WhyNavo 隐私与数据说明
WhyNavo 采用本地优先设计。你无需登录即可使用,登录仅用于可选的跨设备同步。
本机数据
快捷方式、小组件、便签、待办、倒计时、日历、布局和设置默认保存在当前浏览器的 IndexedDB 中。清理浏览器网站数据、卸载扩展、删除浏览器配置文件或系统回收存储空间,都可能影响仅存在本机的数据。请定期使用完整 JSON 备份。
WhyNavo 不会对 IndexedDB 中的应用内容额外实施端到端或字段级加密。本机数据的静态保护依赖浏览器配置文件、操作系统账号、设备锁和磁盘加密;请勿在共享或未受保护的设备上保存敏感内容。
当你主动为固定任务启用提醒时,扩展会把该任务的标题、周期和提醒时间复制到浏览器扩展的本机存储,并使用浏览器的定时与通知能力在设定时间提醒。该提醒副本不会发送给额外的提醒服务;关闭通知权限或删除任务会停止相应提醒。
账号与云同步
当你注册或登录时,密码会从当前表单通过 HTTPS 直接提交给 Supabase Auth。WhyNavo 不会把密码写入持久化应用数据、IndexedDB、导出备份或同步快照;Supabase Auth 负责验证凭据,并在当前浏览器中保存维持登录所需的访问与刷新会话令牌。这些令牌不进入 WhyNavo 数据备份或同步快照,退出登录会撤销或移除相应会话。可同步的 WhyNavo 数据会写入与账号 ID 绑定的云端快照,并通过 Row Level Security、账号绑定的读写接口和带修订号的原子写入限制账号边界。WhyNavo 的云同步接口还会拒绝创建已超过 90 天或连续 30 天未使用的登录会话;这项限制只控制 WhyNavo 云数据访问,不代表浏览器中的 Supabase 会话令牌会被主动销毁。
WhyNavo 会在当前设备上计算登录、注册或新密码的 SHA-1 摘要,只把摘要前 5 个字符发送给 Have I Been Pwned 的 Pwned Passwords 范围查询接口,并在本机比较其余摘要。完整密码和完整摘要不会发送给该服务。注册和设置新密码在检查无法完成或发现公开泄露记录时会停止;登录先由 Supabase 验证,随后在密码已泄露或检查服务不可用时显示安全提醒,因此第三方检查故障不会阻止现有用户进入自己的账号。
处理目的与范围
这些数据只用于提供本机仪表盘、账号验证、跨设备同步、故障恢复和反滥用保护。WhyNavo 不出售个人数据,不投放基于用户内容的广告,也不在应用中接入行为分析 SDK。托管、认证和安全服务可能保留必要的访问、投递和安全日志。
不会同步的内容
本机上传的照片、照片文件名、自定义壁纸、快捷图标和文件夹图标不会进入云端快照。同步数据不是端到端加密;云服务运营方在必要的系统管理场景下可能具备技术访问能力,因此不要在便签或标题中保存密码、恢复码或其他高度敏感秘密。
外部服务
- Supabase:账号、认证邮件、会话和可选云同步。
- Have I Been Pwned Pwned Passwords:使用 k-匿名范围查询检查密码是否出现在已知泄露数据中;只接收本机计算摘要的前 5 个字符。
- 邮件投递服务:发送注册验证、密码重置和账号安全邮件。
- Open-Meteo:根据你填写的城市,或在你主动开启当前位置后根据设备坐标,提供天气和地理编码。
- Simple Icons、DuckDuckGo 和 Google:开启自动图标查找时通过 HTTPS 获取网站图标;这会向相应提供方暴露被请求的网站主机名。
- Cloudflare Pages:托管 WhyNavo 网页版本并提供 HTTPS 与安全响应头。
- Cloudflare R2:在私有存储桶中保留生产数据库的加密灾难恢复副本。
- Cloudflare Turnstile:在注册、登录、密码重置、修改密码和删除账号前进行反滥用验证。
天气城市、“使用当前位置”偏好、天气结果以及启用定位后取得的坐标只按当前账号分区缓存在本机,用于减少重复请求;它们不进入云端同步快照或完整备份。天气卡片只链接到 Open-Meteo 官方来源页,不会把坐标转交给额外的搜索服务。
Turnstile 会处理完成反滥用验证所需的浏览器、网络和交互信号,并返回一个短期一次性令牌。WhyNavo 只在当前页面内存中使用该令牌完成认证请求,不会把它写入本机数据、导出备份或云端同步快照。
保留与删除
本机数据会保留到你在应用中覆盖、清理浏览器网站数据、卸载扩展或删除浏览器配置文件。账号和云端快照会保留到你永久删除账号;删除后会立即从在线账号和业务表中移除。WhyNavo 每日导出生产数据库用于灾难恢复,导出会先以 AES-256-GCM 加密,再上传到私有 Cloudflare R2 存储桶;解密所需私钥与云服务和上传凭据分离保存。加密副本最多保留 35 天后由生命周期规则删除,因此账号删除前形成的副本可能在该期限内继续存在。灾难恢复不得选择性恢复已删除账号,恢复生产服务时必须重新应用备份形成后的删除记录。安全日志和邮件投递日志可能按相应服务商的有限保留周期延迟清除。
跨设备与跨境处理
登录同步时,数据会由所使用的云服务区域和网络节点处理,位置可能不同于你所在的国家或地区。不同网页域名的浏览器本机存储彼此隔离;未同步的本机数据不会仅因更换访问域名而自动迁移。
你的选择
你可以不登录、关闭自动同步、关闭第三方图标查找、导出完整备份并在其他浏览器恢复。新安装默认不读取定位;只有你主动开启“使用当前位置”后,应用才会调用浏览器定位,浏览器或操作系统可能显示权限提示。普通“退出登录”只退出当前设备,并切换到未登录空白数据;“退出所有设备”会撤销该账号的其他刷新会话,其他设备会在会话刷新后退出。
登录后可在“账号与云同步”中永久删除账号。删除前需要再次输入当前邮箱和密码并完成安全验证;当前密码会通过 HTTPS 发送给 WhyNavo 的账号删除云函数,并仅用于向 Supabase Auth 重新验证当前账号,函数不会保存或记录该密码。完成后会删除 Supabase Auth 账号、该账号的云端同步数据,以及此设备上的账号数据、账号备份、图标解析缓存和位置天气缓存。此操作无法恢复,建议先导出完整 JSON 备份。
你可以通过完整备份查看并携带自己的 WhyNavo 内容,也可以直接修改或删除记录。敏感的数据请求或安全问题不要写入公开 Issue,请使用 GitHub 的私密漏洞报告渠道。
未成年人
账号同步服务不面向未满 16 周岁,或未达到所在地可独立同意网络服务年龄的用户。达到当地要求前,请勿创建同步账号。
源代码与支持
源代码、数据模型和安全说明位于 GitHub 仓库。不包含个人数据的一般问题可通过仓库的 Issues 提交;敏感问题使用 私密漏洞报告。
查看服务条款 · 支持 · 返回 WhyNavo
WhyNavo Privacy and Data Notice
WhyNavo is local-first. You can use it without an account; signing in is only required for optional cross-device synchronization.
Data on your device
Shortcuts, widgets, notes, todos, countdowns, calendar entries, layout, and settings are stored in the current browser's IndexedDB by default. Clearing site data, removing the extension, deleting the browser profile, or operating-system storage cleanup can remove device-only data. Use the complete JSON backup regularly.
WhyNavo does not add end-to-end or field-level encryption to application content in IndexedDB. Protection of data at rest depends on the browser profile, operating-system account, device lock, and disk encryption. Do not keep sensitive content on a shared or unprotected device.
When you explicitly enable a reminder for a recurring task, the extension copies that task's title, recurrence, and reminder time to local extension storage and uses the browser's alarm and notification APIs at the scheduled time. This reminder copy is not sent to an additional reminder service. Revoking notification permission or deleting the task stops the corresponding reminder.
Account and cloud synchronization
When you register or sign in, your password is sent directly over HTTPS from the current form to Supabase Auth. WhyNavo does not place passwords in persistent application data, IndexedDB, exported backups, or synchronization snapshots. Supabase Auth stores the access and refresh session tokens needed to remain signed in in the current browser; those tokens are excluded from WhyNavo backups and cloud snapshots and are removed or revoked by the applicable sign-out action. Synchronizable data is stored in an account-scoped cloud snapshot protected by Supabase authentication, Row Level Security, account-bound read and write functions, and revision-checked atomic writes. WhyNavo's cloud-data functions also reject sessions created more than 90 days ago or unused for 30 consecutive days. This restriction controls access to WhyNavo cloud data; it does not claim that the browser's underlying Supabase session token is proactively destroyed.
WhyNavo computes the SHA-1 digest of a sign-in, registration, or replacement password on the current device, sends only the first five digest characters to the Have I Been Pwned Pwned Passwords range API, and compares the remaining digest locally. The full password and full digest are never sent to that service. Registration and replacement stop when the check is unavailable or reports a known breach. Sign-in is authenticated by Supabase first and then displays a security warning for a leaked password or an unavailable check, so a third-party outage cannot lock existing users out of their account.
Purposes and data scope
Data is processed only to provide the local dashboard, account verification, optional synchronization, recovery, and abuse prevention. WhyNavo does not sell personal data, use user content for targeted advertising, or include behavioral analytics SDKs. Hosting, authentication, email, and security providers may retain necessary delivery, access, and security logs.
Data that is not synchronized
Device-uploaded photos, photo filenames, custom wallpapers, shortcut icons, and folder icons are excluded from cloud snapshots. Synchronized data is not end-to-end encrypted. Cloud operators may have technical access when necessary to operate the service, so do not store passwords, recovery codes, or other highly sensitive secrets in titles or notes.
Service providers
- Supabase for accounts, sessions, authentication, and cloud snapshots.
- Have I Been Pwned Pwned Passwords for a k-anonymous leaked-password range query that receives only the first five characters of a locally computed password digest.
- The configured email provider for verification, password reset, and security messages.
- Cloudflare Pages for HTTPS hosting and Cloudflare Turnstile for abuse prevention during account operations.
- Cloudflare R2 for encrypted production-database disaster-recovery copies in a private bucket.
- Open-Meteo for weather and geocoding based on the city you enter or, only after you enable current-location weather, the device coordinates.
- Simple Icons, DuckDuckGo, and Google for HTTPS site-icon requests when remote lookup is enabled; those requests disclose the requested hostname to the applicable provider.
The selected city, current-location preference, weather response, and any device coordinates are cached only in the current account's local browser partition to reduce repeat requests. They are excluded from cloud snapshots and complete backups. Weather source links do not forward coordinates to an additional search provider.
Turnstile processes browser, network, and interaction signals needed to issue a short-lived, single-use challenge token. WhyNavo uses that token only in page memory for the current authentication request.
Retention, deletion, and your choices
Device data remains until you overwrite it or remove the relevant browser storage. Online account data remains until the account is permanently deleted and is removed immediately from the live Auth and application tables. WhyNavo creates a daily production-database export for disaster recovery, encrypts it with AES-256-GCM before upload, and stores only the encrypted envelope and checksum in a private Cloudflare R2 bucket. The recovery private key is kept separately from the cloud services and upload credential. A lifecycle rule deletes encrypted copies after no more than 35 days, so a copy created before account deletion may remain until that period expires. Disaster recovery must not selectively restore a deleted account and must reapply deletions made after the restored backup. Security and email-delivery logs may follow their providers' limited retention periods. You can use WhyNavo without signing in, disable automatic sync and remote icon lookup, and export a complete backup.
You can permanently delete an account after confirming the current email and password and completing the security challenge. The current password is sent over HTTPS to WhyNavo's account-deletion function and used only to reauthenticate the account with Supabase Auth; the function does not store or log it. Successful deletion removes the Supabase Auth account, its cloud snapshot, and that account's data and caches on the current device.
Ordinary sign-out affects only the current device and switches it to an empty signed-out data area. “Sign out all devices” revokes the account's other refresh sessions; other devices sign out when their sessions refresh. Different web origins have separate browser storage, so device-only data does not automatically move when a domain changes.
International processing and age
Cloud services and network nodes may process data outside your country or region. The synchronization account service is not directed to anyone under 16 or below the age at which they can independently consent to an online service in their location.
Support and source
Source code and security documentation are available in the GitHub repository. Use public Issues only for requests that contain no personal data. Report sensitive security matters through private vulnerability reporting.