中文这份政策说明 floato 如何处理你的截图、凭证信息与服务数据。
1. 适用范围与基本原则
本政策适用于 floato(中文名“浮屏”)iPhone App 及其配套云端服务。floato 不要求注册账号,也不收集姓名、邮箱、手机号或密码。我们只处理完成截图识别、实时活动、订阅权益与服务安全所必需的数据。
floato 不是商家或凭证签发方。识别结果仅供你查看,实际使用前请以商家原始信息为准。
2. 我们处理的数据
- 你主动提交的截图:当你从系统分享菜单或照片选择器提交图片时,图片会发送到云端进行 AI 识别。提交前,App 会单独告知并征得你的同意。
- 识别出的凭证信息:可能包括商家名称、取餐码或提货码、商品摘要、时间、有效期及截图中可见的地点线索。
- 订阅与用量:我们处理 Apple 签名的交易凭据,并保存哈希化的匿名订阅标识、订阅状态、当前周期用量及到期时间。我们不会获得你的 Apple Account 密码或完整付款信息。
- 安全与推送数据:我们使用 Apple App Attest 验证合法安装,并为 Live Activity 处理请求作用域的推送令牌。令牌不用于营销。
- 运行日志:为可靠性与故障排查,我们记录请求结果、耗时、错误类别及匿名短 ID;日志不包含截图、取餐码、商品摘要或精确地点。
- 设备本地数据:凭证结果、归档状态、自定义品牌图、提醒设置及你主动校准的地点保存在设备上。校准地点与提醒信息不会上传到 floato 服务端。
3. 使用目的
我们仅将上述数据用于:识别截图中的凭证信息;生成和更新锁屏 Live Activity;提供本地凭证管理、提醒和导航;验证订阅权益与识别额度;防止滥用、保护服务安全;以及排查错误和维持服务可靠性。我们不出售个人数据,不投放第三方广告,不跨 App 或网站跟踪你,也不使用截图建立用户画像。
4. 第三方处理服务
为提供核心功能,数据可能由以下服务处理:
- Apple:StoreKit、App Attest、Apple Push Notification service、ActivityKit 与 MapKit。
- Cloudflare:托管 floato 的云端接口并处理网络请求。
- 云端 AI 服务商:当前识别链路可能使用 Xiaomi MiMo;具体处理服务可能根据你的 App Store 地区与服务可用性调整。截图只用于完成当次识别。
我们要求参与处理的第三方提供与本政策及 Apple 要求相同或相当的数据保护,不得将截图用于训练,并在实时处理完成后不保留图片。
5. 保存与删除
- 原始截图只在上传与当次识别期间短暂使用,不在服务端或设备上持久保存。
- 服务端结构化识别结果最多保存 24 小时,随后自动删除。
- 运行日志最多保存 30 天,随后自动清理。
- 匿名订阅记录在订阅失效 180 天后自动删除。
- App Attest 安全记录仅在验证安装、防止滥用及保护服务所必需的期间保存。
- 设备本地数据保留至你在 App 内删除对应凭证、清除相关设置或卸载 App。
6. 你的选择与控制
- 你可以选择不提交截图;不提交时,云端识别不会开始。
- 你可以在 iOS“设置”中撤回照片、位置或通知权限。位置和通知不是使用截图识别功能的强制条件。
- 你可以在 App 内删除本地凭证及相关地点、提醒与品牌自定义数据。
- 你可以在 Apple 的订阅管理界面取消自动续期。
- 由于 floato 不设账号,多数服务端识别数据会在上述期限内自动删除。如需提出隐私问题或删除请求,请通过 floato 技术支持页面 联系开发者,并提供足以定位请求的匿名信息;请勿发送完整取餐码或原始截图。
7. 数据安全
我们采用传输加密、Apple App Attest、短期会话令牌、访问控制和数据最小化措施保护信息。任何系统都无法保证绝对安全;如发生可能影响你权利的安全事件,我们会按适用法律采取通知和补救措施。
8. 儿童隐私
floato 面向一般用户,不以儿童为目标,也不会故意收集儿童的个人信息。如果你认为儿童在未经适当授权的情况下提交了个人信息,请通过 floato 技术支持页面 联系开发者。
9. 政策变更与联系
我们可能因产品、服务商或法律要求变化而更新本政策。重大变化会在 App 或本页面显著说明,并更新页面顶部日期。如对本政策有疑问,请使用 floato 技术支持页面 联系开发者。
ENThis policy explains how floato handles screenshots, credential information, and service data.
1. Scope and principles
This Privacy Policy applies to the floato iPhone app (Chinese name: 浮屏) and its supporting cloud services. floato does not require an account and does not collect your name, email address, phone number, or password. We process only the data needed for screenshot recognition, Live Activities, subscription entitlement, and service security.
floato is not a merchant or credential issuer. Recognition results are provided for convenience; always verify them against the merchant’s original information before use.
2. Data we process
- Screenshots you submit: When you submit an image through the system share menu or photo picker, it is sent to cloud AI for recognition. The app provides a separate notice and asks for your consent before the first upload.
- Extracted credential information: This may include merchant name, pickup or collection code, item summary, date and time, expiration, and location hints visible in the screenshot.
- Subscription and usage: We process Apple-signed transaction information and retain a hashed anonymous subscription identifier, subscription status, current-period usage, and expiration. We do not receive your Apple Account password or full payment details.
- Security and push data: We use Apple App Attest to validate legitimate installations and process request-scoped push tokens for Live Activities. Push tokens are not used for marketing.
- Operational logs: For reliability and troubleshooting, we record request outcome, duration, error category, and short anonymous IDs. Logs do not contain screenshots, pickup codes, item summaries, or precise locations.
- On-device data: Credential results, archive state, custom brand images, reminder settings, and locations you choose to calibrate are stored on your device. Calibrated locations and reminder information are not uploaded to floato.
3. How we use data
We use the data only to recognize credentials in screenshots; create and update lock-screen Live Activities; provide local credential management, reminders, and navigation; verify subscription entitlement and recognition allowance; prevent abuse and protect service security; and diagnose errors and maintain reliability. We do not sell personal data, serve third-party ads, track you across apps or websites, or use screenshots to build user profiles.
4. Third-party processors
Core features may involve the following services:
- Apple: StoreKit, App Attest, Apple Push Notification service, ActivityKit, and MapKit.
- Cloudflare: Hosts floato’s cloud endpoints and processes network requests.
- Cloud AI providers: The current recognition path may use Xiaomi MiMo. The provider may vary according to your App Store region and service availability. Screenshots are used only to complete the requested recognition.
We require processors to provide the same or equivalent protection described here and required by Apple, not to use screenshots for training, and not to retain images after real-time processing is complete.
5. Retention and deletion
- Original screenshots are used briefly during upload and recognition and are not persistently stored on our servers or your device.
- Structured recognition results are retained on the server for no more than 24 hours and are then automatically deleted.
- Operational logs are retained for no more than 30 days.
- Anonymous subscription records are automatically deleted 180 days after the subscription becomes inactive.
- App Attest security records are kept only as long as needed to validate installations, prevent abuse, and protect the service.
- On-device data remains until you delete the related credential or settings in the app, or uninstall the app.
6. Your choices and controls
- You may choose not to submit a screenshot; cloud recognition will not begin without a submission.
- You may revoke Photos, Location, or Notifications permissions in iOS Settings. Location and notifications are not required to use screenshot recognition.
- You may delete local credentials and their related location, reminder, and brand customization data within the app.
- You may cancel auto-renewal through Apple’s subscription management interface.
- Because floato has no account system, most server-side recognition data is deleted automatically under the periods above. To ask a privacy question or request deletion, contact the developer through the floato Support page and provide enough anonymous information to locate the request. Do not send a full pickup code or original screenshot.
7. Security
We use encryption in transit, Apple App Attest, short-lived session tokens, access controls, and data minimization. No system can guarantee absolute security. If a security incident may affect your rights, we will provide notice and take remedial steps as required by applicable law.
8. Children’s privacy
floato is a general-audience utility and is not directed to children. We do not knowingly collect children’s personal information. If you believe a child submitted personal information without appropriate authorization, contact the developer through the floato Support page.
9. Changes and contact
We may update this policy when our product, processors, or legal requirements change. Material changes will be highlighted in the app or on this page, and the date above will be updated. For questions, use the floato Support page.