For the Keel iOS app (Chinese name: 司元)Effective: July 28, 2026Last updated: September 10, 2026
Summary
We run no servers. The app does not send your ledger data to any server we control — no such server exists.
Your data stays with you. By default it lives only on your device. It reaches the iCloud private database of your own Apple ID only after you deliberately turn on iCloud Sync.
No ads, no analytics SDKs, no trackers, no third-party code of any kind. We do not collect, sell, or share your personal information.
The AI features run on your device. Asking your ledger and receipt capture use the Apple Intelligence on-device model and the system text recognizer; your ledger data is not sent to us, nor to any external AI service provider (the one exception is a Local MCP switch in the macOS version, off by default — see Section 8).
The app never connects to your bank, payment accounts, or credit bureaus. It fetches no statements. Every record is entered or imported by you.
1. Who provides this app
Keel (Chinese name 司元, the "App") is developed and published by gwongsam, an independent developer ("we", "us").
This policy explains how the App handles your information. One premise runs through all of it: the App has no backend server of ours, and your ledger contents never reach us. Most of what follows therefore describes how data moves between your own device and your own iCloud account.
2. What data the app handles
The following data is created by you as you use the App, and is stored on your device:
Account names, types, and balances you create; credit-card billing cycles, loan drawdowns and repayment schedules, buy-now-pay-later orders, prepaid and stored-value accounts
Organization
Categories, tags, projects, and counterparties (people or institutions you name yourself)
Attachments
Images and PDFs of receipts, invoices, and documents that you add
Settings
Language, display options, default book, budgets, statement grouping schemes, and other in-app preferences
Exchange rates
Rates you enter manually, plus a cache of publicly available market rates
Diagnostics
Runtime logs, error records, and system-provided crash and performance metrics
Purchase receipts
App Store transaction receipts and membership entitlement status
The App does not request, collect, or process your legal name, government ID numbers, phone number, email address, card numbers, banking or payment credentials, contacts, location, health data, advertising identifiers (IDFA), or device fingerprints.
A ledger by its nature can contain sensitive financial information. That is precisely why the App is designed so that this data stays within your control — never uploaded to our servers, never handed to third-party analytics.
3. Where your data lives
3.1 On your device (the default)
Out of the box, all of the above is stored locally: the ledger database lives in the app's sandbox container, and attachment files are stored in the app's file repository with system file protection enabled (encrypted and unreadable while the device is locked). iOS sandboxing prevents other apps from reading any of it.
If you never enable iCloud Sync and never export a backup, your ledger data never leaves that device.
3.2 iCloud Sync (off by default; you must turn it on)
You can enable iCloud Sync under Settings › Privacy & Sync. Once enabled:
Books, transactions, accounts, categories, exchange rates, app settings, and attachments are stored in the iCloud private database of your Apple ID (CloudKit private database) so they can sync across your devices.
This data is hosted by Apple within your own iCloud storage quota. We cannot access, read, or export it. Developers have no access to a user's private database — that is how Apple's CloudKit is architected, not merely a promise we make.
Sync uses silent push notifications to tell a device to fetch changes. Those notifications carry no ledger content.
You can turn sync off at any time, and choose either to keep a local copy or to also request deletion of the copy stored in iCloud.
3.3 Shared books
You can share a book with other people for collaboration. This is always initiated by you:
Sharing uses Apple's iCloud sharing mechanism: you generate an iCloud share link and send it to the other person yourself.
Members who accept your invitation can access the contents of that book — including its transactions and attachments — at the permission level you grant (read-only or read-write). Books you have not shared are unaffected.
So the member list can show who is who, the App displays the participant identity information Apple provides (such as the name the person presents through system sharing). You can also set a local-only nickname for a member.
You can remove a member or stop sharing at any time, which revokes their access.
Choose who you share with carefully. Once someone has access, they may view or copy what is in that book, which is beyond our technical control.
3.4 Online exchange rates
The App can fetch reference exchange rates for multi-currency conversion. This feature:
performs a read-only fetch from an iCloud public database (CloudKit public database);
uploads nothing — not your ledger, accounts, currency preferences, or any identifier;
retrieves only public market rate figures, which contain no personal information;
always defers to rates you enter manually.
Rates are for bookkeeping conversion only and are not a quote for any transaction; see Terms of Service, Section 6.
4. Device permissions
The App requests the following permissions only when you use the corresponding feature. You may decline any of them; the rest of the App continues to work.
Permission
Purpose
Where the data goes
Camera
Photograph receipts and invoices, or use document scanning, to attach as records
Stored in the local attachment repository; synced to your iCloud private database along with other attachments if iCloud Sync is on
Photos / Files
Pick existing images or PDFs as attachments, or select a backup file or a spreadsheet to import
Same as above. The system hands only your chosen files to the App; it cannot browse what you did not select
Notifications
Receive the silent pushes iCloud Sync uses to fetch changes from your other devices or from shared-book members
Push payloads contain no ledger data
The App does not request location, contacts, microphone, calendar, health, or App Tracking Transparency permissions.
5. Diagnostics and crash data
To make problems diagnosable, the App records runtime logs and error information on the device, and receives system-provided crash and performance metrics (Apple MetricKit). About this data:
It stays on your device. It is rotated and pruned automatically by size and age, and you can inspect how much space it uses — and clear it — in Settings.
It is never sent to us automatically. We see it only if you deliberately export the diagnostic log in the App and send it to us, for example by email. You can review the contents before sending.
The logs record operation types, error codes, and technical context to locate faults. We take care to keep ledger details out of them, but we cannot rule out that fragments of text such as a note or account name appear in an error context. Please review a log before sending it if it might contain something you would rather not share.
Separately, if you have enabled "Share iPhone Analytics" in iOS Settings, Apple may provide us with aggregated, non-identifying crash and usage statistics through App Store Connect. That channel is controlled by Apple, and you can turn it off at any time under Settings › Privacy & Security › Analytics & Improvements.
6. Purchases and subscriptions
Payment is handled by Apple. We never see your payment information — not your card number, Apple ID password, or billing address.
The App receives transaction receipts from the App Store to determine whether your membership entitlement is valid. Those receipts are used for on-device feature unlocking.
Apple provides us with sales and subscription reports. These are aggregated and contain no information identifying an individual.
Import (files): You can import historical transactions from spreadsheets exported by other bookkeeping apps (such as Qianji's xlsx / CSV files). Files are parsed entirely on your device and are not uploaded anywhere.
Import (YNAB, direct): If you use YNAB, you can paste your own personal access token and the App reads your own budget data straight from YNAB’s API, never through a server of ours (we have none). It is a one-way read: nothing is written to YNAB, and no ledger content from this App is sent there. The token stays in this device’s memory and is cleared when the import ends — never written to disk, never synced to iCloud, never included in a backup.
Backup export: You can export a complete backup. Backups support AES encryption with a passphrase you set. Without a passphrase, the exported file is unencrypted and anyone who obtains it can read your ledger — store it carefully.
You choose the destination. Backups are handed to the system share sheet and go wherever you send them (Files, iCloud Drive, email, a third-party cloud service). Once a file leaves the App, the privacy policy of that destination applies, not this one.
We cannot recover a passphrase. It is used only for encryption and decryption, and is never stored or transmitted. A forgotten passphrase means that backup cannot be restored.
8. How AI features handle your data
Two features in the App are powered by AI, and both run on your device:
Ask your ledger (the assistant): you ask in plain language, and the App fetches just the part of your ledger that question needs — accounts and balances, entries, budgets, commitments falling due — and hands it to the model.
Receipt capture: you hand it a photo of a bill or receipt, the App recognizes the text in it and drafts an entry for you to confirm. It processes only the image you gave it.
Question
Answer
What is sent to the model
Only the part of your ledger the current question needs; for receipt capture, the single image you selected
What does the computing
The Apple Intelligence on-device model (Apple's Foundation Models framework) and the system's built-in text recognition (Vision), on your device
Where the data goes
It does not leave your device. It is not sent to the developer, nor to any external AI service provider
Is it used for training
No. Your ledger data is never used to train any model
Your permission is asked first. The first time you open the assistant, the App shows a full screen stating all of the above, and the conversation begins only after you confirm; until then the assistant reads nothing from your ledger. You can also switch the whole feature group off at any time under Settings › Privacy & Sync › Siri & Shortcuts, after which the assistant entry point disappears.
The two features have different device requirements: asking your ledger needs a device that supports Apple Intelligence with it turned on (not yet available in mainland China); receipt capture uses the system's own text recognizer and does not require Apple Intelligence. Where the requirements are not met, the corresponding entry point does not appear.
One exception, macOS only: Local MCP. The macOS version offers a switch called “Local MCP on Mac” that is off by default. Once you turn it on, AI clients running on that Mac (Claude Desktop or Claude Code, for example) can read ledger data and start entry drafts over a loopback connection, and that ledger content is sent, as part of the conversation, to whichever AI service provider the client is connected to (Anthropic, for example), from which point that provider’s privacy policy applies to it instead of this one. Turning it on is entirely your choice and can be undone at any time; even with it on, nothing is recorded until you confirm it inside the App.
The iOS and iPadOS versions do not include this channel — those versions contain no route that hands ledger data to an external AI service.
9. Third parties: what we don't do
To leave no ambiguity, here is what the App does not do:
No third-party analytics, telemetry, crash-reporting, or A/B testing SDKs are integrated;
No advertising is shown and no ad network is integrated;
No cookies, pixels, device fingerprinting, or cross-app tracking of any kind;
We do not sell, rent, or share your personal information for marketing purposes — including under the meanings of "sell" and "share" in California law;
We do not use your ledger data to train machine-learning models;
We do not provide your data to data brokers, credit bureaus, financial institutions, or any other third party.
By default there is exactly one external party involved: Apple, as the platform provider of iCloud storage, sharing, and payment services. Two further channels exist only if you start them yourself, and neither is on by default:
Importing from YNAB (Section 7): after you paste your own YNAB personal access token, the App reads your own budget data straight from YNAB’s API. It is a one-way read — nothing is written back to YNAB, and no ledger content from this App is sent there. The token stays in this device’s memory and is cleared when the import finishes.
Local MCP in the macOS version (Section 8): once enabled, ledger content reaches whichever AI service provider you connected. The iOS and iPadOS versions have no such channel.
Apart from those cases and legally compelled disclosure (below), there are no other recipients of data.
If we receive a lawful demand for data from an authority with jurisdiction, we can only produce information we actually hold. Because we do not hold your ledger data, such a demand has no effect on your ledger contents; requests concerning data stored in iCloud must be directed to Apple.
10. Retention and deletion
Because you hold the data, you decide how long it is kept. To delete it:
A single record: delete the transaction, account, or attachment in the App.
Everything: Settings offers "Clear All Data", which requires a confirmation code and destroys and rebuilds the current store.
The iCloud copy: choose "Delete iCloud Copy" when turning off iCloud Sync, or delete the app's data under Settings › Apple ID › iCloud › Manage Account Storage. Note that deleting the cloud copy also ends any book sharing you started, and members lose access.
The app: deleting the App from your device removes all local data in its sandbox. Any iCloud copy must be deleted separately, as above.
Backup files you exported elsewhere are yours to delete.
11. Your rights
Under applicable law — including China's Personal Information Protection Law (PIPL), the EU GDPR, and California's CCPA/CPRA — you have rights to be informed about, access, copy, correct, supplement, delete, and port your personal information, and to withdraw consent.
In this App, exercising those rights requires no request to us and no approval from us, because the data has been in your hands all along:
Right
How to exercise it
Access / copy
All data is visible in the App; export a backup for a complete copy
Portability
Export a backup file; transaction history can also be exported in a common spreadsheet format
Correction
Edit the record directly in the App
Deletion
See Section 10 above
Withdraw consent
Turn off iCloud Sync, stop sharing a book, or revoke camera and other permissions in system Settings
Object to automated decisions
The App performs no automated decision-making or profiling
If you believe your rights have not been honored, or you have questions about this policy, contact us using Section 16. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
12. Children
The App is designed for adults. It is not directed at children and does not knowingly collect children's personal information. If you are under 14, please use the App with the consent and guidance of a parent or guardian. Because the App transmits no personal information to us, we hold no age information about any user; a guardian who wishes to erase data from a device can do so directly using Section 10.
13. Security
Local data is isolated by the iOS sandbox; attachment files use system file protection and are encrypted while the device is locked.
iCloud transport and storage are encrypted by Apple; see Apple's documentation for details.
Backup files can be AES-encrypted with a passphrase you choose and we never store.
We hold none of your data, so there is no "we got breached" scenario for it.
That said, the security of your device underpins all of this. Set a passcode, enable biometric unlock, keep iOS updated, and be cautious with jailbroken devices and backup files of unknown origin. No security measure is absolute.
14. International transfers
We neither receive nor transmit your personal information, so there is no cross-border transfer initiated by us. If you enable iCloud Sync, the storage location is determined by Apple based on the country or region of your Apple ID (for example, iCloud services for mainland China are operated by GCBD). For those arrangements and safeguards, see the Apple Privacy Policy and the iCloud terms.
15. Changes to this policy
If the App's data practices change, we will update this page and revise the "Last updated" date at the top. For material changes — such as introducing any form of data upload — we will surface a prominent in-app notice and, where required, ask for your consent again. Previous versions of this page can be reviewed in this site's public repository.
16. Contact us
For any question about this policy or your data, email gwongsam@gmail.com.
Including your app version and iOS version helps us answer faster.
In case of any discrepancy between this English version and the Chinese version, the Chinese version prevails.