隐私政策
更新日期:2026 年 10 月 2 日
CoreWatcher("我们")提供安全的运维控制台服务。本政策说明我们收集哪些数据、如何使用与保护这些数据。
1. 我们收集的信息
- 账号信息:用户名、显示名称、角色。
- 登录与安全记录:登录时间与结果、IP 地址的哈希值、浏览器标识(User-Agent)的哈希值。
- 设备信息:设备绑定公钥与设备标识、设备型号、操作系统版本、App 版本。
- 通行密钥(Passkey):你注册时生成的公钥(私钥始终保存在你设备的芯片中,我们无法获取)。
- 操作审计日志:在你账号下发生的操作事件与安全事件。
2. 我们不收集的信息
- 明文密码(系统仅保存不可逆的密码哈希)。
- 明文 IP 地址(仅保存哈希用于安全审计)。
- 通讯录、短信、相册、位置、麦克风、摄像头等个人数据;我们的移动 App 仅申请网络访问权限。
3. 信息的使用方式
- 验证你的身份、执行设备绑定与访问控制。
- 安全审计、异常检测与故障排查。
- 改进服务的稳定性与安全性。
4. 数据共享
我们不出售、不出租、不向第三方共享你的数据,法律法规另有强制要求的除外。
5. 数据存储与保留
数据存储于我们自有的服务器(AWS 东南亚区域,服务端全链路加密传输)。会话数据在到期后自动失效;审计与登录记录按运营与安全需要保留,并可应你要求删除。
6. 你的权利
你可以随时要求查询、更正或删除你的账号数据,或撤销设备与通行密钥绑定(控制台内可直接操作)。
7. 儿童
本服务面向企业运营与管理人员,不面向 13 岁以下的儿童。
8. 政策变更
如本政策发生重大变更,我们会在控制台内显著提示。
9. 联系我们
隐私相关咨询请联系:support@corewatcher.app
Privacy Policy
Last updated: October 2, 2026
CoreWatcher ("we") provides a secure operations console. This policy explains what data we collect and how we use and protect it.
1. Information We Collect
- Account data: username, display name, role.
- Login and security records: sign-in time and result, hashed IP address, hashed browser identifier (User-Agent).
- Device data: device binding public key and device identifier, device model, OS version, app version.
- Passkeys: the public key created when you register (the private key never leaves your device's secure hardware and is never accessible to us).
- Audit logs: operational and security events under your account.
2. Information We Never Collect
- Plain-text passwords (only irreversible password hashes are stored).
- Plain-text IP addresses (only hashes are stored, for security auditing).
- Contacts, messages, photos, location, microphone or camera data; our mobile app requests network access only.
3. How We Use Information
- To authenticate you and enforce device binding and access control.
- For security auditing, anomaly detection and troubleshooting.
- To improve the stability and security of the service.
4. Data Sharing
We do not sell, rent or share your data with third parties, except where required by law.
5. Storage and Retention
Data is stored on our own servers (AWS Southeast Asia region) and transmitted over encrypted connections. Sessions expire automatically; audit and login records are retained as needed for operations and security, and can be deleted on request.
6. Your Rights
You may request access, correction or deletion of your account data, and you can revoke device or passkey bindings directly in the console.
7. Children
The service is intended for business operations personnel and is not directed to children under 13.
8. Changes
Material changes to this policy will be highlighted in the console.
9. Contact
Privacy inquiries: support@corewatcher.app