1. Giới thiệu
Chính sách này giải thích cách PX Apps (sau đây gọi là “chúng tôi”) xử lý thông tin khi bạn sử dụng ứng dụng và Landing Page Sổ Tiền Hôm Nay. Chúng tôi thiết kế ứng dụng theo nguyên tắc offline-first, giảm tối đa việc thu thập dữ liệu và để người dùng kiểm soát sổ tiền trên thiết bị của mình.
2. Phạm vi áp dụng
Chính sách áp dụng cho ứng dụng Sổ Tiền Hôm Nay trên iOS, Android, Landing Page chính thức và các yêu cầu hỗ trợ gửi trực tiếp cho chúng tôi. Dịch vụ của Apple, Google hoặc trang bên thứ ba được điều chỉnh bởi chính sách riêng của họ.
Mục 5 (dữ liệu sử dụng và báo cáo sự cố) áp dụng cho các phiên bản ứng dụng có tính năng này, trên cả Android lẫn iOS.
3. Dữ liệu bạn tạo trong ứng dụng
Tùy cách sử dụng, bạn có thể nhập số tiền, loại giao dịch, ngày giờ, ghi chú, danh mục, tên người nợ hoặc người được trả, trạng thái khoản nợ và thiết lập hiển thị. Đây có thể là dữ liệu cá nhân hoặc dữ liệu tài chính riêng tư của bạn.
Các dữ liệu này được xử lý cục bộ để:
- Lưu và hiển thị sổ thu, chi và nợ.
- Tính tổng và tạo báo cáo theo khoảng thời gian.
- Cho phép tìm, sửa, xóa hoặc quản lý giao dịch.
- Ghi nhớ danh mục, nghề mẫu và thiết lập trên thiết bị.
4. Dữ liệu chúng tôi không thu thập từ sổ tiền
Ở mọi phiên bản hiện tại:
- Không yêu cầu tạo tài khoản hoặc đăng nhập.
- Không gửi nội dung sổ thu, chi, nợ lên máy chủ của chúng tôi.
- Không bán hoặc cho thuê dữ liệu cá nhân.
- Không dùng nội dung sổ tiền để quảng cáo hoặc lập hồ sơ người dùng.
- Không truy cập tài khoản ngân hàng và không thực hiện giao dịch chuyển tiền.
5. Dữ liệu sử dụng và báo cáo sự cố (tùy chọn — mặc định TẮT)
Sổ Tiền Hôm Nay hoạt động theo mô hình offline-first. Toàn bộ nội dung sổ tiền của bạn — số tiền thu, số tiền chi, tên người, ghi chú, danh mục, các khoản nợ — được lưu và mã hoá ngay trên thiết bị của bạn. Chúng tôi không vận hành máy chủ nhận nội dung sổ tiền của bạn.
Hai lựa chọn riêng, mặc định đều TẮT. Ứng dụng chỉ gửi một lượng dữ liệu kỹ thuật tối thiểu khi bạn đồng ý:
- Gửi dữ liệu sử dụng để cải thiện ứng dụng — mặc định TẮT, bật/tắt bất cứ lúc nào trong Cài đặt.
- Gửi báo cáo sự cố kỹ thuật — mặc định TẮT, bật/tắt bất cứ lúc nào trong Cài đặt.
Hai lựa chọn hoàn toàn độc lập: bạn có thể bật cái này mà không bật cái kia. Nếu bạn không đồng ý, ứng dụng vẫn dùng được đầy đủ — không tính năng nào bị khoá. Lựa chọn của bạn được lưu ngay trên máy, không cần tài khoản, không gửi lên máy chủ, không đồng bộ đám mây.
5.1. Nếu bạn bật “dữ liệu sử dụng”, chúng tôi có thể nhận
- Loại thao tác trong ứng dụng, dưới dạng tên sự kiện kỹ thuật (ví dụ: “đã tạo bản ghi đầu tiên”, “đã mở màn Báo cáo”).
- Loại bản ghi (thu / chi / phải thu / phải trả) — chỉ là phân loại, không phải nội dung.
- Mã mẫu sổ đang dùng (mã chuẩn hoá, không phải tên bạn tự đặt).
- Phiên bản ứng dụng, nền tảng, số thứ tự và thời điểm kỹ thuật.
- Do dịch vụ của Google tự ghi nhận: một mã cài đặt ngẫu nhiên (app-instance / installation identifier); trên iOS còn có mã thiết bị cấp nhà phát hành (identifier for vendor — không phải mã quảng cáo); thông tin thiết bị (model, hãng, phiên bản hệ điều hành, ngôn ngữ); dữ liệu phiên hoạt động và mức độ tương tác; khu vực địa lý gần đúng mà Google suy ra từ địa chỉ IP; và thông tin về giao dịch mua gói Premium.
Về thông tin mua gói Premium: khi bạn mua gói Premium, Google Analytics có thể tự ghi nhận thông tin về giao dịch đó, gồm mã sản phẩm, tên sản phẩm, giá, loại tiền tệ và số lượng của gói Premium. Đây là thông tin về gói Premium của ứng dụng — không phải số tiền hay nội dung nào trong sổ tiền của bạn.
5.2. Nếu bạn bật “báo cáo sự cố”, chúng tôi có thể nhận
Thông tin kỹ thuật về lỗi: vết gọi hàm (stack trace) trong mã ứng dụng, mã lỗi đã chuẩn hoá, phiên bản ứng dụng và hệ điều hành, loại thiết bị, một mã cài đặt kỹ thuật, và trạng thái kỹ thuật liên quan tới lỗi.
5.3. Chúng tôi KHÔNG nhận nội dung sổ tiền của bạn
PX Apps không gửi tới Firebase Analytics/Crashlytics: số tiền thu/chi trong sổ · giá trị các khoản nợ · giá trị giao dịch bạn ghi · tên người · tên khách hàng · người nợ hoặc chủ nợ · ghi chú · nội dung sổ · bản sao lưu · file bạn xuất ra · số điện thoại · email bạn nhập trong sổ · danh bạ · vị trí chính xác · mã quảng cáo (Advertising ID / IDFA).
Ứng dụng cũng không gửi biên lai (receipt), mã giao dịch mua (purchase token) hay mã đơn hàng (order ID) tới Firebase, và không lưu các dữ liệu đó trên máy chủ của PX Apps.
5.4. Mục đích sử dụng và những việc chúng tôi KHÔNG làm
Mục đích: phân tích sản phẩm để cải thiện ứng dụng; khắc phục sự cố khi bạn bật báo cáo lỗi; đo lường hiệu quả các chiến dịch giới thiệu ứng dụng (attribution và campaign measurement) thông qua liên kết với Google Ads.
- Không quảng cáo cá nhân hoá (personalized advertising).
- Không tạo tệp đối tượng remarketing.
- Không chia sẻ tệp đối tượng (audience sharing).
- Không dùng mã quảng cáo (Advertising ID / IDFA): bản Android đã gỡ hẳn quyền này; bản iOS dùng cấu hình Analytics không hỗ trợ IDFA và không tích hợp AdSupport hay App Tracking Transparency — iOS không hiện hộp thoại xin theo dõi.
- Không bán dữ liệu của bạn.
Trong ứng dụng, các trạng thái đồng ý dành cho quảng cáo (ad_storage, ad_user_data, ad_personalization) luôn ở trạng thái từ chối, kể cả khi bạn đã bật “dữ liệu sử dụng”.
5.5. Ai xử lý dữ liệu và dữ liệu đi đâu
- Google Firebase / Google Analytics — xử lý dữ liệu sử dụng và báo cáo sự cố theo chính sách quyền riêng tư của Google.
- Google BigQuery — dữ liệu sử dụng được xuất một lần mỗi ngày sang kho phân tích thuộc dự án Google Cloud của chính PX Apps (đặt tại Singapore). Bản xuất này không kèm mã quảng cáo.
- Google Play (Android) · Apple App Store (iOS) — xử lý giao dịch mua và khôi phục quyền Premium theo điều khoản của từng cửa hàng.
Chúng tôi không dùng Firebase làm đăng nhập, cơ sở dữ liệu đám mây hay đồng bộ sổ tiền.
5.6. Thời hạn lưu trữ
- Sổ tiền và lựa chọn của bạn: trên máy bạn — không có hạn tự động; bạn xoá được bất cứ lúc nào.
- Dữ liệu sử dụng (Google Analytics): 14 tháng ở cấp sự kiện và người dùng.
- Báo cáo sự cố (Crashlytics): khoảng 90 ngày theo tài liệu dịch vụ của Firebase.
- Bản xuất hằng ngày sang kho phân tích (Google BigQuery): bảng dữ liệu hiện tự hết hạn sau khoảng 60 ngày theo cấu hình hiện tại của dự án.
Thiết lập thời hạn áp dụng cho dữ liệu chi tiết; các báo cáo tổng hợp chuẩn không nhất thiết bị xoá theo. Nếu cấu hình lưu trữ thay đổi, chúng tôi sẽ cập nhật chính sách này.
5.7. Rút lại lựa chọn, mã cài đặt
- Tắt công tắc trong Cài đặt ⇒ ngăn việc thu thập mới kể từ thời điểm đó.
- Việc tắt không xoá ngay dữ liệu đã gửi trước đó; dữ liệu đó hết hạn theo mục 5.6.
- Xoá dữ liệu ứng dụng hoặc gỡ ứng dụng xoá toàn bộ sổ tiền của bạn trên máy, nhưng không xoá dữ liệu đã gửi tới Firebase.
- Dữ liệu nêu trên không gắn với tài khoản hay danh tính trực tiếp của bạn — ứng dụng không có đăng nhập. Dữ liệu gắn với một mã cài đặt ngẫu nhiên, được tạo lại khi bạn gỡ và cài lại ứng dụng hoặc xoá dữ liệu ứng dụng.
- Hiện chưa có quy trình tự phục vụ để liên kết một yêu cầu xoá với dữ liệu đã gửi, do dữ liệu đó không gắn với danh tính của bạn. Bạn có thể liên hệ để được giải thích và hỗ trợ.
6. Dữ liệu khi bạn liên hệ hỗ trợ
Khi bạn chủ động gửi email hoặc biểu mẫu hỗ trợ, chúng tôi có thể nhận tên, địa chỉ email, nội dung yêu cầu, thông tin thiết bị, phiên bản ứng dụng và tệp bạn tự đính kèm. Chúng tôi chỉ sử dụng thông tin này để tiếp nhận, xác minh, phản hồi, phòng chống lạm dụng và cải thiện chất lượng hỗ trợ.
Không gửi mật khẩu, OTP, dữ liệu thẻ, mã khóa thiết bị hoặc toàn bộ dữ liệu tài chính. Hãy che thông tin riêng tư trong ảnh chụp màn hình.
7. Dịch vụ cửa hàng ứng dụng
Apple App Store và Google Play có thể xử lý thông tin tài khoản, thiết bị, thanh toán, tải xuống, giao dịch mua và chẩn đoán theo chính sách của họ. Chúng tôi không nhận đầy đủ thông tin thẻ thanh toán của bạn. Chúng tôi có thể nhận trạng thái giao dịch hoặc báo cáo tổng hợp cần thiết để kích hoạt và quản lý quyền Premium.
- Android: mua gói Premium qua Google Play Billing; khôi phục quyền Premium qua tài khoản Google Play của bạn.
- iOS: mua gói Premium qua Apple App Store / StoreKit; khôi phục quyền Premium qua Apple ID / StoreKit.
8. Quyền truy cập trên thiết bị
Ứng dụng chỉ yêu cầu quyền cần thiết cho chức năng mà bạn chủ động sử dụng. Nếu một phiên bản cho phép chọn tệp để nhập hoặc xuất bản sao lưu, ứng dụng chỉ truy cập tệp/vị trí bạn chọn trong phạm vi hệ điều hành cho phép. Mọi quyền mới phải được giải thích tại thời điểm yêu cầu và cập nhật trong chính sách này.
9. Chia sẻ dữ liệu
Chúng tôi không chia sẻ nội dung sổ tiền cục bộ vì chúng tôi không nhận dữ liệu đó. Dữ liệu sử dụng và báo cáo sự cố (nếu bạn bật) được xử lý bởi các nhà cung cấp nêu ở mục 5.5 với vai trò bên xử lý dịch vụ.
Thông tin hỗ trợ chỉ có thể được chia sẻ trong phạm vi cần thiết với nhà cung cấp hạ tầng email/hỗ trợ, cơ quan có thẩm quyền theo yêu cầu hợp pháp, hoặc để bảo vệ quyền và an toàn của người dùng, chúng tôi và cộng đồng.
10. Thời gian lưu giữ và xóa dữ liệu
- Dữ liệu trong ứng dụng: tồn tại trên thiết bị cho đến khi bạn xóa giao dịch, xóa dữ liệu ứng dụng, gỡ ứng dụng hoặc thiết bị bị đặt lại.
- Bản sao lưu do bạn tạo: do bạn tự quản lý tại vị trí đã chọn.
- Dữ liệu sử dụng và báo cáo sự cố (nếu bạn bật): theo thời hạn ở mục 5.6.
- Thông tin hỗ trợ: được giữ trong thời gian cần thiết để xử lý yêu cầu, giải quyết tranh chấp, phòng chống lạm dụng và đáp ứng nghĩa vụ pháp lý; sau đó được xóa hoặc ẩn danh theo quy trình phù hợp.
Bạn có thể xóa dữ liệu trực tiếp trong ứng dụng hoặc thông qua cài đặt của hệ điều hành. Vì không có tài khoản người dùng và không có bản sao sổ tiền trên máy chủ của chúng tôi, chúng tôi không thể khôi phục dữ liệu cục bộ đã bị xóa.
11. Bảo mật
Chúng tôi áp dụng nguyên tắc tối thiểu hóa dữ liệu và các biện pháp kỹ thuật phù hợp trong phạm vi ứng dụng. Tuy nhiên, không có thiết bị hay phương thức lưu trữ nào an toàn tuyệt đối. Bạn nên dùng khóa màn hình, cập nhật hệ điều hành, không chia sẻ thiết bị tùy tiện và tự quản lý bản sao lưu an toàn.
12. Quyền và lựa chọn của bạn
Trong phạm vi pháp luật áp dụng, bạn có thể yêu cầu được biết, truy cập, chỉnh sửa, rút lại sự đồng ý, hạn chế xử lý hoặc xóa dữ liệu cá nhân mà chúng tôi thực sự đang nắm giữ. Đối với dữ liệu chỉ nằm trên thiết bị, bạn tự thực hiện các quyền này bằng chức năng sửa/xóa của ứng dụng hoặc cài đặt hệ điều hành.
Với hai lựa chọn ở mục 5, bạn rút lại sự đồng ý bất cứ lúc nào bằng cách tắt công tắc tương ứng trong Cài đặt. Đối với thông tin đã gửi cho bộ phận hỗ trợ, hãy liên hệ sotienhomnay.app@gmail.com.
13. Trẻ em
Sổ Tiền Hôm Nay không được thiết kế dành riêng cho trẻ em và không chủ động thu thập dữ liệu cá nhân của trẻ em. Cha mẹ hoặc người giám hộ phát hiện trẻ đã gửi thông tin cho bộ phận hỗ trợ có thể liên hệ để yêu cầu xem xét và xóa theo quy định áp dụng.
14. Chuyển dữ liệu ra nước ngoài
Dữ liệu sổ tiền cục bộ không được chúng tôi truyền ra khỏi thiết bị. Nếu bạn gửi email hỗ trợ, bật các lựa chọn ở mục 5, hoặc sử dụng dịch vụ của Apple/Google, thông tin có thể được xử lý tại quốc gia khác (ví dụ kho phân tích đặt tại Singapore — mục 5.5) theo hạ tầng và chính sách của nhà cung cấp liên quan, phù hợp với yêu cầu pháp luật áp dụng.
15. Thay đổi chính sách
Chúng tôi có thể cập nhật chính sách khi chức năng, cách xử lý dữ liệu hoặc yêu cầu pháp luật thay đổi. Phiên bản mới sẽ ghi ngày hiệu lực và được công bố tại URL này. Khi thay đổi ảnh hưởng đáng kể đến quyền của người dùng, chúng tôi sẽ thông báo bằng phương thức phù hợp trước hoặc tại thời điểm áp dụng.
16. Liên hệ về quyền riêng tư
1. Introduction
This policy explains how PX Apps (“we”) handles information when you use the Sổ Tiền Hôm Nay (Today’s Money) app and its landing page. The app is designed offline-first: we minimise data collection and keep your money book under your control, on your device.
2. Scope
This policy covers the app on iOS and Android, the official landing page, and support requests sent directly to us. Apple’s, Google’s and third-party services are governed by their own policies. Section 5 applies to app versions that include the usage-data and crash-report feature, on both platforms.
3. Data you create in the app
Depending on how you use it, you may enter amounts, transaction types, dates, notes, categories, debtor or payee names, debt status and display settings. This may be your personal or private financial data. It is processed locally to:
- Store and display your income, expense and debt records.
- Calculate totals and build reports for a period.
- Let you search, edit, delete and manage transactions.
- Remember categories, the trade template and settings on the device.
4. What we do not collect from your money book
- No account or sign-in is required.
- Your income, expense and debt entries are never sent to our servers.
- We do not sell or rent personal data.
- We do not use money-book contents for advertising or user profiling.
- We do not access bank accounts and do not move money.
5. Usage data and crash reports (optional — OFF by default)
Sổ Tiền Hôm Nay is offline-first. Everything in your money book — income and expense amounts, names, notes, categories, debts — is stored and encrypted on your device. We do not operate a server that receives your money-book contents.
Two separate choices, both OFF by default. The app sends a minimal amount of technical data only when you agree:
- Send usage data to improve the app — OFF by default; turn on/off anytime in Settings.
- Send technical crash reports — OFF by default; turn on/off anytime in Settings.
The two choices are fully independent. If you do not agree, the app remains fully usable — no feature is locked. Your choice is stored on the device itself: no account, no server, no cloud sync.
5.1. If you enable “usage data”, we may receive
- The type of action in the app, as technical event names (e.g. “first record created”, “report screen viewed”).
- The record type (income / expense / receivable / payable) — a classification only, never the content.
- The standardized template code in use (never a name you typed).
- App version, platform, technical sequence and timing.
- Collected automatically by Google’s services: a random installation identifier (app-instance / installation identifier); on iOS also the identifier for vendor (not an advertising identifier); device information (model, brand, OS version, language); session and engagement data; an approximate region inferred by Google from the IP address; and information about Premium purchases.
About Premium purchase information: when you buy Premium, Google Analytics may automatically record the product ID, product name, price, currency and quantity of the Premium package. This is about the app’s Premium package — never any amount or content in your money book.
5.2. If you enable “crash reports”, we may receive
Technical error information: stack traces in the app’s code, normalized error codes, app and OS version, device type, a technical installation identifier, and technical state related to the error.
5.3. We do NOT receive your money-book contents
PX Apps does not send to Firebase Analytics/Crashlytics: income or expense amounts · debt values · transaction values · people’s names · customer names · debtor or creditor names · notes · book contents · backups · exported files · phone numbers · emails you enter in the book · contacts · precise location · advertising identifiers (Advertising ID / IDFA).
The app also never sends receipts, purchase tokens or order IDs to Firebase, and does not store them on PX Apps’ servers.
5.4. Purposes, and what we do NOT do
Purposes: product analytics to improve the app; troubleshooting when you enable crash reports; measuring the effectiveness of campaigns that introduce the app (attribution and campaign measurement) through a link with Google Ads.
- No personalised advertising.
- No remarketing audiences.
- No audience sharing.
- No advertising identifiers (Advertising ID / IDFA): the Android release removed the permission entirely; the iOS build uses an Analytics configuration without IDFA support and integrates neither AdSupport nor App Tracking Transparency — iOS shows no tracking prompt.
- No selling of your data.
In the app, the advertising consent states (ad_storage, ad_user_data, ad_personalization) always remain denied, even after you enable usage data.
5.5. Who processes the data and where it goes
- Google Firebase / Google Analytics — processes usage data and crash reports under Google’s privacy policies.
- Google BigQuery — usage data is exported once per day to an analytics warehouse in PX Apps’ own Google Cloud project (located in Singapore); the export does not include advertising identifiers.
- Google Play (Android) · Apple App Store (iOS) — process purchases and Premium restoration under each store’s own terms.
We do not use Firebase for sign-in, cloud databases, or syncing your money book.
5.6. Retention
- Your money book and choices: on your device — no automatic expiry; you can delete anytime.
- Usage data (Google Analytics): 14 months at event and user level.
- Crash reports (Crashlytics): about 90 days per Firebase service documentation.
- Daily export to the analytics warehouse (Google BigQuery): tables currently expire after about 60 days under the project’s current configuration.
Retention applies to detailed data; standard aggregated reports are not necessarily deleted with it. If the retention configuration changes, we will update this policy.
5.7. Withdrawing your choice; the installation identifier
- Turning a switch off in Settings stops new collection from that moment.
- Turning it off does not immediately delete previously sent data; that data expires per section 5.6.
- Deleting app data or uninstalling deletes your money book on the device, but does not delete data already sent to Firebase.
- The data above is not tied to an account or your direct identity — the app has no sign-in. It is keyed to a random installation identifier, regenerated when you uninstall/reinstall the app or clear app data.
- There is currently no self-service process to link a deletion request to sent data, because that data is not tied to your identity. You can contact us for explanation and support.
6. Data when you contact support
When you email us or submit a support form, we may receive your name, email address, the content of your request, device information, app version and any files you attach. We use this only to receive, verify, respond, prevent abuse and improve support quality.
Do not send passwords, OTPs, card data, device keys or your full financial data. Please mask private information in screenshots.
7. App store services
The Apple App Store and Google Play may process account, device, payment, download, purchase and diagnostic information under their own policies. We do not receive your full payment-card details. We may receive transaction status or aggregate reports needed to activate and manage Premium.
- Android: Premium is purchased through Google Play Billing; restored through your Google Play account.
- iOS: Premium is purchased through the Apple App Store / StoreKit; restored through your Apple ID / StoreKit.
8. Device permissions
The app requests only the permissions needed for features you actively use. If a version lets you pick a file to import or export a backup, it accesses only the file/location you choose, within what the operating system allows. Any new permission must be explained when requested and reflected here.
9. Data sharing
We do not share local money-book contents because we never receive them. Usage data and crash reports (if you enable them) are processed by the providers listed in section 5.5 acting as service processors.
Support information may be shared only as necessary with our email/support infrastructure providers, with competent authorities upon lawful request, or to protect the rights and safety of users, ourselves and the community.
10. Retention and deletion
- In-app data: stays on the device until you delete transactions, clear app data, uninstall the app, or the device is reset.
- Backups you create: managed by you, at the location you chose.
- Usage data and crash reports (if enabled): per the retention list in section 5.6.
- Support information: kept as long as needed to handle the request, resolve disputes, prevent abuse and meet legal obligations; then deleted or anonymised.
You can delete data in the app or through your operating system settings. Because there is no user account and no server-side copy of your money book, we cannot restore local data once deleted.
11. Security
We apply data minimisation and appropriate technical measures within the app. However, no device or storage method is absolutely secure. Use a screen lock, keep your OS updated, avoid sharing your device casually, and keep your backups safe.
12. Your rights and choices
Within applicable law, you may request to know, access, correct, withdraw consent, restrict processing or delete personal data we actually hold. For data that lives only on your device, you exercise these rights directly through the app’s edit/delete functions or your OS settings.
For the two choices in section 5, you withdraw consent anytime by turning the corresponding switch off in Settings. For information already sent to support, contact sotienhomnay.app@gmail.com.
13. Children
Sổ Tiền Hôm Nay is not directed at children and does not knowingly collect children’s personal data. A parent or guardian who finds that a child has sent information to support may contact us to request review and deletion under applicable rules.
14. International transfers
We do not transfer local money-book data off your device. If you email support, enable the choices in section 5, or use Apple/Google services, information may be processed in another country (for example the analytics warehouse located in Singapore — section 5.5) under the relevant provider’s infrastructure and policies, consistent with applicable law.
15. Changes to this policy
We may update this policy when functionality, data handling or legal requirements change. A new version will state its effective date and be published at this URL. Where a change materially affects user rights, we will give notice by appropriate means before or at the time it takes effect.