มีผลบังคับใช้ · ปรับปรุงล่าสุด: 15 มิถุนายน 2026
Astra (“เรา”) ออกแบบโดยยึด ความเป็นส่วนตัวและความปลอดภัยเป็นหัวใจ (privacy & security by design) และปฏิบัติตาม พระราชบัญญัติคุ้มครองข้อมูลส่วนบุคคล พ.ศ. 2562 (PDPA). นโยบายนี้อธิบายว่า เราเก็บ ใช้ และคุ้มครองข้อมูลของคุณอย่างไร
1. ผู้ควบคุมข้อมูล
Astra เป็นผู้ควบคุมข้อมูลส่วนบุคคล ติดต่อเรื่องข้อมูลส่วนบุคคลได้ที่ contact@aiastra.co
AI ทำงานบนเครื่องของคุณทั้งหมด: การแชท การรู้จำเสียงพูด และการสังเคราะห์เสียง ประมวลผลด้วยโมเดลที่ฝังในแอปบนอุปกรณ์ของคุณ — เราไม่ส่งบทสนทนาหรือข้อมูลส่วนตัวของคุณไปยังบริการ AI ของบุคคลที่สาม และไม่มีการเรียกใช้ AI บนคลาวด์.
2. ข้อมูลที่เราเก็บ
- บัญชี Astra ID: อีเมลที่ใช้เข้าสู่ระบบ (แบบไม่มีรหัสผ่าน)
- บทสนทนา: ประมวลผล บนเครื่องของคุณ — เนื้อหาแชทไม่ถูกส่งออกจากเครื่องไปยังบุคคลที่สาม
- ข้อมูลเพื่อพัฒนาโมเดล (เมื่อยินยอม): หากคุณเปิด “ช่วยพัฒนา Astra” ระบบจะสร้างข้อมูลแบบมีโครงสร้างที่ลบข้อมูลส่วนตัวออก บนเครื่อง และเก็บไว้บนเครื่องของคุณเท่านั้น — เวอร์ชันนี้ไม่อัปโหลด และไม่ส่งให้บุคคลที่สามใด ๆ
- ข้อมูลการใช้งาน/ข้อขัดข้อง: สถิติเชิงเทคนิคและรายงาน การล่มแบบไม่ระบุตัวตน (ผ่าน Google Firebase Analytics/Crashlytics) — ไม่รวมเนื้อหาแชทหรือข้อมูล AI
เวอร์ชันนี้ไม่มีการค้นเว็บหรือบริการ AI/ค้นหาของบุคคลที่สาม — คำถามและบทสนทนาของคุณได้รับการตอบโดยโมเดลบนเครื่องเท่านั้น.
3. วัตถุประสงค์การใช้
เพื่อให้บริการผู้ช่วย AI, ปรับปรุงคุณภาพและความปลอดภัยของโมเดล (เฉพาะที่ ยินยอม), วิเคราะห์การใช้งานเชิงสถิติ และดูแลความปลอดภัยของระบบ
4. ฐานทางกฎหมาย (PDPA)
อาศัย ความยินยอม (เช่น การพัฒนาโมเดล) และ ประโยชน์โดยชอบด้วยกฎหมาย (ความปลอดภัย/การทำงานของบริการ)
5. การเปิดเผยและผู้ประมวลผล
เราใช้บริการของ Google Firebase (Authentication, Firestore, Analytics, Crashlytics, Hosting) เป็นผู้ประมวลผลข้อมูลแทนเรา เราไม่ขายข้อมูล ส่วนบุคคล
6. การโอนข้อมูลไปต่างประเทศ
ข้อมูลบางส่วนอาจถูกประมวลผลบนโครงสร้างพื้นฐานของผู้ให้บริการนอกประเทศไทย ภายใต้มาตรการคุ้มครองที่เหมาะสม
7. ระยะเวลาเก็บรักษา
ข้อมูลบัญชีเก็บไว้จนกว่าคุณจะลบบัญชี; ข้อมูลพัฒนาโมเดลเก็บแบบ redacted และ มีเวอร์ชันเท่าที่จำเป็น เราไม่เก็บเนื้อหาดิบที่อ่อนไหวระยะยาว
8. สิทธิของคุณ (PDPA)
คุณมีสิทธิเข้าถึง แก้ไข ลบ ระงับการใช้ คัดค้าน ขอให้โอน และ ถอนความยินยอมได้ทุกเมื่อ — การพัฒนาโมเดลปิดได้ทุกแพ็กเกจ ใน ตั้งค่า › ข้อมูลและการพัฒนาโมเดล. หากมีข้อกังวลสามารถร้องเรียนต่อ สำนักงานคณะกรรมการคุ้มครองข้อมูลส่วนบุคคลได้
9. ความปลอดภัย
ลบข้อมูลส่วนตัวบนเครื่องก่อนจัดเก็บ, เข้ารหัสระหว่างส่ง, และจำกัดสิทธิ์การ เข้าถึงตามบทบาท
10. เด็ก
บริการนี้ไม่ได้มุ่งสำหรับผู้ที่อายุต่ำกว่า 13 ปี
11. การเปลี่ยนแปลง
เราอาจปรับปรุงนโยบายนี้และจะแจ้งผ่านแอปหรือหน้านี้
12. ติดต่อ
Effective / Last updated: 15 June 2026
Astra (“we”) is built privacy- and security-first and complies with Thailand’s Personal Data Protection Act (PDPA). This policy explains what we collect, how we use it, and how we protect it.
1. Data controller
Astra is the data controller. Contact us about personal data at contact@aiastra.co.
All AI runs on your device: chat, speech-to-text, and text-to-speech are processed by models bundled in the app, on your device. We do not send your conversations or personal data to any third-party AI service, and there are no cloud AI calls.
2. Data we collect
- Astra ID account: the email used to sign in (passwordless).
- Conversations: processed on your device — chat content does not leave the device to any third party.
- Model-improvement data (with consent): if you enable “Help improve Astra”, we create structured records that are redacted on-device (emails, phone numbers, IDs, etc. removed) and kept on your device only — this version does not upload them or share them with any third party.
- Usage/diagnostics: anonymous technical metrics and crash reports (via Google Firebase Analytics/Crashlytics) — never chat content or AI data.
This version includes no web search and no third-party AI or search service — your questions and conversations are answered only by the on-device model.
3. How we use data
To provide the AI assistant, improve model quality and safety (only where consented), analyse usage in aggregate, and keep the service secure.
4. Legal basis (PDPA)
Consent (e.g. model improvement) and legitimate interest (security/operating the service).
5. Sharing & processors
We use Google Firebase (Authentication, Firestore, Analytics, Crashlytics, Hosting) as a processor on our behalf. We do not sell personal data.
6. International transfers
Some data may be processed on provider infrastructure outside Thailand, under appropriate safeguards.
7. Retention
Account data is kept until you delete your account; model-improvement data is stored redacted and versioned only as needed. We do not retain raw sensitive content long-term.
8. Your rights (PDPA)
You may access, rectify, erase, restrict, object, port, and withdraw consent at any time — model improvement can be turned off on any plan in Settings › Data & Model Improvement. You may also lodge a complaint with the PDPC.
9. Security
On-device redaction before storage, encryption in transit, and role-based access controls.
10. Children
The service is not directed to children under 13.
11. Changes
We may update this policy and will notify you in-app or on this page.