隱私權政策
本政策說明 PAYGE App、帳號、訂閱及 payge.app 如何使用與保護您的資料。其他產品如有專屬政策,依其政策辦理。
隱私問題及資料權利請聯絡 support@payge.app。本政策也涵蓋 App 使用的第三方服務。
1. 我們處理哪些資料、為什麼
| 資料類型 | 來源與用途 |
|---|---|
| 本機媒體與文件 | 依您授予的權限或選取的檔案,讀取及處理相片、影片、音訊、PDF、EPUB、文章等內容,提供檢視、播放、編輯、轉換與儲存。這些功能主要在裝置上處理,不會僅因開啟或編輯而把檔案內容上傳至我們的伺服器。您選擇分享、遠端網址或系統備份時,另依相應流程處理。 |
| 姓名、電子郵件、使用者 ID | 選用 Google 登入時,由 Google 與 Firebase Authentication 提供或處理顯示名稱、電子郵件地址、登入憑證及使用者 ID,以驗證登入、管理帳號、保護帳號與關聯訂閱。您不需要把 Google 密碼提供給我們。 |
| 購買與訂閱紀錄 | Google Play 的商品、購買權杖、訂閱狀態、交易相關通知及其帳號關聯,用於驗證購買、防止詐欺、啟用/管理付費權益。Premium 狀態及商品操作亦用於分析。付款由 Google Play 處理,我們不因此取得您的信用卡號或銀行帳號。 |
| 網頁瀏覽相關資料 | 使用網頁閱讀器時,會向原始網站載入您指定的頁面。為取得閱讀規則,我們會將網站網域名稱送至 Firebase 後端;此查詢不包含完整網址或文章內容;伺服器會記錄網域及查詢資訊。 |
| 閱讀分享連結 | 您選擇「分享閱讀連結」時,我們會將完整原始網址及可用的標題、摘要、封面網址、網站名稱儲存於 Firebase,用於建立分享連結與預覽。持有連結的人可取得這些資料;不會複製文章全文、WebView Cookie 或授權標頭。分享資料不自動過期,也不與分享者帳號關聯;如需停用,請提供分享連結聯絡客服。原始網站及封面圖片提供者會收到接收者的載入請求。 |
| 閱讀模式問題回報 | 您主動送出回報時,我們會將您確認的網頁/來源網址、問題類型與說明,以及 App、系統、WebView 版本、閱讀外觀、視窗尺寸、擷取規則版本、錯誤碼與內容數量儲存於 Firebase,供授權開發者重現與修正顯示問題。送出前會移除網址中的登入資訊、片段與大部分查詢參數;您仍應檢視網址路徑及說明是否包含私人資訊。不自動附上文章正文、HTML、Cookie、授權標頭或截圖,也不與回報者帳號關聯。回報設定於建立 90 天後自動清除,實際刪除時間依後端排程;防濫用計數使用每日雜湊的來源 IP,設定於一天後清除。若需協助刪除回報,請提供相關網址與回報時間聯絡客服。 |
| 應用程式互動 | 畫面開啟、媒體功能使用、來源 App 資訊、訂閱操作及廣告曝光/點擊等事件,透過 Firebase Analytics 與廣告 SDK 用於功能及服務運作、使用分析、廣告與防詐欺。 |
| 當機、診斷與裝置資訊 | Firebase Crashlytics 等服務處理當機堆疊、非致命例外、呼叫位置、App/系統版本及裝置狀態,以分析問題。廣告 SDK 亦處理啟動、停滯、耗能等診斷資料;App Check/Play Integrity 用於確認 App 完整性及保護服務。例外內容可能包含發生錯誤時的網址或檔案上下文。 |
| 裝置/其他識別碼、IP 與概略位置 | Firebase 與 Google 廣告服務可能處理安裝識別碼、當機回報識別碼、廣告 ID、App set ID 及 IP 位址,以提供服務、分析、廣告及防止濫用。IP 可推估概略位置;此用途不需要 GPS 精確位置權限。 |
| 您主動提供的支援資料 | 您寄信聯絡或申請刪除時,我們處理電子郵件地址、請求內容及必要的身分確認資料,以回覆、執行請求及處理爭議。請勿傳送密碼、完整付款資料或不必要的媒體內容。 |
本機功能可不登入使用;登入、購買及網頁閱讀屬您選用的流程。App 中的部分分析、診斷及識別碼處理沒有完整的 App 內停用選項。購買 Premium 或刪除廣告 ID,不表示所有資料蒐集都會停止。
2. 網站、Cookie 與本機資料
網頁閱讀器會與原始網站及其資源伺服器連線;對方可取得 IP、請求資訊,並可能使用 WebView 的 Cookie 與本機網站儲存。原始網站的登入、追蹤與內容處理亦適用其政策。閱讀規則查詢不會將 WebView Cookie、授權標頭或文章內文作為查詢內容傳給我們。
App 內的檔案、設定、快取與使用配額等資料可儲存在裝置。Android 系統備份/移轉依您的裝置與 Google 備份設定運作,可能包含 App 資料;刪除伺服器帳號不會自動清除每台裝置、匯出檔案或系統備份。
造訪 payge.app 時,Firebase Hosting 及網頁資源提供者會接收載入頁面所需的網路請求,例如 IP、瀏覽器資訊與請求路徑,用於交付內容與服務安全。首頁使用 Google Fonts;本隱私權政策與服務條款頁面使用本站樣式,不安裝分析或廣告追蹤程式。刪除申請頁使用 Firebase Authentication、Cloud Functions、App Check 與 reCAPTCHA Enterprise 驗證帳號及防止濫用,Google 會處理必要的網路、瀏覽器與安全訊號;不在刪除頁加入廣告或產品分析。
4. 保留期間與安全措施
各類資料的保留期間如下:
- 帳號及關聯資料:提供帳號服務期間保留;收到可驗證的刪除請求後,刪除帳號與可刪除的關聯資料。
- 訂閱及交易資料:提供、驗證與恢復權益所需期間保留;為帳務、退款、爭議、法律義務或防詐欺而必要的紀錄,可能在帳號刪除後繼續保留。
- 網域日誌、診斷、分析與廣告資料:依各服務的保留設定及除錯、分析、安全需要保存,到期後清除。
- 支援及刪除請求:在處理請求、確認執行結果及處理相關爭議所需期間保留。
- 快取及備份:刪除作業可能需要等待覆寫或清理週期完成;已保留的法律或安全紀錄僅供相應用途使用。無法合理連回您的匿名彙總統計可能繼續保留。
訂閱交易識別:交易資料包含 App 帳號識別、購買憑證、Google Play 訂閱回應及最新通知,用於驗證與重新綁定訂閱。這些識別不是匿名資料,也不代表 Google Play 付款帳號。刪除作業會清理當時的帳號關聯;其他裝置的後續同步或訂閱通知仍可能重新寫入交易資料,包括原帳號識別與交易回應。這不會重新建立已刪除的登入帳號。 保留期間依上述交易資料政策處理。
刪除收據與防止舊帳號寫入:私人收據可查詢 90 天。刪除完成後,工作紀錄會移除直接帳號識別。工作紀錄、收據與短期安全封鎖紀錄設定於 90 天後到期,實際清除可能稍有延遲。訂閱及分析資料另依各自的保留期間處理。
我們對後端及相關 Google SDK 的資料傳輸使用 HTTPS/TLS,並限制資料存取並驗證服務身分。使用者指定的 HTTP 網頁或媒體連線可能未加密;請勿透過不可信任的來源傳送敏感資訊。任何系統皆無法保證零風險。
5. 您的選擇與資料權利
您可透過 Android 設定撤回媒體/通知權限、清除 App 資料,或選擇不登入、不購買、不使用網頁閱讀器。撤回權限可能影響相應功能。您也可透過 Android/Google 設定管理廣告 ID 與相關隱私選項;這不一定停止其他服務識別碼的處理。
如適用法律提供資料存取、更正、刪除、限制、反對、可攜或撤回同意等權利,請寄信至 support@payge.app 提出。我們會依適用法律處理,並在必要時確認身分。對於無法識別歸屬的裝置事件或由第三方獨立控制的資料,我們會說明限制或適用的聯絡途徑。
6. 帳號刪除
請見帳號刪除說明,了解刪除範圍、處理時間及申請方式。
7. 資料刪除
保留帳號並刪除部分資料,或清除裝置資料,請見資料刪除說明。
8. 未成年人、政策變更與聯絡
若您依所在地法律需要監護人同意,請由監護人協助使用。若您認為我們處理了依法應取得監護人同意卻未取得的兒童資料,請聯絡我們以調查及採取適當措施。
功能或資料處理方式變更時,我們會更新本政策與版本日期;重大變更將透過 App 或網站提供合理通知,依法需要同意時另行取得。您的法定權利不因政策變更而被排除。
聯絡窗口:PAYGE · support@payge.app。
Privacy Policy
This policy explains how PAYGE handles data in its app, accounts, subscriptions and payge.app. Other products may have separate policies. Contact support@payge.app for privacy questions. This policy includes data processing by SDKs integrated into our app.
1. Data and purposes
- Local media and documents: With your permissions or file selection, we access photos, video, audio, PDFs, EPUBs and articles to display, play, edit, convert and save them. These operations primarily run on your device; opening or editing a file does not by itself upload its content to our servers. Sharing, remote content and system backups involve their respective services.
- Account information: Optional Google sign-in involves display name, email, credentials and Firebase user ID for authentication, account security, management and subscription association. Do not provide us with your Google password.
- Purchases: Product information, purchase tokens, subscription status, transaction notifications and account associations are used to verify purchases, prevent fraud and provide paid access. Premium status and product interactions also support analytics. Google Play handles payment; we do not receive your card or bank account numbers through that process.
- Browsing: The reader loads your selected website. For reading-rule lookup, we send the website hostname to our Firebase backend, without the full URL, article HTML or body. Backend logs record the hostname and operational information, these records are stored.
- Reader share links: When you choose “Share reader link”, we store the full original URL and available title, description, cover image URL and site name in Firebase to provide the link and preview. Anyone with the link can retrieve these details. We do not copy the article body, WebView cookies or authorization headers. Share records do not automatically expire and are not linked to the sender’s account. To request disabling a link, contact support with the share link. Original websites and cover image providers receive recipients’ loading requests.
- Reading-mode problem reports: When you submit a report, Firebase stores the page/source URLs you review, issue category and description, app/OS/WebView versions, reading appearance, window size, extraction-rule revision, error code and content counts for authorized developers to reproduce and fix display problems. Credentials, fragments and most query parameters are removed before submission; please still review URL paths and your description for private information. Article text, HTML, cookies, authorization headers and screenshots are not attached automatically. Reports are not linked to your account. Reports are scheduled for automatic deletion after 90 days, subject to backend scheduling. Abuse-prevention counters use a daily hash of the source IP and expire after one day. Contact support with the relevant URL and report time if you need help deleting a report.
- Interactions: Screen views, media feature use, referring-app context, subscription actions and ad impressions/clicks are processed through Firebase Analytics and advertising SDKs for service operation, analytics, advertising and fraud prevention.
- Crashes and diagnostics: Crashlytics processes stack traces, non-fatal exceptions, caller context, app/OS versions and device state for troubleshooting. Ad SDKs also process launch, hang and energy-use diagnostics. App Check/Play Integrity helps protect service integrity. Exception messages may contain URLs or file context.
- Identifiers, IP and approximate location: Firebase and Google advertising services may process installation IDs, crash-report IDs, advertising IDs, app set IDs and IP addresses for functionality, analytics, advertising and abuse prevention. IP addresses can indicate approximate location without GPS permission.
- Support: When you email us, we process your email address, request and necessary verification information to respond, fulfill requests and resolve disputes. Do not send passwords, complete payment details or unnecessary media.
Local features can be used without sign-in. Sign-in, purchases and web reading are optional flows. Some analytics, diagnostics and identifier processing has no complete in-app opt-out; Premium or deleting an advertising ID does not stop all collection.
2. Websites, cookies and local storage
Original websites and resource servers receive network requests and may use WebView cookies and site storage under their own policies. Our reading-rule query does not send WebView cookies, authorization headers or article content as its payload. Files, preferences, caches and usage counts may be stored locally. Android backup and transfer may include app data according to your device and Google settings. Server account deletion does not erase all devices, exported files or backups.
Firebase Hosting and resource providers receive requests such as IP, browser information and paths to deliver payge.app and protect services. The home page uses Google Fonts. These privacy and terms pages use locally hosted styles and do not install advertising or analytics trackers. The deletion page uses Firebase Authentication, Cloud Functions, App Check and reCAPTCHA Enterprise for identity verification and abuse prevention. Google processes necessary network, browser and security signals; we do not add advertising or product analytics to this page.
3. Recipients and international processing
Google/Firebase provides authentication, databases, cloud functions, configuration, analytics, crash reporting, integrity protection, hosting and Google Play billing. Google advertising services and advertising partners collect and share approximate location, interactions, diagnostics and identifiers for advertising, analytics and fraud prevention. Personalization depends on available consent signals, region and service settings. Websites and apps you choose receive data when you open or share content. Necessary information may also be disclosed to parties assisting with support, valid legal processes, legal obligations or protection against fraud and harm.
Services may process data outside your country. See Google Privacy Policy, Firebase privacy and security and Google’s use of information from partner sites and apps.
4. Retention and security
We retain account data while providing the account and delete the account and deletable associated data after a verified request. Subscription and transaction records are retained as needed to provide or restore benefits and, where necessary, handle accounting, refunds, disputes, legal duties or fraud prevention. Host logs, analytics, diagnostics and advertising data follow the relevant service retention settings and operational, analytical or security needs, rather than being memory-only. Support records are retained as needed to handle requests and related disputes.
Caches and backups may take time to be overwritten or cleaned. Records retained for legal or security purposes are limited to those purposes. Aggregated statistics that cannot reasonably be linked to you may remain. We do not promise one fixed deletion deadline for all categories.
Backend and relevant Google SDK transfers use HTTPS/TLS with access controls and service verification. User-selected HTTP websites or media may be unencrypted. No system can guarantee zero risk.
5. Choices and rights
You can revoke Android permissions, clear app data, or avoid optional sign-in, purchases or web reading. Functionality may be affected. Android/Google advertising controls do not necessarily stop other identifiers. Contact us to exercise applicable rights of access, correction, deletion, restriction, objection, portability or withdrawal of consent. We may verify identity and explain limits for unidentifiable events or data independently controlled by others.
Subscription records include app account identifiers, purchase tokens, Google Play subscription responses and the latest notification for verification and rebinding. These identifiers are not anonymous and do not identify the Google Play payment account. Deletion clears the account links present during processing. Later synchronization from other devices or subscription notifications may write transaction data again, including previous account identifiers and transaction responses. This does not recreate the deleted sign-in account. Retention follows the transaction policy above. Private deletion receipts can be queried for 90 days. Pending jobs retain identifiers needed to finish; completed jobs remove direct account identifiers. Completed jobs, receipts and short-lived security blocks use 90-day expiry policies, with possible storage-service cleanup delays. This is not a uniform retention period for all subscription or analytics data.
6. Account deletion
See account deletion for what is deleted, timing and how to apply.
7. Data deletion
To keep your account and delete selected data, or clear device data, see data deletion.
8. Minors, changes and contact
If local law requires a guardian’s consent, use the service with their assistance. Contact us if you believe we processed a child’s data without legally required consent so we can investigate and act. We update this policy and its version for changes, provide reasonable notice of material changes through the app or website, and obtain consent where required. Statutory rights remain unaffected. Privacy contact: PAYGE, support@payge.app.