Privacy Policy for "Inks / 见字"
Version: v1.3
Effective Date: August 28, 2026
📋 Basic Information
- Developer: Wenpeng Wang (Indie Developer)
- Contact Email: hachineko@yeah.net
- Contact WeChat: nekooohachi
- Scope: The Inks app and official website. The app is currently available on the Apple App Store in Mainland China, the United States, the United Kingdom, Australia, and Canada.
- System Support: iOS 17.0 or later. Requirements may vary by the version currently available on the App Store.
🎯 Important Notes
We value your privacy. This app adopts a "Local First" design:
- ✅ Letter content is stored only on your device by default and is never automatically uploaded to servers
- ✅ No user tracking: We do not use advertising identifiers (IDFA) and do not conduct cross-app or cross-site tracking
- ✅ No data selling: We will never sell your personal information to third parties
- ✅ You are in control: You can disable analytics at any time and use the export, deletion, and account-management controls available in the current version
📊 Data Collection Overview
The table below summarizes the types of data we may collect. None of the collected data is used for tracking purposes.
| Apple Data Type Category | Specific Data Items | Collection Purpose | Linked to Your Identity | When Collected |
|---|---|---|---|---|
| Contact Info | Email Address | • Apple Sign-In authentication • Privacy request result notification | Yes | • When using Apple Sign-In • When submitting privacy requests |
| Contact Info | Name (Nickname) | Account profile display | Yes | When you actively set your account profile |
| Identifiers | Local profile ID | • Local profile and app state • Cloud sign-in source association | Yes | Generated locally on first launch; sent to the self-hosted backend during cloud sign-in |
| Identifiers | Cloud account user ID | • Cloud account identification • Profile and entitlement association | Yes | When you sign in or use a related cloud feature |
| Identifiers | Analytics actor ID | Distinguishing analytics records after consent | Yes | After analytics is enabled; generated separately while signed out, with the cloud account ID used after sign-in |
| Identifiers | Device ID | • Consented analytics • Cloud sign-in • Purchase verification and device authorization | Yes | Generated or loaded locally on first launch; transmitted only after analytics consent or when a related cloud feature is used |
| Purchases | Purchase History | • Verifying purchase legitimacy • Restoring purchase entitlements • Purchase conversion analysis | Yes | • When making in-app purchases • When restoring purchases • When analytics is enabled |
| User Content | Photos or Videos | • Setting avatars • Uploading custom stickers • Letter decoration | Yes | When you actively select images |
| User Content | Other User Content | Letter creation & storage (handwriting, text, stickers, metadata) | Yes | When creating letters (local storage only) |
| Usage Data | Product Interaction | Analyzing feature usage to improve experience | Yes | When analytics is enabled |
| Usage Data | Other Usage Data | Technical metadata (device model, system version, etc.) | Yes | When analytics is enabled |
| Diagnostics | - | Not collected | - | - |
| Other Data | Other Data Types | Session identifiers, configuration information, and necessary network-request information | Yes | During app runtime (necessary technical information) |
📌 Key Notes:
- Data marked “Yes” is linked to your Inks account, device authorization, or analytics identity. This does not mean cross-app tracking. We do not associate these identifiers with other companies' apps or websites.
- The local profile ID and analytics identity are separate. A local profile ID is created on first launch for on-device app state and is transmitted during cloud sign-in as account-source context. It is not used to derive the analytics actor ID.
- A random signed-out analytics actor is not already linked to a cloud account. It is marked “Yes” here under Apple's conservative definition because the anonymous phase may later be associated with the signed-in phase in analytics queries.
- In-app analytics requires you to actively enable the Data Analytics/Sharing toggle. You can turn it off at any time. Basic website traffic analytics is described in Section 1.8.
- Letter content (body text and attachments) is excluded from analytics. Relevant content is processed only when you actively choose to share, export, or upload a related resource.
- Live location and unlock snapshots used by location locks are processed only on the device. They are not uploaded to the developer or analytics services and are therefore not treated as collected Location data in Apple's privacy label.
1. Information We Process (Details)
1.1 Content You Create (Letters/Writing)
Corresponding Apple Data Type: Other User Content
What is collected:
- Letter body text, titles, handwritten doodles, text blocks, stickers, metadata
- Letter lists, writing content, letter access configurations, etc.
Storage location:
- ✅ Stored only on your device by default
- ❌ Never automatically uploaded to our servers
How it is used:
- Writing your first letter, local browsing, viewing statistics, and other basic experiences can be completed without signing in
- Creating additional letters requires signing in with an Apple account to register a cloud account (but letter content remains local only)
- Letters protected by a password or security question are encrypted using that credential. Letters without access protection should not be understood as strongly encrypted by default.
When it may be transmitted:
- When you actively choose to export, use the system share sheet, or upload custom resources
- Related files or resources will be processed locally or transmitted over the network according to the action you choose
What we do NOT do:
- ❌ Do not automatically upload your letter content as cloud backup
- ❌ Do not read or report letter body text through analytics
- ❌ Do not transmit letter content without your explicit action
File access:
- This app supports File Sharing, allowing you to manage locally stored .mbx files via iTunes/Finder
1.2 Cloud Account & Sync Data
Corresponding Apple Data Types:
- Email Address
- Name — corresponds to the "Nickname" you set
- User ID
- Device ID
When it is collected:
When you actively use the following cloud features:
- Apple Sign-In
- Cloud account profile management
- Badge system
- Entitlement restoration
- Custom avatar or custom sticker upload
What it includes:
- Apple Sign-In information: Identity credentials, Apple user identifier, email (if provided by Apple)
- Account profile: Nickname, birthday, motto, avatar
- Entitlement status: Purchase entitlements, subscription status, device authorization, feature trial quota, badges
- Custom resources: Custom avatars, custom stickers you actively upload
- Technical information: Device identifier, device model, system version, app version, language, time zone
Why this data is needed:
- Account identification: Distinguish between different users and provide a personalized experience
- Entitlement management: Record your purchase status and support cross-device entitlement restoration
- Resource sync: Provide cloud storage for supported features (such as avatars, custom stickers)
Important notes:
- ✅ Account profile sync is only used for cloud account, entitlements, badges, avatars, custom stickers, and other cloud-connected features
- ❌ The current version does not automatically upload letter body text, attachments, or letter resources as cloud backup
1.3 Usage Analytics
When you enable "Data Analytics/Sharing", we may collect and report event data NOT containing letter content, used to improve experience and optimize paywall performance, such as:
- Feature usage events: Which features/visual effects are used, usage frequency, etc.
- Setting events: Whether "Data Analytics/Sharing" is enabled/disabled.
- Paywall related events: Trigger source, dwell time, page interactions, etc.
- The above events may include necessary technical context fields, such as device model, system version, and app version (see 1.5 for details).
We DO NOT collect or upload any letter body, letter list, or privacy text in analytics.
Regional processing routes in production:
- Mainland China App Store storefront: analytics data is sent to the developer's self-hosted AnalyticsHub.
- United States, United Kingdom, Australia, and Canada App Store storefronts: analytics data is sent to PostHog US.
- If the storefront is temporarily unavailable or unsupported, or the installation is not a supported App Store production release, analytics is not initialized in production.
- App language, device language, and device region are not used to choose the analytics provider. AnalyticsHub and PostHog operate independently and do not fall back to or retransmit data to each other.
Offline & Retry Mechanism: When the device is offline, events may be temporarily stored in a local queue; they will be sent automatically when the connection is restored. If you disable "Data Analytics/Sharing", event reporting will stop.
1.4 In-App Purchases
- Purchases and payments are processed by Apple. We do not collect payment information such as bank card numbers.
- We may submit App Store transaction credentials or transaction status to our self-hosted backend to verify purchases, bind cloud account entitlements, restore entitlements, and process device authorization.
- When you enable "Data Analytics/Sharing", we report purchase-related events (such as paywall views, purchase success/failure, restore purchases, etc.) to analyze conversion rates and optimize user experience. These events do not contain sensitive payment information, only necessary fields like Product ID and Source Page.
1.5 Technical Information & Identifiers (For Analytics, Account, and Security)
When Data Analytics/Sharing is enabled, or when you use cloud account, purchase verification, or privacy request features, we may process the following technical information to provide analytics, account services, and security:
- Device & App Information: Device model, system version, app version, language, time zone, etc.
- Identifiers:
- Local profile ID: Generated on first launch and stored in the local database and Keychain for the local profile and app state. It is sent to the self-hosted backend as source-association context during cloud sign-in, but it is not the stable cloud-account identity or the analytics actor ID.
- Cloud account user ID: Used for account profiles, entitlements, and related cloud features after sign-in.
- Analytics actor ID: Used only after you enable analytics. While signed out, it is a random identifier isolated by backend environment and analytics project; it is not derived from the local profile ID, Apple user identifier, or hardware identity. After sign-in, analytics events use the cloud account user ID, and the earlier anonymous phase may be associated with the signed-in phase in analytics queries.
- Device ID: Created or loaded locally on first launch. Inks uses the system-provided Identifier for Vendor (IDFV) where available; otherwise it uses a random identifier stored in Keychain. It is transmitted only after you enable analytics or use cloud sign-in, purchase verification, device authorization, or another related cloud feature.
- Session ID: A temporary identifier created for an analytics session after analytics is enabled.
- Network Information: When your device sends data to our servers, your Internet Protocol (IP) address is automatically recorded in server logs as part of a standard HTTP request. We collect IP addresses for:
- Prevention of abuse and abnormal access detection (e.g., frequent requests, malicious attacks);
- Technical troubleshooting and service stability monitoring.
We do not actively use IP addresses to identify you, and we do not convert them into precise or coarse location profiles. Server logs are cleaned regularly, and IP addresses are typically retained for no more than 90 days.
1.6 Privacy Request Contact Information (Export/Delete Request)
When you initiate an export or deletion request for statistical data in the App Settings page, we process the following additional information:
- Contact Email (contactEmail): Used to notify you of the processing results.
- Request Note (requesterNote, optional): Used to assist manual processing.
- Request Metadata: Such as request time, device identifier, user identifier, region information, app version, etc.
The above information is used only to process your data rights requests (export/delete) and for audit logging, not for advertising.
1.7 Biometric Features (FaceID / TouchID)
When you use security features like "App Lock" or "Hidden Letters", we may invoke the iOS local authentication framework.
- Local Validation Only: The validation process takes place entirely within your device's Secure Enclave.
- No Collection: We cannot access, store, or upload your raw biometric data (face, fingerprint). The app only receives a "Success" or "Failure" result returned by the system.
1.8 Basic Website Traffic Analytics
Optional website analytics are off by default. Only after you choose “Allow analytics” does the site send basic page-view events to the developer's self-hosted AnalyticsHub in Mainland China. We use this information to check that pages work and understand which help content is visited most often. Declining does not affect the website.
The information may include:
- page path and title;
- the path of a referring page on this site, or the domain of an external referring site;
- browser language;
- visit time;
- a randomly generated website visitor identifier (ah_did);
- the IP address and necessary server logs produced by a standard network request.
The site does not send URL query parameters or page fragments. After you allow analytics, AnalyticsHub sets an HttpOnly first-party cookie named ah_did. It is limited to the current website host and lasts for up to 180 days. If the network is unavailable, up to 50 pending events created within the previous 24 hours may be kept temporarily in local browser storage.
Necessary local storage remembers whether you allowed or declined analytics for up to 180 days. This preference is not used for analytics. You can reopen Analytics settings from the website footer at any time. When you withdraw consent, the site stops sending new events, clears its pending queue, and asks AnalyticsHub to remove ah_did from your browser. Withdrawal does not affect aggregate processing already completed.
The website visitor ID is not linked to letters, cloud accounts, or purchase records in the Inks app. It is not used for advertising, profiling, or cross-site tracking. Website analytics is processed by AnalyticsHub in Mainland China, so visits from other countries or regions may involve an international data transfer. You can use the contact details in this policy to ask questions or request access to or deletion of identifiable data associated with this ID.
2. Permissions Usage
Photo Library Usage Description:
When you choose to save statistical cards, letter screenshots, exported images, or Live Photos to your album, the app requests add-only photo library permission. When you actively select images for avatars, custom stickers, or letter decoration, the app reads only the images you choose. We only process content that you actively select or save.
FaceID / Biometric Usage Description:
We use FaceID/TouchID to protect your letter privacy, used only for locally unlocking the app or hidden content. When you enable App Lock or access hidden content, the app requests authentication. This permission is used only for local verification to protect your privacy; we do not acquire your biometric data.
Motion Usage Description:
We use device motion sensors to provide dynamic lighting effects for stickers.
Location Usage Description:
We need your location information (only while using the app) to provide location-based letter unlock features (such as "arrive" or "stay" restrictions). Location unlock conditions you set are stored locally with the letter access configuration. Runtime geofence checking is completed on your device, and we do not upload your real-time location or movement tracks to any server.
3. Information Sharing & Third-Party Services
We do not sell your personal information. In-app analytics runs only after you enable Data Analytics/Sharing. Website analytics runs only after you allow it. Relevant service providers include:
- PostHog Cloud (US region): For product analytics in App Store production releases from the United States, United Kingdom, Australia, and Canada storefronts.
- AnalyticsHub (the developer's self-hosted service in Mainland China): For product analytics in the Mainland China App Store production release and basic website analytics that a visitor has allowed.
- The developer's self-hosted privacy request system: For receiving export or deletion requests, tracking their status, and sending results.
- Apple: For Apple account sign-in, App Store in-app purchases, subscription management, refunds, and other system capabilities.
- Developer's self-hosted cloud services: For cloud account sign-in, account profiles, avatars, custom stickers and other cloud-connected custom resources, badges, entitlements, purchase verification, device authorization, and remote configuration.
After you submit an export/deletion request, the developer will perform manual processing on the corresponding processing platform (AnalyticsHub / PostHog) and fill the results back into the ticketing system.
Shared data does not contain letter content or private text. We take reasonable measures to limit the scope of data use.
For App Store storefronts in the United States, United Kingdom, Australia, and Canada, app analytics data is processed by PostHog US. Website analytics is processed by AnalyticsHub in Mainland China. Each is enabled only after the relevant choice is made, and you can withdraw that choice in app settings or website Analytics settings.
4. Data Security & Storage
- Letter content is stored ONLY on your local device by default.
- Analytics data storage and transmission: App analytics for the Mainland China App Store storefront and website analytics are processed by AnalyticsHub in Mainland China. App analytics for the United States, United Kingdom, Australia, and Canada storefronts is processed by PostHog US. All network transmission uses HTTPS.
- Cloud account profiles, avatars, custom stickers and other cloud-connected custom resources, badges, entitlements, purchase verification, device authorization, and related data are stored in the developer's self-hosted cloud services to provide account and entitlement features that you actively enable.
- Privacy request ticket data (e.g., requestId, status, contact email, processing notes) is stored in the developer's self-hosted backend database for progress tracking and audit recording.
- Privacy request ticket data is retained for the period necessary to process requests, keep audit records, and comply with legal requirements. After the retention period, it will be deleted or anonymized unless otherwise required by laws and regulations.
- We take reasonable security measures (such as transmission encryption, access control, etc.), but internet transmission does not guarantee absolute security.
- This app does not use non-exempt encryption (ITSAppUsesNonExemptEncryption is false).
5. Your Rights & Choices
- Disable Data Analytics/Sharing: You can disable this feature in Settings; reporting stops immediately upon disabling.
- Boundaries of Revoking Consent: After turning off "Data Analytics/Sharing", only new statistical event reporting will stop; this does not affect processing activities already completed based on legal grounds prior to the withdrawal. Ticket and audit records related to export/deletion requests will be deleted or anonymized upon expiration of the statutory or necessary period.
- Website Analytics: Open Analytics settings from the website footer to allow or decline analytics. Withdrawing clears pending events and asks AnalyticsHub to remove the analytics ID from your browser. Declining does not affect the website.
- Request Export of Statistical Data: You can submit an export request in the Settings page. The system will create a ticket and return the request status. The final result will be notified via email and/or in-app status notification.
- Request Deletion of Statistical Data: You can submit a deletion request in the Settings page. The system will create a ticket and enter the manual processing flow.
- Export Letter Content: You can export a letter as .mbx. If it has no access protection, you can also export images, PDF, video, or Live Photo. A complete local-data package export is not currently available in Settings.
- Delete Local Content: You can delete individual or selected letters in the App. One-step deletion of all App data is not currently available in Settings. Deleting the App will still remove its local data, so back up important letters first.
- Delete Local Data (System Level): You can also delete local data by deleting the app; re-installing will generate a new local user identifier.
- Cloud Account Data: You can manage cloud account profile, avatar, and related content in the App profile/account pages. You can also request processing of cloud account profile, custom stickers and other cloud-connected custom resources, entitlement records, and related data through the contact methods listed in this policy. We will handle such requests according to account status, legal requirements, and necessary audit records.
- Cloud Account Deletion: You can delete your cloud account and associated cloud personal data in the App. Deleting a cloud account does not cancel App Store subscriptions. Subscription cancellation, refunds, and payment records must still be handled through your Apple account or Apple Support.
We handle requests to access, correct, delete, withdraw consent, or object to processing as required by applicable law, and respond within the applicable time limit. Users in the United Kingdom may also complain to the Information Commissioner's Office (ICO). Users in Australia or Canada may contact their local privacy regulator.
6. Protection of Minors
This app is intended for general users and is not specifically directed at children under 13. We do not knowingly collect personal information from children under 13; if discovered, we will delete it as soon as possible.
7. Updates to Policy
We may update this Privacy Policy from time to time. Major changes will be notified via in-app prompts or accessible locations.
8. Contact Us
Email: hachineko@yeah.net
WeChat: nekooohachi
*This document was updated to v1.3 on August 28, 2026 to reflect current availability and analytics routes, explain website analytics choices and how long its cookie and choice record are kept, and clarify exports for letters with access protection.*