小豆记账 隐私政策
生效日期:2026 年 9 月 6 日
运营者:YOUXIANG LIN(下称"我们")。
本政策说明「小豆记账」App(下称"本 App")如何收集、使用、存储和保护你的信息。使用本 App 前请仔细阅读。你继续使用即表示同意本政策。
一、我们收集哪些信息
我们只收集提供记账功能所必需的信息:
| 信息 | 来源 | 用途 |
|---|---|---|
| 账号标识符(Apple 用户标识) | 你使用「通过 Apple 登录」时由 Apple 提供 | 识别并保护你的账号;我们不会获得你的 Apple 账号密码 |
| 姓名或昵称 | 首次使用「通过 Apple 登录」时由 Apple 提供,或由你主动修改 | 作为账号默认昵称及展示名称 |
| 记账数据(总资产、交易金额、类型、分类、备注、日期) | 你在 App 内主动录入 | 记录、统计、展示你的收支 |
| 消费凭证图片(小票、支付截图等) | 你主动上传以自动识别 | 通过文字识别(OCR)自动生成记账记录 |
| 登录令牌 | 登录后由服务器下发 | 保存在你的设备本地,用于保持登录状态 |
我们不收集:手机号、通讯录、位置、用于追踪的设备唯一标识。本 App 不含广告、第三方统计或用户画像。
二、第三方处理(重要)
为实现小票自动识别,你上传的消费凭证图片会被发送至火山引擎(北京火山引擎科技有限公司,字节跳动旗下)提供的大模型服务进行文字识别处理。该处理仅用于识别图片中的消费信息,识别结果返回后用于生成你的记账记录。
当识别结果是一笔退款时,为了找出它对应的原始支出,你最近 90 天的支出摘要(金额、备注、分类、日期)会一并发送至同一服务用于匹配。该处理只在图片识别流程内发生。
- 处理方:火山引擎(ARK 大模型服务)
- 处理内容:你上传的消费凭证图片;退款匹配时另加最近 90 天的支出摘要
- 处理目的:文字识别(OCR)与退款匹配
- 其隐私政策:https://www.volcengine.com/docs/6256/64902
第三方保护水平确认
我们与火山引擎之间适用《火山方舟大模型服务平台专用条款》,其中约定:
- 第 3.7.7 条:「未经您的单独同意,火山引擎不会存储和使用您的数据来训练或优化模型。」
- 第 3.7.11 条:「未经您授权,火山引擎不会访问或使用您的数据。」
据此我们确认:火山引擎对经由本 App 传输的数据提供与本政策所述同等或更高水平的保护——该数据仅用于完成你发起的这一次识别请求,不用于模型训练或优化,未经授权不会被访问或另作他用。完整条款见:https://www.volcengine.com/docs/82379/1104498
上述处理需要你在 App 内明确同意后才会发生。首次使用图片识别时,App 会先说明发送的内容与接收方并征求你的同意;不同意则图片识别不可用,手动记账不受影响。你可随时在 App 内「我的 → AI 识别与隐私」查看该说明或撤回同意。
除上述用于 OCR 与退款匹配的处理外,我们不会将你的记账数据提供、出售或共享给任何第三方。
三、图片留存
上传的消费凭证图片识别成功后立即删除,服务器上只留下识别出的记账数据,不再保留图片本身。
识别失败的图片最多留存 14 天,用于自动重试与你的人工核对,超过留存期后自动删除。
你在 App 内撤回 AI 识别同意时,我们会立即删除你已上传的全部图片,不再等待上述留存期。
四、存储与安全
- 你的数据存储在我们自有的服务器上,全程通过 HTTPS 加密传输。
- 数据按用户隔离,你只能访问自己的数据。
- 我们采取合理的技术与管理措施保护你的信息,但请理解互联网传输无法保证绝对安全。
五、你的权利:删除账号与数据
你可随时在 App 内 「设置 → 删除账号」 永久删除你的账号及全部关联数据(总资产、记账记录、上传图片、访问密钥等)。删除后数据不可恢复,且原有登录立即失效。
六、未成年人
本 App 不面向 14 周岁以下儿童。若你是未成年人,请在监护人指导下使用。
七、政策变更
我们可能适时更新本政策,更新后会在本页面公布并更新生效日期。重大变更将通过 App 内提示等方式告知。
八、联系我们
如对本政策或你的信息有任何疑问,请联系:support@doudou.life
Xiaodou Ledger Privacy Policy
Effective date: September 6, 2026
Operator: YOUXIANG LIN ("we", "us").
This policy explains how the Xiaodou Ledger app ("the App") collects, uses, stores and protects your information. Please read it before using the App. Continuing to use the App means you accept this policy.
This English text and the Chinese text above are the same policy. If they differ, the Chinese text governs.
1. What we collect
We collect only what the expense-tracking function requires:
| Data | How it is collected | What it is used for |
|---|---|---|
| Account identifier (Apple user identifier) | Provided by Apple when you use Sign in with Apple | To identify and secure your account. We never receive your Apple Account password |
| Name or nickname | Provided by Apple on first Sign in with Apple, or edited by you | Used as your default nickname and display name |
| Ledger data (total assets, transaction amount, type, category, note, date) | Entered by you in the App | To record, total and display your income and spending |
| Receipt images (receipts, payment screenshots) | Uploaded by you for automatic recognition | To generate ledger entries through text recognition (OCR) |
| Login token | Issued by our server after sign-in | Stored locally on your device to keep you signed in |
We do not collect: phone number, contacts, location, or any unique device identifier used for tracking. The App contains no advertising, third-party analytics, or user profiling.
2. Third-party processing (important)
To recognise receipts automatically, the receipt image you upload is sent to the large-model service operated by Volcano Engine (Beijing Volcano Engine Technology Co., Ltd., a ByteDance company) for text recognition. The processing is used only to read the spending information in the image; the result is returned and used to create your ledger entry.
When a recognised item is a refund, in order to find the original expense it belongs to, a summary of your last 90 days of expenses (amount, note, category, date) is sent to the same service for matching. This happens only inside the image-recognition flow.
- Recipient: Volcano Engine (ARK large-model service)
- Data sent: the receipt image you upload; plus a 90-day expense summary when matching a refund
- Purpose: text recognition (OCR) and refund matching
- Its privacy policy: https://www.volcengine.com/docs/6256/64902
Confirmation that the third party provides the same or equal protection
Our use of the service is governed by the Volcano Engine ARK Large-Model Service Platform Specific Terms, which provide:
- Article 3.7.7: "Without your separate consent, Volcano Engine will not store or use your data to train or optimise models."
- Article 3.7.11: "Without your authorisation, Volcano Engine will not access or use your data."
On that basis we confirm: Volcano Engine provides protection for data transmitted through the App that is the same as, or stronger than, the protection described in this policy — the data is used only to complete the single recognition request you initiated, is not used to train or optimise models, and is not accessed or repurposed without authorisation. Full terms: https://www.volcengine.com/docs/82379/1104498
The processing above only happens after you give explicit consent inside the App. Before image recognition can be used, the App first states what will be sent and who receives it, and asks for your agreement. If you decline, image recognition is unavailable. You can review that disclosure or withdraw your consent at any time under Profile → AI Recognition & Privacy.
Apart from the OCR and refund-matching processing described above, we do not provide, sell or share your ledger data with any third party.
3. Image retention
Uploaded receipt images are deleted immediately once recognition succeeds; only the recognised ledger entries remain on the server, not the image itself.
Images whose recognition failed are kept for at most 14 days, so that recognition can be retried automatically and so you can check them yourself. They are deleted automatically after that period.
If you withdraw your consent to AI recognition in the App, we delete all images you have uploaded straight away, without waiting for that retention period.
4. Storage and security
- Your data is stored on our own servers and transmitted over HTTPS throughout.
- Data is isolated per user; you can only access your own data.
- We apply reasonable technical and organisational measures to protect your information, though no internet transmission can be guaranteed absolutely secure.
5. Your rights: deleting your account and data
You can permanently delete your account and all associated data (total assets, ledger records, uploaded images, access tokens) at any time under Settings → Delete Account. Deleted data cannot be recovered, and existing sessions stop working immediately.
6. Minors
The App is not directed at children under 14. If you are a minor, please use it under the guidance of a guardian.
7. Changes to this policy
We may update this policy from time to time. Updates will be published on this page with a revised effective date. Material changes will also be announced in the App.
8. Contact us
If you have any question about this policy or your information, contact: support@doudou.life