隐私政策
生效日期:2026 年 9 月 2 日 · English below
Catch(下称「本服务」)帮助开发者接收 App Store 服务器通知并推送到自己的设备。本政策说明我们收集什么、为什么收集、保存多久,以及你如何删除。
我们收集的数据
| 数据 | 来源 | 用途 |
|---|---|---|
| Apple 账号标识(Sign in with Apple 的用户标识)及你选择共享的邮箱 | 你登录时 | 创建并识别你的账号 |
| 设备推送令牌(APNs device token)与平台类型 | 你允许通知时 | 向你的设备发送推送 |
| App Store 服务器通知中的必要字段:通知类型、bundle id、产品 id、价格与货币、商店区域、环境(沙盒/生产)、时间戳 | Apple 发送到你的专属地址时 | 生成推送与流水列表 |
| 你的偏好设置:通知类型、免打扰时段、时区偏移、数据保留天数、转发地址 | 你在 App 内设置时 | 按你的意愿推送与转发 |
我们不收集的数据
- 通知中的
appAccountToken、originalTransactionId、transactionId等可关联到你的用户个人的标识一律不保存。 - 不接入任何分析、广告或第三方追踪 SDK,不收集设备广告标识。
- 不要求也不保存你的 App Store Connect API 密钥或账号密码。
保存多久
- 流水事件按你设置的保留天数自动清理,最长 365 天。
- 验签失败的原始通知最多保留 7 天,仅用于排查兼容性问题,每个账号最多 50 条。
- 登录会话最长 90 天,退出登录即失效。
- 在 App 内「设置 → 删除账号」会立即删除你的账号、设备、App 记录和全部事件,不可恢复。
数据去了哪里
- 服务端运行在 Cloudflare Workers 与 D1 上,数据存储在 Cloudflare 的基础设施中。
- 推送通过 Apple Push Notification service 发送;登录通过 Sign in with Apple 验证。
- 如果你为某个 App 设置了转发地址,该 App 的原始通知会被转发到你指定的服务器;该服务器由你控制,不在本政策范围内。
- 除上述情况外,我们不向任何第三方出售、共享或转让你的数据。
安全
所有传输均使用 HTTPS。每条来自 Apple 的通知都会验证到 Apple Root CA 的完整证书链,伪造的通知不会入库。你的专属通知地址包含随机令牌,可随时在 App 内重新生成。
儿童
本服务面向软件开发者,不面向 13 岁以下儿童,也不会有意收集儿童的个人信息。
变更与联系
本政策如有变更会在此页面更新并注明生效日期。任何问题请通过支持页面联系我们。
Privacy Policy
Effective September 2, 2026
Catch ("the Service") lets developers receive App Store Server Notifications and get them pushed to their own devices. This policy explains what we collect, why, how long we keep it, and how you can delete it.
What we collect
- Your Apple account identifier from Sign in with Apple, and the email address you choose to share, to create and identify your account.
- Push tokens (APNs device tokens) and platform type, to deliver notifications to your devices.
- Selected fields from App Store Server Notifications sent to your personal endpoint: notification type, bundle id, product id, price and currency, storefront, environment (sandbox or production), and timestamps. These are used to build your push notifications and event list.
- Your preferences: notification types, quiet hours, time zone offset, retention period, and any forwarding URL you configure.
What we do not collect
- We never store identifiers that could be linked to your customers, such as
appAccountToken,originalTransactionIdortransactionId. - No analytics, advertising or tracking SDKs. No advertising identifiers.
- We never ask for or store your App Store Connect API keys or passwords.
Retention
- Events are deleted automatically after your configured retention period (up to 365 days).
- Notifications that fail signature verification are kept in raw form for at most 7 days (at most 50 per account) solely to diagnose compatibility problems.
- Sessions expire after 90 days or when you sign out.
- Settings → Delete Account removes your account, devices, apps and all events immediately and irreversibly.
Where your data goes
- The Service runs on Cloudflare Workers and D1; data is stored on Cloudflare infrastructure.
- Pushes are delivered through the Apple Push Notification service; sign-in is verified through Sign in with Apple.
- If you configure a forwarding URL for an app, that app's raw notifications are forwarded to the server you specify, which is under your control and outside the scope of this policy.
- We do not sell, share or transfer your data to any other third party.
Security
All traffic uses HTTPS. Every notification from Apple is verified against the full certificate chain up to the Apple Root CA; forged notifications are never stored. Your endpoint contains a random token that you can regenerate at any time in the app.
Children
The Service is intended for software developers and is not directed at children under 13. We do not knowingly collect personal information from children.
Changes and contact
Changes to this policy will be posted on this page with a new effective date. Questions: see the support page.