Local data and security
Stored locally
Provider connection materials, certificate private keys, packages, file assets, and upload tasks are stored on your computer first. Fox Store maintains them using local SQLite and credential storage, with explicit controls for deleting connections or sensitive materials.
Sent to the license service
The license service only handles Fox Store accounts, license status, feature entitlements, device limits, activation digests, and short-lived signed leases. It does not receive Provider credentials, packages, screenshots, store metadata, or certificate private keys.
Sent to the target Provider
Publishing necessarily sends packages and related materials to Apple, Google, Huawei, or WeChat. Fox Store's precise promise is that uploads do not pass through its own relay, not that all data will remain on the device forever.
Log redaction
Logs and audits retain only public fields and digests needed for troubleshooting. Before sharing logs, still check for business names, Bundle IDs, or other context you do not want to disclose.
Least privilege
Create purpose-specific credentials for automation and grant only the permissions needed for publishing. A leaked high-privilege Key can have a far greater impact than one failed upload.
