Privacy Policy

Aurum Book

Effective date: 8 August 2026
Version: 2.1
Last updated: 8 August 2026

This version applies to Aurum Book distributed via Huawei AppGallery. Documents will be updated when the App is listed on other stores.


1. Introduction

This Privacy Policy explains how Hainan Paiji Digital Intelligence Technology Co., Ltd. (“we”, “us”, “our”), operator of the Aurum Book mobile application (“App”), collects, uses, stores, shares, and protects your personal data when you use the App in the United Arab Emirates (UAE) and other regions.

We are committed to complying with:

By downloading, installing, registering for, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the App.

Data Controller:
Hainan Paiji Digital Intelligence Technology Co., Ltd.
8819 Building, 4th Floor, Walker Park
Hainan Ecological Software Park
Chengmai County, Hainan Province 571924
People's Republic of China
Email: xuhongfei@piazzi.vip
Website: https://piazzi.vip

Summary (quick overview)

Aurum Book (operated by Hainan Paiji Digital Intelligence Technology Co., Ltd.) complies with UAE PDPL. We collect: device information (for guest-mode login), local financial records you enter, chat and voice transcripts, and membership / entitlement subscription status. Backend services and databases are hosted in Dubai; when you use AI, necessary context is sent over HTTPS to a Singapore LLM node (without sensitive account identifiers) solely to provide AI inference; speech-to-text prefers on-device recognition and may use cloud recognition when needed (without sensitive account identifiers). You can Clear Data or Delete Account in Settings. Contact: xuhongfei@piazzi.vip. Full details are in the sections below.


2. Scope

This Policy applies to:

This Policy does not apply to:


3. Who May Use the App

The App is intended for users aged 13 and older (or the higher minimum age required in your country). If you are under 18, you should use the App with the knowledge and consent of a parent or legal guardian.

We do not knowingly collect personal data from children below the applicable minimum age. If you believe a child has provided us data without proper consent, contact xuhongfei@piazzi.vip and we will take appropriate steps to delete it.


4. Personal Data We Collect

We collect only data reasonably necessary to provide personal finance tracking, budgeting, AI assistance, membership / entitlement subscriptions, and in-app purchases of AI credits.

4.1 Data you provide

Category Examples Purpose
Account & profile Nickname, language, currency preference, AI assistant nickname & personality; optional email and password for account recovery Personalise the App and restore data on a new device
Financial records Income/expense amounts, categories, dates, notes, budgets, savings goals Core bookkeeping
AI interactions Text messages to Aurum AI, parsed transaction drafts, voice-derived text AI chat & voice logging
Gift & social records Gift registry entries (names, amounts, occasions) if you use this feature Optional feature
Support enquiries Emails or messages you send to support Customer service

4.2 Data collected automatically

Category Examples Purpose
Device information Device identifier used for guest-mode login, app instance ID, OS version, app version Guest login, authentication, security
Usage & diagnostics API request logs, error logs, membership / entitlement and AI credit counters, first-party in-app analytics events Service operation, abuse prevention
Notifications Local scheduled reminders only — no push token is collected or uploaded Optional reminders you enable in Settings

We do not currently use third-party advertising networks or sell your personal data.

4.3 Permissions

Permission Why we ask Can you refuse?
Microphone Voice input for expense logging via Aurum AI Yes — use text/manual entry instead
Speech recognition Convert voice to text — on-device first; cloud speech recognition when needed (see §8) Yes
Photos / media Save your Money Persona card to your photo album Yes — bookkeeping still works
Notifications Budget and bookkeeping reminders you enable Yes — leave off in Settings or disable in system settings

We request permissions at runtime where required by the OS and only for the stated purposes.

4.4 Payment data

Optional membership / entitlement subscriptions and AI credit packs are processed by the app store from which you downloaded the App (currently primarily Huawei AppGallery). We receive purchase / subscription status and receipts (e.g. product identifier, fulfilment status, whether entitlements are active) but not your full payment card or bank account numbers. Prices are shown only on the store purchase screen and are not listed in this Policy.


5. How We Use Your Data

We use personal data to:

  1. Provide the service — store and display your transactions, budgets, reports, and goals;
  2. Power Aurum AI — send your messages (and voice-derived text) to AI models to generate replies and parse expenses;
  3. Manage AI credits and membership — track free daily credits, purchased credit balances, and membership / entitlement subscription status;
  4. Send notifications — deliver reminders you enable;
  5. Improve reliability — monitor errors, prevent fraud/abuse, enforce quotas;
  6. Comply with law — respond to lawful requests from authorities;
  7. Communicate with you — support requests and important service notices.

We do not use your financial data for third-party advertising profiling.


6. Legal Basis for Processing (UAE PDPL)

Depending on the processing activity, we rely on one or more of the following bases under the UAE PDPL and applicable law:

Basis Application
Consent Optional features (notifications, voice input, saving images to Photos, AI chat beyond essential service)
Contract Providing the App and in-app purchases you request
Legitimate interests Security, fraud prevention, service improvement (balanced against your rights)
Legal obligation Compliance with applicable UAE or court/regulatory requirements

Where consent is required, you may withdraw it at any time through App settings or by contacting us — without affecting processing already lawfully performed.


7. AI & Automated Processing

Aurum Book includes Aurum AI, which uses automated processing and third-party large language models (LLMs) to:

7.1 Where the LLM runs

When you use Aurum AI (chat, understanding after speech-to-text, expense draft parsing, deep report insights, and similar features), requests are forwarded by our backend over HTTPS to a third-party LLM service. The current LLM inference node is located in Singapore. Prompt text and context required to deliver those features are transmitted to and processed in Singapore solely to provide AI inference, and without sensitive account identifiers such as passwords or full payment card numbers.

7.2 Sensitive information we do not send to the LLM

We apply a minimum necessary principle. The backend does not place the following sensitive information in LLM request bodies, including but not limited to:

  1. Account and identity identifiers — user ID / UUID, session tokens, login credentials;
  2. Contact details — email address, phone number;
  3. Secrets and credentials — passwords, payment credentials, server-side API keys (kept in server configuration only; never placed in model context);
  4. Device and advertising identifiers — device ID, advertising ID, precise device fingerprints;
  5. Profile media — avatar or original photo URLs;
  6. Full raw ledger exports — complete transaction dumps from the database that are not part of the current chat or insight request, full bank account numbers, full card numbers, and similar.

7.3 What may still enter model context

To provide AI features, we may send to the Singapore LLM node text or summaries directly required for that request, for example: messages you type and recent chat turns, draft transaction fields before you confirm them, and aggregated report statistics needed for insights (such as category totals or period-over-period changes — not a full database dump). Any text you voluntarily type into chat bubbles (including amounts, merchant names, and notes) may enter LLM context. Do not paste passwords, full card numbers, national ID numbers, or similar sensitive raw strings into chat.

7.4 Other notes


8. Third-Party Service Providers

We use trusted processors who handle data on our instructions:

Provider type Role Typical data shared Location
Cloud hosting App backend, database, cache Account, transactions, chat history United Arab Emirates (Dubai)
AI / LLM provider Chat, parsing, report copy Feature-related prompts and context (see §7) Singapore (inference node)
Speech recognition Voice-to-text On-device first; when needed, audio or transcript segments are forwarded via our backend to cloud speech recognition. We do not attach account IDs, email, passwords, or device identifiers to those speech requests On-device and/or cloud processing nodes as required
App store In-app purchase billing for AI credits Purchase tokens / fulfilment status Per that platform’s policy (currently primarily Huawei AppGallery)

We do not name specific speech or model brands in this Policy. A current list of sub-processors is available on request at xuhongfei@piazzi.vip.


9. International Data Transfers

The App backend services and databases are hosted in the UAE (Dubai). When you use Aurum AI, prompt text and context required for that feature are sent over HTTPS to an LLM inference node in Singapore solely for AI inference (without sensitive account identifiers). When cloud speech recognition is used, necessary audio or transcript segments may be forwarded through our backend to the relevant processing node (also without sensitive account identifiers).

Where required by the UAE PDPL, we implement appropriate safeguards such as:

By using AI and cloud features, you acknowledge such transfers may occur for the purposes described in this Policy.


10. Data Retention

Data type Retention
Active account data While your account exists and you use the App
Purchased AI credit balances Available during the validity period shown in the App; then expire
Deleted transactions / chat (Clear Data) or account deletion Removed or anonymised from active systems; backups may persist up to 90 days
Server logs Typically 90–180 days, unless needed for security investigations
Purchase / billing records As required by tax/accounting law (often 5–7 years)
Inactive guest accounts May be anonymised or deleted after 24 months of inactivity

We may retain anonymised or aggregated data that cannot identify you.


11. Security

We implement appropriate technical and organisational measures, including:

No method of transmission or storage is 100% secure. You are responsible for keeping your device secure and not sharing your login credentials.


12. Your Rights (UAE PDPL)

Subject to applicable law, you may have the right to:

Right How to exercise
Access Request a copy of personal data we hold about you
Rectification Correct inaccurate data in the App or via support
Erasure Settings → Clear All Data (chat & transactions); Settings → Delete Account (full account); or email xuhongfei@piazzi.vip with subject “Account Deletion Request”
Restriction Ask us to limit certain processing
Portability Request export of your data in a machine-readable format (available on reasonable request)
Objection Object to processing based on legitimate interests
Withdraw consent Disable optional features or contact us

We will respond within 30 days (or as required by UAE PDPL), after verifying your identity. Billing records may be retained where required by law. We may refuse requests that are manifestly unfounded, excessive, or prohibited by law.


13. Account & Data Deletion

13.1 In-app Clear Data

Settings → Clear All Data removes your chat history and transactions from active service databases while keeping your guest/account identity so you can continue using the App.

13.2 Full account deletion

Use Settings → Delete Account, or email xuhongfei@piazzi.vip with subject “Account Deletion Request”. We will:

  1. Verify ownership;
  2. Delete or anonymise personal data in active systems (typically within 30 days);
  3. Confirm completion where contact details are available.

Deletion may be delayed where retention is required by law (e.g. billing records). Backups may persist for up to 90 days.


14. Marketing Communications

We do not send unsolicited marketing email or SMS. Service-related notices (e.g. critical updates) may still be sent.

Local reminders are opt-in via the in-app Settings toggle and system notification permissions. We schedule them on your device only; we do not collect a push notification token for this feature.


15. Changes to This Policy

We may update this Policy to reflect legal, technical, or business changes. When we make material changes, we will:

Continued use after the effective date constitutes acceptance of the updated Policy.


16. Complaints & Supervisory Authority

If you have concerns about our data practices:

  1. Contact us first: xuhongfei@piazzi.vip — we aim to resolve issues promptly.
  2. If unresolved, you may lodge a complaint with the UAE Data Office (or successor authority responsible for PDPL enforcement).

Support (non-privacy): xuhongfei@piazzi.vip
Website: https://piazzi.vip


17. Language

This Policy is published in English. Translations (Arabic, Chinese) are provided for convenience. If there is a conflict, the English version prevails unless UAE law requires otherwise.


© 8 August 2026 Hainan Paiji Digital Intelligence Technology Co., Ltd. All rights reserved.