最近更新:2026-08-22
欢迎使用 HashRay(井彩记账)。我们非常重视您的个人信息与隐私。本隐私政策向您说明我们收集哪些信息、如何使用、存储与保护,以及您享有的权利(特别是账号删除)。
1. 我们收集的信息
HashRay 不接入任何广告、统计或分析 SDK,也不会将您的数据出售给第三方。我们仅在提供记账服务所必需的范围内收集以下信息:
1.1 您主动提供的信息
- 账号信息:注册邮箱(用于登录与找回密码)与密码(仅以不可逆哈希形式存储,我们无法读取您的明文密码)。
- 账单数据:您录入或自动记录的账单,包括金额、收支类型、标签、备注、发生时间,以及您主动填写的地点信息。
- 会员信息:您兑换的会员权益记录(兑换码仅以哈希形式存储)。
1.2 自动收集的信息
- 设备信息:设备唯一标识(经 SHA-256 哈希处理,无法反推硬件信息)、平台、设备型号、操作系统版本、App 版本。用于多设备登录、会话管理与安全防护。
- 自动记账相关:当您开启「自动记账」功能并授予通知使用权与无障碍服务权限后,App 会读取支付宝、微信等应用的支付通知内容,提取金额与收款方信息生成账单。该处理主要用于在您的设备本地完成,仅将您确认的账单数据同步到服务器。
- 网络与运行信息:访问时间、App 内操作产生的同步数据,用于同步与故障排查。
2. 我们如何使用信息
- 提供核心记账功能:账单录入、标签管理、统计、预算、周期记账、还款提醒;
- 实现多设备登录与数据同步;
- 发送注册/找回密码/删除账号等验证邮件;
- 提供会员权益与兑换码服务;
- 保障账号与数据安全(如识别被禁用的设备、防滥用限流)。
3. 信息存储与安全
- 存储位置:您的数据存储于我们位于中国境内(阿里云)的服务器,使用 PostgreSQL 与 Redis。
- 传输加密:所有网络通信均通过 HTTPS 加密传输。
- 密码保护:密码经 BCrypt 单向哈希,数据库泄露也无法还原明文。
- 访问控制:仅授权运维人员可访问生产环境,管理员操作留有审计日志。
4. 信息共享与第三方
我们不会向任何第三方出售、出租您的个人信息,也不存在广告或行为追踪。唯一的第三方处理场景:
- 邮件服务商(SMTP / Resend):用于向您的注册邮箱发送验证码邮件,仅传递您的邮箱地址与验证码内容。
5. 信息保留期限
- 在您的账号存续期间,我们持续保存账单与账号数据以提供服务;
- 会话令牌(Refresh Token)有效期 30 天,到期自动失效;
- 您删除账号后,详见第 6 节「账号删除」。
6. 您的权利:账号删除(Account Deletion)
您有权随时删除您的 HashRay 账号及与之关联的全部数据。我们提供两种删除方式,均立即生效:
删除处理时限
删除请求提交后立即生效(账号停用、全部会话撤销)。服务端将在 30 天宽限期后对您的账号及全部关联数据(账单、标签、预算、周期记账、同步记录、设备记录、会员权益等)执行彻底物理删除,无法恢复。宽限期内如需恢复账号,请联系 support@cxsz365.top。
数据保留说明
为满足安全与防欺诈合规要求,以下数据在删除后仍可能以脱敏形式保留:管理员操作审计日志(其中您的邮箱等个人信息将被掩码处理,仅保留操作痕迹)。除此之外,我们不保留您的任何个人信息。
我们不会与第三方共享您的个人数据用于广告或分析;若未来接入第三方服务商,将在删除时同步要求其删除。
7. 儿童隐私
HashRay 不面向 13 周岁以下儿童提供服务,也不会故意收集儿童的个人信息。如您认为我们收集了儿童信息,请联系我们删除。
8. 隐私政策的更新
我们可能不时更新本政策。重大变更(如收集范围、共享对象)将通过在 App 内显著提示或邮件方式通知您。更新后的政策自发布时生效。
9. 联系我们
如您对本隐私政策或个人信息处理有任何疑问、意见或投诉,请通过以下方式联系我们:
Last updated: 2026-08-22
Welcome to HashRay. Your privacy matters to us. This Privacy Policy explains what information we collect, how we use, store and protect it, and the rights you have — especially account deletion.
1. Information We Collect
HashRay integrates no advertising, analytics or tracking SDKs, and never sells your data to third parties. We collect only what is necessary to provide the bookkeeping service:
1.1 Information You Provide
- Account information: your registration email (for sign-in and recovery) and password (stored only as an irreversible hash — we cannot read your plaintext password).
- Transaction data: entries you add or auto-capture, including amount, type, tags, notes, timestamp, and any location you voluntarily provide.
- Membership records: redeemed membership benefits (codes stored only as hashes).
1.2 Information Collected Automatically
- Device information: a device identifier (SHA-256 hashed, not reversible to hardware), platform, device model, OS version and app version — used for multi-device sign-in, session management and security.
- Auto-recording: when you enable "Auto Record" and grant Notification Access and Accessibility Service permissions, the app reads payment notifications (e.g. Alipay, WeChat Pay) to extract the amount and payee into a draft entry. Processing happens primarily on your device; only entries you confirm are synced to the server.
- Network & operational data: access time and sync records, used for synchronization and troubleshooting.
2. How We Use Information
- Deliver core bookkeeping: transactions, tags, statistics, budgets, periodic billing, repayment reminders;
- Multi-device sign-in and data sync;
- Send verification emails (registration, password reset, account deletion);
- Provide membership benefits and redemption codes;
- Protect account and data security (e.g. banned-device detection, anti-abuse rate limiting).
3. Storage & Security
- Location: your data is stored on servers in mainland China (Alibaba Cloud), using PostgreSQL and Redis.
- Encryption in transit: all network communication uses HTTPS.
- Password protection: passwords are one-way hashed with BCrypt; a database leak cannot reveal plaintext.
- Access control: only authorized operations staff can access production; administrator actions are audited.
4. Sharing & Third Parties
We do not sell, rent or trade your personal information to any third party, and there is no advertising or behavioral tracking. The only third-party processing:
- Email service providers (SMTP / Resend): to deliver verification codes to your registered email — only your email address and the code are passed.
5. Data Retention
- While your account exists, we keep your transaction and account data to provide the service;
- Session tokens (refresh tokens) expire after 30 days;
- After account deletion, see Section 6.
6. Your Rights: Account Deletion
You have the right to delete your HashRay account and all associated data at any time. Two methods are available — both take effect immediately:
- In-app deletion: open the app → Settings → Delete Account, and follow the confirmation steps. Your account can no longer sign in or sync.
- Web deletion: visit https://api.cxsz365.top/account-deletion, enter your registered email and complete email-code verification. This works even if you have uninstalled the app.
Processing Timeline
The deletion request takes effect immediately (account disabled, all sessions revoked). Within a 30-day grace period, the server performs a full physical purge of your account and all associated data (transactions, tags, budgets, periodic billing, sync records, device records, membership benefits, etc.), which cannot be undone. To restore your account during the grace period, contact support@cxsz365.top.
Data Retention Disclosure
For security and anti-fraud compliance, the following data may be retained in de-identified form after deletion: administrator audit logs (your email and other personal identifiers are masked; only operation traces are kept). No other personal information is retained.
We do not share your personal data with third parties for advertising or analytics. If third-party processors are onboarded in the future, deletion requests will be propagated to them.
7. Children's Privacy
HashRay is not intended for children under 13 and we do not knowingly collect their personal information. If you believe we have collected such information, please contact us and we will delete it.
8. Changes to This Policy
We may update this policy from time to time. Material changes (e.g. collection scope, sharing parties) will be notified via prominent in-app notice or email. Updates take effect upon publication.
9. Contact Us
If you have any questions, comments or complaints about this policy or your personal data, please contact us: