第三方信息共享清单
Third-Party Information Sharing List
PlantIsle · 植屿 | 最后更新:2026年8月20日
PlantIsle | Last updated: August 20, 2026
清单说明
About this list
- 以下服务会在相应功能触发时处理最小必要信息。这里的“共享”包括委托处理、接口传输或由你主动公开,不代表我们出售个人信息。服务商可能更新其政策,请通过每项的官方链接查看最新版本。
- The services below process minimum necessary information when the corresponding feature is triggered. “Sharing” includes processing on our behalf, API transmission, or disclosure you initiate; it does not mean that we sell personal information. Providers may update their policies, so use each official link for the latest version.
Supabase Pte. Ltd.
Supabase Pte. Ltd.
- 服务:账号认证、Postgres 数据库、实时连接、云函数与 API。
- 处理方式与目的:通过 SDK、HTTPS API、数据库、实时连接和 Edge Functions 提供登录、同步、社区、分享、社交关系、邀请、通知和错误报告。
- 信息种类:账号标识、手机号或邮箱、会话信息、昵称和图片路径、植物与养护数据、社区与互动内容、关注/拉黑/邀请/共养关系、推送令牌与偏好、分享快照,以及你主动上传的反馈和诊断信息。
- 地点与触发:项目服务器位于日本东京,属于向中国大陆境外提供个人信息;登录或使用需要云端的功能时触发。
- 权利渠道:你可在 App 内管理或删除数据,或通过 support@plantisle.com 向我们提出请求,由我们协助向境外接收方行使权利。
- Service: authentication, Postgres database, realtime connections, edge functions, and APIs.
- Method and purpose: SDKs, HTTPS APIs, databases, realtime connections, and Edge Functions provide sign-in, sync, community, sharing, social relationships, invitations, notifications, and error reports.
- Data: account identifier, phone or email, session data, nickname and image paths, plant and care data, community and interaction content, follow/block/invitation/co-care relationships, push token and preferences, share snapshots, and feedback and diagnostics you submit.
- Location and trigger: the project is hosted in Tokyo, Japan and is used when you sign in or use cloud-backed features.
- Rights: manage or delete data in the app, or contact support@plantisle.com and we will help route a request to the overseas recipient.
腾讯云 COS(图片存储与分发)
Tencent Cloud COS (image storage and delivery)
- 提供方:腾讯云计算(北京)有限责任公司。
- 处理方式与目的:通过预签名 HTTPS 地址上传、存储和下载头像、自定义植物图标及社区照片,并按需生成社区缩略图。
- 信息种类:图片内容、包含账号标识的对象路径,以及 IP 地址、请求时间、状态等必要网络日志。
- 地点与触发:对象位于中国上海;当你上传或查看相应图片时触发。
- 特别说明:当前图片桶为公有读取,只有获得难以猜测的完整 URL 才能访问。请勿上传证件、私密影像等敏感内容。
- Provider: Tencent Cloud Computing (Beijing) Co., Ltd.
- Method and purpose: short-lived pre-signed HTTPS URLs upload, store, and download avatars, custom plant icons, and community photos and generate thumbnails when needed.
- Data: image content, object paths containing the account identifier, and necessary network logs such as IP address, request time, and status.
- Location and trigger: objects are stored in Shanghai, China; processing occurs when you upload or view the relevant image.
- Important: the current image bucket is publicly readable. A hard-to-guess complete URL is required, but you should not upload identification documents, intimate images, or other sensitive content.
腾讯云内容安全(自动审核)
Tencent Cloud Content Moderation
- 提供方:腾讯云计算(北京)有限责任公司。
- 处理方式与目的:服务端调用文本与图片内容安全 API 进行自动审核,返回通过、复核或拦截建议,用于阻止违法违规或不适宜的公开内容。
- 信息种类:昵称、社区配文、关联植物名称与养护备注、评论、头像、自定义图标和社区照片;不提供手机号或邮箱。
- 触发:修改昵称或头像、发布或编辑帖子、发表评论时。审核结果可能导致内容被拒绝发布。
- Provider: Tencent Cloud Computing (Beijing) Co., Ltd.
- Method and purpose: our server calls text and image moderation APIs for automated allow/review/block recommendations to prevent illegal or unsuitable public content.
- Data: nickname, community caption, associated plant name and care notes, comments, avatar, custom icon, and community photos; phone number and email are not provided.
- Trigger: when you change a nickname or avatar, publish or edit a post, or add a comment. The result may prevent publication.
Apple(登录)
Apple (sign-in)
- 处理方式与目的:当你选择 Apple 登录或绑定时,由 Apple 完成身份验证,App 再将登录凭证交给 Supabase 建立账号会话。
- 信息种类:Apple 用户标识、身份令牌,以及你选择授权提供的邮箱;Apple 会按其规则处理设备、账号和安全信息。
- 触发:仅在你主动选择 Apple 登录、绑定或重新验证时。
- Method and purpose: Apple authenticates you when you choose Apple sign-in or linking, after which the app provides the credential to Supabase to establish the session.
- Data: Apple user identifier, identity token, and any email address you authorize; Apple processes device, account, and security data under its own rules.
- Trigger: only when you choose Apple sign-in, linking, or reauthentication.
Apple(推送、定位与系统服务)
Apple (push, location, and system services)
- 处理方式与目的:APNs 投递系统通知;Core Location 提供位置,Apple 地理编码把位置解析为城市或区域;App Store Lookup 检查已发布版本;MetricKit 向 App 提供系统生成的崩溃、卡顿与资源异常诊断;本地文件是否进入 iCloud 或整机备份由你的系统设置决定。
- 信息种类:推送设备令牌、App 标识、通知标题与正文(可能含昵称、评论摘要或植物名称),使用地理编码时的设备位置,版本检查所需信息,以及 MetricKit 提供的调用栈、异常类型和资源异常摘要。
- 触发:版本检查会在 App 启动完成及符合条件的回到前台时进行;推送和定位仅在你授权并使用相应功能时处理。MetricKit 诊断只保存在设备,只有当你在错误报告中主动选择诊断信息并提交时才上传。
- Method and purpose: APNs delivers system notifications; Core Location provides location and Apple geocoding resolves it to a city or area; App Store Lookup checks the published version; MetricKit provides system-generated crash, hang, and resource-exception diagnostics to the app; system settings control whether local files enter iCloud or full-device backups.
- Data: push device token, app identifier, notification title and body, device location for geocoding, version-check information, and MetricKit call stacks, exception types, and resource-exception summaries.
- Trigger: version checks run after app startup and on eligible foreground returns. Push and location data are processed only when you grant the relevant permission and use the feature. MetricKit diagnostics remain on-device and are uploaded only when you select diagnostics and submit an error report.
阿里云(短信验证码)
Alibaba Cloud (SMS verification)
- 提供方:阿里云计算有限公司及其关联服务主体。
- 处理方式与目的:Supabase 生成验证码后,通过阿里云短信 API 向你输入的号码发送登录验证码。
- 信息种类与触发:手机号、短信签名/模板参数、验证码及发送结果;仅在你主动发起手机号登录时处理。
- Provider: Alibaba Cloud Computing Ltd. and relevant service affiliates.
- Method and purpose: after Supabase generates a code, Alibaba Cloud's SMS API sends it to the number you entered.
- Data and trigger: phone number, signature/template parameters, verification code, and delivery result; processed only when you request phone sign-in.
Open-Meteo GmbH
Open-Meteo GmbH
- 服务:通过 HTTPS API 返回当前天气、温度和湿度。
- 信息种类:抹粗到约 1 公里精度的经纬度、IP 地址、请求 URL 和时间等必要日志;不包含账号标识、植物数据、手机号或邮箱。
- 地点与期限:由位于瑞士的 Open-Meteo 处理;其公开说明称免费 API 日志可能包含坐标,并在 90 天后删除。
- 触发:你授权位置权限且天气缓存需要刷新时。
- Service: an HTTPS API returns current conditions, temperature, and humidity.
- Data: latitude and longitude coarsened to about 1 km, IP address, request URL and time, and related logs; no account identifier, plant data, phone number, or email.
- Location and retention: Open-Meteo is based in Switzerland. Its public notice says free-API logs may contain coordinates and are deleted after 90 days.
- Trigger: when you grant location permission and the weather cache needs refreshing.
Cloudflare, Inc.
Cloudflare, Inc.
- 服务:为 plantisle.com 提供 DNS、CDN、安全防护和网页托管访问链路。
- 信息种类:IP 地址、请求时间、浏览器或设备类型、请求 URL(公开分享 URL 可能含分享标识)及安全日志。
- 地点与触发:访问官网、协议、技术支持或公开分享落地页时触发;Cloudflare 可能通过其全球网络处理请求。
- Service: DNS, CDN, security, and website-delivery infrastructure for plantisle.com.
- Data: IP address, request time, browser or device type, request URL (public-share URLs may include a share identifier), and security logs.
- Location and trigger: used when you visit the website, legal pages, support, or a public-share landing page. Cloudflare may process requests across its global network.
当前未接入
Not currently integrated
- 目前未接入第三方广告 SDK、统计分析 SDK,也不进行跨 App 跟踪。
- 错误报告和完整本地数据不会自动上传,只有在你查看内容并主动提交时才发送。
- We currently integrate no third-party advertising or analytics SDK and perform no cross-app tracking.
- Error reports and complete local data are never uploaded automatically; they are sent only after you review and submit them.
本文档会随功能更新而修订,修订后会更新顶部的「最后更新」日期;重大变更会在 App 内以适当方式提示。
This document may be revised as features change. The “Last updated” date above will be updated, and material changes will be communicated through appropriate in-app notices.
返回首页 · 用户协议 · 隐私政策 · 第三方信息共享清单 · 技术支持 Home · Terms · Privacy · Third Parties · Support