Sia NAS Manager
Sia Makerlab 제품 포트폴리오 통합 페이지에서 제공하는 개인정보처리방침입니다.
Last Updated: July 21, 2026
Effective Date: July 21, 2026
Revision: 1.0
| Version | Date | Changes |
|---|---|---|
| 1.0 | July 21, 2026 | Initial release |
This Privacy Policy describes how Sia Makerlab ("we," "us," or "our") collects, uses, and shares information in connection with your use of the Sia NAS Manager mobile application (the "App").
The App is an Android tool for monitoring and operating NAS units and Linux home servers that you specify. It is a status-and-operations tool, not a file manager. It connects directly from your device to the servers you configure — over SSH for Generic Linux, over the DSM Web API for Synology, and over the REST API for TrueNAS SCALE. It does not require you to create an account, and we do not operate a server that stores your connection details or your data. By downloading, installing, or using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.
Independence disclaimer: Sia NAS Manager is an independent application and is not affiliated with, endorsed by, or sponsored by Synology Inc., iXsystems, Inc. (TrueNAS), or any other vendor. "Synology" and "DSM" are trademarks of Synology Inc., "TrueNAS" is a trademark of iXsystems, Inc., and "Linux" is a registered trademark of Linus Torvalds; these and other marks belong to their respective owners and are used only descriptively.
The App is designed to function without an account or personal information. We do not collect your name, email address, phone number, or physical address.
To connect to a server, you provide its details — host and port, the connection method (SSH, DSM Web API, or TrueNAS REST), and authentication credentials such as a password, an SSH private key (Ed25519, RSA, or ECDSA) with an optional passphrase, an API key, or a two-factor code, along with transport options such as accepting and pinning a self-signed certificate. This configuration is stored locally on your device and is not collected by us.
When you open a connection, the App communicates directly from your device to the server you specified — there is no Sia Makerlab server, agent, or gateway in the path. Your server addresses, credentials, certificates, SSH keys, system metrics, logs, terminal input and output, and any command results travel between your device and that server — not through us. We do not see, receive, or store any of them. You are responsible for ensuring you are authorized to access any server you connect to and to perform the operations you execute.
The App stores the following data only on your device:
| Data | Collected | Stored | Shared | Purpose |
|---|---|---|---|---|
| Server / connection profiles | Yes | Device only | No | Hosts, ports, connection method, and transport options for servers you configure |
| Credentials & SSH keys | Yes | Device only (encrypted) | No | Passwords, API keys, tokens, and SSH private keys, encrypted at rest with the Android Keystore (AES-GCM); Room stores only a credential reference, and secrets are excluded from backup |
| Pinned host keys / certificates | Yes | Device only | No | SSH host key fingerprints and self-signed certificate pins used to detect server identity changes |
| Monitoring snapshots & alerts | Yes | Device only | No | Recent status/resource snapshots and locally generated alerts used for the dashboard and background checks (secrets are masked) |
| App settings | Yes | Device only | No | Theme, language, refresh intervals, thresholds, and other preferences |
| Purchase state | Yes | Device only | No | Cached ad-removal entitlement (reconciled with Google Play), if the purchase option is offered |
This data is stored exclusively on your device. We do not have access to it, and it is never transmitted to our servers.
The App requests only the following Android permissions:
INTERNET): required to connect to the servers you configure and, if advertising is enabled, to serve ads.ACCESS_NETWORK_STATE): used to detect network availability.POST_NOTIFICATIONS): used to deliver background monitoring alerts — such as offline, low-storage, and pool/disk problem notifications — that you enable.USE_BIOMETRIC): used, at your option, to lock the app and to gate sensitive-value reveals, the terminal, and destructive power operations. A device PIN or pattern may be used instead.AD_ID): used by Google AdMob to serve ads, if advertising is enabled (see Section 2.5).The App does not request location, camera, microphone, or contacts permissions.
The App is planned to be free to use. If advertising is enabled in a release, and unless you purchase the ad-removal option, the App displays advertising through Google AdMob. Ads are never shown on the terminal, log, credential, connection, or destructive-confirmation screens. Where advertising is served, our advertising partner may collect:
Where required, the App uses Google's User Messaging Platform (UMP) to obtain your consent for personalized advertising. Ad requests never fire before consent allows them. This data collection is governed by Google's Privacy Policy: https://policies.google.com/privacy
Advertising does not use your server data. Ads are served by Google AdMob using its own advertising identifier and device signals — not any data obtained from the servers you connect to. Your connection profiles, metrics, logs, and command results are never used for advertising.
We explicitly do not collect:
Data stored on your device is used locally to:
If advertising is enabled, data collected by Google AdMob and Google UMP is used to display personalized or non-personalized advertisements (based on your consent) and to prevent fraud and abuse. Data collected by Google Play Billing is used to process and reconcile your purchase.
We do not sell, trade, or rent your personal information to third parties.
Where enabled, the App integrates the following third-party services, which handle data according to their own privacy policies:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google AdMob | Advertising | https://policies.google.com/privacy |
| Google User Messaging Platform (UMP) | Ad consent management | https://policies.google.com/privacy |
| Google Play Billing | Process the ad-removal purchase | https://policies.google.com/privacy |
Separately, the App communicates directly with the servers you specify. Those servers are operated by you or by parties you choose, and their handling of your connections and data is outside our control.
We may disclose information if required to do so by law or in response to valid requests by public authorities. As we hold no user content, such disclosure would be limited to information actually in our possession.
Data stored on your device remains until you delete it within the App, clear app data in device settings, or uninstall the App. Because we operate no server and receive no data, we retain nothing about you or your servers.
Data collected by Google's advertising, consent, and billing services is retained according to their respective policies.
You have the right to:
Under the GDPR and applicable laws, you also have the rights to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. To exercise rights over data held by a third-party service, contact that service directly.
Manage advertising consent through:
We implement reasonable technical measures to protect data on your device:
Note that the operations available in the App reflect the permissions your credentials hold on the server itself; true access restriction must be configured on the server.
The App is a technical tool and is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children.
Data collected by third-party services may be transferred to and processed in countries with different data protection laws. Please refer to Google's Privacy Policy for more information.
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date and, for material changes, displaying a notice within the App.
We are not responsible for the data collection, use, or security practices of third-party services integrated into the App, including Google AdMob, Google UMP, and Google Play Billing, nor for the servers you choose to connect to.
We are not responsible for any loss of data stored locally on your device, including your server profiles, SSH keys, and monitoring history.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES RESULTING FROM YOUR USE OF THE APP.
This Privacy Policy shall be governed by the laws of the Republic of Korea. For EU users, it shall be interpreted in accordance with applicable EU law including the GDPR.
Sia Makerlab
For GDPR-related inquiries from EEA residents, please include "GDPR Request" in the subject line.
| Data Type | Collected | Stored | Shared | Purpose |
|---|---|---|---|---|
| Server / connection profiles & settings | Yes | Device only | No | Connecting to your servers and preferences |
| Credentials & SSH keys | Yes | Device only (encrypted) | No | Authenticating to your servers |
| Metrics, logs, terminal & NAS data | No (sent device → your servers) | Not retained | Only with servers you specify | Monitoring and operating your servers |
| Monitoring snapshots & alerts | Yes | Device only | No | Dashboard and background checks (secrets masked) |
| Purchase state | Yes | Device only | No | Ad-removal entitlement |
| Advertising ID | Yes* | By Google | With Google | Advertising, where enabled (not combined with your server data) |
| Personal info | No | N/A | No | N/A |
*Collected by third-party services (Google), not by us directly, and only where advertising is enabled.
This Privacy Policy is available in English. If translated versions are provided, the English version shall prevail in case of any discrepancy.