InkBrook · Privacy Policy

Effective date: August 23, 2026


Introduction

InkBrook ("the app") is a personal memory and learning tool developed and operated by Dalian Junjing Xiyu Technology Co., Ltd. (大连峻境溪语科技有限公司) ("we"). It helps you turn every study session into a complete process of learning something and keeping it for the long term.

The app does not create exercises, teach lessons, or provide teaching content; everything you study in the app is created by you. It is intended for learners of all ages and is not directed specifically at minors. We will not provide your personal information to any third party for their own purposes without your consent.

The app is local-first: your study data stays on your own device by default, the app does not upload it to us, and we cannot view your study records. There is exactly one feature that sends information to our server—crash diagnostics (see Section 8): after a crash it sends technical information for troubleshooting, not the study content you wrote.

This policy explains how we treat your information and what rights you have. To get the essentials quickly, we suggest focusing on: "1. What information we collect," "4. Optional iCloud sync," "7. Disclosure and cross-border processing," "8. Crash diagnostics," "11. Your rights," and the contact details at the end. This policy applies to the iOS client of the app and its features.


1. What information we collect

The app collects very little, and most of it stays on your own device. The only things that reach our server are crash diagnostics and the IP address recorded in the server access log when they arrive (see Section 8). Our legal basis for processing is your consent, and some of it is necessary to deliver the features you use. It falls into three categories.

(1) Information you provide

You fill in or create all of this yourself. It stays on your device unless you turn on iCloud sync (see Section 4); otherwise it never leaves your device.

(2) Sign-in information

The app requires sign-in via Apple's "Sign in with Apple," tied to your Apple Account. Sign-in completes on your own device and does not go through our servers. You can sign out anytime in Settings, or use "Delete local data and sign out" to clear everything.

(3) What we collect automatically: crash diagnostics

The app includes no third-party analytics or advertising SDKs and uses no advertising identifiers; we do not collect your device information, usage behavior, or location for analytics or advertising. The app collects only two things automatically. The first is crash diagnostics after a crash—installation identifier, app version and build, OS version, device model, crash time, crash signature, and the exception stack payload—sent to our own server so we can locate and fix the crash. It is off by default: you choose whether to enable it with a separate checkbox on the consent page at first launch, and you can change it in Settings at any time; it is described in full in Section 8. The second is the source IP address and access time that the server access log records when those diagnostics arrive, used for security protection and troubleshooting; access logs are deleted automatically after about 90 days, never go to any third-party logging platform, and are not used for profiling or marketing. If you do not send crash diagnostics, no such log entry is produced.


2. How we use this information

All use happens on your device, solely to make the app work for you:

We do not use your information for profiling, personalized advertising, or cross-user comparison, and we do not analyze your study content for those purposes.


3. Storage and "local-first"

By default the app keeps all your data on your own device:

Retention and deletion:


4. Optional iCloud sync

The app offers optional iCloud sync to keep your study data aligned across your own devices. It is off by default and only you can turn it on.

Three conditions must be met first:

  1. You turn on the "iCloud Sync" switch in Settings;
  2. You confirm "I am 14 or older and have my guardian's consent";
  3. You have unlocked the corresponding paid entitlement.

Once on, your study data syncs to your own iCloud private database (container iCloud.com.junxi.memorycard), solely to align your own devices. Apple iCloud hosts the data under your Apple Account, subject to Apple's terms and privacy policy.

Note: that iCloud database belongs to your Apple Account and is hosted by Apple—it is not a cloud service we operate, and we cannot receive or view its contents. You can turn sync off anytime in Settings. For where this data is stored and possible cross-border scenarios, see Section 7.


5. Device permissions

The app requests the following permissions only when you use the corresponding feature; you can turn them off anytime in system Settings, and declining does not affect basic use.

(Permission / Purpose / Notes)

About photos: the app uses the iOS photo picker (PhotosPicker) to select problem or answer photos. The picker runs outside the app and returns only the image you chose, so the app needs no photo-library permission and never shows a library authorization prompt.

The app does not use location, contacts, calendar, or health permissions.

About notifications: review reminders are local notifications (at most one daily summary—no barrages). The app sends no marketing pushes. With iCloud sync on, your device may receive iCloud sync updates through Apple's push mechanism, which is provided by Apple and never used for ads or reporting personal data.


6. About speech recognition

When you use speech-to-text, recognition is performed by Apple's system speech service. Your audio snippets may be sent to Apple for processing; on supported devices and scenarios, recognition happens on-device without upload. Apple performs this processing as an independent service provider under its own terms and privacy policy; where the data is processed depends on Apple's service arrangements—see Section 7.

We receive only the converted text, which is stored solely on your device; we neither receive nor keep your original audio for any other purpose.


7. Disclosure and cross-border processing

We do not sell, rent, or provide your personal information to any third party for their own purposes. Crash diagnostics are sent to a server we operate ourselves (see Section 8) and do not involve disclosure to a third party.

All external capabilities involved are Apple system services: Sign in with Apple, optional iCloud sync, App Store in-app purchases, and speech recognition. In these scenarios Apple, as an independent processor, handles the information under its own terms and privacy policy; we require it to fulfill the corresponding security obligations. The data involved in these Apple system services does not pass through our servers.

On cross-border processing: we do not actively transfer your personal information outside mainland China. Crash diagnostics go to our server located in mainland China (see Section 8) and do not leave the country. The Apple system services above are handled by Apple as an independent provider under its own terms. iCloud data for mainland-China Apple Accounts (including this app's synced data) is stored within mainland China and does not leave the country; if you use a non-mainland Apple Account, or speech recognition is routed to Apple's services abroad, processing may occur outside mainland China under Apple's responsibility. iCloud sync and voice input are optional—leave them off and no such data flows occur.


8. Crash diagnostics

To locate and fix the problems that make the app crash, the app includes a crash reporting pipeline. Crash diagnostics are the only information the app sends to our server, so we set them out separately here.

(1) What we collect

After a crash, the system generates a crash report. The next time you open the app, the app sends that report to us together with the following:

(2) When it is sent

Only on the next launch after a crash. Ordinary use of the app neither produces nor sends this kind of information.

(3) Purpose and legal basis

This information is used solely to locate and fix crashes—never for profiling, advertising, or behavioral analysis of any kind. Our legal basis for processing it is your consent: the feature is enabled only if you tick the separate "Send crash diagnostics" checkbox on the consent page at first launch. That checkbox is independent of your agreement to this policy, and leaving it unticked does not affect any feature of the app. If you indicate on the consent page that you are under 14 and no guardian consents on your behalf, the app does not enable crash diagnostics.

(4) Default state and how to turn it off

Crash diagnostics are off by default; you choose whether to enable them with a separate checkbox on the consent page at first launch. Afterwards you can turn them on or off anytime in Settings → Help Improve → Send crash diagnostics. Once off, the app immediately stops collecting and uploading, and deletes the crash reports still waiting on your device.

(5) Recipient, location, and retention

This information goes to our own server (api.junjingxiyu.com), which is located in mainland China and operated by us, not routed through any third-party analytics or crash-statistics service. Crash reports are retained on the server for at most 90 days and then deleted automatically. When diagnostics arrive, the server access log records the source IP address and access time for security protection and troubleshooting, and is deleted automatically after about 90 days; the access log stays on that server only and never goes to any third-party logging or alerting platform.

(6) Link to your identity

A crash report is linked only to the random installation identifier described above. It contains no nickname, account, email, or name, and we cannot tell from it who you are.

(7) Deletion

When you use Settings → Account → Delete local data and sign out, the app first asks the server to delete every crash report under this installation identifier, then issues a new installation identifier on your device. If the network is unavailable at that moment and the request does not arrive, those reports on the server are still deleted automatically within at most 90 days. You can also email junxi@junjingxiyu.cn and ask us to delete them; because crash reports are stored only by random installation identifier and are not tied to an account, we need you to confirm from this device which ones to delete, and we will tell you how once we receive your email.

(8) About your study content

We keep your study content out of what we collect as far as we can: a crash report carries the call stacks and the exception information the system produced, not the goals, summaries, review cards, or photos you wrote. But exception information is generated by the app when something goes wrong, and it may carry an error description the app itself assembled; such text cannot be enumerated case by case, so we disclose the possibility honestly. If you would rather not accept it, turn crash diagnostics off as described in item (4).


9. About payment

Payment goes through the Apple App Store as an auto-renewing subscription (monthly or yearly). Eligible first-time subscribers can receive a 7-day free trial; eligibility is determined by the App Store and shown on the purchase confirmation. Where a trial is granted, the subscription auto-renews when the trial ends. The free trial is available once per Apple Account (monthly and yearly share the same trial); accounts that have used the trial are charged immediately upon confirming a new subscription. You can cancel anytime in Settings › your name (Apple Account) › Subscriptions; after cancellation the subscription lapses at the end of the current period.

Apple App Store collects the payment; we never collect or store your payment account or card details. For refunds, use Apple's refund channels. Whether Family Sharing is supported is shown on the App Store product page. The App Store price at the time of purchase applies.


10. How we protect information

Your data lives mainly on your own device, protected by iOS security mechanisms; the sign-in identifier lives in the system Keychain. We follow data minimization: we process only what the app needs to work, and skip whatever we can.

Study data does not pass through our servers; crash diagnostics travel over an encrypted connection (HTTPS). We take reasonable technical and organizational measures to protect your information, but please understand no method is absolutely secure. If a security incident such as leakage, tampering, or loss occurs, we will take remedial measures promptly as required by law and notify you and the relevant regulators when necessary.


11. Your rights

You have the following rights over your information, most exercisable directly in the app:

For further help, to exercise these rights, or to lodge a complaint, contact us via the email at the end of this policy; we will respond within a reasonable time. If you are unhappy with how we handle personal information, you may also complain to the cyberspace, market-regulation, or other personal-information-protection authorities.


12. Updates and contact

We may update this policy from time to time. Updates will carry a new effective date on this page; for material changes we will notify you appropriately.


Personal information collection list

The table below lists every kind of information the app may involve: type, when it arises, purpose, where it is stored, whether it is required, and whether it is shared with third parties. Two notes apply to the whole table:

Meanings of "storage location" values (individual rows may note otherwise): On device = in the local database or files on your device; Keychain = in the device's system Keychain (this device only, not synced via iCloud Keychain); Optional iCloud = on device by default, synced to your own iCloud private database (hosted by Apple under your Apple Account) only after you actively turn on iCloud sync. Individual rows use other phrasings, e.g., voice "not retained (discarded once transcribed)," review reminders "on device (local notifications)," widgets "on device (App Group shared container)," purchases "handled by the Apple App Store."

About iCloud sync: off by default. Turning it on requires flipping the switch yourself, confirming "I am 14 or older with guardian consent," and unlocking the paid entitlement—all three. Once on, study data syncs only to your own iCloud private database (iCloud.com.junxi.memorycard) to align your own devices; that database is not operated by the developer, who can neither receive nor see the data, which Apple iCloud hosts under your Apple Account and its terms and privacy policy.

(Type / When / Purpose / Storage / Required? / Shared with third parties?)

Device permissions: camera, microphone, speech recognition, and notifications are requested as needed; you can decline or revoke them anytime in system Settings. The related feature stops working, but everything else is unaffected.

Your own avatar photo: used only for local display; the developer performs no facial recognition, extracts no biometrics, and the photo is never sent to the developer (it enters your own iCloud only if you turn on sync).

Problem photos: photos you take or pick may contain faces or other sensitive content. They are attached locally to your study entries to aid recall; the developer performs no facial recognition, extracts no biometrics, and the photos are never sent to the developer (your own iCloud only, if you turn on sync).

Sensitive personal information and minors: birthday is optional; if provided, it is used only for profile display and age-based review pacing, and you can change or clear it anytime. Under the Personal Information Protection Law, personal information of children under 14 is sensitive—children under 14 should use the app with guardian knowledge and consent, and their information is handled under the rules for sensitive personal information with separate consent and extra protection.

Apple-handled system services: Sign in with Apple, optional iCloud sync, in-app purchase, and speech recognition are handled by Apple as system-service provider under Apple's terms and privacy policy; where the data resides depends on your Apple Account region (mainland-China accounts' iCloud data is hosted by the domestic operator). The developer retrieves none of this data from Apple.

Retention and deletion: local information stays on your device until you delete it. Deleted entries go to the Recycle Bin, kept up to 30 days, then cleared; uninstalling removes all local data. Voice is never retained—discarded once transcribed. Crash reports are kept on the developer's server for at most 90 days and then deleted automatically.

Processor and your rights: the personal-information processor for this app is Dalian Junjing Xiyu Technology Co., Ltd. (大连峻境溪语科技有限公司) (contact: junxi@junjingxiyu.cn). You have the rights to access, copy, correct, delete, withdraw consent, and deregister; see the policy body for how to exercise them.

Information the app does not touch: no location, contacts, calendar, or health data; your study data is never reported to any third party.

That is the complete list of information the app may involve; see the table above for details.


Third-party sharing list

This list is part of the InkBrook Privacy Policy and carries the same force as the body text.

The app integrates no third-party analytics or advertising SDKs, and uses no third-party crash-statistics service. Your study data is never uploaded to the developer (Dalian Junjing Xiyu Technology Co., Ltd. 大连峻境溪语科技有限公司), who cannot see it either. The only information the app sends to the developer's own server is crash diagnostics (see Section 8 of the Privacy Policy), received and processed by the developer itself; that is not sharing with a third party, so it is not listed in the table below.

Below are the Apple system services the app may involve, plus the local open-source libraries bundled with it. Apple services are provided by Apple, with data handled under Apple's terms; the local libraries run only on your device and collect and transmit nothing.

(Name / Provider / Trigger / Data involved / Data flow / Applicable privacy policy)

On cross-border processing

The app does not actively transfer your personal information outside mainland China; crash diagnostics go to the developer's server located in mainland China and do not leave the country. Everything above is an Apple system service handled by Apple as an independent provider under its own terms and privacy policy:

iCloud sync and voice input are optional—leave them off and none of these data flows occur.

Your control over these flows

Notes on the table:

For any questions about this list or data handling, or to access, correct, or delete your personal information, contact us at junxi@junjingxiyu.cn.


Children's personal information protection

InkBrook is for all ages—a personal memory and learning tool. Since users may include minors, we treat this information strictly under the Personal Information Protection Law, the Provisions on the Cyber Protection of Children's Personal Information, and related regulations, and explain it in this dedicated section.

1. Audience and age

If you are a minor, please use the app with your guardian's knowledge and consent. If the user is a child under 14, a guardian should read this policy and consent on the child's behalf before use; the guardian may also help manage, access, correct, or delete the child's study data.

2. Guardian consent (children under 14)

By law, personal information of children under 14 is sensitive. We process it only with the guardian's separate consent, following data minimization—only what the features require. That consent is obtained when the guardian reads this policy and confirms; it can be withdrawn anytime (see Section 3). Birthday is optional—leave it blank, or change or clear it anytime; if unnecessary, we suggest leaving it blank. We record the policy version, time, and manner of that consent (an adult tapping agree, or a guardian tapping agree on the child's behalf) as evidence of the processing; these records are kept on the device only. If the user is under 14 and no guardian has consented on their behalf, the app does not enable crash diagnostics (see Section 8 of the Privacy Policy).

By default the app keeps data only on the device you (or the child) use, with no automatic upload. Optional iCloud sync is off by default; enabling it requires confirming "I am 14 or older with guardian consent" and unlocking the paid entitlement (the same entitlement gate as for all users, regardless of age). Because sync cannot be enabled before this age confirmation, data of children under 14 is never uploaded to iCloud through this app and always stays on the device.

Retention: we keep minors' information only as long as the features require. Entries deleted in the app go to the Recycle Bin, kept up to 30 days, then cleared; uninstalling removes local data. Crash reports are kept on the developer's server for at most 90 days and then deleted automatically.

3. Rights a guardian may exercise

A guardian may exercise the following on behalf of a child under 14—mostly right in the app, or with our help via the contact at the end of this section:

(Right / How)

Signing out only clears the locally stored Apple sign-in identifier and does not affect other processing, so it is not listed as a way to withdraw consent. If the guardian does not consent or withdraws consent: children under 14 should not use the app before guardian consent is obtained; upon withdrawal we stop the corresponding processing and delete the information at your request (withdrawal does not affect processing already carried out).

4. Rules for processing children's personal information

For the personal information of children under 14, we have set the following dedicated rules:

  1. Purpose: solely to deliver the app's memory and learning features (recording study, scheduling reviews, showing growth state), and, once a guardian has consented, to locate and fix app crashes.
  2. Manner: children enter or create the information themselves in the app, and the app processes it on the device; crash diagnostics are uploaded automatically by the app on the next launch after a crash.
  3. Scope: nickname, optional profile details (education stage, grade, gender, birthday, avatar), study records and problem photos; plus crash diagnostics (installation identifier, app version and build, OS version, device model, crash time, crash signature, exception stack payload). Stage, grade, gender, and birthday may all be left blank.
  4. Storage location: study content and profile stay on the device in use; only crash diagnostics are sent, after guardian consent, to our server located in mainland China. Optional iCloud sync cannot be enabled before the age confirmation, so the study data of children under 14 is never uploaded to iCloud through this app.
  5. Retention: local information is kept until you delete it; entries deleted in the app go to the Recycle Bin and are cleared after up to 30 days; crash reports are kept on the server for at most 90 days and then deleted automatically; uninstalling removes local data.
  6. Security measures: local data is protected by the iOS security mechanisms and the sign-in identifier lives in the system Keychain; crash diagnostics travel over an encrypted connection (HTTPS) and are stored on the server under data minimization with restricted access.
  7. No third-party disclosure: we never provide children's data to third parties for their own purposes, nor sell or trade it. The sign-in, optional iCloud sync, in-app purchase, and speech recognition the app uses are provided by Apple under Apple's terms and privacy policy; speech recognition may send audio snippets to Apple (some devices support on-device recognition), and if that is unwanted, don't use the feature or don't grant the related permissions.

(The wording of this section is pending legal review.)

5. Issues and contact

We designate a person responsible for children's personal information protection. If you believe we collected a child's (under 14) personal information without guardian consent, or a guardian wishes to access, correct, or delete such information, contact us below; once verified, we will delete the information promptly.

(Matter / Contact)


Account deletion and data removal

InkBrook has no account system on a server. Your profile and study records live only on your own device by default; Dalian Junjing Xiyu Technology Co., Ltd. (大连峻境溪语科技有限公司) ("we") can neither receive nor see them. So "account deletion and data removal" here mostly means a few steps you take on your own device and in Apple's systems; only crash reports live on our server, and step 4 below explains how to delete those.

Five steps follow. Do only the ones you need: to wipe records but keep sign-in, step 2 alone is enough; to stop using the app entirely, walk through all five.

For readability, "Settings" below means the settings page opened by tapping your avatar at the top right of any page—the app has no separate Settings tab; enter via the avatar.

1. Sign out, and remove the Apple credential in the system

The app signs in with Sign in with Apple, which is required for use. You can sign out anytime, or "Delete local data and sign out."

1. Sign out in the app: tap your avatar on any page, go to Settings → Account, tap Sign out. This clears the Apple sign-in info stored locally (the Apple user identifier, plus the name/email returned at sign-in) but never touches your study data; your records stay on the device and are available again after you sign back in.

2. To have Apple stop associating the app with your Apple Account, remove the credential in the system: iPhone Settings → your name at the top → Sign in with Apple → InkBrook → Stop using Apple Account (older systems may say "Stop using Apple ID"; follow the actual interface). Apple performs this step, it affects the Apple-side association, and Apple's terms and privacy policy govern it.

2. Delete local study data

Your profile, goals, summaries, review cards, problem photos, growth and check-in records all live on the device. Two ways to delete:

Option 1 · Delete in the app (recoverable): deleting an entry from its detail page or a list sends it to the Recycle Bin for up to 30 days. Within those 30 days, restore it under Settings → Recycle Bin or delete it permanently; after 30 days it is automatically and permanently cleared.

Option 2 · Uninstall the app: uninstalling InkBrook removes the study data stored on this device. Note: the Apple sign-in identifier lives in the system Keychain and may not be cleared by uninstalling. To remove the credential too, sign out in the app first (step 1), then uninstall.

(Goal / Action / Result)

3. If you ever enabled iCloud sync

iCloud sync is off by default and enabled only by you. Only if you turned it on has study data synced to your own iCloud private database (solely to align your own devices). Apple hosts it under your Apple Account; that database is not operated by us, and we likewise can neither receive nor see it. To delete synced data, operate on your Apple devices and iCloud:

1. Turn off sync first: tap your avatar on any page, go to Settings → iCloud Sync, switch it off.

2. On every device that used sync, delete local data as in step 2 (in-app deletion or uninstall). Deleting entries on a device with sync still on usually propagates the deletion through the sync channel to the corresponding data in your iCloud.

3. Delete the iCloud copy: open Settings → your name at the top → iCloud, enter iCloud storage management (called "Manage Account Storage" or "Manage Storage" depending on the system). If InkBrook is listed, delete its iCloud data as prompted; the exact entry and whether the app is listed follow the actual interface. If you can't find the entry, fall back to step 2—delete in-app and let sync propagate—or email us for guidance. Apple iCloud performs this step under Apple's terms and privacy policy.

Note: uninstalling alone clears only this device's local data, not the copy already in iCloud—synced data must be deleted in iCloud separately as above. Also, if you delete data on one device but keep it on another signed in to the same Apple Account with sync on, the data may sync back. Best to turn off sync on all devices first, then clear them one by one. (Re-enabling sync later again requires confirming you are 14 or older with guardian consent, plus the paid entitlement.)

4. Deleting crash diagnostics already sent

Crash reports live on our server located in mainland China, stored by random installation identifier and not tied to your account (see Section 8 of the Privacy Policy). There are three ways to delete them:

  1. Use Settings → Account → Delete local data and sign out: the app first asks the server to delete every crash report under this installation identifier, then issues a new installation identifier on your device.
  2. If the network was unavailable and the request did not arrive, those reports on the server are still deleted automatically within at most 90 days.
  3. You can also email junxi@junjingxiyu.cn and ask us to delete them; because the reports are not tied to an account, we need you to confirm from this device which ones to delete, and we will tell you how once we receive your email.

You can also turn crash diagnostics off in Settings → Help Improve, after which no new reports are produced.

5. About purchases

Payment is an auto-renewing subscription collected by the Apple App Store; we never collect or store your payment details. Deleting local data or signing out never affects your subscription—it is tied to your Apple Account, and after switching or reinstalling you can recover it in-app via Restore Purchases. Subscription and refund records live with the Apple App Store, not in the app; for refunds, use Apple's channels. After expiry or cancellation, your local study data remains intact and reviewable—never deleted or locked (except batch-imported cards: their review scheduling pauses while unsubscribed, the content stays browsable in the app, and resubscribing restores it).

6. Need help

Almost all deletion can be done by you in the app or system Settings. If you hit a snag, or want to confirm everything is gone, email us: junxi@junjingxiyu.cn. We will reply within 15 business days and guide you through; but please understand that we cannot delete what lives on your device or in your iCloud on your behalf—what we can do is guide you through the steps above. Crash reports on the server can be handled as in step 4.

About minors: if the user is a child under 14, the guardian holds the rights to access, copy, correct, and delete the child's personal information, may follow the steps above to help manage it, and may contact us at junxi@junjingxiyu.cn to exercise these rights. If you believe children's information was collected without guardian consent, contact us at the same address.

Your data lives on your own device (and in your own iCloud if you enabled sync). Whether and what to delete is your call.


Contact and filing

This document is a translation of the Simplified Chinese original. In case of any discrepancy, the Simplified Chinese version shall prevail.