Effective date: August 31, 2026
This Privacy Policy applies to Signature PNG, localized in Simplified Chinese as “签名抠图.” Signature PNG is an iPhone and iPad app that turns a paper signature image selected by the user into a transparent PNG.
1. Core processing
Signature extraction, page correction, background removal, stroke repair, color adjustment, transparent preview, and PNG encoding run on the user’s device. The app has no feature that uploads the user’s source image, signature pixels, processing mask, exported PNG, or processing result to a server operated by the developer.
“On-device processing” does not mean that the device can never use a network connection. The following user- or system-initiated features may connect to a network:
- Photos or Files may download a source from Apple services when the selected item exists only in iCloud;
- StoreKit may connect to Apple services to load products, make a purchase, verify a transaction, or restore Lifetime Access;
- a Photos, Files, mail, or sharing destination chosen by the user may sync the exported PNG according to that system, account, or third-party service configuration;
- opening the Terms of Use webpage or sending a feedback email uses the corresponding system service or network connection.
The developer does not receive the signature image through these system behaviors unless the user independently chooses to send an image by email or another destination. The app’s feedback email does not attach a signature image automatically.
2. No account required
Signature PNG does not provide its own account, sign-in, user profile, social graph, or developer-managed cloud sync. It does not use CloudKit to store signatures and does not provide a cross-device signature library.
3. Photos and Files access
Import from Photos
The app uses Apple’s PhotosPicker so the user can explicitly choose one image. It does not request full photo-library read access and does not scan the library in the background. If the selected item exists only in iCloud, the system may need a network connection to download it.
Save to Photos
Only when the user explicitly chooses Save to Photos does the app request add-only photo-library access and write the validated PNG. Content saved to Photos is managed by the user’s system settings and may sync according to the user’s iCloud Photos configuration.
Import from and save to Files
The app uses system document pickers to access an input or output location explicitly chosen by the user; it does not scan all files on the device. While a security-scoped input URL is active, the file is copied into a protected, backup-excluded temporary directory and removed immediately after decoding. A PNG saved to Files is managed by the location and file service chosen by the user.
4. Camera, Apple Pencil, and iCloud
- The current version has no live camera or document-camera entry point and does not request camera permission. A camera graphic in the home animation is illustrative only.
- The app does not use PencilKit and has no Apple Pencil-specific permission or data collection. Its editing canvas uses ordinary touch gestures.
- The app does not use CloudKit or developer-managed iCloud sync. The system Photos/Files picker and a destination chosen by the user may still use iCloud according to the user’s settings.
5. Clipboard
Only when the user explicitly chooses Copy PNG does the app write the exported PNG to the system clipboard. The clipboard item is marked local to the device and is configured to expire after approximately two minutes. The app does not read existing clipboard content.
6. Temporary files and local retention
The app does not create a signature history, signature-template library, or in-app export library, and it does not permanently retain source photos or processed signature images.
To complete Files import and system sharing, the app briefly creates temporary files protected by the system and excluded from backup:
- an imported-file copy is removed after decoding;
- a temporary PNG used by the Share Sheet is removed after the share interface completes or closes;
- after an abnormal interruption, temporary session directories older than 24 hours are removed on a later launch.
When the user intentionally saves or sends a PNG to Photos, Files, the clipboard, email, or another sharing destination, that copy is managed by the corresponding system or service. The user should review its sync, backup, access, and deletion settings.
7. In-app purchases and device-local entitlement records
Signature PNG uses Apple StoreKit for one-time in-app purchases. It does not offer subscriptions or automatic renewal:
- “Unlock This Signature” is a consumable product. The app records the current source result as unlocked on this device so that the same result can be exported again locally. Restore Purchases does not promise to transfer this entitlement to another device.
- “Lifetime Access” is a non-consumable product that can be restored through StoreKit with the Apple Account used for purchase.
Apple processes payment, Apple Account, and transaction services. The app does not receive or store a bank-card number, complete payment details, or an Apple Account password.
The app stores the first free result identifier, unlocked result identifiers, a pending consumable transaction, and processed transaction IDs in a non-synchronizing, ThisDeviceOnly Keychain item. These records prevent repeat purchase of the same result on the device. They do not contain signature images, pixels, filenames, or file paths.
8. Analytics, advertising, third-party SDKs, and tracking
The current version:
- contains no advertising;
- contains no custom behavioral analytics or user profiling;
- contains no third-party analytics or crash-reporting SDK such as Firebase, Crashlytics, or Sentry;
- contains no third-party runtime SDK;
- does not track users across apps or websites; and
- does not sell or share user data for advertising.
The current Privacy Manifest declares no collected data, no tracking, no tracking domains, and no Required Reason API types. Apple may still provide system-level crash or performance diagnostics according to the user’s, device’s, and App Store settings; this is not an embedded third-party collection service in the app.
9. Security and user responsibility
A signature is sensitive personal material. The app applies system file protection to temporary files and hides signature content when inactive or shown in the task switcher, but every local device, system account, and export destination is also affected by its own security configuration. Users should protect their devices with a passcode and choose storage, backup, and sharing destinations carefully.
10. Control and deletion
Because the app has no developer-hosted account or cloud signature database, there is no server-side signature data to request from the developer for deletion. Users can:
- delete exported PNG files from Photos, Files, email, or another destination;
- allow the clipboard item to expire or replace it with other clipboard content;
- delete the app to remove local sandbox state; and
- manage photo permissions and related cloud-service settings in the system.
Permanent purchase records are managed by Apple StoreKit. Deleting the app does not cancel or delete Apple’s transaction record.
11. Changes to this policy
If the app’s data processing, network capabilities, or third-party dependencies change materially, this policy should be updated before the corresponding version is released. The website should display the latest effective date.
12. Contact
For questions about this policy or the privacy behavior of Signature PNG, contact:
dingronghui@163.com
The developer’s legal entity name, registered address, governing law, and jurisdiction have not been confirmed in the current project materials. The website publisher should add the actual information before publication rather than inventing it.