妝櫃研究室 BEAUTY SHELF LAB
PRIVACY POLICY

妝櫃(BeautyShelf)隱私政策

一句話:沒有你按下去,資料不出這支手機。妝櫃沒有帳號、沒有雲端同步、沒有分析追蹤。會自動發生的只有下載;會送出去的,每一項都在你按下按鈕的那一刻才發生,而且這一頁把送出去的欄位一個一個列出來。

最後更新 2026.09.13

WHERE YOUR DATA LIVES

資料存在哪

你的產品清單、開封日與期限、購買日與價格、心得、使用流程、膚況紀錄、用藥、成分關注清單、產品照片,以及你收藏的別人的櫃子,全部只存在 App 在你手機上的專屬空間(本機資料庫與檔案目錄)。開發者看不到任何一筆,也沒有機制看得到。刪掉 App,這些資料就沒了。

AUTOMATIC · DOWNLOAD ONLY

自動發生的只有下載

產品目錄 打開產品挑選畫面時,App 會抓一次妝櫃研究室的公開產品目錄(beautyshelflab.com 上一個固定的 JSON 檔)。請求不帶任何參數、識別碼或你櫃子裡的東西;主機只看得到「有一支手機抓了這個檔」,以及任何連線都會帶的 IP 位址。抓不到就靜靜用上一次的那份,或 App 內建的那份。
App 更新 正式版啟動時會向 Expo 的更新服務(EAS Update,u.expo.dev)檢查有沒有新版本。這個請求帶的是平台、App 版本與一組 App 自己產生的隨機識別碼,用來投遞更新;不含你的身分,也不含妝櫃裡任何內容。Expo 是第三方服務,其隱私政策在 expo.dev/privacy。Android 測試版的安裝檔也由 expo.dev 提供。
ONLY WHEN YOU TAP

你按一次才送一次

成分表帶去網站解讀 你點「在網站解讀成分」時,App 把印在包裝上的成分文字放進網址的井號片段(#)後面開瀏覽器。瀏覽器不會把井號後面的內容送給伺服器,是網頁上的程式自己讀走的。不帶品名、品牌、開封日、期限、價格、批號。
傳給研究室(問一罐與櫃子裡的產品) 「問一罐」掃完一罐、目錄裡沒有它的時候,答案頁會問你要不要把成分表傳給妝櫃研究室;櫃子裡已經登記的產品,也可以在產品頁或「設定 → 傳成分表給研究室」逐件勾選傳送。只在你按「傳給研究室」時發生,送出的只有四欄:品牌、品名、類別、成分表,全是印在包裝上的字。不送膚質、成分關注清單、命中結果、裝置識別;伺服器那邊也只存這四欄。傳來的東西進的是人工核對的候選清單,核對過才會出現在網站的產品頁,不會標示是誰傳的。問過但沒傳的那些,只留在你的手機裡。
公開櫃子:送什麼 只在你按「更新公開櫃子」時發生。送出的是你在 App「公開預覽」裡看得到的東西,一個欄位不多:若你把個人資料設為公開,暱稱、年齡級距、膚質、困擾(設為私密時這四項都不送,訪客看到的是「沒有留暱稱的櫃子」);若你把自介設為公開,另加自介;每一件設為公開的產品的照片、品牌、品名、類別、色號、容量、成分、心得(含「用了不舒服」這類固定標籤)、已停用標記與原因、可轉賣標記;以及你設為公開的使用流程。
公開櫃子:不送什麼 期限、開封日、購買日、價格、通路、批號、備品數、快用完、備註、轉賣價、用藥、膚況紀錄、成分關注清單,以及所有私密產品和它們的心得。送出去的資料格式裡根本沒有這些欄位,伺服器那邊也只存白名單上的欄位,兩邊各擋一次。
沒有帳號,櫃子怎麼認主 第一次發布時,伺服器發給你的手機一組公開碼與密鑰。公開碼是網址的一部分;密鑰只存在你的手機(與你自己匯出的備份檔)裡,伺服器只存它的雜湊。沒有姓名、信箱、電話或裝置識別碼,我們沒有任何東西可以把一個櫃子對回一個人。密鑰弄丟了,就沒有人能改或撤回那個櫃子,包括我們。
存在哪、誰看得到 櫃子的資料與照片存在 Cloudflare 的機房(KV 與 R2),由妝櫃研究室管理。網址長這樣:beautyshelflab.com/u/一串隨機碼/,碼不可枚舉、猜不到,而且這些頁面一律標示 noindex,不會被搜尋引擎收錄。知道網址的人可以看,就這樣。
出現在「逛櫃子」 「允許出現在探索」這個開關預設是開的,隨時可以在 App 裡關掉。開著的櫃子會列在 App 的「逛櫃子」清單裡,讓陌生人用膚質、年齡層找到你;而且上面的成分與心得可能會被我們整理進妝櫃研究室網站的產品頁,標示為使用者心得並附上你的暱稱。關掉的櫃子只有拿到連結的人看得到,成分與心得也不會被整理進產品頁。無論開關,照片一律不會被拿去用。
下架 按「下架」,伺服器上的櫃子、照片與身分整組刪除,連結一分鐘內失效。沒有軟刪除、沒有備份。你手機裡的資料與逐件的公開設定不受影響。
逛別人的櫃子 打開一個公開碼時,App 下載那份櫃子與照片。送出去的只有「你在看哪一個櫃子」,沒有你自己的任何東西。收藏存在你的手機裡。
分享一件產品 「分享這一件」走手機系統的分享面板,產生的圖片要傳去哪由你決定,App 不會上傳。
PERMISSIONS

權限

相機拍下產品包裝或批號當作產品照片。照片只存在手機;只有你設為公開的產品的照片,會在你按「更新公開櫃子」時上傳。
照片圖庫挑選既有的照片當產品照片。只讀取你選的那一張。
通知到期提醒是手機本機的通知,沒有伺服器介入,App 不申請推播權杖。
BACKUPS

備份

換手機時你可以自己匯出一個備份檔,只在你按下去時產生。檔案裡是妝櫃的全部資料:產品、心得、流程、膚況紀錄、用藥、關注清單、照片,以及公開櫃子的公開碼與密鑰。這個檔案沒有加密,請把它當成一份完整的個人資料保管;要存去哪(iCloud Drive、AirDrop 或其他地方)由你決定,App 不會上傳它。匯入時只讀你自己選的那個檔案。

WHAT THE APP DOES NOT DO

沒有的東西

沒有帳號沒有註冊、沒有登入、沒有雲端同步。
沒有追蹤沒有分析、統計或使用行為追蹤;沒有廣告,沒有廣告識別碼。
沒有其他第三方除了上面提到的 Expo 更新服務與 Cloudflare 主機之外,沒有第三方 SDK。你的資料不會賣給、也不會分享給任何人。
CHILDREN

兒童

妝櫃不收集個人資料,因此也不會收集兒童的資料。公開櫃子是你主動發布、任何知道網址的人都看得到的內容;未成年的話,發布前請先跟家長或監護人商量。

CHANGES · CONTACT

政策變更與聯絡

有變更會更新這一頁最上面的日期。若哪天加入了會自動傳送資料的功能,會在 App 內明白告知並徵求同意,不會只改這一頁。網站本身量測了什麼、公開櫃子的內容怎麼被使用,寫在揭露與免責。

有任何疑問,或看到不該出現在公開櫃子上的內容,請寄信到 [email protected],附上網址會處理得比較快。

ENGLISH

BeautyShelf — Privacy Policy

Last updated: 13 September 2026

Nothing leaves your phone unless you tap to send it. BeautyShelf has no account, no cloud sync and no analytics. Your products, opening dates, expiry dates, prices, reviews, routines, skin notes, medications, ingredient watchlist, photos and saved shelves are stored only in the app's own sandbox on your device. The developer cannot see any of it and has no mechanism to.

Automatic activity is download only. When you open the product picker the app fetches a public product catalogue from beautyshelflab.com; the request carries no parameters and no identifiers, so the host only sees that a phone fetched the file plus the IP address any connection carries. Release builds also check Expo's EAS Update service (u.expo.dev) for app updates; that request carries the platform, app version and a random app-generated identifier used to deliver updates, never your identity or any shelf content. Expo is a third party; see expo.dev/privacy.

Sent only when you tap. "Read ingredients on the website" opens your browser with the printed ingredient text in the URL fragment (after #), which browsers do not send to servers. "Update public shelf" uploads exactly what you see in the app's public preview: your nickname, age range, skin type and concerns only if you set your profile to public (a private profile sends none of them); your bio only if you set it to public; and for each product you marked public, its photo, brand, name, category, shade, volume, ingredients, reviews (including fixed tags such as "caused a reaction"), archived status and reason, and resale flag; plus routines you marked public. Expiry and opening dates, purchase dates, prices, stores, batch codes, spare counts, notes, medications, skin notes, your watchlist and every private product are never sent: the upload format has no fields for them, and the server stores only whitelisted fields.

There is no account. On first publish the server issues a random shelf code and a secret; the secret lives only on your phone (and in backups you export) and the server keeps only its hash. We hold nothing that can link a shelf to a person. Shelves and photos are stored on Cloudflare (KV and R2) under an unguessable URL at beautyshelflab.com/u/…/ marked noindex. The "discoverable" switch is on by default and can be turned off in the app; discoverable shelves are listed in the app's explore view, and their ingredients and reviews may be curated into the website's product pages credited to your nickname. Photos are never reused. Tapping "Unpublish" deletes the shelf, its photos and its identity within a minute, with no backups. Viewing someone else's shelf only tells the server which shelf you opened.

Permissions. Camera and Photos are used to attach a product photo; photos stay on the device unless the product is public and you tap to publish. Reminders are local notifications; no push token is requested.

Backups are created only when you choose to export one. The file contains all your data including photos and your shelf secret, and is not encrypted; where you store it is your choice, and the app never uploads it.

No analytics, no advertising or advertising identifiers, no third-party SDKs other than Expo's update service, and your data is never sold or shared. BeautyShelf collects no personal data and therefore none from children. A public shelf is content you choose to publish and anyone with the link can see it; if you are a minor, please talk to a parent or guardian before publishing. Changes will be reflected in the date above, and any future feature that transmits data automatically will be disclosed in the app and require your consent. Questions: [email protected].