SiaFTP Client
Sia Makerlab 제품 포트폴리오 통합 페이지에서 제공하는 개인정보처리방침입니다.
Last Updated: July 31, 2026
Effective Date: July 31, 2026
Revision: 1.0
| Version | Date | Changes |
|---|---|---|
| 1.0 | July 31, 2026 | Initial release |
This Privacy Policy describes how Sia Makerlab ("we," "us," or "our") collects, uses, and shares information in connection with your use of the SiaFTP Client mobile application (the "App").
The App is a modern Android file-transfer client that lets you connect to remote file servers of your choosing over FTP, FTPS, SFTP, and SCP, and transfer files between your device and those servers. It does not require you to create an account, and we do not operate a server that stores your connection profiles, credentials, or files. The App connects directly from your device to the file servers you specify, and file contents are transferred only between your device and those servers. By downloading, installing, or using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.
The App is designed to function without an account or personal information. We do not collect your name, email address, phone number, or physical address.
To connect to a server, you provide its details — a profile name, protocol, host, port, username, and the credentials required (passwords, SSH keys), plus optional proxy settings and FTPS client certificates. This information is stored locally on your device and is not collected by us.
When you connect to a server, the App sends requests directly from your device to the file server you entered (optionally through a proxy you configure). File contents you upload or download are transferred only between your device and the servers you specify — they are never sent to us. We do not see, receive, or store the servers you connect to, your credentials, your directory listings, or the contents of any files you transfer. You are responsible for ensuring you are authorized to access any server and file you add.
The App stores the following data only on your device:
| Data | Collected | Stored | Shared | Purpose |
|---|---|---|---|---|
| Server connection profiles | Yes | Device only (Keystore-encrypted, AES-256/GCM) | No | Protocol, host, port, username, and connection settings |
| Credentials (passwords, SSH keys) | Yes | Device only (Keystore-encrypted, AES-256/GCM) | No | Authenticating to the servers you specify |
| Host-key trust records | Yes | Device only | No | Trust-on-first-use verification of SSH/SFTP/SCP host keys |
| Proxy settings & FTPS client certificates | Yes | Device only (encrypted) | No | Optional HTTP CONNECT/SOCKS proxy and mutual-TLS authentication |
| Transfer queue, sync rules & history | Yes | Device only | No | Managing pending, active, and completed transfers and folder sync |
| App settings | Yes | Device only | No | Theme, language, Wi-Fi-only, schedule, and other preferences |
| Purchase state | Yes | Device only | No | Cached "remove ads" entitlement (reconciled with Google Play) |
This data is stored exclusively on your device. We do not have access to it, and it is never transmitted to our servers.
To upload files, and to receive downloaded files, the App accesses local files and folders that you pick through the Android Storage Access Framework (SAF). The App uses only the scoped URIs you grant and does not request broad or legacy storage permissions. File contents are read from, and written to, only the locations you select, and are transferred only between your device and the servers you specify.
The transfer queue runs in a WorkManager foreground service so transfers can continue reliably, and the App posts local notifications showing transfer progress and results. The App also supports scheduled background synchronization and an optional home-screen widget. These features run directly from your device against the servers you specify; the notifications are generated on-device and are not routed through, or sent to, our servers.
You may export connection profiles as a JSON file that you choose. Exported profile files exclude all secrets (passwords, SSH keys, and certificates are not included). You may import profiles from a SiaFTP JSON file or from a FileZilla Site Manager XML file that you pick; any passwords contained in an imported file are encrypted with the Android Keystore on your device. We do not access, receive, or store these files.
The App can receive files shared to it from other apps, and it accepts explicit upload and download requests from other apps on your device. Files you share in are copied into the App's private cache so the transfer can continue after the temporary access grant expires; those copies are removed once the transfer completes or is cancelled. A transfer request from another app never starts silently — the App always asks you to confirm the destination server first. These files stay on your device and on the servers you specify.
INTERNET): required to connect to the file servers you configure and to serve ads.ACCESS_NETWORK_STATE): used to determine connectivity and honor the Wi-Fi-only option.FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC): used to run the transfer queue and folder synchronization reliably while they are in progress.WAKE_LOCK): used to keep the device awake while a transfer or synchronization is running.POST_NOTIFICATIONS, Android 13+): used to show transfer progress and results.AD_ID): declared by the Google Mobile Ads SDK and used by Google AdMob to serve ads (see Section 2.9).The App does not request location, camera, microphone, contacts, or full/legacy storage permissions; local files are accessed only through the Storage Access Framework picker.
Unless you purchase the ad-removal option, the App displays advertising through Google AdMob using only one format: a banner at the bottom of the screen. The App does not use App Open, interstitial, or native ads. Our advertising partner may collect:
Where required, the App uses Google's User Messaging Platform (UMP) to obtain your consent for personalized advertising, and the Google Mobile Ads SDK is initialized only after consent allows ad requests. This data collection is governed by Google's Privacy Policy: https://policies.google.com/privacy
We explicitly do not collect:
Data stored on your device is used locally to:
Data collected by Google AdMob and Google UMP is used to display personalized or non-personalized advertisements (based on your consent) and to prevent fraud and abuse. Data collected by Google Play Billing is used to process and reconcile your purchase. Google Play In-App Updates and In-App Review are used, respectively, to offer an app update and an optional rating prompt; both flows are operated by Google Play.
We do not sell, trade, or rent your personal information to third parties.
The App integrates the following third-party services, which handle data according to their own privacy policies:
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google AdMob | Advertising | https://policies.google.com/privacy |
| Google User Messaging Platform (UMP) | Ad consent management | https://policies.google.com/privacy |
| Google Play Billing | Process the one-time ad-removal purchase | https://policies.google.com/privacy |
| Google Play In-App Updates | Offer and install app updates | https://policies.google.com/privacy |
| Google Play In-App Review | Optional in-app rating prompt | https://policies.google.com/privacy |
Separately, the App connects to, and transfers files to and from, the file servers you specify. Those servers are operated by you or by parties you choose, and their handling of your connections and files is outside our control.
We may disclose information if required to do so by law or in response to valid requests by public authorities. As we hold no user content, such disclosure would be limited to information actually in our possession.
Data stored on your device remains until you delete it within the App, clear app data in device settings, or uninstall the App.
Data collected by Google's advertising, consent, and billing services is retained according to their respective policies.
You have the right to:
Under the GDPR and applicable laws, you also have the rights to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. To exercise rights over data held by a third-party service, contact that service directly.
Manage advertising consent through:
We implement reasonable technical measures to protect data on your device:
The App is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children.
Data collected by third-party services may be transferred to and processed in countries with different data protection laws. Please refer to Google's Privacy Policy for more information.
We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date and, for material changes, displaying a notice within the App.
We are not responsible for the data collection, use, or security practices of third-party services integrated into the App, including Google AdMob, Google UMP, Google Play Billing, Google Play In-App Updates, and Google Play In-App Review, nor for the servers you choose to connect to.
We are not responsible for any loss of data stored locally on your device, including your connection profiles and credentials, or for any loss, corruption, or overwriting of files during transfer or synchronization.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES RESULTING FROM YOUR USE OF THE APP.
This Privacy Policy shall be governed by the laws of the Republic of Korea. For EU users, it shall be interpreted in accordance with applicable EU law including the GDPR.
Sia Makerlab
For GDPR-related inquiries from EEA residents, please include "GDPR Request" in the subject line.
| Data Type | Collected | Stored | Shared | Purpose |
|---|---|---|---|---|
| Connection profiles & settings | Yes | Device only (encrypted) | No | Connecting to your servers and preferences |
| Credentials (passwords, SSH keys, certificates) | Yes | Device only (AES-256/GCM) | No | Authenticating to your servers |
| File contents transferred | No (device ↔ your servers) | Not retained | Only with servers you specify | Uploading and downloading your files |
| Local files accessed | No | Locations you pick via SAF | No | Reading uploads and writing downloads |
| Exported profile files | No (secrets excluded) | Locations you choose | No | Profile export |
| Imported profile files (SiaFTP JSON / FileZilla XML) | No | Device only (secrets encrypted) | No | Profile import |
| Purchase state | Yes | Device only | No | Ad-removal entitlement |
| Advertising ID | Yes* | By Google | With Google | Advertising |
| Personal info | No | N/A | No | N/A |
*Collected by third-party services (Google), not by us directly.
This Privacy Policy is available in English. If translated versions are provided, the English version shall prevail in case of any discrepancy.