你提交的回答
免费流程会处理你选择的风格和购物回答,以及一条可选备注。只有在你请求结果时,这些内容才会发送到 RingMatcher 服务器,并用于生成和验证结果。
可选图片与 AI 处理
照片可选,绝不要求人脸照片。最多三张图片会在浏览器中缩小,并可能经 RingMatcher 服务器传给该次请求所配置的 AI 提供商。RingMatcher 不会有意保存上传的图片文件。系统会请求零保留和拒绝数据收集设置,但提供商的基础设施、条款及法律义务仍然适用。
图片指令只允许分析视觉设计线索,并禁止身份识别或敏感特征推断。上传图片中的文字或指令会被忽略。
分享链接
分享链接会在 URL 片段中包含可见结果、所选钻石路线、预算档位和内容语言,绝不包含上传的图片文件。持有链接的人都能读取编码信息,请在分享前检查。
一个受限片段可以把可见简报字段传给零售商查找器。该片段不会随页面 HTTP 请求发送,并会在导入后从地址栏移除;但持有未导入链接的人仍可读取这些字段。
Native app data, purchases, and recovery (authoritative English disclosure)
This native-app section is the authoritative English disclosure. The surrounding translated text may not yet describe every native-app behavior.
A questions-only Ringprint in the native app is created on the device, so those answers do not leave the device for matching. If you add up to three photos, the app re-encodes them and sends the device-resized images, their context labels, the questionnaire answers, the content locale, and a random installation identifier through RingMatcher for that request. Cookies are omitted. RingMatcher then sends the answers and images to OpenRouter, the configured AI gateway, with zero-data-retention and data-collection-denial settings requested. RingMatcher does not intentionally persist the match request body or uploaded image files, and saved Ringprints never contain a photo file or image payload. OpenRouter, any routed model provider, and their infrastructure, terms, and legal obligations still apply.
The app stores saved Ringprints in AsyncStorage, including the questionnaire answers, optional note, generated result, locale, source, timestamps, and image-analysis counts. Paid-plan snapshots, generated guidance, setup inputs, and tool activity are also stored in AsyncStorage; source snapshots omit the free-form Ringprint note. These records are app-local but are not encrypted by AsyncStorage. Photo files are excluded. A random installation UUID and purchase capabilities—including draft and access tokens, obfuscated purchase-binding identifiers, and a Google Play purchase token after billing—are stored separately with device-only SecureStore settings.
On Android, RingMatcher disables app backup and excludes its app files, databases, preferences, and device-to-device transfer domains from backup rules. This is intended to keep local Ringprints, plans, and purchase capabilities off Android backup and migration services. Other operating-system, device-administration, forensic, or user-initiated copying behavior is outside RingMatcher's control.
If you choose Report this result, the app sends RingMatcher the result identifier, visible result title, summary and rationale, the selected report reason, an optional note, the content locale, and the random installation identifier in a request header. The service uses the installation identifier and network address to enforce an hourly report limit. It writes the report content, reason, optional note, locale, a generated report identifier, and the receipt time to structured deployment logs so the report can be reviewed. Those report logs do not intentionally include the raw installation identifier or network address; their retention follows the deployment logging configuration. Reporting is optional and does not affect saved Ringprints or paid access.
Starting a Google Play checkout sends RingMatcher the selected pack, random installation UUID, local Ringprint identifier, and a SHA-256 digest of the Ringprint—not the questionnaire answers, uploaded photos, or generated plan. The server persists a digest of the installation identifier, the Ringprint identifier and digest, generated draft/access identifiers, product and pack identifiers, obfuscated Google Play binding identifiers, capability hashes, and timestamps. Claiming a purchase sends the raw Google Play purchase token to RingMatcher so it can be verified with Google Play. The server persists a digest of that token, and may persist an order-ID digest and purchase-completion timestamp; it does not write the raw purchase or order token to its purchase-state file.
The protected Google Play app-review path sends the reviewer access code and random installation UUID to RingMatcher. The server compares a one-way code digest, enforces network and installation limits, and persists only the code digest, installation digest, synthetic draft/claim/access identifiers, pack and product identifiers, and timestamps—not the plaintext review code. It returns signed, expiring plan capabilities to device-only SecureStore. This review path does not open billing or create a charge.
An unclaimed purchase draft expires after 7 days. After a successful claim, its draft and replay-claim record become eligible for pruning when that same 7-day draft capability expires. Paid access expires after 30 days for Shortlist or Complete Plan and after 90 days for Together Plan. Expired eligible rows are pruned atomically during later purchase-state maintenance, such as a subsequent draft creation or purchase grant; there is no background deletion timer. Unexpired drafts and access records are not evicted to make room for newer records.
Saved Ringprints and completed paid plans remain on the device until you remove them, the bounded local history replaces older Ringprints, app storage is cleared, or the operating system removes the app data. Removing a completed paid plan also asks SecureStore to delete its associated capability. A plan with an unfinished purchase is protected from ordinary removal because the local draft may still be needed for Google Play recovery. RingMatcher has no user account or cross-device plan library: clearing local app data, removing protected credentials, changing devices, or uninstalling can make a consumed one-time purchase or its generated plan impossible to recover. Contact contact@ringmatcher.com for privacy or server-record deletion questions.
请求限制、第一方流程衡量与技术日志
服务器可能根据网络地址生成仅存于内存的临时请求限流键。RingMatcher 会记录落地页、Ringprint 创建、分享与下载、可选结账及付费套餐流程和零售商查找器中的第一方流程里程碑。事件规则只允许事件名称、白名单内的指南 slug,以及固定的来源、渠道、套餐、状态、CTA 目的地、CTA 位置或语言区域值、布尔值和有上限的计数或评分;不包含问卷答案、预算、备注、生成的方向文字、任意 URL 或页面路径、自由文本目的地、付款标识符、错误消息或堆栈、个人信息以及任意文本。
零售商查找器事件还可能包含固定的购买类型,以及 RingMatcher 已审核目录中的零售商 ID。
从指南点击进入测验后,浏览器会话存储可能会保存以下归因值:白名单内的指南 slug、语言区域和 CTA 位置,以及技术版本和到期元数据。归因最长 30 分钟内有效,并在一次带来源归因的 Ringprint 请求中被取用。过期记录会被忽略,并在下次访问时移除;会话存储也会随浏览器标签页或会话结束。其中不含问卷答案、预算、照片、联系方式,也不含账户或用户标识符。
接受的事件仅写入结构化的服务器部署日志。RingMatcher 不会将这些事件发送给第三方分析服务,也不会存入专用分析数据库;保留期限取决于部署日志配置。事件不包含账户或用户标识符。技术性 AI 使用数据也可能被记录,但不含问卷答案或上传的照片。
付费套餐与 Stripe
可选付费套餐通过 Stripe 处理一次性付款。RingMatcher 会向 Stripe 发送收据邮箱、所选套餐、服务器设定的金额和币种,以及生成的请求和 PaymentIntent 标识符。付款信息由 Stripe Payment Element 收集;RingMatcher 不会接收或存储完整卡号或安全码。
Stripe 元数据仅包含生成的标识符、付款与交付状态及用于绑定浏览器访问权限的单向哈希,不包含问卷答案、照片、私人备注或报告内容。每个套餐的 HttpOnly、SameSite Cookie 最长可保留 100 天,待处理付款记录可在该浏览器的本地存储中保留最多 30 天。Stripe 的条款和隐私政策适用。
在正式网站中,付费报告会话存储在受保护的服务器卷上,并可在常规重启和部署后恢复。Shortlist 和 Complete Plan 会话在 30 天后到期,Couple’s Edition 会话在 90 天后到期。如果 RingMatcher 更早完成删除请求,则可提前移除相应会话。
RingMatcher 不销售的内容
RingMatcher 不销售戒指或个人数据。如果账户、结账、分析、存储或模型提供商发生变化,必须在公开变更后的服务前重新审查本页。隐私问题可发送至 contact@ringmatcher.com。