Privacy policy
Effective 15 September 2026
私隱政策摘要
社交帖文同地點等資料會儲存喺你嘅瀏覽器,最多 100 筆,唔會上傳去共用帖文資料庫。
如果你連接 Threads 測試功能,伺服器會暫存帳戶名稱同 token,最長 55 分鐘。中斷連接或伺服器重啟就會移除。瀏覽器只有識別連接嘅 HttpOnly cookie,唔會收到 token。搜尋字詞會經伺服器傳去 Meta,結果由你選擇儲存。公開搜尋仍未獲批。
網站用 AWS 東京伺服器,地圖同地點查詢會用到香港政府同 OpenStreetMap;唔會要求 GPS。開啟社交預覽先會載入 Meta 嵌入頁面。目前無廣告或分析 SDK。
詳細保留期同刪除方法請參閱以下內容。聯絡:chester@heavenchester.com。唔好傳送密碼或 token。
This policy describes the current Live Gossip Map website at livemap.heavenchester.com, operated by Heaven Lab. Contact: chester@heavenchester.com.
Information stored in your browser
Social links you import, titles, summaries, timestamps, location notes and engagement counts are stored in this browser's local storage, up to 100 imports. Your language preference is also stored locally. The app does not upload your saved social list to a shared application database. An optional, temporary Threads connection is separate from local saved imports.
Saved imports remain until you remove them, clear this site's browser data, or they are replaced by newer imports when the limit is reached. Installation and offline support cache an offline page and application icons; the service worker does not cache social feeds or government 3D models.
Requests needed to operate the map
Visiting the site sends network information, including your IP address and requested resource, to the hosting infrastructure. The application is hosted on AWS Lightsail in Tokyo. We use this infrastructure to serve the website and operate the Threads test connection. Your browser downloads 3D indexes, models and textures directly from the Lands Department using the configured browser-accessible government API key; Lightsail does not relay these files. Infrastructure and service diagnostics may process request metadata for operation and troubleshooting.
Map tiles, traffic information and place searches use third-party services, including OpenStreetMap and Hong Kong government map and traffic services. Place searches send location search text or the area being queried to the relevant service. Direct third-party requests disclose network information to that provider. The app does not request your device's GPS location.
Threads and Facebook previews
Opening a preview loads an embedded page from Threads or Facebook. The provider receives the requested post link and network information and may use its own cookies, particularly if you are logged in. Opening an original source also takes you to that provider. Their own policies apply: Meta Privacy Policy and Threads privacy information. You can use the map without opening social previews.
When configured, the Threads test connection requests threads_basic and threads_keyword_search. Meta handles account authorization. Our server exchanges the authorization code and holds the access token, username and a session identifier in process memory for at most 55 minutes, until you disconnect, or until the server restarts. Expired sessions are removed within one minute. Tokens are not sent to frontend JavaScript or written to an application database. An essential HttpOnly, SameSite cookie identifies your connection; a separate ten-minute cookie binds the authorization attempt to this browser. Production cookies use HTTPS Secure protection. Search text is sent through our server to Meta using your own connection. Results are displayed in this browser and are saved locally only when you choose to add them. We do not persist search queries or results on the application server, and do not deliberately log credentials or authorization codes. Hosting providers may separately process request metadata. Only nominated test accounts are enabled; keyword search remains limited by Meta to the authenticated account's own posts pending review. We do not run a background collector or request posting or comment permissions.
Use, sharing and retention
We use the information described above to display requested content, remember local choices, resolve place clues and operate the service. The current application has no advertising or analytics SDK and no feature that sells your saved imports. Third-party source content remains with its provider; removing a local import does not delete the original post.
We have not implemented a central visitor-profile or social-import archive. Browser data is retained as described above. Infrastructure records are separate from browser storage and are subject to the hosting service's operation and retention settings; we do not promise immediate deletion of all infrastructure records when browser data is cleared.
Your choices and requests
See data deletion instructions to remove local imports or site storage. For access, correction or deletion requests concerning information you have sent directly to Heaven Lab, email us with enough information to identify the request. Do not send passwords or access tokens. We may need to verify that a request relates to you.
We will update this page if the service's data handling changes.