1. 适用范围与服务主体
本政策适用于在 airphub.online 提供的 Opalia 服务。Opalia 是一个私密、以邀请和权限为基础的互动角色内容平台,提供账号、角色卡、会话存档、场景状态和创作者管理功能。
“Google 用户数据”是指用户选择使用 Google 登录后,由 Google Identity Services 提供并由 Opalia 处理的数据。使用邮箱和密码注册时产生的数据,以及用户在 Opalia 内创建的内容,也按本政策处理。
1. Scope and service identity
This policy applies to the Opalia service available at airphub.online. Opalia is a private, invitation- and permission-based platform for interactive character content, accounts, character cards, saved conversations, scene state, and creator administration.
“Google user data” means data provided through Google Identity Services and processed by Opalia after a user chooses Google Sign-In. Data created through email/password registration and content created within Opalia are also covered by this policy.
2. Google 用户数据
用途摘要:Opalia 只使用 Google 登录来验证身份、创建账号、防止重复注册并让用户再次登录同一个 Opalia 账号。
我们访问和保存什么
- Google 账号的稳定唯一标识符(ID Token 的
sub); - 已验证的邮箱地址及邮箱验证状态;
- 当 Google 提供时,Google Workspace 托管域名(
hd); - 用于完成一次登录验证的签名 ID Token。该 Token 会发送到 Opalia 服务端进行真实性、签发方、受众和有效期验证。
Google 的 ID Token 可能包含其他基础资料声明,但 Opalia 当前服务端只读取并持久保存上述账号标识与邮箱相关字段。Google ID Token 不写入浏览器持久缓存,也不会作为长期凭据保存。
我们不访问什么
Opalia 不请求访问 Gmail 邮件、Google 云端硬盘、通讯录、日历、照片、付款数据或 Google 密码,也不使用 Google Workspace API 获取文件或工作区内容。
Google 用户数据不会用于广告、再营销、数据经纪、信用评估,也不会用于训练或改进通用模型。
2. Google user data
Purpose summary: Opalia uses Google Sign-In only to verify identity, create an account, prevent duplicate registration, and return a user to the same Opalia account.
What we access and retain
- The stable unique identifier for the Google Account (the ID Token
subclaim); - The verified email address and email-verification status;
- The Google Workspace hosted domain (
hd), when Google provides it; and - The signed ID Token needed to complete a single verification. It is sent to the Opalia server to validate its signature, issuer, audience, and expiry.
A Google ID Token may contain other basic profile claims, but Opalia's server currently reads and persistently stores only the identity and email-related fields listed above. The Google ID Token is not placed in persistent browser storage and is not retained as a long-term credential.
What we do not access
Opalia does not request access to Gmail messages, Google Drive, Contacts, Calendar, Photos, payment data, or a Google password, and does not use Google Workspace APIs to obtain files or Workspace content.
Google user data is not used for advertising, retargeting, data brokerage, credit decisions, or training or improving generalized models.
3. 我们处理的其他数据
- 账号与资料数据:邮箱或用户名、密码的安全哈希、邮箱验证码状态、唯一公开账号 ID、登录会话,以及用户主动填写或上传的昵称、简介和头像。
- 用户内容:互动消息、会话存档、角色卡、人物偏好、场景状态、摘要、记忆和创作者配置。
- 社区互动:作品评论、回复、点赞关系及由此产生的通知。评论区会向可访问该作品的注册用户显示昵称、唯一公开账号 ID,以及用户选择设置的头像,不显示登录邮箱。
- 运行与安全数据:请求时间、IP 地址、浏览器和操作系统类型、设备类别、浏览器语言、设备时区、错误记录、限流记录、用量统计以及不包含完整提示词和模型正文的审计事件。近期登录 IP 的出现次数用于在账号页标记常用 IP;设备时区仅用于显示大致位置,不是 GPS 精确定位。
- 浏览器存储:Opalia 会在浏览器本地存储第一方访问和刷新凭据、基础资料元数据及账号隔离所需的缓存标记。当前账号头像及评论作者头像只在登录期间临时加载,不会作为图片数据写入浏览器持久存储。Google ID Token 不会写入该持久存储。
3. Other data we process
- Account and profile data: email address or username, a secure password hash, email verification status, a unique public account ID, sign-in sessions, and the nickname, biography, and avatar a user chooses to provide.
- User content: interactive messages, saved conversations, character cards, persona preferences, scene state, summaries, memories, and creator settings.
- Community interactions: work comments, replies, like relationships, and the resulting notifications. The comment area shows a nickname, unique public account ID, and any avatar the user chooses to set to registered users who can access that work, but does not show the sign-in email address.
- Operations and security data: request time, IP address, browser and operating-system type, device category, browser locale, device time zone, errors, rate-limit records, usage totals, and sparse audit events that do not contain full prompts or model response text. Recent sign-in IP observations are counted to mark a common IP on the account page. The device time zone supplies only an approximate location and is not precise GPS location.
- Browser storage: Opalia stores first-party access and refresh credentials, basic profile metadata, and account-isolation cache markers in local browser storage. The current account avatar and comment-author avatars are loaded temporarily during the signed-in session and are not written as image data to persistent browser storage. The Google ID Token is not written to that persistent storage.
4. 我们如何使用数据
我们仅在提供、保护和改进用户可见的 Opalia 功能所需范围内处理数据,包括:
- 注册、验证、登录和恢复账号会话;
- 在账号安全页面展示近期登录设备、常用 IP 和基于设备时区的大致位置,并允许用户撤销其他设备的会话;
- 保存并展示用户主动设置的昵称、简介和头像;
- 将同一个 Google 身份稳定地映射到同一个 Opalia 账号,并阻止跨登录方式的重复注册;
- 保存并恢复互动进度、构建用户请求的上下文和生成回复;
- 展示作品评论和回复、记录点赞,并向相关评论作者发送账号内通知;
- 执行角色、服务器、邀请及角色卡的访问权限;
- 防止滥用、排查故障、保障服务容量与安全;
- 发送用户请求的邮箱验证码和必要的服务通知。
4. How we use data
We process data only as needed to provide, protect, and improve user-facing Opalia features, including to:
- Register, verify, sign in, and restore account sessions;
- Show recent signed-in devices, a common IP, and approximate device-time-zone location on the account security page, and let the user revoke another device's session;
- Save and display the nickname, biography, and avatar a user chooses to set;
- Reliably map the same Google identity to the same Opalia account and prevent duplicate cross-method registration;
- Save and restore interaction progress, build context requested by the user, and generate responses;
- Display work comments and replies, record likes, and send in-account notifications to the relevant comment author;
- Enforce access to roles, servers, invitations, and character cards;
- Prevent abuse, diagnose failures, and protect service capacity and security; and
- Send requested email verification codes and essential service notices.
6. 数据保留与删除
Google 账号标识与已验证邮箱通常在 Opalia 账号有效期间保留,以便用户持续登录并防止账号冲突。账号内容会在提供用户所请求功能所需期间保留。
你可以删除自己发布的作品评论或回复。没有后续回复时,该条内容会从活动系统中删除;为避免同时删除其他用户的回复,已有回复依赖时会立即清除正文、标签、点赞和该条内容产生的通知,仅在线程中保留“已删除”结构占位。
当前运行维护目标包括:原始会话消息 30 天、已撤销或过期的登录会话记录及其 IP/设备观察记录 30 天、安全审计记录 90 天、聚合用量和维护记录最长 400 天;常规备份轮换目标为 30 天。活动登录会话的设备信息会在该会话有效期间保留。某些数据可能因账号仍在使用、安全事件、争议解决或法律义务而保留更长时间,也可能提前删除或去标识化。
公司联系方式确认后,本页面会公布账号及关联 Google 身份映射的删除申请渠道。完成身份验证后,我们会从活动系统中删除或去标识化不再需要的数据;备份中的残留副本会随备份轮换到期,依法或为防止滥用必须保留的最少记录除外。
6. Data retention and deletion
The Google account identifier and verified email are generally retained while the Opalia account remains active so the user can continue signing in and account conflicts can be prevented. Account content is retained while needed to provide the features requested by the user.
You may delete a work comment or reply posted by your account. It is removed from the active system when no later reply depends on it. When replies depend on it, its text, tag, likes, and notifications are cleared immediately and only a “deleted” structural placeholder remains so other users' replies are not removed.
Current operations targets include 30 days for raw conversation messages, 30 days for revoked or expired sign-in session records and their IP/device observations, 90 days for security audit records, and up to 400 days for aggregate usage and maintenance records; routine backup rotation targets 30 days. Device information for an active sign-in session is retained while that session remains valid. Some data may be kept longer when an account remains in use or when needed for a security incident, dispute, or legal obligation, and data may also be deleted or de-identified sooner.
Once company contact details are finalized, this page will publish the channel for requesting deletion of an Opalia account and its linked Google identity mapping. After identity verification, data no longer needed will be deleted or de-identified from active systems; residual backup copies expire through backup rotation, except for minimal records that must be retained by law or to prevent abuse.
7. 数据安全
Opalia 使用 HTTPS 传输、服务端 Google Token 验签、最小权限访问控制、账号所有权约束、登录限流、敏感凭据哈希或密钥化处理、备份与审计等措施保护数据。我们不会记录明文密码,也不会把 Google ID Token 当作 Opalia 长期会话凭据。
任何互联网服务都无法保证绝对安全。公司联系方式确认后,本页面会公布安全问题报告渠道。
7. Data security
Opalia protects data with HTTPS transport, server-side Google Token verification, least-privilege access controls, account ownership constraints, sign-in rate limits, hashing or secret handling for sensitive credentials, backups, and audit controls. We do not record plaintext passwords or use a Google ID Token as a long-lived Opalia session credential.
No internet service can guarantee absolute security. This page will publish a security-reporting channel after company contact details are finalized.
8. 你的选择与权利
- 你可以选择 Google 登录或邮箱密码注册;不使用 Google 登录不会阻止你使用可用的其他注册方式。
- 你可以退出登录,并可在 Google 账号的第三方连接设置中撤销对 Opalia 的 Google 登录许可。
- 你可以在账号页面查看当前和其他登录设备、常用 IP 与设备时区大致位置,并退出其他设备。
- 你可以在账号页面修改昵称和简介、上传或更换头像。
- 你可以在作品评论区删除自己发布的评论或回复。
- 公司联系方式公布后,你可以通过正式渠道请求访问、更正或删除与账号关联的个人数据;我们可能需要先验证账号所有权。
- 你可以停止使用服务;撤销 Google 许可不会自动删除 Opalia 已创建的账号,请另行提交删除请求。
8. Your choices and rights
- You may choose Google Sign-In or email/password registration; not using Google does not prevent use of another available registration method.
- You may sign out and revoke Opalia's Google sign-in permission from the third-party connections settings of your Google Account.
- You may review the current and other signed-in devices, common IP, and approximate device-time-zone location on the account page, and sign out another device.
- You may change your nickname and biography and upload or replace your avatar from the account page.
- You may delete comments or replies posted by your account from the work comment area.
- After official company contact details are published, you may use that channel to request access, correction, or deletion of personal data associated with your account. We may first need to verify account ownership.
- You may stop using the service. Revoking Google permission does not automatically delete an Opalia account that has already been created; submit a separate deletion request.
9. 本政策的变更
如果 Opalia 访问或使用 Google 用户数据的方式发生变化,我们会在实施前更新本页面及产品内说明,并在适用时重新完成 Google 品牌或 OAuth 验证。页面顶部会标明最新更新日期。
9. Changes to this policy
If the way Opalia accesses or uses Google user data changes, we will update this page and the in-product disclosure before implementation and complete renewed Google brand or OAuth verification when applicable. The latest update date appears at the top of this page.