seedfire 中文 ← Home

Legal

Last updated: September 13, 2026 · ZZZ Tech Solutions LLC

These documents cover three things: the website seedfire.org; the hosted user portal my.seedfire.org and the Seedfire server behind it, which ZZZ Tech Solutions LLC ("ZZZ", "we") operates; and self-hosted Seedfire deployments that other organizations install and run themselves. Where a rule applies to only one of them we say so.

Terms of Service

1. About these Terms

These Terms govern access to and use of the Seedfire software — the server, web console, user portal, desktop applications and command-line tools (together, the "Software") — and of the services ZZZ hosts at seedfire.org and my.seedfire.org (the "Hosted Service"). By creating an account, signing in or using the Software you agree to these Terms. If you do not agree, do not use it.

2. Who operates your deployment

Seedfire is self-hosted software. The organization that installs and runs a Seedfire server (the "Operator") is responsible for that deployment. For accounts created at my.seedfire.org, ZZZ is the Operator. For any other Seedfire server — for example one run by your employer — that organization is the Operator, and ZZZ has no access to it and receives no data from it.

3. Accounts and authorized use

You may reach a device or service through Seedfire only if the Operator has granted you access to it, or if it is a private device you enrolled yourself. Unauthorized access is prohibited and may be unlawful. Sign-ins, grants and connections are recorded in audit and connection logs kept by the Operator (see the Privacy Policy for what is and is not recorded).

You must be at least 16 years old to create an account on the Hosted Service. You are responsible for keeping your password, two-factor codes, recovery codes and signed-in devices secure, and for promptly signing out any device you do not recognise. Tell the Operator immediately if you suspect your account is compromised.

4. Acceptable use

You agree not to: (a) access systems or assets you are not authorized to access; (b) interfere with or circumvent the Software's security or authentication features; (c) use the Software or Hosted Service to attack, scan or harm third-party systems, distribute malware, or violate applicable law; (d) resell the Hosted Service; or (e) reverse engineer, decompile or disassemble the Software except to the extent permitted by applicable law.

5. The Hosted Service

Creating an account, installing the Seedfire app and enrolling private devices within your quota on my.seedfire.org is currently free. We may change quotas, add paid plans or discontinue the free tier in the future; we will give reasonable notice of material changes to existing accounts. Accounts whose email address is never verified may be deleted automatically. We may suspend or remove accounts that violate these Terms.

6. Intellectual property

The Software is licensed, not sold. ZZZ and its licensors retain all right, title and interest in and to the Software and the Seedfire name and mark. Operator marks shown on white-labelled deployments are used with the Operator's permission; the underlying software remains ZZZ's.

7. Disclaimer of warranties

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SOFTWARE AND HOSTED SERVICE ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT. ZZZ DOES NOT WARRANT THAT THE SOFTWARE OR HOSTED SERVICE WILL BE UNINTERRUPTED, ERROR-FREE OR SECURE.

8. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, ZZZ SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF DATA, PROFITS OR BUSINESS, ARISING OUT OF OR RELATING TO THE SOFTWARE OR HOSTED SERVICE. ZZZ'S AGGREGATE LIABILITY SHALL NOT EXCEED THE AMOUNTS YOU PAID FOR THE SOFTWARE OR HOSTED SERVICE IN THE TWELVE MONTHS PRECEDING THE CLAIM, OR USD 100 IF NO FEES WERE PAID.

9. Operator responsibilities

Each Operator is solely responsible for its own deployment, including access-control decisions, the devices made reachable through the Software, compliance with the laws applicable to its use (including data protection and export control), retention of its logs, and any white-label content.

10. Changes

We may update these Terms. For the Hosted Service the version published on this page applies; for self-hosted deployments the version distributed with that version of the Software applies. Material changes are noted here and in release notes.

11. General

If any provision of these Terms is held unenforceable, it will be limited to the minimum extent necessary and the remainder will stay in effect. These Terms are governed by the laws of the jurisdiction in which ZZZ Tech Solutions LLC is organized, without regard to conflict-of-laws rules.

Privacy Policy

1. Summary

Seedfire is built so that the people who run it hold the data. The Software contains no telemetry, analytics or tracking and never "phones home" to ZZZ. What is stored, and who is responsible for it, depends on who operates the server you use:

  • my.seedfire.org — operated by ZZZ. ZZZ is the data controller for accounts created there.
  • Self-hosted deployments — operated by another organization. That Operator is the data controller; ZZZ collects, receives and processes nothing from it. To access, correct or delete your data there, contact your administrator.
  • seedfire.org (this marketing website only) — uses Google Analytics 4 to count visits and page views in aggregate (see Cookie Policy). No analytics runs in the portal, the console, the app or the CLI.

2. Data a Seedfire server stores

To provide sign-in, access management and the connection service, a Seedfire server stores on the Operator's own infrastructure:

  • Account data: username, password hash (argon2id — plaintext passwords are never stored), email address and when it was verified, two-factor secret and hashed recovery codes if you turn 2FA on, and — if you sign in with Google, GitHub or Microsoft — the stable account identifier and email address that provider returns. Seedfire asks the provider for nothing else.
  • Devices: the name, operating system, Seedfire version, last-seen time and last IP address of each computer signed in to your account, and of each device you enroll.
  • Connection records: who connected, to which device, from which computer, when, for how long and how it ended. The content of connections is not recorded — traffic is encrypted end to end between your computer and the device and is not readable by the server.
  • Audit logs: username, action, time and source IP of sign-ins, grants and administrative actions.
  • Access data: groups, grants and, where an Operator chooses to store them, credentials for connecting to devices — encrypted with a master key held by the Operator and never displayed.

3. How ZZZ uses data on my.seedfire.org

Only to operate the service: to sign you in, verify your email, send you account emails you asked for (confirmation links, email-change notices, security notices), enforce quotas, keep the service secure and respond to your requests. We do not sell personal data, do not use it for advertising, and do not share it except with the sub-processors below or when required by law.

4. Sub-processors (my.seedfire.org only)

  • Amazon Web Services (United States) — hosting of the server and delivery of account emails (Amazon SES).
  • Google, GitHub, Microsoft — only if you choose to sign in with one of them; you are also subject to that provider's privacy policy.

5. Retention

On my.seedfire.org, accounts that never verify their email are deleted automatically; connection records and audit logs are kept for a limited period and then deleted; account data is kept while your account exists. You can delete signed-in devices and private devices yourself from the portal; to delete your account, contact us. On self-hosted deployments retention is configured by the Operator.

6. Security

TLS everywhere, argon2id password hashing, per-connection short-lived SSH certificates, sealed credential storage, hashed session and recovery tokens, two-factor authentication, and signed, hash-verified software updates.

7. Your rights

Depending on where you live you may have rights to access, correct, delete or export your personal data, or to object to its processing. For my.seedfire.org, email us (below) and we will respond within 30 days. For a self-hosted deployment, contact its Operator.

Cookie Policy

my.seedfire.org and the Seedfire console use strictly necessary, first-party cookies only — no advertising, analytics or third-party cookies and no cross-site tracking. The public website seedfire.org additionally uses Google Analytics (below).

CookiePurposeLifetime
seedfire_portal, seedfire_sessionKeeps you signed in to the portal / console (HttpOnly, Secure). The server stores only a hash.Session; cleared on sign-out
seedfire_portal_csrfProtects sign-in forms against cross-site request forgery.Short-lived
seedfire_portal_sso, seedfire_portal_sso2Carries the sealed state of a Google/GitHub/Microsoft sign-in while it is in progress.10 minutes
seedfire_trustedConsole only, when you tick "remember this device": skips the code (never the password).Days, set by the Operator
seedfire_langRemembers your language choice.1 year
seedfire_flash and similarShows a one-time confirmation banner after an action.Deleted after display

seedfire.org website analytics

The marketing pages at seedfire.org (home, contact, this page) load Google Analytics 4 (Google LLC) so we can see how many people visit and which pages they read. Google sets the _ga and _ga_* cookies (up to 2 years) to tell returning browsers apart; GA4 does not store IP addresses and we have not enabled advertising features or Google Signals. The data is aggregate visit statistics, not tied to any Seedfire account. To opt out, use a content blocker or Google's opt-out add-on. The language switch is remembered in your browser's local storage only.

Contact

ZZZ Tech Solutions LLC · sales@zzztechs.com · or use the contact form.

法律条款

最后更新:2026 年 9 月 13 日 · ZZZ Tech Solutions LLC

本页文件覆盖三样东西:官网 seedfire.org;由 ZZZ Tech Solutions LLC(下称“ZZZ”或“我们”)运营的用户门户 my.seedfire.org 及其背后的 Seedfire 服务器;以及由其他组织自行安装运行的自托管 Seedfire 部署。某条规则只适用于其中之一时,我们会明说。

服务条款

1. 关于本条款

本条款约束对 Seedfire 软件——服务端、网页控制台、用户门户、桌面应用与命令行工具(合称“本软件”)——以及 ZZZ 在 seedfire.org 与 my.seedfire.org 托管的服务(下称“托管服务”)的访问与使用。创建账号、登录或使用本软件即表示您同意本条款;如不同意,请勿使用。

2. 谁运营您的部署

Seedfire 是自托管软件。安装并运行一台 Seedfire 服务器的组织(下称“运营方”)对该部署负责。在 my.seedfire.org 创建的账号,运营方是 ZZZ;其他任何 Seedfire 服务器——例如您雇主运行的那台——运营方是该组织,ZZZ 无法访问它,也不会从中收到任何数据。

3. 账号与授权使用

仅当运营方授予您访问权限,或该设备是您自己纳管的私有设备时,您方可通过 Seedfire 访问它。未经授权的访问被禁止并可能违法。登录、授权与连接会记录在运营方保管的审计与连接日志中(记录什么、不记录什么见隐私政策)。

在托管服务上创建账号须年满 16 岁。您有责任妥善保管密码、两步验证码、恢复码与已登录设备,并及时退出不认识的设备;如怀疑账号被盗用,请立即通知运营方。

4. 可接受使用

您同意不会:(a) 访问未获授权的系统或资产;(b) 干扰或规避本软件的安全与认证机制;(c) 利用本软件或托管服务攻击、扫描或损害第三方系统、传播恶意软件或违反适用法律;(d) 转售托管服务;(e) 在适用法律允许的范围之外对本软件进行反向工程、反编译或反汇编。

5. 托管服务

目前在 my.seedfire.org 创建账号、安装 Seedfire 应用及在配额内纳管私有设备均为免费。我们未来可能调整配额、增加付费方案或停止免费档位;对现有账号的重大变更会提前合理通知。邮箱始终未验证的账号可能被自动删除。违反本条款的账号可能被暂停或删除。

6. 知识产权

本软件为授权使用而非出售。本软件及 Seedfire 名称与标识的全部权利归 ZZZ 及其许可方所有。白标部署中展示的运营方标识由运营方授权使用;底层软件的权利仍归 ZZZ。

7. 免责声明

在适用法律允许的最大范围内,本软件与托管服务按“现状”和“可用状态”提供,不附带任何明示或默示的保证,包括但不限于对适销性、特定用途适用性及不侵权的默示保证。ZZZ 不保证本软件或托管服务不中断、无错误或绝对安全。

8. 责任限制

在适用法律允许的最大范围内,ZZZ 对因本软件或托管服务引起或与之相关的任何间接、附带、特殊、后果性或惩罚性损害(包括数据、利润或业务损失)概不负责;ZZZ 的累计责任总额不超过索赔前十二个月内您为本软件或托管服务支付的费用(如未支付任何费用,则不超过 100 美元)。

9. 运营方责任

每个运营方对其自己的部署独立承担全部责任,包括访问授权决定、通过本软件可达的设备、对其适用法律(含数据保护与出口管制)的合规、日志保存以及任何白标内容。

10. 条款变更

我们可能更新本条款。托管服务适用本页发布的版本;自托管部署适用随该版本软件分发的版本。重大变更会在本页及版本说明中注明。

11. 一般条款

如本条款任何条文被认定不可执行,该条文将在必要的最小范围内受到限制,其余条文继续有效。本条款受 ZZZ Tech Solutions LLC 注册地法律管辖,不适用其法律冲突规则。

隐私政策

1. 概要

Seedfire 的设计原则是:数据由运行它的人掌握。本软件不含遥测、统计分析或跟踪,绝不向 ZZZ“回传”。存了什么、谁负责,取决于您所用服务器由谁运营:

  • my.seedfire.org —— 由 ZZZ 运营。在此创建的账号,ZZZ 是数据控制者。
  • 自托管部署 —— 由其他组织运营。该运营方是数据控制者;ZZZ 不从中收集、接收或处理任何数据。如需查询、更正或删除那里的数据,请联系您的管理员。
  • seedfire.org(仅此宣传网站) —— 使用 Google Analytics 4 汇总统计访问量与页面浏览(见 Cookie 政策)。门户、控制台、应用与命令行中不运行任何统计分析。

2. Seedfire 服务器存储的数据

为提供登录、访问管理与连接服务,Seedfire 服务器在运营方自己的基础设施上存储:

  • 账号数据:用户名、密码哈希(argon2id,绝不存明文密码)、邮箱地址及验证时间、开启两步验证后的密钥与恢复码哈希;若您用 Google、GitHub 或 Microsoft 登录,则还有该提供方返回的稳定账号标识与邮箱地址。Seedfire 不向提供方索取其他任何信息。
  • 设备:登录您账号的每台电脑及您纳管的每台设备的名称、操作系统、Seedfire 版本、最后活动时间与最后 IP 地址。
  • 连接记录:谁、从哪台电脑、连到哪台设备、何时、多久、如何结束。不记录连接内容——流量在您的电脑与设备之间端到端加密,服务器无法读取。
  • 审计日志:登录、授权与管理操作的用户名、动作、时间与来源 IP。
  • 访问数据:分组、授权,以及运营方选择存储的连接凭据——用运营方持有的主密钥加密,永不回显。

3. ZZZ 如何使用 my.seedfire.org 上的数据

仅用于运营服务:让您登录、验证邮箱、发送您请求的账号邮件(确认链接、换邮箱通知、安全通知)、执行配额、保障服务安全并回应您的请求。我们不出售个人数据、不用于广告,除下列子处理方或法律要求外不与任何人共享。

4. 子处理方(仅 my.seedfire.org)

  • Amazon Web Services(美国)—— 服务器托管与账号邮件投递(Amazon SES)。
  • Google、GitHub、Microsoft —— 仅当您选择用其登录时;同时受该提供方隐私政策约束。

5. 保存期限

在 my.seedfire.org:始终未验证邮箱的账号会被自动删除;连接记录与审计日志保存有限期限后删除;账号数据在账号存续期间保留。已登录设备与私有设备您可在门户自行删除;删除账号请联系我们。自托管部署的保存期限由运营方配置。

6. 安全措施

全程 TLS、argon2id 密码哈希、按次签发的短时效 SSH 证书、封存的凭据存储、哈希化的会话与恢复令牌、两步验证,以及签名并经哈希校验的软件更新。

7. 您的权利

视您所在地区,您可能有权访问、更正、删除或导出个人数据,或反对其处理。针对 my.seedfire.org 请邮件联系我们(见下),我们将在 30 天内回应;针对自托管部署请联系其运营方。

Cookie 政策

my.seedfire.org 与 Seedfire 控制台只使用必要的第一方 Cookie —— 没有广告、统计分析或第三方 Cookie,不做跨站跟踪。公开网站 seedfire.org 另使用 Google Analytics(见下)。

Cookie用途有效期
seedfire_portal、seedfire_session保持门户 / 控制台登录状态(HttpOnly、Secure);服务端只存哈希。会话;退出即清除
seedfire_portal_csrf保护登录表单免受跨站请求伪造。短时
seedfire_portal_sso、seedfire_portal_sso2承载进行中的 Google/GitHub/Microsoft 登录的密封状态。10 分钟
seedfire_trusted仅控制台、勾选“记住此设备”后:免输验证码(密码始终必需)。由运营方设定的天数
seedfire_lang记住您的语言选择。1 年
seedfire_flash 等操作后显示一次性确认横幅。显示后删除

seedfire.org 网站统计

seedfire.org 的宣传页面(首页、联系、本页)加载 Google Analytics 4(Google LLC),用于了解有多少人访问、看了哪些页。Google 会设置 _ga 与 _ga_* Cookie(最长 2 年)以区分回访浏览器;GA4 不存储 IP 地址,我们也未启用广告功能或 Google Signals。数据为汇总访问统计,不与任何 Seedfire 账号关联。如需退出,可使用内容拦截器或 Google 的退出插件。语言切换只记在浏览器本地存储中。

联系方式

ZZZ Tech Solutions LLC · sales@zzztechs.com · 或使用联系表单。