floato (Chinese name 浮屏, “floato”, “we”) is an iPhone app built and operated by an independent developer: you hand it a screenshot of a pass, it recognises the brand, code, time and place, and turns them into a Live Activity card on your Lock Screen.
We process only what is needed to make that work. floato has no accounts, does not sell your data, shows no ads, and does not track your activity across other apps or websites. Below, item by item: what we receive, what it is for, and how long we keep it.
Data we process
Except for the last item, everything below is handled by floato’s server, which runs on Cloudflare Workers.
The screenshot you choose to upload. It is compressed to a JPEG copy on your device first; the original file and its metadata (capture time, location, etc.) never leave the device.
Purpose
Sent to a cloud AI model to recognise the pass information. Every upload is started by you and covers only the one screenshot you picked.
Retention
Not stored. Discarded as soon as recognition finishes; the server keeps no copy of your screenshot.
The recognition result: brand, code or QR content, item summary, time, any place text found in the screenshot, and the recognition status.
Purpose
Returned to the app to build the card, and pushed to update the Lock Screen card’s state.
Retention
Kept on the server for at most 24 hours, then deleted automatically. The copy in the app is yours to delete.
Push credentials: the start and update tokens Apple Push Notification service (APNs) issues for that Live Activity.
Purpose
Delivering results and state changes to your Lock Screen.
Retention
Deleted together with the recognition record (at most 24 hours).
Device integrity credentials: the key identifier and verification result produced by Apple App Attest.
Purpose
Confirming requests come from a genuine, unmodified floato app, to prevent abuse of the service.
Retention
The server keeps the public key and identifier of that device key; they contain no personal information.
An install identifier (a randomly generated UUID) and the entry point used (in-app, share sheet, or Shortcuts).
Purpose
Anonymous statistics on how many installs are actually used and from which entry point. It is not linked to recognition content and cannot be traced back to you.
Retention
About 90 days in Cloudflare Analytics Engine.
Credit balance identity: a hashed identifier derived from an Apple-verified in-app purchase transaction, plus credit batches (amount, expiry, origin). Only created once billing is enabled.
Purpose
Keeping one credit balance and one subscription entitlement across the devices signed in to the same Apple Account.
Retention
The original Apple transaction identifier and receipt are not stored. An account with no balance and no outstanding debt is deleted after 180 days of inactivity.
Subscription status: when a balance session is created, the server asks Apple whether your auto-renewable subscription is active and when the current period ends, and signs the answer with a timestamp into that session.
Purpose
Deciding that cloud recognitions during a subscription do not consume credits, and which daily recognition cap applies during a free trial.
Retention
Not written to the ledger and not kept long-term; it lives only in that session. The ledger records only refund or revocation markers. We never receive your Apple Account password or full payment details.
Problem reports: the problem type and description you write, an automatically generated diagnostic bundle (recent key events and system state — never screenshots, codes, item summaries or precise locations), any images you choose to attach, and an optional contact email.
Purpose
Investigating the problem and getting back to you. The email is used only for that report; it is not an identity.
Retention
The original report, attachments and email are deleted after 14 days; only a digest without email, diagnostics or attachments is kept long-term.
Operational logs: request outcome, timing, error category and a short anonymous identifier.
Purpose
Reliability and troubleshooting.
Retention
At most 30 days. Logs never contain screenshots, codes, item summaries or precise locations.
Hand-off links: when you use “Hand it off”, we store a frozen minimal snapshot — what to collect, where, the pickup name and the code or QR content.
Purpose
Letting the person you choose see the pass by opening a link, with no app required.
Retention
The link expires and is deleted 1 hour after creation; you can revoke it at any time. The snapshot never includes the original screenshot.
On-device data: pass records, archive, location calibration, reminders, the brand logos and avatar you set.
Purpose
Showing and managing your passes on iPhone and Apple Watch.
Retention
Stored only on your devices and never uploaded. Deleting the app removes it.
Third-party services
We rely on the following services to provide the features above. Each processes data only as far as its function requires.
Cloudflare: hosts floato’s server and storage (Workers, Durable Objects, R2, Analytics Engine).
Apple: push notifications (APNs), device integrity (App Attest), in-app purchase verification, and map search and directions (MapKit). Place search and navigation go straight from your device to Apple; floato’s server never handles your location.
Cloud AI model providers: recognition runs on third-party multimodal models, currently reached through OpenRouter. We pick a compliant, available provider based on your current App Store storefront; every provider must commit not to train on your screenshots and not to retain images after real-time recognition. The actual processor may differ by region.
Each provider’s own privacy policy governs its handling of the data.
What we do not do
No account to create; we do not store your name, email or phone number (except an email you volunteer in a problem report, see above).
We do not collect your location. The server only sees place text that appears in the screenshot; turning it into map coordinates, directions and reminders happens on your device.
No advertising, analytics or tracking SDKs; no selling of data, no sharing for advertising; no tracking across apps or websites.
Nothing is uploaded automatically. Every recognition starts with you picking a screenshot or sharing one.
Your controls and rights
Uploads are started by you, one screenshot at a time.
Pass records on the device can be deleted in the app at any time; deleting the app removes all on-device data.
Hand-off links can be revoked in the app at any time, effective immediately.
Server-side data has the automatic deletion periods listed above. To have it removed sooner, or to ask whether we hold anything relating to you, contact us at the email below; filing it through the app’s “Report a Problem” with its reference number helps us locate it faster.
Notification and Photos permissions can be changed at any time in iOS Settings.
Children
floato is prepared for an App Store 4+ rating, is not designed for children, and does not knowingly collect personal information from children under 13.
Where data is processed
floato’s server runs on Cloudflare’s global network, and cloud AI providers are chosen by your App Store storefront, so data may be processed outside your region. We transfer and process data only for as long as recognition requires and within the retention periods stated in this policy.
Changes to this policy
When our data practices change, we update this page and the effective date at the top. Material changes will be announced in the app.
Contact
For any privacy question or request, email support@thoamsy.me or use Settings → Report a Problem in the app.