隱私權說明
Privacy Notice
最後更新:2026-09-08
NYCU LIFE Super App 是 Android 與 iOS 校園服務 App。校車、地圖、活動與學校行事曆等公開資訊不需帳號即可瀏覽;只有個人課表等個人化功能需要透過系統管理的 App 內瀏覽器完成 NYCU OAuth 登入。登入頁面會顯示可供使用者核對的網址與 TLS 連線資訊;Tauri WebView 無法讀取或修改登入內容,也不會收集校務帳號密碼。
我們處理的資料
- 使用者選擇登入時,由 NYCU OAuth 提供的穩定帳號識別,用於建立登入 Session 及隔離個人課表。
- NYCU OAuth 可能提供的顯示名稱,用於首頁問候。App 會先核對名稱資料所屬帳號;名稱服務無法使用、資料無效或帳號不一致時不保存名稱,也不影響登入。Super App 不保存 NYCU 上游 access token。
- NYCU OAuth 提供且通過格式與學校網域檢查的電子郵件,用於已啟用的校園活動報名服務建立參與者身分,以及帳號支援。未取得有效信箱時不會自行推測或補造。
- 帳號資料更新時間與登入 Session 的建立、到期、撤銷及輪替資料,用於登入管理與支援。資料更新時間不代表最近登入或最近使用時間,有效 Session 數量也不代表在線人數或裝置數。
- 帳號曾成功取得 App 登入憑證的標記與首次留存紀錄時間,用於不重複使用者數量統計。此標記隨帳號資料保存,登出或 Session 過期不會移除;管理中心登入不計入。
- 使用者儲存的課表與課表 revision,用於跨裝置同步及避免靜默覆寫。
- 短效 access token 與可輪替 refresh token。access token 只保存在記憶體;refresh token 只保存在 iOS Keychain 或 Android Keystore 保護的加密儲存空間。伺服器只保存 refresh token 的雜湊。
- 使用者授予使用期間定位權限後取得的前景位置。位置只在 App 位於前景時於裝置上處理,用來顯示目前座標、尋找附近校車站點,以及建立外部導航目的地;Super App BFF 不接收或保存裝置位置。拒絕權限後仍可手動選擇路線、站點或地圖座標。
- 維運所需的安全與錯誤紀錄。不得在紀錄中寫入 OAuth code、access token、refresh token 或精確裝置位置。
- 具備使用者查閱權限的管理員可在管理中心搜尋及查看帳號、顯示名稱、完整學校信箱、資料更新時間與有效 Session 數量。查閱紀錄保存管理員帳號、時間、查閱類型與所查閱的帳號識別,不複製姓名、信箱、搜尋文字或登入憑證。
外部資料與 App
App 會讀取 NYCU LIFE 的課表、校車與活動服務,以及公開的學校 Google Calendar 資料。校園底圖來自國土測繪中心。只有在使用者明確選擇路線導航時,App 才會將目的地交給 Apple Maps、Google Maps 或其 HTTPS 地圖頁面;後續處理由該服務自己的條款與隱私權政策規範。
校園活動參與功能啟用後,使用者操作報名等個人活動功能時,Super App 會將學校帳號、顯示名稱(若有)與有效學校信箱提供給 NYCU LIFE 活動服務,用於參與者身分與報名流程。
不進行的處理
MVP 不包含第三方分析工具、廣告、跨 App 追蹤、廣告識別碼、推播通知或背景定位,也不販售個人資料。
保存與控制
Session 最長可延續 30 天,refresh token 每次使用都會輪替。登出會撤銷該 token family 並清除裝置安全儲存。顯示名稱會在下次成功登入時更新,並與個人課表一樣保留至帳號資料依支援流程刪除;個人課表也可由使用者覆寫或清空。上游公開活動、校車與行事曆快取不作為使用者個人檔案。
學校信箱與帳號資料會在下次成功取得學校身分資料時更新,並保留至帳號資料依支援流程刪除。登出不會刪除帳號資料。管理員查閱紀錄供安全稽核使用,由維運人員依保存需求定期清理,並在帳號資料刪除請求中一併檢視其保存必要性。
支援與請求
帳號、Session 撤銷、課表資料或隱私權問題,請使用 https://app.nycu.one/support 公布的正式聯絡方式。
Last updated: 2026-09-08
NYCU LIFE Super App is a campus-services app for Android and iOS. Public bus, map, event, and school-calendar information can be viewed without an account. NYCU OAuth is required only for personal features such as the user's timetable, and sign-in takes place in a system-managed in-app browser that displays the verifiable URL and TLS connection information. The Tauri WebView cannot inspect or modify the sign-in content and never collects the user's NYCU password.
Data we process
- If the user signs in, the stable account identifier returned by NYCU OAuth, used to establish a session and isolate personal timetables.
- The display name NYCU OAuth may provide, used for the home-screen greeting. The app first verifies that the name response belongs to the same account. An unavailable name service, invalid response, or account mismatch prevents the name from being stored but does not prevent sign-in. The Super App does not retain the upstream NYCU access token.
- The email supplied by NYCU OAuth that passes format and university-domain checks, used to establish a participant identity for enabled campus event registration and for account support. Missing or invalid email is never guessed or fabricated.
- Profile update timestamps and session creation, expiry, revocation, and rotation records, used for sign-in management and support. A profile update timestamp is not a last sign-in or last-used timestamp, and valid session counts do not measure online users or devices.
- A marker that an account successfully received app sign-in credentials, with its first retained evidence time, used to count distinct app users. It remains with the account profile after sign-out or session expiry. Administration-only sign-ins are excluded.
- Timetables saved by the user and their revisions, used for cross-device access and conflict-safe updates.
- Short-lived access tokens and rotating refresh tokens. Access tokens remain in memory. Refresh tokens are stored only in iOS Keychain or Android Keystore-protected encrypted storage; the server stores only refresh-token hashes.
- Foreground location after the user grants while-in-use permission. It is processed on-device only while the app is in the foreground to show the current coordinates, find nearby shuttle stops, and prepare an external navigation destination. The Super App BFF neither receives nor stores device location. Route, stop, and map-coordinate selection remain available after permission is denied.
- Security and error records needed to operate the service. OAuth codes, access tokens, refresh tokens, and precise device location must not be logged.
- Administrators explicitly granted user-read permission can search and view accounts, display names, full school email addresses, profile update timestamps, and valid session counts in the administration website. Read audits record the administrator, time, type of read, and account identifiers viewed; they do not copy names, emails, search text, or sign-in credentials.
External data and apps
The app reads NYCU LIFE timetable, bus, and events services and the school's public Google Calendar data. Campus map tiles come from Taiwan's National Land Surveying and Mapping Center. Only after an explicit navigation action does the app hand a destination to Apple Maps, Google Maps, or their HTTPS map page; that service's own terms and privacy policy then apply.
When campus event participation is enabled and the user accesses personal event functions such as registration, the Super App supplies the university account, display name when available, and valid school email to the NYCU LIFE events service for participant identity and registration workflows.
Processing we do not perform
The MVP has no third-party analytics, advertising, cross-app tracking, advertising identifier, push notifications, or background location, and does not sell personal data.
Retention and controls
A session can last up to 30 days and its refresh token rotates on every use. Signing out revokes the token family and clears secure device storage. A display name is refreshed on the next successful sign-in and, like a personal timetable, remains until the account data is deleted through support; the user may also replace or clear a timetable. Cached public events, bus, and calendar data are not maintained as a personal user profile.
School email and account data are updated when university identity data is next successfully retrieved and remain until account data is deleted through support. Signing out does not delete the profile. Administrator read audits support security reviews; operators periodically remove them according to retention needs and review whether continued retention is necessary when processing an account-data deletion request.
Support and requests
For account, session-revocation, timetable-data, or privacy requests, use the official contact published at https://app.nycu.one/support.