隐私政策

适用范围与基本原则

浮屏(英文名 floato,下称「浮屏」或「我们」)是一款由个人开发者开发和运营的 iPhone App:你把一张凭证截图或通过快捷指令提交的一段文字交给它,它识别出品牌、凭证码、时间和地点,做成锁屏上的一张实时活动卡。

我们只处理让这件事跑起来所必需的数据。浮屏没有账号系统,不出售你的数据,没有广告,也不追踪你在其他 App 和网站上的活动。下面按数据逐条说明我们拿什么、用来干什么、留多久。

我们处理的数据

除最后一条外,下面的数据都由浮屏的服务器处理;服务器运行在 Cloudflare Workers 上。

  • 你选择上传的截图。上传前会在你的设备上压缩为 JPEG 副本,原图及其元数据(拍摄时间、位置等)不离开设备。

    用途
    交给云端 AI 模型识别其中的凭证信息。每次上传都由你手动发起,只处理你选中的那一张。
    保留
    不保存。识别完成后即丢弃,服务器上没有你的截图副本。
  • 你通过快捷指令提交的文字(例如取件短信或复制的订单消息)。只接收你交给快捷指令的内容,不读取其他短信。

    用途
    交给云端 AI 模型识别其中的凭证信息;可由你运行快捷指令或设置自动化发起,不用于训练模型。
    保留
    不保存。仅用于当次识别,完成后即丢弃;服务器不保留原文,AI 服务商不得留存或用于训练。本机原文用于查看与重试,不经 iCloud 同步,删除这条记录的最后一个凭证时一并删除。
  • 你开启 AI 检测后,由所配置快捷指令或自动化传入的每条文字,以及你提供的通知 App 或发件人来源。包括最终没有生成凭证的内容;不读取其他短信或通知。

    用途
    经 OpenRouter 交给 OpenAI,判断是否包含可生成凭证的信息。检测默认关闭,首次开启需要明确同意并检查服务可用性;不消耗点数,不确定时由你确认是否继续完整识别。
    保留
    服务器不保存检测原文、来源或判定结果,不写入内容日志。沿用识别服务的不用于训练及不留存原文要求。授权与错误通知去重时间只存本机;可在自动化引导页撤销授权,也可在快捷指令中关闭自动化。
  • 匿名余额身份对应的每月 AI 检测使用次数,不包含原文、来源或检测结果。

    用途
    让同一 Apple 账户的设备共享检测使用上限,防止重复领取;通过已验证的余额会话确定权益档位,检测本身不预留或消耗点数。
    保留
    仅保留当前和上一个 UTC 自然月的计数,更早计数按日自动清理;不保存余额会话原文。
  • 识别结果:品牌、凭证码或二维码内容、商品摘要、时间、截图或文字里出现的地点文字,以及识别状态。

    用途
    回传给 App 生成卡片,并通过推送更新锁屏卡的状态。
    保留
    服务器最多保留 24 小时,之后自动删除。App 本机的副本由你自行删除。
  • 推送凭据:Apple 推送服务(APNs)为这张实时活动卡签发的启动与更新令牌。

    用途
    把识别结果与状态变化推送到你的锁屏。
    保留
    随对应的识别记录一并删除(最多 24 小时)。
  • 设备完整性凭据:Apple App Attest 生成的密钥标识与验证结果。

    用途
    确认请求来自未被篡改的正版浮屏 App,防止服务被滥用。
    保留
    服务器保存该设备密钥的公钥与标识;其中不含任何个人信息。
  • 安装标识(一个随机生成的 UUID)与发起方式(App 内、分享面板或快捷指令)。

    用途
    匿名统计有多少安装真正用起来了、从哪个入口用。它不与识别内容关联,也无法反推到你。
    保留
    Cloudflare Analytics Engine 中保留约 90 天。
  • 点数余额身份:由 Apple 已验证的 App 内购交易派生的哈希标识,以及点数批次(数量、付费点数无到期时间;赠送点数的到期时间、来源)。仅在计费功能开启后产生。

    用途
    把同一 Apple 账户在多台设备上的点数余额与订阅权益归到一处。
    保留
    不保存原始 Apple 交易标识或收据。没有余额、欠账或需保留的购买交易防重记录,且账户闲置 180 天后自动删除。
  • 订阅状态:建立余额会话时,服务器向 Apple 查询你的自动续期订阅是否有效及本期结束时刻,并把结果连同时间戳签进本次会话。

    用途
    判定订阅期间的云端识别不扣点,以及免费试用期适用的每日识别上限。
    保留
    不写入账本、不长期保存,只随当次会话存在;账本只记录退款或撤销的标记。同一时刻我们也会向 RevenueCat 核对一次同样的问题(见「第三方服务」),结果目前只用于比对两边是否一致。我们拿不到你的 Apple 账户密码或完整付款信息。
  • 问题反馈:你填写的问题类型与描述、自动生成的诊断包(近期关键事件与系统状态,不含截图、提交的原文、凭证码、商品摘要或精确地点)、你自选附上的图片,以及你自愿填写的联系邮箱。

    用途
    排查问题并回复你。邮箱只用于这一次反馈的沟通,不作为身份使用。
    保留
    原始反馈连同附件与邮箱在 14 天后自动删除;长期只保留一份不含邮箱、诊断包与附件的处理摘要。
  • 运行日志:请求结果、耗时、错误类别与匿名短标识。

    用途
    保障可靠性与排障。
    保留
    最多 30 天。日志中不记录截图、提交的原文、凭证码、商品摘要或精确地点。
  • 分享图:当你使用「分享」时,票面信息在你的设备上本机生成一张图片;凭证码与二维码只在你打开「显示取件码」时才进图。

    用途
    让你把凭证发给别人,或存进相册。
    保留
    不经过服务器、不上传。图片交给系统分享面板后由你自行保管。图里永不包含原始截图。
  • 本机数据:凭证记录、归档、地点校准、提醒、你设置的品牌 logo 与头像,以及用于查看和重试的原始截图或原文。

    用途
    在 iPhone 与 Apple Watch 上展示和管理你的凭证。
    保留
    只保存在你的设备上,不上传。删除 App 即清除。

第三方服务

为了提供上述功能,我们使用以下第三方服务。它们只在完成对应功能所需的范围内处理数据。

  • Cloudflare:承载浮屏的服务器与存储(Workers、Durable Objects、R2、Analytics Engine)。
  • Apple:推送通知(APNs)、设备完整性验证(App Attest)、App 内购交易验真、以及地图搜索与导航(MapKit)。地点搜索与导航由你的设备直接向 Apple 发起,浮屏的服务器不经手你的位置。
  • RevenueCat:订阅与购买记录的核对。为了判断你的订阅是否有效,Apple 签发的购买/退款通知原文会被原样转发给它,我们也会用你的匿名余额账户号向它查询订阅状态。它接触不到你的截图、提交的原文、凭证内容、位置或 Apple 账户信息。
  • 云端 AI 模型服务商:识别在第三方提供的多模态模型上完成,当前经 OpenRouter 接入。我们会按你当前的 App Store 店面选择合规且可用的服务商,所有服务商都必须承诺不将你的截图或提交的文字用于训练模型,并在完成实时识别后不留存图片或原文。具体处理方可能随地区不同。

这些服务商各自的隐私政策适用于它们对数据的处理。

我们不做的事

  • 不需要注册账号,不保存你的姓名、邮箱或手机号(你在问题反馈里自愿填写的邮箱除外,见上表)。
  • 不收集你的位置。服务器只拿到截图或文字里出现的地点文字;把它变成地图坐标、导航和提醒都在你的设备上完成。
  • 不内置广告或第三方分析、追踪 SDK;不出售数据,不为广告目的共享数据;不追踪你跨 App 或网站的活动。
  • 仅处理你选择的截图、主动分享的截图,或通过你运行或设置的快捷指令及自动化提交的文字,不读取其他短信或内容。

你的控制与权利

  • 你控制上传的截图或提交的文字,也可以在快捷指令 App 中关闭自己设置的自动化。
  • 本机的凭证记录可以随时在 App 内删除;删除 App 会清除全部本机数据。
  • 服务器上的数据都有上述自动删除期限。若你希望更早删除,或想了解我们是否持有与你相关的数据,请通过下方邮箱联系我们;在 App 的「问题反馈」里提交并附带编号,能让我们更快定位。
  • 推送权限、相册访问权限可以随时在 iOS「设置」中更改。

儿童

浮屏按 App Store 4+ 分级准备,不面向儿童设计,也不会有意收集 13 岁以下儿童的个人信息。

数据存放与跨境传输

浮屏的服务器由 Cloudflare 的全球网络承载,云端 AI 服务商按你的 App Store 店面选择;这意味着数据可能在你所在地区之外被处理。我们只在完成识别所需的时间内传输和处理数据,并遵守本政策所述的保留期限。

本政策的变更

当数据处理方式发生变化时,我们会更新本页并修改页首的生效日期。重大变更会在 App 内提示。

联系我们

关于隐私的任何问题或请求,请发邮件至 support@thoamsy.me,或在 App 的「设置 → 问题反馈」中提交。

返回首页

Privacy Policy

Scope and principles

floato (Chinese name 浮屏, “floato”, “we”) is an iPhone app built and operated by an independent developer: you hand it a screenshot of a pass or text through Shortcuts, it recognises the brand, code, time and place, and turns them into a Live Activity card on your Lock Screen.

We process only what is needed to make that work. floato has no accounts, does not sell your data, shows no ads, and does not track your activity across other apps or websites. Below, item by item: what we receive, what it is for, and how long we keep it.

Data we process

Except for the last item, everything below is handled by floato’s server, which runs on Cloudflare Workers.

  • The screenshot you choose to upload. It is compressed to a JPEG copy on your device first; the original file and its metadata (capture time, location, etc.) never leave the device.

    Purpose
    Sent to a cloud AI model to recognise the pass information. Every upload is started by you and covers only the one screenshot you picked.
    Retention
    Not stored. Discarded as soon as recognition finishes; the server keeps no copy of your screenshot.
  • Text you submit through Shortcuts, such as a pickup message or copied order details. We receive only what you pass to the shortcut and do not read other messages.

    Purpose
    Sent to a cloud AI model to recognise pass information, through a shortcut you run or an automation you configure. Never used to train models.
    Retention
    Not stored. Used only for that recognition and discarded when it finishes; the server keeps no source text. AI providers must not retain it or use it for training. The on-device original is used for viewing and retries, is not synced through iCloud, and is deleted with the last pass in that record.
  • Every text passed by a configured shortcut or automation with AI detection enabled, and the notification app or sender source you provide. This includes content that does not produce a pass. No other messages or notifications are read.

    Purpose
    Sent through OpenRouter to OpenAI to check whether it contains pass information. Detection is off by default, requires explicit consent and an availability check, and uses no credits. Uncertain results ask for confirmation before full recognition.
    Retention
    The server does not store detection text, source or verdicts, or write content to logs. The same no-training and no-retention requirements as recognition apply. Authorization and error-notification deduplication times stay on your device. Revoke authorization in the automation guide or turn off the automation in Shortcuts.
  • Monthly AI detection usage counts associated with the anonymous balance identity, without text, source or detection verdicts.

    Purpose
    Share the detection use limit across devices belonging to the same Apple account and prevent duplicate allowances. A verified balance session determines the membership tier; detection itself never reserves or consumes credits.
    Retention
    Only the current and previous UTC calendar month are kept; older counts are automatically removed by daily maintenance. Raw balance sessions are not stored.
  • The recognition result: brand, code or QR content, item summary, time, any place text found in the screenshot or submitted text, and the recognition status.

    Purpose
    Returned to the app to build the card, and pushed to update the Lock Screen card’s state.
    Retention
    Kept on the server for at most 24 hours, then deleted automatically. The copy in the app is yours to delete.
  • Push credentials: the start and update tokens Apple Push Notification service (APNs) issues for that Live Activity.

    Purpose
    Delivering results and state changes to your Lock Screen.
    Retention
    Deleted together with the recognition record (at most 24 hours).
  • Device integrity credentials: the key identifier and verification result produced by Apple App Attest.

    Purpose
    Confirming requests come from a genuine, unmodified floato app, to prevent abuse of the service.
    Retention
    The server keeps the public key and identifier of that device key; they contain no personal information.
  • An install identifier (a randomly generated UUID) and the entry point used (in-app, share sheet, or Shortcuts).

    Purpose
    Anonymous statistics on how many installs are actually used and from which entry point. It is not linked to recognition content and cannot be traced back to you.
    Retention
    About 90 days in Cloudflare Analytics Engine.
  • Credit balance identity: a hashed identifier derived from an Apple-verified in-app purchase transaction, plus credit batches (amount, purchased credits with no expiry, gifted credits with an expiry, and origin). Only created once billing is enabled.

    Purpose
    Keeping one credit balance and one subscription entitlement across the devices signed in to the same Apple Account.
    Retention
    The original Apple transaction identifier and receipt are not stored. An account with no balance, no outstanding debt, and no retained purchase deduplication records is deleted after 180 days of inactivity.
  • Subscription status: when a balance session is created, the server asks Apple whether your auto-renewable subscription is active and when the current period ends, and signs the answer with a timestamp into that session.

    Purpose
    Deciding that cloud recognitions during a subscription do not consume credits, and which daily recognition cap applies during a free trial.
    Retention
    Not written to the ledger and not kept long-term; it lives only in that session. The ledger records only refund or revocation markers. At the same moment we ask RevenueCat the same question (see “Third-party services”); for now that answer is only compared against Apple’s. We never receive your Apple Account password or full payment details.
  • Problem reports: the problem type and description you write, an automatically generated diagnostic bundle (recent key events and system state — never screenshots, submitted text, codes, item summaries or precise locations), any images you choose to attach, and an optional contact email.

    Purpose
    Investigating the problem and getting back to you. The email is used only for that report; it is not an identity.
    Retention
    The original report, attachments and email are deleted after 14 days; only a digest without email, diagnostics or attachments is kept long-term.
  • Operational logs: request outcome, timing, error category and a short anonymous identifier.

    Purpose
    Reliability and troubleshooting.
    Retention
    At most 30 days. Logs never contain screenshots, submitted text, codes, item summaries or precise locations.
  • Share images: when you use “Share”, a picture of the pass details is rendered on your device; the code and QR code are included only when you turn on “Show code”.

    Purpose
    Sending a pass to someone else, or saving it to your Photos.
    Retention
    Never sent to our servers. Once handed to the system share sheet, the image is yours to keep. It never includes the original screenshot.
  • On-device data: pass records, archive, location calibration, reminders, the brand logos and avatar you set, and the original screenshots or source text used for viewing and retries.

    Purpose
    Showing and managing your passes on iPhone and Apple Watch.
    Retention
    Stored only on your devices and never uploaded. Deleting the app removes it.

Third-party services

We rely on the following services to provide the features above. Each processes data only as far as its function requires.

  • Cloudflare: hosts floato’s server and storage (Workers, Durable Objects, R2, Analytics Engine).
  • Apple: push notifications (APNs), device integrity (App Attest), in-app purchase verification, and map search and directions (MapKit). Place search and navigation go straight from your device to Apple; floato’s server never handles your location.
  • RevenueCat: subscription and purchase bookkeeping. To tell whether your subscription is active, the Apple-signed purchase and refund notifications are forwarded to it as-is, and we ask it about your subscription using your anonymous balance account id. It never sees your screenshots, submitted text, pass contents, location or Apple Account details.
  • Cloud AI model providers: recognition runs on third-party multimodal models, currently reached through OpenRouter. We pick a compliant, available provider based on your current App Store storefront; every provider must commit not to train on your screenshots or submitted text and not to retain images or source text after real-time recognition. The actual processor may differ by region.

Each provider’s own privacy policy governs its handling of the data.

What we do not do

  • No account to create; we do not store your name, email or phone number (except an email you volunteer in a problem report, see above).
  • We do not collect your location. The server only sees place text that appears in the screenshot or submitted text; turning it into map coordinates, directions and reminders happens on your device.
  • No advertising, analytics or tracking SDKs; no selling of data, no sharing for advertising; no tracking across apps or websites.
  • We process only screenshots you select or share, or text submitted by Shortcuts and automations you run or configure. We do not read other messages or content.

Your controls and rights

  • You control the screenshots and text submitted, and can turn off your configured automations in the Shortcuts app.
  • Pass records on the device can be deleted in the app at any time; deleting the app removes all on-device data.
  • Server-side data has the automatic deletion periods listed above. To have it removed sooner, or to ask whether we hold anything relating to you, contact us at the email below; filing it through the app’s “Report a Problem” with its reference number helps us locate it faster.
  • Notification and Photos permissions can be changed at any time in iOS Settings.

Children

floato is prepared for an App Store 4+ rating, is not designed for children, and does not knowingly collect personal information from children under 13.

Where data is processed

floato’s server runs on Cloudflare’s global network, and cloud AI providers are chosen by your App Store storefront, so data may be processed outside your region. We transfer and process data only for as long as recognition requires and within the retention periods stated in this policy.

Changes to this policy

When our data practices change, we update this page and the effective date at the top. Material changes will be announced in the app.

Contact

For any privacy question or request, email support@thoamsy.me or use Settings → Report a Problem in the app.

Back to home