隐私政策 / Privacy Policy

更新及生效日期:2026 年 9 月 13 日。适用于 play.whatonearth.work 上由一探究竟视频工作室运营的探帧视频管理与审阅服务。联系:billzhuang@woe.show。

Effective September 13, 2026. This policy covers TanFrame at play.whatonearth.work, operated by WOE Video Studio (一探究竟视频工作室). Contact: billzhuang@woe.show.

1. 处理哪些信息 / Information we process

账户信息包括邮箱、显示名称、您上传的头像、加密哈希后的密码(若设置)、账户状态及登录身份标识。使用服务时,我们处理您上传的视频、图片、音频、文件名、媒体元数据、评论、绘图、附件、分享设置和操作记录。游客发表评论时提供的名称及邮箱(如填写)也会用于识别评论作者。运行及安全日志可能包含 IP 地址、请求时间、请求标识、浏览器信息及错误信息。

We process account email, display name, uploaded avatar, password hash if a password is set, account status and sign-in identifiers. Service data includes uploaded media, filenames, metadata, comments, annotations, attachments, sharing settings and activity records. Guest names and optional email identify comment authors. Operational and security logs may include IP address, request time and identifiers, browser information and errors.

2. Google 登录 / Google Sign-In

Google 登录是可选方式。经您授权,我们请求 openid、email、profile,用于核验身份、创建或绑定探帧账户。我们使用 Google 的稳定用户标识、已验证邮箱及名称;profile 授权可能返回头像地址,但当前登录实现不将 Google 头像自动写入个人资料。我们不请求读取 Gmail、Google Drive、联系人或日历。Google 令牌仅用于登录校验,不持久保存为第三方访问凭证;本站登录会话与 Google 授权分开管理。

Google Sign-In is optional. With your authorization we request openid, email and profile to verify your identity and create or link your TanFrame account. We use your Google subject identifier, verified email and name. Profile authorization may return an avatar URL; the current sign-in implementation does not automatically store it as your profile avatar. We do not request Gmail, Drive, contacts or calendar access. Google tokens are used for sign-in verification and are not persisted as third-party access credentials. TanFrame maintains its own login session.

Google 身份数据仅用于上述登录、账号管理及必要安全保障,不用于广告、出售数据、信用评估或训练通用 AI 模型。探帧对 Google API 信息的使用和转移遵守 Google API Services User Data Policy,包括适用的 Limited Use 要求。

Google identity data is used only for these sign-in, account-management and necessary security purposes, not advertising, data sales, credit assessment or training general-purpose AI models. TanFrame’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including applicable Limited Use requirements.

3. 用途与可见范围 / Purpose and visibility

我们使用信息提供上传、转码、播放、审阅、协作、身份认证、容量统计、故障排查与安全防护。协作者及分享链接访问者可按照项目与分享设置查看素材和评论,包括评论作者的显示名称或头像。获得分享链接的人可能转发链接;请只分享您有权披露的内容,不要把分享链接视为绝对保密措施。

We use information to provide uploads, processing, playback, reviews, collaboration, authentication, storage accounting, troubleshooting and security. Collaborators and share-link visitors can view content and comments according to project and sharing settings, including authors’ display names or avatars. Recipients may forward links; only share material you are authorized to disclose.

4. 存储、服务商与跨境连接 / Storage and providers

当前部署的应用数据库及阿里云对象存储位于中国大陆,云端媒体处理使用阿里云服务。Google 登录会连接 Google;相关认证请求通过美国网络出口转发,Google 接口的 HTTPS 加密保持开启。出口服务可能处理连接目的地、时间与流量等网络元数据,视频素材不会因为 Google 登录而发送给 Google 或该出口。您也可以选择邮箱或飞书登录(以站点开放情况为准)。

The current application database and Alibaba Cloud object storage are hosted in mainland China; cloud media processing uses Alibaba Cloud. Google authentication connects to Google through a US network egress while retaining HTTPS encryption. The egress service may process connection destinations, timing and traffic metadata. Video content is not sent to Google or that egress as part of Google sign-in. Email or Feishu sign-in may also be available.

使用飞书登录时,我们处理飞书返回的身份信息;您主动导出飞书文档时,评论、作者显示信息、静帧及批注、附件引用和审阅链接会发送到配置的飞书应用与文档空间。飞书文档随后适用飞书侧的共享设置,撤销探帧链接不会自动撤销已生成文档。邮件服务商在发送验证码、邀请或通知时处理收件地址与邮件内容。管理员仅应在运营、支持、安全或适用法律所需范围内访问数据。

Feishu sign-in processes identity information returned by Feishu. When you request a Feishu document export, comments, displayed author information, annotated frames, attachment references and the review link are sent to the configured Feishu application and document space. Feishu permissions then govern that document; revoking a TanFrame link does not automatically revoke an exported document. Email providers process recipient addresses and message content for codes, invitations and notifications. Administrator access should be limited to necessary operations, support, security or applicable legal obligations.

5. Cookie、保存与删除 / Cookies, retention and deletion

我们使用必要的 Cookie、浏览器本地存储及短期服务端记录维持登录、保护授权流程、保存语言偏好及游客评论归属。当前没有为 Google 登录使用广告追踪 Cookie。登录会话按服务器配置过期,退出后需重新认证。

Necessary cookies, browser storage and short-lived server records maintain sessions, protect authorization flows, retain language preferences and identify guest comment ownership. Google sign-in does not use advertising-tracking cookies. Sessions expire according to server settings; signing out requires authentication again.

账户及业务数据在提供服务所需期间保存。删除通常先标记为已删除,之后按站点清理策略处理;备份或必要安全记录可能保留更久,不承诺点击删除后立即从所有副本消失。您可修改个人资料、删除权限范围内的内容,或通过联系邮箱申请访问、更正、导出、删除个人数据及关闭账户。我们会核实身份、说明处理结果及必要保留范围;团队共同拥有的素材需与项目管理员协调。

We retain account and service data as needed to provide the service. Deletion generally starts with a soft-delete and later follows site cleanup policies; backups and necessary security records may persist longer. Deletion is not an immediate erasure of every copy. You may edit your profile, delete content within your permissions, or contact us to request access, correction, export, deletion or account closure. We verify identity, explain outcomes and any necessary retention, and coordinate shared team content with project administrators.

您可在 Google 账号连接设置撤销 Google 授权。撤销授权不等于删除探帧账户或已有本站会话;如需移除绑定或删除数据,请退出本站并联系我们。为避免无法登录,请先确保存在另一种可用登录方式。

You can revoke Google authorization in your Google Account connections. Revocation is not deletion of your TanFrame account or existing local sessions. To remove the link or delete data, sign out and contact us. Ensure another sign-in method is available before removing access.

6. 安全与政策更新 / Security and updates

我们采用 HTTPS、访问控制、密码哈希和受限凭据配置等措施,但不承诺绝对安全。请妥善保管账户、API Key、分享链接和机器人凭据。服务面向视频制作与审阅协作,不面向儿童。如发现安全问题或儿童个人信息,请联系我们。信息用途发生重要变化时,我们会更新本页及相关产品提示;需要重新授权的 Google 数据用途将在取得授权后启用。

We use safeguards including HTTPS, access controls, password hashing and restricted credentials, without promising absolute security. Protect your account, API keys, share links and bot credentials. This service is for video-production collaboration, not directed to children. Contact us about security issues or children’s data. Material changes will be reflected here and in relevant product notices; new uses of Google data requiring authorization will not start before that authorization.