隐私政策与用户协议
适用范围:火烧云 Pro iOS 应用程序
生效日期:2026 年 9 月 9 日 · 版本 5.0(iOS)
本文件由《隐私政策》与《用户协议》两部分构成,仅适用于火烧云 Pro 的 iOS 应用程序(以下简称「本应用」)。其他平台版本适用各自发布的条款。您注册或使用本应用,即表示已阅读并接受本文件全部内容。
本应用为网络连接客户端,供已获授权的账号建立加密网络连接之用。账号的开通与授权在本应用之外完成,本应用内不包含任何交易、计费或授权变更流程。
一、收集的信息
我们仅收集维持服务运转与保障账号安全所必需的信息,具体如下:
| 类别 | 具体内容 | 用途 |
| 账户信息 |
电子邮箱地址 |
登录识别、密码找回、服务通知;并作为账号标识符,用于将连接事件与您的账号关联,以便客服排查您所反馈的问题及进行产品分析 |
| 授权与用量 |
账号授权状态、授权有效期、累计流量用量 |
确认账号的服务权限、显示剩余可用量 |
| 设备标识 |
应用生成的设备标识符、设备型号与系统版本 |
识别登录设备、管理账号授权的同时在线设备数量、识别异常的账号共享 |
| IP 地址 |
登录与建立连接时的来源 IP 地址;以及为判断连接是否成功而经公开 IP 查询服务取得的本机公网 IP 地址 |
异常登录检测、账号安全保护、上述设备数量的统计;判断连接是否建立成功、诊断连接失败,并用于第三节所述的产品分析 |
国家或地区 (粗略位置) |
由上述 IP 地址推导的国家/地区与大洲代码 |
判断连接是否成功、诊断特定地区的连线问题、汇整各地区的服务质量分析 |
| 连接概况 |
连接时长、所选节点、节点负载状态;连接建立、中断、失败与核心启动失败等事件 |
线路质量优化、故障排查、服务稳定性监测 |
| 设备与诊断 |
应用版本、系统版本、设备型号、语言;崩溃与错误日志 |
修复缺陷、兼容性适配、识别特定机型或版本的问题 |
您主动提交的 错误报告 |
仅在您于应用内主动点击提交错误报告时,上传近期的应用运行日志 |
重现并修复您所反馈的具体问题 |
您的账号授权规定了可同时在线的设备数量。为据此管理设备使用,我们记录设备标识符与连接来源 IP,并将其与您的账号关联。
上述信息用于设备数量管理、异常登录检测与账号安全,以及判断连接是否成功、诊断连接问题与产品分析(详见第三节)。该等信息不用于广告投放、用户画像,亦不用于追踪您在其他公司应用或网站上的活动;我们不收集广告标识符(IDFA)。
本应用不使用 iOS 定位权限,亦不取得精确位置。所述「国家或地区」仅由 IP 地址推导而得。
本应用不提供应用内购买,应用内不处理任何支付流程,故不在 iOS 应用中收集您的支付信息。
二、不予记录的信息
在您使用连接功能期间,下列内容不被记录或存储:
- 您访问的网站、域名或目的地址
- 您的 DNS 查询请求
- 您使用的应用程序或服务
- 您浏览的内容,或通过连接传输的任何数据
- 通讯录、照片、精确位置、麦克风与摄像头数据
上述记录不会生成,因此我们无法还原您的上网行为,亦无法向任何第三方提供该等记录。
本节所述不予记录的范围,与第一节所述设备标识及 IP 地址的收集互不影响:前者指连接过程中的访问目标与传输内容,后者指账号的登录来源与在线设备数量。
三、数据的共享与披露
我们不出售您的个人信息,亦不为第三方营销目的共享您的数据。仅在下列必要范围内与服务商共享最少量信息:
| 服务商类型 | 共享内容 | 目的 |
| 邮件发送服务 | 邮箱地址 | 发送验证码与服务通知 |
产品分析服务 PostHog(PostHog Inc.) |
作为账号标识符的电子邮箱地址;连接事件(建立、中断、失败、核心启动失败);IP 地址及由其推导的国家/地区;应用版本、系统版本、设备型号与语言;应用内的产品互动事件;以及您主动提交错误报告时上传的应用日志;若您回应应用内问卷,您所填写的内容亦由该服务商接收 |
服务稳定性与连接质量监测、缺陷诊断与产品改善;功能开关(feature flags)的下发与生效;以及应用内问卷的投放与回收 |
| 公开 IP 查询服务 |
为取得本机当前公网 IP 地址而发出的请求,该请求本身会使对方得知发出请求的 IP 地址 |
判断连接是否建立成功。不传送任何账号信息、凭证或通信内容 |
在线客服系统 Crisp(Crisp IM SARL) | 您主动提供的邮箱与对话内容 | 提供技术支持 |
上述服务商依合约仅得按我们的指示处理数据,不得用于其自身目的。我们与 PostHog 之间已签署数据处理协议(DPA)。
在适用法律强制要求的情形下,我们可能披露所持有的信息。如第二节所述,我们不持有您的浏览记录。
数据存放地与国际传输
账户、授权与设备管理数据存放于我们自有的服务器。
产品分析数据存放于 PostHog 位于美国的云端基础设施(AWS)。为提升事件送达率,分析请求会先经由我们自有网域 hsyr.hsyun.cloud 转送;该网域仅作为反向代理,数据最终由 PostHog 接收并存储于美国。
这意味着,若您并非位于美国,前述分析数据将被传输至您所在国家或地区之外。若您所在地的法律对个人信息跨境传输另有规定,请于使用本服务前评估是否接受此项安排;您亦可依第九节所列方式与我们联系。
四、数据保留期限
存放于我们自有服务器的数据
- 账户与授权信息:于账号存续期间保留;账号删除后 30 日内自生产环境清除。
- 设备标识与登录 IP 记录:保留至账号删除为止;登录 IP 仅保留最近一次记录,由新的登录覆盖。
- 适用法律要求更长保留期限的,于该期限内保留,届满后删除。
存放于产品分析服务商(PostHog)的数据
第三节所列的分析数据,依我们在该服务商处所设定的保留期限留存,届满后由该服务商删除。您亦可依第五节请求提前删除与您账号关联的分析记录。
五、账号删除与数据删除请求
您可在本应用内经「设置 → 账户 → 删除账号」自助发起删除。删除后,我们自有服务器上的账户信息、授权记录、设备标识及关联的登录 IP 记录将被清除。该操作不可撤销,剩余授权时长不予保留。
如您希望一并删除存放于产品分析服务商处、与您账号标识符关联的分析记录,可依第九节所列方式提出请求,我们将于 30 日内处理并回复。
如您对本政策或自身数据有疑问,或需协助处理账户信息,可通过第九节所列方式联系我们。
六、数据安全
连接建立后,您的设备与节点之间的数据以加密方式传输。我们对存储的账户数据采取访问控制与加密措施,并限制内部访问范围。任何网络传输或存储方式均无法保证绝对安全。账号密码由您自行保管,不得与他人共享。
七、未成年人
本服务不面向未满 18 周岁的未成年人提供,我们不会有意收集未成年人的个人信息。如发现误收集该等信息,将予以删除。监护人如认为未成年人向我们提供了信息,可联系我们处理。
八、政策变更
本政策发生重大变更时,我们将更新本页面的生效日期,并通过应用内公告或电子邮件通知。变更生效后继续使用本服务,视为接受更新后的政策。
九、联系方式
我们于收到后 30 日内答复。
一、适用范围
本部分仅适用于火烧云 Pro 的 iOS 应用程序。账号的开通、授权与授权范围的变更,由服务提供方于本应用之外完成,不属于本应用的功能范围;相关事项适用服务提供方另行发布的条款。
二、账号与使用规范
账号保管
账号为您使用本服务的凭证。该账号仅供您个人使用,不得转借、租赁或与他人共享,否则可能触发安全风控导致账号异常。因账号密码保管不当造成的损失,由您自行承担。
使用限制
使用本服务时,您不得从事下列行为:
- 资源滥用:长时间占用超大带宽(如 BT 下载)、恶意刷取流量、异常频繁地切换节点。
- 违规用途:从事违反您所在国家或地区法律法规的活动。
- 危害网络:发送垃圾邮件、进行端口扫描、发起攻击,或其他危害他人网络安全的行为。
经检测存在严重违规或异常操作的,我们可视情节限制速度或暂停服务。
设备连接数
您的账号授权规定了可同时在线的设备数量,我们依据授权进行相应管理。如需更多设备同时使用,可联系客服调整账号授权。
授权状态
账号须处于已授权状态方可建立连接。账号未获授权或授权已到期时,本应用将显示相应状态提示并停止连接,直至授权恢复。授权的开通与恢复不在本应用内进行。
三、iOS 平台说明
本应用不提供应用内购买功能,应用内不包含任何交易、计费或授权变更流程。iOS 用户以已获授权的账号登录后使用本服务。应用程序的下载与安装不产生费用。
您在 iOS 平台的下载与使用,同时适用 Apple 的相关服务条款。
四、Apple 平台最终用户许可协议
下列为适用于 iOS 平台的最终用户许可协议必备条款。本协议由火烧云 Pro 与用户(「您」)之间订立,与 Apple 无关。
(一)授权范围
火烧云 Pro 授予您一项有限、非独家、不可转让的许可,允许您在您所拥有或控制的 Apple 品牌设备上,依据 App Store 服务条款使用本应用程序。
(二)维护与支持
火烧云 Pro 负责提供本应用程序的维护与技术支持服务。Apple 对此不承担任何维护或支持义务。
(三)产品质保
在适用法律允许的最大范围内,Apple 对本应用程序不提供任何质保。如本应用程序未能符合适用质保要求,您可通知 Apple,Apple 将退还您的应用购买价款(如适用)。在适用法律允许的最大范围内,Apple 对本应用程序不承担其他任何质保义务。本应用于 App Store 为免费下载且不含应用内购买,故价款退还条款在实际适用中不产生效果。
(四)产品责任
火烧云 Pro(而非 Apple)负责处理因您使用本应用程序而引发或与本应用程序相关的第三方索赔,包括但不限于:产品责任索赔;本应用程序未能符合适用法律法规要求所引发的索赔;依据消费者保护法、隐私法或类似立法产生的索赔。
(五)知识产权侵权
如任何第三方主张本应用程序或您对本应用程序的持有与使用侵犯该第三方的知识产权,火烧云 Pro(而非 Apple)将单独负责对该等索赔进行调查、辩护、和解及解除。
(六)法律合规
您声明并保证:(a)您未被列为受制裁对象或禁止贸易方;(b)您不在美国禁运的国家或地区境内;(c)您不在美国政府的任何禁止或受限方名单上。
(七)第三方受益人
您确认并同意:Apple 及其子公司为本最终用户许可协议的第三方受益人。一旦您接受本协议条款,Apple 将有权(且视为已接受该权利)以第三方受益人身份对您主张本协议权利。
五、服务变更与免责
我们可能不定期调整节点配置或授权范围。重大变更将通过应用内公告或电子邮件通知。
对于因不可抗力(包括海底光缆中断、上游运营商故障、自然灾害等)导致的服务波动或中断,我们不承担赔偿责任。
六、协议变更与联系方式
本文件修订时,我们将更新生效日期并通过应用内公告告知。修订生效后继续使用本服务,视为接受修订后的内容。
七、开源软件声明
本应用包含以 GNU 通用公共许可证第 3 版(GPL-3.0)授权的开源软件组件,主要为 mihomo 代理内核及其相关网络库,包含 sing、sing-tun、sing-quic、sing-vmess、sing-shadowsocks 与 sing-wireguard。
本应用另包含以 MIT、BSD 及 Apache 许可证发布的函式库,以及以 SIL 开放字体许可证 1.1 版(SIL OFL 1.1)发布的 Noto Sans SC 与 Noto Serif SC 字体。应用界面的图形与图标为本应用自行设计制作。
依 GPL-3.0 之规定,自本版本发布之日起三年内,任何用户均有权取得上述 GPL-3.0 组件之对应源代码。如需索取,请来信 info@hsyun.io,我们将于 30 日内提供获取方式。
Privacy Policy & User Agreement
Scope: Hsyun Pro iOS application
Effective: September 9, 2026 · Version 5.0 (iOS)
This document consists of two parts, the Privacy Policy and the User Agreement, and applies only to the Hsyun Pro iOS application (the "App"). Versions on other platforms are governed by their own separately published terms. By registering for or using the App, you confirm that you have read and accepted this document in full.
The App is a network connection client used to establish an encrypted network connection for an account that has already been authorized. Account provisioning and authorization take place outside the App; the App contains no transaction, billing or authorization-management flow.
1. Information Collected
We collect only the information necessary to operate the service and protect account security, as set out below:
| Category | Details | Purpose |
| Account |
Email address |
Sign-in, password recovery, service notices; also used as the account identifier to associate connection events with your account, so that support can diagnose issues you report and for product analytics |
| Authorization & usage |
Account authorization status, authorization validity period, cumulative data usage |
Verify the account's service entitlement, display remaining allowance |
| Device identifier |
App-generated device identifier, device model, OS version |
Identify signed-in devices, manage the simultaneous-device allowance of your account authorization, identify abnormal account sharing |
| IP address |
Source IP address at sign-in and when establishing a connection; and the device's current public IP address, obtained via public IP-lookup services in order to determine whether a connection succeeded |
Detect unusual sign-ins, protect account security, count devices as described above; determine whether a connection was established successfully, diagnose connection failures, and for the product analytics described in Section 3 |
Country or region (coarse location) |
Country/region and continent codes derived from the IP address above |
Determine whether a connection succeeded, diagnose region-specific connectivity problems, and aggregate service-quality analysis by region |
| Connection summary |
Session duration, selected node, node load; connection established / disconnected / failed and core start-failure events |
Route quality optimization, troubleshooting, service reliability monitoring |
| Diagnostics |
App version, OS version, device model, language; crash and error logs |
Fix defects, ensure compatibility, identify model- or version-specific issues |
Error reports you choose to submit |
Recent application logs, uploaded only when you explicitly tap to submit an error report within the App |
Reproduce and fix the specific issue you reported |
Your account authorization specifies how many devices may be online at the same time. To manage device usage on that basis, we record a device identifier and the connecting IP address and associate them with your account.
This information is used for device-count management, unusual sign-in detection and account security, as well as to determine whether a connection succeeded, diagnose connectivity problems, and for product analytics (see Section 3). It is not used for advertising or profiling, nor to track you across apps or websites owned by other companies; we collect no advertising identifier (IDFA).
The App does not use iOS location permission and does not obtain precise location. The "country or region" described above is derived solely from the IP address.
The App does not offer in-app purchases and processes no payment flow, and therefore collects no payment information within the iOS application.
2. Information Not Recorded
While you use the connection feature, the following is neither recorded nor stored:
- The websites, domains or destination addresses you visit
- Your DNS queries
- The applications or services you use
- The content you browse, or any data transmitted through the connection
- Contacts, photos, precise location, microphone and camera data
As these records are never generated, we cannot reconstruct your online activity, nor provide such records to any third party.
The scope of information not recorded under this section is separate from the device identifier and IP address collection described in Section 1: the former concerns destinations and content within a connection; the latter concerns the origin of an account sign-in and the number of devices online.
3. Sharing and Disclosure
We do not sell your personal information, nor share your data for third-party marketing. We share the minimum necessary information with service providers only within the following scope:
| Provider type | Shared | Purpose |
| Email delivery | Email address | Verification codes and service notices |
Product analytics PostHog (PostHog Inc.) |
The email address used as the account identifier; connection events (established, disconnected, failed, core start failure); IP address and the country/region derived from it; app version, OS version, device model and language; in-app product interaction events; and the application logs uploaded when you choose to submit an error report; if you respond to an in-app survey, the answers you provide are also received by this provider |
Service reliability and connection quality monitoring, defect diagnosis and product improvement; delivery and evaluation of remote feature flags; and the delivery and collection of in-app surveys |
| Public IP-lookup services |
The request made to obtain the device's current public IP address; such a request inherently discloses the requesting IP address to that service |
Determine whether a connection was established successfully. No account information, credentials or traffic content is sent |
Live chat support Crisp (Crisp IM SARL) | The email and messages you choose to provide | Provide technical support |
These providers process data solely on our instructions under contract and are not permitted to use it for their own purposes. We have a Data Processing Agreement (DPA) in place with PostHog.
We may disclose information we hold where compelled by applicable law. As stated in Section 2, we do not hold browsing records.
Where Data Is Stored and International Transfers
Account, authorization and device-management data are stored on our own servers.
Product analytics data are stored on PostHog's cloud infrastructure in the United States (AWS). To improve event delivery, analytics requests are first routed through our own domain hsyr.hsyun.cloud; that domain functions purely as a reverse proxy, and the data is ultimately received and stored by PostHog in the United States.
This means that if you are not located in the United States, the analytics data described above will be transferred outside your country or region. If the law of your jurisdiction imposes specific requirements on cross-border transfers of personal information, please consider whether this arrangement is acceptable to you before using the service; you may also contact us using the methods in Section 9.
4. Data Retention
Data held on our own servers
- Account and authorization data: retained while the account exists; purged from production within 30 days of account deletion.
- Device identifiers and sign-in IP records: retained until the account is deleted; the sign-in IP retains only the most recent record, overwritten by each new sign-in.
- Where applicable law requires a longer retention period, data is retained for that period and deleted upon expiry.
Data held by our product analytics provider (PostHog)
The analytics data listed in Section 3 are retained for the retention period we configure with that provider, after which they are deleted by the provider. You may also request earlier deletion of the analytics records associated with your account, as described in Section 5.
5. Account Deletion and Data Deletion Requests
You may delete your account within the App under Settings → Account → Delete Account. Upon deletion, the account details, authorization records, device identifiers and associated sign-in IP records held on our own servers will be removed. The operation cannot be undone, and remaining authorization time is not preserved.
If you also wish to have the analytics records associated with your account identifier deleted at the product analytics provider, you may submit a request using the methods in Section 9; we will process it and respond within 30 days.
For questions about this policy or your data, or for assistance with account information, use the contact methods in Section 9.
6. Data Security
Once a connection is established, data between your device and the node is transmitted in encrypted form. We apply access controls and encryption to stored account data and limit internal access. No method of transmission or storage can be guaranteed absolutely secure. You are responsible for safeguarding your password and must not share your account.
7. Minors
The service is not offered to individuals under 18 years of age, and we do not knowingly collect personal information from minors. If such information is found to have been collected in error, it will be deleted. Guardians who believe a minor has provided us with information may contact us.
8. Changes to This Policy
Where material changes are made, we will update the effective date on this page and give notice by in-app announcement or email. Continued use of the service after a change takes effect constitutes acceptance of the updated policy.
9. Contact
- Support email: info@hsyun.io
- In-app support: tap the support icon in the lower-right corner of the App
We respond within 30 days of receipt.
Part II
User Agreement (iOS)
1. Scope
This Part applies only to the Hsyun Pro iOS application. Provisioning of accounts, granting of authorization and any change to the scope of that authorization are carried out by the service provider outside the App and fall outside the functional scope of the App. Such matters are governed by terms published separately by the service provider.
2. Account and Acceptable Use
Account security
Your account is your credential for using the service. It is for your personal use only and must not be lent, rented or shared, as this may trigger security controls resulting in account irregularities. You bear any loss arising from failure to safeguard your password.
Use restrictions
When using the service, you must not:
- Abuse resources: sustained excessive bandwidth consumption (such as BitTorrent), artificially inflating data usage, or abnormally frequent node switching.
- Use the service unlawfully: engaging in activities that violate the laws or regulations of your country or region.
- Harm networks: sending spam, port scanning, launching attacks, or other conduct endangering the network security of others.
Where serious violations or abnormal operations are detected, we may limit speed or suspend service in proportion to the circumstances.
Simultaneous devices
Your account authorization specifies how many devices may be connected at the same time, and we manage device usage on that basis. If you require more simultaneous devices, contact support to have your account authorization adjusted.
Authorization status
An account must be in an authorized state in order to establish a connection. Where an account is not authorized or its authorization has expired, the App displays the corresponding status and stops connecting until authorization is restored. Granting and restoring authorization do not take place within the App.
3. iOS Platform Notice
The App does not offer in-app purchases and contains no transaction, billing or authorization-management flow. iOS users sign in with an already-authorized account to use the service. Downloading and installing the application incurs no charge.
Your download and use on iOS are also subject to Apple's applicable terms of service.
4. End User License Agreement for iOS
The following are the required EULA provisions applicable to the iOS platform. This agreement is concluded between Hsyun Pro and you, the user, and is not with Apple.
(a) Scope of License
Hsyun Pro grants you a limited, non-exclusive, non-transferable license to use the application on any Apple-branded device that you own or control, as permitted by the App Store Terms of Service.
(b) Maintenance and Support
Hsyun Pro is solely responsible for providing maintenance and support services for the application. Apple has no obligation whatsoever to furnish any maintenance or support services.
(c) Warranty
To the maximum extent permitted by applicable law, Apple provides no warranty with respect to the application. In the event of any failure of the application to conform to any applicable warranty, you may notify Apple, and Apple will refund the purchase price of the application to you, if any. To the maximum extent permitted by applicable law, Apple has no other warranty obligation whatsoever with respect to the application. As the application is a free download with no in-app purchases, the purchase price refund provision has no practical effect.
(d) Product Claims
Hsyun Pro, not Apple, is responsible for addressing any claims by you or any third party relating to the application or your possession and use of it, including but not limited to: product liability claims; any claim that the application fails to conform to any applicable legal or regulatory requirement; and claims arising under consumer protection, privacy or similar legislation.
(e) Intellectual Property Rights
In the event of any third-party claim that the application or your possession and use of it infringes that third party's intellectual property rights, Hsyun Pro, not Apple, will be solely responsible for the investigation, defense, settlement and discharge of any such claim.
(f) Legal Compliance
You represent and warrant that: (a) you are not located in a country that is subject to a U.S. Government embargo, or that has been designated by the U.S. Government as a "terrorist supporting" country; and (b) you are not listed on any U.S. Government list of prohibited or restricted parties.
(g) Third Party Beneficiary
You acknowledge and agree that Apple and Apple's subsidiaries are third-party beneficiaries of this EULA, and that upon your acceptance of these terms, Apple will have the right (and will be deemed to have accepted the right) to enforce this EULA against you as a third-party beneficiary.
5. Service Changes and Disclaimer
We may adjust node configurations or the scope of authorization from time to time. Material changes will be notified by in-app announcement or email.
We bear no liability for service fluctuations or interruptions caused by force majeure, including submarine cable damage, upstream carrier failures and natural disasters.
6. Changes and Contact
Where this document is revised, we will update the effective date and give notice by in-app announcement. Continued use of the service after a revision takes effect constitutes acceptance of the revised content.
- Support email: info@hsyun.io
- In-app support: tap the support icon in the lower-right corner of the App
7. Open Source Software Notice
The App incorporates open-source software components licensed under the GNU General Public License version 3 (GPL-3.0), principally the mihomo proxy core and its associated networking libraries, including sing, sing-tun, sing-quic, sing-vmess, sing-shadowsocks and sing-wireguard.
The App also incorporates libraries released under the MIT, BSD and Apache licenses, and the Noto Sans SC and Noto Serif SC typefaces released under the SIL Open Font License 1.1. The interface artwork and iconography were produced for this App.
As required by GPL-3.0, for a period of three years from the release date of this version, any user is entitled to obtain the corresponding source code for the GPL-3.0 components listed above. To request it, write to info@hsyun.io and we will provide access within 30 days.