Memo 隐私政策
最后更新:2026 年 10 月 6 日 · 运营方:ArkStella · 联系邮箱:support@arkstella.com
本隐私政策说明 ArkStella(下称“ArkStella”或“我们”)在你使用 Memo(下称“本服务”,即 Memo 网页应用)时如何处理你的信息。本政策是 Memo 《服务条款》的一部分,受其约束。
访问或使用本服务,即表示你已阅读并理解本隐私政策,并同意其中描述的做法。如果你不同意,请不要使用本服务。
1. 概要
Memo 是一个跨设备的剪贴板:在一台设备上粘贴文字或图片,在你的其他设备上打开 Memo 就能看到并复制。为此,我们会在服务器上保存你粘贴的内容,并且加密保存(见第 7 节)。你的账号就是你的邮箱地址:可以用发到邮箱的一次性验证码登录,也可以用 Google 账号登录。用 Google 登录时,我们只拿到你的邮箱地址,永远拿不到你的 Google 密码(见第 4 节)。我们不出售你的个人信息,不放广告,也不做跨网站追踪。本概要只是为了方便阅读,不能代替下面的完整政策。
2. 我们是谁
ArkStella 是 Memo 的运营方,是通过本服务处理的个人信息的控制者。有任何隐私问题,或者想行使你的权利,请发邮件到 support@arkstella.com。
3. 我们处理哪些信息
我们只收集和处理提供本服务所需要的信息:
- 账号信息。你的邮箱地址。用邮箱验证码登录时,我们生成一个一次性验证码发到你的邮箱;用 Google 登录时,我们收到第 4 节所述的有限信息。我们的服务器上不以明文保存你的邮箱地址:你的数据存放在一个由邮箱经过带密钥的单向哈希(HMAC)算出来的文件夹里,从文件夹名推不回你的邮箱。
- 你存进 Memo 的内容。你粘贴或上传的文字、图片(以及浏览器为图片生成的缩略图)、你加的标签和项目名称。这些内容加密保存(见第 7 节)。
- 登录和防滥用记录。一次性验证码只以带密钥的哈希形式保存,10 分钟后失效,用过一次就作废。为了限制验证码的发送和尝试次数,我们会记录次数;这些计数按你的邮箱和 IP 地址经过带密钥的哈希之后的值来记,不保存 IP 地址原文。
- 技术数据。你使用本服务时,我们的托管服务商 Cloudflare 会处理 IP 地址、浏览器类型、请求时间等技术信息,用于传送内容、保障安全和排查故障。
- 保存在你设备上的数据。本服务会在你的浏览器里保存登录 cookie 和你的内容的本地副本,让页面打开更快(见第 12 节)。
Memo 会保存你粘贴进去的任何内容。请不要用它长期存放密码、银行卡号、证件号码等高度敏感的信息;如果需要在自己的设备之间临时传一下,复制完请删除。
4. 用 Google 登录
Memo 提供用 Google 登录,这是可选的登录方式之一。用不用完全由你决定:你也可以只用发到邮箱的一次性验证码登录,完全不经过 Google。
我们获取哪些 Google 用户数据。你选择用 Google 登录时,我们使用 Google 的 OAuth 2.0 登录,只申请 openid 和 email 两个权限范围。通过它们,Google 会提供:
- 你的邮箱地址;
- 这个邮箱是否已通过 Google 验证;
- 你的 Google 账号标识(Google 为你的账号分配的唯一编号)。
我们只使用你的邮箱地址和它是否已验证,不保存你的 Google 账号标识。我们不申请、也不会收到你的姓名、头像、联系人、日历、Gmail、Google 云端硬盘或任何其他 Google 数据,也永远不会收到或保存你的 Google 密码。
我们如何使用 Google 用户数据。只有一个用途:用这个邮箱地址创建你的 Memo 账号(或者找到同一邮箱已有的账号),让你安全登录。同一个邮箱,用 Google 登录和用邮箱验证码登录,进入的是同一个账号。我们不把 Google 用户数据用于广告或建立关于你的画像,也不用它训练人工智能或机器学习模型。
我们如何共享 Google 用户数据。我们不出售 Google 用户数据,也不把它转让或披露给第三方。例外只有两种:为了让登录正常工作,托管本服务的基础设施服务商(数据处理方)会接触到它;或者法律要求披露。范围和第 6 节(我们如何共享信息)、第 7 节(安全和加密)所述相同。
我们如何保护和保留 Google 用户数据。你的邮箱地址通过 TLS/HTTPS 传输;在我们的服务器上,它只以第 3 节所述的带密钥哈希的形式使用,并按第 7 节受到保护。你的登录 cookie 里带有你的邮箱地址,并经过签名、无法被篡改;它保存在你自己的浏览器里,在你最后一次使用 30 天后失效,退出登录时也会被清除。删除账号时,相关数据按第 9 节(数据保留)删除。
有限使用(Limited Use)。Memo 对从 Google API 获得的信息的使用,以及向任何其他应用的传输,都将遵守 Google API 服务用户数据政策,包括其中的“有限使用”要求。
你可以在 Google 隐私权政策中了解 Google 如何处理你的信息,也可以随时在 Google 账号的第三方访问权限页面查看或撤销 Memo 对你 Google 账号的访问权限。
5. 我们如何使用信息
我们用上述信息来:
- 提供、维护本服务,在你的设备之间同步内容,保障本服务和你账号的安全;
- 验证你的身份,防止欺诈、滥用和未经授权的访问;
- 给你发送登录验证码邮件;
- 回复你的支持请求,发送与服务相关的通知;
- 监控、排查和改进本服务的性能和可靠性;
- 遵守法律,执行我们的服务条款。
我们不会为了广告或任何与提供本服务无关的目的去查看或分析你存进 Memo 的内容。
在适用的情况下(例如欧盟 / 英国的 GDPR),我们处理信息的法律依据是:履行与你的合同(提供本服务);我们的正当利益(保障和改进本服务、防止滥用);以及遵守法律义务。
6. 我们如何共享信息
我们不出售你的个人信息,除下列情况外也不共享:
- 服务商(数据处理方)。我们用少数几家服务商来运行本服务,它们只按我们的指示处理信息,并且只接触完成各自功能所需的数据:
- Cloudflare:托管网站和接口,存储你加密后的内容(Cloudflare Workers 和 R2);
- Brevo:发送登录验证码邮件,会收到你的邮箱地址和这封邮件的内容;
- Google:仅在你选择用 Google 登录时,由 Google 验证你的身份并告诉我们你的邮箱地址(见第 4 节)。
- 法律和安全。如果我们善意地认为法律、法律程序或政府要求需要披露,或者为了保护 ArkStella、用户或公众的权利、财产或安全,或者为了执行我们的条款,我们可能会披露信息。
- 业务转让。如果 ArkStella 发生合并、收购、融资或资产出售,信息可能作为交易的一部分被转移,并继续受本政策约束。
7. 安全和加密
- 传输加密:全程使用 TLS/HTTPS。
- 存储加密:你存进 Memo 的所有内容都加密保存(AES-256,使用 Cloudflare R2 的客户提供密钥加密方式)。密钥由一把单独保管的主密钥派生,存储服务商那里不保留密钥,所以只拿到存储里的数据是读不出内容的。这把密钥由我们管理。
- 登录保护:登录 cookie 设为 HttpOnly 和 Secure,并经过签名防篡改;一次性验证码只保存带密钥的哈希,10 分钟后失效,错 5 次即作废;发送和尝试验证码都有次数限制。
没有任何传输或存储方式是绝对安全的。我们会尽力保护你的信息,但无法也不保证绝对安全,你使用本服务需自行承担风险。能进入你邮箱(或你的 Google 账号)的人就能登录你的 Memo,所以请保管好它们;发现有人未经授权使用你的账号,请尽快通知我们。
8. 跨境数据传输
我们使用的基础设施和服务商可能在你所在国家 / 地区以外的地方处理信息,那里的数据保护法律可能与你所在地不同。在法律要求时,我们会为这类传输采取适当的保障措施(例如标准合同条款)。使用本服务,即表示你理解你的信息可能在这些地方处理。
9. 数据保留
- 你存进 Memo 的内容会一直保存,直到你删除它。删除一条内容,会把它(包括图片原图和缩略图)从我们的存储中删掉;删除一个项目,会删掉这个项目里的全部内容。
- 一次性验证码 10 分钟后失效。防滥用的计数只用于限制次数,会被不断覆盖。
- 想删除账号及其全部内容,请发邮件到 support@arkstella.com。我们会在合理的时间内删除,法律要求保留的除外。
- 服务商保留的技术日志,按它们各自的保留期限滚动删除。
10. 你的权利和选择
视你所在地的法律,你可能对你的个人信息享有访问、更正、导出(可携带)、删除,或限制、反对某些处理的权利,以及撤回同意的权利。欧洲经济区和英国的居民享有 GDPR 规定的权利;加州居民享有 CCPA/CPRA 规定的权利,包括不因行使这些权利而受到歧视(说明:按这些法律的定义,我们不“出售”也不“共享”个人信息)。
你可以:
- 随时在 Memo 里直接查看、修改、复制和删除你的内容,以及删除项目;
- 退出登录,这会清除这台设备浏览器里的登录 cookie 和你的内容的本地副本,并让浏览器清掉本站缓存的图片(浏览器支持时);
- 发邮件到 support@arkstella.com 行使任何权利,包括删除账号。我们会在适用法律要求的期限内回复;处理请求前,我们可能需要确认你的身份。
11. 儿童
Memo 是面向一般用户的工具,不是专门为儿童设计或面向儿童的,我们也不会故意收集儿童的个人信息。如果未成年人使用本服务,应由其父母或监护人负责并加以监督。如果你认为有儿童在没有父母或监护人参与的情况下向我们提供了个人信息,请联系我们,我们会删除。
12. Cookie 和本机存储
本服务只使用运行所必需的 cookie 和本机存储:
- memo_session:让你保持登录。有效期 30 天,持续使用会自动续期;
- memo_oauth:只在用 Google 登录的过程中使用的临时 cookie,用于防范跨站请求伪造,10 分钟后失效;
- memo_auth_error:用 Google 登录失败时,把失败原因带回登录框,60 秒后失效;
- 浏览器本地存储:你的邮箱地址、项目列表、让页面打开更快的内容本地副本,以及界面偏好(浅色 / 深色、侧栏是否展开、标签的筛选方式)。退出登录时,与账号有关的数据会被清除;界面偏好会保留。
我们不使用第三方广告 cookie,也不做跨网站追踪。
13. 第三方链接和服务
本服务可能链接到第三方网站,或依赖第三方服务(例如用 Google 登录)。我们不对这些第三方的隐私做法或内容负责,本政策也不适用于它们,请另行查看它们的政策。
14. 本政策的变更
我们可能会不时更新本隐私政策。更新时,我们会修改上方的“最后更新”日期,并在本网址发布新版本;重大变更可能会在应用内提示。更新后你继续使用本服务,即表示你接受修订后的政策。
语言版本。本政策有中文和英文两个版本;两者如有不一致,以英文版本为准。
15. 联系我们
关于隐私的问题、请求或投诉:
ArkStella — Memo
邮箱:support@arkstella.com
如果你在欧洲经济区或英国,并认为我们没有妥善处理你的问题,你也可能有权向当地的数据保护机构投诉。
Memo — Privacy Policy
Last updated: October 6, 2026 · Operator: ArkStella · Contact: support@arkstella.com
This Privacy Policy explains how ArkStella (“ArkStella”, “we”, “us”, or “our”) handles information in connection with Memo (the “Service”) — the Memo web application. It forms part of, and is governed by, the Memo Terms of Service.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy and agree to the practices described in it. If you do not agree, do not use the Service.
1. Summary
Memo is a cross-device clipboard: paste text or images on one device, then open Memo on your other devices to see and copy them. To do that, we store the content you paste on our servers, encrypted at rest (see Section 7). Your account is simply your email address: you sign in with a one-time code sent to your email, or with your Google account — in which case we receive your email address and never your Google password (see Section 4). We do not sell your personal information, show ads, or track you across websites. This Summary is for convenience only and does not replace the full Policy below.
2. Who we are
ArkStella is the operator of Memo and the controller responsible for personal information processed through the Service. You can reach us at support@arkstella.com for any privacy question or to exercise your rights.
3. Information we process
We collect and process only what is needed to provide the Service:
- Account information. Your email address. For email sign-in, we generate a one-time code and send it to your email; for Google sign-in, we receive the limited information described in Section 4. We do not keep your email address in plain text on our servers: your data is stored under a folder name derived from your email address with a keyed one-way hash (HMAC), which cannot be turned back into your email address.
- Content you store in Memo. The text and images you paste or upload (and the thumbnails your browser generates for images), the tags you add, and your project names. This content is stored encrypted (see Section 7).
- Sign-in and anti-abuse records. One-time codes are stored only as keyed hashes, expire after 10 minutes, and stop working once used. To limit how often codes can be sent and tried, we keep counters, keyed by keyed hashes of your email address and of your IP address — we do not store the IP address itself.
- Technical data. When you use the Service, our hosting provider Cloudflare processes technical information such as your IP address, browser type, and request times in order to deliver content, keep the Service secure, and diagnose problems.
- Data stored on your device. The Service keeps a sign-in cookie and a local copy of your content in your browser so that pages open quickly (see Section 12).
Memo stores whatever you paste into it. Please do not use it to keep passwords, payment card numbers, government ID numbers, or similarly sensitive information; if you need to pass such information between your own devices, delete it once you have copied it.
4. Signing in with Google
Memo offers Sign in with Google as one optional way to sign in. Using it is entirely your choice — you can instead sign in with a one-time code sent to your email address and never involve Google.
What Google user data we access. When you choose Sign in with Google, we use Google’s OAuth 2.0 sign-in with the openid and email scopes only. Through these, Google provides:
- your email address;
- whether that email address is verified by Google; and
- your Google account identifier (the unique ID Google assigns to your account).
We use only your email address and whether it is verified, and we do not store your Google account identifier. We do not request or receive your name, profile photo, contacts, calendar, Gmail, Google Drive, or any other Google data, and we never receive or store your Google password.
How we use Google user data. We use it for one purpose only: to create your Memo account (or match you to your existing account with the same email address) and sign you in securely. Signing in with Google and signing in with an email code for the same email address open the same account. We do not use Google user data for advertising or for building profiles about you, and we do not use it to train artificial-intelligence or machine-learning models.
How we share Google user data. We do not sell Google user data and do not transfer or disclose it to third parties, except to the infrastructure providers (processors) that host the Service solely so that sign-in can function, or where disclosure is required by law — the same limits described in Sections 6 (How we share information) and 7 (Security and encryption).
How we protect and retain Google user data. Your email address is transmitted over TLS/HTTPS. On our servers it is used only in the keyed-hash form described in Section 3 and is protected as described in Section 7. Your sign-in cookie contains your email address and is signed so that it cannot be altered; it is stored in your own browser and expires 30 days after you last use the Service, or when you sign out. When you delete your account, the associated data is deleted as described in Section 9 (Data retention).
Limited Use. Memo’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can review how Google handles your information in the Google Privacy Policy, and you can review or revoke Memo’s access to your Google Account at any time from your Google Account permissions.
5. How we use information
We use the information above to:
- provide, maintain, sync across your devices, and secure the Service and your account;
- authenticate you and prevent fraud, abuse, and unauthorized access;
- send you sign-in code emails;
- respond to your support requests and send service-related notices;
- monitor, debug, and improve the performance and reliability of the Service; and
- comply with law and enforce our Terms of Service.
We do not look at or analyze the content you store in Memo for advertising or for any purpose unrelated to providing the Service.
We rely on the following legal bases where applicable (e.g., under the EU/UK GDPR): performance of our contract with you (providing the Service); our legitimate interests (securing and improving the Service, preventing abuse); and compliance with legal obligations.
6. How we share information
We do not sell your personal information, and we do not share it except as follows:
- Service providers (processors). We use a small number of vendors to run the Service. They process information only on our instructions and are limited to the data needed for their function:
- Cloudflare — hosts the website and API and stores your encrypted content (Cloudflare Workers and R2);
- Brevo — delivers sign-in code emails, and receives your email address and the content of that email;
- Google — only if you choose Sign in with Google, Google authenticates you and tells us your email address (see Section 4).
- Legal and safety. We may disclose information if we believe in good faith that it is required by law, legal process, or a governmental request, or is necessary to protect the rights, property, or safety of ArkStella, our users, or the public, or to enforce our Terms.
- Business transfers. If ArkStella is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
7. Security and encryption
- Encryption in transit using TLS/HTTPS.
- Encryption at rest. Everything you store in Memo is encrypted at rest (AES-256, using Cloudflare R2’s customer-provided-key encryption). The key is derived from a master key that is kept separately from the storage; the storage provider does not keep it, so a copy of the stored data alone cannot be read. We manage this key.
- Sign-in protection. The sign-in cookie is HttpOnly and Secure and is signed against tampering; one-time codes are stored only as keyed hashes, expire after 10 minutes, and are invalidated after 5 wrong attempts; sending and trying codes are rate-limited.
No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot and do not guarantee absolute security, and you use the Service at your own risk. Anyone who can access your email account (or your Google account) can sign in to your Memo, so keep them secure, and notify us promptly of any suspected unauthorized use.
8. International data transfers
We use infrastructure and providers that may process information in countries other than your own, whose data-protection laws may differ from those where you live. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for such transfers. By using the Service, you understand that your information may be processed in these locations.
9. Data retention
- Content you store in Memo is kept until you delete it. Deleting an item removes it — including the original image and its thumbnail — from our storage; deleting a project removes everything in that project.
- One-time sign-in codes expire after 10 minutes. Anti-abuse counters are used only for rate limiting and are continually overwritten.
- To delete your account and all of its content, email support@arkstella.com. We will delete it within a commercially reasonable period, except where retention is required by law.
- Technical logs kept by our providers are deleted on a rolling basis according to their own retention periods.
10. Your rights and choices
Depending on where you live, you may have rights over your personal information, including the rights to access, correct, export (portability), delete, or restrict or object to certain processing, and to withdraw consent. Residents of the European Economic Area and the United Kingdom have rights under the GDPR; residents of California have rights under the CCPA/CPRA, including the right not to be discriminated against for exercising them (note: we do not sell or “share” personal information as those terms are defined).
You can:
- view, edit, copy, and delete your content, and delete projects, directly in Memo at any time;
- sign out, which removes the sign-in cookie and the local copy of your content from that browser, and asks the browser to clear the images it has cached from Memo (where the browser supports it); and
- contact us at support@arkstella.com to exercise any right, including deleting your account. We will respond within the timeframe required by applicable law. We may need to verify your identity before acting on a request.
11. Children
Memo is a general-audience tool. It is not designed for or specifically directed at children, and we do not knowingly collect personal information from children. Where a minor uses the Service, a parent or guardian is responsible for that use and should supervise it. If you believe a child has provided us personal information without the involvement of a parent or guardian, contact us and we will delete it.
12. Cookies and local storage
The Service uses only cookies and local storage that are strictly necessary for it to work:
- memo_session — keeps you signed in; valid for 30 days and renewed automatically while you keep using the Service;
- memo_oauth — a temporary cookie used only during Sign in with Google, to protect against cross-site request forgery; expires after 10 minutes;
- memo_auth_error — if Sign in with Google fails, carries the reason back to the sign-in box; expires after 60 seconds;
- Browser local storage — your email address, your project list, a local copy of your content so that pages open quickly, and display preferences (light / dark theme, whether the sidebar is open, how tag filters combine). The account-related data is removed when you sign out; display preferences are kept.
We do not use third-party advertising cookies or cross-site tracking.
13. Third-party links and services
The Service may link to third-party websites or rely on third-party services (such as Sign in with Google). We are not responsible for the privacy practices or content of those third parties, and this Policy does not apply to them. Review their policies separately.
14. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and post the new version at this URL; material changes may be highlighted in the app. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
Languages. This Policy is available in Chinese and English. If there is any inconsistency between the two versions, the English version prevails.
15. Contact us
Questions, requests, or complaints about privacy:
ArkStella — Memo
Email: support@arkstella.com
If you are in the EEA or UK and believe we have not addressed your concern, you may also have the right to lodge a complaint with your local data-protection authority.