隐私说明
本说明适用于 PalmRD 当前账号测试服务及这些说明页。运营者为林东扬,隐私联系邮箱为 privacy@palmrd.com。现阶段不提供公开软件下载或付费套餐;未来版本的数据处理发生变化时,我们会更新说明并在适用情况下征求你的同意。
1. 处理哪些信息、用于什么
- 账号:邮箱、验证码请求、账号标识和认证信息,用于注册、登录、找回密码及删除验证。密码在认证时由服务处理;数据库保存带盐密码摘要和验证参数,不保存明文密码。验证码邮件由阿里云邮件服务发送。
- 会话和授权:令牌摘要、到期和撤销时间、电脑及控制设备名称、平台、随机标识、公钥绑定、邀请及授权关系,用于设备发现、安全连接和撤销权限。部分标识能关联账号,不属于完全匿名信息。
- 服务运行:额度、用量及连接状态,用于服务管理;这些字段不代表充值已开放。必要的运行和安全日志可能包含连接地址、时间及状态。
- 客服:你主动发送的邮箱、问题描述和附件,用于答复及处理请求。不要向客服发送密码、验证码或远控密钥;请尽量移除附件中无关的个人信息。
2. 远程内容和终端权限
远程控制会处理你选择共享的画面、声音、输入、窗口信息和主动传输的文件。请只连接你有权控制的电脑,并取得受影响人员的同意。录屏、辅助功能、摄像头扫码等权限由对应终端提示并管理;拒绝权限会影响相应功能。
连接路径随版本和配置而不同。使用账号网关转发时,网关能够处理转发的内容,不能将其理解为服务器无法读取内容的端到端加密。已核对的账号网关不主动将转发正文、明文密码或令牌写入数据库或请求日志,但这不等于所有终端和网络服务均不产生记录。
终端可能保存电脑配置、偏好、输入文本历史和登录材料;例如 iOS 使用钥匙串保存刷新令牌,卸载 App 不保证删除钥匙串。完成传输的文件保存在接收电脑中,清除云账号不会删除这些文件或目标应用已经接收的文本。
3. 故障诊断与网站访问
基本故障诊断在后台自动发送固定故障类型和版本;该接口不上传原始日志、堆栈、账号、设备标识、屏幕或输入内容。部分客户端会在本机暂存最多10条未发送记录,超过24小时的记录在下一次处理队列时丢弃,应用未运行时不保证继续投递。连接性能诊断默认关闭,可由你开启,服务按天汇总限定指标,不保存逐条诊断报告。手动导出诊断用于另行排查,请在主动分享前检查内容。
这些说明页不设置分析或广告 Cookie,不加载第三方统计、字体或跟踪脚本。提供网页和保护服务的基础设施仍会处理请求所需的网络地址等信息。邮件客户端和你访问的外部网站遵循各自的规则。
4. 服务商和数据地点
当前账号测试服务器及私有备份位于腾讯云南京;事务邮件使用阿里云华东1(杭州)邮件推送,客服邮箱使用阿里云中国站邮箱。邮件服务需要处理收件地址及邮件内容,邮件还会保存在收件人的服务商或终端中。客服邮箱及供应商内部日志的完整存储地域和保存期尚未全部确认,因此不能保证所有副本都只保存在同一地区。我们不会据此将服务商的数据处理排除在说明之外。
5. 保存期限和删除边界
账号存在期间保存提供账号和授权功能所需的信息。删除账号后,在线事务清除账号及其会话、控制设备、邀请、授权、额度和用量等关联记录,并解除电脑归属。
- 小时清理任务处理刷新期限已过的会话、超过15分钟窗口的登录失败记录、创建至少24小时的邮箱挑战,以及当前和前6个UTC日桶之外的诊断聚合。验证码失效不代表所有相关记录立即消失。
- 受管常规快照采用7天滚动保留,私有云备份按生命周期清理;部署回滚副本满足期限及有效替代备份条件后清理。清理依赖任务成功,并非所有副本恰在第7天物理擦除。
- 为防止旧备份恢复已删除账号或失效授权,仍保留最小删除/撤销记录、主机身份及撤销回执。这些记录不含邮箱、密码或令牌,但可能关联历史标识。测试阶段尚未完成全部到期清理,不能承诺统一的最终清除日期。
- 专用服务日志设有7天或容量限制,轮转不覆盖全部历史共享日志、客服邮件、收件人副本及供应商内部记录;这些记录也不随在线删号立即消失。
对于因法律要求或技术原因暂不能删除的信息,我们仅为必要存储和安全保护保留处理;你可以联系隐私邮箱了解具体记录或提出删除请求。恢复旧备份存在重新引入历史数据的风险;当前恢复工具禁止将未经核验的候选直接恢复上线。我们不承诺恢复风险已经全部消除。
6. 你的选择与权利
你可以管理终端权限、关闭可选性能诊断、撤销设备授权,或通过应用内和外部入口删除账号。访问、更正、复制个人信息、撤回同意或其他隐私请求,请联系 privacy@palmrd.com。核实必要身份后我们会处理请求;不会要求你把密码或验证码交给客服。撤回权限或必要信息可能影响对应功能,不影响此前依法进行的处理。
当前测试服务仅面向年满18周岁的使用者。若发现未成年人信息或未经授权的信息,请联系隐私邮箱。政策有重要变更时,我们会在页面或服务中提示;新增处理需要同意时另行征求。
English
Privacy notice for the current test service
Effective 22 September 2026. Operator: 林东扬. Contact: privacy@palmrd.com. This notice covers PalmRD's current account test service and these pages. Public downloads and paid plans are not offered here. We will update the notice for changed processing and seek consent where applicable.
Information and purposes
We process email addresses, verification requests, account identifiers and authentication information to register, sign in, reset passwords and verify deletion. Passwords are processed during authentication; the database stores salted hashes and verification parameters, not plaintext passwords. Alibaba Cloud sends verification messages. Token digests, expiry/revocation times, device names, platforms, random identifiers, public-key bindings, invitations and authorizations support discovery and access control. Identifiers may link to an account. Quota, usage and connection records support operation, not an available paid plan. Necessary operational logs may include network addresses, times and status. Support correspondence and attachments are used to handle requests; do not send passwords, codes or remote-access secrets.
Remote content and local storage
Remote control processes selected screens, audio, input, window information and files. Only control authorized computers and obtain affected people's consent. OS-managed screen recording, accessibility and camera permissions affect their respective features. Routes vary by version and configuration. The account gateway can process forwarded content; this route is not end-to-end encryption that hides content from the server. The reviewed gateway does not intentionally store forwarded bodies or plaintext credentials in its database/request logs; that is not a claim that no endpoint or network provider retains anything. Devices may retain preferences, connection settings, text history and login material; uninstalling iOS may leave Keychain entries. Cloud deletion does not erase received files or text in other applications.
Diagnostics and website
Basic background fault reports contain fixed fault categories and versions, not raw logs, stacks, account/device identifiers, screens or input. Some clients queue at most 10 unsent items and discard items older than 24 hours when the queue is next processed; delivery is not guaranteed while the app is closed. Optional performance diagnostics are off by default and aggregate limited metrics by day. Review manually exported diagnostics before sharing them. These pages set no analytics/advertising cookies and load no third-party tracking scripts, fonts or analytics. Infrastructure still processes network information required to serve requests. External websites and email providers have their own practices.
Providers and locations
The current account server and private backups are in Tencent Cloud Nanjing. Transactional mail uses Alibaba Cloud East China 1 (Hangzhou); support mail uses Alibaba Mail's China site. Mail providers process recipient addresses and message contents; recipients also retain messages. Full locations and retention for support mail and provider internal logs are not all confirmed, so we cannot promise every copy stays in one region.
Retention and deletion
While your account exists, we retain information needed for account and authorization functions. Online deletion removes the account, sessions, control devices, invitations, authorizations, quotas and usage, and releases host ownership. Hourly cleanup handles expired refresh sessions, login failures outside a 15-minute window, email challenges at least 24 hours old, and diagnostic buckets outside the current and previous six UTC days. Expiry does not mean immediate deletion everywhere.
Managed snapshots use a seven-day rolling window; cloud backups use lifecycle expiration. Deployment rollback copies require both age and a valid replacement backup before cleanup. Successful jobs are required, so not every copy is physically erased on day seven. Minimal deletion/revocation records, host identities and revocation receipts remain to prevent unsafe restoration. They exclude email addresses, passwords and tokens but can link to historical identifiers. Complete expiry is not yet implemented during testing, and no uniform final deletion date is promised. Dedicated service logs have seven-day or size limits; historical shared logs, correspondence, recipients' copies and provider logs are not all covered or immediately removed on deletion. Where law or technical limitations prevent deletion, retained processing is limited to necessary storage and security. Contact us for specific records or deletion requests. Recovery safeguards exist, but we do not claim restoration risk is fully eliminated.
Your choices
Manage device permissions, disable optional performance reports, revoke access or delete your account. Contact privacy@palmrd.com for access, correction, copies, consent withdrawal or other privacy requests. We verify necessary identity without asking you to share passwords or codes with support. Withdrawing necessary permissions/data may affect the related feature without invalidating earlier lawful processing. This test service is for adults aged 18 or older. Contact us about minors' or unauthorized information. Important changes will be highlighted in the pages or service, with separate consent when required.