一句话总结
本 App 默认把你的课程、成绩、任务等数据保存在你自己的设备上。首次启动时你需要阅读并点击同意本政策后才能使用。首次使用时,App 会随机生成一个安装 USER ID并登记到 Supabase,用于连接本设备与服务器;它不是硬件序列号,也不包含姓名或邮箱。你可以另行登录 Apple / 邮箱账号开启账号云同步与 AI 功能,或开启 iCloud 同步。
1. 我们收集哪些数据
默认情况下,你创建的课程信息、成绩与任务(含导入的评分规则原文)及个人设置保存在本地。
任何用户首次使用 App 时,App 会随机生成安装 UUID 和设备密钥。UUID 会上传作为服务器 USER ID;设备密钥原文仅保存在本机 Keychain,服务器只保存 SHA-256 哈希。它们不包含姓名、邮箱或硬件序列号。Supabase 可能保留请求所需的网络与安全日志;登录后,敏感连接信息改存到正式账号 USER ID 名下。
当你登录账号时,会额外涉及:
- 账号信息:Apple 登录收集 Apple 提供的账号标识符与(可选)姓名;邮箱注册/登录收集你的邮箱地址。昵称由你自行填写。
- 云同步快照:课程/成绩/任务数据(不含附件文件)保存到你自己的账号下。
- 头像(可选):保存在云端私有存储,只有你自己的登录会话能读取,仅在你的账号页显示,不对任何其他用户可见。
- AI 使用量:AI 需登录使用;按账号记录每日调用次数(仅次数与日期,不记录内容),用于每日用量上限。
- Canvas 令牌与课表链接(可选):保存后关联安装 USER ID 或正式账号 USER ID,见第 3 节。
- USYD 自动登录凭据与 MFA 密钥(可选):若你启用自动登录或绑定 MFA 验证器,Unikey、密码、备用 MFA 方式与 MFA/TOTP 密钥会保存到你的账号名下,见第 3 节;可在「设置 → 隐私 → 凭据云端备份」随时关闭。
不含任何广告或第三方分析 SDK,不做用户行为追踪。
2. 数据存储在哪里
- 本地:数据以文件形式保存在 App 沙盒内(设备本机)。
- 后台设备身份(自动):随机安装 USER ID 存在 Supabase;设备密钥原文在本机 Keychain,服务器只保存哈希。App 不读取或上传硬件序列号作为该 ID。
- 账号云同步(可选,需登录):经 Supabase(云数据库,本项目托管于日本东京区域)存到你自己的账号下;数据库启用行级安全(RLS),每个账号只能访问自己的数据。账号标识与会话令牌仅用于让你访问自己的数据,不用于广告或追踪。
- iCloud(可选):若开启,账号快照(包括已保存的 Canvas 令牌与 Timetable 链接)会存入你自己的 iCloud 账户。App 不对快照字段做额外的应用层加密,存储受 Apple 隐私政策 约束。
3. 网络请求
- 拉取课程 Outline:向
sydney.edu.au 请求公开的课程大纲页面。
- 导入课表:向你自己粘贴的课表 iCal 链接发起请求。
- 自动服务器身份:首次使用时与
fkrertabajfzndipnsiq.supabase.co 通信,登记随机安装 USER ID 及设备密钥哈希。账号云同步仍需登录并开启。
- Canvas 令牌与 Timetable 链接同步(可选,不要求登录正式账号):保存后,它们会通过 HTTPS 上传,并以明文字段保存到安装 USER ID 或正式账号 USER ID 名下的 Supabase 专用表;登录时还会进入账号同步快照。App 没有在写入数据库前做额外的应用层加密。专用表不提供客户端直接读取字段值的接口,但 Supabase 服务端、数据库管理员及受授权服务角色可因运维和同步需要访问这些字段。使用「删除令牌」会删除本机副本、同步快照副本和专用表字段。
- USYD 自动登录凭据云端备份(可选,需登录正式账号):若你启用 USYD 自动登录或绑定 MFA 验证器,且「设置 → 隐私 → 凭据云端备份」处于开启状态(默认开启;首次使用 App 前你已阅读并同意本政策),你的 Unikey、密码、备用 MFA 方式,以及 MFA/TOTP 密钥会通过 HTTPS 上传,并以明文字段保存到你的正式账号 USER ID 名下的 Supabase 凭据表,用于换设备恢复与自动登录。与上一条相同,App 没有在写入数据库前做额外的应用层加密。该表不提供跨账号读取的接口,每个账号只能取回自己的凭据;但 Supabase 服务端、数据库管理员及受授权服务角色在履行运维职责时可以访问这些明文字段。本机副本保存在 Keychain;备份开启且处于登录状态时,这些凭据会在每次账号同步时自动上传。随时可撤回:关闭「设置 → 隐私 → 凭据云端备份」会停止上传并删除服务器上的凭据副本(本机 Keychain 副本保留,自动登录不受影响;换设备时需重新输入)。你也可以不启用自动登录、不绑定验证器;已保存的凭据可在对应设置页删除,删除会同时清除本机副本与云端字段。
- AI 功能(需登录,主动使用才触发):本周简报、问问 AI、学习计划、假设一下、评分规则解读、学期复盘,以及 Canvas 成绩对齐(含服务端同步中的对齐),会把成绩、权重、截止日期、任务/评估项名称、评分规则原文等学业数据(不含姓名、邮箱或账号标识)经我们的 Edge Function 转发给模型服务处理:Groq(主通道,隐私政策)与 Google Gemini(备用,隐私政策)。首次使用任一 AI 功能前,App 会先展示数据说明并征得你的明确同意;同意后可在「设置 → AI 功能」随时撤回,撤回后不再发送任何数据,并会一并停用「服务端定时同步」。你的同意状态还会记录到你的账号名下,服务器在执行任何定时对齐前都会先校验它。AI 按账号计每日用量(仅次数)。
- 自动化失败诊断(自动触发,未登录时也会发生):USYD 自动化流程出错时,App 可能上传出错页面的 URL、标题、脱敏后的页面与对话框快照、运行步骤与日志尾段,用于定位问题。适用于全部四条流程:Canvas 令牌获取、MFA 认证器重绑、课表订阅链接、Sydney Student 历史成绩。端上脱敏的口径是默认丢弃全部渲染文本,只保留按钮、标签与错误提示等界面骨架;在此之上还会移除密码、令牌、MFA 二维码与输入框内容(输入框只保留字符长度),对保留下来的文本再打码邮箱、Unikey 与学号,并把 URL 削减到域名与路径以丢弃会话参数。成绩数值所在的表格单元格不在保留白名单内。即便如此,页面结构、课程名称或错误文本仍可能带有个人信息。你未登录时,该上传会使用匿名凭据发送。
- 反馈(一部分自动触发):你主动提交的「反馈 / 报告问题」会上传你填写的内容、App 版本与设备类别。此外,当你在「WAM → 范围」手动纳入或排除某门课时,App 会自动发送一条匿名记录(课程代码、学期、grade code、纳入或排除、算法版本、App 版本),用于改进 WAM 排除算法。这条记录不含课程分数、课程标题、姓名、邮箱、账号 ID 或任何凭据,固定使用匿名凭据发送,未登录时同样会发送。
App 内不含广告网络、不做用户行为追踪。除上述情况外,不上传任何数据——其中「自动服务器身份」「自动化失败诊断」「WAM 算法反馈」可能在你未登录时自动发生。
4. 系统权限
- 日历:仅写入你的作业截止日期到你自己的系统日历,并读回你的改动。
- 提醒事项:仅把截止日期同步为你自己的系统提醒(如启用)。
- 通知:仅本机本地通知,不经过任何服务器。
- 照片:仅在你主动选择头像或给任务添加附件时访问。
- 相机:仅在你主动绑定 MFA 验证器扫描二维码时使用,画面本身不保存、不上传,验证码全部在本机生成。识别出的 MFA 密钥保存在本机 Keychain;如果你已登录正式账号且「凭据云端备份」开启,它还会按第 3 节以明文同步到云端。
你可随时在「设置 → 隐私与安全性」中撤销上述权限。
5. 数据共享
我们不会出售、出租你的数据,也不会用于广告或追踪。涉及的第三方仅有:Supabase(云数据库/存储/边缘函数托管)、Apple(Sign in with Apple 与 iCloud),以及仅当你使用 AI 功能时的 Groq / Google Gemini(处理学业数据,不含姓名或账号身份)。
即使你不登录、也不使用 AI,仍有少量数据会离开设备:公开大纲抓取、首次使用时的设备身份登记,以及自动化失败诊断与 WAM 算法反馈(均见第 3 节)。
6. 数据删除
- 删除某条数据:在 App 内直接删除(登录状态下会同步到云端)。
- 删除 Canvas 令牌:在设置里点「删除令牌」,会清除本机副本、同步快照副本与对应服务端字段。
- 删除本机所有数据:「设置 → 账号 → 删除本机所有数据」清空本机并退出登录(云端保留,可找回)。
- 注销账号:「设置 → 账号 → 注销账号」会在服务器端删除你的账号及名下全部同步数据、令牌与头像(级联删除);也可邮件联系 andy.cai.work@gmail.com 代为删除。
7. 儿童隐私
本 App 面向高校学生,不针对 13 岁以下儿童,也不会有意收集儿童信息。
8. 政策变更
如本政策有重大变更,我们会在 App 或本页面更新生效日期。
9. 联系我们
有任何隐私相关问题,请联系:andy.cai.work@gmail.com
In one sentence
By default, your courses, grades, and tasks stay on your device. On first launch you must read and tap to agree to this policy before using the app. On first use, the app generates a random installation user ID and registers it with Supabase. It is not a hardware serial number and contains no name or email.
1. Data we collect
By default, the course info, grades & tasks (including imported grading-rule text), and preferences you create stay on your device.
For every user on first use, the app generates a random installation UUID and device secret. The UUID is uploaded as the server user ID. The plaintext secret stays in Keychain; the server stores only its SHA-256 hash. Neither contains a name, email, or hardware serial number.
When you sign in, the following applies:
- Account info: with Sign in with Apple we receive an account identifier and (optionally) your name; with email sign-up/sign-in we collect your email address. Your nickname is self-chosen.
- Cloud-sync snapshot: your data (excluding attachment files) is stored under your own account.
- Avatar (optional): kept in private cloud storage readable only by your own signed-in session, shown only on your own account page.
- AI usage: AI requires sign-in; we record a daily call count per account (count and date only, never content) for a daily limit.
- Canvas token & timetable link (optional): associated with the installation user ID or permanent account user ID; see below.
- USYD auto-login credentials & MFA secret (optional): if you enable auto-login or bind an MFA authenticator, your Unikey, password, fallback MFA method, and MFA/TOTP secret are stored under your account; see below. You can turn this off anytime in Settings → Privacy → Credential cloud backup.
There are no ads, no third-party analytics SDKs, and no behavioral tracking.
2. Where data is stored
- Locally: in the app's sandbox on your device.
- Automatic device identity: a random installation user ID is stored in Supabase. The plaintext device secret stays in Keychain and the server stores only its hash.
- Account cloud sync (optional): under your own account via Supabase (Tokyo, Japan region), with Row Level Security.
- iCloud (optional): if enabled, the account snapshot — including any saved Canvas token and Timetable link — is stored in your own iCloud account. The app applies no additional field-level encryption; storage is governed by Apple's Privacy Policy.
3. Network requests
- Unit outline fetch: public pages on
sydney.edu.au.
- Timetable import: the iCal link you paste yourself.
- Automatic server identity: on first use, the app contacts
fkrertabajfzndipnsiq.supabase.co to register a random installation user ID and device-secret hash. Account cloud sync still requires a signed-in account.
- Canvas token and Timetable-link sync (optional; no permanent-account sign-in required): saving uploads it over HTTPS and stores it as a plaintext field under the installation user ID or permanent account user ID in a restricted Supabase source table; signed-in users also include it in the account sync snapshot. The app applies no additional application-layer encryption before database storage. “Delete token” removes the local, snapshot, and source-table copies.
- USYD auto-login credential cloud backup (optional; requires a permanent account): if you enable USYD auto-login or bind an MFA authenticator, and "Settings → Privacy → Credential cloud backup" is on (on by default; you have read and agreed to this policy before first use of the app), your Unikey, password, fallback MFA method, and MFA/TOTP secret are uploaded over HTTPS and stored as plaintext fields in a Supabase credential table under your permanent account user ID, for device migration and auto-login. As with the item above, the app applies no additional application-layer encryption before database storage. The table exposes no cross-account read API — each account can retrieve only its own credentials — but Supabase server components, database administrators, and authorized service roles can access these plaintext fields for operations. The local copy stays in the Keychain; while the backup is on and you are signed in, these credentials are uploaded automatically on every account sync. Withdraw anytime: turning off "Settings → Privacy → Credential cloud backup" stops uploads and deletes the server-side copies (the local Keychain copy is kept and auto-login keeps working; a new device will require re-entry). You may also leave auto-login off and skip binding an authenticator; saved credentials can be deleted from their settings pages, clearing both the local copy and the server fields.
- AI features (signed-in, only when actively used): the weekly briefing, Q&A, study plan, what-if parsing, grading-rules explainer, semester review, and Canvas grade alignment send academic data only — grades, weights, due dates, task/assessment names, grading-rule text — never your name, email, or account identity — via our Edge Functions to Groq (primary, privacy policy) and Google Gemini (fallback, privacy policy). Before your first use of any AI feature, the app shows a data notice and asks for your explicit consent; you can withdraw it anytime in Settings → AI features, after which nothing is sent and server-side scheduled sync is disabled as well. Your consent state is also recorded under your account, and the server verifies it before any scheduled alignment runs. Usage is metered per account (count only).
- Automation failure diagnostics (automatic; can occur while signed out): when a USYD automation flow fails, the app may upload the failing page's URL and title, a redacted snapshot of the page and any dialog, the run steps, and a log tail. This covers all four flows: Canvas token capture, MFA authenticator rebinding, timetable subscription link, and Sydney Student historical results. On-device redaction drops all rendered text by default, keeping only interface scaffolding such as buttons, labels, and error banners; on top of that it strips passwords, tokens, MFA QR codes, and input values (inputs keep only a character count), masks email addresses, Unikeys, and student IDs in whatever text is kept, and reduces the URL to origin plus path to drop session parameters. Table cells holding marks are not on the keep list. Even so, page structure, course names, and error text may still be personal. While you are signed out, this upload is sent with anonymous credentials.
- Feedback (partly automatic): feedback you submit yourself uploads the text you wrote, the app version, and a device category. Separately, when you manually include or exclude a course under “WAM → Scope”, the app automatically sends an anonymous record (course code, semester, grade code, include/exclude, algorithm version, app version) used to improve the WAM exclusion rules. That record contains no course marks, course titles, name, email, account ID, or any credential; it always uses anonymous credentials and is sent while signed out as well.
No ad networks, no tracking. Beyond the cases above nothing is uploaded — and automatic server identity, automation failure diagnostics, and WAM algorithm feedback can occur while you are signed out.
4. System permissions
Calendar (write your due dates, read back your edits) · Reminders (mirror due dates if enabled) · Notifications (local only) · Photos (only when picking an avatar or attaching a file) · Camera (only when you scan an MFA setup QR code; the frames themselves are processed on-device and never stored or uploaded, and codes are generated entirely on-device — but the resulting MFA secret is stored in the local Keychain and, if you are signed in to a permanent account and Credential cloud backup is on, is also synced to the cloud in plaintext as described above). Revocable anytime in Settings → Privacy & Security.
5. Data sharing
We do not sell or rent your data, and never use it for ads or tracking. Third parties: Supabase (cloud database/storage/edge functions), Apple (Sign in with Apple, iCloud), and — only when you use AI features — Groq / Google Gemini (academic data only, no name or account identity).
Even if you never sign in and never use AI, a small amount of data still leaves your device: public outline fetches, the first-use device identity registration, and automation failure diagnostics plus WAM algorithm feedback (all described in §3).
6. Data deletion
- Delete items in-app (synced while signed in).
- “Delete token” removes the local, snapshot, and server-table copies.
- "Erase all local data" clears this device and signs out (cloud copy kept, recoverable).
- "Delete account" removes your account and all synced data, tokens, and avatar server-side (cascading); or email andy.cai.work@gmail.com.
7. Children's privacy
Intended for university students; not directed at children under 13.
8. Changes
Material changes update the effective date here and in the app.
9. Contact
andy.cai.work@gmail.com