InkBrook · Privacy Policy
Effective date: August 23, 2026
Introduction
InkBrook ("the app") is a personal memory and learning tool developed and operated by Dalian Junjing Xiyu Technology Co., Ltd. (大连峻境溪语科技有限公司) ("we"). It helps you turn every study session into a complete process of learning something and keeping it for the long term.
The app does not create exercises, teach lessons, or provide teaching content; everything you study in the app is created by you. It is intended for learners of all ages and is not directed specifically at minors. We will not provide your personal information to any third party for their own purposes without your consent.
The app is local-first: your study data stays on your own device by default, the app does not upload it to us, and we cannot view your study records. There is exactly one feature that sends information to our server—crash diagnostics (see Section 8): after a crash it sends technical information for troubleshooting, not the study content you wrote.
This policy explains how we treat your information and what rights you have. To get the essentials quickly, we suggest focusing on: "1. What information we collect," "4. Optional iCloud sync," "7. Disclosure and cross-border processing," "8. Crash diagnostics," "11. Your rights," and the contact details at the end. This policy applies to the iOS client of the app and its features.
1. What information we collect
The app collects very little, and most of it stays on your own device. The only things that reach our server are crash diagnostics and the IP address recorded in the server access log when they arrive (see Section 8). Our legal basis for processing is your consent, and some of it is necessary to deliver the features you use. It falls into three categories.
(1) Information you provide
You fill in or create all of this yourself. It stays on your device unless you turn on iCloud sync (see Section 4); otherwise it never leaves your device.
- Nickname: used to address you in the app.
- Optional profile details: avatar (choose from built-in illustrations or use your own photo), education stage and grade, international program, gender, birthday. All optional—leave them blank, or change or clear them anytime. We treat items like your birthday with extra care; leaving them blank doesn't limit any feature.
- Study records: goals, focus durations, Pomodoro counts, summaries and reflections, review cards, growth state (streaks, XP, level, badges), subjects, exam schedules, daily check-ins, and so on.
- Problem photos: photos you take or pick for problems, plus photos you attach to answers. They may contain faces or other personal information of you or others. We process them only on your device, only when you actively take or pick them for review purposes, and only to help you recall the problem later. The app performs no facial recognition, extracts no biometric features, and does not use photos to identify anyone. Because photos may contain faces, we protect them locally to the standard of sensitive personal information. By taking or picking a photo you consent to this processing. Photos stay on your device by default; delete them anytime and processing stops.
(2) Sign-in information
The app requires sign-in via Apple's "Sign in with Apple," tied to your Apple Account. Sign-in completes on your own device and does not go through our servers. You can sign out anytime in Settings, or use "Delete local data and sign out" to clear everything.
- After sign-in, we store only the Apple-issued user identifier in your device's system Keychain, so you don't have to sign in again. It exists only on this device and does not sync via iCloud Keychain.
- If you agree to share your email and name at sign-in, Apple returns them to the app and they are stored on your device (the email may be Apple's private relay address). If you decline, we never receive them.
- The sign-in flow calls no authentication backend of ours or anyone else's.
(3) What we collect automatically: crash diagnostics
The app includes no third-party analytics or advertising SDKs and uses no advertising identifiers; we do not collect your device information, usage behavior, or location for analytics or advertising. The app collects only two things automatically. The first is crash diagnostics after a crash—installation identifier, app version and build, OS version, device model, crash time, crash signature, and the exception stack payload—sent to our own server so we can locate and fix the crash. It is off by default: you choose whether to enable it with a separate checkbox on the consent page at first launch, and you can change it in Settings at any time; it is described in full in Section 8. The second is the source IP address and access time that the server access log records when those diagnostics arrive, used for security protection and troubleshooting; access logs are deleted automatically after about 90 days, never go to any third-party logging platform, and are not used for profiling or marketing. If you do not send crash diagnostics, no such log entry is produced.
2. How we use this information
All use happens on your device, solely to make the app work for you:
- your nickname and profile to address and display you in the app;
- your study records, review cards, and growth state to run the "goal → focus → reflect → review" loop and remind you to review at the right time;
- problem photos to help you recall problems during review;
- the sign-in identifier so you don't have to sign in again when reopening the app.
We do not use your information for profiling, personalized advertising, or cross-user comparison, and we do not analyze your study content for those purposes.
3. Storage and "local-first"
By default the app keeps all your data on your own device:
- Study content, profile, growth state, subjects and exams, check-ins, and the like are stored in the app's local database, and do not leave your device unless you turn on iCloud sync (see Section 4).
- The sign-in identifier is stored in the device's system Keychain, on this device only.
- To power the Home Screen and Lock Screen widgets, the app keeps a read-only snapshot in the device's App Group. It contains only non-personal statistics and UI state (e.g., streak days, weekly focus time, level, library count, subject colors)—never your study text, summaries, or photos. Widgets read only this snapshot and never touch your study database.
Retention and deletion:
- Apart from the Recycle Bin rules below, your study data stays on your device until you delete it or uninstall the app. We never delete your data ourselves.
- Entries you delete in the app go to the Recycle Bin first, kept for up to 30 days, then permanently cleared; you can also permanently delete them manually at any time.
- Uninstalling the app clears its local data on the device.
- If you have iCloud sync on, deletions propagate across your devices through Apple iCloud.
4. Optional iCloud sync
The app offers optional iCloud sync to keep your study data aligned across your own devices. It is off by default and only you can turn it on.
Three conditions must be met first:
- You turn on the "iCloud Sync" switch in Settings;
- You confirm "I am 14 or older and have my guardian's consent";
- You have unlocked the corresponding paid entitlement.
Once on, your study data syncs to your own iCloud private database (container iCloud.com.junxi.memorycard), solely to align your own devices. Apple iCloud hosts the data under your Apple Account, subject to Apple's terms and privacy policy.
Note: that iCloud database belongs to your Apple Account and is hosted by Apple—it is not a cloud service we operate, and we cannot receive or view its contents. You can turn sync off anytime in Settings. For where this data is stored and possible cross-border scenarios, see Section 7.
5. Device permissions
The app requests the following permissions only when you use the corresponding feature; you can turn them off anytime in system Settings, and declining does not affect basic use.
(Permission / Purpose / Notes)
- Camera / photograph problems so you can recall them during review / photos stay on your device
- Microphone / speak your study summaries / works with speech recognition; Apple converts speech to text (see Section 6)
- Speech recognition / turn what you say into text for quick capture / provided by Apple, see Section 6
- Notifications / remind you to self-test at your chosen review time; also used by the Pomodoro timer / requested when you enter the feature; local reminders only, no marketing pushes
About photos: the app uses the iOS photo picker (PhotosPicker) to select problem or answer photos. The picker runs outside the app and returns only the image you chose, so the app needs no photo-library permission and never shows a library authorization prompt.
The app does not use location, contacts, calendar, or health permissions.
About notifications: review reminders are local notifications (at most one daily summary—no barrages). The app sends no marketing pushes. With iCloud sync on, your device may receive iCloud sync updates through Apple's push mechanism, which is provided by Apple and never used for ads or reporting personal data.
6. About speech recognition
When you use speech-to-text, recognition is performed by Apple's system speech service. Your audio snippets may be sent to Apple for processing; on supported devices and scenarios, recognition happens on-device without upload. Apple performs this processing as an independent service provider under its own terms and privacy policy; where the data is processed depends on Apple's service arrangements—see Section 7.
We receive only the converted text, which is stored solely on your device; we neither receive nor keep your original audio for any other purpose.
7. Disclosure and cross-border processing
We do not sell, rent, or provide your personal information to any third party for their own purposes. Crash diagnostics are sent to a server we operate ourselves (see Section 8) and do not involve disclosure to a third party.
All external capabilities involved are Apple system services: Sign in with Apple, optional iCloud sync, App Store in-app purchases, and speech recognition. In these scenarios Apple, as an independent processor, handles the information under its own terms and privacy policy; we require it to fulfill the corresponding security obligations. The data involved in these Apple system services does not pass through our servers.
On cross-border processing: we do not actively transfer your personal information outside mainland China. Crash diagnostics go to our server located in mainland China (see Section 8) and do not leave the country. The Apple system services above are handled by Apple as an independent provider under its own terms. iCloud data for mainland-China Apple Accounts (including this app's synced data) is stored within mainland China and does not leave the country; if you use a non-mainland Apple Account, or speech recognition is routed to Apple's services abroad, processing may occur outside mainland China under Apple's responsibility. iCloud sync and voice input are optional—leave them off and no such data flows occur.
8. Crash diagnostics
To locate and fix the problems that make the app crash, the app includes a crash reporting pipeline. Crash diagnostics are the only information the app sends to our server, so we set them out separately here.
(1) What we collect
After a crash, the system generates a crash report. The next time you open the app, the app sends that report to us together with the following:
- Installation identifier (installId): a random string the app generates when you first install it, used to tie together several crashes from the same installation. It is not a device hardware identifier, is not taken from the system, and cannot be used to recognize you across apps.
- The app version and build number;
- The OS version;
- The device model (e.g., iPhone15,2);
- The time the crash occurred;
- Crash signature: a one-line identifier assembled from the exception type and the failure site, used to group crashes caused by the same problem;
- Exception stack payload: the call stacks of each thread at the time of the crash, plus the exception information the system generated.
(2) When it is sent
Only on the next launch after a crash. Ordinary use of the app neither produces nor sends this kind of information.
(3) Purpose and legal basis
This information is used solely to locate and fix crashes—never for profiling, advertising, or behavioral analysis of any kind. Our legal basis for processing it is your consent: the feature is enabled only if you tick the separate "Send crash diagnostics" checkbox on the consent page at first launch. That checkbox is independent of your agreement to this policy, and leaving it unticked does not affect any feature of the app. If you indicate on the consent page that you are under 14 and no guardian consents on your behalf, the app does not enable crash diagnostics.
(4) Default state and how to turn it off
Crash diagnostics are off by default; you choose whether to enable them with a separate checkbox on the consent page at first launch. Afterwards you can turn them on or off anytime in Settings → Help Improve → Send crash diagnostics. Once off, the app immediately stops collecting and uploading, and deletes the crash reports still waiting on your device.
(5) Recipient, location, and retention
This information goes to our own server (api.junjingxiyu.com), which is located in mainland China and operated by us, not routed through any third-party analytics or crash-statistics service. Crash reports are retained on the server for at most 90 days and then deleted automatically. When diagnostics arrive, the server access log records the source IP address and access time for security protection and troubleshooting, and is deleted automatically after about 90 days; the access log stays on that server only and never goes to any third-party logging or alerting platform.
(6) Link to your identity
A crash report is linked only to the random installation identifier described above. It contains no nickname, account, email, or name, and we cannot tell from it who you are.
(7) Deletion
When you use Settings → Account → Delete local data and sign out, the app first asks the server to delete every crash report under this installation identifier, then issues a new installation identifier on your device. If the network is unavailable at that moment and the request does not arrive, those reports on the server are still deleted automatically within at most 90 days. You can also email junxi@junjingxiyu.cn and ask us to delete them; because crash reports are stored only by random installation identifier and are not tied to an account, we need you to confirm from this device which ones to delete, and we will tell you how once we receive your email.
(8) About your study content
We keep your study content out of what we collect as far as we can: a crash report carries the call stacks and the exception information the system produced, not the goals, summaries, review cards, or photos you wrote. But exception information is generated by the app when something goes wrong, and it may carry an error description the app itself assembled; such text cannot be enumerated case by case, so we disclose the possibility honestly. If you would rather not accept it, turn crash diagnostics off as described in item (4).
9. About payment
Payment goes through the Apple App Store as an auto-renewing subscription (monthly or yearly). Eligible first-time subscribers can receive a 7-day free trial; eligibility is determined by the App Store and shown on the purchase confirmation. Where a trial is granted, the subscription auto-renews when the trial ends. The free trial is available once per Apple Account (monthly and yearly share the same trial); accounts that have used the trial are charged immediately upon confirming a new subscription. You can cancel anytime in Settings › your name (Apple Account) › Subscriptions; after cancellation the subscription lapses at the end of the current period.
Apple App Store collects the payment; we never collect or store your payment account or card details. For refunds, use Apple's refund channels. Whether Family Sharing is supported is shown on the App Store product page. The App Store price at the time of purchase applies.
10. How we protect information
Your data lives mainly on your own device, protected by iOS security mechanisms; the sign-in identifier lives in the system Keychain. We follow data minimization: we process only what the app needs to work, and skip whatever we can.
Study data does not pass through our servers; crash diagnostics travel over an encrypted connection (HTTPS). We take reasonable technical and organizational measures to protect your information, but please understand no method is absolutely secure. If a security incident such as leakage, tampering, or loss occurs, we will take remedial measures promptly as required by law and notify you and the relevant regulators when necessary.
11. Your rights
You have the following rights over your information, most exercisable directly in the app:
- Know and decide: learn from this policy how we handle your information at any time, and decide through the in-app switches whether to enable the corresponding features (crash diagnostics, iCloud sync, and so on);
- Access and correction: view and edit your profile and study records in the app anytime;
- Copy and export: export the whole database as a zip in Settings, and re-import it;
- Deletion: delete entries in the app (Recycle Bin first, permanently cleared after up to 30 days), or uninstall to clear local data;
- Withdraw consent: turn off camera, microphone, and other system permissions anytime, or turn off iCloud sync;
- Sign out and account deletion: the app has no account system on a server. "Sign out" clears only the locally stored Apple sign-in identifier and leaves your study data untouched. "Delete local data and sign out" clears the local data and at the same time asks the server to delete the crash reports under that installation identifier (see Section 8); if that request does not arrive, the reports on the server are still deleted automatically within at most 90 days.
For further help, to exercise these rights, or to lodge a complaint, contact us via the email at the end of this policy; we will respond within a reasonable time. If you are unhappy with how we handle personal information, you may also complain to the cyberspace, market-regulation, or other personal-information-protection authorities.
12. Updates and contact
We may update this policy from time to time. Updates will carry a new effective date on this page; for material changes we will notify you appropriately.
- Developer and operator: Dalian Junjing Xiyu Technology Co., Ltd. (大连峻境溪语科技有限公司)
- Contact email: junxi@junjingxiyu.cn
- ICP filing: 辽ICP备2026012126号-2A
- Last updated: August 23, 2026
Personal information collection list
The table below lists every kind of information the app may involve: type, when it arises, purpose, where it is stored, whether it is required, and whether it is shared with third parties. Two notes apply to the whole table:
- Most items are optional; the app works fine with nothing filled in. Items marked "optional" can be left blank at any time.
- What you create stays on your own device by default, and the developer cannot view your study records. The app integrates no third-party analytics or advertising SDKs; crash diagnostics are handled by the developer's own service (see Section 8 of the Privacy Policy), and what is sent is technical information from the crash, not study content. Only when you actively turn on iCloud sync, or use Apple system services such as sign-in, speech-to-text, or in-app purchase, is the relevant information handled by Apple as described below.
Meanings of "storage location" values (individual rows may note otherwise): On device = in the local database or files on your device; Keychain = in the device's system Keychain (this device only, not synced via iCloud Keychain); Optional iCloud = on device by default, synced to your own iCloud private database (hosted by Apple under your Apple Account) only after you actively turn on iCloud sync. Individual rows use other phrasings, e.g., voice "not retained (discarded once transcribed)," review reminders "on device (local notifications)," widgets "on device (App Group shared container)," purchases "handled by the Apple App Store."
About iCloud sync: off by default. Turning it on requires flipping the switch yourself, confirming "I am 14 or older with guardian consent," and unlocking the paid entitlement—all three. Once on, study data syncs only to your own iCloud private database (iCloud.com.junxi.memorycard) to align your own devices; that database is not operated by the developer, who can neither receive nor see the data, which Apple iCloud hosts under your Apple Account and its terms and privacy policy.
(Type / When / Purpose / Storage / Required? / Shared with third parties?)
- Nickname / entered at onboarding or edited in My Profile / to address you and show your profile / on device (optional iCloud) / optional / no
- Education stage, enrollment year, grade, international program / entered at onboarding or on the profile page / derive grade; decide long-term review by stage / on device (optional iCloud) / optional / no
- Gender / profile page / profile display / on device (optional iCloud) / optional / no
- Birthday / profile page / profile display and age-based review pacing (may be left blank, see notes) / on device (optional iCloud) / optional / no
- Avatar (built-in illustration or your own photo) / chosen from presets or a local photo / local profile display (no facial recognition, see notes) / on device (optional iCloud) / optional / no
- Apple user identifier / when you sign in with Apple / recognize sign-in state locally (does not go through the developer's server) / Keychain (this device only) / required (the app requires sign-in) / no (generated by Apple, stored locally only, never sent back)
- Email / name returned by Apple / when you agree to share at sign-in / display account info / on device / optional (decline, or use Apple's private relay email) / no (returned by Apple with your consent, then stored locally only)
- Study goals, focus time, Pomodoro counts / setting goals, running the timer / record the process, build statistics / on device (optional iCloud) / optional (goals may be blank) / no
- Summaries / reflections, review cards / reflections, backfills, quick notes, reviews / form your own review content, scheduled by memory science / on device (optional iCloud) / optional / no
- Problem photos (may contain faces, see notes) / taken or picked while reflecting, backfilling, reviewing / attached to entries to aid recall / on device (optional iCloud) / optional / no (picked via the system picker, which returns only your chosen image)
- Growth state (level, streaks, badges…) / accumulates as you study / show progress, daily quests, check-ins / on device (optional iCloud) / arises with use / no
- Subjects, exams, daily check-ins / created by you; recorded as you study / per-subject records, exam-driven pacing, check-in stats / on device (optional iCloud) / optional / no
- Voice recordings / when dictating summaries / transcribed to text for quick capture / not retained (discarded once transcribed) / optional (you can type) / speech-to-text is provided by Apple; depending on device and settings, audio may be processed on-device or sent to Apple; the developer never receives your audio
- Review reminders / after you allow notifications / one daily review summary / on device (local notifications) / optional (disable in system settings) / no
- Widget snapshot / when you add Home/Lock Screen widgets / read-only display of streaks, focus time, level, library count, subject colors—non-personal stats / on device (App Group shared container, no study text) / arises with use / no
- Purchase / subscription receipts / when you subscribe to Premium (auto-renewing, monthly or yearly) / verify and unlock Premium, restore purchases / handled by the Apple App Store / optional (the free version works without) / Apple App Store collects payment; the developer never collects or stores payment details; refunds via Apple
- Crash diagnostics (installation identifier, app version and build, OS version, device model, crash time, crash signature, exception stack payload) / on the next launch after a crash / to locate and fix crashes / developer's own server (api.junjingxiyu.com, in mainland China), deleted automatically after at most 90 days / optional (off by default; chosen with a separate checkbox on the consent page at first launch; can be changed in Settings → Help Improve) / no (no third-party analytics or crash-statistics service involved)
- IP address and access time / when crash diagnostics arrive at our server / security protection and troubleshooting / access log of the developer's own server (in mainland China), deleted automatically after about 90 days / produced automatically (not produced if you do not send crash diagnostics) / no (never goes to a third-party logging platform)
Device permissions: camera, microphone, speech recognition, and notifications are requested as needed; you can decline or revoke them anytime in system Settings. The related feature stops working, but everything else is unaffected.
Your own avatar photo: used only for local display; the developer performs no facial recognition, extracts no biometrics, and the photo is never sent to the developer (it enters your own iCloud only if you turn on sync).
Problem photos: photos you take or pick may contain faces or other sensitive content. They are attached locally to your study entries to aid recall; the developer performs no facial recognition, extracts no biometrics, and the photos are never sent to the developer (your own iCloud only, if you turn on sync).
Sensitive personal information and minors: birthday is optional; if provided, it is used only for profile display and age-based review pacing, and you can change or clear it anytime. Under the Personal Information Protection Law, personal information of children under 14 is sensitive—children under 14 should use the app with guardian knowledge and consent, and their information is handled under the rules for sensitive personal information with separate consent and extra protection.
Apple-handled system services: Sign in with Apple, optional iCloud sync, in-app purchase, and speech recognition are handled by Apple as system-service provider under Apple's terms and privacy policy; where the data resides depends on your Apple Account region (mainland-China accounts' iCloud data is hosted by the domestic operator). The developer retrieves none of this data from Apple.
Retention and deletion: local information stays on your device until you delete it. Deleted entries go to the Recycle Bin, kept up to 30 days, then cleared; uninstalling removes all local data. Voice is never retained—discarded once transcribed. Crash reports are kept on the developer's server for at most 90 days and then deleted automatically.
Processor and your rights: the personal-information processor for this app is Dalian Junjing Xiyu Technology Co., Ltd. (大连峻境溪语科技有限公司) (contact: junxi@junjingxiyu.cn). You have the rights to access, copy, correct, delete, withdraw consent, and deregister; see the policy body for how to exercise them.
Information the app does not touch: no location, contacts, calendar, or health data; your study data is never reported to any third party.
That is the complete list of information the app may involve; see the table above for details.
Third-party sharing list
This list is part of the InkBrook Privacy Policy and carries the same force as the body text.
The app integrates no third-party analytics or advertising SDKs, and uses no third-party crash-statistics service. Your study data is never uploaded to the developer (Dalian Junjing Xiyu Technology Co., Ltd. 大连峻境溪语科技有限公司), who cannot see it either. The only information the app sends to the developer's own server is crash diagnostics (see Section 8 of the Privacy Policy), received and processed by the developer itself; that is not sharing with a third party, so it is not listed in the table below.
Below are the Apple system services the app may involve, plus the local open-source libraries bundled with it. Apple services are provided by Apple, with data handled under Apple's terms; the local libraries run only on your device and collect and transmit nothing.
(Name / Provider / Trigger / Data involved / Data flow / Applicable privacy policy)
- Sign in with Apple / Apple / when you sign in (required to use the app) / the Apple user identifier; plus the name and email Apple returns if you agree to share (possibly a private relay address) / Apple performs the authentication. The identifier is stored only in your local system Keychain (this device only, not synced via iCloud Keychain); name/email stay on device, and that information does not go to the developer / Apple Privacy Policy (https://www.apple.com/legal/privacy/)
- Optional iCloud sync / Apple / after you actively enable it in Settings. Off by default; requires flipping the switch, confirming "14 or older with guardian consent," and the paid entitlement / study data you created (entries, review cards, problem photos, etc.) / synced to your own iCloud private database (iCloud.com.junxi.memorycard), hosted by Apple under your Apple Account, solely to align your own devices. iCloud for mainland-China Apple Accounts is operated by GCBD with data stored in mainland China; elsewhere Apple hosts it. That database is not operated by the developer, who cannot access the data / Apple Privacy Policy (https://www.apple.com/legal/privacy/); for mainland China see also the GCBD iCloud terms
- App Store in-app purchase / Apple / when you subscribe to Premium (auto-renewing, monthly or yearly; eligible first-time subscribers may receive a 7-day free trial) / payment and transaction data handled by Apple; the developer receives only a "subscription valid or not" receipt result / Apple App Store collects payment; the developer never collects or stores payment details; refunds via Apple; Family Sharing support is shown on the App Store product page / Apple Privacy Policy (https://www.apple.com/legal/privacy/)
- Apple speech recognition / Apple / when you dictate summaries or reflections / your spoken audio snippets / processed by Apple's system speech recognition, which may send snippets to Apple (some devices support on-device recognition), solely to convert speech to text. Audio never goes to developer servers, and the developer never receives it / Apple Privacy Policy (https://www.apple.com/legal/privacy/)
- ConfettiSwiftUI / open-source ConfettiSwiftUI (https://github.com/simibac/ConfettiSwiftUI, MIT license, bundled as a local Swift Package) / celebration confetti when you complete study actions / none / runs only on your device, no network, collects and transmits nothing / not applicable (processes no data)
- swift-fsrs / open-source swift-fsrs (https://github.com/open-spaced-repetition/swift-fsrs, MIT license, bundled as a local Swift Package) / computes each card's next review time on-device / none / runs only on your device, no network, collects and transmits nothing / not applicable (processes no data)
On cross-border processing
The app does not actively transfer your personal information outside mainland China; crash diagnostics go to the developer's server located in mainland China and do not leave the country. Everything above is an Apple system service handled by Apple as an independent provider under its own terms and privacy policy:
- iCloud sync: iCloud data for mainland-China Apple Accounts (including this app's synced data) is operated by GCBD and stored within mainland China, with no cross-border transfer; with a non-mainland Apple Account, Apple hosts your iCloud data in the corresponding region, possibly outside mainland China.
- Speech recognition: provided by the Apple system; depending on device and settings, it may complete on your device or be routed to Apple's services (possibly outside mainland China).
- Sign in with Apple and App Store purchases: handled by Apple; the app transmits none of your personal information to them beyond what Apple's flows require, under Apple's terms.
- All of the above are subject to the Apple Privacy Policy (https://www.apple.com/legal/privacy/); you can manage related information through your Apple Account settings.
iCloud sync and voice input are optional—leave them off and none of these data flows occur.
Your control over these flows
- The app requires Sign in with Apple; you can sign out anytime, or use "Delete local data and sign out" in Settings.
- iCloud sync is off by default and can be turned off anytime; once off, no new data syncs to iCloud.
- Microphone, speech recognition, and camera permissions can be revoked anytime in system Settings.
- Deleted entries go to the Recycle Bin, kept up to 30 days, then cleared; uninstalling removes local data.
- Crash diagnostics are off by default, chosen with a separate checkbox on the consent page at first launch, and can be changed anytime in Settings → Help Improve; once off, the app immediately stops collecting and uploading, and deletes the reports still waiting on the device.
Notes on the table:
- Beyond the items listed, the app has no other third-party data recipients, and shares no personal information with any analytics, advertising, or sign-in verification platform.
- Notifications such as review reminders are scheduled locally on the device, with no third-party push service.
For any questions about this list or data handling, or to access, correct, or delete your personal information, contact us at junxi@junjingxiyu.cn.
Children's personal information protection
InkBrook is for all ages—a personal memory and learning tool. Since users may include minors, we treat this information strictly under the Personal Information Protection Law, the Provisions on the Cyber Protection of Children's Personal Information, and related regulations, and explain it in this dedicated section.
1. Audience and age
If you are a minor, please use the app with your guardian's knowledge and consent. If the user is a child under 14, a guardian should read this policy and consent on the child's behalf before use; the guardian may also help manage, access, correct, or delete the child's study data.
2. Guardian consent (children under 14)
By law, personal information of children under 14 is sensitive. We process it only with the guardian's separate consent, following data minimization—only what the features require. That consent is obtained when the guardian reads this policy and confirms; it can be withdrawn anytime (see Section 3). Birthday is optional—leave it blank, or change or clear it anytime; if unnecessary, we suggest leaving it blank. We record the policy version, time, and manner of that consent (an adult tapping agree, or a guardian tapping agree on the child's behalf) as evidence of the processing; these records are kept on the device only. If the user is under 14 and no guardian has consented on their behalf, the app does not enable crash diagnostics (see Section 8 of the Privacy Policy).
By default the app keeps data only on the device you (or the child) use, with no automatic upload. Optional iCloud sync is off by default; enabling it requires confirming "I am 14 or older with guardian consent" and unlocking the paid entitlement (the same entitlement gate as for all users, regardless of age). Because sync cannot be enabled before this age confirmation, data of children under 14 is never uploaded to iCloud through this app and always stays on the device.
Retention: we keep minors' information only as long as the features require. Entries deleted in the app go to the Recycle Bin, kept up to 30 days, then cleared; uninstalling removes local data. Crash reports are kept on the developer's server for at most 90 days and then deleted automatically.
3. Rights a guardian may exercise
A guardian may exercise the following on behalf of a child under 14—mostly right in the app, or with our help via the contact at the end of this section:
(Right / How)
- Access / view all study records and profile in the app; export a copy of the data in the app
- Correction / edit the nickname, profile, and study records in the app
- Deletion / delete entries in the app (Recycle Bin first, cleared after up to 30 days); uninstall to remove local data
- Withdraw consent / turn off iCloud sync; revoke camera / microphone / speech recognition / notification permissions in system Settings; or delete data in the app and uninstall
- Refuse or decline / choosing "Not now" on the consent page means you do not enter the app; if consent was already given, withdraw it as in the row above
- Complaints and reports / contact us at the email at the end of this section; you may also complain to the cyberspace, market-regulation, or other personal-information-protection authorities
Signing out only clears the locally stored Apple sign-in identifier and does not affect other processing, so it is not listed as a way to withdraw consent. If the guardian does not consent or withdraws consent: children under 14 should not use the app before guardian consent is obtained; upon withdrawal we stop the corresponding processing and delete the information at your request (withdrawal does not affect processing already carried out).
4. Rules for processing children's personal information
For the personal information of children under 14, we have set the following dedicated rules:
- Purpose: solely to deliver the app's memory and learning features (recording study, scheduling reviews, showing growth state), and, once a guardian has consented, to locate and fix app crashes.
- Manner: children enter or create the information themselves in the app, and the app processes it on the device; crash diagnostics are uploaded automatically by the app on the next launch after a crash.
- Scope: nickname, optional profile details (education stage, grade, gender, birthday, avatar), study records and problem photos; plus crash diagnostics (installation identifier, app version and build, OS version, device model, crash time, crash signature, exception stack payload). Stage, grade, gender, and birthday may all be left blank.
- Storage location: study content and profile stay on the device in use; only crash diagnostics are sent, after guardian consent, to our server located in mainland China. Optional iCloud sync cannot be enabled before the age confirmation, so the study data of children under 14 is never uploaded to iCloud through this app.
- Retention: local information is kept until you delete it; entries deleted in the app go to the Recycle Bin and are cleared after up to 30 days; crash reports are kept on the server for at most 90 days and then deleted automatically; uninstalling removes local data.
- Security measures: local data is protected by the iOS security mechanisms and the sign-in identifier lives in the system Keychain; crash diagnostics travel over an encrypted connection (HTTPS) and are stored on the server under data minimization with restricted access.
- No third-party disclosure: we never provide children's data to third parties for their own purposes, nor sell or trade it. The sign-in, optional iCloud sync, in-app purchase, and speech recognition the app uses are provided by Apple under Apple's terms and privacy policy; speech recognition may send audio snippets to Apple (some devices support on-device recognition), and if that is unwanted, don't use the feature or don't grant the related permissions.
(The wording of this section is pending legal review.)
5. Issues and contact
We designate a person responsible for children's personal information protection. If you believe we collected a child's (under 14) personal information without guardian consent, or a guardian wishes to access, correct, or delete such information, contact us below; once verified, we will delete the information promptly.
(Matter / Contact)
- Guardian access / correction / deletion requests / junxi@junjingxiyu.cn
- Reporting collection of children's information without consent / junxi@junjingxiyu.cn
Account deletion and data removal
InkBrook has no account system on a server. Your profile and study records live only on your own device by default; Dalian Junjing Xiyu Technology Co., Ltd. (大连峻境溪语科技有限公司) ("we") can neither receive nor see them. So "account deletion and data removal" here mostly means a few steps you take on your own device and in Apple's systems; only crash reports live on our server, and step 4 below explains how to delete those.
Five steps follow. Do only the ones you need: to wipe records but keep sign-in, step 2 alone is enough; to stop using the app entirely, walk through all five.
For readability, "Settings" below means the settings page opened by tapping your avatar at the top right of any page—the app has no separate Settings tab; enter via the avatar.
1. Sign out, and remove the Apple credential in the system
The app signs in with Sign in with Apple, which is required for use. You can sign out anytime, or "Delete local data and sign out."
1. Sign out in the app: tap your avatar on any page, go to Settings → Account, tap Sign out. This clears the Apple sign-in info stored locally (the Apple user identifier, plus the name/email returned at sign-in) but never touches your study data; your records stay on the device and are available again after you sign back in.
2. To have Apple stop associating the app with your Apple Account, remove the credential in the system: iPhone Settings → your name at the top → Sign in with Apple → InkBrook → Stop using Apple Account (older systems may say "Stop using Apple ID"; follow the actual interface). Apple performs this step, it affects the Apple-side association, and Apple's terms and privacy policy govern it.
2. Delete local study data
Your profile, goals, summaries, review cards, problem photos, growth and check-in records all live on the device. Two ways to delete:
Option 1 · Delete in the app (recoverable): deleting an entry from its detail page or a list sends it to the Recycle Bin for up to 30 days. Within those 30 days, restore it under Settings → Recycle Bin or delete it permanently; after 30 days it is automatically and permanently cleared.
Option 2 · Uninstall the app: uninstalling InkBrook removes the study data stored on this device. Note: the Apple sign-in identifier lives in the system Keychain and may not be cleared by uninstalling. To remove the credential too, sign out in the app first (step 1), then uninstall.
(Goal / Action / Result)
- Delete a few entries but keep an undo window / delete in the app → Recycle Bin / restorable within 30 days, cleared automatically after
- Certain entries are no longer needed / permanently delete in the Recycle Bin / cleared immediately, unrecoverable
- Wipe everything on this device at once / uninstall the app / local study data goes with the uninstall (sign out first to clear the credential)
3. If you ever enabled iCloud sync
iCloud sync is off by default and enabled only by you. Only if you turned it on has study data synced to your own iCloud private database (solely to align your own devices). Apple hosts it under your Apple Account; that database is not operated by us, and we likewise can neither receive nor see it. To delete synced data, operate on your Apple devices and iCloud:
1. Turn off sync first: tap your avatar on any page, go to Settings → iCloud Sync, switch it off.
2. On every device that used sync, delete local data as in step 2 (in-app deletion or uninstall). Deleting entries on a device with sync still on usually propagates the deletion through the sync channel to the corresponding data in your iCloud.
3. Delete the iCloud copy: open Settings → your name at the top → iCloud, enter iCloud storage management (called "Manage Account Storage" or "Manage Storage" depending on the system). If InkBrook is listed, delete its iCloud data as prompted; the exact entry and whether the app is listed follow the actual interface. If you can't find the entry, fall back to step 2—delete in-app and let sync propagate—or email us for guidance. Apple iCloud performs this step under Apple's terms and privacy policy.
Note: uninstalling alone clears only this device's local data, not the copy already in iCloud—synced data must be deleted in iCloud separately as above. Also, if you delete data on one device but keep it on another signed in to the same Apple Account with sync on, the data may sync back. Best to turn off sync on all devices first, then clear them one by one. (Re-enabling sync later again requires confirming you are 14 or older with guardian consent, plus the paid entitlement.)
4. Deleting crash diagnostics already sent
Crash reports live on our server located in mainland China, stored by random installation identifier and not tied to your account (see Section 8 of the Privacy Policy). There are three ways to delete them:
- Use Settings → Account → Delete local data and sign out: the app first asks the server to delete every crash report under this installation identifier, then issues a new installation identifier on your device.
- If the network was unavailable and the request did not arrive, those reports on the server are still deleted automatically within at most 90 days.
- You can also email junxi@junjingxiyu.cn and ask us to delete them; because the reports are not tied to an account, we need you to confirm from this device which ones to delete, and we will tell you how once we receive your email.
You can also turn crash diagnostics off in Settings → Help Improve, after which no new reports are produced.
5. About purchases
Payment is an auto-renewing subscription collected by the Apple App Store; we never collect or store your payment details. Deleting local data or signing out never affects your subscription—it is tied to your Apple Account, and after switching or reinstalling you can recover it in-app via Restore Purchases. Subscription and refund records live with the Apple App Store, not in the app; for refunds, use Apple's channels. After expiry or cancellation, your local study data remains intact and reviewable—never deleted or locked (except batch-imported cards: their review scheduling pauses while unsubscribed, the content stays browsable in the app, and resubscribing restores it).
6. Need help
Almost all deletion can be done by you in the app or system Settings. If you hit a snag, or want to confirm everything is gone, email us: junxi@junjingxiyu.cn. We will reply within 15 business days and guide you through; but please understand that we cannot delete what lives on your device or in your iCloud on your behalf—what we can do is guide you through the steps above. Crash reports on the server can be handled as in step 4.
About minors: if the user is a child under 14, the guardian holds the rights to access, copy, correct, and delete the child's personal information, may follow the steps above to help manage it, and may contact us at junxi@junjingxiyu.cn to exercise these rights. If you believe children's information was collected without guardian consent, contact us at the same address.
Your data lives on your own device (and in your own iCloud if you enabled sync). Whether and what to delete is your call.
Contact and filing
- Developer and operator: Dalian Junjing Xiyu Technology Co., Ltd. (大连峻境溪语科技有限公司)
- Contact email: junxi@junjingxiyu.cn
- ICP filing: 辽ICP备2026012126号-2A
- Effective date: August 23, 2026
This document is a translation of the Simplified Chinese original. In case of any discrepancy, the Simplified Chinese version shall prevail.