SURFBOUNDKEEP SURFING

PRIVACY POLICY · 隱私政策

你的衝浪紀錄,
屬於你。

基本功能不需要帳號;浪人社群需要以 Apple 登入。我們不販售你的資料。

繁體中文

SurfBound 隱私政策(繁體中文)

最後更新:2026-10-02

我們的原則

基本功能不需要帳號;浪人社群需要以 Apple 登入。你的衝浪紀錄屬於你。

收集與儲存的資料

  • 健康與健身資料(心率、卡路里、workout 與體能統計):由 Apple HealthKit 管理,並儲存在你的裝置與你的 iCloud。
  • 精確位置資料(GPS 軌跡、浪點提醒的地理圍欄):儲存在你的裝置;軌跡隨 session 紀錄保存在你的裝置與 iCloud 備份中。
  • 其他資料(50 Hz 加速度計/陀螺儀動作感測 CSV):session 期間記錄,儲存在你的裝置。
  • 其他使用資料(偵測參數、浪點名稱):隨 session 儲存在你的裝置。
  • 手機的動作與健身活動歷史:app 只會在每一場衝浪 session 的時間範圍內於裝置上查詢,用來辨識開車時段並修正誤判的浪。app 僅暫時取出開車區間的起訖時間,用完即丟;原始活動資料不會儲存或上傳。拒絕這項權限不影響其他功能,只會停用這項自動修正。
  • Garmin 來源的 session:若你連結 Garmin 手錶使用 SurfBound,app 會接收該手錶記錄的衝浪 session,包括浪數、乘浪軌跡片段、速度與時長。

未啟用「分享資料改進偵測」時,以上資料不會上傳至我們的 CloudKit 測試資料庫。

選擇性分享(可隨時關閉)

啟用 app 設定分頁的「分享資料改進偵測」時(首次啟動時明確揭露),上傳內容包括 session 統計與標註修正(其中可能包含偵測參數與浪點名稱)、精確位置資料(GPS 軌跡),以及其他資料(50 Hz 動作感測紀錄)。上傳內容不包含心率、卡路里或其他 HealthKit 健康與健身資料。這些資料用於 App 功能與分析,且僅限改進浪數偵測演算法。

如果本機活動歷史判定某些浪發生在開車時段,上傳的只有「浪被標記為行車」這項衍生結果,並歸在既有的 session 統計與標註修正中;手機的原始活動歷史與開車區間起訖時間不會上傳。這項衍生結果同樣受「分享資料改進偵測」開關控制。

若你連結 Garmin 手錶使用 SurfBound,該手錶記錄的浪數、乘浪軌跡片段、速度與時長同樣依「分享資料改進偵測」開關決定是否分享給開發者,用途同樣僅限改進浪的偵測。Garmin session 的上傳內容不包含心率、卡路里或其他健康與健身資料。

Garmin 來源的資料與 Apple Watch 來源分開儲存與分析,不會用其中一種來校正另一種。

上傳紀錄會與你的 iCloud 識別碼關聯,因此同一使用者的紀錄可以彼此連結,但不包含你的姓名或 email。我們不會將這些資料用於廣告、販售或跨 app/網站追蹤。

你可以隨時在 app 設定分頁關閉「分享資料改進偵測」;關閉後不再上傳新資料。

浪人社群(測試中)

浪人社群目前只在 TestFlight 測試中,需以 Apple 登入。社群資料由 Cloudflare 上的 SurfBound 社群伺服器處理,正式服務網域為 api.surfbound.app。登入不要求提供姓名或 email,社群伺服器不保存 email;我們使用 Apple 提供的帳號識別碼與社群使用者識別碼維持帳號及登入狀態,並保存你設定的暱稱、代號、自我介紹與提供的個人頁資料。這些資料與你的社群帳號關聯。

你逐場選擇「分享給浪人朋友」時,會送出該場日期時間與時區、紀錄來源,以及你選擇分享的時長、浪點名稱、浪數、最遠一道浪距離、最高浪速或浪況資料。有路線的紀錄可包含簡化後的路線與乘浪區段;不會送出完整 GPS 時序、速度序列、心率、卡路里、原始動作感測紀錄或私人備註。

從 Apple 健康匯入時,若來源提供路線,app 會讀取路線,並與匯入紀錄一起保存在你的裝置與你自己的 iCloud,不會上傳到 SurfBound 的研究資料庫。只有你選擇分享到浪人社群時,才會送出該場的日期時間、時長、浪點,以及你自行填寫的體感浪數與當天浪況(有填寫時)。日期時間與時長屬於 Apple 健康衍生資料;社群分享不包含路線、心率或卡路里。

分享預設只供你與已核准的追蹤者查看。若開啟「公開我的動態」,所有浪人都能查看你的分享,分享也會出現在大家的動態牆上,包括你分享的浪點名稱與路線。個人頁的暱稱、自我介紹及提供的個人資料可能對其他登入使用者可見;設定代號後會有可對外分享的連結,公開帳號的連結頁也會顯示暱稱。封鎖限制優先於公開設定。

我們保存分享文字(最多 500 字,可被檢舉)、分享下的留言、提及、shaka 與追蹤請求/關係,用於顯示互動及通知。可查看該分享的人也能看到留言與 shaka 名單(含暱稱);封鎖會限制彼此內容的可見性。檢舉會送出檢舉對象、理由與你提供的補充文字;我們保存檢舉與封鎖資料,用於處理不當內容與執行封鎖。

為提供社群推播,我們會保存與帳號關聯的推播 token、推播服務/環境,以及 app 安裝時產生的隨機裝置識別碼;後者不是硬體識別碼。推播可能包含互動者暱稱與相關分享、留言識別碼。登出或刪除帳號時,伺服器會清除相應推播登記。

你可在「浪人」→ 右上角「你的帳號」→「我的分享」向左滑動該筆紀錄,選「撤回」。撤回後,伺服器不再提供該分享,路線、統計及相關互動會清除,無法復原;想再次分享需要重新發佈。刪除已分享的本機紀錄也會啟動撤回,需由伺服器完成處理。你也能刪除自己的留言,分享作者可刪除該分享下的留言。

你可在「浪人」→ 右上角「你的帳號」選「刪除帳號」,依畫面輸入暱稱確認(有暱稱時)。伺服器受理後會立即撤回所有分享、移除追蹤關係並撤銷登入狀態,其餘清理由背景工作完成。只登出、刪除 app 或在 Apple 設定撤銷登入授權,不等於刪除社群帳號。

浪人社群與「分享資料改進偵測」是不同的資料用途與管線;關閉研究資料分享不會撤回已發佈的社群內容。社群資料用於帳號、分享、互動、通知與內容管理,不用於廣告或販售。

第三方服務(Garmin Connect)

Garmin session 從手錶傳到 iPhone 時,會經由你自己安裝並使用的 Garmin Connect app 中繼。SurfBound 不會與 Garmin 交換任何資料,也無法取得你的 Garmin 帳號。

分析工具(Google Analytics for Firebase)

SurfBound 使用 Google Analytics for Firebase 收集使用行為,包括畫面瀏覽、功能使用次數、裝置型號與 app 版本,用於改善產品。

這項分析不包含姓名、Email、健康資料(包括心率與卡路里)、GPS 座標或 session 內容;分析資料與用於改進衝浪偵測的 CloudKit 測試資料是兩條獨立管線。

資料由 Google 依其隱私條款處理。詳情請參閱 Google Analytics for Firebase 隱私資訊。

Garmin 早期測試者登記

當你自願登記 Garmin 早期測試時,我們會收集 Email、Garmin 錶款,以及你選擇提供的 SurfBound 支援代碼與 LINE ID。支援代碼是由 iCloud 識別碼衍生的識別碼。

這些資料只用於 Garmin 測試聯絡、寄送 TestFlight 邀請與提供安裝說明,儲存在受控的測試者名單中,不會出現在公開頁面或 URL。為寄送 TestFlight 邀請,我們會將你登記的 Email 提供給 Apple App Store Connect/TestFlight,由 Apple 依其隱私政策處理;Garmin 錶款、支援代碼與 LINE ID 不會提供給 Apple。你可以寄信至下方聯絡信箱要求刪除登記資料。

資料保留與刪除

當你在 app 內刪除 session 紀錄時,對應的雲端資料會標記為已刪除,並排除於後續分析。若希望將先前上傳的資料從 CloudKit 完整刪除,請寄信至下方聯絡信箱提出要求。

我們不做的事

  • 不販售、不出租你的任何資料
  • 不追蹤你跨 app 或跨網站的行為
  • 不投放廣告
  • 基本功能不要求註冊帳號

訂閱

付費由 Apple App Store 處理,我們不接觸你的付款資訊。

聯絡

keepsurfing@surfbound.app

English

SurfBound Privacy Policy (English)

Last updated: 2026-10-02

Our principle

Basic features require no account; the community requires Sign in with Apple. Your surf data is yours.

Data we collect and where it lives

  • Health and fitness data (heart rate, calories, workouts, and fitness statistics) is managed by Apple HealthKit and stored on your devices and in your iCloud.
  • Precise location data (GPS tracks and geofenced spot reminders) is stored on your device; tracks are kept with your session records on your devices and in your iCloud backup.
  • Other data (50 Hz accelerometer/gyroscope motion CSV files) is recorded during sessions and stored on your device.
  • Other usage data (detection parameters and surf spot names) is stored with sessions on your device.
  • Motion and fitness activity history from your phone is queried on-device only within the time range of each surf session, solely to identify driving intervals and correct waves detected by mistake. The app temporarily extracts only the start and end times of driving intervals, then discards them; the raw activity data is neither stored nor uploaded. Denying this permission does not affect other features and only disables this automatic correction.
  • Garmin-source sessions: if you link a Garmin watch to SurfBound, the app receives surf sessions recorded by that watch, including wave count, ride-track segments, speed, and duration.

When "Share data to improve detection" is not enabled, this data is not uploaded to our CloudKit test database.

Optional sharing (can be turned off at any time)

When "Share data to improve detection" is enabled from the app's settings (disclosed at first launch), uploaded content includes session statistics and labeling corrections (which may include detection parameters and surf spot names), precise location data (GPS tracks), and other data (50 Hz motion recordings). Uploaded content does not include heart rate, calories, or other HealthKit health and fitness data. This data is used for app functionality and analytics, solely to improve the wave-detection algorithm.

If on-device activity history identifies waves that occurred while driving, only the derived result that those waves were marked as driving may be uploaded as part of the existing session statistics and labeling corrections. Raw phone activity history and the start and end times of driving intervals are not uploaded. This derived result is also controlled by the "Share data to improve detection" setting.

If you link a Garmin watch to SurfBound, the wave count, ride-track segments, speed, and duration recorded by that watch are also shared with the developer only when "Share data to improve detection" is enabled, and solely to improve wave detection. Uploaded Garmin-session content does not include heart rate, calories, or other health and fitness data.

Garmin-source data and Apple Watch-source data are stored and analyzed separately. Neither source is used to calibrate the other.

Uploaded records are associated with your iCloud identifier, so records from the same user can be linked, but they do not contain your name or email. We do not use this data for advertising, sell it, or track you across apps or websites.

You can turn off "Share data to improve detection" at any time from the app's settings. No new data is uploaded after it is turned off.

Community (in testing)

Lineup is currently in TestFlight testing and requires Sign in with Apple. Community data is processed by SurfBound's community server on Cloudflare; the production service domain is api.surfbound.app. Sign-in does not request your name or email, and the community server does not store email addresses. We use the account identifier provided by Apple and a community user identifier to maintain your account and sign-in sessions. We store the nickname, handle, bio, and profile information you provide, linked to your community account.

When you choose to share an individual session, we send its date and time, time-zone offset, recording source, and the duration, spot name, wave count, longest ride distance, maximum ride speed, or surf conditions you choose to share. Sessions with a route may include a simplified route and ride segments. We do not send full timestamped GPS data, speed sequences, heart rate, calories, raw motion recordings, or private notes.

When importing from Apple Health, the app reads a route if the source provides one and stores it with the imported session on your devices and in your own iCloud, not in SurfBound's research database. Only when you choose to share the session to the community do we send its date and time, duration, spot name, and any wave count and surf conditions you entered yourself. The date and time and duration are derived from Apple Health. Community sharing does not include routes, heart rate, or calories.

By default, shares are visible only to you and your approved followers. Enabling “Public activity” makes your shares visible to everyone on Lineup and places them in everyone's feed, including any spot name and route you share. Your nickname, bio, and provided profile information may be visible to other signed-in users. Setting a handle creates an externally shareable link; the link page for a public account also displays its nickname. Blocking takes precedence over public visibility.

We store share captions (up to 500 characters, which can be reported), comments, mentions, shakas, and follow requests and relationships to display interactions and notifications. People who can view a share can also see its comments and shaka list, including nicknames, subject to blocking restrictions. Reports send the target, reason, and any note you provide. We store reports and blocks to handle inappropriate content and enforce blocking.

For community push notifications, we store an account-linked push token, provider and environment, and a random identifier generated for the app installation—not a hardware identifier. Notifications may include the interacting user's nickname and related share or comment identifiers. The server clears the corresponding push registration when you sign out or delete your account.

To withdraw a share, open Lineup → Your account → My shares, swipe left on the session, and select Withdraw. The server stops serving the share and clears its route, statistics, and associated interactions. Withdrawal cannot be undone; sharing again creates a new post. Deleting a shared local session also starts withdrawal, which must be completed by the server. You can delete your own comments, and a share's author can delete comments on that share.

To delete your community account, open Lineup → Your account → Delete Account. Confirm by entering your nickname when prompted. Once accepted, the server immediately withdraws all shares, removes follow relationships, and revokes sign-in sessions; remaining cleanup runs in the background. Signing out, deleting the app, or revoking Sign in with Apple in Apple settings does not by itself delete your community account.

Community sharing and Share data to improve detection serve separate purposes and use separate pipelines. Turning off research-data sharing does not withdraw community posts. Community data is used for accounts, sharing, interactions, notifications, and moderation—not advertising or sale.

Third-party service (Garmin Connect)

When a Garmin session moves from your watch to your iPhone, it is relayed through the Garmin Connect app that you install and use. SurfBound does not exchange any data with Garmin and cannot access your Garmin account.

Analytics (Google Analytics for Firebase)

SurfBound uses Google Analytics for Firebase to collect usage behavior, including screen views, feature-use counts, device model, and app version, to improve the product.

This analytics data does not include your name, email, health data (including heart rate or calories), GPS coordinates, or session content. Analytics data and the CloudKit test data used to improve surf detection are handled through separate pipelines.

Google processes this data under its privacy terms. See Google Analytics for Firebase privacy information for details.

Garmin early tester registration

When you voluntarily register for Garmin early testing, we collect your email address and Garmin watch model, plus a SurfBound support code and LINE ID if you choose to provide them. The support code is an identifier derived from your iCloud identifier.

We use this data only to contact Garmin testers, send TestFlight invitations, and provide installation instructions. It is stored in a controlled tester list and is never published on a public page or URL. To send a TestFlight invitation, we provide your registered email address to Apple App Store Connect/TestFlight, where Apple processes it under its privacy policy; your Garmin watch model, support code, and LINE ID are not provided to Apple. You may email the contact address below to request deletion of your registration data.

Data retention and deletion

When you delete a session in the app, the corresponding cloud data is marked as deleted and excluded from future analysis. To request complete deletion of previously uploaded data from CloudKit, email the contact address below.

What we never do

  • Sell or rent any of your data
  • Track you across apps or websites
  • Show ads
  • Require an account for basic features

Subscriptions

Subscriptions are processed by the Apple App Store; we never see your payment information.

Contact

keepsurfing@surfbound.app