Privacy Policy
This document applies to the Mainland China iOS App and matches the current text available in the App.
Welcome to TracePoint. This Policy applies to the Mainland China iOS App. The operator controls personal information on its servers. Data expressly processed only on the current device or in the current process cannot be remotely read by the operator.
1. Processed only on the device
Footprint IDs, titles, precise place names, categories, descriptions, coordinates, times, Lit administrative areas, on-device photos, photo-to-Footprint relationships, and companion nickname snapshots remain on the current device. Photo EXIF coordinates and capture times are read in memory only after your explicit choice. Saved JPEG files have metadata removed, and the local directory is excluded from device backup.
2. Processed on the servers
When you use Accounts, Friends, and Trips, the servers process a Mainland China phone number, account and session metadata, nickname and avatar, agreement consent, Friend code, requests, relationship categories, blocks, profile reports, Trip name and dates, members and invitations, confirmed destination names, expenses, shares, and preparation items. The servers also process push-registration metadata, account-separated anonymous daily installation activity, minimal security logs, and reliable-cleanup records. Only digests of passwords, refresh tokens, and installation credentials are stored. Verification-code text is not stored.
3. Administration access
Authenticated administrators may inspect these server records for operations, security, support, and profile-report handling, including Trip text, destination names, expense notes, shares, and checklist content. User content is read-only. The administration interface keeps only account activation or suspension and fixed profile-report actions. Responses do not expose password or token digests, installation-credential digests, verification codes, APNs device tokens, or object keys. A short-lived avatar URL is used only to render the current page. On-device Footprints, coordinates, Lit data, and photos never enter the administration interface.
4. Maps and third-party processing
Apple provides MapKit place search and reverse geocoding in Mainland China. When you browse the map, actively locate, tap a map business, save a Footprint, or actively search for a place, Apple may process necessary map requests, a current or selected coordinate, search terms, the current map region, and results. Footprint selections remain on the device. For Trips, only the finally confirmed POI name string is sent to TracePoint servers.
5. Retention, security, and rights
Server data is retained for the period needed for the feature and lawful security requirements. SMS dispatch metadata is kept for up to 24 hours, refresh tokens for up to 30 days, pending invitations for up to 7 days, minimal security logs and administrator audits for up to 6 months, and anonymous analytics for the periods in the appended details. In the App, you can manage profiles, Friends, Trips, on-device data, analytics, notifications, or delete the account. Send other access, copy, correction, deletion, restriction, objection, explanation, or complaint requests to support@suancore.com.
Local nickname and account sync
After agreeing to the Privacy Policy, you must actively enter a nickname of 1 to 30 characters before opening the main interface for the first time. The nickname and pending-sync state are stored in the App's local preferences. They are not associated with an account ID, anonymous installation ID, Footprint, or location and are never included in anonymous usage analytics. On the first sign-in, or the next sign-in after changing the nickname while signed out, the App sends the pending nickname once through the account profile API and saves it as the current account nickname. After success, the pending state is cleared and the server account profile becomes authoritative and is written back locally instead of being overwritten on every launch. Signing out or deleting an account does not remove the local nickname. Uninstalling the App or clearing App data removes it.
Anonymous usage analytics details
After you agree to the current Privacy Policy, anonymous usage analytics is enabled by default. The App processes only a random installation ID, installation credential, agreement version, document language, App version and build, a daily activity date generated by the server in China Standard Time, and a Boolean indicating whether a signed-in state appeared that day. This is used to calculate new installations, DAU, WAU, MAU, guest and signed-in activity shares, and version coverage. The installation credential stays in the App-private directory excluded from device backups, and the server stores only its digest. The random installation ID is not related to a phone number, nickname, account ID, IDFA, IDFV, APNs token, device fingerprint, or security-log IP. Analytics does not receive a client date, nickname, screen, Footprint, Lit result, location, city, map, search, photo, or free-form event. One installation is recorded idempotently for one server-generated day, and signed-in state can change only from false to true. An authenticated administrator can inspect the stored agreement version, language, registration time, last active date, and each day's App version, build, and signed-in Boolean by random installation ID. The administration interface does not expose the credential digest or associate the installation with an account, local nickname, APNs token, or security-log IP. Daily records are kept for at most 90 days; registrations that never become active for at most 7 days; other installation records are deleted after two years without activity. You can disable analytics in Privacy settings. Disabling stops reports and deletes the installation and daily records. If the network fails, the App retries only deletion and does not upload prior-day activity.