Sia Makerlab
홈회사소개서비스포트폴리오공지사항문의하기

© since 2025 Sia Makerlab. All rights reserved.

사업자등록번호: 649-11-03282 | 대표: 이장욱

통신판매업신고번호: 제2025-충북제천-0264호

Sia NAS Manager

개인정보처리방침

Sia Makerlab 제품 포트폴리오 통합 페이지에서 제공하는 개인정보처리방침입니다.

개인정보처리방침v1.0

Privacy Policy

Last Updated: July 21, 2026

Effective Date: July 21, 2026

Revision: 1.0

Revision History

VersionDateChanges
1.0July 21, 2026Initial release

1. Introduction

This Privacy Policy describes how Sia Makerlab ("we," "us," or "our") collects, uses, and shares information in connection with your use of the Sia NAS Manager mobile application (the "App").

The App is an Android tool for monitoring and operating NAS units and Linux home servers that you specify. It is a status-and-operations tool, not a file manager. It connects directly from your device to the servers you configure — over SSH for Generic Linux, over the DSM Web API for Synology, and over the REST API for TrueNAS SCALE. It does not require you to create an account, and we do not operate a server that stores your connection details or your data. By downloading, installing, or using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.

Independence disclaimer: Sia NAS Manager is an independent application and is not affiliated with, endorsed by, or sponsored by Synology Inc., iXsystems, Inc. (TrueNAS), or any other vendor. "Synology" and "DSM" are trademarks of Synology Inc., "TrueNAS" is a trademark of iXsystems, Inc., and "Linux" is a registered trademark of Linus Torvalds; these and other marks belong to their respective owners and are used only descriptively.

2. Information We Collect

2.1 Information You Provide

The App is designed to function without an account or personal information. We do not collect your name, email address, phone number, or physical address.

To connect to a server, you provide its details — host and port, the connection method (SSH, DSM Web API, or TrueNAS REST), and authentication credentials such as a password, an SSH private key (Ed25519, RSA, or ECDSA) with an optional passphrase, an API key, or a two-factor code, along with transport options such as accepting and pinning a self-signed certificate. This configuration is stored locally on your device and is not collected by us.

2.2 Connections You Configure (Outbound Requests)

When you open a connection, the App communicates directly from your device to the server you specified — there is no Sia Makerlab server, agent, or gateway in the path. Your server addresses, credentials, certificates, SSH keys, system metrics, logs, terminal input and output, and any command results travel between your device and that server — not through us. We do not see, receive, or store any of them. You are responsible for ensuring you are authorized to access any server you connect to and to perform the operations you execute.

2.3 Information Stored on Your Device

The App stores the following data only on your device:

DataCollectedStoredSharedPurpose
Server / connection profilesYesDevice onlyNoHosts, ports, connection method, and transport options for servers you configure
Credentials & SSH keysYesDevice only (encrypted)NoPasswords, API keys, tokens, and SSH private keys, encrypted at rest with the Android Keystore (AES-GCM); Room stores only a credential reference, and secrets are excluded from backup
Pinned host keys / certificatesYesDevice onlyNoSSH host key fingerprints and self-signed certificate pins used to detect server identity changes
Monitoring snapshots & alertsYesDevice onlyNoRecent status/resource snapshots and locally generated alerts used for the dashboard and background checks (secrets are masked)
App settingsYesDevice onlyNoTheme, language, refresh intervals, thresholds, and other preferences
Purchase stateYesDevice onlyNoCached ad-removal entitlement (reconciled with Google Play), if the purchase option is offered

This data is stored exclusively on your device. We do not have access to it, and it is never transmitted to our servers.

2.4 Permissions

The App requests only the following Android permissions:

  • Internet (INTERNET): required to connect to the servers you configure and, if advertising is enabled, to serve ads.
  • Network state (ACCESS_NETWORK_STATE): used to detect network availability.
  • Notifications (POST_NOTIFICATIONS): used to deliver background monitoring alerts — such as offline, low-storage, and pool/disk problem notifications — that you enable.
  • Biometric (USE_BIOMETRIC): used, at your option, to lock the app and to gate sensitive-value reveals, the terminal, and destructive power operations. A device PIN or pattern may be used instead.
  • Advertising ID (AD_ID): used by Google AdMob to serve ads, if advertising is enabled (see Section 2.5).

The App does not request location, camera, microphone, or contacts permissions.

2.5 Advertising Data (Third-Party)

The App is planned to be free to use. If advertising is enabled in a release, and unless you purchase the ad-removal option, the App displays advertising through Google AdMob. Ads are never shown on the terminal, log, credential, connection, or destructive-confirmation screens. Where advertising is served, our advertising partner may collect:

  • Advertising ID (Android Advertising ID)
  • Device information (device type, operating system version)
  • IP address
  • General location data (country/region level)
  • Ad interaction data

Where required, the App uses Google's User Messaging Platform (UMP) to obtain your consent for personalized advertising. Ad requests never fire before consent allows them. This data collection is governed by Google's Privacy Policy: https://policies.google.com/privacy

Advertising does not use your server data. Ads are served by Google AdMob using its own advertising identifier and device signals — not any data obtained from the servers you connect to. Your connection profiles, metrics, logs, and command results are never used for advertising.

2.6 Information We Do NOT Collect

We explicitly do not collect:

  • Personal or contact information
  • Your servers, credentials, SSH keys, metrics, logs, terminal input/output, or NAS data
  • Analytics or usage tracking data by us directly
  • Precise location data
  • Payment or card information (handled by Google Play)

3. How We Use Information

3.1 Local Data Usage

Data stored on your device is used locally to:

  • Establish the connections you configure and run the operations you request
  • Remember your server profiles, pinned host identities, and monitoring history
  • Deliver the background monitoring alerts you enable
  • Apply your settings and preferences
  • Apply your ad-removal entitlement, if the purchase option is offered

3.2 Third-Party Data Usage

If advertising is enabled, data collected by Google AdMob and Google UMP is used to display personalized or non-personalized advertisements (based on your consent) and to prevent fraud and abuse. Data collected by Google Play Billing is used to process and reconcile your purchase.

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data

We do not sell, trade, or rent your personal information to third parties.

4.2 Third-Party Service Providers

Where enabled, the App integrates the following third-party services, which handle data according to their own privacy policies:

ServicePurposePrivacy Policy
Google AdMobAdvertisinghttps://policies.google.com/privacy
Google User Messaging Platform (UMP)Ad consent managementhttps://policies.google.com/privacy
Google Play BillingProcess the ad-removal purchasehttps://policies.google.com/privacy

Separately, the App communicates directly with the servers you specify. Those servers are operated by you or by parties you choose, and their handling of your connections and data is outside our control.

4.3 Legal Requirements

We may disclose information if required to do so by law or in response to valid requests by public authorities. As we hold no user content, such disclosure would be limited to information actually in our possession.

5. Data Retention

5.1 Local Data

Data stored on your device remains until you delete it within the App, clear app data in device settings, or uninstall the App. Because we operate no server and receive no data, we retain nothing about you or your servers.

5.2 Third-Party Data

Data collected by Google's advertising, consent, and billing services is retained according to their respective policies.

6. Your Rights and Choices

6.1 For All Users

You have the right to:

  • Access: View your data within the App
  • Delete: Remove server profiles in the App, or clear app data or uninstall the App to remove all local data
  • Opt out of personalized ads: Manage ad personalization through your device's advertising settings or the UMP consent options, where advertising is enabled

6.2 For Users in the EEA, United Kingdom, and Switzerland

Under the GDPR and applicable laws, you also have the rights to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. To exercise rights over data held by a third-party service, contact that service directly.

6.3 Managing Consent

Manage advertising consent through:

  • In-App: privacy/consent options provided via Google UMP, where advertising is enabled
  • Device Settings: Android Settings > Google > Ads

7. Data Security

We implement reasonable technical measures to protect data on your device:

  • Credentials and SSH keys are encrypted at rest with the Android Keystore (AES-GCM), stored in Room only as a credential reference, and excluded from app-data backup
  • SSH host keys are verified by SHA-256 fingerprint and pinned on approval; self-signed certificates are pinned on your confirmation — a changed host key or certificate blocks the connection rather than trusting it silently, and no "trust all certificates" option is provided
  • Sensitive screens — credentials, SSH keys, and the terminal — can be protected from screen capture
  • Secrets and identifiers such as IP addresses, hostnames, tokens, API keys, SSH fingerprints, and paths are masked in logs
  • Data is stored only on your device; we operate no server and keep no copies
  • No cloud synchronization and no user accounts
  • Network access is used only to reach the servers you configure and, where enabled, to serve third-party advertising

Note that the operations available in the App reflect the permissions your credentials hold on the server itself; true access restriction must be configured on the server.

8. Children's Privacy

The App is a technical tool and is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children.

9. International Data Transfers

Data collected by third-party services may be transferred to and processed in countries with different data protection laws. Please refer to Google's Privacy Policy for more information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date and, for material changes, displaying a notice within the App.

11. Disclaimer of Liability

11.1 Third-Party Services

We are not responsible for the data collection, use, or security practices of third-party services integrated into the App, including Google AdMob, Google UMP, and Google Play Billing, nor for the servers you choose to connect to.

11.2 Data Loss

We are not responsible for any loss of data stored locally on your device, including your server profiles, SSH keys, and monitoring history.

11.3 Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES RESULTING FROM YOUR USE OF THE APP.

12. Governing Law

This Privacy Policy shall be governed by the laws of the Republic of Korea. For EU users, it shall be interpreted in accordance with applicable EU law including the GDPR.

13. Contact Us

Sia Makerlab

  • Email: sia@siamakerlab.com
  • Website: https://siamakerlab.com

For GDPR-related inquiries from EEA residents, please include "GDPR Request" in the subject line.


Summary of Data Practices

Data TypeCollectedStoredSharedPurpose
Server / connection profiles & settingsYesDevice onlyNoConnecting to your servers and preferences
Credentials & SSH keysYesDevice only (encrypted)NoAuthenticating to your servers
Metrics, logs, terminal & NAS dataNo (sent device → your servers)Not retainedOnly with servers you specifyMonitoring and operating your servers
Monitoring snapshots & alertsYesDevice onlyNoDashboard and background checks (secrets masked)
Purchase stateYesDevice onlyNoAd-removal entitlement
Advertising IDYes*By GoogleWith GoogleAdvertising, where enabled (not combined with your server data)
Personal infoNoN/ANoN/A

*Collected by third-party services (Google), not by us directly, and only where advertising is enabled.


This Privacy Policy is available in English. If translated versions are provided, the English version shall prevail in case of any discrepancy.

Sia NAS Manager 제품 페이지로 돌아가기