最后更新:2026年6月12日 · 生效日期:2025年1月1日 · v3.6
KeyAssist(“我们”“本公司”)致力于保护您的隐私。本隐私政策说明我们收集哪些数据、如何使用这些数据,以及您就个人数据所享有的各项权利。
如需行使上述权利,请联系:privacy@keyassist.app
| 类别 | 数据 | 用途 | 法律依据 |
|---|---|---|---|
| 账户 | 姓名、电子邮箱、国家/地区 | 身份验证、服务交付 | 合同 |
| Profile & onboarding | Equipment you own (equipment, equipmentOther), how you heard about us (hearAbout), and preferred country & equipment used as search defaults (prefCountry, prefEquipment) | Personalization, onboarding, tailoring search results | Consent |
| 使用情况 | 查看的案例、搜索记录、会话时长 | 服务改进、分析 | 正当利益 |
| 账单 | 支付方式(通过 Stripe 处理——我们不存储卡号) | 订阅管理 | 合同 |
| 技术信息 | IP 地址、浏览器类型、设备类型 | 安全、欺诈防范 | 正当利益 |
| Cookie | 会话令牌、偏好设置 | 身份验证、个性化 | 同意 / 合同 |
我们仅与以下第三方服务提供商共享您的数据:
| 服务 | 用途 | 共享的数据 | 合规性 |
|---|---|---|---|
| Firebase (Google) | 身份验证与数据库 | 电子邮箱、UID、使用事件 | EU-US DPF、GDPR SCCs |
| Stripe | 支付处理 | 电子邮箱、账单地址 | PCI DSS Level 1 |
| Vercel | 托管与边缘分发 | IP 地址(日志) | SOC 2 Type II |
| Sentry | 错误跟踪(仅限选择加入) | 错误事件、设备类型 | GDPR,可选用欧盟数据区域 |
| Microsoft Clarity(Microsoft Corporation) | 注重隐私的产品分析及会话热图(需经同意方可启用) | 匿名化交互事件、页面 URL、设备/浏览器信息;在美国/欧盟处理 | 数据处理附录 |
| Upstash(Vercel KV / Redis) | API 速率限制 | 经哈希处理的 IP + 请求计数器(临时性,约 1 小时 TTL);在美国/欧盟处理 | 数据处理附录 |
| Resend (Resend Inc.) | Transactional email (email-change verification, trial reminders) | Recipient email address, message content; delivered via AWS SES (USA) | Data Processing Addendum |
| NHTSA vPIC (US Dept. of Transportation) | VIN decoding (optional VIN lookup you initiate) | Only the VIN you type; no account identifier is sent — a public government API | Public API (no PII stored by us) |
| jsDelivr (open-source CDN) | Delivery of static library assets (incl. the transformers.js on-device voice-search engine) | No personal data beyond the standard HTTP request (IP), same as any CDN fetch | Privacy policy |
| Hugging Face (Hugging Face, Inc.) | On-device voice search — delivers the offline Whisper speech-recognition model to your browser (the transformers.js library itself is served via jsDelivr, above) | None — model files download to your device; your audio is transcribed locally and never leaves your browser | Public CDN file downloads. Hosts: huggingface.co, *.hf.co, cas-bridge.xethub.hf.co |
我们绝不向第三方出售您的个人数据。Sentry 和 Microsoft Clarity 仅在您明确同意 Cookie 后方可启用。
本分包处理方清单将保持最新,并在我们新增、变更或移除任何服务提供商时随时更新。
我们使用两类 Cookie:
我们不使用广告 Cookie、跨站跟踪器,也不出售浏览数据。您可随时在“账户设置 → Cookie 偏好设置”中更改您的 Cookie 偏好,或通过电子邮件联系我们。
| 数据类别 | 保留期限 | 删除时的处理方式 |
|---|---|---|
| 账户资料(Firestore) | 账户处于活跃状态期间 | 在收到账户删除请求后 24 小时内删除 |
| 收藏夹与已保存的案例 | 账户处于活跃状态期间 | 与账户同时删除 |
| 账单记录(Stripe) | 自最后一笔交易起 7 年 | Stripe 出于法律/税务合规需要予以保留——我们无权令其提前删除 |
| 错误日志(Sentry) | 90 天(Sentry 免费版) | 由 Sentry 自动清除;您可通过 privacy@ 请求立即删除 |
| 服务器请求日志(Vercel) | 30 天 | 由 Vercel 基础设施自动清除 |
| 匿名化分析数据 | 最长 2 年 | 已匿名化——不含个人身份信息(PII);不受删除请求约束 |
| CSP violation reports (security telemetry) | 180 days | Auto-purged; security telemetry with minimal / no personal data |
| Bot / abuse-detection reports | 180 days | Auto-purged; honeypot / abuse-prevention data |
| API request logs (paid endpoints) | 90 days | Auto-purged; access audit for paid endpoints |
| Email-change magic-link tokens | 7 days | Auto-purged; single-use, expire within 24h of issue |
账户删除时间安排:当您删除账户(账户设置 → 删除账户)时,KeyAssist 将在 24 小时内删除您的 Firestore 资料及 Firebase Auth 条目。Stripe 订阅将立即取消。根据加拿大税法(《所得税法》),账单记录将保留 7 年。
我们通过以下措施保护您的数据:
KeyAssist 不面向未满 18 周岁的用户。我们不会在知情的情况下收集儿童数据。
您的数据可能在美国境内处理(Firebase、Stripe、Vercel)。这些服务提供商通过标准合同条款遵守包括 GDPR 在内的适用数据保护框架。
| Processor | Processing location | Transfer mechanism |
|---|---|---|
| Firebase (Google) | USA / EU | EU-US Data Privacy Framework + SCCs |
| Stripe | USA | Standard Contractual Clauses (Stripe DPA) |
| Vercel | USA | Standard Contractual Clauses (Vercel DPA) |
| Sentry | USA / EU | SCCs; EU data region available |
| Microsoft Clarity | USA / EU | EU-US Data Privacy Framework + Microsoft DPA/SCCs |
| Upstash (Vercel KV) | USA / EU | Standard Contractual Clauses (Upstash DPA) |
| Resend (via AWS SES) | USA | Standard Contractual Clauses (Resend DPA) |
| Hugging Face & jsDelivr (CDN) | Global CDN | Public model/library file downloads — no personal data transferred |
Scope of self-serve export: "Export my data" returns your profile, saved preferences, favorites, and locally-stored data as JSON/CSV. For a complete GDPR Article 15 copy of everything linked to your account (including server-side records not in the self-serve bundle), email privacy@keyassist.app and we will provide it within 30 days.
如果您是加利福尼亚州居民,《加利福尼亚州消费者隐私法》(CCPA)赋予您就个人信息享有的额外权利。
如需行使您的 CCPA 权利,请联系:privacy@keyassist.app · 邮件主题:“CCPA Request”
请勿出售我的个人信息:KeyAssist 不向第三方出售个人信息。本页即为我们的拒绝出售声明——您无需采取任何进一步行动。
在发生重大变更前,我们将至少提前 30 天通过电子邮件和/或应用内显著通知告知您。本文档顶部的“最后更新”日期反映最近一次修订。
数据隐私相关问题:privacy@keyassist.app
邮寄地址:327 Portage Ave, Winnipeg, MB R3B 2C1, 加拿大
响应时间:GDPR 请求将在 30 天内处理。
English · Українська · Español · Português · Deutsch · Français · Polski · العربية · עברית · فارسی · اردو · Italiano · Türkçe · 日本語 · 简体中文 · Русский · हिन्दी · Bahasa Indonesia · Tiếng Việt · 한국어 · ไทย · Nederlands · Română · Bahasa Melayu · 繁體中文 · Ελληνικά · Čeština · Magyar · Svenska · বাংলা