Digital Wallet (数字卡包, "the App") is provided independently by the developer. This privacy policy explains how the App collects, uses, stores, and protects your information. Please read it carefully before use; by starting to use the App you are agreeing to everything in it.
1.Our Core Commitment
No uploads. No account. No tracking.
The App is a fully local document and file management tool. We do not collect, upload, or share any user data. All of your document fields, photos, attachments, and backup files are encrypted and kept on your own device; the developer cannot and will not access them.
2.Information We Collect
Category
Collected?
Notes
Document fields (name, number, expiry, etc.)
Not collected
Encrypted and stored on the device only
Document photos / attachments
Not collected
Written to the on-device Vault after encryption
Notes, owner, tags
Not collected
As above
Device information (model, OS version)
Not collected
Never read, never reported
Usage behaviour (taps, time on screen)
Not collected
No instrumentation, no analytics
Location
Not collected
Location capability is not used at all
Contacts
Not collected
Not touched in any way
There is no scenario in which this App needs the internet to handle your data. If you ever observe an undeclared network request, please tell us through the contact details at the end so we can verify it.
3.What Each Permission Is Used For
System permission
Purpose
Required?
Camera
Capture photos of documents
No (you may import from the photo library instead)
Photo library
Import existing photos
No (you may use the camera directly instead)
Files
Import contracts / PDF / Word / Excel and other attachments
No
Local notifications
Expiry reminders
No (disabling it only removes reminders)
Face ID / Touch ID
App-lock verification
No (a pattern or numeric passcode also works)
System Keychain
Store the master key and app-lock credential digests
System-level; the App cannot bypass it
Every permission request shows the standard iOS system prompt. You can revoke any of them at any time under "Settings → Digital Wallet"; doing so disables only that feature and leaves the rest working.
4.Data Storage and Encryption
Encryption: document fields, photo file names, and attachment metadata are encrypted with AES-256-GCM before being written to disk — only ciphertext ever reaches storage.
Master key: held in the iOS system Keychain with device-level protection enabled (this device only, reachable via an encrypted backup).
App-lock credentials: pattern and numeric passcodes are written to the Keychain as SHA-256 digests only; plaintext and pattern details are never stored.
File protection: the photo and attachment directories use FileProtectionType.complete, so they cannot be read while the device is locked.
Destroying data: deleting a document cascades to all of its photo and attachment ciphertext; "Erase all data" resets the encryption key and wipes every local record, irreversibly.
5.Data Retention and Deletion
Retention period: your data is kept until you delete it.
Uninstalling the App: removing the App from the Home screen triggers system-level data destruction, including this App's Keychain items.
Erase all data: Settings → Data → Erase all data resets the encryption key and removes all documents, photos, attachments, reminders, and backup records.
Individual deletion: deleting one document from the top-right of its detail page cascades to its photo and attachment ciphertext.
6.Backup and Restore
The App offers passphrase-encrypted backups:
You can manually export a passphrase-encrypted .dwallet backup file to a directory you choose (for example the Files App).
Importing requires the correct passphrase; a wrong passphrase or a corrupt file is rejected with a message.
Import overwrites all current data by default, and a strong confirmation dialog appears first.
Backup files use a key derived with PBKDF2-HMAC-SHA256 (200,000 iterations) plus AES-256-GCM encryption.
⚠️ We cannot recover your passphrase. Only you hold it; if it is lost, the backup file cannot be restored.
7.Third-Party Services
The App integrates no third-party SDKs whatsoever, and contains none of the following:
any form of analytics (Firebase, Umeng, Bugly, and similar);
any form of crash reporting (Crashlytics, Bugsnag, and similar);
any advertising SDK;
any social sharing or third-party sign-in.
All dependencies are official Apple frameworks: Foundation, UIKit, CoreData, LocalAuthentication, UserNotifications, CryptoKit, PDFKit, Photos, PhotosUI, and Vision (on-device recognition, only when you enable it).
8.Children and Minors
The App is designed for adult users with full civil capacity. Minors under 14 should use it only under a guardian's supervision, and users aged 14 to 18 should use it only with their legal guardian's consent.
The developer does not knowingly collect information from minors and does not provide any service to minors through this App.
9.Changes to This Policy
If this policy changes, we will notify you in advance through:
an in-App first-launch dialog or an announcement on the Settings screen;
the App Store release notes, summarising what changed;
a fresh confirmation from you for material changes.
Continuing to use the App means you accept the revised policy.
10.Governing Law and Dispute Resolution
The interpretation, validity, and dispute resolution of this policy are governed by the laws of the People's Republic of China. In the event of a dispute both sides shall first attempt friendly negotiation; failing that, the matter shall be brought before the competent people's court at the developer's place of business.
11.Contact Us
Questions, comments, and complaints about this policy can be sent to: