隐私政策

适用范围与基本原则

浮屏(英文名 floato,下称「浮屏」或「我们」)是一款由个人开发者开发和运营的 iPhone App:你把一张凭证截图交给它,它识别出品牌、凭证码、时间和地点,做成锁屏上的一张实时活动卡。

我们只处理让这件事跑起来所必需的数据。浮屏没有账号系统,不出售你的数据,没有广告,也不追踪你在其他 App 和网站上的活动。下面按数据逐条说明我们拿什么、用来干什么、留多久。

我们处理的数据

除最后一条外,下面的数据都由浮屏的服务器处理;服务器运行在 Cloudflare Workers 上。

  • 你选择上传的截图。上传前会在你的设备上压缩为 JPEG 副本,原图及其元数据(拍摄时间、位置等)不离开设备。

    用途
    交给云端 AI 模型识别其中的凭证信息。每次上传都由你手动发起,只处理你选中的那一张。
    保留
    不保存。识别完成后即丢弃,服务器上没有你的截图副本。
  • 识别结果:品牌、凭证码或二维码内容、商品摘要、时间、截图里出现的地点文字,以及识别状态。

    用途
    回传给 App 生成卡片,并通过推送更新锁屏卡的状态。
    保留
    服务器最多保留 24 小时,之后自动删除。App 本机的副本由你自行删除。
  • 推送凭据:Apple 推送服务(APNs)为这张实时活动卡签发的启动与更新令牌。

    用途
    把识别结果与状态变化推送到你的锁屏。
    保留
    随对应的识别记录一并删除(最多 24 小时)。
  • 设备完整性凭据:Apple App Attest 生成的密钥标识与验证结果。

    用途
    确认请求来自未被篡改的正版浮屏 App,防止服务被滥用。
    保留
    服务器保存该设备密钥的公钥与标识;其中不含任何个人信息。
  • 安装标识(一个随机生成的 UUID)与发起方式(App 内、分享面板或快捷指令)。

    用途
    匿名统计有多少安装真正用起来了、从哪个入口用。它不与识别内容关联,也无法反推到你。
    保留
    Cloudflare Analytics Engine 中保留约 90 天。
  • 点数余额身份:由 Apple 已验证的 App 内购交易派生的哈希标识,以及点数批次(数量、到期、来源)。仅在计费功能开启后产生。

    用途
    把同一 Apple 账户在多台设备上的点数余额与订阅权益归到一处。
    保留
    不保存原始 Apple 交易标识或收据。账户在没有余额也没有欠账的状态下闲置 180 天后自动删除。
  • 订阅状态:建立余额会话时,服务器向 Apple 查询你的自动续期订阅是否有效及本期结束时刻,并把结果连同时间戳签进本次会话。

    用途
    判定订阅期间的云端识别不扣点,以及免费试用期适用的每日识别上限。
    保留
    不写入账本、不长期保存,只随当次会话存在;账本只记录退款或撤销的标记。我们拿不到你的 Apple 账户密码或完整付款信息。
  • 问题反馈:你填写的问题类型与描述、自动生成的诊断包(近期关键事件与系统状态,不含截图、凭证码、商品摘要或精确地点)、你自选附上的图片,以及你自愿填写的联系邮箱。

    用途
    排查问题并回复你。邮箱只用于这一次反馈的沟通,不作为身份使用。
    保留
    原始反馈连同附件与邮箱在 14 天后自动删除;长期只保留一份不含邮箱、诊断包与附件的处理摘要。
  • 运行日志:请求结果、耗时、错误类别与匿名短标识。

    用途
    保障可靠性与排障。
    保留
    最多 30 天。日志中不记录截图、凭证码、商品摘要或精确地点。
  • 代取分享链接:当你使用「找人代取」时,我们保存一份冻结的最小快照——取什么、去哪取、取件姓名与凭证码或二维码内容。

    用途
    让你指定的人打开链接就能看到凭证,对方无需安装浮屏。
    保留
    链接创建后 1 小时自动失效并删除;你可以随时撤销。快照不含原始截图。
  • 本机数据:凭证记录、归档、地点校准、提醒、你设置的品牌 logo 与头像。

    用途
    在 iPhone 与 Apple Watch 上展示和管理你的凭证。
    保留
    只保存在你的设备上,不上传。删除 App 即清除。

第三方服务

为了提供上述功能,我们使用以下第三方服务。它们只在完成对应功能所需的范围内处理数据。

  • Cloudflare:承载浮屏的服务器与存储(Workers、Durable Objects、R2、Analytics Engine)。
  • Apple:推送通知(APNs)、设备完整性验证(App Attest)、App 内购交易验真,以及地图搜索与导航(MapKit)。地点搜索与导航由你的设备直接向 Apple 发起,浮屏的服务器不经手你的位置。
  • 云端 AI 模型服务商:识别在第三方提供的多模态模型上完成,当前经 OpenRouter 接入。我们会按你当前的 App Store 店面选择合规且可用的服务商,所有服务商都必须承诺不将你的截图用于训练模型,并在完成实时识别后不留存图片。具体处理方可能随地区不同。

这些服务商各自的隐私政策适用于它们对数据的处理。

我们不做的事

  • 不需要注册账号,不保存你的姓名、邮箱或手机号(你在问题反馈里自愿填写的邮箱除外,见上表)。
  • 不收集你的位置。服务器只拿到截图里出现的地点文字;把它变成地图坐标、导航和提醒都在你的设备上完成。
  • 不内置广告或第三方分析、追踪 SDK;不出售数据,不为广告目的共享数据;不追踪你跨 App 或网站的活动。
  • 不自动上传任何内容。每一次识别都由你手动选择一张截图或主动分享发起。

你的控制与权利

  • 上传由你逐次发起,只处理你选中的那一张截图。
  • 本机的凭证记录可以随时在 App 内删除;删除 App 会清除全部本机数据。
  • 代取链接可以随时在 App 内撤销,撤销即刻生效。
  • 服务器上的数据都有上述自动删除期限。若你希望更早删除,或想了解我们是否持有与你相关的数据,请通过下方邮箱联系我们;在 App 的「问题反馈」里提交并附带编号,能让我们更快定位。
  • 推送权限、相册访问权限可以随时在 iOS「设置」中更改。

儿童

浮屏按 App Store 4+ 分级准备,不面向儿童设计,也不会有意收集 13 岁以下儿童的个人信息。

数据存放与跨境传输

浮屏的服务器由 Cloudflare 的全球网络承载,云端 AI 服务商按你的 App Store 店面选择;这意味着数据可能在你所在地区之外被处理。我们只在完成识别所需的时间内传输和处理数据,并遵守本政策所述的保留期限。

本政策的变更

当数据处理方式发生变化时,我们会更新本页并修改页首的生效日期。重大变更会在 App 内提示。

联系我们

关于隐私的任何问题或请求,请发邮件至 support@thoamsy.me,或在 App 的「设置 → 问题反馈」中提交。

返回首页

Privacy Policy

Scope and principles

floato (Chinese name 浮屏, “floato”, “we”) is an iPhone app built and operated by an independent developer: you hand it a screenshot of a pass, it recognises the brand, code, time and place, and turns them into a Live Activity card on your Lock Screen.

We process only what is needed to make that work. floato has no accounts, does not sell your data, shows no ads, and does not track your activity across other apps or websites. Below, item by item: what we receive, what it is for, and how long we keep it.

Data we process

Except for the last item, everything below is handled by floato’s server, which runs on Cloudflare Workers.

  • The screenshot you choose to upload. It is compressed to a JPEG copy on your device first; the original file and its metadata (capture time, location, etc.) never leave the device.

    Purpose
    Sent to a cloud AI model to recognise the pass information. Every upload is started by you and covers only the one screenshot you picked.
    Retention
    Not stored. Discarded as soon as recognition finishes; the server keeps no copy of your screenshot.
  • The recognition result: brand, code or QR content, item summary, time, any place text found in the screenshot, and the recognition status.

    Purpose
    Returned to the app to build the card, and pushed to update the Lock Screen card’s state.
    Retention
    Kept on the server for at most 24 hours, then deleted automatically. The copy in the app is yours to delete.
  • Push credentials: the start and update tokens Apple Push Notification service (APNs) issues for that Live Activity.

    Purpose
    Delivering results and state changes to your Lock Screen.
    Retention
    Deleted together with the recognition record (at most 24 hours).
  • Device integrity credentials: the key identifier and verification result produced by Apple App Attest.

    Purpose
    Confirming requests come from a genuine, unmodified floato app, to prevent abuse of the service.
    Retention
    The server keeps the public key and identifier of that device key; they contain no personal information.
  • An install identifier (a randomly generated UUID) and the entry point used (in-app, share sheet, or Shortcuts).

    Purpose
    Anonymous statistics on how many installs are actually used and from which entry point. It is not linked to recognition content and cannot be traced back to you.
    Retention
    About 90 days in Cloudflare Analytics Engine.
  • Credit balance identity: a hashed identifier derived from an Apple-verified in-app purchase transaction, plus credit batches (amount, expiry, origin). Only created once billing is enabled.

    Purpose
    Keeping one credit balance and one subscription entitlement across the devices signed in to the same Apple Account.
    Retention
    The original Apple transaction identifier and receipt are not stored. An account with no balance and no outstanding debt is deleted after 180 days of inactivity.
  • Subscription status: when a balance session is created, the server asks Apple whether your auto-renewable subscription is active and when the current period ends, and signs the answer with a timestamp into that session.

    Purpose
    Deciding that cloud recognitions during a subscription do not consume credits, and which daily recognition cap applies during a free trial.
    Retention
    Not written to the ledger and not kept long-term; it lives only in that session. The ledger records only refund or revocation markers. We never receive your Apple Account password or full payment details.
  • Problem reports: the problem type and description you write, an automatically generated diagnostic bundle (recent key events and system state — never screenshots, codes, item summaries or precise locations), any images you choose to attach, and an optional contact email.

    Purpose
    Investigating the problem and getting back to you. The email is used only for that report; it is not an identity.
    Retention
    The original report, attachments and email are deleted after 14 days; only a digest without email, diagnostics or attachments is kept long-term.
  • Operational logs: request outcome, timing, error category and a short anonymous identifier.

    Purpose
    Reliability and troubleshooting.
    Retention
    At most 30 days. Logs never contain screenshots, codes, item summaries or precise locations.
  • Hand-off links: when you use “Hand it off”, we store a frozen minimal snapshot — what to collect, where, the pickup name and the code or QR content.

    Purpose
    Letting the person you choose see the pass by opening a link, with no app required.
    Retention
    The link expires and is deleted 1 hour after creation; you can revoke it at any time. The snapshot never includes the original screenshot.
  • On-device data: pass records, archive, location calibration, reminders, the brand logos and avatar you set.

    Purpose
    Showing and managing your passes on iPhone and Apple Watch.
    Retention
    Stored only on your devices and never uploaded. Deleting the app removes it.

Third-party services

We rely on the following services to provide the features above. Each processes data only as far as its function requires.

  • Cloudflare: hosts floato’s server and storage (Workers, Durable Objects, R2, Analytics Engine).
  • Apple: push notifications (APNs), device integrity (App Attest), in-app purchase verification, and map search and directions (MapKit). Place search and navigation go straight from your device to Apple; floato’s server never handles your location.
  • Cloud AI model providers: recognition runs on third-party multimodal models, currently reached through OpenRouter. We pick a compliant, available provider based on your current App Store storefront; every provider must commit not to train on your screenshots and not to retain images after real-time recognition. The actual processor may differ by region.

Each provider’s own privacy policy governs its handling of the data.

What we do not do

  • No account to create; we do not store your name, email or phone number (except an email you volunteer in a problem report, see above).
  • We do not collect your location. The server only sees place text that appears in the screenshot; turning it into map coordinates, directions and reminders happens on your device.
  • No advertising, analytics or tracking SDKs; no selling of data, no sharing for advertising; no tracking across apps or websites.
  • Nothing is uploaded automatically. Every recognition starts with you picking a screenshot or sharing one.

Your controls and rights

  • Uploads are started by you, one screenshot at a time.
  • Pass records on the device can be deleted in the app at any time; deleting the app removes all on-device data.
  • Hand-off links can be revoked in the app at any time, effective immediately.
  • Server-side data has the automatic deletion periods listed above. To have it removed sooner, or to ask whether we hold anything relating to you, contact us at the email below; filing it through the app’s “Report a Problem” with its reference number helps us locate it faster.
  • Notification and Photos permissions can be changed at any time in iOS Settings.

Children

floato is prepared for an App Store 4+ rating, is not designed for children, and does not knowingly collect personal information from children under 13.

Where data is processed

floato’s server runs on Cloudflare’s global network, and cloud AI providers are chosen by your App Store storefront, so data may be processed outside your region. We transfer and process data only for as long as recognition requires and within the retention periods stated in this policy.

Changes to this policy

When our data practices change, we update this page and the effective date at the top. Material changes will be announced in the app.

Contact

For any privacy question or request, email support@thoamsy.me or use Settings → Report a Problem in the app.

Back to home