Introduction
Welcome to VoiceExpense (Chinese name “鹦财记账”, Traditional Chinese “鸚財記帳”, the “App”). The App is developed and operated by Inner Mongolia Xuanqian Technology Co., Ltd. (registered address: Unit 25-6, Hongya New Town, Longxingchang Town, Wuyuan County, Bayannur, Inner Mongolia, China; “we” or “us”).
We understand how important your personal information is to you. The App is built around a “local-first” design: by default, your bookkeeping data is stored only on your own device; our servers do not store that data unless you actively enable cloud backup. We protect your personal information in accordance with the Personal Information Protection Law, the Cybersecurity Law, the Data Security Law and the Regulations on Network Data Security Management of the People's Republic of China, with reference to applicable national standards, and we apply reasonable security measures consistent with prevailing industry practice.
Please read this policy before using the App, especially the highlighted clauses. On first launch, the App links to the full website versions of this policy and the User Agreement; you can enter only after voluntarily tapping “Agree”, which is never preselected. Before that, the App requests no system permission and makes no business-network request except those necessary when you open a legal page. Normal website access necessarily involves network metadata such as IP address, request time, page URL, browser or WebView type, and operating system. The App does not add your account, random installation identifier or bookkeeping data to that legal-page request. See the website Privacy Policy.
If you do not agree to this policy, stop using and exit the App. Until you agree, the consent screen continues to block access to all other features, although you may still actively open the full Privacy Policy and User Agreement website pages. Apart from the network requests necessary to load those legal pages at your direction, the App collects no personal information, requests no other system permission and makes no other network transmission before you agree.
You can access the latest online versions of this policy and the User Agreement (website pages) at any time via the entry under Settings in the App: Privacy Policy www.xuanqiantech.com/legal/voiceexpense/privacy.html, User Agreement www.xuanqiantech.com/legal/voiceexpense/terms.html.
Key Points at a Glance
To help you quickly grasp the core of this policy, we summarize as follows (please read the full text for details):
- By default, your bookkeeping data lives on your device (a local SQLite database). When you actively use cloud AI parsing, we process only that parse's transcript in real time and do not write it to our business database. A selected ledger's backup file is stored in the cloud only when you actively enable cloud backup, a Premium feature enabled ledger by ledger.
- We do not collect your audio recordings, nor do we proactively upload them to our servers. Speech recognition is performed by your device's system speech service (Apple / Google or your device maker / Huawei) or by the App's built-in offline recognition model; when a system speech service is used, audio may be processed by that provider under its own terms.
- Recognized text reflects transactions and spending, so we protect it as sensitive personal information. The App uploads a parse only after you have accepted this Policy, are signed in, have cloud credits, and initiate a parse while Cloud AI is selected on the record screen. Text is used and discarded, never written to our business database. You may select Local Parsing before a parse without affecting local bookkeeping.
- Basic local bookkeeping works without an account, and signed-out use currently includes 20 on-device smart-parsing trials. A newly registered account currently receives 500 account-level local parses; a Free user receives 5 additional local parses on the first daily check-in. Basic and Premium users have unlimited local parsing, so check-in only records the day and adds no parses. A direct Basic purchase currently grants 50 one-time cloud AI parses, while Premium receives a daily cloud allowance (see 1.4 and 1.5).
- Basic or Premium purchases are processed by the applicable App Store / Google Play / Huawei AppGallery channel. We do not collect your bank-card or payment-account information; we receive only the store-issued transaction credential needed to verify entitlements. Entitlements are account-level and can be used after signing into the same account on clients that support them; purchases, cancellations and refunds must still be handled through the original app store (see 1.4).
- The App currently integrates no third-party analytics, crash-reporting or advertising SDKs; the “ads” currently shown in the App are locally bundled placeholder images that send no data anywhere.
- You may view, correct, delete and export your data in the App at any time, and may initiate account deletion in-app with one action; we respond to rights requests within 15 business days.
Table of Contents
- 1. How We Collect and Use Your Personal Information (Scenario by Scenario)
- 2. System Permissions We Request
- 3. How We Share and Entrust Processing of Your Personal Information (Third-Party List)
- 4. Where Your Information Is Stored and for How Long
- 5. How We Protect Your Personal Information and Handle Security Incidents
- 6. Your Rights
- 7. Account Deletion
- 8. Protection of Minors
- 9. Updates to This Policy and Delivery of Notices
- 10. Liability and Your Obligations (Please Read Carefully)
- 11. Dispute Resolution and Governing Law (Please Read Carefully)
- 12. How to Contact Us
1. How We Collect and Use Your Personal Information (Scenario by Scenario)
We follow the principle of minimum necessity: we collect and use your information only in the scenarios below and only to the extent necessary for the corresponding feature. The App's basic features are local manual/voice bookkeeping, which require no personal information and no account.
1.1 Voice Bookkeeping (Core Feature)
(1) Recording and recognition both take place on your device. We do not collect your audio recordings, nor do we proactively upload them to our servers. Specifically:
- when you tap the record button, we request microphone permission and capture your speech;
- speech-to-text uses either ① a system service (Apple on iOS; Google or the device maker on Android; Huawei as a HarmonyOS fallback) or ② the built-in sherpa-onnx offline model (available on Android in offline scenarios and preferred on HarmonyOS; entirely on-device);
- please note: when a system speech service is used, depending on language and device, your audio may be processed by servers of Apple, Google, Huawei or your device maker under their respective privacy policies. We make no commitments regarding those system services; see the third-party list in Section 3. We do not collect or store your original recordings, and we do not extract any voiceprint features.
(2) The recognized text (the “speech transcript”) and the records generated from it (amount, item, category, date, currency, etc.) are saved by default in the local database on your device. Please be aware that the speech transcript is part of your bookkeeping data: it is included in your locally saved records, backup files you actively export, and cloud-backup data you actively enable. When you actively use cloud AI parsing, that transcript is also uploaded and processed in real time as described in Section 1.2. iCloud sync is currently disabled.
(3) Local smart parsing: by default, converting speech text into a record is done by the App's built-in local rule engine on your device, with no network transmission whatsoever.
1.2 Cloud AI Parsing (Optional Online Feature; Involves Sensitive Personal Information — Please Read Carefully)
The speech transcript and the records generated from it substantively reflect your transactions and spending and constitute sensitive personal information. We protect them to the standard applicable to sensitive personal information, and we hereby explain the specific purpose and necessity of processing and the impact on your interests: the purpose is to convert your natural language into more accurate record suggestions; the necessity lies in the fact that large-model parsing must be performed server-side; the potential impact on your interests is that the text is briefly relayed through our servers to an entrusted large-model service for processing (see below and Section 3 for handling and safeguards). This handling is prominently disclosed through the general privacy-consent screen before you first enter the App; the transmission occurs only after you accept this Policy and use Cloud AI parsing.
Cloud AI is used only where actually available in the client and while you have accepted the current Policy, are signed in, have credits, and initiate a parse with Cloud AI selected on the record screen. You may select Local Parsing before a parse; signed-out, local-selected, exhausted-credit or offline states do not upload. If the purpose, method, information type or processor materially changes, we will update this Policy and provide any further notice or obtain consent required by law. The configured processor is Volcano Engine “Doubao”; availability is as displayed by your client and service configuration.
When cloud parsing is used, we send the following over an encrypted channel (HTTPS) to our server (api.xuanqiantech.com, deployed on Tencent Cloud within the People's Republic of China):
| Data item | Description | Required? |
| Speech transcript (text; sensitive personal information) | Parsed by the large model into record suggestions | Required for this feature |
| Your custom category codes, names, types and keywords | So results match your personal categories | Required for this feature |
| Device local date and current time (e.g., “2026-07-06 12:30”) | The current time gives the model time-of-day context when you do not state it (for example which meal); the local date is used only to meter your daily parsing credits and is not sent to the large model. Relative date words such as “yesterday” or “the day before yesterday” are recognized by the App on your device and stripped from the uploaded text; the cloud does not infer the record date | Required for this feature |
| Voice-language setting | To select the parsing language | Required for this feature |
| Account login token | Identity and credit verification | Required for this feature |
| Premium subscription credential (when included in the request; see 1.4) | Immediate verification of Premium entitlement and sync to the account | Required when immediate verification is needed |
In this process we do not collect your transaction history, account balances, location, or any device hardware identifier.
Upon receiving the text, our server relays it in real time to Volcano Engine's “Doubao” large language model (an entrusted processor, see Section 3) for parsing, and returns the result for your confirmation. Parsed text is used and discarded: we never write your speech transcript to our business database and never intentionally record it in logging systems. If temporary technical records arise from troubleshooting, we delete them promptly once troubleshooting is complete.
Each cloud parse creates an audit record with no transcript or bookkeeping content: internal user ID, Premium status, success/failure and creation time. It is automatically deleted 90 days after creation. Any processing the entrusted processor must perform under law is described in Section 3.
On iOS, the App may access Apple's captive.apple.com to test connectivity. The App adds no account, installation identifier or bookkeeping data, although Apple necessarily receives network metadata such as IP address and request time.
If a cloud-parsing request fails (including network unavailability or exhausted credits), the App automatically falls back to local parsing and bookkeeping is unaffected. AI parsing results are suggestions only and may contain errors; please verify before saving.
1.3 Account Registration and Sign-In (Optional)
You do not need an account for local bookkeeping. If you choose to sign in, the account is used to receive and sync parsing credits, check in, bind sign-in identities, sync Basic/Premium entitlements and use cloud backup. Where the relevant client and service configuration actually support it, signing in to the same Account lets you use entitlements the server has already verified for that Account; the actual scope is as displayed by each client.
(1) Sign in with Apple (iOS): we receive your identityToken through Apple's “Sign in with Apple” service and, after verification, store the user identifier assigned by Apple. The identity token may contain your email address (or an Apple-generated relay address). Our server uses the token only to authenticate and does not extract or store the email contained in it; the App decodes that email only locally on your device, to show a masked account identifier on the account page and, when Apple returns no name and no nickname is stored, to derive an on-device nickname from the part before “@” (relay addresses are not used for this). That email is kept in the device Keychain and is not uploaded to our servers. Name information returned by Apple is used only to generate an on-device nickname and is not uploaded to our servers.
(2) Email verification-code sign-in and binding: when you sign in or register with email, or bind an email address to an existing account, we collect the address, trim surrounding whitespace and convert it to lowercase to send a code, verify ownership and identify your account. After verification, the normalized email address is retained as a sign-in identity until account deletion. If the address already belongs to another account, after you confirm binding the related account data may be merged into the current account.
The code is a one-time 6-digit number valid for 30 minutes. The temporary code table stores only keyed one-way HMAC values of the email and code, not either value in plaintext. Successful verification invalidates the code so it cannot be reused; five consecutive incorrect attempts also invalidate it, and sending a replacement overwrites the previous code. Invalid records are automatically deleted within 7 days. To deter abusive sending, the same address cannot request another code within 60 seconds and may request at most 10 per day. We entrust Tencent Cloud Simple Email Service (SES) to deliver the message, providing it with the recipient address, code and selected language template; see Section 3.
(3) Random app-installation identifier: to limit the number of devices signed into one account, protect account security and deter abuse, the App generates a random UUID unrelated to device hardware on first launch and uploads it with sign-in requests. On iOS it is stored in this App's UserDefaults; on Android it is stored in app-private SharedPreferences and excluded from system backup and device transfer; on HarmonyOS it is stored in app-private Preferences and likewise excluded from system backup and device transfer. A normal uninstall/reinstall generates a new UUID on all three platforms. It is not IDFA, IMEI, Android ID, OAID or any other system device identifier and cannot associate your activity across other apps.
(4) For your account, the server stores: an internal account ID; bound sign-in identities (such as Apple, Google or Huawei user identifiers and normalized email addresses); random app-installation identifiers and their last-use times; parsing credit counters; check-in records; and Basic/Premium entitlement records. The server does not store parsed text, but it does store the content-free cloud-parsing audit records described in Section 1.2.
(5) Besides Apple and email, Google, Huawei and other platform sign-in methods are available only where displayed by the relevant client and enabled by service configuration. We obtain no identity token from a platform unless you actively choose its sign-in method. Actual availability is what the client you use displays.
1.4 Basic and Premium Purchases and Entitlement Verification (Optional)
(1) Basic is a one-time purchase and Premium is an auto-renewing subscription. Where a client offers purchases, they are completed through the App Store (iOS) / Google Play (Android) / Huawei AppGallery (HarmonyOS). Payment is handled by the relevant app store; we do not collect or access your card number, payment-account password or other payment information.
(2) To verify your entitlement, the App sends our server the store-issued transaction credential (for example, an iOS StoreKit transaction JWS containing product ID, original transaction ID, expiry time and related data, but no bank-card information). We retain the verification result, including platform, product, transaction identifier, validity period and revocation status, and bind it to the account signed in at purchase. A verified entitlement can sync across clients that support it under the same account; however, purchase restoration, cancellation and refunds remain with the original app store and must follow that store's procedures.
(3) Current parsing entitlements are: a Free user receives 500 local parses on first account registration and 5 more local parses on the first daily check-in; a Basic user has unlimited local parsing and a direct Basic purchase grants 50 one-time cloud AI parses; a Premium user has unlimited local parsing and currently 30 cloud AI parses per day. The 50 Basic parses are a one-time balance and do not reset daily; unused Premium daily allowance does not roll over. If an account has both the Premium daily allowance and a one-time cloud balance, the daily Premium allowance is used first, followed by the one-time balance. Basic entitlement bundled with an annual Premium subscription does not grant another 50 cloud parses. Actual entitlements are as shown on the purchase page and confirmed by account verification.
(4) Entitlement status is cached on your device for offline decisions; when online, app-store and server verification prevails.
(5) Please note in particular: Premium is an auto-renewing subscription and will be charged for renewal before the subscription period ends under the applicable store rules. Prices, subscription periods, renewal and cancellation rules are those shown on the purchase page and imposed by the applicable store. You may cancel auto-renewal at any time through the original purchase channel: on iOS, system Settings → your Apple Account → Subscriptions; on Android, Play Store → Payments & subscriptions → Subscriptions; on HarmonyOS, Settings → Huawei ID → Payment & billing → Subscriptions, or tap “Manage subscription” on the account page in the App. Refund requests are also handled by the original app store; we do not directly process store refunds.
1.5 Daily Check-In (Optional)
After signing in, you may check in daily. Under the current rules, a Free user's first check-in each day adds 5 local parses; Basic and Premium already include unlimited local parsing, so check-in for those tiers records the day only and grants no additional parses. We store your account's check-in date on the server; streaks and other check-in statistics are calculated by the App from on-device data.
1.5-A Exchange-Rate Refresh (Optional Online Feature)
When you are signed in and use multi-currency bookkeeping, the App may request daily rates from our server. It sends the account login token for authentication and rate limiting and generates ordinary network logs such as IP address and request time. No records, amounts, balances, ledger names or custom categories are uploaded. Our server does not pass your token, internal user ID or bookkeeping data to the public rate source. Rates are for bookkeeping conversion only.
1.6 Cloud Backup (Optional Premium Feature; Involves Sensitive Personal Information — Please Read Carefully)
Premium users can back up ledger data to the cloud. This feature is optional and off by default: only ledgers you select or actively back up are uploaded; unselected ledgers are never uploaded. Before you first use cloud backup—by first tapping “Back Up Now” or first enabling automatic backup for a ledger—we obtain your separate consent through a standalone, non-preselected pop-up. No bookkeeping data is uploaded before you consent and actively enable the feature.
A complete backup includes transaction details, ledger name, budgets, savings goals, custom categories, speech transcripts, and multi-currency fields such as transaction currency, base currency, exchange rate and converted base amount. It is stored in Tencent Cloud Object Storage in China. Transmission uses HTTPS, and our server requires server-side encryption at rest when the backup is written to object storage. Cloud backup is not end-to-end encrypted. Authorized staff may access content only to the minimum extent necessary for security troubleshooting, disaster recovery, your request or legal obligations; we do not use it for advertising, profiling, model training or product-algorithm improvement.
For uploads, the App first obtains a short-lived, single-use upload ticket and then uploads the backup file through our fixed HTTPS endpoint (api.xuanqiantech.com); our business server receives the complete backup in memory, verifies its file size and SHA-256 digest, and, once verified, writes it to Tencent Cloud Object Storage itself. The server therefore processes the complete backup content transiently for the time necessary to complete that upload, but does not write the uploaded content to the business database. For retrieval downloads, the App first obtains a short-lived, single-use download ticket and then downloads through our fixed HTTPS endpoint. Our business server reads the complete backup from object storage, verifies its size and SHA-256 digest in memory, forwards it to the App, and marks the response as non-cacheable. The server therefore processes the complete backup content transiently for the time necessary to complete that retrieval, but does not write the downloaded content to the business database. For authorization, list display, version management and integrity checks, our business server stores metadata: ledger identifier (ledgerId), ledger name (ledgerName), version number (version), file size (size), SHA-256 digest (sha256) and backup-device label (deviceLabel). This metadata contains no transaction details and is retained and deleted on the same schedule as the corresponding backup.
Storage rules: each user can back up at most 10 ledgers, with at most 2 backups per ledger by default. We first retain the latest 1; if there is a version at least 7 days old that is not that one, we also retain the newest such version as a weekly anchor. If no separate weekly anchor exists, including where the anchor is already the latest one, we retain no more than the latest 2. When an auto-backup ledger changes, the App coalesces changes made within a short interval, then attempts an upload while idle, entering the background, or next launching/returning to the foreground, over Wi-Fi or another non-cellular network. Each ledger can complete at most one automatic backup per day; it does not upload once for every transaction. Manual backup remains available.
When Premium expires, uploads and auto-backup stop. After grace or billing-retry protection, backups enter a minimum 90-day retrieval period and the App shows a planned deletion date. You may view, restore, renew or delete during that period. Deletion may run only after the minimum period and final confirmation that no Premium entitlement remains. If the deletion chain is not safely enabled, external entitlement status cannot be verified, or another condition risks erroneous deletion, deletion is deferred and retrieval, renewal and voluntary deletion remain available. Renewal cancels the plan before actual deletion; once safely deleted, a backup cannot be recovered. Deferral may only delay deletion.
You may delete cloud backups by ledger or version and disable automatic backup in the App at any time. The 90-day retrieval period does not apply to account deletion; all cloud backups are then deleted under the account-deletion process in Section 7.
Apple iCloud sync/backup in the iOS edition is currently disabled, has no accessible entry point, and sends no bookkeeping data to iCloud. If enabled in future, we will first update this policy and obtain any consent required before processing your bookkeeping data.
1.7 Data Export and Import (Local Feature)
You may export your records as CSV / JSON / Excel files. We guarantee that you can always export a CSV file of your record details (containing date, type, item, category and amount) free of charge, as the baseline channel for exercising your right to data portability and retrieving and copying your own bookkeeping data. Import and export of complete JSON backups, as well as Excel report export, are available to Basic and Premium users. Export files are unencrypted plaintext files, generated on your device and handed to the system share sheet, without passing through our servers. JSON backup files contain all transaction details and speech transcripts. You are responsible for safeguarding exported files; please store them carefully and avoid sharing them with untrusted parties.
1.8 Support and Contact
When you contact us by email, we receive your email address and the information you voluntarily provide in the message, used solely to respond to your inquiry, complaint or rights request, and retained after resolution for the period stated in Section 4.
1.9 What We Do Not Do
- we do not collect your location, contacts, photo library, clipboard or camera data, and we do not request the corresponding permissions;
- we do not collect IDFA, IMEI, Android ID, OAID or any other system device identifiers;
- we do not use any of your data for advertising profiles, user profiling or automated decision-making;
- we currently integrate no third-party analytics, crash-reporting, push or advertising SDKs;
- except in the following two cases, the App does not auto-start or chain-start other apps: ① redirects you actively trigger (e.g., going to the app store to manage a subscription, or opening your mail app to contact us); ② the Android edition is woken by the system after a device restart (the “boot” permission listed in Section 2) solely to reschedule the daily reminders you have enabled — no data collection or network transmission occurs in that process.
1.10 App Lock (Optional Local Security Feature)
If you enable App Lock, the App stores its enabled state, lock method, failed-attempt count and lock state locally. A PIN is represented only by a random salt and irreversible verifier, never plaintext. System biometrics or device credentials are verified by the operating system; the App receives only the result and never reads, stores or uploads facial or fingerprint templates. Email recovery uses the email and one-time-code processing in Section 1.3. Disabling App Lock clears its local verifier data.
2. System Permissions We Request
We request only the permissions below; you may decline them or turn them off in system settings at any time. Declining any permission does not affect basic features such as manual bookkeeping. Timing: microphone and speech-recognition permissions are requested when you first open the recording page and use voice bookkeeping; the notification permission is requested once after you agree to this policy and first enter the main screen (for the daily bookkeeping reminder) — you may decline and re-enable it later in system settings.
2.1 iOS
| Permission | Purpose | If declined |
| Microphone | Capture speech for voice bookkeeping | Voice bookkeeping unavailable; manual bookkeeping unaffected |
| Speech recognition | Convert your speech to text | Same as above |
| Notifications | Daily bookkeeping reminder | No reminders; other features unaffected |
| Face ID / Touch ID or device credential (only if App Lock is enabled) | On-device system verification; the App does not obtain biometric templates | Biometric unlock unavailable; use a PIN |
2.2 Android
| Permission | Purpose | If declined |
| Recording (RECORD_AUDIO) | Capture speech for voice bookkeeping | Voice bookkeeping unavailable; manual bookkeeping unaffected |
| Notifications (POST_NOTIFICATIONS, Android 13+) | Daily bookkeeping reminder | No reminders |
| Network (INTERNET / network state; normal install-time permissions) | Cloud parsing and account features; network state is read only to auto-switch to the built-in offline speech recognition when offline | — |
| Boot (RECEIVE_BOOT_COMPLETED, normal permission) | Reschedule your daily reminders after a device restart (see 1.9 regarding auto-start) | — |
| Biometrics (USE_BIOMETRIC, normal permission) | If App Lock is enabled, invoke on-device system verification; the App never collects or uploads biometric data | Biometric unlock unavailable; use a PIN |
| Fingerprint (USE_FINGERPRINT, normal permission) | Legacy Android 8.1-and-below compatibility permission; same purpose as above | Same as above |
The Android edition requests no storage read/write permissions; import and export use the system file picker.
2.3 HarmonyOS
| Permission | Purpose | If declined |
| Network (ohos.permission.INTERNET; normal permission) | Connect when you actively sign in, use cloud AI parsing, verify account entitlements, manually back up, or run an automatic backup you enabled | — |
| Microphone (while in use) | Voice bookkeeping | Voice bookkeeping unavailable; manual bookkeeping unaffected |
| Agent reminders | Daily bookkeeping reminder | No reminders |
| Vibration | Haptic feedback | No haptic feedback |
| Biometrics (ohos.permission.ACCESS_BIOMETRIC; only if App Lock is enabled) | On-device system verification; the App receives only the result | Biometric unlock unavailable; use a PIN |
3. How We Share and Entrust Processing of Your Personal Information (Third-Party List)
We do not sell your personal information. Your information is processed by third parties only in the circumstances below. The App currently integrates no third-party analytics, crash, push or advertising SDKs. Some platform services depend on client version, server configuration and app-store configuration; processing occurs only when the capability is actually available in your client and you trigger it. This list is kept in sync with releases and actual integrations.
| Name | Provider | Information involved | Permissions | Purpose | Status | Privacy policy |
| Volcano Engine “Doubao” LLM (entrusted processor) | Beijing Volcano Engine Technology Co., Ltd. | Speech transcript (sensitive personal information), current time, language setting, custom category codes, names, types and keywords (relayed only via our server) | None | Cloud AI parsing | Used only where actually offered and when the user triggers Cloud AI parsing | volcengine.com/docs/6348/68918 |
| Tencent Cloud infrastructure and Object Storage | Tencent Cloud Computing (Beijing) Co., Ltd. | Account, credit, entitlement, parsing-audit and cloud-backup metadata; Premium cloud-backup files you actively upload (server-side encrypted under the conditions in 1.6) | None | Server hosting, database and Premium cloud backup | In use | cloud.tencent.com/document/product/301/17345 |
| Tencent Cloud Simple Email Service (SES; entrusted processor) | Tencent Cloud Computing (Beijing) Co., Ltd. | Recipient email address, one-time code and email language template | None | Delivery of sign-in/binding verification messages | Used when email sign-in/binding is actually offered and triggered | cloud.tencent.com/document/product/301/17345 |
| Apple speech recognition | Apple Inc. (overseas recipient) | Your speech audio (processed by the system service, not via our servers) | Microphone, speech recognition | Speech-to-text | Used where actually offered and triggered on iOS | apple.com/legal/privacy |
| Sign in with Apple | Apple Inc. (overseas recipient) | Identity token, Apple user identifier | Network | Account sign-in | Used where actually offered and triggered on iOS | apple.com/legal/privacy |
| App Store in-app purchase (StoreKit) | Apple Inc. (overseas recipient) | Basic/Premium transactions handled by Apple; we receive only the transaction credential | Network | Purchase and entitlement verification | Used where actually offered and triggered on iOS | apple.com/legal/privacy |
| Apple iCloud | Apple Inc. | Currently processes no bookkeeping data from this App | Network | Cloud sync/backup | Disabled; no entry point | apple.com/legal/privacy |
| System speech recognition (Android) | Google LLC (overseas recipient) or your device maker | Your speech audio (processed by the on-device engine; may be uploaded to the engine provider when online; not via our servers) | Recording, network | Speech-to-text | Used where actually offered and triggered on Android | policies.google.com/privacy or your device maker's policy |
| Built-in offline speech recognition (sherpa-onnx) | Open-source model bundled in the App | Runs entirely on-device; zero network transmission | Recording | Speech-to-text when offline | Used where actually offered on Android | — (no data leaves the device) |
| Built-in offline speech recognition (sherpa-onnx) | Open-source model bundled in the App | Runs entirely on-device; zero network transmission | Microphone | Preferred on-device speech-to-text | Used where actually offered on HarmonyOS | — (no data leaves the device) |
| Google sign-in / Google Play Billing | Google LLC (overseas recipient) | Identity token / transaction credential | Network | Account sign-in / Basic and Premium entitlement verification | Used when configuration is enabled and the user triggers it; subject to what the Android client actually displays | policies.google.com/privacy |
| Huawei ID / Huawei IAP / Huawei system speech recognition | Huawei Technologies Co., Ltd. | Identity token / transaction credential / speech audio (system service) | Microphone, network | Account sign-in / Basic and Premium entitlement verification / speech-to-text | Used only where the corresponding capability is actually offered on HarmonyOS and triggered; unavailable capabilities process nothing | consumer.huawei.com/cn/privacy/privacy-policy/ |
| Google AdMob (advertising) | Google LLC | — (current ads are locally bundled placeholder images; no SDK, no data leaves the device) | — | Advertising | Not integrated; no data processing occurs | policies.google.com/privacy |
On entrusted processing (Volcano Engine): through applicable service agreements, data-processing terms and settings, we require the processor to use text only for the requested parse and not for model training beyond that purpose, subject to mandatory security processing under law. A material change to the provider, purpose or data categories requires renewed notice and consent where required.
On entrusted delivery (Tencent Cloud SES): we provide your email address and one-time code only to complete a sign-in or binding verification you requested, never for marketing. Our business database does not separately retain message bodies or per-message delivery details. Tencent Cloud SES console delivery statistics are currently available for approximately 30 days; any additional retention required for security, troubleshooting or legal compliance is governed by Tencent Cloud's rules. Retention of our normalized email identity and temporary code-verification records is described in Section 4.
On overseas services: Apple / Google system speech, sign-in, payment and connectivity services may act as independent handlers, and network metadata, audio, identity tokens or transaction information may be transferred outside China. You ordinarily trigger these system services directly and we mainly receive verification results stored in China. Where entitlement verification, security investigation or channel notices require us to call an overseas channel API, we provide only the necessary transaction or channel-account identifiers. We will meet applicable notice, separate-consent and transfer requirements and do not exclude any legal responsibility. Rights channels are listed below:
- Apple Inc. (involves: speech audio [system speech recognition], identity token and user identifier [Sign in with Apple], transaction credential [IAP]; iCloud sync is disabled and does not involve bookkeeping data actively uploaded by this App): privacy policy apple.com/legal/privacy; contact and rights channel apple.com/legal/privacy/contact, or self-service access, correction and deletion via its Data & Privacy page (privacy.apple.com).
- Google LLC (involves: speech audio [system speech recognition on some Android devices], and, where you actively use an enabled capability, identity tokens and transaction credentials): privacy policy policies.google.com/privacy; contact and rights channel support.google.com/policies, or self-service management, export and deletion via your Google Account page (myaccount.google.com).
Other disclosures required by law: where disclosure is required by laws and regulations or by mandatory administrative or judicial demands, we require presentation of valid legal documents; where personal information is transferred due to merger, division or dissolution, we will inform you of the recipient, which remains bound by this policy or must otherwise obtain your fresh consent.
4. Where Your Information Is Stored and for How Long
4.1 Storage Location
- Bookkeeping data (including speech transcripts): stored by default in the local database on your device. Text is processed as described in 1.2 only when you actively use cloud AI parsing; selected ledger backups are stored in Tencent Cloud Object Storage as described in 1.6 only when you actively enable cloud backup.
- Account data, parsing-audit records and cloud-backup metadata: within the People's Republic of China, on the deployed Tencent Cloud servers and database. Account data includes bound identity values such as normalized email addresses, credits, check-ins and entitlements.
- Data involved in system-level services such as Sign in with Apple and system speech recognition is stored by the relevant providers as described in Section 3. iCloud sync/backup for this App is currently disabled and no bookkeeping data is actively sent to iCloud by the App.
- Please note: your operating system's whole-device cloud backup (e.g., iCloud device backup, or Google/vendor cloud backup on Android) may back up the App's local data to your own system cloud account; that is governed by your agreement with the system provider and is not collection by us.
4.2 Retention Periods (by Category)
| Category | Retention |
| Local bookkeeping data | Kept on your device under your control; deleted records enter a soft-deleted state first and are physically purged by the App after 30 days |
| Cloud-parsed text | Used and discarded: never written to the business database, never intentionally retained (see 1.2; the entrusted processor's lawful security-compliance processing is covered in Section 3) |
| Cloud-parsing audit records | Internal user ID, Premium status, success/failure and creation time only; no transcript or bookkeeping content; automatically deleted 90 days after creation |
| Account data (internal account ID, bound identities including normalized email, random app-installation identifiers, credits, check-ins and Basic/Premium entitlements) | Kept until you delete your account; then handled under Section 7 |
| Temporary email-code verification records | Codes are valid for 30 minutes; successful verification invalidates the code so it cannot be reused; expiry or 5 wrong attempts also invalidates it; invalid records are automatically deleted within 7 days. Only HMAC values are stored, not plaintext |
| Email rate-limit and anti-abuse records | Stores keyed HMAC values rather than plaintext email/IP, plus daily counts and date; automatically deleted 90 days after that date |
| Tencent Cloud SES delivery data | We do not separately retain message bodies or per-message delivery details in our business database; SES console delivery statistics are currently available for about 30 days, with any other retention for security, troubleshooting or legal duties governed by Tencent Cloud's rules |
| Sign-in state (login token) | Until you sign out or delete your account, and in any case a sign-in session expires automatically 180 days after issuance and requires signing in again; when the number of signed-in devices for one account reaches the limit, the least-recently-used device is signed out; session data on the device is cleared immediately at sign-out |
| Cloud-backup files and metadata | At most 2 versions per ledger while Premium is valid; a minimum 90-day retrieval period after expiry. Deletion runs only after final verification. If the deletion chain is not safely enabled, external status cannot be verified or erroneous deletion is otherwise possible, deletion is deferred and retrieval remains available. Actual safe deletion is irreversible |
| Support email correspondence | No more than 3 years from resolution, for dispute handling and service improvement; then deleted or anonymized |
| Server operation logs | Operational logs of servers and network infrastructure (may contain network access information such as network addresses; never your parsed text), used only for security and troubleshooting, retained no less than six months as required by law and deleted or anonymized promptly after the statutory period |
| Anti-abuse and refund anti-replay records | See Section 7: after account deletion, we retain keyed one-way HMAC verification values for relevant sign-in identities or transaction identifiers, plus necessary grant-claim records, refund anti-replay records and remaining-credit snapshots; no plaintext email, third-party account identifier or transaction identifier is retained. They are kept until no longer necessary for duplicate-grant prevention, refund/chargeback disputes, tax or another legal duty. We review them at least periodically and delete or anonymize records no longer necessary; a statutory period controls where applicable |
After these periods we delete your personal information or anonymize it, unless laws and regulations provide otherwise.
5. How We Protect Your Personal Information and Handle Security Incidents
5.1 Security Measures
- Architecture: local-first design — bookkeeping data stays on-device except when you actively use cloud parsing or enable cloud backup;
- Encryption in transit: all client–server communication uses HTTPS;
- Minimal storage: servers do not retain cloud-parsed text; they retain only the identities necessary for account service (including a normalized email when email sign-in is used), credits/entitlements, check-ins, content-free parsing audits and cloud-backup metadata. A selected ledger's backup file enters object storage only after you actively enable cloud backup;
- Credential protection: on iOS, login credentials are stored in the system keychain; the iOS local database uses system file protection (encrypted while the device is locked); on Android / HarmonyOS, data resides in the OS's per-app isolated private directory;
- Anti-abuse minimization: original identity or transaction identifiers used for matching are stored only as keyed one-way HMAC verification values that cannot be reversed. Associated grant-claim, refund anti-replay and remaining-credit snapshots are used only to prevent duplicate claims or post-refund entitlement replay, never for marketing or profiling;
- Access control: server database access is protected by keys and network isolation; signing keys are kept strictly confidential.
Please understand that the internet is never absolutely secure and no technical measure can guarantee absolute security. Statements in this policy that data is “not uploaded, not retained” describe our product design and intentional processing; they are not a guarantee against unexpected events such as unlawful attacks or malicious sabotage. Please safeguard your device, exported files and account, and do not disclose them to others.
5.2 Security Incident Response
In the event of a personal-information security incident, we will immediately activate our contingency plan, take remedial measures and, as required by law, promptly inform you — via in-app notice, email or announcement — of the basic facts and possible impact, the measures we have taken or will take, suggestions for you to mitigate risk, and remedies available to you, while reporting to the competent authorities as required. Where the measures we take can effectively prevent harm from leakage, tampering or loss, under Article 57 of the Personal Information Protection Law we may refrain from notifying each individual, unless the authority responsible for personal-information protection requires notification; where laws provide otherwise on notification, those provisions prevail.
6. Your Rights
You have the following rights over your personal information; we will respond within 15 business days of receiving a request:
- Access and copy: all your bookkeeping data is visible in the App; account information is under Me → Account; cloud-parsing credits are shown on the parsing/membership pages.
- Correction and supplementation: any record can be edited directly on its detail page; categories, ledgers and budgets can all be modified in the App. To change your sign-in email, use account binding or contact us under Section 12.
- Deletion: any record can be deleted in the App (physically purged after 30 days); cloud backups can be deleted by ledger or version on the cloud-backup page; you may also uninstall the App to erase all local data (please export a backup first — local data lost through uninstalling cannot be recovered by us).
- Export (portability): export your records via Settings → Data Export. CSV export of record details (date, type, item, category, amount) is free for all users; complete JSON backup import/export and Excel report export are available to Basic and Premium users.
- Withdrawal or stopping specific processing: you may disable system permissions, select Local Parsing on the record screen to stop later Cloud AI uploads, disable auto-backup or delete backups. Signing out clears the on-device session and stops new user-initiated cloud parsing, check-ins, backups and entitlement refreshes, but does not delete the account or stop server processing needed for transactions, refunds, subscription notices, security, fraud prevention or legal duties. Stopping later processing does not invalidate prior processing or affect local bookkeeping.
- Restriction and objection: you may restrict or object to specific processing of your personal information — by not using or disabling the relevant feature (e.g., not using voice bookkeeping, not signing in), by signing out, or by sending us a request via Section 12; we will respond and act within 15 business days.
- Account deletion: see Section 7.
- Explanations and complaints: you may ask us to explain our personal-information processing rules. If you believe our processing harms your lawful rights and interests, you may complain via Section 12 and we will reply within 15 business days; you may also complain or report to competent authorities such as the cyberspace administration and market regulation departments.
If you cannot complete the above in the App yourself, you may email the address listed in Section 12. For security, we may first need to verify your identity.
7. Account Deletion
- You may delete in-app under Me → Account → Delete Account. Identity verification may be required for theft risk or abnormal activity. If you cannot use the App, visit the account-deletion request page and use its primary email route, which requires no installation, or email privacy@xuanqiantech.com directly; we respond within 15 business days. The email-request route never asks you to send passwords, verification codes or third-party identity tokens. The page's email-code or Google self-service channel processes verification data only if that service is actually enabled in the target environment and you choose it; otherwise the page directs you to the email-request route.
- When account deletion takes effect, the deletion transaction removes the account and its identities (including normalized email and random app-installation identifiers), credits, check-ins, Basic/Premium entitlements, cloud-parsing audits, cloud-backup metadata and other online business-database data; your login token is invalidated immediately. Cloud-backup objects are simultaneously added to a persistent deletion queue and deletion from object storage is attempted immediately. If object storage is temporarily unavailable, the queue retries at fixed intervals until deletion succeeds. Until then it retains only the object key, failure reason and attempt count needed for deletion and no longer offers restoration service. Historical records may remain in access-restricted database disaster-recovery copies until the established rotation cycle ends, when they are overwritten or deleted. Disaster recovery is used only for security restoration, not normal business, and we do not restore a deleted Account into normal business operation. The specific cycle follows the backup policy reviewed and actually enforced in the target environment.
- Retention exceptions: to prevent repeated registration, check-in or purchase grants after delete-and-re-register, and to record refund revocations, we retain keyed one-way HMAC values of relevant sign-in identities or transaction identifiers plus necessary claim records, refund anti-replay records and remaining-credit snapshots. They contain no plaintext email, third-party account identifier or transaction identifier, are not used for marketing or profiling, and are used only for fraud prevention and avoiding duplicate grants. Deleting your account means starting over: entitlements and quotas granted free of charge (including the Basic entitlement bundled with a yearly subscription and any granted parsing counts or their unused balances) are not restored after deletion; a Basic buy-out you paid for, or a subscription still within its term, can be re-verified through the original app store’s “Restore Purchases”. Their retention and review rules are in Section 4. Until object deletion succeeds, the queue described above also retains object keys containing internal account and ledger UUIDs. Temporary verification-code HMAC records and date-aggregated send counters are not directly linked by foreign key to the account table and are handled under Section 4.
- Please note in particular: deletion removes the cloud account; the bookkeeping data on your device is not deleted and remains entirely under your control. To erase it too, uninstall the App or delete the data in-app.
- Deletion does not affect billing arrangements of subscriptions purchased through app stores. To stop auto-renewal, cancel separately in the respective store's subscription management page (see 1.4(5) for paths).
8. Protection of Minors
- The App is primarily for adults. We do not offer account registration, cloud AI, cloud backup, purchases or other online features to children under 14. They may use only signed-out, offline local bookkeeping under guardian consent and guidance.
- We do not knowingly collect children's personal information. If a child circumvents these restrictions, we stop the online service and delete the information promptly unless law requires retention. Users aged 14–17 should use the App under guardian guidance and purchase cautiously.
9. Updates to This Policy and Delivery of Notices
- We may revise this policy from time to time due to legal changes or product changes (for example, adding a sign-in method or integrating an advertising SDK). We will not reduce your rights under this policy without your explicit consent.
- We notify updates prominently and update the version, last-updated and effective dates; historical versions are available on request. Explanatory or non-materially adverse changes apply from the stated effective date. If you disagree, stop using the relevant feature and you may delete the account.
- For material changes — such as substantive changes to the purposes, methods or categories of personal-information processing — we will obtain your consent again in a prominent manner such as a pop-up before they apply; the “continued use constitutes acceptance” rule does not apply to such material changes.
- Delivery of notices: notices related to this policy (update notices, security-incident notifications, feature announcements) may be given via in-app pop-up, push notification, announcement or the email address you provide, and are deemed delivered on the date of publication or sending. Please watch for in-app notices.
10. Liability and Your Obligations (Please Read Carefully)
- You are responsible for the truthfulness and legality of the information you enter or import. The App is a personal bookkeeping tool; its statistics, charts and budget features merely organize your own records and do not constitute investment, financial, tax or legal advice.
- Speech-recognition and AI-parsing results may contain errors and are for reference only; please verify before saving. Errors arising from recognition or parsing deviations can be corrected by you at any time; we bear no liability for losses arising therefrom, except where caused by our intent or gross negligence, and without prejudice to your statutory rights.
- To the extent permitted by law, we are not liable for data loss or leakage caused by force majeure (including natural disasters, war, strikes, riots, epidemics and containment measures, government actions, changes in laws or regulatory policies, telecom line failures, large-scale network or power outages, hacking, computer viruses and other unforeseeable, unavoidable and insurmountable circumstances), by failure or loss of your own device, by your failure to safeguard exported files or to make backups, or for interruptions or data processing of third-party services (app stores, system speech recognition, etc.) not attributable to our fault; provided that this clause does not exempt liability arising from our intent or gross negligence, nor exclude your statutory rights.
- The App's online features (cloud parsing, check-in, account and Basic/Premium entitlement verification, etc.) may be affected by devices, networks, maintenance and upgrades; we do not warrant that they will be uninterrupted or error-free. Where online features are temporarily unavailable due to maintenance, upgrades or failures, we will restore them as soon as possible; local bookkeeping is unaffected. To the extent permitted by law we bear no liability for such temporary interruptions, except where caused by our intent or gross negligence; if Premium subscription service is unavailable for an extended period for reasons attributable to us, we will provide reasonable compensation such as extending the subscription term.
- The liability caps in Sections 9.7–9.8 of the User Agreement apply: the aggregate cap is all fees actually paid for the Service, including Basic and Premium, in the preceding 12 months; for a free user, RMB 100. Statutorily non-excludable liability, intent, gross negligence and personal injury are excluded from the cap.
- If any provision of this policy is held invalid in whole or in part, the remaining provisions remain effective; the invalid provision shall be reinterpreted and applied, without violating the law, in the manner closest to its original purpose.
11. Dispute Resolution and Governing Law (Please Read Carefully)
This policy is governed by mainland Chinese law. The parties first negotiate; if unresolved within 30 days after a written request, either party may sue in a competent court at the defendant's domicile or another court competent under law. Mandatory protections or arrangements in your jurisdiction that cannot be excluded remain applicable.
The foregoing does not affect your statutory right to complain or report to competent authorities such as the cyberspace administration and market regulation departments (see Sections 6 and 12).
12. How to Contact Us
For any question, comment, complaint or rights request concerning this policy or personal-information protection, please contact us as follows; we will reply within 15 business days:
Operator: Inner Mongolia Xuanqian Technology Co., Ltd.
Registered address: Unit 25-6, Hongya New Town, Longxingchang Town, Wuyuan County, Bayannur, Inner Mongolia, China
Dedicated personal-information email: privacy@xuanqiantech.com (personal-information matters only; reply within 15 business days)
General contact: contact@xuanqiantech.com
Official website: xuanqiantech.com (ICP filing: 蒙ICP备2026005964号-1)
If you are dissatisfied with our reply, or believe our processing of personal information harms your lawful rights and interests, you may also complain or report to competent authorities such as the cyberspace administration and market regulation departments, or resolve the dispute as agreed in Section 11.
This policy is made and published in Chinese. Versions in any other language are provided for convenience only; in case of any ambiguity or discrepancy with the Chinese version, the Chinese version shall prevail.
Inner Mongolia Xuanqian Technology Co., Ltd.
September 9, 2026