LEGAL / PRIVACY
Privacy Policy
How 汇流直播 handles data across the app, iCloud sync, App Store purchases, and the optional cloud go-live alert service.
Last updated: September 5, 2026 · Effective: September 5, 2026
Overview
汇流直播 (the “App”) processes only the data needed to provide live-stream aggregation, go-live alerts, synchronization, diagnostics, and App Store purchase features. This policy explains which information Conflux, Cloudflare, Apple, and third-party streaming platforms process.
Data We Process
- Basic analytics and diagnostics: feature interaction events, error categories, and an anonymous device identifier are processed through TelemetryDeck to improve stability and the core experience. They are not used to track you across apps or websites.
- App Store purchases: the App uses Apple StoreKit to load product information and verify valid purchase status. Apple processes orders, payments, and billing information. Conflux does not require a purchase email or receive payment card or bank account details. The one-time signed-transaction verification described below applies only when you explicitly enable Cloud Go-Live Alerts.
- iCloud sync: when enabled, followed-streamer lists, cross-device preferences, and third-party platform login credentials you choose to save are synchronized through your own iCloud / CloudKit account across devices using the same Apple Account.
- Third-party platform login: when you sign in, the App stores the cookies or credentials required by that platform on your device. They are used only to restore your session, request live-stream content, or provide signed-in features.
- Referral rewards: when you take part in the referral reward program, our cloud service stores your referral code, reward ledger entries, and withdrawal request records. Attribution and deduplication use only a digest of the signed-transaction identifier; we store neither the signed transaction itself nor a plaintext transaction identifier. The feature collects no email address, requires no account registration, stores no device fingerprint, and introduces no new category of personal data.
- The App does not use advertising SDKs or track you across apps or websites.
Local Storage and iCloud
Followed-streamer lists, video quality and danmaku preferences, temporary player state, and third-party platform login credentials you choose to save are primarily stored on your device. Turning off iCloud sync stops future synchronization; data already on the device remains available.
App Store purchase records and entitlement status are provided by StoreKit. They are not synchronized through Conflux’s iCloud / CloudKit data area and do not create a website purchase credential. iCloud sync does not include purchase or historical trial status, player caches, live-status snapshots, viewing-session history, crash logs, or temporary local state.
Go-Live Alerts
Local go-live notifications (liveNotifications) are triggered when the client checks status while the App is running or during a system-scheduled background refresh, then uses the system notification service. This is a Free feature. Notification permission, APNs, and system banners are also free system capabilities.
Cloud Go-Live Alerts (cloudLiveMonitoring) are an optional Conflux-hosted service included with the Full Version. You must explicitly enable the service on iPhone, iPad, or Mac; it is off by default. Once enabled, Conflux uses Cloudflare to keep monitoring registered rooms while the App is not running, deduplicate live-state changes, and deliver alerts through Apple Push Notification service (APNs). Delivery depends on network and third-party services and is provided on a best-effort basis.
Cloud Alert Data and Retention
- Room subscriptions: Cloudflare D1 stores a random installation ID, platform, room ID, the nickname used by that installation, the notification setting, and the identifier needed for platform status checks (currently the streamer UID for Bilibili). Status and go-live events are deduplicated by platform and that check identifier. Each delivery target separately snapshots the matching installation's room route and nickname. Some platforms’ online checks read a public per-broadcast identifier in memory for that request (the video ID on Yizhibo, the broadcast number on SOOP, the stream session ID on Twitch, the live stream ID on TikTok, the live-feed ID on Huajiao, the session ID on Inke) to distinguish separate upstream sessions that remain continuously online. The raw value is not persisted; D1 stores only a platform- and check-identifier-scoped HMAC digest in room state, and deletes it after confirmed offline status or room-state cleanup. Neither the raw value nor its digest enters Queue, APNs, or logs. For every platform, upstream room names and live titles are discarded at the adapter boundary even when returned; they do not enter D1, Queue, APNs, logs, or the shared business fixtures. An incorrect check identifier affects only the subscription belonging to that installation. Each successful signed registration from iPhone, iPad, or Mac renews that installation for 90 days. Monitoring uses only subscriptions whose lease and push address are valid and whose notifications are enabled. After 90 continuous days without a successful registration, the installation expires and enters bounded daily cleanup, which deletes its room subscriptions, delivery targets, push address, and installation record. Turning off the service immediately sends an unregister request; successful unregistration deletes the records immediately, and the client retries on a later launch after a network or service failure.
- Push address: the client sends its APNs device token to Cloudflare. The device token is encrypted at rest in D1 with AES-GCM, with a separate HMAC digest used for deduplication, and is retained until successful unregistration, expiry of the 90-day installation lease, or an APNs 410 response reporting the token as invalid. When a 410 deletion leaves the installation without another token, the service also deletes that installation's room subscriptions, delivery targets, and installation record. For delivery, Cloudflare sends APNs the device token, the corresponding room route, and a visible alert containing only the title “<nickname for this installation's subscription> 开播了” with no body. Apple processes delivery data under its privacy policy.
- StoreKit verification input: a service-registration request made after you explicitly enable Cloud Go-Live Alerts sends a StoreKit signed transaction. The Cloudflare Worker uses Apple root certificates for one-time offline verification of each input's product and transaction state and does not call an Apple API. The original value exists only in memory for that request and is discarded after verification. Conflux does not persist the original signed transaction or retain a plaintext transaction ID. The service retains only a one-way transaction digest and the
cloudLiveMonitoringadmission result until successful unregistration or expiry of the 90-day installation lease, then deletes both with the installation record. - Short-term registration claim: initial registration creates a short-term registration claim after request HMAC authentication and IP admission, and before StoreKit verification. The claim stores only an installation-keyed digest, encrypted installation secret, one-way secret digest, and expiry for at most 601 seconds; it contains no plaintext installation secret, StoreKit JWS, or device token. It permits authenticated unregistration during verification and prevents an in-flight registration canceled by that unregistration from being persisted. Authenticated unregistration immediately deletes the claim. A later registration that passes request HMAC authentication and IP admission lazily deletes expired claims.
- Security rate limits and unregistration protection: the registration endpoint converts the request IP address into a one-way HMAC digest for replay protection and short-term rate limiting. The digest is retained for no longer than the configured 10-minute window. A random nonce digest is retained until signed timestamp + 301 seconds for ordinary mutation replay protection. When the service successfully processes unregistration, the same D1 batch deletes installation data and makes logical unregistration effective immediately. It then retains a 601-second active installation tombstone containing only an installation-keyed digest, generation, expiry, and encrypted installation secret. This blocks older registrations from restoring data and permits an authenticated retry after a lost 204 response. After expiry, the next registration admitted by the IP limit lazily deletes the tombstone row. A structurally valid, current unregister request for an unknown installation ID returns a read-only 204 and performs no cleanup write. Logs exclude device tokens, signed transactions, JWTs, and complete notification payloads.
Cloud Go-Live Alerts use an explicit opt-in, one-way, non-readable notification subscription index. It is separate from product-data sync: the Worker exposes no subscription read endpoint and never returns your follow list to any client. iCloud remains the product-data sync path between Apple clients.
The cloud service never uploads third-party platform cookies, platform login credentials, or a device fingerprint. Those sign-in credentials remain on your device or in your personal iCloud when you choose to enable iCloud sync.
Network Services
- Streaming-platform APIs: retrieve streams, danmaku, streamer status, and signed-in features you request.
- TelemetryDeck: provides basic analytics and error diagnostics without advertising tracking.
- Apple StoreKit: displays products, completes purchases, receives transaction updates, and restores purchases on supported platforms.
- Apolu: receives a copy of the App Store server notifications Apple sends to the Conflux server, used to review sales and refund activity. What is forwarded is Apple’s own signed notification and contains transaction identifiers, product, price, currency, and storefront. It contains no name, email address, payment method, device identifier, push address, or your following data.
- Apple iCloud / CloudKit: synchronizes the data described above only when you enable iCloud sync.
- Cloudflare: hosts registration, room subscriptions, status monitoring, deduplication, and delivery orchestration for Cloud Go-Live Alerts that you explicitly enable.
- Apple Push Notification service (APNs): delivers cloud-detected go-live alerts to a registered iPhone, iPad, or Mac.
- Cloudflare D1 and R2: host the website feedback board's submissions and attachments.
Apple’s privacy policy applies to purchases, refunds, and Apple Account data. Conflux processes only the data expressly described in this policy.
Website Feedback Board
The website's feedback board (Chinese only) is a public, anonymous page. Anything submitted there becomes publicly visible immediately, with no pre-publication review. Do not include phone numbers, government identifiers, credentials, or anything else that identifies you.
- Submission content: the text you write, the type (defect or request), an optional device type and app version, and the submission time. This content is retained long term because it forms the product's record of requests.
- Display nickname: derived from a random string generated locally in your browser. That string is sent with the request and used only to compute the nickname on the spot; it is never written to the database or to logs. Only the resulting word pair is stored. It is not an account, cannot identify you, and clearing browser storage yields a new nickname.
- Attachments: images or videos you choose to upload, stored in Cloudflare R2 and deleted automatically after 180 days. Images are re-encoded inside your browser before upload, so EXIF data such as capture location never leaves your device; videos are not processed and may contain location data, so decide accordingly before uploading.
- Source IP address: stored only as a keyed digest that cannot be reversed to the original address, used to rate-limit submissions. A digest expires after 24 hours and is deleted the next time anyone visits the feedback board. The raw address is not stored.
- Local storage: the page keeps the random string above and your own up or down votes in your browser's localStorage so it can remember what you voted on. Neither is uploaded or used for tracking.
The board requires no sign-in, collects no email address or other contact details, and sets no tracking cookies. Votes carry no server-side identity.
The page provides no in-page reporting or deletion control. To have your submission removed, or to report advertising, unlawful, or privacy-violating content, contact [email protected].
Historical Website Purchases and Support Services
New App Store purchases do not require a Conflux purchase account and do not use the historical systems described below. During the migration window, the retained account, payment-result, and Apple TV authorization pages serve existing website purchasers only and may process:
- Account and contact data: purchase email, account status, deletion requests, and withdrawal status, used to authenticate historical accounts, recover Licenses, send reset or migration email, and handle support requests.
- Purchase and entitlement records: original order ID, payment status, amount and time, payment-provider transaction identifier, License Key and status, and refund or dispute status, used to verify historical purchases, restore an existing License, handle disputes, and arrange entitlement migration. Original payment card and bank-account details were handled by the former payment provider and are not provided to Conflux.
- Device and activation records: a device-fingerprint hash, device name and type, activation state, last-active time, License device seat, and temporary Apple TV authorization codes valid for ten minutes, used to maintain historical-version authorization and unlink or replace devices.
- Security and session data: historical account session tokens, payment-result query tokens, and necessary audit records, used for sign-in, existing-order status checks, abuse prevention, and account protection. A payment-result token is kept in the current browser session and removed from the address bar; local session tokens are cleared when the session is closed or the user signs out.
This data is used only for historical account support, existing-order verification, entitlement migration, refund or dispute handling, security audits, and legal obligations. It is not used to create new website purchases. Eligible historical purchasers will primarily migrate through App Store offer codes; an offline final build will be available when that method cannot be used. Steps and timing are available from [email protected].
When an account deletion request is submitted, the historical License and device sessions are disabled immediately and a seven-day withdrawal period begins; deletion can be cancelled from the historical account page during that period. After the period ends, Conflux deletes or de-identifies the account email, device records, login sessions, and usage data. Minimal order, transaction, audit, and historical trial anti-abuse records may be retained until applicable tax, reconciliation, transaction-idempotency, fraud-prevention, refund-dispute, purchase-recovery, and migration obligations end, then deleted or anonymized.
Historical website purchases are not App Store transactions and cannot be read through Restore Purchases in the App. From the historical account page, you can review or unlink devices, reset the License Key, request account deletion, or cancel deletion during the withdrawal period. To request access to, correction of, or deletion of other historical support data held by Conflux, or if you cannot access the account page, contact [email protected]. Data required by law or for unresolved refunds, disputes, or migration obligations may not be deleted immediately.
Your Controls
An App Store purchase does not create a Conflux purchase account. Apple manages Apple Accounts and App Store purchase history under its policies, and Conflux cannot delete purchase history held by Apple. When you turn off Cloud Go-Live Alerts, the local switch immediately remains off and the client immediately sends an unregister request. After the service successfully processes it, the service deletes that installation's cloud subscriptions, push address, transaction digest, and service-admission record; the client retries on a later launch after a failure. Uninstalling the App or going 90 continuous days without a successful registration expires the installation lease and places the related cloud records into bounded daily cleanup; short-term security digests expire under the limits above. You can also clear local data in the App and manage iCloud data in system settings. Contact us regarding diagnostics, support, or historical migration data held by Conflux.
Third-Party Platforms
The App accesses third-party streaming platforms including Bilibili, Douyu, Huya, Douyin, Xiaohongshu, Bigo, Laixiu, Twitch, YY, TikTok, CHZZK, and SOOP. Saved login credentials are used only to request live streams, danmaku, or signed-in features from the corresponding platform on your behalf. Your use of those platforms is also subject to their terms and privacy policies.
Changes to This Policy
We will announce material changes through an App update or on this website. Material changes affecting existing paid entitlements will be communicated separately in accordance with applicable law and approved legacy arrangements.
Contact
For privacy questions, contact [email protected].
If you contact us to withdraw a referral reward, the payment details you provide in that email do not enter our systems. They are used only to complete that payout, and we delete the email once the payout is done.