社交舞會照片協尋 隱私權政策
最後更新:2026-09-27
社交舞會照片協尋(Social Dancer Find,以下稱「這個工具」)是 Arthur 做給舞蹈社群用的免費小工具,讓你在活動照片裡找到自己。不收費、不是公司,就是希望大家不用再一張一張翻相簿找照片。這份文件想用你聽得懂的方式,說清楚這個工具會碰到你的哪些資料、怎麼處理、可以怎麼要求刪除。
1你上傳來查詢的照片
查詢時可以在上傳頁面選擇兩種辨識方式,差別在「運算發生在哪裡」:
- 瀏覽器端辨識(上傳頁面可手動開啟,目前預設關閉——還在驗證中的實驗性功能):整段運算都在你自己的瀏覽器裡完成,你的照片完全不會上傳到我們的伺服器,只有運算出來的一小段數字(人臉特徵向量,沒辦法還原回照片本人長相)會傳過來跟活動照片比對。這是目前隱私保護最強的選項,缺點是首次使用要下載約 190MB 的辨識模型。
- 伺服器端辨識(預設):你上傳或拍下的臉部照片,只會在當下這次查詢用來運算——判斷完就直接丟掉,不會存進任何資料庫,也不會留下檔案。整個過程都在記憶體裡處理,這次查詢一結束,或伺服器重開,這些照片跟運算結果就不存在了。
不管選哪一種,你上傳的照片本身都不會被保留——這點兩種方式一樣,只是瀏覽器端辨識連「上傳」這個動作都省了。
2登入資料(LINE)
查詢功能需要先用 LINE 登入。這不是要幫你建立臉部檔案,單純是用來限制查詢頻率、擋掉機器人亂打——如果沒有這道關卡,系統很容易被打爆。登入後我們會存:你的 LINE 使用者代號(用來認出「這是同一個人」)、你選擇公開的顯示名稱。就這樣,不會拿去做其他事。
3活動照片人臉索引
這裡要老實說一件比較特別的事:活動相簿在建檔時,我們會掃描裡面每一張照片、標記出每一張偵測到的臉孔,才能拿你的照片去比對。這代表只要你出現在某場活動的照片裡,不管你有沒有用過這個工具,都可能已經被標記在這份索引裡——這是目前這種比對方式沒辦法繞開的技術限制。
我們的因應方式:
- 這份索引只用來回答「你是不是出現在某場活動的照片裡」,不會被拿來做「這個人是誰」的反向查詢。
- 活動相簿建檔後 90 天,這份索引會自動清除(這是我們的目標,實際自動清除機制還在建置中;建置完成前如果你想確認或提早移除,直接寫信給我們,我們會手動處理)。
- 想移除?先讓我們知道「你」是誰。寫信到 contact@socialdancer-find.mooo.com,附一張你的臉的照片——對,要幫你把臉從索引裡挑出來,我們得先知道要挑的是哪張臉 🙈(不然萬一挑錯,變成把舞伴的臉也一起清掉就尷尬了)。這張照片只會拿來比對、找出哪些是你,比對完就丟掉,不會另外存檔或留底。
- 不相信我們真的清乾淨了?歡迎親自驗貨。處理完我們會回信告訴你一聲。之後你可以拿同一張臉照片再上傳來查一次——如果索引裡真的沒有你了,系統應該完全找不到任何一張命中的活動照片。如果還找得到,代表我們沒做乾淨,請直接回來罵我們,我們會補上。
4我們不會做的事
- 不會把你的照片或比對結果賣給任何人、也不會拿去打廣告。
- 不會自己代管或公開活動的原始照片——搜尋結果的縮圖跟連結,都是直接連到攝影師自己公開分享的 Google Drive 相簿,我們沒有另存一份給大家看。
- 不使用任何追蹤用 cookie。網頁會用瀏覽器內建的
sessionStorage/localStorage 記住你的登入狀態跟語言偏好,這些資料只留在你自己的裝置上,我們的伺服器看不到。
5法律依據
這個工具目前依照台灣個人資料保護法第 51 條「個人或家庭活動目的」的空間運作——說白了就是:這還是一個朋友幫朋友的小工具,不是正式營運的商業服務。如果之後規模變大,我們會找正式的法律意見重新檢視這份文件,不會一直用這個當擋箭牌。
6你的權利
- 想知道自己在會員資料裡存了什麼、想刪掉這筆資料:寫信給我們,我們會手動處理,沒有問題。
- 想確認或移除自己在某場活動照片裡被索引的臉:同上,寫信就好。
我們目前沒有自助刪除的介面,這些都是人工處理——工具不大,暫時這樣最實際。
7有登入才能用
再提醒一次:登入本身不會讓你變成「會員」或建立你的臉部資料,這兩件事完全分開。登入單純是為了限流防濫用(見第 2 點)。
8政策異動
這份文件之後可能會調整(例如第 3 點提到的 90 天自動清除機制做完之後)。有實質變動我們會直接更新這個頁面,最上面的「最後更新」日期會跟著改。
9語言版本
這份文件的中文版是正式版本。英文版本僅供參考,如果中英文版本有出入,以中文版為準。
Social Dancer Find — Privacy Policy
Last updated: 2026-09-27
Social Dancer Find is a free little tool Arthur built for the dance community, to help you find yourself in event photos. It's not a company, not for profit — just a way to stop everyone from scrolling through hundreds of photos one by one. This page explains, in plain language, what data this tool touches, how it's handled, and how to ask us to delete it.
1Photos you upload to search
The upload page lets you pick between two ways of running the recognition — the difference is where the computation actually happens:
- On-device (browser) recognition (an opt-in toggle on the upload page, currently off by default — still an experimental feature we're validating): the whole computation runs inside your own browser. Your photo never gets uploaded to our server at all — only a small numeric summary (a face embedding vector, which can't be reconstructed back into what you look like) is sent over to be compared against the event's photos. This is the strongest privacy option available, at the cost of a ~190MB model download the first time you use it.
- Server-side recognition (the default): any face photo you upload or take is used only to process that one search — as soon as the result is returned, it's discarded. It's processed entirely in memory; nothing is written to a database or saved as a file. Once the search is done (or the server restarts), that photo and its result are gone.
Either way, your photo itself is never kept — that part is identical between the two. On-device recognition just skips the "upload" step entirely.
2Login data (LINE)
Searching requires logging in with LINE first. This isn't to build a face profile on you — it's purely to limit how often the search can be called and block bot abuse; without this, the system would be an easy target for being hammered. After login we store: your LINE user identifier (so we can recognize repeat requests from "the same person") and the display name you've chosen to share. That's it — it isn't used for anything else.
3The whole-event face index
Here's something worth being upfront about: when we index an event's photo album, we scan every photo in it and mark every face our detector finds, so your photo has something to be compared against. That means if you appear in an event's photos, you may already be in this index whether or not you've ever used this tool — that's an unavoidable technical limitation of how this kind of matching works.
How we handle that:
- This index is only ever used to answer "are you in this event's photos?" — never to answer "who is this stranger?"
- We're committed to automatically clearing this index 90 days after an album is indexed (that's the goal; the automated cleanup itself is still being built — until it's live, email us and we'll remove it by hand).
- Want out? First we need to know who "you" is. Email contact@socialdancer-find.mooo.com with a photo of your face — to pick your face out of the index, we kind of need to know which face is yours 🙈 (otherwise we might accidentally scrub your dance partner instead). That photo is used only to find matches, then discarded — not kept, not filed away.
- Don't take our word for it — check yourself. We'll email you once it's done. Then upload that same face photo again to search — if you're really gone from the index, the system shouldn't find any matching event photos at all. If it still finds you, we messed up — come yell at us and we'll fix it.
4Things we don't do
- We never sell your photos or search results, and never use them for advertising.
- We don't host or publish the original event photos ourselves — every result thumbnail and link points straight to the photographer's own publicly shared Google Drive album; we don't keep a second copy for anyone to browse.
- We don't use tracking cookies. The page uses your browser's built-in
sessionStorage/localStorage to remember your login and language preference — that data stays on your own device; our servers never see it.
5Legal basis
This tool currently operates under Taiwan's Personal Data Protection Act §51 exemption for personal/family-scale activities — plainly put, this is still a friend-helping-friends tool, not a formally operated commercial service. If it ever grows beyond that scale, we'll get real legal advice and revisit this document rather than keep leaning on that exemption.
6Your rights
- Want to know what we hold on you in our member records, or want it deleted? Email us — we'll handle it by hand, no problem.
- Want to check or remove your face from a specific event's index? Same — just email us.
We don't have a self-service deletion tool yet; everything above is handled manually. This is a small project, and for now that's the most honest way to do it.
7Why login is required
To repeat the point from #2: logging in is required purely to rate-limit and block abuse — it is not the same as becoming a "member" or building a face profile. Those are two completely separate things.
8Changes to this policy
This document may change over time (for example, once the 90-day auto-cleanup mentioned above is actually built). Any real change will be posted here directly, and the "last updated" date at the top will move.
9Language
The Chinese version of this document is authoritative. This English version is provided for convenience only; if there's any discrepancy, the Chinese version governs.