隱私權政策
最後更新:2026 年 10 月 2 日
CellarCube(以下稱「本服務」)是一套以 AI 協助管理酒窖的線上工具。我們知道你的收藏清單與市值資訊屬於高度私人的財產資訊,因此在設計上盡可能少收資料、少對外傳送。本政策說明我們收集什麼、為什麼收集、交給誰處理,以及你可以怎麼要求我們處理。
一、我們收集哪些資料
- 帳號資料:Email、顯示名稱。登入由 Google Firebase Authentication 處理,我們不會儲存你的密碼。
- 你建立的內容:酒款資料(名稱、年份、數量、購入價、參考市價、存放位置、標籤、備註)、酒窖名稱、你上傳或由 Excel 擷取的酒標照片、你自訂的統計卡片。
- 操作紀錄:出入庫紀錄(誰在什麼時候領出或放回幾瓶)、匯入紀錄。
- 使用量:AI 匯入筆數、問答次數、拍照辨識張數,以及實際的 token 用量,用於計算方案額度與成本。
- 技術紀錄:連線的 IP、瀏覽器類型與錯誤日誌,用於排除故障與防止濫用。
- 許願池:你提出的需求或回報的問題。為了重現問題,會一併記下你的 Email、目前方案、介面語言、當時停留的頁面與瀏覽器版本,並通知開發者。不想附上這些資訊的話,改用下方信箱聯絡我們即可。
我們不使用任何分析或廣告追蹤工具,沒有 Google Analytics、沒有廣告像素、沒有第三方 Cookie。
二、Cookie 與瀏覽器儲存
我們只使用維持服務運作所必需的項目:Firebase 的登入狀態、你選擇的語言、分頁大小等介面偏好。這些不會用於追蹤你在其他網站的行為。
三、AI 如何處理你的資料(重要)
本服務的匯入整理、酒窖問答、統計報表與拍照辨識功能,會把必要的內容傳送到平台所設定的 AI 模型供應商(可能是 OpenAI、Anthropic、Google 或你自行指定的服務)進行處理:
- 匯入時傳送的是試算表的欄位與資料列;
- 問答時傳送的是你的問題,以及模型查詢後得到的酒窖資料;
- 拍照辨識時傳送的是縮小後的酒標照片。
我們透過各供應商的商用 API 介面呼叫,依其條款,API 傳入的內容預設不會被用於訓練模型。若你對此有疑慮,可以選擇:(一) 使用「自備金鑰」方案,費用與資料關係直接建立在你與供應商之間;(二) 選擇買斷版並搭配地端模型(Ollama),資料完全不離開你的設備。
四、第三方服務
- Google Firebase Authentication —— 帳號登入與身分驗證。
- Google Cloud Platform(台灣彰化 asia-east1) —— 伺服器與資料庫所在位置。
- AI 模型供應商 —— 如前條所述。
- Lemon Squeezy —— 付款處理。Lemon Squeezy 為 Merchant of Record(記錄商),信用卡號等付款資訊由其直接收集與保管,我們看不到也不儲存。我們只會收到訂單編號、購買的方案、付款人 Email 與金額。
五、資料存放與保留
- 資料存放於台灣的伺服器;每日自動備份,備份保留 30 天後自動刪除。
- 訂閱到期後,你的資料仍會保留一段期間(預設於到期提醒中說明),逾期未續約我們會通知後刪除。
- 你可以隨時在「帳號」頁自行刪除帳號與全部資料,按下去立即從正式系統移除、無法復原;備份會隨 30 天輪替結束一併消失。你也可以改用下方信箱請我們代為處理。
- 刪除會移除你擁有的酒窖、酒款、照片、出入庫紀錄、統計卡片與用量紀錄。別人分享給你的酒窖不會被刪除,只會收回你的存取權。付款紀錄與你在許願池提過的內容會去識別化後保留(付款是為了帳務對帳,發票由 Lemon Squeezy 保存;許願池是因為那已經是產品待辦事項)。
六、分享功能
當你把酒窖分享給其他帳號時,對方會看到該酒窖內的酒款資料、照片與出入庫紀錄;若給予編輯權限,對方也能修改。對方看不到你其他未分享的酒窖、你的帳務資料或平台設定。你可以隨時收回分享。
七、你的權利
依據中華民國《個人資料保護法》及其他適用法規,你可以要求查閱、複製、補充或更正、停止處理或刪除你的個人資料。請以下列信箱聯絡我們,我們會在合理期間內回覆。
八、資料安全
連線全程使用 HTTPS;API 金鑰與憑證以受限權限存放於伺服器;備份上傳的服務帳號只有寫入權限、沒有刪除權限,以降低遭入侵時備份被一併破壞的風險。惟任何系統都無法保證絕對安全,請同時妥善保管你的登入憑證。
九、未成年人
本服務與酒類收藏管理有關,不適合未成年人使用,亦不針對未成年人提供服務或主動收集其個人資料。
十、政策變更
本政策如有重大變更,我們會於服務內或以 Email 通知。繼續使用本服務即視為同意更新後的內容。
十一、聯絡我們
任何隱私權相關問題,請來信 [email protected]。
Privacy Policy
Last updated: 2 October 2026
CellarCube is an AI-assisted wine cellar management service. We understand that your collection and its valuation are highly private financial information, so the product is designed to collect as little as possible and to send as little as possible to third parties. This policy explains what we collect, why, who processes it, and what you can ask us to do.
1. What we collect
- Account data: email address and display name. Sign-in is handled by Google Firebase Authentication — we never store your password.
- Content you create: wine records (name, vintage, quantity, cost, market price, location, tags, notes), cellar names, label photos you upload or that we extract from your spreadsheet, and custom report cards.
- Activity log: stock movements (who checked out or returned how many bottles, and when) and import history.
- Usage: rows imported, questions asked, photos recognised, and actual token consumption — used for plan allowances and cost tracking.
- Technical logs: IP address, browser type and error logs, used for troubleshooting and abuse prevention.
- Wishlist: feature requests and problem reports you send. So the issue can be reproduced we also record your email, current plan, interface language, the page you were on and your browser version, and notify the developer. If you would rather not include that, email us instead using the address below.
We use no analytics or advertising trackers. No Google Analytics, no ad pixels, no third-party cookies.
2. Cookies and browser storage
We only use what the service needs to work: your Firebase sign-in session, your language choice, and interface preferences such as page size. None of it tracks you across other websites.
3. How AI processes your data (important)
Import, cellar Q&A, reports and photo recognition send the necessary content to the AI model provider configured for the platform (which may be OpenAI, Anthropic, Google, or a provider you specify yourself):
- For imports: the columns and rows of your spreadsheet.
- For Q&A: your question and the cellar data the model retrieves to answer it.
- For photo recognition: a downscaled copy of the label photo.
We call these providers through their commercial APIs, under whose terms API content is not used to train models by default. If you prefer not to rely on that, you can (a) use the "own API key" plan, which puts the data relationship directly between you and the provider, or (b) buy the self-hosted edition and run a local model (Ollama), so data never leaves your own machine.
4. Third-party services
- Google Firebase Authentication — sign-in and identity.
- Google Cloud Platform (asia-east1, Taiwan) — where the server and database live.
- AI model providers — as described above.
- Lemon Squeezy — payments. Lemon Squeezy acts as Merchant of Record: card details are collected and held by them, never seen or stored by us. We receive only the order ID, the plan purchased, the payer's email and the amount.
5. Storage and retention
- Data is stored on servers in Taiwan, backed up daily, with backups deleted automatically after 30 days.
- After a subscription expires your data is retained for a grace period (stated in the expiry reminder). If it is not renewed we will notify you before deletion.
- You can delete your account and all data yourself at any time from the Account page. It is removed from the live system immediately and cannot be recovered; backups disappear as they rotate out within 30 days. You can also email us to have it done for you.
- Deletion removes the cellars, wines, photos, stock log, report cards and usage records you own. Cellars others shared with you are not deleted — you simply lose access. Purchase records and anything you sent to the wishlist are kept with identifying details removed (purchases for accounting — invoices are held by Lemon Squeezy; wishlist entries because they have become product to-dos).
6. Sharing
When you share a cellar with another account, that person can see the wines, photos and movement log in that cellar, and can edit them if you grant edit access. They cannot see your other cellars, your billing information or platform settings. You can revoke sharing at any time.
7. Your rights
Under Taiwan's Personal Data Protection Act and other applicable law, you may request access to, a copy of, correction of, restriction of processing of, or deletion of your personal data. Contact us at the address below and we will respond within a reasonable period.
8. Security
All traffic uses HTTPS. API keys and credentials are stored on the server with restricted permissions. The service account that uploads backups has write access but no delete permission, so a compromise of the server cannot destroy existing backups. No system is perfectly secure; please also keep your own credentials safe.
9. Minors
This service concerns alcohol collection management. It is not intended for minors, and we do not knowingly collect personal data from them.
10. Changes
If this policy changes materially we will notify you in the app or by email. Continued use constitutes acceptance of the updated policy.
11. Contact
For any privacy question, email [email protected].