DAILYFLORA
Today's bouquetMy gardenAbout DailyFloraObjects & CollaborationsPlatformsSciFi Flora

DailyFlora Legal

Privacy Policy

Version 0.71Effective: 3 August 2026Controller: CALFN LAU / DailyFlora

DailyFlora 隐私政策

本政策说明 DailyFlora 正式注册版如何处理服务器账户、照片上传、收藏、摄像头手势、Cookie、广告与商业合作数据。个人信息处理者/控制者为 CALFN LAU(DailyFlora 独立创作者与运营者),联系邮箱:find@calfn.com。

1. 注册版处理哪些信息

信息处理方式与目的保存位置
名称、邮箱、登录与账户标识创建和保护注册账户、登录、跨设备同步及用户支持。账户数据库及必要的安全日志。
收藏、日期、seed、花束方案、生成记录和偏好文字恢复收藏、生成相似花束、展示个人记录及改进服务。账户数据库;部分界面偏好也可能保存在浏览器。
你上传的参考照片及派生特征预览、色彩与构图分析、生成私人花束、保存结果、安全检查和故障恢复。服务端会在可行范围内移除不必要的 EXIF 与精确位置元数据,不以该功能进行人脸身份识别。受访问控制的对象存储、处理内存和备份。
摄像头画面和手部关键点在你主动授权后进行页面内手势控制。DailyFlora 不录制画面、不进行身份识别。实时内存;关闭手势、页面或权限后停止。
Cookie、设备标识、语言、界面、时钟与同意偏好登录、安全、记住设置、统计分析、衡量活动;经适用选择后可用于广告和商业合作归因。Cookie、localStorage、账户记录及合作方系统。
IP、请求时间、浏览器/设备信息、错误和安全日志由你访问的托管或网络服务商为传输页面、安全、防滥用和运维而处理。依实际托管服务商的日志政策保存。

2. 照片上传的准确边界

正式注册版会把你确认提交的参考照片上传到 DailyFlora 使用的服务器和对象存储。上传不是公开发布:照片默认私密,只用于提供注册版功能以及本政策明确的安全、运维和商业处理。

请不要上传包含他人肖像、儿童、证件、医疗信息、精确地址、私密内容或你无权处理的个人信息。若照片包含依法属于敏感个人信息的内容,应在上传前确认已有合法依据和所需同意。

  • 上传界面和本政策说明处理目的、保存期限、接收方类别、跨境处理与删除入口;法律要求单独同意时另行取得。
  • 照片默认私密,不进入公开图库;除非用户另行主动发布,不允许其他用户访问。
  • 原始照片用于生成用户请求的私人花束、内容与技术安全检查及故障恢复。除非另行取得适用的明确同意,不使用原始照片训练通用 AI 模型、制作身份/生物识别档案或直接作为广告素材。
  • 服务端应在可行范围内移除不需要的 EXIF 及精确位置元数据,对传输和存储加密,并限制员工和处理商访问。
  • 原始照片应在生成完成后 30 天内自动删除,或在用户请求时更早删除;用户主动保存的派生花束记录保留至账户删除,备份副本在额外 30 天内滚动清除,法律另有要求除外。

3. 摄像头与 MediaPipe

手势功能按需使用 Google MediaPipe Tasks Vision。DailyFlora 将模型与 WASM 文件从当前站点加载,并在浏览器内处理摄像头帧;不会有意将图像帧发送给 CALFN LAU 或 Google。MediaPipe 官方说明其 Tasks API 可能发送性能和使用指标,因此启用前应查看 MediaPipe 项目隐私说明。你可以拒绝摄像头权限,或随时关闭手势并在浏览器设置中撤销权限。

4. 处理目的与法律依据

  • 履行你的请求:显示花束、建立服务器账户、保存收藏、处理你上传的照片及启用手势。
  • 同意:摄像头、照片上传、非必要 Cookie、广告或法律要求单独同意的处理。
  • 合法利益:在不凌驾于你的权利之上时,用于安全、防滥用、故障排查和改进服务。
  • 法律义务:响应有效法律要求、保护权利并履行数据安全或消费者义务。

对中国用户,处理遵循合法、正当、必要、诚信、目的明确与最小范围原则;需要单独同意的敏感信息、未成年人信息或跨境提供不会以概括同意代替。

5. 共享、出售和广告

DailyFlora 可以向以下类别披露必要信息:云托管、对象存储、CDN、账户、邮件、支付、客户支持、分析、安全与广告服务商;共同品牌、花店、商品、活动及内容合作伙伴;专业顾问;依法承接业务的收购方;以及法律要求的机构。共享目的包括提供服务、履约、支持、安全、统计分析、衡量推广、个性化内容、联合活动和商业合作。

共享范围可能包括账户与联系信息、设备/Cookie 标识、使用与购买活动、偏好、派生花束数据以及为特定合作所必要的内容。原始私人照片仅在提供存储、生成、安全或用户主动参与的合作确有必要时向受约束的处理方提供。DailyFlora 不会通过一条概括条款放弃法律要求的选择:适用法律将某种披露认定为“出售”“共享”、定向广告或要求单独同意的第三方提供时,会提供 Cookie 设置、退出链接、同意界面或其他法定机制。

6. 跨境处理

注册账户、照片、日志、Cookie/设备标识和支持记录可能由位于你所在国家/地区以外的 DailyFlora 服务商或商业伙伴处理。DailyFlora 将根据适用法律采用中国个人信息出境机制及所需单独同意、欧盟/欧洲经济区充分性决定或标准合同条款与转移评估、日本 APPI 境外第三方提供措施,或其他有效保障。你可通过隐私请求了解与你相关的接收方类别、目的和行权方式。

7. 保存与删除

  • 账户、收藏和派生记录:保存至账户删除,或为履约、争议、安全和法定义务所需的更短/更长期限。
  • 原始参考照片:通常在生成完成后 30 天内删除,或应请求更早删除;备份副本在额外 30 天内滚动清除,法律保全除外。
  • Cookie 与设备标识:按 Cookie 设置中所示期限或你清除/撤回选择为止;不同技术的期限可能不同。
  • 摄像头帧:仅在页面实时处理中存在,不作为视频保存在 DailyFlora 服务器。
  • 托管日志:依服务商的必要安全与运维期限保存;DailyFlora 会要求任何自行控制的日志遵守最短必要期限。
  • 权利请求记录:仅为核验和证明已处理请求所必需的期限保存。

8. 你的隐私权利

无论所在地,你均可请求了解、访问、更正、删除、限制或停止处理、撤回同意、获取可携带副本,并可提出投诉。你也可以通过 Cookie 设置、浏览器控制或适用的通用退出信号管理非必要 Cookie、出售/共享、定向广告及相关设备标识。

中国

依据《个人信息保护法》,你可请求知情、决定、限制/拒绝、查阅复制、更正补充、删除,并要求解释处理规则;近亲属可依法行使逝者相关权利。

欧盟/欧洲经济区及英国

在适用 GDPR/UK GDPR 时,你可请求访问、更正、删除、限制、可携带、反对基于合法利益的处理、撤回同意,并向所在地数据保护机构投诉。基于同意的撤回不影响撤回前处理的合法性。

美国

适用的州法可能赋予知情/访问、删除、更正、可携带以及退出出售、共享、定向广告或特定分析的权利。DailyFlora 将在相关活动适用时提供退出机制并识别依法有效的通用退出信号;行使权利不会受到歧视。COPPA 保护的儿童不得使用注册和照片功能。

日本

在 APPI 适用时,你可请求通知利用目的、公开保有个人数据、订正/追加/删除、停止利用/消除及停止第三方提供,并可就处理方式提出投诉。

提交请求:find@calfn.com。请说明国家/地区、请求类型和用于匹配记录的最少信息。DailyFlora 只会为核验身份收集必要信息,并在适用期限内答复。

9. 未成年人

DailyFlora 不面向 16 岁以下用户提供注册、照片或摄像头功能,也不会明知收集其个人信息。如果你认为儿童信息已被提交,请立即联系;经核实后将停止处理并依法删除。未来如提供儿童服务,必须先建立独立儿童隐私规则、年龄与监护人同意机制。

10. 安全与事件响应

DailyFlora 采用数据最小化、传输和存储加密、访问控制、按需摄像头权限和功能关闭后释放摄像头等措施。任何互联网或设备存储都无法保证绝对安全。若发生影响个人权益的数据事件,将调查、控制风险,并按适用法律向用户和监管机构通知。

11. Cookie 与类似技术

DailyFlora 可以使用必要 Cookie(登录、安全、负载与同意记录)、偏好 Cookie(语言和界面)、分析 Cookie(访问与性能)以及广告/合作 Cookie(推广衡量、频次、归因和依法允许的个性化)。非必要 Cookie 会按照适用法律通过 Cookie 横幅或设置中心提供同意或退出选择。关闭某些 Cookie 可能影响登录、偏好或合作活动功能。

12. 政策更新与联系

DailyFlora 可因功能、服务商、合作伙伴或法律变化更新本政策。重大变化将通过注册邮箱或页面显著通知;仅在法律允许且用途兼容时通过更新页面直接生效。适用法律要求重新同意、单独同意或退出选择时,页面更新或普通邮件不会替代该机制。隐私联系:find@calfn.com。

参考框架:中国《个人信息保护法》、EU GDPR、FTC COPPA 指南、California CCPA/CPRA、日本 APPI 通则指南。

DailyFlora Privacy Policy

This Policy describes how the production registered version handles server accounts, photo uploads, favorites, camera gestures, cookies, advertising, and commercial-partner data. The controller is CALFN LAU, independent creator and operator of DailyFlora. Contact: find@calfn.com.

1. Information handled by the registered version

InformationPurpose and handlingLocation
Name, email, login and account identifiersCreate and secure accounts, login, cross-device sync, and support.Account database and necessary security logs.
Favorites, date, seed, bouquet plan, generated records, preference textRestore favorites, generate similar bouquets, show personal records, and improve the service.Account database; some interface preferences may also remain in the browser.
Uploaded reference photos and derived featuresPreview, color/composition analysis, private-bouquet generation, record storage, security checks, and recovery. Unneeded EXIF and precise-location data are removed where feasible; this feature does not perform face-identity recognition.Access-controlled object storage, processing memory, and backups.
Camera frames and hand landmarksGesture control after permission; no identity recognition or recording by DailyFlora.Real-time page memory.
Cookies, device identifiers, locale, interface, clock, and consent preferencesLogin, security, settings, analytics, campaign measurement, and—subject to applicable choices—advertising and partner attribution.Cookies, localStorage, account records, and partner systems.
IP, time, device/browser, error and security logsPage delivery, security, abuse prevention, and operations.Provider systems under applicable retention.

2. Photo-upload boundary

The production registered version uploads a reference photo you confirm to DailyFlora's servers and object storage. Upload is not public posting: photos are private by default and used for registered features and the security, operations, and commercial processing expressly described here.

Do not upload another person's likeness, children, identity documents, health information, precise addresses, intimate content, or personal information you lack authority to process.

  • The interface and this Policy describe purposes, retention, recipient categories, international processing, and deletion; separate consent is obtained where required.
  • Photos remain private unless the user separately chooses to publish.
  • Original photos support requested private-bouquet generation, content/technical security, and recovery. Without an additional explicit basis and legally required consent, they are not used for general AI training, identity/biometric profiles, or as direct advertising creative.
  • Unnecessary EXIF and precise-location data are removed where feasible; transfer and storage are encrypted and access restricted.
  • Originals are deleted within 30 days after generation or earlier on request; saved derived records remain until account deletion and backups roll off within an additional 30 days unless legal preservation applies.

3. Camera and MediaPipe

Gesture control uses Google MediaPipe Tasks Vision on demand. DailyFlora serves its model and WASM files from the current site and processes frames in the browser; it does not intentionally send image frames to CALFN LAU or Google. MediaPipe states that Tasks APIs may send performance and utilization metrics, so review the MediaPipe project privacy notice. You may deny or revoke camera permission at any time.

4. Purposes and legal bases

  • Contract/request: show bouquets, create a server account, save favorites, process uploaded photos, and enable gestures.
  • Consent: camera access, photo upload, non-essential cookies, advertising, and processing requiring separate consent.
  • Legitimate interests: proportionate security, abuse prevention, debugging, analytics, service improvement, and compatible commercial operations where not overridden by your rights.
  • Legal obligation: valid legal requests, rights protection, security, and consumer obligations.

For users in China, processing follows lawfulness, propriety, necessity, good faith, specific purpose, transparency, and minimum scope; separate consent is used where required.

5. Disclosure, sale, and advertising

DailyFlora may disclose necessary information to cloud hosting, object storage, CDN, account, email, payment, support, analytics, security, and advertising providers; co-branded, florist, merchandise, event, and content partners; professional advisers; lawful business successors; and authorities. Purposes include service delivery, fulfillment, support, safety, analytics, campaign measurement, personalization, joint activities, and commercial collaborations.

Categories may include account/contact information, device/cookie identifiers, usage and purchase activity, preferences, derived bouquet data, and content necessary for a specific collaboration. Original private photos are provided only to bound processors when necessary for storage, generation, security, or a collaboration the user actively joins. Where applicable law treats disclosure as a “sale,” “sharing,” targeted advertising, or a transfer requiring separate consent, DailyFlora provides cookie settings, opt-out links, consent controls, or another required mechanism.

6. International processing

Accounts, photos, logs, cookie/device identifiers, and support records may be processed by providers or commercial partners outside your country. DailyFlora uses an applicable China PIPL transfer route and separate consent, EU/EEA adequacy decision or Standard Contractual Clauses and transfer assessment, Japan APPI foreign-third-party measure, or another valid safeguard. You may request recipient categories, purposes, and rights channels relevant to you.

7. Retention

  • Accounts, favorites, and derived records remain until account deletion or a shorter/longer period required for fulfillment, disputes, security, or law.
  • Original photos are normally deleted within 30 days after generation or earlier on request; backups roll off within an additional 30 days unless legal preservation applies.
  • Cookies/device identifiers remain for the period shown in Cookie Settings or until you clear or withdraw the relevant choice.
  • Camera frames remain only for real-time page processing and are not stored as video on DailyFlora servers.
  • Rights-request records remain only as needed to verify and document the response.

8. Your rights

Regardless of location, you may ask to know, access, correct, delete, restrict or stop processing, withdraw consent, obtain a portable copy, object, and complain. Cookie Settings, browser controls, and applicable universal opt-out signals can manage non-essential cookies, sale/sharing, targeted advertising, and related device identifiers.

China

PIPL rights may include information and decision-making, restriction/refusal, access/copy, correction/completion, deletion, explanation, and certain rights concerning a deceased person.

EU/EEA and UK

Where GDPR/UK GDPR applies: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority.

United States

Applicable state laws may provide rights to know/access, delete, correct, obtain a copy, and opt out of sale, sharing, targeted advertising, or certain profiling. DailyFlora provides an opt-out when relevant and recognizes legally valid universal opt-out signals; exercising rights will not cause discrimination. Children covered by COPPA must not use registration or photo features.

Japan

Where APPI applies: notification of utilization purpose, disclosure, correction/addition/deletion, cessation/erasure, cessation of third-party provision, and complaint handling.

Submit a request to find@calfn.com with your region, request type, and the minimum information needed to locate a record.

9. Minors

Registration, photo, and camera features are not offered to users under 16. If you believe a child's information has been submitted, contact us; verified information will be stopped and deleted as required. Any future child-directed service requires a separate child policy, age design, and verifiable guardian-consent process first.

10. Security and incidents

Measures include data minimization, encryption in transit and at rest, access control, permission-gated camera access, and camera release when gestures are disabled. No device or network storage is perfectly secure. A qualifying incident will be investigated, contained, and notified to users and regulators as applicable.

11. Cookies and similar technologies

DailyFlora may use necessary cookies (login, security, load management, consent records), preference cookies (language/interface), analytics cookies (visits/performance), and advertising/partner cookies (campaign measurement, frequency, attribution, and legally permitted personalization). Non-essential cookies receive consent or opt-out controls through a banner or settings center as required. Disabling some cookies may affect login, preferences, or partner features.

12. Updates and contact

DailyFlora may update this Policy for feature, provider, partner, or legal changes. Material changes receive notice by registered email or prominent site notice; a page-only update takes effect directly only when legally permitted and compatible with the stated purposes. Where renewed/separate consent or an opt-out is required, a page update or ordinary email does not replace that mechanism. Contact: find@calfn.com.

Frameworks consulted: China PIPL, EU GDPR, FTC COPPA guidance, California CCPA/CPRA, and Japan APPI guidelines.

One bouquet a day. No need to possess it.

SystemHow to useTerms of UseCredits & AttributionsCopyright Notice