TXLedger Privacy Policy

App homepage · 简体中文 · English · 日本語

Last updated: September 15, 2026
Effective date: July 18, 2026
We take your personal information and privacy seriously and always follow the principles of lawfulness, data minimization, transparency, and security. This Privacy Policy (the “Policy”) explains how we collect, use, transmit, store, and protect your personal information, and how you can exercise your related rights.
This Policy applies to the “TXLedger” (Chinese name: 甜心账本) products and services provided by Mianchi Tianxin Technology Co., Ltd. (渑池甜心科技有限公司, “we” or “us”), including the iOS and Android mobile apps and any new product forms that emerge as technology evolves. By using TXLedger, you acknowledge that you understand the personal-information practices described in this Policy; for non-essential information related to extended features, we will notify you separately and obtain the necessary authorization where required.
1. Types of Personal Information We Collect
1.1 Account Login and Security Verification
TXLedger supports phone-number login with an SMS code or password, and WeChat, Apple, or Google login on supported platforms (see Section 1.5). A phone number is optional when signing in with a third-party account. To complete registration, login, identity verification, session persistence, account protection, and troubleshooting, we may collect and process information relevant to your chosen login method, including your phone number, SMS verification result, third-party user identifiers and authorized name, email address and avatar, secure processing result of login credentials, user ID, login status, and device and network access logs as necessary.
To protect your account and the service, a security check may be required during login or sensitive operations; during that check we may process the verification result, IP address, and device and network access logs as necessary.
If you choose to set a nickname, avatar, or other profile details, we store what you submit and display it in ledger-member and profile scenarios. Unless a feature explicitly displays it or you actively share it, we do not show your phone number to other ledger members.
1.2 Bookkeeping and Collaboration
TXLedger is a tool for shared ledgers, bookkeeping, and financial insights. To provide the core service, we process the ledger and bookkeeping information you actively create, join, edit, view, or share, including basic ledger information, member collaboration information, income and expense records, notes, dates, amounts, information needed for statistics, and necessary operation records.
Content in a shared ledger may be visible to members of the same ledger according to the product’s permission rules. We only process this information to the extent necessary for bookkeeping, collaboration, queries, statistics, security auditing, and troubleshooting.
The app uses necessary service interfaces to complete account authorization, data storage, queries, synchronization, and permission checks. We do not disclose your ledgers or bookkeeping records to unrelated parties, nor do we use them for third-party advertising.
1.3 Bookkeeping Assistant, AI Features, and Voice
When you use the bookkeeping assistant, we store the messages you actively send or generate, message processing status, and other information necessary for the bookkeeping features, for message review, feature continuity, and troubleshooting.
When you trigger AI-assisted bookkeeping by text or voice, your input, necessary bookkeeping context, AI suggestions, and confirmation status are used to generate a draft entry for your confirmation. AI results are suggestions only and are recorded to the ledger only after you confirm them.
When you use voice input, the app processes your voice audio after obtaining the system microphone permission, and may use necessary service interfaces for speech-to-text, entry-suggestion generation, message review, and troubleshooting. The image entry point is currently a placeholder; the current version does not store original image assets.
To provide speech-to-text and AI bookkeeping suggestions, the bookkeeping text you enter, your voice audio, and necessary bookkeeping context (such as ledger category names, tag names, currency, and time zone) are sent to our third-party AI service provider, Alibaba Cloud (DashScope / Tongyi speech-recognition and large-language-model services), for processing. This content is sent anonymously: it never carries your phone number, user ID, ledger identifiers, or any other account or identity information. The data is used only to produce speech transcriptions and draft entries for your confirmation, and is never used for advertising or purposes unrelated to bookkeeping. Before you use AI bookkeeping for the first time, the app explains this data sharing in-app and asks for your consent; without your consent the app does not send any of the above data to the third-party AI service. You can withdraw your consent at any time in Settings → “AI Service & Data”; after withdrawal, AI bookkeeping is unavailable, while manual bookkeeping and all other features continue to work.
We never use your SMS verification codes, login status, account passwords, or account security information for AI-assisted bookkeeping, and we never send such sensitive information to unrelated services.
1.4 Device, Runtime, and Local Cache
To keep the product running properly, secure the service, optimize compatibility, and troubleshoot issues, we may collect or process necessary runtime information, including your IP address, device model, operating-system version, app version, language, network status, API access logs, error logs, and security logs. We do not sell or rent your personal information for third-party marketing purposes.
The app may store login status, preferences, recently used data, interface settings, and other necessary caches locally on your device to improve loading speed and experience. You can manage local data through app settings, system settings, clearing app data, or uninstalling the app.
1.5 Third-Party Login and SDKs
You may optionally sign in with or link WeChat, Apple, or Google. WeChat authorization uses Tencent’s WeChat Open Platform SDK (fluwx_no_pay); we process the authorization code, OpenID/UnionID, and the nickname and avatar you authorize. Apple authorization provides identity credentials, a user identifier, and any name or email Apple supplies, including a private relay email. Google login uses the Google Sign-In SDK (google_sign_in) on iOS/Android and Google web authorization on Web/macOS; we process ID tokens, authorization codes, your Google user identifier, and the name, email, and avatar you authorize. We request only the openid, email, and profile scopes. Authorization credentials are securely handled by our authentication service. This information is used only for authentication, account linking, and profile display. Ledger entries, bookkeeping text, and voice recordings are not sent to WeChat, Apple, or Google. Linked Accounts below Theme mode in Settings lets you unlink this app while retaining at least one login method available on your platform. Linking a phone number is optional. The WeChat SDK also sends your selected invitation link and display information when you actively share a ledger invitation. Apart from the login SDKs’ own data processing, we do not add separate third-party analytics, event-tracking, or advertising SDKs; see Sections 1.3 and 4.2 for AI services.
On iOS, the Google Sign-In SDK may also process user identifiers, IP addresses, device identifiers, and SDK-related usage data for authentication, security, and service analytics. An IP address may be used to estimate the device’s general location for fraud prevention. This SDK processing does not mean that we send ledger entries, bookkeeping text, or voice recordings to Google. See Google’s Sign-In SDK data disclosure and Google’s Privacy Policy.
When you unlink or delete this app account, we remove its third-party links and attempt to revoke Apple and Google authorization. If revocation cannot be completed, we provide manual instructions and ask you to acknowledge them. Identity links still used by other apps remain; unused third-party identity links are removed. This device temporarily stores a credential limited to recovering an interrupted deletion, and removes it after acknowledgment and local cleanup.
1.5.1 Google User Data: Processing, Retention, and Deletion
Google account information is processed by the authentication service and app services that we operate, for identity verification, account linking, profile display, and account security. We host and operate our authentication service ourselves. Infrastructure providers for hosting, storage, and network delivery process relevant data only as necessary to provide those services. Google processes sign-in authorization and revocation requests; its SDK processing is described above. We do not provide Google account information or authorization credentials to advertisers or data brokers.
If you use your Google name or avatar as your app nickname or avatar, authorized members of the same ledger can see that display information in collaboration screens. Your Google email and authorization credentials are not shared as ledger-member display information.
We request only the basic openid, email, and profile scopes, not access to Gmail messages, Google Drive files, contacts, or calendars. We do not sell Google user data or use it for targeted advertising, credit assessment, or developing, improving, or training generalized or non-personalized AI or machine-learning models. We do not use Google Workspace API data to train such models. We do not automatically attach account information or authorization credentials obtained through Google sign-in to requests to third-party AI services. Content you actively enter is handled as described for the corresponding features in this Policy.
While your Google sign-in or link remains active and the information is needed to provide account features, we retain your Google user identifier and the authorized basic profile information returned by Google. Authorization codes and ID tokens are used to complete authentication. If Google returns an available refresh token, our authentication service stores it for this app’s authorization management and subsequent revocation. We protect this data with HTTPS encryption in transit and service access controls; authorization credentials are not displayed to other users.
Unlinking Google in Settings removes this app’s Google link and its stored authorization credentials and attempts to revoke Google authorization. It does not automatically delete the app account, app data, or the nickname and avatar previously used for app display; you can edit these in your profile or request deletion. You can delete this app account from the in-app Edit Profile page, or contact service@tianxin.tech to ask about or request deletion of personal information. Deleting this app account does not delete your shared Tianxin sign-in account; identity information and authorizations still used by other apps remain. We remove third-party identity links that are no longer used by any app. You can use the same email address to ask about or request deletion of any remaining shared account information. Backups and necessary logs follow the retention principles in Section 6.
You can also remove this app’s authorization through Google Account third-party connections. Removing a connection at Google does not delete app data we have already stored; use the in-app deletion option or contact email above to request deletion. If automatic Google revocation cannot be completed, we provide manual instructions. Acknowledging that notice confirms that you have read it and does not mean Google authorization has been successfully revoked.
2. Service Interfaces and System Capabilities
When you use TXLedger features, the app may process related information through necessary service interfaces or system capabilities. The information types and scenarios are as follows:
Feature or capability Personal information involved Purpose and scenario Notes
Login and account authorization Phone number, login status, user ID, authentication result, login and authorization logs, etc. Phone-number login, SMS verification, password login, session management, and account security Used only for login, account authorization, and service security
Security verification Verification result, IP address, device and network access logs, etc. Pre-login security checks, abuse prevention, and account protection Processed only when a security check is required for login or sensitive operations
System microphone and voice capability Voice audio, transcribed text, speech-recognition status, device permission status, etc. Voice bookkeeping, speech-to-text, and subsequent AI-assisted confirmation Processed only when you actively use voice features, grant the microphone permission, and consent to AI data sharing; voice audio is transcribed by the third-party AI provider Alibaba Cloud (DashScope)
AI-assisted bookkeeping Bookkeeping text you actively enter, transcribed text, necessary bookkeeping context, suggestion results, etc. Parsing natural-language input into a draft entry for confirmation Processed only when you actively use AI features and consent to AI data sharing; entries are recorded only after your confirmation; parsing is performed by the third-party AI provider Alibaba Cloud (DashScope / Tongyi models)
File and message asset storage Voice and message assets you actively upload or generate, upload logs, etc. Voice-message storage, message review, service continuity, and troubleshooting Processed only as needed to provide the corresponding features
3. How We Use Your Personal Information
We use, store, and process your information only to the extent necessary to provide phone-number login, account authorization, bookkeeping, shared collaboration, statistics, the bookkeeping assistant, AI suggestions, voice input, version compatibility, troubleshooting, and system security, and to fulfill our legal obligations.
We take reasonable precautions to protect your personal information from unauthorized access, disclosure, use, modification, damage, or loss — for example access control, encrypted transmission, security auditing, rate limiting, and monitoring at the technical level, and policies and permission management at the organizational level. Please understand that no security measure is absolutely risk-free.
We do not use your ledger records, chat messages, or voice content for third-party advertising, and, apart from the login SDK processing described in Section 1.5, we do not send your behavioral data to third-party analytics platforms. If additional advertising, analytics, crash reporting, or third-party marketing capabilities are added in the future, we will update this Policy before launch and fulfill notification and authorization obligations as required by law.
4. Sharing, Transfer, and Disclosure
4.1 Necessary Sharing Among Ledger Members
TXLedger supports shared ledgers. After you create or join a shared ledger, members with the appropriate permissions may view shared ledger content, necessary member information, and related operation results according to the product rules. The actual visibility scope is determined by product features and member permission rules.
4.2 Necessary Processing by Service Providers
To provide login and account authorization, security verification, speech recognition, AI assistance, file storage, API access, and security protection, we may provide necessary information to, or entrust its processing to, relevant service providers within the minimum necessary scope. We require these providers to process personal information in accordance with applicable laws, this Policy, and reasonable security standards, and prohibit them from using the information for purposes unrelated to the service.
Specifically, speech recognition and AI bookkeeping suggestions are powered by the third-party AI service provider Alibaba Cloud (DashScope / Tongyi speech-recognition and large-language-model services). After you consent to AI data sharing in the app, your voice audio, bookkeeping text, and necessary bookkeeping context are transmitted to Alibaba Cloud anonymously (without your phone number, user ID, ledger identifiers, or any other account or identity information), solely for speech transcription and entry-suggestion generation. We require this provider to protect your personal information to a standard no lower than this Policy, to comply with applicable laws and security standards, and not to use the information for any purpose unrelated to this service.
4.3 Disclosure Required by Law or for Safety
In general, we do not transfer or publicly disclose your personal information to any company, organization, or individual. However, where required by laws and regulations, by competent administrative or judicial authorities, to protect the life or property of you or others, to safeguard the legitimate rights and interests of the platform and its users, or as necessary to handle security incidents or disputes, we may share, transfer, or disclose relevant information in accordance with the law.
If TXLedger undergoes a merger, acquisition, reorganization, asset transfer, bankruptcy, or similar transaction, your personal information may be transferred as part of that transaction. In such cases, we will take reasonable measures within the scope required by law and notify you of the change where appropriate.
5. Your Rights
You may, in accordance with the law, access, correct, copy, or delete your personal information, withdraw granted permissions, deactivate your account, or ask us to explain our personal-information practices. You can make a request through the relevant in-app entry, system permission settings, or the contact information at the end of this Policy. To protect your account, we may verify your identity before processing your request.
For information stored locally on your device, you can manage it through app settings, system settings, clearing app data, or uninstalling the app. For account details such as phone number, nickname, and avatar, and for cloud data such as bookkeeping records, collaboration, and messages, you can query, correct, delete, or deactivate through product features or by contacting us.
Please understand that shared-ledger data may also involve the legitimate rights of other ledger members. Account deactivation or deletion requests do not automatically delete shared-ledger data that other members remain entitled to view or lawfully retain; subject to applicable laws and product rules, we will delete, anonymize, or otherwise reasonably handle information directly associated with your personal identity.
6. Data Retention, Transfer, and Deletion
We retain your personal information only for as long as necessary to fulfill the service purposes described in this Policy, unless a longer retention period is required by law. Retention periods for account, bookkeeping, collaboration, message, voice, and necessary log data are determined by service provision, dispute resolution, security auditing, accounting records, and legal requirements.
After you delete bookkeeping records, messages, or voice assets, or deactivate your account, we delete or anonymize the relevant information within a reasonable period; however, due to backups, auditing, security, dispute handling, or mandatory legal requirements, some copies may not be immediately and completely removed from backup systems.
Where the service involves cross-border provision of personal information, we take the necessary protective measures required by applicable law and, where required, fulfill statutory obligations such as notification, consent, assessment, certification, or standard contracts.
7. Permissions
TXLedger may request system permissions such as microphone, network access, notifications, photo library, or camera as features require. The current core features require network access; voice input requires the microphone permission; the image entry point is currently a placeholder — if photo capture or image parsing is enabled later, we will request camera or photo-library permission before use and update the relevant descriptions. You can manage permissions in system settings; disabling a permission may affect the corresponding feature but will not affect unrelated features.
8. Protection of Minors
TXLedger is intended primarily for users capable of independently managing personal or family finances. If you are a minor, please use the service with the consent and guidance of your guardian. If a guardian finds that a minor has provided personal information to us without consent, they may contact us via the contact information at the end of this Policy, and we will handle it in accordance with the law.
9. Updates to This Policy
This Policy may be updated from time to time as the product and business evolve. Without your explicit consent, we will not materially reduce the rights you are entitled to under this Policy. After an update, we will inform you of the changes through website announcements, page prompts, in-app notifications, or other appropriate means; please check the latest version in a timely manner.
10. Governing Law
The formation, effectiveness, interpretation, amendment, supplementation, termination, enforcement, and dispute resolution of this Policy are governed by the laws of the People’s Republic of China; where the law has no relevant provision, general international commercial practice and/or industry practice shall be referenced. If any provision of this Policy is deemed void, invalid, or unenforceable, that provision is severable and does not affect the validity and enforceability of the remaining provisions.
Disputes arising from this Policy shall first be resolved through friendly negotiation between the platform and you; if negotiation fails within 60 days from the date the dispute arises, either party may submit the dispute to the Mianchi Arbitration Commission for arbitration under its then-effective rules, with Chinese as the language of arbitration. The arbitral award is final and binding on all parties.
11. Contact Us
If you have any questions, comments, or suggestions about this Policy or your personal information, you can contact us at service@tianxin.tech. We will generally respond within fifteen business days.