GridFix 隱私權政策
生效日期:2026 年 8 月 10 日
適用版本:GridFix 1.1 起
GridFix(以下稱「本 App」)是一款在 iPhone 與 iPad 上進行照片透視校正、鏡頭變形校正,並提供即時校正拍攝與錄影功能的工具。
本 App 由 PEI-CHUN CHAO(獨立開發者,台灣)開發與營運,並為本政策所述資料處理之資料控制者。
本政策說明本 App 會取用哪些裝置資料、為什麼取用、以及這些資料去了哪裡。
一、總則:我們不蒐集您的個人資料
本 App 不會蒐集、上傳、儲存或分享您的任何個人資料。
- 本 App 沒有伺服器,也不會發出任何網路請求來傳送您的資料。
- 本 App 未內嵌任何第三方分析、廣告或追蹤 SDK。
- 本 App 不會蒐集廣告識別碼(IDFA),也不會進行跨 App 或跨網站的使用者追蹤。
- 您的照片、影片與所有編輯內容,全程只在您的裝置上處理,不會離開裝置。
本 App 在 App Store 的隱私權標示為「不收集資料」(Data Not Collected),與上述事實一致。
二、本 App 會取用的裝置權限
以下權限都會在您第一次使用相關功能時,由系統向您詢問。您可以隨時到「設定」→「GridFix」中調整或撤銷。
1. 相機
- 用途:提供「即時校正拍攝」的取景畫面與拍照、錄影功能。
- 處理方式:影像串流僅在裝置本機記憶體中處理,用於即時計算並顯示校正後的畫面。
- 不會:上傳、備份或傳送任何影格到裝置以外的任何地方。
2. 麥克風
- 用途:僅在您主動切換到錄影模式時使用,用於為影片收音。
- 時機:只拍照不錄影的使用者,永遠不會被詢問麥克風權限。
- 處理方式:收到的音訊直接寫入您正在錄製的影片檔案中,不另行儲存、分析或傳送。
- 拒絕的後果:您仍可正常錄影,只是影片沒有聲音。
3. 照片(完整存取)
-
用途:
- 將您拍攝的照片與影片存入系統「照片」App;
- 當您在 App 內相簿中標示「喜好」時,將該標記同步寫回系統「照片」中的同一張照片或影片。
- 為什麼需要「完整存取」而非「僅加入」:iOS 的「僅加入」權限只能寫入新項目,無法修改既有項目的屬性。喜好標記的同步屬於修改,因此必須使用完整存取權限。
- 本 App 不會:瀏覽、讀取、索引、分析或傳送您相簿中的其他照片。本 App 只會接觸「由本 App 建立的項目」以及「您主動透過系統選取器挑選的項目」。
- 本 App 不會刪除您相簿中的任何項目。App 內相簿的「移除」只影響本 App 當次拍攝的清單,系統「照片」中的檔案不受影響。
4. 動作與方向感測器(陀螺儀/加速度計)
- 用途:讀取重力方向,計算手機的俯仰與水平傾斜角度,據以即時校正取景畫面的透視變形,並顯示角度讀數與扶正提示。
- 處理方式:感測器讀數即時運算後即丟棄,不會被記錄成軌跡或歷史。
- 例外:若您使用「水平感測校正」功能,本 App 會將您量測到的固定偏移角度(兩個數值)與校正時間儲存在裝置本機,用於後續全程扣除。此資料不含位置、不含動作歷程,也不會離開裝置。
- 本 App 不使用定位服務,也不會取得您的所在位置。關於既有照片中已含的位置標記如何處理,請參閱第三節。
5. 檔案
- 用途:讓您從「檔案」App 或 iCloud 雲碟匯入照片(含 RAW 格式)。
- 範圍:本 App 僅能存取您主動在系統選取器中挑選的檔案,無法瀏覽其他內容。
三、照片中繼資料(EXIF)
照片檔案本身通常帶有中繼資料(EXIF/TIFF),可能包含拍攝時間、相機與鏡頭型號、曝光參數,以及原始拍攝地點的 GPS 座標。本 App 對這些資料的處理如下:
本 App 不會讀取、解析或傳送這些中繼資料的內容,也不會用它來判斷您的所在位置。本 App 未使用定位服務,任何情況下都不會主動為您的照片加上位置資訊。中繼資料在輸出檔中的去留,依方案而不同:
| 輸出來源 | 免費版 | 訂閱/買斷 |
| 匯入照片編輯後輸出 |
移除鏡頭、曝光、機型、GPS 位置等拍攝資訊,僅保留原始拍攝日期與方向標籤 |
完整保留原始照片的中繼資料,包含其中既有的 GPS 位置資訊 |
| 以「即時校正拍攝」拍照 |
不含任何中繼資料 |
完整保留相機當下產生的中繼資料 |
| 錄影(訂閱功能) | ─ | 影片檔不含位置資訊 |
免費版保留拍攝日期,是為了讓修過的舊照片在系統「照片」中仍排在原本的時間位置,不會全部跳到今天;方向標籤則是影像顯示所必需。無論哪個方案,輸出時都會把方向(Orientation)與像素尺寸重寫成與校正後影像相符的值,因為校正後的影像已與原檔不同。
簡而言之:本 App 永遠不會替您的照片新增位置。免費版輸出會移除原本就有的位置,訂閱版則完整保留。因此,若您是訂閱用戶且打算公開分享編輯後的照片,而原始照片是在「相機」的定位權限開啟時拍攝的,該照片會仍帶有拍攝地點座標。您可以在系統「照片」App 分享時點選「選項」並關閉「位置」,或以其他工具移除後再行分享。
四、儲存在您裝置上的資料
以下資料儲存在您的裝置本機,不會上傳:
| 資料 | 儲存位置 | 用途 |
| 格線模式、自動轉正水平、拍攝與錄影格式等偏好 | UserDefaults | 記住您的設定 |
| 放大鏡位置偏好 | UserDefaults | 記住您的設定 |
| 介面語言偏好 | UserDefaults | 記住您選擇的顯示語言 |
| 水平感測校正的偏移值與校正時間 | UserDefaults | 扣除感測器固定誤差 |
| 評分提示的計次與上次提示時間 | UserDefaults | 避免重複打擾 |
| 免費版每日編輯輸出次數與相機儲存張數,及其日期 | 鑰匙圈(Keychain) | 計算免費額度 |
| 編輯紀錄庫(原圖副本、校正參數、成品與縮圖) | App 私有目錄 | 讓您回到先前的編輯繼續調整 |
其中兩個每日額度計數器(編輯輸出次數與相機儲存張數)存放於鑰匙圈,是為了讓免費額度不會因「移除後重新安裝」而被繞過。這些項目以 kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly 儲存,僅限本裝置、不會同步至 iCloud 鑰匙圈,僅包含兩個次數與一個共用的日期,每日自動歸零,不含任何可識別您身分的資訊。它們在您移除 App 後仍會留存於裝置上,這是上述設計的必然結果,詳見第八節。
編輯紀錄庫
當您匯入照片開始編輯時,本 App 會在裝置本機建立一筆「編輯紀錄」,讓您日後能回到同一張照片繼續調整。一筆紀錄包含作為編輯基準的原圖副本、目前的校正參數(引導線位置與各項角度、位移數值),以及校正後的成品與一張供列表顯示的縮圖。
- 儲存位置:本 App 在裝置上的私有目錄(Application Support),其他 App 無法讀取。
- 不會離開裝置:這些檔案已標記為排除備份,不會進入 iCloud 備份或電腦備份,也不會同步到您的其他裝置。它們與本 App 的其他資料一樣,不會被上傳到任何伺服器。
- 數量上限:最多保留 100 筆,超過時自動淘汰最久未更新的一筆。
- 刪除方式:您可以在 App 內的紀錄列表中長按任一筆紀錄將其刪除;移除本 App 則會一併刪除全部紀錄。
- 免費版的原圖副本長邊會縮至 4032 像素以節省空間;訂閱者則保留匯入時的完整解析度。
您拍攝的照片與影片,其原始檔案存放於系統「照片」App 中,由您完全掌控。請注意本 App 內有兩份性質不同的清單:相機畫面中的「本次拍攝」僅存在於記憶體中,關閉相機即清空;上述的編輯紀錄庫則會長期保存,直到您刪除為止。
此外,當您使用分享功能時,本 App 會在系統暫存目錄產生一份輸出檔交給分享對象。該檔案會在您下次分享時自動清除,也會隨 iOS 對暫存空間的清理一併移除。
五、購買與訂閱
- 本 App 的訂閱與買斷購買,全部透過 Apple 的 App 內購買(StoreKit) 完成。
- 本 App 不會接觸、傳輸或儲存您的付款資訊(信用卡號、Apple 帳號密碼等)。這些資料全程由 Apple 處理。
- 本 App 僅從 StoreKit 取得「目前是否具有使用權限」這一項結果,用於解鎖付費功能。此狀態不會被寫入裝置儲存空間,每次都向 StoreKit 重新確認。
- 有關 Apple 如何處理您的購買資料,請參閱 Apple 隱私權政策。
六、分享擴充功能(Share Extension)
當您在「照片」、「檔案」等其他 App 中選擇分享到 GridFix 時,該張照片會透過 iOS 的分享機制傳遞給本 App 進行編輯。此過程完全發生在您的裝置上,不涉及任何網路傳輸。
七、兒童隱私
本 App 不蒐集任何個人資料,因此也不會蒐集兒童的個人資料。本 App 不含社群功能、留言、聊天或使用者間的內容分享機制。
八、資料保留與刪除
由於本 App 不蒐集任何資料,我們手上沒有任何屬於您的資料,因此也沒有需要向我們申請刪除的對象。
若您希望清除本 App 儲存在裝置上的偏好設定(即第四節表格中 UserDefaults 的部分)以及整個編輯紀錄庫,將本 App 從裝置移除即可。編輯紀錄也可以在 App 內的紀錄列表中個別刪除,不必移除整個 App。
關於鑰匙圈中的每日額度計數器(編輯輸出次數與相機儲存張數),請注意以下三點:
- 依 iOS 對鑰匙圈項目的處理方式,這些項目在移除 App 後仍會留存於裝置上。如第四節所述,這是刻意的設計,用於避免每日免費額度被「移除後重新安裝」繞過;因此重新安裝本 App 並不會將它們清空,App 內也沒有提供重設入口。
- 它們僅包含兩個次數與一個日期,且每日自動歸零,不含任何可識別您身分的資訊。
- 由於本 App 沒有伺服器,也不會與我們的任何系統連線,我們無法從遠端存取、讀取或刪除您裝置上的任何資料,包括這些項目。它們完全存放在您的裝置本機,我們既看不到也碰不到。
九、第三方
本 App 未整合任何第三方服務,包含但不限於:分析工具、當機回報服務、廣告聯播網、社群登入、雲端儲存服務。
不過,有兩項由 Apple 提供給開發者的資料需要向您說明。它們不經過本 App,也不在本 App 的控制範圍內:
- 若您在 iOS 的「設定」→「隱私權與安全性」→「分析與改進」中開啟了「與 App 開發者共享」,Apple 會將當機紀錄與去識別化的使用量統計提供給開發者。此資料由 Apple 蒐集並去識別化後提供,我們無法從中識別出個別使用者。您可以隨時在該處關閉。
- Apple 會向開發者提供去識別化的彙總銷售與下載統計,其中不包含可識別個別購買者的資訊。
本 App 中僅有的對外連結為:隱私權政策、使用者授權合約(EULA)、App Store 評分頁與訂閱管理頁。點擊這些連結會開啟 Safari 或 App Store,屆時將適用該網站或 Apple 的隱私權政策。
十、您的權利
由於本 App 不蒐集、不傳輸也不持有您的任何個人資料,各地法規(例如歐盟 GDPR 第 15 至 22 條、美國加州 CCPA/CPRA、台灣個人資料保護法)所賦予的查詢、閱覽、更正、刪除、限制處理、資料可攜與拒絕自動化決策等權利,在本 App 並無可行使的對象——因為我們手上沒有任何您的資料。
我們亦不會因您行使上述任何權利而對您有差別待遇。若您對本政策或您的權利有任何疑問,歡迎依第十二節聯絡我們。
十一、政策變更
本政策若有修改,我們會更新本頁上方的生效日期;本頁所載版本即為當前有效版本。涉及重大變更時,會於 App 更新說明中一併告知。
十二、聯絡我們
對本政策有任何疑問,請透過以下方式聯絡:
依歐盟數位服務法(DSA)應揭露之完整交易者聯絡資訊,載於本 App 在 App Store 的產品頁。
語言版本:本政策以繁體中文版為準。下方英文版僅供參考,若兩者有任何歧異,概以繁體中文版為準。
GridFix Privacy Policy
Effective date: 10 August 2026
Applies to: GridFix 1.1 and later
GridFix is an iPhone and iPad tool for correcting perspective and lens distortion in photographs, including a live-corrected camera and video recording.
GridFix is developed and operated by PEI-CHUN CHAO (independent developer, Taiwan), who is the data controller for the processing described here.
This policy sets out what device data the app uses, why, and where it goes.
1. Summary: we do not collect your personal data
GridFix does not collect, upload, store, or share any personal data.
- The app has no server and makes no network requests to transmit your data.
- The app contains no third-party analytics, advertising, or tracking SDKs.
- The app does not access the advertising identifier (IDFA) and does not track you across apps or websites.
- Your photos, videos, and every edit you make are processed entirely on your device and never leave it.
GridFix's App Store privacy label reads “Data Not Collected”, consistent with the above.
2. Device permissions
Each of these is requested by the system the first time you use the relevant feature. You can change or revoke them at any time in Settings → GridFix.
Camera
Used for the live-corrected viewfinder and for taking photos and video. Frames are processed only in device memory and are never uploaded or transmitted.
Microphone
Used only when you switch to video mode, to record audio into the clip. If you only take photos, you will never be asked for it. Audio is written straight into your recording and is not otherwise stored, analysed, or transmitted. Declining still leaves you a usable silent recording.
Photos (full access)
Used to (a) save the photos and videos you capture into the system Photos app, and (b) mirror the “favourite” flag you set inside the app onto that same item in Photos.
Full access is required rather than add-only because iOS’s add-only authorisation can create new items but cannot modify existing ones, and setting a favourite is a modification.
GridFix does not browse, read, index, analyse, or transmit any other photo in your library. It touches only items it created itself, and items you explicitly choose through the system picker. It never deletes anything from your library — “remove” in the in-app gallery affects only that session’s list.
Motion sensors
Used to read the direction of gravity, from which the app derives the device’s pitch and roll in order to correct perspective live and to show the angle readout. Readings are used and discarded; no motion history is kept.
If you use the sensor calibration feature, the app stores the two measured offset angles and the date on your device, so the same fixed error can be subtracted from later readings. This contains no location and no motion history.
GridFix does not use location services. For how location tags already present in an existing photo are handled, see section 3.
Files
Used to import photos, including RAW, from the Files app or iCloud Drive. The app can access only the files you explicitly select in the system picker.
3. Photo metadata (EXIF)
A photo file usually carries metadata of its own (EXIF/TIFF), which may include the capture time, the camera and lens, exposure settings, and the GPS coordinates of where it was taken. GridFix handles this as follows:
GridFix does not read, parse, or transmit the contents of that metadata, and does not use it to determine where you are. GridFix does not use location services and never adds location information to your photos under any circumstances. What survives into an exported file depends on your tier:
| Output | Free | Subscribed / lifetime |
| Exporting an imported photo |
Lens, exposure, camera model and GPS location are removed; only the original capture date and the orientation tags are kept |
The original photo's metadata is retained in full, including any GPS location already present |
| Photos taken with the live-corrected camera |
No metadata at all |
The metadata the camera produced is retained in full |
| Video (a subscriber feature) | — | Recordings contain no location information |
The capture date is kept on free exports so an edited older photo still sits in its original place in the Photos timeline rather than jumping to today; the orientation tag is required for the image to display correctly. On either tier, orientation and pixel dimensions are rewritten to match the corrected image, because the corrected image differs from the original.
In short: GridFix never adds location to your photos. Free exports remove location that was already there; subscriber exports keep it. So if you are a subscriber intending to share an edited photo publicly, and the original was taken with the Camera's location permission enabled, that photo will still carry the coordinates of where it was taken. You can turn this off in the system Photos app by tapping “Options” in the share sheet and disabling “Location”, or strip it with a tool of your choice before sharing.
4. Data stored on your device
| Data | Where | Purpose |
| Grid mode, auto-level, capture and recording format, and other shooting preferences | UserDefaults | Remember your settings |
| Loupe corner preference | UserDefaults | Remember your settings |
| Interface language preference | UserDefaults | Remember the language you chose |
| Sensor calibration offsets and date | UserDefaults | Subtract a fixed sensor error |
| Review prompt counters | UserDefaults | Avoid asking repeatedly |
| Free-tier daily editor-export count and camera-save count, and their date | Keychain | Enforce the free allowances |
| Edit-record library (baseline copy, correction parameters, result and thumbnail) | App-private directory | Let you return to an earlier edit |
The two daily counters — editor exports and camera saves — are kept in the keychain so that the free allowances cannot be bypassed by deleting and reinstalling the app. They are stored with kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly — this device only, never synced to iCloud Keychain — consist of two numbers and one shared date, reset themselves each day, and contain nothing that identifies you. They survive removal of the app, which follows directly from the purpose above; see section 8.
Edit-record library
When you import a photo to edit, GridFix creates an “edit record” on your device so you can come back to that photo and carry on adjusting it later. A record holds a baseline copy of the photo, the current correction parameters (guide-line positions and the various angle and offset values), the corrected result, and a thumbnail for the list.
- Where: a directory private to GridFix on your device (Application Support), which no other app can read.
- It does not leave the device: these files are marked as excluded from backup, so they do not go into iCloud or computer backups and do not sync to your other devices. Like everything else in the app, they are never uploaded to any server.
- Limit: at most 100 records are kept; beyond that the least recently updated one is discarded automatically.
- Deleting: press and hold any record in the in-app list to delete it; removing the app deletes all of them.
- On the free tier the baseline copy is reduced to 4032 pixels on its long edge to save space; subscribers keep the full resolution the photo was imported at.
Photos and videos you capture live in the system Photos app, under your control. Note that the app has two distinct lists: the camera's “this session” strip exists only in memory and is cleared when you close the camera, while the edit-record library above persists until you delete it.
Separately, when you share an export, GridFix writes the finished file to the system temporary directory to hand it over. That file is cleared the next time you share, and is removed along with anything else iOS reclaims from temporary storage.
5. Purchases
All subscriptions and one-time purchases are handled by Apple’s In-App Purchase (StoreKit). GridFix never sees, transmits, or stores your payment details — Apple handles all of that. The app receives only whether you currently hold an entitlement, and that answer is re-checked with StoreKit rather than written to disk.
See Apple’s Privacy Policy for how Apple handles purchase data.
6. Share extension
When you share a photo to GridFix from another app, the photo is passed to GridFix through iOS’s own sharing mechanism. This happens entirely on your device.
7. Children
GridFix collects no personal data, and therefore collects none from children. It contains no social features, comments, chat, or user-to-user sharing.
8. Retention and deletion
Because nothing is collected, we hold no data belonging to you, and there is therefore nothing to request the deletion of.
To clear the preferences the app stores on your device (the UserDefaults rows in section 4) together with the whole edit-record library, remove the app from your device. Individual records can also be deleted from the record list inside the app, without removing anything else.
Three things to know about the daily counters held in the keychain:
- Consistent with how iOS treats keychain items, they remain on your device after the app is removed. As noted in section 4, this is deliberate: it prevents the daily free allowances from being bypassed by deleting and reinstalling. Reinstalling the app therefore does not clear them, and the app offers no way to reset them.
- They consist of two numbers and one date, reset themselves each day, and contain nothing that identifies you.
- Because the app has no server and never connects to any system of ours, we cannot remotely access, read, or delete anything on your device, these items included. They live entirely on your device, where we can neither see nor reach it.
9. Third parties
GridFix integrates no third-party services — no analytics, no crash reporting, no ad networks, no social sign-in, no cloud storage.
Two categories of data do reach the developer from Apple, however. Neither passes through the app, and neither is within its control:
- If you have enabled “Share with App Developers” under Settings → Privacy & Security → Analytics & Improvements, Apple provides developers with crash logs and de-identified usage statistics. This data is collected and de-identified by Apple; we cannot identify individual users from it. You can turn it off at any time in that same setting.
- Apple provides developers with de-identified, aggregated sales and download reports, which contain nothing identifying an individual purchaser.
The only outbound links in the app are to this privacy policy, the End User Licence Agreement, the App Store review page, and the subscription management page. Following them opens Safari or the App Store, at which point that site’s or Apple’s privacy policy applies.
10. Your rights
Because GridFix collects, transmits, and holds none of your personal data, the rights granted by applicable law — access, rectification, erasure, restriction, portability, and objection to automated decision-making under the EU GDPR (Articles 15–22), the California CCPA/CPRA, and Taiwan’s Personal Data Protection Act — have nothing to operate on here: we hold no data of yours.
You will not be treated differently for exercising any of those rights. If you have questions about this policy or your rights, contact us using section 12.
11. Changes
If this policy changes, the effective date above will be updated, and the version published on this page is the version in force. Material changes will also be noted in the app’s release notes.
12. Contact
Full trader contact details, as required for disclosure under the EU Digital Services Act, are published on the app’s App Store product page.
Governing language: the Traditional Chinese version above is the authoritative text. This English version is provided for convenience; in the event of any discrepancy, the Traditional Chinese version prevails.