SHIO BOX · PUBLIC INFO
私隱政策 · Privacy Policy
重點摘要
有效嘅商店試用或 Shio Plus 會建立一個雲端儲存嘅「目前廚房」,可供一至兩人使用。雪櫃、食譜、餐單同購物清單會快取喺成員裝置,並經 Shio Box 伺服器同步;只有 30 秒示範廚房純粹存在記憶體。喺支援嘅平台啟動 app 時,RevenueCat 同 Firebase Messaging 可能會處理假名化 app/裝置識別資料;Scribe、通知、訂閱同作業系統備份嘅其他資料處理會按下面說明進行。
Shio Box 亦會將少量、唔含廚房內容文字嘅啟用里程碑同每日使用訊號傳送去自家伺服器,幫我哋了解設定、持續使用同二人共同計劃流程係咪正常。
我哋唔賣資料、唔賣廣告,亦唔使用廣告識別碼或跨 app 追蹤。
食譜分享連結同公開食譜
當你明確建立分享連結或撳「發佈最新版本」,Shio Box 會上載只包含你所揀食譜嘅目前發佈版本。內容可以包括食譜名稱、材料、份量、單位、步驟、時間、食用人數同標籤,但唔包括你嘅雪櫃、家庭、個人資料或真實作者身份。你喺 app 儲存嘅修改唔會自動改到分享連結。
一般分享係不公開列出嘅持有者連結,唔係私人或保密連結;任何收到或獲轉寄連結嘅人都可以睇到完整食譜。只有你再撳「畀埋大家睇」,明確同意公開食譜守則、確認分享權利同食譜完整性,並通過完整度、版本、分享權限、匯入來源同明顯不適合公開內容嘅檢查後,食譜先會以「匿名分享」出現喺「大家最近煮緊」。支援自動內容檢查嘅 app 版本通過後可即時公開;較舊版本會顯示等候審核,獲批先公開。舊分享唔會自動公開。
為咗限制濫用、處理舉報、畀個別瀏覽者隱藏同一分享者,同埋營運公開食譜安全,伺服器會保留經用途分隔雜湊處理嘅穩定分享者識別、公開同審核事件、舉報原因、處理結果同時間;呢啲資料唔會公開或放入分析 payload。網頁會用高熵 HttpOnly cookie、app 會用用途分隔嘅安裝識別,分開記住瀏覽者隱藏選擇。公開漏斗只記錄不含食譜內容或身份嘅總量訊號。
舉報唔會因單一舉報自動全局落架;Shio Box 可以為安全、權利或濫用問題保留或收起公開內容。你可以「停止公開」令食譜唔再列出,而原有分享 link 繼續有效;「停止分享」會移除食譜內容並永久保留不含內容嘅代碼 tombstone。為維護舉報、封鎖同服務安全,假名化處理紀錄可繼續保留。遺失原本裝置後,我哋只可以憑完整分享網址或六位代碼定位呢類無帳戶分享。
1. 我哋處理嘅資料
目前廚房資料
包括材料名稱與別名、雪櫃/冰格/儲物櫃存量、數量、到期日、食譜、餐單、購物項目、包裝文字備忘、反應同其他活動。可保存嘅「目前廚房」會儲存喺 Shio Box 伺服器,並快取喺成員裝置供使用同同步。一個訂閱涵蓋一個廚房,可供一至兩人使用;邀請多一個人係自選。服務使用隨機裝置憑證,首個版本唔要求一般電郵/密碼帳戶。裝置設定同小工具快照可以只留喺裝置;30 秒示範廚房只存在記憶體,離開後會清除。
包裝相片
你明確加入目前廚房嘅包裝相片會先喺裝置縮細、壓縮同移除內嵌 metadata,再儲存到 Shio Box 私有 RustFS object storage,畀獲授權嘅廚房裝置查看。儲存服務憑證唔會交俾 app;上載同讀取只會使用短效 signed URL,伺服器亦會先檢查目前廚房存取權。30 秒示範廚房唔會保存或上載包裝相片。
自家啟用分析
為咗了解設定、持續使用同共享計劃流程係咪有效,Shio Box 會向自家伺服器傳送少量、唔含內容文字嘅資料。首次里程碑包括完成或略過 30 秒示範廚房、見到訂閱頁、開始商店確認、完成購買、完成 onboarding、首個雪櫃項目或食譜、廚房啟用/邀請/加入、首個能證明兩位不同家庭成員參與嘅已確認餐單,同首個剔選購物項目。訂閱漏斗只記錄經限定嘅入口、月費/年費選擇,以及商店當時有冇顯示試用資格;唔會記錄價格、付款資料或商店帳戶。每日使用訊號只記錄:每個安裝喺啟動或返回前台時每日最多一次、每個家庭成功驗證同步嘅活躍日,以及通過上述兩位不同有效家庭成員證明後嘅共同決定日。首次里程碑紀錄可包括隨機 event ID、經用途分隔雜湊處理嘅安裝或家庭 ID、時間、app 版本、平台、粗略語言,同嚴格限定嘅布林/分類資料;每日紀錄只包括用途分隔 subject hash、固定事件名稱、UTC 日期同收件時間,冇額外 properties。分析 payload 同資料表唔會儲存食譜或材料名稱、餐單/slot 名稱、留言、相片、網址、錄音、逐字稿、顯示名稱、人物/裝置 ID、邀請/恢復碼、驗證或推送 token、廣告識別碼或任意文字;現有隨機安裝憑證只用嚟驗證傳送。失敗事件可暫存喺最多 100 項嘅本機 queue 再重試。伺服器首次里程碑同每日紀錄最多保留 180 日,之後由有界、非阻塞嘅自動清理移除。管理摘要只回傳 DAU/WAU/MAU、活躍家庭、共同決定家庭同首次漏斗總數,唔會回傳 subject hash。呢套分析由 Shio Box 自家處理,冇加入第三方分析 SDK。
Scribe
第一次使用網上 Scribe 時,裝置會取得一個隨機、假名化嘅安裝憑證;伺服器只儲存憑證雜湊。你撳「完成」後,所揀錄音先會經 Shio Box 伺服器交俾目前設定嘅語音轉文字服務:自家託管 SenseVoice 或 Groq。確認逐字稿後,文字會經伺服器交俾自家託管 Qwen 整理成食譜。
Shio Box 伺服器唔會將原始錄音寫入檔案或作獨立長期儲存;錄音會轉送去完成所選語音處理。為咗執行免費用量、避免重複扣次同診斷可靠性,伺服器可能喺 Scribe attempt 記錄保留逐字稿、structured result、狀態同時間。目前呢類 attempt 記錄未設自動到期,會保留至營運清理或完成可核實嘅刪除要求。你確認儲存食譜後,食譜先會進入目前廚房。使用 Groq 時,供應商可能按其資料控制設定為可靠性或防止濫用保留有限紀錄;詳情見 Groq 資料控制說明。
訂閱及裝置資料
Shio Plus 購買由 Apple App Store 或 Google Play 收款,RevenueCat 幫我哋處理權益狀態、購買紀錄及用於啟用/還原購買嘅 app 使用者或裝置識別資料。我哋唔會收到完整付款卡資料。
通知同小工具
如果你允許通知,裝置推送 token、平台同語言設定會交俾 Shio Box 伺服器,並加密儲存,用嚟經 Firebase Cloud Messaging 傳送家庭提議、回應、確認及購物更新。你可以隨時喺系統設定關閉通知。當你加入主畫面小工具,今晚餐單、快到期數量同最多三項購物內容會寫入作業系統嘅共享小工具儲存空間,可能喺 app 外顯示。
2. 用途、保留及分享
- 提供目前廚房、跨裝置同步、食譜分享、Scribe、訂閱權益、通知同客戶支援。
- 保護服務、防止濫用,同埋診斷技術故障。
- 目前廚房資料會快取喺成員裝置,並保留喺 Shio Box 伺服器,直至你刪除相關內容,或我哋完成可核實及可定位嘅刪除要求;作業系統備份可能另行保留副本,需喺裝置設定管理。
- 訂閱權益完結後,同一個廚房會保留並變成唯讀,直至重新訂閱。
- 已發佈食譜內容保留至你停止分享;停止後即時移除內容,只留不含內容嘅代碼 tombstone。
- 訂閱紀錄由 Apple、Google 及 RevenueCat 按提供服務、退款、法律及會計需要保留。
處理服務包括 Zeabur/Shio Box 自家基礎設施、PostgreSQL、私有 RustFS object storage(目前廚房包裝相片)、SenseVoice、Qwen、Groq(選用語音處理)、Firebase Cloud Messaging(通知)、RevenueCat、Apple 同 Google。除咗向呢啲服務供應商提供完成指定功能所需資料,或法律要求外,我哋唔會向第三方披露資料。
3. 你嘅選擇
訂閱前,你可以使用只存在記憶體、離開後唔會保留內容嘅 30 秒示範廚房。建立可保存嘅真實廚房需要有效嘅商店試用或 Shio Plus;權益完結後,現有廚房資料會保留並可唯讀查看,直至重新訂閱。食譜分享可喺 Shio Box 嘅有效分享連結清單停止。要刪除其他資料,請睇 刪除資料指引。同步、自家分析、推送或 RevenueCat 客戶紀錄可電郵 coffeebb71@gmail.com 開始刪除要求;我哋會先按你嘅使用方式提供安全核實步驟,只有喺可以核實擁有權同定位相關紀錄後先會刪除。Apple 或 Google 為交易、退款或法定義務保留嘅紀錄,要按其政策處理。
Shio Box 面向一般家庭煮食用途,唔係特別為 13 歲以下兒童而設;我哋唔會在知情情況下向 13 歲以下兒童收集個人資料。如你認為兒童向我哋提供咗資料,請聯絡我哋。
Recipe share links and public recipes
When you explicitly create a share link or tap “Publish latest version,” Shio Box uploads the current published version of only the recipe content you selected. It may include recipe names, ingredients, quantities, units, steps, time, servings and tags, but not your fridge, household, person profile or real author identity. Saving edits in the app does not automatically update the share link.
An ordinary share is an unlisted bearer link, not a private or secret link. It appears in “What everyone is cooking” only after you separately tap “Make it public,” explicitly accept the public recipe rules, confirm your rights and recipe completeness, and pass completeness, version, share-ownership, import-provenance, and high-confidence objectionable-content checks. Supported app versions publish immediately after automated checks pass; older versions show a pending review and publish only after approval. Old shares are never listed automatically.
To limit abuse, process reports, support viewer-specific publisher hiding and operate public-recipe safety, the server retains domain-separated pseudonymous publisher identifiers, publication and review events, report reasons, resolutions and timestamps. These identifiers are not public or included in analytics payloads. The web uses a high-entropy HttpOnly cookie and the app uses a separately domain-separated installation identity for viewer hiding. Public-funnel analytics are content-free aggregate signals.
A single report does not automatically remove content globally. Shio Box may keep or remove public content to address safety, rights or abuse. “Stop publishing” removes the listing but keeps the bearer link working. “Stop sharing” removes recipe content and permanently reserves the content-free code tombstone; pseudonymous handling records may remain for reporting, blocking and service safety. If you lose the creating installation, we can locate an accountless share only from the exact share URL or six-character code sent to coffeebb71@gmail.com.
Summary
A Store trial or active Shio Plus entitlement creates one persistent, cloud-backed Current Kitchen for one or two people. Fridge items, recipes, plans and shopping lists are cached on your device and synced through Shio Box servers; the 30-second Sample Kitchen is the exception and exists only in memory. On supported platforms, RevenueCat and Firebase Messaging may process pseudonymous app/device identifiers during app startup; Scribe, notifications, subscriptions and operating-system backup process other data as described below.
Shio Box also sends a small set of content-free activation milestones and daily activity signals to its own server so we can understand whether setup, continued use and the shared planning flow work.
We do not sell personal data, show third-party ads, use advertising identifiers or track you across apps.
1. Data we process
Current Kitchen data
This may include ingredient names and aliases, inventory locations, quantities, expiry dates, recipes, meal plans, shopping items, packaging notes, reactions and related activity. A persistent Current Kitchen is stored on Shio Box servers and cached on its members' devices for access and sync. One subscription covers one Kitchen with one or two people; inviting a second person is optional. Random device credentials protect access, and the initial product does not require a general email/password account. Device settings and widget snapshots may remain local to a device. The 30-second Sample Kitchen exists only in memory and is discarded when you leave it.
First-party activation analytics
To understand whether setup, continued use and shared planning work, Shio Box sends a small content-free set to its own server. First-only milestones cover completing or skipping the 30-second Sample Kitchen; viewing the subscription screen; starting Store confirmation; completing a purchase; onboarding completion; the first fridge item or recipe; kitchen activation, invite and join; the first confirmed meal that proves two distinct valid household people participated; and the first checked shopping item. Subscription-funnel events contain only an allowlisted entry source, monthly/yearly selection and whether the Store showed trial eligibility; they do not include price, payment details or a Store account. Daily activity records cover an installation at most once per UTC day on launch or resume, a household after a successful authenticated sync request, and a shared-decision day only after that same two-person household proof passes. Milestone rows may contain a random event ID, a domain-separated installation or household subject hash, timestamps, app version, platform, coarse locale, and tightly allowlisted boolean/category fields. Daily rows contain only a domain-separated subject hash, fixed event name, UTC day and received timestamp, with no properties. The analytics payload and tables do not store recipe or ingredient names, meal or slot names, comments, photos, URLs, audio, transcripts, display names, person or device IDs, invite or recovery codes, authentication or push tokens, advertising identifiers, or arbitrary text; the existing random installation credential is used only to authenticate delivery. Failed client events may wait in a bounded on-device queue of at most 100 rows. Server milestone and daily analytics rows are automatically deleted after 180 days by bounded, non-blocking cleanup. The admin summary returns only DAU/WAU/MAU, active-household, shared-decision-household and activation-funnel counts, never subject hashes. This is handled by Shio Box without a third-party analytics SDK.
Scribe
Online Scribe creates a random pseudonymous installation credential; the server stores only a hash. After you tap Done, the selected recording is sent through Shio Box to the configured speech-to-text provider, either self-hosted SenseVoice or Groq. After you confirm the transcript, text is sent through Shio Box to a self-hosted Qwen model to structure a recipe.
Shio Box does not write the original audio to a file or keep it as a separate long-term recording; it is proxied for the selected speech processing. To enforce fair use, avoid double charging and diagnose reliability, the server may retain transcript, structured result, status and timestamps in a Scribe attempt record. Those attempt records currently have no automatic expiry and remain until operational cleanup or completion of a verifiable deletion request. A recipe enters Current Kitchen storage only after you review and save it. When Groq is used, limited logs may be retained under its account data-control settings for reliability or abuse prevention; see Groq's data controls.
Subscriptions and device data
Apple App Store or Google Play processes payment. RevenueCat helps us manage entitlements, purchase history, and app-user or device identifiers needed to activate and restore purchases. We do not receive full payment-card details.
Notifications and widgets
If you opt in, a push token, platform and locale are sent to Shio Box and encrypted at rest to deliver Kitchen proposals, comments, confirmations and shopping updates through Firebase Cloud Messaging. You can disable notifications in system settings. A home-screen widget writes tonight's meal, expiring counts and up to three shopping items to operating-system shared widget storage, where they may appear outside the app.
Packaging photos
A packaging photo you explicitly add to the Current Kitchen is resized, compressed and stripped of embedded metadata on the device, then stored in Shio Box's private RustFS object storage for authorized Kitchen devices. Storage credentials are never sent to the app. Uploads and reads use short-lived signed URLs, and the server checks Current Kitchen access before issuing them. The 30-second Sample Kitchen does not save or upload packaging photos.
2. Uses, retention and providers
We process data to provide the app, prevent abuse, diagnose failures and answer support requests. Current Kitchen data is cached on member devices and remains on Shio Box servers until you delete it or we complete a verifiable and locatable deletion request; operating-system backups may retain a separate copy that must be managed in device settings. When subscription access ends, the same Kitchen is preserved read-only until you resubscribe. Store and subscription providers may retain transaction records for service, refund, legal or accounting needs.
Processors may include Zeabur/Shio Box infrastructure, PostgreSQL, private RustFS object storage for Current Kitchen packaging photos, self-hosted SenseVoice and Qwen, Groq for selected speech processing, Firebase Cloud Messaging, RevenueCat, Apple and Google. We disclose only what is needed for those functions or as required by law.
3. Your choices and contact
Before subscribing, you may use the 30-second Sample Kitchen, which exists only in memory and does not keep its contents after you leave. A Store trial or active Shio Plus entitlement is required to create a persistent real Kitchen. When access ends, existing Kitchen data is preserved and remains available read-only until you resubscribe. See Delete Your Data. To start a deletion request for synced, first-party analytics, push-registration or RevenueCat customer records, email coffeebb71@gmail.com. We will provide verification steps appropriate to your setup and can delete records only after ownership can be verified and the records located. Records retained by Apple or Google for transactions, refunds or legal duties remain subject to their policies.
Shio Box is a general household cooking product and is not directed to children under 13. Contact us if you believe a child has provided data.