Offline Cents Privacy Policy Effective Date: July 10, 2026 Introduction Offline Cents (hereinafter referred to as “the App”) prioritizes your privacy as its core design principle. The App operates fully offline with zero cloud data transmission. This Privacy Policy clearly explains how the App accesses and processes local data on your device, as well as all privacy rights you hold. This Policy applies to all users who install and use the App on iOS and Android devices. By installing and accessing the App, you acknowledge that you have fully read, understood, and agreed to all terms of this Policy. If you disagree with any provisions herein, please uninstall the App immediately and discontinue use. 1. Core Privacy Commitments 1. No Automatic Data Uploads: The App will not initiate any network requests to send your records to external servers at any time. The only optional network function is manual version check triggered solely by your active tap. All records stay locally on your device only. 2. Zero Data Sharing & Selling: We never sell, rent, share or exchange any local data stored on your device with advertisers, analytics providers, third-party service vendors or any external parties. 3. Full Data Erasure Upon Uninstallation: All local records including bills, receipt images, reports, token balances and local usage statistics will be permanently deleted once you uninstall the App. There is no cloud backup or data recovery channel available. 4. No Silent Background Collection: The App will not secretly gather irrelevant device information in the background without your explicit permission. 2. Device Permissions the App May Request The App only requests minimal permissions required to deliver core offline functions. All permission-related data remains on your device and will never be transmitted via network: Mandatory Permission: Local Storage - Purpose: Save your manually entered expense records, receipt images from OCR scanning, offline rate packages, offline consumption reports, token balance records, exported CSV files and app preference settings. - Scope: Data is confined to the App’s private sandbox folder only. The App cannot access files of other applications or system storage outside its dedicated directory. Optional Permission: Camera - Purpose: Support local OCR scanning for receipts to auto-fill expense amounts and dates. You may deny camera access at any time. If denied, the OCR function entry will be hidden entirely without affecting other App features. - Important Note: All scanned receipt images are stored exclusively within the App’s private folder. Images will not be automatically saved to your system photo gallery or uploaded online. Permissions the App Will Never Request The App will never apply for location, contact list, microphone, SMS, calendar, push notification, unrestricted photo gallery access, device unique identifiers or any other non-essential privacy permissions. No hidden permission calls run in the background. 3. Types of Local Data Stored on Your Device All data listed below is stored locally on your device only, solely visible to you, and never synchronized to any external server: 1. Expense records: Manually input or OCR-identified bill amounts, service surcharges, tax figures, expense categories, transaction dates, notes and split-bill records. Data is only used for offline calculation, offline report generation and over-budget reminders. 2. Scanned receipt images: Photos captured via camera OCR, used only for local text recognition. You may manually delete any image at any time. 3. Offline static data packages: Preloaded tax rate templates, tipping guidelines and multi-currency exchange rate packages purchased with in-app tokens. These files contain no personal user information and are only used for offline calculations. 4. In-app token records: Your token balance, purchase history and consumption logs for premium features. Records are stored locally to verify premium feature access without cloud synchronization. 5. Local usage statistics: Offline counts of feature usage such as surcharge calculation, OCR scans and report generation. These statistics remain local only and will never be sent to any external server. 6. Custom user preferences: Self-defined expense categories, monthly budget limits, default surcharge ratios and language settings, effective only on your local device. Restrictions on Local Data Usage - All locally stored data is solely used to execute the App’s offline calculation, expense tracking and budget management core functions. Data will never be used to build user profiles, deliver targeted ads or conduct external behavioral analysis. - The App contains no advertisements, promotional feeds or recommendation modules based on your spending records. 4. Limited Network Access Rules The App is fully functional without network connection at all times. There is only one optional network entry point located in the Profile page: Check for App Updates. 1. Trigger condition: A network request is initiated only if you manually tap the update button. Automatic background update detection is permanently disabled. 2. Transmitted content: The request only fetches the latest App version number and update descriptions. No personal records, device identifiers, expense data or token information will be attached to the request. 3. Termination control: You may disable your device network at any time to abort the update request without disrupting any offline App functions. No other network requests will be generated by the App under any circumstances. No local data will be transmitted out of your device. 5. Privacy Terms for Premium Token-Based Functions All premium functions operate on a one-time token consumption model with no recurring subscriptions or auto-renewals. All in-app purchases comply with official platform rules of App Store and Google Play: 1. Payment processing is fully handled by official platform payment channels. The App cannot access or store your bank card, payment account or other sensitive payment information. 2. Token balances and consumption logs are stored locally only, with no cloud synchronization. 3. All premium functions including offline rate package import, OCR receipt scanning, full report generation and CSV export run entirely on your local device. No calculation files, images or reports will be sent to third-party servers. 6. Your Full Control Over Local Data 1. Real-time viewing: You may check all local expense records on the Expense and Report pages at any time. 2. Single record deletion: Individual expense entries and corresponding receipt images can be deleted separately. 3. One-click full data wipe: A dedicated “Clear All Local Data” function is available in the App settings. Executing this action permanently deletes all bills, images, reports and token logs with no recovery option. 4. Local CSV export: You may export full expense records as CSV files saved locally on your device. The App will not retain any copies of exported files. 5. Permission revocation: You may disable camera or storage permissions via your device system settings at any time. Disabling permissions only turns off related functions without impacting other core features. 6. Complete erasure via uninstallation: Uninstalling the App automatically destroys all local stored data with no residual cache or hidden backups. 7. Local Data Security Measures 1. Local expense records, token logs and reports are encrypted locally to prevent unauthorized direct access via device file explorers. 2. Receipt images from OCR scans are isolated in the App’s private sandbox and cannot be accessed by the system gallery or other third-party applications. 3. No persistent background processes run to read or modify local data when the App is minimized, reducing data leakage risks. 4. The App has no built-in file sharing or wireless transmission functions to send local records externally. 8. Minors Usage The App is a neutral offline expense tracking tool with no functions designed exclusively for minors. We do not actively collect any information from minors. If you are under 18 years old, please read this Policy with your guardian’s guidance and obtain guardian consent before using the App. Guardians may uninstall the App to fully erase all minor-related local records at any time. 9. Policy Updates 1. If core privacy rules or App functions are adjusted, a pop-up window displaying the updated Privacy Policy will appear upon launching the new App version. You must manually confirm acceptance to continue using the App. 2. All policy revisions will only optimize local storage and permission rules. No new clauses enabling cloud upload or third-party data sharing will be added. 3. Historical versions of this Privacy Policy can be viewed offline within the Help & Privacy section in the App. 10. Contact If you have inquiries regarding this Privacy Policy, local data storage or permission usage, you may contact the developer via official app store message channels. All consultations are processed without requiring you to upload any personal data for verification. 11. Disclaimer 1. The App shall not be liable for data leakage caused by you voluntarily sharing your device with others, device loss, or manually exporting and distributing CSV record files to third parties. 2. Data leakage resulting from jailbroken, rooted devices or third-party tools forcibly accessing the App’s private folder is outside the scope of the App’s security protection. 3. Offline exchange rate packages are static version-locked data without real-time network updates. Calculation deviations caused by market exchange rate fluctuations are not deemed privacy security issues.