
隐私说明
更新于 2026-09-29 · 邀请测试
TapeNow 保存用于登录的邮箱、你的项目配置、供应商授权和发布记录,以提供构建、预览和部署服务。登录由 Supabase Auth 处理;项目元数据存放在 Supabase,发布文件归档存放在 Cloudflare R2。供应商令牌在服务端加密保存,不发给网页前端。
授权时,你可以选择供应商允许的账户、项目或仓库范围。GitHub 构建运行在你的 GitHub Actions,Vercel 接入只读取来源配置。供应商会按各自规则处理你的数据。你可以在工作台撤销连接,也可以在供应商控制台撤销授权。
新导入默认仅归档。私有预览保存加盐密码校验值,不保存明文密码,访客获得限时、仅对应预览网址的加密会话 Cookie。撤销、换密码和过期会拒绝后续请求,但无法收回已下载的文件。明确发布的公开预览可以被任何持有链接的人访问。不要上传个人隐私、API 密钥或数据库管理凭据。链上发布需钱包确认,发布后无法保证删除或撤回。移除授权不会自动删除已经部署的网站或链上数据。
项目入口统计按日保留近 30 天请求量、HTTP 错误及文件响应字节,不保存访客 IP、查询参数或页面内容;限流服务另使用短期标识。测试期保留必要操作日志,不记录密码或令牌。项目可配置归档保留期限,自动回收默认关闭;文件移入回收站后七天内可恢复,清除后保留清单和发布历史。加密备份按独立保留策略轮换,回收不会即时删除已有备份。平台维护者可以邀请或撤销邮箱的使用资格;供应商接受邮件不等于实际送达。客户数据库的邮件测试仅发送给当前登录邮箱,需用户确认并输入收到的验证码;客户 SMTP 密码仍留在其 Supabase。需要导出项目或申请清理测试数据,可通过邀请你的维护者联系处理。首版尚不提供全自动账户删除。
A 公测另保存去敏的工作空间操作类型、耗时、状态和 RPC 方法计数(最近30天),以及操作重试记录(7天;到期记录在每日维护或后续操作中清理)。统计不包含 RPC 参数、供应商令牌或私钥,不代表第三方网页访问或供应商账单。详情见 A 公测说明。
← TapeNowPrivacy notice
Updated 29 September 2026 · Invitation testing
TapeNow stores your sign-in email, project configuration, provider authorizations, and release records to provide build, preview, and deployment services. Supabase Auth handles sign-in; Supabase holds project metadata and Cloudflare R2 stores release archives. Provider tokens are encrypted on the server and are not sent to the frontend.
You choose the account, project, or repository scope offered by each provider. GitHub builds run in your own GitHub Actions; Vercel access reads source configuration only. Providers process data under their own policies. Remove connections in TapeNow or revoke authorization in the provider dashboard.
New imports are archived without public publication. Private previews store salted password verifiers, not plaintext passwords. Visitors receive encrypted, time-limited session cookies scoped to the preview hostname. Revocation, password rotation, and expiry reject future requests but cannot recall downloaded files. Explicitly published public previews are accessible to anyone with the URL. Do not upload private personal data, API keys, or database admin credentials. Chain publication requires wallet confirmation and cannot be guaranteed removable or reversible. Revoking authorization does not automatically delete deployed websites or chain data.
Daily entry statistics retain 30 days of request counts, HTTP errors, and file response bytes, excluding visitor IPs, query parameters, and page contents. Rate limiting uses separate short-lived identifiers. Necessary operational logs exclude passwords and tokens. Projects can configure archive retention; automatic recycling is disabled by default. Files in trash are recoverable for seven days; purging retains manifests and release history. Encrypted backups rotate under a separate policy and are not immediately deleted by recycling. Platform operators can invite or revoke email access; provider acceptance does not prove actual email delivery. Customer database email tests send only to the signed-in email after confirmation and require the received code. SMTP passwords stay in the customer's Supabase. Contact the maintainer who invited you for exports or test-data cleanup. Fully automated account deletion is not available in this version.
A beta also keeps redacted workspace action categories, duration, status and RPC method counts for 30 days, and retry records for seven days. Expired records are cleaned during daily maintenance or subsequent actions. These measurements exclude RPC parameters, provider tokens and private keys and are not third-party website traffic or supplier invoices. See the A-beta guide.