Sia Makerlab
홈회사소개서비스포트폴리오공지사항문의하기

© since 2025 Sia Makerlab. All rights reserved.

사업자등록번호: 649-11-03282 | 대표: 이장욱

통신판매업신고번호: 제2025-충북제천-0264호

SiaFTP Client

개인정보처리방침

Sia Makerlab 제품 포트폴리오 통합 페이지에서 제공하는 개인정보처리방침입니다.

개인정보처리방침v1.0

Privacy Policy

Last Updated: July 31, 2026

Effective Date: July 31, 2026

Revision: 1.0

Revision History

VersionDateChanges
1.0July 31, 2026Initial release

1. Introduction

This Privacy Policy describes how Sia Makerlab ("we," "us," or "our") collects, uses, and shares information in connection with your use of the SiaFTP Client mobile application (the "App").

The App is a modern Android file-transfer client that lets you connect to remote file servers of your choosing over FTP, FTPS, SFTP, and SCP, and transfer files between your device and those servers. It does not require you to create an account, and we do not operate a server that stores your connection profiles, credentials, or files. The App connects directly from your device to the file servers you specify, and file contents are transferred only between your device and those servers. By downloading, installing, or using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the App.

2. Information We Collect

2.1 Information You Provide

The App is designed to function without an account or personal information. We do not collect your name, email address, phone number, or physical address.

To connect to a server, you provide its details — a profile name, protocol, host, port, username, and the credentials required (passwords, SSH keys), plus optional proxy settings and FTPS client certificates. This information is stored locally on your device and is not collected by us.

2.2 Connections and Transfers You Configure (Outbound Requests)

When you connect to a server, the App sends requests directly from your device to the file server you entered (optionally through a proxy you configure). File contents you upload or download are transferred only between your device and the servers you specify — they are never sent to us. We do not see, receive, or store the servers you connect to, your credentials, your directory listings, or the contents of any files you transfer. You are responsible for ensuring you are authorized to access any server and file you add.

2.3 Information Stored on Your Device

The App stores the following data only on your device:

DataCollectedStoredSharedPurpose
Server connection profilesYesDevice only (Keystore-encrypted, AES-256/GCM)NoProtocol, host, port, username, and connection settings
Credentials (passwords, SSH keys)YesDevice only (Keystore-encrypted, AES-256/GCM)NoAuthenticating to the servers you specify
Host-key trust recordsYesDevice onlyNoTrust-on-first-use verification of SSH/SFTP/SCP host keys
Proxy settings & FTPS client certificatesYesDevice only (encrypted)NoOptional HTTP CONNECT/SOCKS proxy and mutual-TLS authentication
Transfer queue, sync rules & historyYesDevice onlyNoManaging pending, active, and completed transfers and folder sync
App settingsYesDevice onlyNoTheme, language, Wi-Fi-only, schedule, and other preferences
Purchase stateYesDevice onlyNoCached "remove ads" entitlement (reconciled with Google Play)

This data is stored exclusively on your device. We do not have access to it, and it is never transmitted to our servers.

2.4 Local File Access

To upload files, and to receive downloaded files, the App accesses local files and folders that you pick through the Android Storage Access Framework (SAF). The App uses only the scoped URIs you grant and does not request broad or legacy storage permissions. File contents are read from, and written to, only the locations you select, and are transferred only between your device and the servers you specify.

2.5 Transfers, Background Service, and Notifications

The transfer queue runs in a WorkManager foreground service so transfers can continue reliably, and the App posts local notifications showing transfer progress and results. The App also supports scheduled background synchronization and an optional home-screen widget. These features run directly from your device against the servers you specify; the notifications are generated on-device and are not routed through, or sent to, our servers.

2.6 Profile Export and Import

You may export connection profiles as a JSON file that you choose. Exported profile files exclude all secrets (passwords, SSH keys, and certificates are not included). You may import profiles from a SiaFTP JSON file or from a FileZilla Site Manager XML file that you pick; any passwords contained in an imported file are encrypted with the Android Keystore on your device. We do not access, receive, or store these files.

2.7 Files Shared Into the App and App-to-App Transfer Requests

The App can receive files shared to it from other apps, and it accepts explicit upload and download requests from other apps on your device. Files you share in are copied into the App's private cache so the transfer can continue after the temporary access grant expires; those copies are removed once the transfer completes or is cancelled. A transfer request from another app never starts silently — the App always asks you to confirm the destination server first. These files stay on your device and on the servers you specify.

2.8 Permissions

  • Internet (INTERNET): required to connect to the file servers you configure and to serve ads.
  • Network state (ACCESS_NETWORK_STATE): used to determine connectivity and honor the Wi-Fi-only option.
  • Foreground service (FOREGROUND_SERVICE, FOREGROUND_SERVICE_DATA_SYNC): used to run the transfer queue and folder synchronization reliably while they are in progress.
  • Wake lock (WAKE_LOCK): used to keep the device awake while a transfer or synchronization is running.
  • Notifications (POST_NOTIFICATIONS, Android 13+): used to show transfer progress and results.
  • Advertising ID (AD_ID): declared by the Google Mobile Ads SDK and used by Google AdMob to serve ads (see Section 2.9).

The App does not request location, camera, microphone, contacts, or full/legacy storage permissions; local files are accessed only through the Storage Access Framework picker.

2.9 Advertising Data (Third-Party)

Unless you purchase the ad-removal option, the App displays advertising through Google AdMob using only one format: a banner at the bottom of the screen. The App does not use App Open, interstitial, or native ads. Our advertising partner may collect:

  • Advertising ID (Android Advertising ID)
  • Device information (device type, operating system version)
  • IP address
  • General location data (country/region level)
  • Ad interaction data

Where required, the App uses Google's User Messaging Platform (UMP) to obtain your consent for personalized advertising, and the Google Mobile Ads SDK is initialized only after consent allows ad requests. This data collection is governed by Google's Privacy Policy: https://policies.google.com/privacy

2.10 Information We Do NOT Collect

We explicitly do not collect:

  • Personal or contact information
  • The servers you connect to, your credentials, your directory listings, or the contents of any files you transfer
  • The contents of the profile files you export or import
  • Analytics or usage tracking data by us directly
  • Precise location data
  • Payment or card information (handled by Google Play)

3. How We Use Information

3.1 Local Data Usage

Data stored on your device is used locally to:

  • Connect to the file servers you configure and transfer files to and from them
  • Manage the transfer queue, folder synchronization, and scheduled background sync
  • Show transfer progress and result notifications and populate the optional widget
  • Remember your profiles, settings, and preferences
  • Apply your ad-removal entitlement

3.2 Third-Party Data Usage

Data collected by Google AdMob and Google UMP is used to display personalized or non-personalized advertisements (based on your consent) and to prevent fraud and abuse. Data collected by Google Play Billing is used to process and reconcile your purchase. Google Play In-App Updates and In-App Review are used, respectively, to offer an app update and an optional rating prompt; both flows are operated by Google Play.

4. Data Sharing and Disclosure

4.1 We Do Not Sell Your Data

We do not sell, trade, or rent your personal information to third parties.

4.2 Third-Party Service Providers

The App integrates the following third-party services, which handle data according to their own privacy policies:

ServicePurposePrivacy Policy
Google AdMobAdvertisinghttps://policies.google.com/privacy
Google User Messaging Platform (UMP)Ad consent managementhttps://policies.google.com/privacy
Google Play BillingProcess the one-time ad-removal purchasehttps://policies.google.com/privacy
Google Play In-App UpdatesOffer and install app updateshttps://policies.google.com/privacy
Google Play In-App ReviewOptional in-app rating prompthttps://policies.google.com/privacy

Separately, the App connects to, and transfers files to and from, the file servers you specify. Those servers are operated by you or by parties you choose, and their handling of your connections and files is outside our control.

4.3 Legal Requirements

We may disclose information if required to do so by law or in response to valid requests by public authorities. As we hold no user content, such disclosure would be limited to information actually in our possession.

5. Data Retention

5.1 Local Data

Data stored on your device remains until you delete it within the App, clear app data in device settings, or uninstall the App.

5.2 Third-Party Data

Data collected by Google's advertising, consent, and billing services is retained according to their respective policies.

6. Your Rights and Choices

6.1 For All Users

You have the right to:

  • Access: View your data within the App
  • Delete: Remove connection profiles, transfer history, and other data in the App, or clear app data or uninstall the App to remove all local data
  • Opt out of personalized ads: Manage ad personalization through your device's advertising settings or the UMP consent options

6.2 For Users in the EEA, United Kingdom, and Switzerland

Under the GDPR and applicable laws, you also have the rights to access, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of consent. To exercise rights over data held by a third-party service, contact that service directly.

6.3 Managing Consent

Manage advertising consent through:

  • In-App: privacy/consent options provided via Google UMP
  • Device Settings: Android Settings > Google > Ads

7. Data Security

We implement reasonable technical measures to protect data on your device:

  • Server profiles, credentials, SSH keys, and certificates are encrypted with the Android Keystore using AES-256/GCM
  • SSH/SFTP/SCP host keys are verified on a trust-on-first-use basis, and insecure-FTP warnings are surfaced
  • Data is stored only on your device; we operate no server and keep no copies
  • No cloud synchronization and no user accounts
  • Network access is used only to reach the servers you configure and third-party advertising

8. Children's Privacy

The App is not directed to children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children.

9. International Data Transfers

Data collected by third-party services may be transferred to and processed in countries with different data protection laws. Please refer to Google's Privacy Policy for more information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by updating the "Last Updated" date and, for material changes, displaying a notice within the App.

11. Disclaimer of Liability

11.1 Third-Party Services

We are not responsible for the data collection, use, or security practices of third-party services integrated into the App, including Google AdMob, Google UMP, Google Play Billing, Google Play In-App Updates, and Google Play In-App Review, nor for the servers you choose to connect to.

11.2 Data Loss

We are not responsible for any loss of data stored locally on your device, including your connection profiles and credentials, or for any loss, corruption, or overwriting of files during transfer or synchronization.

11.3 Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES RESULTING FROM YOUR USE OF THE APP.

12. Governing Law

This Privacy Policy shall be governed by the laws of the Republic of Korea. For EU users, it shall be interpreted in accordance with applicable EU law including the GDPR.

13. Contact Us

Sia Makerlab

  • Email: sia@siamakerlab.com
  • Website: https://siamakerlab.com

For GDPR-related inquiries from EEA residents, please include "GDPR Request" in the subject line.


Summary of Data Practices

Data TypeCollectedStoredSharedPurpose
Connection profiles & settingsYesDevice only (encrypted)NoConnecting to your servers and preferences
Credentials (passwords, SSH keys, certificates)YesDevice only (AES-256/GCM)NoAuthenticating to your servers
File contents transferredNo (device ↔ your servers)Not retainedOnly with servers you specifyUploading and downloading your files
Local files accessedNoLocations you pick via SAFNoReading uploads and writing downloads
Exported profile filesNo (secrets excluded)Locations you chooseNoProfile export
Imported profile files (SiaFTP JSON / FileZilla XML)NoDevice only (secrets encrypted)NoProfile import
Purchase stateYesDevice onlyNoAd-removal entitlement
Advertising IDYes*By GoogleWith GoogleAdvertising
Personal infoNoN/ANoN/A

*Collected by third-party services (Google), not by us directly.


This Privacy Policy is available in English. If translated versions are provided, the English version shall prevail in case of any discrepancy.

SiaFTP Client 제품 페이지로 돌아가기