Shelf 用于跨设备整理和同步文字、文件与附件。本说明适用于 shareshelf.cc.cd 提供的网页与 Google Drive 授权服务。选择自建服务时,还需查看该服务运营者的隐私说明。
Google Drive 连接仅申请 openid 与 drive.file:读取账号标识,用于区分各账号的独立空间;管理 Shelf 创建或由你明确授予访问权的文件,用于你发起的上传、同步、下载和删除。我们使用账号标识的哈希值,不申请整盘访问权限。Shelf 不接收 Google 登录密码,请只在 Google 官方页面输入。
Google 文件存入你自己的网盘中独立的 Shelf 目录。原 Cloudflare 文件与原本地测试空间保留,不自动迁移或删除。百度网盘尚未开放。
Google 空间中的文字、文件名和附件内容在设备上加密后上传;空间密码与解锁密钥不提交给授权服务。运行期间保留解锁密钥,遗忘空间密码无法恢复内容。原 Shelf / Cloudflare 空间不具有同样的整空间客户端加密,请勿混淆两种存储方式。
Cloudflare 承载网页与授权接口,转发 Google 密文;服务端使用独立密钥加密保存 Google 授权凭据、账号标识哈希、Shelf 会话及上传进度。服务会使用授权凭据访问网盘并刷新授权,运营者在技术上能够使用这些凭据,因此客户端加密不能保证密文永不被删除或替换。Google 与服务可能观察到大小、时间、数量和网络信息。
为避免恶意请求影响登录,服务保存加密的、带服务密钥散列的请求来源标识和授权次数,限流窗口为 5 分钟。会话通常有效 7 天,授权流程有效 5 分钟;到期后不再有效,在后续状态写入时从服务记录中清理,不承诺到期即物理擦除。我们未开启 Worker 请求日志,但网络服务提供者仍按各自政策处理网络与运行信息。
Google 授权凭据与账号标识哈希持续保留,直到处理删除请求;仅退出 Shelf 会撤销当前 Shelf 会话、清除运行中的解锁密钥,不会自动删除服务端账号或 Google refresh token。撤销 Google 授权也不会自动删除 Shelf 服务记录。
你可以在 Google 第三方连接中移除 Shelf,阻止继续访问;自行删除 Google Drive 中的 Shelf 目录;并通过下方支持邮箱请求删除服务端账号与授权记录。处理删除请求时会核验账号归属,请不要发送密码或令牌。
桌面端默认按设置清理闲置 7 天的已同步缓存,云端保留期限默认 30 天;清理由客户端运行时执行,可在设置中调整,云端删除会影响所有设备。这不是到期即执行的服务器定时承诺。网盘中已删除文件的回收站期限由 Google 决定,请为重要文件保留独立备份。
设备上的缓存、预览、导出、下载与剪贴板可能包含明文,受设备及目标应用的保护措施约束。退出不会保证导出文件或所有本地缓存被擦除。
Google 用户数据仅用于提供用户主动选择的 Shelf 存储与同步功能,不出售,不用于广告或训练通用人工智能模型,不安排人员主动查看用户文件内容。Shelf 对从 Google API 收到的信息的使用与向其他应用的传输遵循 Google API Services User Data Policy,包括其 Limited Use 要求。
Shelf uses Google account identifiers and the non-sensitive openid and drive.file scopes to provide user-requested file storage and synchronization. Content and filenames are encrypted on the device before upload to your Google Drive. Cloudflare hosts the app and authorization service; credentials and service records are encrypted at rest. Logout removes the current Shelf session, not the stored account or Google grant. Revoke access in your Google account and contact support to request deletion of server-side authorization records. Google user data is not sold, used for advertising or used to train general-purpose AI. Shelf's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
支持与数据删除请求:zhaotian5868@gmail.com