นโยบายความเป็นส่วนตัว
มีผลบังคับใช้: 24 สิงหาคม 2569 · ปรับปรุงล่าสุด: 15 กันยายน 2569 (2026-09-15) — เพิ่มขอบเขตปฏิทินและรายชื่อติดต่อ
นโยบายนี้อธิบายว่า Inquiry Copilot (“แอปพลิเคชัน” หรือ “เรา”) เข้าถึง ใช้ จัดเก็บ และเปิดเผยข้อมูลอย่างไร โดยเฉพาะข้อมูลจากบัญชี Google ของผู้ใช้ผ่าน Google API
01แอปพลิเคชันนี้คืออะไร
Inquiry Copilot เป็นเครื่องมือสำหรับพนักงานสอบสวนใช้บริหารจัดการคดี จัดทำเอกสารคำให้การ และเปิดให้ผู้เสียหาย/พยานกรอกข้อมูลสอบปากคำล่วงหน้าผ่านเว็บ
02ข้อมูลบัญชี Google ที่เข้าถึง
เมื่อผู้ใช้ (พนักงานสอบสวน) เลือกเชื่อมต่อบัญชี Google แอปจะขอสิทธิ์ตามฟีเจอร์ที่ผู้ใช้เปิดใช้เท่านั้น (ทุกฟีเจอร์เป็นแบบเลือกเปิดเอง — opt-in):
https://www.googleapis.com/auth/drive.file— (สอบปากคำล่วงหน้า) สร้างและเข้าถึง เฉพาะไฟล์ Google Sheet ที่แอปสร้างขึ้นเอง เท่านั้น แอปไม่สามารถเห็นหรือเข้าถึงไฟล์อื่นใน Google Drive ของผู้ใช้https://www.googleapis.com/auth/calendar.app.created— (Sync กับปฏิทิน) สร้างและจัดการ เฉพาะปฏิทินรองชื่อ “Inquiry Copilot” ที่แอปสร้างขึ้นเอง เพื่อส่งกำหนดการของคดี (หมายเรียก นัดหมาย ฝากขัง ผัดฟ้อง ฯลฯ) ขึ้นปฏิทิน แอปไม่เห็นและไม่แก้ปฏิทินอื่นของผู้ใช้https://www.googleapis.com/auth/contacts— (Sync รายชื่อติดต่อ) สร้าง แก้ไข และลบ เฉพาะรายชื่อติดต่อที่แอปสร้างขึ้นเอง ภายใน label ชื่อ “Inquiry Copilot” ในบัญชี Google ของผู้ใช้ เพื่อให้มือถือแสดงว่าสายเข้าเป็นบุคคลใดในคดีใด (ชื่อในรูปแบบ “บทบาท ชื่อ · เลขคดี”) แอปไม่อ่าน ไม่แสดงรายการ ไม่ส่งออก และไม่แก้ไขรายชื่อติดต่ออื่นของผู้ใช้ — Google ไม่มีขอบเขตสิทธิ์ที่แคบกว่านี้สำหรับการสร้าง/แก้/ลบรายชื่อ แอปจึงจำกัดตัวเองด้วยบัญชีรายการที่ตนสร้าง (ledger) และเครื่องหมายภายในรายชื่อemail,openid— เพื่อแสดงชื่อบัญชีอีเมลที่เชื่อมต่ออยู่ให้ผู้ใช้ทราบ
03การนำข้อมูลไปใช้
- สร้าง Google Sheet หนึ่งไฟล์ในบัญชีของผู้ใช้ เพื่อจัดเก็บข้อมูลคดีสอบปากคำล่วงหน้า (เช่น ชื่อผู้ให้ปากคำ ประเด็นคำถาม และคำตอบ)
- อ่าน/เขียนข้อมูลในไฟล์ดังกล่าว เพื่อให้ผู้เสียหาย/พยานกรอกคำตอบผ่านลิงก์ที่ปลอดภัย และให้พนักงานสอบสวนนำคำตอบมาใช้ประกอบการสอบสวน
- ปฏิทิน: สร้างปฏิทิน “Inquiry Copilot” หนึ่งอันในบัญชีของผู้ใช้ แล้วเพิ่ม/แก้/ลบเหตุการณ์ในปฏิทินนั้นให้ตรงกับกำหนดการที่บันทึกไว้ในแอป
- รายชื่อติดต่อ: สร้าง label “Inquiry Copilot” หนึ่งอัน แล้วเพิ่ม/แก้/ลบรายชื่อในนั้นให้ตรงกับหมายเลขโทรศัพท์ของบุคคลในคดี (ผู้กล่าวหา ผู้ต้องหา พยาน และผู้เกี่ยวข้อง) ที่บันทึกไว้ในแอป — ข้อมูลที่เขียนมีเพียง ชื่อ หมายเลขโทรศัพท์ โน้ต และการอยู่ใน label
- อีเมลใช้เพื่อแสดงบัญชีที่เชื่อมต่อเท่านั้น
04การจัดเก็บข้อมูล
- ข้อมูลคดีสอบปากคำล่วงหน้าทั้งหมดถูกเก็บใน Google Drive ของผู้ใช้เอง ผู้ใช้เป็นเจ้าของและควบคุมข้อมูลได้ตลอดเวลา
- เซิร์ฟเวอร์ของเราจัดเก็บเพียง: โทเคนการเข้าถึง (refresh token) แบบเข้ารหัส, รหัสอ้างอิงไฟล์ Sheet และคีย์สำหรับตรวจสอบลายเซ็นลิงก์ — ทั้งหมดเข้ารหัสด้วย AES-256-GCM
- เซิร์ฟเวอร์ทำหน้าที่เป็นตัวกลางส่งต่อข้อมูลเท่านั้น ไม่จัดเก็บเนื้อหาคำให้การไว้อย่างถาวร
- ข้อมูลปฏิทินและรายชื่อติดต่อไหลระหว่าง เครื่องของผู้ใช้กับบัญชี Google ของผู้ใช้เองโดยตรง เท่านั้น ไม่ผ่านและไม่ถูกเก็บบนเซิร์ฟเวอร์ของเรา — บนเครื่องผู้ใช้เก็บเพียงบัญชีรายการ (ledger) ว่ารายการใดที่แอปสร้างไว้ เพื่อให้แก้/ลบได้เฉพาะรายการของตน
05การเปิดเผย/แบ่งปันข้อมูล
เราไม่ขาย ไม่ให้เช่า และไม่แบ่งปันข้อมูลจากบัญชี Google ของผู้ใช้แก่บุคคลที่สาม ข้อมูลสอบปากคำล่วงหน้าถูกส่งต่อเฉพาะระหว่างพนักงานสอบสวนเจ้าของบัญชีกับผู้เสียหาย/พยานที่ได้รับลิงก์เท่านั้น เพื่อวัตถุประสงค์การสอบสวนตามกฎหมาย · ข้อมูลปฏิทินและรายชื่อติดต่อไม่ถูกส่งให้ผู้ใดนอกจากบัญชี Google ของผู้ใช้เอง และไม่ถูกใช้เพื่อการโฆษณา การวิเคราะห์ หรือฝึกโมเดลใดๆ
06Limited Use (การใช้แบบจำกัด)
การใช้และการโอนข้อมูลที่ได้รับจาก Google API ของ Inquiry Copilot เป็นไปตาม Google API Services User Data Policy รวมถึงข้อกำหนด Limited Use อย่างเคร่งครัด
07การเก็บรักษาและการลบข้อมูล
- ผู้ใช้สามารถยกเลิกการเชื่อมต่อได้ในแอปทุกเมื่อ ซึ่งจะลบโทเคนออกจากเครื่องผู้ใช้
- ผู้ใช้สามารถถอนสิทธิ์การเข้าถึงของแอปได้ที่ Google Account › ความปลอดภัย › แอปของบุคคลที่สาม
- ผู้ใช้สามารถลบ Google Sheet ที่แอปสร้างไว้ใน Google Drive ของตนเองได้โดยตรง
- ปฏิทิน: ปุ่ม “ยกเลิก sync และลบปฏิทินออกจาก Google Account” ในแอป จะลบปฏิทิน “Inquiry Copilot” พร้อมเหตุการณ์ทั้งหมดในนั้น · หรือลบปฏิทินเองใน Google Calendar
- รายชื่อติดต่อ: ปุ่ม “ยกเลิก sync และลบรายชื่อออกจาก Google Account” ในแอป จะลบ label “Inquiry Copilot” พร้อมรายชื่อทั้งหมดที่แอปสร้าง (รายชื่ออื่นของผู้ใช้ไม่ถูกแตะ) · หรือลบ label เองใน Google Contacts · เมื่อบุคคล/คดีถูกลบออกจากแอป รายชื่อที่เกี่ยวข้องจะถูกลบออกจาก label ในการ sync รอบถัดไป
- หากต้องการให้ลบข้อมูลที่เก็บบนเซิร์ฟเวอร์ (โทเคนที่เข้ารหัส) โปรดติดต่อเราตามช่องทางด้านล่าง
08ความปลอดภัย
โทเคนและคีย์ทั้งหมดถูกเข้ารหัสขณะจัดเก็บ (encryption at rest) การรับส่งข้อมูลใช้การเข้ารหัส HTTPS/TLS และลิงก์สำหรับผู้ให้ปากคำถูกเซ็นลายเซ็นดิจิทัล (HMAC) เพื่อป้องกันการปลอมแปลง
09ติดต่อ
หากมีคำถามเกี่ยวกับนโยบายความเป็นส่วนตัวนี้ ติดต่อ: ittaek.dev@gmail.com
Privacy Policy
Effective date: 24 August 2026 · Last updated: 15 September 2026 (2026-09-15) — added Calendar and Contacts scopes
This policy explains how Inquiry Copilot (“the application”, “we”) accesses, uses, stores, and discloses information — in particular data obtained from a user's Google Account through Google APIs.
01What this application is
Inquiry Copilot is a tool for police investigators to manage cases, produce statement documents, and let complainants/witnesses fill in interview information in advance through a web form.
02Google account data accessed
When a user (an investigator) chooses to connect their Google Account, the app requests only the scopes needed for the features the user turns on (every feature is opt-in):
https://www.googleapis.com/auth/drive.file— (pre-interview) create and access only the Google Sheet files created by the app itself. The app cannot see or access any other files in the user's Google Drive.https://www.googleapis.com/auth/calendar.app.created— (calendar sync) create and manage only the secondary calendar named “Inquiry Copilot” that the app created, to publish case deadlines and appointments (summons, hearings, detention and prosecution deadlines, etc.). The app cannot see or modify any other calendar of the user.https://www.googleapis.com/auth/contacts— (contact sync) create, update and delete only the contacts the app itself created, inside one label named “Inquiry Copilot” in the user's Google account, so that the user's phone identifies incoming calls from people involved in the user's cases (names in the form “role name · case number”). The app never lists, reads, exports or modifies the user's other contacts. Google offers no narrower scope for creating, updating and deleting contacts; the app therefore restricts itself through a local ledger of the records it created and an app-private marker stored on each such contact.email,openid— to display the connected account's email address to the user.
03How the data is used
- Create one Google Sheet in the user's account to store pre-interview case data (e.g., interviewee name, questions, and answers).
- Read/write that file so complainants/witnesses can submit answers through a secure link, and so investigators can use those answers in their investigation.
- Calendar: create one “Inquiry Copilot” calendar in the user's account and add/update/delete events in that calendar so that it mirrors the schedule recorded in the app.
- Contacts: create one “Inquiry Copilot” label and add/update/delete contacts in it so that it mirrors the phone numbers of people involved in the user's cases (complainants, suspects, witnesses and their representatives) as recorded in the app. Only the name, phone number, a note and the label membership are written.
- The email is used only to display the connected account.
04Data storage
- All pre-interview case data is stored in the user's own Google Drive. The user owns and controls the data at all times.
- Our server stores only: an encrypted refresh token, the Sheet's file ID, and a key used to verify link signatures — all encrypted with AES-256-GCM.
- The server acts only as a relay and does not permanently store statement content.
- Calendar and contact data flow directly between the user's device and the user's own Google account; they never pass through or get stored on our servers. The user's device keeps only a local ledger of which records the app created, so that it edits and deletes nothing else.
05Data sharing
We do not sell, rent, or share a user's Google account data with third parties. Pre-interview data is relayed only between the investigator who owns the account and the complainant/witness who receives the link, for lawful investigative purposes. Calendar and contact data are never sent to anyone other than the user's own Google account, and are never used for advertising, analytics, or training any model.
06Limited Use
Inquiry Copilot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
07Data retention and deletion
- Users can disconnect in the app at any time, which removes tokens from the user's device.
- Users can revoke the app's access at Google Account › Security › Third-party apps.
- Users can delete the app-created Google Sheet directly from their own Google Drive.
- Calendar: the in-app button “Cancel sync and delete the calendar from the Google Account” deletes the “Inquiry Copilot” calendar together with all of its events; the user can also delete the calendar directly in Google Calendar.
- Contacts: the in-app button “Cancel sync and delete contacts from the Google Account” deletes the “Inquiry Copilot” label together with every contact the app created (the user's other contacts are untouched); the user can also delete the label directly in Google Contacts. When a person or case is removed from the app, the corresponding contacts are removed from the label on the next sync.
- To request deletion of server-side data (encrypted tokens), contact us using the details below.
08Security
All tokens and keys are encrypted at rest. Data in transit is protected with HTTPS/TLS, and interviewee links are digitally signed (HMAC) to prevent forgery.
09Contact
For questions about this Privacy Policy, contact: ittaek.dev@gmail.com