生效日期:2026年3月5日(最後更新)
版本:v2.0
🔗 TON Connect 生態系聲明
CryptoMind 是 TON Connect 生態系的一部分。我們使用 TON Connect SDK 進行身份驗證和支付處理。您的部分資料將與 TON Connect 共享,受其TON Connect 隱私權政策約束。
CryptoMind 重視您的隱私。本政策說明我們如何收集、使用和保護您的個人資料。
📋 個人資料保護法(PDPA)合規揭露
依據中華民國《個人資料保護法》第 15 條,本平台於收集您的個人資料時,應明確告知以下事項:
- 收集者名稱:CryptoMind(本平台營運團隊)
- 收集目的:帳戶識別、支付處理、社群互動、AI 分析服務、安全防護
- 資料類別:TON 錢包地址、暱稱、發文/評論/打賞記錄、私人訊息、API 請求日誌、好友清單
- 使用期間/地區/對象/方式:帳戶存續期間 + 保留期限(見第 6 條);資料存儲於台灣伺服器及 TON Connect 全球基礎設施;僅供本平台及 TON Connect 使用
- 您的權利(第 3 條):查詢/閱覽、製給複製本、補充/更正、停止收集/處理/利用、停止利用
- 不提供之影響:若不提供錢包地址,將無法註冊及使用本平台服務
1. 我們收集的資料
1.1 身份資訊
- TON 錢包地址:用於帳戶識別和交易記錄
- 暱稱與個人資料:您在平台上設定的顯示資訊
1.2 使用數據
- 瀏覽記錄、功能使用習慣
- 論壇發文、評論、打賞記錄
- 詐騙檢舉與治理系統參與記錄
- API 請求日誌(IP 位址、時間戳)
- 私人訊息內容:您與其他用戶之間的聊天訊息,僅供雙方存取
- 好友與封鎖清單:您的社交關係連結記錄
1.3 交易資訊
- TON 支付記錄(會員訂閱、發文費用、打賞)
- 交易金額、時間、收款方資訊
1.4 AI 分析使用記錄
- 您觸發 AI 市場脈動分析的幣種與時間記錄
- 台股、美股深度分析的查詢記錄
🔒 重要:API 金鑰安全性
您的 OKX API 金鑰僅存儲在您的瀏覽器 localStorage 中,絕不上傳至我們的伺服器。
這表示:
- ✅ 您的 API 金鑰只存在於您的裝置上
- ✅ 我們無法存取您的交易所帳戶
- ✅ 更換裝置需重新輸入 API 金鑰
- ✅ 清除瀏覽器快取將刪除本地金鑰
2. 資料使用方式
2.1 服務提供
- 驗證身份並維護帳戶安全
- 提供個人化加密貨幣、台股、美股市場分析
- 處理 TON 支付交易(會員訂閱、發文費用、打賞)
- 提供 AI 市場脈動分析與深度研究報告
- 維護好友關係、私訊通訊功能
2.2 社群管理
- 偵測並防範詐騙、濫用行為
- 執行治理系統的懲罰與申訴機制
- 審核論壇內容是否符合社群守則
2.3 安全與防護
- 監控可疑活動(異常登入、惡意檢舉)
- 維護系統穩定性與資料完整性
3. 資料分享與第三方
3.1 TON Connect(重要)
我們使用 TON Connect SDK 進行身份驗證和支付處理。以下資料會與 TON Connect 共享:
- 您的 TON 錢包地址
- 認證 Token(用於身份驗證)
- 支付交易資訊(金額、時間)
這些資料受 TON Connect 隱私權政策 約束。TON Connect 可能將資料儲存於全球伺服器。
3.2 OKX API
加密貨幣市場數據通過 OKX public API 獲取。我們不會將您的個人資訊發送給 OKX。
3.3 yfinance(台股 / 美股資料)
台灣股市及美國股市資料通過 yfinance 開源套件獲取,屬延遲盤後資料。我們不會將您的個人資訊發送給 yfinance 或相關資料提供商。
3.4 法律要求
在以下情況下,我們可能需要披露資料:
- 遵守法律義務或政府要求
- 保護平台、用戶或公眾的權利與安全
- 調查涉嫌違法行為(詐騙、洗錢等)
- 回應 TON Connect 的合規要求
4. 用戶權利
4.1 存取與下載
您可以在「設定」頁面查看並下載您的個人資料。
4.2 修改資料
您可以隨時更新個人資料設定(暱稱、顯示圖片)。
4.3 刪除帳戶
您可以申請刪除帳戶。刪除後:
- 個人資料將被移除
- 論壇發文可能保留但匿名化(顯示為「已刪除用戶」)
- 已發送的 TON 打賞無法撤回
- 已支付的會員費用不予退款
- TON Connect 端的資料需依其政策處理
5. Cookie 與追蹤技術
5.1 必要 Cookie
我們僅使用必要的 Cookie 來維護登入狀態和語言偏好。
5.2 無廣告追蹤
我們不使用第三方廣告追蹤器或分析工具。
6. 資料保留期限
- 帳戶資料:帳戶活躍期間 + 刪除後 30 天
- 交易記錄:7 年(符合金融法規要求)
- 治理記錄:永久保留(防範重複違規)
- API 日誌:90 天
- TON Connect 資料:依 TON Connect 政策保留
7. 年齡限制
本平台不向 18 歲以下用戶提供服務。我們不會故意收集未成年人的個人資料。若發現未成年用戶,我們將立即刪除相關帳戶並通知 TON Connect。
8. 跨境資料傳輸
您的資料主要存儲在台灣伺服器。使用 TON Connect SDK 時,資料可能傳輸至 TON Connect 的全球基礎設施(可能位於美國或其他國家)。我們確保所有傳輸符合:
- GDPR(歐盟通用數據保護條例)
- 台灣個人資料保護法
- TON Connect 隱私政策要求
9. 資料安全措施
- 資料庫加密(AES-256)
- HTTPS 加密傳輸(SSL/TLS)
- 定期安全審計與漏洞修補
- 限制員工存取權限(最小權限原則)
- API 金鑰不存儲於伺服器
9.1 資料外洩通報
若發生個人資料安全事件(資料外洩、未授權存取、損毀),本平台將:
- 立即啟動應變措施,控制損害範圍並修復漏洞
- 於 72 小時內通知受影響用戶,說明外洩範圍、可能影響及建議防護措施
- 依法向主管機關通報(依個人資料保護法及未來「個人資料保護委員會」相關規定)
- 保留事件紀錄以供查核
通報方式:平台公告、電子郵件或站內通知。
10. 隱私政策變更
我們可能更新本政策。重大變更將通過平台公告通知,並要求您重新確認同意。
11. 聯絡我們
如有隱私相關疑問或數據請求,請聯絡:
- 平台論壇:私訊 @Admin
- 平台網址:cryptomind-ton.zeabur.app
🔗 TON Ecosystem Declaration
CryptoMind is part of the TON ecosystem. We use TON Connect SDK for authentication and payment processing. Some of your data is shared with TON Connect and subject to their TON Connect 隱私權政策.
CryptoMind values your privacy. This policy explains how we collect, use, and protect your personal data.
📋 Personal Data Protection Act (PDPA) Disclosure
Pursuant to Article 15 of the ROC Personal Data Protection Act, when collecting your personal data, the Platform explicitly informs you of the following:
- Data Collector: CryptoMind (Platform operating team)
- Purpose of Collection: Account identification, payment processing, community interaction, AI analysis services, security protection
- Categories of Data: TON wallet address, nickname, post/comment/tip records, private messages, API request logs, friends list
- Usage Period/Region/Recipients/Methods: During account lifetime + retention period (see Section 6); data stored on Taiwan servers and TON Connect global infrastructure; used only by the Platform and TON Connect
- Your Rights (Article 3): Access/view, request copies, supplement/correct, cease collection/processing/use, cease utilization
- Impact of Non-Provision: If you do not provide your wallet address, you will not be able to register or use the Platform's services
1. Information We Collect
1.1 Identity Information
- TON wallet address: Used for account identification and transaction records
- Nickname & Profile: Display information you set on the platform
1.2 Usage Data
- Browsing history, feature usage patterns
- Forum posts, comments, tipping records
- Scam reporting and governance participation
- API request logs (IP addresses, timestamps)
- Private message content: Chat messages between users, accessible only to the parties involved
- Friends & blocklist: Your social connection records
1.3 Transaction Information
- TON payment records (membership, post fees, tips)
- Transaction amounts, timestamps, recipient info
1.4 AI Analysis Usage
- Symbols and timestamps of AI Market Pulse analysis you trigger
- Query records for TW and US stock deep analysis
🔒 Important: API Key Security
Your OKX API keys are stored ONLY in your browser's localStorage and are NEVER uploaded to our servers.
This means:
- ✅ Your API keys exist only on your device
- ✅ We cannot access your exchange account
- ✅ Switching devices requires re-entering API keys
- ✅ Clearing browser cache deletes local keys
2. How We Use Data
2.1 Service Provision
- Verify identity and maintain account security
- Provide personalized crypto, Taiwan and US stock market analysis
- Process TON payment transactions (membership, post fees, tips)
- Deliver AI Market Pulse analysis and deep research reports
- Maintain friends, messaging, and social features
2.2 Community Management
- Detect and prevent fraud, abuse
- Execute governance penalties and appeals
- Moderate forum content against community guidelines
2.3 Security & Protection
- Monitor suspicious activity (abnormal logins, malicious reports)
- Maintain system stability and data integrity
3. Data Sharing & Third Parties
3.1 TON Connect (Important)
We use TON Connect SDK for authentication and payment processing. The following data is shared with TON Connect:
- Your TON wallet address
- Authentication tokens (for identity verification)
- Payment transaction info (amount, timestamp)
This data is subject to TON Connect 隱私權政策. TON Connect may store data on global servers.
3.2 OKX API
Cryptocurrency market data is fetched via OKX public API. We do not send your personal information to OKX.
3.3 yfinance (TW & US Stock Data)
Taiwan and US stock market data is retrieved via the yfinance open-source library (delayed post-market data). We do not send your personal information to yfinance or its data providers.
3.4 Legal Requirements
We may disclose data when:
- Complying with legal obligations or government requests
- Protecting rights and safety of platform, users, or public
- Investigating suspected illegal activities (fraud, money laundering)
- Responding to TON Connect compliance requirements
4. User Rights
4.1 Access & Download
You can view and download your personal data in Settings.
4.2 Modify Data
You can update profile settings (nickname, avatar) anytime.
4.3 Account Deletion
You can request account deletion. After deletion:
- Personal data will be removed
- Forum posts may be retained but anonymized (shown as "Deleted User")
- Sent TON tips are irreversible
- Paid membership fees are non-refundable
- TON Connect-side data is subject to their policy
5. Cookies & Tracking
5.1 Necessary Cookies
We only use necessary cookies to maintain login state and language preference.
5.2 No Ad Tracking
We do not use third-party ad trackers or analytics tools.
6. Data Retention
- Account Data: During active period + 30 days after deletion
- Transaction Records: 7 years (financial regulation compliance)
- Governance Records: Permanent (prevent repeat violations)
- API Logs: 90 days
- TON Connect Data: Per TON Connect policy
7. Age Restriction
This platform does not provide services to users under 18 years of age. We do not knowingly collect personal data from minors. Underage accounts will be deleted immediately upon discovery, and TON Connect will be notified.
8. Cross-Border Data Transfer
Your data is primarily stored on Taiwan servers. When using TON Connect SDK, data may transfer to TON Connect's global infrastructure (potentially in the US or other countries). We ensure all transfers comply with:
- GDPR (General Data Protection Regulation)
- Taiwan Personal Data Protection Act
- TON Connect Privacy Policy requirements
9. Data Security Measures
- Database encryption (AES-256)
- HTTPS encrypted transmission (SSL/TLS)
- Regular security audits and vulnerability patches
- Restricted employee access (least privilege principle)
- API keys not stored on servers
9.1 Data Breach Notification
In the event of a personal data security incident (data breach, unauthorized access, or destruction), the Platform will:
- Immediately initiate incident response to contain the damage and fix vulnerabilities
- Notify affected users within 72 hours, explaining the scope of the breach, potential impact, and recommended protective measures
- Report to competent authorities as required by the Personal Data Protection Act and future Personal Data Protection Commission regulations
- Retain incident records for inspection
Notification methods: Platform announcements, email, or in-app notifications.
10. Privacy Policy Changes
We may update this policy. Major changes will be announced on the platform and require your re-confirmation.
11. Contact Us
For privacy questions or data requests, contact:
- Platform Forum: DM @Admin
- Platform URL: cryptomind-ton.zeabur.app