Peer Path Wire — Privacy Policy
English
Peer Path Wire collects no data about you. It has no accounts, no analytics, no advertising identifiers and no crash reporting. It makes one automatic request — to fetch a small signed file listing the addresses the service is currently reachable at — and that request carries nothing about you. Nothing else leaves the device unless you ask for it. No service, ours or anyone else's, is sent information about you, so there is nothing for us to store and nothing for us to hand to anyone else.
This policy is published by Toy Tech LLC ("we", "us"), the developer of Peer Path Wire ("the app"). It describes the app's behaviour exhaustively — if a connection or a stored item is not listed here, the app does not make it or keep it.
More than two parties
Most privacy policies describe two parties: you, and the company. This app has four, and the difference matters more than anything else in this document.
- Us. We wrote the app. We run no proxy servers, no accounts and no backend of any kind.
- Your device. Everything the app knows lives here.
- The server operator you chose. The app is a tool for connecting to servers you supply. Your traffic travels to whoever gave you that server. What they can see, and what they record, is governed by their policy — not by this one.
- The service operator whose address list the app carries. One address is written into the app, so that it can find out where that operator's website can currently be reached without that address being frozen into a release. You did not choose it and cannot change it, and the app contacts it on its own — described in full under "Connections the app makes". It is sent nothing about you. If you later import a list from that operator's website, they are also the server operator above.
We cannot make promises on behalf of a server operator we have never met. Add servers only from people you trust.
What the app stores, and where
All of the following is stored only on your iPhone, in the app's own container and keychain. None of it is transmitted to us, because there is nowhere for it to be transmitted to.
- The servers you added — by pasting a link, scanning a QR code, typing one in, or accepting a handoff link — including their addresses, ports and credentials.
- Any subscription address you added, so the list can be refreshed.
- If a list brought a private network with it: the key that network issued,
held in the iPhone's keychain rather than in the app's files, and the
ppw-name described below. Removing the list deletes both. - Your routing mode and kernel settings.
- Latency measurements, held in memory while the app is running.
- The signed address list described below, exactly as it was received, so it can be checked again every time it is read and so the app still works offline.
- A random number generated on this device the first time it was needed. It is used for one thing — giving this install a stable starting point in the list of addresses, so that everyone does not try the same one first. It is not taken from anything that identifies your phone, and it is never sent anywhere.
Deleting the app removes all of it. There is no copy anywhere else, and no export or backup path that sends it off the device.
Connections the app makes
This list is exhaustive. Two entries — the first and the second — are made by the app without a gesture from you; every other entry is something you started.
- Finding the service's current addresses. Shortly after the
app opens, it makes one HTTPS
GETto a single fixed address written into the app, and reads back a small file listing the addresses the service operator's website is currently reachable at. The file is signed, and the app refuses it outright if the signature does not match the key it carries. This is the one connection no gesture of yours triggers, so three things about it are worth stating plainly. It does not happen at all until you have accepted the summary shown on first launch. It sends nothing: no account, no device identifier, none of your servers, and no identifier we added — it is a request for a public file and nothing more. And as with any web request, whoever serves that address necessarily sees the IP address it came from and the time it arrived — there is nothing in the request that tells them which device, install or person it was, and no record of it comes back to the app. The stored file carries its own expiry, so a later launch repeats the request only once that has passed. - Fetching a subscription. An HTTPS request to the address you supplied, to retrieve the server list it holds. The request carries no identifier we added. That address is contacted only when you add it or ask for a refresh.
- Keeping a list you imported up to date. If you added a list that can update itself, the app asks that list's own website for a current copy — when you open the app, and at most a few times a day. The request goes to whoever gave you the list, never to us, and it carries the link they issued so they can tell which list to send; it carries nothing we added. This is the second of the two connections no gesture of yours triggers, and it exists so that a server your provider adds or retires reaches your iPhone without you fetching it by hand. It does not happen until you have accepted the summary shown on first launch, and it does not happen at all for a list that cannot update itself.
- Joining a private network a list brought with it. Some
servers can only be reached from inside a private network the provider runs. If
a list you imported includes one, then connecting registers this iPhone with
that provider's coordination server: the app sends the key the provider issued
and a name it generated on this device —
ppw-followed by eight random characters, not taken from anything that identifies your phone — and the coordination server gives the device an address on that network. Before connecting, the app also makes one HTTPS request to that server to see which of its addresses is answering. The provider can therefore see that a device is a member of their network. The app never offers your device as a route for anyone else's traffic and never lets that network decide where your traffic goes. Removing the list ends the membership and deletes the key. - Redeeming a handoff link. If you open a
ppw://importlink and confirm the prompt, the app sends the ticket from that link to the address named in the link, over HTTPS, and receives a server list back. Nothing is sent until you confirm, and the ticket is never stored or logged. - Testing a server. The app opens a plain TCP connection to a server you added, measures how long it took, and closes it. No data is sent through it and nothing is exchanged beyond the connection itself.
- Choosing the fastest server while connected. When automatic
selection is active, the network engine periodically requests
https://www.gstatic.com/generate_204— a connectivity-check endpoint operated by Google — through the proxy server you selected, and compares how long each took. Because it travels through the proxy, the address Google sees is the proxy server's, not yours. This is a timing measurement; no information about you is included.
The app makes no network connection beyond those listed above. It contains no analytics SDK, no advertising SDK and no crash-reporting SDK, and the only address it ever reaches for by itself is the one named in the first entry above.
Your traffic
The app keeps no record of the sites you visit, the addresses you connect to, or the data you send and receive. Diagnostic messages from the network engine stay in memory on this device, are never written to a file, are never uploaded, and are discarded when the app stops.
Camera and photos
The camera is used for exactly one thing: reading a QR code you point it at, so you can add a server without typing it. Frames are examined on the device as they arrive and are never stored, never sent anywhere, and never used for anything else. Choosing a saved image instead uses the system photo picker, which runs outside the app and hands over only the single image you selected — the app is never granted access to your photo library.
What we do with your data
We do not sell, use, or disclose to third parties any user data, for any purpose. We hold no user data to sell, use or disclose.
We engage no data processors, no advertising networks and no analytics providers in connection with this app. There is no category of person or company to whom your information could be passed, because none of it reaches us in the first place.
Payments
The app has no purchases, no subscriptions, no accounts and no payment of any kind. It never asks for a card, and it contains no link that leads somewhere to pay.
Children
The app is a network utility and is not directed to children. It collects no personal information from anyone, and therefore collects none from children.
Your rights
Laws including the EU General Data Protection Regulation and the California Consumer Privacy Act give you rights to access, correct, export and delete the personal information a company holds about you. We hold none, so there is nothing for us to produce or erase. The data described under "What the app stores" is already entirely under your control: it is on your device, and deleting the app deletes it.
If you believe this is inaccurate, or you want to ask about anything in this policy, write to us at the address below and we will answer.
Changes
If this policy changes in substance, the effective date at the top changes with it, and the app shows you the revised disclosure before you next use it. Wording improvements that do not change what happens to your data are made without a prompt.
Contact
Toy Tech LLC
privacy@papawall.com
简体中文
Peer Path Wire 不收集任何关于你的数据。它没有账号、没有统计分析、 没有广告标识符、没有崩溃上报。它会自动发起一次请求——取回一个很小的、带签名的文件, 里面是本服务当前可达的地址清单——这次请求不携带任何与你有关的内容。除此之外,没有 你未要求的东西离开本设备。任何服务(我们的或别人的)都不会收到关于你的信息,因此我们 手上没有任何与你有关的信息,也就没有任何可以交给别人的东西。
本政策由 Peer Path Wire(下称“本 App”)的开发者 Toy Tech LLC (下称“我们”)发布。以下内容穷尽地描述了本 App 的行为——凡是未在此列出的连接或存储项, 本 App 都不会发起、也不会保存。
不止两方
大多数隐私政策只描述两方:你,和公司。本 App 涉及四方,这个区别比本文任何其他内容 都更重要。
- 我们。我们编写了这个 App。我们不运营任何代理服务器、任何账号 体系,也没有任何形式的后端。
- 你的设备。本 App 知道的一切都只存在于这里。
- 你自己选择的服务器运营方。本 App 是一个连接你自行提供的 服务器的工具。你的流量流向把这台服务器给你的那一方。他们能看到什么、记录什么,由他们 自己的政策决定,而不是由本政策决定。
- 本 App 内置其地址清单的那一家服务运营方。App 里写死了一个地址, 用来查出这家运营方的网站当前在哪,以免这个地址被冻结在某一个版本里。 这个地址不是你选的,也无法更改,而且 App 会自行去访问它——完整说明见「本 App 会发起的 连接」。它不会收到任何与你有关的内容。如果你之后从这家运营方的网站导入了服务器列表, 那么他们同时也是上面那个「你自己选择的服务器运营方」。
我们无法替一个素未谋面的服务器运营方作出承诺。请只添加来自你信任的人的服务器。
本 App 保存什么,保存在哪里
以下所有内容只保存在你的 iPhone 上,位于本 App 自己的容器与钥匙串中。它们不会被 传输给我们——因为根本不存在可供传输的接收端。
- 你添加的服务器(粘贴链接、扫码、手动填写或接受交接链接添加的),包括其地址、 端口与凭据。
- 你添加的订阅地址,用于刷新服务器列表。
- 如果某个列表附带了专用网络:该网络签发的密钥,保存在 iPhone 的钥匙串中而非 App 的
文件里,以及下文所述的
ppw-名称。删除该列表会一并删除两者。 - 你的路由模式与内核设置。
- 延迟测试结果,仅在 App 运行期间保存在内存中。
- 下文所述的那份带签名的地址清单,按收到时的原样保存,以便每次读取时都能重新验签, 也使 App 在离线时仍可工作。
- 本设备在首次需要时生成的一个随机数。它只用于一件事:让本次安装在地址清单中有一个 固定的起始位置,以免所有设备都先去试同一个地址。它不取自任何能标识你手机的东西, 也从不被发送到任何地方。
删除本 App 即删除上述全部内容。别处不存在副本,也不存在任何把它们送出设备的导出或 备份路径。
本 App 会发起的连接
以下列表是穷尽的。其中第一、二项由本 App 自行发起,无需你的操作;其余每一项都由你主动触发。
- 查出本服务当前的地址。App 打开后不久,会向一个写死在 App 里的
固定地址发起一次 HTTPS
GET,取回一个很小的文件, 其中是这家服务运营方的网站当前可达的地址清单。该文件带签名;若签名与 App 内置的公钥不符,App 会整份拒收。这是唯一一项不由你的操作触发的连接,因此有三件事必须 明说:在你确认首次启动时展示的说明之前,它根本不会发生;它不发送任何内容——没有账号、 没有设备标识、没有你的服务器、也没有任何由我们添加的标识,它只是一次对公开文件的请求; 以及,与任何网络请求一样,提供该地址的一方必然会看到请求来自哪个 IP 地址、在什么时间 到达——但请求里没有任何东西能说明它来自哪台设备、哪一次安装或哪个人,也没有任何相关 记录回到 App。取回的文件自带有效期, 只有在有效期过去之后,后续启动才会再次发起这次请求。 - 获取订阅。向你提供的地址发起一次 HTTPS 请求,取回其中的服务器 列表。请求不携带任何由我们添加的标识。只有在你添加该地址或主动要求刷新时才会发生。
- 让你导入的列表保持最新。如果你添加的列表支持自我更新,本 App 会向 该列表自己的网站索取一份当前副本——在你打开 App 时,以及每天至多数次。该请求发往把列表 给你的那一方,绝不发往我们;它携带对方签发的链接,以便对方知道该发哪一份列表,不携带 任何由我们添加的标识。这是两个无需你操作即发生的连接中的第二个,它的存在是为了让服务 提供方新增或下架的服务器无需你手动获取即可到达你的 iPhone。在你接受首次启动时展示的 摘要之前不会发生;对于不支持自我更新的列表则完全不会发生。
- 加入列表附带的专用网络。有些服务器只能从服务提供方运营的专用网络
内部访问。如果你导入的列表包含这样一个网络,那么在连接时,本 App 会把这台 iPhone 注册
到该服务商的协调服务器:App 会发送对方签发的密钥,以及一个在本设备上生成的名称——
ppw-加八个随机字符,不取自任何能标识你手机的东西——协调服务器则为本设备 分配一个该网络内的地址。连接前,App 还会向该服务器发起一次 HTTPS 请求,以确认它的哪个 地址可用。因此,服务提供方能够看到有一台设备是其网络的成员。本 App 绝不把你的设备作为 他人流量的出口,也绝不让该网络决定你的流量走向。删除该列表即结束成员身份并删除密钥。 - 兑换交接链接。当你打开一个
ppw://import链接并在 弹窗中确认后,本 App 会通过 HTTPS 将该链接中的票据发送到链接指定的地址,并取回服务器 列表。在你确认之前不会发送任何内容;票据不会被保存,也不会被记录。 - 测试服务器。本 App 会向你添加的服务器建立一次普通 TCP 连接, 测量耗时后关闭。不会通过该连接发送任何数据,除建立连接本身外不交换任何内容。
- 连接期间选择最快的服务器。当自动选择生效时,网络内核会周期性地
经由你所选择的代理服务器请求
https://www.gstatic.com/generate_204(由 Google 运营的连通性检测端点), 并比较各自耗时。由于该请求经过代理,Google 看到的是代理服务器的地址,而不是你的地址。 这只是一次计时测量,其中不包含任何关于你的信息。
本 App 不发起任何其他网络连接。它不包含任何统计 SDK、广告 SDK 或崩溃上报 SDK; 它唯一会自行访问的地址,就是上面第一项里点名的那一个。
你的流量
本 App 不记录你访问的站点、你连接的地址,也不记录你收发的数据。网络内核的诊断信息 仅保存在本设备的内存中,不会写入文件,不会上传,并在 App 停止时丢弃。
相机与照片
相机只用于一件事:读取你对准的二维码,使你无需手动输入即可添加服务器。画面在设备上 即时解析,不会被保存、不会被发送到任何地方,也不会用于任何其他用途。若改为选择已保存的 图片,则使用系统图片选择器——它在本 App 之外运行,只把你选中的那一张图片交给本 App, 本 App 从未获得你相册的访问权限。
我们如何处理你的数据
我们不会出于任何目的出售、使用或向第三方披露任何用户数据。我们手上 不存在任何可供出售、使用或披露的用户数据。
就本 App 而言,我们未委托任何数据处理方、未接入任何广告网络、未使用任何统计服务。 不存在任何可能拿到你信息的个人或公司类别——因为这些信息从一开始就没有到达我们这里。
付费
本 App 没有任何内购、订阅、账号或任何形式的付费,从不索要银行卡信息,也不包含任何 指向付费页面的链接。
儿童
本 App 是一个网络工具,并非面向儿童。它不收集任何人的个人信息,因此也不会收集儿童的 个人信息。
你的权利
包括欧盟《通用数据保护条例》(GDPR) 与《加州消费者隐私法》(CCPA) 在内的法律赋予你 访问、更正、导出与删除公司所持有的你的个人信息的权利。我们不持有任何此类信息,因此没有 可供提供或删除的内容。“本 App 保存什么”一节所述的数据本就完全在你的掌控之中:它们在你 的设备上,删除 App 即删除它们。
如果你认为上述描述不准确,或对本政策有任何疑问,请通过下方地址与我们联系,我们会 回复。
变更
若本政策发生实质性变更,顶部的生效日期会随之更新,并且本 App 会在你下次使用前向你 展示修订后的声明。不改变数据处理方式的文字改进不会触发提示。
联系方式
Toy Tech LLC
privacy@papawall.com