Node Pocket Privacy Policy
Node Pocket is provided by Zihua Huang (“we,” “us,” or “our”). This policy explains how the Node Pocket iPhone and iPad app handles information.
Summary
The app does not include a developer-operated advertising or analytics service, and the app does not sell personal data. The embedded network node’s diagnostic log upload is switched off, so it reports nothing about your devices to its vendor. Starting the Network connects you to the control plane and services you configure, plus the provider infrastructure needed to operate that connection; the browser, SSH terminal, and file client can also connect straight to an ordinary server without it.
Information handled on your device
- Network settings. The selected control-server URL, device name, and appearance preference are stored locally so the app can restore your setup. An auth key is used only for the current start and is not persisted by the app.
- Network node state. Tailscale/libtailscale stores the local node state required to reconnect. Using the app’s Sign Out action removes this state.
- SSH and SFTP credentials. Passwords, private keys, and passphrases entered for a connection are held in app memory while the corresponding connection fields remain populated. They are used only for connections you request, are not written to persistent settings by the app, and are cleared when the app process ends unless you clear or replace them sooner. Trusted host-key records (host, port, and fingerprint) are stored locally to help detect an unexpected host-key change on a later connection.
- Files. Items you download are saved in the app’s local Documents container, which can be exposed through Apple’s Files app and device file-sharing tools. Items you choose to upload are read only to complete your requested upload. Sharing, saving to Files, and ZIP export occur only after you initiate them.
- Diagnostic messages. The app writes connection breadcrumbs to the operating system’s log on your device so a problem can be diagnosed. Credentials are removed before a line is written, and lines that name a user, host, or address are marked private so the system withholds them from ordinary log readers. Nothing is written to the app’s own storage and nothing is sent to us.
- In-app purchase. Apple’s StoreKit provides localized Pocket Pro product information and a verified entitlement status so the app can unlock purchased features. Apple processes the purchase and App Store account relationship. The app does not receive or store your payment-card details.
Connections you initiate
When you start the Network, the app may communicate with the Network control server you configure, provider-selected coordination or relay infrastructure, and the HTTP/HTTPS, SSH, or SFTP services you use. Those services process information under their own policies. A Network control-plane provider may receive the account, node, device, and network information needed to provide its service. If you use Tailscale’s control plane, review Tailscale’s Privacy Policy. A custom control server or selected host is governed by its own policy.
The browser, SSH terminal, and file client also reach servers that are not on your private network, with the Network stopped. For those, the address you enter is resolved by your device’s normal DNS resolver and the app connects to it directly over your current internet or Wi-Fi connection: no control plane and no relay infrastructure is involved, and the destination host receives whatever that connection carries, including the user name and credentials you supply and the file contents you transfer.
The in-app browser can open HTTP and HTTPS URLs in WebKit. HTTP traffic is not encrypted; use HTTPS whenever available. This web-content allowance does not change the app’s normal App Transport Security settings.
Data sharing and tracking
We do not use information that we control for cross-app or cross-site tracking, and we do not share it with advertising networks. Information may be transmitted to the control-plane provider, provider infrastructure, third-party service, or host involved in the Network, browser, SSH, SFTP, or file-transfer function you request.
Pocket Pro purchase and restoration requests are sent to Apple through StoreKit and are governed by Apple’s applicable privacy terms.
Retention and deletion
Downloaded files remain in the app’s Documents container until you delete them. Signing out removes saved Tailscale node state, but does not remove the saved control server, device name, appearance preference, trusted host-key records, or downloaded files. Trusted host-key records can be removed separately with Forget Trusted Host Keys in Settings, which makes every host ask you to confirm its fingerprint again. Removing the app removes its sandboxed data, subject to iOS and any device-backup settings you control.
Children
Node Pocket is not directed to children and is not designed to collect personal information from children.
Changes to this policy
We may update this policy when the app’s data practices change. The current version will be published at the privacy-policy URL listed on the App Store product page.
Contact
For privacy questions or requests, contact support@zihuahuang.com.