
Bullion Note · 贵金属手账
隐私政策 · 更新于 2026-08-07
本地优先
Bullion Note 是贵金属账本与生活账本工具。默认情况下,核心账本数据保存在当前设备的应用沙盒内,使用记账与估值功能不需要注册或登录。
本地数据包括:贵金属账本中的品类、金属、克重、纯度、成本与备注;生活账本中的账本名称、收支金额、分类、日期、时区与备注;以及显示、市场、币种、单位和其他应用设置。生活账本显示的黄金克重按行情重新计算,不作为交易原始金额的替代。
可选账号与提醒
你可以选择使用 Google 或 Apple 登录。登录后,Cloudflare 托管的 Worker / D1 会保存运行账号所需的信息,包括邮箱、显示名称、第三方登录提供方用户 ID、会话记录,以及你启用提醒时产生的设备令牌、提醒规则与偏好。名为 bullionnote_session 的会话 Cookie 有效期约 30 天。Cloudflare 基础设施也会处理完成网络请求所需的网络信息。
退出登录不会清除设备本地账本。账号删除会移除服务器端账号标识、会话、设备令牌、提醒规则与偏好;关联安全审计记录会去标识化。出于安全、防滥用和数据完整性目的,可能保留匿名删除事件与账号删除占位记录。详情见删除账号说明。
行情与备份
行情通过 Bullion Note 的服务器代理获取。报价请求会包含完成请求所需的市场、币种、单位与网络信息,但不会附带你的贵金属持仓或生活收支明细。
只有你主动导出时,应用才会生成 bullion-note-backup.json。备份可包含贵金属账本、生活账本、分类、提醒和设置,并交给系统分享面板,由你选择保存或发送位置。导出后,文件的保管与接收方处理受你所选位置或服务的规则约束。
用途、保留与选择
我们使用上述数据来提供登录、会话、行情、提醒、备份和支持功能,维护服务安全,并解决故障。Bullion Note 不展示广告,不出售个人数据,也不将个人数据用于跨服务广告跟踪。
设备本地数据保留到你在应用或系统中清除数据、或卸载应用为止。账号运营数据保留到账号删除或不再为上述用途所需为止,但法律、安全与防滥用所需的去标识化记录可能继续保留。
你可以在应用内查看账号状态、导出本地备份、退出登录或删除账号。无法使用应用时,可发送邮件至 hi@incosmos.art 请求访问、更正或删除账号数据。
政策更新与联系
我们可能随产品与法律要求更新本政策,并在此页面标注更新时间;重大变更会通过适当的产品内方式提示。
运营方:InCosmos KK(在宇株式会社,日本)。隐私问题请联系 hi@incosmos.art。
Local-first by default
Bullion Note is a precious-metal ledger and everyday-money ledger. Core ledger data stays in the app sandbox on your current device by default. You do not need an account to use recording and valuation features.
Local data includes the category, metal, weight, purity, cost, and note in your metal ledger; ledger name, income or expense amount, category, date, time zone, and note in your life ledger; and display, market, currency, unit, and other app settings. Gold-gram values shown for life-ledger entries are recalculated from market prices and do not replace the original cash amounts.
Optional account and alerts
You may choose Google or Apple sign-in. After sign-in, a Cloudflare-hosted Worker / D1 stores data needed to operate the account: email address, display name, provider user ID, session records, and—if you enable alerts—device tokens, alert rules, and preferences. The bullionnote_session cookie lasts about 30 days. Cloudflare infrastructure also processes network information needed to complete requests.
Signing out does not clear local ledgers. Deleting an account removes server-side account identifiers, sessions, device tokens, alert rules, and preferences; related security audit records are de-identified. An anonymous deletion event and account deletion tombstone may be retained for security, abuse prevention, and data integrity. See Delete Account for details.
Quotes and backup export
Market quotes are fetched through Bullion Note's server proxy. Quote requests include the market, currency, unit, and network information needed to complete the request, but do not include your metal holdings or life-ledger entries.
The app creates bullion-note-backup.json only when you choose to export. A backup may include metal ledgers, life ledgers, categories, alerts, and settings. It is handed to the system share sheet so you choose where to save or send it. After export, the selected destination or service governs how the file is kept and processed.
Use, retention, and your choices
We use the data above to provide sign-in, sessions, quotes, alerts, backup, and support; to secure the service; and to troubleshoot issues. Bullion Note does not display ads, sell personal data, or use personal data for cross-service advertising tracking.
Local data remains until you clear it in the app or system, or uninstall the app. Account-operation data remains until account deletion or until it is no longer needed for the purposes above. De-identified records may be retained where needed for legal, security, or abuse-prevention purposes.
In the app, you can review account status, export a local backup, sign out, or delete the account. If you cannot use the app, email hi@incosmos.art to request access, correction, or deletion of account data.
Updates and contact
We may update this policy as the product or legal requirements change. The revision date appears on this page, and material changes will be communicated through an appropriate in-product notice.
Operator: InCosmos KK, Japan. For privacy questions, contact hi@incosmos.art.
ローカルファースト
Bullion Note は、貴金属台帳と暮らしのお金の台帳です。主要な台帳データは、標準では現在の端末のアプリ領域に保存されます。記録と評価機能の利用にアカウントは必要ありません。
端末内データには、貴金属台帳のカテゴリ・金属・重量・純度・取得コスト・メモ、暮らしの台帳の台帳名・収支金額・カテゴリ・日付・タイムゾーン・メモ、表示・市場・通貨・単位などの設定が含まれます。暮らしの台帳に表示される金グラムは相場から再計算され、元の金額を置き換えるものではありません。
任意のアカウントとアラート
Google または Apple でのログインは任意です。ログイン後、Cloudflare 上の Worker / D1 は、メールアドレス、表示名、プロバイダーのユーザー ID、セッション、およびアラート利用時の端末トークン・規則・設定を保存します。bullionnote_session Cookie の有効期間は約 30 日です。Cloudflare の基盤は、リクエスト処理に必要なネットワーク情報も扱います。
ログアウトしても端末内の台帳は消えません。アカウント削除では、サーバー側の識別子、セッション、端末トークン、アラート規則と設定を削除し、関連するセキュリティ監査記録を匿名化します。セキュリティ、不正利用防止、データ整合性のため、匿名の削除イベントと削除済み記録(tombstone)が保持される場合があります。詳しくはアカウント削除をご覧ください。
相場とバックアップ
相場は Bullion Note のサーバープロキシを通じて取得します。リクエストには必要な市場・通貨・単位・ネットワーク情報が含まれますが、貴金属の保有明細や暮らしの収支明細は含まれません。
bullion-note-backup.json は、ユーザーが書き出しを選んだ場合にのみ作成されます。貴金属台帳、暮らしの台帳、カテゴリ、アラート、設定が含まれる場合があり、システム共有画面から保存・送信先を選びます。書き出し後は、選択した保存先またはサービスの規則に従って処理されます。
利用目的・保持・選択肢
上記データは、ログイン、セッション、相場、アラート、バックアップ、サポート、サービス保護、障害対応のために利用します。Bullion Note は広告を表示せず、個人データを販売せず、サービス横断の広告トラッキングに利用しません。
端末内データは、アプリやシステムで消去するか、アプリをアンインストールするまで残ります。アカウント運用データは、アカウント削除または上記目的に不要となるまで保持します。法令、セキュリティ、不正利用防止に必要な匿名化済み記録は保持される場合があります。
アプリ内でアカウント状態の確認、バックアップ書き出し、ログアウト、アカウント削除ができます。アプリを利用できない場合は、hi@incosmos.art へアクセス・訂正・削除を申請してください。
更新と連絡先
製品や法的要件の変更に応じて本ポリシーを更新する場合があります。更新日はこのページに表示し、重要な変更は適切なアプリ内方法でお知らせします。
運営者:InCosmos KK(在宇株式会社、日本)。お問い合わせ:hi@incosmos.art