隱私權政策

本 App 由 rollitinno(個人開發者)營運,下稱「我們」。

本政策適用於 iOS 上的失常相機,下稱「本 App」。它不適用於 Apple、RevenueCat、Google,也不適用於任何你自己選擇把照片分享過去的 App,那些各自適用它們的政策。Android 版目前未公開發佈;若之後發佈,同一份政策一併適用。

使用本 App 即表示你同意這份政策。不同意的話,請不要使用本 App。

一、摘要

失常相機沒有帳號、不用登入,我們也沒有任何伺服器保管你的資料。你在 App 裡做的事(抽到哪幾台相機、拍了什麼)都留在你的裝置上。

只有四件事會離開你的裝置:

  • 查詢購買狀態。App 開啟時會向 RevenueCat 詢問這台裝置有沒有有效的訂閱或買斷,以及方案的價格。App 開啟時就會發生一次,購買時再發生一次。它不會帶上你的照片或任何我們自己造的識別碼。RevenueCat 會自己給這台裝置一個匿名 ID。連不上網路時 App 照樣能用,除了付費相關的功能以外全部離線。
  • 購買與恢復購買。付款由 Apple 處理,購買憑證由 RevenueCat 驗證。
  • 你自己按分享。交出去的是一張照片,交給裝置的系統分享單,去哪裡由你決定。
  • 當機回報。App 當掉、或遇到一個它接不住的錯誤時,一份回報會送到 Firebase Crashlytics,讓我們找到那個問題。裡面有什麼,見第四節。

第 1、4 項會自己發生;第 2、3 項只有你自己做才會發生。

本 App 不會上傳你的照片。你可以自行分享照片;裝置備份與相簿同步依你的系統設定運作(見第八節)。我們沒有伺服器可以接收照片,也沒有寫任何上傳照片的程式。

二、本 App 存在你裝置上的資料

存在本 App 自己的偏好儲存空間:

照片。本 App 有自己的相簿,所以它會在自己的私有儲存空間裡保留最近 24 張照片。超過 24 張之後,最舊的檔案會在下一次存檔時自動刪除。

同時,每張照片會自動存進你的照片圖庫(前提是你給了相簿權限),並收進圖庫裡一個叫「Salvage Cam」的相簿。那一份是你的,不歸我們管,也不受上面 24 張的規則影響。

⚠️ 如果你沒有給相簿權限,照片就只會留在 App 的私有空間,也就會被 24 張的規則汰換掉。要留住作品,請開啟相簿權限。

本 App 不會把位置資訊寫進照片,也沒有要求位置權限。

三、這些資料怎麼被使用

第二節列出的一切,都在你的裝置上被用來讓這個 App 運作:

我們沒有伺服器,也不會收到你的照片、你抽到哪幾台相機,或你用了多久。除了第四節說明的購買相關連線與當機回報,本 App 不會自動把資料送給我們或第三方。

與你有關的資料裡,由本 App 送到第三方的只有購買相關的那兩件與當機回報(見第四節)。

四、購買與第三方服務

當你購買或恢復購買時:

當機回報會送到 Firebase Crashlytics(Google),時機是 App 當掉、或遇到一個它接不住的錯誤。一份回報可能包含當機的堆疊、你的裝置型號、作業系統版本、App 版本、發生的時間、當下的部分 App 狀態,以及一個 Firebase 產生的安裝識別碼。裡面沒有你的照片,也沒有你抽到哪幾台相機。我們只用它來找出並修好那個問題。

以上就是全部。本 App 沒有接分析工具、沒有廣告 SDK,也沒有任何 AI 服務。故障是在你的裝置上由演算法即時算出來的。

它們的政策:

五、權限

本 App 沒有要求位置、聯絡人、行事曆、健康或任何其他權限。

六、我們不做的事

七、資料保存與刪除

第二節列出的所有資料都留在你的裝置上,直到你把它們刪掉為止。

八、裝置備份

iOS:本 App 的偏好資料以及它私有空間裡的那 24 張照片,可能被納入你的裝置所做的 iCloud 備份或加密的本機備份。那份副本屬於你、留在你的 Apple 帳號裡,可以在 iOS 設定裡刪除。我們讀不到它。

你存進相簿的照片依你自己的相簿備份設定處理,與本 App 無關。

九、你的權利

因為沒有帳號、我們也沒有伺服器,我們手上沒有任何一份你的資料可以代你查閱、更正、匯出或刪除。它們全部在你手上:移除 App 就清掉偏好資料,相簿裡的照片由你自己管理。

至於第四節說的購買紀錄,來信告訴我們,我們會把你的請求轉給 RevenueCat。與付款資料有關的請求,Apple 依它自己的政策直接處理。

十、兒童

失常相機不以未滿 13 歲的兒童為對象,我們也不會在知情的情況下蒐集他們的個人資料。若你認為有兒童透過本 App 提供了資料給我們,請與我們聯絡。不過實際上本 App 沒有帳號、不上傳任何內容,我們這邊沒有東西可以移除。

十一、國際傳輸

我們沒有伺服器,也不會把你的資料跨境傳輸。Apple 與 RevenueCat 可能在你所在地以外的國家(包括美國)處理購買資料,Google 可能在美國處理當機回報,依它們自己的政策與保護措施進行。

十二、安全

本 App 的偏好資料與最近 24 張照片存於它自己的私有儲存空間,由你的作業系統與螢幕鎖保護。取得相簿權限後,拍照完成時也會自動嘗試存入照片圖庫,並收進「Salvage Cam」相簿。

請注意本 App 沒有另外的密碼鎖:任何能解鎖你裝置的人都可以打開它。沒有任何儲存方式是絕對安全的,我們無法保證百分之百的安全。

十三、供應範圍

失常相機目前不在歐洲經濟區(歐盟 27 國、冰島、挪威、列支敦斯登)提供。

十四、本政策的變更

如果本 App 的資料流有變(新增服務、新增備份功能,或任何會把資料送出裝置的東西),這份政策會在同一次改版一起更新,最上面的日期也會跟著改。重大變更也會寫在版本更新說明裡。更新後繼續使用本 App,即表示你接受修訂後的政策。

十五、聯絡方式

[email protected]

Privacy Policy

The app is operated by rollitinno, an individual developer, referred to below as "we".

This policy covers Salvage Cam on iOS, referred to below as "the app". It does not cover Apple, RevenueCat, Google, or any other app you choose to share a photo into; those are governed by their own policies. The Android build is not publicly released; if it is released later, this same policy applies to it.

Using the app means you accept this policy. If you do not accept it, please do not use the app.

1. Summary

Salvage Cam has no accounts and no sign-in, and we run no server that holds your data. What you do in the app (which cameras you drew, what you shot) stays on your device.

Only four things ever leave your device:

  • Checking your purchase status. On launch, the app asks RevenueCat whether this device has an active subscription or lifetime unlock, and what the plans cost. It happens once at launch, then again when you buy. It carries none of your photos and no identifier we invent. RevenueCat assigns this device an anonymous ID of its own. The app works without a connection; everything except the paid-purchase paths is offline.
  • Buying and restoring purchases. Apple handles payment; RevenueCat validates the receipt.
  • Sharing, when you tap share. A photo goes to your device's share sheet. Where it goes from there is your choice.
  • Crash reports. When the app crashes, or hits an error it cannot handle, a report goes to Firebase Crashlytics so we can find the fault. What it contains is in section 4.

The first and fourth happen on their own. The other two happen only when you do them.

The app does not upload your photos. You can share them yourself; device backups and photo-library syncing follow your system settings (see section 8). We have no server to receive photos and no code that uploads them.

2. What the app stores on your device

In the app's own preference storage:

Photos. The app has its own roll, so it keeps the 24 most recent photos in its private storage. Past 24, the oldest files are deleted automatically on the next save.

Every shot is also saved to your photo library automatically, provided you granted photo access, and filed into an album called “Salvage Cam”. That copy is yours, is not ours to manage, and the 24-photo limit does not touch it.

If you have not granted photo access, a shot lives only in the app's private storage, which means the 24-photo limit will eventually remove it. Grant access if you want to keep what you shoot.

The app does not write location data into photos and does not request location permission.

3. How that data is used

We have no server and never receive your photos, your cameras, or how long you used the app. Apart from the purchase paths and crash reports in section 4, nothing is sent to us or to third parties.

4. Purchases and third-party services

Crash reports go to Firebase Crashlytics (Google) when the app crashes or hits an error it cannot handle. A report may contain the stack trace, your device model, its OS version, the app version, the time it happened, some of the app's state at that moment, and an installation identifier that Firebase generates. It contains none of your photos and none of the cameras you drew. We use these reports only to find and fix the fault.

That is the complete list. There is no analytics tool, no advertising SDK, and no AI service. Faults are computed on your device.

Their policies: RevenueCat · Apple · Firebase

5. Permissions

The app requests no location, contacts, calendar, health, or other permissions.

6. What we do not do

7. Retention and deletion

8. Device backups

iOS: the app's preference data and the 24 photos in its private storage may be included in your device's iCloud or encrypted local backup. That copy is yours, sits in your Apple account, and can be deleted in iOS settings. We cannot read it.

Photos in your system library follow your own photo-library backup settings, independently of this app.

9. Your rights

Because there are no accounts and no server of ours, we hold no copy of your data to access, correct, export, or delete on your behalf. It is all in your hands: remove the app to clear preferences; manage saved photos in your library.

For the purchase records in section 4, write to us and we will pass your request to RevenueCat. Payment-data requests are handled directly by Apple under its own policy.

10. Children

Salvage Cam is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided data to us through the app, please get in touch. In practice there are no accounts and nothing is uploaded, so there is nothing on our side to remove.

11. International transfers

We have no server and transfer no data across borders. Apple and RevenueCat may process purchase data, and Google may process crash reports, in countries outside your own, including the United States, under their own policies and safeguards.

12. Security

The app's preferences and 24 most recent photos sit in its private storage, protected by your operating system and screen lock. After you grant photo access, the app also automatically attempts to save each completed shot to your photo library, filed into the “Salvage Cam” album.

Note that the app has no separate passcode: anyone who can unlock your device can open it. No method of storage is completely secure, and we cannot guarantee absolute security.

13. Where the app is available

Salvage Cam is currently not offered in the European Economic Area (the 27 EU member states plus Iceland, Norway, and Liechtenstein).

14. Changes to this policy

If the app's data flows change (a new service, a new backup feature, anything that sends data off the device), this policy is updated in the same release and the dates above change with it. Significant changes are also noted in the release notes. Continuing to use the app after an update means you accept the revised policy.

15. Contact

[email protected]