Side Path · Privacy Policy
Side Path (the "App") is developed and operated by Shenzhen Poke Cloud Technology Co., Ltd. (深圳市破壳云科技有限公司) ("we", "us"). We take your personal information and privacy seriously. This policy explains what we collect, how we use it, where it is stored, and how we protect it.
1. Information we collect
1.1 Data you enter yourself (stored locally by default)
- Primary-job and side-hustle income records (amount, date, category, note, and so on)
- App settings (financial-freedom goal, category list, theme preference, privacy toggle, and so on)
- Achievement unlock records
This data is stored locally on your device by default and is not uploaded merely because you sign in. Only when you actively use "Export backup" is a backup transmitted over HTTPS and relayed through our server. The backup is stored as ciphertext; devices signed in to the same account can scan and read it repeatedly with no automatic expiry until you export again (which replaces it with a new one) or delete your account (which erases it).
1.2 Optional sign-in and account profile
Signing in is optional — the App keeps full local bookkeeping without an account. Depending on the installation source, build and device capabilities, the App may show Google, WeChat, or both sign-in methods. The Google Play version offers both Google and WeChat sign-in.
- Google Sign-In. When you tap "Sign in with Google", Google Identity Services (Credential Manager) asks you to choose an account and returns a signed ID token, which the App sends to our server over HTTPS for verification. From that token we store your Google account identifier (the
subclaim), email address and verification status, display name and profile-picture URL. We do not retain the token itself long-term; only its hash and expiry time are stored to prevent replay, and expired records are periodically removed. - WeChat sign-in. When you tap "Sign in with WeChat", we obtain and store on our server via the WeChat Open Platform: your WeChat identifier (openid, and unionid where available), your WeChat nickname and avatar.
In either case we also store an internal user ID generated by the App, the registration and update time, the last sign-in time, the sign-in count, the default currency derived from your device region, the distribution channel, and the installationId randomly generated by this installation. These fields identify the account, initialize its currency, maintain sessions and enforce the limit of 3 simultaneously signed-in installations. Sign-in does not upload the device brand, model, OS version or App package name, and the App does not provide device-management features. You can change your display name after signing in; beyond the 3-installation limit, the least recently active installation is signed out automatically.
To understand overall usage, the App reports anonymously once per launch: a hash of this installation's random identifier, the install source of this App (that is, which app store you installed it from — for example Google Play or a device-vendor store; recorded as "unknown" when unavailable), and the App version. The install source is used only to distinguish usage across distribution channels, and the version number only to understand the share of each version in use. We do not read the list of other apps installed on your device. Our server aggregates these reports by day into launch counts and device counts only, with no link to your account, and keeps no per-event detail past the day.
This information is used only to identify your account, display your profile, keep sign-in secure, and lay the account groundwork for cloud sync that you may choose to enable in future. We do not use hardware identifiers such as IMEI or Android ID as account identifiers.
1.3 Device and runtime information (for core functionality)
- Screen and status-bar dimensions, read to lay out the interface correctly
- Camera permission, requested when you import a backup; we only decode QR codes generated by this App, and neither store nor upload the camera image
- A short vibration may be triggered as haptic feedback on some buttons (where the device supports it)
- If the App hits a program error, it reports the error details plus the device brand, model, OS version, vendor UI version and App version, solely for troubleshooting. This never includes your bookkeeping data.
1.4 Suggestions and feedback (when you submit them)
When you submit something through "Me → Suggestions & Feedback", we store on our server the feedback type, the message body, the email address you provide, plus the submission time, App version, interface language, and the device brand, model, OS version and vendor UI version (so we can reproduce the issue on the same kind of device). The email address is required, and is used only to reply to that piece of feedback. You may also submit while signed out, in which case the item is marked "not signed in". When you are signed in, the internal user ID is attached so we can locate the problem you reported. Submitting feedback does not upload your bookkeeping data. Feedback is used only to improve the product and to reply to you, and we delete it from our admin console once handled.
1.5 DCloud uni-app engine
This product is built on DCloud uni-app (5+ App). While the App runs, the DCloud engine may collect device identifiers (IMEI / Android ID / DEVICE_ID, OAID and similar), SIM IMSI information, app launch data and exception logs, for statistical analysis and to improve performance and user experience. We have disabled uni statistics (uniStatistics) in the App manifest, but the engine may still produce the operational logs it requires. See the DCloud App engine privacy policy for details.
2. How we use information
- Compute your replacement rate, trend charts and achievement progress on your device, and display them to you
- Relay an encrypted backup at your request, and restore it on the receiving device
- Complete Google or WeChat authentication when you choose to sign in, store and display your account profile, and maintain multi-device sessions
- Read the suggestions and feedback you submit, to improve the product, and reply to that feedback at the email address you provided
- We do not use personal information for advertising, profiling, or sale to third parties
3. Permissions
The core features of this App work without a network connection. The Android package declares the following system permissions:
- Local storage: saves your records and settings (in the app-private directory; no additional sensitive permission required)
- Camera (CAMERA): only when you tap to scan a backup QR code; the camera image is not stored
- Vibration (VIBRATE): haptic feedback on some interactions
- Network (INTERNET / ACCESS_NETWORK_STATE): for the policy pages, Google/WeChat sign-in, account sessions, and the encrypted backup transfer you initiate
- Photos / images: only when you choose to save a share image
- Notifications (POST_NOTIFICATIONS): requested only when you turn on "Settings → Notification shortcut", to keep one quick-entry notification in the shade. It is never used for marketing or advertising.
This App does not use location, microphone, contacts, SMS, or phone-state permissions.
4. Storage and deletion
- Bookkeeping data is stored locally on your phone; uninstalling the App clears it
- You can export a backup or erase all data under "Me → Data & Backup"
- Transfer backups are stored encrypted with AES-256-GCM and can be scanned repeatedly by devices on the same account. Only the most recent backup per account is kept; the ciphertext is deleted when you export again or delete your account
- Account profiles are stored on our servers. Signing out revokes only the current device; deleting your account erases the server-side account profile, avatar, sign-in identity index, all sessions, and any transfer backup
- Deleting your account does not erase the bookkeeping data on your phone — you can keep using the App signed out
- Suggestions and feedback submitted while signed in are linked to the internal user ID and are deleted with the account. Feedback submitted while signed out is not linked to an account; contact us using the details below if you want a specific item and its email address removed
- Security event logs record only a request ID, event type, timestamp and an anonymized account digest, and are retained for 30 days by default
Our servers are located in the Chinese mainland. If you use the App from outside that region, the account, feedback and transfer-backup data described above is transferred to and processed there.
5. Third-party SDKs
This App uses the DCloud uni-app runtime, and integrates Google Identity Services (Credential Manager) and the Tencent WeChat Open SDK for the optional sign-in feature. The App only invokes a sign-in provider when you actively tap to sign in or to delete your account. See the in-app "Third-Party Data Sharing List" for exactly what is shared.
6. Children
This App is intended for adults. If you are a minor, please use it under the guidance of a guardian, and have your guardian read this policy.
7. Your rights
You can access and correct your account profile in the App, export or erase your local data at any time, and delete your server-side account from "Me → Account". For any other request concerning your personal information — including access, correction, deletion or a copy of it — contact us at the address below and we will respond within a reasonable period.
8. Updates to this policy
We may revise this policy from time to time. Updated versions will be published in the App or through our release channels. For material changes we will ask for your consent again.
9. Contact us
Operator: Shenzhen Poke Cloud Technology Co., Ltd. (深圳市破壳云科技有限公司). For questions, comments or complaints about this policy, email yangwang1919@gmail.com. We will reply within a reasonable period.