Last updated: 26 July 2026
CloudDrive2(以下简称「本应用」)由 CloudDrive2 开发团队提供,覆盖 Windows、macOS、Linux、iOS / iPadOS、tvOS、visionOS、Android、Android TV 与 Meta Quest 等平台。本政策说明本应用收集哪些信息、如何使用,以及你如何控制这些信息。
核心原则:本应用是一个客户端工具。你的文件不会经过我们的服务器。浏览、播放、上传、下载与跨云传输均由你的设备直接与你自己的云盘 / 存储服务之间完成。
2.1 账户信息:如果你注册 CloudDrive2 账户,我们会收集你的邮箱地址,以及你密码的哈希值——我们不保存你的密码本身,因此无法读取或还原你的密码。这些信息用于身份验证、找回密码,以及记录你的会员 / 订阅状态。
2.2 云盘凭证(加密同步,默认开启):为了让你在同一账户的多台设备之间共享已添加的云盘,本应用默认开启「同步数据到云端」。开启时,你添加的云盘账号、密码与 OAuth 令牌会先在你的设备上用你的密码加密,再上传保存到我们的服务器。
由于我们只保存密码哈希、不保存密码本身,我们无法解密这些凭证——只有持有你明文密码的设备才能解密。对我们而言,它们只是无法读取的密文。
你可以在登录时取消勾选「同步数据到云端」,此时凭证仅保存在本机、不会上传。
请注意:正因为我们无法解密,如果你忘记密码,已同步的云盘凭证将无法恢复,需要重新添加云盘。
2.3 购买记录:会员与内购的交易由 Apple App Store、Google Play 或 Meta Horizon Store 处理。我们仅接收用于开通权益所需的交易凭证与产品标识,不会接收你的完整支付卡号或银行信息。
2.4 技术支持信息:仅当你主动联系我们或主动提交日志时,我们才会收到你提供的日志、截图与设备信息。
3.1 你的文件内容:本应用不会将你的文件、照片、视频、音乐或文档上传到我们的服务器。
3.2 可读的云盘凭证:我们无法读取你的云盘账号、密码与 OAuth 令牌。它们在离开你的设备之前就已用你的密码加密(见 2.2);我们只持有无法解密的密文。如果你关闭「同步数据到云端」,它们根本不会离开你的设备。
3.3 广告与追踪:本应用不含广告 SDK、不含第三方分析或崩溃统计 SDK,不读取广告标识符(Advertising ID),不进行跨应用追踪。
3.4 位置信息:本应用不请求也不收集位置信息。
4.1 所有文件访问权限(MANAGE_EXTERNAL_STORAGE):用于本应用的核心功能——浏览与管理设备本地文件,并将本地文件夹备份 / 同步到云盘。文件仅在你的设备与你指定的云盘之间传输。
4.2 照片与视频权限(READ_MEDIA_IMAGES / READ_MEDIA_VIDEO / READ_MEDIA_AUDIO):用于你主动发起的相册备份与媒体文件上传。
4.3 前台服务(数据同步 / 媒体播放):用于在你切换应用或锁屏时继续进行传输任务与媒体播放。
4.4 通知权限:用于显示传输进度、备份结果与播放控制。
4.5 网络、Wi-Fi 状态与组播:用于访问云盘、以及在局域网内发现 Emby / Jellyfin 媒体服务器。
4.6 USB 主机模式与音频设置:用于向外接 USB DAC 输出原生 DSD / 比特完美音频。
5.1 你连接的云盘与存储服务:当你添加 115、阿里云盘、百度网盘、123云盘、迅雷云盘、天翼云盘、光鸭云盘、Google Drive、OneDrive、S3 / 兼容对象存储、WebDAV、SMB、FTP/SFTP 等服务时,你与这些服务之间的交互受该服务自身的隐私政策约束。
5.2 AI 实时字幕翻译(可选功能):本功能可完全在设备端运行。如果你主动配置了远程语音识别或翻译服务(例如 OpenAI、Groq、Qwen,或你自建的 Speaches / MTranServer),相应的音频片段或字幕文本会使用你自己的 API 密钥发送到你指定的服务商,并受该服务商的隐私政策约束。我们不接收也不代理这些数据。
5.3 Emby / Jellyfin:你填写的媒体服务器地址与凭证仅保存在本地,用于直接连接你自己的服务器。
6.1 账户密码以哈希形式保存,我们不保存密码原文;与我们服务器之间的所有通信均使用 HTTPS / TLS 加密传输。
6.2 云盘凭证保存在设备的应用私有存储空间内;若开启同步,另有一份用你的密码加密后的密文保存在我们的服务器上(见 2.2)。应用设置保存在本机。
6.3 卸载本应用会清除设备上保存的本地设置与云盘凭证。若你曾开启同步,服务器上的加密副本会保留,直到你删除账户(见 7.2)。
7.1 查询与更正:你可以在应用内或通过邮件联系我们,查询或更正你的账户信息。
7.2 删除账户:你可以随时请求删除 CloudDrive2 账户及其关联数据。方法见 账户删除说明。
7.3 撤回权限:你可以在系统设置中随时撤回已授予本应用的任何权限。
本应用不面向 13 岁以下儿童设计,也不会有意收集儿童的个人信息。
本政策如有更新,我们会修改本页顶部的「最后更新」日期。重大变更会通过应用内或官网公告告知。
邮箱:waytechcloudfs@gmail.com
问题反馈:GitHub Issues
CloudDrive2 ("the app") is provided by the CloudDrive2 development team for Windows, macOS, Linux, iOS / iPadOS, tvOS, visionOS, Android, Android TV and Meta Quest. This policy explains what information the app collects, how it is used, and how you can control it.
Core principle: the app is a client tool. Your files do not pass through our servers. Browsing, playback, uploads, downloads and cross-cloud transfers all happen directly between your device and your own cloud or storage services.
2.1 Account information. If you register a CloudDrive2 account we collect your email address and a hash of your password — we do not store your password itself, so we cannot read or recover it. This is used for authentication, password recovery, and to record your membership or subscription status.
2.2 Cloud credentials (encrypted sync, on by default). So that the clouds you add are
available on every device signed in to the same account, the app enables "sync data to cloud" by default.
When it is on, the account details, passwords and OAuth tokens for the clouds you add are
encrypted on your device using your password before being uploaded to our servers.
Because we hold only a password hash and never your password, we cannot decrypt these
credentials — only a device holding your plaintext password can. To us they are unreadable
ciphertext.
You can untick "sync data to cloud" when signing in, in which case credentials
never leave your device.
Please note: precisely because we cannot decrypt them, if you forget your
password the synced cloud credentials cannot be recovered and the clouds must be added again.
2.3 Purchase records. Membership and in-app purchases are processed by the Apple App Store, Google Play or the Meta Horizon Store. We receive only the transaction receipt and product identifier needed to grant entitlements — never your full card or bank details.
2.4 Support information. We receive logs, screenshots and device details only when you choose to send them to us.
3.1 Your file content. The app never uploads your files, photos, videos, music or documents to our servers.
3.2 Readable cloud credentials. We cannot read the account details, passwords or OAuth tokens for the clouds you add. They are encrypted with your password before they leave your device (see 2.2), and we hold only ciphertext we are unable to decrypt. With "sync data to cloud" turned off, they never leave your device at all.
3.3 Advertising and tracking. The app contains no advertising SDK, no third-party analytics or crash-reporting SDK, does not read the Advertising ID, and performs no cross-app tracking.
3.4 Location. The app neither requests nor collects location data.
4.1 All files access (MANAGE_EXTERNAL_STORAGE). Required for the app's core purpose — browsing and managing local files on the device, and backing local folders up to the cloud. Files move only between your device and the cloud services you choose.
4.2 Photo and video permissions (READ_MEDIA_IMAGES / READ_MEDIA_VIDEO / READ_MEDIA_AUDIO). Used for photo-library backup and media uploads that you initiate.
4.3 Foreground services (data sync / media playback). Keep transfers and playback running when you switch apps or lock the screen.
4.4 Notifications. Transfer progress, backup results and playback controls.
4.5 Network, Wi-Fi state and multicast. Reaching your clouds, and discovering Emby / Jellyfin servers on your local network.
4.6 USB host mode and audio settings. Native DSD / bit-perfect output to an external USB DAC.
5.1 Clouds and storage you connect. When you add services such as 115, Aliyun Drive, Baidu Pan, 123 Pan, Xunlei Cloud, Tianyi Cloud, GuangYaPan, Google Drive, OneDrive, S3-compatible object storage, WebDAV, SMB or FTP/SFTP, your interaction with those services is governed by their own privacy policies.
5.2 AI live subtitle translation (optional). This feature can run entirely on-device. If you configure a remote speech-recognition or translation service (for example OpenAI, Groq, Qwen, or your own Speaches / MTranServer instance), audio segments or subtitle text are sent to the provider you chose, using your own API key, and are governed by that provider's privacy policy. We neither receive nor proxy this data.
5.3 Emby / Jellyfin. Server addresses and credentials you enter are stored locally and used only to connect to your own server.
6.1 Account passwords are stored as a hash — we never store the password itself. All communication with our servers uses HTTPS / TLS.
6.2 Cloud credentials are kept in the app's private storage on the device; if sync is enabled, a copy encrypted with your password is also held on our servers (see 2.2). App settings stay on the device.
6.3 Uninstalling the app removes the locally stored settings and cloud credentials. If you enabled sync, the encrypted copy on our servers remains until you delete your account (see 7.2).
7.1 Access and correction. You can review or correct your account information in the app or by contacting us.
7.2 Account deletion. You may request deletion of your CloudDrive2 account and its associated data at any time — see Account Deletion.
7.3 Withdrawing permissions. Any permission granted to the app can be revoked at any time in your system settings.
The app is not directed to children under 13 and we do not knowingly collect personal information from children.
If this policy changes we will update the "Last updated" date at the top of this page. Material changes will be announced in the app or on our website.
Email: waytechcloudfs@gmail.com
Issue tracker: GitHub Issues