隱私權政策
生效日:2026-08-29 最後更新:2026-09-07
本 App 由 rollitinno(個人開發者)營運,下稱「我們」。
本政策適用於 iOS 上的失常相機,下稱「本 App」。它不適用於 Apple、RevenueCat、Google,也不適用於任何你自己選擇把照片分享過去的 App,那些各自適用它們的政策。Android 版目前未公開發佈;若之後發佈,同一份政策一併適用。
使用本 App 即表示你同意這份政策。不同意的話,請不要使用本 App。
一、摘要
失常相機沒有帳號、不用登入,我們也沒有任何伺服器保管你的資料。你在 App 裡做的事(抽到哪幾台相機、拍了什麼)都留在你的裝置上。
只有四件事會離開你的裝置:
- 查詢購買狀態。App 開啟時會向 RevenueCat 詢問這台裝置有沒有有效的訂閱或買斷,以及方案的價格。App 開啟時就會發生一次,購買時再發生一次。它不會帶上你的照片或任何我們自己造的識別碼。RevenueCat 會自己給這台裝置一個匿名 ID。連不上網路時 App 照樣能用,除了付費相關的功能以外全部離線。
- 購買與恢復購買。付款由 Apple 處理,購買憑證由 RevenueCat 驗證。
- 你自己按分享。交出去的是一張照片,交給裝置的系統分享單,去哪裡由你決定。
- 當機回報。App 當掉、或遇到一個它接不住的錯誤時,一份回報會送到 Firebase Crashlytics,讓我們找到那個問題。裡面有什麼,見第四節。
第 1、4 項會自己發生;第 2、3 項只有你自己做才會發生。
本 App 不會上傳你的照片。你可以自行分享照片;裝置備份與相簿同步依你的系統設定運作(見第八節)。我們沒有伺服器可以接收照片,也沒有寫任何上傳照片的程式。
二、本 App 存在你裝置上的資料
存在本 App 自己的偏好儲存空間:
- 你在導引流程抽到的那幾台相機(以編號的形式儲存)
- 一個累加的抽選序號,用來決定下一張照片的錯誤種子
- 介面語言、主題(Signal/Studio)
- 「保留原始色調」這個開關的狀態
- 導引流程走完了沒有
- 購買狀態的本機快取
照片。本 App 有自己的相簿,所以它會在自己的私有儲存空間裡保留最近 24 張照片。超過 24 張之後,最舊的檔案會在下一次存檔時自動刪除。
同時,每張照片會自動存進你的照片圖庫(前提是你給了相簿權限),並收進圖庫裡一個叫「Salvage Cam」的相簿。那一份是你的,不歸我們管,也不受上面 24 張的規則影響。
⚠️ 如果你沒有給相簿權限,照片就只會留在 App 的私有空間,也就會被 24 張的規則汰換掉。要留住作品,請開啟相簿權限。
本 App 不會把位置資訊寫進照片,也沒有要求位置權限。
三、這些資料怎麼被使用
第二節列出的一切,都在你的裝置上被用來讓這個 App 運作:
- 抽到的相機決定你能用哪幾台相機拍照。
- 抽選序號與當天的日期一起決定錯誤種子——同一顆種子永遠產生同一種故障。這是為了讓故障可以重現。
- 語言、主題與色調開關決定這個 App 看起來的樣子。
我們沒有伺服器,也不會收到你的照片、你抽到哪幾台相機,或你用了多久。除了第四節說明的購買相關連線與當機回報,本 App 不會自動把資料送給我們或第三方。
與你有關的資料裡,由本 App 送到第三方的只有購買相關的那兩件與當機回報(見第四節)。
四、購買與第三方服務
當你購買或恢復購買時:
- Apple 依它自己的條款處理付款。我們看不到你的卡號、姓名或帳單地址。
- RevenueCat 收到購買憑證,用來驗證是否有效並解鎖付費功能。RevenueCat 用它自己產生的匿名識別碼來辨識這台裝置的購買。我們不會把任何我們自己造的識別碼傳給它。RevenueCat 的隱私清單載明:它只蒐集購買紀錄、不與你的身分連結、不用於追蹤。
當機回報會送到 Firebase Crashlytics(Google),時機是 App 當掉、或遇到一個它接不住的錯誤。一份回報可能包含當機的堆疊、你的裝置型號、作業系統版本、App 版本、發生的時間、當下的部分 App 狀態,以及一個 Firebase 產生的安裝識別碼。裡面沒有你的照片,也沒有你抽到哪幾台相機。我們只用它來找出並修好那個問題。
以上就是全部。本 App 沒有接分析工具、沒有廣告 SDK,也沒有任何 AI 服務。故障是在你的裝置上由演算法即時算出來的。
它們的政策:
- RevenueCat:revenuecat.com/privacy
- Apple:apple.com/legal/privacy
- Firebase:firebase.google.com/support/privacy
五、權限
- 相機:拍照。這是這個 App 的本體,不給權限就沒有東西可以弄壞。
- 相簿:取得權限後,拍照完成時自動嘗試把照片存入你的照片圖庫,並放進「Salvage Cam」相簿。
「分類」需要讀寫權限,不是「僅新增」—— 因為要先找到或建立那個相簿。本 App 只寫入自己拍的那幾張,不會讀取、修改或上傳你原本就有的照片,也沒有任何一行程式在做那件事。你也可以只給「僅新增」或「選取的照片」:照片仍然會存進圖庫,只是可能不會被分類。 - 麥克風:本 App 不錄音。iOS 的相機模組連結了系統的音訊擷取介面,所以作業系統要求宣告用途字串;音訊擷取在程式裡是關閉的。Android 版則已在設定檔中明確移除相機套件帶進來的錄音權限,不會出現在權限清單上。
本 App 沒有要求位置、聯絡人、行事曆、健康或任何其他權限。
六、我們不做的事
- 不做產品分析。我們不量測你開了哪些畫面、按了幾次快門、停留多久,也刻意沒有裝 Google Analytics。一個例外:當機回報會帶上工作階段的計數,Firebase 用它算出這支 App 多常當掉。那是穩定度,不是使用行為。
- 當機回報不帶你的內容。見第四節:裡面沒有照片,也沒有你在 App 裡做過的任何事。回報只在當機時送出,不是持續在背景記錄。
- 不放廣告。沒有廣告 SDK,也沒有廣告識別碼。
- 不做追蹤。不會把任何東西與其他 App 或網站的資料合併。
- 沒有帳號,我們也沒有任何保管你資料的伺服器。
- 不接任何 AI 服務。你的照片不會被送到任何模型,我們的或別人的都一樣。
- 絕不販售或出租個人資料。
七、資料保存與刪除
第二節列出的所有資料都留在你的裝置上,直到你把它們刪掉為止。
- 移除本 App 會一併移除它存在那台裝置上的所有偏好資料。
- App 私有空間裡的那 24 張會隨著你繼續拍照自動汰換,移除 App 也會一併刪掉。
- 你存進系統相簿的照片不會被刪除。它們是你的,在你的相簿裡,用相簿本身的方式管理。
- 你的購買紀錄由 Apple 與 RevenueCat 保管,不在我們這裡。要取消訂閱請用裝置的訂閱設定。要請 RevenueCat 刪除它的紀錄,請寫信到第十五節的信箱,我們會代為轉達;請附上 App Store 的訂單編號,那是我們唯一能對到你那筆紀錄的線索。
八、裝置備份
iOS:本 App 的偏好資料以及它私有空間裡的那 24 張照片,可能被納入你的裝置所做的 iCloud 備份或加密的本機備份。那份副本屬於你、留在你的 Apple 帳號裡,可以在 iOS 設定裡刪除。我們讀不到它。
你存進相簿的照片依你自己的相簿備份設定處理,與本 App 無關。
九、你的權利
因為沒有帳號、我們也沒有伺服器,我們手上沒有任何一份你的資料可以代你查閱、更正、匯出或刪除。它們全部在你手上:移除 App 就清掉偏好資料,相簿裡的照片由你自己管理。
至於第四節說的購買紀錄,來信告訴我們,我們會把你的請求轉給 RevenueCat。與付款資料有關的請求,Apple 依它自己的政策直接處理。
十、兒童
失常相機不以未滿 13 歲的兒童為對象,我們也不會在知情的情況下蒐集他們的個人資料。若你認為有兒童透過本 App 提供了資料給我們,請與我們聯絡。不過實際上本 App 沒有帳號、不上傳任何內容,我們這邊沒有東西可以移除。
十一、國際傳輸
我們沒有伺服器,也不會把你的資料跨境傳輸。Apple 與 RevenueCat 可能在你所在地以外的國家(包括美國)處理購買資料,Google 可能在美國處理當機回報,依它們自己的政策與保護措施進行。
十二、安全
本 App 的偏好資料與最近 24 張照片存於它自己的私有儲存空間,由你的作業系統與螢幕鎖保護。取得相簿權限後,拍照完成時也會自動嘗試存入照片圖庫,並收進「Salvage Cam」相簿。
請注意本 App 沒有另外的密碼鎖:任何能解鎖你裝置的人都可以打開它。沒有任何儲存方式是絕對安全的,我們無法保證百分之百的安全。
十三、供應範圍
失常相機目前不在歐洲經濟區(歐盟 27 國、冰島、挪威、列支敦斯登)提供。
十四、本政策的變更
如果本 App 的資料流有變(新增服務、新增備份功能,或任何會把資料送出裝置的東西),這份政策會在同一次改版一起更新,最上面的日期也會跟著改。重大變更也會寫在版本更新說明裡。更新後繼續使用本 App,即表示你接受修訂後的政策。
十五、聯絡方式
Privacy Policy
Effective date: 2026-08-29 Last updated: 2026-09-07
The app is operated by rollitinno, an individual developer, referred to below as "we".
This policy covers Salvage Cam on iOS, referred to below as "the app". It does not cover Apple, RevenueCat, Google, or any other app you choose to share a photo into; those are governed by their own policies. The Android build is not publicly released; if it is released later, this same policy applies to it.
Using the app means you accept this policy. If you do not accept it, please do not use the app.
1. Summary
Salvage Cam has no accounts and no sign-in, and we run no server that holds your data. What you do in the app (which cameras you drew, what you shot) stays on your device.
Only four things ever leave your device:
- Checking your purchase status. On launch, the app asks RevenueCat whether this device has an active subscription or lifetime unlock, and what the plans cost. It happens once at launch, then again when you buy. It carries none of your photos and no identifier we invent. RevenueCat assigns this device an anonymous ID of its own. The app works without a connection; everything except the paid-purchase paths is offline.
- Buying and restoring purchases. Apple handles payment; RevenueCat validates the receipt.
- Sharing, when you tap share. A photo goes to your device's share sheet. Where it goes from there is your choice.
- Crash reports. When the app crashes, or hits an error it cannot handle, a report goes to Firebase Crashlytics so we can find the fault. What it contains is in section 4.
The first and fourth happen on their own. The other two happen only when you do them.
The app does not upload your photos. You can share them yourself; device backups and photo-library syncing follow your system settings (see section 8). We have no server to receive photos and no code that uploads them.
2. What the app stores on your device
In the app's own preference storage:
- Which cameras you drew during onboarding, stored as index numbers
- A running draw counter, used to pick the error seed for the next shot
- Interface language and theme (Signal / Studio)
- Whether "keep the original colour" is on
- Whether you finished onboarding
- A local cache of your purchase status
Photos. The app has its own roll, so it keeps the 24 most recent photos in its private storage. Past 24, the oldest files are deleted automatically on the next save.
Every shot is also saved to your photo library automatically, provided you granted photo access, and filed into an album called “Salvage Cam”. That copy is yours, is not ours to manage, and the 24-photo limit does not touch it.
If you have not granted photo access, a shot lives only in the app's private storage, which means the 24-photo limit will eventually remove it. Grant access if you want to keep what you shoot.
The app does not write location data into photos and does not request location permission.
3. How that data is used
- The cameras you drew decide which cameras you can shoot with.
- The draw counter, together with the current date, decides the error seed; the same seed always produces the same fault. That exists to make faults reproducible.
- Language, theme and the colour switch decide how the app looks.
We have no server and never receive your photos, your cameras, or how long you used the app. Apart from the purchase paths and crash reports in section 4, nothing is sent to us or to third parties.
4. Purchases and third-party services
- Apple handles payment under its own terms. We never see your card number, name, or billing address.
- RevenueCat receives the purchase receipt to validate it and unlock paid features, identifying the purchase by an anonymous identifier it generates. Its privacy manifest declares that it collects purchase history only, not linked to your identity, and not used for tracking.
Crash reports go to Firebase Crashlytics (Google) when the app crashes or hits an error it cannot handle. A report may contain the stack trace, your device model, its OS version, the app version, the time it happened, some of the app's state at that moment, and an installation identifier that Firebase generates. It contains none of your photos and none of the cameras you drew. We use these reports only to find and fix the fault.
That is the complete list. There is no analytics tool, no advertising SDK, and no AI service. Faults are computed on your device.
Their policies: RevenueCat · Apple · Firebase
5. Permissions
- Camera: to take photographs. Without it there is nothing to break.
- Photo library: to automatically attempt to save each completed shot to your photo library after you grant access, and to file it into the “Salvage Cam” album.
Filing needs read-write access rather than add-only, because the album has to be found or created first. The app writes only the shots it takes; it never reads, changes, or uploads photos that are already there, and no code in it does. Grant add-only or limited access instead and shots still reach your library, just possibly unfiled. - Microphone: the app does not record audio. On iOS the camera module links the system's audio-capture interface, so the OS requires a purpose string; capture is disabled in code. On Android the recording permission the camera package would otherwise merge in is explicitly removed, so it never appears in the permission list.
The app requests no location, contacts, calendar, health, or other permissions.
6. What we do not do
- No product analytics. We do not measure which screens you open, how many shots you take, or how long you stay, and Google Analytics is deliberately not installed. One exception: crash reporting counts sessions, which is how Firebase works out how often the app crashes. That is stability, not behaviour.
- Crash reports carry none of your content. See section 4: no photos, and nothing about what you did in the app. They are sent only when something breaks, not logged continuously.
- No advertising. No ad SDK, no advertising identifier.
- No tracking. Nothing is combined with data from other apps or sites.
- No accounts, and no server of ours holding your data.
- No AI services. Your photos are never sent to any model, ours or anyone else's.
- We never sell or rent personal data.
7. Retention and deletion
- Removing the app removes every preference it stored on that device.
- The 24 in the app's private storage rotate out as you keep shooting, and removing the app deletes them all.
- Photos in your system library are not deleted. They are yours, in your library, managed by your library.
- Your purchase record is held by Apple and RevenueCat, not by us. Cancel through your device's subscription settings. To ask RevenueCat to delete its record, write to the address in section 15 and we will pass the request on; include your App Store order number, which is the only way we can match your record.
8. Device backups
iOS: the app's preference data and the 24 photos in its private storage may be included in your device's iCloud or encrypted local backup. That copy is yours, sits in your Apple account, and can be deleted in iOS settings. We cannot read it.
Photos in your system library follow your own photo-library backup settings, independently of this app.
9. Your rights
Because there are no accounts and no server of ours, we hold no copy of your data to access, correct, export, or delete on your behalf. It is all in your hands: remove the app to clear preferences; manage saved photos in your library.
For the purchase records in section 4, write to us and we will pass your request to RevenueCat. Payment-data requests are handled directly by Apple under its own policy.
10. Children
Salvage Cam is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided data to us through the app, please get in touch. In practice there are no accounts and nothing is uploaded, so there is nothing on our side to remove.
11. International transfers
We have no server and transfer no data across borders. Apple and RevenueCat may process purchase data, and Google may process crash reports, in countries outside your own, including the United States, under their own policies and safeguards.
12. Security
The app's preferences and 24 most recent photos sit in its private storage, protected by your operating system and screen lock. After you grant photo access, the app also automatically attempts to save each completed shot to your photo library, filed into the “Salvage Cam” album.
Note that the app has no separate passcode: anyone who can unlock your device can open it. No method of storage is completely secure, and we cannot guarantee absolute security.
13. Where the app is available
Salvage Cam is currently not offered in the European Economic Area (the 27 EU member states plus Iceland, Norway, and Liechtenstein).
14. Changes to this policy
If the app's data flows change (a new service, a new backup feature, anything that sends data off the device), this policy is updated in the same release and the dates above change with it. Significant changes are also noted in the release notes. Continuing to use the app after an update means you accept the revised policy.