‹ 返回

Hummy 隱私權政策

生效日期:2026 年 6 月 8 日 · 最後更新:2026 年 6 月 10 日

Hummy(以下稱「我們」)開發並營運 Hummy — AI 聲紋親子繪本(以下稱「本服務」或「App」)。本政策說明我們蒐集哪些資料、為何蒐集、如何使用與保護、與哪些第三方共享、跨境傳輸情形,以及您(家長/監護人)可行使的權利。請家長/監護人在使用本服務前詳閱本政策。本服務的付費者與操作者為家長/監護人;內容聆聽對象為 0–10 歲兒童。我們在設計上即以「最小化兒童個資蒐集」為原則。

1. 我們是誰、本服務做什麼

Hummy 讓家長以自己的聲音陪伴孩子:家長錄製一段簡短的語音樣本(約 30–60 秒),透過語音技術建立「聲音模型」,再從我們預先製作的故事庫中挑選故事,以「家長的聲音」朗讀給孩子聽。

2. 我們蒐集哪些資料

我們僅蒐集為提供本服務所必要的最少資料。

2.1 家長帳號資料

電子郵件地址、(若使用 Apple/Google 第三方登入)對應的帳號識別碼、帳號建立時間。由 Supabase Auth 提供身分驗證。用途:建立與驗證帳號、登入、客服、重要服務通知。

2.2 家長聲紋(語音樣本與聲音模型)

您主動錄製的語音樣本(m4a 音檔)、由語音技術供應商(MiniMax)產生的聲音模型識別碼(voice_id)、聲紋標籤(如「媽媽」「爸爸」)與建立時間。語音樣本儲存於私有、加密的雲端儲存空間(Supabase Storage 私有 bucket),以資料列權限(RLS)限定僅您本帳號可存取。這是「敏感/生物特徵相關」資料:我們以加密保存、限定本帳號使用,並提供一鍵刪除。法律依據:您的明示同意(錄音前會以畫面說明並取得同意)+履行服務契約。

2.3 收藏與播放紀錄

您收藏的故事、播放/收聽紀錄、篩選與偏好設定。用途:保留收藏、提供「繼續收聽」與連續播放、改善推薦。若您使用「離線下載」,故事音檔與插圖僅快取於您的裝置本機,可隨時於 App 內移除。

2.4 孩子的名字(僅本機處理,不上傳)

您可輸入孩子的名字,讓故事中的 {孩子名字} 佔位符被替換成孩子的稱呼。此名字僅儲存與處理於您的裝置本機,不會上傳至我們的伺服器、不寫入伺服器日誌、不傳送給語言模型或繪圖服務。 在以您的聲音生成朗讀音訊時,已替換好名字的故事文字會傳送給語音技術供應商以產生語音;該文字不含其他兒童識別資料,且依約不得用於供應商的模型訓練。

2.5 訂閱與交易資料

訂閱方案、訂閱狀態與權利(entitlement)、交易識別碼。我們不會接觸或儲存您的信用卡號或完整付款資訊——付款由 Apple App Store 處理。本服務提供免費方案(精選故事+1 組聲紋)與家庭方案 NT$90/月(完整故事庫含學習英文雙語故事+最多 4 組聲紋,不定期新增節慶限定故事),經 Apple App Store 計費並自動續訂,您可隨時於 App Store 帳號設定中取消。

2.6 我們不會蒐集的項目

3. 第三方服務與資料邊界

我們僅與下列「服務供應商(資料處理者)」共享為提供本服務所必要的資料。各供應商僅得依我們的指示、為特定目的處理資料,不得用於其自身行銷或廣告。

3.1 MiniMax(語音處理:聲音克隆與文字轉語音)

使用 MiniMax 國際服務端(API 端點 api.minimax.io)。用途:依您錄製的語音樣本建立聲音模型;以該模型將故事文字轉為語音(TTS)。共享資料:語音樣本、voice_id、待朗讀的故事文字(已於本機替換好孩子名字、不含其他兒童識別資料)。所有對 MiniMax 的呼叫一律經由我們的伺服器端代理(Supabase Edge Function)轉送;App 本身不持有 MiniMax 金鑰。跨境傳輸:MiniMax 國際端可能在台灣以外地區處理或儲存上述資料(見第 8 節)。我們以契約要求供應商不得將您的資料用於模型訓練。當您刪除聲紋或帳號時,我們會一併要求 MiniMax 刪除對應的聲音模型。

3.2 Supabase(雲端後端)

帳號驗證、儲存帳號資料/voice_id/收藏與播放紀錄、以私有加密 bucket 保存語音樣本、運行伺服器端代理函式。依我們的指示與存取控制(RLS)處理資料,僅您的帳號可存取您的資料。

3.3 Apple/Google(第三方登入,若您選用)

若您以 Sign in with Apple 或 Google 帳號登入,由其驗證身分並提供帳號識別碼(與 email,視您的授權)。不含兒童資料。

3.4 RevenueCat(訂閱管理)

用於管理訂閱狀態與權利、跨裝置同步購買、還原購買。僅共享匿名/假名化的 App 使用者識別碼與訂閱狀態,不含您的姓名、email 內容或任何兒童資料。

3.5 Apple App Store(付款與訂閱)

付款、自動續訂與取消由 Apple 依其條款處理;我們不接觸您的付款工具明細。

我們不會販售您或孩子的個人資料,也不會將其用於第三方廣告或跨 App 追蹤。

4. 我們如何使用資料

目的使用的資料
建立/驗證帳號、登入家長帳號資料
以您的聲音朗讀故事語音樣本、voice_id、(本機替換後的)故事文字
保留收藏、繼續收聽、改善推薦收藏/播放紀錄、偏好
開通與管理訂閱、還原購買訂閱與交易資料
客服與重要通知家長帳號資料
防止濫用、維護安全、履行法律義務視情況之必要資料

我們不會將您的資料用於:第三方廣告、跨 App 追蹤、出售給第三方,或供 AI 供應商訓練其模型。

5. 資料保存與安全

6. 您的權利(含一鍵刪除)

身為家長/監護人,您可隨時:

敏感操作(建立聲音模型、付費、刪除等)皆受家長關卡(parental gate)保護,避免兒童誤觸。

7. 兒童隱私(重點章節)

8. 國際資料傳輸(跨境)

我們會採取合理措施,確保跨境傳輸符合適用之資料保護法律(含 GDPR 跨境傳輸要求)。

9. 政策變更

我們可能因功能或法規調整而更新本政策。重大變更將於 App 內或以適當方式通知,並更新本頁「最後更新」日期。

10. 聯絡我們


Hummy Privacy Policy

Effective date: June 8, 2026 · Last updated: June 10, 2026

Hummy (referred to as "we", "us" or "our") develops and operates Hummy — AI voice storybooks for families (the "Service" or the "App"). This Policy explains what data we collect, why we collect it, how we use and protect it, which third parties we share it with, how it may be transferred across borders, and the rights you — as a parent or guardian — may exercise. Please read this Policy before using the Service. The Service is purchased and operated by parents/guardians; the listening audience is children aged 0–10. The Service is designed around the principle of minimizing the collection of children's personal data. This English version corresponds to the Traditional Chinese version above; in the event of any inconsistency, the Chinese version prevails.

1. Who We Are and What the Service Does

Hummy lets parents accompany their children with their own voice: a parent records a short voice sample (about 30–60 seconds), which is used to create a "voice model" through voice technology. The parent then picks stories from our pre-produced story library, and the stories are read aloud to the child in the parent's voice.

2. What Data We Collect

We collect only the minimum data necessary to provide the Service.

2.1 Parent Account Data

Email address, the account identifier provided by Apple/Google if you use third-party sign-in, and account creation time. Authentication is provided by Supabase Auth. Purpose: creating and verifying your account, sign-in, customer support, and important service notices.

2.2 Parent Voiceprint (Voice Samples and Voice Models)

The voice sample you actively record (an m4a audio file), the voice model identifier (voice_id) generated by our voice technology provider (MiniMax), the voice label (e.g. "Mom", "Dad"), and creation time. Voice samples are stored in private, encrypted cloud storage (a private Supabase Storage bucket), with row-level security (RLS) restricting access to your account only. This is sensitive, biometric-related data: we store it encrypted, restrict its use to your account, and provide one-tap deletion. Legal basis: your explicit consent (an on-screen explanation and consent step precedes recording) and performance of our service contract with you.

2.3 Favorites and Playback Records

Stories you favorite, playback/listening history, and filter and preference settings. Purpose: keeping your favorites, providing "continue listening" and continuous playback, and improving recommendations. If you use offline downloads, story audio files and illustrations are cached only locally on your device and can be removed in the App at any time.

2.4 Your Child's Name (Processed Locally Only — Never Uploaded)

You may enter your child's name so that the {child's name} placeholder in stories is replaced with it. The name is stored and processed only locally on your device. It is not uploaded to our servers, not written to server logs, and not sent to any language model or image-generation service. When generating narration audio in your voice, the story text with the name already substituted is sent to our voice technology provider to produce the audio; that text contains no other child-identifying data and, by contract, must not be used for the provider's model training.

2.5 Subscription and Transaction Data

Subscription plan, subscription status and entitlements, and transaction identifiers. We never access or store your credit card number or full payment details — payment is handled by the Apple App Store. The Service offers a Free plan (featured stories + 1 voice) and a Family plan at NT$90/month (the full story library including bilingual English-learning stories + up to 4 voices, with festival-limited stories added from time to time). Billing is via the Apple App Store with automatic renewal; you can cancel anytime in your App Store account settings.

2.6 What We Do NOT Collect

3. Third-Party Services and Data Boundaries

We share data only with the following service providers (data processors), and only as necessary to provide the Service. Each provider may process data solely on our instructions and for the specified purposes — never for their own marketing or advertising.

3.1 MiniMax (Voice Processing: Voice Cloning and Text-to-Speech)

We use MiniMax's international service (API endpoint api.minimax.io). Purpose: creating a voice model from the voice sample you record, and converting story text to speech (TTS) with that model. Data shared: voice samples, the voice_id, and the story text to be narrated (with the child's name already substituted locally; containing no other child-identifying data). All calls to MiniMax are relayed through our server-side proxy (a Supabase Edge Function); the App itself holds no MiniMax key. Cross-border transfer: MiniMax's international service may process or store the above data outside Taiwan (see Section 8). We contractually require the provider not to use your data for model training. When you delete a voiceprint or your account, we also request that MiniMax delete the corresponding voice model.

3.2 Supabase (Cloud Backend)

Account authentication; storage of account data, voice_ids, and favorites/playback records; storage of voice samples in a private encrypted bucket; and hosting of our server-side proxy functions. Supabase processes data under our instructions and access controls (RLS) — only your account can access your data. Data is encrypted in transit (TLS) and at rest.

3.3 Apple / Google (Third-Party Sign-In, If You Choose)

If you sign in with Sign in with Apple or a Google account, they verify your identity and provide an account identifier (and email, depending on your authorization). No children's data is involved.

3.4 RevenueCat (Subscription Management)

Used to manage subscription status and entitlements, sync purchases across devices, and restore purchases. Only an anonymous/pseudonymous app user identifier and subscription status are shared — never your name, email content, or any children's data.

3.5 Apple App Store (Payments and Subscriptions)

Payment, automatic renewal, and cancellation are handled by Apple under its terms; we never access your payment instrument details.

We never sell your or your child's personal data, and we never use it for third-party advertising or cross-app tracking.

4. How We Use Data

PurposeData used
Creating/verifying your account, sign-inParent account data
Reading stories in your voiceVoice samples, voice_id, story text (substituted locally)
Keeping favorites, continue listening, improving recommendationsFavorites/playback records, preferences
Activating and managing subscriptions, restoring purchasesSubscription and transaction data
Customer support and important noticesParent account data
Preventing abuse, maintaining security, meeting legal obligationsData necessary as the case requires

We never use your data for: third-party advertising, cross-app tracking, sale to third parties, or training of AI providers' models.

5. Data Retention and Security

6. Your Rights (Including One-Tap Deletion)

As a parent/guardian, you may at any time:

Sensitive operations (creating a voice model, payment, deletion, etc.) are protected by a parental gate to prevent accidental activation by children.

7. Children's Privacy (Key Section)

8. International Data Transfers (Cross-Border)

We take reasonable measures to ensure that cross-border transfers comply with applicable data protection laws (including GDPR cross-border transfer requirements).

9. Changes to This Policy

We may update this Policy as features or regulations change. Material changes will be announced in the App or by other appropriate means, and the "Last updated" date on this page will be revised.

10. Contact Us