Privacy Notice · 私隱通知
How SteadyStep stores, uses and minimizes information.
English
This notice applies to the iOS and Android versions of SteadyStep. The exact features available may depend on your device, storefront and release version.
Who operates SteadyStep
SteadyStep is operated by Hanghang Yu, an individual developer. Privacy questions can be sent to steadystep@yeah.net.
Information stored in the app
Debt, income, expense, repayment and completed-report records are stored in the app's private storage on your device. On iOS, they may also be stored in your private iCloud database when iCloud is available. On Android, eligible local data may be included in the encrypted system backup selected in your device settings. SteadyStep does not operate a public profile or advertising account for free users.
Paid account and purchase information
Free planning does not require a SteadyStep account. For purchases, restoring paid access and unlocking complete reports, Sign in with Apple on iOS or Google sign-in on Android associates a verified App Store or Google Play transaction, entitlement and deletion metadata with a pseudonymous membership record. SteadyStep receives the identity token needed to verify the account, but not your account password. Payment-card information is handled by Apple or Google and is not received by SteadyStep.
On-device complete reports
In the iOS 1.2 local-report release, balances, interest, dates, repayment order, actions, warnings and report text are generated by deterministic software on your device. A new report request does not send a financial snapshot, raw or derived financial values, lender or debt names, payment history, notes or report content to SteadyStep's server or a third-party automated processor. Existing completed reports remain readable in their original format and are not migrated or uploaded. Paid reports remain unavailable in a release or platform that has not passed this local-report capability gate.
After a local report is generated and saved, the app submits an idempotent entitlement confirmation containing only a random report ID, generator version, report language and authenticated purchase context. It is used to consume one single-report credit or confirm an active subscription. Repeating the same report ID after a crash or network failure cannot consume access twice. No snapshot hash or financial data is stored for this operation.
Aggregate product events
SteadyStep records a small set of first-party product events to understand whether onboarding, planning, repayment tracking, report previews, purchasing and exporting work as intended. Each event contains only an allowlisted event name, app version, language and time. A random event ID is retained as a keyed hash for up to 48 hours to prevent retry duplication; accepted events are stored only as daily aggregate counts. The payload contains no account, user, session, device, advertising, campaign, product or financial identifier and no financial value. These events are not used for advertising, profiling, sale or tracking across apps or websites.
Purpose and retention
Information is used to provide app functions, verify purchases, enforce report access, secure the service, handle deletion and support requests, and comply with legal obligations. Limited identity-provider, transaction, entitlement, metadata-only local-commit and security records may be retained as needed for fraud prevention, accounting, refunds, service integrity and law. Legacy consent or report-job metadata may remain only where required for compatibility or law; the local-report release does not create a new financial-snapshot job. We do not use this information for advertising or cross-app tracking.
Your choices
You can use free features without a SteadyStep account, sign out without deleting local data, delete your SteadyStep membership, or separately delete app financial records and reports. The in-app deletion control removes the signed-in membership and its server metadata; local records remain under your control until you delete them in the app or remove the app's data. Daily aggregate event counts cannot be connected back to you. You can also follow the instructions on the account deletion page. Residents of the United States and other supported regions may contact us to request access, correction or deletion where applicable. We do not sell or share personal information for cross-context behavioural advertising.
Security, children and changes
SteadyStep uses TLS, Keychain storage, private CloudKit storage, signed transaction verification, strict request schemas, access controls and retention limits. No system is completely secure. SteadyStep is not designed for children. If you are below the age at which you can consent to data processing or contracts where you live, use SteadyStep only with permission from a parent or legal guardian. SteadyStep does not ask for a date of birth, and free planning does not transmit financial records to SteadyStep. Material changes will be reflected here and, where required, in the app.
繁體中文
本通知適用於穩行計劃的 iOS 及 Android 版本。實際可用功能可能因裝置、商店地區及發佈版本而異。
營運者
穩行計劃由個人開發者 Hanghang Yu 營運。私隱問題可電郵至 steadystep@yeah.net。
儲存在 App 內的資料
債務、收入、支出、還款及已完成報告儲存於你裝置內的 App 私有儲存。iOS 版本可在 iCloud 可用時將資料儲存於你的私人 iCloud 資料庫;Android 版本的合資格本機資料,可依你的裝置設定納入加密系統備份。穩行計劃不會為免費使用者建立公開個人檔案或廣告帳戶。
付費帳戶與購買資料
免費規劃無須建立穩行計劃帳戶。購買、恢復付費權益及解鎖完整報告時,iOS 的「透過 Apple 登入」或 Android 的 Google 登入會將經驗證的 App Store 或 Google Play 交易、權益及刪除中繼資料與假名化會員記錄關聯。穩行計劃會收到核實帳戶所需的身份權杖,但不會收到你的帳戶密碼。付款卡資料由 Apple 或 Google 處理,穩行計劃不會收到。
裝置端完整報告
在 iOS 1.2 本地報告版本中,餘額、利息、日期、還款次序、行動、警示及報告文字均由裝置上的確定性程式產生。新的報告請求不會把財務快照、原始或衍生財務數值、貸款方或債務名稱、付款記錄、備註或報告內容傳送至穩行計劃伺服器或第三方自動化處理商。既有的已完成報告會繼續以原有格式讀取,不會遷移或上載。尚未通過本地報告能力檢查的版本或平台,付費報告會保持不可用。
本地報告產生並儲存後,App 會提交具冪等性的權益確認,只包含隨機報告 ID、產生器版本、報告語言及經驗證的購買內容。伺服器以此消耗一份單次報告權益,或確認有效訂閱。崩潰或網絡失敗後重送同一報告 ID,不會重複消耗權益。此操作不會儲存快照雜湊或財務資料。
匯總產品事件
穩行計劃會記錄少量第一方產品事件,協助了解新手流程、規劃、還款記錄、報告預覽、購買及匯出是否正常。每項事件只包含白名單事件名稱、App 版本、語言及時間。隨機事件 ID 最多以帶密鑰雜湊保留 48 小時,只用於避免重試時重複計數;已接受事件只保存為每日匯總數量。請求不包含帳號、使用者、工作階段、裝置、廣告、活動、商品或財務識別碼,也不包含財務數值。這些事件不會用於廣告、建立個人檔案、出售或跨 App/網站追蹤。
用途與保留
資料用於提供 App 功能、驗證購買、執行報告權益、保障服務安全、處理刪除和支援請求,以及履行法律義務。為防止詐騙、會計、退款、服務完整性或遵守法律要求,有限的身份提供者、交易、權益、只含中繼資料的本地提交及安全記錄可能需要保留。舊版同意或報告任務中繼資料只會在相容性或法律要求下保留;本地報告版本不會建立新的財務快照任務。我們不會將這些資料用於廣告或跨 App 追蹤。
你的選擇
你可以在沒有穩行計劃帳戶的情況下使用免費功能、登出而不刪除本機資料、刪除穩行計劃會員帳戶,或另行刪除 App 內的財務記錄與報告。App 內的刪除功能會移除已登入會員及其伺服器中繼資料;本機記錄仍由你控制,直至你在 App 內刪除或清除 App 資料。每日匯總事件數量無法連回個別使用者。你亦可依照帳戶刪除頁面的指示提出請求。美國及其他支援地區的居民可聯絡我們提出適用的查閱、更正或刪除請求。我們不會出售個人資料,亦不會為跨情境行為廣告而分享資料。
安全、兒童與變更
穩行計劃使用 TLS、Keychain 儲存、私人 CloudKit 儲存、已簽署交易驗證、嚴格請求格式、存取控制及保留期限。任何系統均不能保證絕對安全。穩行計劃並非為兒童而設。未達所在地可自行同意資料處理或訂立合約年齡的使用者,只應在父母或法定監護人允許下使用。穩行計劃不會要求出生日期,而免費規劃不會把財務記錄傳送給穩行計劃。重大變更會在此及 App 內更新。