隐私政策
生效日期:2026 年 9 月 30 日 · 凪 NAGI 运营团队
凪 NAGI(下称「本服务」)是一个看海放空的冥想场景网页应用。我们尽可能少地收集信息——本政策说明我们会收集哪些数据、为什么收集,以及你如何控制它们。
一、我们收集的信息
- 账户信息:注册时提供的邮箱地址,以及密码的加盐 PBKDF2 哈希值(我们不存储密码明文)。
- 会员权益记录:你购买的套餐、到期时间与支付流水标识(如支付会话 / 支付意图 ID),用于开通、续费顺延与退款核对。
- 匿名标识:未注册时,浏览器会生成一个随机匿名 ID(uid),用于挂靠免费额度与会员权益;它不包含任何个人身份信息。注册或登录后,匿名 ID 名下的有效权益会并入你的账户。
- 基本请求日志:服务器进程会记录请求时间与请求路径,仅用于故障排查,不对外提供。
二、本地存储(localStorage)
本服务不使用 Cookie。你的偏好(界面语言、上次场景、时间与云量设置、音量、免费剩余额度、登录状态等)保存在你自己浏览器的 localStorage 中,前缀为 kanhai.,不会上传服务器(登录令牌与会员缓存除外)。清除浏览器数据即会删除这些内容。
三、支付信息
付费通过 Stripe Checkout 托管收银台完成。你的银行卡信息由 Stripe 直接处理,不经过本服务的服务器;我们无法看到也不会存储完整卡号。Stripe 对支付数据的处理适用其自身隐私政策(stripe.com/privacy)。
四、第三方服务
本服务页面不加载任何第三方统计、广告、字体、脚本或图片 CDN。唯一的第三方环节是支付时的 Stripe。
五、数据的使用与保留
- 邮箱仅用于账户识别、登录与找回账户,我们不会用它发送营销邮件。
- 账户与权益数据在你使用本服务期间保留;会员到期后记录仅用于续费顺延计算。
- 退款完成后,全额退款的对应权益会被撤销。
六、你的权利
你可以随时通过文末联系方式:查询我们保存的账户数据、更正错误信息、或请求删除账户及相关权益记录。删除后该邮箱可重新注册,但已购会员无法恢复,请谨慎操作。
七、未成年人
本服务面向一般用户。若你是未满 14 周岁的未成年人,请在监护人同意与指导下使用本服务并提供信息。
八、政策变更
我们可能不时更新本政策,更新后会在本页发布并修改顶部的生效日期。重大变更会在应用内以显著方式提示。
九、联系我们
对本政策或个人数据有任何疑问,请联系:[email protected](占位邮箱,部署前请替换)。
使用本服务即表示你已阅读并同意本政策与《用户协议》。
Privacy Policy
Effective date: September 30, 2026 · NAGI team
NAGI ("the Service") is a web app of calming seaside meditation scenes. We collect as little as possible — this policy explains what we collect, why, and how you stay in control.
1. Information we collect
- Account data: the email address you register with and a salted PBKDF2 hash of your password (we never store plaintext passwords).
- Membership records: the plan you purchased, its expiry, and payment reference IDs (checkout session / payment intent), used to grant access, stack renewals, and reconcile refunds.
- Anonymous ID: if you are not signed in, your browser holds a random anonymous ID (uid) that carries your free quota and entitlements; it contains no personal identity. On sign-up or sign-in, valid entitlements under the anonymous ID merge into your account.
- Basic request logs: the server records request time and path for troubleshooting only, never shared.
2. Local storage
The Service does not use cookies. Your preferences (language, last scene, time and weather settings, volumes, remaining free quota, login state, etc.) live in your browser's localStorage under the kanhai. prefix and are not uploaded to the server (login token and membership cache excepted). Clearing browser data removes them.
3. Payments
Paid plans are processed through Stripe Checkout. Card details are handled by Stripe directly and never reach our server; we cannot see or store full card numbers. Stripe's handling of payment data is governed by its own privacy policy (stripe.com/privacy).
4. Third parties
The Service loads no third-party analytics, ads, fonts, scripts, or image CDNs. Stripe is the only external party involved, and only when you pay.
5. Use and retention
- Your email is used only for account identity and sign-in; we send no marketing mail.
- Account and entitlement data is kept while you use the Service; expired records are retained only to compute renewal extensions.
- When a payment is fully refunded, the corresponding entitlement is revoked.
6. Your rights
Via the contact below, you may at any time request a copy of the account data we hold, correct it, or ask us to delete your account and related entitlement records. After deletion the email can register again, but a purchased membership cannot be restored.
7. Minors
The Service is for general audiences. If you are under 14, please use the Service and provide information only with a parent or guardian's consent and guidance.
8. Changes to this policy
We may update this policy from time to time. Updates are published on this page with a revised effective date; material changes will be announced prominently in the app.
9. Contact
Questions about this policy or your data: [email protected] (placeholder — replace before deploying).
By using the Service you agree to this policy and our Terms of Service.