隱私權說明
Privacy Notice
最後更新:2026-08-14
NYCU LIFE Super App 是 Android 與 iOS 校園服務 App。校車、地圖、活動與學校行事曆等公開資訊不需帳號即可瀏覽;只有個人課表等個人化功能需要透過系統管理的 App 內瀏覽器完成 NYCU OAuth 登入。登入頁面會顯示可供使用者核對的網址與 TLS 連線資訊;Tauri WebView 無法讀取或修改登入內容,也不會收集校務帳號密碼。
我們處理的資料
- 使用者選擇登入時,由 NYCU OAuth 提供的穩定帳號識別,用於建立登入 Session 及隔離個人課表。
- NYCU OAuth 可能提供的顯示名稱,用於首頁問候。App 會先核對名稱資料所屬帳號;名稱服務無法使用、資料無效或帳號不一致時不保存名稱,也不影響登入。Super App 不保存 NYCU 上游 access token。
- 使用者儲存的課表與課表 revision,用於跨裝置同步及避免靜默覆寫。
- 短效 access token 與可輪替 refresh token。access token 只保存在記憶體;refresh token 只保存在 iOS Keychain 或 Android Keystore 保護的加密儲存空間。伺服器只保存 refresh token 的雜湊。
- 使用者授予使用期間定位權限後取得的前景位置。位置只在 App 位於前景時於裝置上處理,用來顯示目前座標、尋找附近校車站點,以及建立外部導航目的地;Super App BFF 不接收或保存裝置位置。拒絕權限後仍可手動選擇路線、站點或地圖座標。
- 維運所需的安全與錯誤紀錄。不得在紀錄中寫入 OAuth code、access token、refresh token 或精確裝置位置。
外部資料與 App
App 會讀取 NYCU LIFE 的課表、校車與活動服務,以及公開的學校 Google Calendar 資料。校園底圖來自國土測繪中心。只有在使用者明確選擇路線導航時,App 才會將目的地交給 Apple Maps、Google Maps 或其 HTTPS 地圖頁面;後續處理由該服務自己的條款與隱私權政策規範。
不進行的處理
MVP 不包含分析工具、廣告、跨 App 追蹤、廣告識別碼、推播通知或背景定位,也不販售個人資料。
保存與控制
Session 最長可延續 30 天,refresh token 每次使用都會輪替。登出會撤銷該 token family 並清除裝置安全儲存。顯示名稱會在下次成功登入時更新,並與個人課表一樣保留至帳號資料依支援流程刪除;個人課表也可由使用者覆寫或清空。上游公開活動、校車與行事曆快取不作為使用者個人檔案。
支援與請求
帳號、Session 撤銷、課表資料或隱私權問題,請使用 https://app.nycu.one/support 公布的正式聯絡方式。
Last updated: 2026-08-14
NYCU LIFE Super App is a campus-services app for Android and iOS. Public bus, map, event, and school-calendar information can be viewed without an account. NYCU OAuth is required only for personal features such as the user's timetable, and sign-in takes place in a system-managed in-app browser that displays the verifiable URL and TLS connection information. The Tauri WebView cannot inspect or modify the sign-in content and never collects the user's NYCU password.
Data we process
- If the user signs in, the stable account identifier returned by NYCU OAuth, used to establish a session and isolate personal timetables.
- The display name NYCU OAuth may provide, used for the home-screen greeting. The app first verifies that the name response belongs to the same account. An unavailable name service, invalid response, or account mismatch prevents the name from being stored but does not prevent sign-in. The Super App does not retain the upstream NYCU access token.
- Timetables saved by the user and their revisions, used for cross-device access and conflict-safe updates.
- Short-lived access tokens and rotating refresh tokens. Access tokens remain in memory. Refresh tokens are stored only in iOS Keychain or Android Keystore-protected encrypted storage; the server stores only refresh-token hashes.
- Foreground location after the user grants while-in-use permission. It is processed on-device only while the app is in the foreground to show the current coordinates, find nearby shuttle stops, and prepare an external navigation destination. The Super App BFF neither receives nor stores device location. Route, stop, and map-coordinate selection remain available after permission is denied.
- Security and error records needed to operate the service. OAuth codes, access tokens, refresh tokens, and precise device location must not be logged.
External data and apps
The app reads NYCU LIFE timetable, bus, and events services and the school's public Google Calendar data. Campus map tiles come from Taiwan's National Land Surveying and Mapping Center. Only after an explicit navigation action does the app hand a destination to Apple Maps, Google Maps, or their HTTPS map page; that service's own terms and privacy policy then apply.
Processing we do not perform
The MVP has no analytics, advertising, cross-app tracking, advertising identifier, push notifications, or background location, and does not sell personal data.
Retention and controls
A session can last up to 30 days and its refresh token rotates on every use. Signing out revokes the token family and clears secure device storage. A display name is refreshed on the next successful sign-in and, like a personal timetable, remains until the account data is deleted through support; the user may also replace or clear a timetable. Cached public events, bus, and calendar data are not maintained as a personal user profile.
Support and requests
For account, session-revocation, timetable-data, or privacy requests, use the official contact published at https://app.nycu.one/support.