floato (Chinese name 浮屏, “floato”, “we”) is an iPhone app built and operated by an independent developer: you hand it a screenshot of a pass or text through Shortcuts, it recognises the brand, code, time and place, and turns them into a Live Activity card on your Lock Screen.
We process only what is needed to make that work. floato has no accounts, does not sell your data, shows no ads, and does not track your activity across other apps or websites. Below, item by item: what we receive, what it is for, and how long we keep it.
Data we process
Except for the last item, everything below is handled by floato’s server, which runs on Cloudflare Workers.
The screenshot you choose to upload. It is compressed to a JPEG copy on your device first; the original file and its metadata (capture time, location, etc.) never leave the device.
Purpose
Sent to a cloud AI model to recognise the pass information. Every upload is started by you and covers only the one screenshot you picked.
Retention
Not stored. Discarded as soon as recognition finishes; the server keeps no copy of your screenshot.
Text you submit through Shortcuts, such as a pickup message or copied order details. We receive only what you pass to the shortcut and do not read other messages.
Purpose
Sent to a cloud AI model to recognise pass information, through a shortcut you run or an automation you configure. Never used to train models.
Retention
Not stored. Used only for that recognition and discarded when it finishes; the server keeps no source text. AI providers must not retain it or use it for training. The on-device original is used for viewing and retries, is not synced through iCloud, and is deleted with the last pass in that record.
Every text passed by a configured shortcut or automation with AI detection enabled, and the notification app or sender source you provide. This includes content that does not produce a pass. No other messages or notifications are read.
Purpose
Sent through OpenRouter to OpenAI to check whether it contains pass information. Detection is off by default, requires explicit consent and an availability check, and uses no credits. Uncertain results ask for confirmation before full recognition.
Retention
The server does not store detection text, source or verdicts, or write content to logs. The same no-training and no-retention requirements as recognition apply. Authorization and error-notification deduplication times stay on your device. Revoke authorization in the automation guide or turn off the automation in Shortcuts.
Monthly AI detection usage counts associated with the anonymous balance identity, without text, source or detection verdicts.
Purpose
Share the detection use limit across devices belonging to the same Apple account and prevent duplicate allowances. A verified balance session determines the membership tier; detection itself never reserves or consumes credits.
Retention
Only the current and previous UTC calendar month are kept; older counts are automatically removed by daily maintenance. Raw balance sessions are not stored.
The recognition result: brand, code or QR content, item summary, time, any place text found in the screenshot or submitted text, and the recognition status.
Purpose
Returned to the app to build the card, and pushed to update the Lock Screen card’s state.
Retention
Kept on the server for at most 24 hours, then deleted automatically. The copy in the app is yours to delete.
Push credentials: the start and update tokens Apple Push Notification service (APNs) issues for that Live Activity.
Purpose
Delivering results and state changes to your Lock Screen.
Retention
Deleted together with the recognition record (at most 24 hours).
Device integrity credentials: the key identifier and verification result produced by Apple App Attest.
Purpose
Confirming requests come from a genuine, unmodified floato app, to prevent abuse of the service.
Retention
The server keeps the public key and identifier of that device key; they contain no personal information.
An install identifier (a randomly generated UUID) and the entry point used (in-app, share sheet, or Shortcuts).
Purpose
Anonymous statistics on how many installs are actually used and from which entry point. It is not linked to recognition content and cannot be traced back to you.
Retention
About 90 days in Cloudflare Analytics Engine.
Credit balance identity: a hashed identifier derived from an Apple-verified in-app purchase transaction, plus credit batches (amount, purchased credits with no expiry, gifted credits with an expiry, and origin). Only created once billing is enabled.
Purpose
Keeping one credit balance and one subscription entitlement across the devices signed in to the same Apple Account.
Retention
The original Apple transaction identifier and receipt are not stored. An account with no balance, no outstanding debt, and no retained purchase deduplication records is deleted after 180 days of inactivity.
Subscription status: when a balance session is created, the server asks Apple whether your auto-renewable subscription is active and when the current period ends, and signs the answer with a timestamp into that session.
Purpose
Deciding that cloud recognitions during a subscription do not consume credits, and which daily recognition cap applies during a free trial.
Retention
Not written to the ledger and not kept long-term; it lives only in that session. The ledger records only refund or revocation markers. At the same moment we ask RevenueCat the same question (see “Third-party services”); for now that answer is only compared against Apple’s. We never receive your Apple Account password or full payment details.
Problem reports: the problem type and description you write, an automatically generated diagnostic bundle (recent key events and system state — never screenshots, submitted text, codes, item summaries or precise locations), any images you choose to attach, and an optional contact email.
Purpose
Investigating the problem and getting back to you. The email is used only for that report; it is not an identity.
Retention
The original report, attachments and email are deleted after 14 days; only a digest without email, diagnostics or attachments is kept long-term.
Operational logs: request outcome, timing, error category and a short anonymous identifier.
Purpose
Reliability and troubleshooting.
Retention
At most 30 days. Logs never contain screenshots, submitted text, codes, item summaries or precise locations.
Share images: when you use “Share”, a picture of the pass details is rendered on your device; the code and QR code are included only when you turn on “Show code”.
Purpose
Sending a pass to someone else, or saving it to your Photos.
Retention
Never sent to our servers. Once handed to the system share sheet, the image is yours to keep. It never includes the original screenshot.
On-device data: pass records, archive, location calibration, reminders, the brand logos and avatar you set, and the original screenshots or source text used for viewing and retries.
Purpose
Showing and managing your passes on iPhone and Apple Watch.
Retention
Stored only on your devices and never uploaded. Deleting the app removes it.
Third-party services
We rely on the following services to provide the features above. Each processes data only as far as its function requires.
Cloudflare: hosts floato’s server and storage (Workers, Durable Objects, R2, Analytics Engine).
Apple: push notifications (APNs), device integrity (App Attest), in-app purchase verification, and map search and directions (MapKit). Place search and navigation go straight from your device to Apple; floato’s server never handles your location.
RevenueCat: subscription and purchase bookkeeping. To tell whether your subscription is active, the Apple-signed purchase and refund notifications are forwarded to it as-is, and we ask it about your subscription using your anonymous balance account id. It never sees your screenshots, submitted text, pass contents, location or Apple Account details.
Cloud AI model providers: recognition runs on third-party multimodal models, currently reached through OpenRouter. We pick a compliant, available provider based on your current App Store storefront; every provider must commit not to train on your screenshots or submitted text and not to retain images or source text after real-time recognition. The actual processor may differ by region.
Each provider’s own privacy policy governs its handling of the data.
What we do not do
No account to create; we do not store your name, email or phone number (except an email you volunteer in a problem report, see above).
We do not collect your location. The server only sees place text that appears in the screenshot or submitted text; turning it into map coordinates, directions and reminders happens on your device.
No advertising, analytics or tracking SDKs; no selling of data, no sharing for advertising; no tracking across apps or websites.
We process only screenshots you select or share, or text submitted by Shortcuts and automations you run or configure. We do not read other messages or content.
Your controls and rights
You control the screenshots and text submitted, and can turn off your configured automations in the Shortcuts app.
Pass records on the device can be deleted in the app at any time; deleting the app removes all on-device data.
Server-side data has the automatic deletion periods listed above. To have it removed sooner, or to ask whether we hold anything relating to you, contact us at the email below; filing it through the app’s “Report a Problem” with its reference number helps us locate it faster.
Notification and Photos permissions can be changed at any time in iOS Settings.
Children
floato is prepared for an App Store 4+ rating, is not designed for children, and does not knowingly collect personal information from children under 13.
Where data is processed
floato’s server runs on Cloudflare’s global network, and cloud AI providers are chosen by your App Store storefront, so data may be processed outside your region. We transfer and process data only for as long as recognition requires and within the retention periods stated in this policy.
Changes to this policy
When our data practices change, we update this page and the effective date at the top. Material changes will be announced in the app.
Contact
For any privacy question or request, email support@thoamsy.me or use Settings → Report a Problem in the app.