隐私政策

适用于 Keel(中文名「司元」)iOS 应用生效日期:2026 年 7 月 28 日最后更新:2026 年 9 月 10 日

一句话摘要

  • 我们没有服务器。本应用不会把你的记账数据发送到开发者控制的任何服务器——因为不存在这样的服务器。
  • 数据在你自己手里。默认只存在本机;只有你主动开启 iCloud 同步后,才会保存到你自己 Apple ID 名下的 iCloud 私有数据库
  • 没有广告、没有分析 SDK、没有追踪器、没有任何第三方代码。我们不收集、不出售、不共享你的个人信息。
  • AI 功能全部在你的设备上运行。问账本与截图记账用的是你设备上的 Apple Intelligence 设备端模型与系统文字识别,账本数据不会发送给我们,也不会发送给任何外部人工智能服务提供方(唯一例外是 macOS 版本里一个默认关闭的「本地 MCP」开关,见第 8 条)。
  • 本应用不连接你的银行、支付账户或征信机构,不会自动抓取任何账单。所有数据都由你手动录入或主动导入。

1. 谁在提供这款应用

Keel(中文名「司元」,下称「本应用」)由个人开发者 gwongsam(下称「我们」)开发与发行。

本政策说明本应用如何处理你的信息。请注意一个贯穿全文的前提:本应用不设任何后端服务器,你的账本内容不会到达我们手中。因此本政策的绝大部分内容,实际是在说明数据如何在你自己的设备你自己的 iCloud 账户之间流动。

2. 应用处理哪些数据

以下数据由你在使用过程中产生,保存在你的设备上:

类别具体内容
账本数据账本、流水记录(收入、支出、转账、资产买卖、还款、调整等)、金额、币种、日期、备注
账户数据你自建的账户名称、类型与余额;信用卡账单周期、贷款借据与还款计划、先买后付订单、储值与预付账户
分类与组织收支分类、标签、项目、往来对象(由你自行命名的人或机构)
附件你主动添加的小票、发票、单据的图片与 PDF 文件
设置与偏好语言、显示选项、默认账本、预算设置、报表分组方案等应用内设置
汇率你手动录入的汇率,以及从公开行情获取的汇率缓存
诊断日志运行日志、错误记录,以及系统提供的崩溃与性能指标
购买凭据来自 App Store 的交易凭据与会员权益状态

本应用不索取、不收集、不处理以下信息:真实姓名、身份证件号码、手机号码、电子邮箱、银行卡号、银行账户或支付平台的登录凭据、通讯录、位置信息、健康数据、广告标识符(IDFA)、设备指纹。

需要说明的是:账本本身的性质决定了它可能包含敏感的财务信息。正因如此,本应用的设计原则是让这些数据尽可能不离开你的掌控范围——不上传我们的服务器,不交给第三方分析工具。

3. 数据存放在哪里

3.1 设备本地(默认状态)

安装后默认情况下,上述全部数据只保存在本机:账本数据库位于应用沙盒目录,附件文件保存在应用的文件仓中并启用了系统文件保护(设备锁屏时文件处于加密不可读状态)。这些数据受 iOS 沙盒机制保护,其他应用无法读取。

如果你从未开启 iCloud 同步,也从未导出备份,那么你的账本数据从不离开这台设备

3.2 iCloud 同步(默认关闭,需你手动开启)

你可以在「设置 › 隐私与同步」中开启 iCloud 同步。开启后:

3.3 共享账本

你可以把某个账本共享给他人协作。这是由你发起的主动行为

3.4 在线汇率

本应用可以获取多币种折算所需的参考汇率。该功能:

汇率仅供记账折算参考,不构成任何交易报价,另见服务条款第 6 条

4. 设备权限

本应用只在你使用对应功能时请求以下权限,全部可以拒绝,拒绝后其余功能照常使用:

权限用途数据去向
相机拍摄小票与发票照片、使用文稿扫描功能,作为凭证附到记录上照片保存在本机附件仓;开启 iCloud 同步后随附件一同同步至你的 iCloud 私有数据库
照片 / 文件从相册或「文件」中选择已有图片、PDF 作为附件,或选择备份文件、待导入的表格文件同上;你选择的文件由系统直接交给应用,应用不会浏览你未选择的内容
通知接收 iCloud 同步所需的静默推送,以便及时拉取其他设备或共享成员的变更推送内容不含账本数据

本应用不请求定位、通讯录、麦克风、日历、健康或跟踪(App Tracking Transparency)权限。

5. 诊断日志与崩溃数据

为了排查问题,本应用会在设备上记录运行日志与错误信息,并接收系统提供的崩溃与性能指标(Apple MetricKit)。关于这些数据:

此外,如果你在 iOS 系统设置中开启了「共享 iPhone 分析」,Apple 可能会通过 App Store Connect 向我们提供聚合且不含身份标识的崩溃与使用统计。这项由 Apple 控制,你可以在系统设置的「隐私与安全性 › 分析与改进」中随时关闭。

6. 购买与订阅

本应用的会员功能通过 Apple 的 App Store 内购提供:

购买相关的商业条款见服务条款第 3 条

7. 导入、导出与备份

8. AI 功能如何处理你的数据

本应用有两项由人工智能承担的功能,都在你的设备上完成

问题回答
送进模型的是什么只有当次提问所需的那部分账本数据;截图记账则是你选定的那一张图片
谁在运算你设备上的 Apple Intelligence 设备端模型(Apple 的 Foundation Models 框架)与系统内置的文字识别(Vision)
数据去了哪里没有离开你的设备。不发送给开发者,也不发送给任何外部人工智能服务提供方
会不会用于训练不会。你的账本数据不会被用于训练任何模型

使用之前会先征得你的同意。首次打开助手时,应用会先用一整屏说明上述内容,你确认之后才进入对话;在此之前助手不会读取任何账本数据。你也可以随时在「设置 › 隐私与同步 › Siri 与快捷指令」里关闭这一整组功能,关闭后助手入口不再出现。

这两项功能对设备的要求不同:问账本需要你的设备支持并已开启 Apple Intelligence(该功能在中国大陆暂未提供);截图记账用的是系统自带的文字识别,不要求 Apple Intelligence。条件不满足时,对应的入口不会出现。

仅 macOS 版本存在的例外:本地 MCP。macOS 版本提供一个默认关闭的开关「Mac 本地 MCP」。开启后,你在这台 Mac 上运行的人工智能客户端(例如 Claude Desktop、Claude Code)可以经由本机回环连接读取账本数据、发起记账草稿;这些账本内容会随对话一并发送给该客户端所连接的人工智能服务提供方(例如 Anthropic),并自那一刻起适用该提供方的隐私政策,不再受本政策约束。是否开启完全由你决定,随时可以关掉;即便开着,任何一笔账仍要你在应用内确认之后才会落账。

iOS 与 iPadOS 版本不包含这条通道——那两个版本里没有任何把账本数据交给外部人工智能服务的途径。

9. 第三方:我们不做的事

为免歧义,明确列出本应用不存在的行为:

默认状态下,本应用涉及的外部主体只有一个:Apple——它作为平台方提供 iCloud 存储、共享机制与支付服务。另有两条通道只有你主动发起才成立,默认都不存在:

除上述情形与法律强制要求外(见下),不存在其他数据接收方。

如果我们收到具有法定管辖权的机关依法提出的数据要求,我们只能提供我们实际持有的信息。由于我们不持有你的账本数据,这类要求对你的账本内容不产生影响;针对存储在 iCloud 中的数据,应向 Apple 提出。

10. 数据保留与删除

因为数据由你自己保管,保留期限也由你决定。删除方式:

你自行导出到设备其他位置或第三方服务的备份文件,需要你自己删除。

11. 你的权利

在适用的法律(包括中华人民共和国《个人信息保护法》、欧盟 GDPR、加州 CCPA/CPRA 等)下,你对自己的个人信息享有知情、查阅、复制、更正、补充、删除、转移以及撤回同意等权利。

在本应用中,行使这些权利不需要联系我们,也不需要等待我们审批——因为数据一直在你手里:

权利怎么行使
查阅 / 复制数据在应用内全程可见;导出备份即可获得完整副本
可携带(数据转移)导出备份文件;历史流水也可导出为通用表格格式
更正 / 补充直接在应用内编辑对应记录
删除见上文第 10 条
撤回同意关闭 iCloud 同步、停止账本共享、在系统设置中收回相机等权限
拒绝自动化决策本应用不做任何自动化决策或用户画像

如果你认为你的权利未能得到落实,或对本政策有任何疑问,可以通过第 16 条的方式联系我们。我们会在收到后 30 日内答复。你也有权向所在地的个人信息保护监管机构投诉。

12. 未成年人

本应用面向成年用户设计,不针对儿童,也不会有意收集儿童的个人信息。若你未满 14 周岁,请在监护人的同意与指导下使用本应用。由于本应用不向我们回传任何个人信息,我们不掌握任何用户的年龄信息;如监护人发现相关情况并希望清除设备上的数据,可按第 10 条自行删除。

13. 数据安全

与此同时请注意:设备本身的安全是这一切的前提。请为设备设置锁屏密码、开启生物识别、及时更新系统,并谨慎对待越狱设备与来路不明的备份文件。没有任何技术措施能保证绝对安全。

14. 跨境传输

我们自身不接收、不传输你的个人信息,因此不存在由我们发起的跨境传输。若你开启 iCloud 同步,数据的存储位置由 Apple 依据你的 Apple ID 所属国家或地区决定(例如中国大陆的 iCloud 服务由云上贵州运营)。相关安排与保障措施请参阅 Apple 隐私政策及 iCloud 条款。

15. 政策变更

如果本应用的数据处理方式发生变化,我们会更新本页面并修改顶部的「最后更新」日期。涉及重大变更(例如引入任何形式的数据上传)时,我们会在应用内以显著方式提示,并在需要时重新征求你的同意。本页面的历史版本可在本站的公开代码仓库中查阅。

16. 联系我们

关于本政策或你的数据的任何问题,请发送邮件至:gwongsam@gmail.com

请在邮件中说明你使用的应用版本与设备系统版本,这有助于我们更快答复。


本政策的中文版本与英文版本如有歧义,以中文版本为准。

Privacy Policy

For the Keel iOS app (Chinese name: 司元)Effective: July 28, 2026Last updated: September 10, 2026

Summary

  • We run no servers. The app does not send your ledger data to any server we control — no such server exists.
  • Your data stays with you. By default it lives only on your device. It reaches the iCloud private database of your own Apple ID only after you deliberately turn on iCloud Sync.
  • No ads, no analytics SDKs, no trackers, no third-party code of any kind. We do not collect, sell, or share your personal information.
  • The AI features run on your device. Asking your ledger and receipt capture use the Apple Intelligence on-device model and the system text recognizer; your ledger data is not sent to us, nor to any external AI service provider (the one exception is a Local MCP switch in the macOS version, off by default — see Section 8).
  • The app never connects to your bank, payment accounts, or credit bureaus. It fetches no statements. Every record is entered or imported by you.

1. Who provides this app

Keel (Chinese name 司元, the "App") is developed and published by gwongsam, an independent developer ("we", "us").

This policy explains how the App handles your information. One premise runs through all of it: the App has no backend server of ours, and your ledger contents never reach us. Most of what follows therefore describes how data moves between your own device and your own iCloud account.

2. What data the app handles

The following data is created by you as you use the App, and is stored on your device:

CategoryContents
Ledger dataBooks, transactions (income, expense, transfer, asset trades, repayments, adjustments), amounts, currencies, dates, notes
Account dataAccount names, types, and balances you create; credit-card billing cycles, loan drawdowns and repayment schedules, buy-now-pay-later orders, prepaid and stored-value accounts
OrganizationCategories, tags, projects, and counterparties (people or institutions you name yourself)
AttachmentsImages and PDFs of receipts, invoices, and documents that you add
SettingsLanguage, display options, default book, budgets, statement grouping schemes, and other in-app preferences
Exchange ratesRates you enter manually, plus a cache of publicly available market rates
DiagnosticsRuntime logs, error records, and system-provided crash and performance metrics
Purchase receiptsApp Store transaction receipts and membership entitlement status

The App does not request, collect, or process your legal name, government ID numbers, phone number, email address, card numbers, banking or payment credentials, contacts, location, health data, advertising identifiers (IDFA), or device fingerprints.

A ledger by its nature can contain sensitive financial information. That is precisely why the App is designed so that this data stays within your control — never uploaded to our servers, never handed to third-party analytics.

3. Where your data lives

3.1 On your device (the default)

Out of the box, all of the above is stored locally: the ledger database lives in the app's sandbox container, and attachment files are stored in the app's file repository with system file protection enabled (encrypted and unreadable while the device is locked). iOS sandboxing prevents other apps from reading any of it.

If you never enable iCloud Sync and never export a backup, your ledger data never leaves that device.

3.2 iCloud Sync (off by default; you must turn it on)

You can enable iCloud Sync under Settings › Privacy & Sync. Once enabled:

3.3 Shared books

You can share a book with other people for collaboration. This is always initiated by you:

3.4 Online exchange rates

The App can fetch reference exchange rates for multi-currency conversion. This feature:

Rates are for bookkeeping conversion only and are not a quote for any transaction; see Terms of Service, Section 6.

4. Device permissions

The App requests the following permissions only when you use the corresponding feature. You may decline any of them; the rest of the App continues to work.

PermissionPurposeWhere the data goes
CameraPhotograph receipts and invoices, or use document scanning, to attach as recordsStored in the local attachment repository; synced to your iCloud private database along with other attachments if iCloud Sync is on
Photos / FilesPick existing images or PDFs as attachments, or select a backup file or a spreadsheet to importSame as above. The system hands only your chosen files to the App; it cannot browse what you did not select
NotificationsReceive the silent pushes iCloud Sync uses to fetch changes from your other devices or from shared-book membersPush payloads contain no ledger data

The App does not request location, contacts, microphone, calendar, health, or App Tracking Transparency permissions.

5. Diagnostics and crash data

To make problems diagnosable, the App records runtime logs and error information on the device, and receives system-provided crash and performance metrics (Apple MetricKit). About this data:

Separately, if you have enabled "Share iPhone Analytics" in iOS Settings, Apple may provide us with aggregated, non-identifying crash and usage statistics through App Store Connect. That channel is controlled by Apple, and you can turn it off at any time under Settings › Privacy & Security › Analytics & Improvements.

6. Purchases and subscriptions

The commercial terms for purchases are in Terms of Service, Section 3.

7. Import, export, and backups

8. How AI features handle your data

Two features in the App are powered by AI, and both run on your device:

QuestionAnswer
What is sent to the modelOnly the part of your ledger the current question needs; for receipt capture, the single image you selected
What does the computingThe Apple Intelligence on-device model (Apple's Foundation Models framework) and the system's built-in text recognition (Vision), on your device
Where the data goesIt does not leave your device. It is not sent to the developer, nor to any external AI service provider
Is it used for trainingNo. Your ledger data is never used to train any model

Your permission is asked first. The first time you open the assistant, the App shows a full screen stating all of the above, and the conversation begins only after you confirm; until then the assistant reads nothing from your ledger. You can also switch the whole feature group off at any time under Settings › Privacy & Sync › Siri & Shortcuts, after which the assistant entry point disappears.

The two features have different device requirements: asking your ledger needs a device that supports Apple Intelligence with it turned on (not yet available in mainland China); receipt capture uses the system's own text recognizer and does not require Apple Intelligence. Where the requirements are not met, the corresponding entry point does not appear.

One exception, macOS only: Local MCP. The macOS version offers a switch called “Local MCP on Mac” that is off by default. Once you turn it on, AI clients running on that Mac (Claude Desktop or Claude Code, for example) can read ledger data and start entry drafts over a loopback connection, and that ledger content is sent, as part of the conversation, to whichever AI service provider the client is connected to (Anthropic, for example), from which point that provider’s privacy policy applies to it instead of this one. Turning it on is entirely your choice and can be undone at any time; even with it on, nothing is recorded until you confirm it inside the App.

The iOS and iPadOS versions do not include this channel — those versions contain no route that hands ledger data to an external AI service.

9. Third parties: what we don't do

To leave no ambiguity, here is what the App does not do:

By default there is exactly one external party involved: Apple, as the platform provider of iCloud storage, sharing, and payment services. Two further channels exist only if you start them yourself, and neither is on by default:

Apart from those cases and legally compelled disclosure (below), there are no other recipients of data.

If we receive a lawful demand for data from an authority with jurisdiction, we can only produce information we actually hold. Because we do not hold your ledger data, such a demand has no effect on your ledger contents; requests concerning data stored in iCloud must be directed to Apple.

10. Retention and deletion

Because you hold the data, you decide how long it is kept. To delete it:

Backup files you exported elsewhere are yours to delete.

11. Your rights

Under applicable law — including China's Personal Information Protection Law (PIPL), the EU GDPR, and California's CCPA/CPRA — you have rights to be informed about, access, copy, correct, supplement, delete, and port your personal information, and to withdraw consent.

In this App, exercising those rights requires no request to us and no approval from us, because the data has been in your hands all along:

RightHow to exercise it
Access / copyAll data is visible in the App; export a backup for a complete copy
PortabilityExport a backup file; transaction history can also be exported in a common spreadsheet format
CorrectionEdit the record directly in the App
DeletionSee Section 10 above
Withdraw consentTurn off iCloud Sync, stop sharing a book, or revoke camera and other permissions in system Settings
Object to automated decisionsThe App performs no automated decision-making or profiling

If you believe your rights have not been honored, or you have questions about this policy, contact us using Section 16. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

12. Children

The App is designed for adults. It is not directed at children and does not knowingly collect children's personal information. If you are under 14, please use the App with the consent and guidance of a parent or guardian. Because the App transmits no personal information to us, we hold no age information about any user; a guardian who wishes to erase data from a device can do so directly using Section 10.

13. Security

That said, the security of your device underpins all of this. Set a passcode, enable biometric unlock, keep iOS updated, and be cautious with jailbroken devices and backup files of unknown origin. No security measure is absolute.

14. International transfers

We neither receive nor transmit your personal information, so there is no cross-border transfer initiated by us. If you enable iCloud Sync, the storage location is determined by Apple based on the country or region of your Apple ID (for example, iCloud services for mainland China are operated by GCBD). For those arrangements and safeguards, see the Apple Privacy Policy and the iCloud terms.

15. Changes to this policy

If the App's data practices change, we will update this page and revise the "Last updated" date at the top. For material changes — such as introducing any form of data upload — we will surface a prominent in-app notice and, where required, ask for your consent again. Previous versions of this page can be reviewed in this site's public repository.

16. Contact us

For any question about this policy or your data, email gwongsam@gmail.com.

Including your app version and iOS version helps us answer faster.


In case of any discrepancy between this English version and the Chinese version, the Chinese version prevails.