中文(默认) · English below

拍菜记 隐私政策

更新日期:2026-08-11 · 适用应用:拍菜记(AIDineLog,iOS)

拍菜记是一款餐饮单据识别与记账应用。我们的原则是:账单数据属于你,默认保存在你的设备上;我们只在提供识别服务所必需的范围内处理最少量的数据。

1. 我们如何处理你的数据

1.1 本地存储

默认情况下,你的账单(商家、日期、金额、菜品、标签、备注)和单据照片保存在你设备的本地数据库中。应用没有自建账号体系,你无需注册即可使用记账功能。

1.2 iCloud 同步(Pro,可选)

当你主动开启 iCloud 同步时,账单、菜品、自定义标签,以及设备上已保留的单据照片会保存到你的 Apple iCloud 私有数据库,并在登录同一 Apple 账户的设备间同步。单据照片没有单独的“仅不同步”开关;如果你在“我的 → 数据”关闭“保留单据照片”,已保留的照片会从本机、iCloud 及其他同步设备删除,但账单字段仍会保留。API Key、官方 AI 使用额度和订阅状态不会保存到 iCloud。iCloud 数据由 Apple 根据其隐私政策处理;开发者无法通过本应用查看你的 iCloud 私有数据。

1.3 官方 AI 识别

使用官方 AI 识别时,应用先在你的设备上通过 Apple Vision 完成文字识别(OCR),然后将识别出的文本(不含照片)与目标语言、应用版本一起发送到我们的服务器,由服务器调用第三方大语言模型完成结构化识别。我们的服务器不会将你的 OCR 文本、单据照片或识别结果正文写入数据库;第三方 AI 服务可能按其技术机制短期缓存请求内容,通常在数小时至数天内清理,具体处理以该服务的隐私政策为准。我们仅保存与随机设备标识关联的用量记录(时间、Token 数量、耗时、成功状态与错误码),用于额度计量与服务质量分析。

1.4 自定义 AI(Pro)

Pro 用户可配置自己的第三方 AI 服务(如 DeepSeek、OpenAI 等)。此时 OCR 文本(若开启图像识别,还包括单据照片)由应用直接发送到你选择的第三方服务,不经过我们的服务器;你的 API Key 仅保存在设备钥匙串中。第三方服务对数据的处理适用其各自的隐私政策。

1.5 设备标识与订阅

应用生成一个随机设备标识(UUID,保存在设备钥匙串,与广告无关),用于免费识别额度计量。订阅 Pro 时,Apple 的签名交易信息(订单标识、产品、到期时间)会发送到我们的服务器用于验证订阅有效性;支付由 Apple 完成,我们不接触你的付款信息。

1.6 购买流程分析

为了判断 Pro 功能介绍是否清晰、定位购买流程中的技术问题,应用会向我们的服务器发送最少量的产品交互事件,包括付费页面展示来源、套餐选择、购买或恢复购买的开始与结果、应用版本、系统语言、额度区间及标准化错误类型。这些事件与随机设备标识关联,但不包含单据内容、照片、商家、金额、付款资料、Apple 收据正文或自由文本错误信息。我们不接入第三方分析 SDK,不将这些数据用于广告或跨应用跟踪;原始事件保留不超过 90 天,之后删除。

1.7 汇率

识别到外币单据时,应用会向我们的服务器请求对应日期的参考汇率;该请求不包含你的账单内容。

2. 我们不做的事

3. 数据保留与删除

删除应用会删除该设备上的本地账单数据与照片。如果你开启过 iCloud 同步,仅删除某台设备上的应用不会自动删除 iCloud 中的同步副本;重新安装或在其他设备开启同步时,数据可能再次恢复。你可以在应用中删除记录并完成同步,或在系统的 iCloud 存储管理中删除本应用的 iCloud 数据。购买流程原始事件保留不超过 90 天。服务器上与随机设备标识关联的用量记录可通过邮件申请删除(提供应用内“开发者选项/关于”中的设备标识)。订阅记录按法律与财务要求保留。

4. 儿童隐私

本应用不面向 13 周岁以下儿童。

5. 政策变更

政策更新时,我们会修改本页面并更新生效日期;重大变更会在应用内提示。

6. 联系我们

邮箱:mu514983786@gmail.com


中文在上方 · English

PaiCaiJi Privacy Policy

Updated: August 11, 2026 · Applies to: AIDineLog (拍菜记) for iOS

PaiCaiJi is a receipt-scanning and food-expense tracking app. Our principle: your records belong to you and stay on your device by default; we process only the minimum data needed to provide recognition.

1. How your data is handled

1.1 Local storage

By default, your records (merchant, date, amounts, items, tags, notes) and receipt photos are stored in a local database on your device. The app has no developer-operated account system and requires no sign-up.

1.2 iCloud Sync (Pro, optional)

When you enable iCloud Sync, receipts, items, custom tags, and receipt photos currently retained on the device are stored in your private Apple iCloud database and synchronized between devices signed in to the same Apple Account. Receipt photos do not have a separate sync-only switch. If you turn off Keep Receipt Photos under Me → Data, retained photos are removed from this device, iCloud, and other synced devices, while receipt details remain. API keys, official AI quota, and subscription status are never stored in iCloud. Apple handles iCloud data under its privacy policy; the developer cannot view your private iCloud data through this app.

1.3 Official AI recognition

With official AI recognition, text is first extracted on-device using Apple Vision (OCR). The extracted text (not the photo), plus your display language and app version, is sent to our server, which calls a third-party large language model to structure it. Our server does not write your OCR text, photos, or recognition results to its database. The third-party AI provider may temporarily cache request content as part of its technical operation, typically clearing unused caches within hours to days; its own privacy policy governs that processing. We retain only usage records linked to a random device identifier (timestamp, token counts, latency, success status, and error codes) for quota metering and service quality.

1.4 Bring-your-own AI (Pro)

Pro users may configure a third-party AI service (e.g. DeepSeek, OpenAI). In that mode OCR text (and, if you enable image recognition, the photo) is sent by the app directly to the provider you choose and never passes through our server. Your API key is stored only in the device Keychain. The provider's own privacy policy applies.

1.5 Device identifier & subscriptions

The app generates a random UUID (stored in the Keychain, unrelated to advertising) to meter the free recognition quota. When you subscribe, Apple's signed transaction (order identifier, product, expiry) is sent to our server to verify entitlement. Payment is handled entirely by Apple; we never see your payment details.

1.6 Purchase funnel analytics

To understand whether the Pro explanation is clear and diagnose technical problems in the purchase flow, the app sends a minimal set of product-interaction events to our server: where the paywall was opened, plan selection, the start and result of purchase or restore, app version, display language, quota range, and a standardized error category. These events are linked to the random device identifier, but never include receipt content, photos, merchants, amounts, payment details, Apple receipt bodies, or free-form error messages. We use no third-party analytics SDK and do not use this data for advertising or cross-app tracking. Raw events are retained for no more than 90 days and then deleted.

1.7 Exchange rates

For foreign-currency receipts the app requests a reference exchange rate for the receipt date from our server. That request contains no receipt content.

2. What we don't do

3. Retention & deletion

Deleting the app removes local records and photos from that device. If you previously enabled iCloud Sync, deleting the app from one device does not automatically remove its iCloud copies; reinstalling the app or enabling sync on another device may restore them. You can delete records in the app and allow the deletion to sync, or remove this app's data in iCloud storage settings. Raw purchase-funnel events are retained for no more than 90 days. You may request deletion of server-side usage records linked to the random device identifier by email (include the device identifier shown in the app's About section). Subscription records are retained as required by law and accounting.

4. Children

The app is not directed at children under 13.

5. Changes

We will update this page and its effective date when the policy changes; material changes will be announced in the app.

6. Contact

Email: mu514983786@gmail.com