นโยบายความเป็นส่วนตัว

ภาษาไทย

เอกสารนี้อธิบายตรงไปตรงมาว่าเราจัดการข้อมูลของคุณอย่างไร — อะไรที่ระบบเข้าถึงไม่ได้เลย และ ข้อมูลส่วนไหนที่ต้องผ่านเซิร์ฟเวอร์เพื่อให้ผู้ช่วยทำงานได้

1. สิ่งที่เรามองไม่เห็น

  • เนื้อหาข้อความแชต — เข้ารหัสแบบต้นทางถึงปลายทางบนระบบ Matrix เฉพาะคุณกับคนที่ร่วมสนทนาเท่านั้นที่เปิดอ่านได้ เซิร์ฟเวอร์เก็บไว้แค่ข้อความที่เข้ารหัสแล้ว ไม่มีทางเปิดอ่านได้
  • ความทรงจำ บันทึก และไฟล์ของคุณ — ข้อมูลจะถูกเข้ารหัสบนเครื่องก่อนส่งขึ้นเซิร์ฟเวอร์เสมอ เซิร์ฟเวอร์จึงเก็บไว้เป็นข้อความที่อ่านไม่ออก กุญแจถอดรหัสอยู่บนเครื่องคุณคนเดียว ระบบจะถอดรหัสและใช้งานบนเครื่องของคุณเท่านั้น

ข้อยกเว้นที่ต้องบอกกันตรง ๆ: บทสนทนากับผู้ช่วยเอไอ จะไม่ได้เข้ารหัสแบบต้นทางถึงปลายทาง เพราะระบบต้องส่งข้อความให้โมเดลประมวลผล โดยค่าเริ่มต้นจะส่งผ่านเซิร์ฟเวอร์ของเราไปหาโมเดล แต่เราไม่ได้เก็บบันทึกบทสนทนานั้นไว้ และไม่ส่งบัญชีของคุณต่อให้ผู้ให้บริการโมเดล ดูรายละเอียดเพิ่มเติมในข้อ 4

2. ข้อมูลที่เราประมวลผล

  • บัญชี — รหัสผู้ใช้ระบบ Matrix และข้อมูลยืนยันตัวตน เพื่อให้คุณล็อกอินและซิงก์ข้อมูลข้ามเครื่องได้ (ชื่อผู้ใช้ถูกเข้ารหัสลับไว้) รวมถึงอีเมล ในกรณีที่คุณเลือกล็อกอินด้วย Google หรือ Apple
  • การแจ้งเตือน — โทเค็นอุปกรณ์จากระบบ Firebase เพื่อใช้ส่งการแจ้งเตือน โดยข้อความแจ้งเตือนที่ส่งไปจะไม่แนบเนื้อหาหรือความทรงจำของคุณไปด้วย
  • การสมัครสมาชิก — สถานะแพ็กเกจพรีเมียมจัดการผ่าน App Store, Google Play และ RevenueCat เราไม่เห็นและไม่ได้เก็บข้อมูลบัตรของคุณ สโตร์ของ Apple และ Google เป็นผู้ดูแลการชำระเงินทั้งหมด
  • กล้อง — ใช้สำหรับสแกนเอกสารเพื่อแปลงเป็นข้อความ การทำงานเกิดขึ้นบนเครื่องของคุณ รูปภาพจะไม่ถูกอัปโหลดขึ้นเซิร์ฟเวอร์
  • คลังรูป (ถ้าคุณอนุญาต) — ใช้กับฟีเจอร์สแกนสลิปย้อนหลังเท่านั้น คือเปิดดูรูปที่คุณถ่ายไว้ในช่วงวันที่คุณเลือก เพื่อหาใบเสร็จและสลิปโอนมาให้คุณดูก่อนจดลงสมุดบัญชี การคัดกรองเกิดบนเครื่องคุณทั้งหมด — ปิ่นเปิดดูทุกรูปในช่วงที่คุณเลือกบนเครื่อง เพื่อหาว่าใบไหนเป็นใบเสร็จหรือสลิปโอน รูปทั้งคลังไม่ถูกอัปโหลด จากนั้นเฉพาะใบที่เป็นสลิปจริง (โดยทั่วไปไม่กี่ใบจากหลายสิบรูป) จะถูกส่งไปให้ AI อ่านยอด วันที่ และคู่ค้า เพื่อให้ได้ตัวเลขที่ถูกต้อง · เราไม่ลบ ไม่ย้าย ไม่แก้ไขรูปในคลังของคุณ · ถ้าคุณกดบันทึกรายการแล้วเลือกเก็บสลิปไว้เป็นหลักฐาน สลิปใบนั้นจะถูกเก็บแบบเข้ารหัสในห้องข้อมูลของคุณเอง · บนแอนดรอยด์ 14 ขึ้นไป คุณเลือกให้เห็นเฉพาะบางรูปได้ และปิ่นจะอ่านเฉพาะรูปที่คุณแชร์ให้
  • การเชื่อมต่อ Gmail (ถ้าเปิดใช้) — เป็นการขอสิทธิ์ตามขอบเขตที่คุณอนุญาต คุณสามารถกดยกเลิกสิทธิ์นี้ได้ทุกเมื่อผ่านการตั้งค่าบัญชี Google ของคุณ
  • งานตั้งเวลาและการเตือน — เซิร์ฟเวอร์รู้แค่ว่าต้องปลุกบัญชีไหนในเวลาไหน โดยไม่เห็นเนื้อหาของงาน รายละเอียดงานจริงเก็บอยู่บนเครื่องคุณเท่านั้น
  • เราไม่เก็บ — ตำแหน่งที่อยู่ รายชื่อผู้ติดต่อ หรือพฤติกรรมการใช้งานเพื่อไปยิงโฆษณา

3. เราใช้ข้อมูลทำอะไร

เราใช้ข้อมูลเพื่อให้บริการผู้ช่วยเท่านั้น (เช่น ล็อกอิน ซิงก์ข้อมูลข้ามเครื่อง ส่งการแจ้งเตือน จัดการสมาชิก) และส่งอีเมลตามที่คุณขอ เราไม่นำข้อมูลของคุณไปยิงโฆษณา และไม่ขายต่อให้ใคร รายได้ของแอปมาจากค่าสมาชิกพรีเมียมเท่านั้น ไม่นำข้อมูลของคุณไปหารายได้

4. ผู้ช่วยเอไอทำงานอย่างไร

โดยค่าเริ่มต้น ข้อความที่คุณคุยกับเอไอจะถูกส่งผ่านเซิร์ฟเวอร์ของเราไปหาโมเดล คำขอแต่ละครั้งจะผูกกับบัญชีของคุณเพื่อนับปริมาณการใช้งานเท่านั้น และไม่ได้เข้ารหัสแบบต้นทางถึงปลายทาง — แต่เราไม่ได้เก็บบันทึกบทสนทนานั้นไว้ และไม่มีระบบใดบันทึกเนื้อหาลงฐานข้อมูล สิ่งที่เราเก็บมีเพียงจำนวนครั้งและปริมาณการใช้งาน เพื่อใช้นับโควตาและคำนวณค่าบริการเท่านั้น

ระบบของเราทำหน้าที่ส่งต่อคำขอไปยังผู้ให้บริการโมเดล โดยส่งเฉพาะเนื้อหาที่จำเป็นสำหรับคำตอบ และไม่ส่งข้อมูลตัวตนหรือบัญชีของคุณไปด้วย ผู้ให้บริการโมเดลจึงประมวลผลข้อความนั้นโดยไม่รู้เลยว่าคุณเป็นใคร

ถ้าไม่อยากให้ข้อความผ่านเซิร์ฟเวอร์ของเราเลย คุณสามารถใส่คีย์ Google AI Studio ของตัวเองในแอปได้ ระบบจะส่งคำขอจากเครื่องคุณตรงไปที่ Google โดยไม่ผ่านเซิร์ฟเวอร์ของ Pin

5. ผู้ให้บริการภายนอก

  • App Store และ Google Play — จัดจำหน่ายแอปและดูแลระบบชำระเงิน
  • Firebase (Google) — ระบบส่งการแจ้งเตือนมายังอุปกรณ์
  • RevenueCat — ระบบจัดการสถานะแพ็กเกจพรีเมียม
  • ผู้ให้บริการโมเดลเอไอ — Gemini และ OpenRouter สำหรับประมวลผลคำตอบของเอไอ

6. การเก็บรักษาและการลบข้อมูล

บทสนทนาและความทรงจำทั้งหมดทำงานและเก็บอยู่บนเครื่องของคุณ ปกป้องด้วยการเข้ารหัสแบบต้นทางถึงปลายทาง โดยมีคุณคนเดียวที่ถือกุญแจถอดรหัส

คุณสามารถลบบัญชีตัวเองได้ทุกเมื่อในแอปที่ ตั้งค่า → ความปลอดภัย เมื่อลบบัญชีแล้ว ข้อมูลบัญชีและสิทธิ์การเข้าถึงทั้งหมดจะถูกลบออกจากระบบทันที ส่วนข้อความที่เคยเข้ารหัสไว้จะไม่มีใครอ่านได้อีกเมื่อไม่มีกุญแจของคุณ หากต้องการให้ลบข้อมูลส่วนอื่นเพิ่มเติม สามารถติดต่อเราได้ตามอีเมลด้านล่าง

7. ความปลอดภัย

การเข้ารหัสแบบต้นทางถึงปลายทางและการเก็บข้อมูลให้น้อยที่สุด คือหัวใจด้านความปลอดภัยของเรา ไม่มีระบบใดในโลกที่ปลอดภัย 100% แต่เราออกแบบให้ข้อมูลส่วนตัวของคุณ ไม่เคยตกมาอยู่ในมือเราตั้งแต่แรก

8. สิทธิ์ของคุณ

คุณมีสิทธิ์ขอดู แก้ไข หรือลบข้อมูลบัญชีของตัวเองได้ทุกเมื่อ รวมถึงยกเลิกการรับอีเมลได้ตลอดเวลา ติดต่อเราตามอีเมลด้านล่าง ทีมงานพร้อมช่วยเหลือทันที

9. เด็กและเยาวชน

แอป Pin ไม่ได้ออกแบบมาสำหรับเด็กอายุต่ำกว่า 13 ปี และเราไม่มีนโยบายเก็บข้อมูลจากเด็ก หากตรวจพบ เราจะลบข้อมูลออกทันที

10. การเปลี่ยนแปลงนโยบาย

หากมีการปรับปรุงนโยบายฉบับนี้ เราจะอัปเดตวันที่ด้านบนสุดของหน้า และหากเป็นการเปลี่ยนแปลงสำคัญ เราจะแจ้งเตือนให้คุณทราบล่วงหน้าในแอป

11. ติดต่อ

มีข้อสงสัยเรื่องความเป็นส่วนตัว: privacy@tokens2.io

English

pin is built on the principle that privacy is the foundation, not an add-on. This document explains how we handle your data — what we cannot access at all, and what has to pass through us for the assistant to answer you.

1. What we cannot see

  • Chat message content — end-to-end encrypted (E2EE) on the Matrix protocol. Only you and the people you talk to can decrypt it. The server stores only ciphertext it cannot read.
  • Your memories, books and files — encrypted on the device before they leave it and stored in your own room, so the server holds them as ciphertext it cannot open. The keys stay on your device, which is where they are decrypted and used.

One exception, stated plainly: conversations with the AI assistant are not E2EE — they have to reach a model to be answered. By default they pass through our server on the way, so that hop is not locked away from us the way your chats are. We do not store those conversations, and we do not pass your identity on to the model provider. Section 4 has the detail.

2. Data we process

  • Account — your Matrix user ID and authentication data, so you can sign in and sync across devices (the username itself is a hash), plus your email if you sign in with Google or Apple.
  • Notifications — a device token from Firebase Cloud Messaging (FCM) to deliver push notifications. Notifications carry no message content.
  • Subscriptions — purchase status is handled through App Store / Google Play Billing and RevenueCat. We never see or store your card number; the store processes payment.
  • Camera — used to scan documents (into text), processed on-device. Images are not uploaded automatically.
  • Gmail connector (if enabled) — scoped OAuth access you grant, revocable anytime through your Google account.
  • Scheduled jobs and reminders — a server-side queue stores only which account to wake and when. It cannot see the contents of the job; the job itself lives on your device.
  • We do not collect — location, contacts, or usage behaviour for advertising.

3. What we use it for

To run the assistant (sign-in, cross-device sync, notifications, subscription management) and to send only the email you asked for. We do not use your data for advertising and we do not sell it. We intend to be funded by subscriptions, not by your data.

4. How the AI assistant works

By default your prompts travel through our server on the way to the model and the answer comes back the same way. Each request is tied to your account so it can be counted against your quota, and that hop is not end-to-end encrypted. We do not store the conversation, and nothing writes its content to a database — what is recorded is the number of calls and the volume used, for quota and cost.

The proxy forwards it to a model provider for inference, sending only what the answer requires and attaching neither your identity nor your account. The AI provider processes that content under its own policy, without knowing who you are.

If you would rather keep us out of the path entirely, add your own Google AI Studio key in the app and the device calls Google directly, never touching our server.

5. Third parties

  • App Store · Google Play — app distribution and payment processing.
  • Firebase (Google) — push notification delivery.
  • RevenueCat — subscription status management.
  • AI providers — Gemini / OpenRouter for model inference.

6. Retention and deletion

Conversations and memories run and are stored on your device, protected by end-to-end encryption. The keys are yours alone.

You can delete your account in the app under ตั้งค่า → ความปลอดภัย. When you do, your account data and associated tokens are removed. Encrypted messages are meaningless without your keys. To request further deletion, contact us below.

7. Security

End-to-end encryption and data minimisation are our primary defences. No system is perfectly secure, but pin is designed so your most sensitive data is never in our hands to begin with.

8. Your rights

You can ask to see, correct or delete your account data at any time, and unsubscribe from email whenever you like. Contact us below and we will act on it.

9. Children

pin is not directed at children under 13, and we do not knowingly collect data from them. If we find such data, we delete it.

10. Changes

If we revise this policy, we will update the effective date above and note significant changes in the app.

11. Contact

Privacy questions: privacy@tokens2.io · operated by Tokens2