HabitBox Privacy Policy / 一叶习惯隐私政策
English
1. Overview
HabitBox is a habit tracking and self-management app provided by JustToday. We respect your privacy and design HabitBox to keep your habit content on your device by default. You can use the core habit features without an account. An account is required only when you choose account-based membership services offered in certain distribution channels.
This policy explains what information HabitBox processes, why it is used, and the choices available to you.
2. Information stored on your device
HabitBox stores information such as the following locally on your device:
- Habits, goals, completion records, notes, and progress history
- Reminder schedules and notification preferences
- Appearance, language, calendar, widget, and other app settings
- Locally generated statistics and achievement progress
This content itself is not intentionally uploaded to JustToday servers as part of normal HabitBox use. On iOS and Google Play distributions, HabitBox may send only the aggregate usage counts and interaction information described in Section 6 for product analytics. It does not send habit names, notes, reminder text, or individual completion dates to the analytics service.
3. Accounts, memberships, and purchases
An account is optional and is used only for account-based membership services in supported distribution channels. Registering or signing in does not upload your habits, completion records, notes, selected images, or other local habit content.
When you use account features, JustToday processes:
- Email address: used to register, sign in, send verification codes, reset your password, identify your account, and contact you about account security.
- Password: transmitted to the HabitBox server over an encrypted HTTPS connection. The server stores only a password hash, not the plain-text password.
- Verification records: the verification purpose, a protected verification-code value, expiry time, resend limit, and failed-attempt count. The code record is deleted after successful use or expiry.
- Account and session information: an account identifier, account status, email-verification time, membership status, session expiry, and revocation status. The app stores the active session token in the operating system's secure storage; the server stores a hash of the token.
- Network and security logs: the HabitBox server may record the IP address, request time, request method and path, response status, and processing time needed to operate the service, investigate errors, prevent abuse, and protect accounts.
You can also use the password-reset function with your email address, verification code, and new password. Failed sign-in counters are temporarily processed to limit repeated attempts and protect your account.
Purchase processing depends on the distribution channel:
- Apple App Store and Google Play purchases may use RevenueCat to manage purchase status and entitlements.
- In supported mainland China distribution channels, payments are processed by Alipay. JustToday processes the order number, product, amount, payment status, Alipay transaction identifier, and membership entitlement needed to complete and verify the purchase. To measure when users choose to purchase, the order may also include a locally generated anonymous analytics identifier, the paywall entry source, estimated days since first use, and aggregate counts of habits, completed check-ins, active days, activity streak, and reminder-enabled habits at the time the order is created. It does not include habit names, notes, reminder text, or individual completion dates.
JustToday does not receive your full payment card number, Alipay payment password, or app store account password.
4. Device features and permissions
HabitBox requests or uses a device capability only when it is needed for the relevant function. The available capabilities vary by operating system and distribution channel.
| Capability or permission | Platform and trigger | Purpose and information handling | Effect of denial |
|---|---|---|---|
| Network access and network status | Android, iOS, and HarmonyOS; when you open a legal page, use an optional account, or purchase or restore membership | Connects to the HabitBox account service, the selected payment provider, RevenueCat where applicable, or a web page you choose to open. Habit content is not uploaded by account sign-in. | Online pages, account functions, and purchases may be unavailable; local habit tracking continues to work. |
| Notifications | Android, iOS, macOS, and HarmonyOS; when you enable reminders or request permission | Delivers habit reminders and optional persistent reminder-protection notifications. A notification may contain the habit name or reminder text and is generated on your device. | Habit reminders cannot be displayed. |
| Exact alarms or system alarms | Android and supported Apple platforms; when you enable a precise reminder or system-alarm mode | Schedules reminders at the time you choose, including iOS AlarmKit where available. | The reminder may be unavailable or delivered less precisely. |
| Background start after reboot, vibration, foreground service, and battery-optimization exemption | Android; used for reminder recovery or only when you enable the related reminder-protection option | Restores scheduled reminders after restart, vibrates for reminders, or keeps an optional ongoing notification visible. These capabilities do not read habit content for advertising or upload it. | Reminder reliability or vibration may be reduced. |
| Photo library or system photo picker | iOS and supported platforms; only when you choose an image for the lock-screen habit design | Reads only the image you select. The selected image is saved locally for that design and is not uploaded to JustToday servers. On supported Android versions, HabitBox uses the system photo picker instead of broad photo-library access. | You cannot add a custom image; other habit functions continue to work. |
| Clipboard | HarmonyOS and other supported platforms; only when you tap a paste action, such as pasting a custom color value | Reads the text you choose to paste. Copy actions write only the text you explicitly choose. Clipboard content is not uploaded. | Paste shortcuts are unavailable; you can still enter the value manually. |
| Local network | iOS; when required by the system AlarmKit presentation | Supports the local connection used by the system alarm presentation. HabitBox does not use this permission to discover or upload unrelated local-network data. | The system-alarm presentation may not work correctly. |
| Accelerometer | Supported devices; while an interactive star or achievement scene is open | Uses motion values to move visual elements. Sensor values are processed in memory on the device and are not stored or uploaded. | The scene remains usable but will not react to device tilt. |
| Widgets and shared app storage | Supported platforms; when you add a HabitBox widget | Shares only the selected local habit and display data with HabitBox's own widget extension. | The widget cannot display or update the selected habit. |
HabitBox does not use these permissions to build an advertising profile, and the current app does not include a third-party advertising SDK. You can change system permissions at any time in device settings. Disabling a permission affects only the related function.
5. How information is used
Information is processed only as needed to:
- Save and display your habits and completion history
- Provide reminders, widgets, statistics, and app preferences
- Verify subscriptions or lifetime purchases
- Restore purchases across eligible devices
- Register and authenticate an optional HabitBox account
- Process Alipay orders and maintain account-based membership status in supported channels
- Measure paywall visits, plan selection, checkout attempts, purchase outcomes, and the aggregate usage stage at which a purchase is considered
- Improve the membership purchase experience and diagnose checkout failures
- Diagnose purchase or reliability problems when you contact support
6. Third-party SDKs and services
HabitBox does not include a third-party advertising SDK. Depending on your platform and distribution channel, it may use the following analytics, purchase, or delivery services:
Google Analytics for Firebase
- Provider: Google LLC and its affiliates.
- Platforms and scenario: iOS and Google Play distributions, when the app initializes and when you interact with the membership paywall or purchase flow. It is disabled in mainland China domestic Android and HarmonyOS distributions.
- Purpose: measure paywall and checkout conversion, understand the aggregate usage stage at which users consider purchasing, improve the membership experience, and diagnose purchase-flow errors. It is not used by HabitBox for advertising.
- Information processed: a locally generated anonymous analytics identifier and Firebase app instance identifier; paywall entry source; app distribution, platform, app version, device type, operating system, language, approximate region, and session information; selected product, plan type, displayed price and currency; payment provider, client-side purchase result, bounded error code, and paywall display duration; and aggregate counts including estimated days since first use, active and total habits, completed check-ins, active days, current activity streak, and reminder-enabled habits.
- Information not sent by HabitBox: habit names, goals, notes, reminder text, selected images, individual completion dates, HabitBox account email address, payment credentials, or advertising identifiers.
- Permission or system capability: network access. Analytics collection does not require access to contacts, photos, location sensors, or advertising tracking permission.
- Policy: Google Privacy Policy and Privacy and Security in Firebase
RevenueCat SDK
- Provider: RevenueCat, Inc.
- Platforms and scenario: iOS and Google Play distributions, when the app initializes purchase status or when you view, purchase, or restore paid membership.
- Purpose: retrieve products, verify App Store or Google Play transactions, manage entitlements, restore purchases, and show the purchase or customer-management interface.
- Information processed: an anonymous app user identifier, device type and operating system, locale and currency code, last app-use time, product identifiers, purchase history, Apple receipt data or Google purchase token, and entitlement status. HabitBox does not provide RevenueCat with your HabitBox email address and does not enable advertising-identifier integrations.
- Permission or system capability: network access and the relevant app-store billing capability.
- Policy: RevenueCat Privacy Policy
Alipay Client SDK
- Provider: Alipay (China) Network Technology Co., Ltd. and its affiliates.
- Platforms and scenario: supported mainland China Android and HarmonyOS distributions, only when checking whether Alipay is available or when you choose Alipay to pay for membership.
- Purpose: open Alipay, process the payment, protect account and transaction security, return the payment result, and support fraud prevention and legal compliance.
- Information the SDK may process: order and transaction information; IP address and network type; Wi-Fi status or parameters; device brand, model, operating system, system settings or properties; Android ID, OAID, or similar device identifiers where available; carrier information; and limited installed-app or Alipay-installation information needed to launch and secure the payment flow. The exact scope is controlled by the SDK version, device, and Alipay's rules.
- Permission or system capability: network and network-state access, querying the Alipay app, and opening the Alipay URL scheme. HabitBox does not receive your Alipay password or full bank-card number.
- Policy: Alipay Client SDK Privacy Statement and Alipay Privacy Policy
Apple App Store and StoreKit
- Provider: Apple Inc. and its affiliates.
- Platforms and scenario: Apple platforms, when loading products, making a purchase, managing a subscription, requesting a refund, or restoring purchases.
- Information processed: app-store account and region information held by Apple, product and transaction identifiers, purchase status, and signed transaction or receipt information.
- Policy: Apple Privacy Policy
Google Play Billing
- Provider: Google LLC and its affiliates.
- Platforms and scenario: Google Play distribution, when loading products, making a purchase, managing a subscription, requesting a refund, or restoring purchases.
- Information processed: Google Play account and region information held by Google, product and transaction identifiers, purchase status, and purchase tokens.
- Policy: Google Privacy Policy
Verification-email delivery
When you request a registration or password-reset code, HabitBox uses an email delivery provider to send the message. The provider receives the destination email address, message subject and content, and delivery metadata only as needed to deliver and protect the email service. It does not receive your habit records or plain-text password.
Local components used for notifications, system alarms, image selection, secure token storage, sensors, and widgets process the related data on your device and are not used by JustToday as independent data-upload or advertising services.
7. Sharing, transfer, and cross-border processing
JustToday does not sell your personal information and does not share habit content for advertising.
Necessary information is shared only:
- With an email delivery provider to send registration or password-reset codes
- With Google to provide product analytics in the iOS and Google Play distributions described above
- With Apple, Google, RevenueCat, or Alipay to load products, process or verify a purchase, manage entitlements, or restore purchases
- With infrastructure providers that host the HabitBox account service under confidentiality and security obligations
- When required by applicable law or a valid legal request
- When needed to protect the rights, safety, and property of users, JustToday, or others
RevenueCat is based in the United States and states that its service data may be stored or processed in the United States or other countries where it or its providers operate. This applies only to distributions that initialize RevenueCat. Google Analytics for Firebase, Apple, Google Play, and Alipay may process information in the regions described in their own policies.
8. Retention and deletion
Local HabitBox data remains on your device until you delete the relevant records, clear the app's data, or uninstall the app. Selected images and widget data remain in HabitBox's local or shared app storage until you replace or delete them, clear app data, or uninstall the relevant app components. Uninstalling the app may permanently remove local data that has not been backed up through a device or platform service.
Verification-code records are kept only until successful use or expiry. Failed sign-in counters and related security records are retained only as long as reasonably needed to prevent abuse. Account and session records are retained while the account is active or until the session expires or is revoked.
If you delete your HabitBox account, JustToday anonymizes the account email, replaces the password credential, revokes active sessions and account-based membership entitlements, and removes the account from normal use. Order, payment, server security logs, and audit records may be retained when reasonably necessary for accounting, dispute handling, fraud prevention, security, and compliance with legal obligations.
Purchase and subscription records may be retained by Apple, Google, RevenueCat, or Alipay according to their policies and legal obligations.
The locally generated analytics identifier remains on your device until you clear the app's data or uninstall it. Analytics events are retained according to the Google Analytics retention settings and Google's applicable policies. Aggregate purchase-timing fields attached to a mainland China order may be retained with that order for accounting, product analysis, dispute handling, fraud prevention, security, and legal compliance.
9. Your choices
You can:
- Edit or delete habits and completion records in HabitBox
- Manage notifications and other permissions in system settings
- Manage or cancel subscriptions through your App Store or Google Play account
- Use Restore Purchases in HabitBox to refresh eligible purchase status
- Delete your HabitBox account from the account page when you use account-based membership services
- Clear the app's data or uninstall it to remove the locally stored anonymous analytics identifier; this does not necessarily delete analytics records already retained by a service provider
- Contact JustToday with privacy questions
10. Children's privacy
HabitBox is not directed at collecting personal information from children. If you believe a child has provided personal information to JustToday through a support request, contact us so that we can take appropriate action.
11. Changes to this policy
We may update this policy when HabitBox features, legal requirements, or third-party services change. The effective date at the top of this page will be updated when revisions are published. The URL of this policy will remain stable.
12. Contact
For privacy questions, contact:
JustToday
oneleafdev@qq.com
See also the HabitBox User Agreement and HabitBox Support.
简体中文
1. 概述
一叶习惯是由 JustToday 提供的习惯追踪和自我管理应用。我们重视你的隐私,并将一叶习惯设计为默认在设备本地保存习惯内容。核心习惯功能无需账号即可使用;仅当你主动使用部分分发渠道提供的账号会员服务时,才需要注册账号。
本政策说明一叶习惯会处理哪些信息、处理目的,以及你可以进行哪些选择。
2. 保存在设备上的信息
一叶习惯会在你的设备本地保存以下信息:
- 习惯、目标、完成记录、备注和进度历史
- 提醒计划和通知偏好
- 外观、语言、日历、小组件及其他应用设置
- 在设备本地生成的统计数据和成就进度
在正常使用一叶习惯的过程中,这些内容本身不会被主动上传到 JustToday 服务器。iOS 和 Google Play 分发版本可能仅将第 6 节所述的汇总使用数量和交互信息用于产品分析;不会向分析服务发送习惯名称、备注、提醒文案或单次打卡日期。
3. 账号、会员与购买
账号为可选功能,仅用于部分分发渠道提供的账号会员服务。注册或登录账号不会上传你的习惯、打卡记录、备注、所选图片或其他保存在本地的习惯内容。
当你使用账号功能时,JustToday 会处理:
- 邮箱地址: 用于注册、登录、发送验证码、重置密码、识别账号以及发送账号安全相关邮件。
- 密码: 通过加密的 HTTPS 连接传输至一叶习惯服务器;服务器仅保存密码的安全哈希值,不保存明文密码。
- 验证码记录: 包括验证码用途、受保护的验证码值、有效期、重发限制和失败尝试次数;验证成功或到期后会删除对应验证码记录。
- 账号与会话信息: 包括账号标识符、账号状态、邮箱验证时间、会员状态、会话有效期和撤销状态。当前会话令牌保存在操作系统安全存储中,服务器仅保存令牌的哈希值。
- 网络与安全日志: 一叶习惯服务器可能记录 IP 地址、请求时间、请求方法和路径、响应状态及处理耗时,用于运行服务、排查错误、防止滥用和保护账号安全。
你也可以使用邮箱地址、验证码和新密码重置密码。为限制连续失败尝试并保护账号安全,系统会短期处理登录失败次数。
购买处理方式取决于应用的分发渠道:
- Apple App Store 和 Google Play 的购买可能使用 RevenueCat 管理购买状态和权益。
- 在支持的中国大陆分发渠道中,付款由支付宝处理。JustToday 会处理完成和验证购买所需的订单号、商品、金额、支付状态、支付宝交易号和会员权益。为分析用户在什么阶段选择购买,创建订单时还可能附带本地生成的匿名分析标识符、付费页入口、估算的首次使用天数,以及当时的习惯数、打卡次数、活跃天数、连续活跃天数和开启提醒习惯数等汇总数量;不会包含习惯名称、备注、提醒文案或单次打卡日期。
JustToday 不会获取你的完整银行卡号、支付宝支付密码或应用商店账号密码。
4. 设备功能与权限
一叶习惯仅在相关功能确有需要时申请或使用设备能力。不同操作系统和分发渠道可用的能力可能不同。
| 权限或能力 | 平台与触发时机 | 使用目的与信息处理方式 | 拒绝后的影响 |
|---|---|---|---|
| 网络访问与网络状态 | Android、iOS、HarmonyOS;当你打开协议页面、使用可选账号或购买/恢复会员时 | 连接一叶习惯账号服务、你选择的支付服务商、适用渠道中的 RevenueCat,或你主动打开的网页。账号登录不会上传习惯内容。 | 在线页面、账号和购买功能可能不可用,本地习惯记录仍可继续使用。 |
| 通知 | Android、iOS、macOS、HarmonyOS;当你启用提醒或主动请求授权时 | 发送习惯提醒及可选的常驻提醒保护通知。通知可能包含习惯名称或提醒文案,内容在设备本地生成。 | 无法显示习惯提醒。 |
| 精确闹钟或系统闹钟 | Android 及支持的 Apple 平台;当你启用精确定时提醒或系统闹钟模式时 | 在你设定的时间发送提醒;支持时会使用 iOS AlarmKit。 | 提醒可能不可用或无法精确到达。 |
| 开机后后台恢复、振动、前台服务与忽略电池优化 | Android;用于恢复提醒,或仅在你启用对应提醒保护功能时使用 | 重启后恢复已安排提醒、使提醒振动,或显示可选常驻通知。这些能力不会读取习惯内容用于广告,也不会将其上传。 | 提醒可靠性或振动效果可能降低。 |
| 相册或系统照片选择器 | iOS 及支持的平台;仅在你为锁屏习惯设计选择图片时 | 仅读取你选中的图片。图片保存在本地用于该设计,不会上传至 JustToday 服务器。支持的 Android 版本使用系统照片选择器,而非广泛读取相册。 | 无法添加自定义图片,其他习惯功能不受影响。 |
| 剪贴板 | HarmonyOS 及其他支持的平台;仅在你点击粘贴操作时,例如粘贴自定义颜色值 | 读取你主动选择粘贴的文本;复制操作仅写入你明确选择的内容。剪贴板内容不会上传。 | 无法使用快捷粘贴,仍可手动输入。 |
| 本地网络 | iOS;系统 AlarmKit 展示确有需要时 | 支持系统闹钟展示所需的本地连接。一叶习惯不会借此发现或上传无关的局域网数据。 | 系统闹钟展示可能无法正常工作。 |
| 加速度传感器 | 支持的设备;仅在互动星空或成就场景打开期间 | 使用设备运动数值驱动画面元素。传感器数值仅在设备内存中即时处理,不保存、不上传。 | 场景仍可使用,但不会随设备倾斜产生互动。 |
| 小组件与应用共享存储 | 支持的平台;当你添加一叶习惯小组件时 | 仅与一叶习惯自身的小组件扩展共享你选择的本地习惯和展示数据。 | 小组件无法展示或更新所选习惯。 |
一叶习惯不会使用上述权限建立广告画像,当前应用也未集成第三方广告 SDK。你可以随时在系统设置中修改权限;关闭权限只会影响对应功能。
5. 信息用途
相关信息仅用于:
- 保存和展示习惯及完成历史
- 提供提醒、小组件、统计和应用偏好设置
- 验证订阅或一次性购买
- 在符合条件的设备上恢复购买
- 注册和认证可选的一叶习惯账号
- 在支持的渠道处理支付宝订单并维护账号会员状态
- 分析付费页访问、套餐选择、开始结账、购买结果,以及用户考虑购买时所处的汇总使用阶段
- 改进会员购买体验并排查结账失败
- 在你联系支持时排查购买或稳定性问题
6. 第三方 SDK 与服务
一叶习惯未集成第三方广告 SDK。根据你的平台和分发渠道,应用可能使用以下分析、购买或信息发送服务:
Google Analytics for Firebase
- 第三方名称: Google LLC 及其关联方。
- 平台与使用场景: iOS 和 Google Play 分发版本;应用初始化,以及你与会员付费页或购买流程交互时。中国大陆国内 Android 与 HarmonyOS 分发版本不启用该服务。
- 使用目的: 分析付费页和结账转化、了解用户考虑购买时所处的汇总使用阶段、改进会员体验及排查购买流程错误。一叶习惯不会将其用于广告。
- 处理的信息: 本地生成的匿名分析标识符与 Firebase 应用实例标识符;付费页入口;应用分发渠道、平台、应用版本、设备类型、操作系统、语言、大致地区及会话信息;所选商品、套餐类型、展示价格与币种;支付服务商、客户端购买结果、限制长度的错误代码及付费页停留时长;以及估算的首次使用天数、启用中与全部习惯数、打卡次数、活跃天数、当前连续活跃天数和开启提醒习惯数等汇总数量。
- 一叶习惯不会主动发送的信息: 习惯名称、目标、备注、提醒文案、所选图片、单次打卡日期、一叶习惯账号邮箱、支付凭据或广告标识符。
- 所需权限或系统能力: 网络访问。分析功能不需要读取通讯录、照片、位置传感器,也不需要广告跟踪权限。
- 处理规则: Google 隐私权政策及 Firebase 中的隐私权和安全性
RevenueCat SDK
- 第三方名称: RevenueCat, Inc.
- 平台与使用场景: iOS 和 Google Play 分发版本;应用初始化购买状态,或你查看、购买、恢复付费会员时。
- 使用目的: 获取商品、验证 App Store 或 Google Play 交易、管理会员权益、恢复购买,以及展示购买或会员管理界面。
- 处理的信息: 匿名应用用户标识符、设备类型与操作系统、地区与货币代码、最近一次使用应用的时间、商品标识符、购买历史、Apple 购买凭证或 Google 购买令牌、会员权益状态。一叶习惯不会向 RevenueCat 提供你的一叶习惯账号邮箱,也未启用广告标识符集成。
- 所需权限或系统能力: 网络访问及对应应用商店的支付能力。
- 处理规则: RevenueCat 隐私政策
支付宝客户端 SDK
- 第三方名称: 支付宝(中国)网络技术有限公司及其关联方。
- 平台与使用场景: 支持的中国大陆 Android、HarmonyOS 分发版本;仅在检测支付宝是否可用,或你主动选择支付宝购买会员时。
- 使用目的: 唤起支付宝、完成付款、保护账号和交易安全、返回支付结果,以及用于反欺诈和履行法定义务。
- SDK 可能处理的信息: 订单与交易信息;IP 地址、网络类型、Wi-Fi 状态或参数;设备品牌、型号、操作系统、系统设置或属性;在设备和系统允许时的 Android ID、OAID 等设备标识符;运营商信息;以及为唤起和保护支付流程所需的有限应用安装信息或支付宝安装状态。实际范围受 SDK 版本、设备环境及支付宝规则影响。
- 所需权限或系统能力: 网络与网络状态、查询支付宝客户端、唤起支付宝 URL Scheme。一叶习惯不会获取你的支付宝密码或完整银行卡号。
- 处理规则: 支付宝客户端 SDK 隐私说明及支付宝隐私权政策
Apple App Store 与 StoreKit
- 第三方名称: Apple Inc. 及其关联方。
- 平台与使用场景: Apple 平台;加载商品、购买、管理订阅、申请退款或恢复购买时。
- 处理的信息: 由 Apple 持有的应用商店账号与地区信息、商品和交易标识符、购买状态,以及签名交易或购买凭证信息。
- 处理规则: Apple 隐私政策
Google Play Billing
- 第三方名称: Google LLC 及其关联方。
- 平台与使用场景: Google Play 分发版本;加载商品、购买、管理订阅、申请退款或恢复购买时。
- 处理的信息: 由 Google 持有的 Google Play 账号与地区信息、商品和交易标识符、购买状态及购买令牌。
- 处理规则: Google 隐私权政策
验证邮件发送服务
当你请求注册或重置密码验证码时,一叶习惯会通过邮件发送服务商发送邮件。服务商仅为完成邮件发送及保障邮件服务安全而接收收件邮箱、邮件主题与正文及投递元数据,不会收到你的习惯记录或明文密码。
用于通知、系统闹钟、图片选择、安全存储会话令牌、传感器和小组件的本地功能组件,仅在你的设备上处理相关数据,JustToday 不会将其作为独立的数据上传或广告服务使用。
7. 信息共享、转让与跨境处理
JustToday 不会出售你的个人信息,也不会为广告目的共享习惯内容。
仅在以下必要情形共享相应信息:
- 与邮件发送服务商共享发送注册或重置密码验证码所需的信息
- 在上述 iOS 和 Google Play 分发版本中,与 Google 共享提供产品分析所需的信息
- 与 Apple、Google、RevenueCat 或支付宝共享加载商品、处理或验证购买、管理权益或恢复购买所需的信息
- 与受保密和安全义务约束的基础设施服务商共享托管一叶习惯账号服务所需的信息
- 遵守适用法律法规或有效法律要求
- 保护用户、JustToday 或其他人的权利、人身安全和财产安全
RevenueCat 位于美国,并说明其服务数据可能在美国或其服务商所在的其他国家或地区存储和处理;这仅适用于实际初始化 RevenueCat 的分发版本。Google Analytics for Firebase、Apple、Google Play 和支付宝可能按照各自隐私政策所述的地区处理信息。
8. 保存与删除
一叶习惯本地数据会保留在你的设备上,直到你删除相关记录、清除应用数据或卸载应用。所选图片和小组件数据会保存在一叶习惯的本地或应用共享存储中,直到你替换或删除、清除应用数据,或卸载相关应用组件。卸载应用可能永久删除未通过设备或平台服务备份的本地数据。
验证码记录仅保留到验证成功或到期。登录失败次数及相关安全记录仅在防止滥用的合理期限内保留。账号处于正常状态时会保留账号记录;会话记录保留至到期或被撤销。
如果你注销一叶习惯账号,JustToday 会匿名化账号邮箱、替换密码凭据、撤销活跃会话和账号会员权益,并使该账号无法继续正常使用。出于财务记账、争议处理、反欺诈、安全保障及履行法定义务的合理需要,订单、支付、服务器安全日志和审计记录可能继续保留。
Apple、Google、RevenueCat 或支付宝可能依据各自政策和法律义务保留购买及订阅记录。
本地生成的匿名分析标识符会保存在你的设备上,直到你清除应用数据或卸载应用。分析事件会按照 Google Analytics 的数据保留设置及 Google 的适用规则保存。附加在中国大陆订单上的汇总购买时机字段,可能随订单一起为财务记账、产品分析、争议处理、反欺诈、安全保障及履行法定义务而保留。
9. 你的选择
你可以:
- 在一叶习惯中编辑或删除习惯及完成记录
- 在系统设置中管理通知和其他权限
- 通过 App Store 或 Google Play 账号管理或取消订阅
- 在一叶习惯中使用“恢复购买”刷新符合条件的购买状态
- 在使用账号会员服务时,通过账号页面注销一叶习惯账号
- 清除应用数据或卸载应用,以移除保存在本地的匿名分析标识符;这不一定会删除服务商已经保存的分析记录
- 联系 JustToday 咨询隐私问题
10. 儿童隐私
一叶习惯并非以收集儿童个人信息为目的。如果你认为儿童通过支持请求向 JustToday 提供了个人信息,请联系我们,我们会采取适当措施。
11. 政策变更
当一叶习惯功能、法律要求或第三方服务发生变化时,我们可能更新本政策。发布修订内容时,页面顶部的生效日期会同步更新。本政策的 URL 将保持不变。
12. 联系方式
如有隐私问题,请联系:
JustToday
oneleafdev@qq.com