Kazenagi 風凪
Privacy Terms Home Portal

KAZENAGI HOME

Privacy Policy

This notice explains how Kazenagi handles personal data when you use kazenagi.com, the Home Portal, Google Sign-In, Google Home Cloud-to-cloud and connected Kazenagi Link services.

Effective
15 August 2026
Last updated
4 September 2026
Contact
[email protected]
English繁體中文

1. Who controls your data

Kazenagi Home is operated by the Kazenagi project operator (“Kazenagi”, “we”, “us”). For privacy questions or requests, contact [email protected]. This policy applies to the public website, Home Portal, central cloud service and connected Kazenagi Link devices.

2. Data we collect

Account and identity data

  • Your email address, display name, internal account identifier, email-verification state and a securely hashed password when you use email sign-in.
  • If you use or link Google Sign-In: Google’s stable account subject identifier (sub), verified email address and basic name information needed to create or connect your Kazenagi account. We do not request access to Gmail, Google Drive, contacts or calendars, and we do not store a Google password or Google API refresh token.
  • Home invitations, membership and role information, room associations, linked sign-in methods and account-security events.

Home, device and environmental data

  • Home and room names, time zone, an address or place search you submit, and the resulting latitude and longitude used for local weather and opt-in location-aware features.
  • Device identifiers, names, model/profile information, connection state, firmware and operational status.
  • Air-conditioner state, target settings, schedules, manual overrides, dry-out jobs, commands, confirmations and execution results.
  • Time-stamped environmental readings reported by a connected device, such as temperature and, where supported, humidity and air pressure, together with the operating mode needed to present history.

Technical and communications data

If you opt into Geofencing in the Android App, the phone uses background location even when the App is closed or not in use to determine whether it is near the selected Home. It sends only home, away or unknown, an installation identifier, a sequence counter and a report time to Kazenagi. We do not receive the phone's GPS coordinates or a route history. Google Play services supplies the on-device location/geofence service under Google's terms. The latest report replaces the previous report; room-level status and resulting automation actions may be visible to authorised Home members. Stopping sharing, signing out or revoking location permission stops new location observations; old reports expire to unknown. You can also stop your own registered phone from Home settings.

For an App- or Web-initiated remote Wi-Fi update, that client encrypts the Wi-Fi name, password and optional IP settings for the selected controller. Central relays the encrypted message and records the job outcome; it does not decrypt or store the Wi-Fi password in plaintext. The Web client uses a separate browser-generated maintenance key that is not exportable; signing out revokes its server binding and removes the local key. Encrypted job payloads are cleared when the job finishes or expires. Outcome metadata follows the configured activity-record retention period. The controller separately reports its current network diagnostics, such as Wi-Fi name and IP address, to authorised Home members.

  • Essential session records, authentication events, request times and limited infrastructure logs used to operate, diagnose and secure the service. Hosting or network infrastructure may process an IP address and browser/network metadata.
  • Verification, password-reset, email-change, invitation and support communications, including delivery status.
  • Browser preferences stored locally for theme, language and the last selected Home.

3. How and why we use data

We use the data above to provide the service you request: create and secure accounts; authenticate users; organise Homes, rooms, people and devices; display live and historical status; send and confirm controls; run cloud schedules and dry-out jobs; provide local weather; deliver invitations and account emails; provide support; prevent abuse; diagnose faults; and comply with law.

Where applicable, processing is based on performing our service agreement with you, your consent or deliberate request (including choosing Google Sign-In or entering a location), our legitimate interests in operating and securing the service, and compliance with legal obligations. We do not use personal data for third-party advertising, sell it, or make decisions producing legal or similarly significant effects through profiling.

4. Google user data

Google Sign-In

Google Identity Services is used only to authenticate you and, when you choose, link a Google identity to an existing Kazenagi account. A linked identity is matched by Google’s stable sub, not merely by email. Google-derived data is used only for account access, security and the user-facing features described here. It is not sold, used for advertising, or shared with data brokers. If our use of Google user data changes materially, we will update this policy and seek any consent required before using it for the new purpose.

Google Home Cloud-to-cloud

If you explicitly link Kazenagi to Google Home, Kazenagi and Google exchange only the information needed to discover, display, control and keep your selected devices up to date. This may include:

  • an opaque Kazenagi agent-user identifier, account-link status, granted scope and the Home/device selections that you control;
  • short-lived authorization codes and Kazenagi OAuth access and refresh credentials exchanged to complete and maintain the link; Kazenagi stores one-way hashes rather than the raw credential values;
  • selected device identifiers, names, room assignments, device types, traits, capabilities, device model and firmware version;
  • confirmed current online availability, operating mode, target temperature, current room temperature, optional current humidity and fan setting used for Google Home QUERY and Report State;
  • commands sent through Google Home and their durable acceptance or execution status used for EXECUTE; and
  • limited request, synchronization, delivery and error metadata needed for SYNC, Request Sync, Report State, unlinking, security, retry and support.

Google Home linking does not give Google your Kazenagi password or Kazenagi’s Google service-account private key, nor access to your Gmail, Google Drive, contacts or calendars. We do not send unselected devices, your precise Home address or historical environmental readings to Google Home. Google processes information it receives under Google’s own privacy terms. Kazenagi uses this exchange only to provide the Google Home features you request, protect the link and diagnose delivery.

5. Cookies and local storage

Kazenagi uses a strictly necessary, secure HTTP-only refresh-session cookie to keep you signed in. Short-lived access credentials are held in browser memory. Theme, language and last-Home preferences are stored in local storage. If you use Web remote Wi-Fi maintenance, the browser stores a non-exportable device-bound maintenance key in IndexedDB and Central stores only its public-key binding; signing out revokes and removes it. We currently do not use advertising cookies or third-party behavioural analytics. You can clear browser storage, but doing so may sign you out, reset preferences or require a new maintenance identity.

6. When data is shared

We disclose only what is reasonably necessary to:

  • other authorised members of the same Home, according to their role;
  • Google Identity Services for the sign-in flow you initiate;
  • Google Home and HomeGraph when you explicitly link the integration, limited to the selected-device, confirmed-state, command and synchronization information described in section 4;
  • the configured email-delivery provider (such as Mailgun or an encrypted SMTP provider) to send transactional messages;
  • Open-Meteo and Nominatim/OpenStreetMap services to resolve a location query and retrieve weather using a location or coordinates;
  • hosting, database, storage, network and security providers acting for us under appropriate safeguards;
  • authorities or other parties when required by law, needed to protect rights and safety, or involved in a reorganisation with appropriate notice and safeguards.

Service providers may process data in countries outside your own. Where transfer rules apply, we use an appropriate lawful mechanism and limit the data transferred to what the relevant service needs.

7. Retention and deletion

Account, Home and device data is generally kept while the relevant account or Home remains active. Authentication audit events are normally retained for up to 90 days. Expired or revoked refresh-session records are normally removed after a further 7 days. Expired verification, reset and pairing credentials are normally removed after a further 30 days, and expired Home invitations after a further 365 days. Environmental history is normally retained for up to 365 days: recent readings remain as individual reports, older readings become hourly and then daily summaries that retain the real minimum, maximum, average and sample count for each metric. Completed command, schedule, dry-out and OTA activity is retained for up to 730 days; privileged administration, OTA and cloud-entitlement audit evidence for up to seven years. Deletion and compaction run in bounded batches and remain subject to backup rotation and legal preservation requirements.

You can delete your Kazenagi account from Settings after transferring or deleting any Home for which you are the sole owner. Deletion removes active sign-in identities, ordinary sessions and memberships, revokes active credentials, and de-identifies remaining account/audit references where the service supports that lifecycle. Residual copies may remain temporarily in protected backups until normal rotation and will not be used for ordinary service operation.

For Google Home, revoked account-link, Home-grant and device-selection metadata and one-way hashes of revoked OAuth tokens may be retained to enforce revocation, prevent token reuse, preserve ownership and security history, and support safe reauthorization. Completed or superseded Google Home delivery records are normally retained for 30 days; dead-letter delivery records and agent-user deletion audit tombstones are normally retained for up to 730 days; related cloud audit events are normally retained for up to seven years. Related expired or consumed authorization-code records containing a one-way code hash, user ID, redirect URI, granted scope, issued/expiry/consumed times and the selected Home/device consent snapshot, and revoked link, grant, selection and token-hash records currently have no shorter automatic deletion period. They may remain after unlinking or Kazenagi account deletion, subject to access controls, backup rotation and applicable legal deletion requirements.

8. Your choices and rights

The Portal and App let you update your name and email, change or set a password, download a machine-readable account export including accessible recent and summarised environmental history, and delete your account. You can choose not to use Google Sign-In and use email sign-in instead. To request access, correction, deletion, restriction, portability, objection, or help unlinking Google where applicable, email [email protected]. We may need to verify your identity and must protect other Home members’ rights. You may also complain to the data-protection authority that applies to you.

You can globally unlink Kazenagi in the Google Home app. This revokes the entire Google Home account link and its active Kazenagi OAuth credentials for all Homes under that link, and stops future device synchronization, state reporting and commands. In Kazenagi settings, you can instead disconnect a single Home. That revokes only that Home’s grant and device selections; if other Homes remain authorised, the overall account link and its credentials remain active for them. Authorization-code consent snapshots, revoked metadata, token hashes, delivery records and audit records may remain as described in section 7. To manage information already held by Google, use the controls provided in your Google Account and Google Home.

9. Security

We use measures designed to protect data, including HTTPS/WSS transport, hashed passwords and credentials, short-lived signed access tokens, rotating HTTP-only refresh sessions, role-based Home permissions and encrypted storage for configured email-provider secrets. No system is completely secure; please use a unique password, protect your devices and notify us if you suspect unauthorised access.

10. Children

Kazenagi is not directed to children under 13, or below any higher minimum age required where they live. A minor may use a Home only with the permission and supervision required by applicable law. Do not submit a child’s personal data unless you are authorised to do so.

11. Changes

We may update this policy as the service, providers or law changes. We will change the “Last updated” date and provide additional notice when a material change requires it.

繁體中文版本

1. 誰負責處理你的資料

Kazenagi Home 由 Kazenagi 專案營運者營運(下稱「Kazenagi」或「我們」)。如有私隱查詢或資料權利要求,請電郵至 [email protected]。本政策適用於公開網站、Home Portal、中央雲端服務及已連接的 Kazenagi Link 裝置。

2. 我們收集的資料

帳戶及身份資料

  • 你的電郵地址、顯示名稱、內部帳戶識別碼、電郵驗證狀態;如使用電郵登入,亦包括經安全雜湊的密碼。
  • 如你使用或連結 Google 登入:Google 的穩定帳戶 subject 識別碼(sub)、已驗證電郵地址,以及建立或連結 Kazenagi 帳戶所需的基本名稱資料。我們不會要求 Gmail、Google Drive、聯絡人或日曆權限,亦不會保存 Google 密碼或 Google API refresh token。
  • Home 邀請、成員資格及角色資料、房間關聯、已連結登入方式及帳戶安全事件。

Home、裝置及環境資料

  • Home 及房間名稱、時區、你提交的地址或地點搜尋,以及用於當地天氣和自願啟用之到家/離家功能的經緯度。
  • 裝置識別碼、名稱、型號/profile 資料、連線狀態、韌體及運作狀態。
  • 冷氣狀態、目標設定、排程、手動 override、乾燥工作、指令、確認及執行結果。
  • 已連接裝置實際回報並附有時間的環境讀數,例如溫度;如裝置支援,亦包括濕度、氣壓,以及顯示歷史所需的運轉模式。

技術及通訊資料

如你在 Android App 自願啟用「到家與離家」,手機會在 App 關閉或未使用時於背景使用位置資料,判斷是否位於指定家庭附近。手機只向 Kazenagi 回報在家、離家或未知狀態、安裝識別碼、順序編號及回報時間;我們不會收到手機 GPS 座標或行蹤路線。手機上的位置及地理圍欄服務由 Google Play 服務提供,適用 Google 的相關條款。最新狀態會取代上一筆;獲授權家庭成員可查看房間層面的判斷結果及所產生的自動化操作。停用分享、登出或撤銷位置權限會停止新的位置觀測;舊資料過期後視為未知。你亦可在家庭設定停止自己已登記手機的回報。

透過 App 或 Web 發起遠端 Wi-Fi 更新時,該用戶端會為指定控制器加密 Wi-Fi 名稱、密碼及選用的 IP 設定。中央伺服器只轉送加密訊息並記錄工作結果,不會解密或以明文保存 Wi-Fi 密碼。Web 會使用由瀏覽器另行產生、不可匯出的維護金鑰;登出時會撤銷伺服器綁定並清除本機金鑰。加密工作內容會在完成或逾時後清除;結果紀錄依系統所設定的活動資料保留期限處理。控制器會另行向獲授權家庭成員回報目前 Wi-Fi 名稱、IP 位址等網絡診斷資料。

  • 營運、診斷及保護服務所需的必要 session 紀錄、認證事件、要求時間及有限基建紀錄。託管或網絡基建可能會處理 IP 地址及瀏覽器/網絡 metadata。
  • 驗證、重設密碼、更改電郵、邀請及支援通訊,包括投遞狀態。
  • 保存在瀏覽器本機的顯示模式、語言及最後選擇 Home 偏好。

3. 我們使用資料的方法及原因

我們使用上述資料提供你要求的服務:建立及保護帳戶;驗證用戶;管理 Home、房間、成員及裝置;顯示即時與歷史狀態;發送及確認控制指令;執行雲端排程和乾燥工作;提供當地天氣;寄出邀請及帳戶郵件;提供支援;防止濫用;排解故障;以及遵守法律。

在適用情況下,處理依據包括履行與你的服務協議、你的同意或主動要求(包括選擇 Google 登入或輸入地點)、我們營運及保護服務的正當利益,以及履行法律責任。我們不會將個人資料用於第三方廣告、不會出售個人資料,亦不會透過 profiling 作出對你產生法律或類似重大影響的決定。

4. Google 使用者資料

Google 登入

Google Identity Services 只用於驗證你的身份,以及在你選擇時將 Google 身份連結至現有 Kazenagi 帳戶。已連結身份按 Google 穩定的 sub 配對,而不是單靠電郵。Google 衍生資料只用於帳戶存取、安全及本政策所述的用戶功能,不會出售、用於廣告或與資料經紀分享。如我們使用 Google 使用者資料的方式有重大改變,我們會更新本政策,並在將資料用於新用途前取得任何所需同意。

Google Home Cloud-to-cloud

如你明確把 Kazenagi 連結至 Google Home,Kazenagi 與 Google 只會交換搜尋、顯示、控制及保持你所選裝置資料最新所需的資料,可能包括:

  • Kazenagi 產生的不透明 agent-user 識別碼、帳戶連結狀態、已授予 scope,以及由你控制的 Home/裝置選擇;
  • 完成及維持連結時交換的短效 authorization code,以及 Kazenagi OAuth access/refresh credential;Kazenagi 只保存單向雜湊,而不保存原始 credential 值;
  • 已選裝置的識別碼、名稱、房間配置、裝置類型、trait、能力、裝置型號及韌體版本;
  • Google Home QUERY 及 Report State 所需、經裝置確認的目前連線狀態、運轉模式、目標溫度、目前室溫、選擇性目前濕度及風速設定;
  • 經 Google Home 發出的指令,以及 EXECUTE 所需的可靠接收或執行狀態;以及
  • SYNC、Request Sync、Report State、解除連結、安全、重試及支援所需的有限要求、同步、投遞及錯誤 metadata。

連結 Google Home 不會讓 Google 取得你的 Kazenagi 密碼或 Kazenagi 的 Google service-account 私密金鑰,亦不會讓 Google 存取你的 Gmail、Google Drive、聯絡人或日曆。我們不會向 Google Home 傳送未選裝置、你的 Home 精確地址或歷史環境讀數。Google 會按照其私隱條款處理其收到的資料。Kazenagi 只會使用上述交換來提供你所要求的 Google Home 功能、保護連結及診斷投遞。

5. Cookie 及本機儲存

Kazenagi 使用一個嚴格必要、Secure、HTTP-only 的 refresh-session cookie 維持登入。短效 access credential 保留在瀏覽器記憶體。顯示模式、語言及最後選擇 Home 偏好保存在 local storage。如你使用 Web 遠端 Wi-Fi 維護,瀏覽器會在 IndexedDB 保存不可匯出、綁定該裝置的維護金鑰,中央伺服器只保存其公鑰綁定;登出時會撤銷並清除該金鑰。目前沒有廣告 cookie 或第三方行為分析。你可以清除瀏覽器儲存,但此舉可能令你登出、重設偏好,或需要重新建立維護身份。

6. 資料分享情況

我們只會在合理必要範圍內向以下對象披露資料:

  • 同一 Home 內按角色獲授權的其他成員;
  • 處理你所發起登入流程的 Google Identity Services;
  • 在你明確連結 integration 時的 Google Home 及 HomeGraph,並只限第 4 節所述的已選裝置、確認狀態、指令及同步資料;
  • 寄送交易訊息的已設定電郵投遞供應商,例如 Mailgun 或加密 SMTP 供應商;
  • 使用地點或座標解析地點搜尋及取得天氣的 Open-Meteo 和 Nominatim/OpenStreetMap 服務;
  • 在適當保障下代表我們處理資料的託管、資料庫、儲存、網絡及安全供應商;
  • 法律要求、保障權利與安全所需,或在提供適當通知及保障下參與重組的主管機關或其他人士。

服務供應商可能在你所在國家/地區以外處理資料。適用跨境傳輸規則時,我們會採用適當合法機制,並將傳送資料限制於相關服務所需範圍。

7. 保存及刪除

帳戶、Home 和裝置資料一般會在相關帳戶或 Home 維持使用期間保存。認證稽核事件通常最多保存 90 日;已過期或撤銷的 refresh-session 紀錄通常在額外 7 日後移除。已過期的驗證、重設及配對憑證通常在額外 30 日後移除;已過期 Home 邀請通常在額外 365 日後移除。環境歷史通常最多保存 365 日:近期讀數保留為個別回報,較舊讀數改為每小時、再改為每日摘要,並保存各項讀數的真實最低、最高、平均及樣本數。已完成的指令、排程、乾燥關機及 OTA 活動最多保存 730 日;特權管理、OTA 及雲端權益稽核證據最多保存七年。刪除及壓縮會以有上限的批次執行,並仍受備份輪替及法律保存要求限制。

如你是任何 Home 的唯一 owner,須先移交或刪除該 Home,然後便可在「設定」刪除 Kazenagi 帳戶。刪除會移除有效登入身份、一般 session 及成員資格,撤銷有效憑證,並在服務資料生命週期支援的情況下將剩餘帳戶/稽核參照去識別化。受保護備份可能暫時保留副本直至正常輪替,但不會用於日常服務。

就 Google Home 而言,已撤銷的帳戶連結、Home grant、裝置選擇 metadata,以及已撤銷 OAuth token 的單向雜湊可能會保留,用以執行撤銷、防止 token 被重用、保存擁有權與安全歷史,以及支援安全重新授權。已完成或被取代的 Google Home 投遞紀錄通常保存 30 日;dead-letter 投遞紀錄及 agent-user deletion 稽核 tombstone 通常最多保存 730 日;相關 cloud audit event 通常最多保存七年。已過期或已使用的 authorization-code 紀錄(包括單向 code 雜湊、user ID、redirect URI、已授予 scope、發出/到期/使用時間,以及已選 Home/裝置 consent snapshot),以及已撤銷的 link、grant、selection 和 token-hash 紀錄目前沒有更短的自動刪除期限。這些資料可能在解除連結或刪除 Kazenagi 帳戶後仍然保留,但須受存取控制、備份輪替及適用法律刪除要求限制。

8. 你的選擇與權利

Portal 及 App 提供更改名稱及電郵、設定或更改密碼、下載包含可存取近期及摘要環境歷史的機器可讀帳戶資料,以及刪除帳戶。你可以不使用 Google 登入,改用電郵登入。如要申請查閱、更正、刪除、限制、可攜、反對處理,或在適用情況下協助解除 Google 連結,請電郵至 [email protected]。我們可能需要核實你的身份,亦須保障其他 Home 成員的權利。你亦可向適用於你的資料保障監管機構投訴。

你可以在 Google Home app 全域解除 Kazenagi 連結。此操作會撤銷整個 Google Home 帳戶連結,以及該連結下所有 Home 的有效 Kazenagi OAuth 憑證,並停止日後的裝置同步、狀態回報及指令。你亦可以改為在 Kazenagi 設定中只中斷單一 Home;此操作只會撤銷該 Home 的 grant 及裝置選擇。如仍有其他已授權 Home,整體帳戶連結及其憑證會繼續對該等 Home 有效。Authorization-code consent snapshot、已撤銷 metadata、token 雜湊、投遞及稽核紀錄可能按第 7 節所述保留。如要管理 Google 已持有的資料,請使用 Google 帳戶及 Google Home 提供的控制。

9. 安全

我們使用旨在保障資料的措施,包括 HTTPS/WSS 傳輸、密碼及憑證雜湊、短效簽署 access token、輪替 HTTP-only refresh session、按角色劃分的 Home 權限,以及加密保存已設定郵件供應商密鑰。任何系統均不能保證絕對安全;請使用獨立密碼、保護你的裝置,並在懷疑未經授權存取時通知我們。

10. 兒童

Kazenagi 並非以 13 歲以下兒童,或未達其居住地所規定更高最低年齡的人士為對象。未成年人只可在適用法律要求的許可及監督下使用 Home。除非你獲授權,否則請勿提交兒童的個人資料。

11. 變更

我們可能因服務、供應商或法律改變而更新本政策。我們會更改「最後更新」日期,並在重大改變需要額外通知時提供通知。

© KazenagiHomeTerms of ServiceContact