# 衡迹(Weight Trace)隐私政策 / Privacy Policy
**生效日期 / Effective Date:2026/07/16
**最后更新 / Last Updated:2026/07/16
**开发者 / Developer:panda
**联系邮箱 / Contact Email:leepanda2023@gmail.com
---
## 中文版
欢迎使用衡迹(Weight Trace,以下简称“本应用”)。本隐私政策说明本应用处理哪些信息、处理目的、保存方式,以及您如何访问、导出、更正或删除相关数据。
> 本文本为上线前通用模板。正式发布前,请根据最终代码、第三方 SDK、运营地区和适用法律复核,并替换所有占位内容。
### 1. 适用范围
本政策适用于衡迹 iOS App、Widget 及相关本地功能。Apple 健康、App Store、Apple Account、系统通知、设备备份和系统分享等服务由 Apple 独立提供,并适用其自身政策。
### 2. 数据处理原则
本应用遵循本地优先和数据最小化原则:
- 核心功能无需注册开发者账号;
- 健康数据默认保存在设备本地;
- 不出售、出租健康数据,也不向数据经纪商提供;
- 不将 HealthKit 数据用于广告、营销、跨应用跟踪或无关数据挖掘;
- 提供查看、导出和删除数据的控制方式;
- 尽量避免在日志、通知和 Widget 中暴露敏感信息。
### 3. 本应用处理的信息
#### 3.1 您主动记录的信息
可能包括:
- 体重数值及记录日期、时间;
- 体重目标或维持范围;
- 标签和备注;
- 每日代表记录和离群值状态;
- 趋势、方向、波动、数据充分度和洞察结果;
- Timeline 或历史事件;
- 显示单位、主题、提醒和其他应用偏好。
除非您主动导出或分享,本应用不会将这些信息发送至开发者服务器。
#### 3.2 Apple 健康数据
经您明确授权后,本应用可能通过 HealthKit 读取或写入“体重(Body Mass)”数据。当前计划的 HealthKit 范围仅限体重。
您可以:
- 拒绝 HealthKit 权限并继续手动记录;
- 在 Apple 健康或系统设置中修改或撤回权限;
- 删除本应用本地保存的导入记录;
- 在本应用提供对应功能时,明确选择删除由本应用写入 Apple 健康的记录。
本应用不会删除其他应用、设备、医疗机构或其他来源写入 Apple 健康的数据。由于 HealthKit 的隐私机制,本应用有时无法区分“读取权限被拒绝”和“没有可读取数据”。
#### 3.3 应用设置和状态
可能包括显示单位、主题、提醒时间、HealthKit 偏好、Widget 隐私设置、Onboarding 状态、迁移与恢复状态、删除流程状态及本地订阅权益缓存。
系统通知权限、HealthKit 系统权限和 App Store 购买历史由 Apple 管理,并非本应用可直接删除的本地偏好。
#### 3.4 Widget 数据
启用 Widget 后,本应用可能通过 App Group 提供最小必要快照。若您选择隐藏精确体重,本应用会避免将精确体重写入 Widget 快照,而不是仅在界面上遮挡。
#### 3.5 通知信息
如您启用提醒,本应用会安排 iOS 本地通知。通知采用中性文案,原则上不显示精确体重、备注或健康结论。
#### 3.6 订阅和购买信息
Pro 订阅由 Apple App Store 和 StoreKit 处理。本应用可能获取商品标识、验证状态、订阅状态、到期或撤销状态及恢复购买结果。
本应用不会获取或保存银行卡号、完整付款信息或 Apple Account 密码。
#### 3.7 诊断信息
本应用可能在设备系统日志中记录有限的技术事件,例如安全错误代码、迁移阶段或不包含健康数值的故障类别。
日志不会主动记录体重、目标、备注、标签正文、HealthKit 标识、交易凭据、导出完整路径或原始系统错误内容,也不会自动上传至开发者服务器。
### 4. 使用目的
相关信息仅用于:
- 保存和展示体重记录;
- 生成趋势、方向、波动、充分度和非医疗洞察;
- 展示历史、日历和 Timeline;
- 同步您授权的 Apple 健康体重数据;
- 安排本地提醒和生成 Widget 快照;
- 验证和恢复 Pro 权益;
- 导出数据;
- 执行迁移、恢复和数据删除;
- 维护应用安全和稳定运行。
### 5. 数据保存位置
本应用目前不提供开发者云端账号或云同步服务。数据主要保存在:
- 应用私有本地数据库;
- 本地偏好存储;
- 受保护的 App Group 区域;
- Apple 健康;
- 您主动选择的导出或分享目标。
设备备份是否包含部分应用数据,取决于您的设备设置和 Apple 的备份机制。
### 6. 数据共享
我们不会出售、出租或向数据经纪商提供您的个人信息或健康数据。
数据可能在以下情况下流转:
- 您主动使用导出或系统分享;
- 使用 Apple 提供的 HealthKit、StoreKit、通知、Widget、备份或分享服务;
- 适用法律要求,并且仅限合法、必要范围。
### 7. 数据导出
导出文件可能包含敏感健康信息。请谨慎选择保存位置和接收方。
本应用会尽量使用不含健康数据的安全文件名、受保护临时目录、TTL 和启动清理,并避免在日志中记录完整路径。CSV 导出会采取必要的公式注入防护。
### 8. 保存期限和删除
本地数据通常保存至您主动删除、完全重置或卸载本应用。
本应用可能提供:
- **重置设置:** 恢复应用偏好,不删除健康记录;
- **删除健康数据:** 删除本地健康记录及其派生数据,保留非健康偏好;
- **完全重置:** 删除本应用拥有的本地数据、设置、缓存、Widget 快照、通知计划和临时文件。
上述操作不会自动取消 App Store 订阅、删除 Apple 购买历史、修改系统权限、删除其他来源的 Apple 健康数据,或删除您已保存到其他位置的导出文件。
为安全恢复中断的删除流程,本应用可能暂时保留最小化的删除日志,直至删除完成。
### 9. 您的权利和控制
根据适用法律,您可能享有访问、更正、导出、删除、限制处理、撤回同意、数据可携或投诉等权利。
您可以通过应用内功能、Apple 健康、系统设置、App Store 订阅管理或联系邮箱行使相关控制。
由于数据主要保存在您的设备上,开发者通常无法远程查看、修改或恢复您的具体健康记录。
### 10. 数据安全
本应用采用合理措施,包括 iOS 沙盒、文件保护、Core Data 事务与迁移保护、受控 App Group 快照、隐私安全日志、临时文件清理和可恢复删除流程。
任何存储方式都无法保证绝对安全。您也应保护设备密码、Apple Account 和导出文件。
### 11. 未成年人
本应用不以儿童为主要服务对象。未成年人应在父母或监护人指导下使用;适用法律要求同意时,应先获得相应同意。
### 12. 非医疗声明
本应用用于个人记录、趋势展示和一般信息整理,不提供医疗诊断、治疗、处方、紧急医疗服务或减重保证。
请勿仅依据本应用作出医疗决定。如有健康疑虑,请咨询具有资质的专业人员;紧急情况请联系当地紧急服务。
### 13. 政策变更
我们可能因功能、法律或安全要求更新本政策。重大变更将通过应用内提示、版本说明或其他适当方式告知。
### 14. 联系我们
**开发者 / 运营者:panda
**联系邮箱: leepanda2023@gmail.com
---
## English Version
Welcome to Weight Trace (Chinese name: 衡迹, the “App”). This Privacy Policy explains what information the App processes, why it is processed, how it is stored, and how you can access, export, correct, or delete relevant data.
> This is a general pre-launch template. Before release, review it against the final code, third-party SDKs, operating regions, and applicable laws, and replace all placeholders.
### 1. Scope
This Policy applies to the Weight Trace iOS app, its widgets, and related local features. Apple Health, the App Store, Apple Account, system notifications, device backups, and system sharing are independently provided by Apple and are governed by Apple’s own terms and policies.
### 2. Processing Principles
The App follows local-first and data-minimization principles:
- Core features do not require a developer-operated account;
- Health data remains on your device by default;
- We do not sell or rent health data or provide it to data brokers;
- We do not use HealthKit data for advertising, marketing, cross-app tracking, or unrelated data mining;
- The App provides controls to view, export, and delete data;
- Sensitive content is minimized in logs, notifications, and widgets.
### 3. Information Processed
#### 3.1 Information You Enter
This may include:
- Weight values, dates, and times;
- Weight goals or maintenance ranges;
- Tags and notes;
- Daily representative records and outlier status;
- Trend, direction, volatility, sufficiency, and insight results;
- Timeline or history events;
- Display unit, theme, reminders, and other preferences.
Unless you choose to export or share it, the App does not send this information to a developer-operated server.
#### 3.2 Apple Health Data
With your explicit authorization, the App may read or write Body Mass data through HealthKit. The currently planned HealthKit scope is limited to Body Mass.
You may:
- Decline HealthKit permission and continue manual tracking;
- Change or revoke permission in Apple Health or system settings;
- Delete locally imported records;
- Where supported, explicitly choose to delete records written to Apple Health by this App.
The App does not delete HealthKit data created by another app, device, healthcare provider, or other source. Because of HealthKit privacy protections, the App may not always distinguish between denied read permission and the absence of matching data.
#### 3.3 App Settings and State
This may include display units, themes, reminder time, HealthKit preferences, widget privacy settings, onboarding state, migration and recovery state, erasure workflow state, and a local subscription-entitlement cache.
System notification permissions, HealthKit authorization, and App Store purchase history are controlled by Apple and are not local preferences that the App can directly delete.
#### 3.4 Widget Data
When a widget is enabled, the App may provide a minimal snapshot through an App Group. When exact weight is hidden, the App is designed to avoid writing that value into the widget snapshot rather than merely obscuring it visually.
#### 3.5 Notifications
If reminders are enabled, the App schedules iOS local notifications. Notification wording is designed to remain neutral and generally does not display exact weight, notes, or health conclusions.
#### 3.6 Subscription and Purchase Information
Pro subscriptions are handled by the Apple App Store and StoreKit. The App may receive product identifiers, verification status, subscription status, expiration or revocation state, and restore-purchase results.
The App does not obtain or store your payment-card number, full payment details, or Apple Account password.
#### 3.7 Diagnostics
The App may record limited technical events in system logs, such as privacy-safe error codes, migration stages, or failure categories that do not include health values.
The App is designed not to log weight, goals, note or tag text, HealthKit identifiers, transaction credentials, full export paths, or raw system error content. Logs are not automatically uploaded to a developer-operated server.
### 4. Purposes
Information is used only to:
- Save and display weight records;
- Generate trends, direction, volatility, sufficiency, and non-medical insights;
- Display history, calendar, and timeline information;
- Synchronize authorized Body Mass data with Apple Health;
- Schedule local reminders and generate widget snapshots;
- Verify and restore Pro access;
- Export data;
- Perform migration, recovery, and erasure;
- Maintain security and reliable operation.
### 5. Storage
The App currently does not provide a developer-operated cloud account or cloud-sync service. Data is primarily stored in:
- The App’s private local database;
- Local preference storage;
- A protected App Group area;
- Apple Health;
- An export or sharing destination you choose.
Whether device backups contain some App data depends on your device settings and Apple’s backup mechanisms.
### 6. Sharing
We do not sell, rent, or provide your personal or health data to data brokers.
Data may move when:
- You use export or system sharing;
- You use Apple services such as HealthKit, StoreKit, notifications, widgets, backups, or sharing;
- Applicable law requires disclosure, limited to what is lawful and necessary.
### 7. Export
Export files may contain sensitive health information. Choose the storage location and recipient carefully.
The App is designed to use safe filenames without health content, protected temporary storage, TTL and launch cleanup, and privacy-safe logging. CSV exports apply appropriate protection against spreadsheet-formula injection.
### 8. Retention and Deletion
Local data is generally retained until you delete it, perform a full reset, or uninstall the App.
The App may provide:
- **Reset Settings:** Reset preferences without deleting health records;
- **Delete Health Data:** Delete local health records and derived data while retaining non-health preferences;
- **Full Reset:** Delete App-owned local data, settings, caches, widget snapshots, notification schedules, and temporary files.
These actions do not automatically cancel an App Store subscription, delete Apple purchase history, change system permissions, delete Apple Health data from another source, or delete exports already saved elsewhere.
A minimal erasure journal may be retained temporarily to safely resume an interrupted deletion.
### 9. Your Rights and Controls
Depending on applicable law, you may have rights to access, correct, export, delete, restrict processing, withdraw consent, receive portable data, or lodge a complaint.
You can exercise control through in-App features, Apple Health, system settings, App Store subscription management, or the contact email below.
Because data is primarily stored on your device, the developer generally cannot remotely inspect, modify, or recover your specific health records.
### 10. Security
The App uses reasonable safeguards, including the iOS sandbox, file protection, Core Data transaction and migration safeguards, controlled App Group snapshots, privacy-safe logging, temporary-file cleanup, and recoverable erasure workflows.
No storage method can guarantee absolute security. You are also responsible for protecting your device passcode, Apple Account, and exported files.
### 11. Children
The App is not primarily directed at children. Minors should use it under the guidance of a parent or guardian, and consent should be obtained where required by law.
### 12. Medical Disclaimer
The App is intended for personal tracking, trend display, and general information. It does not provide medical diagnosis, treatment, prescriptions, emergency medical services, or guaranteed weight-loss outcomes.
Do not make medical decisions solely based on the App. Consult a qualified professional for health concerns and contact local emergency services in an emergency.
### 13. Changes
We may update this Policy because of feature, legal, or security changes. Material changes will be communicated through the App, release notes, or another appropriate method.
### 14. Contact
**Developer / Operator: panda
**Contact Email: leepanda2023@gmail.com