DATA PRACTICES
This policy explains how the individual operator using the unregistered NeuralNexusLab brand handles personal data through AstraNote. Contact: neuralnexuslab@hotmail.com. AstraNote does not sell personal data or use advertising or analytics trackers.
1. Data controller and scope
The Operator determines why and how AstraNote processes personal data and is the data controller for this service. This policy covers the primary domain, backup domain, service APIs, and account data. Third-party NexaCAPTCHA processing is also subject to that provider’s own practices.
2. Data collected
- Registration: username, email address, password hash, registration IP address, UTC time, agreement version and acceptance time.
- Use: last-login IP and UTC time, session identifiers, CSRF tokens, language, theme, public display name, storage use, and note metadata.
- Content: note names and content, encryption selection, update time, and optional share token. Server-managed encrypted notes are stored as ciphertext with nonce and authentication tag.
- Security: rate-limit events, CAPTCHA verification identifiers and tokens, error and operational records reasonably necessary to prevent abuse.
- Deletion: username, request time, reversal deadline, permanent-lock time, erasure deadline, and status.
3. Purposes and legal bases
Data is processed to create and authenticate accounts, store and display notes, enforce storage limits, provide sharing, remember settings, prevent fraud and attacks, comply with law, respond to rights requests, and establish or defend legal claims. Depending on applicable law, the bases are performance of the service agreement, consent, compliance with legal obligations, and legitimate interests in security and reliable operation.
4. Cookies and local storage
A host-only, HttpOnly session cookie is used for authentication and security. The browser stores language, theme, and acknowledgement of the necessary-cookie notice. These technologies are essential or preference-only; no advertising, cross-site tracking, profiling, or analytics cookie is used. The primary and backup domains have separate browser sessions.
5. NexaCAPTCHA
For registration, login, logout, note creation, note saving, note
deletion, sharing changes, and account deletion, the browser loads
NexaCAPTCHA Gravity from nexacaptcha.zone.id. AstraNote
sends the resulting verification ID and one-time response token to
NexaCAPTCHA’s fixed server verification endpoint. The token is
intended to work once and expire after five minutes. Do not place
personal information in the CAPTCHA response field.
6. Disclosure
The Operator does not proactively sell or share account data with advertisers or data brokers. Data may be processed by infrastructure hosting and NexaCAPTCHA as necessary to operate the service; disclosed when legally required; or used to protect users, systems, and legal rights. When you enable a sharing link, you instruct AstraNote to disclose that note, your public display name, and masked email to link holders.
7. Retention
Account and security data is retained while the account exists. A deletion request begins a seven-day cancellation period. After seven days, access is permanently disabled. Identifiable account files are manually erased no later than two months after the request, unless a longer period is required by law or necessary for legal claims. Individual deleted notes are removed immediately from the live account and have no service backup. Session records expire no later than twenty-eight days after login. Daily-login uniqueness records reset at UTC 00:00.
8. Security
AstraNote uses password hashing, authenticated encryption, opaque sessions, CSRF and Origin checks, server-side CAPTCHA verification, rate limits, access-control checks, restrictive security headers, atomic writes, and request-size limits. No system is completely secure. Users should use a unique password, avoid placing irreplaceable material in the service, and retain independent copies.
9. Children and guardians
The service may be used by all ages only with the legally required involvement of a guardian. Under seven, a legal representative must create and manage the account. Users aged seven to seventeen must obtain legal-representative permission unless applicable law permits independent use. The Operator does not intentionally request date of birth. A guardian may contact the Operator regarding a minor’s data and may be asked to demonstrate authority and account control.
10. Your rights
Subject to applicable law, you may request access, a copy, correction, cessation of processing, restriction, objection, or deletion. Settings provide correction of display name, language, and theme, and a deletion-request process. Requests may be sent to the contact email. Identity may be verified using account credentials or other proportionate information. You may also complain to a competent data-protection or consumer authority.
11. International access
AstraNote may be accessed worldwide and hosting or CAPTCHA processing may occur outside your location. Applicable mandatory transfer, privacy, and consumer protections remain unaffected. Because the Operator is based in Taiwan, data is principally administered under the laws of the Republic of China (Taiwan).
12. Changes
Material changes will be communicated reasonably through the service and identified by a new effective date. Where new consent is legally required, it will be requested before the new processing begins.
本政策說明以 NeuralNexusLab 未登記品牌名義營運的個人服務提供者,如何透過 AstraNote 處理個人資料。聯絡信箱:neuralnexuslab@hotmail.com。AstraNote 不販售個資,亦不使用廣告或分析追蹤器。
一、資料控制者與範圍
營運者決定 AstraNote 處理個人資料的目的及方式,為本服務的資料控制者。本政策適用主要及備用網域、服務 API 與帳號資料。NexaCAPTCHA 的第三方處理亦受該提供者自身政策規範。
二、蒐集資料
- 註冊:Username、Email、密碼雜湊、註冊 IP、UTC 時間、同意版本與時間。
- 使用:最後登入 IP 與 UTC 時間、Session 識別資料、CSRF Token、語言、主題、公開顯示名稱、儲存用量與筆記中繼資料。
- 內容:筆記名稱、內容、加密選項、更新時間及選擇性分享代碼。伺服器管理的加密筆記會以密文、Nonce 及驗證標籤保存。
- 安全:速率限制事件、CAPTCHA 驗證 ID 與 Token,以及防止濫用所合理必要的錯誤及運作紀錄。
- 刪除:Username、申請時間、反悔期限、永久鎖定時間、最遲清除時間及狀態。
三、目的與依據
資料用於建立及驗證帳號、保存及顯示筆記、執行容量限制、提供分享、記住設定、防止詐欺與攻擊、遵守法律、回應權利請求,以及提出或防禦法律請求。依適用法律,處理依據可能為履行服務協議、同意、遵守法定義務,以及保障安全與可靠運作的正當利益。
四、Cookie 與本機儲存
驗證及安全使用僅限目前主機、HttpOnly 的 Session Cookie。瀏覽器會保存語言、主題及已閱讀必要 Cookie 通知的狀態。本服務不使用廣告、跨站追蹤、使用者輪廓或分析 Cookie。主要與備用網域各自擁有獨立登入階段。
五、NexaCAPTCHA
註冊、登入、登出、新增、儲存、刪除筆記、變更分享及申請刪除帳號時,瀏覽器會從
nexacaptcha.zone.id 載入 Gravity。AstraNote 會將驗證 ID
及一次性 Token 傳至 NexaCAPTCHA 固定的後端驗證端點。Token
原則上僅可使用一次並於五分鐘後失效。請勿在 CAPTCHA
欄位輸入個人資料。
六、揭露
營運者不主動向廣告商或資料仲介販售或分享帳號資料。為運作服務,託管基礎設施與 NexaCAPTCHA 可能處理必要資料;依法要求或為保護使用者、系統及合法權利時亦可能揭露。開啟分享即代表您指示 AstraNote 向連結持有人揭露指定筆記、公開顯示名稱與遮罩 Email。
七、保存期限
帳號存在期間保存帳號與安全資料。刪除申請有七日反悔期;七日後永久停止存取。可識別帳號檔案最遲於申請後兩個月由管理員清除,法律要求或法律請求所必要者除外。個別刪除的筆記會立即移出現行帳號且沒有服務備份。Session 最遲於該次登入後二十八日失效。每日不同登入帳號紀錄於 UTC 00:00 重置。
八、安全
AstraNote 採用密碼雜湊、具認證加密、不透明 Session、CSRF 與 Origin 檢查、後端 CAPTCHA 驗證、速率限制、權限確認、嚴格安全標頭、原子寫入及請求大小限制。任何系統均無法保證絕對安全;請使用獨立密碼、勿將不可取代資料只存於本服務,並自行保存副本。
九、兒童與法定代理人
所有年齡均可在法律要求的法定代理人參與下使用。未滿七歲者須由法定代理人建立及管理;七至十七歲者除法律允許獨立使用外,須取得法定代理人同意。營運者不主動要求出生日期。法定代理人可就未成年人資料聯絡營運者,並可能須證明代理權與帳號控制權。
十、您的權利
依適用法律,您可能享有查詢、閱覽、取得複本、更正、停止處理、限制、反對或刪除的權利。設定頁可更正公開名稱、語言及主題,並可提出刪除申請。其他請求可寄至聯絡信箱;營運者可能使用帳號憑證或合比例資料確認身分。您亦可向有管轄權的個資或消費者主管機關申訴。
十一、跨境存取
AstraNote 可由全球存取,託管或 CAPTCHA 處理可能發生於您所在地以外。適用且不得排除的個資、移轉及消費者保護仍有效。因營運者位於臺灣,資料主要依中華民國法律管理。
十二、政策變更
重大變更將以合理方式於服務中公告並標示新生效日期。如新的處理依法須另行取得同意,會在開始前提出要求。