GrowPocket 隱私權政策

適用範圍:GrowPocket(成長口袋)行動應用程式與相關服務
營運方:StellarLabs · 聯絡信箱:[email protected]
最後更新:2026-05-02

歡迎使用 GrowPocket(以下簡稱「本服務」)。本政策說明我們如何收集、 使用、保存及分享你的個人資料。請在使用本服務前仔細閱讀。

1. 我們是誰

GrowPocket 是由 StellarLabs 開發的家庭親子集點、儲蓄、承諾與任務管理 應用程式。本服務的資料儲存於 Firebase(Google Cloud,新加坡資料中心) 以及 Cloudflare Workers 的全球邊緣節點。

2. 我們收集哪些資料

本服務只收集為了讓 App 正常運作所必要的資料,範圍如下:

2.1 你主動提供的資料

  • 帳號資訊:使用者名稱(暱稱)、Email(用於虛擬登入網域)、密碼雜湊值。
  • 第三方登入資訊:當你選擇用 Google 或 Facebook 登入時,我們會接收你授權範圍內的公開個人資料(顯示名稱、Email、頭像 URL)。我們不會取得你的 Facebook 好友清單、貼文或私訊內容。
  • 家庭成員與小孩資料:你建立的小孩名稱、頭像、生日(可選)、暱稱。注意:小孩本身不擁有帳號,所有小孩資料都由家長帳號代為輸入與管理。
  • 應用程式內容資料:點數紀錄、儲蓄(現金與股票)紀錄、承諾與任務、家庭邀請碼。
  • 支付相關資料:當你訂閱 GrowPocket+ 時,我們會接收 Apple 或 Google 支付平台回傳的訂閱狀態(不包含信用卡或銀行資訊)。
  • 意見回饋:當你透過 App 內回饋功能聯繫我們時所提供的訊息。

2.2 自動收集的資料

  • 裝置資訊:作業系統版本、App 版本、語言偏好,用於除錯與相容性檢查。
  • 使用紀錄:登入時間、連續登入天數,用於成就 / 連續登入獎勵。
  • 當機紀錄:若 App 發生錯誤,我們會接收匿名的當機堆疊資訊。

3. 我們如何使用這些資料

  • 建立並維護你的帳號、提供登入功能。
  • 讓你管理小孩、家庭成員與相關資料。
  • 同步資料至你登入的所有裝置。
  • 在訂閱 GrowPocket+ 後解鎖進階功能。
  • 改善 App 品質、修正錯誤。
  • 回應你的客服或意見回饋訊息。

我們不會把你的資料用於廣告投放、行為分析、或販售給第三方。

4. 兒童資料保護

GrowPocket 是設計給家長使用的工具。雖然 App 中會出現 兒童的姓名與資料,但這些資料是由家長帳號代為輸入與管理的。 兒童本身不會建立獨立帳號、不會直接登入、也不會直接與我們互動。

家長對其兒童資料具有完整控制權,可以隨時新增、修改或刪除。我們不會收集 13 歲以下兒童的直接登入資訊,也不會主動向兒童索取資料。

5. 我們會跟誰分享資料

我們不販售你的個人資料。在以下幾種情況我們會與第三方服務商共用必要的 資料,僅限為了讓本服務運作:

  • Google Firebase(Authentication、Realtime Database、Storage):帳號驗證與資料儲存。
  • Cloudflare Workers:股票與匯率資料代理、支付驗證。
  • Apple App Store / Google Play / RevenueCat:訂閱狀態同步。
  • Google / Facebook(僅當你選擇使用第三方登入時):接收登入授權所需的最小公開資料。

除上述商業合作外,我們僅會在法律明確要求(例如法院命令) 時提供資料,並會盡力通知你。

6. 資料保存期間

  • 帳號資料:在你的帳號存在期間持續保留。
  • 當你刪除帳號時,我們會在 30 天內刪除所有與你帳號關聯的個人資料。
  • 長時間未登入照片自動清理:若帳號連續 12 個月未登入,系統將自動刪除你先前上傳的照片 (零用錢憑證、承諾完成照等)以節約儲存資源。 帳號、孩子資料、點數紀錄等本身不會被刪除 — 你下次登入時仍可正常使用,僅照片歸零。建議定期登入或先匯出資料 (設定 → 帳號 → 匯出我的資料)。
  • 匿名化的使用統計可能會無限期保留,但無法回溯到個人。

7. 你的權利

你對自己的個人資料具有以下權利,可隨時透過 App 內功能或來信行使:

  • 查閱權:查看我們儲存了你哪些資料。
  • 更正權:要求修正不正確的資料。
  • 刪除權:要求刪除你的帳號與所有相關資料。
  • 資料可攜權:要求以可攜的格式取得你的資料。
  • 撤回同意權:隨時撤回你給予的資料處理同意。

要行使任一權利,請寄信至 [email protected], 我們會在 30 天內回覆。

8. 資料安全

我們使用業界標準的加密(TLS 1.3 傳輸加密、Firebase Auth 雜湊密碼儲存) 保護你的資料。但任何網際網路傳輸都無法保證 100% 安全,我們會盡力 採取合理的安全措施。

9. 國際資料傳輸

本服務的資料伺服器位於新加坡(Firebase asia-southeast1)以及 Cloudflare 的全球邊緣節點。當你使用本服務時,資料可能會被傳輸至這些地區處理。

10. 政策變更

當本政策有重要變更時,我們會在 App 內以顯眼方式通知你,並更新本頁 頂端的「最後更新」日期。重大變更生效前我們會提供至少 14 天的緩衝期。

11. 聯絡我們

對於本政策或你的個人資料,有任何問題、意見或請求,請寄信至:
[email protected]


GrowPocket Privacy Policy

Scope: GrowPocket mobile application and related services
Operator: StellarLabs · Contact: [email protected]
Last updated: 2026-05-02

Welcome to GrowPocket (the "Service"). This Privacy Policy explains how we collect, use, store, and share your personal information. Please read it before using the Service.

1. Who we are

GrowPocket is a parent-oriented family chore-points, savings, promise and task management app developed by StellarLabs. Service data is stored on Firebase (Google Cloud, asia-southeast1 / Singapore) and edge-cached on Cloudflare Workers globally.

2. Information we collect

We collect only what is necessary for the Service to function:

2.1 Information you provide

  • Account info: username (display name), email (for the virtual login domain), hashed password.
  • Third-party sign-in: when you choose to sign in with Google or Facebook, we receive only the public profile information you authorize (display name, email, avatar URL). We never retrieve your Facebook friend list, posts, or messages.
  • Family and child data: child names, avatars, optional birthdays, nicknames. Children do not have their own accounts; this information is entered and managed by the parent on the child's behalf.
  • App content: points history, savings (cash and stock) records, promises and tasks, family invitation codes.
  • Subscription data: when you subscribe to GrowPocket+, we receive subscription status from Apple or Google's billing platforms. We do not receive credit card or banking information.
  • Feedback: messages you submit through the in-app feedback feature.

2.2 Information collected automatically

  • Device info: OS version, app version, language preference (for compatibility and debugging).
  • Usage records: sign-in timestamps, login streak counts (for achievement features).
  • Crash logs: anonymized stack traces when the app encounters errors.

3. How we use your information

  • To create and maintain your account and provide sign-in.
  • To let you manage children, family members, and related data.
  • To sync your data across devices you sign in from.
  • To unlock premium features after you subscribe to GrowPocket+.
  • To improve quality and fix bugs.
  • To respond to your support requests or feedback.

We do not use your data for ad targeting, behavioral profiling, or selling to third parties.

4. Children's data

GrowPocket is designed to be used by parents. Although children's names and information appear in the app, this information is entered and managed by the parent on the child's behalf. Children do not register their own accounts, do not log in directly, and do not interact with us directly.

Parents have full control over their children's data and can add, modify, or delete it at any time. We do not knowingly collect direct login credentials from children under 13, nor do we proactively solicit information from children.

5. Sharing with third parties

We do not sell your personal information. We share necessary data with the following service providers solely so that the Service can operate:

  • Google Firebase (Authentication, Realtime Database, Storage): authentication and data storage.
  • Cloudflare Workers: stock/exchange-rate proxy, payment receipt verification.
  • Apple App Store / Google Play / RevenueCat: subscription state sync.
  • Google / Facebook (only when you choose third-party sign-in): minimum public profile required for the auth grant.

Beyond these operational partners, we will only disclose data when legally compelled (e.g. court order), and we will attempt to notify you when permitted.

6. Data retention

  • Account data is retained while your account exists.
  • When you delete your account, we delete all personal data associated with it within 30 days.
  • Inactive-account photo cleanup: if your account has not been signed in to for 12 consecutive months, we automatically delete your previously uploaded photos (savings receipts, promise completion shots) to free storage. Your account, child records, point history, and other data are preserved — only the photo blobs are removed. You can sign back in and continue using the App normally. We recommend signing in periodically or exporting your data first via Settings → Account → Export My Data.
  • Anonymized usage statistics may be retained indefinitely; they cannot be traced back to an individual.

7. Your rights

You have the following rights over your personal data and may exercise them via in-app controls or by emailing us:

  • Access: see what data we hold about you.
  • Rectification: ask us to correct inaccurate data.
  • Erasure: ask us to delete your account and all associated data.
  • Portability: ask for your data in a portable format.
  • Withdraw consent: withdraw any consent you previously gave.

To exercise any right, email [email protected]; we will respond within 30 days.

8. Security

We use industry-standard encryption (TLS 1.3 in transit, Firebase Auth for password hashing at rest) to protect your data. No internet transmission can be guaranteed 100% secure, but we make commercially reasonable efforts.

9. International data transfers

Service data resides in Singapore (Firebase asia-southeast1) and on Cloudflare's global edge. When you use the Service, your data may be transferred to and processed in these regions.

10. Changes to this policy

When we make material changes, we will notify you prominently in the app and update the "Last updated" date at the top of this page. We provide at least a 14-day notice before material changes take effect.

11. Contact us

For any questions, comments, or requests regarding this policy or your data:
[email protected]