Privacy Policy
Weektrace is a calendar-based time-tracking app. It is designed local-first: everything works without an account, and your data stays on your device unless you explicitly sign in and enable cloud sync.
1. Data we collect and why
| Data | Purpose | Where it is stored |
|---|---|---|
| Events, categories, sub-tasks, app settings you create | Core app functionality | On your device (local database) |
| Account email + password (optional) | Sign-in / cloud sync | Supabase (auth provider); passwords are handled by Supabase Auth and never visible to us |
| Your events/categories/tasks, when signed in with an active Pro subscription | Cloud backup & multi-device sync | Supabase database, isolated per account (row-level security) |
| Google Calendar events (optional, see §2) | Display your Google Calendar alongside Weektrace events | On your device only — never uploaded to our servers |
| Purchase state (when subscriptions launch) | Unlock Pro features | Processed by Google Play and RevenueCat; we never see your payment card details |
| Diagnostic logs (see §6) | Troubleshooting | On your device only |
| Feedback you choose to send (optional, Settings → Report a problem) | Improving the app, fixing issues | Supabase database; sent anonymously when not signed in, with your account ID when signed in (so we can match reports to their context); the app version is attached |
We do not collect location, contacts, or any data unrelated to the features above. We do not sell or rent any user data. The current version of the app contains no ads, collects no advertising identifier, and includes no third-party analytics SDK.
Ads in a future version. We plan to show ads (Google AdMob) in the free tier of a future release. When that happens, the ad provider will collect an advertising identifier from your device; we will ask for your consent before any ad is shown where the law requires it, and this policy and our Play Data safety declaration will both be updated in the same release. The paid Pro tier will not show ads.
2. Google Calendar (read-only)
If you choose to connect Google Calendar:
- Weektrace requests the read-only scope
https://www.googleapis.com/auth/calendar.readonly. The app cannot create, edit, or delete anything in your Google Calendar. - Calendar events you select are mirrored only on your device for display and search. They are never transmitted to our servers, never included in cloud sync, and never shared with any third party.
- OAuth tokens are stored only on your device. Disconnecting (Settings → Google Calendar) deletes the tokens, your calendar selection, and all locally mirrored calendar data. Deselecting an individual calendar removes that calendar's mirrored events; clearing the app's data or uninstalling removes everything.
- Weektrace's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Accounts, sync, and where data lives
- Without an account, all data lives in a local database on your device and is removed by clearing the app's data or uninstalling.
- With an account (email + password) and an active Pro entitlement, the content you create is synced to our cloud database (hosted on Supabase) so it can be backed up and restored across devices. Access is restricted to your own account via row-level security; transport is encrypted (TLS).
- You can export your data at any time from the in-app backup feature; the export goes wherever you choose to share it and is not sent to us.
4. Data retention and deletion
- Local data: delete by clearing app data or uninstalling.
- Cloud data (accounts only): you can delete your account and all associated cloud data from within the app (Settings → Account → Delete account). If you no longer have the app installed, you can also request deletion by emailing support@weektrace.com; deletion is completed within 30 days.
5. Notifications
Event notifications are scheduled and delivered entirely on your device. No notification content leaves the device.
6. Diagnostics
The app keeps small, on-device diagnostic logs (e.g. sync timing, frame performance) to help investigate bugs. They are stored only on your device, never transmitted automatically, and are only shared if you manually copy and send them.
7. Children
Weektrace is a general-audience productivity tool and is not directed at children under 13.
8. Changes
We will post any changes to this policy at this URL and update the effective date. Material changes will be highlighted in the app's release notes.
隱私權政策(繁體中文)
Weektrace 是以行事曆為核心的時間記錄 App,採 local-first 設計:不註冊帳號即可使用全部核心功能,除非你主動登入並啟用雲端同步,資料只存在你的裝置上。
1. 我們蒐集什麼、為什麼
| 資料 | 用途 | 存放位置 |
|---|---|---|
| 你建立的行程、類別、待辦、App 設定 | App 核心功能 | 你的裝置(本機資料庫) |
| 帳號 Email + 密碼(選用) | 登入/雲端同步 | Supabase(驗證服務);密碼由 Supabase Auth 處理,我們無法看到 |
| 登入且訂閱 Pro 時的行程/類別/待辦 | 雲端備份與多裝置同步 | Supabase 資料庫,以帳號隔離(row-level security) |
| Google 日曆行程(選用,見 §2) | 在 Weektrace 中並列顯示你的 Google 日曆 | 僅你的裝置 —— 絕不上傳到我們的伺服器 |
| 購買狀態(訂閱功能上線後) | 解鎖 Pro 功能 | 由 Google Play 與 RevenueCat 處理;我們不會接觸你的付款卡片資料 |
| 診斷紀錄(見 §6) | 除錯 | 僅你的裝置 |
| 你主動送出的回饋內容(選用,設定 → 回報問題與建議) | 改善 App、修正問題 | Supabase 資料庫;未登入時匿名送出、登入時附帶帳號識別以便對回問題脈絡;一併附上 App 版本號 |
我們不蒐集位置、聯絡人或任何與上述功能無關的資料;不出售、不出租任何使用者資料。目前這個版本的 App 沒有廣告、不蒐集廣告識別碼,也沒有第三方分析 SDK。
未來版本的廣告。我們計畫在未來版本的免費層顯示廣告(Google AdMob)。屆時廣告服務會從你的裝置取得廣告識別碼;在法規要求的地區,我們會先徵得你的同意才顯示廣告,本政策與 Google Play 的資料安全聲明也會在同一個版本一併更新。付費的 Pro 版不顯示廣告。
2. Google 日曆(唯讀)
若你選擇連結 Google 日曆:
- Weektrace 只請求唯讀權限範圍
https://www.googleapis.com/auth/calendar.readonly,App 無法新增、修改或刪除你 Google 日曆中的任何內容。 - 你勾選的日曆行程僅鏡像於你的裝置供顯示與搜尋,絕不傳輸到我們的伺服器、不納入雲端同步、不提供任何第三方。
- OAuth 權杖僅存於裝置。中斷連結(設定 → Google Calendar)會刪除權杖、日曆選取以及全部本機鏡像資料;取消勾選單一日曆會移除該日曆的鏡像行程;清除 App 資料或解除安裝則移除一切。
- Weektrace 對自 Google API 取得之資訊的使用與轉移,遵循 Google API 服務使用者資料政策,包括其中的 Limited Use(有限使用) 要求。
3. 帳號、同步與資料存放
- 未註冊時,所有資料存於裝置本機資料庫,清除 App 資料或解除安裝即移除。
- 註冊帳號(Email + 密碼)且持有有效 Pro 資格時,你建立的內容會同步到我們的雲端資料庫(Supabase 託管)以供備份與跨裝置還原;存取以 row-level security 限制於你本人帳號,傳輸全程加密(TLS)。
- 你隨時可用 App 內建匯出功能備份資料;匯出檔流向由你選擇,不會傳送給我們。
4. 資料保存與刪除
- 本機資料:清除 App 資料或解除安裝即刪除。
- 雲端資料(僅帳號):可在 App 內刪除帳號與所有雲端資料(設定 → 帳號 → 刪除帳號);若已解除安裝,也可來信 support@weektrace.com 申請刪除,我們將於 30 天內完成。
- 刪除帳號後唯一保留的是付費資格的變更紀錄(方案、變更時間、變更原因),用於帳務追溯與客訴處理;這份紀錄不含姓名、Email 或任何內容資料,帳號刪除後也無法再對應到本人。保留期限為五年(比照《商業會計法》第 38 條會計憑證的保存年限),到期自動清除。
5. 通知
行程通知完全在裝置上排程與發送,通知內容不離開裝置。
6. 診斷
App 在裝置上保留少量診斷紀錄(如同步耗時、畫面效能)以協助除錯。這些紀錄僅存於你的裝置、絕不自動傳輸,只有在你手動複製並提供時才會離開裝置。
7. 兒童
Weektrace 為一般族群的生產力工具,非以未滿 13 歲兒童為對象。
8. 政策變更
政策若有修改將公告於本網址並更新生效日期;重大變更會在 App 更新說明中提示。