简体中文

Pigni Privacy Policy

Pigni is local first. This policy explains which information is processed only on your device, and which information is sent to Apple, a third-party AI service you configure, or another necessary service when you choose to enable an online feature.

1. Information We Process

Your ledgers are stored on your device by default. Information you enter or import may include amounts, currencies, dates and times, merchants, categories, accounts, notes, tags, budgets, refund or reimbursement relationships, transaction candidates, and import records.

When you use screenshot recognition, the app processes the photos or bill screenshots you select, OCR text, and recognition results. When you use voice bookkeeping, it processes recordings and transcribed text. The app also stores feature settings, AI model configurations, membership status, and structured diagnostic logs that exclude transaction content, amounts, merchants, images, prompts, and keys.

When you submit feedback, the app sends your feedback text, app and operating system versions, device type, and language and region. Contact details, screenshots, and structured diagnostics are sent only if you choose to include them. Structured diagnostics contain only fixed stages, results, anonymous correlation IDs, durations, and approximate counts. They exclude ledgers, amounts, merchants, accounts, screenshot content, original OCR text, AI prompts or responses, URLs, and keys.

2. Local Storage and System Permissions

Camera, photo, microphone, speech recognition, notification, and Face ID / Touch ID permissions are requested only when the relevant feature needs them. You can withdraw them in system settings; doing so may make the corresponding feature unavailable. The app receives only whether biometric authentication succeeded, not your biometric templates.

Where your region, operating system, and the app's signing capabilities support it, the FinanceKit transaction picker provides the app with only the transactions you explicitly select for that operation. Pigni stores them as local candidates awaiting confirmation. It does not automatically post them to a ledger, send them to a Pigni server, or retain the original FinanceKit account identifiers. If you separately enable iCloud backup, these saved transaction candidates may be included with other candidate records in the backup.

Third-party AI API keys are stored only in the local Keychain and are used to authenticate with the selected service. They are not included in model message content, ledger exports, or iCloud backups. You can remove a key when deleting its model configuration. Spotlight indexing is off by default; when enabled, it stores only merchants, categories, and dates in the on-device index.

3. AI and OCR

Third-party AI is optional and off by default. The app sends a data type to third-party AI only after you configure and enable a model, the model and request endpoint fall within the permitted scope below, and you turn on that specific data type in Me → Privacy & Security → Data & Privacy. You can also reach this page through AI Models → AI Recognition Settings. Access does not require membership, so you can review recipients or withdraw consent at any time. Enabling a data switch provides ongoing consent for subsequent uses of the same feature type. Some features in the foreground also show the data scope and ask for confirmation before that operation sends it. When you upgrade to this version, earlier AI authorizations become invalid. You must review the current scope and actively authorize it again.

The app retains presets for Alibaba Cloud Model Studio (dashscope.aliyuncs.com), DeepSeek (api.deepseek.com), Zhipu Open Platform (open.bigmodel.cn), Kimi Open Platform (api.moonshot.cn), SiliconFlow (api.siliconflow.cn), and Volcengine Ark (ark.cn-beijing.volces.com), as well as custom Base URL configurations. Presets do not include a developer account or API key, enable data authorization, or send data automatically. **Only the verified scope below may receive your financial content in this version. Other models, presets, and custom routes may retain their configurations and keys and run capability tests using app-generated synthetic content, but cannot receive your financial content.** Saving or enabling a connection, retrieving a model list, or passing a capability test does not remove this restriction.

Within this general-purpose API scope, Model Studio processes data under the agreement and request instructions. Delegated processors are bound by purposes and instructions, and data is not used for model training without authorization. Processing required by law or regulators may still occur. This scope does not include additional authorizations or special agreements that change data-processing purposes. When Pigni learns of changes to applicable terms, the model supplier, or the processing scope, it will review the affected route again rather than continuing to permit it based solely on a model name or saved configuration.

Implicit context caching for ordinary Chat requests is automatic and cannot be disabled. It has no uniform fixed retention period; the provider periodically clears caches that have not been used for a long time. Records needed for the service or required by law may also be retained. Correction or deletion can be requested under the service agreement, but legal, security, or backup-related technical restrictions may prevent immediate removal of some copies. A short expiry for explicit caching is not a maximum retention period for all data. Pigni's withdrawal switches cannot delete data the provider has already received. You can contact Pigni for help with rights requests as described in Section 7.

Settings show the selected recipient's provider name, Base URL, model, and protection scope. For features that support automatic fallback, enabling “Automatically try fallback models after failure” allows the same authorized data to be sent only to listed fallback models that still fall within the permitted scope in this section. Unverified routes cannot receive it as fallbacks. A custom Base URL identifies only the direct request endpoint; it does not establish the operator behind it, onward forwarding, or the processing region. An address or a successful connection alone therefore does not enable financial-data sending.

The switches may allow the following data to be sent for the following purposes:

To parse data according to your settings, the requests described above may also include your configured prompt templates and JSON Schema, category names and keywords, and the applicable default currency and date. The app does not put third-party AI API keys in business message content, ledger exports, or iCloud backups. Report summaries are processed locally and are not sent to third-party AI.

Text and vision capability tests use only synthetic content generated by the app. They do not read your ledgers, screenshots, recordings, imported files, or financial text you have entered. Tests still send authentication credentials and necessary request information to the configured service. Passing a test demonstrates only that the capability worked for that test; it does not establish verified protection or permission to send financial data.

Turning off a data switch stops requests of that type that have not yet been sent, including retries and fallback model requests. Deferred tasks recheck the authorization version, recipients, routing, and protection scope before sending. Turning a switch back on does not resume old tasks; you must start the operation again. Creating, editing, enabling, or disabling a provider, changing model routing, or changes to recipients or protection scope invalidate existing authorization and unfinished old tasks. You must review the new scope in Data & Privacy and authorize it again. Re-enabling a switch cannot permit an unverified route to receive financial data. Turning off a switch cannot recall data already received by a third party; its retention and deletion remain subject to applicable terms and legal exceptions.

Pigni is responsible for checking the operators and applicable API terms of the third parties it connects to, including data purposes, security, retention, deletion, further sharing, and cross-border processing, and for requiring recipients to provide the same or equivalent protection for shared data as required by this policy and applicable app review rules. Reading terms, saving a configuration, or enabling a switch expresses your informed choice for a specific operation. It does not replace Pigni's verification of protection or require you to guarantee a third party's conduct. Reviewing public sources is not an independent security audit or Apple approval. You can leave external AI disabled and continue using basic on-device features. If the selected vision model or route is unavailable, the app explains its unavailability and any applicable local processing; it does not silently describe OCR text processing as visual recognition of the original image.

4. iCloud Backup

iCloud backup is off by default and is an optional membership feature. When enabled, the app can save ledgers, candidate records, accounts, categories, rules, preferences, and AI configurations without API keys to Apple CloudKit according to your actions or settings. This is a backup, not real-time merging between multiple users.

Source screenshots are not included in new iCloud backups. Source images stored on your device can be removed within the safeguards provided in Ledgers & Data → Storage. Turning off automatic backup stops future automatic uploads; it does not delete existing cloud backups. Older backups that included source screenshots are not automatically deleted when you turn off the switch. On the iCloud Backup page, you can delete all LedgerSnapshot cloud backups. Deletion does not require an active membership or automatic backup to be enabled, and it does not delete your local ledgers. CloudKit data is processed by Apple infrastructure and is subject to your Apple ID, iCloud settings, and Apple's terms.

5. Other Online Services

6. Purposes and Sharing Boundaries

We process information only for bookkeeping, recognition, analysis, search, backup, subscription verification, security, diagnostics, and exports you explicitly request. The app does not integrate advertising tracking SDKs, sell personal information, or build advertising profiles from ledger content.

Ledger content is not provided to recipients other than the Apple services and exchange-rate service listed in this policy, third-party AI routes permitted under Section 3 and explicitly authorized by you, export destinations you actively select, and the operator's own server receiving content you choose to include when you voluntarily submit feedback, unless disclosure is legally required.

7. Retention, Deletion, and Withdrawal

Local data is generally retained until you delete its records or clear or remove the app's data. Some deleted transactions remain briefly in Recently Deleted as explained in the app. The system may retain Keychain keys after the app is uninstalled. Please delete or clear them in AI model settings first.

Up to 20 feedback history entries are stored on your device. Feedback and attachments on the server are used only for customer support, replies, security, and abuse prevention, and are retained for a maximum of 180 days by default. You can delete a feedback entry and its server records, attachments, and public replies through the app's feedback history, or request deletion using the contact details in this policy. After deletion, a minimal deletion record may be retained for up to 30 days to complete interrupted cleanup and ensure repeated deletion requests are handled consistently. It excludes feedback content and the original client capability identifier.

You can view, correct, export, and delete ledger data in the app, turn off iCloud backup, Spotlight, notifications, third-party AI models, or any AI data switch, and withdraw system permissions in system settings. Turning off AI data switches stops future sending. Data already received by a third-party service remains subject to that service's retention, use, and deletion rules.

To exercise rights such as access, copying, correction, deletion, restriction of processing, or withdrawal of consent, please contact us using the details on this page. For data already sent to third-party AI, Pigni will help direct your request to the applicable recipient, explain necessary identity verification and information needed to locate the request, and inform you of the outcome or why it could not be completed. Requests remain subject to legal retention requirements, other people's lawful rights, and applicable technical limitations. Deleting local data, withdrawing consent, or submitting a request does not itself mean all remote records and backups have been deleted.

8. Security Measures

The app uses the system sandbox, Keychain, an optional biometric lock, and a privacy cover while in the background to reduce the risk of unauthorized access. No storage or transmission method can guarantee absolute security. Please protect your device, Apple ID, and third-party service keys.

9. Children

The app is not primarily intended for children under 14. If you are under 14, use it with a guardian's consent and guidance. If you discover that relevant information has been processed without guardian consent, please contact the operator.

10. Cross-Border Processing

In this version, third-party AI may receive financial data only within the Beijing access and storage and mainland China inference scope in Section 3. Synthetic capability tests for other configurations or custom addresses may be processed outside mainland China, but cannot include your financial content. A Base URL or provider name alone does not establish the underlying processors or regions. Before making a future route involving cross-border financial-data processing available, the operator must verify its recipients and protection scope, provide specific disclosure, and meet any applicable requirements for separate consent or other conditions. Saving an overseas address does not automatically enable such a route. You can leave external AI disabled.

11. Updates and Contact

If features or processing practices change materially, we will update this policy and notify you through in-app notices or other reasonable means. Where renewed consent is legally required, we will request it again.

Personal information controller: Chentao Fan Privacy contact: xxxkkk0101@foxmail.com