Hengcang Privacy Policy
Updated: 2026-09-29
Data we process
Hengcang records personal assets, accounts, holdings, transactions, target allocations, and review data. By default, this data is stored in a local database on your device. The app does not require registration or sign-in, create a Hengcang cloud account, or execute brokerage trades.
Network requests
When you manually refresh market data or a background sync runs, the app requests security prices, fund net asset values, and exchange rates from a dedicated FinUnity service. A request may include a security symbol, asset type, base currency, and currency pair, but does not include holding quantities, costs, account balances, or transaction details. The dedicated service connects to the data provider. Returned data may be delayed, missing, or revised, and is not investment advice.
Screenshot recognition
Only after you explicitly confirm, the selected holding screenshot is sent over HTTPS to a dedicated FinUnity server in Singapore and then forwarded to Alibaba Cloud DashScope (Qwen qwen3.7-flash) for recognition. The current dashscope.aliyuncs.com endpoint uses access and data-storage regions in mainland China (Beijing). The inference location also depends on the model's service deployment scope and is not determined by the server location alone. The international dashscope-intl.aliyuncs.com endpoint uses Singapore for access and storage. Before switching in the future, the account, model deployment scope, and availability must be checked and this policy updated. See Alibaba Cloud region information.
FinUnity processes the original image only in request memory and does not write it to server files or databases; it is released when the request ends. Structured results from anonymous installation sessions are not written to the server's user-data tables. They are kept only in a capacity-limited in-memory idempotency cache for up to 24 hours and may expire sooner due to eviction or restart. You can cancel the import; after confirmation, the data is stored on your device. A hash of the installation identifier and the client IP are used for abuse-prevention quotas, with counters kept for up to 24 hours and expired counts cleared on later requests.
Alibaba Cloud's official notice states that customer data is not used for model training and that data generated by model and application calls is retained under applicable rules. FinUnity cannot promise zero upstream retention or one universal deletion period. Upstream terms govern processing and retention. See the Alibaba Cloud Model Studio Privacy Notice and the service terms linked there. FinUnity does not use screenshots or local ledger data to train models. Before uploading, cover names, account numbers, identity numbers, and other unrelated information.
Backups, retention, and deletion
You can manually export or restore a JSON file in Backup and Restore. Exported files may contain complete financial information and are unencrypted; store them only in a trusted location. The app does not use Android automatic cloud backup. Uninstalling the app or clearing its data removes the local database.
Data sharing
Except for market-data requests you choose to make, confirmed DashScope screenshot recognition, and the system file picker, the app does not share personal investment data with advertising, analytics, or social services. The app contains no advertising SDK, sign-in SDK, or third-party analytics SDK.
Contact
Support: chongqing115@126.com. Contact email may be forwarded through Cloudflare to this inbox. Do not send passwords, recovery codes, or complete financial screenshots. Public policy: Hengcang Android Privacy Policy; Web account policy: FinUnity Web Privacy Policy. To delete local data, clear the app's data or uninstall it. The anonymous server cache expires under the limits described above.
Before release, the maintainer must publish the public policy page, verify that the configured endpoint matches this policy, and configure spending alerts. Server-side OCR_ENABLED may be enabled only after these checks are complete. Updating this document alone does not mean the policy has been published or that the release checks have passed.