FAMILY LEARNING COMPANION

把成长留在
值得信任的地方

影伴面向家庭和未成年学习者,记录每天的小小进步,也认真说明每一份数据如何被使用。

01 / PRINCIPLE数据最小化只收集完成家庭学习所需的信息。
02 / BY DESIGN本地优先朗读文本在设备上朗读,不上传录音。
03 / FAMILY家长确认学习者档案由家长或监护人管理。

影伴隐私说明

产品:影伴 Shadow Mate · 当前版本:privacy-v1 · 生效日期:2026 年 8 月 12 日

影伴面向家庭和未成年学习者,默认遵循数据最小化原则。本说明描述当前 Dogfooding 和小规模内测版本的技术行为。

我们收集和保存什么

  • 家长用于登录的邮箱,由 Supabase Auth 处理。
  • 家庭空间名称。
  • 学习者显示名称和年级。建议使用昵称,不填写真实姓名。
  • 打卡、积分、书架和阅读日志等学习状态。

当前版本不要求儿童提供邮箱、手机号、生日、学校、地址、精确位置或照片,也不包含广告。

分析服务和朗读功能

应用通过 Vercel Web Analytics 记录匿名、聚合的页面访问数据;当前没有自定义事件,也不把学习状态、邮箱或儿童显示名称作为 Analytics 自定义字段发送。页面访问数据可能包含时间、页面 URL、来源、设备、浏览器、操作系统和粗略地理位置。详情见 Vercel Web Analytics Privacy and Compliance

当前版本的本地 Piper 朗读不把文本发送到影伴服务器。影伴不采集麦克风录音。

家长同意和学习者档案

学习者不是独立登录账号。创建第一个学习者或添加学习者前,登录用户必须确认自己是家长或监护人,并阅读本隐私说明。系统会在 Supabase 数据库记录家庭 ID、认证用户 ID、同意类型 learner_data_processing、隐私说明版本 privacy-v1 和数据库生成的同意时间。客户端不能修改同意时间戳,也不能在没有同意记录的情况下通过公开 API 创建新的学习者档案。

数据存放和访问

  • 离线学习状态保存在当前设备的浏览器存储中。
  • 登录后,家庭和学习状态同步到项目配置的 Supabase 数据库。
  • 登录会话使用浏览器会话存储;关闭对应浏览器会话后需要重新登录。
  • 学习数据按家庭隔离,登录用户仍必须通过家庭成员关系和 RLS 才能读取或修改记录。

本机缓存通常会在关闭浏览器后继续保留,直到用户清除该网站的浏览器数据、使用隐私/无痕窗口、浏览器或系统自动清理,或更换访问域名。登录并同步后,云端家庭记录才是跨设备恢复来源。

删除、导出和保留

  • “清除本机数据”只删除当前设备的离线学习记录并退出登录,不删除云端记录。
  • 家庭所有者可以从账号面板导出完整家庭 JSON 数据,也可以使用“删除全部家庭数据”删除当前家庭的云端记录、清理本机数据并退出登录。
  • 共享 Supabase 项目中的家庭数据删除不会删除 Supabase Auth 身份;用户仍可使用同一邮箱重新登录。
  • 删除学习者或家庭时,同意记录随家庭或学习者所属家庭级联删除。

当前没有独立的“撤回同意但保留家庭”的自助流程。数据保留期限、删除、导出、更正和撤回请求会根据产品运营地区和适用法律持续更新。

安全问题

请不要在公开 Issue 中提交个人数据或安全漏洞。安全问题请通过仓库的私密漏洞报告功能提交。

Shadow Mate Privacy Policy

Product: Shadow Mate · Current version: privacy-v1 · Effective date: August 12, 2026

Shadow Mate is designed for families and learners who may be minors. We follow data minimization by default. This policy describes the technical behavior of the current Dogfooding and small-scale beta version.

What We Collect and Store

  • The parent's email address used to sign in, handled by Supabase Auth.
  • The family space name.
  • The learner's display name and grade. We recommend using a nickname instead of a real name.
  • Learning activity such as check-ins, points, bookshelf items, and reading logs.

The current version does not require a child to provide an email address, phone number, birthday, school, address, precise location, or photo. It does not contain advertising.

Analytics and Reading Aloud

The app uses Vercel Web Analytics for anonymous, aggregated page-visit data. It currently sends no custom events and does not send learning status, email addresses, or learner display names as custom Analytics fields. Page-visit data may include the time, page URL, referrer, device, browser, operating system, and approximate location. See Vercel Web Analytics Privacy and Compliance for details.

The local Piper text-to-speech feature does not send text to Shadow Mate servers in the current version. Shadow Mate does not record microphone audio.

Parental Consent and Learner Profiles

A learner is not an independent login account. Before creating or adding a learner, the signed-in user must confirm that they are the child's parent or guardian and read this policy. Supabase stores the household ID, authenticated user ID, consent type learner_data_processing, policy version privacy-v1, and a database-generated consent timestamp. The client cannot change the timestamp, and the public API cannot create a new learner profile without a consent record.

Where Data Is Stored and Who Can Access It

  • Offline learning state is stored in the browser storage on the current device.
  • After sign-in, household and learning state sync to the Supabase database configured for the project.
  • The sign-in session uses browser session storage; a new browser session may require signing in again.
  • Learning data is isolated by household. Signed-in users must still pass household membership checks and Row Level Security (RLS) to read or change records.

Local cache normally remains after the browser closes until the site's browser data is cleared, a private/incognito session is used, the browser or operating system cleans it up, or the site domain changes. After synchronization, the cloud household record is the source for cross-device recovery.

Deletion, Export, and Retention

  • “Clear local data” removes only offline learning records from the current device and signs the user out; it does not delete cloud records.
  • The household owner can export the full household data as JSON or use “Delete all household data” to remove the current household's cloud records, clear local data, and sign out.
  • Deleting household data in the shared Supabase project does not delete the Supabase Auth identity; the user can sign in again with the same email.
  • When a learner or household is deleted, its consent record is deleted through the household-level cascade.

There is currently no self-service flow to withdraw consent while keeping the household. Data retention periods and requests for deletion, export, correction, or withdrawal will be updated as the operating region and applicable laws require.

Security Issues

Do not submit personal data or security vulnerabilities in public issues. Please use the repository's private vulnerability reporting process for security issues.