隐私政策
Privacy Policy
PlantIsle · 植屿 | 最后更新及生效:2026年9月28日
PlantIsle | Last updated and effective: September 28, 2026
政策范围与处理者
Scope and controller
- 本政策适用于 PlantIsle(植屿)App、plantisle.com 网站及其相关服务。个人信息处理者为 PlantIsle 开发者,联系邮箱为 support@plantisle.com。
- 我们遵循最小必要原则处理信息。不登录时,多数植物数据仅保存在设备;启用登录、同步、社区、分享或反馈功能时,相应信息才会上传或对外提供。
- This policy applies to the PlantIsle app, plantisle.com, and related services. The PlantIsle developer is the controller. Contact: support@plantisle.com.
- We process only what is reasonably necessary. Without sign-in, most plant data remains on your device. Relevant information is uploaded or disclosed only when you enable sign-in, sync, community, sharing, or feedback features.
我们处理的信息
Information we process
- 账号信息:账号标识、手机号,或 Apple 登录返回的标识、邮箱及可能提供的姓名,或 Google 登录返回的账号标识、邮箱及邮箱验证状态;以及登录会话与账号绑定状态。Google 登录不申请 profile 权限,也不读取、保存或使用 Google 账号姓名和头像。
- 版本与登录记录:每次 App 建立账号登录态时,记录当前 App 版本、构建号和服务端上报时间,用于版本兼容、故障定位与升级运营。
- 个人资料与社交关系:可选昵称、头像、注册或加入时间、关注与粉丝、拉黑、邀请、协作者关系及新手引导完成状态。
- 植物与养护数据:植物名称、品种、种植日期、分组、备注、图标、排序、收藏与删除状态,养护事件,以及提醒类型、周期、下次提醒日期和完成记录等养护计划。
- 公开与互动内容:你主动发布的社区照片、配文、关联植物与养护快照、评论、点赞、举报,以及公开分享快照和分享者主页入口。
- 通知信息:APNs 或 Huawei Push Kit 设备令牌、推送平台与环境、设备语言与时区、分类开关,以及投递互动、邀请、系统公告和按类型聚合的养护计划提醒所需的信息。
- 位置与天气信息:经授权后读取设备位置;向 Open-Meteo 发送抹粗到约 1 公里的坐标查询天气,并使用 Apple 地理编码解析城市或区域。
- 反馈与诊断信息:仅在你主动上传错误报告时,处理问题描述、可选联系方式,以及你选择附带的版本、设备、语言时区、同步状态、数量统计、受控操作轨迹和 Apple 提供的崩溃或卡顿诊断(如有);只有额外开启“附带本地数据与植物信息”时才上传完整植物与事件数据。
- 网络与安全日志:访问云端、图片、天气或网站服务时,服务提供方可能自动接收 IP 地址、请求时间、请求 URL、设备或浏览器类型、响应状态等必要日志。
- Account information: account identifier; phone number; the identifier, email, and any name returned by Apple sign-in; or the account identifier, email address, and email-verification status returned by Google sign-in; plus session data and linked sign-in status. Google sign-in does not request the profile scope and does not read, store, or use the Google account name or profile photo.
- Version and sign-in record: whenever the app establishes an account session, it records the current app version, build number, and server receipt time for compatibility, troubleshooting, and upgrade operations.
- Profile and social relationships: optional nickname and avatar, registration or join date, follows and followers, blocks, invitations, collaborator relationships, and onboarding completion.
- Plant and care data: plant name, variety, planting date, group, notes, icon, order, favorite and deletion status; care events; and care-plan action, interval, next reminder date, and completion history.
- Public and interactive content: community photos, captions, associated plant and care snapshots, comments, likes, reports, public share snapshots, and links to the sharer's public profile.
- Notification information: APNs or Huawei Push Kit device token, push platform and environment, device language and time zone, category preferences, and information needed to deliver interactions, invitations, system announcements, and care-plan reminders aggregated by care type.
- Location and weather: with permission, the app reads device location, sends coordinates coarsened to about 1 km to Open-Meteo for weather, and uses Apple geocoding to resolve a city or area.
- Feedback and diagnostics: only when you submit an error report, we process your description, optional contact details, and selected version, device, locale/time zone, sync state, counts, controlled operation breadcrumbs, and Apple-provided crash or hang diagnostics when available. Complete plant and event data is uploaded only if you separately enable that option.
- Network and security logs: cloud, image, weather, and website providers may automatically receive IP address, request time and URL, device or browser type, status code, and similar necessary logs.
设备权限
Device permissions
- 位置权限用于显示当地天气;拒绝或关闭后,记录等核心功能仍可使用。
- 相机和相册权限仅在你主动拍摄或选择头像、自定义图标、社区照片时使用;App 只处理你拍摄或选择的内容。
- 通知权限用于养护提醒和互动、邀请消息;你可在系统设置或 App 通知设置中关闭。
- Location permission supports local weather. Core record features continue to work if you decline or disable it.
- Camera and photo access is used only when you take or select an avatar, custom icon, or community photo. The app processes only the content you capture or choose.
- Notification permission supports care reminders, interactions, and invitations. You can disable it in system settings or the app's notification settings.
哪些信息可能对其他人可见
Information visible to others
- 排行榜与公开主页可能展示昵称或默认代称、头像、加入时间、关注统计、植物数、事件数、养护天数、完成计划数和获赞数等统计。
- 社区会向其他登录用户展示你发布的照片、配文、关联植物与养护快照、评论、点赞关系及公开资料。拉黑会限制双方后续查看,但不能撤回对方此前已保存的内容。
- 公开分享会展示你选择的植物名称、图标、养护快照和公开主页入口;任何获得链接或二维码的人都可能访问。
- 转让或共同养护邀请会向你选定的接收方展示发起者资料、植物名称和图标;接受共同养护后,协作者可查看该植物、时间线和相关计划。
- 植物品种、种植日期和植物备注不会进入社区帖子或公开分享快照,除非你自行写入公开文字或图片。
- Leaderboards and public profiles may show your nickname or default alias, avatar, join date, follow counts, plant count, event count, care days, completed plans, likes received, and similar statistics.
- Community content shown to other signed-in users includes your photos, captions, associated plant and care snapshots, comments, like relationships, and public profile. Blocking restricts future visibility but cannot retract copies someone already saved.
- Public shares show the selected plant name, icon, care snapshot, and public-profile entry. Anyone with the link or QR code may access them.
- Transfer or co-care invitations show the selected recipient the sender's profile, plant name, and icon. After co-care is accepted, the collaborator can view that plant, its timeline, and related plans.
- Variety, planting date, and private plant notes do not enter community posts or public share snapshots unless you place them in public text or images yourself.
我们如何使用信息
How we use information
- 提供账号认证、跨设备同步、备份恢复、植物记录、日历、计划提醒、天气、排行榜、社区、分享、关注、通知、转让与共同养护。
- 进行自动内容安全审核、举报与拉黑处理,防止违法内容、滥用、欺诈和安全风险。
- 响应你主动提交的反馈、数据恢复和个人信息权利请求,并排查故障。
- 我们不出售个人信息,不进行跨 App 追踪,也不将植物、备注、照片、手机号或邮箱用于第三方广告投放。
- To provide authentication, cross-device sync, backup and recovery, plant records, calendar, care reminders, weather, leaderboards, community, sharing, follows, notifications, transfer, and co-care.
- To perform automated content-safety review, reports, and blocks, and to prevent illegal content, abuse, fraud, and security threats.
- To respond to feedback, data-recovery requests, and privacy-rights requests you submit and to troubleshoot issues.
- We do not sell personal information, track you across apps, or use plant data, notes, photos, phone numbers, or email addresses for third-party advertising.
存储地点与跨境处理
Storage and international processing
- 本机数据保存在 App 沙盒;最近 30 天的滚动数据备份仅保存在设备,不主动上传。是否随 iCloud 或整机备份由你的系统设置决定。
- 登录后,账号、植物与养护、个人资料路径、社交关系、社区、分享、通知和错误报告等数据由 Supabase Pte. Ltd. 在日本东京的服务器处理,属于向中国大陆境外提供个人信息。处理方式包括存储、查询、传输、同步和删除;你可通过我们向境外接收方行使访问、更正、删除等权利。
- 头像、自定义植物图标和社区照片存储在腾讯云 COS 上海地域。其他服务可能在其政策说明的地点处理必要信息,详见第三方信息共享清单。
- 当你在登录页勾选同意并使用登录或云端功能,即表示你已阅读本节并同意按上述目的、方式和范围向境外提供相关信息。如不同意,请不要登录;本地记录功能仍可使用。
- On-device data is stored in the app sandbox. A rolling 30-day backup remains only on the device and is not actively uploaded. Whether it enters iCloud or a full-device backup depends on your system settings.
- After sign-in, Supabase Pte. Ltd. processes account, plant and care, profile-path, social, community, share, notification, and error-report data on servers in Tokyo, Japan. Processing includes storage, retrieval, transmission, sync, and deletion. You may exercise access, correction, and deletion rights through us.
- Avatars, custom plant icons, and community photos are stored in Tencent Cloud COS in Shanghai. Other services may process necessary data in the locations described in their policies; see the Third-Party Information Sharing List.
- By checking the consent box on the sign-in screen and using account or cloud features, you acknowledge this section and consent to the described international transfer. If you do not agree, do not sign in; local record features remain available.
保存期限与删除
Retention and deletion
- 账号和同步数据通常保存至你删除相应内容或注销账号。删除的植物、事件和计划会进入近期删除并在 30 天后清除,也可提前彻底删除。
- 公开分享快照默认 30 天失效;转让或共同养护邀请默认 7 天失效。
- 删除社区帖子后会停止公开,关联照片会尽力删除;必要的帖子状态记录在账号注销时一并删除。
- 站内消息读取后可保存在当前设备,直至你清理、卸载 App 或系统移除数据;社区帖子与评论缓存最长保留 24 小时。
- 错误报告保存至问题处理完成、你提出删除或账号注销,以先发生者为准。服务商安全日志和备份可能按其最短必要周期延迟删除。
- 注销账号会删除 Supabase 中的账号及关联业务数据,并尽力清理腾讯云图片;因网络失败产生的孤立对象会进入后续巡检清理。
- Account and sync data is generally kept until you delete the relevant content or account. Deleted plants, events, and plans remain in Recently Deleted for 30 days unless permanently cleared sooner.
- Public share snapshots expire after 30 days by default. Transfer and co-care invitations expire after 7 days by default.
- Deleting a community post removes it from public view and we attempt to delete associated photos. Necessary post-status records are deleted with the account.
- Read in-app messages may remain on the current device until you clear them, uninstall the app, or the system removes data. Community post and comment caches are kept for no more than 24 hours.
- Error reports remain until the issue is resolved, you request deletion, or the account is deleted, whichever occurs first. Provider security logs and backups may take longer to disappear under their shortest necessary retention periods.
- Account deletion removes the account and related business data from Supabase and attempts to clean Tencent Cloud images. Orphaned objects caused by network failures are queued for later inspection and cleanup.
第三方服务与公开披露
Service providers and public disclosure
- 我们仅为实现明确功能向 Supabase、腾讯云、Apple、Google、阿里云、Open-Meteo 和 Cloudflare 提供必要信息,不允许其将我们的业务数据用于第三方广告。具体接收方、用途、信息种类、处理方式和官方隐私政策见第三方信息共享清单。
- 除你主动使用社区、公开分享、互动、邀请或共同养护产生的可见内容外,我们不会公开披露你的个人信息,法律法规另有要求或为保护重大权益所必需的除外。
- We provide only necessary information to Supabase, Tencent Cloud, Apple, Google, Alibaba Cloud, Open-Meteo, and Cloudflare for defined features and do not permit them to use our service data for third-party advertising. See the Third-Party Information Sharing List for recipients, purposes, data types, methods, and official privacy notices.
- Except for content made visible through your community, public-share, interaction, invitation, or co-care actions, we do not publicly disclose personal information unless required by law or necessary to protect significant rights and interests.
安全措施
Security
- 云端数据按账号实施访问控制;跨用户读取通过受限接口返回必要字段,网络传输使用 HTTPS。
- 图片上传使用短期预签名地址,写入路径限定在当前用户目录;公开图片采用难以猜测的对象路径,但获得有效 URL 的人仍可访问。
- 互联网服务无法保证绝对安全。如发生可能影响你权益的安全事件,我们会依法采取补救和告知措施。
- Cloud data is protected by account-based access controls. Cross-user reads use restricted interfaces that return necessary fields, and network transport uses HTTPS.
- Image uploads use short-lived pre-signed URLs and are restricted to the current user's object path. Public images use hard-to-guess paths, but anyone with a valid full URL can access them.
- No internet service can guarantee absolute security. If an incident may affect your rights, we will take remedial and notification measures as required by law.
你的权利与选择
Your rights and choices
- 你可以在 App 中查阅、更正或删除植物、养护记录、计划、昵称、头像、社区内容和其他可编辑信息。
- 你可以在系统设置中撤回位置、相机、相册和通知权限;撤回不影响此前基于授权完成的处理。
- 你可以退出登录停止新的云端同步,并在账号管理中管理登录方式或注销账号。
- 如需访问、复制、更正、补充、删除、限制处理或撤回对其他信息处理的同意,请联系 support@plantisle.com;我们会在 15 个工作日内答复。
- 拒绝非必要权限不影响核心记录功能;拒绝账号认证或云端处理时,登录后功能将无法使用。
- You can view, correct, or delete plants, care records, plans, nickname, avatar, community content, and other editable information in the app.
- You can withdraw location, camera, photo, and notification permissions in system settings. Withdrawal does not affect processing already completed under prior authorization.
- You can sign out to stop new cloud sync and manage sign-in methods or delete the account under Account Management.
- To access, copy, correct, supplement, delete, restrict, or withdraw consent for other processing, contact support@plantisle.com. We will respond within 15 business days.
- Declining optional permissions does not affect core records. If you decline account authentication or cloud processing, signed-in features cannot be provided.
未成年人保护
Children
- PlantIsle 面向一般用户,不专门面向未满 14 周岁的未成年人。
- 未满 14 周岁的用户应在监护人同意和指导下使用需要账号的功能。若发现未经监护人同意处理了儿童个人信息,我们会尽快删除或采取其他必要措施。
- PlantIsle is intended for a general audience and is not specifically directed to children under 14.
- Users under 14 should use account-based features only with guardian consent and guidance. If we learn that a child's information was processed without guardian consent, we will delete it promptly or take other necessary measures.
政策更新与联系我们
Updates and contact
- 如处理目的、方式或信息种类发生重大变化,我们会更新日期,并通过 App 内提示等适当方式重新告知或征得同意。如有疑问、意见、投诉或删除请求,请发送邮件至 support@plantisle.com,或通过 App 内“设置 → 上传错误报告”留言。
- If purposes, methods, or data types materially change, we will update the date and provide a new notice or obtain consent through appropriate means such as an in-app prompt. For questions, complaints, or deletion requests, email support@plantisle.com or use Settings → Upload Error Report in the app.
本文档会随功能更新而修订,修订后会更新顶部的「最后更新」日期;重大变更会在 App 内以适当方式提示。
This document may be revised as features change. The “Last updated” date above will be updated, and material changes will be communicated through appropriate in-app notices.
返回首页 · 用户协议 · 隐私政策 · 第三方信息共享清单 · 技术支持 Home · Terms · Privacy · Third Parties · Support