FinUnity Web Privacy Policy

Updated: 2026-09-29. For the Android local ledger, see the Hengcang Android Privacy Policy.

Data we process

Registration collects a username, optional display name, password hash, and recovery-code hash; an email address is not required. Existing email accounts retain their email address for compatible sign-in during migration. Passwords and recovery codes are not stored in plain text. We store the accounts, holdings, transactions, sources, import records, settings, and structured results from screenshot recognition that you enter or submit. Session tokens are used for authentication. The browser stores tokens, language, and theme preferences in sessionStorage and localStorage.

Screenshot recognition and processing regions

Only after you submit an image, it is sent over HTTPS to the FinUnity server in Singapore and then forwarded to Alibaba Cloud DashScope (Qwen qwen3.7-flash) for recognition. The current China-site endpoint, dashscope.aliyuncs.com, uses access and data-storage regions in mainland China (Beijing). The inference location also depends on the model's service deployment scope and is not determined solely by the server location. The international endpoint, dashscope-intl.aliyuncs.com, uses Singapore for access and storage. Before any future switch, we will check the account and model deployment scope and update this policy. See Alibaba Cloud region information.

The original image is processed in FinUnity request memory, is not written to server files or databases, and is released when the request ends. You must review and confirm the structured results before they are imported as holdings. Before uploading, cover names, account numbers, identity numbers, and other information that is not needed for recognition.

Alibaba Cloud's official privacy notice states that customer data is not used to train models and explains that data generated by model and application calls is retained under applicable rules. We cannot promise zero retention by upstream providers or confirm one universal upstream deletion period. Their terms govern upstream processing and retention. See the Alibaba Cloud Model Studio Privacy Notice and the service terms linked there. FinUnity does not use screenshots or ledger data to train models.

Retention and deletion

Ledger data, settings, and registered users' structured OCR results are retained while the account exists. Archiving hides a record from normal lists but keeps it in the database for audit; archiving is not physical deletion. You can enter your password again in Settings to delete your account. Deletion immediately removes the account and all business data, including archived data, from the current business database and revokes sessions. The username can then be registered again. You can export accounts, holdings, and transactions as JSON while the account exists.

Idempotency cache entries are kept for up to 24 hours and subject to a capacity limit, so they may expire sooner due to eviction or restart. Abuse-prevention counters store IP addresses, installation-identifier hashes, and counts; they are normally cleared when the relevant window ends, up to 24 hours. Login-failure records older than 24 hours are cleared during a later authentication request. The deployment plan requires business backups to be kept for no more than 14 days, with rotation performed by the maintainer. Account deletion does not automatically change offline backups; contact the maintainer to request deletion of a backup copy.

Third parties and contact

Other than Alibaba Cloud DashScope for screenshot recognition, we do not sell or share your financial data with advertising, social, or analytics platforms. Send feedback or deletion requests to chongqing115@126.com. Contact email may be forwarded through Cloudflare to this inbox. Do not include passwords, recovery codes, or complete financial screenshots in email.

Terms of Use