EdgePocket

Privacy

The app policy below matches the text currently bundled with EdgePocket.

EdgePocket privacy policy Effective draft date: 16 September 2026 Independent third-party cloud management client. Developer contact: huhh1998@icloud.com.

Direct cloud connections

Cloudflare and Vercel credentials are sent directly over HTTPS to their respective official services. API tokens and OAuth credentials are stored in the iOS Keychain with device-only accessibility. The app does not ask for account passwords or a Cloudflare Global API Key. Cloud account IDs, connection names and operation summaries are saved in app-local files protected by iOS file protection, excluded from backup. Resource data is loaded on demand. Provider privacy policies also apply to requests made to them.

Local safety and data

The default build includes no advertising, tracking SDK or developer-hosted analytics. It does not create an EdgePocket user account. Logs and object previews remain in memory until dismissed; provider and app operation diagnostics can contain resource names. Known sensitive fields are redacted, but automated redaction cannot identify every possible secret. Review any exported file before sharing it. Files you export to Files or share are controlled by you and are not removed when local app data is deleted. The app covers its interface when inactive; iOS cannot prevent a user from manually capturing screenshots.

Optional notification service

The default configuration has no notification server and does not register for remote notifications automatically. If the operator enables a notification service and you explicitly pair it, its operator processes an APNs device token, a hashed device authentication credential, owner mapping and allowlisted event metadata (provider, event type, receiver label, time and delivery result). The supplied server does not need cloud API tokens and discards raw webhook payloads after verification. Event history is retained up to seven days, subject to a global 2,000-event storage limit; registered devices expire after 30 days. Security and reverse-proxy logs may have separate operator-configured retention. The operator must publish its identity, purpose, regions, retention and contact policy before enabling this feature. Push delivery is best effort, not guaranteed. If you self-host the service, you control its storage and retention.

Removing access

Settings can remove a local connection and erase local metadata. OAuth grants can be explicitly revoked through the provider. Manually issued API tokens must be revoked in the provider console; local removal is not remote revocation and does not delete your cloud account. Remove notification pairing before deleting local app data to revoke the server registration immediately; otherwise it expires according to the server policy. Removing the app does not guarantee Keychain erasure.

Publication requirement

This policy is bundled for inspection. Before distributing the app, the publisher must also provide a publicly accessible matching policy URL and complete App Store privacy answers for the exact final binary and any enabled server. No statement here asserts Apple approval.

Website hosting

This website is hosted on Cloudflare and includes no analytics scripts. Cloudflare processes requests to deliver and protect the site. See Cloudflare’s privacy policy.