隐私政策
更新日期:2026-09-30 · 本政策适用于 the-almanac-of-you 站点
一、计算在本地,服务器只是档案柜
排盘与黄历计算全部在你的浏览器内完成(纯确定性代码,无大模型调用)。服务器 只保存你主动输入的出生信息(姓名选填、公历年月日时分、性别、时区/经度等选项), 不保存排盘结果——命盘每次都由你的浏览器重新计算。不登录使用时,数据不离开你的设备。
二、登录时我们从 Google 拿到什么
- 邮箱地址、显示昵称、头像链接,以及 Google 侧的用户标识。
- 我们不接触、也无法获得你的 Google 密码;授权随时可在你的 Google 账号设置中撤销。
三、Cookie 与登录时的机器人检查
-
almanac_session:登录会话凭证(HttpOnly、Secure、SameSite=Lax,有效期 30 天)。 oauth_flow:登录跳转期间的一次性防 CSRF 凭证,10 分钟自动过期。- 登录入口使用 Cloudflare Turnstile 做机器人检查:它会加载 Cloudflare 的验证脚本并可能写入仅用于防机器人的 Cookie。这不是跟踪或分析用途。
- 没有广告,没有第三方分析脚本,不做跨站跟踪。
四、数据存在哪里
数据存放在 Cloudflare D1(SQLite 数据库)中,位于离你最近的 Cloudflare 边缘网络并全球复制。这是零成本架构的一部分,没有独立的异地备份。
五、谁能看到你的数据
除你本人登录之后,不会有任何其他人通过产品界面看到你的存档;我们不会向第三方出售或共享你的数据。 仅在安全或法律所必需时,站点运营者才可能直接访问数据库。
六、订阅邮件默认不勾选
登录后的订阅邀请默认关闭。勾选与否不改变你获得的功能;勾选目前仅代表意愿标记, 本站尚未开通任何营销邮件发送。
七、你的权利:随时、自助
- 退出所有设备:账号菜单一键让此前签发的全部登录凭证立即失效(例如在网吧登录过之后)。
- 删除我的账户:账号菜单内两步确认后,你的用户记录与全部出生档案立即从数据库删除 (级联清空),不可恢复;旧登录凭证永久失效。
- 删除单份存档:「我的历书」列表内直接删除。
八、第一方统计(自建埋点)的范围
本站使用自建的第一方统计记录产品事件(如生成日历、购买、导出), 不引入任何第三方分析脚本,也不从任何外部 CDN 加载资源。其口径如下:
- 浏览器侧的会话标识存放在 sessionStorage(不是 Cookie),关闭标签页即失效,不用于跨会话跟踪。
-
不记录 IP 地址:只保留 Cloudflare
提供给你的大致国家/地区(
request.cf.country)。 - 事件明细保留 13 个月后滚动删除;按月的聚合计数长期保留——聚合数字无法还原到任何个人。
- 完成 Google 登录后,此后产生的事件会与你的账号关联(用于回答「这一单来自哪里」与权益对账); 未登录时的浏览与使用不关联任何身份。删除账户时,关联事件一并处理。
Privacy Policy
Updated: 2026-09-30 · Applies to the the-almanac-of-you site
1. Computation is local; the server is just a filing cabinet
Chart and almanac computation happens entirely in your browser (pure deterministic code, no LLM calls). The server stores only the birth information you enter (optional name, solar date/time, gender, timezone/longitude options) and never stores computed chart results — your chart is recalculated locally every time. If you use the site without signing in, nothing leaves your device.
2. What we receive from Google at sign-in
- Your email address, display name, avatar URL, and a Google-side user identifier.
- We never see your Google password, and you can revoke the authorization anytime in your Google account settings.
3. Cookies and the bot check at sign-in
-
almanac_session: your sign-in credential (HttpOnly, Secure, SameSite=Lax, 30-day lifetime). -
oauth_flow: a one-time CSRF-protection value during the sign-in redirect, expiring in 10 minutes. - Sign-in is protected by Cloudflare Turnstile, a bot check: it loads Cloudflare's verification script and may set bot-protection cookies. It is not used for tracking or analytics.
- No ads, no third-party analytics scripts, no cross-site tracking.
4. Where your data lives
Data is stored in Cloudflare D1 (a SQLite database) on Cloudflare's edge network, globally replicated. This is part of a zero-cost architecture; there is no separate off-network backup.
5. Who can see your data
No one other than you (while signed in) can view your saved charts through the product. We do not sell or share your data with third parties. The site operator may access the database directly only where required for security or legal reasons.
6. Newsletter opt-in is off by default
The post-sign-in newsletter invitation is unchecked by default. Your choice does not change any functionality; for now an opt-in is only a preference flag — no marketing emails are sent by this site.
7. Your rights: self-service, anytime
- Sign out of all devices: one click in the account menu immediately invalidates every session credential issued before it (e.g. after logging in at an internet café).
- Delete my account: after a two-step confirmation in the account menu, your user record and all saved birth profiles are deleted from the database immediately (cascaded) and irreversibly; old session cookies stop working permanently.
- Delete a single saved chart from the "My almanacs" list.
8. First-party product analytics
This site uses its own first-party analytics to record product events (chart generated, purchase, export). No third-party analytics scripts run here, and nothing loads from external CDNs. Specifically:
- The browser-side session identifier lives in sessionStorage (not a cookie) and dies when the tab closes; it is not used for cross-session tracking.
-
IP addresses are never stored: only the coarse country provided by
Cloudflare (
request.cf.country) is kept. - Event details are deleted on a rolling 13-month basis; monthly aggregate counts are kept long-term — aggregates cannot be traced back to any individual.
- After you sign in with Google, events produced from then on are linked to your account (to answer "where did this order come from" and for entitlement reconciliation). Browsing and usage while signed out are not linked to any identity. Deleting your account also handles the linked events.