跳到隐私政策
TripCost
功能 隐私优先 隐私政策 联系
清楚、克制、由你掌控

隐私政策

本政策说明 TripCost 如何处理 App 与官网中的信息。简单来说:无需注册,核心记录默认保存在本机,票据原图不会上传,iCloud 结构化同步由你选择。

生效日期 2026 年 8 月 20 日 政策版本 1.0
01 本地优先

行程、消费、支付规则与票据默认保存在你的设备。

02 只在需要时联网

在线汇率只发送币种、日期等查询参数,不发送票据或账本。

03 没有广告追踪

TripCost 不接入广告、跨 App 追踪或用户行为分析 SDK。

本页目录 1. 适用范围 2. 处理的信息 3. 使用方式 4. 第三方与共享 5. 系统权限 6. 保留与删除 7. 你的控制与权利 8. 安全与跨境 9. 儿童隐私 10. 官网数据 11. 政策更新 12. 联系我们

1. 适用范围与运营者

本隐私政策适用于 TripCost iOS App、桌面小组件以及本官网。TripCost 是一款免费的旅行真实消费成本助手,由 TripCost 独立开发者运营。

TripCost 不要求你注册账号,也不会要求你提供姓名、手机号或邮箱来使用核心功能。我们不读取或保存完整银行卡号、有效期、CVV、安全码、银行登录凭据、身份证件、短信或邮件。

本政策描述当前 V1.0 的实际数据处理方式。如果未来加入账号、分析、推送或其他联网功能,我们会在功能启用前更新本政策和必要的授权说明。

2. 我们处理的信息

“处理”包括在你的设备上保存、读取、计算、导出,或在你主动开启功能时发送到相应服务。不同信息的处理方式如下:

信息类别内容示例默认位置何时外发
行程与预算目的地、日期、预算、行程名称本机数据库仅在你开启 iCloud 同步后进入你的 CloudKit 私有数据库
消费与支付规则金额、币种、类别、商户备注、支付方式名称、卡组织、账单币种、手续费、返现、实际入账金额本机数据库仅在你开启 iCloud 同步后同步结构化记录;不包含完整卡号、CVV 或银行凭据
票据与扫描内容你拍摄或选择的价签、菜单、小票图片,以及本地 OCR 识别出的候选金额和文字本机内存、临时目录或 App 私有目录原图与 OCR 内容不上传,也不进入 CloudKit
汇率与币种查询基础币种、目标币种、查询日期、汇率来源与缓存时间本机缓存在线刷新时向 Frankfurter 发送币种和日期参数;网络服务可能处理 IP 地址、User-Agent 等标准连接信息
设置与同步元数据默认币种、语言、刷新频率、收藏币种、同步开关、记录版本、冲突和删除标记本机数据库开启 iCloud 同步后,必要的结构化设置和同步元数据会进入 CloudKit;设备本地偏好可能不参与同步
小组件摘要选定币种对、参考汇率、预算与近期消费的最小摘要本机 App Group 共享文件仅由本机 TripCost 小组件读取,不发送到第三方
导出与备份你生成的 CSV、PDF 和 JSON 备份本机临时目录只有你在 iOS 系统分享面板选择目标后才离开 App

关于网络连接信息

任何互联网请求都可能使服务器或其网络服务商看到 IP 地址、请求时间、设备网络相关信息及请求路径。TripCost 不会在汇率请求中附加账户标识、票据图片、行程、消费记录或支付规则。

3. 信息的使用方式

TripCost 仅为以下目的处理信息:

  • 完成汇率换算、数学表达式计算、支付成本比较和 DCC 额外成本检查;
  • 使用 Apple Vision 在设备上识别价格、票据文字和候选金额;
  • 创建和展示行程、预算、消费账本、实际入账校准与历史快照;
  • 按你的设置缓存或刷新每日参考汇率,并在离线时提供最近缓存;
  • 在你主动开启时,通过 CloudKit 在同一 Apple 账户的设备间同步结构化数据;
  • 刷新本机小组件,或按你的操作生成、分享、备份与恢复数据;
  • 维护数据完整性、处理同步冲突并防止旧数据覆盖新记录。

TripCost 不会将这些信息用于广告、跨 App 追踪、用户画像、信用评估、出售数据或训练第三方 AI 模型。

4. 第三方服务、共享与披露

TripCost 不出售个人信息。以下服务仅在对应功能需要时参与处理:

  • Apple Vision:在设备本地执行 OCR。图片不因使用 Vision 而上传给 TripCost 服务器。
  • Apple iCloud / CloudKit:当你在 App 内开启同步时,结构化数据会存入你的 CloudKit 私有数据库。CloudKit 的处理和安全措施受 Apple 隐私政策约束。
  • Frankfurter 与 Cloudflare:在线汇率请求发往 Frankfurter 公共 API。Frankfurter 说明其 API 本身不收集个人数据,但公共服务使用 Cloudflare,Cloudflare 可能为安全、性能和基础分析处理标准网络信息;相关处理受其各自政策约束。
  • 你选择的分享目标:当你通过 iOS 分享面板导出 CSV、PDF 或备份时,接收 App、联系人或云服务由你选择,之后由对应接收方按照其政策处理。

如法律要求、为保护用户或公众安全、或处理有效法律程序,我们可能依法披露必要信息。但由于 TripCost 的核心数据默认留在本机,且开发者无法通过 CloudKit 控制台查看用户私有数据库内容,我们通常不持有可供披露的核心账本数据。

5. 系统权限

  • 相机:仅在你选择拍照扫描时请求,用于拍摄价签、菜单、小票或账单并在设备上识别。
  • 照片:仅在你选择从相册导入时请求,用于读取你明确选择的图片并在设备上识别。
  • iCloud:只有你开启结构化数据同步时才访问 CloudKit。iCloud 不可用不会阻止本地记账与查看。

V1.0 不需要定位、通讯录、麦克风、通知或 App Tracking Transparency 权限。拒绝相机或照片权限后,你仍可以手动输入金额和记账。你可随时在 iOS“设置”中修改权限。

6. 数据保留与删除

  • 本机数据库与票据:保留到你删除相关记录、使用“清除票据图片”或“清除全部数据”,或卸载 App。系统备份的副本可能按照 Apple 的备份保留规则继续存在。
  • 小组件摘要:随主 App 更新;使用“清除全部数据”时会先删除共享摘要,避免继续显示旧账本信息。
  • CloudKit 数据:保留在你的 Apple 账户私有数据库中,直到你通过 iCloud 存储管理删除第三方 App 数据或 Apple 依据其规则删除。关闭 TripCost 内的同步会停止后续同步,但不会自动删除此前存入 iCloud 的数据。
  • 导出与备份:由你选择的保存位置和接收方决定保留时间;TripCost 不控制已分享出去的副本。
  • 汇率服务日志:可能由 Frankfurter 或 Cloudflare 按其安全和运营政策保留,TripCost 无法控制其具体期限。
“清除全部数据”会删除本机数据库、票据文件、同步状态和小组件摘要。若你曾开启 iCloud 同步,请同时前往“设置 > [你的名字] > iCloud > 存储空间/管理账户存储空间”查看并删除 TripCost 的云端数据。系统路径名称可能随 iOS 版本而变化。

7. 你的控制与权利

你可以直接在 App 或系统设置中:

  • 查看、修改和删除行程、消费、支付方式与设置;
  • 导出 CSV、PDF 或创建 JSON 备份,获取自己的数据副本;
  • 单独清除票据图片,或通过双重确认清除全部本机数据;
  • 关闭 iCloud 同步,或在 iOS 的 iCloud 设置中停止 TripCost 使用 iCloud;
  • 撤回相机和照片权限,并继续使用手动输入作为替代;
  • 在 iCloud 存储管理中查看并删除第三方 App 的 iCloud 数据。

Apple 说明,CloudKit 私有数据库内容由用户拥有,默认仅用户本人可访问;开发者无法通过 Developer Portal 查看这些私有内容。你也可以通过下方邮箱联系我们,咨询政策、数据流程或无法自行完成的隐私操作。

8. 安全、存储地点与跨境处理

TripCost 采用数据最小化、本地优先、系统沙盒、按需权限和结构化同步隔离等措施。CloudKit 使用 Apple 账户身份验证及传输和存储保护;但任何电子存储或传输方式都无法保证绝对安全。

本机数据位于你的 Apple 设备。若你使用 iCloud 或在线汇率,Apple、Frankfurter、Cloudflare 及其基础设施可能在你所在国家或地区以外处理数据。此类服务按各自隐私政策和适用法律提供保护。请勿在商户备注等自由文本字段中填写不必要的敏感个人信息。

9. 儿童隐私

TripCost 面向一般旅行者,不专门面向儿童,也不要求用户提供年龄或身份信息。我们不会故意收集儿童的姓名、联系方式或账户资料。如果你认为儿童在自由文本字段或导出文件中提供了不必要的信息,请在设备上删除相应记录,或联系我们了解处理方式。

10. 官网的数据处理

本官网是静态页面,不提供账户、表单或支付功能,不使用广告、分析服务、追踪像素或外部字体。语言切换会在浏览器的 localStorage 中保存一个仅用于记住“中文/English”选择的本地键;网站不设置用于追踪的 Cookie。

网站托管服务商可能为交付页面、安全防护和排障处理 IP 地址、访问时间、User-Agent 与请求路径等标准服务器日志。实际托管服务确定后,应以本页公布的托管商及其隐私政策为准。

11. 隐私政策更新

当功能、第三方服务、数据处理方式或法律要求发生重要变化时,我们会更新本政策,并修改顶部的生效日期与版本号。若变化会显著影响你的权利,我们会在 App 内或官网提供适当提示,并在需要时重新取得同意。

12. 联系我们

如果你对本政策、TripCost 的数据处理方式或隐私控制有疑问,请通过以下方式联系。我们会在合理期限内回复。

TripCost 独立开发者隐私与支持联系邮箱
djl13333995679@163.com
On this page 1. Scope 2. Information handled 3. How it is used 4. Third parties 5. Permissions 6. Retention & deletion 7. Your controls 8. Security & transfers 9. Children 10. Website data 11. Changes 12. Contact

1. Scope and operator

This Privacy Policy applies to the TripCost iOS app, its home-screen widget, and this website. TripCost is a free true travel cost assistant operated by an independent TripCost developer.

TripCost does not require an account and does not ask for your name, phone number, or email address to use its core features. We do not read or store full payment card numbers, expiration dates, CVV or security codes, bank credentials, identity documents, text messages, or email.

This policy describes the actual data handling in V1.0. If account, analytics, notification, or other connected features are added later, we will update this policy and any required consent disclosures before enabling them.

2. Information we handle

“Handle” includes storing, reading, calculating, or exporting information on your device, and sending it to a relevant service only when you enable the related feature.

CategoryExamplesDefault locationWhen it leaves the device
Trips and budgetsDestination, dates, budget, and trip nameOn-device databaseOnly to your private CloudKit database after you enable iCloud sync
Expenses and payment rulesAmounts, currencies, category, merchant notes, payment method name, card network, billing currency, fees, cashback, and final posted amountOn-device databaseStructured records sync only after you enable iCloud; full card numbers, CVV, and bank credentials are not included
Receipts and scansPrice tags, menus, receipts, or bills you capture or select, plus OCR candidates and recognized textDevice memory, temporary storage, or the app's private directoryOriginal images and OCR content are not uploaded and do not enter CloudKit
Rate and currency queriesBase currency, quote currency, date, rate source, and cache timeOn-device cacheCurrency and date parameters go to Frankfurter for online refresh; network providers may process standard connection data such as IP address and User-Agent
Settings and sync metadataDefault currency, language, refresh interval, favorites, sync setting, record versions, conflicts, and deletion markersOn-device databaseNecessary structured settings and sync metadata enter CloudKit after sync is enabled; some device-local preferences are excluded
Widget summaryA minimal summary of the selected currency pair, reference rate, budget, and recent expensesOn-device App Group fileRead only by the TripCost widget on your device; not sent to third parties
Exports and backupsCSV, PDF, and JSON backup files you createOn-device temporary directoryOnly after you choose a destination in the iOS share sheet

Network connection data

Any internet request can expose an IP address, request time, device network information, and request path to the server or its network provider. TripCost does not attach an account identifier, receipt image, trip, expense record, or payment rule to a rate request.

3. How information is used

TripCost handles information only to:

  • perform currency conversion, expression calculation, payment-cost comparison, and DCC markup checks;
  • recognize prices, receipt text, and candidate amounts on device with Apple Vision;
  • create and show trips, budgets, expense records, final-posting reconciliation, and historical snapshots;
  • cache or refresh daily reference rates according to your settings and provide the latest cache offline;
  • sync structured data across devices on the same Apple Account when you enable CloudKit sync;
  • refresh the on-device widget or create, share, back up, and restore data at your request; and
  • maintain data integrity, resolve sync conflicts, and prevent stale records from overwriting newer ones.

TripCost does not use this information for advertising, cross-app tracking, profiling, credit scoring, data sales, or training third-party AI models.

4. Third-party services, sharing, and disclosure

TripCost does not sell personal information. The following services participate only when a feature requires them:

  • Apple Vision: performs OCR on your device. Using Vision does not upload the image to a TripCost server.
  • Apple iCloud / CloudKit: stores structured data in your private CloudKit database after you enable sync in the app. CloudKit processing and safeguards are governed by Apple's Privacy Policy.
  • Frankfurter and Cloudflare: online rate requests go to the Frankfurter public API. Frankfurter states that its API itself does not collect personal data, but that its public service uses Cloudflare, which may process standard network information for security, performance, and basic analytics. Their respective policies govern that processing.
  • Share destinations you choose: when you export a CSV, PDF, or backup through the iOS share sheet, you choose the recipient app, person, or cloud service. That recipient then handles the file under its own policy.

We may disclose necessary information where required by law, to protect users or the public, or in response to valid legal process. However, because core TripCost data stays on device by default and developers cannot view users' private CloudKit database content in the Developer Portal, we generally do not possess the core ledger data to disclose.

5. System permissions

  • Camera: requested only when you choose to scan with the camera, to capture and recognize a price tag, menu, receipt, or bill on device.
  • Photos: requested only when you choose to import from your photo library, to read the image you explicitly select and recognize it on device.
  • iCloud: CloudKit is accessed only after you enable structured-data sync. Local entry and viewing continue to work when iCloud is unavailable.

V1.0 does not require location, contacts, microphone, notifications, or App Tracking Transparency permission. If you decline camera or photo access, you can still enter amounts and expenses manually. You can change permissions at any time in iOS Settings.

6. Data retention and deletion

  • On-device database and receipts: retained until you delete a record, use “Clear receipt images” or “Clear all data,” or uninstall the app. Copies in a system backup may remain under Apple's backup retention rules.
  • Widget summary: updated with the main app and removed before the local database when you use “Clear all data,” so stale accounting information is not left on the widget.
  • CloudKit data: retained in your Apple Account's private database until you delete third-party app data through iCloud storage management or Apple deletes it under its rules. Turning off sync in TripCost stops future sync but does not automatically erase information previously stored in iCloud.
  • Exports and backups: retained according to the location and recipient you choose. TripCost cannot control copies you have already shared.
  • Rate-service logs: may be retained by Frankfurter or Cloudflare under their security and operations policies. TripCost does not control their exact retention periods.
“Clear all data” removes the local database, receipt files, sync state, and widget summary. If you previously enabled iCloud sync, also review and delete TripCost cloud data in Settings > [your name] > iCloud > Storage / Manage Account Storage. Labels may vary by iOS version.

7. Your controls and rights

You can use the app or system settings to:

  • view, edit, and delete trips, expenses, payment methods, and settings;
  • export CSV or PDF files or create a JSON backup to obtain a copy of your data;
  • clear receipt images separately or clear all on-device data after a two-step confirmation;
  • turn off iCloud sync, or stop TripCost from using iCloud in iOS iCloud settings;
  • withdraw camera and photo permission while continuing to use manual entry; and
  • review and delete a third-party app's iCloud data through iCloud storage management.

Apple states that users own content in their private CloudKit databases and, by default, only the user can access it; developers cannot view this private content in the Developer Portal. You can also contact us at the address below with questions about this policy, data flows, or a privacy action you cannot complete yourself.

8. Security, storage location, and international processing

TripCost uses data minimization, local-first storage, the operating system sandbox, just-in-time permissions, and separation of structured sync data. CloudKit uses Apple Account authentication and protections in transit and at rest. However, no electronic storage or transmission method can be guaranteed absolutely secure.

On-device data resides on your Apple device. If you use iCloud or online rates, Apple, Frankfurter, Cloudflare, and their infrastructure may process data outside your country or region. Those services apply safeguards under their own privacy policies and applicable laws. Avoid entering unnecessary sensitive personal information in free-text fields such as merchant notes.

9. Children's privacy

TripCost is intended for general travelers and is not directed specifically to children. It does not ask users for age or identity details. We do not knowingly collect a child's name, contact information, or account details. If you believe a child added unnecessary information to a free-text field or export, delete that record on the device or contact us for guidance.

10. Data handled by this website

This is a static website with no accounts, forms, or payment features. It uses no advertising, analytics service, tracking pixel, or external font. The language switch stores one localStorage key solely to remember your Chinese/English preference. The website sets no tracking cookie.

A hosting provider may process standard server logs such as IP address, access time, User-Agent, and request path to deliver the site, provide security, and troubleshoot. Once a production host is selected, this page should identify the host and link to its privacy policy.

11. Changes to this policy

We will update this policy when important changes occur in features, third-party services, data handling, or legal requirements. We will revise the effective date and version number above. If a change materially affects your rights, we will provide an appropriate notice in the app or on this website and obtain renewed consent where required.

12. Contact us

If you have questions about this policy, TripCost's data handling, or privacy controls, contact us below. We will respond within a reasonable time.

Independent TripCost developerPrivacy and support email
djl13333995679@163.com
联系我们

需要帮助?给我们发邮件。

你可以复制下面的邮箱地址;如果浏览器支持,也可以直接打开邮件客户端。

联系邮箱 djl13333995679@163.com
发送邮件 ↗

TripCost

旅行真实消费成本助手。

官网 汇率来源 iCloud 数据说明 联系我们

© 2026 TripCost

本政策最后更新于 2026 年 8 月 20 日。