YOUR DATA, YOUR SERVER

Privacy.

HiBoss connects to a server you choose. This policy explains what the iOS app handles and where that information goes.

HiBoss iOS app · Published by Ming Sun · Last updated September 23, 2026

How HiBoss connects

The app has no default hosted account. You enter a HiBoss server URL and Boss Token, or pair with a code from the Mac client. The app sends authentication requests to that server. It stores the server URL in device settings and the connection token in the iOS Keychain. Pairing can also create a signing key in the device's Secure Enclave.

The server you choose may be operated by you or someone else. Its operator controls the storage, access, retention, and deletion of data sent to it. Installing the app alone does not send your messages to the app developer.

Information sent to your server

To show and act on your work, the app exchanges messages, replies, decisions, session content, progress posts, preferences, and related media with your selected server. Connecting or pairing can send a device label and a connection or device token. These are used to authenticate and identify the client to that server.

If you allow notifications, the app sends an Apple Push Notification service (APNs) device token to the selected server so it can address notifications to this installation.

Notifications and camera

Notifications pass through Apple APNs. Depending on the server's settings, a notification may include message text. The private notification option uses a generic alert and retrieves the message from your server after you open the app. Notification delivery also depends on the server being configured for this app's Apple signing team.

The camera is used to scan a pairing code. The iOS app processes the code on your device and does not upload camera video for the scan.

Analytics and tracking

The current iOS app contains no advertising or third-party analytics SDK. It does not use app data for cross-app advertising tracking. A server you choose may use its own service providers; ask that server's operator about their practices.

Retention and your choices

Signing out disconnects the app and asks iOS to remove the saved connection token and signing key. If Keychain removal fails, those credentials may remain on the device. The previously entered server URL remains in device settings. Signing out or removing the app does not delete content stored on the server.

Signing out does not remove the APNs device registration from your server. To stop alerts on this device, turn off HiBoss notifications in iOS Settings. Contact the server's operator to remove its device registration or to access or delete server-side data.

You can deny or change notification and camera permissions in iOS Settings. Without camera access, you can still enter a server URL and Boss Token manually.

Questions

For questions about this iOS app or this policy, email [email protected]. For a server you do not operate, direct requests about its stored content to that server's operator.