隱私權政策
營運者:臻環科技股份有限公司
隱私與刪除請求:izev@zev.city
本政策說明 ZEV City 網站、ZevRouter,以及 ZEV 傑夫(ZEV LINE AI)如何處理個人資料。ZEV 傑夫是透過 LINE 使用的雲端 AI 助理;ZevRouter 提供模型路由及 Google 帳號連接等後端服務。Google 同意畫面可能顯示應用程式名稱「ZEV City」。
先看重點
- 我們依你使用的功能,處理帳號、訊息、檔案、任務及必要營運紀錄。AI 回答可能需要將內容交由所選模型或工具服務處理。
- Google 連接是選用功能。Drive、Calendar 與 Gmail 各有不同權限;Gmail 排程通知只要求寄信,不讀取收件匣。
- 解除授權、停用功能、收回 LINE 訊息及申請刪除資料,是不同操作。歷史回答、記憶、備份及收件人的副本不會全部連動消失。
- 你可以聯絡我們查詢、更正、取得副本或申請停止處理、刪除資料。請勿在來信附上密碼、驗證碼或授權憑證。
1. 資料類別與使用目的
- 帳號與偏好:LINE 使用者或群組識別、Google 授權的基本個人資料與電子郵件、帳號綁定及功能設定,用於辨識帳號、隔離工作區及提供選用功能。
- 內容與任務:你傳送的問題、附件、工作檔案、AI 回答、記憶或摘要、工具結果、排程內容、寄信收件人與寄送狀態,用於完成請求、延續對話、呈現結果及提供你啟用的通知。
- 連接與復原:經你授權的外部資料、OAuth 權杖、連接狀態、同步及備份資料,用於維持已授權功能及服務復原。我們不要求你將 Google 密碼交給 ZEV。
- 使用與技術紀錄:模型或供應商路由、時間、用量、費用、請求識別、錯誤與安全紀錄,以及網站連線所需的 IP、瀏覽器及請求資訊,用於計量、帳務、安全、故障排除與服務維護。
- 付款與聯絡:你提供的客服內容及交易識別、金額、幣別、付款或退款狀態,用於回應請求及對帳。若經第三方付款頁付款,完整卡號等付款憑證由付款服務處理,不由 ZevRouter 用量帳本保存。
網站或設定頁會使用必要的 Cookie/瀏覽器儲存保存登入狀態與偏好;停用後可能影響登入及設定。此隱私頁本身沒有追蹤程式、登入或資料收集表單。其他服務另有功能說明時,應與本政策一併閱讀;新的資料用途會另行說明,不能以閱讀本頁代替必要的授權。
2. LINE 群組與對話
加入 bot 不會自動讓 ZEV 取得你的其他私聊、未加入的群組,或未曾收到的加入前歷史。你自行轉貼或上傳的內容則屬於提供給本服務的資料。
群組服務擁有者(owner)開啟「群聊保存」後,一般背景文字即使沒有呼叫 bot,也可能保存供後續回答參考。owner 應向群友說明;不能把 owner 的設定當成每位群友都已個別同意。
群組 AI 回答供群友閱讀。群組 bot 對話、摘要及產出可能包含在 owner 工作區備份中;已啟用 Google Drive 備份時,也可能存於 owner 的 Drive。原始背景快取與工作區備份不同,但被引用的內容可能進入回答或檔案。群友不會僅因加入群組而取得 owner 的私人 Google 授權。
3. Google 資料:存取、用途與控制
我們透過 Google 的授權頁取得你同意的權限;未授權的 Google 功能無法使用,但不代表必須授權所有功能才能使用一般 AI 對話。各功能只在有效授權及相應設定下使用。
身分與帳號連接
openid、userinfo.email、userinfo.profile 用於確認你登入的 Google 帳號、顯示基本帳號資訊並連接到正確的 ZEV 帳戶。
Google Drive
https://www.googleapis.com/auth/drive.file 用於處理由本應用程式建立、開啟或經你選取分享給本應用程式的檔案,例如工作檔案、匯出內容,以及目前啟用的同步/備份。並非取得整個 Drive 的所有檔案權限。
Google Calendar
https://www.googleapis.com/auth/calendar.app.created 用於建立及管理應用程式建立的日曆與其中的事件,不是讀取你全部私人日曆的權限。
Gmail 排程寄信
https://www.googleapis.com/auth/gmail.send 需另外同意。當你連接 Gmail、啟用排程的 Email 通知並儲存收件人後,我們透過你的 Gmail 帳號寄送該排程結果。會處理寄件帳號、你設定的收件人、主旨、結果內文及寄送狀態。這個整合不讀取、搜尋或刪除收件匣,也不要求 Gmail 全信箱權限。
Gmail 寄信權杖用於後端呼叫,不提供給聊天模型作為提示詞。寄出的 AI 結果仍可能包含你在原任務中提供的內容;請留意自己指定的收件人。Google 已連接,不代表 Email 通知會自動開啟。
解除授權
你可以在 ZEV 設定關閉 Email 通知或解除 Google 連接,也可到 Google 帳戶的第三方連接撤銷存取。解除連接會停止依賴該授權的後續功能,不會登出你的 Google 帳號,也不會自動刪除已寄出的信、Drive 檔案或既有備份。既有資料的刪除方式見第 6、7 節。
4. Google 資料的使用限制
Google 授權取得的資料及其衍生內容,僅限於你使用且在服務中可見的功能。我們不以這些資料販售名單、建立廣告受眾、進行信用評估,或訓練跨使用者的通用 AI 模型。AI 為你的請求生成回答,與將內容用於通用模型訓練,是不同用途。
提供給其他服務的 Google 資料,限於經你同意、完成相應功能所必要的範圍,或必要的安全及依法處理情況;不將 Google 授權視為任意轉售或公開資料的同意。人工讀取 Google 資料限於你明確同意的特定協助、必要的安全問題、依法處理,或符合適用要求的去識別化彙總作業。
這些限制依據 Google API Services User Data Policy 及 Google Workspace Limited Use 要求。它們不是 Google 已核准本應用程式的聲明,也不是對所有第三方保存期間的零留存保證。
6. 資料保留與刪除
- 群組背景文字:目前依群組設定的時間及則數清理,可設定 1–720 小時及 10–5,000 則,兩項限制同時適用。這不是所有資料的保存期限。停用群聊保存會清除該背景快取;LINE 收回事件會處理相應背景文字及附件參照。
- AI 對話、記憶與工作檔案:為帳號持續使用、延續工作及取回成果而保存,目前沒有全部自動到期的統一期限。你可以申請刪除指定範圍或停用帳號;刪除處理前我們會確認身分、資料範圍及需保留的例外。
- Google 授權:為維持已連接功能而保存必要權杖與連接資訊。解除連接或撤銷後不再用於後續存取;已取得的工作成果與紀錄不等於同時刪除。
- 備份:公司復原備份及 Drive/匯出副本有各自的版本與保留機制。刪除主要資料不代表舊備份在同一瞬間被抹除。我們處理刪除請求時會說明可處理的副本、復原用途及限制,不以某一份備份的天數代表所有副本已清空。
- 帳務、安全與法律需要:依核對交易、處理爭議、防止濫用及適用義務所需範圍保存,與聊天內容分開判斷。若請求中有不能立即刪除的部分,會說明理由及處理方式。
已生成的回答、摘要或記憶不保證隨原訊息收回而連動刪除。群友、Email 收件人或你自行儲存的副本不在我們的完整控制範圍;Google 帳戶中的檔案、日曆或已寄郵件也可能需要由你在該服務另行刪除。
7. 你的選擇、資料請求與聯絡方式
你可以調整模型與群聊保存、關閉排程通知、撤銷 Google 權限、停止使用服務,或向我們提出資料查詢、閱覽/副本、更正、停止蒐集處理利用及刪除請求。未提供某項資料或撤回授權,可能使依賴它的功能無法運作,不等於同意其他用途。
請寄信至 izev@zev.city,主旨註明「隱私/資料請求」,說明服務、可供核對的帳號資訊、資料期間與希望處理的範圍。我們會以必要資訊確認你對該帳號或資料的權限,再回覆可處理項目、方式及預估時間。不要附上密碼、驗證碼、API key 或完整私人授權連結。
若資料涉及其他群友、法定保存義務或第三方自行保有的副本,我們會說明限制,並在可行範圍內協助。沒有經過身分確認,不會只憑持有連結就向他人提供你的私人資料。
營運者:臻環科技股份有限公司
公開隱私及刪除請求窗口:izev@zev.city
8. 政策更新
我們會在本頁標示更新日期。重要的資料用途、權限或處理方式有變更時,會透過適當的服務內提示或其他可用管道說明,並在需要時另行取得同意。閱讀本頁不會改動設定、開啟寄信或授予新的 Google 權限。
功能現況可另參考 ZEV 傑夫 Beta 資料處理說明;該說明的早期版本曾記載正式營運者及窗口待公布,現以本政策所列資料為準。
Privacy Policy
Operator and services
The operator is 臻環科技股份有限公司. Contact izev@zev.city for privacy and deletion requests. This policy covers the ZEV City website, ZevRouter and ZEV LINE AI (ZEV 傑夫), a cloud AI assistant used through LINE. ZevRouter provides model routing and Google account connection services. Google consent screens may identify the application as “ZEV City”.
Information and purposes
We process account and group identifiers, authorized Google identity information, connections and settings; prompts, attachments, work files, responses, memories or summaries and tool results; scheduled tasks, email recipients and delivery status; necessary authorization tokens, synchronization and recovery data; usage, model routes, request identifiers, costs, transactions, support, technical and security records. These support your requested features, continuity, billing, security and service operation. Website infrastructure receives connection information such as IP addresses and browser/request information. Necessary cookies or browser storage support sessions and preferences. This policy page itself has no tracking scripts or collection form.
Payment services handle their payment credentials. The ZevRouter usage ledger records transaction details rather than full card credentials. We do not ask you to give ZEV your Google password. New purposes will be explained separately; merely visiting this policy does not authorize them.
LINE groups
The bot does not automatically obtain unrelated private chats, groups it has not joined, or unseen earlier history. When a group owner enables background-message retention, ordinary group text may be retained even without invoking the bot. Owners should inform participants; an owner's setting is not each participant's individual consent. Group responses are visible to members. Bot conversations and outputs may be included in the owner's workspace backups, including enabled Drive backups. Raw background caches are separate, but quoted content may appear in responses or files. Group membership does not grant access to the owner's personal Google authorization.
Optional Google access
openid,userinfo.emailanduserinfo.profile: identify the signed-in Google account, show basic account information and connect it to the correct ZEV account.https://www.googleapis.com/auth/drive.file: work with files created or opened by this application, or specifically shared with it by you, for work files, exports and currently enabled synchronization/backups. It does not grant access to every Drive file.https://www.googleapis.com/auth/calendar.app.created: create and manage application-created calendars and their events, not read all your private calendars.https://www.googleapis.com/auth/gmail.send: separately authorized sending of scheduled task results from your Gmail account, after you enable Email notifications and save recipients. This uses the sender, recipients, subject, result body and delivery status. It does not read, search or delete inbox mail or request full mailbox access. Gmail authorization tokens are used by the backend, not supplied as chat-model prompts. Generated results can contain information from your original task, so choose recipients carefully. Connecting Gmail does not itself enable Email notifications.
Permissions and the relevant settings must be active. You can disable Email notifications, disconnect Google in ZEV settings or revoke access in Google third-party connections. This stops future authorization-dependent access; it does not log you out of Google or automatically delete previous mail, files or backups.
Limits on Google data use
Google-authorized data and derived content are limited to the visible features you use. We do not use this data for sale of data lists, advertising audiences, credit decisions or training general-purpose AI models across users. Generating an answer for your request is distinct from general model training. Transfers are limited to necessary, consented features, security or applicable legal requirements; authorization is not permission for arbitrary resale or publication. Human reading is limited to specifically consented assistance, necessary security matters, legal requirements or appropriately de-identified aggregate operations. These limits are based on the Google API Services User Data Policy and Workspace Limited Use requirements; they are not a claim that Google has approved the app or that every third party provides zero retention.
Sharing, international processing and safeguards
Necessary inputs go to the selected model and routing providers, and to tools such as search. Available model families may include Google Gemini, OpenAI GPT, DeepSeek, Qwen and GLM. Attachment or image services can differ from the main chat model. LINE delivers messages, Google Cloud provides hosting and recovery storage, Cloudflare provides website/network/security services, and payment services handle their payment flows. Necessary disclosures may also occur for security or legal duties. This does not mean we sell your conversations.
Processing may take place in Taiwan and other provider locations, including the United States, rather than only in Taiwan. Third-party handling depends on the applicable service and arrangements; we do not promise universal zero retention. We use encrypted transmission, account/workspace isolation and authentication/access restrictions. Privileged operators may technically access stored content: this is not end-to-end encryption that excludes the operator. Processing is limited by work necessity, not casual browsing of private content. Optional hosted-browser features process page displays and login state separately from Google API authorization, without taking over your personal device.
Retention and deletion
Group background caches use both configured time and message-count limits (currently 1–720 hours and 10–5,000 messages). Disabling retention clears that cache; LINE unsend events handle matching background text and attachment references. These are not universal retention periods. AI history, memories and work files persist for continuity and retrieving results, without a single automatic expiry across all data. You may request deletion or account closure. Authorization records support connected functions; disconnected or revoked access is not used for future access.
Recovery backups, Drive versions, exports, usage/security and transaction records have separate purposes and retention mechanisms. Main-data deletion is not simultaneous erasure of all backup copies. We explain the scope, available deletion actions, recovery limitations and any justified retention when handling requests. Previously generated answers or memories may not disappear when a source message is unsent. Copies held by group participants, recipients or in your external accounts may require separate action and are not fully under our control.
Your choices and requests
You may adjust models and group retention, disable notifications, revoke Google access, stop using the service or request access, a copy, correction, cessation of processing or deletion. A feature may stop working if required information or permission is withdrawn. Email izev@zev.city with “Privacy / data request”, the service, account information needed for verification, relevant dates and requested scope. We verify your authority with necessary information, then explain available actions and an estimated timeline. Do not send passwords, verification codes, API keys or private authorization links. We explain any limitations involving others' data, required retention or third-party copies. Possession of a link alone is not sufficient to disclose private account data.
Updates
We date changes here and explain material changes through appropriate service notices or other available channels, requesting consent where required. Reading this page does not change settings, enable email or grant Google permissions. Earlier Beta data-processing notes deferred the operator and public contact details; the details in this policy now apply.