Sia Linux VM
Sia Makerlab 제품 포트폴리오 통합 페이지에서 제공하는 개인정보처리방침입니다.
Last Updated: July 21, 2026
Effective Date: July 21, 2026
Revision: 1.1
| Version | Date | Changes |
|---|---|---|
| 1.1 | July 21, 2026 | Updated to reflect the current app architecture: bundled GPL v2 QEMU runtime, user-supplied Linux images, serial console instead of in-app SSH credentials, QGA monitoring, foreground service permissions, diagnostic export, and repeatable donation billing. |
| 1.0 | July 17, 2026 | Initial release |
This Privacy Policy describes how Sia Makerlab ("we," "us," or "our") handles information in connection with your use of the Sia Linux VM mobile application (the "App").
The App creates and runs ARM64 Linux virtual machines locally on your Android device. It includes a verified QEMU runtime, but it does not include Linux operating system images. You provide Linux disk images, installer ISOs, additional disks, guest software, and any services you run inside a VM. The App does not require a Sia Makerlab account, and we do not operate a server that stores your VM files, guest activity, console output, or local configuration.
Independence disclaimer: Sia Linux VM is an independent application and is not affiliated with, endorsed by, or sponsored by the QEMU project, Canonical (Ubuntu), the Debian project, the Fedora project, Docker, Inc., Red Hat, Inc., or any other vendor. "Linux" is a registered trademark of Linus Torvalds, and QEMU, Ubuntu, Debian, Fedora, Docker, and other names are trademarks of their respective owners, used here only descriptively.
The App is designed to work without an account or contact information. We do not collect your name, email address, phone number, or physical address through the App.
You may create VM profiles and choose CPU, RAM, storage, boot mode, image references, local TCP port-forwarding rules, safety policies, language, and other preferences. This information is stored locally on your device in app-private storage.
The App imports files selected by you through the Android Storage Access Framework and can download files from URLs or publisher pages you choose. App-managed copies, VM disks, installer ISOs, ZIP/folder imports, boot metadata, checksum data, and task state remain on your device. We do not receive, host, mirror, or store your Linux images, additional disks, guest files, or VM data.
The App includes a QEMU runtime and related firmware/ROM files required for local VM execution. Linux images and guest software are not included.
The built-in terminal uses a local QEMU serial console. The App does not require SSH usernames, passwords, or private keys for its built-in terminal. If you configure guest networking or local port forwarding, network traffic is between your device, the VM, and endpoints you or the guest choose. We do not route that traffic through a Sia Makerlab server.
Where available, the App reads status from QEMU Guest Agent using a private local channel to show guest OS, filesystem, interface, load, and memory-block information. It does not use QGA to run Docker commands, list containers, control containers, or collect guest content for us.
Diagnostic export is created only when you explicitly request it. The export is written to cache and shared only through Android Sharesheet to the app or destination you select. The export is designed to remove guest console content, names, URLs, addresses, secrets, and internal absolute paths.
| Data | Stored | Shared with us | Purpose |
|---|---|---|---|
| VM profiles and settings | Device only | No | Create, configure, start, stop, pause, resume, and recover VMs |
| Imported images and VM disks | Device only | No | Run VMs and manage storage |
| Download and import task state | Device only | No | Resume interrupted work and recover after app restart |
| Console and runtime state | Device only | No | Display VM output, errors, and recovery steps |
| Recent host monitoring samples | Memory/local device only | No | Show CPU, memory, disk, network, storage, battery, charging, and thermal status |
| QGA status values | Device only | No | Show read-only guest status where available |
| App settings | Device only | No | Preserve language, onboarding, safety, privacy, and UI preferences |
| Donation/ad-removal state mirror | Device only | No | Hide ads after a confirmed donation for the current app installation |
The App sets android:allowBackup="false", so app-private data is excluded from Android OS/cloud backup.
The App declares the following Android permissions:
INTERNET): user-requested downloads, QEMU guest networking, advertising, and Google Play services.ACCESS_NETWORK_STATE): connection checks, Wi-Fi-only download conditions, and network status display.POST_NOTIFICATIONS): foreground VM, download/import progress, and safety alerts on Android 13+.FOREGROUND_SERVICE) and foreground service special use (FOREGROUND_SERVICE_SPECIAL_USE): keep a user-started local Linux VM process running.The App does not declare location, contacts, calendar, camera, microphone, call log, SMS, biometric, broad storage (MANAGE_EXTERNAL_STORAGE), or installed-app inventory (QUERY_ALL_PACKAGES) permissions. File access is limited to documents or folders you select through the Storage Access Framework.
Unless ads are removed for the current app installation after a confirmed donation, the App displays Google AdMob advertising using the App Open format only. App Open ads are not shown while a VM is running, during onboarding, during the consent flow, during purchase flow, or for a donated current installation.
Google AdMob and related Google services may process advertising identifiers where available, device information, IP address, coarse location inferred by Google, and ad interaction data according to Google's policies. The App uses Google's User Messaging Platform (UMP) where required to request or manage advertising consent before ads are requested.
Advertising does not use your Linux images, VM disks, console input/output, QGA data, diagnostic export contents, or VM configuration.
We do not collect:
Local data is used to run the App features you request: creating and operating VMs, importing and verifying images, resuming tasks, showing terminal output, presenting monitoring charts, enforcing safe deletion and resource rules, and creating an optional scrubbed diagnostic export.
Google AdMob and UMP use data to provide advertising and consent management. Google Play Billing uses data to process the voluntary repeatable donation product.
We do not sell, trade, or rent your information. Because the App has no Sia Makerlab account system or VM backend, we do not receive your VM content.
Third-party services integrated into the App handle data under their own policies:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google AdMob | App Open advertising | https://policies.google.com/privacy |
| Google User Messaging Platform | Advertising consent management | https://policies.google.com/privacy |
| Google Play Billing | Process the voluntary donation product | https://policies.google.com/privacy |
| Google Play Review / In-App Update | Optional review prompt and update guidance | https://policies.google.com/privacy |
Separately, downloads and guest network traffic go to endpoints you or the guest choose. Those endpoints are not operated by us unless explicitly identified as Sia Makerlab.
Local App data remains on your device until you delete it in the App, clear app data in Android settings, or uninstall the App. Deleting a VM profile and deleting an image file are separate actions. The App may block deletion of images still referenced by a VM or by damaged metadata that cannot be safely interpreted.
Third-party data retained by Google services is governed by Google's policies.
You can:
The App uses app-private storage, disables Android backup, verifies bundled QEMU/firmware integrity, checks imported image formats and checksums where available, uses Storage Access Framework boundaries, applies Zip Slip and path-escape defenses, limits diagnostic export paths through FileProvider, and avoids automatic upload of diagnostic files. You remain responsible for the safety, license compliance, and trustworthiness of any Linux image, guest software, or endpoint you use.
The App is a technical tool and is not directed to children under the age of 13, or 16 where applicable. We do not knowingly collect personal information from children.
Google services may process data in countries other than your own according to Google's policies. VM files and local configuration are not transferred to us.
We may update this Privacy Policy from time to time. We will update the "Last Updated" date and, for material changes, may provide notice in the App or on the App listing.
Sia Makerlab
This Privacy Policy is available in English. If translated versions are provided, the English version shall prevail in case of any discrepancy.