# Privacy Policy

Last updated: 16 September 2026

月涌星-生活看板 (Hearthboard) is an iOS team board operated by shenzhepei. When you use the app, team content (chores, meals, member names, and member relationships (teammates or relatives)) is sent to our servers so team members and operators can view it. We do not sell your data or use advertising SDKs.

## Information we collect and its purposes
- Team membership, display names, and member relationships (teammates or relatives); optional gender is used for labels such as Father/Mother and Son/Daughter shown to team members
- Chores and meal orders to coordinate team tasks and dining
- Device tokens required to sign you in
- Sign in with Apple account identifier (`sub`) for sign-in and account linking, and verified email (possibly a private relay address) for profile display. Apple does not provide an avatar.
- Mobile number, country or region, and SMS codes for optional phone sign-in or phone linking (via Tencent Cloud)
- App version heartbeats used for support and forced updates
- Optional Face ID stays on your device
- After manual city selection, catalog coordinates, country/region and an optional mainland city address are sent to Hearthboard to obtain Caiyun weather. Amap resolves mainland city addresses or converts mainland coordinates; overseas coordinates go directly to Caiyun. On entering Today, the app requests location permission and, if granted, obtains your city and weather automatically. If you decline, you can still choose a city manually. When locating, iOS uses Apple reverse geocoding to resolve country/region and city. The location candidate uses a nearby catalog city or coordinates rounded to two decimal places; raw precise GPS is not persisted. City selection stays on your device. The server briefly caches weather and does not write coordinates to the database.

- Uploaded avatars, team logos and dish images to display your chosen content; profile gender and names for team display
- Home layout preferences to synchronize your chosen sections across your account
- Subscription transaction identifiers and status to verify purchases and display membership; feedback text and contact details you submit to respond to support requests

- The contact email and one-time email verification code you provide are used to verify mailbox ownership and manage your profile. Changing email requires verification with your current phone, Apple identity, or password. For password accounts, it also changes the sign-in email; your Apple identity is unchanged.

- Email/password registration, sign-in and recovery use your email and one-time codes. Passwords are stored as BCrypt hashes. Verification email is sent through the operator’s configured SMTP provider. Request and verification attempt counts help prevent abuse. Apple sign-in does not require a phone number.

## How we protect information
We validate session tokens and enforce account and team access controls. Apple identity tokens are checked for signature, issuer, audience and expiry. Third-party service keys remain on the server. Operational access is restricted and backups support recovery. Do not share verification codes or sign-in credentials.

## Third-party data processing in our services
See the [third-party sharing list](hearthboard://sharing) for Apple, Amap, Caiyun and Tencent Cloud, including Tencent Captcha, the information processed, purposes and privacy policies.

## How you manage your information
Edit your name, gender and avatar in Me → Personal profile, check or link Apple in Account security, and revoke location access in iOS Settings at any time. Manual city selection remains available. Reorder or hide home sections in Home layout. Edit or delete chores and meals where you have permission, or request account deletion in Settings → Account security → Delete account. Contact the email below for access, correction, deletion or withdrawal requests. Withdrawal does not affect lawful processing before withdrawal.

## Contact
Support and account questions: shenzhepei@gmail.com
Use GitHub Security Advisories on this repository for private security reports.

## Team travel journal (introduced in 1.0.1)

You may submit cities you visited and visit dates. We associate the catalog city ID, city-center coordinates and date with your account and current team. Current team members can view these records; the author and team owner can manage them subject to team permissions. When you leave or are removed from a team, you keep your own visits, but former teammates can no longer see them. Deleting your account removes your travel records. Closing a team does not delete authors' visit rows; team views only show active members. This feature does not request GPS location, track routes, or upload photos or travel prose. City-center coordinates come from the GeoNames catalog and are not your device's precise location.

The Today globe uses the native Mapbox Maps SDK for iOS (not a web SDK). Mapbox loads globe and style resources and may receive a network IP address, device/SDK information and map usage data. Place labels follow the in-app language. The app fills city administrative outlines from the travel summary and does not submit team member names, account IDs or visit dates to Mapbox. Mainland outlines come from Amap district data using the weather Amap key; other regions use OpenStreetMap Nominatim polygons. Both are cached on the server. If no public token is configured, the system map draws the same fills. New visits cannot be saved offline.

## Account support and operational diagnostics

To investigate login, security, delivery and payment issues, we record authentication methods, success or failure categories, recent session activity, provider request identifiers, processing duration and payment notification outcomes. Diagnostic records are retained for 90 days and do not contain passwords, verification codes or message bodies. Support staff and authorized administrators may view linked phone numbers, account and login email addresses, and Apple sign-in identifiers. Access to sensitive account details is audited.

Support-assisted email changes or Apple unlinking require proof of an existing linked identity. Email changes also require verification of the new email. An account cannot be forcibly recovered when all original identities are lost. Execution revokes previous sessions without deleting account content or cancelling Apple subscriptions. Closed support cases and necessary administrator audit records are retained for one year. Account deletion removes related diagnostic and case personal information; audits retain only necessary de-identified operational facts.
