Privacy by design
隱私政策
沒有帳號或儲存使用者資料的後端,也沒有廣告與追蹤。這份政策說明 App 在裝置上處理哪些資料,以及你始終保有的選擇。
1. 哪些資料會被處理
我們不蒐集你輸入的內容、GPS 位置、聯絡人、搜尋紀錄或一般畫面/操作紀錄。 防災口袋沒有使用者帳號或登入機制,也不建立使用者檔案。App 在平時模式檢查公開版本, 或你主動檢查/下載地圖與道路資料時,Cloudflare CDN 會為了傳遞、安全與可靠性處理 IP 位址、 請求檔案與時間等標準連線資料。Google ML Kit 會為 QR 掃描功能處理有限的技術診斷與使用指標; 完整範圍與第三方政策見第 4 節。
2. 儲存在裝置上的資料
為了讓 App 在斷網時仍然可用,下列資料會儲存在你的裝置本機。 App 不會主動上傳,我們也沒有任何方式讀取它們。若你啟用作業系統備份,系統供應商 可能依平台設定保存部分偏好資料;這不是防災口袋主動發出的連線。
| 資料 | 用途 | 儲存位置 |
|---|---|---|
| 位置資訊(GPS/網路定位) | 顯示救援位置卡、在地圖上顯示你的位置、從目前位置新增「我的地點」、計算到收容所、AED 等設施的直線距離與方位,及在你選擇時帶入簡訊 | 目前定位只在使用當下處理;位置卡會把最後一次可靠座標、水平誤差與取得時間保存在裝置本機,可由你清除,且排除系統備份 |
| 我的地點名稱、備註與精確座標 | 保存你自行建立或從 QR Code 匯入的私人地點,並提供地圖、方位與離線道路參考 | 裝置的 Application Support;不會上傳,可由你個別或全部刪除,且排除系統備份 |
| 裝置動作與方向(羅盤) | 沒有底圖時,讓方位箭頭隨手機轉向指出收容所、AED 等設施方向 | 僅在使用當下於記憶體中處理,不保存 |
| 緊急聯絡人姓名與電話 | 由你自行輸入,用於快速產生報平安簡訊 | 裝置本機儲存區;iOS 系統備份可能包含 |
| 你選擇的縣市、已下載的離線地圖 | 離線時顯示正確區域的地圖與設施資料 | 縣市設定在裝置本機;離線地圖排除 App 備份 |
| 緊急避難包清單的勾選與自訂項目 | 記住你的整備進度與自行增減的物品 | 裝置本機儲存區;iOS 系統備份可能包含 |
| 語言設定、受困信標標語 | 記住你的偏好設定 | 裝置本機儲存區;iOS 系統備份可能包含 |
| App 版本檢查時間、已驗證的公開版本與「稍後」選擇 | 限制自動檢查頻率,並避免重複顯示同一個更新提醒 | 裝置本機儲存區;不含裝置識別碼或使用紀錄 |
刪除方式:解除安裝會刪除目前裝置上的 App 資料。若作業系統先前建立過 備份,備份副本可能依你的平台設定繼續保留或在日後還原;你可以在系統的備份設定中 管理該副本。你也可以在 App 內自行清除最後一次可靠位置、「我的地點」、緊急聯絡人與已下載的離線地圖/道路資料。
# 後方),作業系統
會交給 App 在裝置上驗證,瀏覽器的 HTTP 請求不會把 fragment 傳給防災口袋網站或 Cloudflare。
若 App 未安裝,網站只會收到不含私人內容的 /places/v1 路徑並顯示安裝說明。
3. App 不讀取你的通訊錄
緊急聯絡人是由你手動輸入的,防災口袋不會存取你的通訊錄或聯絡人清單。
4. 網路連線
防災口袋是離線優先的 App,核心救命功能在完全斷網時仍然可用。App 只在下列情況連線網路:
4.1 檢查與下載離線地圖/道路資料(由你操作才發生)
- 離線地圖與道路資料存放於
maps.rescuepocket.com,由 Cloudflare 提供 CDN 服務。 - 只有在你明確確認之後才會開始下載。App 不會在背景自動下載地圖; 使用行動數據前會先顯示檔案大小並要求你確認。
- 如同任何一次網路連線,伺服器與 CDN 供應商在技術上會看到你的 IP 位址與標準的
HTTP 請求資訊(例如請求的檔案與時間)。我們送出的 User-Agent 是固定字串
RescuePocket-MapDownloader/1,不含任何裝置識別碼、廣告識別碼或帳號資訊。 - 我們不會使用這些連線紀錄建立使用者輪廓,也不會將其與任何其他資料關聯。 Cloudflare 作為 CDN 供應商可能依其自身政策保留連線紀錄,請參閱 Cloudflare 隱私政策(另開視窗)。
4.2 檢查 App 公開版本
- Onboarding 完成後,App 只在平時模式首頁背景檢查公開版本;成功後 24 小時內不重查,失敗後至少 6 小時不自動重試。災時模式不建立更新提醒。
- 版本 manifest 與簽章存放於
rescuepocket.com/app-releases/,由 Cloudflare Pages 提供。請求使用固定 User-AgentRescuePocket-AppUpdate/1,不含裝置識別碼、帳號、位置或 App 使用內容。 - 查詢只比較目前 build 與受簽章保護的公開 build;不會自動下載或安裝 App,提醒也 永遠可以稍後處理,不影響既有離線功能。設定頁的手動檢查不受 24 小時節流限制。
4.3 使用 Google ML Kit 掃描 QR Code
- iOS 與 Android 的 QR 掃描器使用 Google ML Kit。條碼辨識在裝置端執行; 相機畫面、解碼後的 QR 內容,以及「我的地點」名稱、備註與座標不會傳送給 Google。
- 依 Google 的 SDK 揭露,ML Kit 會以 HTTPS 傳送有限技術指標:裝置製造商、型號、 作業系統版本/build 與硬體加速器,App 套件識別碼與版本,每次安裝產生的識別碼, 功能/事件類型、API 設定、輸入與輸出大小、功能版本、延遲與錯誤碼。用途是使用情形 分析、診斷,以及提供錯誤修正、模型或硬體相容性更新;Google 表示不將這些資料用於追蹤或移轉給第三方。
- App 未啟用自動縮放,因此 Google 文件所列的掃描工作階段、縮放比例與條碼框座標等 自動縮放額外指標不適用。沒有網路時仍可進行裝置端辨識。
詳見 Google 的 Android 資料揭露(另開視窗)、 iOS 資料揭露(另開視窗)與 ML Kit 條款與隱私(另開視窗)。
4.4 開啟外部網頁(由你點擊才發生)
指引卡與地圖版權標示中的官方來源,以及 Android App 或本網站的 Portaly 自願支持頁, 都會以外部瀏覽器開啟。只有你點擊連結才會離開防災口袋;之後的瀏覽、付款與 資料處理由該網站、付款服務及你的瀏覽器規範,不在本政策範圍內。iOS App 內的自願支持使用 Apple In-App Purchase,不會開啟 Portaly。
4.5 報平安簡訊與系統撥號入口(由你操作才發生)
- 報平安簡訊:App 只會開啟你手機內建的簡訊程式並預先填入內容, 由你自己按下傳送。防災口袋不代發簡訊,訊息也不會經過我們的任何伺服器。
- 系統撥號入口:119 緊急號碼,以及地圖中部分警察與消防單位的 公開電話,可由 App 交給你手機的電話程式預先填入,仍由你確認撥出。單位電話 可離線查看,但實際通話仍需可用電話服務;緊急狀況應優先使用 110 或 119, 防災口袋不是緊急服務,也不保證電話有人接聽。
防災口袋不要求直接撥號或通訊錄權限,不讀取通話紀錄、聯絡人或裝置電話號碼, 也不知道電話是否撥出、接通或取消。公開單位電話隨 App 版本內建,不會在使用時送到 我們的伺服器查詢。
5. 我們不做的事
- 不蒐集或上傳你的 GPS 位置、聯絡人、設定、搜尋紀錄或一般畫面/操作紀錄。
- 不販售、出租或提供資料作廣告與行銷用途。
- 不置入廣告,不使用任何廣告或行銷 SDK。
- 不使用開發者營運的一般產品分析、使用者行為追蹤或當機回報工具;ML Kit 只傳送第 4.3 節所列的 QR 掃描技術診斷與使用指標。
- 不使用 Cookie 或跨 App 追蹤識別碼。
- 不在背景自動下載資料或追蹤位置。
6. 兒童隱私
防災口袋並非專為兒童設計,也不會要求任何年齡層的使用者建立帳號或提供個人資料。 版本檢查/地圖 CDN 的標準連線資料與 ML Kit 技術指標,無論使用者年齡都依第 4 節處理。
7. 權限說明
| 權限 | 平台 | 為什麼需要 | 可否拒絕 |
|---|---|---|---|
| 位置(使用期間) | iOS / Android | 救援座標、地圖定位、從目前位置新增「我的地點」、設施距離與方位、報平安簡訊帶入座標 | 可以。改為手動選擇縣市並從地圖新增地點 |
| 動作與方向 | iOS | 無底圖時的方位箭頭 | 可以。改為北方朝上加文字方位 |
| 相機 | iOS / Android | 只在你主動開啟掃描頁時,辨識防災口袋的地點 QR Code | 可以。仍可手動新增、編輯與刪除地點 |
| 網路存取 | iOS / Android | 公開版本檢查,以及你操作的離線地圖/道路資料檢查與下載 | 可以。略過連線,內建核心功能仍可離線使用 |
| 喚醒鎖定(WAKE_LOCK) | Android | CPR 節拍與受困信標運作期間避免螢幕鎖定中斷急救 | 系統自動授予,僅在功能啟用時使用 |
8. 資料安全
防災口袋不保存你輸入的內容、GPS 位置、聯絡人、搜尋或使用紀錄的伺服器副本。 存於裝置上的資料受你手機作業系統的沙箱機制與螢幕鎖保護;系統備份則由平台供應商 與你的帳號設定管理。版本檢查與地圖 CDN 的標準連線資料由 Cloudflare、QR 掃描器的有限 技術指標由 Google ML Kit 依第 4 節所述處理。 離線地圖下載採 HTTPS 傳輸,並以雜湊與數位簽章驗證檔案完整性,防止內容遭竄改。
9. 內容免責聲明
防災口袋內的防災與急救指引,是官方機關與公領域來源的離線快照, 每張卡片都標示來源機關、原始網址與取得日期。英文若為中文的機器輔助譯文, 會在 App 內標示,且未經獨立翻譯審核;中文版本為準。本 App 不自行創作救命內容, 也未經獨立醫療或防災專業人員審核。 災害現場請以官方警報、現場救援人員指示與專業醫療判斷為優先。
10. 政策變更
本政策如有修改,我們會更新本頁面頂端的「最後更新」日期。 涉及資料處理方式的重大變更,會在 App 更新說明中一併告知。
11. 聯絡我們
對本隱私政策有任何疑問,請來信: scottliu.apps@gmail.com
本政策依中華民國《個人資料保護法》相關規定訂定。
Privacy Policy
Rescue Pocket (防災口袋)
Effective: 28 July 2026 · Last updated: 3 September 2026
1. What data is processed
We do not collect data you enter, GPS location, contacts, search history or general screen/action history. Rescue Pocket has no user accounts or sign-in and builds no user profiles. When the app checks the public version in normal mode, or when you choose to check or download maps and road data, Cloudflare's CDN processes standard connection data such as IP address, requested file and time for delivery, security and reliability. Google ML Kit processes limited technical diagnostics and usage metrics for QR scanning. Section 4 describes the full scope and third-party policies.
2. Data stored on your device
So the app keeps working with no network connection, the following data is stored locally on your device. The app does not upload it and we have no means of accessing it. If operating-system backup is enabled, the platform provider may retain some preferences under your backup settings; this is not a connection initiated by Rescue Pocket.
| Data | Purpose | Where it is stored |
|---|---|---|
| Location (GPS / network positioning) | Show the rescue-location card and your map position, create a My Place from your current location, calculate straight-line distance and bearing to shelters, AEDs and other listed facilities, and insert coordinates into an SMS when you choose | The current fix is handled only during use. The location card stores the last reliable coordinates, horizontal accuracy and capture time locally; you can clear it, and it is excluded from system backup |
| My Place names, notes and precise coordinates | Keep private places you create or import from a QR code, and provide map, bearing and offline road references | Application Support on the device; never uploaded, individually or fully deletable, and excluded from system backup |
| Device motion and heading (compass) | Point the bearing arrow toward a facility when no offline base map is available | Held in memory during use only; not persisted |
| Emergency contact names and phone numbers | Entered by you, used to compose an "I'm safe" SMS quickly | Local device storage; may be included in iOS system backup |
| Selected county and downloaded offline maps | Show the correct area's map and facilities while offline | County preference is local; offline maps are excluded from app backup |
| Emergency kit checklist state and custom items | Remember your preparedness progress and the items you added or removed | Local device storage; may be included in iOS system backup |
| Language setting, distress beacon message | Remember your preferences | Local device storage; may be included in iOS system backup |
| App-version check time, verified public version and “Later” choice | Limit automatic checks and avoid repeating the same update reminder | Local device storage; contains no device identifier or usage history |
Deletion: Uninstalling removes the app data from the current device. If the operating system created a backup earlier, that copy may remain or be restored according to your platform settings; you can manage it in the system backup settings. You can also clear the last reliable location and delete My Places, emergency contacts and downloaded offline map/road data from within the app.
#),
which the operating system passes to the app for on-device validation and which browsers do
not include in HTTP requests to Rescue Pocket or Cloudflare. If the app is not installed, the
website receives only the non-private /places/v1 path and shows installation guidance.
3. The app does not read your contacts
Emergency contacts are entered manually by you. Rescue Pocket does not access your address book or contact list.
4. Network connections
Rescue Pocket is offline-first: its core life-safety features work with no network connection at all. The app connects to the network only in the following cases.
4.1 Checking and downloading offline maps or road data (only when you act)
- Offline maps and road data are hosted at
maps.rescuepocket.com, served through Cloudflare's CDN. - Downloads start only after you explicitly confirm. The app never downloads maps or road data without your request, and it shows the file size and asks for confirmation before using mobile data.
- As with any network connection, the server and CDN provider can technically see
your IP address and standard HTTP request information (such as which file was
requested and when). The User-Agent we send is the fixed string
RescuePocket-MapDownloader/1and contains no device identifier, advertising ID or account information. - We do not use these connection logs to build user profiles and do not correlate them with any other data. Cloudflare, as our CDN provider, may retain connection logs under its own policy — see the Cloudflare Privacy Policy (opens in a new tab).
4.2 Checking the public app version
- After onboarding, the app checks only from the normal-mode home screen. It waits 24 hours after a successful check and at least six hours after a failed automatic attempt. Emergency mode does not create the update reminder.
- The signed manifest and signature are hosted under
rescuepocket.com/app-releases/on Cloudflare Pages. The request uses the fixed User-AgentRescuePocket-AppUpdate/1and includes no device identifier, account, location or app-use content. - The check only compares this build with a signed public build. It never downloads or installs an app automatically, can always be deferred, and does not affect offline features. A manual Settings check is not subject to the 24-hour interval.
4.3 Scanning QR codes with Google ML Kit
- The iOS and Android QR scanner uses Google ML Kit. Barcode recognition runs on device; camera frames, decoded QR content, and My Place names, notes and coordinates are not sent to Google.
- According to Google's SDK disclosures, ML Kit sends limited technical metrics over HTTPS: device manufacturer, model, OS version/build and hardware accelerators; app package/bundle and version; a per-installation identifier; feature/event types, API configuration, input/output sizes, feature version, latency and error codes. Google describes the purposes as usage analytics, diagnostics, bug fixes, and model or hardware-compatibility updates, and says the data is not used for tracking or transferred to third parties.
- Rescue Pocket does not enable auto-zoom, so the additional scan-session, zoom and barcode bounding-box metrics listed for that feature do not apply. On-device recognition remains available offline.
See Google's Android data disclosure (opens in a new tab), iOS data disclosure (opens in a new tab) and ML Kit terms and privacy (opens in a new tab).
4.4 Opening external pages (only when you tap a link)
Official source links on guidance cards and in map attribution, as well as the optional Portaly support page linked from the Android app or this website, open in an external browser. Rescue Pocket leaves the app or website only after you tap the link. Subsequent browsing, payment and data handling are governed by that website, payment provider and your browser, not by this policy. Optional support inside the iOS app uses Apple In-App Purchase and does not open Portaly.
4.5 "I'm safe" SMS and system dialler links (only when you act)
- "I'm safe" SMS: the app opens your phone's own messaging app with the message pre-filled. You send it yourself. Rescue Pocket does not send messages on your behalf and no message passes through any server of ours.
- System dialler links: the app can pre-fill the 119 emergency number or a public phone number for certain police and fire/rescue units in your phone's dialler. You still confirm the call. Facility numbers can be viewed offline, but an actual call still requires available phone service. In an emergency, use 110 or 119 first. Rescue Pocket is not an emergency service and does not guarantee an answer.
Rescue Pocket requests no direct-call or contacts permission, and does not read call history, contacts or your device phone number. It does not know whether you dialled, connected or cancelled. Public facility numbers are bundled with the app and are not looked up from our servers at runtime.
5. What we never do
- Collect or upload your GPS location, contacts, settings, search history or general screen/action history.
- Sell, rent or provide data for advertising or marketing.
- Show ads or include any advertising or marketing SDK.
- Use developer-operated general product analytics, behavioural tracking or crash reporting; ML Kit sends only the QR-scanner technical diagnostics and usage metrics listed in Section 4.3.
- Use cookies or cross-app tracking identifiers.
- Download data or track location in the background.
6. Children's privacy
Rescue Pocket is not directed at children and does not ask users of any age to create an account or provide personal data. Standard app-version/map CDN connection data and ML Kit technical metrics are handled as described in Section 4 regardless of user age.
7. Permissions
| Permission | Platform | Why it is needed | Can you decline? |
|---|---|---|---|
| Location (while in use) | iOS / Android | Rescue coordinates, map positioning, creating a My Place from your current location, facility distance/bearing and coordinates in the "I'm safe" SMS | Yes — select a county and add places from the map manually |
| Motion and orientation | iOS | Bearing arrow when no base map is available | Yes — falls back to north-up plus a text bearing |
| Camera | iOS / Android | Recognise a Rescue Pocket place QR code only after you open the scanner | Yes — add, edit and delete places manually instead |
| Network access | iOS / Android | Public-version checks and offline map/road checks or downloads you initiate | Yes — skip connections; bundled core features remain available offline |
| Wake lock | Android | Prevents the screen locking mid-rescue while the CPR metronome or distress beacon is running | Granted automatically; used only while those features are active |
8. Data security
Rescue Pocket holds no server-side copy of data you enter, GPS location, contacts, searches or usage history. Data on your device is protected by the operating system's sandbox and your screen lock; any system backup is governed by your platform provider and account settings. Standard app-version and map CDN connection data is processed by Cloudflare, and limited QR-scanner technical metrics by Google ML Kit, as described in Section 4. Offline map downloads use HTTPS and are verified with hashes and digital signatures to ensure the files have not been tampered with.
9. Content disclaimer
The disaster preparedness and first-aid guidance in Rescue Pocket is compiled from verifiable official government and public-domain sources. Every card shows its issuing authority, original URL and retrieval date. Machine-assisted translations from Chinese are labeled in the app, have not been independently reviewed, and defer to the Chinese version as authoritative. The app does not author life-safety content of its own and has not been reviewed by independent medical or emergency-management professionals. In an actual emergency, official alerts, on-scene responders and professional medical judgement take precedence.
10. Changes to this policy
If this policy changes we will update the "Last updated" date at the top of this page. Material changes to how data is handled will also be noted in the app's release notes.
11. Contact
Questions about this privacy policy: scottliu.apps@gmail.com