Privacy Policy / 隐私政策

Pwdx for iPhone, iPad and Mac · 适用于 iPhone、iPad 和 Mac

Effective September 9, 2026 · 生效日期:2026 年 9 月 9 日

Your vault

This policy describes how Pwdx handles your information. Your vault is stored in your private Apple CloudKit database. Account names are not encrypted by Pwdx. Passwords, titles, websites and notes are encrypted on your device using AES-GCM and RSA-OAEP before upload. The RSA private key is stored encrypted; its wrapping key syncs through iCloud Keychain. Your recovery code is not uploaded. We do not receive your vault contents through the notification service and do not have the keys needed to decrypt them.

Local authentication, AutoFill and keyboard

Face ID, Touch ID or device passcode verification is handled by Apple. Pwdx does not receive biometric templates. AutoFill decrypts the credential you select on the device. The keyboard provides basic typing without Full Access; optional vault insertion needs access to the app’s shared storage and a one-use field authorization lasting up to 60 seconds. It does not record or upload your keystrokes, surrounding text or filled credentials.

Optional notifications and Feedback

After you read the disclosure and agree to connect the optional notification service, it stores your installation identifier, device name, platform, APNs environment and push token, authentication token hashes, and the message titles, bodies, replies, timestamps and delivery status used to provide the service. Feedback is not end-to-end encrypted. Authorized third-party integrations can send you requests and receive the replies you submit. System notification previews may display the supplied title and part of the message body. You control previews and notification permissions in system settings.

Support, service providers and retention

We share information only as needed to provide the features you choose, meet legal obligations or protect the service. Service providers must protect information consistently with this policy and applicable requirements; authorized integrations must protect received messages and replies and use them only for their stated purpose. Apple and Cloudflare also describe their processing in their own privacy policies: Apple and Cloudflare. If you connect a different notification server, its operator is responsible for that server’s data practices; review its policy before connecting.

Our support form stores the message and optional email you submit so we can help you. Apple provides iCloud, Keychain, purchases, TestFlight and APNs; Cloudflare provides notification hosting, storage and operational logs. Infrastructure may process IP addresses and request metadata for delivery and abuse prevention. We do not sell personal information, use advertising SDKs or track you across apps or websites. Device registration is retained until deletion or service closure. Messages and replies are retained in your Feedback history until you delete the device’s notification data or request deletion; the ten-minute reply deadline does not erase message history. Support requests are retained until resolved and no longer needed, or until you request deletion. Short-lived rate-limit records are removed automatically after their enforcement window. Some operational backups and logs may persist according to provider retention settings.

Your choices

You can withdraw notification-service consent in Settings using “Disconnect and delete notification data”. This removes the installation’s server messages, replies and push identifiers and stops future notifications. Disabling system notifications alone stops alerts, but does not delete your inbox. Third parties may already have received your reply; contact them to exercise deletion rights for their copy. You can delete vault entries in the app; deletion markers sync across devices. Local encrypted caches can remain until devices sync or the app is removed. Deleting the app does not automatically delete iCloud data or notification records. Manage iCloud storage through Apple settings; contact us through Support to request notification or support data deletion. For access, correction, deletion or other privacy requests, use the Pwdx support form. Provide your client ID or support-request reference if available, and an email if you want a response. We may ask for limited information to verify control of the affected installation; we never need your vault secrets. Never send us your passwords, private keys or recovery code. We may update this policy when service behavior changes and will update the effective date here.

密码库

本政策说明 Pwdx 如何处理你的信息。密码库保存在你的 Apple CloudKit 私有数据库。账号名称不做 Pwdx 应用层加密;密码、标题、网站与备注在设备上经 AES-GCM 和 RSA-OAEP 加密后上传。RSA 私钥以加密形式存储,包装密钥通过 iCloud Keychain 同步,恢复码不上传。通知服务不会接收密码库内容,我们不持有解密密码库所需的密钥。

本地认证、自动填充与键盘

Face ID、Touch ID 和设备密码验证由 Apple 处理,Pwdx 不接收生物识别模板。自动填充在设备上解密你选定的凭据。键盘无需完全访问即可基本输入;可选的密码库字段填充需要访问 App 共享存储,并取得最长 60 秒的一次性字段授权。键盘不记录或上传按键、上下文文本或已填充的凭据。

可选通知与 Feedback

阅读说明并同意连接可选通知服务后,服务端保存安装标识、设备名称、平台、APNs 环境与推送 token、认证 token 的哈希,以及消息标题、正文、回复、时间和投递状态。Feedback 不提供端到端加密。经授权的第三方软件可发送请求并取得你提交的回复。系统通知预览可能展示标题和部分正文;你可以在系统设置中控制通知权限与预览。

支持、服务提供商和保留期限

仅在提供你选择的功能、履行法律义务或保护服务所需时共享信息。服务提供商须按本政策和适用要求保护信息;经授权的集成方须保护收到的消息与回复,并仅用于其已说明的用途。Apple 与 Cloudflare 的处理方式亦见其隐私政策:AppleCloudflare。若连接自定义通知服务器,该服务器的数据处理由其运营方负责,请先阅读其政策。

支持表单会保存你提交的问题和可选邮箱。Apple 提供 iCloud、Keychain、购买、TestFlight 和 APNs;Cloudflare 提供通知托管、存储及运行日志。基础设施可能为请求交付和防滥用处理 IP 地址及请求元数据。我们不出售个人信息,不使用广告 SDK,也不跨 App 或网站跟踪你。设备注册信息保留至删除或服务关闭;消息和回复作为 Feedback 历史保留至你删除该设备通知数据或申请删除。10 分钟回复期限结束不代表自动删除历史消息。支持请求在处理完毕且不再需要时删除,你也可申请提前删除。短期限流记录在执行窗口结束后自动清理。部分备份和运行日志按服务商保留设置保留。

你的控制权

可在设置中选择“断开并删除通知数据”撤回同意,这会删除该安装实例在服务端的消息、回复和推送标识并停止后续推送。仅关闭系统通知不会删除收件箱。第三方可能已经取得你的回复,其副本需要向该第三方申请删除。

在 App 中删除凭据会同步删除标记;其他设备的本地密文缓存可能保留至其同步或移除 App。卸载 App 不会自动删除 iCloud 或通知数据。可在 Apple 设置中管理 iCloud 存储,并通过支持页面申请删除通知或支持数据。访问、更正、删除或其他隐私请求请使用 Pwdx 支持表单;可提供客户端 ID 或支持请求编号,若希望获得回复请留下邮箱。我们可能要求有限信息以验证你对相关安装实例的控制权,但绝不需要密码库秘密。请勿向我们发送密码、私钥或恢复码。政策变更时会更新本页生效日期。