GoMuseum 隐私政策

Privacy Policy · 生效日期 / Effective: 2026-09-05 · 适用应用:GoMuseum(com.gomuseum.app)

1. 我们是谁

GoMuseum("我们")是一款博物馆导览应用,提供拍照识别展品、AI 讲解、语音播放与问答功能。数据控制者联系方式:appcraft008@gmail.com。

GoMuseum is a museum guide app offering artwork recognition, AI-generated narration and Q&A. Data controller contact: appcraft008@gmail.com.

2. 我们收集哪些数据、为什么

数据 / Data用途 / Purpose保留 / Retention
账号信息:邮箱、用户名(或 Google 账号基本资料)创建与登录账号、找回访问权限至账号删除
展品照片(拍照识别时)仅用于实时识别展品,临时处理、不存储原图,处理完成即丢弃不保留
识别事件:图片指纹、识别到的作品与置信度、所在馆、语言两个用途:①改进识别准确率、统计哪些展品被拍到却认不出,据此优先补充资料;②生成你的「足迹」——登录状态下拍照识别时会记下你的账号,让你能在应用内回看拍过哪些作品。你可以在足迹页逐条删除,也可以随时导出与账号的关联至账号删除或你自行删除;去除账号关联后的统计记录长期保留
设备标识符免费额度管理与防滥用至账号删除
诊断数据(崩溃日志、性能)改进应用稳定性最长 90 天
使用统计:应用打开、页面浏览、会话时长,以及设备型号与系统版本了解哪些功能被使用、改进产品。由 Google Firebase 采集(见第 3 节)。我们不采集广告标识符依 Firebase 默认设置
交易记录:购买时间、商品、金额、订单号发放与核验通票权益、退款处理、会计与税务留存删除账号后仍保留(见第 4 节)

We collect account info (email/username) for authentication; photos are processed ephemerally for recognition only and never stored. Recognition events (image fingerprint, matched artwork, confidence) improve accuracy and, when you are signed in, power your in-app "Footprints" history — you can delete entries individually or export them. Device identifiers manage free quota. Crash reports and default usage analytics come from Google Firebase — no custom events, no advertising ID. Transaction records are retained after account deletion for accounting and tax obligations (see section 4).

3. 数据如何被处理(第三方处理者)

Recognition/narration is processed by OpenAI per our instructions (not used for training per OpenAI API policy). Sign-in by Google; crash reporting and default usage analytics by Google Firebase (no custom events, advertising-ID permission removed). In-app purchases are processed by Google Play Billing — we never see or store your payment method; we receive only a purchase receipt to verify and grant your pass. We never sell your data; no advertising.

4. 你的权利(GDPR/CCPA)

Delete your account in-app at Settings → Delete account. This permanently deletes your profile and quota records, and unlinks your footprints — the account identifier is stripped from recognition events, which then point to no one; the de-identified statistics are kept for recognition-accuracy analysis. Any purchased pass is voided immediately and cannot be recovered — passes are consumable products, already consumed on Google Play's side, so "Restore purchases" will not bring them back; re-registering does not restore them either. Transaction records (order ID, item, amount, date) are retained to meet accounting and tax obligations, but are unlinked from your identity and stripped of personal data. To export your data, email appcraft008@gmail.com; we respond within 30 days.

5. 数据安全与存储位置

数据通过 TLS 加密传输;账号与交易等个人数据存储在位于欧盟(法国)的服务器,密码以 bcrypt 加密存储。藏品图片与语音等内容资产存放在 Cloudflare R2 对象存储(不含个人数据)。我们采取访问控制、速率限制与每日备份等措施保护数据。

Data is encrypted in transit (TLS). Personal data (accounts, transactions) is stored on servers located in the EU (France); passwords are bcrypt-hashed. Media assets (artwork images, audio) are served from Cloudflare R2 and contain no personal data.

6. 儿童隐私

本应用不面向 13 岁以下儿童设计,我们不会有意收集儿童个人信息。如你认为我们无意中收集了儿童数据,请联系 appcraft008@gmail.com,我们将予以删除。

This app is not directed to children under 13, and we do not knowingly collect their personal information.

7. 政策更新

政策如有重大变更,我们将在应用内或本页面公告。继续使用即视为接受更新后的政策。