「宝贝书架」(以下简称“本应用”)由知社管理咨询(北京)有限公司(以下简称“我们”)运营。我们深知儿童及家庭信息的敏感性,本政策说明我们收集哪些信息、为什么收集、如何保护,以及您享有的权利。我们承诺:只收集提供服务所必需的信息,不出售您的个人信息。
| 信息 | 收集场景 | 用途 | 是否必需 |
|---|---|---|---|
| 手机号或邮箱 | 注册 / 登录 / 找回密码 | 创建账号、验证身份 | 必需(二选一) |
| 微信开放标识(OpenID / UnionID)与您授权的头像、昵称 | 您选择使用微信登录时 | 创建或绑定账号、在应用内显示您的头像与昵称 | 可选,仅在您选择微信登录时 |
| 孩子昵称、生日 | 您主动添加孩子档案 | 计算适读年龄、生成阅读计划 | 可选,昵称无需真实姓名 |
| 藏书与阅读记录 | 扫码、打卡 | 书架管理、阅读统计 | 服务核心数据 |
| 您拍摄的照片 | 拍封面识图、拍藏书位置 | 识别图书 / 标记存放位置 | 可选,仅在您主动拍摄时 |
| 设备 IP 地址 | 获取短信 / 邮件验证码时 | 防刷防滥用(频次限制) | 自动收集 |
| 设备名称、系统平台、App 版本、登录 IP | 登录时 | 在设置页的「登录设备」列表中显示,供您认出并远程退出可疑登录 | 自动收集 |
我们不收集:通讯录、精确位置、设备识别码、浏览记录等与服务无关的信息。相机权限仅在您使用扫码 / 拍照功能时调用,图片不会在未经您确认的情况下上传。
1. 本应用面向家长使用。孩子档案(昵称、生日)由您作为监护人自主填写,仅用于本政策第一条所述用途,仅您的家庭成员可见。
2. 我们建议使用昵称而非真实姓名。您可以随时在应用内修改或删除孩子档案。
3. 用于生成图书评估的人工智能不会接收任何孩子的个人信息——评估针对图书本身,全平台共享,与具体儿童无关。书目详情页上「是否适合您的孩子」这类适龄提示,是用评估里的适读年龄区间和孩子生日在您的设备本地比对得出的,不上传。
4. 「阅读计划」是例外:您主动生成阅读计划时,我们会把孩子的年龄(由生日换算,如「5 岁 3 个月」)、您设置的阅读目标与频次、以及家中藏书和阅读记录发送给人工智能服务商,用于排出这一周的书单。孩子的昵称和生日本身不会发送。
1. 数据存储于中华人民共和国境内的服务器。我们不会将您的个人信息传输至境外。
2. 手机号在展示时一律脱敏(如 138****8000),完整号码不下发到任何客户端,家庭成员之间亦不可见。密码以加密散列存储,我们无法获知原文。短信验证码以散列存储且 5 分钟内有效。
3. 您的设备上保留一份本地数据副本以支持离线使用;退出并换账号登录时,本地副本会被清除。
4. 账号注销后,我们将删除您的个人信息;家庭中无其他成员时,家庭数据一并删除。法律法规要求留存的记录(如短信发送日志)在法定期限内保留后删除。
我们不出售个人信息;未经您的单独同意,也不会向第三方提供您的个人信息用于营销。以下场景涉及第三方服务,均为提供服务所必需:
| 第三方 | 提供的信息 | 目的 |
|---|---|---|
| 境内短信服务商 | 手机号 | 发送验证码短信 |
| 邮件服务商 | 邮箱地址 | 发送找回密码验证码 |
| 微信开放平台(腾讯) | 您发起微信登录时由微信客户端处理的授权请求 | 完成微信登录授权 |
| 境内已备案的大模型服务商 | 图书信息(书名 / ISBN / 封面图);生成阅读计划时另有孩子年龄、阅读目标与频次、藏书与阅读记录 | 生成图书评估、识别封面、制定阅读计划 |
图书评估与封面识别只提供图书相关信息,不含任何个人信息;您拍摄的封面照片仅用于识别该图书。只有您主动生成阅读计划时,才会额外提供第二条第 4 项列出的那几项,其中不含姓名、昵称、生日、手机号等可直接识别到个人的信息。
依照《个人信息保护法》,您有权:
1. 查阅、更正:孩子档案、阅读记录等均可在应用内直接查看和修改。
2. 删除:可在应用内删除任何一条记录、任何一个孩子档案。
3. 注销账号:通过应用内入口或联系我们注销,我们将在 15 个工作日内完成删除。
4. 撤回同意:可随时停止使用相机等权限(在系统设置中关闭),不影响已提供服务的效力。若您使用微信登录,可在微信「设置 → 隐私 → 授权管理」中解除授权。
行使上述权利如需协助,请通过第七条方式联系我们。
本政策变更时,我们会更新页首的版本号,重大变更会在应用内显著提示。持续使用即表示同意修订后的政策。
个人信息保护相关的疑问、意见或投诉,请联系:
邮箱:raphael.xiao@gmail.com
我们将在 15 个工作日内答复。
KidShelf (宝贝书架, “the App”) is operated by 知社管理咨询(北京)有限公司 (“we”, “us”). We know how sensitive family and children's data is. This policy explains what we collect, why, how we protect it, and what rights you have. Our commitment: we collect only what the service needs, and we never sell your personal information.
| Data | When | Why | Required? |
|---|---|---|---|
| Phone number or email | Sign-up / sign-in / password reset | Creating your account, verifying identity | Yes (either one) |
| WeChat OpenID / UnionID, plus the avatar and nickname you authorise | Only if you choose to sign in with WeChat | Creating or linking your account; showing your avatar and nickname inside the App | Optional, only with WeChat sign-in |
| Child nickname and birthday | When you add a child profile | Age-fit matching, generating reading plans | Optional; a real name is never required |
| Books and reading logs | Scanning, check-ins | Bookshelf management, reading statistics | Core service data |
| Photos you take | Cover recognition, shelf-location photos | Identifying a book / marking where it is kept | Optional, only when you take them |
| Device IP address | When requesting an SMS or email verification code | Rate-limiting and abuse prevention | Collected automatically |
| Device name, platform, app version, sign-in IP | When you sign in | Shown in the “Signed-in devices” list in Settings so you can recognise and remotely sign out a suspicious session | Collected automatically |
We do not collect contacts, precise location, advertising identifiers, browsing history, or anything else unrelated to the service. The camera is used only when you actively scan or take a photo, and no image is uploaded without your confirmation.
1. The App is designed to be used by parents. Child profiles (nickname, birthday) are entered by you as the guardian, at your discretion, are used only for the purposes in Section 1, and are visible only to members of your family.
2. We recommend using a nickname rather than a real name. You can edit or delete a child profile at any time in the App.
3. The AI that generates book insights never receives any child's personal information: insights describe the book itself, are shared platform-wide, and are not tied to any individual child. The age-fit hint on a book's detail page (“is this right for my child”) is computed locally on your device, by comparing the insight's suitable-age range against your child's birthday. Nothing is uploaded for it.
4. Reading plans are the exception. When you generate a reading plan, we send the AI provider your child's age (derived from the birthday, e.g. “5 years 3 months”), the reading goals and frequency you set, and the books you own together with their reading history, so it can lay out the week. Your child's nickname and birthday itself are not sent.
1. Data is stored on servers located within the People's Republic of China. We do not transfer your personal information outside mainland China.
2. Phone numbers are always masked when displayed (e.g. 138****8000); the full number is never sent to any client and is not visible to other family members. Passwords are stored as salted hashes and cannot be read by us. Verification codes are stored hashed and expire within 5 minutes.
3. Your device keeps a local copy of your data so the App works offline. That copy is cleared when you sign out and sign in with a different account.
4. When you delete your account we delete your personal information; if no other member remains in the family, the family's data is deleted with it. Records we are legally required to retain (such as SMS delivery logs) are deleted once the statutory period ends.
We do not sell personal information, and we will not provide it to third parties for marketing without your separate consent. The following processors are used, each only as far as the service requires:
| Third party | Data | Purpose |
|---|---|---|
| SMS provider (in mainland China) | Phone number | Sending verification codes |
| Email provider | Email address | Sending password-reset codes |
| WeChat Open Platform (Tencent) | The authorisation request handled by the WeChat client when you start WeChat sign-in | Completing WeChat sign-in |
| AI provider (a large-language-model service filed in mainland China) | Book information (title / ISBN / cover image); for reading plans, additionally the child's age, reading goals and frequency, and the books owned with their reading history | Generating book insights, cover recognition, building reading plans |
For book insights and cover recognition, what reaches the AI provider is book information only, with no personal information at all; a cover photo you take is used solely to identify that book. Only when you generate a reading plan do we send the additional items listed in Section 2.4 — which contain no name, nickname, birthday, phone number or anything else that identifies a person directly.
Under the PIPL you have the right to:
1. Access and correct — child profiles, reading logs and everything else can be viewed and edited directly in the App.
2. Delete — you can delete any individual record or any child profile in the App.
3. Delete your account — through the in-app option or by contacting us; we complete deletion within 15 business days.
4. Withdraw consent — you can revoke permissions such as the camera at any time in your device settings, without affecting the lawfulness of processing before withdrawal. If you use WeChat sign-in, you can revoke it in WeChat under Settings → Privacy → Authorisation Management.
If you need help exercising any of these rights, contact us using Section 7.
When this policy changes we update the version at the top of the page, and material changes are announced prominently in the App. Continued use means you accept the revised policy.
For questions, comments or complaints about personal information protection:
Email: raphael.xiao@gmail.com
We respond within 15 business days.