Vailuna
기능 자주 묻는 질문 신뢰 모델 개인정보

    隐私政策

    最近更新:2026-07-16

    Vailuna("本应用""我们")是一款本地端到端加密的文件管理器。这份隐私政策说明本应用如何处理你的数据——最重要的一点是:本应用没有自己的后端服务器,开发者无法访问、也无从收集你存入保险库的任何文件内容。

    1. 核心原则

    • 你的照片、文件在离开你的设备之前就已经用 XChaCha20-Poly1305(配合 Argon2id 派生密钥)在本机加密,密钥由你的密码/生物识别派生,开发者不掌握、也无法找回。
    • 云端同步(iCloud / Dropbox / Google Drive)中,服务器只保存密文,无法读取你的文件内容或文件名。
    • 本应用不运营任何自有服务器;不含广告 SDK;不含第三方数据分析/统计 SDK;不做用户行为追踪。
    • 崩溃诊断日志完全保存在本机,从不自动上传——只有你主动点击"导出诊断日志"并通过邮件发给开发者时才会离开设备,且日志中不含文件名或文件内容。

    2. 会离开你设备的数据

    除了你主动发起的云同步(见第 3 节)之外,本应用只有以下几种情况会把数据发送出设备,全部经由 Apple 官方服务,不经过本应用开发者:

    场景发送内容发给谁可否关闭
    相册地图搜索你手动输入的地名搜索文本(不含照片坐标)Apple 地图(MKLocalSearch)不使用该功能即不触发
    属性面板小地图快照照片拍摄坐标所在的约 1 公里范围Apple 地图(MKMapSnapshotter)不点开属性面板即不触发
    属性面板地址反查照片的精确拍摄坐标Apple 地图(CLGeocoder 反向地理编码)随打开属性面板自动发生;离线/失败静默降级
    密码 AutoFill 系统建议已保存登录条目的域名 + 用户名(不含密码)仅写入 iOS 本机系统索引,不经网络设置页可随时关闭并清空

    以上均为向 Apple 自身的系统服务发起的请求,不经过本应用开发者的服务器(因为本应用没有服务器);照片文件内容、文件名、非坐标类元数据不会包含在这些请求中。

    3. 云同步(可选)

    你可以选择把加密后的保险库同步到自己的 iCloud、Dropbox 或 Google Drive 账号。授权过程直接在你的设备与 Apple / Dropbox / Google 的官方登录页之间完成(OAuth2 + PKCE),登录凭证不经过本应用开发者的任何服务器中转。Dropbox 仅申请"App 专属文件夹"权限;Google Drive 仅使用对用户不可见的 appDataFolder 隐藏空间——两者都接触不到你账号里的其它文件。无论选哪个渠道,云端存储的都只是加密后的密文,开发者与云服务提供商都无法解密查看。你可以随时在设置里断开同步渠道。

    4. 设备权限

    • 相机:拍照后直接加密存入保险库,或用于"按物件搜索"的实时取景(图像仅在本机处理)。
    • 相册:导入你选择的照片/视频;选择过程走系统选择器,本应用不会读取未被选中的内容。
    • Face ID / 生物识别:仅用于本机解锁或授权 AutoFill 填充,识别结果由系统 Secure Enclave 处理,不离开设备。
    • 位置相关权限:本应用不读取设备实时 GPS 位置;地图功能使用的是照片自带的拍摄地点元数据,具体网络请求见第 2 节。

    5. 你的选择

    是否开启云同步、AutoFill、地理位置相关展示,均由你在设置中主动选择。你可以随时删除本机保险库、断开云同步账号授权、在设置中关闭 AutoFill。因为本应用不运营账号系统、不做用户画像,也就没有"导出我的数据""删除我的账号"这类需要向开发者发起的请求——你的数据本来就只存在于你自己的设备和你自己的云账号里。

    6. 儿童隐私

    本应用不专门面向 13 岁以下儿童,也不会有意收集其个人信息。

    7. 政策变更

    如本政策有实质性变更,我们会更新本页"最近更新"日期,并在应用内"关于"页提示。继续使用本应用即表示你接受更新后的政策。

    8. 联系我们

    如对本隐私政策有疑问,可发邮件至 [email protected]。

    This page isn't translated into your language yet — showing the English version below.

    Privacy Policy

    Last updated: 2026-07-16

    Vailuna ("the app", "we") is a local, end-to-end encrypted file manager. This policy explains how the app handles your data — most importantly: the app has no backend server of its own. The developer cannot access, and has no way to collect, any file content you store in your vault.

    1. Core principles

    • Your photos and files are encrypted on-device with XChaCha20-Poly1305 (keys derived via Argon2id) before they ever leave your device. Keys are derived from your password/biometrics; the developer never holds them and cannot recover them.
    • When you sync to iCloud / Dropbox / Google Drive, the server only ever stores ciphertext — it cannot read your file contents or filenames.
    • The app runs no server of its own, contains no advertising SDK, no third-party analytics SDK, and does no user behavior tracking.
    • Diagnostic logs stay on-device and are never uploaded automatically — they only leave your device if you explicitly tap "Export diagnostic log" and email it to the developer yourself, and they never contain filenames or file content.

    2. Data that leaves your device

    Other than cloud sync you initiate yourself (see section 3), the app only sends data off-device in the following cases — all of them requests to Apple's own system services, never to the developer:

    ScenarioWhat's sentSent toCan it be turned off
    Gallery map searchThe place name text you type (never photo coordinates)Apple Maps (MKLocalSearch)Not triggered unless you use the feature
    Item detail mini-map snapshotA roughly 1 km region around a photo's capture locationApple Maps (MKMapSnapshotter)Not triggered unless you open the item detail panel
    Item detail address lookupThe photo's precise capture coordinatesApple Maps (CLGeocoder reverse geocoding)Happens automatically when you open the detail panel; fails silently offline
    Password AutoFill system suggestionsDomain + username of saved logins (never passwords)iOS's own on-device credential index only — no network requestCan be turned off any time in Settings, which also clears the index

    All of the above are requests to Apple's own system services and never pass through the developer's infrastructure (because none exists). File content, filenames, and non-location metadata are never included in these requests.

    3. Cloud sync (optional)

    You can choose to sync your encrypted vault to your own iCloud, Dropbox, or Google Drive account. Sign-in happens directly between your device and Apple's / Dropbox's / Google's own login pages (OAuth2 + PKCE) — credentials never pass through any server operated by the developer. Dropbox access is scoped to an app-specific folder only; Google Drive access is scoped to the hidden appDataFolder that's invisible in your regular Drive — neither can touch the rest of your account. Whichever channel you use, only ciphertext is ever stored in the cloud; neither the developer nor the cloud provider can decrypt it. You can disconnect sync at any time in Settings.

    4. Device permissions

    • Camera — used to encrypt a photo straight into your vault, or for live preview during object search (processed entirely on-device).
    • Photo library — used to import the photos/videos you pick via the system picker; the app never reads anything you didn't select.
    • Face ID / biometrics — used only to unlock the vault locally or authorize AutoFill; results are handled by the system Secure Enclave and never leave the device.
    • Location-related access — the app never reads your device's live GPS location; map features use a photo's own embedded capture location metadata, if present. See section 2 for the exact network requests involved.

    5. Your choices

    Cloud sync, AutoFill, and map-related display are all opt-in features you control in Settings. You can delete your local vault, disconnect sync accounts, or turn off AutoFill at any time. Since the app has no account system and builds no user profile, there's no "export my data" or "delete my account" request to make of the developer — your data only ever lives on your own device and in your own cloud account.

    6. Children's privacy

    The app is not directed at children under 13 and does not knowingly collect personal information from them.

    7. Changes to this policy

    If we make a material change to this policy, we'll update the "Last updated" date on this page and note it in the app's About screen. Continuing to use the app after an update means you accept the revised policy.

    8. Contact us

    Questions about this policy? Email [email protected].

    Vailuna

    열쇠는 당신 손에

    보안 데모 기능 시작하기 자주 묻는 질문 신뢰 모델 개인정보
    iOS · iPadOS · macOS · Android · Windows © 2026 Vailuna