私隱政策 · Privacy Policy
又飛機 (flyg9)
私隱政策
生效日期:2026-08-20
我哋收集乜嘢
- 顯示名同預設頭像(你揀) — 用嚟喺同場朋友之間顯示你嘅身份;同場參加者會見到,頭像係 app 內置圖案,唔係你嘅相片。
- 裝置識別碼同本機登入憑證 — app 自動產生 UUID 作為帳號替代,另產生隨機登入憑證並只保存喺你部裝置;server 只保存憑證嘅不可逆雜湊。
- 可選擇提供嘅電郵地址 — 你唔使登入都可以直接玩。如果你喺設定主動加入電郵,我哋會保存經驗證嘅電郵地址,用嚟寄一次性驗證碼,等你重裝 app 或轉裝置後登入返同一個玩家帳號;我哋唔會用佢做廣告。
- 活動同玩法內容 — 包括你輸入嘅活動名稱、集合時間、地點、可選擇落嘅集合點座標、今場懲罰、催人內容,以及你嘅出發/到場狀態、挑戰、投票同賽果。集合點座標只會向已加入相關活動嘅參加者顯示。任何攞到該場邀請 link 嘅人,都可以喺唔使登入嘅入場頁見到活動名稱、集合時間同參加人數,但該頁唔會顯示地點文字或集合點座標;其餘內容只會向相關活動參加者顯示。
- 舉報同封鎖資料 — 包括你舉報嘅內容/用戶、舉報原因,同你選擇封鎖嘅用戶,用嚟處理濫用、爭議同執行封鎖。
- 自證相片(你主動上載) — 屬用戶生成內容,只限同場參加者睇到,用嚟做報到/挑戰嘅證據。上載前,app 會將所選圖片重新編碼成新 JPEG,移除原相嘅 EXIF、拍攝位置同其他 metadata;如果無法安全處理,就唔會上載。
- 粗略或精確位置(完全 opt-in) — 只有喺你自己選擇附上自證 GPS,或者撳「出發中」/「到咗」時揀分享位置,先會收集。預設只收集你主動撳掣嗰刻嘅一次 snapshot;如你另行開啟自動更新,app 只會喺你開住該場活動畫面、而且 app 位於前景時,每 10 分鐘重複收集 one-shot snapshot。離開該畫面、鎖機、將 app 放入背景、到咗、活動結算或你手動停止時就會停,重開 app 亦唔會自動恢復。唔 share 一樣玩到晒;位置唔會自動決定投票或判決,亦唔會背景追蹤或記錄行程路線。
- Firebase Cloud Messaging app/安裝識別資料及推送通知資料 — Firebase SDK 可能喺通知權限畫面之前初始化並處理 app/安裝識別資料;只有你容許通知後,我哋先會登記推送 token,並處理通知送達所需嘅事件資料。
- 購買及訂閱資料 — 如果 build 有配置商店 key,RevenueCat 會喺 app 啟動時建立匿名 app-user/安裝識別資料,並查詢產品 offering 同 entitlement 狀態,即使你未訂閱亦會發生。當你購買「搞手 Pass」,App Store/Google Play 同 RevenueCat 亦會提供產品、購買、續訂、取消、到期同退款狀態。我哋唔會收到你完整嘅付款卡或銀行資料。
我哋唔收集乜嘢
我哋唔會收集你嘅通訊錄、通話紀錄、瀏覽紀錄、廣告識別碼、健康資料,亦唔會直接收集完整付款卡或銀行資料。冇廣告追蹤(tracking)、冇廣告 SDK,亦唔會出售你嘅資料。
Call爆狀態
同場參加者會見到每位玩家嘅 Call爆狀態(已準備/未開/待確認),避免將 Call爆道具用喺暫時收唔到通知嘅人身上。其他玩家唔會見到你嘅通知、聲音、靜音、Focus、勿擾模式或其他裝置設定。
地圖服務
當你打開自證位置或戰況地圖,app 會向 OpenStreetMap Foundation(OSMF)嘅地圖服務要求你所睇附近區域嘅地圖圖塊。呢個要求會將該附近區域同你嘅 IP 位址傳送俾 OSMF,但唔會傳送你嘅顯示名、活動內容或相片。詳情見 OSMF 私隱政策;地圖資料版權及授權見 OpenStreetMap copyright。
落集合點時,你亦可以主動輸入地方或地址,再撳「搵」將地圖移去附近;冇即時建議或自動完成。只有你明確提交後,Flyg9 server 先會將搜尋文字放入供應商 request,交俾已配置嘅地理編碼供應商(beta 期間可能係 OSMF Nominatim),連同 server IP 同 app 聯絡資料作功能性搜尋;唔會傳送你嘅顯示名、活動資料或裝置憑證。server 只會用搜尋文字嘅 SHA-256 指紋做限流/cache key,短期 cache 最多三個已整理結果;唔會將原始搜尋文字放入 Flyg9 endpoint/access URL、app log 或資料庫,亦唔會保存供應商 Place ID。搜尋內容同結果唔會寫入活動;只有你最後撳「落喺呢度」確認嘅座標先會保存成該場集合點。
另外,只有你喺活動詳情主動撳「用地圖搵」之後,app 先會將搞手輸入嘅活動地點文字交俾外部地圖 app 搜尋(Android 交俾你揀嘅地圖 app;iOS 交俾 Apple Maps)。打開活動詳情本身唔會傳送呢段搜尋文字。外部地圖供應商可能會按佢嘅私隱政策收到搜尋內容、IP 位址同裝置資料;搜尋結果唔會寫返入又飛機。
服務供應商同資料傳送
我哋只會為提供 app 功能而俾服務供應商處理所需資料:Resend 只會喺你要求加入電郵或恢復帳號時,處理你提供嘅電郵地址同一次性驗證碼以送出電郵;RevenueCat 處理匿名 app-user/安裝識別、offering/entitlement 查詢同訂閱收據;Firebase SDK/Cloud Messaging 處理 app/安裝識別資料,並喺你容許通知後處理推送 token 同通知送達;OSMF 提供地圖圖塊,而已配置嘅地理編碼供應商只喺你明確提交時處理地方/地址搜尋;雲端託管、資料庫同物件儲存供應商代我哋儲存及傳送活動資料同相片。佢哋按各自條款及私隱政策處理資料。呢啲功能性處理唔係廣告追蹤,亦唔係出售資料。
資料點樣儲存同保護
顯示名、預設頭像、裝置識別碼、你選擇加入嘅已驗證電郵地址、活動/玩法內容(包括搞手確認嘅集合點座標)、舉報同封鎖資料存放喺 PostgreSQL 資料庫;登入憑證只保存不可逆雜湊,電郵同驗證碼亦有 keyed hash 供安全比對。目的地搜尋 cache 只以搜尋文字嘅 SHA-256 指紋做 key,保存最多三個已整理結果至多 24 小時;原始搜尋文字同供應商 Place ID 唔會持久保存。已重新編碼並移除 metadata 嘅自證 JPEG 存放喺 S3 相容嘅物件儲存。每位參加者每場只會保留最新一次自願分享嘅戰況位置(連時間、準確度同當時狀態),只供同場成員查看,新 snapshot 會覆蓋舊 snapshot。app 同公開後端之間嘅資料傳輸經 HTTPS 加密;內部資料庫同物件儲存流量走託管平台嘅私人網絡。相片以有時效嘅 presigned URL 提供,連結過期後便無法再存取。
資料保留
我哋只會喺提供 app、處理爭議、防止濫用或符合法律要求所需嘅期間保留資料。電郵驗證碼 10 分鐘後失效;超過 24 小時嘅 challenge 會喺電郵服務下次處理要求時清理,恢復要求唔會將未驗證嘅電郵地址明文寫入 challenge。你可以隨時喺設定移除已驗證電郵。戰況位置 snapshot 會喺相關活動正式封盤(closed)時清除。成功刪除帳號後,我哋會刪除你嘅電郵同驗證 challenge、所有安裝登入憑證、分享嘅戰況位置、推送 token、自證相片、參加紀錄、投票、催人內容、封鎖關係、現有準時分錢包/物品同物品使用關係。
已經同其他成員共享嘅活動資料同玩法結果(例如你建立嘅活動同挑戰結果)可以為維持其他成員嘅活動紀錄而保留,但你嘅顯示名、預設頭像、裝置識別、登入憑證雜湊同同意紀錄會由保留嘅隨機墓碑帳號移除。為避免重複派發準時分,已用過嘅內部冪等紀錄可以保留,但會移除帳號 owner 欄位;內部冪等 key 仍可能包含隨機墓碑 ID。舉報可以為處理濫用、爭議或法律要求而保留,但舉報人帳號連結會移除。訂閱 entitlement/每月派發紀錄可以用隨機墓碑 ID 保留,供會計、退款、防詐及 App Store、Google Play、RevenueCat 狀態對數;商店或服務供應商亦可能按佢哋嘅政策或法律要求保留交易紀錄。
刪除要求
你可以喺 app「設定」入面直接刪除帳號,或者透過 支援頁 聯絡我哋。只有物件儲存確認自證相片已刪除後,server 先會回覆帳號刪除成功;如果儲存服務暫時失敗,帳號會保持未刪除而你可以重試。商店或服務供應商依法/按其政策保留嘅訂閱交易紀錄,要由相應平台處理。
兒童
本 app 並非為 13 歲以下兒童而設,我哋亦唔會刻意收集兒童嘅個人資料。
政策更新
本政策日後可能更新。有重大改動時,我哋會更新本頁頂部嘅生效日期。
Privacy Policy
Effective date: 2026-08-20
What we collect
- Display name and preset avatar (you choose them) — used to show your identity inside your friend events. Event participants can see both; the avatar is an artwork built into the app, not your photo.
- Device identifier and local sign-in credential — the app generates a UUID as an account substitute and a random sign-in credential retained only on your device; the server stores only an irreversible digest of that credential.
- Optional email address — you can play without signing in. If you choose to add an email in Settings, we store the verified address and use it to send one-time codes so you can return to the same player account after reinstalling or changing devices. We do not use it for advertising.
- Event and gameplay content — includes event names, gathering times, locations, an optional destination coordinate selected by the host, forfeits, and nudge text you enter, plus your travel/arrival status, challenges, votes, and results. Destination coordinates are shown only to participants who joined the relevant event. The event name, gathering time, and participant count appear on a no-sign-in join page available to anyone holding that event's invite link, but that page does not show the location text or destination coordinates; other content is shown only to participants in the relevant event.
- Report and block data — includes the content or users you report, your report reason, and users you choose to block, used to address abuse and disputes and to enforce blocks.
- Proof photos (you upload them) — user-generated content, visible only inside the relevant friend event, used as check-in / challenge evidence. Before upload, the app re-encodes the selected image as a new JPEG and removes the original photo's EXIF, capture location, and other metadata. If safe processing fails, the image is not uploaded.
- Coarse or precise location (strictly opt-in) — collected when you choose to attach proof GPS or share location on an “en route” / “arrived” action. The default is one snapshot at the moment you tap. If you separately enable automatic updates, the app collects a new one-shot snapshot every 10 minutes only while that event screen remains open and the app is in the foreground. It stops when you leave the screen, lock or background the app, arrive, enter settlement, or stop it yourself, and it does not resume after relaunch. The app works fully without location; location never decides a vote or verdict automatically, and there is no background tracking or route history.
- Firebase Cloud Messaging app/installation identifiers and push notification data — the Firebase SDK may initialize and process app/installation identifiers before the notification-permission prompt. We register a push token and process event data for notification delivery only after you allow notifications.
- Purchase and subscription data — in builds configured with a store key, RevenueCat creates an anonymous app-user/installation identifier and checks product offerings and entitlement status at app launch, even before you subscribe. If you buy 搞手 Pass, the App Store / Google Play and RevenueCat also provide purchase, renewal, cancellation, expiry, and refund status. We do not receive your full payment-card or bank details.
What we do NOT collect
We do not collect your contacts, call logs, browsing history, advertising identifiers, health data, or full payment-card or bank details. There is no advertising tracking, no advertising SDK, and we do not sell your data.
Call Blast status
Participants in the same event can see each player’s Call Blast status (ready, off, or unknown) so the app does not spend an item on someone who is not currently ready to receive it. We do not show other players your OS notification, sound-channel, Silent, Focus, Do Not Disturb, or device-setting details.
Map service
When you open a proof-location or event battle map, the app requests map tiles for the nearby area you are viewing from the OpenStreetMap Foundation (OSMF) map service. That request sends the nearby map area and your IP address to OSMF, but does not send your display name, friend-event content, or photos. See the OSMF Privacy Policy and OpenStreetMap copyright and licence information.
While placing a destination pin, you can also enter a place or address and explicitly tap Search to move the map nearby; there are no live suggestions or autocomplete. Only after that explicit submit does the Flyg9 server put the submitted text in a provider request to the configured geocoder (which may be OSMF Nominatim during beta), together with the server IP and app contact details needed for the functional request. It does not send your display name, event data, or device credential. The server uses only a SHA-256 fingerprint of the search text as a rate-limit/cache key and briefly caches at most three sanitized results; it does not put the raw query in a Flyg9 endpoint/access URL, persist it, write it to app logs, or retain a provider Place ID. Neither the query nor results are stored in the event. Only coordinates you separately confirm with “落喺呢度” are saved as that event's destination.
Separately, the app passes the event-location text entered by the host to an external map app only after you tap “用地圖搵” in the event details (to a map app you choose on Android, or to Apple Maps on iOS). Merely opening the event details does not send that search text. The external map provider may receive the search query, IP address, and device data under its privacy policy; search results are not written back to 又飛機.
Service providers and data transfers
We let service providers process only the data needed to operate the app: Resend processes the email address and one-time code only when you request email linking or account recovery, to deliver that email; RevenueCat processes anonymous app-user/installation identifiers, offering/entitlement checks, and subscription receipts; Firebase SDK / Cloud Messaging processes app/installation identifiers and, after notification permission, push tokens and delivery; OSMF provides map tiles, while the configured geocoder processes place/address text only after explicit search submit; and cloud hosting, database, and object-storage providers store and transmit event data and photos on our behalf. They process data under their own terms and privacy policies. This functional processing is not advertising tracking or a sale of data.
How data is stored and protected
Display names, preset avatars, device identifiers, an optional verified email address, event/gameplay content (including a host-confirmed destination coordinate), reports, and blocks are stored in a PostgreSQL database. Sign-in credentials are stored only as irreversible digests, and keyed hashes are used to compare email addresses and one-time codes securely. The destination-search cache is keyed only by a SHA-256 fingerprint of the query and retains at most three sanitized results for up to 24 hours; the raw query and provider Place ID are not persisted. Proof JPEGs that have been re-encoded with metadata removed are stored in S3-compatible object storage. For each participant and event, we keep only the latest voluntarily shared battle-map location (with its time, accuracy, and captured status), visible only to that event's members; a new snapshot overwrites the old one. Data between the app and the public backend is encrypted over HTTPS; internal database and object-storage traffic uses the hosting platform's private network. Photos are served via time-limited presigned URLs that stop working once they expire.
Retention
We keep data only as long as needed to operate the app, resolve disputes, prevent abuse, or meet legal obligations. Email codes expire after 10 minutes; challenge records older than 24 hours are purged when the email service next processes a request, and recovery requests do not write an unverified email address in plaintext to a challenge. You can remove a verified email in Settings at any time. Battle-map location snapshots are cleared when a friend event is closed. Successful account deletion removes your email and verification challenges, every installation credential, in-event locations, push tokens, proof photos, participation records, votes, nudge content, block relationships, current points wallet/inventory, and item-use relationships.
Event facts and gameplay outcomes already shared with other members (such as events you created and challenge outcomes) may remain so their event records still work, but your display name, preset avatar, device identifier, sign-in credential digest, and consent record are removed from the retained random tombstone account. Used points-idempotency records may remain to prevent duplicate awards, but their account-owner field is removed; an internal idempotency key may still contain the random tombstone ID. Reports may be retained to handle abuse, disputes, or legal obligations, but the reporter-account link is removed. Subscription entitlement/monthly-grant records may remain under the random tombstone ID for accounting, refunds, fraud prevention, and reconciliation with App Store, Google Play, and RevenueCat status; stores and service providers may also retain transaction records under their policies or legal obligations.
Deletion requests
You can delete your account directly inside the app under Settings, or contact us through the support page. The server reports account deletion as successful only after object storage confirms deletion of your proof photos; if storage temporarily fails, your account remains undeleted and you can retry. Subscription transaction records retained by a store or service provider under law or its policies must be handled by that platform.
Children
This app is not directed at children under 13, and we do not knowingly collect personal data from them.
Changes to this policy
We may update this policy over time. When we make material changes, we will update the effective date at the top of this page.