Tanuki Vision is a personal video player. Your video library is stored and managed on your iPhone or iPad unless you choose a feature that contacts an external service. Your video files are not uploaded to Tanuki Vision servers for storage.
If you choose Sign in with Apple, Tanuki Vision connects to Tanuki Cloud to provide an optional app account. We store the app account identifier, name and email address supplied during sign-in, plus session records and a device label when supplied. When both your sign-in session and Apple’s Store proof are verified on the same installation, we associate these records for account support. This does not transfer purchases or playback allowances. Login sessions are device-specific; signing out or session expiry removes the active association. We do not receive your Apple ID password. Purchases are verified separately with Apple StoreKit; membership status is retained where needed to apply playback and subtitle limits.
Optional iCloud Sync (CloudKit) can keep source-connection settings, folder or file selections, appearance preferences, and video playback progress aligned across your devices. Media files are not included in that sync. Source credentials, including supported cloud tokens and network-share credentials, can be synchronized using encrypted fields in your private CloudKit database; they are stored locally in Keychain and are not sent to Tanuki Cloud. iCloud Sync is not limited to members.
To apply the free weekly playback-time allowance consistently after reinstall and across your devices, the app sends Apple’s signed AppTransaction proof to our first-party server. Apple provides an app-scoped transaction identifier for the Apple Account using the app. Our server verifies Apple’s signature and stores only a keyed, pseudonymous hash of that identifier—not the raw identifier. When available, an active membership transaction is also verified and must belong to the same AppTransaction. A device-local installation counter identifies reinstallations without hardware tracking. If free playback was denied and the same device is then reinstalled, free playback requires Membership until a verified purchase or an administrator clears the restriction. First installation and use on a new device do not trigger this restriction.
For free playback, we store short playback leases, seconds used or reserved in the current UTC week, the number of distinct active playback weeks, allowance configuration, and a link to the app’s random install identifier for support and administration. We do not receive video titles, file paths, viewing positions, media content, or Apple Account contact details through this process. Playback allowance ledgers and inactive links are retained for up to 90 days. A verified active StoreKit membership provides unlimited playback time; offline access follows the server verification policy.
App activity reports use a verified, pseudonymous App Store account key and a random installation identifier. Reports contain activity timestamps, app version, distribution environment, device display name and type, upload country observed by Cloudflare, and video counts by source type (local files, iCloud Drive, SMB, NFS, FTP, WebDAV and OneDrive). They do not contain video titles, file paths, source addresses or credentials. Reports are retained for up to 90 days and support product statistics and support; you may request deletion by email. Older retired activity endpoints discard their payloads. Review-prompt history and playback error diagnostics stay on your device. No standalone third-party analytics SDK is included. Cloudflare processes network requests and retains service request/error logs for operation and security; those logs may include metadata search text. Playback, subtitle and handoff business records are separate.
Version checks send platform, Apple storefront, OS version and device family to Tanuki Cloud to find a compatible published Apple release. Playback verification stores the last offline-access decision and a persistent per-account revision to prevent older responses from restoring expired access. Under strict verification, monthly and yearly members can play offline through their verified expiry; lifetime members have no expiry. A successful server check is needed before new offline access is granted.
For playback support, we retain the latest verified request’s IP address, country, network ASN, Cloudflare edge location and time per installation, for up to 90 days. These are network diagnostics, not GPS location, and can be deleted with activity records. The latest verified membership product, purchase or renewal date and expiry are retained separately for account support; deleting activity does not change playback usage or purchase evidence.
Online video metadata matching is managed in Settings → Metadata. When enabled, search text derived from a video’s title, year, or file name may be sent to TMDB via our first-party proxy. Tanuki Vision may download matching posters or related artwork for the selected match. Video files and your full library are never uploaded. Metadata searches can be cached briefly by the proxy and may appear in service request logs.
When online subtitles are enabled and a suitable embedded subtitle is unavailable, Tanuki Vision may send the selected audio language, preferred device language, movie or episode identifiers, season and episode numbers, and limited matching text such as a title, year, or file name to Tanuki Cloud. After verifying Apple’s signed AppTransaction, Tanuki Cloud forwards only the information needed to search SubDL and enforces per-user and shared download limits. Video contents, full paths, source URLs, and source credentials are not sent. Tanuki Cloud retains quota counters, request decisions, membership plan and selected subtitle-resource identifiers linked to the app-scoped user identity to apply limits and retrieve subtitles. Downloaded subtitle files are stored in app-managed local storage and can be removed from storage settings.
Optional cross-device playback handoff uses Tanuki Cloud to store device identifiers and display names, a media matching key, playback position/state, and recent handoff commands associated with your app-scoped Apple transaction identity. A matching key may include source or path-like information, but no video file is uploaded. You can turn this off in Playback settings. Handoff is not limited to members.
Opening a trailer loads YouTube’s embedded player in privacy-enhanced mode (youtube-nocookie.com). Loading and playing the trailer sends Google/YouTube network and device/browser information, including IP address and identifiers, and playback interactions. Google may derive an approximate location from the IP address and process player diagnostics and advertising interactions for playback, security, analytics and ad delivery. Trailers may include non-personalized ads. YouTube states that privacy-enhanced views are not used to personalize your YouTube experience or advertising outside the app. Opening YouTube or another browser uses that service’s own settings and policies. See the Google Privacy Policy and YouTube privacy-enhanced mode documentation.
OneDrive is an optional video source. Tanuki Vision browses folders and supported files for library indexing and playback, and may rename or delete items that you explicitly confirm in the app. Tanuki Vision does not create folders, upload files, or move items in this cloud account, and your media files are not uploaded to Tanuki Vision servers.
If you connect an SMB, NFS, FTP, or WebDAV share, Tanuki Vision reads media from locations you select so you can browse, index, and play videos. On network shares, you may rename or delete items after an explicit in-app confirmation. Credentials are stored in local Keychain and can be synchronized through encrypted private CloudKit records when credential sync is active; they are not sent to Tanuki Cloud.
Video and related media files remain in iCloud Drive, your connected cloud accounts, network shares, or on your device. Tanuki Vision does not upload your media library to our servers for storage. Optional iCloud Sync stores connection settings, selections, appearance, playback progress, and encrypted source credentials in your private CloudKit database.
Email jie.mei.dev@icloud.com.
Tanuki Vision(狸猫视界)是个人视频播放器。资料库在 iPhone / iPad 本地管理;视频文件不会上传到我们的服务器托管。
Tanuki Cloud:Apple 登录用于可选 App 账户,保存账户标识、登录时提供的姓名和邮箱,以及会话与设备标签。同一安装上的登录会话与 Apple 商店凭证均验证通过后,会关联这些记录用于账户支持,不转移购买或播放额度。登录会话按设备独立,退出或过期后关联不再有效。不会获取 Apple ID 密码;购买由 StoreKit 校验,并按业务需要记录会员状态。可选 iCloud Sync 同步来源设置、选取项、外观与播放进度;来源凭据可通过私人 CloudKit 数据库的加密字段同步,本地存于钥匙串,不发送至 Tanuki Cloud。不会同步媒体文件,也不要求会员。
播放时长与会员:为使免费用户的每周播放时长在重装及多设备之间保持一致,App 会将 Apple 签名的 AppTransaction 凭证发送至自有服务器。服务器校验 Apple 签名后,仅保存该 App 专属交易标识的密钥化假名散列,不保存原始标识。服务器记录短期播放租约、本周已用/预留秒数、活跃播放周数、规则版本及与随机安装标识的关联;不含片名、路径、播放位置、媒体内容或 Apple 账户联系方式。账本及不活跃关联最长保留 90 天。有效会员可无限播放;离线权限遵循服务器验证策略。
App 活跃统计:服务器通过校验后的假名 Apple 账户标识和随机安装标识,保存活跃时间、App 版本、发布环境、设备名称与类型、Cloudflare 观察到的上报国家/地区,以及本地、iCloud Drive、SMB、NFS、FTP、WebDAV、OneDrive 各来源的视频数量。记录最长保留 90 天,用于产品统计与支持,可通过邮件申请删除;不采集片名、路径、来源地址或凭据。旧遥测端点仍直接丢弃内容。评分提示和播放错误诊断保留在本机。Cloudflare 保留运行和安全所需日志,可能包含元数据搜索文本;播放额度、字幕及接力业务记录独立保存。版本检查发送平台、商店地区、系统版本和设备类型,以核验 Apple 已发布的兼容版本。离线验证保存最近决定和持久递增版本号;严格模式下月付、年付会员可离线至已验证到期日,终身会员无到期日,新的离线权限须先联网验证。
为排查播放连接问题,服务器按安装保留最近一次已验签请求的 IP、国家/地区、网络 ASN、Cloudflare 节点及时间,最长 90 天,可随活动记录删除;不采集 GPS 位置。最近一次已验证的会员商品、购买或续费时间及到期日独立保留,用于账户支持;删除活动不改变播放用量或购买凭据。
可选视频元数据:在 设置 → 元数据 中开启后,可能将标题/年份/文件名相关搜索文本经自有代理发送至 TMDB,并下载匹配海报。不会上传视频文件或完整资料库,不要求会员。
可选在线字幕:开启在线字幕且没有合适的内嵌字幕时,App 可能将当前音轨语言、设备首选语言、影视或剧集标识、季集号,以及片名、年份或文件名等有限匹配信息发送至 Tanuki Cloud。服务器校验 Apple 签名的 AppTransaction 后,仅将搜索所需信息转发至 SubDL,并执行用户级与全局下载额度。不会发送视频内容、完整路径、来源 URL 或来源凭据。下载的字幕保存在 App 管理的本地空间中,可在存储设置中清理。
字幕与接力记录:字幕服务保存额度计数、请求结果、会员状态及所选字幕资源标识。接力保存设备标识和名称、媒体匹配键、播放位置与状态及近期指令,并关联 App 专属用户标识。匹配键可能含来源或路径信息,不含视频文件。
YouTube 预告片(可选):打开预告片会加载 youtube-nocookie.com 隐私增强播放器,并向 Google/YouTube 发送 IP、设备/浏览器信息与标识、播放互动等数据;可能据 IP 推算大致位置,处理诊断及广告互动,用于播放、安全、统计和广告展示。预告片可能含非个性化广告。YouTube 表示此模式下的观看不会用于个性化 YouTube 体验或 App 外广告;跳转至 YouTube 后适用其设置。详见 Google 隐私政策。
OneDrive(可选):浏览、建库、播放,以及你确认后的重命名或删除;不创建文件夹、不上传、不移动。
网络共享(可选):SMB / NFS / FTP / WebDAV,用于读取并播放你选择的位置;网络共享上可在确认后重命名或删除。凭据保存在本地钥匙串;启用凭据同步时,可通过私人 CloudKit 加密记录同步,不发送至 Tanuki Cloud。
Tanuki Vision(狸貓視界)是個人影片播放器。資料庫在裝置本機管理;影片檔不會上傳到我們的伺服器託管。
Tanuki Cloud:Apple 登入用於可選 App 帳號,保存帳號識別碼、提供的姓名與電子郵件、工作階段和裝置標籤;同一安裝的登入工作階段與 Apple 商店憑證均驗證通過後,會關聯紀錄以提供帳號支援,不轉移購買或播放額度。工作階段按裝置獨立,登出或到期後關聯不再有效。不取得 Apple ID 密碼。StoreKit 校驗購買,並依業務需要記錄會員狀態。iCloud Sync 同步設定、選取項目、外觀及進度;來源憑證可透過私人 CloudKit 加密欄位同步,本機儲存於鑰匙圈,不送至 Tanuki Cloud,也不同步媒體檔。
播放時數:自有伺服器會校驗 Apple 簽署的 AppTransaction,僅保存 App 專屬交易識別碼的密鑰化假名雜湊,以及每週已用/預留秒數與短期租約;不含片名、路徑或媒體。最長保留 90 天。有效會員可無限播放;離線權限依伺服器驗證策略決定。
App 活躍統計:以驗證後的假名 Apple 帳號識別碼與隨機安裝識別碼,保存活躍時間、App 版本、發行環境、裝置名稱與類型、Cloudflare 觀察到的上報國家/地區,以及各來源的影片數量,最長保留 90 天,用於產品統計及支援,可透過郵件要求刪除。不收集片名、路徑、來源位址或憑證。舊端點丟棄內容;評分提示和播放錯誤診斷保留在本機。Cloudflare 保存執行與安全日誌,可能包含中繼資料搜尋文字;播放、字幕與接力業務記錄獨立保存。版本檢查傳送平台、商店地區、系統版本及裝置類型。離線驗證保存最近決定與持久遞增版本號;嚴格模式下月付及年付會員可離線至已驗證到期日,終身會員無到期日,新的離線權限須先連線驗證。
為排查播放連線問題,伺服器按安裝保留最近一次已驗證請求的 IP、國家/地區、網路 ASN、Cloudflare 節點與時間,最長 90 天,可隨活動紀錄刪除;不蒐集 GPS 位置。最近一次已驗證的會員商品、購買或續訂時間與到期日獨立保留,用於帳戶支援;刪除活動不改變播放用量或購買憑據。
可選影片中繼資料:設定 → 元數據 可將搜尋文字經代理送至 TMDB,不要求會員。不會上傳影片檔。
可選線上字幕:啟用線上字幕且沒有合適的內嵌字幕時,App 可能把目前音軌語言、裝置偏好語言、影視或劇集識別碼、季集號,以及片名、年份或檔名等有限比對資訊送至 Tanuki Cloud。伺服器驗證 Apple 簽署的 AppTransaction 後,只把搜尋所需資訊轉送至 SubDL,並套用使用者及全域下載額度。不會傳送影片內容、完整路徑、來源 URL 或憑證。下載字幕保存在 App 管理的本機空間,可由儲存空間設定清除。
字幕與接力記錄:字幕服務保存額度、請求結果、會員狀態及所選資源識別碼。接力保存裝置識別碼與名稱、媒體比對鍵、位置與播放狀態、近期指令,並關聯 App 專屬使用者識別碼。比對鍵可能含來源或路徑資訊,不含影片檔。
YouTube 預告片(可選):開啟預告片會載入 youtube-nocookie.com 隱私增強播放器,向 Google/YouTube 傳送 IP、裝置/瀏覽器資訊與識別碼、播放互動等資料。可能由 IP 推算概略位置,並處理診斷、廣告互動,用於播放、安全、統計和廣告展示;可能顯示非個人化廣告。YouTube 表示此模式的觀看不會用於個人化 YouTube 體驗或 App 外廣告。跳轉後適用 YouTube 設定。詳見 Google 隱私權政策。
OneDrive / 網路共享:雲端為重新命名或刪除;網路共享同樣可在確認後重新命名或刪除。憑證存於本機鑰匙圈,啟用同步時可透過私人 CloudKit 加密記錄同步,不送至 Tanuki Cloud。
Tanuki Vision(タヌキビジョン)は個人向け動画プレーヤーです。ライブラリは端末上で管理され、動画ファイルを当社サーバーにホストしません。
Tanuki Cloud:任意の Apple サインインでは、アカウント識別子、提供された氏名・メール、セッションと端末ラベルを保存します。同じインストールのサインインセッションと Apple の購入元証明を検証した場合、サポートのため記録を関連付けます。購入や再生枠は移行しません。セッションは端末ごとに独立し、サインアウトまたは期限切れで関連付けは無効になります。Apple ID のパスワードは取得しません。購入は StoreKit で検証し、機能に必要な会員状態を記録します。iCloud Sync は設定・選択・外観・再生位置を同期します。接続先の認証情報はローカルのキーチェーンに保存され、プライベート CloudKit の暗号化フィールドで同期できます。Tanuki Cloud には送信せず、動画本体も同期しません。
再生時間:当社サーバーは Apple 署名済み AppTransaction を検証し、アプリ固有取引 ID の鍵付き仮名ハッシュ、週ごとの使用/予約秒数、短期リースのみを保存します。タイトル、パス、メディアは含まず、最大 90 日保持します。有効な会員は再生時間が無制限です。オフライン利用にはサーバーの検証方針が適用されます。
利用状況:検証済みの仮名 Apple アカウントキーとランダムなインストール ID に関連付けて、利用日時、アプリのバージョン、配布環境、端末名・種類、Cloudflare が確認した送信元の国・地域、接続元の種類別動画数を最大 90 日保存し、製品統計とサポートに使用します。メールで削除を依頼できます。作品名、パス、接続先アドレス、認証情報は収集しません。旧エンドポイントのデータは破棄し、評価表示履歴と再生エラー診断は端末内に残ります。Cloudflare は運用・安全性のためログを保存し、メタデータ検索文字列が含まれる場合があります。再生枠・字幕・引き継ぎの記録は別管理です。更新確認ではプラットフォーム、ストア地域、OS バージョン、端末種類を送信します。オフライン検証では直近の判断と永続的なリビジョンを保存します。厳格モードでは月額・年額会員は検証済みの有効期限まで、永久会員は期限なしでオフライン再生できます。新しいオフライン権限にはオンライン検証が必要です。
再生接続の診断のため、インストールごとに直近の検証済みリクエストの IP、国・地域、ネットワーク ASN、Cloudflare 拠点と日時を最大 90 日保存し、利用記録と共に削除できます。GPS 位置は収集しません。直近の検証済み会員商品、購入・更新日時と有効期限はアカウントのサポートのため別に保持します。利用記録の削除は再生使用量や購入の証拠を変更しません。
任意の動画メタデータ:設定 → メタデータで TMDB(当社プロキシ)へ検索テキストを送る場合があります。会員限定ではなく、動画ファイルはアップロードしません。
任意のオンライン字幕:オンライン字幕が有効で適切な内蔵字幕がない場合、現在の音声言語、端末の優先言語、作品・エピソード識別子、シーズン/話数、タイトル・年・ファイル名などの限定的な照合情報を Tanuki Cloud に送信することがあります。Apple 署名済み AppTransaction の検証後、検索に必要な情報だけを SubDL に転送し、利用者別および全体のダウンロード上限を適用します。動画本体、完全なパス、配信元 URL、認証情報は送信しません。取得した字幕はアプリ管理のローカル領域に保存され、ストレージ設定から削除できます。
字幕と引き継ぎ:字幕サービスは利用枠、リクエスト結果、会員状態、選択した字幕の識別子を保存します。引き継ぎでは端末 ID・表示名、メディア照合キー、再生位置・状態、最近の操作をアプリ固有の利用者 ID に関連付けて保存します。照合キーに接続先やパス情報が含まれる場合がありますが、動画本体は送りません。
YouTube 予告編(任意):予告編を開くと youtube-nocookie.com のプライバシー強化プレーヤーを読み込み、Google/YouTube に IP、端末・ブラウザ情報と識別子、再生操作などを送信します。IP から推定した大まかな位置、診断情報、広告操作を再生・安全性・分析・広告表示に使用する場合があり、パーソナライズされていない広告が表示されることがあります。YouTube はこのモードの視聴を YouTube 体験やアプリ外広告のパーソナライズに使用しないとしています。YouTube に移動した後は同サービスの設定が適用されます。Google プライバシーポリシーをご覧ください。
OneDrive / ネットワーク共有:クラウドは名前変更/削除のみ。ネットワーク共有も確認後の名前変更/削除。認証情報はローカルのキーチェーンに保存され、同期が有効な場合はプライベート CloudKit の暗号化レコードで同期されます。Tanuki Cloud には送信しません。