This is a first-draft privacy policy based on ifgame's current data boundaries. Before launch, it must be legally reviewed against the production domains, deployment regions, third-party Providers and payment integration.
1. 我们处理哪些信息
- 账户与身份信息:用于登录、账户归属和服务授权。
- 操作与计费信息:Provider 操作身份、状态、用量、成本凭据、余额和账本记录。
- 用户提交内容:为完成用户明确发起的 Planning、Agent 或媒体操作而提交的任务内容和相关输入。
- 远端结果与恢复信息:Provider 原始结果、结果哈希、结算状态及服务恢复所需记录。
- 本地项目数据:项目文件、Godot 执行、媒体后处理、检查点与最终验证主要保留并运行在用户设备。
2. 处理目的
上述信息用于提供与鉴权 ifgame 服务、执行用户发起的 Provider 操作、完成计费与余额结算、交付和恢复结果、维护安全与稳定、处理故障和履行适用法律要求。
3. 本地与远端数据边界
ifgame 的桌面端负责本地项目文件、Codex/Agent 工具进程、媒体后处理、检查点、Godot 执行和最终验证。业务服务器负责会话、账户归属、数据库操作、付费操作预留与结算、受控 Provider 调用、原始结果保留和操作恢复。正式版本会按实际部署进一步说明各服务所在区域。
4. 第三方 Provider
当用户主动发起需要第三方模型或媒体 Provider 的操作时,完成该操作所必要的输入会发送给对应 Provider。ifgame 通过固定或受控的服务端路由调用相关上游。正式上线时将根据实际启用的 Provider 更新第三方服务清单及其隐私信息。
5. 支付信息
正式接入支付宝电脑网站支付后,用户支付过程由支付宝页面处理。ifgame 的支付服务接收并验证支付结果,并将与充值订单、到账和对账有关的必要信息写入业务记录。客户端页面跳转本身不会作为余额入账依据。
6. 保存与清理
账户、操作、账本、结算和必要的结果元数据按服务运行与合规需要保存。远端原始 Provider 结果不会因为下载完成而立即删除;当结果存储达到系统容量阈值时,可按既定清理规则删除最早的已结算原始结果,活跃或未结算操作不参与该清理。正式政策将结合实际合规要求补充具体保存期限或判断标准。
7. 安全措施
我们通过身份与所有权校验、服务端凭据隔离、受控 Provider 路由、操作级记录、HTTPS 以及必要的恢复与核对机制保护服务数据。任何互联网服务都无法保证绝对安全,正式运营期间会持续维护合理的技术和组织措施。
8. 用户权利
正式上线后,用户可依适用法律请求查询、更正、删除依法可删除的个人信息,或撤回特定同意、注销账户及提出隐私相关问题。具体入口、身份核验方式和例外情形将在正式政策中明确。
9. 未成年人
正式上线前将根据实际服务受众和适用法律明确未成年人使用条件。在相关规则完成前,不将本服务宣传为专门面向未成年人的产品。
10. 政策更新
当产品能力、数据处理、第三方服务或法律要求发生变化时,我们可能更新本政策。重大变更将按适用法律要求采用合理方式通知用户。
11. 联系我们
运营主体:北京易富网络科技有限公司
统一社会信用代码:91110105078554409Y
联系邮箱:待正式上线配置
联系电话:待正式上线配置
1. Information we process
- Account and identity information used for sign-in, ownership and authorization.
- Operation and billing information such as Provider operation identity, status, usage, cost receipts, balance and ledger records.
- User-submitted content required to perform Planning, Agent or media operations explicitly requested by the user.
- Remote results and recovery information including original Provider results, hashes, settlement state and recovery records.
- Local project data: project files, Godot execution, media post-processing, checkpoints and final verification primarily remain and run on the user's device.
2. Why we process it
We process this information to provide and authorize ifgame services, execute requested Provider operations, complete billing and balance settlement, deliver and recover results, maintain service security and reliability, resolve failures and meet applicable legal requirements.
3. Local and remote data boundaries
The desktop application owns local project files, Codex/Agent tool processes, media post-processing, checkpoints, Godot execution and final verification. Business servers own sessions, account ownership, database operations, paid-operation reservation and settlement, controlled Provider calls, raw-result retention and operation recovery. The production policy will describe actual deployment regions.
4. Third-party Providers
When a user requests an operation that needs a third-party model or media Provider, input necessary to complete that operation is sent to the applicable Provider through a fixed or controlled server route. The production policy will identify the Providers actually enabled and link to relevant privacy information.
5. Payment information
After Alipay web payments are integrated, payment interaction will be handled on Alipay pages. ifgame's payment service will receive and verify payment results and write the necessary top-up, credit and reconciliation data to business records. A client-side page redirect alone is not evidence for crediting balance.
6. Retention and cleanup
Account, operation, ledger, settlement and necessary result metadata are kept as required to operate the service and meet compliance needs. Remote raw Provider results are not deleted simply because they were downloaded; when result storage reaches a configured capacity threshold, the oldest settled raw results may be removed under established cleanup rules while active or unsettled operations remain protected. Production policy will add retention periods or criteria required by applicable law.
7. Security
We protect service data using identity and ownership checks, server-side credential isolation, controlled Provider routing, operation-level records, HTTPS and recovery/reconciliation mechanisms. No internet service can guarantee absolute security; reasonable technical and organizational safeguards will be maintained during production operation.
8. User rights
After launch, users may exercise rights available under applicable law, including requests to access, correct or delete eligible personal information, withdraw certain consent, close an account or ask privacy questions. The production policy will specify request channels, identity verification and applicable exceptions.
9. Minors
Before launch, conditions for minors will be defined according to the actual audience and applicable law. Until those rules are finalized, the service is not presented as a product specifically directed to minors.
10. Policy updates
We may update this policy when product capabilities, data processing, third-party services or legal requirements change. Material changes will be communicated in a reasonable manner where required by applicable law.
11. Contact
Operator: 北京易富网络科技有限公司
Unified Social Credit Code: 91110105078554409Y
Email: To be configured before launch
Phone: To be configured before launch