Memo (“บริการ”) เป็นผู้ช่วยส่วนตัวที่ทำงานผ่าน LINE และหน้าเว็บของบริการ
เอกสารนี้อธิบายว่าบริการเก็บข้อมูลอะไร ใช้ทำอะไร และคุณควบคุมได้อย่างไร
1. ข้อมูลที่เก็บ
- สิ่งที่คุณส่งให้บริการ — ข้อความ โน้ต การเตือน รายการเงิน และไฟล์ที่คุณส่งเข้ามา
- ข้อมูลบัญชี LINE — ชื่อที่แสดงและรหัสผู้ใช้ (user ID) เพื่อระบุว่าเป็นของคุณ
- เมื่อคุณเชื่อมบัญชี Google (โดยสมัครใจ) — โทเคนเข้าถึงของ Google และข้อมูลเท่าที่สิทธิ์ที่คุณอนุญาตครอบคลุม:
- Google Calendar — อ่านนัดเพื่อแสดงในปฏิทินของแอป และสร้าง/แก้/ลบนัดที่คุณสั่งผ่านบริการ
- Google Drive — เฉพาะไฟล์ที่บริการสร้างขึ้นเอง (ขอบเขต
drive.file) บริการไม่เห็นไฟล์อื่นในไดรฟ์ของคุณ
2. ใช้ข้อมูลทำอะไร
ใช้เพื่อให้บริการผู้ช่วยส่วนตัวแก่ตัวคุณเท่านั้น — เตือนความจำ จดบันทึก สรุปการเงิน จัดการไฟล์ และเชื่อมปฏิทิน
บริการไม่ใช้ข้อมูลของคุณเพื่อโฆษณา และไม่นำไปฝึกโมเดลใด ๆ
3. การเปิดเผยและการแบ่งปัน
บริการไม่ขายและไม่แบ่งปันข้อมูลของคุณกับบุคคลที่สาม ยกเว้นผู้ให้บริการที่จำเป็นต่อการทำงานตามที่คุณสั่ง
(เช่น LINE, Google, และพื้นที่เก็บไฟล์ที่คุณเลือก) ข้อมูลของผู้ใช้แต่ละคนแยกจากกัน มองเห็นข้ามกันไม่ได้
4. การใช้ข้อมูลจาก Google (Limited Use)
การที่บริการใช้และถ่ายโอนข้อมูลที่ได้รับจาก Google API เป็นไปตาม
Google API Services User Data Policy
รวมถึงข้อกำหนด Limited Use อย่างเคร่งครัด — ข้อมูลจาก Google ถูกใช้เพื่อมอบฟีเจอร์ที่คุณเห็นในบริการเท่านั้น
ไม่ถ่ายโอนให้ผู้อื่นเว้นแต่จำเป็นต่อฟีเจอร์นั้น ไม่ใช้เพื่อโฆษณา และไม่มีมนุษย์อ่านนอกจากกรณีที่คุณอนุญาตชัดแจ้ง
เพื่อความปลอดภัย หรือเพื่อปฏิบัติตามกฎหมาย
5. การปกป้องข้อมูล (มาตรการความปลอดภัย)
บริการใช้มาตรการทางเทคนิคและการบริหารจัดการเพื่อคุ้มครองข้อมูลของคุณ
โดยเฉพาะข้อมูลที่ได้รับผ่านสิทธิ์ Google (Google Calendar และ Google Drive) ดังนี้
- เข้ารหัสระหว่างส่ง (in transit) — ทุกการเชื่อมต่อกับบริการ กับ Google API และกับที่เก็บไฟล์
ใช้ HTTPS/TLS ทั้งหมด · การเชื่อมต่อ NAS บังคับให้เป็น
https:// เท่านั้น
- เข้ารหัสข้อมูลลับที่จัดเก็บ (at rest) — รหัสผ่านของที่เก็บไฟล์เข้ารหัสด้วย AES-256-GCM
ก่อนบันทึกลงฐานข้อมูล · รหัสผ่านบัญชีผู้ใช้เก็บเป็นค่าแฮชแบบ scrypt (มี salt เฉพาะราย)
ไม่เก็บรหัสผ่านในรูปแบบที่อ่านกลับได้ · รหัสเข้าใช้แบบใช้ครั้งเดียวเก็บเป็นค่าแฮชเช่นกัน
- โทเคนของ Google — เก็บในฐานข้อมูลที่เข้าถึงได้เฉพาะกระบวนการของบริการ
ไม่เปิดสู่อินเทอร์เน็ต ไม่ถูกส่งไปยังหน้าเว็บหรืออุปกรณ์ของผู้ใช้ และไม่ถูกบันทึกลงไฟล์บันทึกการทำงาน (log)
เมื่อคุณเลิกเชื่อมบัญชี บริการจะเพิกถอนโทเคนที่ Google แล้วลบออกจากฐานข้อมูลทันที
- ควบคุมการเข้าถึง — ทุกคำสั่งอ่าน/เขียนข้อมูลผูกกับรหัสผู้ใช้เจ้าของข้อมูลเสมอ
ผู้ใช้คนหนึ่งเข้าถึงข้อมูลของอีกคนไม่ได้ · เซสชันของหน้าเว็บลงลายเซ็นด้วย HMAC
และเทียบแบบคงเวลา (timing-safe) เพื่อกันการเดาลายเซ็น
- ลิงก์ไฟล์มีอายุจำกัด — ลิงก์ดาวน์โหลดถูกเก็บเป็นค่าแฮช มีอายุ 15 นาที
และจำกัดจำนวนครั้งที่ใช้ได้ หมดอายุแล้วถูกลบทิ้งอัตโนมัติ
- ขอสิทธิ์เท่าที่จำเป็น — ขอบเขต Google Drive ที่ใช้คือ
drive.file
ซึ่งเห็นเฉพาะไฟล์ที่บริการสร้างเอง บริการไม่สามารถเข้าถึงไฟล์อื่นในไดรฟ์ของคุณได้เลย
และไม่ขอขอบเขตแบบ restricted ใด ๆ
- ข้อมูลส่วนบุคคลในเอกสาร — เมื่อบริการตรวจพบว่าเอกสารมีข้อมูลอ่อนไหว
(เช่น เลขประจำตัวประชาชน) เอกสารนั้นจะถูกทำเครื่องหมายและซ่อนจากรายการไฟล์ของกลุ่ม
โดยอัตโนมัติ เห็นได้เฉพาะเจ้าของเท่านั้น
- ความปลอดภัยของหน้าเว็บ — ตั้ง Content-Security-Policy และ
X-Content-Type-Options: nosniff เพื่อลดความเสี่ยงการฝังสคริปต์แปลกปลอม
- จำกัดผู้เข้าถึงฝั่งผู้ดูแล — เซิร์ฟเวอร์เข้าถึงได้เฉพาะผู้ดูแลระบบผ่านช่องทางที่เข้ารหัส
ไม่มีบุคคลที่สามเข้าถึงข้อมูลของคุณ และไม่มีการอ่านเนื้อหาของผู้ใช้เพื่อวัตถุประสงค์อื่น
- หากเกิดเหตุละเมิดข้อมูล — บริการจะแจ้งผู้ใช้ที่ได้รับผลกระทบทางอีเมลหรือทาง LINE
โดยไม่ชักช้า พร้อมระบุขอบเขตของเหตุการณ์และสิ่งที่คุณควรทำ
6. การเก็บรักษาและการลบข้อมูล
ข้อมูลถูกเก็บบนเซิร์ฟเวอร์ของผู้ให้บริการ ส่วนไฟล์เก็บบน NAS หรือ Google Drive ของคุณเองตามที่เลือก
- ข้อมูลจาก Google — บริการไม่ได้คัดลอกนัดในปฏิทินหรือไฟล์ในไดรฟ์มาเก็บไว้เป็นสำเนาถาวร
แต่ดึงมาแสดงตอนคุณเปิดดู · สิ่งเดียวที่เก็บไว้คือโทเคนเข้าถึงและตัวเชื่อม (id ของนัดที่บริการสร้างให้)
เพื่อให้แก้/ลบนัดเดิมได้ถูกใบ
- โทเคน Google — เก็บไว้เท่าที่ยังเชื่อมบัญชีอยู่ · เลิกเชื่อมเมื่อไหร่ ถูกเพิกถอนที่ Google
และลบออกจากฐานข้อมูลทันทีในคำสั่งเดียวกัน ไม่มีสำเนาค้าง
- ข้อความแจ้งเตือนในแอป — ลบอัตโนมัติเมื่อเก่าเกิน 180 วัน
- ลิงก์ดาวน์โหลดไฟล์ — หมดอายุใน 15 นาที และถูกลบทิ้งอัตโนมัติหลังหมดอายุ
- โน้ต การเตือน รายการเงิน — เก็บไว้จนกว่าคุณจะลบเอง (ลบได้เองในแอปทุกรายการ)
- ลบทั้งบัญชี — ส่งอีเมลมาที่ที่อยู่ท้ายหน้านี้ บริการจะลบข้อมูลทั้งหมดของคุณออกจากฐานข้อมูล
ภายใน 30 วัน และยืนยันกลับเมื่อทำเสร็จ · ไฟล์ที่อยู่บน Google Drive ของคุณเองยังเป็นของคุณ
คุณลบเองได้จากไดรฟ์ (บริการไม่ลบไฟล์ให้โดยไม่ได้สั่ง)
7. ปัญญาประดิษฐ์ (AI) กับข้อมูลของคุณ
- ไม่ใช้ข้อมูลของคุณฝึกโมเดล — ข้อมูลที่ได้จาก Google Workspace API (Calendar และ Drive)
ทั้งแบบดิบและแบบรวม/ไม่ระบุตัวตน ไม่ถูกนำไปพัฒนา ปรับปรุง หรือฝึกโมเดล AI/ML ใด ๆ
และไม่ถูกส่งให้บริการภายนอกที่นำไปฝึกโมเดลของตน
- การอ่านตัวหนังสือในรูป (OCR) — ทำผ่านบัญชี Google ของคุณเอง
(อัปไฟล์ชั่วคราวเข้าไดรฟ์ของคุณ ให้ Google อ่าน แล้วลบไฟล์ชั่วคราวทิ้งทันที)
ข้อมูลไม่ออกไปนอกบัญชีของคุณ
- สรุป/ถาม-ตอบเอกสารด้วย AI — ทำงานเฉพาะเมื่อคุณกดสั่งเองทีละครั้ง
โดยส่งเฉพาะข้อความที่แกะได้จากเอกสารใบนั้นไปยัง API ของผู้ให้บริการโมเดล
ซึ่งตามข้อกำหนดของผู้ให้บริการ ไม่นำข้อมูลที่ส่งผ่าน API ไปฝึกโมเดล
บริการไม่ส่งข้อมูลของคุณไปโดยที่คุณไม่ได้สั่ง
คำแถลงตามข้อกำหนดของ Google: The use of raw or derived user data received from Workspace APIs
will adhere to the Google User Data Policy, including the Limited Use requirements.
8. สิทธิ์และการควบคุมของคุณ
- เลิกเชื่อม Google ได้ทุกเมื่อในแอป (⚙️ ระบบ → Google) หรือที่
myaccount.google.com
— เมื่อเลิกเชื่อม โทเคนถูกเพิกถอนและลบทันที
- ขอดู แก้ไข หรือลบข้อมูลของคุณได้ โดยติดต่ออีเมลด้านล่าง
9. ติดต่อ
คำถามเรื่องความเป็นส่วนตัว ติดต่อ [email protected]
Memo — Privacy Policy · Last updated: 2 September 2026
Memo (“the Service”) is a personal assistant that runs inside LINE chat and this web app.
This policy explains what the Service collects, what it is used for, and how you stay in control.
1. What we collect
- What you send us — messages, notes, reminders, expense entries and files you send in.
- LINE account data — your display name and user ID, to know which data is yours.
- When you connect Google (entirely optional) — OAuth tokens and only the data the scopes you granted cover:
- Google Calendar (
calendar.events) — read your upcoming events to show them in the in-app calendar,
and create / update / delete the events you ask for from chat.
- Google Drive (
drive.file) — only files the Service itself created.
The Service cannot see any other file in your Drive.
2. How we use it
Only to provide the assistant features to you — reminders, notes, expense summaries, file filing and calendar sync.
We do not use your data for advertising, and we do not use it to train any AI/ML model.
3. Sharing
We do not sell or share your data with third parties, except the providers required to perform what you asked for
(LINE, Google, and the file storage you chose). Each user's data is isolated; users cannot see each other's data.
4. Google user data — Limited Use
Memo's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy,
including the Limited Use requirements. Google user data is used only to provide or improve the user-facing features
you can see in the Service; it is not transferred to others except as necessary to provide those features, comply with
applicable law, or as part of a merger or acquisition; it is not used for advertising; and it is not read by humans
unless you explicitly consent, it is necessary for security purposes, or it is required by law.
Google user data is never used to develop, improve or train generalised AI and/or ML models.
5. Data protection (security measures)
We apply the following technical and organisational measures to protect your data, and in particular the
sensitive data obtained through Google scopes (Calendar and Drive):
- Encryption in transit — all connections to the Service, to the Google APIs and to file storage use HTTPS/TLS.
NAS connections are required to be
https://.
- Encryption of stored secrets (at rest) — file-storage passwords are encrypted with AES-256-GCM
before being written to the database. Account passwords are stored as scrypt hashes with a per-user salt,
never in a recoverable form. One-time sign-in codes are stored hashed as well.
- Google tokens — stored in a database reachable only by the Service process, never exposed to the
internet, never sent to the browser or device, and never written to application logs. When you disconnect,
the Service revokes the token at Google and deletes it from our database immediately.
- Access control — every read and write is scoped to the owning user ID, so one user can never reach
another user's data. Web sessions are signed with HMAC and verified using timing-safe comparison.
- Time-limited file links — download links are stored hashed, expire after 15 minutes, are limited in
number of uses, and are purged automatically after expiry.
- Minimum scopes — we request
drive.file, which grants access only to files this app created.
We request no restricted scopes at all.
- Sensitive content in documents — when the Service detects sensitive personal data in a document
(for example a national ID number), that document is flagged and automatically hidden from shared group
file lists; only its owner can see it.
- Web hardening — a Content-Security-Policy and
X-Content-Type-Options: nosniff are set
to reduce the risk of injected scripts.
- Administrative access — the server is reachable only by the operator over an encrypted channel.
No third party has access to your data, and user content is not read for any other purpose.
- Breach notification — if a data breach occurs, we will notify affected users without undue delay
by email or via LINE, describing the scope of the incident and what you should do.
6. Data retention and deletion
Data is held on the operator's server; files are stored on your NAS or your own Google Drive, as you choose.
- Google user data — we do not keep a permanent copy of your calendar events or Drive files.
They are fetched from Google when you view them. The only things stored are the OAuth tokens and a link
record (the ID of an event the Service created) so the right event can later be updated or deleted.
- Google tokens — retained only while your account stays connected. On disconnect they are revoked
at Google and deleted from our database in the same operation; no copy is kept.
- In-app notifications — deleted automatically once older than 180 days.
- File download links — expire after 15 minutes and are purged automatically after expiry.
- Notes, reminders and expense entries — kept until you delete them; every item can be deleted in the app.
- Full account deletion — email the address at the bottom of this page. We will delete all of your data
from our database within 30 days and confirm when it is done. Files that live in your own Google Drive
remain yours and can be deleted by you in Drive (the Service never deletes them unless you ask).
7. AI and your data
- No model training — raw and aggregated/anonymised data obtained from Google Workspace APIs
(Calendar and Drive) is never used to develop, improve or train any AI/ML model, and is never
transferred to any third-party service that would use it to train its models.
- OCR stays in your own account — text recognition is performed through your own Google account:
a temporary file is uploaded to your Drive, Google performs the OCR, and the temporary file is deleted
immediately. The data never leaves your account.
- AI document summary / Q&A — runs only when you explicitly request it, one document at a time.
Only the text extracted from that document is sent to the model provider's API, whose terms state that data
submitted through the API is not used to train models. Nothing is sent without your action.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy,
including the Limited Use requirements.
8. Your rights and controls
- Disconnect Google at any time in the app (⚙️ Settings → Google) or at
myaccount.google.com
— the token is revoked and deleted immediately.
- Request access to, correction of, or deletion of your data by emailing us below.
9. Contact
Privacy questions: [email protected]