Privacy Policy
1. Introduction
Keeva ("the App") is developed and maintained by MERIENA DIGITAL TECHNOLOGY CO., LTD. (星維數位科技有限公司), a company incorporated in Taiwan ("the developer", "we", "us"). This Privacy Policy explains how the App handles your information. We are committed to protecting your privacy.
2. Data Collection
We do not sell or share data with advertisers or data brokers.
Keeva has no user accounts or login. You do not need to provide your name, email, or phone number to use the App. The App's network features process the technical data described in §3.
What the App does send is fully described in §3 below: crash diagnostics (default on) and usage analytics (default OFF, opt-in only) (Tier 2), and purchase receipts handled by the App Store / Google Play (Tier 3). Both are explicitly disclosed — we do not make blanket "we collect nothing" claims when analytics and store receipts are involved. No advertising SDKs are integrated into the App.
2a. Why We Process This Data, and On What Legal Basis
For readers in the EU/EEA and the UK, this section sets out the legal basis we rely on under the GDPR. Device and installation identifiers can be personal data even when they do not directly include your name. The identifiers described in §3 are covered by this section.
| What | Why | Legal basis |
|---|---|---|
| Habit data on your device | To provide the app you bought | Performance of a contract (Art. 6(1)(b)) — and it stays on your device |
| Crash diagnostics (default on) | To find and fix crashes so the app keeps working | Legitimate interests (Art. 6(1)(f)) — keeping the app functional; the diagnostics and identifiers collected are described in §3 |
| Version-safety check (always on) | To block a release found to be broken | Legitimate interests (Art. 6(1)(f)) — user safety and operational integrity |
| Usage analytics (off by default) | To understand which features help | Consent (Art. 6(1)(a)) — you turn it on, and you can turn it off again at any time |
| Purchase receipts | To sell you the app through the store | Performance of a contract (Art. 6(1)(b)) — handled by the store, not by us |
3. How Your Data Is Stored
Keeva handles three distinct categories of data differently. Here is what goes where:
Tier 1 — Habit data (stored on this device, with OS-level backup relay)
Your habits, completion records, streaks, monthly highlights, and settings are stored on this device using a local SQLite database (powered by Drift) and your device's private application storage. This data is never shared with third parties through Keeva and is accessible only through the App on your device.
OS-level backup disclosure (per ADR-017 D7): When your device's OS-level backup is turned on, the operating system may include Keeva's local database in your personal cloud backup:
- Android: Google Drive Auto Backup (under your Google Account)
- iOS: iCloud Backup (under your Apple ID, uses your iCloud storage)
This OS-level backup is between you and Google / Apple. Keeva is not involved in this process and never sees the backed-up data. The purpose is to help your habits survive device migration — when you set up a new device, if your previous device had OS backup enabled, reinstalling Keeva from the App Store / Google Play with the same Google / Apple account may restore your habit database. (Exact restore behavior depends on your device's OS backup state, the platform, and OEM-specific settings.)
A note on encryption: Keeva does not add its own encryption layer on top of this local database — whether on-device or in the OS-level backup copy described above — so protection at rest relies on your device's own security, such as its lock screen and built-in disk encryption; if you'd like a copy of your data under your own control, you can export one anytime via Settings → Export My Data.
Monthly memory photos are excluded from Android Auto Backup / Google Drive backup. iOS iCloud Backup exclusion requires native verification before iOS submission; until then, iCloud Backup may include monthly memory photos if enabled by the user. SharedPreferences identity / migration preferences are excluded from Android OS-level backup. Keeva may back up a small notification_preferences.json file containing your notification preferences and privacy consent choices (notification on/off, quiet-hours window, lock-screen content hiding, secure-screen and App-Lock toggles, absence-reminder opt-in, and analytics/crash-reporting opt-out), so restoring to a new device does not silently re-enable reminders. You can disable OS-level backup at any time in your device's system settings; doing so does not affect Keeva's on-device storage.
In-app, you can review this disclosure under Settings → Your Data Safety. For extra safety, you can also export a JSON copy anytime via Settings → Export My Data.
Cloud sync as a Keeva-controlled feature (separate from OS backup) is optional and planned for a future update (Phase 2+); the App itself does not currently transmit your habit data to any Keeva server.
Tier 2 — Crash diagnostics (default on) and usage analytics (default OFF, opt-in only)
The App uses Firebase Crashlytics for crash diagnostics (enabled by default) and Firebase Analytics for usage statistics (disabled by default — you must opt in via Settings → About Your Data). These services send technical data to Google, including crash details or usage events and app-installation identifiers. Those identifiers distinguish installations and should not be treated as fully anonymous data. Crash reports are retained by Google's Crashlytics service for approximately 90 days, after which they are automatically deleted. No advertising SDKs are integrated into the App.
Tier 3 — Purchase receipts (managed by App Store / Google Play)
Your one-time paid-app purchase is processed by Apple App Store or Google Play. Keeva does not process or store payment information directly. Payment receipts are handled exclusively by the respective store platform. If future-capability in-app purchases are introduced, the same policy applies: payment and entitlement are managed by Apple / Google, not by Keeva directly.
Also on the network — version safety check (always on)
Separately from the tiers above, Keeva asks Firebase Remote Config whether your app version is still one we support, so that a release found to be broken can be blocked. This check runs for everyone and is not user-configurable, to support version safety. It sends a Firebase installation ID, your app version, and your device locale to Google, without your habit data. It is listed on our third-party services page.
3a. Photos (Monthly Memory Photo Feature)
Keeva allows you to optionally add one photo per month as a personal memory anchor ("Monthly Memory Photo"). When you use this feature:
- Permission: Keeva requests access to your device photo library only at the moment you tap "Leave a picture for this month." You can decline at any time; the rest of the App works normally without photo access.
- Storage: The photo you select is compressed on your device (JPEG, max 1920px long side, quality 85) and saved to Keeva's private application storage directory — a location accessible only to Keeva on your device.
- EXIF stripping: All embedded metadata, including GPS location, camera model, and original timestamps, is removed during compression. Keeva never reads or stores this metadata.
- No Keeva upload: Your photos are never uploaded, transmitted, or shared by Keeva. They are not included in Firebase Analytics. They are excluded from Android Auto Backup / Google Drive backup. iOS iCloud Backup exclusion requires native verification before iOS submission; until then, iCloud Backup may include them if enabled by the user.
- Deletion: You can delete any monthly photo at any time via Settings → Monthly Memories. Deleting the App or using Settings → Delete All Data also removes all photos from your device.
3b. Sub-Processors (Third-Party Service Providers)
Keeva uses a small number of third-party services to deliver platform-essential functions (app distribution, crash reporting). For full transparency, the complete list of sub-processors — what data each one receives, the region they operate in, and the data-protection terms that apply — is published on our third-party services page. We commit to publishing notice of any new sub-processor at least 30 days before activation.
Keeva may send local reminder notifications to help you stay on track with your habits. These notifications are:
- Generated and scheduled entirely on your device
- Not powered by any remote push notification service (e.g., Firebase Cloud Messaging)
- Fully under your control — you can enable or disable them at any time in your device settings
3c. Habit Names in Reminders
When you set a per-habit reminder, the habit name you entered appears as the notification's title. If you turn on the optional re-engagement reminders (off by default), the earlier reminders in that series may also include one of your habit names in the notification text. Because you write your own habit names, they may contain information you consider sensitive — for example, medical, mental-health, or recovery-related wording.
Anything shown in a reminder can appear on your device's lock screen and can be read by other apps to which you have granted notification-access permission (such as accessibility services, smart-watch companions, or notification-management apps). Keeva does not send habit names off your device for reminders — they are scheduled locally by your device's operating system.
To limit what is visible:
- Keeva includes a Hide reminders on lock screen setting (Settings → Notifications) that shows reminders without the habit name on the lock screen. On Android this is on by default; on iOS, whether reminder content appears on the lock screen is controlled by your device's notification-preview setting.
- You can also enable your device's own "hide notification content" option in system settings.
- You can choose a less specific habit name (for example, "Morning routine" instead of a medication name).
- You can turn reminders off entirely and rely on Keeva's in-app surfaces instead.
The Hide reminders on lock screen setting affects only the lock screen; apps with notification-access permission can still read reminder content regardless of that setting.
4. App Lock (Device Authentication)
Keeva offers an optional App Lock that requires your device's screen-lock authentication — biometric (fingerprint or face) or your device PIN / passcode — before the App opens. You can enable or disable it under Settings → App Lock.
- The authentication is performed entirely by your device's operating system. Keeva only receives a success or failure result — it never accesses, stores, or transmits your biometric data, PIN, or passcode.
- No biometric or authentication data ever leaves your device, and none is sent to Keeva, Google, Apple, or any third party.
- App Lock is off by default; you choose whether to turn it on.
5. Data Deletion
You can permanently delete your habit data from the app's settings. Some settings are retained; review the confirmation before deleting. Uninstalling also removes the remaining local app data. Device backups are managed separately.
5a. Your Rights
Because your habit data never leaves your device through Keeva, most of these rights you exercise directly, without asking us:
- Access — open the app; your data is all there.
- Portability — the app's settings include an export that gives you a complete JSON copy.
- Erasure — delete your data from the app's settings, or uninstall. See our data deletion guide.
- Rectification — edit or delete any habit, note, or photo in the app.
- Objection and restriction — you can contact us to object to processing or request a restriction where applicable. We will assess your request under applicable law. Analytics and crash reporting can be turned off in the app's settings. The version-safety check has no in-app switch; that does not prevent you from making a request.
For anything we do hold — crash diagnostics — write to privacy@keevaapp.com and tell us what you need. Reports can include installation identifiers. We may not be able to locate a report from your name or email alone; if we cannot identify the relevant records, we will explain that limitation and any information needed to assess your request.
If you are in the EU/EEA or the UK, you also have the right to lodge a complaint with your national data protection authority. You are welcome to raise it with us first, but you do not have to.
5b. Change log
2026-09-08: §5 deletion scope corrected — the in-app wipe keeps some settings by design. Added the legal-basis and rights sections, and clarified installation identifiers and requests about service-held data.
Added an encryption-at-rest disclosure to §3 Tier 1 — Keeva does not add its own encryption layer on top of the local database, on-device or in the OS-level backup copy. Prior 2026-07-04: Added §3c Habit Names in Reminders — habit name appears in reminder title / earlier opt-in re-engagement reminders; lock-screen and notification-listener exposure disclosed. Prior 2026-06-02: Added §4 App Lock device-authentication disclosure. Prior 2026-05-21: Analytics default opt-OUT; crash diagnostics default-on; OS-level backup disclosure clarified for monthly photos
6. Children's Privacy
Keeva does not knowingly collect personal information from children under the age of 13. The technical data described in §3 may still be processed when the relevant services are enabled. If you are a parent or guardian and have concerns, please contact us using the information below.
7. Changes to This Policy
The developer may update this Privacy Policy from time to time. Any changes will be reflected by the "Last Updated" date at the top of this page. Continued use of the App after changes constitutes acceptance of the revised policy.
8. Contact
If you have any questions or concerns about this Privacy Policy, please contact us at:
Email: privacy@keevaapp.com (privacy / legal questions) · support@keevaapp.com (general support)
隱私權政策
1. 簡介
Keeva(以下簡稱「本應用程式」)由星維數位科技有限公司(MERIENA DIGITAL TECHNOLOGY CO., LTD.)開發與維護;該公司於台灣設立(以下簡稱「開發者」、「我方」)。本隱私政策說明本應用程式如何處理您的資訊。我們致力於保護您的隱私。
2. 資料收集
我們不會販售或分享資料給廣告商或資料仲介。
Keeva 沒有帳號系統、不需登入。使用 App 不需要提供姓名、電子郵件或電話。連線服務會處理的技術資料詳見 §3。
本應用程式實際傳送的資料完整列於下方 §3:當機診斷(預設開啟)與使用分析(預設關閉,須主動開啟)(第二類),以及由 App Store / Google Play 處理的購買收據(第三類)。兩者皆已明確揭露——當應用程式確實有使用 analytics 與商店收據時,我們不會做出「完全不收集任何資料」的籠統聲明。本應用程式未整合任何廣告 SDK。
2a. 我們為何處理這些資料,以及依據為何
對於歐盟/歐洲經濟區與英國的讀者,本節說明我方依 GDPR 所援引的法律依據。裝置與安裝識別碼即使未直接包含姓名,仍可能屬於個人資料。§3 所述的識別碼也包含在本節範圍內。
| 項目 | 目的 | 法律依據 |
|---|---|---|
| 裝置上的習慣資料 | 提供您所購買的 App | 契約履行(第 6(1)(b) 條)——且資料留在您的裝置上 |
| 當機診斷(預設開啟) | 找出並修復當機,使 App 持續可用 | 正當利益(第 6(1)(f) 條)——維持 App 運作;收集的診斷資料與識別碼詳見 §3 |
| 版本安全檢查(一律啟用) | 阻擋已知有問題的版本 | 正當利益(第 6(1)(f) 條)——使用者安全與營運完整性 |
| 使用分析(預設關閉) | 了解哪些功能真的有幫助 | 同意(第 6(1)(a) 條)——由您開啟,亦可隨時關閉 |
| 購買收據 | 透過商店將 App 售予您 | 契約履行(第 6(1)(b) 條)——由商店處理,非由我方處理 |
3. 您的資料如何儲存
Keeva 對三類資料採取不同的處理方式,以下說明各類資料的儲存位置:
第一類 — 習慣資料(儲存於您的裝置上,含作業系統層級備份)
您在 Keeva 中建立的習慣記錄、完成紀錄、連續天數、月度重點及設定,均透過本地 SQLite 資料庫(使用 Drift)與您裝置上的應用程式私有儲存空間儲存。這些資料永遠不會由 Keeva 與第三方共享,且僅能透過您裝置上的本應用程式存取。
作業系統層級備份揭露(依 ADR-017 D7):當您裝置的作業系統層級備份功能開啟時,作業系統可能會將 Keeva 的本地資料庫包含在您個人的雲端備份中:
- Android:Google Drive 自動備份(您的 Google 帳號下)
- iOS:iCloud 備份(您的 Apple ID 下,使用您的 iCloud 空間)
此作業系統層級備份僅在您與 Google / Apple 之間進行。Keeva 不參與此過程,亦永遠看不到被備份的資料。其目的是協助您的習慣資料在換機時延續——當您設定新裝置時,若先前裝置已啟用作業系統備份,使用同一個 Google / Apple 帳號從 App Store / Google Play 重新安裝 Keeva,有機會還原您的習慣資料庫。(實際還原行為依您裝置的作業系統備份狀態、平台與 OEM 設定而定。)
關於加密的說明:Keeva 不會為這份本機資料庫另外加上一層加密——無論是裝置上的資料,或是上述作業系統層級備份中的副本皆然——因此靜態保護仰賴您裝置本身的安全機制,例如鎖定畫面與作業系統內建的磁碟加密;如果您想要一份由您自己掌控的資料副本,可隨時透過「設定 → 匯出我的資料」匯出。
每月回憶照片已從 Android 自動備份 / Google Drive 備份中排除。iOS 的 iCloud Backup 排除需在 iOS 提交前完成原生驗證;在驗證完成前,若使用者啟用 iCloud 備份,iCloud Backup 可能包含每月回憶照片。SharedPreferences 中的身分 / 遷移偏好已從 Android 作業系統層級備份中排除。Keeva 可能備份一個很小的 notification_preferences.json 檔案,其中包含您的通知偏好與隱私同意設定(通知開關、免打擾時段、鎖定畫面內容隱藏、安全畫面與應用程式鎖定開關、無使用提醒開關,以及分析與當機回報的退出選擇),避免換機還原後提醒被靜默重新開啟。您可隨時於裝置系統設定中關閉作業系統備份;此舉不影響 Keeva 在裝置上的本地儲存。
App 內,您可於「設定 → 你的資料安全」檢視本揭露。若需額外保險,您也可隨時透過「設定 → 匯出我的資料」匯出 JSON 備份。
由 Keeva 主導的雲端同步功能(不同於作業系統備份)為選用功能,將於未來更新(Phase 2+)提供;本應用程式目前不會將您的習慣資料傳送至任何 Keeva 伺服器。
第二類 — 當機診斷(預設開啟)與使用分析(預設關閉,須主動開啟)
本應用程式使用 Firebase Crashlytics 進行當機診斷(預設開啟)及 Firebase Analytics 收集使用統計(預設關閉——您須透過設定 → 關於你的資料主動開啟)。這些服務會將當機資訊或使用事件,以及 App 安裝識別碼等技術資料傳送至 Google。識別碼可用於區分不同安裝實例,因此不應將這些資料視為完全匿名。當機報告由 Google 的 Crashlytics 服務保留約 90 天,之後將自動刪除。本應用程式未整合任何廣告 SDK。
第三類 — 購買收據(由 App Store / Google Play 管理)
您的一次性付費 App 購買由 Apple App Store 或 Google Play 處理。Keeva 不直接處理或儲存付款資訊。付款收據由各自的應用程式商店平台專屬管理。若未來引入選購功能性 In-App Purchase,相同政策適用:付款與使用權由 Apple / Google 管理,而非由 Keeva 直接處理。
另一項網路使用 — 版本安全檢查(一律啟用)
在上述三類之外,Keeva 會向 Firebase Remote Config 確認您的 App 版本是否仍在支援範圍內,以便在發現某個版本有問題時將其阻擋。此檢查對所有使用者執行,且不提供使用者設定,用於版本安全檢查。它會將 Firebase 安裝 ID、您的 App 版本與裝置語言傳送給 Google,不包含您的習慣資料。此項目已列於第三方服務頁面。
3a. 照片(每月回憶照片功能)
Keeva 提供「每月回憶照片」功能,您可選擇每月新增一張照片作為個人回憶的錨點。使用此功能時:
- 權限:Keeva 僅在您點選「為這個月留下一張照片」時,才向裝置請求相簿存取權限。您可隨時拒絕;其他所有功能在沒有照片權限時仍可正常運作。
- 儲存:您選擇的照片會在裝置上壓縮(JPEG 格式,長邊最大 1920px,品質 85),並儲存到 Keeva 的應用程式私有目錄——這個位置在您的裝置上只有 Keeva 能存取。
- EXIF 移除:壓縮時會移除所有嵌入的中繼資料,包含 GPS 位置、相機型號、原始拍攝時間。Keeva 不讀取、也不儲存這些資料。
- Keeva 不上傳:您的照片永遠不會由 Keeva 上傳、傳輸或共享。不會包含在 Firebase Analytics 中。已從 Android 自動備份 / Google Drive 備份中排除。iOS 的 iCloud Backup 排除需在 iOS 提交前完成原生驗證;在驗證完成前,若使用者啟用 iCloud 備份,iCloud Backup 可能包含這些檔案。
- 刪除:您可隨時在設定 → 每月回憶中刪除任何單張照片。移除應用程式或使用設定 → 刪除所有資料也會清除裝置上的所有照片。
3b. 第三方服務提供商(Sub-Processors)
Keeva 使用少數第三方服務以提供平台必要功能(應用程式發佈、當機回報)。為求完全透明,所有第三方服務提供商的完整清單——包含每一方接收的資料類型、營運地區,以及適用的資料保護條款——都公佈於第三方服務頁面。新增任何第三方服務之前,我們承諾至少提前 30 天公告。
Keeva 可能會傳送本地提醒通知,協助您維持習慣追蹤。這些通知:
- 完全在您的裝置上產生與排程
- 不依賴任何遠端推播通知服務(例如 Firebase Cloud Messaging)
- 由您完全掌控——您可隨時在裝置設定中啟用或關閉
3c. 提醒通知中的習慣名稱
當您為個別習慣設定提醒時,您所輸入的習慣名稱會顯示為通知的標題。若您開啟選用的回歸提醒(預設關閉),該系列較早的提醒的通知內文也可能包含您的其中一個習慣名稱。由於習慣名稱由您自行輸入,其中可能含有您認為敏感的資訊——例如醫療、心理健康或戒治相關的字詞。
凡是出現在提醒中的內容,都可能顯示在您裝置的鎖定畫面上,也可能被您授予「通知存取」權限的其他應用程式(例如協助工具、智慧手錶配對程式、通知管理工具)讀取。Keeva 不會為了提醒而將您的習慣名稱傳送到裝置以外——這些通知由您裝置的作業系統在本機排程。
若要限制可見範圍,您可以:
- 使用 Keeva 內建的「在鎖定畫面隱藏提醒」設定(設定 → 通知),讓提醒在鎖定畫面上不顯示習慣名稱。在 Android 上此設定預設開啟;在 iOS 上,提醒內容是否出現在鎖定畫面,取決於您裝置的通知預覽設定。
- 在系統設定中開啟裝置本身的「在鎖定畫面隱藏通知內容」選項。
- 使用比較不直接的習慣名稱(例如以「晨間例行」取代具體藥名)。
- 完全關閉提醒,改用 Keeva 的 App 內畫面。
「在鎖定畫面隱藏提醒」設定僅影響鎖定畫面;擁有通知存取權限的應用程式無論此設定為何,仍可讀取提醒內容。
4. 應用程式鎖定(裝置驗證)
Keeva 提供選用的應用程式鎖定功能,開啟 App 前會要求您通過裝置的螢幕鎖定驗證——生物辨識(指紋或臉部)或您的裝置 PIN/密碼。您可在設定 → 應用程式鎖定中啟用或關閉。
- 驗證完全由您裝置的作業系統執行。Keeva 只會收到成功或失敗的結果,永遠不會存取、儲存或傳送您的生物辨識資料、PIN 或密碼。
- 任何生物辨識或驗證資料都不會離開您的裝置,也不會傳送給 Keeva、Google、Apple 或任何第三方。
- 應用程式鎖定預設為關閉,是否啟用由您決定。
5. 資料刪除
您可以在 App 設定中永久刪除習慣資料。部分設定會保留,請在操作前查看確認提示。解除安裝也會移除其餘本機 App 資料。裝置備份則需另外管理。
5a. 您的權利
由於您的習慣資料不會透過 Keeva 離開您的裝置,以下多數權利您可直接行使,無須向我方申請:
- 存取——開啟 App,您的資料都在裡面。
- 可攜——App 設定中提供匯出功能,可取得完整的 JSON 副本。
- 刪除——於 App 設定中刪除資料,或解除安裝。請見我方的資料刪除說明。
- 更正——在 App 內編輯或刪除任何習慣、備註或照片。
- 反對與限制處理——您可在適用情況下聯絡我們,反對處理資料或要求限制處理。我們會依適用法律評估您的請求。使用分析與當機回報可在 App 設定中關閉。版本安全檢查沒有 App 內開關,但您仍可提出請求。
至於確實由我方持有的部分——當機診斷——請來信 privacy@keevaapp.com 說明您的需求。回報可能包含安裝識別碼,我們未必能僅憑姓名或電子郵件找到相關紀錄。若無法識別紀錄,我們會說明限制,以及評估請求所需的資訊。
若您位於歐盟/歐洲經濟區或英國,您另有權向所在國之個人資料保護主管機關提出申訴。您可以先向我方反映,但並非必要。
5b. 變更紀錄
2026-09-08:修正 §5 資料刪除範圍——App 內清除會依設計保留部分設定。新增處理依據與資料權利說明,並釐清安裝識別碼及服務端資料的請求方式。
於 §3 第一類新增靜態加密揭露:Keeva 不會為本機資料庫另外加上一層加密——無論裝置上或作業系統層級備份中的副本皆然。先前 2026-07-04:新增 §3c 提醒通知中的習慣名稱 — 習慣名稱會出現在提醒標題/選用回歸提醒系列較早的通知;揭露鎖定畫面與通知存取應用程式的可見性。先前 2026-06-02:新增 §4 應用程式鎖定裝置驗證揭露。先前 2026-05-21:分析功能預設關閉;當機診斷預設開啟;釐清每月回憶照片的作業系統層級備份揭露
6. 兒童隱私
Keeva 不會刻意收集 13 歲以下兒童的任何個人資訊。相關服務啟用時,仍可能處理 §3 所述的技術資料。若您是家長或監護人並有任何疑慮,請透過下方聯絡資訊與我們聯繫。
7. 政策變更
開發者可能不定期更新本隱私政策。任何變更將反映於本頁面頂部的「最後更新」日期。在變更後繼續使用本應用程式,即視為接受修訂後的政策。
8. 聯絡方式
若您對本隱私政策有任何疑問或疑慮,請透過以下方式聯絡我們:
電子郵件:privacy@keevaapp.com(隱私 / 法律相關)· support@keevaapp.com(一般客服)
This policy is governed by the English version. In case of any discrepancy between translations, the English version prevails.