更新日期:2026 年 9 月 24 日Updated September 24, 2026
隱私權政策Privacy Policy
了解本機資料、限時路線分享、Apple 服務及含廣告版本的資料處理。Understand local data, time-limited route sharing, Apple services, and data handling in versions with ads.
概述與適用版本
LocationLab 的配對、收藏與一般路線資料預設在 iPhone 本機處理,App 本身不要求建立帳號。只有使用者主動使用限時路線執行碼時,相關資料才會依下列說明傳送到服務端。地圖與訂閱使用 Apple 服務;包含廣告的版本另使用 Google AdMob。下列功能說明只適用於具備相應功能的版本。
裝置上處理的資料
LocationLab 可能在裝置上處理:
- 由使用者明確匯入、且只適用於該裝置的配對檔。
- 使用者要求將地圖移回目前位置,或以目前位置建立路線時的 iPhone 位置。
- 收藏、最近座標、手動路線及使用者選擇的 GPX 檔。
- 操作與問題排除所需的本機連線狀態及診斷活動。
上述資料預設保存在 LocationLab 的 App container。LocationLab 不會把配對檔、配對密鑰、收藏、一般路線、GPX 內容或本機詳細診斷活動加入廣告或分析請求。只有使用者主動使用下述路線執行碼時,該次所選路線才會傳送到服務端。
刪除 LocationLab 會移除其 App container 內的資料。重設 iPhone 的信任設定、移除電腦配對關係或清除 iPhone,也可能讓既有配對檔失效。
Apple 服務與地圖搜尋
LocationLab 使用 Apple MapKit 顯示地圖及搜尋地點。透過 MapKit 送出的請求會依 Apple 適用的條款與隱私政策處理;LocationLab 不會在開發者伺服器另存一份請求。
LocationLab 使用裝置上的本機網路延伸功能建立操作所需的安全本機連線。這不是一般用途 VPN,不會路由、檢查、記錄或修改 Safari 及其他一般 Internet 流量。
路線執行碼
有效 Pro 使用者主動建立路線執行碼時,LocationLab 會把所選路線快照、分享期限、隨機產生的分享識別資料、經 Apple 驗證的訂閱交易資料及 App Attest 安全證明傳送到 LocationLab 的 HTTPS 服務。路線快照會在服務端加密保存;接收者貼入代碼並再次通過 Pro 與安全驗證後,App 才會取得該次執行所需的完整路線。App 不把它加入接收者的一般路線或提供匯出。
分享者可以撤銷代碼;到期或撤銷會阻止新的執行。已合法開始的執行最長可維持 24 小時。分享失效且沒有進行中的執行時,加密路線快照預計於一小時內刪除;若仍有執行,會在最後一次完成、停止或 24 小時期限後一小時內刪除。安全與防重播所需的最小化雜湊、狀態及稽核紀錄可能另依安全需要保存,但不保存可直接使用的分享密碼。
請只執行由可信任測試人員提供、且你有權測試的代碼。App 的執行設定頁提供回報入口,只在電子郵件中加入不可逆的代碼指紋,不附上原始代碼或座標。我們會檢視回報,必要時撤銷分享或停用濫用的分享憑證。
定位權限
只有在使用者要求移回目前位置,或使用目前位置建立路線時,LocationLab 才要求「使用 App 期間」定位權限。輸入座標、搜尋地點或在地圖上選點不需要此權限。
Pairing Assistant
另行提供的 macOS/Windows LocationLab Pairing Assistant,會在使用者授權且接上 USB 的情況下建立裝置專屬配對檔。配對檔及配對密鑰維持在本機,不會傳送給開發者。為支援相容裝置,Assistant 可能使用 Apple 提供的服務取得必要的裝置支援元件;LocationLab 不會藉此接收配對內容或完整 UDID。Windows 試行版只將輸出寫入本機「下載」資料夾。
訂閱與版本檢查
付款由 Apple 處理,App 使用 Apple 提供的交易與訂閱狀態確認 Pro 權限及到期時間,開發者不會取得信用卡資料。免費使用次數保存在裝置上;Sandbox 測試交易不會扣款。版本檢查可能連接 Apple 的商店查詢服務,傳送 App 識別資訊及適用地區,不附上配對檔、收藏或路線。
廣告與隱私選項
含廣告版本的免費使用者可能看到 Google AdMob 廣告;有效 Pro 訂閱不顯示廣告。我們將廣告設為非個人化,並關閉 Publisher first-party ID,但這不等於不處理任何資料。廣告與同意管理 SDK 可能處理 IP 位址及推估的大致地區、裝置識別資訊、廣告與產品互動、當機、效能及其他診斷資料,用於放送與衡量廣告、運作、安全及問題排查。
LocationLab 不會把配對檔、配對密鑰、真實或模擬座標、收藏、搜尋字串或路線內容加入廣告請求。廣告 SDK 的診斷資料與 App 本機詳細活動紀錄不同。我們依適用地區提供同意或退出選項;當 App 顯示「廣告隱私選項」時,可由該入口重新查看或變更選擇。第三方服務的處理與保存另受其政策及你的選擇影響。請參閱 Google 隱私權政策及 Apple 隱私權政策。
匯出、刪除與本機紀錄
你可查看、匯出或刪除已儲存的收藏與一般路線,也可撤銷仍有效的路線執行碼。主動分享的檔案可能包含名稱與座標,由接收者或你選擇的儲存服務處理。刪除 App 不會刪除已匯出的副本、寄出的郵件、仍在期限內的服務端分享或 Apple 交易紀錄;訂閱到期不會自動刪除收藏與路線。
具備新版日誌保存功能的版本,將本機詳細日誌限制為約 1 MB,超限時替換舊內容而不另存輪替副本;這是容量限制而非固定天數期限。清除活動紀錄也會排程刪除本機日誌檔案,後續操作可能產生新紀錄。正式版支援報告不包含該詳細日誌。
網站紀錄
網站在瀏覽器保存中英文顯示偏好。瀏覽網站或下載檔案時,主機及 CDN 等網路傳輸服務會處理 IP、時間、瀏覽器、請求資源與回應狀態等資訊,用於運作、安全及排查問題。這不會讓網站取得 App 內的配對、收藏或路線。
自本次設定更新起,LocationLab 專用的一般存取紀錄以約 30 天為保存目標,每日批次清理,主機可用性及輪替時間可能影響實際刪除時間。此目標不涵蓋既有共用主機紀錄、仍供審查用途的紀錄或 CDN 自身紀錄;這些資料依其用途與適用保存安排另行處理。
支援郵件
若你主動透過電子郵件聯絡支援,我們會收到你的電子郵件地址及你選擇提供的內容,只用於回覆與處理問題。請勿寄送配對檔、配對密鑰、密碼或其他敏感信任資料。
支援資料保存
一般支援郵件採結案後保留 90 天的清理作業目標;重新開案時重新計算。未結案、爭議或必要保存案件另行管理。此流程由信箱管理人執行,郵件供應商的垃圾桶及備份可能有不同刪除時程。你可透過下方信箱提出資料相關請求;我們無法直接存取或代你刪除只保存在你裝置上的資料。
聯絡方式
隱私相關問題請寄至 locationlab.tw@gmail.com。
政策變更
若本政策有重大變更,我們會在相關 App 更新發布前更新本頁與生效日期。
Overview and applicable versions
Pairing records, favorites, and ordinary routes are handled locally on the iPhone by default, and the app itself does not require an account. Data is sent to the service only when the user chooses to use a time-limited Route Execution Code, as described below. Maps and subscriptions use Apple services; versions with ads also use Google AdMob. Feature-specific sections apply only to versions that provide those features.
Data handled on the device
LocationLab may handle the following data locally:
- A device-specific pairing record that the user explicitly imports.
- The iPhone's current location when the user asks to recenter the map or start a route from the current position.
- Favorites, recent coordinates, routes, and GPX files selected by the user.
- Local connection status and diagnostic activity needed to operate and troubleshoot the app.
This data remains in LocationLab's app container by default. LocationLab does not add pairing records or keys, favorites, ordinary routes, GPX contents, or detailed local diagnostics to advertising or analytics requests. A selected route is sent to the service only when the user explicitly uses Route Execution Codes as described below.
Deleting LocationLab removes the data stored in its app container. Resetting iPhone trust settings, removing a computer pairing relationship, or erasing the iPhone may also invalidate a pairing record.
Apple services and map search
LocationLab uses Apple MapKit for map display and place search. Requests made through MapKit are processed by Apple under Apple's applicable terms and privacy policy. LocationLab does not receive or retain a separate server-side copy of those requests.
LocationLab uses an on-device local network extension to establish the secure local connection required for operation. It is not a general-purpose VPN service and does not route, inspect, record, or modify Safari traffic or other general Internet traffic.
Route Execution Codes
When an active Pro user chooses to create a Route Execution Code, LocationLab sends the selected route snapshot, sharing expiry, randomly generated sharing identifiers, Apple-verified subscription transaction data, and App Attest security proof to LocationLab's HTTPS service. The route snapshot is encrypted at rest. After a recipient enters the code and separately passes Pro and security verification, the app receives the complete route needed for that run. It is not added to the recipient's ordinary route library or made available for export.
The sender can revoke a code. Expiry or revocation prevents new runs, while an already authorized run may continue for up to 24 hours. If no run is active, the encrypted snapshot is scheduled for deletion within one hour after expiry or revocation; otherwise it is scheduled within one hour after the final run completes, stops, or reaches its 24-hour limit. Minimal hashes, state, and audit records needed for security and replay prevention may be retained separately, but usable sharing secrets are not stored.
Use only codes supplied by a trusted tester for testing you are authorized to perform. The execution setup screen provides a report link. It adds only a non-reversible code fingerprint to the email, not the original code or coordinates. Reports are reviewed, and we may revoke a share or disable abusive sharing credentials when appropriate.
Location permission
LocationLab requests When In Use location access only when the user asks to recenter the map or start a route from the current position. The permission is not required to enter coordinates, search for a place, or select a point on the map.
Pairing Assistant
The separately distributed LocationLab Pairing Assistant for macOS and Windows creates a device-specific pairing record while the user has authorized and connected the iPhone over USB. Pairing records and pairing keys remain local and are not sent to the developer. To support compatible devices, the assistant may use Apple-provided services to obtain required device-support components; LocationLab does not receive pairing contents or the full UDID through this process. The Windows pilot writes output only to local Downloads.
Subscriptions and update checks
Apple processes payments. The app uses Apple transaction and subscription status to confirm Pro access and expiry; the developer does not receive credit-card details. Free-use counts remain on the device and Sandbox test transactions incur no charge. Update checks may contact Apple's store lookup service with app identification and an applicable region, without pairing records, favorites or routes.
Advertising and privacy choices
Free users of versions with ads may see Google AdMob ads. An active Pro subscription removes ads. We configure ads as non-personalized and disable Publisher first-party ID; this does not mean that no data is processed. Advertising and consent SDKs may process IP addresses and estimated coarse region, device identifiers, ad and product interactions, crash, performance and other diagnostic data for ad delivery and measurement, operation, security and troubleshooting.
LocationLab does not add pairing records or keys, real or simulated coordinates, favorites, search text or route contents to ad requests. Ad SDK diagnostics are distinct from the app's detailed local activity log. Consent or opt-out choices are provided in applicable regions. When the app displays Ad privacy options, use that entry to review or change your choices. Third-party processing and retention also depend on their policies and your choices. See the Google Privacy Policy and Apple Privacy Policy.
Export, deletion and local logs
You can view, export, or delete saved favorites and ordinary routes, and revoke an unexpired Route Execution Code. Shared files may include names and coordinates and are handled by recipients or your chosen storage services. Deleting the app does not delete exported copies, sent emails, unexpired server-side shares, or Apple transaction records. Subscription expiry does not automatically delete favorites or routes.
Versions with the updated log-retention feature cap the detailed local log at approximately 1 MB, replacing old contents when the limit would be exceeded without keeping rotated copies. This is a size limit, not a fixed retention period. Clearing activity logs also schedules deletion of the local log file; subsequent activity may create new entries. Release support reports do not include that detailed log.
Website logs
The website stores your Chinese/English display preference in the browser. Hosting and network delivery services such as a CDN process connection information including IP addresses, times, browser information, requested resources and response status for operation, security and troubleshooting. This does not give the website access to the app's pairing records, favorites or routes.
From this configuration update, dedicated LocationLab general access logs have an approximately 30-day retention target with daily batch cleanup, subject to host availability and rotation timing. This target does not cover historical shared-host logs, records still required for app review, or the CDN's own records, which are handled separately according to their purposes and applicable retention arrangements.
Support email
If you choose to contact support by email, we receive your email address and the content you choose to provide. We use it only to respond to and resolve the issue. Do not send pairing files, pairing keys, passwords, or other sensitive trust material.
Support data retention
General support emails have a cleanup target of 90 days after case closure, recalculated if a case is reopened. Open cases, disputes and necessary preservation are handled separately. The mailbox administrator operates this process; providers may use different trash and backup deletion schedules. Contact the address below for data-related requests. We cannot directly access or delete data stored only on your device.
Contact
Privacy questions may be sent to locationlab.tw@gmail.com.
Changes
Material changes to this policy will be reflected by updating this page and its effective date before the corresponding app update is released.