Privacy Policy
隐私政策
Privacy Policy
本政策适用于 iOS 应用 Scanner(固件与源码安全扫描客户端,Bundle ID:com.cracompliance.scannerapp)。
本页公开可访问、无需登录,供 App Store 审核与用户查阅。
1. 关于本应用
本应用用于向授权用户提供固件 / 源码安全扫描结果(漏洞、SBOM、许可证信息)。 应用通过 HTTPS 连接扫描服务。如需联系:见 支持页。
2. 我们收集的信息
我们只收集提供扫描服务所必需的数据,不收集与扫描无关的通讯录、相册、精确位置、健康或金融信息。
| 类别(对应 App Store 隐私标签) | 具体内容 | 是否关联用户 | 用途 |
|---|---|---|---|
| 联系信息 / 账号 | 用户名;密码仅用于登录校验(服务端存储密码哈希,应用不保存明文密码) | 是 | 身份验证、授权访问扫描任务 |
| 用户 ID | 服务端账号 ID、角色(如 user / admin) | 是 | 账号识别与权限控制 |
| 用户内容 | 您主动上传的源码压缩包或固件镜像,以及文件名、扫描状态、漏洞/SBOM/许可证报告 | 是 | 执行安全扫描并展示结果 |
| 产品交互(有限) | 扫描任务创建、取消、重试等操作记录(与任务绑定) | 是 | 提供扫描工作流 |
| 设备上的会话数据 | 登录后的会话令牌、用户名、角色,保存在本机 UserDefaults | 仅本机 | 保持登录状态,避免重复输入密码 |
我们不收集:广告标识符(IDFA)、精确地理位置、通讯录、相机胶卷(应用仅通过系统文件选择器读取您选定的文件)、支付信息、浏览历史、或用于跨 App 追踪的数据。
3. 权限说明
- 文件访问:仅在您点击上传并选择文件时,读取该文件以上传扫描。不会后台扫描设备文件。
- 本地网络说明文案:系统可能展示本地网络相关说明;当前正式版后端为固定 HTTPS 云端服务,不用于探测家庭局域网中的其他设备。
4. 如何使用
- 创建并维持登录会话;
- 将您上传的文件交给扫描服务生成漏洞与 SBOM / 许可证报告;
- 按账号隔离任务(普通用户仅能看到自己的任务,管理员可按系统设计查看更多任务);
- 提供取消 / 重试扫描、下载报告等功能。
我们不会将上述数据用于定向广告、营销画像或出售给第三方。
5. 共享与第三方
我们不会出售您的个人信息。扫描在我们运营的服务器上完成,可能使用开源安全工具分析软件包名称与版本。 我们不接入第三方广告、分析或追踪 SDK(无 Google Analytics、无 Facebook SDK、无 App Tracking Transparency 追踪)。
6. 存储与保留
- 设备:会话令牌与基本账号显示信息存在本机;退出登录后清除。
- 服务器:账号、上传文件与扫描报告保存在我们运营的扫描平台,用于完成您请求的扫描。保留期限为提供服务所需期间,或直至您申请删除。
传输使用 HTTPS。请勿上传与扫描无关的个人敏感资料(如身份证照片、未脱敏客户数据)。
7. 账号与删除
您可在应用「设置」中退出登录,清除本机会话。如需删除服务器上的账号、历史上传文件与扫描报告,请通过 支持页 提交请求(注明用户名)。我们将在合理期限内处理,法律要求保留的除外。
8. 儿童
本应用面向专业安全 / 合规用户,不面向 13 岁以下儿童,也不会故意收集儿童个人信息。
9. 政策更新
若收集范围发生实质变化,我们将更新本页并调整「生效日期」。继续使用应用即表示您知悉更新后的政策。
10. 联系我们
隐私相关请求请发至 bobojensen@163.com,或使用 支持页 中的联系方式。
This policy applies to the iOS app Scanner (firmware & source-code security scanner client, bundle ID
com.cracompliance.scannerapp). This page is public and does not require sign-in.
1. About this app
This app lets authorized users obtain firmware / source security scan results (vulnerabilities, SBOM, licenses). The app talks to the scanner service over HTTPS. Contact details are on the Support page.
2. Data we collect
We collect only what is needed to provide scanning. We do not collect contacts, photo library contents, precise location, health, or financial data unrelated to a scan.
| App Store category | What | Linked to identity | Purpose |
|---|---|---|---|
| Contact Info / Account | Username; password used only to authenticate (server stores a password hash; the app does not keep the plaintext password) | Yes | Sign-in and access control |
| User ID | Account ID and role (for example user / admin) | Yes | Identify the account and enforce permissions |
| User Content | Source archives or firmware images you choose to upload, plus filenames, scan status, and vulnerability / SBOM / license reports | Yes | Run scans and show results |
| Product Interaction (limited) | Scan create / cancel / retry actions tied to a task | Yes | Operate the scan workflow |
| On-device session | Session token, username, and role in on-device UserDefaults | On device only | Keep you signed in |
We do not collect: IDFA, precise location, contacts, camera roll (the app only reads a file you pick in the system document picker), payment info, browsing history, or data used to track you across other companies’ apps and websites.
3. Permissions
- Files: only the file you select for upload is read, and only when you start a scan. The app does not scan your device in the background.
- Local network usage string: iOS may show a local-network purpose string. The shipping app uses a fixed HTTPS cloud backend and does not probe other devices on your home network.
4. How we use data
- Create and maintain a login session;
- Send files you upload to the scanner to produce vulnerability and SBOM / license reports;
- Isolate tasks by account (standard users see their own tasks; admins may see more as designed);
- Support cancel / retry and report download.
We do not use this data for targeted advertising, marketing profiles, or sale to third parties.
5. Sharing
We do not sell personal information. Scans run on servers we operate and may use open-source security tools that inspect software package names and versions. We do not embed third-party advertising, analytics, or tracking SDKs.
6. Storage and retention
- Device: session token and basic account display fields stay on device and are cleared on sign-out.
- Server: accounts, uploads, and reports stay on our scanner platform for as long as needed to provide the service, or until you request deletion.
Transport uses HTTPS. Do not upload sensitive personal documents unrelated to a security scan.
7. Account deletion
Sign out in Settings to clear the on-device session. To delete the server account, historical uploads, and scan reports, request it via Support (include your username). We will process the request within a reasonable period, unless law requires retention.
8. Children
The app is intended for professional security / compliance users. It is not directed at children under 13, and we do not knowingly collect children’s data.
9. Changes
If collection practices change materially, we will update this page and the effective date.
10. Contact
Privacy requests: bobojensen@163.com or the Support page.