Third-party services and data processing
When you use Keeva, certain third-party services (sub-processors) process limited categories of data on our behalf to provide essential platform services. We list them here so you can see exactly who has access to what.
We commit to giving at least 30 days advance notice before adding a new sub-processor. To subscribe to changes, contact us and we'll add you to the notification list.
Current sub-processors (v1.0 — Android)
| Provider | Purpose | Data shared | Region | Provider DPA / Privacy |
|---|---|---|---|---|
| Google LLC (Firebase) | Error reporting (Crashlytics) — crash payloads + a device-instance UUID for grouping crashes | Device-instance UUID; crash stack traces (no user-typed content per our Privacy Policy) | United States, with regional processing per Google's data center policy | Firebase Privacy & Security · Google Cloud DPA |
| Google LLC (Firebase Analytics) | Optional usage analytics — disabled by default and sent only after the user opts in via Settings → About Your Data | App-instance / installation ID; bounded app-activity events; timezone user property when analytics is enabled | Google global (US-primary) | Firebase Privacy & Security · Google Cloud DPA |
| Google LLC (Play Store) | Play Store distribution; receipt validation | Google Play account ID (Play Store users only); purchase receipts | United States, with regional CDN | Google Play Terms |
| Google LLC (Firebase Remote Config) | App version kill switch (force-update fetch) — fetchAndActivate() called on cold start + onResume (5-min rate-limit) to enforce minimum app version | Firebase installation ID + app version + device locale | Google global (US-primary) | Firebase Privacy & Security · Google Cloud DPA |
Planned sub-processors (v1.1+, not yet active)
| Provider | Purpose | Data shared | Region | Provider DPA / Privacy |
|---|---|---|---|---|
| Apple Inc. | App Store distribution; paid-app purchase receipt validation (iOS — planned after Android launch; no subscription processing planned for v1.0) | Apple ID (when signed in to App Store), purchase receipts | United States (with regional CDN) | Apple Privacy Policy |
| IAP infrastructure (TBD) | Future-capability IAP / subscription state aggregation (if introduced, per new ADR) | User identifier; subscription status; receipt metadata (provider TBD) | TBD | To be confirmed when Phase 2+ future-capability IAP is introduced |
When a future-capability IAP infrastructure is integrated (Phase 2+, requires new ADR decision), this section moves to "Current sub-processors" and a 30-day advance notice is published here first.
What we deliberately do NOT use
For transparency, here is what Keeva v1.0 does not delegate to any sub-processor:
- No backend application server — Keeva is local-first. Your habits, logs, notes, and photos live on your device, and Keeva does not upload them (an OS-level backup, if you have one switched on, is between you and Google or Apple — see the Privacy Policy)
- No Firebase Authentication — Keeva v1.0 ships without sign-in. No Firebase user account exists for you
- No Firestore / Cloud Storage — your habit data and photos are never uploaded to Google Cloud
- No marketing analytics SDK (Mixpanel / Amplitude / Segment / etc.) — Keeva uses Crashlytics for default-on crash diagnostics and Firebase Analytics only for optional usage analytics, disabled by default
- No advertising SDK — Keeva is ad-free
- No direct payment processor — Paid-app purchase billing is handled by Google (and by Apple if Keeva later ships on iOS); we never see your card number
Cross-border transfers
The sub-processors above are headquartered in the United States. When you use Keeva from outside the US, your error-report data and (for Play Store users) Play account identifier may be transferred to and processed in the United States.
We rely on the safeguards each provider offers:
- Google (Firebase + Play) — the only sub-processors active in v1.0: Standard Contractual Clauses per Google Cloud DPA
- Apple (planned, not yet active): published privacy policy + EU-US Data Privacy Framework certification. No data reaches Apple today — this applies only if Keeva later launches on iOS.
- Future IAP infrastructure (when active): Standard Contractual Clauses per provider DPA (confirmed when Phase 2+ IAP is introduced)
Change notification
We commit to publishing a notice of upcoming sub-processor changes at least 30 calendar days before the change takes effect. Notice is delivered via:
- This page's "Last updated" timestamp + change log below
Change log
| Date | Change |
|---|---|
| 2026-04-25 | Page created — initial sub-processor inventory for v1.0 launch |
| 2026-04-28 | firebase_remote_config row added per Wave 4 force-update kill switch ship + GDPR Art. 28 disclosure requirement |
| 2026-05-21 | Firebase Analytics row added and default-off / opt-in wording aligned with app privacy settings |
| 2026-07-31 | Cross-border safeguards re-ordered so Apple is shown as planned-not-yet-active, matching the tables above (v1.0 is Android-only — no data reaches Apple today); "No payment processor" corrected to "No direct payment processor". No sub-processor added — the 30-day advance-notice commitment is not engaged. |
| 2026-09-08 | Clarified installation identifiers without claiming complete anonymity. No provider added or data flow changed. |
Contact
For questions about this list or to subscribe to change notifications, see our Privacy Policy contact section.
第三方服務與資料處理
當您使用 Keeva 時,某些第三方服務提供者(亦稱「子處理者」)會代表我方處理有限類別的資料,以提供平台必要服務。我們在此列出,讓您確切了解誰能存取哪些資料。
我方承諾在新增任何子處理者之前,至少提前 30 天通知。若要訂閱變更通知,請聯繫我們,我們將把您加入通知名單。
目前的子處理者(v1.0 — Android)
| 提供商 | 用途 | 共享的資料 | 地區 | 提供商 DPA / 隱私 |
|---|---|---|---|---|
| Google LLC(Firebase) | 當機回報(Crashlytics)——當機資料 + 用於分組當機的裝置實例 UUID | 裝置實例 UUID;當機堆疊追蹤(依據隱私政策,不含使用者輸入內容) | 美國,含依 Google 資料中心政策的地區性處理 | Firebase 隱私與安全 · Google Cloud DPA |
| Google LLC(Firebase Analytics) | 選用的使用分析——預設關閉,僅在使用者透過「設定 → 關於你的資料」主動開啟後傳送 | App 實例 / 安裝 ID;有界限的 App 活動事件;啟用分析時設定的時區使用者屬性 | Google 全球(美國為主) | Firebase 隱私與安全 · Google Cloud DPA |
| Google LLC(Play Store) | Play Store 發佈;收據驗證 | Google Play 帳號 ID(僅 Play Store 用戶);購買收據 | 美國,含地區性 CDN | Google Play 條款 |
| Google LLC(Firebase Remote Config) | App 版本強制更新開關——於冷啟動 + onResume 時呼叫 fetchAndActivate()(5 分鐘速率限制)以強制執行最低 App 版本 | Firebase 安裝 ID + App 版本 + 裝置語言 | Google 全球(美國為主) | Firebase 隱私與安全 · Google Cloud DPA |
計劃中的子處理者(v1.1+,尚未啟用)
| 提供商 | 用途 | 共享的資料 | 地區 | 提供商 DPA / 隱私 |
|---|---|---|---|---|
| Apple Inc. | App Store 發佈;付費 App 購買收據驗證(iOS——Android 上架後計劃推出;v1.0 無訂閱處理) | Apple ID(登入 App Store 時)、購買收據 | 美國(含地區性 CDN) | Apple 隱私政策 |
| IAP 基礎設施(待定) | 未來能力 IAP / 訂閱狀態彙總(若引入,依新 ADR 決定) | 用戶識別符;訂閱狀態;收據元資料(提供商待定) | 待定 | 待 Phase 2+ 未來能力 IAP 引入時確認 |
當未來能力 IAP 基礎設施整合後(Phase 2+,需新 ADR 決定),本章節將移至「目前的子處理者」,並於本頁先行發布 30 天提前通知。
我們刻意不使用的服務
為求透明,以下是 Keeva v1.0 不委託任何子處理者的項目:
- 無後端應用伺服器——Keeva 採本地優先設計。您的習慣、日誌、筆記、照片存於您的裝置,Keeva 不會上傳(若您開啟作業系統層級備份,該備份僅存在於您與 Google 或 Apple 之間——請見隱私權政策)
- 無 Firebase Authentication——Keeva v1.0 不需登入。您沒有 Firebase 用戶帳號
- 無 Firestore / Cloud Storage——您的習慣資料和照片永不上傳至 Google Cloud
- 無行銷型 analytics SDK(Mixpanel / Amplitude / Segment 等)——Keeva 使用 Crashlytics 進行預設開啟的當機診斷,Firebase Analytics 僅用於選用的使用分析且預設關閉
- 無廣告 SDK——Keeva 不含廣告
- 無直接支付處理商——付費 App 購買計費由 Google 處理(Keeva 未來推出 iOS 版時另由 Apple 處理);我們看不到您的卡號
跨境傳輸
上述子處理者總部位於美國。當您在美國以外使用 Keeva 時,您的錯誤回報資料以及(對 Play Store 用戶)Play 帳號識別符可能會被傳輸至美國並在當地處理。
我們依賴每個提供商提供的安全保障:
- Google(Firebase + Play)——v1.0 唯一實際啟用的子處理者:依 Google Cloud DPA 的標準合約條款
- Apple(計劃中,尚未啟用):已發佈的隱私政策 + EU-US 資料隱私框架認證。目前沒有任何資料傳送至 Apple——此項僅於 Keeva 未來推出 iOS 版時適用。
- 未來 IAP 基礎設施(啟用時):依提供商 DPA 的標準合約條款(待 Phase 2+ IAP 引入時確認)
變更通知
我方承諾在子處理者變更生效前至少 30 個日曆天發佈通知。通知透過以下方式傳遞:
- 本頁面的「最後更新」時間戳 + 以下變更日誌
變更日誌
| 日期 | 變更 |
|---|---|
| 2026-04-25 | 頁面建立——v1.0 上架初始子處理者清單 |
| 2026-04-28 | 新增 firebase_remote_config 列,依 Wave 4 強制更新開關上線 + GDPR 第 28 條揭露要求 |
| 2026-05-21 | 新增 Firebase Analytics 列,並與 App 隱私設定中的預設關閉 / 主動開啟語意對齊 |
| 2026-07-31 | 跨境傳輸的安全保障重新排序,將 Apple 標示為「計劃中、尚未啟用」,與上方表格一致(v1.0 僅支援 Android——目前沒有任何資料傳送至 Apple);「無支付處理商」修正為「無直接支付處理商」。未新增任何子處理者——不涉及 30 天提前通知承諾。 |
| 2026-09-08 | 釐清安裝識別碼的說明,不再宣稱資料完全匿名。未新增服務提供者,也未變更資料傳輸方式。 |
聯絡
如對本清單有任何疑問或要訂閱變更通知,請見隱私政策聯絡章節。
This policy is governed by the English version. In case of any discrepancy between translations, the English version prevails.