Penjelasan privasi dengan bahasa sederhana

Privasi di RingMatcher

Pelajari apa yang dikirim RingMatcher untuk analisis, apa yang sengaja disimpan, dan apa yang tercakup saat Anda membagikan Ringprint.

Jawaban yang Anda kirim

Alur gratis memproses jawaban gaya dan belanja yang Anda pilih, serta catatan opsional. Data tersebut dikirim ke server RingMatcher hanya ketika Anda meminta hasil dan digunakan untuk membuat serta memvalidasi hasil itu.

Gambar opsional dan pemrosesan AI

Foto bersifat opsional dan foto wajah tidak pernah diwajibkan. Maksimal tiga gambar diperkecil di browser dan dapat melewati server RingMatcher ke penyedia AI yang dikonfigurasi untuk permintaan itu. RingMatcher tidak sengaja menyimpan berkas gambar unggahan. Pengaturan tanpa retensi dan penolakan pengumpulan diminta, tetapi infrastruktur, ketentuan, dan kewajiban hukum penyedia tetap berlaku.

Instruksi gambar hanya mengizinkan petunjuk desain visual serta melarang identifikasi atau inferensi sifat sensitif. Teks atau instruksi di dalam gambar diabaikan.

Tautan yang dibagikan

Tautan berbagi memuat hasil yang terlihat, rute berlian, kelompok anggaran, dan bahasa konten di fragmen URL. Tautan tidak pernah memuat berkas gambar unggahan. Siapa pun yang memiliki tautan dapat membaca informasi terenkode, jadi tinjau sebelum membagikan.

Fragmen terbatas dapat memindahkan bidang panduan yang terlihat ke pencari peritel. Fragmen tidak dikirim bersama permintaan HTTP halaman dan dihapus dari bilah alamat setelah diimpor, tetapi pemegang tautan yang belum diimpor masih dapat membacanya.

Native app data, purchases, and recovery (authoritative English disclosure)

This native-app section is the authoritative English disclosure. The surrounding translated text may not yet describe every native-app behavior.

A questions-only Ringprint in the native app is created on the device, so those answers do not leave the device for matching. If you add up to three photos, the app re-encodes them and sends the device-resized images, their context labels, the questionnaire answers, the content locale, and a random installation identifier through RingMatcher for that request. Cookies are omitted. RingMatcher then sends the answers and images to OpenRouter, the configured AI gateway, with zero-data-retention and data-collection-denial settings requested. RingMatcher does not intentionally persist the match request body or uploaded image files, and saved Ringprints never contain a photo file or image payload. OpenRouter, any routed model provider, and their infrastructure, terms, and legal obligations still apply.

The app stores saved Ringprints in AsyncStorage, including the questionnaire answers, optional note, generated result, locale, source, timestamps, and image-analysis counts. Paid-plan snapshots, generated guidance, setup inputs, and tool activity are also stored in AsyncStorage; source snapshots omit the free-form Ringprint note. These records are app-local but are not encrypted by AsyncStorage. Photo files are excluded. A random installation UUID and purchase capabilities—including draft and access tokens, obfuscated purchase-binding identifiers, and a Google Play purchase token after billing—are stored separately with device-only SecureStore settings.

On Android, RingMatcher disables app backup and excludes its app files, databases, preferences, and device-to-device transfer domains from backup rules. This is intended to keep local Ringprints, plans, and purchase capabilities off Android backup and migration services. Other operating-system, device-administration, forensic, or user-initiated copying behavior is outside RingMatcher's control.

If you choose Report this result, the app sends RingMatcher the result identifier, visible result title, summary and rationale, the selected report reason, an optional note, the content locale, and the random installation identifier in a request header. The service uses the installation identifier and network address to enforce an hourly report limit. It writes the report content, reason, optional note, locale, a generated report identifier, and the receipt time to structured deployment logs so the report can be reviewed. Those report logs do not intentionally include the raw installation identifier or network address; their retention follows the deployment logging configuration. Reporting is optional and does not affect saved Ringprints or paid access.

Starting a Google Play checkout sends RingMatcher the selected pack, random installation UUID, local Ringprint identifier, and a SHA-256 digest of the Ringprint—not the questionnaire answers, uploaded photos, or generated plan. The server persists a digest of the installation identifier, the Ringprint identifier and digest, generated draft/access identifiers, product and pack identifiers, obfuscated Google Play binding identifiers, capability hashes, and timestamps. Claiming a purchase sends the raw Google Play purchase token to RingMatcher so it can be verified with Google Play. The server persists a digest of that token, and may persist an order-ID digest and purchase-completion timestamp; it does not write the raw purchase or order token to its purchase-state file.

The protected Google Play app-review path sends the reviewer access code and random installation UUID to RingMatcher. The server compares a one-way code digest, enforces network and installation limits, and persists only the code digest, installation digest, synthetic draft/claim/access identifiers, pack and product identifiers, and timestamps—not the plaintext review code. It returns signed, expiring plan capabilities to device-only SecureStore. This review path does not open billing or create a charge.

An unclaimed purchase draft expires after 7 days. After a successful claim, its draft and replay-claim record become eligible for pruning when that same 7-day draft capability expires. Paid access expires after 30 days for Shortlist or Complete Plan and after 90 days for Together Plan. Expired eligible rows are pruned atomically during later purchase-state maintenance, such as a subsequent draft creation or purchase grant; there is no background deletion timer. Unexpired drafts and access records are not evicted to make room for newer records.

Saved Ringprints and completed paid plans remain on the device until you remove them, the bounded local history replaces older Ringprints, app storage is cleared, or the operating system removes the app data. Removing a completed paid plan also asks SecureStore to delete its associated capability. A plan with an unfinished purchase is protected from ordinary removal because the local draft may still be needed for Google Play recovery. RingMatcher has no user account or cross-device plan library: clearing local app data, removing protected credentials, changing devices, or uninstalling can make a consumed one-time purchase or its generated plan impossible to recover. Contact contact@ringmatcher.com for privacy or server-record deletion questions.

Batas permintaan, pengukuran pihak pertama, dan log teknis

Server dapat membuat kunci pembatasan permintaan sementara yang hanya disimpan di memori dari alamat jaringan. RingMatcher mencatat tahapan corong pihak pertama pada halaman awal, pembuatan Ringprint, berbagi dan unduhan, checkout opsional dan alur paket berbayar, serta pencari peritel. Kontrak peristiwa hanya mengizinkan nama peristiwa, nilai sumber, kanal, paket, status, tujuan CTA, posisi CTA atau locale yang tetap, boolean, serta jumlah atau skor yang dibatasi. Jawaban kuesioner, anggaran, catatan, teks arah yang dihasilkan, URL atau jalur halaman arbitrer, tujuan berupa teks bebas, pengenal pembayaran, pesan atau jejak kesalahan, data pribadi, dan teks bebas tidak disertakan.

Peristiwa pencari peritel juga dapat memuat jenis pembelian tetap dan ID peritel dari katalog yang telah ditinjau RingMatcher.

Setelah klik dari panduan ke kuis, penyimpanan sesi browser dapat menyimpan hanya nilai atribusi berikut: slug panduan yang masuk daftar izin, locale, dan posisi CTA, beserta metadata teknis versi dan kedaluwarsa. Atribusi diterima paling lama 30 menit dan dipakai satu kali untuk permintaan Ringprint beratribusi. Catatan kedaluwarsa diabaikan dan dihapus saat akses berikutnya; penyimpanan sesi juga berakhir bersama tab atau sesi browser. Data itu tidak memuat jawaban kuesioner, anggaran, foto, detail kontak, maupun pengenal akun atau pengguna.

Peristiwa yang diterima hanya ditulis ke log penerapan server yang terstruktur. RingMatcher tidak mengirimkannya ke layanan analitik pihak ketiga atau menyimpannya di basis data analitik khusus; retensi bergantung pada konfigurasi log penerapan. Peristiwa tidak memuat pengenal akun atau pengguna. Penggunaan teknis AI juga dapat dicatat tanpa jawaban kuesioner atau foto yang diunggah.

Paket berbayar dan Stripe

Paket berbayar opsional memakai Stripe untuk memproses pembayaran satu kali. RingMatcher mengirimkan email tanda terima, paket yang dipilih, jumlah dan mata uang yang ditetapkan server, serta pengenal permintaan dan PaymentIntent yang dibuat. Payment Element milik Stripe mengumpulkan rincian pembayaran; RingMatcher tidak menerima atau menyimpan nomor kartu lengkap maupun kode keamanan.

Metadata Stripe hanya memuat pengenal yang dibuat, status pembayaran dan pemenuhan, serta hash satu arah yang terkait dengan akses browser—bukan jawaban kuesioner, foto, catatan pribadi, atau isi laporan. Cookie HttpOnly dan SameSite per paket dapat bertahan hingga 100 hari, sedangkan catatan pembayaran tertunda dapat tersimpan hingga 30 hari di penyimpanan lokal browser tersebut. Ketentuan dan kebijakan privasi Stripe berlaku.

Di situs produksi, sesi laporan berbayar disimpan pada volume server yang terlindungi dan dipulihkan setelah mulai ulang serta deployment rutin. Sesi Shortlist dan Complete Plan berakhir setelah 30 hari; sesi Couple’s Edition setelah 90 hari. RingMatcher dapat menghapus sesi lebih awal saat menyelesaikan permintaan penghapusan.

Hal yang tidak dijual RingMatcher

RingMatcher tidak menjual cincin atau data pribadi. Jika akun, pembayaran, analitik, penyimpanan, atau penyedia model berubah, halaman ini harus ditinjau sebelum layanan yang berubah ditawarkan. Pertanyaan privasi dapat dikirim ke contact@ringmatcher.com.