Privacy Policy

隐私政策

更新日期:2026年10月6日

单玉提琴是供琴房老师、教务及已报名学生使用的课程管理工具,由 Wang Yue 提供。联系邮箱:support@wangyue.org。

我们处理的信息及用途

正式使用需匹配琴房已登记的人员资料。使用 Apple 登录时,我们处理 Apple 提供的用户标识及经授权提供的姓名、邮箱,用于身份验证、账号关联和人员权限管理,不获取 Apple 密码。也可使用老师登记邮箱手动登录:邮箱、姓名选项、完整姓名和性别答案会通过加密连接交给我们的验证服务,与已登记资料核对;这不是邮箱验证码登录。验证服务处理登录会话和必要的防滥用请求信息,用于维持登录和限制重复尝试,不用于广告。

新老师可在 Apple 验证后提交真实姓名以及原老师目录支持的个人资料申请加入;隐藏邮箱同样可用。申请须由琴房确认人员权限后才可访问教学记录。学生可输入报名时登记的姓名和完整手机号,由 Cloudflare 托管的服务与飞书档案匹配后,只返回本人的排课。该方式为登记资料匹配,不是短信验证码验证,也不代表验证了手机号当前所有权。

由授权人员录入的学生姓名、昵称、联系方式、性别、年龄范围、学习目标、课包与剩余课时、课程日期、课程类型、老师、上课地点及教学备注、试听咨询、跟进状态、用户主动选取的聊天截图,以及缴费日期、金额、方式和购买课节记录,以及老师的任职和教学资料,用于建档、排课和教学管理。相关业务记录通过加密连接保存于琴房使用的飞书多维表格,并提供给具有相应权限的琴房工作人员。请仅录入开展教学所必需、且已获学生或监护人授权的信息,勿在备注中填写无关敏感资料。

本版本不使用广告、跨应用追踪或第三方分析SDK,不出售个人信息,不将教学资料用于广告或营销。

使用人数与版本统计

自0.15.3版起,为了解实际使用人数、核对版本更新及旧入口迁移,我们在已验证账号进入应用或恢复使用时,记录由账号派生的去标识化统计键、iOS或Android平台、应用版本和构建号、首次及最近使用日期。同一账号在同一平台按日合并记录,版本变化时更新。统计记录不保存姓名、邮箱、手机号、IP、设备广告标识或具体操作内容;仅向管理员展示人数及平台、版本汇总,不用于广告或跨应用追踪。统计由现有Cloudflare服务处理,连续90天未使用该平台的统计在后续统计更新时清理;账号注销后清除对应统计。为防止注销时尚在传输的旧请求重新写入统计,仅保留去标识化账号键及到期时间的阻断标记,有效期30天,到期后在后续统计请求中清理。统计键仍与账号相关联,不将其声称为完全匿名数据。旧版本或未重新验证的旧Apple会话可能不被统计,因此统计人数不等于全部安装人数。

设备上的信息

登录凭据保存在系统钥匙串,界面偏好保存在本机。用户选择保存的表单草稿及所选附件保存在本机,完成提交或丢弃后清除。复制课程提醒仅在用户主动点击时将预览文字写入系统剪贴板,App不会自动发送到微信群。桌面小组件会在本机共享容器保存当前账号可见的课程摘要;退出登录时清除该摘要。添加小组件后,学生姓名和课程安排可能显示在设备主屏幕,请妥善保护设备。

通知权限由用户在系统中决定。当前版本仅在本机注册并保存推送设备标识,尚未提供自动课程通知发送服务,不将该标识上传到开发者通知服务器。

第三方服务

Apple 提供登录服务;飞书承担教学业务数据存储与接口服务;我们的登录验证、学生课表访问和账号注销服务托管于 Cloudflare,处理验证请求、会话、必要的防滥用信息,以及注销时与 Apple、飞书的接口请求。使用这些服务还受其各自隐私政策约束。教学记录并非仅存储于设备本地。

保存、更正与删除

教学资料在琴房数据库中保存,直至琴房依据业务需要和适用要求删除。退出登录或卸载App不会自动删除数据库里的教学记录。老师可在“设置 → 注销账号”发起删除;尚未获准加入的老师也可在申请页面选择“注销账号并撤回申请”。确认身份后,系统撤销本App的 Apple 授权(已绑定 Apple 的账号),清除老师目录中的个人资料、登录绑定及使用权限,并退出登录。学生、课包及历史排课是琴房业务记录,不因老师注销而删除;其中原老师的关联保留为不含其姓名、联系方式等资料的“已注销老师”。如需查询、更正、删除学生资料或其他关联业务记录,请联系琴房管理员或 support@wangyue.org,核实身份后处理。退出学生登录会清除本机学生会话;学生入口不新建学生档案。

未成年人及体验模式

学生入口面向已有报名档案的学生,不提供学生自助建档。录入未成年学生资料前应取得监护人的适当授权。审核体验模式只包含虚构资料,修改仅在内存中保留,退出或重新启动后重置,不连接正式教学数据库。

English summary

Shanyu Violin supports studio teachers, coordinators and enrolled students. Teachers can apply after Apple authentication, including Hide My Email; access to teaching records requires studio approval. Students use their registered name and full phone number to match an existing enrollment record and view only their own schedule. This is profile matching, not SMS verification or proof of current phone ownership. Sign in with Apple supplies an app-specific user identifier and, where authorized, name and email for authentication and staff matching. Authorized staff manage student contact details, learning goals, lesson packages, schedules, locations, staff profiles and teaching notes. Authorized staff also record payment amounts, dates and methods, consultation status and voluntarily selected screenshot attachments. Production records are stored in the studio's Feishu database over encrypted connections and accessed for app functionality by authorized staff. Optional manual sign-in sends the registered email, name and profile challenge answers to our Cloudflare-hosted service for matching, sessions, scoped student schedule access, account deletion and abuse prevention; it does not send an email verification code. We do not use advertising or analytics SDKs, sell personal data, or track users across apps.

Starting with version 0.15.3, verified account use is recorded to understand active account counts, app version adoption and migration from old download addresses. Our existing Cloudflare service stores a pseudonymous account-derived key, platform, app version/build, and first/last use dates, consolidated per account and platform each day or when the version changes. Usage records do not store names, email addresses, phone numbers, IP addresses, advertising identifiers or detailed actions. Administrators receive aggregate counts by platform and version. An account’s platform record becomes eligible for cleanup after 90 days of inactivity and is removed during a subsequent statistics update, and the associated staff account’s records are removed on deletion. To prevent an in-flight request from recreating usage after deletion, a block marker containing only the pseudonymous account key and expiry is retained for 30 days and cleaned up on a subsequent statistics request. These records remain account-linked and are not described as fully anonymous. Older versions and existing Apple sessions may not be covered, so active counts are not total installations. This information is not used for advertising or cross-app tracking.

Credentials use the system Keychain. Saved form drafts and selected attachments remain on the device until submitted or discarded. Copying a lesson reminder is an explicit user action that writes to the system clipboard; the app does not automatically message others. Widgets store authorized lesson summaries locally; signing out clears them. Push registration is currently local only; automatic lesson notifications are not available. Demo data is fictional and session changes reset on restart or exit. Signing out or uninstalling does not delete production records. Contact the studio administrator or support@wangyue.org for access, correction, deletion or account unlinking requests. Staff must obtain appropriate authorization before recording student or minor information.

Teachers can delete their account in Settings; pending applicants can withdraw and delete from the application screen. After identity confirmation, the service revokes this app’s Apple authorization when linked and removes personal profile details, sign-in bindings and access. Studio student, package and lesson records remain, with historical teacher links anonymized as Deleted teacher. Student sign-in does not create enrollment records; contact the studio for student record deletion.