This policy explains how the individual operator using the unregistered NXLabTW brand handles personal data through AstraNote. Contact: astranote@nxlabtw.com. AstraNote does not sell personal data or use advertising or analytics trackers.

1. Data controller and scope

The Operator determines why and how AstraNote processes personal data and is the data controller for this service. This policy covers the primary domain, backup domain, service APIs, and account data. Third-party NexaCAPTCHA, Satora, and OpenAI processing is also subject to each provider’s own practices.

2. Data collected

  • Registration: username, email address, password hash, registration IP address, UTC time, agreement version and acceptance time.
  • Use: last-login IP and UTC time, session identifiers, CSRF tokens, a short browser label, sign-in and last-use times, language, theme, public display name, storage use, and note metadata. To label signed-in devices and relevant account-security emails, AstraNote may send a public IP address to the NXLabTW-operated nxlabtw.com/ipinfo/ endpoint and store only the returned country or region. This lookup is not sent to an unrelated commercial IP-location provider.
  • Content: note names and content, encryption selection, update time, and optional share token. Titles remain plaintext in every mode. Encrypted content is stored as ciphertext with the information needed for authenticated decryption. AstraSecret, AstraConfidential and legacy SCHybrid also store a random client salt. AstraZero stores a PIN-protected note key and encrypted content, never your PIN or a usable plaintext key. Keys exist temporarily in client memory during use.
  • Security and Email: rate-limit events, CAPTCHA verification identifiers and tokens, single-use Email-verification, password-reset, sign-in, and account-deletion challenge verifiers, and error and operational records reasonably necessary to prevent abuse. Email codes and links expire after ten minutes.
  • Plans and payments: remaining Plus, Pro and Ultra time, local order ID, selected plan and months, BTC amount, Satora payment ID and URL, status, TXID, and fulfilment time. The Satora API credential is never sent to the client.
  • Astra AI: only when you choose to generate a preview, the note title, note content, and instruction are sent to OpenAI. The API request uses store:false. PINs and encryption keys are not sent. Do not use this feature for content you do not want processed by OpenAI.

3. Purposes and legal bases

Data is processed to create and authenticate accounts, store and display notes, enforce storage limits, provide sharing, remember settings, prevent fraud and attacks, comply with law, respond to rights requests, and establish or defend legal claims. Depending on applicable law, the bases are performance of the service agreement, consent, compliance with legal obligations, and legitimate interests in security and reliable operation.

4. Cookies and local storage

A host-only, HttpOnly session cookie is used for authentication and security. The client stores language, theme, and acknowledgement of the necessary-cookie notice. These technologies are essential or preference-only; no advertising, cross-site tracking, profiling, or analytics cookie is used. The primary and backup domains have separate client sessions.

5. Human verification

For registration, permanent note deletion, and payment-order creation, the client loads a CAPTCHA from nexacaptcha.nxlabtw.com. AstraNote sends the resulting verification ID and one-time response token to NexaCAPTCHA’s fixed server verification endpoint. The token is intended to work once and expire after five minutes. Do not place personal information in the CAPTCHA response field.

6. Disclosure

The Operator does not proactively sell or share account data with advertisers or data brokers. Data may be processed by infrastructure hosting, NexaCAPTCHA, Satora, and OpenAI as necessary to operate the service; disclosed when legally required; or used to protect users, systems, and legal rights. When you enable a sharing link, you instruct AstraNote to disclose that note, your public display name, and masked email to link holders.

7. Retention

Account and security data is retained while the account exists. Notes exceeding the effective plan are locked by the server; a note continuously locked for 30 days is permanently deleted without a service backup. Unlocking it before that time clears the deletion schedule. Confirmed account deletion immediately removes the live account directory and notes and revokes its sessions and sharing links; it cannot be cancelled or restored, and AstraNote has no service backup. Manual deletion and recoverable trash follow the retention rules above; permanent deletion is immediate. Records may be retained only where required by law or necessary for legal claims. Session records expire no later than twenty-eight days after login. Distinct daily authenticated-activity records reset at UTC 00:00.

8. Security

AstraNote uses password hashing, authenticated encryption, opaque sessions, CSRF and Origin checks, server-side CAPTCHA verification, rate limits, access-control checks, restrictive security headers, atomic writes, and request-size limits. The server-managed AES modes can technically be decrypted by the Operator. AstraSecret, AstraConfidential and legacy SCHybrid encrypt content in the client using the user's PIN and server-assisted protection, but they are not a zero-knowledge guarantee and still require trust in the application and server while unlocking. No system is completely secure. Users should use a unique password, avoid keeping the only copy of irreplaceable material in the service, and retain independent copies.

9. Children and guardians

The service may be used by all ages only with the legally required involvement of a guardian. Under seven, a legal representative must create and manage the account. Users aged seven to seventeen must obtain legal-representative permission unless applicable law permits independent use. The Operator does not intentionally request date of birth. A guardian may contact the Operator regarding a minor’s data and may be asked to demonstrate authority and account control.

10. Your rights

Subject to applicable law, you may request access, a copy, correction, cessation of processing, restriction, objection, or deletion. Settings provide correction of display name, language, and theme, and an immediate permanent account-deletion control. Requests may be sent to the contact email. Identity may be verified using account credentials or other proportionate information. You may also complain to a competent data-protection or consumer authority.

11. International access

AstraNote may be accessed worldwide and hosting or CAPTCHA processing may occur outside your location. Applicable mandatory transfer, privacy, and consumer protections remain unaffected. Because the Operator is based in Taiwan, data is principally administered under the laws of the Republic of China (Taiwan).

12. Changes

Material changes will be communicated reasonably through the service and identified by a new effective date. Continued use after that date accepts the updated policy only to the extent permitted by law. Where new consent is legally required, it will be requested before the new processing begins.

本政策說明以 NXLabTW 未登記品牌名義營運的個人服務提供者,如何透過 AstraNote 處理個人資料。聯絡信箱:astranote@nxlabtw.com。AstraNote 不販售個資,亦不使用廣告或分析追蹤器。

一、資料控制者與範圍

營運者決定 AstraNote 處理個人資料的目的及方式,為本服務的資料控制者。本政策適用主要及備用網域、服務 API 與帳號資料。NexaCAPTCHA、Satora 與 OpenAI 的第三方處理亦受該提供者自身政策規範。

二、蒐集資料

  • 註冊:使用者名稱、電子郵件、密碼雜湊、註冊 IP、UTC 時間、同意版本與時間。
  • 使用:最後登入 IP 與 UTC 時間、登入階段 識別資料、CSRF 驗證權杖、簡短應用程式識別、登入及最近使用時間、語言、主題、公開顯示名稱、儲存用量與筆記中繼資料。為標示已登入裝置及相關帳號安全信件,AstraNote 可能將公開 IP 位址傳送至 NXLabTW 營運的 nxlabtw.com/ipinfo/ 端點,並僅保存其回傳的國家或地區;不會將此查詢傳送給無關的商業 IP 定位服務。
  • 內容:筆記名稱、內容、加密選項、更新時間及選擇性分享代碼。 新版加密筆記的標題會以獨立 AES-256-GCM 保護;加密內容連同解密驗證所需資訊保存。登入中的帳號仍可在筆記清單中取得標題,以供顯示與搜尋。 AstraSecret、AstraConfidential 與舊版 SCHybrid 另保存隨機客戶端加密參數。 AstraZero 保存以 PIN 保護的筆記金鑰與密文,不保存 PIN 或可直接解密的明文金鑰。 解鎖時,金鑰會短暫存在客戶端記憶體。
  • 安全與 Email:速率限制事件、CAPTCHA 驗證 ID 與 驗證權杖、一次性 Email 驗證、重設密碼、登入及刪除帳號驗證資料的驗證值,以及防止濫用所合理必要的錯誤及運作紀錄。Email 驗證碼與連結會在十分鐘後失效。
  • 方案與付款:Plus、Pro 與 Ultra 剩餘時間、本地訂單編號、方案與月數、 Bitcoin 金額、Satora 付款編號及網址、狀態、交易識別碼與交付時間。 Satora 服務憑證不會傳送至客戶端。
  • Astra AI:僅在您選擇產生預覽時,筆記標題、內容與指令才會傳送至 OpenAI。API 請求使用 store:false;PIN 與加密金鑰不會傳送。若不希望內容由 OpenAI 處理,請不要使用此功能。

三、目的與依據

資料用於建立及驗證帳號、保存及顯示筆記、執行容量限制、提供分享、記住設定、防止詐欺與攻擊、遵守法律、回應權利請求,以及提出或防禦法律請求。依適用法律,處理依據可能為履行服務協議、同意、遵守法定義務,以及保障安全與可靠運作的正當利益。

四、Cookie 與本機儲存

驗證及安全使用僅限目前主機、HttpOnly 的 登入階段 Cookie。客戶端會保存語言、主題及已閱讀必要 Cookie 通知的狀態。本服務不使用廣告、跨站追蹤、使用者輪廓或分析 Cookie。主要與備用網域各自擁有獨立登入階段。

五、人類驗證

註冊、永久刪除筆記及建立付款訂單時,客戶端會從 nexacaptcha.nxlabtw.com 載入 CAPTCHA。AstraNote 會將驗證 ID 及一次性 驗證權杖 傳至 NexaCAPTCHA 固定的後端驗證端點。驗證權杖 原則上僅可使用一次並於五分鐘後失效。請勿在 CAPTCHA 欄位輸入個人資料。

六、揭露

營運者不主動向廣告商或資料仲介販售或分享帳號資料。為運作服務,託管基礎設施、NexaCAPTCHA、Satora 與 OpenAI 可能處理必要資料;依法要求或為保護使用者、系統及合法權利時亦可能揭露。開啟分享即代表您指示 AstraNote 向連結持有人揭露指定筆記、公開顯示名稱與遮罩 電子郵件。

七、保存期限

帳號存在期間保存帳號與安全資料。超出有效方案額度的筆記會由後端鎖定;連續鎖定滿30天後會在沒有服務備份的情況下永久刪除,期限前解鎖則會清除預定刪除時間。確認永久刪除帳號後,現行帳號資料夾及筆記會立即移除,所有登入階段與分享連結同時失效;此操作不能取消或復原,AstraNote 亦無服務備份。手動刪除與垃圾桶依前述保存規則處理;永久刪除則立即移除。僅於法律要求或法律請求所必要時可能保留必要紀錄。登入階段 最遲於該次登入後二十八日失效。每日曾發出已登入請求的不同帳號紀錄於 UTC 00:00 重置。

八、安全

AstraNote 採用密碼雜湊、具認證加密、不透明 登入階段、CSRF 與 Origin 檢查、後端 CAPTCHA 驗證、速率限制、權限確認、嚴格安全標頭、原子寫入及請求大小限制。伺服器管理的 AES 模式在技術上可由營運者解密;AstraSecret、AstraConfidential 與舊版 SCHybrid 會用 PIN 與伺服器端保護在客戶端加密內容,但並非零知識保證,解鎖時仍須信任應用程式與伺服器。筆記名稱維持明文。任何系統均無法保證絕對安全;請使用獨立密碼、勿將不可取代資料只存於本服務,並自行保存副本。

九、兒童與法定代理人

所有年齡均可在法律要求的法定代理人參與下使用。未滿七歲者須由法定代理人建立及管理;七至十七歲者除法律允許獨立使用外,須取得法定代理人同意。營運者不主動要求出生日期。法定代理人可就未成年人資料聯絡營運者,並可能須證明代理權與帳號控制權。

十、您的權利

依適用法律,您可能享有查詢、閱覽、取得複本、更正、停止處理、限制、反對或刪除的權利。設定頁可更正公開名稱、語言及主題,並可立即永久刪除帳號。其他請求可寄至聯絡信箱;營運者可能使用帳號憑證或合比例資料確認身分。您亦可向有管轄權的個資或消費者主管機關申訴。

十一、跨境存取

AstraNote 可由全球存取,託管或 CAPTCHA 處理可能發生於您所在地以外。適用且不得排除的個資、移轉及消費者保護仍有效。因營運者位於臺灣,資料主要依中華民國法律管理。

十二、政策變更

重大變更將以合理方式於服務中公告並標示新生效日期。在法律允許的範圍內,生效日後繼續使用即表示接受更新政策;如新的處理依法須另行取得同意,會在開始前提出要求。

本ポリシーは未登録の NXLabTW ブランドで AstraNote を運営する個人による個人情報の取扱いを説明します。連絡先:astranote@nxlabtw.com。個人情報の販売、広告・分析用の追跡は行いません。

1. 管理者と適用範囲

運営者は処理の目的と方法を決定します。主・予備ドメイン、サービス API、アカウント情報に適用します。NexaCAPTCHA、Satora、OpenAI での第三者処理には各提供者の方針も適用されます。

2. 収集する情報

  • 登録:ユーザー名、メール、パスワードのハッシュ、登録 IP、UTC 日時、同意した版と日時。
  • 利用:最終ログイン IP・UTC 日時、セッション識別子、CSRF トークン、短縮したブラウザ名、ログイン・最終利用時刻、言語、外観、公開表示名、容量、ノート情報。ログイン中端末と関連するアカウントセキュリティメールの表示のため、公開 IP アドレスを NXLabTW 運営の nxlabtw.com/ipinfo/ に送信し、返された国または地域だけを保存する場合があります。無関係な商用 IP 位置情報サービスには送信しません。
  • 内容:タイトル、内容、暗号化方式、更新日時、任意の共有コード。タイトルは平文です。暗号化内容と復号検証用情報を保存します。AstraSecret、AstraConfidential、従来の SCHybrid はランダムなクライアント用パラメーターも保存します。AstraZero は PIN で保護した鍵と暗号文を保存しますが、PIN や直接使える平文の鍵は保存しません。利用時のみ鍵がクライアントのメモリーに一時的に存在します。
  • 安全とメール:頻度制限、CAPTCHA 識別子・トークン、メール認証・パスワード再設定・サインイン・アカウント削除の一回限りの検証情報、濫用防止に合理的に必要なエラーと運用記録。メールのコードとリンクは10分で失効します。
  • プラン・支払い:Plus、Pro、Ultra の残り時間、注文番号、プラン・月数、Bitcoin 金額、Satora 支払い番号・URL、状態、取引識別番号、付与日時。圧縮した支払い記録とクーポン記録は前述のとおりです。サービスの認証秘密はクライアントに送信しません。
  • Astra AI:「プレビューを生成」を選んだ場合のみ、ノート名、内容、指示を OpenAI に送信します。API リクエストには store:false を設定し、PIN と暗号鍵は送信しません。OpenAI に処理させたくない内容にはこの機能を使わないでください。

3. 目的と根拠

登録・認証、ノート保存・表示、上限の適用、共有、設定保持、不正防止、法律遵守、権利請求対応、法的請求の主張・防御のため処理します。適用法に応じ、契約履行、同意、法的義務、安全で信頼できる運用の正当な利益を根拠とします。

4. Cookie と端末内保存

認証・安全のためホスト限定の HttpOnly セッション Cookie を使用します。クライアントは言語、外観、必要な Cookie 通知の確認状態を保持します。広告、サイト横断追跡、プロファイリング、分析 Cookie は使用しません。主・予備ドメインのセッションは別々です。

5. 人間による認証

登録、ノートの完全削除、支払い注文作成の際、クライアントは nexacaptcha.nxlabtw.com から CAPTCHA を読み込みます。認証識別子と一回限りの応答を固定のサーバー検証先へ送信します。トークンは原則一回のみ、5分で期限切れです。認証欄に個人情報を入力しないでください。

6. 提供先

広告主やデータ仲介業者へ積極的に販売・共有しません。ホスティング、NexaCAPTCHA、Satora と OpenAI は運用、認証、決済、またはあなたが選択した Astra AI 処理に必要な情報を処理する場合があります。法的要求、利用者・システム・権利保護のため開示する場合があります。共有リンクを有効にすると、指定ノート、公開表示名、マスク済みメールを保持者に開示するよう指示したものとします。

7. 保存期間

アカウントの存続中、アカウント・安全情報を保持します。上限超過のロックが30日続くとバックアップなしで完全削除し、期限前に解除すればその予定を取り消します。手動削除とゴミ箱は前述の期限に従います。完全なアカウント削除は稼働中のフォルダーとノートを即時削除し、セッションと共有を失効させ、復元できません。法的義務・請求に必要な別記録を保持する場合があります。セッションは各ログインから最長28日、当日認証済みの要求を送信したアカウントの重複除外記録は UTC 00:00 にリセットします。

8. 安全対策

パスワードのハッシュ、認証付き暗号化、不透明セッション、CSRF・送信元検証、サーバー CAPTCHA、頻度・権限・要求サイズ制限、安全な応答ヘッダー、原子的書込みを使用します。サーバー管理 AES は運営者が技術的に復号可能です。AstraSecret、AstraConfidential、従来の SCHybrid は PIN とサーバー支援によるクライアント暗号化で、ゼロ知識の保証ではありません。AstraZero の保護と限界は前述のとおりです。完全な安全は保証できません。固有のパスワードを使い、重要情報の唯一のコピーを本サービスに置かないでください。

9. 子どもと法定代理人

全年齢が法的に必要な代理人の関与のもとで利用できます。7歳未満は代理人が作成・管理し、7~17歳は法律が単独利用を認める場合を除き許可が必要です。生年月日を積極的に要求しません。代理人からのデータ相談では代理権・アカウント管理権の確認を求める場合があります。

10. 利用者の権利

適用法に従い、照会、閲覧、コピー、訂正、処理停止、制限、異議、削除を求められます。設定で表示名・言語・外観を修正し、アカウントを直ちに完全削除できます。その他は連絡先メールへお送りください。適切な認証情報等で本人確認する場合があります。管轄の個人情報保護・消費者機関への申立ても可能です。

11. 国際的アクセス

世界からアクセスでき、ホスティング、CAPTCHA、決済処理が利用者の所在地外で行われる場合があります。移転・プライバシー・消費者に関する強行法規は影響を受けません。運営者は台湾に所在し、原則として中華民国(台湾)の法に従って管理します。

12. 変更

重要な変更はサービス内で合理的に通知し、新しい施行日を表示します。法が許す範囲で、施行日後の継続利用は更新されたポリシーへの同意となります。新たな同意が法律上必要な場合、処理開始前に求めます。