清晰、克制、尊重Clear, restrained, respectful

隐私政策Privacy Policy

奇巧的大多数功能在设备本地运行。只有当你主动使用在线计分、刷新汇率、进行 App Store 购买或联系我们时,相关数据才会交由对应服务处理。 Most ChanceKit features run locally on your device. Relevant data is handled by connected services only when you choose online scoring, refresh exchange rates, make an App Store purchase, or contact us.

生效日期:2026 年 7 月 30 日 Effective: July 30, 2026

01

范围与负责人Scope and controller

本政策适用于奇巧(英文名 ChanceKit,以下简称“奇巧”“本 App”或“我们”)iOS 和 iPadOS App,以及与在线计分功能相关的网页。本 App 的开发者负责本政策所述的数据处理。This policy applies to the ChanceKit iOS and iPadOS app and the web page used for its online scoring feature. The developer of ChanceKit (“ChanceKit,” “the app,” “we,” or “us”) is responsible for the processing described here.

如对本政策、你的数据或权利请求有疑问,请发送邮件至 inostarlin@gmail.comFor questions about this policy, your data, or a rights request, email inostarlin@gmail.com.

02

设备本地数据Data kept on your device

默认留在本地Local by default

随机生成、硬币、骰子、转盘、名单抽取、翻牌、彩票号码、本地计数与计分、日期计算等主要功能在设备上处理。Core features—including random generation, coins, dice, wheels, list draws, card reveals, lottery numbers, offline counters and scores, and date calculations—are processed on your device.

你输入或导入的名单、转盘选项、生成设置、历史状态和本地计分内容会保存在 App 的本地存储中。试用状态及部分安全状态会保存在系统钥匙串中。除非你主动使用下述在线功能,这些内容不会由奇巧上传到开发者服务器。Lists you enter or import, wheel options, generation settings, saved state, and offline scoring content are stored in the app’s local storage. Trial status and certain security state are stored in the system Keychain. ChanceKit does not upload this content to the developer’s server unless you actively use an online feature described below.

删除 App 或清除相关设备数据通常会移除本地内容,但系统钥匙串中的部分安全或购买恢复状态可能按照 Apple 平台行为继续存在。Deleting the app or clearing its device data generally removes local content, although some security or purchase-restoration state in the system Keychain may persist according to Apple platform behavior.

03

在线计分处理的数据Data processed for online scoring

在线计分是可选功能。使用时,本 App 会通过加密的 HTTPS 和 WebSocket 连接与我们的服务通信,以创建房间并同步参与者的操作。Online scoring is optional. When you use it, the app communicates with our service over encrypted HTTPS and WebSocket connections to create a room and synchronize participant actions.

数据Data
用途Purpose
游戏与用户内容Gameplay and user content玩家显示名称、玩家 UUID、顺序、分数、胜局、支付/转分记录与时间Player display names, player UUIDs, order, scores, wins, payment/point-transfer records, and timestamps
创建和显示房间、同步状态、执行计分规则、展示支付记录Create and display rooms, synchronize state, apply scoring rules, and show payment records
用户与设备标识符User and device identifiers随机生成的房主 ID、玩家 ID、App Attest 密钥标识、房间 ID 和认证令牌Randomly generated owner and player IDs, App Attest key identifiers, room IDs, and authentication tokens
认证合法 App 实例与房主、阻止未授权操作、防止欺诈和滥用Authenticate legitimate app instances and room owners, block unauthorized actions, and prevent fraud and abuse
诊断与网络数据Diagnostic and network dataIP 地址、请求路径、房间 ID、状态版本、连接/断开事件、错误类别和请求诊断编号IP address, request path, room ID, state revision, connection and disconnection events, error category, and request diagnostic ID
安全限流、故障排查、监控可用性、维护性能与容量Security rate limiting, troubleshooting, availability monitoring, and performance and capacity management

这些数据只用于提供、安全保护和维护在线计分功能,不用于第三方广告、开发者营销、跨 App 跟踪、用户画像或个性化推荐。请使用昵称,并避免在玩家名称中输入敏感个人信息。We use this data only to provide, secure, and maintain online scoring. We do not use it for third-party advertising, developer marketing, cross-app tracking, user profiling, or personalized recommendations. Use nicknames and avoid entering sensitive personal information as player names.

04

第三方服务与共享Service providers and sharing

我们不出售个人数据,也不与广告网络或数据经纪商共享数据。为提供特定功能,下列服务会按照各自条款处理必要信息:We do not sell personal data or share it with advertising networks or data brokers. The following services process necessary information under their own terms when providing specific features:

  • Apple StoreKit / App Store处理购买、恢复购买和 App Store 身份验证。我们不会收到你的银行卡号、App Store 密码或完整支付凭据。Handles purchases, purchase restoration, and App Store authentication. We do not receive your card number, App Store password, or full payment credentials.
  • Apple App Attest验证连接在线计分服务器的 App 实例是否合法。证明对象和加密断言用于安全和防欺诈。Validates that app instances connecting to online scoring are legitimate. Attestation objects and cryptographic assertions are used for security and fraud prevention.
  • Frankfurter API在你刷新汇率时提供公开参考汇率。请求包含固定基准货币等查询信息,网络服务通常也会接收 IP 地址。Frankfurter 说明其公开服务通过 Cloudflare 提供,Cloudflare 会为分析和安全处理基本请求信息。Provides public reference exchange rates when you refresh rates. Requests contain query details such as the selected base currency, and network services ordinarily receive an IP address. Frankfurter states that its public service uses Cloudflare, which processes basic request information for analytics and security.
  • 托管与网络基础设施Hosting and network infrastructure为在线计分提供服务器、传输、安全防护与运行日志。这些服务商仅应依照我们的指示和适用法律处理数据,并提供不低于本政策所述的保护。Provides servers, transport, security protections, and operational logs for online scoring. These providers are expected to process data only under our instructions and applicable law and to provide protections no less protective than those described here.

若法律要求、为保护用户或服务安全,或在业务重组中依法转移服务,我们可能在必要范围内披露信息,并采取适用的保护措施。We may disclose information when legally required, when necessary to protect users or service security, or as part of a lawful service transfer or reorganization, subject to applicable safeguards.

05

数据保留与删除Data retention and deletion

我们遵循数据最小化原则,仅在实现上述目的所需的最短期间内保留数据:We follow data-minimization principles and retain data only for the shortest period reasonably necessary for the purposes above:

  • 本地内容Local content保留在你的设备上,直至你在 App 中重置、清除设备数据或删除 App;钥匙串项目可能依照系统行为继续存在。Remains on your device until you reset it in the app, clear device data, or delete the app; Keychain items may persist according to system behavior.
  • 在线房间内容Online room content用于维持活动房间,不作为永久账号档案保存;当房间或服务进程失效、过期或不再需要提供同步时删除。Is held to maintain active rooms and is not designed as permanent account storage; it is removed when the room or service process ends, expires, or is no longer needed for synchronization.
  • 安全身份与证明Security identities and attestations在防止未经授权访问和维持 App Attest 信任关系所需期间保留,并在密钥轮换、失效或不再需要时删除或替换。Are retained while needed to prevent unauthorized access and maintain App Attest trust, then deleted or replaced when keys rotate, become invalid, or are no longer needed.
  • 运行与安全日志Operational and security logs仅在排查故障、保护服务、执行速率限制和满足适用法律所必需的有限期间内保留,之后删除或去标识化。具体期间根据事件严重性、安全调查与法定义务确定。Are retained for a limited period necessary to troubleshoot failures, protect the service, enforce rate limits, and meet legal obligations, then deleted or de-identified. The period is determined by incident severity, security investigations, and applicable legal duties.
  • 支持邮件Support email在解决请求、维护必要记录及履行法律义务所需期间保留。你可以请求删除不再需要的信息。Is retained while needed to resolve your request, maintain necessary records, and meet legal obligations. You may request deletion of information no longer needed.

在法律要求保留或删除在技术上暂时不可行时,我们会限制除存储和必要安全保护之外的处理,并在条件允许后删除。Where law requires retention or deletion is temporarily technically infeasible, we restrict processing to storage and necessary security protection and delete the data when permitted.

06

你的选择与权利Your choices and rights

根据所在地适用法律,你可能有权请求访问、复制、更正、删除或限制处理你的个人数据,撤回同意,或对处理提出异议。你也可以向有管辖权的数据保护机构投诉。Depending on applicable law, you may have rights to request access, a copy, correction, deletion, or restriction of your personal data, withdraw consent, or object to processing. You may also complain to a competent data protection authority.

你可以不使用在线计分或停止刷新汇率,以避免后续相关数据传输。若要提出数据请求,请通过 inostarlin@gmail.com 联系我们,并说明请求类型和可帮助定位数据的非敏感信息。请勿发送房间令牌、密码或 App Attest 密钥材料。You can avoid further related transmissions by not using online scoring or by no longer refreshing exchange rates. To make a data request, contact inostarlin@gmail.com and describe the request and non-sensitive details that may help locate the data. Do not send room tokens, passwords, or App Attest key material.

为防止未经授权的访问或删除,我们可能需要合理验证请求与你相关。由于奇巧不要求注册账号,部分匿名或短期房间数据可能无法可靠关联到你;我们会说明能够采取的措施及无法完成请求的原因。To prevent unauthorized access or deletion, we may reasonably verify that a request relates to you. Because ChanceKit does not require an account, some anonymous or short-lived room data may not be reliably attributable to you; we will explain what we can do and why a request may not be fully actionable.

07

安全、儿童、跨境与政策更新Security, children, transfers, and changes

安全措施Security measures

我们采用 HTTPS/WSS 加密传输、App Attest 请求验证、短期挑战、防重放断言、访问令牌、输入校验、连接与速率限制、日志脱敏及最小化记录等措施。任何系统都无法保证绝对安全,请勿在玩家名称或支持邮件中提交不必要的敏感信息。We use measures including HTTPS/WSS encryption, App Attest request validation, short-lived challenges, replay-resistant assertions, access tokens, input validation, connection and rate limits, log redaction, and data minimization. No system can guarantee absolute security; do not submit unnecessary sensitive information in player names or support email.

儿童隐私Children’s privacy

奇巧不是专门面向儿童设计的服务,我们不会明知而收集法律要求取得监护人同意但未取得同意的儿童个人信息。如果你认为儿童向我们提供了此类信息,请联系我们。ChanceKit is not specifically directed to children. We do not knowingly collect a child’s personal data where applicable law requires parental consent and that consent has not been obtained. Contact us if you believe a child has provided such data.

跨境处理International processing

在线服务和服务提供商可能在你所在国家或地区之外处理数据。我们会根据适用法律采取合理保护措施,并仅传输提供相关功能所必要的数据。Online services and providers may process data outside your country or region. We apply reasonable safeguards required by applicable law and transfer only what is necessary to provide the relevant feature.

政策更新Policy changes

功能、服务商或法律要求变化时,我们可能更新本政策。我们会修改生效日期;如变化重大,会通过 App、产品页面或其他适当方式提供更明显的通知。We may update this policy when features, providers, or legal requirements change. We will revise the effective date and, for material changes, provide more prominent notice through the app, product page, or another appropriate channel.

08

联系我们Contact us

隐私问题、数据请求或技术支持:Privacy questions, data requests, or technical support:

inostarlin@gmail.com