隐私政策
maskable 不收集任何数据。你的图片永远不离开你的设备,我们没有服务器,也没有任何可以接收数据的地方。
这不是一句口号,而是应用的架构:除了 Apple 的 App 内购买(StoreKit)之外,应用中不存在任何网络请求。
1. 我们收集什么
不收集。这份政策之所以很短,是因为没有太多可写的。具体来说:
- 不收集个人身份信息
- 不收集使用数据、崩溃日志或统计信息
- 不收集设备标识符、广告标识符
- 不收集位置信息
- 没有账号系统,无需注册或登录
应用在 App Store 上的隐私标签为「未收集数据(Data Not Collected)」,与此一致。
2. 你的图片
所有图像处理 —— 文字识别、隐私风险检测、打码、标注、拼接、导出 —— 全部在你的设备本机完成。
图片不会被上传、不会被写入应用沙盒之外的位置、不会出现在任何日志中。
识别出的敏感内容(手机号、身份证号等)只存在于内存与你设备上的编辑记录里,同样不进日志、不进导出文件、不参与任何诊断。
你在应用内建立的隐私词库属于最高敏感数据,只存于本机,处理方式同上。
3. 权限说明
| 权限 | 用途 |
|---|---|
| 照片 | 展示你的相册、读取你选择的图片进行编辑、把结果存回相册。仅在你主动操作时读取,不做后台批量扫描。 |
| 相机 | 仅在你选择「拍照」时使用,用于拍摄后立即在本机编辑。 |
| Face ID | 可选的应用锁。它只是界面上的一道门禁,不加密任何数据。 |
你可以选择「有限访问」,此时应用只能看到你明确授权的那些照片。
4. 第三方
应用中没有集成任何第三方 SDK:没有分析、没有崩溃上报、没有广告、没有远程配置、没有 A/B 测试。
唯一涉及外部的是 Apple 的 StoreKit,用于处理订阅与购买。这部分由 Apple 直接处理,我们收不到你的支付信息,也收不到你的 Apple 账户信息 —— 应用只能知道「当前这台设备上的这个 Apple 账户是否持有有效权益」这一个布尔结果,且该判断在设备本地完成。
Apple 对 App Store 交易的处理适用 Apple 隐私政策。
5. 数据存储与保留
应用的项目文件与缓存保存在你设备的应用沙盒内,启用了系统的完整文件保护。你删除应用时,这些数据随之删除。
「临时编辑」模式下的内容在你退出时即被删除。
iCloud 备份默认关闭;你可以在设置中自行开启。
6. 儿童
本应用不面向 13 岁以下儿童,也不会有意收集儿童的任何信息 —— 事实上它不收集任何人的信息。
7. 你的权利(GDPR / CCPA 等)
访问、更正、删除、可携、拒绝出售等权利都以「控制者持有你的个人数据」为前提。我们不持有任何数据,因此没有可供访问、导出或删除的记录。你设备上的数据完全由你控制:删除应用即全部清除。
我们不出售、不分享、不交易任何个人信息,因为我们没有。
8. 政策变更
本政策可能随应用更新而调整。变更会通过更新本页的生效日期体现。如果未来出现任何形式的数据收集(目前没有这样的计划),我们会在应用内明确告知并征求你的同意。
9. 联系方式
关于隐私的任何问题,请发邮件至 peimao918@gmail.com。
Privacy Policy
maskable collects nothing. Your images never leave your device. We have no server, and no place that could receive data.
That is architecture, not a slogan: apart from Apple’s in-app purchases (StoreKit), the app makes no network requests at all.
1. What we collect
Nothing. This policy is short because there is little to write. Specifically, we do not collect:
- personal information
- usage data, crash logs, or analytics
- device or advertising identifiers
- location
There is no account system; nothing to register or sign in to. The App Store privacy label reads Data Not Collected, consistent with the above.
2. Your images
All image work — text recognition, privacy risk detection, redaction, annotation, stitching, export — happens on your device.
Images are never uploaded, never written outside the app’s own container, and never appear in any log.
Sensitive values found during a scan (phone numbers, ID numbers, and so on) exist only in memory and in the edit record on your device. They are likewise kept out of logs, out of exported files, and out of any diagnostics.
The privacy term list you build inside the app is treated as the most sensitive data of all: stored locally only, handled the same way.
3. Permissions
| Permission | Why |
|---|---|
| Photos | To show your albums, read the image you pick for editing, and save the result back. Read only when you act; there is no background scan of your library. |
| Camera | Only when you choose to take a photo, so it can be edited on-device straight away. |
| Face ID | An optional app lock. It is a gate in the interface and does not encrypt anything. |
You may grant limited photo access, in which case the app sees only the photos you explicitly select.
4. Third parties
There are no third-party SDKs in the app: no analytics, no crash reporting, no advertising, no remote config, no A/B testing.
The only external component is Apple’s StoreKit, for subscriptions and purchases. Apple handles that directly. We never receive your payment details or your Apple Account information — the app learns exactly one thing, decided locally on the device: whether an active entitlement exists.
Apple’s handling of App Store transactions is covered by the Apple Privacy Policy.
5. Storage and retention
Project files and caches live in the app’s container on your device with the system’s complete file protection enabled. Deleting the app deletes them.
Content in temporary editing mode is deleted when you leave it.
iCloud backup is off by default; you can turn it on in Settings.
6. Children
The app is not directed at children under 13 and does not knowingly collect information from them — it collects nothing from anyone.
7. Your rights (GDPR, CCPA, and similar)
Rights of access, rectification, erasure, portability, and opt-out of sale all presuppose that a controller holds your personal data. We hold none, so there is no record to access, export, or delete. The data on your device is entirely under your control: removing the app removes all of it.
We do not sell, share, or trade personal information, because we have none.
8. Changes
This policy may change as the app is updated; changes are reflected in the effective date above. If any form of data collection is ever introduced — there is no such plan — you will be told inside the app and asked to agree first.
9. Contact
Privacy questions: peimao918@gmail.com.