隱私權政策 · Privacy Policy
核心承諾:Lexa Vireon 是一套運行在使用者本機電腦上的桌面工作台應用程式。所有模型金鑰、對話紀錄與 API 授權存取 Token 皆加密保存在使用者本機系統,不會上傳至中央伺服器或轉售給任何第三方。
一、我們存取的資料與使用目的
當您在 Lexa Vireon 啟用 Google 帳號整合或連動相關服務時,本軟體僅在您授權的範圍內請求以下權限:
- 基本設定檔與電子郵件地址(Google Account Profile & Email):用於在桌面端介面顯示您的帳號資訊,以識別目前工作台操作身分。
- 工作管理與輔助存取權(行事曆、Gmail、雲端硬碟 - 如有選取):僅在您於對話中主動要求 AI 特工執行相關任務(例如:查詢今日行程、整理郵件摘要或讀取指定檔案)時,由本機直接向 Google API 發送請求。
二、Google API 使用者資料政策遵循聲明(Limited Use Policy)
Google API Services User Data Policy Compliance:
Lexa Vireon 對從 Google API 收到的任何資訊之使用與傳輸,均嚴格遵守 Google API Services User Data Policy(Google API 服務使用者資料政策),包含其中的「有限使用(Limited Use)」要求。
三、資料絕不用於 AI 訓練或廣告販售
- 絕不用於 AI 模型訓練:我們承諾絕不將透過 Google API 取得的任何使用者資料、電子郵件內容、檔案或個人資訊,用於訓練、微調或改進任何通用人工智慧(AI)或機器學習(ML)模型。
- 絕不販售或散布:我們絕不會向任何廣告商、數據仲介商或第三方機構出售、出租或分享您的 Google 使用者個人資料。
四、資料保存與安全架構
Lexa Vireon 採用去中心化與 Zero Trust(零信任)本機儲存架構:
- 本機加密保存:OAuth 存取 Token(Access Token 與 Refresh Token)直接保存在使用者 Windows 系統的憑證保護存放區中(Windows Credential Manager / DPAPI 加密保護)。
- 無中繼伺服器攔截:授權請求直接由本機程式連線至 Google 官方端點,官方網域
lexavapula.com僅提供靜態網站說明與公開安裝檔下載,不保存亦無權查看任何使用者的 Google Token。
五、使用者權益:撤銷授權與刪除資料
使用者保有對個人資料的絕對控制權:
- 隨時撤銷 Google 授權:您可以隨時前往 Google 帳戶安全性設定 - 第三方應用程式存取權限,立即一鍵撤銷 Lexa Vireon 的存取許可。
- 清除本機憑證:在 Lexa Vireon 軟體設定介面中點擊「登出」或「清除金鑰」,本機存放之所有 Token 與快取將立即被徹底銷毀。
Privacy Policy & Google API Disclosure (English)
This section outlines our strict adherence to Google API Services User Data Policy for the Google OAuth Verification Team.
1. Google User Data Accessed
Lexa Vireon is a local desktop application. When users explicitly connect their Google Account, Lexa Vireon requests minimal access:
- Profile & Email Address: Used solely to authenticate and identify the user in the local desktop workspace.
- User-Initiated Productive Scopes (Calendar, Gmail, Drive - optional): Invoked strictly upon explicit user prompt within the local desktop runtime to execute user-requested automated workflows.
2. Adherence to Google Limited Use Policy
Lexa Vireon's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Prohibition on AI Training & Data Selling
- No AI Model Training: Google user data obtained via Google APIs is never used to train, retrain, fine-tune, or develop generalized artificial intelligence (AI) or machine learning (ML) models.
- No Third-Party Sharing / Sale: We do not sell, rent, license, or disclose Google user data to any third parties, data brokers, or advertisers.
4. Data Storage & Security
All OAuth credentials, access tokens, and refresh tokens are stored locally on the user's host operating system using platform-level encryption (Windows Data Protection API / Credential Vault). No user tokens or private data are transmitted to or stored on lexavapula.com servers.
5. Revocation & Contact Information
Users can revoke access to their data at any time via Google Account Permissions. To request complete deletion of local configuration, simply sign out within the application or delete local app configuration files.
For inquiries regarding this Privacy Policy, please contact: [email protected] or [email protected].