Introduction
Welcome to VoiceExpense (Chinese name “鹦财记账”, Traditional Chinese “鸚財記帳”, the “App”). The App is developed and operated by Inner Mongolia Xuanqian Technology Co., Ltd. (registered address: Unit 25-6, Hongya New Town, Longxingchang Town, Wuyuan County, Bayannur, Inner Mongolia, China; “we” or “us”).
We understand how important your personal information is to you. The App is built around a “local-first” design: by default, your bookkeeping data is stored only on your own device; our servers do not store that data unless you actively enable cloud backup. We protect your personal information in accordance with the Personal Information Protection Law, the Cybersecurity Law, the Data Security Law and the Regulations on Network Data Security Management of the People's Republic of China, with reference to applicable national standards, and we apply reasonable security measures consistent with prevailing industry practice.
Please read this policy before using the App, especially the highlighted clauses. On first launch, the App links to the full website versions of this policy and the User Agreement; you can enter only after voluntarily tapping “Agree”, which is never preselected. Before that, the App requests no system permission and makes no business-network request except those necessary when you open a legal page. Normal website access necessarily involves network metadata such as IP address, request time, page URL, browser or WebView type, and operating system. The App does not add your account, random installation identifier or bookkeeping data to that legal-page request. See the website Privacy Policy.
If you do not agree to this policy, stop using and exit the App. Until you agree, the consent screen continues to block access to all other features, although you may still actively open the full Privacy Policy and User Agreement website pages. Apart from the network requests necessary to load those legal pages at your direction, the App collects no personal information, requests no other system permission and makes no other network transmission before you agree.
You can access the latest online versions of this policy and the User Agreement (website pages) at any time via the entry under Settings in the App: Privacy Policy www.xuanqiantech.com/legal/voiceexpense/privacy.html, User Agreement www.xuanqiantech.com/legal/voiceexpense/terms.html.
Key Points at a Glance
To help you quickly grasp the core of this policy, we summarize as follows (please read the full text for details):
- By default, your bookkeeping data lives on your device (a local SQLite database). When you actively use cloud AI parsing, we process only that parse's transcript in real time and do not write it to our business database. A selected ledger's backup file is stored in the cloud only when you actively enable cloud backup, a Premium feature enabled ledger by ledger.
- We do not collect your audio recordings, nor do we proactively upload them to our servers. Speech recognition is performed by your device's system speech service (Apple / Google / Huawei) or by the App's built-in offline recognition model; when a system speech service is used, audio may be processed by that provider under its own terms.
- Recognized text reflects transactions and spending, so we protect it as sensitive personal information. The App uploads a parse only after you have accepted this Policy, have cloud credits (on a signed-in account, or — on iOS — credits held by the signed-out purchase identity described in 1.4(6) after you buy without signing in), and initiate a parse while Cloud AI is selected on the record screen. On iOS, the App also asks for your separate consent in a dedicated dialog before your first cloud AI parse, and you can turn cloud AI parsing off at any time under Settings → AI Smart Parsing. Text is used and discarded, never written to our business database. You may select Local Parsing before a parse without affecting local bookkeeping.
- Basic local bookkeeping works without an account, and signed-out use currently includes 20 on-device smart-parsing trials; on iOS, buying and restoring Basic and Premium also require no sign-in (see 1.4(6)). A newly registered account currently receives 500 account-level local parses; a Free user receives 5 additional local parses on the first daily check-in. Basic and Premium users have unlimited local parsing, so check-in only records the day and adds no parses. A direct Basic purchase currently includes 50 one-time cloud AI parses that do not expire, while Premium receives a daily cloud allowance (see 1.4 and 1.5).
- Basic or Premium purchases are processed by the app store of your platform (the App Store on iOS). We do not collect your bank-card or payment-account information; we receive only the store-issued transaction credential needed to verify entitlements. Entitlements are account-level and can be used after signing into the same account on clients that support them; on iOS, purchases made while signed out take effect on the device immediately and are recorded under a signed-out purchase identity that contains no information directly identifying you (such as your name, email or phone number), which merges into your account once you sign in and confirm; purchases, cancellations and refunds must still be handled through the original app store (see 1.4).
- The App currently integrates no third-party analytics, crash-reporting or advertising SDKs; the App currently displays no advertising. To offer WeChat sign-in, the App integrates the WeChat Open SDK (Shenzhen Tencent Computer Systems Company Limited): it is initialized only after you accept this Policy and only when you actively choose WeChat sign-in; we store only the WeChat-assigned user identifier openid (a unionid WeChat may return with the authorization result is not stored) and do not obtain or store your WeChat profile picture or nickname (see 1.3 and Section 3).
- You may view, correct, delete and export your data in the App at any time, and may initiate account deletion in-app with one action; we respond to rights requests within 15 business days.
Table of Contents
- 1. How We Collect and Use Your Personal Information (Scenario by Scenario)
- 2. System Permissions We Request
- 3. How We Share and Entrust Processing of Your Personal Information (Third-Party List)
- 4. Where Your Information Is Stored and for How Long
- 5. How We Protect Your Personal Information and Handle Security Incidents
- 6. Your Rights
- 7. Account Deletion
- 8. Protection of Minors
- 9. Updates to This Policy and Delivery of Notices
- 10. Liability and Your Obligations (Please Read Carefully)
- 11. Dispute Resolution and Governing Law (Please Read Carefully)
- 12. How to Contact Us
1. How We Collect and Use Your Personal Information (Scenario by Scenario)
We follow the principle of minimum necessity: we collect and use your information only in the scenarios below and only to the extent necessary for the corresponding feature. The App's basic features are local manual/voice bookkeeping, which require no personal information and no account.
1.1 Voice Bookkeeping (Core Feature)
(1) Audio is captured on your device; speech-to-text is performed by your device's system speech recognition service or the App's built-in offline model. We do not collect your audio recordings, nor do we proactively upload them to our servers. Specifically:
- when you tap the record button, we request microphone permission and capture your speech;
- speech-to-text uses either ① a system service (Apple on iOS; a signature-verified Google speech service on Android — other vendors' engines are not used, and the built-in offline model is used instead when no usable Google speech service is present; Huawei as a HarmonyOS fallback) or ② the built-in sherpa-onnx offline model (used on Android when no usable Google speech service is present or when offline, and preferred on HarmonyOS; entirely on-device);
- please note: when a system speech service is used, depending on language and device, your audio may be processed by servers of Apple, Google or Huawei under their respective privacy policies. We make no commitments regarding those system services; see the third-party list in Section 3. We do not collect or store your original recordings, and we do not extract any voiceprint features.
(2) The recognized text (the “speech transcript”) and the records generated from it (amount, item, category, date, currency, etc.) are saved by default in the local database on your device. Please be aware that the speech transcript is part of your bookkeeping data: it is included in your locally saved records, backup files you actively export, and cloud-backup data you actively enable. When you actively use cloud AI parsing, that transcript is also uploaded and processed in real time as described in Section 1.2. iCloud sync is currently disabled.
(3) Local smart parsing: by default, converting speech text into a record is done by the App's built-in local rule engine on your device, with no network transmission whatsoever.
1.2 Cloud AI Parsing (Optional Online Feature; Involves Sensitive Personal Information — Please Read Carefully)
The speech transcript and the records generated from it substantively reflect your transactions and spending and constitute sensitive personal information. We protect them to the standard applicable to sensitive personal information, and we hereby explain the specific purpose and necessity of processing and the impact on your interests: the purpose is to convert your natural language into more accurate record suggestions; the necessity lies in the fact that large-model parsing must be performed server-side; the potential impact on your interests is that the text is briefly relayed through our servers to an entrusted large-model service for processing (see below and Section 3 for handling and safeguards). This handling is prominently disclosed through the general privacy-consent screen before you first enter the App; on iOS, a separate dialog shown before your first cloud parse also names the entrusted provider, the data sent and how to turn it off, and asks for your separate consent. The transmission occurs only after you accept this Policy (and, on iOS, give that separate consent) and use Cloud AI parsing.
Cloud AI is used only where actually available in the client and while you have accepted the current Policy (and, on iOS, have given and not withdrawn separate consent to cloud AI parsing); are signed in or — on iOS only — have a signed-out purchase identity created after a signed-out purchase (see 1.4(6)); have credits or an active Premium entitlement; and initiate a parse with Cloud AI selected on the record screen. You may select Local Parsing before a parse; no upload occurs if you have neither an account session nor a signed-out purchase identity, if (on iOS) separate consent has not been given or has been withdrawn, or if Local Parsing is selected, credits are exhausted or you are offline. If the purpose, method, information type or processor materially changes, we will update this Policy and provide any further notice or obtain consent required by law. The configured processor is Volcano Engine “Doubao”; availability is as displayed by your client and service configuration.
When cloud parsing is used, we send the following over an encrypted channel (HTTPS) to our server (api.xuanqiantech.com, deployed on Tencent Cloud within the People's Republic of China):
| Data item | Description | Required? |
| Speech transcript (text; sensitive personal information) | Parsed by the large model into record suggestions | Required for this feature |
| Your custom category codes, names, types and keywords | So results match your personal categories | Required for this feature |
| Device local date and current time (e.g., “2026-07-06 12:30”) | The current time gives the model time-of-day context when you do not state it (for example which meal); the local date is used only to meter your daily parsing credits and is not sent to the large model. Relative date words such as “yesterday” or “the day before yesterday” are recognized by the App on your device and stripped from the uploaded text; the cloud does not infer the record date | Required for this feature |
| Voice-language setting | To select the parsing language | Required for this feature |
| Account login token (on iOS, when you bought without signing in, the session token of the signed-out purchase identity) | Identity and credit verification | Required for this feature |
| Premium subscription credential (when included in the request; see 1.4) | Immediate verification of Premium entitlement and sync to the account | Required when immediate verification is needed |
In this process we do not collect your transaction history, account balances, location, or any device hardware identifier.
Upon receiving the text, our server relays it in real time to Volcano Engine's “Doubao” large language model (an entrusted processor, see Section 3) for parsing, and returns the result for your confirmation. Parsed text is used and discarded: we never write your speech transcript to our business database and never intentionally record it in logging systems. If temporary technical records arise from troubleshooting, we delete them promptly once troubleshooting is complete.
Each cloud parse creates an audit record with no transcript or bookkeeping content: internal user ID, Premium status, success/failure and creation time. It is automatically deleted 90 days after creation. Any processing the entrusted processor must perform under law is described in Section 3.
On iOS, the App may access Apple's captive.apple.com to test connectivity. The App adds no account, installation identifier or bookkeeping data, although Apple necessarily receives network metadata such as IP address and request time.
If a cloud-parsing request fails (including network unavailability or exhausted credits), the App automatically falls back to local parsing and bookkeeping is unaffected. AI parsing results are suggestions only and may contain errors; please verify before saving.
1.3 Account Registration and Sign-In (Optional)
You do not need an account for local bookkeeping. If you choose to sign in, the account is used to receive and sync parsing credits, check in, bind sign-in identities, sync Basic/Premium entitlements and use cloud backup. Where the relevant client and service configuration actually support it, signing in to the same Account lets you use entitlements the server has already verified for that Account; the actual scope is as displayed by each client.
(1) Sign in with Apple (iOS): we receive your identityToken through Apple's “Sign in with Apple” service and, after verification, store the user identifier assigned by Apple. The identity token may contain your email address (or an Apple-generated relay address). Our server uses the token only to authenticate and does not extract or store the email contained in it; the App decodes that email only locally on your device, to show a masked account identifier on the account page and, when Apple returns no name and no nickname is stored, to derive an on-device nickname from the part before “@” (relay addresses are not used for this). That email is kept in the device Keychain and is not uploaded to our servers. Name information returned by Apple is used only to generate an on-device nickname and is not uploaded to our servers.
(2) Sign in with Google (Android international edition): Google sign-in is offered only in the international edition of the Android app, and is shown only when Google Mobile Services are available on your device (it cannot be used unless the service configuration is enabled); it is not offered in the Android edition for app stores in mainland China, on iOS or on HarmonyOS. When you choose to sign in with Google, link a Google account on the account page, or verify your identity with Google before a sensitive action such as account deletion, the App uses Android’s Credential Manager to open Google’s account picker; after you pick an account, Google returns an ID token to the App, and our server, after verifying it, stores the user identifier assigned by Google. The ID token and the account information returned with it may contain profile information such as your Google account’s email address, name and profile-picture link. Our server uses the token only to authenticate; it does not extract or store that email, name, profile-picture link or other profile information, and does not write the token to the database or to logs. Only when you sign in with Google does the App read, locally on your device, the account email and display name returned by Google, to show a masked account identifier on the account page and to derive an on-device nickname from the display name (or, if there is none, from the part of the email before “@”). Both are kept in the App’s private on-device storage, which is excluded from system backup, and are not uploaded to our servers. The App does not read or use the profile-picture link. Unless you take one of these actions, the App does not open Google’s account picker and we obtain no ID token. In addition, where the service is actually enabled in the target environment, the website account-deletion request page (see Section 7(1)) offers “Verify with Google” as a self-service option: the page then loads Google's sign-in component from Google when it opens, so Google receives your browser's network request information (such as IP address and browser type) under its privacy policy; Google returns an ID token to that web page only when you choose this option there, and our server, after verifying it, uses only the Google user identifier in it to find and delete the corresponding account, without extracting or storing the email, name, profile-picture link or other profile information in it. Google handles the account picker and token issuance under its own privacy policy; see Section 3.
(3) Email verification-code sign-in and binding: when you sign in or register with email, or bind an email address to an existing account, we collect the address, trim surrounding whitespace and convert it to lowercase to send a code, verify ownership and identify your account. After verification, the normalized email address is retained as a sign-in identity until account deletion. If the address already belongs to another account, after you confirm binding the related account data may be merged into the current account.
The code is a one-time 6-digit number valid for 30 minutes. The temporary code table stores only keyed one-way HMAC values of the email and code, not either value in plaintext. Successful verification invalidates the code so it cannot be reused; five consecutive incorrect attempts also invalidate it, and sending a replacement overwrites the previous code. Invalid records are automatically deleted within 7 days. To deter abusive sending, the same address cannot request another code within 60 seconds and may request at most 10 per day. We entrust Tencent Cloud Simple Email Service (SES) to deliver the message, providing it with the recipient address, code and selected language template; see Section 3.
(4) Random app-installation identifier: to limit the number of devices signed into one account, protect account security and deter abuse, the App generates a random UUID unrelated to device hardware on first launch and uploads it with sign-in requests (on iOS, also with requests that create or restore the signed-out purchase identity; see 1.4(6)). On iOS it is stored in this App's UserDefaults; on Android it is stored in app-private SharedPreferences and excluded from system backup and device transfer; on HarmonyOS it is stored in app-private Preferences and likewise excluded from system backup and device transfer. A normal uninstall/reinstall generates a new UUID on all three platforms. It is not IDFA, IMEI, Android ID, OAID or any other system device identifier and cannot associate your activity across other apps.
(5) For your account, the server stores: an internal account ID; bound sign-in identities (such as Apple, Google, Huawei or WeChat user identifiers and normalized email addresses); random app-installation identifiers and their last-use times; parsing credit counters; check-in records; and Basic/Premium entitlement records. The server does not store parsed text, but it does store the content-free cloud-parsing audit records described in Section 1.2. What the server stores for the signed-out purchase identity on iOS is described in 1.4(6).
(6) Besides Apple and email, Google, Huawei, WeChat and other platform sign-in methods are available only where displayed by the relevant client and enabled by service configuration. We obtain no identity token from a platform unless you actively choose its sign-in method. Actual availability is what the client you use displays.
(7) WeChat sign-in (optional): when you choose WeChat sign-in, the App uses the WeChat Open SDK (provider: Shenzhen Tencent Computer Systems Company Limited) to open the WeChat app, where you confirm the authorization. On success WeChat returns a one-time authorization code, which our server exchanges with WeChat for the user identifiers assigned by WeChat, storing only the openid (a unionid that WeChat may include in the response passes through only while that sign-in is processed and is neither stored nor logged). We do not call WeChat’s user-profile interface and do not obtain or store your WeChat profile picture, nickname, gender or region. WeChat has also stopped returning gender and region through this authorization interface since 20 October 2021. The authorization code is single-use and valid for 10 minutes; it is passed only in memory and is never written to disk or to logs.
So the interface can correctly indicate availability, the App makes a single targeted query for “whether WeChat is installed on this device” (declared via LSApplicationQueriesSchemes on iOS, a <queries> declaration for com.tencent.mm on Android, and querySchemes on HarmonyOS). That query answers only this one yes/no question; it does not read or upload your list of installed apps. The App does not request Android’s QUERY_ALL_PACKAGES permission.
The WeChat Open SDK is initialized only after you accept this Policy — this is both Tencent’s requirement in its WeChat Open SDK compliance guide and how this App is implemented. The personal information it processes, the permissions it needs, the purpose and Tencent’s privacy policy link are listed in Section 3.
1.4 Basic and Premium Purchases and Entitlement Verification (Optional)
(1) Basic is a one-time purchase and Premium is an auto-renewing subscription. Where a client offers purchases, they are completed through the app store of your platform (the App Store on iOS). Payment is handled by the relevant app store; we do not collect or access your card number, payment-account password or other payment information.
(2) To verify your entitlement, the App sends our server the store-issued transaction credential (for example, an iOS StoreKit transaction JWS containing product ID, original transaction ID, expiry time and related data, but no bank-card information). We retain the verification result, including platform, product, transaction identifier, validity period and revocation status, and bind it to the account at purchase: the account you are signed into or, on iOS when you buy without signing in, the signed-out purchase identity described in 1.4(6). To do this, when you start a purchase the App passes the app store a random purchase-account identifier that we generate and that contains no information directly identifying you, such as your name, email or phone number (on iOS, the random UUID of the account or signed-out purchase identity, known as appAccountToken; on the Android international edition, a one-way hash of that UUID, known as obfuscatedAccountId; on HarmonyOS, once Huawei in-app purchase is actually offered, the account's random UUID). The store returns it unchanged in transaction credentials or subscription notifications, so we can attribute transactions, renewals and refunds to the correct account. A verified entitlement can sync across clients that support it under the same account; however, purchase restoration, cancellation and refunds remain with the original app store and must follow that store's procedures.
(3) Current parsing entitlements are: a Free user receives 500 local parses on first account registration and 5 more local parses on the first daily check-in; a Basic user has unlimited local parsing and a direct Basic purchase includes 50 one-time cloud AI parses; a Premium user has unlimited local parsing and currently 30 cloud AI parses per day. The 50 Basic parses are a one-time balance that does not reset daily or expire; unused Premium daily allowance does not roll over. If an account has both the Premium daily allowance and a one-time cloud balance, the daily Premium allowance is used first, followed by the one-time balance. Basic entitlement bundled with an annual Premium subscription does not grant another 50 cloud parses. Actual entitlements are as shown on the purchase page and confirmed by account verification.
(4) Entitlement status is cached on your device for offline decisions; when online, app-store and server verification prevails.
(5) Please note in particular: Premium is an auto-renewing subscription and will be charged for renewal before the subscription period ends under the applicable store rules. Prices, subscription periods, renewal and cancellation rules are those shown on the purchase page and imposed by the applicable store. You may cancel auto-renewal at any time through the original purchase channel: for App Store purchases, on your iPhone go to system Settings → your Apple Account → Subscriptions; for purchases through another channel, cancel on the subscription management page of the app store you purchased from, or, where the App provides a “Manage subscription” entry on the account page for that platform, start there. Refund requests are also handled by the original app store; we do not directly process store refunds.
(6) Signed-out purchase identity (iOS only): so that you can buy, restore and use what you bought (including cloud AI parsing credits) without signing in, when — after you have accepted this Policy — you first start a purchase while signed out (or when restoring purchases requires the server to verify purchases made on this device while signed out), the App:
① generates a 256-bit random secret on your device, stores it in the system Keychain and syncs it through iCloud Keychain to your devices signed in to the same Apple Account with iCloud Keychain turned on (whether it syncs depends on your system settings; Apple encrypts and syncs this data under its iCloud Keychain mechanism and we cannot read it). After you confirm linking or deleting the identity, the App also records in the same iCloud Keychain the identity's random account ID and what became of it (for a linked identity, together with the internal account ID of the account it was merged into), so that your other devices can tell which account the related purchases belong to;
② sends that secret, together with the random app-installation identifier in 1.3(4), to our server over HTTPS. The server derives a random account ID from the secret one-way and creates (or restores) a purchase identity that contains no sign-in identity and no information directly identifying you, such as your name, email or phone number, and issues a session kept only on the device. The server does not store the secret itself, and does not write the secret, the random account ID or the installation identifier to operational logs. Afterwards, on any device that holds the secret (including other devices it reached through iCloud Keychain, whether or not that device is signed in to an account), the App also restores the identity's session in the same way when it launches or refreshes purchase status, uploading that device's random installation identifier. This purchase identity receives no 500-parse new-account grant, cannot check in and cannot use cloud backup;
③ passes that random account ID to the App Store as the purchase-account identifier described in (2) when you buy.
For the signed-out purchase identity the server stores: the random account ID; random app-installation identifiers and their last-use times; sessions; cloud-parsing credit counters; Basic/Premium entitlement and transaction-verification records; and the content-free cloud-parsing audit records described in 1.2. One identity can hold sessions on at most 10 devices at the same time.
After you sign in, if this device has purchases made while signed out, the App asks whether to link them to the current account; only after you confirm does the server merge that identity's credits and entitlements into your account (this cannot be undone) and keep its random account ID with your account as a purchase-account anchor (see Sections 4 and 7), also keeping a keyed one-way verification value of that random account ID, used only to prevent the same secret from re-creating the merged identity; the App then deletes the secret from the device and from iCloud Keychain. If you choose Not Now, features keep working on the device and you can link later from the membership page.
While signed out, you can delete this identity at any time under Me → Purchase Data Without Sign-in in the App (see Section 6(3) and Section 7(6)); that entry is not shown while you are signed in, so sign out first to delete it, or link it to your account as described above. If the secret is lost — for example because you turned off iCloud Keychain or erased the device — features on the device can still be recovered through the App Store's Restore Purchases, but cloud benefits held by that identity (such as remaining cloud parses) may no longer be usable; you then also cannot delete the identity yourself in the App, and can ask us to delete it by contacting us under Section 12 (to verify your link to the identity, we may ask for information such as the order number of an App Store purchase made under it).
1.5 Daily Check-In (Optional)
After signing in, you may check in daily. Under the current rules, a Free user's first check-in each day adds 5 local parses; Basic and Premium already include unlimited local parsing, so check-in for those tiers records the day only and grants no additional parses. We store your account's check-in date on the server; streaks and other check-in statistics are calculated by the App from on-device data.
1.5-A Exchange-Rate Refresh (Optional Online Feature)
When you use multi-currency bookkeeping and the device is signed in or (iOS only) holds a signed-out purchase identity (see 1.4(6)), the App may request daily rates from our server. It sends the account login token or that purchase identity's session token for authentication and rate limiting and generates ordinary network logs such as IP address and request time. No records, amounts, balances, ledger names or custom categories are uploaded. Our server does not pass your token, internal user ID or bookkeeping data to the public rate source. Rates are for bookkeeping conversion only.
1.6 Cloud Backup (Optional Premium Feature; Involves Sensitive Personal Information — Please Read Carefully)
Premium users can back up ledger data to the cloud. This feature is optional and off by default: only ledgers you select or actively back up are uploaded; unselected ledgers are never uploaded. Before you first use cloud backup—by first tapping “Back Up Now” or first enabling automatic backup for a ledger—we obtain your separate consent through a standalone, non-preselected pop-up. No bookkeeping data is uploaded before you consent and actively enable the feature.
A complete backup includes transaction details, ledger name, budgets, savings goals, custom categories, speech transcripts, and multi-currency fields such as transaction currency, base currency, exchange rate and converted base amount. It is stored in Tencent Cloud Object Storage in China. Transmission uses HTTPS, and our server requires server-side encryption at rest when the backup is written to object storage. Cloud backup is not end-to-end encrypted. Authorized staff may access content only to the minimum extent necessary for security troubleshooting, disaster recovery, your request or legal obligations; we do not use it for advertising, profiling, model training or product-algorithm improvement.
For uploads, the App first obtains a short-lived, single-use upload ticket and then uploads the backup file through our fixed HTTPS endpoint (api.xuanqiantech.com); our business server receives the complete backup in memory, verifies its file size and SHA-256 digest, and, once verified, writes it to Tencent Cloud Object Storage itself. The server therefore processes the complete backup content transiently for the time necessary to complete that upload, but does not write the uploaded content to the business database. For retrieval downloads, the App first obtains a short-lived, single-use download ticket and then downloads through our fixed HTTPS endpoint. Our business server reads the complete backup from object storage, verifies its size and SHA-256 digest in memory, forwards it to the App, and marks the response as non-cacheable. The server therefore processes the complete backup content transiently for the time necessary to complete that retrieval, but does not write the downloaded content to the business database. For authorization, list display, version management and integrity checks, our business server stores metadata: ledger identifier (ledgerId), ledger name (ledgerName), version number (version), file size (size), SHA-256 digest (sha256) and backup-device label (deviceLabel). This metadata contains no transaction details and is retained and deleted on the same schedule as the corresponding backup.
Storage rules: each user can back up at most 10 ledgers, with at most 2 backups per ledger by default. We first retain the latest 1; if there is a version at least 7 days old that is not that one, we also retain the newest such version as a weekly anchor. If no separate weekly anchor exists, including where the anchor is already the latest one, we retain no more than the latest 2. When an auto-backup ledger changes, the App coalesces changes made within a short interval, then attempts an upload while idle, entering the background, or next launching/returning to the foreground, over Wi-Fi or another non-cellular network. Each ledger can complete at most one automatic backup per day; it does not upload once for every transaction. Manual backup remains available.
When Premium expires, uploads and auto-backup stop. After grace or billing-retry protection, backups enter a minimum 90-day retrieval period and the App shows a planned deletion date. You may view, restore, renew or delete during that period. Deletion may run only after the minimum period and final confirmation that no Premium entitlement remains. If the deletion chain is not safely enabled, external entitlement status cannot be verified, or another condition risks erroneous deletion, deletion is deferred and retrieval, renewal and voluntary deletion remain available. Renewal cancels the plan before actual deletion; once safely deleted, a backup cannot be recovered. Deferral may only delay deletion.
You may delete cloud backups by ledger or version and disable automatic backup in the App at any time. The 90-day retrieval period does not apply to account deletion; all cloud backups are then deleted under the account-deletion process in Section 7.
Apple iCloud sync/backup in the iOS edition is currently disabled, has no accessible entry point, and sends no bookkeeping data to iCloud. If enabled in future, we will first update this policy and obtain any consent required before processing your bookkeeping data.
1.7 Data Export and Import (Local Feature)
You may export your records as CSV / JSON / Excel files. We guarantee that you can always export a CSV file of your record details (containing date, type, item, category and amount) free of charge, as the baseline channel for exercising your right to data portability and retrieving and copying your own bookkeeping data. Import and export of complete JSON backups, as well as Excel report export, are available to Basic and Premium users. Export files are unencrypted plaintext files, generated on your device and handed to the system share sheet, without passing through our servers. JSON backup files contain all transaction details and speech transcripts. You are responsible for safeguarding exported files; please store them carefully and avoid sharing them with untrusted parties.
1.8 Support and Contact
When you contact us by email, we receive your email address and the information you voluntarily provide in the message, used solely to respond to your inquiry, complaint or rights request, and retained after resolution for the period stated in Section 4.
1.9 What We Do Not Do
- we do not collect your location, contacts, photo library, clipboard or camera data, and we do not request the corresponding permissions;
- we do not collect IDFA, IMEI, Android ID, OAID or any other system device identifiers;
- we do not use any of your data for advertising profiles, user profiling or automated decision-making;
- we currently integrate no third-party analytics, crash-reporting, push or advertising SDKs (the WeChat Open SDK, integrated to provide WeChat sign-in, is none of these four categories; its processing scope, permissions and status are in Section 3);
- except in the following two cases, the App does not auto-start or chain-start other apps: ① redirects you actively trigger (e.g., going to the app store to manage a subscription, opening your mail app to contact us, or opening WeChat when you choose WeChat sign-in); ② the Android edition is woken by the system after a device restart (the “boot” permission listed in Section 2) solely to reschedule the daily reminders you have enabled — no data collection or network transmission occurs in that process.
1.10 App Lock (Optional Local Security Feature)
If you enable App Lock, the App stores its enabled state, lock method, failed-attempt count and lock state locally. A PIN is represented only by a random salt and irreversible verifier, never plaintext. System biometrics or device credentials are verified by the operating system; the App receives only the result and never reads, stores or uploads facial or fingerprint templates. Email recovery uses the email and one-time-code processing in Section 1.3. Disabling App Lock clears its local verifier data.
2. System Permissions We Request
We request only the permissions below; you may decline them or turn them off in system settings at any time. Declining any permission does not affect basic features such as manual bookkeeping. Timing: microphone and speech-recognition permissions are requested when you first open the recording page and use voice bookkeeping; the notification permission is requested once after you agree to this policy and first enter the main screen (for the daily bookkeeping reminder) — you may decline and re-enable it later in system settings.
2.1 iOS
| Permission | Purpose | If declined |
| Microphone | Capture speech for voice bookkeeping | Voice bookkeeping unavailable; manual bookkeeping unaffected |
| Speech recognition | Convert your speech to text | Same as above |
| Notifications | Daily bookkeeping reminder | No reminders; other features unaffected |
| Face ID / Touch ID or device credential (only if App Lock is enabled) | On-device system verification; the App does not obtain biometric templates | Biometric unlock unavailable; use a PIN |
| Pasteboard (only when you choose WeChat sign-in and the WeChat Open SDK opens WeChat) | Tencent states it is used “to transfer data between the third-party app and WeChat”; the App itself neither reads nor writes the pasteboard | Not invoked unless you choose WeChat sign-in |
2.2 Android
| Permission | Purpose | If declined |
| Recording (RECORD_AUDIO) | Capture speech for voice bookkeeping | Voice bookkeeping unavailable; manual bookkeeping unaffected |
| Notifications (POST_NOTIFICATIONS, Android 13+) | Daily bookkeeping reminder | No reminders |
| Network (INTERNET / network state; normal install-time permissions) | Cloud parsing and account features; network state is read only to auto-switch to the built-in offline speech recognition when offline | — |
| Boot (RECEIVE_BOOT_COMPLETED, normal permission) | Reschedule your daily reminders after a device restart (see 1.9 regarding auto-start) | — |
| Biometrics (USE_BIOMETRIC, normal permission) | If App Lock is enabled, invoke on-device system verification; the App never collects or uploads biometric data | Biometric unlock unavailable; use a PIN |
| Fingerprint (USE_FINGERPRINT, normal permission) | Legacy Android 8.1-and-below compatibility permission; same purpose as above | Same as above |
| Targeted query for WeChat installation (<queries> declaration for com.tencent.mm; not a runtime permission) | Determines whether WeChat is installed so the WeChat sign-in entry can be enabled; answers yes/no only and does not read the app list; QUERY_ALL_PACKAGES is not requested | — |
The Android edition requests no storage read/write permissions; import and export use the system file picker.
2.3 HarmonyOS
| Permission | Purpose | If declined |
| Network (ohos.permission.INTERNET; normal permission) | Connect when you actively sign in, use cloud AI parsing, verify account entitlements, manually back up, or run an automatic backup you enabled | — |
| Microphone (while in use) | Voice bookkeeping | Voice bookkeeping unavailable; manual bookkeeping unaffected |
| Agent reminders | Daily bookkeeping reminder | No reminders |
| Vibration | Haptic feedback | No haptic feedback |
| Biometrics (ohos.permission.ACCESS_BIOMETRIC; only if App Lock is enabled) | On-device system verification; the App receives only the result | Biometric unlock unavailable; use a PIN |
| Targeted query for WeChat installation (querySchemes in module.json5; not a runtime permission) | Determines whether WeChat is installed so the WeChat sign-in entry can be enabled; answers yes/no only and does not read the app list | — |
3. How We Share and Entrust Processing of Your Personal Information (Third-Party List)
We do not sell your personal information. Your information is processed by third parties only in the circumstances below. The App currently integrates no third-party analytics, crash, push or advertising SDKs (the WeChat Open SDK, integrated to provide WeChat sign-in, is none of these four categories and is listed in the table below). Some platform services depend on client version, server configuration and app-store configuration; processing occurs only when the capability is actually available in your client and you trigger it. This list is kept in sync with releases and actual integrations. Through service agreements, data-processing terms and similar means, we require our entrusted processors (Volcano Engine, Tencent Cloud and Tencent Cloud SES) to provide the same or an equal level of protection for your personal information as described in this Policy; Apple, Google, Huawei and Tencent (WeChat) process the relevant information as independent handlers under their own privacy policies (linked in the table below).
| Name | Provider | Information involved | Permissions | Purpose | Status | Privacy policy |
| Volcano Engine “Doubao” LLM (entrusted processor) | Beijing Volcano Engine Technology Co., Ltd. | Speech transcript (sensitive personal information), current time, language setting, custom category codes, names, types and keywords (relayed only via our server) | None | Cloud AI parsing | Used only where actually offered and when the user triggers Cloud AI parsing | volcengine.com/docs/6348/68918 |
| Tencent Cloud infrastructure and Object Storage | Tencent Cloud Computing (Beijing) Co., Ltd. | Account, credit, entitlement, parsing-audit and cloud-backup metadata; Premium cloud-backup files you actively upload (server-side encrypted under the conditions in 1.6) | None | Server hosting, database and Premium cloud backup | In use | cloud.tencent.com/document/product/301/17345 |
| Tencent Cloud Simple Email Service (SES; entrusted processor) | Tencent Cloud Computing (Beijing) Co., Ltd. | Recipient email address, one-time code and email language template | None | Delivery of sign-in/binding verification messages | Used when email sign-in/binding is actually offered and triggered | cloud.tencent.com/document/product/301/17345 |
| Apple speech recognition | Apple Inc. (overseas recipient) | Your speech audio (processed by the system service, not via our servers) | Microphone, speech recognition | Speech-to-text | Used where actually offered and triggered on iOS | apple.com/legal/privacy |
| Sign in with Apple | Apple Inc. (overseas recipient) | Identity token, Apple user identifier | Network | Account sign-in | Used where actually offered and triggered on iOS | apple.com/legal/privacy |
| App Store in-app purchase (StoreKit) | Apple Inc. (overseas recipient) | Basic/Premium transactions handled by Apple; the App passes Apple a purchase-account identifier (a random UUID with no information directly identifying you, such as name or email; see 1.4); we receive only the transaction credential | Network | Purchase and entitlement verification | Used where actually offered and triggered on iOS | apple.com/legal/privacy |
| Apple iCloud (sync/backup) | Apple Inc. | Currently processes no bookkeeping data from this App | Network | Cloud sync/backup | Disabled; no entry point | apple.com/legal/privacy |
| iCloud Keychain (iOS signed-out purchase identity only) | Apple Inc. | The signed-out purchase identity's random secret; a list of random IDs of deleted signed-out purchase identities; and the random IDs of linked signed-out purchase identities together with the internal account ID of the account each was merged into (no information directly identifying you, such as name, email or phone number, and no bookkeeping data; encrypted and synced by Apple, unreadable by us) | Network | Syncing the signed-out purchase identity and its linked/deleted status across your devices | Used from the time you first start a purchase or restore while signed out; syncing depends on your iCloud Keychain setting | apple.com/legal/privacy |
| System speech recognition (Android) | Google LLC (overseas recipient) | Your speech audio (processed by the signature-verified Google speech service; may be uploaded to Google when online; not via our servers) | Recording, network | Speech-to-text | Used where actually offered and triggered on Android; if no usable Google speech service is present, the built-in offline model is used instead | policies.google.com/privacy |
| Built-in offline speech recognition (sherpa-onnx) | Open-source model bundled in the App | Runs entirely on-device; zero network transmission | Recording | Speech-to-text when offline or when no usable Google speech service is present | Used where actually offered on Android | — (no data leaves the device) |
| Built-in offline speech recognition (sherpa-onnx) | Open-source model bundled in the App | Runs entirely on-device; zero network transmission | Microphone | Preferred on-device speech-to-text | Used where actually offered on HarmonyOS | — (no data leaves the device) |
| Google sign-in / Google Play Billing | Google LLC (overseas recipient) | Identity token / transaction credential; at purchase the App also gives Google a one-way hash of the purchase-account identifier, which contains no information directly identifying you, such as name or email (see 1.4) | Network | Account sign-in / Basic and Premium entitlement verification | Used when configuration is enabled and the user triggers it; subject to what the Android client actually displays | policies.google.com/privacy |
| Huawei ID / Huawei IAP / Huawei system speech recognition | Huawei Technologies Co., Ltd. | Identity token / transaction credential / speech audio (system service); once Huawei in-app purchase is actually offered, the App also gives Huawei the purchase-account identifier (a random UUID with no information directly identifying you, such as name or email) at purchase (see 1.4) | Microphone, network | Account sign-in / Basic and Premium entitlement verification / speech-to-text | Used only where the corresponding capability is actually offered on HarmonyOS and triggered; unavailable capabilities process nothing | consumer.huawei.com/cn/privacy/privacy-policy/ |
| WeChat Open SDK (WeChat sign-in) | Shenzhen Tencent Computer Systems Company Limited | What we store: the WeChat-assigned identifier openid (a unionid WeChat may return with the authorization result is not stored). On the SDK side: whether WeChat is installed on the device; on iOS additionally the device model (Tencent states it is “stored locally on the device”). We do not call WeChat’s user-profile interface and obtain no profile picture, nickname, gender or region | iOS: pasteboard (invoked by the SDK when opening WeChat); Android / HarmonyOS: verify whether WeChat is installed; network | WeChat account sign-in | Used where enabled by configuration and triggered by you; the SDK is not initialized before you accept this Policy | WeChat Open SDK personal-information rules |
On entrusted processing (Volcano Engine): through applicable service agreements, data-processing terms and settings, we require the processor to use text only for the requested parse and not for model training beyond that purpose, subject to mandatory security processing under law. A material change to the provider, purpose or data categories requires renewed notice and consent where required.
On entrusted delivery (Tencent Cloud SES): we provide your email address and one-time code only to complete a sign-in or binding verification you requested, never for marketing. Our business database does not separately retain message bodies or per-message delivery details. Tencent Cloud SES console delivery statistics are currently available for approximately 30 days; any additional retention required for security, troubleshooting or legal compliance is governed by Tencent Cloud's rules. Retention of our normalized email identity and temporary code-verification records is described in Section 4.
On the WeChat Open SDK: in its WeChat Open SDK personal-information rules Tencent states that, apart from the information expressly listed there, it does not process any other personal information through the WeChat Open SDK. This App does not use WeChat Pay: on iOS it uses the SDK package Tencent provides without payment functionality, and on all three platforms the App issues no WeChat Pay request and processes no payment order identifier or payment status. On HarmonyOS we additionally disable the SDK’s built-in payment-reporting switch explicitly (that switch is on by default; once disabled the SDK reports no runtime information to Tencent). The WeChat Open SDK is initialized only after you accept this Policy, and collects and reports nothing before that. If we integrate WeChat Pay in future, we will give notice again as required by law and update this list.
On overseas services: Apple / Google system speech, sign-in, payment and connectivity services may act as independent handlers, and network metadata, audio, identity tokens or transaction information may be transferred outside China. You ordinarily trigger these system services directly and we mainly receive verification results stored in China. Where entitlement verification, security investigation or channel notices require us to call an overseas channel API, we provide only the necessary transaction or channel-account identifiers. We will meet applicable notice, separate-consent and transfer requirements and do not exclude any legal responsibility. Rights channels are listed below:
- Apple Inc. (involves: speech audio [system speech recognition], identity token and user identifier [Sign in with Apple], transaction credential and purchase-account identifier [IAP]; iCloud sync is disabled and does not involve bookkeeping data actively uploaded by this App; on iOS, the random secret of the signed-out purchase identity and its linked/deleted records are synced through iCloud Keychain, see 1.4(6)): privacy policy apple.com/legal/privacy; contact and rights channel apple.com/legal/privacy/contact, or self-service access, correction and deletion via its Data & Privacy page (privacy.apple.com).
- Google LLC (involves: speech audio [system speech recognition on some Android devices], and, where you actively use an enabled capability, identity tokens, transaction credentials and a one-way hash of the purchase-account identifier): privacy policy policies.google.com/privacy; contact and rights channel support.google.com/policies, or self-service management, export and deletion via your Google Account page (myaccount.google.com).
Other disclosures required by law: where disclosure is required by laws and regulations or by mandatory administrative or judicial demands, we require presentation of valid legal documents; where personal information is transferred due to merger, division or dissolution, we will inform you of the recipient, which remains bound by this policy or must otherwise obtain your fresh consent.
4. Where Your Information Is Stored and for How Long
4.1 Storage Location
- Bookkeeping data (including speech transcripts): stored by default in the local database on your device. Text is processed as described in 1.2 only when you actively use cloud AI parsing; selected ledger backups are stored in Tencent Cloud Object Storage as described in 1.6 only when you actively enable cloud backup.
- Account data, parsing-audit records and cloud-backup metadata: within the People's Republic of China, on the deployed Tencent Cloud servers and database. Account data includes bound identity values such as normalized email addresses, credits, check-ins and entitlements, and the data of the signed-out purchase identity on iOS (see 1.4(6)).
- Data involved in system-level services such as Sign in with Apple and system speech recognition is stored by the relevant providers as described in Section 3. iCloud sync/backup for this App is currently disabled and no bookkeeping data is actively sent to iCloud by the App. On iOS, the random secret of the signed-out purchase identity and its linked/deleted records are kept in the system Keychain and synced through iCloud Keychain; they contain no bookkeeping data (see 1.4(6)).
- Please note: your operating system's whole-device cloud backup (e.g., iCloud device backup, or Google/vendor cloud backup on Android) may back up the App's local data to your own system cloud account; that is governed by your agreement with the system provider and is not collection by us.
4.2 Retention Periods (by Category)
| Category | Retention |
| Local bookkeeping data | Kept on your device under your control; deleted records enter a soft-deleted state first and are physically purged by the App after 30 days |
| Cloud-parsed text | Used and discarded: never written to the business database, never intentionally retained (see 1.2; the entrusted processor's lawful security-compliance processing is covered in Section 3) |
| Cloud-parsing audit records | Internal user ID, Premium status, success/failure and creation time only; no transcript or bookkeeping content; automatically deleted 90 days after creation |
| Account data (internal account ID, bound identities including normalized email, random app-installation identifiers, credits, check-ins and Basic/Premium entitlements) | Kept until you delete your account; then handled under Section 7 |
| Signed-out purchase identity on iOS (random account ID, random app-installation identifiers, sessions, credit and entitlement records) | Kept until you delete the identity in the App, or until you sign in and confirm linking it, after which it is kept as account data; after deletion or linking, an anti-reuse verification value is kept, and after deletion the purchase-account anchor record and unlinked purchase records are also kept under Section 7(6) |
| Temporary email-code verification records | Codes are valid for 30 minutes; successful verification invalidates the code so it cannot be reused; expiry or 5 wrong attempts also invalidates it; invalid records are automatically deleted within 7 days. Only HMAC values are stored, not plaintext |
| Email rate-limit and anti-abuse records | Stores keyed HMAC values rather than plaintext email/IP, plus daily counts and date; automatically deleted 90 days after that date |
| Tencent Cloud SES delivery data | We do not separately retain message bodies or per-message delivery details in our business database; SES console delivery statistics are currently available for about 30 days, with any other retention for security, troubleshooting or legal duties governed by Tencent Cloud's rules |
| Sign-in state (login token) | Until you sign out or delete your account, and in any case a sign-in session expires automatically 180 days after issuance and requires signing in again; when the number of signed-in devices for one account reaches the limit, the least-recently-used device is signed out; session data on the device is cleared immediately at sign-out; on iOS, the session token of the signed-out purchase identity is kept only in the device Keychain (not synced through iCloud) under the same expiry rules, and one identity can hold sessions on at most 10 devices at the same time |
| Cloud-backup files and metadata | At most 2 versions per ledger while Premium is valid; a minimum 90-day retrieval period after expiry. Deletion runs only after final verification. If the deletion chain is not safely enabled, external status cannot be verified or erroneous deletion is otherwise possible, deletion is deferred and retrieval remains available. Actual safe deletion is irreversible |
| Support email correspondence | No more than 3 years from resolution, for dispute handling and service improvement; then deleted or anonymized |
| Server operation logs | Operational logs of servers and network infrastructure (may contain network access information such as network addresses; never your parsed text), used only for security and troubleshooting, retained no less than six months as required by law and deleted or anonymized promptly after the statutory period |
| Records retained after deletion for anti-abuse, purchases and refunds | See Section 7: after account deletion, we retain keyed one-way HMAC verification values for relevant sign-in identities or transaction identifiers, plus necessary grant-claim records, the remaining-credit snapshot and purchase-account anchors (random account UUIDs) kept with sign-in identities, and purchase, refund and refund anti-replay records unlinked from the account; no plaintext email or third-party account identifier is retained, and store transaction identifiers, purchase tokens and similar identifiers are kept only in encrypted form. The remaining-credit snapshot and purchase-account anchors are cleared from an identity’s record once restored to an account that registers again with, or links, that sign-in identity. These records are kept until no longer necessary for duplicate-grant prevention, purchase restoration, refund/chargeback disputes, tax or another legal duty. We review them at least periodically and delete or anonymize records no longer necessary; a statutory period controls where applicable. After a signed-out purchase identity on iOS is deleted or merged into an account, we also keep a keyed one-way verification value of its random account ID, used only to prevent the same secret from re-creating the deleted or merged identity |
After these periods we delete your personal information or anonymize it, unless laws and regulations provide otherwise.
5. How We Protect Your Personal Information and Handle Security Incidents
5.1 Security Measures
- Architecture: local-first design — bookkeeping data stays on-device except when you actively use cloud parsing or enable cloud backup;
- Encryption in transit: all client–server communication uses HTTPS;
- Minimal storage: servers do not retain cloud-parsed text; they retain only the identities necessary for account service (including a normalized email when email sign-in is used), credits/entitlements, check-ins, content-free parsing audits and cloud-backup metadata. A selected ledger's backup file enters object storage only after you actively enable cloud backup;
- Credential protection: on iOS, login credentials and the session token of the signed-out purchase identity are stored in the system keychain (on this device only); the random secret of the signed-out purchase identity is stored in the system keychain and synced through iCloud Keychain, and our server keeps only the random account ID derived from it one-way, never the secret itself; the iOS local database uses system file protection (encrypted while the device is locked); on Android / HarmonyOS, data resides in the OS's per-app isolated private directory;
- Anti-abuse minimization: sign-in identifiers used for duplicate-claim matching are stored only as keyed one-way HMAC verification values that cannot be reversed; store transaction identifiers, purchase tokens and other billing identifiers are stored encrypted with AES-GCM and looked up through keyed one-way values. Associated grant-claim and refund anti-replay records, remaining-credit snapshots and purchase-account anchors are used only to prevent duplicate claims or post-refund entitlement replay, and to restore the remaining parsing counts once and reconnect store purchases when you register again with, or link, the corresponding sign-in identity, never for marketing or profiling;
- Access control: server database access is protected by keys and network isolation; signing keys are kept strictly confidential.
Please understand that the internet is never absolutely secure and no technical measure can guarantee absolute security. Statements in this policy that data is “not uploaded, not retained” describe our product design and intentional processing; they are not a guarantee against unexpected events such as unlawful attacks or malicious sabotage. Please safeguard your device, exported files and account, and do not disclose them to others.
5.2 Security Incident Response
In the event of a personal-information security incident, we will immediately activate our contingency plan, take remedial measures and, as required by law, promptly inform you — via in-app notice, email or announcement — of the basic facts and possible impact, the measures we have taken or will take, suggestions for you to mitigate risk, and remedies available to you, while reporting to the competent authorities as required. Where the measures we take can effectively prevent harm from leakage, tampering or loss, under Article 57 of the Personal Information Protection Law we may refrain from notifying each individual, unless the authority responsible for personal-information protection requires notification; where laws provide otherwise on notification, those provisions prevail.
6. Your Rights
You have the following rights over your personal information; we will respond within 15 business days of receiving a request:
- Access and copy: all your bookkeeping data is visible in the App; account information is under Me → Account; cloud-parsing credits are shown on the parsing/membership pages.
- Correction and supplementation: any record can be edited directly on its detail page; categories, ledgers and budgets can all be modified in the App. To change your sign-in email, use account binding or contact us under Section 12.
- Deletion: any record can be deleted in the App (physically purged after 30 days); cloud backups can be deleted by ledger or version on the cloud-backup page; you may also uninstall the App to erase all local data (please export a backup first — local data lost through uninstalling cannot be recovered by us). On iOS, the signed-out purchase identity can be deleted while signed out under Me → Purchase Data Without Sign-in (see Section 7(6)).
- Export (portability): export your records via Settings → Data Export. CSV export of record details (date, type, item, category, amount) is free for all users; complete JSON backup import/export and Excel report export are available to Basic and Premium users.
- Withdrawal or stopping specific processing: you may disable system permissions, select Local Parsing on the record screen or, on iOS, turn off cloud AI parsing under Settings → AI Smart Parsing (which withdraws your separate consent to cloud AI parsing) to stop later Cloud AI uploads, disable auto-backup or delete backups. Signing out clears the on-device session and stops new user-initiated cloud parsing, check-ins, backups and entitlement refreshes (on iOS, if an unlinked signed-out purchase identity exists on the device, its purchases and cloud-parsing credits remain usable on the device under 1.4(6)), but does not delete the account or stop server processing needed for transactions, refunds, subscription notices, security, fraud prevention or legal duties. Stopping later processing does not invalidate prior processing or affect local bookkeeping.
- Restriction and objection: you may restrict or object to specific processing of your personal information — by not using or disabling the relevant feature (e.g., not using voice bookkeeping, not signing in), by signing out, or by sending us a request via Section 12; we will respond and act within 15 business days.
- Account deletion: see Section 7.
- Explanations and complaints: you may ask us to explain our personal-information processing rules. If you believe our processing harms your lawful rights and interests, you may complain via Section 12 and we will reply within 15 business days; you may also complain or report to competent authorities such as the cyberspace administration and market regulation departments.
If you cannot complete the above in the App yourself, you may email the address listed in Section 12. For security, we may first need to verify your identity.
7. Account Deletion
- You may delete in-app under Me → Account → Delete Account. Identity verification may be required for theft risk or abnormal activity. If you cannot use the App, visit the account-deletion request page and use its primary email route, which requires no installation, or email privacy@xuanqiantech.com directly; we respond within 15 business days. The email-request route never asks you to send passwords, verification codes or third-party identity tokens. The page's email-code or Google self-service channel processes verification data only if that service is actually enabled in the target environment and you choose it; otherwise the page directs you to the email-request route.
- When account deletion takes effect, the deletion transaction removes the account and its identities (including normalized email and random app-installation identifiers), credits, check-ins, Basic/Premium entitlements, cloud-parsing audits, cloud-backup metadata and other online business-database data; your login token is invalidated immediately. Cloud-backup objects are simultaneously added to a persistent deletion queue and deletion from object storage is attempted immediately. If object storage is temporarily unavailable, the queue retries at fixed intervals until deletion succeeds. Until then it retains only the object key, failure reason and attempt count needed for deletion and no longer offers restoration service. Historical records may remain in access-restricted database disaster-recovery copies until the established rotation cycle ends, when they are overwritten or deleted. Disaster recovery is used only for security restoration, not normal business, and we do not restore a deleted Account into normal business operation. The specific cycle follows the backup policy reviewed and actually enforced in the target environment.
- Retention exceptions: after account deletion we retain: ① keyed one-way HMAC values of relevant sign-in identities or transaction identifiers plus necessary grant-claim records, to prevent repeated registration, check-in or purchase grants through delete-and-re-register; ② a remaining-credit snapshot — the local-parsing and one-off cloud-parsing counts left at deletion, plus the dates and counters needed to prevent a repeat claim on the same day — kept with only one of the sign-in identities (selected by the system under a fixed rule; if the account had several sign-in methods, you cannot choose which); ③ purchase-account anchors — the random account UUIDs the account used to link store purchases — kept with each sign-in identity; ④ purchase and refund records unlinked from the account, including contracts, products, start and expiry times, status and refund anti-replay records, in which store transaction identifiers, purchase tokens, order numbers and original store evidence are stored encrypted with AES-GCM and looked up through keyed one-way values. These records contain no plaintext email or third-party account identifier, are not used for marketing or profiling, and are used only for fraud prevention, avoiding duplicate grants, financial and tax records, handling refunds and chargebacks, and — when you register again with the corresponding sign-in identity — restoring once the parsing counts that remained at deletion (merged once under the account-merge rules if that identity is linked to an existing account) and reconnecting store purchases that are still valid; the remaining-credit snapshot and purchase-account anchors are cleared from that identity’s record once restored. Deleting your account means starting over: counts already granted (including new-account and daily check-in grants and the one-off cloud parses included with the same purchase) are not granted again on re-registration or “Restore Purchases”, and the Basic entitlement bundled with a yearly subscription is not restored after deletion; if you register again with the same sign-in method, the parsing counts that remained at deletion can be restored once (if your account had several sign-in methods, only the one holding the snapshot can restore them); a Basic buy-out you paid for, or a subscription still within its term, can be re-verified through the original app store’s “Restore Purchases”. Their retention and review rules are in Section 4. Until object deletion succeeds, the queue described above also retains object keys containing internal account and ledger UUIDs. Temporary verification-code HMAC records and date-aggregated send counters are not directly linked by foreign key to the account table and are handled under Section 4.
- Please note in particular: deletion removes the cloud account; the bookkeeping data on your device is not deleted and remains entirely under your control. To erase it too, uninstall the App or delete the data in-app.
- Deletion does not affect billing arrangements of subscriptions purchased through app stores. To stop auto-renewal, cancel separately in the respective store's subscription management page (see 1.4(5) for paths).
- Deleting the signed-out purchase identity on iOS: while signed out, you can delete the signed-out purchase identity described in 1.4(6) yourself under Me → Purchase Data Without Sign-in → Delete Purchase Data (if you are signed in, sign out first). Deletion requires both the session and the random secret on the device and runs after you confirm: the server deletes the identity and its random app-installation identifiers, sessions, credits and related data, and any remaining cloud parses are cleared and cannot be restored (the identity has no sign-in identity, so no remaining-credit snapshot under paragraph 3 is kept); related purchase and refund records, together with the purchase-account anchor record written in advance when the identity was created (its random account ID encrypted with AES-GCM and looked up by a keyed one-way verification value; this record exists even if the identity never paid), are kept unlinked under paragraph 3 ④ to handle store transactions and refund notifications that arrive later; and we keep a keyed one-way verification value of the identity's random account ID, used only to prevent the same secret from re-creating the deleted identity. The App also deletes the secret from the device and from iCloud Keychain; if the secret is lost and the identity cannot be deleted in the App, you can ask us to delete it as described in 1.4(6). Your App Store purchases themselves are not affected and still unlock features on the device through Restore Purchases; when you restore, the App creates a new signed-out purchase identity and purchases that are still valid are re-linked under the purchase re-linking rules (including a 24-hour cooling-off period), but counts already granted or included are not granted again. Deletion does not cancel auto-renewal; to stop charges, manage your subscription in the App Store (see 1.4(5)). A signed-out purchase identity that you have linked to an account has become part of that account and is handled with the account under paragraphs 1 to 5.
8. Protection of Minors
- The App is primarily for adults. We do not offer account registration, cloud AI, cloud backup, purchases or other online features to children under 14. They may use only signed-out, offline local bookkeeping under guardian consent and guidance.
- We do not knowingly collect children's personal information. If a child circumvents these restrictions, we stop the online service and delete the information promptly unless law requires retention. Users aged 14–17 should use the App under guardian guidance and purchase cautiously.
9. Updates to This Policy and Delivery of Notices
- We may revise this policy from time to time due to legal changes or product changes (for example, adding a sign-in method or integrating a new third-party SDK). We will not reduce your rights under this policy without your explicit consent.
- We notify updates prominently and update the version, last-updated and effective dates; historical versions are available on request. Explanatory or non-materially adverse changes apply from the stated effective date. If you disagree, stop using the relevant feature and you may delete the account.
- For material changes — such as substantive changes to the purposes, methods or categories of personal-information processing — we will obtain your consent again in a prominent manner such as a pop-up before they apply; the “continued use constitutes acceptance” rule does not apply to such material changes.
- Delivery of notices: notices related to this policy (update notices, security-incident notifications, feature announcements) may be given via in-app pop-up, push notification, announcement or the email address you provide, and are deemed delivered on the date of publication or sending. Please watch for in-app notices.
10. Liability and Your Obligations (Please Read Carefully)
- You are responsible for the truthfulness and legality of the information you enter or import. The App is a personal bookkeeping tool; its statistics, charts and budget features merely organize your own records and do not constitute investment, financial, tax or legal advice.
- Speech-recognition and AI-parsing results may contain errors and are for reference only; please verify before saving. Errors arising from recognition or parsing deviations can be corrected by you at any time; we bear no liability for losses arising therefrom, except where caused by our intent or gross negligence, and without prejudice to your statutory rights.
- To the extent permitted by law, we are not liable for data loss or leakage caused by force majeure (including natural disasters, war, strikes, riots, epidemics and containment measures, government actions, changes in laws or regulatory policies, telecom line failures, large-scale network or power outages, hacking, computer viruses and other unforeseeable, unavoidable and insurmountable circumstances), by failure or loss of your own device, by your failure to safeguard exported files or to make backups, or for interruptions or data processing of third-party services (app stores, system speech recognition, etc.) not attributable to our fault; provided that this clause does not exempt liability arising from our intent or gross negligence, nor exclude your statutory rights.
- The App's online features (cloud parsing, check-in, account and Basic/Premium entitlement verification, etc.) may be affected by devices, networks, maintenance and upgrades; we do not warrant that they will be uninterrupted or error-free. Where online features are temporarily unavailable due to maintenance, upgrades or failures, we will restore them as soon as possible; local bookkeeping is unaffected. To the extent permitted by law we bear no liability for such temporary interruptions, except where caused by our intent or gross negligence; if Premium subscription service is unavailable for an extended period for reasons attributable to us, we will provide reasonable compensation such as extending the subscription term.
- The liability caps in Sections 9.7–9.8 of the User Agreement apply: the aggregate cap is all fees actually paid for the Service, including Basic and Premium, in the preceding 12 months; for a free user, RMB 100. Statutorily non-excludable liability, intent, gross negligence and personal injury are excluded from the cap.
- If any provision of this policy is held invalid in whole or in part, the remaining provisions remain effective; the invalid provision shall be reinterpreted and applied, without violating the law, in the manner closest to its original purpose.
11. Dispute Resolution and Governing Law (Please Read Carefully)
This policy is governed by mainland Chinese law. The parties first negotiate; if unresolved within 30 days after a written request, either party may sue in a competent court at the defendant's domicile or another court competent under law. Mandatory protections or arrangements in your jurisdiction that cannot be excluded remain applicable.
The foregoing does not affect your statutory right to complain or report to competent authorities such as the cyberspace administration and market regulation departments (see Sections 6 and 12).
12. How to Contact Us
For any question, comment, complaint or rights request concerning this policy or personal-information protection, please contact us as follows; we will reply within 15 business days:
Operator: Inner Mongolia Xuanqian Technology Co., Ltd.
Registered address: Unit 25-6, Hongya New Town, Longxingchang Town, Wuyuan County, Bayannur, Inner Mongolia, China
Dedicated personal-information email: privacy@xuanqiantech.com (personal-information matters only; reply within 15 business days)
General contact: contact@xuanqiantech.com
Official website: xuanqiantech.com (ICP filing: 蒙ICP备2026005964号-1)
If you are dissatisfied with our reply, or believe our processing of personal information harms your lawful rights and interests, you may also complain or report to competent authorities such as the cyberspace administration and market regulation departments, or resolve the dispute as agreed in Section 11.
This policy is made and published in Chinese. Versions in any other language are provided for convenience only; in case of any ambiguity or discrepancy with the Chinese version, the Chinese version shall prevail.
Inner Mongolia Xuanqian Technology Co., Ltd.
September 29, 2026