隐私政策
本隐私政策适用于 “My Homepage”(以下简称“本服务”),一个托管于 https://324893.xyz/ 的自定义浏览器起始页。我们只收集为提供书签云同步所必需的最少信息,不作广告用途,也不出售你的数据。
1. 我们收集哪些数据、为什么收集
| 数据类别 | 具体内容 | 用途 |
|---|---|---|
| 账户数据 | 邮箱地址;密码(仅保存为加盐的 PBKDF2-SHA256 哈希,服务端无法还原明文) | 创建账户、登录验证 |
| 你保存的内容 | 书签页面配置(页面标题与书签的网址、名称、图标地址、备注)与收藏记录 | 在你登录的设备之间同步你的配置 |
| 会话数据 | 随机会话令牌、创建/过期时间、浏览器 User-Agent | 保持登录状态、会话安全(30 天过期) |
| 第三方登录数据 | 当你选择使用 Google 或 GitHub 登录时,由该平台返回的用户 ID、邮箱、昵称、头像地址 | 识别你的账户并与既有账户关联 |
| 安全日志 | 登录失败的次数与时间窗口(按邮箱聚合,15 分钟内最多 10 次) | 防止暴力破解与滥用 |
我们不收集:精确地理位置、通讯录、短信、相册、设备唯一标识、广告标识符,也不使用分析/追踪类 Cookie。
2. 使用 Google API 数据的方式(Limited Use 声明)
My Homepage 对通过 Google API 获得的信息的使用,将遵守 Google API Services User Data Policy,包括其 Limited Use(有限使用)要求。
My Homepage's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
具体而言:
- 我们仅在你主动点击「Google 登录」时请求
openid、email、profile三个范围,仅用于识别你的身份并在你的账户名下保存书签配置。 - 我们不保存 Google 的访问令牌或刷新令牌;授权完成后仅在当次请求中读取上述资料。
- Google 用户数据不会被用于广告、用户画像、信用评估、借贷,不会被出售或转让给第三方,不会被用于训练或改进任何人工智能/机器学习模型,不会被用于生成任何 AI 内容(包括但不限于 AI 生成的非自愿亲密影像,AI NCII)。
- 人类(开发者本人)仅在处理你主动提交的支持请求或法律合规要求时,才会访问与你账户直接相关的数据。
3. 数据存储与安全
- 账户与内容数据存储在 Cloudflare D1 数据库,应用逻辑运行于 Cloudflare Pages Functions;全部流量通过 HTTPS/TLS 传输。
- 密码使用 PBKDF2-SHA256(WebCrypto)加盐哈希存储;会话使用 32 字节随机令牌,仅以 SHA-256 哈希形式落库,并通过
HttpOnly+Secure+SameSite=Lax的 Cookie 传递,防止脚本读取。 - Cloudflare 的数据中心分布于全球,因此你的数据可能被传输并存储在你所在国家/地区以外的服务器(当前数据库区域为欧洲西部)。
4. 数据共享与第三方
我们不会出售或出租你的个人数据。仅在以下情形与第三方交互:
- Cloudflare(主机、数据库与网络防护,我们的数据处理服务商)。
- Google / GitHub:仅当你选择使用其账号登录时;分别适用其各自隐私政策。
- 图标/头像来源(DiceBear、Manifest.im、Brandfetch、Logo.dev、Vemetric favicon):仅在你加载页面时按需请求图片,不会向其发送你的账户资料。
- 法律要求:在收到有效的法律程序要求时,我们可能依法律义务提供所掌握的数据。
5. Cookie
hp_session:登录会话票据(HttpOnly,30 天)。hp_oauth_state:第三方登录流程中用于防止 CSRF 的临时票据,10 分钟自动过期。
除此之外,本服务不使用任何广告或分析 Cookie,也不使用本地存储之外的追踪技术(localStorage 仅用于缓存你自己的书签配置)。
6. 数据保留与删除
- 账户数据与书签配置:保留至你请求删除。
- 会话记录:30 天过期,或在你登出时立即删除。
- 登录失败计数:15 分钟后自动失效。
- 删除方式:通过下方联系方式提交删除请求,我们将在 30 天内删除你的账户及其全部关联数据(书签配置、收藏、会话)。你也可以随时使用站内的「导出配置」自行导出数据备份。
7. 你的权利
你可以请求:访问我们持有的关于你的数据、更正不准确的数据、导出数据(站内导出或向我们索取)、删除账户与数据、撤回对第三方登录的授权(在 Google/GitHub 的授权管理页面撤销即可)。我们将在合理期限内(通常 30 天内)响应。
8. 儿童
本服务不面向 13 岁以下儿童,我们不会有意收集儿童的个人信息。若你发现此类情况,请联系我们删除。
9. 政策变更
若本政策发生实质变更,我们会更新本页顶部的日期;继续使用本服务即表示你接受更新后的政策。
10. 联系方式
数据控制者:My Homepage 开发者 · 邮箱:jemchmi@gmail.com · 或通过 GitHub Issues 提交请求。
Privacy Policy — English
Effective 2026-10-02. My Homepage (https://324893.xyz/) collects only what is needed to sync your bookmarks: your email address; a salted PBKDF2-SHA256 hash of your password (never the plaintext); the bookmark configuration and favourites you save; a random session token (stored hashed server-side and delivered in an HttpOnly, Secure, SameSite=Lax cookie, expiring after 30 days); and, if you choose to sign in with Google or GitHub, the user ID, email, name and avatar URL returned by that provider. Login failures are counted per email for 15 minutes for brute-force protection.
Data is stored on Cloudflare (D1 database, Pages Functions) and transmitted over HTTPS. We show no ads, run no analytics or tracking cookies, create no user profiles, and never sell or rent your data. We do not store Google or GitHub access tokens — they are used only during the sign-in request itself.
Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising, profiling, credit/lending assessment, sold or transferred to third parties, used to train or improve AI/ML models, or used to generate AI content of any kind, including AI-generated non-consensual intimate imagery (NCII).
You can request access, correction, export or deletion of your data at any time by emailing jemchmi@gmail.com or opening a GitHub issue; we delete accounts and all associated data within 30 days. Sessions expire after 30 days. The service is not directed at children under 13. Material changes to this policy will be posted on this page with an updated date.