Privacy Policy
隐私政策
Effective date · 生效日期:2026-09-07
1.Who we are我们是谁
crabai is an operations workspace that Open Media INC. (Open Media) provides to the restaurants it works with. Accounts are opened by an administrator; there is no self-serve sign-up. This policy covers the crabai workspace and the publishing tools inside it.
crabai 是 Open Media INC.(Open Media)为合作餐饮门店提供的运营工作台。 账号由管理员开通,不提供自助注册。本政策覆盖 crabai 工作台及其中的发布工具。
2.What we collect我们收集什么
- Account — your sign-in email. Passwords are stored only as a salted hash, never in plain text.
- Conversations — the messages you send and the assistant’s replies, kept so your history is there when you come back.
- Store business data — orders, reviews, menus and similar records from the store systems and merchant platform accounts you have authorised us to connect.
- Connected platform data — see section 4.
账号信息(登录邮箱,密码只存加盐哈希)、对话内容、你已授权接入的门店经营数据, 以及已连接的社媒平台数据(见第 4 节)。
3.How we use it我们怎么用
To show you your own store’s data, to draft replies and social posts you asked for, and to publish those posts to the accounts you connected. We do not sell your information, we do not rent it, and we do not use it to target advertising.
用来展示你自己门店的数据、按你的要求起草回复与帖子、把帖子发到你连接的账号。 我们不出售、不出租你的信息,也不用它做广告定向。
4.TikTok dataTikTok 数据
When you connect a TikTok account, you authorise crabai through TikTok’s own login screen and you choose which permissions to grant. Here is exactly what we receive, where it lives, and how it goes away.
What we obtain
- Account identifiers and profile — your TikTok open ID, display name and profile picture, so the workspace can show which account a post will go out from.
- Creator posting settings — the privacy levels available to you, whether comments, Duet and Stitch are allowed on your account, your maximum video length, and how many posts you have made today. These are read from TikTok each time the posting screen opens and are shown to you before you post.
- Publishing results — the publish identifier and status TikTok returns for each post we send on your behalf.
- Access and refresh tokens — the credentials TikTok issues so we can act on your behalf until you disconnect.
We do not read your inbox, your followers, your analytics, or anyone else’s content.
How we store it
- Tokens are encrypted at rest, held on our servers only, and never sent to a browser or to any third party.
- Creator posting settings are not kept — they are fetched live for the screen you are looking at and discarded when you leave it.
- We keep a record of what was published, when, and by which account, so you can see your own posting history and so we can investigate failures.
How it is deleted
- You can disconnect a TikTok account from the workspace at any time. On disconnect we revoke the token with TikTok and delete our copy of it and of the profile fields immediately.
- Publishing records are kept for up to 12 months and then deleted. You can ask us to delete them sooner.
- To have everything removed, email info@openmediaads.com. We act on the request within 30 days and confirm when it is done.
连接 TikTok 时你在 TikTok 自己的授权页上选择给哪些权限。我们取得的是:账号标识与 昵称头像、创作者发帖设置(可选隐私级别、是否允许评论/合拍/拼接、最长时长、当天已发条数,每次打开发帖页都实时重新拉取并展示给你)、每条发布的结果与 publish id、 以及访问与刷新令牌。我们不读你的私信、粉丝、后台分析,也不读别人的内容。 令牌加密存储、只留在服务端;创作者设置不落库,看完即弃;发布记录保留至多 12 个月。 你随时可以在工作台断开连接 —— 断开时我们会向 TikTok 撤销令牌并立即删除本地副本。 要彻底删除,发邮件到 info@openmediaads.com,我们在 30 天内处理并回复确认。
5.Other connected platforms其他已连接平台
Google Business Profile and Meta (Facebook / Instagram) accounts work the same way: you authorise them, we obtain only what is needed to read your reviews and publish the posts you approve, tokens are encrypted at rest, and disconnecting revokes and deletes them.
Google 商家资料与 Meta(Facebook / Instagram)同理:由你授权,只取读评价和发你已确认的帖子 所必需的部分,令牌加密存储,断开即撤销并删除。
6.Who else sees it还有谁能看到
Our hosting and database providers, and the large-language-model provider that generates the drafts you ask for — conversation content is sent there to produce a reply. That is the whole list. We do not share your data with advertisers or data brokers.
托管与数据库服务商,以及生成草稿所用的大模型服务商(对话内容会发过去以生成回复)。 就这些。不与广告商或数据经纪商共享。
7.Security安全
Access requires an administrator-issued account. Platform credentials are encrypted at rest and are only ever used server-side. No method of transmission or storage is perfectly secure, and we do not claim otherwise.
需管理员开通的账号才能访问;平台凭据加密存储且只在服务端使用。 没有任何传输或存储方式是绝对安全的,我们不作此承诺。
8.Your choices你的选择
You can disconnect any platform account, ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Contact your Open Media representative or email info@openmediaads.com. Step-by-step instructions are on the Data Deletion page.
你可以随时断开任一平台账号,也可以要求查阅、更正或删除我们持有的你的信息。 联系你的 Open Media 对接人,或发邮件到 info@openmediaads.com;具体怎么做见「数据删除」页。
9.Children未成年人
crabai is a business tool and is not directed to anyone under 18.
crabai 是面向商户的工具,不面向 18 岁以下人群。
10.Changes政策变更
We may update this policy. The effective date at the top always reflects the current version.
本政策可能更新,顶部生效日期即当前版本。