Kinote Privacy Policy
This policy explains how the Kinote iOS app handles your data. Its wording matches the in-app “Privacy and Security” page, and each section covers one data path.
Where your data lives
Local Data Device only
Ledgers stay in the app sandbox. Imported files are read once and never copied in.
- Ledger files are stored in the app sandbox On device
- Names, currencies, categories and plans are included in ledger backups With the ledger
- Language, feedback preferences, local member selection and account status stay on this device Device only
- Imported files are read only for parsing and are not copied into the app On device
- App Lock uses Face ID, Touch ID, or your device passcode to protect access to the interface. Background previews are always hidden; you can still take screenshots or recordings. Device only
In-app entry: Manage Ledgers · delete local ledgers individually
Backup & Restore Three boundaries
Manual backups are password-encrypted; iCloud backups stay in your Apple ID.
- Manual backups are encrypted with your chosen password. Kinote does not save it; forgetting it makes that file permanently unrestorable. Older unencrypted JSON backups can still be restored after acknowledging a warning. Wherever you save it
- Store them somewhere trusted and avoid public sharing Caution
- The pre-restore safety snapshot stays in the app sandbox and is used only to undo the last restore On device
- iCloud backups are stored in the current Apple ID’s private CloudKit space Your Apple ID
- Internal safety snapshots and iCloud backups have no separate file password; on-device data protection relies on iOS. Relies on iOS
In-app entry: Backup & Restore · turn off automatic backup or delete the cloud backup
Members & Sync Two Apple IDs
Sharing happens only between the inviter’s and invitee’s two Apple IDs. No server of ours sits in between.
- Shared ledgers sync through Apple CloudKit between the inviter and the invitee The other Apple ID
- Kinote runs no server of its own, and the developer cannot view your ledgers through CloudKit Not via the developer
- After unlinking, both members keep a local copy On device
- Changing Apple ID pauses cloud operations first. Once you confirm the new account, old shared ledgers become independent local copies, and the old account’s cloud contents are neither moved nor deleted Old account’s cloud kept
In-app entry: Members & Sync · turn off sync, unlink or stop sharing
Network and Feedback No entries sent
Rate queries send only currencies and dates. Feedback goes out only when you send the email yourself. No ads, no analytics SDKs.
- Exchange-rate queries send currencies and dates to Frankfurter Rate source
- Ledger entries, amounts, notes and member details are never sent Never sent
- Location collection and map queries are not enabled in this version Not enabled
- Problem reports send the message, screenshots you select and redacted diagnostic logs to the developer only after you confirm sending the email Developer’s inbox
- Kinote includes no ads, tracking or third-party analytics SDKs Never sent
Uninstalling the app deletes local data and internal safety snapshots, but not backups or shared data still in iCloud. Delete files exported outside the app from wherever you saved them.
Operator and contact
Kinote is operated by ZHANG YUNXIANG, an individual developer, the same seller shown on the App Store product page. Send privacy requests (access, correction, deletion or other questions) to kinote@onevroad.com; I reply within 7 business days.
Feedback emails (your message, the screenshots you chose and the diagnostic log) are used only to handle the issue you reported. They reach the developer’s personal mailbox through Cloudflare’s email forwarding service and are not passed on to anyone else. They are deleted within 90 days after the issue is handled; you can also email at any time to request earlier deletion.
Third-party services
Kinote does not sell or share user data with any third party. Sync and iCloud backup use Apple CloudKit and are covered by Apple’s privacy policy; exchange-rate lookups send only currency codes and a date to Frankfurter; feedback is sent from your own email account. Kinote has no server of its own and contains no ads, tracking or third-party analytics SDKs.
Changes to this policy
When this policy changes, the date at the top is updated. When a new data path is added (for example location and maps), the in-app description and this page are updated together.