PaperPhoneLite · Privacy

隐私政策
Privacy Policy

本页面公开说明 PaperPhoneLite 客户端、服务器、Tor 网络与可选通知服务的数据处理方式。

生效及更新 / Effective and updated: 2026-08-18FM619 Technolog LTDApp review
自托管责任:您所选择的服务器运营者通常决定该实例的数据保留、备份、通知服务与法律合规,并可能是相关数据的实际控制者。请同时阅读运营者公布的隐私规则。
Self-hosted responsibility: The selected server operator ordinarily determines retention, backups, notification services, and legal compliance and may be the relevant data controller. Review that operator’s privacy terms as well.

1. 适用范围与责任主体 / Scope and Data Controller

本政策说明 PaperPhoneLite 客户端和服务端软件如何处理数据。PaperPhoneLite 是可自托管的开源项目。

This Policy explains how the PaperPhoneLite client and server software process data. PaperPhoneLite is self-hostable open-source software.

2. 我们处理的信息 / Information Processed

账号与关系数据

用户名、昵称、密码哈希、头像、两步验证状态、好友关系、备注、标签、拉黑关系、群组、成员和邀请信息。注册不强制要求手机号或电子邮箱。

通信和路由元数据

发送方和接收方或群组标识、消息标识、类型、时间、投递/已读状态、客户端序号、自动删除设置、密钥版本,以及 WebSocket、同步和防重复投递所需信息。项目没有朋友圈、时间线、公开帖子或举报审核数据。

设备与会话数据

设备名称和类型、操作系统、客户端或浏览器标识、会话标识、登录和最后活动时间、刷新令牌哈希,以及服务器可见的连接信息。Tor 降低来源 IP 暴露,但其他可关联元数据仍可能产生。

English: Processed data includes account and relationship data; communication and routing metadata needed for delivery, receipts, synchronization, expiry, and deduplication; and device/session information. Registration does not require a phone number or email. The project has no social feed, public timeline, public posts, or report-review data. Tor reduces source-IP exposure but does not eliminate other linkable metadata.

3. 消息加密与限制 / Message Encryption and Limits

私聊使用 X25519 与 ML-KEM-768 混合密钥协商,并以 XSalsa20-Poly1305 加密;加密群聊使用 Sender Key。身份私钥和 Sender Key 保存在本地,服务器存储并转发密文。可选“消息隐私”密码在正常端到端加密前增加本地加密,且不会上传或自动同步。

端到端加密不隐藏账号关系、群成员、时间、消息类型、大小、投递状态等运行所需元数据,也不能保护已被控制的设备、截图或收件人保存、转发的内容。

Private chats use hybrid X25519 and ML-KEM-768 key agreement with XSalsa20-Poly1305; encrypted groups use Sender Keys. Private keys remain local while the server stores and relays ciphertext. E2EE does not hide required operational metadata or protect a compromised device, screenshots, or recipient-saved or forwarded content.

4. 文件与数据存储 / Files and Data Storage

上传的图片、视频、语音和文档保存在所选服务器的持久卷中,由 Rust 服务端传输,单文件上限 500MB;本项目不使用 Cloudflare R2。客户端通过 localStorage 和 IndexedDB 保存登录状态、设置、本地密钥、联系人、群组、消息与媒体缓存。服务器运营者负责存储位置、备份、访问控制和保留期限。

Uploads remain on the selected server’s persistent volume and are transferred by the Rust server, with a 500MB per-file limit; Cloudflare R2 is not used. The client stores state, settings, local keys, contacts, groups, messages, and media cache locally. The server operator controls storage, backups, access, and retention.

5. Tor 网络 / Tor Network

生产客户端必须内嵌 Tor,等待 bootstrap 完成,并仅通过隔离代理连接 v3 .onion 服务,不允许明网回退。Tor 旨在隐藏来源 IP 和服务器公开 IP,但不能保证绝对匿名,也不能消除设备指纹、账号行为、通知服务或用户主动披露造成的关联。

Production clients must embed Tor, wait for bootstrap, and connect only to a v3 .onion service through an isolated proxy with no clearnet fallback. Tor is intended to conceal source and public server IP addresses but cannot guarantee absolute anonymity or eliminate all forms of linkage.

6. 通知服务与第三方 / Notifications and Third Parties

Android 可使用 ntfy:服务器向运营者配置的 ntfy 实例发送主题、通知标题和正文。iOS 用户可提供 Bark 地址;服务器只发送发件人名称和通用的新消息提示,不发送消息正文,Bark App 最终通过 Apple APNs 显示提醒。PaperPhoneLite 自身不注册 APNs token,也不使用 Web Push、FCM、Firebase 或 OneSignal。通知可能显示在锁屏上。

Android may use ntfy, to which the server sends a topic, notification title, and body. iOS users may provide a Bark endpoint; only the sender name and a generic new-message alert—not message content—are sent, and Bark ultimately displays the alert through Apple APNs. PaperPhoneLite itself registers no APNs token and uses no Web Push, FCM, Firebase, or OneSignal.

7. 使用目的与信息披露 / Purposes and Disclosure

数据仅用于创建和保护账号、连接联系人和群组、路由与同步消息、传输文件、提供已启用的通知、检测滥用、排查故障及履行法律义务。项目不出售个人信息,不提供广告或跨应用追踪。服务器运营者、ntfy 或 Bark 服务运营者、基础设施供应商或依法提出要求的机构,可能在各自角色和法律范围内接触相关数据。

Data is used to secure accounts, connect contacts and groups, route and synchronize messages, transfer files, provide enabled notifications, detect abuse, troubleshoot, and comply with law. The project does not sell personal information or provide advertising or cross-app tracking. Relevant operators, providers, or legally authorized authorities may access data within their roles and applicable law.

8. 保留、删除与您的选择 / Retention, Deletion, and Your Choices

消息可永久保留,或在 1、3、7、30 天后自动删除。您可以清理本地缓存、撤销设备会话、拉黑用户或请求删除账号。账号删除会触发服务器数据库中关联记录的删除,但离线设备、接收方副本、ntfy/Bark 记录与服务器备份可能按各自周期继续存在。相关法定权利请求应联系所选服务器运营者。

Messages may remain indefinitely or expire after 1, 3, 7, or 30 days. You may clear local cache, revoke sessions, block users, or request account deletion. Offline devices, recipient copies, notification-service records, and backups may persist according to their own cycles. Direct legal-rights requests to the selected server operator.

9. 未成年人 / Children

PaperPhoneLite 不面向 13 岁以下儿童,也不会故意收集其个人信息。部分地区规定更高的数字同意年龄;未达到当地适用年龄的用户应在监护人同意和监督下使用,或停止使用。

PaperPhoneLite is not directed to children under 13 and does not knowingly collect their personal information. Where a higher digital age of consent applies, younger users should use the service only with guardian consent and supervision or stop using it.

10. 安全、变更与联系 / Security, Changes, and Contact

我们采取加密、密码哈希、会话撤销与 Tor-only 连接等措施,但任何系统都无法保证绝对安全。本政策可能随版本更新,重大变更将在应用或仓库中公布。项目问题请联系 [email protected];实例数据请求应优先联系您选择的服务器运营者。

Measures include encryption, password hashing, session revocation, and Tor-only connections, but no system is absolutely secure. Material policy changes will be published in the app or repository. For project questions, contact [email protected]; direct instance-specific requests to the selected server operator.

本页面依据 PaperPhoneLite 主分支内置 Privacy Policy 生成。
This page is based on the Privacy Policy bundled in the PaperPhoneLite main branch.