2026/09/13

Wallbum Privacy Policy

Wallbum 隱私權政策 / Privacy Policy

最後更新:2026-09-13 · Last updated: 13 September 2026


中文

我們不收集任何個人資料

Wallbum(專輯牆)沒有我們自己的帳號、沒有分析工具、沒有廣告、沒有第三方追蹤 SDK,也沒有崩潰回報服務。我們沒有伺服器會接收你的資料 —— 不是「我們承諾不看」,是那個東西不存在。

你的音樂資料庫

App 需要「媒體與 Apple Music」的存取權,否則牆上沒有任何東西可以鋪。取得授權之後,App 透過 Apple 的 MusicKit 讀取這些內容:

  1. 專輯清單 —— 標題、演出者、曲目數、加入資料庫的日期,以及 Apple 已經替每張封面算好的代表色(光暈用的就是它)。
  2. 曲目清單 —— 只有在你長按某一張封面把它翻面時才會去讀那一張的曲目。
  3. 封面圖檔 —— 由 MusicKit 提供,縮到畫面需要的尺寸之後存進 App 自己的沙箱目錄當快取。
  4. 播放狀態 —— 現在在播哪一軌、播到第幾秒、是播放還是暫停。

這些全部留在你的裝置上。 沒有任何一項會被上傳、被同步、被記錄到別的地方。我們既看不到你的資料庫裡有什麼,也看不到你播了什麼。

封面快取有容量上限(約 200MB),滿了就從最久沒用到的開始丟。刪除 App 會連同快取一起消失。你也可以在系統「設定 → 一般 → iPhone 儲存空間」裡直接移除 App。

播放

播放是交給 Apple Music 的播放器做的,不是我們自己接的串流。要串流 Apple Music 曲庫裡的專輯,需要有效的 Apple Music 訂閱;已經下載到裝置上、或你自己匯入資料庫的內容不需要訂閱也能播。訂閱關係在你與 Apple 之間,與我們無關,我們也讀不到你的訂閱資料 —— App 只問 Apple 一個是非題:「這台裝置現在能不能播曲庫內容」。

網路連線

App 自己不發任何網路請求。會用到網路的只有兩件事,而且都是 Apple 的框架在做:

  1. 串流與封面 —— MusicKit 取得你資料庫裡的封面與音訊。
  2. 購買與恢復購買 —— 與 App Store 的付款服務溝通。

除此之外,已經下載的音樂與已經快取的封面在完全離線的狀態下都能用。

購買

App 內有兩種購買,都由 Apple 的 App Store 處理:

  • 完整資料庫 —— 一次性買斷的非消耗性商品,解除免費版「牆上最多 50 張專輯」的上限。不是訂閱,不會自動續訂。
  • 支持開發者 —— 三個金額的自願小費,消耗性商品,可以重複。它不解鎖任何東西。

付款資訊由 Apple 收取與保管。我們看不到你的付款方式、帳單資料或 Apple ID,也沒有伺服器會記錄你買了什麼。我們從 App Store 收到的只有「這台裝置是否已購買完整資料庫」這一個是非值,並把它寫在你自己的裝置上,讓 App 下次打開時不必等網路就知道答案。

小費我們連「付過幾次」都不記 —— 那是消耗性商品,付完就結束了。

這台裝置上存了什麼

App 寫在裝置上的東西只有三類,全部都在 App 自己的沙箱裡:

  1. 封面圖檔的快取。
  2. 牆的欄數(2–4 欄)。
  3. 「是否已購買完整資料庫」這一個是非值。

沒有播放紀錄、沒有使用統計、沒有任何識別碼。

兒童

App 不收集資料,因此也不會收集兒童的資料。App 內沒有廣告,也沒有使用者之間的通訊功能。App 內購買可以在「螢幕使用時間 → 內容與隱私權限制 → iTunes 與 App Store 購買項目」中關閉。

權限被拒絕或撤銷

沒有給「媒體與 Apple Music」權限時,App 會停在說明頁,不會做任何事。權限可以隨時在系統「設定 → 專輯牆」裡收回;收回之後 App 會退回那一頁,已經快取的封面也會在下次清理時被丟掉。

變更

若這份政策有變更,會更新本頁最上方的日期,並隨 App 更新一併發佈。

聯絡

有任何隱私相關問題,請寄到:candanweng@gmail.com


English

We collect nothing

Wallbum has no accounts of ours, no analytics, no advertising, no third-party tracking SDKs and no crash-reporting service. There is no server of ours that receives your data — not "we promise not to look", but rather that the thing does not exist.

Your music library

The app needs access to Media & Apple Music; without it there is nothing to put on the wall. Once granted, it reads the following through Apple's MusicKit:

  1. The album list — titles, artists, track counts, the date each was added to your library, and the representative colour Apple has already computed for each piece of artwork (that is what the ambient glow uses).
  2. Track lists — read for one album only, and only when you press and hold its cover to flip it over.
  3. Artwork images — supplied by MusicKit, scaled down to the size the screen needs and cached in the app's own sandbox directory.
  4. Playback state — which track is playing, how far into it, and whether it is playing or paused.

All of it stays on your device. None of it is uploaded, synced, or recorded anywhere else. We cannot see what is in your library, and we cannot see what you played.

The artwork cache has a ceiling of about 200MB; past that, the least recently used files are discarded. Deleting the app removes the cache with it.

Playback

Playback is done by Apple Music's own player; we do not stream anything ourselves. Streaming an album from the Apple Music catalogue requires an active Apple Music subscription. Content already downloaded to the device, or added to your library from your own files, plays without one. Your subscription is between you and Apple; we cannot read anything about it — the app asks Apple a single yes/no question: whether this device can currently play catalogue content.

Network access

The app makes no network requests of its own. Only two things reach the network, and Apple's own frameworks do both:

  1. Streaming and artwork — MusicKit fetching the covers and audio in your library.
  2. Purchases and restoring purchases — talking to the App Store's payment service.

Otherwise, downloaded music and cached artwork work fully offline.

Purchases

There are two kinds of purchase in the app, both handled by Apple's App Store:

  • Full library — a one-time, non-consumable purchase that lifts the free version's limit of 50 albums on the wall. It is not a subscription; nothing renews.
  • Supporting the developer — three voluntary tip amounts, consumable, and repeatable. They unlock nothing.

Payment details are collected and held by Apple. We never see your payment method, your billing information or your Apple ID, and there is no server of ours that records what you bought. All we receive from the App Store is a single yes/no — whether this device has bought the full library — which is then stored on your device so the app knows the answer without waiting on a network.

For tips we do not even record how many times you have given one; a consumable is finished the moment it is paid for.

What is stored on this device

The app writes only three things, all inside its own sandbox:

  1. The artwork cache.
  2. The number of columns on the wall (2–4).
  3. A single yes/no: whether the full library has been bought.

There is no playback history, no usage statistics, and no identifier of any kind.

Children

The app collects no data, and therefore collects no data from children. There is no advertising and no communication between users. In-app purchases can be turned off under Screen Time → Content & Privacy Restrictions → iTunes & App Store Purchases.

If permission is refused or withdrawn

Without access to Media & Apple Music the app stops at an explanatory screen and does nothing else. Access can be withdrawn at any time under Settings → Wallbum; the app then returns to that screen, and the cached artwork is discarded at the next cleanup.

Changes

If this policy changes, the date at the top of this page is updated and the change ships with an app update.

Contact

For any privacy question, write to: candanweng@gmail.com

沒有留言: