隐私政策

版本 1.16 · 最后更新 2026-09-17

本隐私政策(以下简称「本政策」)适用于本应用及其随附的网络扩展组件。本政策说明本应用在何种情形下处理何种信息、处理的目的与方式、信息的存储位置与留存期限,以及您就此享有的权利。请您在使用本应用前完整阅读本政策。

1. 定义

1.1 「本应用」指本网络代理客户端软件,包括其主程序与随附的网络扩展(NetworkExtension)组件。

1.2 「开发者」指本应用的开发与发布主体,即本政策项下信息处理活动的责任主体。开发者不运营任何服务端。

1.3 「第三方服务提供者」指由您自行选择并在本应用中配置的网络服务提供者。第三方服务提供者与开发者之间不存在隶属、代理、合作或其他控制关系。

1.4 「个人信息」指以电子或者其他方式记录的、能够单独或者与其他信息结合识别特定自然人身份或者反映特定自然人活动情况的各种信息。

2. 信息的收集

2.1 本应用不收集的信息

本应用不收集下列信息:

(1)姓名、出生日期、身份证件号码、电话号码等可直接或间接识别您身份的个人信息;

(2)用于广告投放或者跨应用跟踪的设备标识符;

(3)您经由本应用访问的网址、域名、目标服务器地址、连接发起时间、连接持续时长等访问记录与连接元数据;

(4)经由隧道传输的任何流量内容。

本应用不设置自有账户体系,不要求您向开发者注册或登录,不与任何由开发者运营的服务器通信,亦未集成任何第三方统计分析、广告或崩溃采集软件开发工具包(SDK)。

2.2 您在设备上提供或生成的信息

您在使用本应用的过程中可能输入、导入或生成下列信息:订阅地址、线路配置信息,以及订阅地址中通常内嵌的访问凭据(如令牌、UUID 等)。

上述信息由本应用在您的设备本地处理与存储,存储方式见第 5 条,不向开发者传输。

本应用于「设置 → 订阅」页内提供「复制订阅地址」操作。该操作由您主动发起,本应用不会自动执行;经由该操作写入系统剪贴板的内容已被限定为仅在本机可用(不经由「接力」等功能同步至您的其他设备),并设定十分钟后自动失效。请注意,订阅地址通常内嵌访问凭据,效力等同于密码。

2.3 本地诊断日志

为便于您自行排查连接故障,本应用会在您的设备本地写入运行日志。除隧道建立情况与内核错误信息外,该日志还包含由内核记录的逐条连接记录,其内容包括目标主机名或者 IP、端口、所使用的出站线路以及失败原因。该日志:

(1)仅存储于您设备的本地容器内,不会由本应用自动上传至开发者或者任何第三方;

(2)在本应用内查看或者导出该日志时,逐条连接记录中的目标主机名与 IP 将被替换为占位符,端口、出站线路与失败原因予以保留。即:您主动分享出去的内容不含前述目标地址,而设备本地留存的原始文件仍然包含;

(3)按写入方与内容分别清除:隧道进程写入的内核日志(含轮转产生的副本,其中包含逐条连接记录)在每次发起连接时删除;隧道进程自身的运行日志(仅记录隧道建立、网络切换、启动与停止等事件,不包含连接记录)在每次发起连接时滚存,设备上保留上一次连接的一份;本应用主进程写入的内核日志在每次重新开启日志(应用启动、以及每次连接前测速)时删除;连接前测速的记录每轮覆盖写入。即含连接记录的日志始终仅保留最近一次;

(4)随本应用被卸载而一并删除。

本应用于「活动」页内提供「诊断日志」功能,供您查阅上述日志。您可在该页面主动执行下列操作,该等操作均由您发起,本应用不会自动执行:

(1)复制:日志文本将写入您设备的系统剪贴板。本应用已将该项内容限定为仅在本机可用(不经由「接力」等功能同步至您的其他设备),并设定十分钟后自动失效。

(2)导出:本应用在您设备的临时目录内生成一份日志文件,以供您通过系统分享功能发送。该文件在分享界面关闭后即由本应用删除。

若您为获得技术支持而主动将该日志发送给开发者,该行为属于您的主动提供,其内容与范围由您自行决定。日志内容可能包含您所配置的线路地址与服务器域名,建议您在发送前自行查阅。

3. 信息的使用

3.1 第 2.2 条所述信息,仅用于在您的设备本地建立与维持网络连接、解析与更新您所配置的订阅内容,以及在界面中呈现线路与账户信息。

3.2 第 2.3 条所述信息,仅用于您本人对连接故障的排查。

3.3 本应用不将上述任何信息用于自动化决策、广告投放或者跨应用跟踪,亦不将其用于本政策载明目的之外的用途。

4. 信息的共享、转让与公开披露

4.1 第三方软件开发工具包

本应用未集成任何第三方统计分析、广告或崩溃采集 SDK,不因该等目的向任何第三方共享信息。

4.2 第三方服务提供者

(1)订阅更新:当您导入订阅或者请求更新订阅时,本应用按您所配置的订阅地址向相应第三方服务提供者发起请求。该地址通常内嵌您的访问凭据,该第三方因此可获知您的 IP 地址、请求时间及客户端类型。上述信息流由订阅机制本身决定。

(2)流量传输:连接建立后,您的网络流量经由您所配置的第三方服务提供者的服务器传输,不经过开发者控制的任何服务器。

(3)责任划分:第三方服务提供者对其所获信息的处理适用其自身的隐私政策,不在开发者的控制范围内,开发者亦不就此作出任何陈述或者担保。请您仅配置您信任的服务地址。

(4)首次启动连通性探测:本应用在首次启动时,向 Apple 的连通性检测地址(captive.apple.com)发起一次 HEAD 请求。该请求不携带任何设备标识、账户信息或者您的配置内容,其唯一目的是让操作系统在此时弹出无线数据访问授权(部分机型),以免该授权在您首次导入订阅或者发起连接时中途弹出而导致该次操作失败。该探测在本应用的每次安装中仅执行一次,其结果不被记录、不被上报,亦不影响本应用的任何行为。

(5)设备时钟校正:部分线路协议要求客户端与服务器的时间相差在数十秒以内,设备时钟不准会使该等线路全部无法连接。为此本应用在下列三种情形下查询外部时间源,仅用于计算本设备时钟与标准时间的偏差:① 连接前测速与发起连接之前,向公共 NTP 服务(默认 time.apple.com)查询一次;② 上述查询失败时,改向 cloudflare.com、apple.com、microsoft.com 三个站点发起 HEAD 请求,读取应答头中的标准时间并取一致值;③ 连接建立后,隧道进程按固定间隔(默认 30 分钟)以及在设备唤醒、网络切换时,再次向同一 NTP 服务查询。上述请求均不携带任何设备标识、账户信息或者您的配置内容;相应服务可获知您的 IP 地址与请求时间。查询结果仅在设备本地用于校正时间偏差,不被上报。

4.3 依法披露

除依据法律法规的强制性规定或者有权机关依法定程序提出的要求外,开发者不向任何第三方转让或者公开披露信息。鉴于开发者不持有第 2.2 条、第 2.3 条所述信息,就该等信息而言,开发者不具备提供的条件。

5. 信息的存储、留存与安全

5.1 存储位置

(1)订阅地址、线路配置信息、第三方服务提供者返回的流量与到期信息、内核运行配置与诊断日志,存储于本应用在您设备上的沙盒目录及 App Group 共享容器内。

(2)上述信息均不存储于开发者或者任何第三方控制的服务器。

5.2 留存期限

第 5.1 条第(1)项所述信息随本应用被卸载而一并删除;其中诊断日志另受第 2.3 条第(3)项所述删除机制的约束。

5.3 安全措施

本应用依赖 iOS 提供的应用沙盒隔离与文件保护(Data Protection)机制保护上述本地存储。请您同时为设备设置锁屏密码,并避免在越狱设备上使用本应用。

5.4 iCloud 备份

若您在系统中启用 iCloud 备份或者进行本地加密备份,前述本地数据可能作为系统备份的组成部分被备份。该备份行为由 Apple 提供并控制,适用 Apple 的隐私政策,不构成本应用向开发者的传输。

6. 网络扩展权限的使用

6.1 本应用使用 Apple 提供的 NetworkExtension 框架,在系统「设置 — 通用 — VPN 与设备管理」中创建一项 VPN 配置。该配置的用途,是将设备的网络流量交由运行在您本机的隧道进程处理,并按您所配置的规则转发。iOS 因此在状态栏显示 VPN 标识。

6.2 开发者不利用该项权限进行流量分析、内容读取、内容修改或者注入,亦不记录访问记录。隧道进程运行于您的设备本地,其处理过程不向开发者回传任何数据。

7. 您的权利

7.1 查阅:您可在本应用界面内查阅当前所配置的订阅地址、线路列表,以及订阅返回的流量与到期信息。

7.2 清除与更换:您可在本应用「设置 → 订阅」页执行下列操作:

(1)「移除订阅」:清除订阅地址、已获取的线路列表以及订阅返回的流量与到期信息,断开当前连接,并移除本应用写入系统设置的 VPN 配置;

(2)「更换订阅地址」:以新的订阅地址替换当前配置;

(3)「更新订阅」:按当前订阅地址重新获取线路列表。

执行第(1)项所述操作后,若您再次发起连接,操作系统将重新请求您授权添加 VPN 配置。

7.3 全部删除:卸载本应用将删除本应用存储在设备容器内的全部数据,包括订阅配置与诊断日志。本应用未提供逐条删除历史订阅记录或者手动清除诊断日志的入口。

7.4 撤回同意:您可通过停止使用并卸载本应用撤回对本政策的同意。

7.5 鉴于开发者不存储您的个人信息,向开发者提出的查阅、复制、更正、删除或者可携带请求不存在可执行的对象;相关操作均可由您在本设备上自行完成。

8. 未成年人保护

8.1 本应用不面向 13 周岁以下的儿童,开发者不会有意收集儿童的个人信息。鉴于本应用不收集任何用户的个人信息,亦不存在收集儿童个人信息的情形。

8.2 若您为未成年人,请在监护人的指导下决定是否使用本应用。监护人如对相关事项有疑问,可依第 10 条载明的方式联系开发者。

9. 本政策的变更

9.1 本政策变更时,其版本号将相应提升,并在本应用内再次向您完整展示。您需再次表示同意,方可继续使用本应用。

9.2 本政策的版本号与最后更新日期载于正文末尾的版本标注行。

10. 联系我们

就本政策的任何问题、意见或者投诉,您可通过下列方式联系开发者:hachiminemo@gmail.com


Privacy Policy

Version 1.16 · Last updated 2026-09-17

This Privacy Policy (the "Policy") applies to the Application and its bundled network extension. It describes what information is processed, for what purposes and by what means, where that information is stored and for how long, and what rights you have in relation to it. Please read this Policy in full before using the Application.

1. Definitions

1.1 "Application" means this network proxy client software, including its main program and the bundled NetworkExtension component.

1.2 "Developer" means the entity that develops and distributes the Application, and the party responsible for the processing described in this Policy. The Developer operates no server of any kind.

1.3 "Third-Party Provider" means a network service provider that you select and configure yourself within the Application. No relationship of affiliation, agency, partnership, or control exists between any Third-Party Provider and the Developer.

1.4 "Personal Information" means any information, recorded electronically or otherwise, that identifies an individual or reflects an individual's activities, whether on its own or in combination with other information.

2. Information Collected

2.1 Information Not Collected

The Application does not collect:

(a) your name, date of birth, government identification number, telephone number, or any other information that identifies you directly or indirectly;

(b) device identifiers for advertising or cross-application tracking purposes;

(c) the addresses, domains, or destination servers you reach through the Application, the times at which connections are initiated, their duration, or any other access records or connection metadata;

(d) the contents of any traffic carried through the tunnel.

The Application maintains no account system of its own, does not require you to register with or sign in to the Developer, and communicates with no server operated by the Developer. It integrates no third-party analytics, advertising, or crash-reporting software development kit (SDK).

2.2 Information You Provide or Generate on Your Device

In the course of using the Application you may enter, import, or generate subscription URLs, server configuration data, and the access credentials such URLs commonly embed (tokens, UUIDs, and the like).

This information is processed and stored locally on your device as described in Section 5 and is not transmitted to the Developer.

The Application provides a "Copy subscription URL" action on the Settings → Subscription screen. You initiate it; the Application never performs it automatically. Content written to the system pasteboard by that action is marked local-only (it is not synchronised to your other devices via Handoff or Universal Clipboard) and is set to expire after ten minutes. Note that a subscription URL usually embeds access credentials and is equivalent in effect to a password.

2.3 Local Diagnostic Log

So that you can investigate connection problems yourself, the Application writes a runtime log on your device. In addition to whether the tunnel was established and what errors the core reported, that log contains a per-connection record written by the core, comprising the destination host name or IP address, the port, the outbound route used, and any failure reason. That log:

(a) is stored only within the local container on your device and is never uploaded automatically to the Developer or to any third party;

(b) when viewed or exported within the Application, has the destination host names and IP addresses in those per-connection records replaced with a placeholder, while ports, outbound routes, and failure reasons are retained. In other words, what you choose to share does not contain those destination addresses, whereas the original file retained on your device still does;

(c) is cleared according to which process wrote it and what it contains: the core log written by the tunnel process (including any copy produced by the core's log rotation, and containing the per-connection records) is deleted at the start of each connection; the tunnel process's own runtime log (which records only events such as tunnel start and stop and network changes, and contains no connection records) is rotated at the start of each connection so that one copy from the previous connection is kept on the device; the core log written by the Application's main process is deleted each time that log is reopened (at launch, and before each pre-connection speed test); the pre-connection speed-test record is overwritten on every round. Logs containing connection records therefore exist on the device only for the most recent connection;

(d) is deleted when the Application is uninstalled.

The Application provides a "Diagnostic Log" screen within the Activity tab for you to review that log. You may initiate the following operations there; the Application performs neither of them automatically:

(a) Copy: the log text is written to your device's system pasteboard. The Application marks that content local-only (it is not synchronised to your other devices via Handoff or Universal Clipboard) and sets it to expire after ten minutes.

(b) Export: the Application writes a copy of the log to a temporary directory on your device so that it may be sent through the system share sheet. The Application deletes that file once the share sheet is dismissed.

Should you choose to send that log to the Developer in order to obtain support, that is a disclosure you make deliberately and whose scope you determine. The log may contain the addresses and domain names of the servers you have configured. You are advised to review its contents before sending it.

3. Use of Information

3.1 The information described in Section 2.2 is used solely to establish and maintain network connections locally on your device, to parse and update the subscriptions you configure, and to display server and account information in the interface.

3.2 The information described in Section 2.3 is used solely for your own diagnosis of connection failures.

3.3 None of the above is used for automated decision-making, advertising, or cross-application tracking, or for any purpose beyond those stated in this Policy.

4. Sharing, Transfer, and Disclosure

4.1 Third-Party SDKs

The Application integrates no third-party analytics, advertising, or crash-reporting SDK and therefore shares no information with any third party for those purposes.

4.2 Third-Party Providers

(a) Subscription updates. Where you import a subscription or request a subscription update, the Application issues a request to the relevant Third-Party Provider using the subscription URL you configured. That URL commonly embeds your access credentials, and the provider is accordingly able to observe your IP address, the time of the request, and the client type. This flow is inherent in how subscriptions operate.

(b) Traffic. Once a connection is established, your traffic passes through the servers of the Third-Party Provider you configured. It does not pass through any server controlled by the Developer.

(c) Allocation of responsibility. A Third-Party Provider's handling of the information it receives is governed by that provider's own privacy policy, lies outside the Developer's control, and is not the subject of any representation or warranty by the Developer. Configure only services you trust.

(d) Launch connectivity check. On first launch, the Application issues a single HEAD request to Apple's connectivity-check endpoint (captive.apple.com). The request carries no device identifier, account information, or configuration content. Its sole purpose is to have the operating system present its wireless-data authorization prompt (on device models that have one) at that moment, rather than mid-way through your first subscription import or connection, where it would cause that operation to fail. It runs once per installation; its result is neither recorded nor reported and does not affect the Application's behaviour.

(e) Device clock correction. Some line protocols require the client and server clocks to agree to within tens of seconds; a device whose clock is wrong cannot connect to any of those lines. The Application therefore queries external time sources in the following three situations, solely to compute the offset between this device's clock and standard time: (i) before a pre-connection speed test and before starting a connection, it queries a public NTP service once (time.apple.com by default); (ii) if that query fails, it issues HEAD requests to cloudflare.com, apple.com, and microsoft.com and takes the agreed standard time from their response headers; (iii) once a connection is established, the tunnel process queries the same NTP service again at a fixed interval (30 minutes by default) and when the device wakes or the network changes. None of these requests carries a device identifier, account information, or configuration content; the services concerned can observe your IP address and the time of the request. The results are used only on the device to correct the clock offset and are not reported.

4.3 Disclosure Required by Law

Except where required by mandatory provisions of law or by a competent authority acting through lawful process, the Developer transfers and discloses no information to any third party. As the Developer does not hold the information described in Sections 2.2 and 2.3, it is in any event not in a position to produce it.

5. Storage, Retention, and Security

5.1 Where Information Is Stored

(a) Subscription URLs, server configuration data, the traffic and expiry information returned by your third-party provider, core runtime configuration, and the diagnostic log are stored within the Application's sandbox directory and App Group shared container on your device.

(b) None of this information is stored on any server controlled by the Developer or by any third party.

5.2 Retention

The information described in Section 5.1(a) is deleted when the Application is uninstalled; the diagnostic log is additionally subject to the deletion behavior described in Section 2.3(c).

5.3 Security

The Application relies on the application sandbox and Data Protection mechanisms provided by iOS to protect the local storage described above. You are encouraged to set a device passcode and to avoid using the Application on a jailbroken device.

5.4 iCloud Backup

If you enable iCloud Backup or create an encrypted local backup, the local data described above may be included in that backup. Backup is provided and controlled by Apple and is governed by Apple's privacy policy; it does not constitute a transmission from the Application to the Developer.

6. Use of the Network Extension Permission

6.1 The Application uses Apple's NetworkExtension framework to install a VPN configuration under Settings — General — VPN & Device Management. The purpose of that configuration is to hand the device's network traffic to a tunnel process running on your own device, which forwards it according to the rules you configured. iOS displays the VPN indicator in the status bar as a consequence.

6.2 The Developer does not use this permission to analyze traffic, to read, modify, or inject content, or to record access history. The tunnel process runs locally on your device and returns no data to the Developer.

7. Your Rights

7.1 Access. You may view the subscription URL, the server list, and the traffic and expiry information returned by your subscription within the Application's interface.

7.2 Clearing and replacement. The Settings → Subscription screen of the Application provides the following operations:

(a) "Remove subscription", which clears the subscription URL, the server list already obtained, and the traffic and expiry information returned by the subscription, disconnects the current session, and removes the VPN configuration the Application wrote to system settings;

(b) "Replace subscription URL", which substitutes a new subscription URL for the current configuration;

(c) "Update subscription", which retrieves the server list again using the current subscription URL.

After performing the operation described in (a), the operating system will ask you to authorise a VPN configuration again the next time you start a connection.

7.3 Deletion of everything. Uninstalling the Application deletes all data it holds in the device container, including subscription configuration and the diagnostic log. The Application provides no facility for deleting individual historical subscriptions or for clearing the diagnostic log manually.

7.4 Withdrawal of consent. You may withdraw your acceptance of this Policy by ceasing to use the Application and uninstalling it.

7.5 Because the Developer stores none of your Personal Information, a request to the Developer for access, portability, rectification, or erasure has no subject matter to operate on; all such operations can be carried out by you on your own device.

8. Children

8.1 The Application is not directed to children under 13, and the Developer does not knowingly collect personal information from children. As the Application collects personal information from no user, no collection of children's information arises.

8.2 If you are a minor, please decide whether to use the Application under the guidance of your guardian. Guardians with questions may contact the Developer as provided in Section 10.

9. Changes to This Policy

9.1 Where this Policy changes, its version number is raised and the full text is presented to you again within the Application. Your renewed acceptance is required before you may continue to use it.

9.2 The version number and date of last update appear in the version line at the end of this text.

10. Contact

Questions, comments, or complaints regarding this Policy may be directed to the Developer at: hachiminemo@gmail.com