PRIVACY POLICY

隐私政策

本政策说明 BaoLong Lab 在网站访问、百度统计、手机号账号认证、恢复邮箱与账号找回、收藏、AI 图片生成、实时 AI 文本功能、上传内容、第三方技术服务与网络安全日志等场景中如何处理相关信息。

1. 运营主体与适用范围

BaoLong Lab 的运营主体为成都市成华区暴龙灵感装饰设计工作室(个体工商户)。本政策适用于 BaoLong Lab 网站当前公开提供的浏览、账号、工具与 AI 辅助功能。

2. 网站访问与百度统计

网站可能通过百度统计(Baidu Tongji)处理页面浏览、访问时间、访问来源、设备与浏览器环境以及由统计服务生成的访问标识,用于了解网站访问、页面表现与异常情况。

为了解哪些公开内容和工具更有帮助,BaoLong Lab 还可能记录有限的站内交互事件,例如打开灵感卡片、收藏或取消收藏、打开 Prompt 卡片、复制 Prompt 或进入图片工作流。自定义统计事件仅附带内容标识、页面或板块、操作类型、站点语言与视口类别等必要上下文。

为提供上述访问统计与站内交互分析,相关访问数据与统计事件会通过百度统计技术服务发送至百度服务器,并由百度统计按照其适用的隐私政策进行处理。你可以通过浏览器设置限制或清除 Cookie,或使用浏览器或扩展提供的内容拦截功能;具体效果取决于相应设置。百度统计对相关信息的收集、存储、使用及保护规则,请参阅《百度统计隐私政策》

BaoLong Lab 不会在上述自定义产品统计事件中加入 Prompt 正文、简历内容、自由输入文本、手机号、邮箱、上传文件内容、Cookie/session/auth token 或登录凭据。

3. 账号、手机号认证与恢复邮箱

当前公开账号入口使用中国大陆 +86 手机号和短信验证码。手机号用于账号注册与登录、基于移动电话号码的真实身份信息认证、账号安全、额度与防滥用控制,以及必要的安全审计。手机号将作为与账号绑定的身份信息,在账号存续及履行安全、合规义务所必要的期间保存;具体删除、注销或其他个人信息权利请求可通过本政策列明的联系渠道提出,法律法规另有要求的除外。

当前生产配置下,用户完成手机号登录后,服务器通常签发约 30 天有效的可撤销登录会话。用户主动退出、会话到期、账号恢复或手机号换绑,或因必要的账号安全控制导致会话被撤销时,登录状态可能提前失效。

历史内测期间形成的既有邮箱账号及相关账号数据,可能在系统迁移、兼容和账号连续性维护期间继续保留;这些历史邮箱账号当前不作为面向公众的登录方式。相关用户可通过本政策列明的联系渠道提出访问、更正、删除或账号注销请求,法律法规另有保存或处理要求的除外。

验证码发送和核验目前通过阿里云手机号认证(PNVS / DYPNSAPI)相关技术服务完成。为完成验证码发送、核验及必要的安全控制,手机号及认证请求所需的必要技术信息可能按照实际接口和配置传输至该技术服务。BaoLong Lab 不在本地保存明文短信验证码。该技术服务对相关信息的处理,以 BaoLong Lab 实际开通或签约信息、适用服务条款及技术配置为准。

为降低滥用和短信轰炸风险,BaoLong Lab 会对验证码发送和核验请求实施基于手机号经哈希处理后的标识、来源网络和站点级的频率限制;认证尝试记录不会以明文手机号作为认证主体保存。

BaoLong Lab 可提供可选的恢复邮箱功能。恢复邮箱仅用于账号安全、恢复邮箱验证、手机号无法使用时的账号找回以及必要的安全通知,不作为当前公开登录方式,也不用于设置或恢复邮箱密码。恢复邮箱在用户主动绑定并完成验证后与现有手机号账号关联;用户可在账号安全页面更换或移除。恢复邮箱地址将在账号存续且该功能保持绑定期间保存,或在用户更换、移除、注销账号及法律法规另有要求时按相应规则处理。

当用户通过恢复邮箱发起账号找回时,BaoLong Lab 会先核验此前已验证的恢复邮箱,再要求新的中国大陆 +86 手机号完成短信验证码核验;两项验证均通过后,才会将该现有账号换绑至新手机号,并使此前的正常登录会话失效。恢复邮箱验证链接、敏感操作授权和账号恢复授权采用短期、单次或受限用途的安全状态;服务端仅保存相应令牌的哈希值或必要状态,不保存可直接重放的明文验证令牌。

恢复邮箱验证、账号恢复邮件以及必要的账号安全通知目前通过阿里云 DirectMail 邮件发送服务完成。为完成邮件投递,恢复邮箱地址及与该次投递有关的必要技术信息可能传输至该邮件服务。BaoLong Lab 不会将恢复邮箱用于营销邮件。该邮件服务对相关信息的处理,以 BaoLong Lab 实际开通或签约信息、适用服务条款及技术配置为准。

4. AI 图片生成与上传内容

当你主动使用当前开放的 AI 图片工作流时,BaoLong Lab 可能处理提示词、生成参数、项目图、参考图片以及完成任务所需的技术信息,并通过服务端将完成任务所必需的数据发送给第三方 AI 技术服务。当前生产图片生成服务使用火山引擎方舟提供的 Seedream 图片生成能力。

当前生产配置中,生成结果在本站本地保留 7 天,生成任务记录本地保留 30 天。用户上传的项目图、参考图等生成输入仅在完成相应任务所必要的期间临时保存和处理;正常情况下,任务进入终态后相关上传输入及临时清单会被删除,不按生成结果的 7 天期限继续保存;因异常中断产生的临时残留,由系统清理和恢复机制处理。

如上传内容包含可识别自然人的肖像、隐私或其他个人信息,请确保具有合法处理依据,并仅提交完成本服务所必要的内容。

5. 实时 AI 文本功能

当你在 Prompt 工具主动执行 AI 优化,或在简历工具主动执行工作经历优化、按职位优化或全文翻译时,BaoLong Lab 会处理完成该功能所必要的 Prompt、简历文本、职位要求、输出语言/操作指令及必要技术信息,并通过服务端向当前使用的第三方 DeepSeek 模型服务发送完成请求所必要的文本。

这些信息用于完成对应文本功能、服务器端额度与安全控制、返回结果以及必要的故障排查和服务维护。请不要在 Prompt、简历、职位要求或其他自由输入中提交与任务无关的敏感个人信息、账号凭据或其他不必要信息。

本节实时 AI 文本功能不适用上文 AI 图片生成结果“7 天”与生成任务记录“30 天”的本地留存规则;如相关请求产生必要的网络与安全日志,则按本政策“网络运行与安全日志”一节处理。第三方模型服务自身的数据处理与留存规则,以其适用服务条款、合同、控制台配置及实际技术实现为准。

6. 灵感板 AI 辅助预生成内容

平面灵感、剖面灵感与综合灵感中的部分 Prompt 与创作参数由运营方使用 AI 辅助预先生成后静态发布。用户浏览灵感板、打开创作参数、复制 Prompt 或查看相关素材时,不会因这些动作实时向 Qwen 发送用户内容。

7. 收藏与本地存储

登录账号的收藏功能可在服务器端保存与账号关联的内容标识,用于恢复和管理收藏;相关记录包括账号范围、收藏所属板块、内容标识与创建时间等必要字段。本机历史收藏还可能通过浏览器本地存储保存,并在符合条件时由用户账号的收藏迁移/合并逻辑处理。

部分页面还可能使用 Cookie、本地存储或浏览器缓存保存语言偏好、工具状态与页面交互状态。

8. 网络运行与安全日志

为履行网络安全义务并支持系统运行维护、安全审计、故障与安全事件排查,以及依法配合有关主管部门,BaoLong Lab 会记录必要的网络运行状态和网络安全事件相关日志。相关网络日志按照适用法律法规要求留存不少于六个月。

网络/安全日志留存与 AI 图片生成结果 7 天、生成任务记录 30 天属于不同的数据处理与留存事项,不相互替代。

9. 第三方链接

本站可能包含淘宝、Pinterest、百度网盘、作品来源、素材来源、即梦、可灵及其他第三方网站链接。点击后将离开 BaoLong Lab,第三方如何处理信息以其自身规则为准。BaoLong Lab 当前不在本站处理淘宝订单、支付或收款,也不主动收集淘宝账号、订单与支付信息。

10. 个人信息权利与联系

如需提出账号注销、访问、更正、删除或其他个人信息权利请求,或对本政策、AI 技术处理与数据安全有疑问,可通过联系页面提出。法律法规另有保存或处理要求的除外。

11. 政策更新

本政策会随着网站真实功能、第三方技术服务或数据处理方式变化进行更新。更新后的版本会发布在本页面,并以页面显示内容为准。

最后更新:2026-09-11

PRIVACY POLICY

Privacy Policy

This Policy explains how BaoLong Lab handles information in connection with website visits, Baidu Analytics, mobile-number accounts, recovery email and account recovery, favorites, AI image generation, real-time AI text features, uploaded content, third-party technical services, and network-security logs.

1. Operator and Scope

BaoLong Lab is operated by 成都市成华区暴龙灵感装饰设计工作室(个体工商户). This Policy applies to the browsing, account, tool, and AI-assisted features currently made public on the BaoLong Lab website.

2. Website Visits and Baidu Analytics

The website may use Baidu Tongji to process page views, visit time, traffic source, device and browser environment, and access identifiers generated by the analytics service, in order to understand traffic, page performance, and abnormal behavior.

BaoLong Lab may also record limited on-site interaction events, such as opening an inspiration card, saving or removing a favorite, opening a Prompt card, copying a Prompt, or entering an image workflow. Custom product events include only necessary context such as content identifiers, page or board, action type, site language, and viewport class.

To provide the access analytics and on-site interaction analysis described above, relevant access data and analytics events may be transmitted through Baidu Analytics to Baidu servers and processed by Baidu Analytics under its applicable privacy policy. You may use browser settings to restrict or clear cookies, or use content-blocking features provided by your browser or extensions; the effect depends on those settings. For Baidu Analytics' rules on collecting, storing, using, and protecting such information, see the Baidu Analytics Privacy Policy.

BaoLong Lab does not add Prompt text, resume content, free-text input, phone numbers, email addresses, uploaded file contents, Cookie/session/auth tokens, or login credentials to these custom product analytics events.

3. Accounts, Mobile Authentication, and Recovery Email

The current public account flow uses mainland China +86 mobile numbers and SMS verification codes. The mobile number is used for account sign-up and sign-in, identity-information verification based on a mobile number, account security, quota and abuse controls, and necessary security auditing. The mobile number is retained as account-bound identity information for the period necessary while the account exists and to meet security and compliance obligations. Requests concerning deletion, account closure, or other personal-information rights may be made through the contact channels listed in this Policy, subject to applicable legal requirements.

Under the current production configuration, a successful mobile-number sign-in normally results in a revocable server-side session valid for about 30 days. The sign-in state may end earlier if the user signs out, the session expires, the account is recovered or the mobile number is rebound, or the session is revoked for necessary account-security controls.

Existing email-based accounts and related account data created during earlier internal testing may continue to be retained during system migration, compatibility maintenance, and account-continuity support; those legacy email accounts are not currently offered as a public sign-in method. Users associated with such accounts may request access, correction, deletion, or account closure through the contact channels listed in this Policy, except where retention or other processing is required by applicable law.

Verification-code delivery and checking are currently performed through Alibaba Cloud (Aliyun) mobile-number authentication (PNVS / DYPNSAPI) related technical services. To deliver and verify codes and apply necessary security controls, the mobile number and technical information necessary for the authentication request may be transmitted to that service according to the actual interface and configuration. BaoLong Lab does not locally store plaintext SMS verification codes. The service's processing of relevant information is governed by BaoLong Lab's actual activation or contracting information, applicable service terms, and technical configuration.

To reduce abuse and SMS-bombing risk, BaoLong Lab applies rate limits to verification-code delivery and checking based on a hashed identifier derived from the mobile number, source network, and site-level controls; authentication-attempt records do not store the raw mobile number as the authentication subject.

BaoLong Lab may provide an optional recovery-email feature. A recovery email is used only for account security, recovery-email verification, account recovery when the sign-in phone is unavailable, and necessary security notices. It is not a current public sign-in method and is not used to set or reset an email password. A recovery email is associated with the existing mobile-number account only after the user actively adds and verifies it, and it may later be changed or removed from Account Security. The address is retained while the account exists and the recovery channel remains configured, subject to change, removal, account closure, and applicable legal requirements.

When account recovery is started through a recovery email, BaoLong Lab first verifies the previously verified recovery email and then requires SMS verification of a new mainland China +86 mobile number. Only after both factors succeed is the existing account rebound to the new mobile number, and prior normal sign-in sessions are invalidated. Recovery-email links, sensitive-action grants, and account-recovery authorizations use short-lived, single-use, or purpose-limited security state. The server stores the relevant token hash or necessary state rather than replayable plaintext verification tokens.

Recovery-email verification, account-recovery email, and necessary account-security notices are currently delivered through Alibaba Cloud DirectMail. To complete delivery, the recovery email address and technical information necessary for the relevant mailing may be transmitted to that email service. BaoLong Lab does not use the recovery email for marketing mail. The provider's processing of relevant information is governed by BaoLong Lab's actual activation or contracting information, applicable service terms, and technical configuration.

4. AI Image Generation and Uploaded Content

When you actively use an available AI image workflow, BaoLong Lab may process prompts, generation parameters, project images, reference images, and technical information necessary to complete the task, and send the data necessary for the task from its server to a third-party AI technology service. The current production image-generation service uses Seedream image-generation capabilities provided through Volcengine Ark.

Under the current production configuration, generated results are retained locally for 7 days and generation-job records for 30 days. Uploaded project images, reference images, and other generation inputs are stored and processed only temporarily for the period necessary to complete the task; under normal operation they and temporary manifests are deleted after the job reaches a terminal state and are not retained under the seven-day generated-result period. Temporary remnants caused by abnormal interruption are handled by system cleanup and recovery mechanisms.

If uploaded content contains an identifiable person's portrait, privacy, or other personal information, make sure you have a lawful basis and submit only content necessary to use the service.

5. Real-Time AI Text Features

When you actively run AI optimization in the Prompt Tool, or experience optimization, job-targeted optimization, or full-text translation in the Resume Tool, BaoLong Lab processes the Prompt, resume text, job requirements, output-language/action instructions, and technical information necessary for the function, and sends the text necessary to complete the request from its server to the current third-party DeepSeek model service.

This information is used to perform the requested text function, apply server-side quota and safety controls, return the result, and support necessary troubleshooting and service maintenance. Do not include unrelated sensitive personal information, account credentials, or other unnecessary information in Prompts, resumes, job requirements, or free-text inputs.

The 7-day generated-result and 30-day generation-job local-retention periods described above for AI image generation do not apply to these real-time text features. Where a request produces necessary network or security logs, those logs are handled under the Network Operation and Security Logs section below. The third-party model service's own processing and retention practices are governed by its applicable terms, contracts, console settings, and actual technical implementation.

6. AI-Assisted Pre-Generated Inspiration Content

Some prompts and creative parameters on the Plan / Section / Mixed Inspiration Boards are generated in advance by the operator with AI assistance and published as static content. Browsing the boards, opening creative parameters, copying a Prompt, or viewing related assets does not, by itself, send user content to Qwen in real time.

7. Favorites and Local Storage

For signed-in accounts, favorites may be stored server-side as content identifiers associated with the account so favorites can be managed and restored. Necessary fields include account scope, the board or content category of the favorite, content identifier, and creation time. Historical local favorites may also be stored in browser local storage and handled by the account-favorites migration/merge flow where applicable.

Some pages may also use cookies, local storage, or browser cache for language preference, tool state, and page-interaction state.

8. Network Operation and Security Logs

To meet applicable cybersecurity obligations and support system operations, security auditing, troubleshooting, security-incident investigation, and lawful cooperation with competent authorities, BaoLong Lab records necessary network-operation and cybersecurity-event logs. Such logs are retained for at least six months as required by applicable laws and regulations.

Network/security-log retention is separate from the 7-day generated-result and 30-day generation-job retention described for AI image generation.

9. Third-Party Links

The website may link to Taobao, Pinterest, Baidu Netdisk, source references, asset sources, Jimeng, Kling, and other third-party websites. Once you follow those links, the third party's own rules govern its data handling. BaoLong Lab does not currently process Taobao orders or payments on this website and does not actively collect Taobao account, order, or payment information.

10. Personal-Information Rights and Contact

For account closure, access, correction, deletion, or other personal-information rights requests, or questions about this Policy, AI technical processing, or data security, use the Contact page, subject to any retention or processing required by applicable law.

11. Policy Updates

This Policy may be updated as the website's actual features, third-party technical services, or data-processing practices change. Updated content will be published on this page and will apply as displayed.

Last updated: 2026-09-11