Privacy Policy

WebHarbor · Updated 30 September 2026 · Port location and developer sampling disclosure

English

WebHarbor is a local-first iPhone app without advertising or advertising tracking. Version 3.0 adds an optional notification gateway; notification processing applies when you connect a workspace and the service is available. Port also offers a separate, voluntary developer location-sampling workflow described below. Earlier builds may not include these features. Availability depends on deployment and device validation.

Optional notifications in 3.0

After you opt in, notify.lihenry.com processes an encrypted Apple push device token, an installation credential hash, a random notification route identifier, language preference, and site user/group references to send reminders. For a Hezhang workspace, the gateway may also receive an encrypted, bounded summary containing the actor display name, amount and category so the alert can show those details when lock-screen details are enabled. It does not receive your WebKit data-store UUID, website cookies, passwords, memo text, record IDs or counterparties. Hidden-details subscriptions receive generic alert text. Apple delivers the notification through APNs.

In 3.0, connecting GitHub requires separate official GitHub App authorization. The gateway stores encrypted authorization credentials, verified GitHub identity, selected repository references and necessary event/target identifiers. Signed events are filtered for assigned Issues, direct review requests and failed or timed-out Actions. It does not synchronize the whole personal notification center or copy website login cookies. Availability is gated by deployment and verification.

Creating a private push entry sends its display name, HTTPS starting URL and random route to the gateway. Your server or script can send a message title, body and same-origin target URL. This content is encrypted at rest but must be processed to show messages; do not send passwords or secrets. Send credentials are stored in this device's Keychain; the server retains only their verification hashes. Invited websites can connect a restricted subscription after your confirmation, without obtaining your APNs token or global installation credential.

Optional Port region-assisted reminders

Location assistance is off by default and requires separate permission and verified region configuration. It can monitor at most four predefined border regions in the background. As of this update, production regions remain unconfigured pending real-world validation. Region reminders send a region code, enter/exit transition, time, configuration version and event ID, associated with the notification binding, through the gateway to Port. This reminder workflow does not upload raw coordinates or a continuous route. Without the required permission or configuration, Port uses the travel-plan time estimate. You can turn assistance off in Inbox → Notification Sources → Port → account/workspace → Location Assistance.

Port removes online semantic region-event records older than 24 hours during scheduled maintenance, not necessarily at the exact 24-hour boundary. Daily operation normally means cleanup within the next maintenance run; outages can delay it. Backups have the separate retention described below. This is not a promise that every copy disappears within 24 hours.

Port developer foreground location sampling

Only an authenticated Port developer account can use this voluntary workflow. After reading the collection notice and consenting, each explicit capture requests one foreground location fix. Port receives WGS84 latitude and longitude, accuracy, observation and receipt times, travel direction, selected border stage, journey/sample identifiers and the current account association. These points help compare visits across days and prepare region definitions for human review. They are not automatically turned into active geofences, traffic corrections, training labels or notification events, and are not sent to the notification gateway by this workflow.

The collector does not continuously watch location or run background sampling, and does not persist raw coordinates in browser LocalStorage or IndexedDB. You can view, export, replace or delete your own samples. Private responses use no-store. Deleting or replacing a point removes its previous raw coordinates from active records; limited operation audit metadata may remain until cleanup. Online samples and their sampling audit records are eligible for deletion 30 days after the original server receipt time and are removed by scheduled maintenance; retries do not restart that period.

Port maintenance creates a recovery backup before cleanup. Its rotating maintenance backups retain the newest 14 snapshots and up to eight older Sunday snapshots. Backup copies may therefore outlast online records; their expiry depends on successful maintenance and rotation. Separately retained deployment or incident backups are not covered by that automatic rotation and require operational removal. Contact us about removal from retained copies. Collection is for Port functionality, not advertising or cross-app tracking.

Notification retention and removal

3.0 stores necessary encrypted message content and routing/delivery records in a cloud inbox for 30 days from creation and keeps a bounded device cache. Earlier device-only history may be incomplete and is not reconstructed. Clearing notification history or deleting messages hides them from the inbox without clearing website data; deletion markers prevent reappearance during retries, and retained records expire under the retention period. Removing a source can also remove its history. Pairing tickets expire after 180 seconds; GitHub authorization sessions after 15 minutes.

Disconnecting or deleting a workspace disables its local route and queues server revocation if offline. GitHub credentials are removed from the active connector; encrypted credentials may be retained only to retry revocation while GitHub is unavailable. Installation credentials and inactive references may remain for authentication and stale-route protection. Contact us for server-side removal, or revoke the App directly in GitHub settings. Notifications are device-bound; losing the device credential requires reconnecting, not automatic cross-device recovery. Apple accepting a push does not guarantee that iOS displays it. Notification data is not used for advertising, analytics or tracking; message-open state is not sent back to websites by default.

Stored on your device

The app stores workspace metadata (URL, title, UUID, dates and icon filenames) in Application Support. Custom and downloaded icons are stored as local PNG files. Each workspace uses a named WebKit data store that may contain cookies, LocalStorage, IndexedDB and other data created by the website you open.

Network requests

Websites receive the network requests made by their pages and may process cookies, account information and analytics under their own policies. WebHarbor may request a website title and favicon after a successful load. Favicon requests use an isolated session and do not copy your website cookies.

Payments

Permanent Unlock purchases are processed by Apple through StoreKit. WebHarbor does not receive or store your payment details. Purchase entitlement is read from verified Apple transactions and is not written to app metadata, UserDefaults or Keychain.

Deletion

Delete a workspace in the app to remove its metadata, icons and named WebKit data store. Clear Website Data keeps the workspace itself but removes its website data. Removing the app also follows iOS storage rules.

Contact

Questions: henrylidoyle@gmail.com.

简体中文

WebHarbor 是一款本地优先、没有广告和广告追踪的 iPhone App。3.0 新增可选通知网关,通知处理适用于服务可用且主动连接工作区的用户。Port 另有下述独立、自愿的开发者位置采集流程。早期版本可能不包含这些功能,可用性取决于部署与设备验证完成。

3.0 可选通知

您主动开启后,notify.lihenry.com 会处理加密的 Apple 推送设备令牌、安装凭据哈希、随机通知路由标识、语言偏好及网站用户/家庭引用,用于发送提醒。对于合账工作区,网关还可能接收加密且有长度限制的摘要(记账人显示名、金额和分类),在允许锁屏详情时显示在提醒中。网关不接收 WebKit 数据仓 UUID、网页登录 Cookie、密码、备注、记录 ID 或其他成员信息;隐藏锁屏详情时只发送通用文案。通知由 Apple APNs 投递。

3.0 的 GitHub 连接需要单独通过官方 GitHub App 授权。网关保存加密授权凭据、验证后的 GitHub 身份、所选仓库引用及必要的事件和目标标识,按签名事件筛选任务分配、直接评审请求和失败或超时的 Actions。它不完整同步个人通知中心,也不复制网页登录 Cookie。功能仅在部署和验证完成后开放。

创建私有推送入口时,入口名称、HTTPS 起始网址及随机路由会提交到网关。您的服务器或脚本可发送标题、正文和同源目标网址;这些内容加密保存,但展示消息时需要处理,请勿发送密码或密钥。发送凭据保存在本机 Keychain,服务器只保留校验摘要。邀请网站经您确认后取得受限订阅标识,不会取得 APNs 令牌或全局安装凭据。

Port 可选区域辅助提醒

位置辅助默认关闭,需要单独授权及经过核实的区域配置,可在后台监测最多四个预设口岸区域。截至本次更新,生产区域仍未配置,等待真实场景验证。区域提醒经网关向 Port 发送区域代码、进入/离开状态、时间、配置版本和事件编号,并关联对应通知绑定;此提醒流程不上传原始坐标或连续轨迹。权限或配置不可用时,Port 使用通行方案时间估算。您可在“收件箱 → 通知来源 → Port → 账户/工作区 → 位置辅助提醒”关闭此功能。

Port 在定时维护时清理超过 24 小时的在线语义区域事件,而不是保证在第 24 小时即时删除。正常每日运行时会在下一次维护清理,故障可能造成延迟。备份适用下述独立保留规则,不承诺所有副本严格在 24 小时内消失。

Port 开发者前台位置采集

此自愿流程仅供已登录的 Port 开发者账户使用。阅读采集告知并同意后,每次明确点击采集只请求一次前台定位。Port 接收 WGS84 经纬度、定位精度、观测和接收时间、通行方向、所选口岸节点、行程/样本编号及当前账户关联,用于比较多日通行位置并形成待人工核验的区域定义。样本不会自动变为正式围栏、拥堵纠偏、训练标签或通知事件,此流程也不会向通知网关发送原始坐标。

采集器不持续监听位置、不进行后台采样,也不将原始坐标持久保存在浏览器 LocalStorage 或 IndexedDB。您可查看、导出、替换或删除自己的样本;私有响应设置 no-store。删除或替换点位会从活动记录移除原始坐标,有限的操作审计信息可能保留到清理时。在线样本及采集审计在首次服务器接收时间满 30 天后,由定时维护删除;重试不会延长此期限。

Port 维护先创建恢复备份,再清理在线数据。维护备份轮换保留最新 14 份及最多八份更早的周日备份,因此备份中的副本可能比在线记录保留更久,清除依赖维护及轮换成功执行。单独保留的发布或事故备份不受此自动轮换约束,需要运维另行删除;如需处理保留副本,请联系我们。采集用于 Port 功能,不用于广告或跨 App 追踪。

通知保留与删除

3.0 云端收件箱保存必要的加密消息内容、路由和投递记录,自创建起保留 30 天,本机保留有限缓存。早期版本的本机历史可能不完整,不会虚构恢复。清除通知历史或删除消息会将其从收件箱隐藏,不清除网页数据;删除标记防止同步重试时重新出现,保留记录按期限清理。删除来源时可以一并删除历史。配对票据 180 秒过期,GitHub 授权会话 15 分钟过期。

关闭提醒或删除工作区会停用本地路由,离线时排队撤销服务器订阅。GitHub 凭据从活动连接删除;平台暂不可用时,加密凭据可仅为重试撤销而保留。安装凭据及停用引用可能保留以验证身份和防止旧路由复用。可联系我们请求服务器删除,也可在 GitHub 设置撤销 App。通知仅绑定当前设备,设备凭据丢失需重新连接,不自动跨设备恢复。Apple 接受推送不代表 iOS 必然展示。通知数据不用于广告、分析或跟踪,消息打开状态默认不回传给网站。

保存在设备上的内容

App 将工作区元数据(网址、标题、UUID、日期和图标文件名)保存在 Application Support。自定义图标和下载的图标以本地 PNG 文件保存。每个工作区使用具名 WebKit 数据仓,其中可能包含您打开的网站创建的 Cookie、LocalStorage、IndexedDB 和其他数据。

网络请求

网页会接收其页面发出的网络请求,并可能依据自身政策处理 Cookie、账户信息和分析数据。页面成功加载后,WebHarbor 可能读取网站标题并请求 favicon。favicon 请求使用隔离会话,不会复制网站 Cookie。

支付

永久解锁由 Apple 通过 StoreKit 处理。WebHarbor 不接收或保存支付信息。购买权益只依据经过验证的 Apple 交易读取,不写入 App 元数据、UserDefaults 或 Keychain。

删除

在 App 中删除工作区会移除元数据、图标和具名 WebKit 数据仓。“清除网站数据”会保留工作区,但删除其网站数据。移除 App 还会遵循 iOS 的存储规则。

联系方式

问题请联系:henrylidoyle@gmail.com。