餘裕 · PICO LEDGER

隱私權政策 · Privacy Policy · プライバシーポリシー

隱私權政策(繁體中文)

最後更新:2026 年 9 月 4 日

「餘裕 · PICO LEDGER」(套件名稱 com.fish.picoledger,以下稱「本 App」) 是一款個人記帳與預算工具。本 App 的核心設計是:不開啟雲端同步時,你的帳本 完全留在你自己的裝置上;開啟雲端同步後,帳本內容在離開裝置之前就已加密, 我們的伺服器只存得到我們自己也無法解讀的密文。

一、一分鐘摘要

  • 不註冊帳號也能完整使用,這種情況下本 App 不會把你的任何帳本資料傳出裝置。
  • 註冊並開啟雲端同步後,我們只會收到:你的電子郵件、密碼的雜湊值,以及加密後的帳本密文。
  • 我們(開發者)無法解讀你的交易明細、金額、備註、貸款或存錢目標——技術上做不到,因為解密金鑰從未離開你的裝置。
  • 本 App 會顯示 Google AdMob 廣告;廣告 SDK 會依 Google 的政策處理裝置與廣告識別碼。購買「去廣告」後,本 App 連廣告 SDK 都不會再載入。
  • 語音記帳是選用功能:使用時,錄音與逐字稿會以明文送到我們的伺服器並轉送 Groq 進行辨識,這一段無法端對端加密。我們不保存錄音、逐字稿或對話內容,且一定要你按確認才會寫進帳本——詳見第七節。
  • 你可以隨時在 App 內「設定 → 刪除帳號」自行刪除帳號與伺服器上的加密帳本,不需要來信申請。

二、不使用雲端同步時(預設狀態)

本 App 安裝後預設就是純本機模式:不需要註冊、不需要登入。你的交易紀錄、自訂分類、 儲蓄目標、貸款、固定收支、語系與主題設定,全部只寫在你這台裝置的 App 儲存空間裡。 本 App 不會把這些內容上傳到任何伺服器,我們也無從得知你是否安裝了它、記了幾筆帳。

解除安裝本 App 會一併刪除這些本機資料。請注意:純本機模式下沒有任何雲端備份, 換手機或清除 App 資料前請自行匯出或先啟用雲端同步。

三、雲端同步與端對端加密

啟用雲端同步後,你的帳本資料在離開你的裝置「之前」就已經加密——加密與解密都只發生在你的 手機或瀏覽器上,我們的伺服器只儲存加密後、我們自己也無法解讀的密文。

技術上是怎麼做到的:你登入用的密碼,會在你的裝置上被用來產生一把只存在於裝置 本機、從未被傳送出去的「加密金鑰」。伺服器收到的登入密碼,經過一層與這把加密金鑰完全無關的 轉換——即使伺服器遭入侵,也無法從中還原出你的加密金鑰。你的交易紀錄、分類、備註、貸款、 存錢目標等所有帳本內容,一律先在本機以 AES-256-GCM 加密才會上傳;我們資料庫裡看到的只是一段 無法解讀的亂碼。這把金鑰存放在系統提供的硬體保護金鑰庫中——Android 上是 Android Keystore,iOS 上是 Keychain。

這個保護的實際範圍(請容我們誠實說明限制):

四、我們在伺服器上實際儲存的資料

只有在你註冊帳號之後才會有下列資料。伺服器位於我們自行維運的主機 (網域 picoledger.fish-zero.com),流量經由 Cloudflare 傳輸。

資料用途我們讀得懂嗎
電子郵件地址帳號識別、登入是
密碼的雜湊值驗證登入(不儲存原始密碼)否(單向雜湊)
登入工作階段(session token)維持登入狀態是
帳本密文與其初始化向量(IV)雲端同步否
密文大小、版本號、更新時間衝突偵測、容量顯示是
以密碼包覆的加密金鑰(wrapped DEK)讓你在新裝置輸入密碼後解開自己的帳本否(沒有你的密碼就解不開)
復原金鑰的驗證雜湊、以復原金鑰包覆的加密金鑰忘記密碼時的復原流程否
購買紀錄:商品代號、平台、購買憑證(token)、驗證時間、是否有效解鎖已購買的功能、恢復購買、退款處理是

此外,如同任何網路服務,伺服器與 Cloudflare 會在一般連線紀錄中處理你的 IP 位址、 時間與請求路徑,用途僅限於維持服務運作與防止濫用。我們不會用這些紀錄建立使用者輪廓, 也不會將其與你的帳本內容關聯(我們本來就讀不到帳本內容)。

我們不做的事:不販售個人資料、不與廣告商分享你的帳本或電子郵件、 沒有安裝任何行為分析或追蹤 SDK(本 App 沒有 Firebase Analytics、沒有第三方統計工具)。

五、廣告(Google AdMob)

本 App 免費提供,並以 Google AdMob 廣告支撐開發成本。廣告出現在兩個位置:畫面上方的 橫幅廣告,以及你按下「轉出 PDF」年度報告時的一次全螢幕插頁廣告。

廣告由 Google 提供與投放。Google 及其合作夥伴可能會收集或使用裝置的廣告識別碼 (Advertising ID)、裝置與 App 的基本資訊,以及由 IP 位址推斷的粗略位置,用於投放與衡量 廣告成效。這些資料由 Google 依其自身政策處理,本 App 不會把你的帳本內容、電子郵件 或任何帳號資訊提供給廣告服務。

購買「去廣告」或「終身解鎖」之後,本 App 不會再初始化廣告 SDK——不是把廣告藏起來, 而是根本不載入。

六、購買與付款

本 App 提供兩項一次性購買(非訂閱):「去廣告」與「終身解鎖」(去廣告+雲端同步)。 付款完全由你所在平台的官方付款機制處理——iOS 是 Apple 的 App 內購買 (App Store),Android 是 Google Play 帳單服務;本 App 與我們的伺服器 都不會接觸到你的信用卡號、帳單地址或任何付款工具資料。

為了確認一筆購買是真的且屬於你,我們會把平台發出的購買憑證(iOS 是 App Store 簽章的交易 憑證,Android 是 Google Play 的 purchase token)送到我們的伺服器,由伺服器向該平台驗證,並記錄 第四節表格中列出的購買紀錄。送給平台的帳號識別碼是經過雜湊處理的,不是你的電子郵件 本身。你可以隨時在 App 內使用「恢復購買」,在同一個 Apple 帳號或 Google 帳號的其他裝置上取回 已購買的權益。

七、語音記帳(選用功能)

這是本 App 唯一無法端對端加密的功能,請讀完這一節再決定要不要使用。 語音記帳需要你主動點擊麥克風按鈕才會啟動,第一次使用前會再次向你說明並徵求同意。 你不使用它,本節就完全不適用於你,本 App 也不會錄下任何聲音。

八、其他第三方服務

九、權限

在 Android 上,本 App 宣告兩類權限:網際網路存取(INTERNET),用於雲端同步、 廣告與購買驗證;以及錄音(RECORD_AUDIO)與音訊設定(MODIFY_AUDIO_SETTINGS), 僅供第七節的語音記帳使用。錄音權限採「用到才問」:只有在你第一次點擊麥克風按鈕時, 系統才會跳出授權詢問;你拒絕或從不使用語音記帳,本 App 就永遠不會錄音。iOS 沒有對應的 「網路權限宣告」機制,App 本來就能連網,麥克風同樣是第一次使用語音記帳時才由系統詢問; 廣告個人化牽涉的追蹤授權請求已列在上一節。兩個平台上,本 App 都不要求 存取你的相機、通訊錄、簡訊、通話紀錄、精確位置或相簿,也不要求額外的儲存空間權限 (轉出 PDF 由系統列印服務處理)。

十、兒童

本 App 並非以 13 歲以下兒童為對象設計,我們也不會刻意向兒童收集個人資料。 若你認為有兒童在未經監護人同意下向我們提供了資料,請來信告知,我們會儘速刪除。

十一、資料保留與刪除

十二、政策變更與聯絡方式

本政策若有修訂,會更新本頁最上方的日期並在此公告。

對本政策、你的資料,或想行使查詢/更正/刪除等權利,請來信: fish@coss.com.tw

Privacy Policy (English)

Last updated: 4 September 2026

“餘裕 · PICO LEDGER” (package name com.fish.picoledger, the “App”) is a personal budgeting and expense-tracking tool. Its core design: with cloud sync off, your ledger never leaves your device; with cloud sync on, your ledger is encrypted before it leaves the device, and our server only ever stores ciphertext that we ourselves cannot read.

1. One-minute summary

  • The App is fully usable without an account. In that mode none of your ledger data leaves the device.
  • If you sign up and enable cloud sync, we receive only your email address, a hash of your password, and encrypted ledger ciphertext.
  • We (the developer) cannot read your transactions, amounts, notes, loans, or savings goals. Not “we promise not to” — we technically cannot, because the decryption key never leaves your device.
  • The App shows Google AdMob ads. If you buy “remove ads”, the App stops loading the ad SDK entirely.
  • Voice entry is optional. When you use it, the recording and its transcript are sent unencrypted to our server and forwarded to Groq for recognition — that part cannot be end-to-end encrypted. We keep no audio, transcript, or conversation, and nothing is written to your ledger until you confirm it. See section 7.
  • You can delete your account and its encrypted ledger yourself, in-app, under Settings → Delete account. No email request needed.

2. When cloud sync is off (the default)

After installation the App is local-only: no sign-up, no sign-in. Your transactions, custom categories, savings goals, loans, recurring items, language and theme settings are written only to this device’s app storage. Nothing is uploaded, and we have no way of knowing that you installed the App or how many entries you keep.

Uninstalling the App deletes this local data. Note that local-only mode has no cloud backup — export your data or enable cloud sync before switching phones or clearing app data.

3. Cloud sync and end-to-end encryption

When cloud sync is enabled, your ledger is encrypted before it leaves your device. Encryption and decryption happen only on your phone or in your browser; our server stores only ciphertext that we cannot read.

How this works technically: your sign-in password is used, on your device, to derive an encryption key that exists only locally and is never transmitted. The password value that reaches the server goes through a separate transformation that is unrelated to that encryption key — even if the server were breached, the encryption key could not be recovered from it. All ledger content is encrypted locally with AES-256-GCM before upload; our database holds an opaque blob. The key is held in the system’s hardware-backed keystore — Android Keystore on Android, the Keychain on iOS.

The honest limits of this protection:

4. What we actually store on the server

None of this exists until you create an account. The server is self-hosted by us (domain picoledger.fish-zero.com) and traffic is carried through Cloudflare.

DataPurposeReadable by us?
Email addressAccount identity, sign-inYes
Password hashSign-in verification (the password itself is not stored)No (one-way hash)
Session tokenKeeping you signed inYes
Ledger ciphertext and its IVCloud syncNo
Ciphertext size, version number, updated-at timeConflict detection, storage displayYes
Password-wrapped encryption keyLets you unlock your own ledger on a new deviceNo (useless without your password)
Recovery-key verifier hash and recovery-key-wrapped encryption keyThe forgotten-password recovery flowNo
Purchase records: product id, platform, purchase token, verification time, validityUnlocking what you bought, restoring purchases, refundsYes

As with any online service, the server and Cloudflare process your IP address, timestamps and request paths in ordinary connection logs, solely to operate the service and prevent abuse. We do not build user profiles from those logs, and they are not linked to ledger content (which we cannot read in the first place).

What we do not do: we do not sell personal data, do not share your ledger or email with advertisers, and ship no behavioural analytics or tracking SDK (no Firebase Analytics, no third-party statistics library).

5. Advertising (Google AdMob)

The App is free and supported by Google AdMob ads in two places: a banner at the top of the screen, and a single full-screen interstitial when you export the annual PDF report.

Ads are served by Google. Google and its partners may collect or use the device advertising ID, basic device and app information, and coarse location inferred from your IP address, to serve and measure ads. That data is handled by Google under its own policies. The App never passes your ledger content, email address, or any account information to the ad service.

After buying “remove ads” or the lifetime unlock, the App no longer initialises the ad SDK — the ads are not merely hidden; the SDK is never loaded.

6. Purchases and payment

The App offers two one-time purchases (not subscriptions): “remove ads” and “lifetime unlock” (remove ads plus cloud sync). Payment is handled entirely by your platform’s own payment system — Apple In-App Purchase (the App Store) on iOS, Google Play Billing on Android. Neither the App nor our server ever sees your card number, billing address, or any payment instrument data.

To confirm a purchase is genuine and yours, the receipt the platform issues (an App Store signed transaction on iOS, a Google Play purchase token on Android) is sent to our server, verified against that platform, and recorded as described in section 4. The account identifier we hand to the platform is a hashed value, not your email address. You can use “Restore purchases” in the App at any time to recover entitlements on another device signed in to the same Apple Account or Google account.

7. Voice entry (optional feature)

This is the one feature in the App that cannot be end-to-end encrypted. Please read this section before using it. Voice entry only starts when you tap the microphone button, and the App explains this and asks for your consent before the first recording. If you never use it, this section does not apply to you and the App records no audio at all.

8. Other third-party services

9. Permissions

On Android, the App declares two kinds of permission: INTERNET, used for cloud sync, ads, and purchase verification; and RECORD_AUDIO / MODIFY_AUDIO_SETTINGS, used only for the voice entry feature described in section 7. The microphone is requested at the point of use: the system prompt appears the first time you tap the microphone button, and if you decline it — or simply never use voice entry — the App never records anything. iOS has no equivalent network-access permission to declare, and the microphone there is likewise requested by the system the first time you use voice entry; the tracking-authorization prompt tied to ad personalisation is covered in the previous section. On both platforms, the App never requests access to your camera, contacts, SMS, call logs, precise location, or photo library, and it does not request extra storage permission (PDF export is handled by the system print service).

10. Children

The App is not directed at children under 13, and we do not knowingly collect personal data from children. If you believe a child has provided us with data without a guardian’s consent, please contact us and we will delete it promptly.

11. Retention and deletion

12. Changes and contact

If this policy changes, the date at the top of this page is updated and the change announced here.

Questions about this policy or your data, or to exercise access / correction / deletion rights: fish@coss.com.tw

プライバシーポリシー(日本語)

最終更新日:2026 年 9 月 4 日

「餘裕 · PICO LEDGER」(パッケージ名 com.fish.picoledger、以下「本アプリ」)は、 個人向けの家計簿・予算管理ツールです。設計の中心は次の二点です。クラウド同期を使わない場合、 帳簿データは端末の外に出ません。クラウド同期を使う場合も、帳簿の内容は端末を離れる前に 暗号化され、当方のサーバーには開発者自身にも解読できない暗号文しか保存されません。

1. 要約

  • アカウント登録なしで全機能を利用できます。その場合、帳簿データが端末外に送信されることはありません。
  • 登録してクラウド同期を有効にした場合、当方が受け取るのはメールアドレス、パスワードのハッシュ値、そして暗号化された帳簿データのみです。
  • 開発者は取引明細・金額・メモ・ローン・貯蓄目標を解読できません。「しない」ではなく、復号鍵が端末から出ないため技術的にできません。
  • 本アプリは Google AdMob の広告を表示します。「広告非表示」を購入すると、広告 SDK 自体を読み込まなくなります。
  • 音声入力は任意機能です。利用時は録音と文字起こしが暗号化されないまま当方のサーバーへ送られ、認識のため Groq へ転送されます。この部分はエンドツーエンド暗号化の対象外です(帳簿そのものは引き続き暗号化されます)。音声・文字起こし・会話は保存せず、確認するまで帳簿には記録されません。詳しくは第 7 節をご覧ください。
  • アカウントとサーバー上の暗号化帳簿は、アプリ内の「設定 → アカウント削除」からご自身で削除できます。メールでの申請は不要です。

2. クラウド同期を使わない場合(既定)

インストール直後はローカル専用モードで、登録もログインも不要です。取引記録、カスタム分類、 貯蓄目標、ローン、定期収支、言語・テーマ設定はこの端末のアプリ領域にのみ保存されます。 アップロードは行われず、当方は利用の有無や記録件数を知ることができません。

アンインストールするとこれらのローカルデータも削除されます。ローカル専用モードにはクラウド バックアップがありませんので、機種変更やアプリデータ消去の前にエクスポートするか、クラウド同期を 有効にしてください。

3. クラウド同期とエンドツーエンド暗号化

クラウド同期を有効にすると、帳簿データは端末を離れる「前」に暗号化されます。暗号化と復号は お使いのスマートフォンまたはブラウザー上でのみ行われ、サーバーには解読できない暗号文だけが 保存されます。

技術的な仕組み:ログイン用パスワードは端末上で「暗号鍵」の生成に使われ、この鍵は端末内に のみ存在し、送信されることはありません。サーバーに届くパスワードは、この暗号鍵とはまったく無関係な 変換を経ています。仮にサーバーが侵害されても、そこから暗号鍵を復元することはできません。取引記録、 分類、メモ、ローン、貯蓄目標などの帳簿内容はすべて、端末上で AES-256-GCM により暗号化されてから アップロードされます。この鍵はシステムが提供するハードウェア保護のキーストアに保管されます—— Android では Android Keystore、iOS では Keychain です。

この保護の範囲(限界も正直に記します):

4. サーバーに実際に保存される情報

以下はアカウント作成後にのみ存在します。サーバーは当方が自身で運用しており (ドメイン picoledger.fish-zero.com)、通信は Cloudflare を経由します。

データ目的開発者が読めるか
メールアドレスアカウント識別・ログインはい
パスワードのハッシュ値ログイン検証(パスワード自体は保存しません)いいえ(一方向ハッシュ)
セッショントークンログイン状態の維持はい
帳簿の暗号文と初期化ベクトル(IV)クラウド同期いいえ
暗号文のサイズ、バージョン番号、更新日時競合検出、容量表示はい
パスワードで包んだ暗号鍵新しい端末で自分の帳簿を復号するためいいえ(パスワードなしでは開けません)
リカバリーキーの検証ハッシュ、リカバリーキーで包んだ暗号鍵パスワード忘れ時の復旧いいえ
購入記録:商品 ID、プラットフォーム、購入トークン、検証日時、有効性購入済み機能の解除、購入の復元、返金処理はい

また、一般的なオンラインサービスと同様に、サーバーおよび Cloudflare は接続ログとして IP アドレス、 日時、リクエストパスを処理します。用途はサービスの運用と不正利用防止に限られます。これらのログから 利用者プロファイルを作成することはなく、帳簿の内容と関連付けることもありません(そもそも内容を 読めません)。

行わないこと:個人データの販売、帳簿やメールアドレスの広告事業者への提供、行動分析・ トラッキング SDK の搭載(Firebase Analytics も第三者統計ツールも使用していません)。

5. 広告(Google AdMob)

本アプリは無料で提供され、Google AdMob の広告により開発費を賄っています。広告は画面上部の バナーと、年間レポートを「PDF に出力」する際の全画面インタースティシャル広告の 2 か所です。

広告は Google により配信されます。Google およびそのパートナーは、広告 ID、端末とアプリの基本情報、 IP アドレスから推定されるおおよその位置情報を、広告の配信・効果測定のために収集・利用する場合が あります。これらは Google のポリシーに基づいて処理されます。本アプリが帳簿の内容、メールアドレス、 アカウント情報を広告サービスに渡すことはありません。

「広告非表示」または「ライフタイム解除」を購入すると、本アプリは広告 SDK を初期化しなくなります。 広告を隠すのではなく、SDK 自体を読み込みません。

6. 購入と支払い

本アプリには買い切りの購入が 2 種類あります(サブスクリプションではありません)。「広告非表示」と 「ライフタイム解除」(広告非表示+クラウド同期)です。決済はご利用のプラットフォーム公式の仕組みが すべて処理します(iOS は Apple の App 内課金(App Store)、Android は Google Play の 課金システム)。本アプリおよび当方のサーバーがカード番号・請求先住所などの決済情報に触れることは ありません。

購入が正当かつご本人のものであることを確認するため、プラットフォームが発行するレシート(iOS は App Store が署名した取引、Android は Google Play の購入トークン)を当方のサーバーへ送信し、当該 プラットフォームに対して検証したうえで第 4 節の購入記録として保存します。プラットフォームに渡す アカウント識別子はハッシュ化された値であり、メールアドレスそのものではありません。同じ Apple アカウントまたは Google アカウントの別端末では、アプリ内の「購入の復元」でいつでも権利を回復できます。

7. 音声入力(任意機能)

本アプリで唯一、エンドツーエンド暗号化ができない機能です。ご利用の前にこの節をお読みください。 音声入力はマイクボタンをタップしたときにのみ動作し、初回の録音前に改めて説明と同意の確認を行います。 ご利用にならない場合、この節は該当せず、本アプリが録音することもありません。

8. その他の第三者サービス

9. 権限

Android で本アプリが宣言する権限は 2 種類です。インターネット接続(INTERNET)は クラウド同期・広告・購入検証に使用し、録音(RECORD_AUDIO)と音声設定(MODIFY_AUDIO_SETTINGS)は 第 7 節の音声入力にのみ使用します。マイクは「必要になったときに確認する」方式で、 初めてマイクボタンをタップしたときに OS の許可ダイアログが表示されます。許可しない場合、または音声入力を 使わない場合、本アプリが録音することはありません。iOS には対応する「ネットワーク権限」の宣言はなく、 マイクについても同様に、音声入力を初めて使うときに OS が確認します。広告のパーソナライズに関わる追跡許可に ついては前節をご参照ください。両プラットフォームとも、カメラ、連絡先、SMS、通話履歴、 正確な位置情報、写真ライブラリへのアクセスは要求せず、追加のストレージ権限も要求しません (PDF 出力はシステムの印刷サービスが担当します)。

10. お子様について

本アプリは 13 歳未満のお子様を対象としておらず、お子様の個人情報を意図的に収集することはありません。 保護者の同意なくお子様が情報を提供したと思われる場合は、ご連絡いただければ速やかに削除します。

11. 保存期間と削除

12. 本ポリシーの変更とお問い合わせ

本ポリシーを改訂した場合は、このページ冒頭の日付を更新し、ここでお知らせします。

本ポリシーやお客様のデータに関するお問い合わせ、開示・訂正・削除のご請求は次のアドレスまで: fish@coss.com.tw