Privacy Policy

Last Updated: May 25, 2026

This Privacy Policy describes the policies and procedures on the collection, use, and disclosure of Your information when You use our suite of productivity tools, news aggregator, digital storage, and lifestyle services. Gigantic Bear is a personal, non-profit passion project ('Labor of Love'), and we are committed to protecting your privacy with the highest standards.

1. Interpretation and Definitions

1.1 Interpretation

The words of which the initial letter is capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.

1.2 Definitions

  • Account means a unique account created for You to access our Service or parts of our Service.
  • Operator (referred to as either "the Operator", "We", "Us" or "Our" in this Agreement) refers to the individual developer operating Gigantic Bear.
  • Service refers to the Website and its ecosystem of features including Dashboard, Notes, Rabbit News, Storage, Fortune, and the Yukine AI Assistant.
  • Personal Data is any information that relates to an identified or identifiable individual.
  • Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).

2. Collecting and Using Your Personal Data

2.1 Types of Data Collected

We collect several different types of information to empower the diverse functionality of our platform.

  • Personal Identity Information: Email address (required for registration and newsletter subscriptions).
  • Productivity Data: Tasks, calendar events, personal notes, and project plans you manage via the Dashboard.
  • Digital Assets: Images, drawings, and files you upload to Storage or create via the Draw feature.
  • Preferences & Configuration: Your customized settings for Rabbit News sources, UI themes (Dark/Light), and language preferences.
  • Usage Data: Internet Protocol (IP) address, browser type, and interaction metrics used to optimize system performance.

2.2 Artificial Intelligence & Automated Processing

Our Service utilizes advanced Artificial Intelligence (AI) across multiple modules, including the AI Assistant, News Summarization, and Tarot readings.

  • Processing Scope: We use AI to summarize news articles, assist in drafting notes, and generate entertainment content (fortune telling).
  • Ephemeral Processing: Data sent to our AI Assistant or Tarot engine is processed in real-time. Unless you explicitly 'Save' the output, the reasoning context is ephemeral and not permanently stored.
  • Data Isolation: Your private storage files and personal calendar details are NOT used to train our public AI models. Your data remains yours.
  • Third-Party LLMs: We utilize third-party Large Language Models (LLMs) for inference. We implement strict data sanitization to strip PII before transmission where feasible.

3. Retention of Your Personal Data

The Operator will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.

For example, your 'Rabbit News' browsing history and 'Storage' files are retained until you delete them or close your account.

4. Location of Data (Cloud Infrastructure)

Our Service is hosted on modern cloud infrastructure (e.g., Supabase) to ensure high availability and security. This means your data is stored in secure data centers that may be located outside your immediate region. By using the Service, you acknowledge this necessary technical arrangement.

5. Disclosure of Your Personal Data

5.1 Service Transfer

If the Service is involved in a transfer of ownership or operational control, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.

5.2 Law Enforcement

Under certain circumstances, the Operator may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

6. Security of Your Personal Data

The security of Your Personal Data is important to Us. We employ commercially robust protections for your digital warehouse, notes, and profile data, including HTTPS encryption, database row-level security (RLS), and rigorous access logging to safeguard your information.

7. Your Rights under GDPR and CCPA

Depending on your location, you may have specific rights regarding your personal data:

  • The right to access, update or to delete the information We have on You.
  • The right of rectification. You have the right to have Your information rectified if that information is inaccurate or incomplete.
  • The right to object. You have the right to object to our processing of Your Personal Data.
  • The right of restriction. You have the right to request that We restrict the processing of Your personal information.
  • The right to data portability. You have the right to be provided with a copy of the information We have on You in a structured, machine-readable and commonly used format.
  • The right to withdraw consent. You also have the right to withdraw Your consent at any time where the Operator relied on Your consent to process Your personal information.

8. Yukine + Kohaku AI Assistant Services

8.1 Service Description

Yukine and Kohaku are AI-powered assistants integrated into the Gigantic Bear platform. They provide intelligent conversation, content generation, task assistance, real-time translation, and various productivity features. Both assistants operate as automated services powered by third-party Large Language Models (LLMs) and may access certain Google services on your behalf when authorized.

8.2 Google Account Data

When you authorize Yukine or Kohaku to connect with your Google account, the following data may be accessed:

  • Google Drive: Read and write access to files within designated folders for document collaboration, report generation, and file sharing.
  • Google Docs & Sheets: Read and write access to create, edit, and manage documents and spreadsheets on your behalf.
  • Google Slides: Read and write access to create, edit, and manage presentations on your behalf.
  • Google Analytics: Read-only access to website analytics data for generating traffic reports and insights.
  • Gmail (Read-Only): Read-only access to your email messages for retrieving information, summarizing emails, or performing tasks you explicitly request. The assistants cannot send, delete, or modify your emails.
  • Basic Profile Information: Your Google account email address and display name for authentication purposes.

8.3 How Google Data Is Used

Google account data accessed by Yukine and Kohaku is used solely to provide the services you have explicitly requested. Specifically:

  • Documents, spreadsheets, and presentations are created or edited only in response to your direct instructions.
  • Google Drive files are accessed only within folders you have authorized.
  • Gmail messages are read only when you explicitly request email-related tasks; the assistants never send, delete, or modify emails.
  • Analytics data is used exclusively to generate reports you have requested.
  • Your Google data is NOT used to train AI models, serve advertisements, or shared with any third parties.
  • Your Google data is NOT sold, rented, or disclosed to any external entity.

8.4 Data Storage & Retention

Yukine and Kohaku process most Google data in real-time and do not permanently store copies of your Google Drive files, documents, or spreadsheets. Temporary caches used during task execution are automatically purged. Conversation logs may be retained to improve service continuity, but these logs do not contain raw Google file contents. You may request deletion of all stored data at any time by contacting us.

8.5 Revoking Access

You may revoke Yukine and Kohaku's access to your Google account at any time through your Google Account settings (https://myaccount.google.com/permissions). Upon revocation, the assistants will immediately lose the ability to access your Google data, and any cached data will be purged within 24 hours.

9. Changes to this Privacy Policy

We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

10. Contact Us

If you have any questions about this Privacy Policy, You can contact us:
By email: [email protected]


Disclaimer: The interpretations provided by our Tarot service and AI Assistant are for reference and entertainment purposes only. Please do not rely on AI for critical medical, legal, or financial advice.


隐私政策

最后更新日期:2026年5月25日

本隐私政策描述了当您使用我们的生产力工具套件、新闻聚合器、数字仓库及生活方式服务时,我们收集、使用和披露您信息的政策和程序。Gigantic Bear 是一个非营利性的个人项目(用爱发电),我们承诺以最高标准保护您的隐私。

1. 解释与定义

1.1 解释

首字母大写的词语在以下条件下具有定义的含义。无论以单数还是复数形式出现,下列定义均具有相同的含义。

1.2 定义

  • “账户” 指为您创建的用于访问我们服务或部分服务的唯一账户。
  • “运营方”(在本协议中称为“运营方”、“我们”或“我们的”)是指 Gigantic Bear 的个人开发者。
  • “服务” 指本网站及其包含的功能生态,涵盖仪表盘、笔记、兔兔快报、数字仓库、占卜功能及雪音 AI 助手。
  • “个人数据” 是指与已识别或可识别的个人有关的任何信息。
  • “使用数据” 指自动收集的数据,这些数据可以是由使用服务产生的,也可以是服务基础设施本身产生的(例如,访问页面的持续时间)。

2. 收集和使用您的个人数据

2.1 收集的数据类型

为了赋能我们平台的多元化功能,我们收集多种不同类型的信息。

  • 个人身份信息:电子邮件地址(注册账户及订阅通讯所需)。
  • 生产力数据:您通过仪表盘管理的任务、日历日程、个人笔记及项目计划。
  • 数字资产:您上传至仓库或通过画板功能创作的图片、绘图及文件。
  • 偏好配置:您对兔兔快报新闻源的定制设置、界面主题(深色/亮色)及语言偏好。
  • 使用数据:互联网协议(IP)地址、浏览器类型及用于优化系统性能的交互指标。

3. 个人数据的保留

运营方仅在本隐私政策规定的目的所需的时间内保留您的个人数据。我们将在遵守我们的法律义务、解决争议以及执行我们的法律协议和政策所需的范围内保留和使用您的个人数据。

例如,您的“兔兔快报”浏览历史和“数字仓库”文件将保留直至您删除它们或注销账户。

4. 数据存储位置(云基础设施)

我们的服务托管在现代化的云基础设施(如 Supabase)上,以确保高可用性和安全性。这意味着您的数据会被安全地存储在可能位于您所在地区之外的数据中心。使用本服务即表示您理解并接受这种必要的跨区域技术架构。

5. 个人数据的披露

5.1 服务所有权转移

如果本服务涉及所有权转移或运营控制权变更,您的个人数据可能会被转移。在您的个人数据被转移并受不同的隐私政策约束之前,我们将发出通知。

5.2 执法

在某些情况下,如果法律要求或为了响应公共机构(例如法院或政府机构)的有效请求,运营方可能需要披露您的个人数据。

6. 个人数据的安全

您的个人数据的安全性对我们很重要。我们采用商业上可靠的保护措施来保护您的数字仓库、笔记和个人资料数据,包括 HTTPS 加密、数据库行级安全(RLS)和严格的访问日志记录,以保障您的信息安全。

7. 您在 GDPR 和 CCPA 下的权利

根据您所在的位置,您可能对您的个人数据拥有特定权利:

  • 访问、更新或删除我们拥有的关于您的信息的权利。
  • 更正权。如果您的信息不准确或不完整,您有权要求更正您的信息。
  • 反对权。您有权反对我们处理您的个人数据。
  • 限制权。您有权要求我们限制处理您的个人信息。
  • 数据可携带权。您有权获得我们拥有的关于您的信息的副本,格式应为结构化、机器可读且常用的格式。
  • 撤回同意权。在运营方依赖您的同意来处理您的个人信息的情况下,您也有权随时撤回您的同意。

8. Yukine + Kohaku AI 助手服务

8.1 服务描述

雪音 (Yukine) 和琥珀 (Kohaku) 是集成于 Gigantic Bear 平台的 AI 智能助手。它们提供智能对话、内容生成、任务辅助、实时翻译及多种生产力功能。两个助手均作为自动化服务运行,由第三方大语言模型 (LLM) 驱动,在您授权的情况下可代表您访问某些 Google 服务。

8.2 Google 账户数据

当您授权雪音或琥珀连接您的 Google 账户时,以下数据可能会被访问:

  • Google Drive:对指定文件夹内的文件进行读写访问,用于文档协作、报告生成和文件共享。
  • Google Docs 和 Sheets:读写访问权限,用于代表您创建、编辑和管理文档与电子表格。
  • Google Slides:读写访问权限,用于代表您创建、编辑和管理演示文稿。
  • Google Analytics:只读访问网站分析数据,用于生成流量报告和洞察。
  • Gmail(只读):对您的电子邮件进行只读访问,用于在您明确请求时检索信息、总结邮件或执行相关任务。助手无法发送、删除或修改您的邮件。
  • 基本个人资料信息:您的 Google 账户电子邮件地址和显示名称,仅用于身份验证。

8.3 Google 数据的使用方式

雪音和琥珀访问的 Google 账户数据仅用于提供您明确请求的服务。具体来说:

  • 文档、电子表格和演示文稿仅在您直接指示下创建或编辑。
  • Google Drive 文件仅在您授权的文件夹内访问。
  • Gmail 邮件仅在您明确请求邮件相关任务时读取;助手绝不会发送、删除或修改邮件。
  • 分析数据仅用于生成您请求的报告。
  • 您的 Google 数据不会被用于训练 AI 模型、投放广告或与任何第三方共享。
  • 您的 Google 数据不会被出售、出租或披露给任何外部实体。

8.4 数据存储与保留

雪音和琥珀实时处理大部分 Google 数据,不会永久存储您的 Google Drive 文件、文档或电子表格的副本。任务执行期间使用的临时缓存会自动清除。对话记录可能会被保留以改善服务连续性,但这些记录不包含原始 Google 文件内容。您可以随时通过联系我们请求删除所有已存储的数据。

8.5 撤销访问权限

您可以随时通过 Google 账户设置 (https://myaccount.google.com/permissions) 撤销雪音和琥珀对您 Google 账户的访问权限。撤销后,助手将立即失去访问您 Google 数据的能力,任何缓存数据将在 24 小时内清除。

9. 本隐私政策的变更

我们可能会不时更新我们的隐私政策。我们将通过在本页面上发布新的隐私政策来通知您任何更改。建议您定期查看本隐私政策以了解任何更改。本隐私政策的更改在本页面发布时生效。

10. 联系我们

如果您对本隐私政策有任何疑问,您可以联系我们:
通过电子邮件:[email protected]


Disclaimer: 本网站塔罗服务及 AI 助手提供的解读仅供参考与娱乐。请勿依赖 AI 做出关键的医疗、法律或财务决策。


Home | Privacy Policy | Terms of Service