. They may include life stories, Today Self entries, life responses, visions, insights, thoughts, life events, journey information, and generated Life Reflections.

These local records are your primary life records. Installing SelfVerse does not cause the App to permanently upload all local data to AI services or the SelfVerse Server.

02

Anonymous User Identifier

SelfVerse uses Firebase Anonymous Authentication to create an anonymous user identifier (UID). It is not a profile created with your name, email address, or social account, but it is a persistent identifier used to recognize the same Server user.

The UID is used to authenticate Server requests, isolate Life Memory and Life Reflection data, maintain feature and subscription continuity, and associate necessary Server records with the correct user. Server data belonging to different users is separated by verified UID.

03

Usage Data and Firebase Analytics

SelfVerse uses Firebase Analytics for basic product events, such as App opens, screen views, feature actions, and interaction results. We use this information to understand feature usage, improve the experience, and analyze aggregate usage trends.

Firebase Analytics may use identifiers associated with an App installation or app instance. SelfVerse does not currently set a Firebase Analytics user ID, and our reviewed implementation does not use IDFA, advertising personalization, ad targeting, or cross-app tracking. Analytics events should not contain the full text of your life records.

04

AI and the SelfVerse Server

When you actively use a feature that requires organization or generation—such as Traveler's Poem, Life Memory, Life Reflection, or privacy review before sharing—the App may select the content needed for that request and send it to the SelfVerse Server.

The SelfVerse Server runs on Google Cloud Run, verifies the anonymous UID, controls requests to OpenAI when needed, and returns results to the App. Depending on the feature, derived data and generation stages are stored in Firestore. SelfVerse does not use AI to score your life or determine your personality.

05

Life Memory, Embeddings, and Life Reflection

To retrieve relevant life moments across time, the Server may create summaries, embeddings, source and time metadata, links, versions or fingerprints, and a derived index for selected records.

Original source text is processed when summaries and embeddings are created. The current Life Memory index stores primarily derived summaries, embeddings, and related metadata rather than preserving the complete source text as the index document.

Life Reflection processes selected current and historical content through planning, synthesis, and output stages. The Server stores stage status and responses, including final output, generation identifiers, quota or token usage, and timestamps when needed for idempotency, retries, service operation, and cost controls. These records are associated with and isolated by anonymous UID.

06

OpenAI API

OpenAI processes only the content required for an AI feature at the request of the SelfVerse Server. OpenAI does not receive your Apple ID password or payment card details from SelfVerse, and SelfVerse does not automatically send your entire local database.

SelfVerse does not use life content to train a SelfVerse-owned model. OpenAI's handling of API data, abuse monitoring, and retention is governed by its API data controls. We do not promise Zero Data Retention unless the relevant account controls have been formally approved and enabled.

OpenAI API data controls ↗
07

Subscriptions and Apple

SelfVerse uses StoreKit for purchases and purchase restoration. The SelfVerse Server uses the App Store Server API to verify subscription entitlement.

The App sends the Apple original transaction identifier with Firebase authentication. The Server may store the product identifier, entitlement state, expiration and check times, and the transaction identifier or a derived value in association with the anonymous UID.

Apple processes payment. SelfVerse does not receive or store your payment card number, Apple ID password, or complete payment credentials.

08

Memory Backup and Sharing

Memory Backup v4

You may actively export and import a SelfVerse Memory Backup. The App creates a backup file and hands it to the system file exporter for storage in a location you choose, such as Files, iCloud Drive, or another file provider.

SelfVerse does not automatically upload Memory Backup files to the SelfVerse Server and does not currently provide SelfVerse Server Cloud Backup. Your selected storage provider may process the file under its own policy.

Sharing

Sharing a life chapter card, text summary, or complete reflection requires your action. SelfVerse does not automatically publish life content. Some reflection-sharing flows may send draft share content to the SelfVerse Server and OpenAI for privacy detection before the App returns share-ready content.

09

Retention, Deletion, and Security

Local data generally remains on your device until you delete applicable records, clear App data, or remove the App. Copies may remain in device backups according to your system settings.

Life Memory derived indexes, Life Reflection stages and outputs, entitlement records, and necessary usage or service records in Firestore are retained for as long as reasonably necessary to provide and maintain the features, protect the service, and comply with legal obligations. There is currently no single fixed retention period for all Server records, so we do not claim an unimplemented 30- or 90-day limit.

The App does not currently provide a single control that deletes every Server-side Life Memory, Life Reflection generation, and subscription record. Contact us to request access to or deletion of data linked to your anonymous UID. Requests are handled subject to applicable law, identity verification, and technical feasibility. Copies in backups, service logs, or provider systems may remain until ordinary overwrite or retention cycles complete.

We use reasonable safeguards, including authenticated requests, UID-based data isolation, and controls intended to keep raw life content out of normal diagnostic logs. No system can be guaranteed to be completely secure.

10

Third-Party Services

  • Apple StoreKit and App Store Server API — payment, restoration, and entitlement verification
  • Firebase Authentication — anonymous UID and request authentication
  • Firebase Analytics — product events and usage trends
  • Google Cloud Run — SelfVerse Server and AI/subscription processing
  • Google Cloud Firestore — UID-isolated derived records, generation state, and entitlement data
  • OpenAI API — necessary summarization, embedding, generation, and share-privacy processing

The current third-party service list is limited to the services above. Each provider processes the data it receives under its own terms and privacy policy. We will update this policy before adding another third-party service that processes personal data.

Firebase privacy and security ↗
Google Cloud Privacy Notice ↗
Apple Privacy Policy ↗

11

Your Rights

Subject to applicable law, you may request access, correction, deletion, restriction, or cessation of processing. You may delete applicable local records in the App, stop using SelfVerse, and manage exported backup or sharing files.

A Server data request may require your anonymous UID or other information necessary to avoid affecting the wrong user. Do not email complete life records, an Apple ID password, or payment information.

12

Children's Privacy

SelfVerse is not primarily intended for children under 13. Contact us if you believe a child provided data without appropriate consent.

13

Changes and Contact

We may update this policy when the product, Server architecture, law, or third-party services change. Material updates will be posted here with a revised date.

For privacy questions or data requests, contact:

selfverse.dev@gmail.com ↗