餘裕 · PICO LEDGER
隱私權政策 · Privacy Policy · プライバシーポリシー
隱私權政策(繁體中文)
最後更新:2026 年 9 月 4 日
「餘裕 · PICO LEDGER」(套件名稱 com.fish.picoledger,以下稱「本 App」)
是一款個人記帳與預算工具。本 App 的核心設計是:不開啟雲端同步時,你的帳本
完全留在你自己的裝置上;開啟雲端同步後,帳本內容在離開裝置之前就已加密,
我們的伺服器只存得到我們自己也無法解讀的密文。
一、一分鐘摘要
- 不註冊帳號也能完整使用,這種情況下本 App 不會把你的任何帳本資料傳出裝置。
- 註冊並開啟雲端同步後,我們只會收到:你的電子郵件、密碼的雜湊值,以及加密後的帳本密文。
- 我們(開發者)無法解讀你的交易明細、金額、備註、貸款或存錢目標——技術上做不到,因為解密金鑰從未離開你的裝置。
- 本 App 會顯示 Google AdMob 廣告;廣告 SDK 會依 Google 的政策處理裝置與廣告識別碼。購買「去廣告」後,本 App 連廣告 SDK 都不會再載入。
- 語音記帳是選用功能:使用時,錄音與逐字稿會以明文送到我們的伺服器並轉送 Groq 進行辨識,這一段無法端對端加密。我們不保存錄音、逐字稿或對話內容,且一定要你按確認才會寫進帳本——詳見第七節。
- 你可以隨時在 App 內「設定 → 刪除帳號」自行刪除帳號與伺服器上的加密帳本,不需要來信申請。
二、不使用雲端同步時(預設狀態)
本 App 安裝後預設就是純本機模式:不需要註冊、不需要登入。你的交易紀錄、自訂分類、 儲蓄目標、貸款、固定收支、語系與主題設定,全部只寫在你這台裝置的 App 儲存空間裡。 本 App 不會把這些內容上傳到任何伺服器,我們也無從得知你是否安裝了它、記了幾筆帳。
解除安裝本 App 會一併刪除這些本機資料。請注意:純本機模式下沒有任何雲端備份, 換手機或清除 App 資料前請自行匯出或先啟用雲端同步。
三、雲端同步與端對端加密
啟用雲端同步後,你的帳本資料在離開你的裝置「之前」就已經加密——加密與解密都只發生在你的 手機或瀏覽器上,我們的伺服器只儲存加密後、我們自己也無法解讀的密文。
技術上是怎麼做到的:你登入用的密碼,會在你的裝置上被用來產生一把只存在於裝置 本機、從未被傳送出去的「加密金鑰」。伺服器收到的登入密碼,經過一層與這把加密金鑰完全無關的 轉換——即使伺服器遭入侵,也無法從中還原出你的加密金鑰。你的交易紀錄、分類、備註、貸款、 存錢目標等所有帳本內容,一律先在本機以 AES-256-GCM 加密才會上傳;我們資料庫裡看到的只是一段 無法解讀的亂碼。這把金鑰存放在系統提供的硬體保護金鑰庫中——Android 上是 Android Keystore,iOS 上是 Keychain。
這個保護的實際範圍(請容我們誠實說明限制):
- 我們(開發者)無法讀取你的交易明細、金額、備註或任何帳本內容——即使我們想看,技術上也做不到,因為我們從未擁有能解密的金鑰。
- 我們仍然能看到:你的帳號是否存在(電子郵件)、上次同步的時間、加密後資料的大約大小——但看不到內容本身。
- 這個保護的前提是你使用的是官方、未被竄改的 App;如果你的裝置本身已中毒或安裝了被竄改過的版本,任何端對端加密都無法保護你——這是所有端對端加密服務共同的限制,並非本 App 獨有。
- 忘記密碼:因為我們沒有你的加密金鑰,我們也「無法」幫你重設密碼後救回資料。因此我們會在你啟用雲端同步時提供一組「復原金鑰」,請務必妥善保存;往後若忘記密碼,只有這組復原金鑰能救回你的資料。若密碼與復原金鑰都遺失,資料將無法復原。
四、我們在伺服器上實際儲存的資料
只有在你註冊帳號之後才會有下列資料。伺服器位於我們自行維運的主機
(網域 picoledger.fish-zero.com),流量經由 Cloudflare 傳輸。
| 資料 | 用途 | 我們讀得懂嗎 |
|---|---|---|
| 電子郵件地址 | 帳號識別、登入 | 是 |
| 密碼的雜湊值 | 驗證登入(不儲存原始密碼) | 否(單向雜湊) |
| 登入工作階段(session token) | 維持登入狀態 | 是 |
| 帳本密文與其初始化向量(IV) | 雲端同步 | 否 |
| 密文大小、版本號、更新時間 | 衝突偵測、容量顯示 | 是 |
| 以密碼包覆的加密金鑰(wrapped DEK) | 讓你在新裝置輸入密碼後解開自己的帳本 | 否(沒有你的密碼就解不開) |
| 復原金鑰的驗證雜湊、以復原金鑰包覆的加密金鑰 | 忘記密碼時的復原流程 | 否 |
| 購買紀錄:商品代號、平台、購買憑證(token)、驗證時間、是否有效 | 解鎖已購買的功能、恢復購買、退款處理 | 是 |
此外,如同任何網路服務,伺服器與 Cloudflare 會在一般連線紀錄中處理你的 IP 位址、 時間與請求路徑,用途僅限於維持服務運作與防止濫用。我們不會用這些紀錄建立使用者輪廓, 也不會將其與你的帳本內容關聯(我們本來就讀不到帳本內容)。
我們不做的事:不販售個人資料、不與廣告商分享你的帳本或電子郵件、 沒有安裝任何行為分析或追蹤 SDK(本 App 沒有 Firebase Analytics、沒有第三方統計工具)。
五、廣告(Google AdMob)
本 App 免費提供,並以 Google AdMob 廣告支撐開發成本。廣告出現在兩個位置:畫面上方的 橫幅廣告,以及你按下「轉出 PDF」年度報告時的一次全螢幕插頁廣告。
廣告由 Google 提供與投放。Google 及其合作夥伴可能會收集或使用裝置的廣告識別碼 (Advertising ID)、裝置與 App 的基本資訊,以及由 IP 位址推斷的粗略位置,用於投放與衡量 廣告成效。這些資料由 Google 依其自身政策處理,本 App 不會把你的帳本內容、電子郵件 或任何帳號資訊提供給廣告服務。
- Google 如何在合作夥伴網站與 App 使用資料:policies.google.com/technologies/partner-sites
- 你可以在 Android 系統的「設定 → Google → 廣告」中重設或刪除廣告 ID、關閉廣告個人化。
- 在 iOS 上,本 App 會依 Apple「App 追蹤透明度」(ATT)規範,於需要用於個人化廣告時請求你的授權;你可以隨時在系統「設定 → 隱私權與安全性 → 追蹤」中調整每個 App 的授權。
- 在適用歐盟/英國法規的地區,首次顯示廣告前會出現 Google 的使用者同意訊息(UMP),你可以在其中選擇是否同意個人化廣告。
購買「去廣告」或「終身解鎖」之後,本 App 不會再初始化廣告 SDK——不是把廣告藏起來, 而是根本不載入。
六、購買與付款
本 App 提供兩項一次性購買(非訂閱):「去廣告」與「終身解鎖」(去廣告+雲端同步)。 付款完全由你所在平台的官方付款機制處理——iOS 是 Apple 的 App 內購買 (App Store),Android 是 Google Play 帳單服務;本 App 與我們的伺服器 都不會接觸到你的信用卡號、帳單地址或任何付款工具資料。
為了確認一筆購買是真的且屬於你,我們會把平台發出的購買憑證(iOS 是 App Store 簽章的交易 憑證,Android 是 Google Play 的 purchase token)送到我們的伺服器,由伺服器向該平台驗證,並記錄 第四節表格中列出的購買紀錄。送給平台的帳號識別碼是經過雜湊處理的,不是你的電子郵件 本身。你可以隨時在 App 內使用「恢復購買」,在同一個 Apple 帳號或 Google 帳號的其他裝置上取回 已購買的權益。
七、語音記帳(選用功能)
這是本 App 唯一無法端對端加密的功能,請讀完這一節再決定要不要使用。 語音記帳需要你主動點擊麥克風按鈕才會啟動,第一次使用前會再次向你說明並徵求同意。 你不使用它,本節就完全不適用於你,本 App 也不會錄下任何聲音。
- 會送出什麼:你按下錄音到再次按下停止之間的錄音內容,以及辨識出來的逐字稿。兩者都是明文送出的——聲音要被辨識、文字要被理解,技術上就不可能同時維持端對端加密。這與第三節所述的帳本同步是兩回事:你的帳本本身仍然只以密文離開裝置。
- 送到哪裡:先送到我們的伺服器,再由我們的伺服器轉送給 Groq, Inc.(美國公司)進行語音辨識與內容解析。除此之外不會送給任何其他第三方。
- 我們保存什麼:不保存錄音,也不保存逐字稿或對話內容。音訊只在轉送的當下存在於記憶體中。我們唯一寫進資料庫的是「你今天用了幾次」這個數字,用途是計算每日免費額度。
- 對話留在哪裡:整段語音對話只存在你這台裝置的記憶體裡,關掉語音視窗就消失。它不會被同步、不會被上傳,也不會寫進帳本以外的任何地方。
- 寫進帳本前一定要你確認:AI 只會提出一份建議清單,金額、類別、日期、備註都可以當場修改,你按下確認之後才會真的記進帳本。
- 後續處理:資料送抵 Groq 之後的處理適用 Groq 自己的隱私權政策(groq.com/privacy-policy)。
八、其他第三方服務
- 平台付款服務:購買與購買驗證(見第六節)——iOS 為 Apple 的 App 內購買/StoreKit,Android 為 Google Play 服務/Google Play 帳單。
- 應用程式內評論 API:當你已記帳滿一定筆數且本裝置尚未詢問過時,本 App 會呼叫平台官方的評分視窗(Android 為 Google Play 應用程式內評論 API,iOS 為 Apple 的
SKStoreReviewController)。整個流程由平台處理,本 App 不會得知你是否評分、評了幾顆星。 - Cloudflare:作為我們伺服器對外的連線通道與防護層。
- Google Fonts:轉出 PDF 年度報告時,報告版面會嘗試載入網路字型以取得最佳排版;載入失敗(例如離線)時會自動改用系統字型,不影響轉出。
- 系統列印服務:「轉出 PDF」是交給作業系統內建的列印/儲存為 PDF 功能完成的(Android 與 iOS 皆同),檔案存放位置由你在系統對話框中自行選擇。本 App 不會讀取、上傳或保留你存出的 PDF。
九、權限
在 Android 上,本 App 宣告兩類權限:網際網路存取(INTERNET),用於雲端同步、 廣告與購買驗證;以及錄音(RECORD_AUDIO)與音訊設定(MODIFY_AUDIO_SETTINGS), 僅供第七節的語音記帳使用。錄音權限採「用到才問」:只有在你第一次點擊麥克風按鈕時, 系統才會跳出授權詢問;你拒絕或從不使用語音記帳,本 App 就永遠不會錄音。iOS 沒有對應的 「網路權限宣告」機制,App 本來就能連網,麥克風同樣是第一次使用語音記帳時才由系統詢問; 廣告個人化牽涉的追蹤授權請求已列在上一節。兩個平台上,本 App 都不要求 存取你的相機、通訊錄、簡訊、通話紀錄、精確位置或相簿,也不要求額外的儲存空間權限 (轉出 PDF 由系統列印服務處理)。
十、兒童
本 App 並非以 13 歲以下兒童為對象設計,我們也不會刻意向兒童收集個人資料。 若你認為有兒童在未經監護人同意下向我們提供了資料,請來信告知,我們會儘速刪除。
十一、資料保留與刪除
- 刪除帳號:App 內「設定 → 刪除帳號」即可自行刪除。這會一併刪除伺服器上的帳號、登入工作階段、加密帳本副本與購買紀錄,且無法復原。不需要來信申請、不需要等待人工處理。
- 本機資料:刪除帳號不會自動清空你這台裝置上的帳本;如需一併清除,請解除安裝本 App 或清除 App 資料。
- 保留期間:上述伺服器端資料在你刪除帳號之前會持續保存,因為那正是雲端同步的用途。
- 購買紀錄:刪除帳號後我們這邊的購買紀錄也會刪除;但你的購買仍記錄在你購買時所用的平台(iOS 是 Apple 的 App Store,Android 是 Google Play),日後可用同一個帳號透過「恢復購買」取回。
十二、政策變更與聯絡方式
本政策若有修訂,會更新本頁最上方的日期並在此公告。
對本政策、你的資料,或想行使查詢/更正/刪除等權利,請來信: fish@coss.com.tw
Privacy Policy (English)
Last updated: 4 September 2026
“餘裕 · PICO LEDGER” (package name com.fish.picoledger, the “App”) is a personal
budgeting and expense-tracking tool. Its core design: with cloud sync off, your ledger never
leaves your device; with cloud sync on, your ledger is encrypted before it leaves the
device, and our server only ever stores ciphertext that we ourselves cannot read.
1. One-minute summary
- The App is fully usable without an account. In that mode none of your ledger data leaves the device.
- If you sign up and enable cloud sync, we receive only your email address, a hash of your password, and encrypted ledger ciphertext.
- We (the developer) cannot read your transactions, amounts, notes, loans, or savings goals. Not “we promise not to” — we technically cannot, because the decryption key never leaves your device.
- The App shows Google AdMob ads. If you buy “remove ads”, the App stops loading the ad SDK entirely.
- Voice entry is optional. When you use it, the recording and its transcript are sent unencrypted to our server and forwarded to Groq for recognition — that part cannot be end-to-end encrypted. We keep no audio, transcript, or conversation, and nothing is written to your ledger until you confirm it. See section 7.
- You can delete your account and its encrypted ledger yourself, in-app, under Settings → Delete account. No email request needed.
2. When cloud sync is off (the default)
After installation the App is local-only: no sign-up, no sign-in. Your transactions, custom categories, savings goals, loans, recurring items, language and theme settings are written only to this device’s app storage. Nothing is uploaded, and we have no way of knowing that you installed the App or how many entries you keep.
Uninstalling the App deletes this local data. Note that local-only mode has no cloud backup — export your data or enable cloud sync before switching phones or clearing app data.
3. Cloud sync and end-to-end encryption
When cloud sync is enabled, your ledger is encrypted before it leaves your device. Encryption and decryption happen only on your phone or in your browser; our server stores only ciphertext that we cannot read.
How this works technically: your sign-in password is used, on your device, to derive an encryption key that exists only locally and is never transmitted. The password value that reaches the server goes through a separate transformation that is unrelated to that encryption key — even if the server were breached, the encryption key could not be recovered from it. All ledger content is encrypted locally with AES-256-GCM before upload; our database holds an opaque blob. The key is held in the system’s hardware-backed keystore — Android Keystore on Android, the Keychain on iOS.
The honest limits of this protection:
- We cannot read your transactions, amounts, notes, or any ledger content — we never hold a key that could decrypt it.
- We can still see: that your account exists (your email address), when you last synced, and the approximate size of the encrypted blob — but not its contents.
- This protection assumes you are running the official, unmodified App. If your device is compromised or you installed a tampered build, no end-to-end encryption can protect you. That limitation is common to every end-to-end encrypted service.
- Forgotten passwords: because we do not hold your key, we cannot reset your password and recover your data. When you enable cloud sync we give you a recovery key — keep it safe. It is the only way back in if you forget your password. If both the password and the recovery key are lost, the data cannot be recovered.
4. What we actually store on the server
None of this exists until you create an account. The server is self-hosted by us
(domain picoledger.fish-zero.com) and traffic is carried through Cloudflare.
| Data | Purpose | Readable by us? |
|---|---|---|
| Email address | Account identity, sign-in | Yes |
| Password hash | Sign-in verification (the password itself is not stored) | No (one-way hash) |
| Session token | Keeping you signed in | Yes |
| Ledger ciphertext and its IV | Cloud sync | No |
| Ciphertext size, version number, updated-at time | Conflict detection, storage display | Yes |
| Password-wrapped encryption key | Lets you unlock your own ledger on a new device | No (useless without your password) |
| Recovery-key verifier hash and recovery-key-wrapped encryption key | The forgotten-password recovery flow | No |
| Purchase records: product id, platform, purchase token, verification time, validity | Unlocking what you bought, restoring purchases, refunds | Yes |
As with any online service, the server and Cloudflare process your IP address, timestamps and request paths in ordinary connection logs, solely to operate the service and prevent abuse. We do not build user profiles from those logs, and they are not linked to ledger content (which we cannot read in the first place).
What we do not do: we do not sell personal data, do not share your ledger or email with advertisers, and ship no behavioural analytics or tracking SDK (no Firebase Analytics, no third-party statistics library).
5. Advertising (Google AdMob)
The App is free and supported by Google AdMob ads in two places: a banner at the top of the screen, and a single full-screen interstitial when you export the annual PDF report.
Ads are served by Google. Google and its partners may collect or use the device advertising ID, basic device and app information, and coarse location inferred from your IP address, to serve and measure ads. That data is handled by Google under its own policies. The App never passes your ledger content, email address, or any account information to the ad service.
- How Google uses data from sites and apps that use its services: policies.google.com/technologies/partner-sites
- You can reset or delete your advertising ID and turn off ad personalisation under Settings → Google → Ads on Android.
- On iOS, the App asks for your permission under Apple’s App Tracking Transparency (ATT) framework whenever it needs to use tracking data for ad personalisation; you can change any app’s permission at any time under Settings → Privacy & Security → Tracking.
- Where EU/UK rules apply, Google’s consent message (UMP) is shown before ads appear, and you choose there whether to allow personalised ads.
After buying “remove ads” or the lifetime unlock, the App no longer initialises the ad SDK — the ads are not merely hidden; the SDK is never loaded.
6. Purchases and payment
The App offers two one-time purchases (not subscriptions): “remove ads” and “lifetime unlock” (remove ads plus cloud sync). Payment is handled entirely by your platform’s own payment system — Apple In-App Purchase (the App Store) on iOS, Google Play Billing on Android. Neither the App nor our server ever sees your card number, billing address, or any payment instrument data.
To confirm a purchase is genuine and yours, the receipt the platform issues (an App Store signed transaction on iOS, a Google Play purchase token on Android) is sent to our server, verified against that platform, and recorded as described in section 4. The account identifier we hand to the platform is a hashed value, not your email address. You can use “Restore purchases” in the App at any time to recover entitlements on another device signed in to the same Apple Account or Google account.
7. Voice entry (optional feature)
This is the one feature in the App that cannot be end-to-end encrypted. Please read this section before using it. Voice entry only starts when you tap the microphone button, and the App explains this and asks for your consent before the first recording. If you never use it, this section does not apply to you and the App records no audio at all.
- What is sent: the audio between the moment you start and stop recording, and the transcript produced from it. Both are sent unencrypted — speech has to be recognised and text has to be understood, which is technically incompatible with end-to-end encryption. This is separate from ledger sync in section 3: your ledger itself still leaves the device only as ciphertext.
- Where it goes: first to our server, which forwards it to Groq, Inc. (a US company) for speech recognition and parsing. It is not sent to any other third party.
- What we keep: no audio, no transcript, no conversation. The audio exists only in memory while it is being forwarded. The only thing we write to our database is a count of how many times you used the feature today, to enforce the daily free allowance.
- Where the conversation lives: entirely in your device's memory. Closing the voice window discards it. It is never synced, uploaded, or written anywhere other than the ledger entries you confirm.
- Nothing is recorded without your confirmation: the assistant only proposes a list. Amount, category, date, and note are all editable, and entries reach your ledger only after you press confirm.
- Downstream handling: once data reaches Groq it is governed by Groq's own privacy policy (groq.com/privacy-policy).
8. Other third-party services
- Platform payment services — purchases and purchase verification (section 6): Apple In-App Purchase / StoreKit on iOS, Google Play services / Google Play Billing on Android.
- In-app review API — once you have recorded a certain number of entries and this device has not been asked before, the App calls the platform’s own rating dialog (the Google Play In-App Review API on Android, Apple’s
SKStoreReviewControlleron iOS). The platform handles the whole flow; the App is not told whether you rated it or what score you gave. - Cloudflare — the network path and protection layer in front of our server.
- Google Fonts — the annual PDF report tries to load web fonts for best typography; if that fails (for example offline) it falls back to system fonts and the export still works.
- System print service — “Export PDF” is handed to the operating system’s built-in print / save-as-PDF function (on both Android and iOS), and you choose where the file is saved. The App does not read, upload, or retain the PDF you saved.
9. Permissions
On Android, the App declares two kinds of permission: INTERNET, used for cloud sync, ads, and purchase verification; and RECORD_AUDIO / MODIFY_AUDIO_SETTINGS, used only for the voice entry feature described in section 7. The microphone is requested at the point of use: the system prompt appears the first time you tap the microphone button, and if you decline it — or simply never use voice entry — the App never records anything. iOS has no equivalent network-access permission to declare, and the microphone there is likewise requested by the system the first time you use voice entry; the tracking-authorization prompt tied to ad personalisation is covered in the previous section. On both platforms, the App never requests access to your camera, contacts, SMS, call logs, precise location, or photo library, and it does not request extra storage permission (PDF export is handled by the system print service).
10. Children
The App is not directed at children under 13, and we do not knowingly collect personal data from children. If you believe a child has provided us with data without a guardian’s consent, please contact us and we will delete it promptly.
11. Retention and deletion
- Deleting your account: use Settings → Delete account in the App. This deletes the account, sessions, encrypted ledger copy and purchase records from our server, irreversibly. No email request, no manual processing, no waiting.
- Local data: deleting the account does not automatically wipe the ledger on this device. Uninstall the App or clear its app data if you want that too.
- Retention period: the server-side data above is kept until you delete your account — that is exactly what cloud sync is for.
- Purchase records: deleting your account also deletes our copy of your purchase records. Your purchase itself remains recorded with the store you bought it from (the App Store on iOS, Google Play on Android) and can be recovered later with “Restore purchases” on the same account.
12. Changes and contact
If this policy changes, the date at the top of this page is updated and the change announced here.
Questions about this policy or your data, or to exercise access / correction / deletion rights: fish@coss.com.tw
プライバシーポリシー(日本語)
最終更新日:2026 年 9 月 4 日
「餘裕 · PICO LEDGER」(パッケージ名 com.fish.picoledger、以下「本アプリ」)は、
個人向けの家計簿・予算管理ツールです。設計の中心は次の二点です。クラウド同期を使わない場合、
帳簿データは端末の外に出ません。クラウド同期を使う場合も、帳簿の内容は端末を離れる前に
暗号化され、当方のサーバーには開発者自身にも解読できない暗号文しか保存されません。
1. 要約
- アカウント登録なしで全機能を利用できます。その場合、帳簿データが端末外に送信されることはありません。
- 登録してクラウド同期を有効にした場合、当方が受け取るのはメールアドレス、パスワードのハッシュ値、そして暗号化された帳簿データのみです。
- 開発者は取引明細・金額・メモ・ローン・貯蓄目標を解読できません。「しない」ではなく、復号鍵が端末から出ないため技術的にできません。
- 本アプリは Google AdMob の広告を表示します。「広告非表示」を購入すると、広告 SDK 自体を読み込まなくなります。
- 音声入力は任意機能です。利用時は録音と文字起こしが暗号化されないまま当方のサーバーへ送られ、認識のため Groq へ転送されます。この部分はエンドツーエンド暗号化の対象外です(帳簿そのものは引き続き暗号化されます)。音声・文字起こし・会話は保存せず、確認するまで帳簿には記録されません。詳しくは第 7 節をご覧ください。
- アカウントとサーバー上の暗号化帳簿は、アプリ内の「設定 → アカウント削除」からご自身で削除できます。メールでの申請は不要です。
2. クラウド同期を使わない場合(既定)
インストール直後はローカル専用モードで、登録もログインも不要です。取引記録、カスタム分類、 貯蓄目標、ローン、定期収支、言語・テーマ設定はこの端末のアプリ領域にのみ保存されます。 アップロードは行われず、当方は利用の有無や記録件数を知ることができません。
アンインストールするとこれらのローカルデータも削除されます。ローカル専用モードにはクラウド バックアップがありませんので、機種変更やアプリデータ消去の前にエクスポートするか、クラウド同期を 有効にしてください。
3. クラウド同期とエンドツーエンド暗号化
クラウド同期を有効にすると、帳簿データは端末を離れる「前」に暗号化されます。暗号化と復号は お使いのスマートフォンまたはブラウザー上でのみ行われ、サーバーには解読できない暗号文だけが 保存されます。
技術的な仕組み:ログイン用パスワードは端末上で「暗号鍵」の生成に使われ、この鍵は端末内に のみ存在し、送信されることはありません。サーバーに届くパスワードは、この暗号鍵とはまったく無関係な 変換を経ています。仮にサーバーが侵害されても、そこから暗号鍵を復元することはできません。取引記録、 分類、メモ、ローン、貯蓄目標などの帳簿内容はすべて、端末上で AES-256-GCM により暗号化されてから アップロードされます。この鍵はシステムが提供するハードウェア保護のキーストアに保管されます—— Android では Android Keystore、iOS では Keychain です。
この保護の範囲(限界も正直に記します):
- 開発者は取引明細・金額・メモなど帳簿の内容を読み取れません。復号できる鍵を保有していないためです。
- 当方が把握できるのは、アカウントの存在(メールアドレス)、最終同期日時、暗号化データのおおよそのサイズまでで、内容は分かりません。
- この保護は、公式かつ改変されていないアプリを利用していることが前提です。端末自体が侵害されている場合、いかなるエンドツーエンド暗号化も保護できません。これはすべての同種サービスに共通する限界です。
- パスワードを忘れた場合:当方は鍵を保有していないため、パスワードを再設定してデータを復旧させることは「できません」。そのためクラウド同期の有効化時に「リカバリーキー」をお渡しします。大切に保管してください。パスワードとリカバリーキーの両方を失うと、データは復旧できません。
4. サーバーに実際に保存される情報
以下はアカウント作成後にのみ存在します。サーバーは当方が自身で運用しており
(ドメイン picoledger.fish-zero.com)、通信は Cloudflare を経由します。
| データ | 目的 | 開発者が読めるか |
|---|---|---|
| メールアドレス | アカウント識別・ログイン | はい |
| パスワードのハッシュ値 | ログイン検証(パスワード自体は保存しません) | いいえ(一方向ハッシュ) |
| セッショントークン | ログイン状態の維持 | はい |
| 帳簿の暗号文と初期化ベクトル(IV) | クラウド同期 | いいえ |
| 暗号文のサイズ、バージョン番号、更新日時 | 競合検出、容量表示 | はい |
| パスワードで包んだ暗号鍵 | 新しい端末で自分の帳簿を復号するため | いいえ(パスワードなしでは開けません) |
| リカバリーキーの検証ハッシュ、リカバリーキーで包んだ暗号鍵 | パスワード忘れ時の復旧 | いいえ |
| 購入記録:商品 ID、プラットフォーム、購入トークン、検証日時、有効性 | 購入済み機能の解除、購入の復元、返金処理 | はい |
また、一般的なオンラインサービスと同様に、サーバーおよび Cloudflare は接続ログとして IP アドレス、 日時、リクエストパスを処理します。用途はサービスの運用と不正利用防止に限られます。これらのログから 利用者プロファイルを作成することはなく、帳簿の内容と関連付けることもありません(そもそも内容を 読めません)。
行わないこと:個人データの販売、帳簿やメールアドレスの広告事業者への提供、行動分析・ トラッキング SDK の搭載(Firebase Analytics も第三者統計ツールも使用していません)。
5. 広告(Google AdMob)
本アプリは無料で提供され、Google AdMob の広告により開発費を賄っています。広告は画面上部の バナーと、年間レポートを「PDF に出力」する際の全画面インタースティシャル広告の 2 か所です。
広告は Google により配信されます。Google およびそのパートナーは、広告 ID、端末とアプリの基本情報、 IP アドレスから推定されるおおよその位置情報を、広告の配信・効果測定のために収集・利用する場合が あります。これらは Google のポリシーに基づいて処理されます。本アプリが帳簿の内容、メールアドレス、 アカウント情報を広告サービスに渡すことはありません。
- Google がパートナーのサイト・アプリで情報を使用する方法:policies.google.com/technologies/partner-sites
- Android の「設定 → Google → 広告」で広告 ID のリセット・削除、広告のパーソナライズ無効化が可能です。
- iOS では、個人化広告にトラッキングデータが必要な場合、Apple の「App 追跡の透明性」(ATT)規定に基づき許可を求めます。許可はいつでも「設定 → プライバシーとセキュリティ → トラッキング」から変更できます。
- EU/英国の規制が適用される地域では、広告表示前に Google の同意メッセージ(UMP)が表示されます。
「広告非表示」または「ライフタイム解除」を購入すると、本アプリは広告 SDK を初期化しなくなります。 広告を隠すのではなく、SDK 自体を読み込みません。
6. 購入と支払い
本アプリには買い切りの購入が 2 種類あります(サブスクリプションではありません)。「広告非表示」と 「ライフタイム解除」(広告非表示+クラウド同期)です。決済はご利用のプラットフォーム公式の仕組みが すべて処理します(iOS は Apple の App 内課金(App Store)、Android は Google Play の 課金システム)。本アプリおよび当方のサーバーがカード番号・請求先住所などの決済情報に触れることは ありません。
購入が正当かつご本人のものであることを確認するため、プラットフォームが発行するレシート(iOS は App Store が署名した取引、Android は Google Play の購入トークン)を当方のサーバーへ送信し、当該 プラットフォームに対して検証したうえで第 4 節の購入記録として保存します。プラットフォームに渡す アカウント識別子はハッシュ化された値であり、メールアドレスそのものではありません。同じ Apple アカウントまたは Google アカウントの別端末では、アプリ内の「購入の復元」でいつでも権利を回復できます。
7. 音声入力(任意機能)
本アプリで唯一、エンドツーエンド暗号化ができない機能です。ご利用の前にこの節をお読みください。 音声入力はマイクボタンをタップしたときにのみ動作し、初回の録音前に改めて説明と同意の確認を行います。 ご利用にならない場合、この節は該当せず、本アプリが録音することもありません。
- 送信されるもの:録音の開始から停止までの音声と、そこから生成された文字起こしです。いずれも暗号化されずに送信されます。音声を認識し文章を解釈することは、技術的にエンドツーエンド暗号化と両立しないためです。これは第 3 節の帳簿同期とは別の話で、帳簿そのものは暗号文としてのみ端末を出ます。
- 送信先:まず当方のサーバーへ送られ、そこから音声認識と解析のために Groq, Inc.(米国企業)へ転送されます。それ以外の第三者へ送ることはありません。
- 保存されるもの:音声・文字起こし・会話のいずれも保存しません。音声は転送中にメモリ上に存在するだけです。データベースに書き込むのは、無料利用枠を管理するための利用回数のみです。
- 会話の保存場所:お使いの端末のメモリ内だけです。音声画面を閉じると破棄され、同期もアップロードもされません。
- 確認するまで記録されません:AI は候補を提示するだけです。金額・カテゴリ・日付・メモはその場で修正でき、確認ボタンを押して初めて帳簿に記録されます。
- 転送後の取り扱い:Groq に届いた後のデータは、Groq 自身のプライバシーポリシー(groq.com/privacy-policy)に従って取り扱われます。
8. その他の第三者サービス
- プラットフォームの決済サービス:購入と購入検証(第 6 節)。iOS は Apple の App 内課金/StoreKit、Android は Google Play サービス/Google Play 課金です。
- アプリ内レビュー API:一定の記録件数に達し、かつこの端末で未表示の場合に、各プラットフォーム公式の評価ダイアログを呼び出します(Android は Google Play アプリ内レビュー API、iOS は Apple の
SKStoreReviewController)。処理はプラットフォーム側で完結し、評価したかどうか、何点かを本アプリが知ることはありません。 - Cloudflare:サーバー前段の通信経路・保護レイヤー。
- Google Fonts:PDF 年間レポートの出力時に最適な組版のため Web フォントの読み込みを試みます。オフラインなどで失敗した場合はシステムフォントに切り替わり、出力は問題なく行えます。
- システム印刷サービス:「PDF に出力」は OS 標準の印刷/PDF 保存機能に引き渡され(Android・iOS 共通)、保存先はお客様が選択します。本アプリが保存された PDF を読み取る・アップロード・保持することはありません。
9. 権限
Android で本アプリが宣言する権限は 2 種類です。インターネット接続(INTERNET)は クラウド同期・広告・購入検証に使用し、録音(RECORD_AUDIO)と音声設定(MODIFY_AUDIO_SETTINGS)は 第 7 節の音声入力にのみ使用します。マイクは「必要になったときに確認する」方式で、 初めてマイクボタンをタップしたときに OS の許可ダイアログが表示されます。許可しない場合、または音声入力を 使わない場合、本アプリが録音することはありません。iOS には対応する「ネットワーク権限」の宣言はなく、 マイクについても同様に、音声入力を初めて使うときに OS が確認します。広告のパーソナライズに関わる追跡許可に ついては前節をご参照ください。両プラットフォームとも、カメラ、連絡先、SMS、通話履歴、 正確な位置情報、写真ライブラリへのアクセスは要求せず、追加のストレージ権限も要求しません (PDF 出力はシステムの印刷サービスが担当します)。
10. お子様について
本アプリは 13 歳未満のお子様を対象としておらず、お子様の個人情報を意図的に収集することはありません。 保護者の同意なくお子様が情報を提供したと思われる場合は、ご連絡いただければ速やかに削除します。
11. 保存期間と削除
- アカウント削除:アプリ内の「設定 → アカウント削除」から実行できます。サーバー上のアカウント、セッション、暗号化された帳簿、購入記録が削除され、復元はできません。メール申請も手動対応の待ち時間も不要です。
- ローカルデータ:アカウントを削除しても、この端末内の帳簿は自動的には消えません。併せて消す場合はアンインストールまたはアプリデータの消去を行ってください。
- 保存期間:上記のサーバー側データは、アカウントを削除するまで保存されます(それがクラウド同期の目的です)。
- 購入記録:アカウント削除により当方の購入記録も削除されますが、購入自体は購入時のプラットフォーム(iOS は App Store、Android は Google Play)に記録されており、同じアカウントで「購入の復元」により回復できます。
12. 本ポリシーの変更とお問い合わせ
本ポリシーを改訂した場合は、このページ冒頭の日付を更新し、ここでお知らせします。
本ポリシーやお客様のデータに関するお問い合わせ、開示・訂正・削除のご請求は次のアドレスまで: fish@coss.com.tw