DragonSpeak Mandarin is a local-first learning app. Learning activity and voice recordings stay on your device. If you buy or restore optional content, the app creates a pseudonymous billing account and sends purchase information and limited authentication security metadata to a billing-verification service.
Information handled on your device
- Learning preferences, progress, review schedules, scores and streaks are stored locally on your device.
- If you choose a speaking exercise, the app requests microphone access. Recordings remain in the app’s temporary local storage, are not uploaded and are removed when replaced, when the recorder closes or when local learning data is cleared. Only derived practice results are kept locally.
- If you enable a reminder, its time, permission state and operating-system schedule identifier are stored locally. The app does not request a remote push token.
- The app stores local entitlement status and a non-reversible transaction fingerprint so it can avoid duplicate grants.
Purchase verification and authentication security data
Only when you start a purchase or restore purchases, the app uses Firebase Authentication to create a random anonymous user ID. It sends that ID, a pseudonymous App Account Token, product ID, signed store transaction, transaction and original-transaction IDs, purchase status, and relevant purchase, renewal, expiry or revocation dates to our Firebase/Google Cloud billing service. We use this information only to verify ownership, prevent fraud and duplicate grants, unlock or restore content, and process subscription, renewal, refund or support events.
When account deletion begins, the service creates a deletion-race fence that actively blocks writes for two hours. Its document key is an irreversible HMAC derived from the anonymous billing ID using a server-only key; it contains no raw user ID, purchase identifier or transaction data. It stores only its anti-race purpose, schema version, creation time and expiry time. After two hours it no longer blocks writes, and Firestore's asynchronous TTL process is configured to delete the expired document—typically within 24 hours after expiration.
When the anonymous billing account authenticates, Firebase Authentication processes its user-agent and IP address to provide authentication and help prevent abuse and unauthorized access. Firebase states that Authentication keeps logged IP addresses for a few weeks. Firebase Functions also processes request metadata such as the function name and IP address to operate and protect the billing service, and states that Functions retains IP addresses only temporarily. We treat this as linked Other Diagnostic Data used only for App Functionality. We do not derive a location from the IP address or use this metadata for advertising, marketing, learning analytics, personalization, or tracking.
To limit automated abuse of authenticated billing functions, our service also keeps a short-lived counter whose document key is an irreversible keyed HMAC of the anonymous billing ID and operation. The record contains no raw user ID, IP address, purchase token or transaction. It stores only its security purpose, schema version, operation name, request count, rate-limit window start and expiry. Account deletion removes these counters; otherwise Firestore TTL is configured to delete them after their 24-hour expiry.
Apple processes payments. We do not receive your Apple Account name, email address, password or payment-card information.
Sharing, linkage and tracking
Google Firebase/Google Cloud processes the anonymous billing account, verification records, and authentication security metadata on our behalf, and Apple processes App Store transactions. Purchase history and authentication security metadata are linked to the random billing user ID while the account exists. We do not use this data for advertising, marketing, learning analytics or personalization, do not sell it, and do not track you across other companies’ apps or websites. The app contains no third-party advertising SDK.
Your choices, deletion and retention
- Open Me → Settings → Delete Billing Account & Server Data to delete the anonymous Firebase account and the developer-held purchase and account records linked to it. Deletion begins immediately and is retry-safe; only the non-reversible, data-free deletion-race fence described above remains during its two-hour active period and asynchronous TTL removal so in-flight operations cannot recreate the records. Provider security logs are controlled by Firebase’s retention schedule and may remain for a few weeks; they do not contain lesson progress or voice recordings.
- Account deletion does not cancel an Apple subscription and does not delete Apple’s records. Manage or cancel subscriptions separately in App Store account settings. You may restore an eligible purchase later; doing so creates a new anonymous billing account.
- Open Me → Settings → Delete Learning Data to erase on-device learning progress, preferences, local purchase evidence and app-owned reminder schedules.
- You may also email apple72899@gmail.com with a privacy request. Because the billing account is anonymous, the in-app deletion control is the reliable way to identify and delete its linked records.
Permissions
Microphone and notification permissions are optional and requested only when you use the related feature. You can revoke them in iOS Settings.
Security and international processing
Billing requests use encrypted network connections and signed store transactions. Firebase/Google Cloud and Apple may process data in countries where they operate, subject to their service terms and privacy safeguards.
Changes and contact
If app behavior changes, this policy and the App Store privacy answers will be updated. Questions can be sent to apple72899@gmail.com.
隱私權政策摘要
DragonSpeak Mandarin 採本機優先設計。學習偏好、進度、複習排程、分數、連續學習紀錄與口說錄音都留在你的裝置上。只有在你購買或恢復選購內容時,App 才會建立隨機的匿名計費帳號,並把購買資料與有限的驗證安全中繼資料送到計費驗證服務。
- 只有在你主動錄製口說練習時才會要求麥克風權限;錄音不會上傳。
- 每日提醒使用本機通知,不會取得遠端推播 token。
- 購買或恢復時,App 會收集匿名 Firebase 使用者 ID、假名化 App Account Token、商品與 StoreKit 交易識別碼、購買狀態及購買/續訂/到期/撤銷日期,用途僅限驗證所有權、防止詐騙或重複授權、解鎖與恢復內容,以及處理續訂與退款。
- 匿名計費帳號驗證時,Firebase Authentication 會處理 user-agent 與 IP 位址,用於提供驗證並防止濫用或未授權存取;Firebase 表示登入 IP 紀錄保留數週。Firebase Functions 也會暫時處理請求 IP。這些資料在 App Store 申報為與匿名 ID 連結、僅供 App 功能使用的「其他診斷資料」。本 App 不會從 IP 推導位置,也不會將其用於廣告、行銷、學習分析、個人化或追蹤。
- 為限制已驗證計費功能的自動化濫用,服務另保存短期計數器;文件鍵是以匿名計費 ID 與操作名稱產生的不可逆 keyed HMAC,不含原始使用者 ID、IP、購買 token 或交易內容,只保存安全用途、版本、操作、請求次數、計數期間開始與到期時間。刪除帳號會移除此資料;否則 Firestore TTL 會在其 24 小時到期後非同步刪除。
- 付款由 Apple 處理;開發者不會取得你的 Apple 帳號姓名、電子郵件、密碼或付款卡資料。
- 購買資料在匿名計費帳號存在期間會與該隨機 ID 連結,但不會用於廣告、行銷、分析、販售資料或跨 App/網站追蹤。
- 你可在「我的 → 設定 → 刪除計費帳號與伺服器資料」刪除匿名 Firebase 帳號及開發者保存的關聯資料;Firebase 控制的安全紀錄仍依其保留期保存,可能留存數週,且不含課程進度或錄音。此操作不會取消 Apple 訂閱,也不會刪除 Apple 保存的交易紀錄。
- 刪除開始後,刪除競態防護標記會在兩小時內主動阻擋寫入,避免尚在執行的計費操作重建資料。標記鍵是使用伺服器專用金鑰從匿名 ID 產生的不可逆 HMAC,不含原始 ID、購買識別碼或交易內容,只保存用途、版本、建立與到期時間。兩小時後即停止阻擋,Firestore 非同步 TTL 通常會在到期後 24 小時內刪除文件。
- 你可另用「刪除學習資料」移除裝置上的學習資料、提醒與本機購買證據。
Google Firebase/Google Cloud 代表開發者處理匿名計費、購買驗證與驗證安全中繼資料,Apple 處理 App Store 交易。本 App 不含第三方廣告 SDK,也不會跨 App 或網站追蹤你。問題請寄至 apple72899@gmail.com。