Privacy Policy / 隱私權政策

Draft — 待法律顧問審閱後始得正式發布 / Draft — requires counsel review before publication. Last updated: 2026-09-04. Placeholder contact: ray@noise-and-signal.com (replace with a real, monitored address before publishing).

Archi 是一款拍攝房間照片、取得 AI 佈置建議並直接購買真實商品的行動應用程式。本政策 說明我們如何蒐集、使用、分享與保護您的個人資料。

Archi is a mobile app that photographs a room, generates AI decor suggestions, and links directly to real, purchasable products. This policy explains how we collect, use, share, and protect your personal data.


1. 前言 / Introduction

本政策適用於 Archi App(下稱「本服務」),由 [開發者/公司名稱,待填] 營運 (下稱「我們」)。如對本政策有任何疑問,請透過第 12 節之聯絡方式與我們聯繫。

This policy applies to the Archi app (the "Service"), operated by [developer/company name, TBD] ("we", "us"). Questions about this policy can be sent to us using the contact details in Section 12.

2. 我們蒐集的資料 / Data We Collect

帳號資料 / Account data — 電子郵件、電話號碼、Apple/Google/簡訊驗證識別碼、 使用者 ID。Email address, phone number, Apple/Google/phone-OTP account identifiers, and your internal user ID.

內容資料 / Content data — 您拍攝或上傳的房間照片,以及由此產生的 AI 建議、 色票與商品推薦。Room photos you capture or upload, and the AI-generated suggestions, color palettes, and product recommendations produced from them.

使用資料 / Usage data — 掃描次數與每日配額使用狀況(用於配額限制,非用於 廣告或行銷分析)。Scan counts and daily quota usage, used only to enforce your scan limit — not for advertising or marketing analytics. Archi does not currently bundle any third-party analytics or crash-reporting SDK.

3. 資料使用方式 / How We Use Your Data

我們使用您的資料以:(a) 產生 AI 房間佈置建議;(b) 管理您的帳號與每日掃描配額; (c) 維運與改善服務的可靠性與安全性。您的房間照片不會被用於訓練我們或第三方 AI 供應商的模型。

We use your data to: (a) generate AI decor suggestions from your room photos; (b) manage your account and enforce your daily scan quota; (c) operate, secure, and maintain the reliability of the Service. Your room photos are not used to train our models or any third-party AI provider's models, beyond the abuse-monitoring retention described in Section 4.

4. 第三方分享(含 AI 處理)/ Third-Party Sharing, Including AI Processing

OpenAI — 當您傳送房間照片進行分析時,該照片會透過我們的伺服器端傳送給 OpenAI,L.L.C.(我們的 AI 服務供應商)進行影像分析,以產生佈置建議與商品搜尋 查詢。OpenAI 依其政策,基於防止濫用之目的可能保留該資料最長 30 天 (此為一般預設值;若我們的帳號已核准零資料保留(Zero Data Retention),將 以此政策的後續更新版本反映該狀態 — 發布前請以 OpenAI 官方文件為準重新確認)。 詳見 OpenAI 隱私權政策:https://openai.com/policies/privacy-policy

When you submit a room photo for analysis, it is sent server-side to OpenAI, L.L.C. (our AI service provider) to generate decor suggestions and product search queries. Under OpenAI's standard terms, this data may be retained for up to 30 days for abuse-monitoring purposes (this is the general default; if our account has been approved for Zero Data Retention, this section will be updated to reflect that — verify against OpenAI's current documentation before relying on this figure). See OpenAI's privacy policy: https://openai.com/policies/privacy-policy

Supabase — 我們使用 Supabase(基礎設施委外服務)處理帳號驗證、資料庫、 檔案儲存與伺服器函式,資料存放於東京(ap-northeast-1)機房。

We use Supabase as our infrastructure sub-processor for authentication, database, file storage, and server functions. Data is hosted in Tokyo (ap-northeast-1, Japan).

零售商連結 / Retailer links — 商品連結(如 IKEA、MUJI、Nitori、Amazon)由 我們的伺服器驗證後提供;點擊連結後,您與該零售商之間的互動受該零售商自身的 隱私權政策規範,與本服務無關。

Product links (e.g. IKEA, MUJI, Nitori, Amazon) are validated by our servers before being shown to you; once you follow a link, your interaction with that retailer is governed by that retailer's own privacy policy, not this one.

我們不會將您的資料出售給第三方,亦不使用任何廣告或追蹤 SDK。

We do not sell your data to third parties, and we do not use any advertising or tracking SDK. Our Privacy Manifest declares no tracking domains.

5. 法律依據與同意 / Legal Basis / Consent

在您第一次傳送房間照片供 AI 分析前,App 會顯示一個獨立的同意畫面,要求您明確 按下「我同意」(依 Apple 準則 5.1.2(i) 及個人資料保護法第 19、20 條之精神)。 該同意時間戳記會儲存於您的帳號紀錄(profiles.ai_consent_at)。

Before your first photo is ever transmitted for AI analysis, the app shows a dedicated consent screen requiring an affirmative "I agree" tap (per Apple Guideline 5.1.2(i) and in the spirit of PDPA Articles 19–20). The timestamp of that consent is stored against your account (profiles.ai_consent_at), and our analyze-room server function refuses to process a photo without it.

6. 資料保存期間 / Data Retention

您的照片與分析結果會保留於您的帳號中,直到您刪除該筆掃描紀錄或刪除整個帳號 為止。刪除帳號將自您裝置與我們的伺服器上永久移除您的所有照片、掃描紀錄與 個人資料(受限於第 4 節所述 OpenAI 之濫用防制保留期間)。

Your photos and analysis results remain in your account until you delete that scan or delete your account entirely. Deleting your account permanently removes all your photos, scans, and personal data from our servers (subject to OpenAI's abuse-monitoring retention window described in Section 4, which we do not control once a photo has been transmitted for analysis).

7. 您的權利 / Your Rights

依台灣個人資料保護法第 3 條,您有權:查詢、請求閱覽、請求製給複製本、請求 補充或更正、請求停止蒐集、處理或利用,以及請求刪除您的個人資料。您可在 App 內「個人檔案 → 刪除帳號」直接完成刪除;如需其他請求,請透過第 12 節聯絡 我們。

Under Taiwan's Personal Data Protection Act (PDPA) Article 3, you have the right to: inquire about, access, obtain a copy of, request correction or supplementation of, request cessation of collection/processing/use of, and request deletion of your personal data. In-app account deletion is available directly from Profile → Delete Account; for any other request, contact us using Section 12.

8. 兒童隱私 / Children's Privacy

本服務不適用於未滿 13 歲之兒童,我們不會刻意蒐集兒童之個人資料。

The Service is not directed at children under 13, and we do not knowingly collect personal data from children.

9. 跨境資料傳輸 / International Data Transfers

您的帳號與掃描資料儲存於 Supabase 位於東京(日本)之伺服器。您傳送分析之 照片會傳輸至 OpenAI(美國)進行處理。使用本服務即表示您同意上述跨境傳輸。

Your account and scan data are stored on Supabase servers in Tokyo, Japan. Photos you submit for analysis are transmitted to OpenAI (United States) for processing. By using the Service, you consent to these cross-border transfers.

10. 安全維護措施 / Security Measures

我們採行下列適當安全措施(個資法第 27 條):所有資料傳輸皆使用 TLS 加密; 房間照片儲存於私有、僅擁有者可存取的儲存空間;每個資料表皆設有列級安全性 (RLS)政策,確保使用者僅能存取自己的資料;AI 服務金鑰僅存在於伺服器端密鑰 管理系統,從未包含於 App 安裝檔中。

We maintain the following security measures (PDPA Article 27): all data in transit is encrypted (TLS); room photos are stored in a private, owner-only-accessible storage bucket; every data table is protected by row-level security (RLS) policies so users can only access their own data; the AI service key exists only in server-side secret management and is never included in the app binary.

11. 政策變更 / Changes to This Policy

我們可能不時更新本政策。重大變更將於 App 內另行通知。持續使用本服務即表示 您接受更新後之政策。

We may update this policy from time to time. Material changes will be notified in-app. Continued use of the Service after an update constitutes acceptance of the revised policy.

12. 聯絡我們 / Contact Us

如對本政策或您的個人資料有任何問題,請聯繫:ray@noise-and-signal.com (待正式發布前請以真實可聯絡之地址取代此佔位符)。

For any question about this policy or your personal data, contact: ray@noise-and-signal.com (replace this placeholder with a real, monitored address before publishing).