Last updated: 2026-10-01 · Provider: Chen Yitong · Contact: yitong0322@gmail.com
SpendSmart is a personal-finance app built to keep your ledger on your own device and, if enabled, in your private iCloud. The server features described below are optional.
Your transactions, accounts, budgets, savings goals, loans, investments, subscriptions, categories, notes, attachments, settings, and local insights are stored locally. If you enable iCloud, Apple CloudKit synchronizes them through your private iCloud account. SpendSmart does not receive your raw ledger database.
When you sign in to Built-in AI, our server receives an app-specific identifier from Sign in with Apple. Apple and RevenueCat purchase events provide transaction identifiers, product, currency, value, and entitlement status. We use this data only to authenticate you, deliver and restore purchases, maintain AI credit balances, prevent duplicate grants and abuse, secure the service, and support refunds.
The server stores revocable sessions, entitlements, credit-source balances, purchase records, and limited usage/cost records such as action, provider, model, region, token counts, and estimated provider cost. We do not receive payment-card details.
Hosted AI is off until you give separate permission. Each new request follows your current country or region: in mainland China it uses the mainland service and Alibaba Cloud Qwen; elsewhere it uses the overseas service and OpenAI. The device's coarse country is preferred; if unavailable, the network exit's country is used. The routing feature does not store or upload precise coordinates. Account, purchase, and allowance records are verified by one mainland ledger, including when an overseas service requests allowance authorization. The minimum financial summary needed for an answer, your question, and any attachment you choose go to the service region selected for that request. A central outbound gateway applies best-effort filtering to remove email addresses, UUIDs, and long account-number-like values from semantic text fields; it cannot guarantee removal of every identifier. Image contents are not automatically redacted. Do not upload content you do not wish to share. Protocol linkage identifiers and attachment references are sent unchanged when needed to complete the request. SpendSmart does not persist AI request content. To recover a paid answer lost in transit, its response is available for replay only as authenticated ciphertext for up to 10 minutes; after expiry it is inaccessible and deleted by scheduled cleanup. Durable ledgers contain no request or response body. A network failure never silently moves an in-flight request to another region.
We require each selected AI provider to provide the same or equal protection for shared data as described in this policy. The provider processes the request under its own privacy and retention terms solely to return the requested response.
Account, entitlement, balance, and purchase records remain while your Built-in AI account is active. Detailed usage and cost records are retained for up to 90 days. Purchase-webhook idempotency records are retained for up to 400 days. AI request content is not retained; encrypted response replay data becomes inaccessible after 10 minutes and is removed by scheduled cleanup.
You can revoke consent for future hosted-AI transfers at any time by turning off “Allow Hosted AI to Process Financial Data” in AI Service settings. Local insights, on-device AI, and bring-your-own-key features remain available.
Use “Delete Built-in AI Account” in the app, or email us, to revoke sessions and remove the server account, balances, purchase lots, and usage records. To prevent repeated trials, invitations, or one-time grants, limited one-way HMAC markers may remain while the benefit is non-repeatable; they cannot reconstruct your Apple identifier or account. Deleting the app alone does not delete an active server account.
If you connect your own AI provider key, it is stored in your device Keychain and is not sent to SpendSmart servers. Requests using that key go directly to the provider you selected under that provider’s terms.
Camera or Photos may be used to import receipts; Microphone and Speech Recognition for dictation; Location to optionally tag a transaction and, after hosted-AI permission, determine the coarse service country; and Face ID or Touch ID to unlock the app. If location is denied, a trusted network-country observation may be used instead. You can deny or revoke permissions in iOS Settings. Biometrics are handled by iOS and are never received by SpendSmart.
SpendSmart does not sell your data, use advertising or analytics/tracking SDKs, or track you across apps or websites. SpendSmart is not directed to children under 13 and does not knowingly collect their data.
Material changes will be reflected by the “Last updated” date. For privacy questions or deletion help, contact yitong0322@gmail.com.
最后更新:2026-10-01 · 提供者:陈奕潼 · 联系:yitong0322@gmail.com
SpendSmart 是一款个人财务应用,账本数据默认保存在你的设备,并可由你选择同步到私有 iCloud。下述服务端功能均为可选功能。
交易、账户、预算、储蓄目标、贷款、投资、订阅、分类、备注、附件、设置和本地洞察保存在设备本地。开启 iCloud 后,Apple CloudKit 会通过你的私有 iCloud 账户同步这些数据。SpendSmart 服务器不会接收你的原始账本数据库。
登录内置 AI 时,服务器会从“通过 Apple 登录”接收应用专用标识;Apple 与 RevenueCat 的购买事件会提供交易标识、商品、币种、金额和权益状态。它们仅用于身份验证、交付与恢复购买、维护 AI 额度、防止重复领取和滥用、保障服务安全及处理退款。
服务器保存可撤销会话、权益、分来源额度、购买记录,以及操作、供应商、模型、地区、token 数和估算成本等有限用量记录。我们不接收支付卡信息。
托管 AI 默认关闭,只有你另行许可后才启用。每次新请求按当前所在国家或地区选择服务:人在中国大陆时使用大陆服务与阿里云通义千问,人在海外时使用海外服务与 OpenAI。设备的大致国家或地区优先;不可用时按网络出口国家或地区判断。路由功能不保存或上传精确坐标。账号、购买及额度由大陆统一账本核验;海外服务执行请求时也向该账本核验额度。回答所需的最少财务摘要、你的问题和你选择的附件会发送给当次服务区。统一出站网关会尽力过滤语义文本字段中的邮箱、UUID 和长账号等直接标识,但不能保证移除所有标识。图片内容不会自动脱敏,请勿上传不愿分享的内容。协议关联标识和附件引用会在完成请求所必需时原样发送。SpendSmart 不保存 AI 请求正文;为恢复传输中丢失的付费回答,回复只会以认证密文提供最多 10 分钟的重放,过期后不可访问并由定时清理删除,长期账本不含请求或回复正文。网络失败不会把正在执行的请求静默切到另一区。
我们要求所选 AI 提供商对共享数据提供与本政策相同或同等的保护。提供商仅为返回所请求的回答,按照其自身隐私与保留条款处理请求。
内置 AI 账号存续期间会保留账号、权益、额度和购买记录;详细用量及成本记录最多保留 90 天,购买 Webhook 幂等记录最多保留 400 天;AI 请求正文不会保留,回复重放密文在 10 分钟后不可访问并由定时清理删除。
你可以随时在“AI 服务”设置中关闭“允许托管 AI 处理财务数据”,撤回今后传输的同意;本地洞察、本机 AI 和自带密钥功能仍可使用。
使用 App 内“删除内置 AI 账号”或通过邮件联系我们,可撤销会话并删除服务端账号、额度、购买批次和用量记录。为防止重复领取体验、邀请或一次性权益,对应的用途受限、不可逆 HMAC 标记可在该权益不可重复领取期间继续保留;它们不能还原 Apple 标识或账号。仅删除 App 不会删除仍然有效的服务端账号。
自带 AI 密钥只保存在设备 Keychain,不会发送到 SpendSmart 服务器;使用该密钥的请求会直接发给你选择的提供商,并适用该提供商的条款。
相机或相册用于导入收据,麦克风和语音识别用于口述;定位用于可选的交易地点标记,以及同意托管 AI 后判断大致服务国家或地区。拒绝定位时可用可信的网络出口国家或地区兜底。Face ID 或 Touch ID 用于解锁 App。你可以在 iOS 设置中拒绝或撤销权限;生物特征完全由 iOS 处理,SpendSmart 不会收到。
SpendSmart 不出售数据,不使用广告或分析/追踪 SDK,也不跨 App 或网站追踪你。SpendSmart 不面向 13 岁以下儿童,也不会有意收集其数据。
重大变更会通过上方“最后更新”日期体现。隐私问题或删号协助请联系 yitong0322@gmail.com。