隱私政策

最後更新:2026年8月22日  ·  生效日期:2026年8月22日  ·  版本:3.8
本政策依中華民國《個人資料保護法》及相關法規制定

本服務「知識宇宙 Moku」(以下簡稱「Moku」)係指網域 moku-ahvpc2nsb3n0-pano.xyz 所提供之應用程式及相關網頁服務,包含網頁版 PWA、Android 版及 iOS 版。

摘要:知識宇宙 Moku 是一個學習輔助工具。我們蒐集您的帳號資訊和學習紀錄以提供服務;我們不出售您的個人資料,也不會將輔助使用事件或已安裝 App 清單用於廣告或分析。支援廣告的版本可能透過 Google AdMob、Appodeal 與其廣告中介合作夥伴、AppLovin MAX,或網頁版 Google AdSense/Adsterra 顯示廣告;所有付費方案都不顯示橫幅式/一般插頁式廣告;包含 NT$60 無橫幅/插頁廣告版在內,使用者仍可在功能提供時自行選擇觀看獎勵廣告以取得額外額度。免費版亦可透過自願獎勵廣告體驗部分付費 AI 功能;支援的付費 AI 功能可透過自願獎勵廣告取得跨功能共用的「單次功能使用權」;目前每 3 次一般激勵廣告可取得 1 次,免費方案每月最多透過廣告取得 10 次。另有可累積的 Deep Credits(深度額度)供較高成本 AI 工作使用,目前每 5 次一般激勵廣告可取得 1 個,且不計入上述 10 次上限。樹洞對話歷史主要保存在您的裝置;當您要求 AI 回覆時,訊息及必要的近期對話會經 Moku 後端傳送給所選 AI 服務商處理。日記內容則會儲存在您的帳號中。您可以隨時啟動已驗證的刪除帳號流程,以清除與帳號相關的可識別資料;依法、退款、安全、防詐、備份或系統輪替所需的有限例外,依本政策第10節處理。

01 資料控管者資訊

服務名稱知識宇宙 Moku
聯絡信箱[email protected]
服務網址https://moku-ahvpc2nsb3n0-pano.xyz/
個資申請窗口[email protected](主旨請標注「個資申請」)

本服務為個人開發者經營,未設置專職個人資料保護長(DPO)。個資相關事務由上述聯絡信箱受理,並依《個人資料保護法》第8條及第19條辦理。

02 適用範圍

本隱私政策適用於知識宇宙 Moku 應用程式(包含網頁版 PWA、Android 版、iOS 版)及相關網站(包含 moku-ahvpc2nsb3n0-pano.xyz 及子頁面)。

本政策不適用於:透過本服務連結至的第三方網站或服務;各 AI 服務商(Gemini、Claude、DeepSeek、OpenAI)與 AI 路由服務(例如 OpenRouter)的獨立隱私政策;RevenueCat、Google Play、Apple App Store,以及未來另行啟用之網頁付款服務商的獨立付款流程。

03 我們蒐集的個人資料

A. 您主動提供的資料

資料類別具體內容蒐集時機是否必要
帳號識別資料電子郵件地址、顯示名稱、密碼(Firebase 加密處理,Moku 無法讀取原始密碼)註冊帳號必要
個人資料(選填)頭像圖片、就讀學校、目標科系、考試年度設定個人檔案選填
學習紀錄科目名稱、學習日期、學習時數、學習深度(0-100)、筆記文字內容、AI 自動生成的摘要每次記錄學習核心功能
目標與計畫每日學習目標、優先事項、複習排程設定目標功能性
作文、考卷與練習紀錄使用者提交批改的作文全文(最多 2000 字)、使用者主動儲存的原文與修改後作文、批改結果與分數;AI 出題設定、生成考卷、作答紀錄與錯題本內容使用 AI、作文紀錄、考卷歷史或錯題本功能功能性
情緒、睡眠與身心狀態相關資料*您在心情打卡、睡眠紀錄、樹洞或日記中自願提供的情緒、睡眠與心理感受;以及為提供個人化支持而產生的有限功能訊號,例如單次讀書時間、是否使用便條/考試寫作功能,以及由您輸入內容辨識出的負面自我評價標記。樹洞歷史主要存於裝置;日記、睡眠紀錄與上述訊號存於 Firestore;要求 AI 回覆時,必要內容會傳送至 Moku 後端與 AI 服務商(詳見第6節)使用相關選用功能功能性/選填
付款與交易資料訂單編號、購買方案、付款時間、付款狀態與訂閱權益狀態;信用卡或付款憑證由 Google Play、Apple App Store,或未來另行啟用且於結帳頁揭露的付款平台處理;Moku 與 RevenueCat 均不取得或儲存完整卡號購買付費方案付款功能
上傳媒體自訂頭像圖片、拍照解題的題目圖片使用圖片功能選填
群組與社交群組名稱、群組說明、邀請碼、好友關係使用社交功能功能性

* 情緒、睡眠與心理感受可能屬敏感或健康相關資料;這些功能均為選用。我們只在您主動輸入、儲存或使用相關功能時,依本政策所述目的處理。

B. 系統自動蒐集的資料

資料類別具體內容用途
認證日誌登入與安全中繼資料。Firebase/Google 可能依其服務處理登入時間、登入方式與 IP 位址;Moku 僅在安全、除錯或支援所需時使用可取得的紀錄帳號安全
學習 Session 狀態計時器是否運作中、當前科目、今日累計時數(即時同步至學習室)學習室功能
裝置與環境資訊作業系統類型(iOS / Android / Web)、瀏覽器 User-Agent(用於平台適配),以及由 App 隨機產生並儲存在裝置上的 moku_device_id平台適配;隨機識別碼會隨 AI 請求傳給 Moku 後端,用於配額管理與防止濫用,不用於廣告追蹤
功能使用紀錄AI 功能每日使用次數,以及使用者主動使用相關功能時產生的有限支持訊號(如心情打卡、睡眠紀錄、單次讀書時間、便條或考試寫作使用狀態)配額管理、跨裝置同步與個人化學習/情緒支持
廣告與獎勵驗證技術資料支援廣告的版本可能由廣告 SDK/合作夥伴處理 IP 位址、廣告識別碼(如 AAID/IDFA,依平台權限與同意狀態)、裝置/網路資訊與廣告請求、曝光、點擊等互動資料。當您主動使用獎勵廣告時,Moku 另以 Firebase UID 作為不含姓名或 Email 的 Appodeal User ID,並在後端處理廣告商提供的 transaction/impression ID、時間戳記、獎勵數量/幣別及驗證結果。廣告投放、同意管理、頻率控制、成效量測、反詐,以及伺服器端驗證與防止重複發放獎勵

C. 透過 Google 或 Apple 登入取得的資料

使用 Google 帳號登入(OAuth 2.0)時,本服務只要求 emailprofile;我們不會要求或取得 Gmail、Google 聯絡人、Google 日曆、Google Drive 或其他 Google 服務內容。

使用「使用 Apple 登入」時,Firebase Authentication 會接收 Apple 提供的穩定帳號識別碼,以及您選擇分享的電子郵件與姓名。若您使用 Apple 的「隱藏我的電子郵件」,Moku 只會取得 Apple 提供的私人轉寄地址。

D. Android 裝置端權限與敏感 API

以下存取只會在您主動使用對應功能並完成 App 內明確說明與同意後發生。除非下表另有說明,資料僅在裝置端即時處理,不會傳送至 Moku 伺服器、不會分享給第三方,也不會用於廣告或分析

功能/API存取內容與用途儲存、上傳與分享
輔助使用服務(AccessibilityService)僅在您啟用 App 專注鎖定期間,從視窗切換事件辨識目前開啟 App 的套件名稱;若命中您自行設定的黑名單,執行 Android 系統的「返回桌面」動作。此服務不是身心障礙輔助工具。不讀取畫面文字、通知、訊息、密碼、按鍵或可存取性節點;不自動點擊;不儲存、不上傳、不分享輔助使用事件資料。
可啟動 App 清單/套件可見性在您按下「同意並顯示清單」後,讀取可從桌面啟動的 App 名稱與套件名稱,讓您勾選要加入黑名單的 App。Moku 使用範圍限定的 Launcher intent 查詢,不要求完整套件查詢權限。清單只在您的裝置上顯示與選擇;不傳送至伺服器、不用於建立使用者輪廓、廣告或分析。
前景服務(specialUse)只有在您主動開啟翻蓋自動計時後,持續讀取加速度感測以辨識裝置正面朝上或朝下,並顯示常駐通知;關閉翻蓋功能後即停止。一般讀書計時不使用此前景服務。前景服務本身不蒐集或傳輸個人資料,也不負責偵測或封鎖其他 App。
通知與勿擾模式存取顯示計時/翻蓋功能狀態,或在您自行開啟「計時自動勿擾」後切換 Android 勿擾狀態。Moku 不讀取通知內容;勿擾模式存取只用於切換狀態。
顯示在其他應用程式上層(SYSTEM_ALERT_WINDOW)僅在您主動開啟「App 外懸浮角色」時,讓您選擇的角色與其對話框顯示在其他 App 上方,並可拖曳、依附螢幕邊緣或點擊互動。此權限不讓 Moku 讀取其他 App 的畫面、文字、通知、輸入內容或觸控資料;角色設定僅用於顯示功能。角色與對話框以外的透明區域不應攔截其他 App 的觸控。您可隨時在 Android 系統設定撤銷此權限或於 Moku 關閉懸浮角色。

E. iOS 裝置端權限與 Screen Time API

iOS 版不使用 AccessibilityService,也不讀取其他 App 的畫面或前景事件。專注鎖定改用 Apple 公開的 FamilyControls、ManagedSettings 與 DeviceActivity API;使用者必須先在系統授權畫面同意,並在 Apple 提供的選擇器中自行挑選 App 或類別。

功能/API存取內容與用途儲存、上傳與分享
FamilyControls/ManagedSettings顯示 Apple 系統選擇器,取得使用者自行選取之 App、網站或類別的不可讀識別 Token,並在專注期間由系統顯示遮蔽畫面。選擇結果只保存在 App Group 的裝置端儲存;Moku 無法從 Token 還原完整使用清單,也不將其上傳、用於廣告或分析。
DeviceActivity在使用者設定的專注期間啟用或停止系統遮蔽。實際可用性受 Apple entitlement、家長監護設定及系統版本限制。不讀取畫面文字、通知、訊息、密碼或按鍵;不建立其他 App 使用行為的伺服器端紀錄。
Core Motion僅在使用者主動開啟翻蓋自動計時且 App 可執行對應工作時,讀取裝置方向與加速度來辨識正面朝上或朝下。iOS 可能在背景暫停此功能。原始感測值不儲存、不上傳、不分享。
通知顯示計時、提醒及功能狀態。iOS 版不嘗試以私有 API 自動切換系統專注模式或勿擾模式。Moku 不讀取其他 App 的通知內容。
AppTrackingTransparency/廣告識別碼(IDFA)若支援廣告的 iOS 版本需要存取裝置廣告識別碼或進行 Apple 所定義的追蹤,會先顯示 Apple 的系統授權提示;只有在您允許後,廣告 SDK 才可依平台規則使用該識別碼進行較相關的廣告投放或廣告成效量測。拒絕不會限制 Moku 的學習功能;未取得授權時 Moku 不會以 IDFA 進行追蹤。Moku 不會把樹洞、日記、作文、考卷或學習內容交給廣告系統做定向。

F. 我們不蒐集的資料

✓ 我們明確不蒐集
  • 精確 GPS 位置資料
  • 裝置通訊錄或電話記錄
  • 輔助使用事件內容、畫面文字、通知、訊息、密碼或按鍵
  • 可啟動 App 清單或黑名單的伺服器端副本
  • 生物特徵資料(指紋、臉部辨識等)
  • 完整信用卡號碼或完整付款憑證(由 Portaly、Google Play 或 Apple App Store 等付款平台處理)
  • 樹洞完整歷史的 Firestore 永久副本;送出訊息時仍會將該訊息與必要近期內容經 Moku 後端傳給 AI 服務商

04 蒐集目的與法律依據

依《個人資料保護法》第19條,本服務蒐集個人資料之特定目的與法律依據如下:

蒐集目的特定目的代碼法律依據涉及資料
帳號建立與身分驗證069(契約關係)個資法第19條第1項第2款(契約關係必要)電子郵件、顯示名稱
提供學習追蹤核心服務069、090個資法第19條第1項第2款學習紀錄、目標設定
AI 個人化分析功能069、157(研究分析)個資法第19條第1項第5款;首次將內容傳給第三方 AI 前取得明確同意,且可在設定中撤回學習摘要、科目資料
付款處理與交易記錄069、148(電子商務)個資法第19條第1項第2款;稅務法律義務付款資訊、訂單紀錄
社交與群組功能069、090個資法第19條第1項第5款(當事人同意)顯示名稱、頭像、Session
選用的情緒、睡眠與身心支持功能069您主動使用選用功能並依介面告知提供資料心情、睡眠、日記、樹洞內容與有限支持訊號
廣告投放、同意管理與獎勵驗證069、135依所在地適用法規、平台同意選擇,以及提供使用者主動選擇之廣告/獎勵功能所必要廣告識別碼與裝置/網路技術資料(依權限與同意狀態)、Firebase UID、廣告交易/曝光識別碼與驗證結果
服務安全與防詐135(資訊管理)個資法第19條第1項第6款(正當利益)登入與安全中繼資料
匿名化統計分析157個資法第19條第1項第6款;完全去識別化後適用匿名使用趨勢
法律遵循法律義務(稅務、消費者保護法等)依法或為會計、退款與防詐所需的交易紀錄
⚠ 我們明確不做的事
  • 不將個人資料出售或出租給任何第三方
  • 不將樹洞、日記、作文、考卷、筆記或其他學習內容交給廣告系統做定向;支援廣告的版本中,Google AdMob、Appodeal/其廣告中介合作夥伴、AppLovin MAX 或網頁版 Adsterra 仍可能依適用同意狀態與各自政策處理 IP 位址、Cookie/廣告識別碼、裝置/網路資訊及必要廣告技術資料,以進行投放、頻率控制、反詐與成效量測
  • 不將個人資料用於與上述目的無關的用途
  • 不在未取得您同意的情況下變更蒐集目的

05 第三方服務商(服務提供者)

本服務會使用以下第三方服務。各服務商依其在特定功能中的角色、合約、適用條款與法律處理必要資料;其中屬受託處理性質者,我們要求採取適當安全措施並限制於提供服務所必要的範圍。

基礎架構類

服務商用途處理的資料伺服器位置隱私政策
Google Firebase Authentication帳號建立、身分驗證、登入電子郵件、顯示名稱,以及服務商為驗證與安全所處理的登入中繼資料依 Google/Firebase 當時配置的基礎設施與適用條款連結
Google Cloud Firestore儲存學習紀錄、設定、群組、社交資料所有結構化用戶資料美國(us-central1)連結
Firebase Realtime Database即時 Session 同步(學習室)計時狀態、當前科目美國(us-central1)連結
Cloudinary圖片儲存與 CDN頭像、題目圖片美國(全球 CDN)連結
Cloudflare Pages應用程式部署與 CDN連線日誌(匿名化)全球邊緣節點連結

AI 服務類

服務商用途傳送的資料重要說明
Capgo UpdaterAndroid 測試或非 App Store 發行版本的版本檢查(若另行啟用)目前 Bundle 版本與更新檢查所需的基本裝置/網路資訊iOS App Store 送審版已關閉自動 Web Bundle 更新;iOS 功能與程式變更只透過 App Store 新版本發布
Google Gemini API依後端路由處理圖片 OCR、圖片/PDF/網址理解、搜尋型資料取得,以及部分 AI 學習功能您送出的提示、必要近期內容、圖片、文件或網址等功能必要資料Gemini API 服務條款及隱私政策處理
OpenRouter目前作為部分 Claude、DeepSeek 與 OpenAI GPT 請求的 API 路由/閘道;例如一般英文/數理自然出題可路由至 DeepSeek V4 Flash,人文標準出題可路由至 OpenAI GPT,並將請求轉交所選模型服務該次 AI 功能所必要的提示、文字與上下文,以及路由所需技術中繼資料;不會因為使用 OpenRouter 而額外把樹洞、作文或學習資料交給廣告系統OpenRouter 隱私政策、適用條款及所選下游模型服務商政策處理
Anthropic Claude API依後端路由處理需要較高文字判斷品質的作文示範改寫、部分人文/法律內容,以及學習歷程/備審在主要模型失敗時的備援任務作文、經壓縮的文件證據、提示與其他功能必要內容Anthropic 隱私政策及適用 API 條款處理
DeepSeek API依後端路由處理英文、數學、自然、物理、化學、生物等出題、文件抽取後的純文字資料分析與其他成本敏感文字推理;標準出題可使用非思考模式,深度生成或較重分析可啟用推理模式;政治敏感人文與台灣法律審查不以 DeepSeek 作為主要路由您送出的提示與功能必要文字內容DeepSeek 隱私政策及適用 API 條款處理
OpenAI GPT(目前可經 OpenRouter 路由)依後端路由處理部分成本敏感、量較大的標準人文文字出題與必要備援;目前不作為台灣法律出題的主要路由您送出的出題提示、指定範圍、必要上下文與格式要求依 OpenRouter、OpenAI 及所選路由適用的 API 條款與隱私政策處理
Google AdMob(支援廣告的原生版本)顯示橫幅、插頁、激勵或獎勵式插頁廣告;實際格式依方案與使用者選擇廣告 SDK 為投放、頻率控制、反詐與成效量測所需的裝置/廣告技術資料;在 iOS 上,若存取 IDFA 或涉及 Apple 所定義的追蹤,會先依 AppTrackingTransparency 取得系統授權;實際處理依 Google 與平台適用政策所有付費方案不顯示橫幅式/一般插頁式廣告;獎勵廣告僅在使用者自行選擇且功能有提供時啟動;Moku 不把學習內容交給 AdMob 做定向
Appodeal 與其廣告中介合作夥伴(支援廣告的原生版本)依目前啟用的原生廣告 provider 與 Appodeal mediation 設定提供橫幅、插頁或獎勵廣告Appodeal/合作廣告來源可能依同意與平台權限處理 IP 位址、廣告識別碼、裝置/網路資訊及廣告互動資料。獎勵廣告另使用 Firebase UID 作為不含姓名或 Email 的 Appodeal User ID,供伺服器端獎勵對帳。Appodeal 隱私政策與其廣告需求來源清單處理;Moku 不把學習內容提供給廣告系統做定向
AppLovin MAX(原生版本,於被選為廣告 provider 時)作為可由遠端設定選擇的原生廣告 provider,提供支援的廣告格式依 AppLovin 與平台適用政策處理投放、頻率控制、反詐與成效量測所需的廣告/裝置技術資料僅在該版本實際選用 MAX provider 時啟用;實際處理依 AppLovin 隱私政策
Google AdSense/Adsterra(網頁版公開內容)在符合內容與頁面條件的公開文章/學習資源頁顯示廣告;Adsterra 公開內容頁目前僅使用橫幅,並依適用的同意與隱私閘門載入依 Google 適用政策與使用者同意狀態處理廣告投放、反詐與成效量測所需的 Cookie/裝置/網路技術資料Moku 不把登入後的學習內容、樹洞、日記、作文或考卷提供給 AdSense 做定向
Adsterra(登入後網頁版免費方案)在登入後的網頁版免費方案顯示 320×50/728×90 橫幅;並在自然完成點確保單一 Social Bar script 已載入,由 Adsterra 控制其通知/widget/overlay 等輪替樣式與頻率。所有付費方案不載入這些強制格式Adsterra 與其廣告技術合作方可能依其政策處理 IP 位址、Cookie、瀏覽器/裝置/網路資訊、廣告請求、曝光、點擊、頻率與反詐所需技術資料。Moku 不把樹洞、日記、作文、考卷、筆記或其他學習內容傳給 Adsterra 做定向。Adsterra 隱私政策處理。Moku 會向訪客提供 Web 廣告 Cookie/隱私選擇提示。於 Moku 目前未列為需事前取得額外廣告同意訊號的地區,一般 Adsterra 廣告可能在使用者尚未作出選擇前載入;使用者選擇拒絕後,Moku 會停止後續 Adsterra 載入。於 EEA/英國/瑞士及 Moku 目前保守列管的美國情境,若尚未取得適用的使用者選擇及 IAB TCF/GPP 訊號,Adsterra 仍會暫停載入。此區域判斷是 Moku 的保守技術閘門,並不取代各地適用法律或 Adsterra 自身義務。

付款類

服務商用途處理的資料說明
網頁付款服務商(若未來啟用)網頁版購買方案收款訂單金額與付款所需資料;具體服務商會在結帳頁揭露,Moku 不儲存完整卡號目前原生 App 的數位商品由 Google Play 或 Apple App Store 結帳
Google Play BillingAndroid 版訂閱與應用程式內購買商品、交易狀態及由 Google 提供的購買憑證;Moku 不取得完整付款卡號依 Google Play 的付款與隱私政策
RevenueCat在已啟用內購的版本中驗證訂閱、同步跨裝置權益與管理方案狀態以 Firebase UID 作為 App 使用者識別碼,並處理商品識別碼、購買/訂閱狀態及平台交易識別資訊;不處理完整卡號僅在設定有效的 RevenueCat 公開 API 金鑰並啟用內購後傳送
Apple App StoreiOS 版訂閱與應用程式內購買(啟用時)商品與交易狀態;Moku 不取得完整付款卡號依 Apple 的付款與隱私政策

第三方服務安全:我們會依服務性質、合約與適用政策限制傳送範圍,並對受託處理個人資料的服務商要求適當安全措施。廣告、付款或平台型服務商可能依其自身法定角色與政策處理必要技術資料,並非所有第三方在所有情境下都屬於單純「受 Moku 指示的資料處理者」。若發生與 Moku 相關且依法需通知的資料外洩,我們將依第14節所述程序處理。

06 AI 功能與對話資料

明確同意:第一次使用會把內容傳給第三方 AI 的功能前,Moku 會先顯示獨立說明,列出可能使用的 Google Gemini、Anthropic Claude、DeepSeek 或 OpenAI GPT;目前部分 Claude/DeepSeek/OpenAI GPT 請求會經 OpenRouter 路由。說明也會列出可能傳送的文字、圖片、作文、學習摘要或必要近期內容。只有按下同意後該次內容才會送出;拒絕不影響非 AI 功能。您可在「設定 → 隱私 → 政策與安全」撤回同意,撤回後下次使用 AI 會再次詢問。

樹洞功能(默的 AI 對話)

實際資料流:樹洞的對話歷史主要保存在您的裝置(localStorage,最多保留最近 100 則訊息)。每次您送出訊息時,該訊息與為維持對話所需的近期內容會經 HTTPS 傳送到 Moku 的後端,再由後端交由所選 AI 服務商(可能為 Google Gemini、Anthropic Claude 或 DeepSeek)產生回覆。Moku 不會把完整樹洞歷史另行寫入 Firestore;後端仍可能依基礎設施與安全需求產生短期技術日誌,但不會將對話內容用於廣告或販售。

  • 清除樹洞記錄、清除 App 資料或解除安裝,可移除裝置上的對話歷史
  • 為取得 AI 回覆,輸入內容必須傳送至 Moku 後端與 AI 服務商;未送出的草稿不會傳送
  • 請不要輸入身分證號、完整住址、金融帳號、密碼等不必要的高度敏感識別資訊
  • 樹洞提供一般情緒支持,不是醫療、心理治療或緊急服務

日記功能

  • 您主動儲存的日記會寫入您帳號下的 Firebase Firestore,以便跨裝置同步
  • 只有在您要求「讓默回覆」時,該篇內容才會經 Moku 後端傳送至所選 AI 服務商處理
  • 刪除日記會從 Firestore 移除該筆內容;刪除帳號時會依本政策一併刪除帳號相關資料

作文批改與完整示範改寫(AI 服務)

  • 照片作文在您確認前可先由 Gemini 進行忠實 OCR;系統要求保留原始錯字、拼字與文法,不在 OCR 階段自動潤稿。
  • 一般作文評分可能由 DeepSeek 等後端模型進行多次評閱;完整作文 AI 示範改寫不會自動產生,只有使用者手動要求時才會另外送往文字生成模型(目前可包含 Claude)。
  • 批改結果可能快取於您的私人 Firestore 區域一段有限時間,以減少重複 API 呼叫。若您另外按下「儲存到作文紀錄」,原文、您修改後的版本、分數與批改結果會保存到您帳號下的私人 Firestore 作文紀錄,直到您刪除該筆紀錄或刪除帳號。

AI 出題與模擬考

  • 出題會傳送您選擇的考試、科目、題量、難度、指定範圍,以及生成題目所需的提示內容;若您貼入教材、筆記或其他內容,只有完成該次出題所需的內容會隨請求傳送。
  • 10 題、20 題與完整模考可依後端路由交由不同 AI 服務商處理。標準人文出題目前可優先使用成本較低的 OpenAI GPT 路由,必要時由 Gemini 或 Claude 備援;深度人文出題可使用 Gemini 的較高推理設定並由 Claude 備援。數學與量化 STEM 可使用 DeepSeek。供應商與模型可能因品質、可用性及成本調整。
  • 完整模考或深度生成可能使用 Deep Credits。Moku 只以題量、品質與工作量等資訊做額度/成本控制,不會把您的考題內容提供給廣告系統做定向。

Deep Credits 好友贈送

  • 當您主動把 Deep Credits 贈送給好友時,Moku 後端會處理寄件者 UID、收件者 UID、贈送數量、交易識別碼與時間,以完成扣除、入帳、避免重複轉帳並執行滾動 24 小時接收上限。
  • 收到的贈予額度會記錄在收件者的私人 Deep Credit 帳本中,可正常用於 Deep 功能,但不能再次轉送。每個帳號在任意滾動 24 小時內最多收到 10 個贈予 Deep Credits。
  • 好友贈送紀錄不用於廣告定向;刪除帳號時,與該帳號相關的 Deep Credit 轉移紀錄會依刪除流程一併清理。

文件、資料與學習分析

  • 週報、月報、科目總結等分析功能只傳送完成該次請求所需的學習摘要或內容。
  • 圖片、PDF 與網址可由 Gemini 處理;對部分 PDF/學習歷程文件,Moku 可先用較低成本的 Gemini 模型客觀抽取內容,再將壓縮後的文字交由 DeepSeek 或 Gemini 進一步分析/撰寫。備審最終評審目前可優先使用 Gemini 3.7,Claude 僅在主要路由失敗或輸出不可用時作備援,以減少長文件重複傳送與不必要成本。
  • 文件功能設有檔案大小、檔案數量、頁數與使用額度等限制,以提升穩定性並避免異常資源消耗。對採用 Deep Credits 的長文件功能,系統可在裝置端或 Moku 後端依 PDF 頁數、檔案數量、檔案大小及可解析文字量等技術資訊自動估算工作量與預計額度。資料解析目前對圖片、網址與 10 頁以內 PDF 使用一般 AI 額度,11–20 頁 PDF 使用 1 個 Deep Credit,21–30 頁 PDF 使用 2 個 Deep Credits;若無法可靠取得 PDF 頁數,可依檔案大小作保守估算。這些指標用於成本控制與服務穩定,不會提供給廣告系統做定向。
⚠ 關於 AI 與您的資料

傳送至各 AI 服務商的內容將依各服務商當時適用的 API 條款與隱私政策處理。建議避免在 AI 功能中輸入真實姓名、身分證號、手機號碼、完整通訊地址等高度敏感的個人識別資訊。

07 資料跨境傳輸

本服務使用的部分服務商伺服器位於台灣境外(主要為美國),因此涉及個人資料跨境傳輸。依《個人資料保護法》第21條,我們採取以下措施保障跨境傳輸的安全性:

傳輸目的地主要服務商安全依據
美國Google Firebase、Cloudinary、Anthropic、Google Gemini、OpenRouter、OpenAI、DeepSeek服務商符合 SOC 2 Type II、ISO 27001 等國際安全標準;採用業界標準合約條款
全球 CDN 節點CloudflareCloudflare 符合 GDPR SCCs,連線日誌匿名化

目前中華民國個人資料保護法主管機關尚未公告限制特定國家之跨境傳輸。若未來法規有所變更,我們將依規定調整,並於本政策更新後通知您。

08 Cookie 與本地儲存

本服務使用瀏覽器的 localStorage 與 sessionStorage(非傳統 Cookie)保存下列裝置端資料;這不代表本服務的所有帳號資料都只儲存在裝置上:

儲存項目具體內容保存期限是否可清除
Firebase 認證 Token維持登入狀態的加密 Token至登出或 Token 過期登出即清除
樹洞對話歷史最近 100 則使用者與默的訊息永久(直到手動清除、清除 App 資料或解除安裝)可在樹洞中清除
語言與外觀偏好介面語言、主題設定永久清除瀏覽器資料
上次所在分頁返回應用程式時的位置記憶永久清除瀏覽器資料
好友 / 個人資料快取好友頭像、顯示名稱(避免重複讀取 Firestore)30 分鐘自動過期自動過期
AI 回應快取週報、學習分析結果6 至 24 小時自動過期自動過期
隨機裝置識別碼moku_device_id,用於 AI 配額與防止濫用,不作廣告追蹤直到清除 App/瀏覽器資料清除 App/瀏覽器資料
待處理邀請碼點擊群組邀請連結後暫存登入後立即清除自動清除
待確認付款發起付款後的訂單暫存(sessionStorage)瀏覽器分頁關閉後清除自動清除

Moku 本身不以廣告追蹤 Cookie 建立自有的跨站行為輪廓;網頁版公開頁面若載入 Google AdSense,可能依 Google 適用政策與同意狀態使用必要的 Cookie/廣告技術資料;公開文章/學習資源等合格內容頁可能載入 Adsterra 橫幅;登入後免費方案的 Web App 另可能載入 Adsterra 橫幅,並在自然完成點確保單一 Social Bar script 已載入。Adsterra 可能依其政策處理 Cookie、IP 位址、瀏覽器/裝置/網路資訊與廣告互動資料。Moku 不會把登入後的學習內容傳給 Adsterra 做定向;Moku 會向訪客提供 Web 廣告 Cookie/隱私選擇提示。於目前未列為需事前取得額外廣告同意訊號的地區,一般 Adsterra 廣告可能在使用者尚未作出選擇前載入;若使用者選擇拒絕,後續 Adsterra 載入會停止。於 EEA/英國/瑞士及 Moku 目前保守列管的美國情境,若沒有適用的使用者選擇與 IAB TCF/GPP 同意訊號,Adsterra 仍會暫停載入。支援廣告的原生版本則可能載入 Google AdMob、Appodeal/其廣告中介合作夥伴或 AppLovin MAX;這些 SDK 可能依適用政策、平台權限與同意狀態處理 IP 位址、廣告識別碼、裝置/網路資訊,以及投放、反詐、頻率控制與成效量測所需的廣告互動資料。Moku 不會把樹洞、日記、作文或學習內容交給廣告系統做定向。所有付費方案不顯示橫幅式/一般插頁式廣告;使用者仍可在功能提供時自願選擇獎勵廣告。免費版也可用獎勵廣告體驗部分付費 AI 功能;支援的付費功能可透過獎勵廣告取得跨功能共用的單次功能使用權;目前一般激勵廣告每 3 次取得 1 次,免費方案每月最多 10 次。Deep Credits 為另一個獨立、可累積的高成本 AI 額度,目前每 5 次一般激勵廣告取得 1 個,不計入該 10 次上限。若適用法規或平台要求同意,Moku 會依目前選用的廣告 provider 使用 Google User Messaging Platform(UMP)及/或 Appodeal 內建、相容 IAB TCF v2 的 Stack Consent Manager 更新廣告隱私狀態;只有在目前 provider 的隱私閘門允許請求廣告後才初始化或載入正式廣告。Moku 將 Google 原生廣告的最高內容分級限制為 Teen(青少年)或更低;未達所在地同意年齡(TFUA)屬於獨立訊號,只有在系統取得可靠的適用訊號時才會提供給 Google,不會僅以「已滿 13 歲」確認推測使用者的所在地同意年齡。若目前使用的同意管理機制判定需要提供隱私選項入口,Moku 會在「設定」中顯示「廣告隱私設定」,供您之後重新查看、重新同意或依適用規則選擇退出。

09 社交功能的資料可見性

使用好友、群組等社交功能時,部分資料對特定對象可見,請在使用前了解:

資料項目可見對象說明
顯示名稱、頭像所有已登入用戶公開個人資料,可在設定中修改
今日學習狀態(是否在讀書、讀什麼科目)您的好友好友才可在學習室看到;可在設定中調整可見性
學習紀錄摘要依您設定的隱私層級預設僅好友可見;可設為公開或私人
群組成員身分同群組成員加入群組即對組內成員可見
群組聊天訊息同群組成員群組聊天室的訊息對所有成員可見

您可以在「設定 → 隱私設定」調整學習紀錄和個人資料的可見範圍,或隨時退出群組。

10 資料保存期限

資料類別保存期限依據
帳號資訊(電子郵件、顯示名稱)帳號存續期間;完成已驗證的刪帳流程後,從主要驗證系統移除履約必要
學習紀錄、筆記、目標帳號存續期間;完成刪帳流程時從主要服務刪除;備份與安全日誌依系統輪替及法律必要期間限制保存履約必要
作文紀錄、考卷歷史與錯題本由使用者主動儲存後保留於帳號存續期間;可刪除個別紀錄;完成刪帳流程時隨帳號資料一併刪除跨裝置查看與延續學習
AI 分析快取6 至 24 小時(自動過期刪除)技術需要(降低成本)
樹洞對話裝置端最多 100 則,直到使用者清除;Moku 不在 Firestore 建立完整歷史副本。送出的訊息與必要近期內容仍依第6節傳輸,基礎設施或 AI 服務商可能依其政策保留短期技術紀錄提供 AI 對話與服務安全
心情、睡眠與支持訊號帳號存續期間;刪除帳號後依刪除流程清除跨裝置同步與選用的個人化支持
上傳圖片(Cloudinary)帳號存續期間;完成刪帳流程時從主要服務刪除;備份與 CDN 快取依服務商輪替及法律必要期間限制保存履約必要
獎勵廣告驗證 Session 與去重紀錄待驗證 Session 約 30 分鐘有效;已驗證的 transaction/impression ID 與必要驗證中繼資料依防止重複發放、客服與反詐所合理需要保存。完成已驗證的刪帳流程時,Moku 會刪除其主要資料庫中仍可由 UID 連結至該帳號的 AdMob/Appodeal 獎勵驗證紀錄;廣告服務商自行保存的資料依其政策處理。獎勵完整性、反重放、客服與防詐
付款與交易紀錄依法、會計、退款或防詐所需的必要期間適用法律與正當業務需要
認證日誌(Firebase)依 Firebase 預設(90 天)安全需要;Firebase 自動管理
匿名化統計資料無限期(已去識別化,不含個人資訊)服務改善

如您申請刪除帳號,Moku 會在驗證身分後立即嘗試從主要資料庫、檔案儲存與驗證系統刪除關聯資料;付款、防詐、安全日誌或備份可能依法律與系統輪替週期保留必要期間,並限制用途。刪除後無法復原。若您在刪除前希望匯出資料,請提前聯絡我們。

11 未成年使用者

本服務主要面向準備大學入學考試的高中生(通常為 15–18 歲)。

  • 最低年齡限制:13 歲。未滿 13 歲者不得使用本服務,我們不會蒐集未滿 13 歲兒童的個人資料。
  • 13 至 18 歲的未成年用戶:依《兒童及少年福利與權益保障法》,建議在父母或法定監護人知情及同意的情況下使用。
  • 父母或監護人:如發現子女未成年即使用本服務,可聯絡我們要求刪除相關資料。
  • 若我們發現未滿 13 歲兒童已建立帳號,將立即停用並刪除所有相關個人資料。

給家長的說明:樹洞的完整歷史主要存於使用者裝置,但每次送出的訊息與必要近期內容會經 Moku 後端傳給 AI 服務商產生回覆;日記會儲存在使用者帳號中,開啟 AI 回覆時也會傳給 AI 服務商。本功能僅提供一般情緒支持,不是醫療、心理治療或緊急服務。

12 您的個資法權利

依《個人資料保護法》第3條,您對於本服務持有的個人資料享有以下權利:

權利說明行使方式回應時限
查閱權(§3.1)查閱本服務持有哪些您的個人資料聯絡 [email protected]15 個工作日
製給複製本(§3.2)取得個人資料的可攜式複本(JSON 格式)聯絡客服並完成身分驗證30 個工作日
更正 / 補充(§3.3)更正不正確或不完整的個人資料設定頁直接修改,或聯絡客服即時(設定頁)/ 15 個工作日(客服)
停止蒐集、處理或利用(§3.4)要求停止特定目的之資料蒐集聯絡客服(部分請求可能影響服務功能)15 個工作日
刪除(§3.5)刪除帳號及所有個人資料App 內「設定頁 → 刪除帳號」,或不打開 App 也可以透過 網頁版刪除帳號頁面;頁面會在各刪除步驟完成後回報結果主要服務在驗證後處理;備份或必要日誌依輪替週期清除
部分刪除只刪除特定類別的資料(例如讀書紀錄、筆記),保留帳號本身網頁版資料管理頁面;頁面會回報實際結果驗證後處理;若任一步驟失敗不會顯示完成

例外情形:以下資料可能不隨一般刪除流程立即移除:(1) 依法、會計、退款、安全或防詐所需而限制用途保存的交易或技術紀錄;(2) 已無法識別個人的彙總統計資料。

身分驗證:為保護您的帳號安全,行使上述權利時我們可能要求驗證您的身分(如從帳號登入 Email 發信)。

申訴管道:若您對本服務的個人資料處理方式有疑慮,除聯絡我們外,您亦可向個人資料保護委員會(ppc.gov.tw)提出申訴。

13 資料安全措施

技術性安全措施

  • 傳輸加密:所有資料傳輸均使用 HTTPS(TLS 1.2 以上)加密,防止中間人攻擊
  • 密碼安全:密碼由 Firebase Authentication 安全雜湊並管理,Moku 無法讀取您的原始密碼
  • 資料庫存取控制:Firestore 安全規則確保每位用戶只能讀寫自己的資料;群組、好友資料有獨立的存取規則
  • 圖片上傳簽名:Cloudinary 採用伺服器端簽名上傳,防止未授權上傳
  • API/S2S 金鑰管理:AI 服務商私密 API 金鑰及 Appodeal S2S encryption key 儲存於受保護的後端環境變數,不放入前端程式碼、APK/IPA 或公開版本庫
  • 廣告獎勵伺服器驗證:正式 AdMob 獎勵使用 Google SSV 並以 transaction ID 去重;正式 Appodeal 獎勵使用加密 S2S callback、完整性雜湊驗證與 impression ID 去重。Moku 只有在伺服器驗證成功後才將正式獎勵寫入帳號額度
  • 付款安全:完整信用卡與付款憑證由 Google Play、Apple App Store,或未來另行揭露的付款平台處理,不經過 Moku 後端伺服器;RevenueCat 僅處理訂閱與權益狀態
  • AI 使用配額:每位用戶設有每日 AI 使用上限,防止帳號被濫用產生異常費用

管理性安全措施

  • 定期檢視 Firestore 安全規則,確保不存在過於寬鬆的存取權限
  • 服務商帳號使用強密碼及二步驟驗證
  • 僅在必要時存取用戶資料(如客服協助)

雖然我們採取合理的安全措施,但沒有任何網際網路傳輸或電子儲存系統能保證 100% 安全。如發現帳號被盜用,請立即聯絡我們。

14 資料外洩通報程序

若發生個人資料外洩(或疑似外洩)事件,我們將依以下程序處理:

  1. 發現後 72 小時內:評估外洩範圍與影響,確認受影響的用戶
  2. 發現後 7 個工作日內:以電子郵件通知受影響用戶,說明外洩的資料類別、可能影響及建議採取的保護措施
  3. 若外洩涉及大量用戶,亦將在應用程式內公告
  4. 依《個人資料保護法》第12條,通知個人資料保護委員會(如適用)

建議您啟用電子郵件的二步驟驗證,以降低帳號被盜用的風險。

15 自動化決策

本服務使用自動化邏輯進行以下決策,但均不產生對您的法律效力或重大影響:

  • AI 使用配額計算:系統自動計算每日 AI 使用次數,超過免費版限制時自動提示升級
  • AI 摘要生成:系統根據您的學習紀錄自動生成摘要(可手動編輯)
  • 方案功能解鎖:付款成功後系統自動解鎖對應功能

上述自動化決策均基於您的帳號資料,不涉及種族、性別、健康狀況等敏感因素。您可隨時聯絡我們對自動化決策結果提出異議。

16 政策變更

本政策可能因服務發展、法規更新而修訂。我們的承諾:

  • 每次更新均在本頁面頂部更新「最後更新日期」及版本號
  • 非重大變更(如文字澄清、新增服務商說明):在應用程式內通知,繼續使用即表示接受
  • 重大變更(如新增蒐集目的、擴大資料分享範圍):提前 30 天以電子郵件通知,並重新取得您的同意
  • 本政策的歷史版本將在此處存檔,可透過客服索取

17 申訴與聯絡

資料控管者:知識宇宙 Moku

個資申請 Email[email protected](主旨請標注「個資申請」)

一般客服 Email[email protected]

個資申請:15 個工作日內回覆
一般客服:7 個工作日內回覆

如對本服務的個人資料處理方式有疑慮,您亦可向個人資料保護委員會申訴:ppc.gov.tw

Privacy Policy

Last updated: August 22, 2026  ·  Effective: August 22, 2026  ·  Version 3.8
Prepared in compliance with Taiwan's Personal Data Protection Act (PDPA)

The service "知識宇宙 Moku" (hereinafter referred to as "Moku") refers to the application and related web services provided at moku-ahvpc2nsb3n0-pano.xyz, including the web PWA, Android, and iOS versions.

Summary: Moku is a study tool. We collect account information and learning records to provide the service. We do not sell your data and never use accessibility events or the installed-app list for advertising or analytics. Releases that support advertising may show ads through Google AdMob, Appodeal and its mediated demand partners, AppLovin MAX, or Google AdSense / Adsterra on the web. All paid plans have no forced banner or ordinary interstitial ads. This includes the No Ads plan, whose users may still voluntarily choose rewarded ads where an extra-quota option is offered. Free users may also unlock selected paid AI features through optional rewarded ads. Supported paid AI features may use a universal single-use feature pass earned voluntarily from rewarded ads. Currently 3 Rewarded ads grant 1 pass, and Free accounts may earn up to 10 such passes per month. Separately accumulated Deep Credits are used for higher-cost AI workloads; currently 5 Rewarded ads grant 1 Deep Credit, and those credits do not count toward the 10-pass cap. Tree Hole history is primarily stored on your device; when you request an AI reply, the message and necessary recent context are sent through Moku’s backend to the selected AI provider. Diary entries are stored in your account. You may start the verified account-deletion flow at any time to remove identifiable data linked to your account, subject to the limited legal, refund, security, anti-fraud, backup, and system-rotation exceptions described in the retention section.

This page is provided in Traditional Chinese and English. The Traditional Chinese version controls in case of a conflict; the English version is provided for review and convenience.

01 Data Controller

ServiceMoku — Knowledge Universe
Contact[email protected]
Websitehttps://moku-ahvpc2nsb3n0-pano.xyz/
Privacy requests[email protected] (subject: "Privacy Request")

02 Data We Collect

Data you provide

CategoryDetailsRequired
AccountEmail, display name, password (encrypted by Firebase; Moku cannot read it)Required
Profile (optional)Avatar, school, target department, exam yearOptional
Learning recordsSubject, date, hours, depth score, notes, AI-generated summariesCore feature
Essays, quizzes & practice recordsEssay text submitted for grading (max 2,000 characters), original and edited essays you choose to save, grading results and scores, quiz-generation settings, generated quiz history, answers, and wrong-book entriesFeature use
Emotional, sleep, and well-being data*Information you voluntarily provide through mood check-ins, sleep records, Tree Hole, or Diary, plus limited support signals used for personalization, such as study-session length, use of notes or exam-writing features, and a flag inferred when your own text contains negative self-evaluation language. Tree Hole history is primarily on-device; Diary, sleep records, and these signals are stored in Firestore; content needed for an AI reply is sent through Moku’s backend to an AI provider.Optional feature use
Payment dataOrder number, plan, payment time, payment status, and subscription entitlement status. Full card details or payment credentials are handled by Google Play, Apple App Store, or a future web payment provider disclosed at checkout; Moku and RevenueCat do not receive or store full card numbers.Payment

* Emotional, sleep, and psychological information may be sensitive or health-related data. These features are optional and are processed only when you actively enter, save, or use the related feature, for the purposes described here.

Automatically collected

  • Authentication and security metadata. Firebase/Google may process login time, sign-in method, and IP address under its service terms; Moku uses available records only when needed for security, debugging, or support
  • Session state: timer status, current subject (shared with friends in Study Room)
  • Device info: OS type, browser User-Agent, and an app-generated random moku_device_id. The random ID is sent with AI requests for quota enforcement and abuse prevention, not advertising tracking.
  • Feature activity: daily AI usage count and limited signals created when you use optional features, such as mood check-ins, sleep records, study-session length, notes, or exam-writing status
  • Advertising and reward-verification technical data: ad-supported releases may allow advertising SDKs/partners to process IP address, advertising identifiers (such as AAID/IDFA depending on platform permission and consent), device/network information, and ad-request, impression, click, or similar interaction data. When you voluntarily use rewarded ads, Moku also provides Appodeal with your Firebase UID as an opaque user ID that does not contain your name or email, and Moku’s backend processes provider transaction/impression IDs, timestamps, reward amount/currency, and verification status to validate and deduplicate rewards.

From Google or Apple Sign-In

Google Sign-In requests only email and profile; Moku does not access Gmail, Contacts, Calendar, Drive, or other Google-service content. Sign in with Apple provides Firebase Authentication with a stable account identifier and the email/name you choose to share. If you use Hide My Email, Moku receives only Apple's private relay address.

Android on-device permissions and sensitive APIs

The following access occurs only after you intentionally use the related feature and complete the in-app prominent disclosure and consent flow. Unless stated otherwise, the information is processed in real time on your device and is not sent to Moku servers, shared with third parties, or used for advertising or analytics.

Feature / APIAccess and purposeStorage, upload, and sharing
AccessibilityServiceOnly while App Focus Lock is enabled, Moku identifies the package name of the currently opened app from window-change events. If it matches your own block list, Moku performs Android's “Go to Home screen” action. This service is not a disability accessibility tool.Moku does not read on-screen text, notifications, messages, passwords, keystrokes, or accessibility nodes; it does not auto-click; accessibility event data is not stored, uploaded, or shared.
Launchable-app list / package visibilityAfter you tap “Agree and show apps,” Moku reads the names and package names of apps launchable from the Home screen so you can select apps for your block list. Moku uses a scoped launcher-intent query and does not request broad package visibility.The list is displayed and selected only on your device. It is not uploaded, profiled, or used for advertising or analytics.
Foreground service (specialUse)Only after you enable flip-to-time, it continuously reads accelerometer data to detect whether the device is face up or face down and displays an ongoing notification. It stops when flip-to-time is turned off. Regular study timers do not use this foreground service.The foreground service itself does not collect or transmit personal data and does not detect or block other apps.
Notifications and Do Not Disturb accessShows timer/flip status, or changes Android's Do Not Disturb state only when you enable automatic DND for timers.Moku does not read notification content; DND access is used only to change the state.
Display over other apps (SYSTEM_ALERT_WINDOW)Only when you enable the external floating-character feature, Moku displays your selected character and its speech bubble above other apps so it can be dragged, docked to a screen edge, and tapped.This permission does not let Moku read another app's screen, text, notifications, input, or touch data. Transparent space outside the visible character and speech bubble should not intercept touches intended for other apps. You can disable the feature or revoke the permission in Android settings at any time.

iOS on-device permissions and Screen Time APIs

The iOS app does not use AccessibilityService or inspect foreground-app events. Focus Lock uses Apple's public FamilyControls, ManagedSettings, and DeviceActivity frameworks. You must approve the system authorization sheet and select apps or categories in Apple's system picker.

Feature / APIAccess and purposeStorage, upload, and sharing
FamilyControls / ManagedSettingsReceives opaque tokens for apps, websites, or categories you select, then asks iOS to show a system shield during focus sessions.Selections remain in on-device App Group storage. Moku cannot reverse the tokens into a complete installed-app list and does not upload or use them for advertising or analytics.
DeviceActivityStarts or stops system shielding during a user-selected focus period, subject to Apple's entitlement and system restrictions.No screen text, notifications, messages, passwords, or keystrokes are read or uploaded.
Core MotionWhen you enable flip-to-time, motion/orientation data may be read to detect face-up or face-down state. iOS may suspend this work in the background.Raw sensor samples are not stored, uploaded, or shared.
NotificationsShows timer and reminder status. The iOS app does not use private APIs to toggle system Focus or Do Not Disturb.Moku does not read notification content from other apps.
AppTrackingTransparency / advertising identifier (IDFA)If an ad-supported iOS build needs access to the device advertising identifier or performs tracking as defined by Apple, Moku first presents Apple's system permission prompt. Only after permission may the ad SDK use that identifier under platform rules for more relevant ads or ad-performance measurement.Declining does not limit Moku learning features. Without permission, Moku does not use IDFA for tracking. Tree Hole, Diary, essays, quizzes, notes, and learning content are not supplied to the ad system for targeting.

03 Why We Collect It

PurposeLegal Basis (Taiwan PDPA Art. 19)
Account creation and authenticationArt. 19(1)(ii) — necessary for contract performance
Core learning tracking serviceArt. 19(1)(ii) — necessary for contract performance
AI personalization featuresArt. 19(1)(v); explicit consent is requested before content is first shared with a third-party AI provider and may be withdrawn in Settings
Payment processingArt. 19(1)(ii) — contract; legal obligation (accounting)
Social & group featuresArt. 19(1)(v) — user consent
Optional emotional, sleep, and well-being featuresYou intentionally use the optional feature after the related in-app disclosure
Advertising delivery, consent management, and reward verificationAs required by applicable regional rules, platform consent choices, and delivery of user-initiated ad/reward features
Security & fraud preventionArt. 19(1)(vi) — legitimate interest
Anonymized analyticsArt. 19(1)(vi); fully de-identified, no personal data
Legal complianceApplicable legal, accounting, refund, and fraud-prevention obligations
⚠ We do NOT
  • Sell or rent your personal data to any third party
  • Provide Tree Hole, Diary, essay, quiz, note, or other learning content to the ad system for targeted advertising or behavioral profiling. Ad-supported releases may still let the advertising SDK process advertising/device technical data under your platform-consent choices and the provider's policies for ad delivery, frequency control, fraud prevention, and measurement.
  • Use your data for purposes beyond those listed above

04 Third-Party Service Providers

ProviderPurposeDataLocation
Google Firebase (Auth + Firestore + RTDB)Authentication, database, session syncAccount and service data used by the enabled Firebase featuresInfrastructure configured by Google/Firebase under the applicable terms
CloudinaryImage storage & CDNProfile photos, problem imagesUSA / Global CDN
Cloudflare PagesApp hosting & CDNConnection and security logs that may include network metadataCloudflare global edge infrastructure
Capgo UpdaterOptional version checks for Android testing or non-App-Store releases, when separately enabledCurrent bundle version and basic device/network information needed to check for updatesAutomatic web-bundle updating is disabled in the iOS App Store build; iOS code and feature changes are released through App Store updates
Google Gemini APIImage OCR, image/PDF/URL understanding, search-grounded retrieval, and selected learning features depending on backend routingYour prompt, necessary context, images, documents, URLs, and feature-required dataProvider infrastructure
OpenRouterCurrent API routing/gateway for some Claude, DeepSeek, and OpenAI GPT requests, forwarding the request to the selected model servicePrompt, text, context, and technical routing metadata necessary for that AI request; using OpenRouter does not cause Moku learning content to be supplied to the advertising systemOpenRouter and the selected downstream provider process data under their applicable terms and privacy policies
Anthropic Claude APIHigher-value language judgment such as optional full essay sample rewriting, selected humanities/legal tasks, and fallback portfolio/document workEssay text, compressed document evidence, prompts, and feature-required contentProvider infrastructure
DeepSeek APIMath/quantitative STEM quiz generation, selected essay scoring, document-extraction follow-up analysis, and high-volume text reasoning; it is not the primary route for politically sensitive humanities or Taiwan-law reviewYour prompt and feature-required textProvider infrastructure
OpenAI GPT (currently may be routed through OpenRouter)Selected cost-sensitive, higher-volume standard text quiz generation and necessary fallback; not the primary route for Taiwan-law quiz generationQuiz prompt, selected scope, necessary context, and formatting instructionsOpenRouter/OpenAI infrastructure under the applicable API terms and privacy policies
Google AdMob (ad-supported native releases)Banner, interstitial, rewarded, or rewarded-interstitial advertising depending on plan and user choiceDevice and advertising technical data needed by the SDK for delivery, frequency control, fraud prevention, and measurement under Google policies. On iOS, if access to IDFA or Apple-defined tracking is involved, Moku first uses the AppTrackingTransparency permission flow.All paid plans have no forced ads; rewarded formats run only when voluntarily selected where offered, including on the No Ads plan. Moku does not provide Tree Hole, Diary, essay, quiz, note, or learning content to AdMob for targeting.
Appodeal and its mediated demand partners (ad-supported native releases)Banner, interstitial, or rewarded advertising according to the selected native provider and current Appodeal mediation configurationDepending on consent and platform permission, Appodeal/its demand partners may process IP address, advertising identifiers, device/network information, and ad-interaction data. For rewarded ads, Moku also uses the Firebase UID as an opaque Appodeal User ID that contains neither the user’s name nor email, so the server can match and verify the reward.Processing is subject to the Appodeal Privacy Policy and its ad demand-source list. Moku does not provide learning content to the advertising system for targeting.
AppLovin MAX (native releases when selected as the provider)An optional native ad provider selected by remote configuration for supported ad formatsAdvertising/device technical data needed for delivery, frequency control, fraud prevention, and measurement under AppLovin and platform policiesEnabled only when the release actually selects MAX as its native provider; see the AppLovin Privacy Policy.
Google AdSense / Adsterra (public web content)Advertising on eligible public articles/resource pages; Adsterra banners load only after the applicable consent/privacy gate allows themCookies and device/network advertising data needed for delivery, fraud prevention, and measurement under Google policies and the user’s applicable consent choicesMoku does not provide signed-in learning content, Tree Hole, Diary, essays, or quizzes to AdSense for targeting.
Adsterra (signed-in Free-plan Web App)Responsive 320×50 / 728×90 banners; at natural completion points Moku may ensure one Social Bar script is loaded, after which Adsterra controls its rotating in-page/overlay formats and frequency. Paid plans do not load these forced formatsAdsterra and its advertising technology partners may process IP address, cookies, browser/device/network information, ad requests, impressions, clicks, frequency-control, and anti-fraud technical data under their policies. Moku does not send Tree Hole, Diary, essay, quiz, note, or other learning content to Adsterra for targeting.See the Adsterra Privacy Policy. Moku provides visitors with a Web advertising cookie/privacy choice notice. In regions that Moku does not currently classify as requiring an additional prior advertising-consent signal, ordinary Adsterra ads may load before the visitor makes a choice; choosing decline stops future Adsterra loading. In the EEA, UK, Switzerland, and Moku’s currently conservative US gate, Adsterra remains blocked until the applicable user choice and IAB TCF/GPP signal are available. This region gate is a conservative technical control and does not replace applicable law or Adsterra’s own obligations.
Web payment provider (if enabled later)Web paymentsOrder amount and payment data required by the provider disclosed at checkout; Moku does not store full card numbersProvider infrastructure
Google Play BillingAndroid subscriptions and in-app purchasesProduct and transaction status, Google-issued purchase tokenGoogle infrastructure
RevenueCatSubscription validation and entitlement synchronization, when enabledFirebase UID as the App User ID, product ID, subscription status, and platform transaction identifiers; no full card detailsProvider infrastructure
Apple App StoreiOS subscriptions and in-app purchases, when enabledProduct and transaction status; no full card detailsApple infrastructure

We do not sell data to these providers. Their legal role depends on the service and applicable terms. Where a provider processes personal data on Moku's behalf, we limit the transmitted scope and require appropriate safeguards; advertising, payment, and platform providers may also process necessary technical data under their own applicable policies and legal roles.

05 AI Features & Conversation Data

Explicit consent: Before Moku first sends content to a third-party AI provider, it shows a separate disclosure naming Google Gemini, Anthropic Claude, DeepSeek, and OpenAI GPT; some Claude/DeepSeek/OpenAI GPT requests are currently routed through OpenRouter. The disclosure also describes the text, images, essays, learning summaries, or necessary recent context that may be shared. Nothing is sent unless you accept. Declining does not disable non-AI features. You may withdraw consent in Settings → Privacy → Policies & Safety; Moku will ask again before the next AI request.

Tree Hole data flow: Conversation history is primarily stored on your device (localStorage, up to the most recent 100 messages). When you send a message, that message and the recent context needed for continuity are sent over HTTPS to Moku’s backend and then to the selected AI provider, which may be Google Gemini, Anthropic Claude, or DeepSeek. Moku does not separately write the full Tree Hole history to Firestore. Short-lived technical logs may still be created by infrastructure for security and reliability, but conversation content is not sold or used for advertising.

  • Deleting Tree Hole history, clearing app data, or uninstalling removes the on-device history
  • Unsent drafts are not transmitted
  • Diary entries you save are stored in your account’s Firebase Firestore for synchronization
  • A Diary entry is sent through Moku’s backend to an AI provider only when you request an AI reply
  • Tree Hole and Diary provide general emotional support, not medical care, psychotherapy, or emergency services

Essays, quiz prompts, images, documents, URLs, and learning summaries submitted to AI features are routed only as needed for the requested feature. Gemini may perform OCR, document/image extraction, selected standard work, and higher-reasoning Deep humanities generation; OpenAI GPT may be used for selected cost-sensitive standard humanities quiz generation; DeepSeek may be used for selected scoring and quantitative/STEM generation; Claude may be used for higher-value language judgment, Taiwan-law tasks, essay sample rewriting, portfolio review, and fallbacks. Moku may route only a failed or low-quality quiz section to another provider instead of rerunning the entire paper. Some Claude, DeepSeek, and OpenAI GPT requests currently pass through OpenRouter as the API routing layer before reaching the selected model service. For quiz generation, 10- and 20-question Standard Practice use no Deep Credit; supported 10- or 20-question Deep Practice uses 1. For Full Mock Exams with a formal blueprint, Standard full papers in Chinese/Chinese-comprehensive use 1 Deep Credit and Deep full papers use 2; Standard full papers in social studies, history, geography, and civics use 1 Deep Credit and Deep full papers use 3; hard/hell mathematics Deep full papers currently use 2. A full sample essay rewrite is generated only when you request it and uses 1 Deep Credit without an additional single-use feature pass. For portfolio/document PDFs, Moku may first extract objective evidence with a lower-cost Gemini route and then send compressed text to DeepSeek or Gemini for analysis/writing. Portfolio final review may use Gemini 3.7 first, with Claude used as a fallback when the primary route fails or produces unusable output. Other long-document Deep Credit requirements may be estimated from PDF pages, file count, file size, and extractable text volume. These signals are used for quota/cost control and service reliability, not ad targeting. Some generated results may be cached in your private Firestore area for a limited period to reduce repeated requests. If you separately tap “Save to Essay History,” the original essay, your edited/revised version, score, and grading result are stored in your private Firestore essay history until you delete that record or delete your account. Provider processing is governed by each provider's applicable API terms and privacy policy. Avoid entering unnecessary highly sensitive identifiers.

Deep Credit friend gifts: When you voluntarily gift Deep Credits to a friend, Moku’s backend processes the sender UID, recipient UID, amount, transfer identifier, and timestamp to debit and credit the balances atomically, prevent duplicate transfers, and enforce the rolling 24-hour receipt limit. Gifted Deep Credits are stored in the recipient’s private Deep Credit ledger, may be used for Deep features, and cannot be gifted again. An account may receive at most 10 gifted Deep Credits in any rolling 24-hour window. These transfer records are not used for ad targeting and are cleaned up through the account-deletion flow.

06 Cross-Border Data Transfers

Moku uses providers that may process data outside Taiwan through global infrastructure. The destination and safeguards depend on each provider’s current configuration, contractual terms, and applicable law. Moku limits transfers to data needed for the requested feature and links to provider policies above.

07 Cookies & Local Storage

We use localStorage and sessionStorage for certain on-device items, including up to 100 Tree Hole messages, preferences, caches, and the random moku_device_id. This does not mean all account data stays on-device. Moku itself does not create its own cross-site advertising profile. Eligible public web pages may load Google AdSense, which can use cookies or advertising technical data under Google policies and applicable consent choices. Eligible public articles/resource pages and the signed-in Free-plan Web App may also load Adsterra banners; at natural completion points the signed-in Free Web App may ensure one Social Bar script is loaded, after which Adsterra controls its rotating in-page/overlay formats and frequency; Adsterra may process cookies, IP address, browser/device/network information, and ad-interaction technical data under its policies. Moku does not send signed-in learning content to Adsterra for targeting. Moku shows visitors a Web advertising cookie/privacy choice notice. In regions not currently classified by Moku as requiring an additional prior advertising-consent signal, ordinary Adsterra ads may load before the visitor makes a choice; declining stops future Adsterra loading. In the EEA, UK, Switzerland, and Moku’s currently conservative US gate, Adsterra remains blocked until the applicable user choice and IAB TCF/GPP signal are available. Ad-supported native releases may load Google AdMob, Appodeal and mediated demand partners, or AppLovin MAX; depending on consent and platform permission, those SDKs may process IP address, advertising identifiers, device/network information, and ad-interaction data for delivery, fraud prevention, frequency control, and measurement. Moku does not provide Tree Hole, Diary, essay, or learning content to the ad system for targeting. All paid plans have no forced ads, while optional rewarded ads may be chosen where offered, including on the No Ads plan. Free users may use optional rewarded ads to unlock selected paid AI features. Supported paid features may use a universal single-use feature pass earned from optional rewarded ads; currently 3 Rewarded ads grant 1 pass, with a 10-pass monthly ad-earned cap on Free accounts. Deep Credits are a separate, accumulable higher-cost AI allowance; currently 5 Rewarded ads grant 1 Deep Credit and do not count toward that cap. Where consent or a privacy choice is required by law or platform policy, Moku uses Google User Messaging Platform (UMP) and/or Appodeal’s built-in Stack Consent Manager, which is compatible with IAB TCF v2, according to the native provider currently selected. Live ads are initialized or loaded only after the applicable provider privacy gate allows ad requests. Google-served native ads are capped at the Teen content rating or lower. The under-age-of-consent (TFUA) signal is separate and is sent only when Moku has a reliable applicable signal; Moku does not infer local age-of-consent status solely from the account's 13+ confirmation. If the active consent-management flow requires a privacy-options entry point, Moku shows an Ad Privacy Settings control in Settings so you can revisit, re-consent, or opt out where applicable. See the Chinese version for the full itemized table.

08 Data Retention

DataRetention
Account info & learning recordsWhile the account is active; removed from primary systems during the verified deletion flow. Backups and security logs follow restricted-use rotation or legally required retention periods
Essay history, quiz history & wrong-book entriesStored in your private account area until you delete the individual record or delete your account, subject to the backup/security-log limitations described above
AI analysis cache6–24 hours (auto-expires)
Tree Hole conversationsUp to 100 messages on-device until cleared. Moku does not create a full Firestore history copy; submitted messages and necessary recent context are still transmitted as described above, and infrastructure or AI providers may retain short-lived technical records under their policies.
Diary entries, sleep records, mood and support signalsWhile the account is active; removed through the account-deletion process
Rewarded-ad verification sessions and deduplication recordsPending sessions are valid for about 30 minutes. Verified transaction/impression IDs and the minimum verification metadata are retained as reasonably needed to prevent duplicate rewards, support users, and detect fraud. During verified account deletion, Moku removes AdMob/Appodeal reward-verification records in its primary database that remain linked to the deleted Firebase UID; ad providers retain their own records under their policies.
Payment and transaction recordsOnly for the period required by applicable law or reasonably needed for accounting, refunds, security, and fraud prevention
Authentication and security logsAccording to Firebase/Google retention settings and the period reasonably needed for security and support

09 Minors

Minimum age: 13. Users aged 13–17 should use this service with parental knowledge and consent, in accordance with Taiwan's Protection of Children and Youths Welfare and Rights Act. If we discover an account belonging to a child under 13, we will immediately delete it. Parents may contact us to request deletion of a minor's data.

10 Your Rights (Taiwan PDPA Art. 3)

RightHow to ExerciseResponse Time
Access your dataEmail [email protected]15 business days
Receive a portable copy (JSON)Email with identity verification30 business days
Correct inaccurate dataSettings page or emailImmediate (settings) / 15 days (email)
Stop collection / processingEmail (may affect service features)15 business days
Delete account & all dataSettings → Delete Account, or emailDeletion starts after identity verification. Primary systems report success only after required steps complete; backups and required logs follow restricted-use rotation or legal retention periods

You may also lodge a complaint with Taiwan's Personal Data Protection Commission: ppc.gov.tw

11 Security

  • HTTPS / TLS 1.2+ for all data transmission
  • Passwords are securely hashed and managed by Firebase Authentication; Moku cannot read the original password
  • Firestore security rules enforce per-user data isolation
  • Cloudinary signed uploads prevent unauthorized image uploads
  • Private AI service credentials and the Appodeal S2S encryption key are handled through protected server-side configuration and are not intentionally embedded in frontend code or mobile packages
  • Live AdMob rewards use Google server-side verification (SSV) with transaction-ID deduplication; live Appodeal rewards use encrypted S2S callbacks, integrity-hash validation, and impression-ID deduplication. Moku credits live rewards only after server verification succeeds.
  • Full card details and payment credentials are handled by Google Play, Apple App Store, or a future web payment provider disclosed at checkout; RevenueCat processes subscription and entitlement status only

12 Data Breach Notification

In the event of a personal data breach: within 72 hours we assess scope and affected users; within 7 business days we notify affected users by email with the data categories involved, potential impact, and recommended protective steps. We will notify Taiwan's Personal Data Protection Commission as required by PDPA Art. 12.

13 Policy Updates

Non-material changes: in-app notification; continued use constitutes acceptance. Material changes (new collection purposes, expanded sharing): 30 days' advance email notice and re-consent required. Historical versions available on request.

14 Contact

Data Controller: Moku — Knowledge Universe

Email: [email protected] (subject: "Privacy Request")

LINE: @132nuzti

Privacy requests: 15 business days  ·  General enquiries: 7 business days
Regulatory complaints: ppc.gov.tw