TracePoint
简体中文English繁體中文日本語

Personal Information Collection List

This document applies to the Mainland China iOS App and matches the current text available in the App.

OPERATOR
Beijing Suanshu Technology Co., Ltd.
Document version
1.0
Updated and effective
August 29, 2026

I. Processed only on the current device or in the current process

Footprint text, precise place names, coordinates, administrative areas, Lit results, on-device photos, photo relationships, and companion nickname snapshots remain on the current device. Map viewports, search terms, addresses, unselected POIs, POI details, and result lists are used temporarily only on the current page.

II. Processed on the operator's servers

  1. Accounts and sessions: user ID, Mainland China phone number, password and refresh-token digests, role, status, agreement version, language, consent, and session times.
  2. Profiles and Friends: nickname, metadata-free avatar, Friend code, requests, Friend relationships, your private relationship categories, blocks, profile reports, and short-lived rate-limit records.
  3. Private Trips: Trip ID, name, dates, members, and invitations; confirmed destination names; CNY integer-cent expenses, fixed category, optional note, payer, visibility, and shares; preparation-item text, completion status, and related times.
  4. Operations and security: SMS purpose and dispatch status, APNs registration metadata, account-separated anonymous installations and daily activity, source IP, request time, route, status code, necessary error type, reliable deletion jobs, database migrations, and administrator audits.

III. Administration display

Administrators can inspect these server business and operations records, including Friend and Trip content, but the interface does not expose password or token digests, installation-credential digests, verification codes, APNs device tokens, or object keys. Avatars may be rendered through a non-persisted short-lived URL. The administration interface does not read or trigger upload of on-device Footprints, location, Lit data, or photos.

Local nickname and account sync

After agreeing to the Privacy Policy, you must actively enter a nickname of 1 to 30 characters before opening the main interface for the first time. The nickname and pending-sync state are stored in the App's local preferences. They are not associated with an account ID, anonymous installation ID, Footprint, or location and are never included in anonymous usage analytics. On the first sign-in, or the next sign-in after changing the nickname while signed out, the App sends the pending nickname once through the account profile API and saves it as the current account nickname. After success, the pending state is cleared and the server account profile becomes authoritative and is written back locally instead of being overwritten on every launch. Signing out or deleting an account does not remove the local nickname. Uninstalling the App or clearing App data removes it.

Anonymous usage analytics details

After you agree to the current Privacy Policy, anonymous usage analytics is enabled by default. The App processes only a random installation ID, installation credential, agreement version, document language, App version and build, a daily activity date generated by the server in China Standard Time, and a Boolean indicating whether a signed-in state appeared that day. This is used to calculate new installations, DAU, WAU, MAU, guest and signed-in activity shares, and version coverage. The installation credential stays in the App-private directory excluded from device backups, and the server stores only its digest. The random installation ID is not related to a phone number, nickname, account ID, IDFA, IDFV, APNs token, device fingerprint, or security-log IP. Analytics does not receive a client date, nickname, screen, Footprint, Lit result, location, city, map, search, photo, or free-form event. One installation is recorded idempotently for one server-generated day, and signed-in state can change only from false to true. An authenticated administrator can inspect the stored agreement version, language, registration time, last active date, and each day's App version, build, and signed-in Boolean by random installation ID. The administration interface does not expose the credential digest or associate the installation with an account, local nickname, APNs token, or security-log IP. Daily records are kept for at most 90 days; registrations that never become active for at most 7 days; other installation records are deleted after two years without activity. You can disable analytics in Privacy settings. Disabling stops reports and deletes the installation and daily records. If the network fails, the App retries only deletion and does not upload prior-day activity.

support@suancore.comSUAN CORE京ICP备2026046759号-1京公网安备11011402056917号