NasPilot 隐私政策
一句话
NasPilot 不收集、不上传、不分析你的任何个人数据。应用只和你自己配置的 Synology NAS(以及可选的、你自己部署在 NAS 上的 NasPilot 侧车)通信。开发者不运营任何服务器,看不到你的数据。
1. 我们收集什么
什么都不收集。应用不含广告 SDK、不含统计 / 崩溃上报 SDK,不会向开发者或任何第三方发送设备信息、使用记录或文件内容。
2. 数据保存在哪里
- NAS 地址与会话:保存在你的手机上。登录密码不落盘,只保存登录后的会话令牌,令牌存放在系统安全存储(Android Keystore)。
- 证书指纹:你信任过的自签名证书指纹保存在本机,用于后续连接校验。
- 观看进度、最近目录、小组件配置:保存在本机。
- 缩略图缓存:来自你 NAS 的图片缩略图会缓存在本机,用于加快显示。
3. 数据传输
应用与 NAS 之间全部使用 HTTPS 加密传输。自签名证书按主机与证书指纹信任,首次连接需你手动确认。
4. 「问 NAS」功能(可选)
「问 NAS」需要你在自己的 NAS 上以 Docker 部署 NasPilot 侧车,并配置你自己的大模型服务账号。启用后:
- 应用只与侧车通信,不直接连接任何模型服务;模型服务凭据只保存在侧车里,不在手机上。
- 侧车默认只把文本(你的提问、文件名与路径、统计结果)发送给你配置的模型服务;原始文件永不出网。
- 图片 / 文档 / 视频内容是否可以发送给模型服务,由你在应用的「AI 设置」里按目录逐一授权;每次发送都有记录并在对话里标明。
- 模型服务对这些数据的处理适用该服务商自己的隐私政策。
这条数据流由你自己搭建、自己控制,不经过开发者。
5. 权限说明
- 网络:连接你的 NAS。
- 相机 / 相册(照片与视频):仅在你主动选择「拍照上传」「从相册上传」时使用,用于把你选中的内容上传到你的 NAS。
- 生物识别:可选,用于本机解锁应用。
6. 删除数据
在应用内「管理 → App 设置 → 退出登录」即可清除本机保存的会话、证书指纹与缓存;卸载应用会删除全部本地数据。开发者处没有任何你的数据可供删除。
7. 儿童
NasPilot 面向成年 NAS 用户,不面向 13 岁以下儿童,也不收集任何人的个人信息。
8. 变更与联系
政策变更会更新本页并修改生效日期。问题与反馈:haha@superhaha.top 或 GitHub Issues。
NasPilot Privacy Policy
In one sentence
NasPilot does not collect, upload or analyze any of your personal data. The app talks only to the Synology NAS you configure (and, optionally, the NasPilot sidecar you deploy on that NAS yourself). The developer operates no servers and cannot see your data.
1. What we collect
Nothing. The app contains no advertising SDK and no analytics or crash-reporting SDK. It never sends device information, usage data or file contents to the developer or any third party.
2. Where data is stored
- NAS address and session: stored on your phone. Your password is never stored; only the session token is kept, in the system secure storage (Android Keystore).
- Certificate fingerprints: fingerprints of self-signed certificates you trusted are stored locally for later verification.
- Playback progress, recent folders, widget settings: stored locally.
- Thumbnail cache: thumbnails from your NAS are cached locally for faster display.
3. Data in transit
All traffic between the app and your NAS uses HTTPS. Self-signed certificates are pinned by host and fingerprint and must be confirmed by you on first connection.
4. "Ask NAS" (optional)
"Ask NAS" requires you to deploy the NasPilot sidecar on your own NAS via Docker and configure your own LLM provider account. When enabled:
- The app talks only to the sidecar and never connects to any model provider directly; provider credentials live only in the sidecar, not on the phone.
- By default the sidecar sends only text (your question, file names and paths, statistics) to the provider you configured; original files never leave your network.
- Whether image, document or video content may be sent to the provider is your per-folder choice in the app's AI settings; every transfer is logged and marked in the conversation.
- The provider's own privacy policy governs its handling of that data.
This data flow is built and controlled by you and does not pass through the developer.
5. Permissions
- Network: to connect to your NAS.
- Camera / Photos and videos: used only when you choose "take photo" or "upload from gallery", to upload the items you selected to your NAS.
- Biometrics: optional, to unlock the app locally.
6. Deleting data
"Manage → App settings → Sign out" clears the local session, certificate fingerprints and caches; uninstalling removes all local data. The developer holds no data of yours to delete.
7. Children
NasPilot is intended for adult NAS owners, is not directed at children under 13, and collects no personal information from anyone.
8. Changes and contact
Changes will be posted on this page with a new effective date. Questions: haha@superhaha.top or GitHub Issues.