隐私政策 / Privacy Policy
草稿声明 / DRAFT NOTICE 本文件为基于产品当前数据处理实现起草的隐私政策草稿,尚未经执业律师审核,不构成最终生效文本。正式发布前须由法律顾问按《中华人民共和国个人信息保护法》《数据安全法》《网络安全法》及配套规范核定,并补全所有
【】占位信息。 This is a DRAFT privacy policy derived from the product’s current data-handling implementation. It has not been reviewed by qualified counsel and is not a final, binding text. Before publication it must be vetted by legal counsel against the PRC Personal Information Protection Law (PIPL), Data Security Law, and Cybersecurity Law, and every【】placeholder must be filled in.起草日期 / Drafted: 2026-06-01 · 生效日期 / Effective: 【待定 TBD】 · 版本 / Version: v0.1-draft
相关文档 / Related: 用户服务协议 / Terms of Service
0. 关于本政策 / About This Policy
中文
本隐私政策(“本政策”)说明 【运营方法律主体全称】(“我们”)通过 rtrade 桌面客户端、移动客户端(Android)及 stock.avania.cn 相关网页(合称“本服务”)如何收集、使用、存储、共享和保护您的个人信息,以及您就个人信息所享有的权利。
本服务是一款面向中国 A 股市场的行情分析与交易记录辅助工具。本服务不是证券经纪、投资咨询或资产管理服务,不接入任何券商交易通道,不代您下单,不提供投资建议。详见《用户服务协议》。
在使用本服务前,请您仔细阅读并充分理解本政策,特别是以加粗标识的条款。一旦您注册账户或使用本服务,即表示您已阅读并同意本政策。
English
This Privacy Policy (“Policy”) explains how 【full legal name of operator】 (“we”, “us”) collects, uses, stores, shares, and protects your personal information through the rtrade desktop client, the Android mobile client, and the stock.avania.cn website (collectively, the “Service”), and describes your rights regarding your personal information.
The Service is an A‑share market analysis and trade‑recording tool. It is not a brokerage, investment‑advisory, or asset‑management service; it does not connect to any broker order channel, place orders on your behalf, or provide investment advice. See the Terms of Service.
Please read this Policy carefully before using the Service, paying particular attention to the clauses in bold. By registering an account or using the Service, you confirm that you have read and agree to this Policy.
1. 我们如何收集和使用您的个人信息 / What We Collect and Why
我们仅在为实现本服务功能所必需的范围内收集个人信息。以下按业务场景说明。 We collect personal information only as necessary to provide the Service. The following is organized by scenario.
1.1 账户注册与登录 / Account registration & login
中文
- 收集内容:用户名、登录密码(我们以 bcrypt 算法加盐哈希后存储,不保存明文密码)、可选的电子邮箱、第三方登录标识(
open_id,如适用)。 - 登录态:登录成功后我们签发有效期为 7 天的访问令牌(JWT)。
- 使用目的:创建和验证账户、维持登录状态、区分会员等级(VIP)、保障账户安全。
- 必要性:用户名与密码为注册和使用核心功能所必需;不提供将无法创建账户。电子邮箱为选填。
English
- Data: username, login password (stored as a salted bcrypt hash; we do not store plaintext passwords), optional email address, and a third‑party login identifier (
open_id, where applicable). - Session: upon login we issue an access token (JWT) valid for 7 days.
- Purpose: account creation/authentication, session maintenance, membership‑tier (VIP) differentiation, and account security.
- Necessity: username and password are required to register and use core features; email is optional.
1.2 设备与技术信息 / Device & technical information
中文
- 收集内容:设备标识符(
device_id,由客户端本地计算的 SHA‑256 摘要,截断为 32 位十六进制;桌面端基于机器标识生成,Android 端读取系统ANDROID_ID)、平台类型(桌面/移动)、操作系统、CPU 架构、应用版本号、首次与最近活跃时间。 - 使用目的:识别在用设备、统计活跃设备数、辅助账户安全(异常登录排查)、保障版本兼容(低于最低版本将提示升级)。
- 这些信息随每次请求的
User-Agent上报,并在登录、注册、刷新令牌及健康检查时记录。
English
- Data: a device identifier (
device_id— a SHA‑256 digest computed locally on the client and truncated to 32 hex chars; on desktop derived from a machine identifier, on Android read from the systemANDROID_ID), platform (desktop/mobile), operating system, CPU architecture, app version, and first/last‑seen timestamps. - Purpose: identifying active devices, counting active devices, supporting account security (anomalous‑login investigation), and version compatibility (clients below the minimum version are prompted to upgrade).
- This is reported via the
User-Agenton each request and recorded on login, registration, token refresh, and health checks.
1.3 使用与行为分析 / Usage & behavioral analytics
中文
- 收集内容:页面浏览与功能操作事件,包括:会话标识(
session_id)、事件类型(页面浏览/操作)、所访问的功能页面与操作名称(取自固定的受控词表,如“行情总览/图表/持仓/日志/AI 助手”等)、页面停留时长、以及有限的上下文(如所查看的股票代码、周期、来源入口)。 - 使用目的:分析产品使用情况、改进功能与体验、统计日活与功能热度。
- 我们不在分析事件中收集您输入的自由文本;操作名称与页面名称均为预定义枚举值。
English
- Data: page‑view and action events, including a session id (
session_id), event type (page view / action), the feature screen and action name (drawn from a fixed controlled vocabulary, e.g. market overview / chart / holdings / journal / AI assistant), dwell time, and limited context (e.g. the stock symbol, period, or entry source viewed). - Purpose: understanding product usage, improving features and experience, and measuring daily active users and feature popularity.
- We do not collect your free‑text input in analytics events; action and screen names are predefined enumerations.
1.4 您主动录入的自选与交易记录 / Watchlists & trading records you enter
中文
以下内容由您主动创建并保存,属于您的个人投资数据:
- 自选股 / 关注列表(
selfpick、track_stock):股票代码、添加时间、跟踪参数。 - 持仓记录(
positions):股票代码、持仓数量、平均成本、止损/目标价、开/平仓时间、来源、备注。 - 交易日志(
trade_journal):买卖价格、数量、盈亏金额与比例(由系统按成本与卖出价自动计算)、交易思路(thesis)、复盘心得(lesson)、标签、截图本地路径。 - 图表标注(
drawings):在 K 线图上绘制的趋势线、支撑/压力等图形。 - 策略扫描与回测记录(
strategy_scan_runs、backtest_runs):您发起的扫描/回测的配置、进度、统计指标、资金曲线与模拟成交明细。
使用目的:向您提供持仓管理、交易复盘、自选跟踪、策略回测等会员功能;上述数据仅与您的账户关联,用于向您本人展示。
English
The following are created and saved by you and constitute your personal investment data:
- Watchlists (
selfpick,track_stock): symbol, added time, tracking parameters. - Holdings (
positions): symbol, share quantity, average cost, stop/target prices, open/close times, source, notes. - Trade journal (
trade_journal): buy/sell prices and quantities, profit/loss amount and percentage (computed automatically by the system from cost and exit price), trade thesis, post‑trade lessons, tags, and a local screenshot path. - Chart annotations (
drawings): trendlines, support/resistance and other shapes drawn on candlestick charts. - Strategy scans & backtests (
strategy_scan_runs,backtest_runs): the configuration, progress, statistics, equity curve, and simulated‑trade details of scans/backtests you run.
Purpose: to provide member features such as holdings management, trade review, watchlist tracking, and strategy backtesting. This data is associated only with your account and is displayed to you.
1.5 AI 智能助手 / AI assistant
中文
- 收集内容:您与 AI 助手的多轮对话内容,包括对话标题、您发送的消息、模型回复、所选模板、工具调用记录、令牌用量与成本统计、对话创建/活跃时间。
- 重要——第三方处理:为生成回复,我们会将您的对话内容(含历史消息与系统提示)以明文传输至第三方大模型服务商深度求索(DeepSeek,杭州深度求索人工智能基础技术研究有限公司)进行处理。请勿在对话中输入您不希望被第三方处理的敏感个人信息、账号密码或商业秘密。
- 使用目的:提供多轮 AI 问答与分析功能、计费与配额管理、防滥用。
- 详见第 4 节“委托处理与共享”。
English
- Data: your multi‑turn conversations with the AI assistant — conversation titles, your messages, model replies, the selected template, tool‑call records, token‑usage and cost figures, and conversation timestamps.
- Important — third‑party processing: to generate replies, we transmit your conversation content (including message history and system prompts) in plaintext to the third‑party large‑model provider DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.) for processing. Do not enter sensitive personal information, credentials, or trade secrets that you do not wish a third party to process.
- Purpose: multi‑turn AI Q&A and analysis, billing/quota management, and abuse prevention.
- See Section 4 (“Entrusted processing and sharing”).
1.6 日志与安全信息 / Logs & security information
中文
- 收集内容:服务端运行日志可能记录请求标识(
req_id)、访问来源 IP 地址与端口、客户端平台与版本、请求方法、路由、状态码、响应耗时。 - 使用目的:故障排查、安全审计、防止滥用与攻击、保障服务稳定。
- 我们对接口访问进行按 IP 的频率限制(如登录、设备上报),以防止暴力破解与滥用。
English
- Data: server logs may record a request id (
req_id), the source IP address and port, client platform and version, request method, route, status code, and latency. - Purpose: troubleshooting, security auditing, abuse/attack prevention, and service stability.
- We apply per‑IP rate limiting to certain endpoints (e.g. login, device reporting) to deter brute‑force attacks and abuse.
2. 本地存储与登录态 / Local Storage & Sessions
中文
- 本服务采用基于令牌(JWT)的鉴权,不使用浏览器 Cookie 进行身份识别。
- 客户端会在您设备的本地配置目录(桌面端
~/.config/rtrade/,移动端为应用私有目录)保存登录凭据文件,用于“自动登录”。当您开启自动登录时,该文件会保存用户名、密码与访问令牌;密码以明文形式保存于本地。 - 安全提示(请重点阅读):若您在公用或他人可访问的设备上使用本服务,请勿开启自动登录,并在使用后及时退出登录以清除本地凭据。我们计划在后续版本改进本地凭据的保护方式。
- 您可随时通过“退出登录”清除本地保存的凭据。
English
- The Service uses token‑based (JWT) authentication and does not use browser cookies for identification.
- The client stores a credentials file in your device’s local config directory (desktop:
~/.config/rtrade/; mobile: the app‑private directory) to support “auto‑login”. When auto‑login is enabled, this file stores your username, password, and access token; the password is stored locally in plaintext. - Security notice (please read): do not enable auto‑login on shared or publicly accessible devices, and log out after use to clear local credentials. We plan to improve local‑credential protection in a future release.
- You can clear locally stored credentials at any time by logging out.
3. 我们如何使用收集的信息 / How We Use Information
中文 — 我们将个人信息用于:(a) 提供、维护和改进本服务功能;(b) 账户管理与身份验证;(c) 会员权益与计费;(d) 安全保障、风控、反滥用;(e) 产品分析与体验优化;(f) 履行法律法规要求的义务。我们不会将您的个人信息用于自动化决策对您作出具有重大影响的决定。
English — We use personal information to: (a) provide, maintain, and improve the Service; (b) manage accounts and authenticate users; (c) administer membership and billing; (d) ensure security and prevent abuse; (e) analyze and improve the product; and (f) comply with legal obligations. We do not use automated decision‑making to make decisions that significantly affect you.
4. 委托处理、共享、转让与公开披露 / Entrusted Processing, Sharing, Transfer & Disclosure
中文
我们不会出售您的个人信息。仅在下列情形下,您的信息可能被委托处理或共享:
| 接收方 / 角色 | 涉及数据 | 目的 | 说明 |
|---|---|---|---|
| 深度求索 DeepSeek(受托方/子处理者) | AI 助手对话内容、历史消息、系统提示 | 生成 AI 回复 | 仅在您使用 AI 助手时发生;境内服务商 |
| 智图 zhituapi(zhituapi.cn) | 不涉及个人信息 | 我们向其获取行情/基本面数据 | 单向获取公开市场数据,不向其发送任何用户信息 |
| 飞书 / Lark Webhook(运营内部告警,按需配置) | 含股票代码、信号类型、(持仓提醒中的)盈亏与提醒类型等 | 运营监控与告警 | 用于我们内部运维与播报渠道;如该渠道可能涉及您的持仓信息,我们将限制接收范围 |
| 基础设施/托管 | 视服务所需 | 服务器运行、数据库托管 | 我们自有服务器,运营主体控制 |
- 委托处理:我们与受托方约定其仅按本政策目的处理,不得超范围使用。
- 依法披露:在法律法规要求、司法或行政机关依法定程序要求时,我们可能披露必要信息。
- 业务转让:如发生合并、收购或资产转让,我们将要求承继方继续受本政策约束,否则将重新征得您的同意。
English
We do not sell your personal information. Your information may be entrusted or shared only as follows:
| Recipient / role | Data involved | Purpose | Notes |
|---|---|---|---|
| DeepSeek (processor / sub‑processor) | AI conversation content, history, system prompts | Generate AI replies | Only when you use the AI assistant; PRC‑domiciled provider |
| zhituapi (zhituapi.cn) | No personal information | We fetch market/fundamental data from it | One‑way retrieval of public market data; no user data is sent |
| Feishu / Lark webhook (internal operational alerts, configured as needed) | Stock symbols, signal types, and (in holdings alerts) P&L and alert type | Operational monitoring & alerting | Used for our internal ops/broadcast channels; where such a channel may involve your holdings data, we limit recipients |
| Infrastructure / hosting | As required | Server operation, database hosting | Our own servers, under the operator’s control |
- Entrusted processing: processors are contractually bound to process only for the purposes in this Policy and not beyond.
- Legal disclosure: we may disclose necessary information where required by law or by judicial/administrative authorities following lawful procedures.
- Business transfer: in a merger, acquisition, or asset transfer, we will require the successor to remain bound by this Policy or will seek your consent anew.
5. 存储地点与保存期限 / Storage Location & Retention
中文
- 存储地点:您的个人信息存储于位于中华人民共和国境内的服务器。本服务不向境外传输您的个人信息(AI 助手所用的大模型服务商亦为境内主体)。
- 保存期限:
| 数据类别 | 保存期限 |
|---|---|
| 账户信息(用户名、邮箱、密码哈希等) | 账户存续期间;注销后按法律要求的最短期限内删除或匿名化 |
| 设备信息、活跃记录 | 账户存续期间 |
| 行为分析事件(明细) | 180 天滚动留存,逾期分区删除 |
| 行为分析(聚合统计) | 长期保留(不含可识别个人的明细) |
| 持仓 / 交易日志 / 自选 / 标注 / 回测 | 由您控制,账户存续期间保留,您可自行删除 |
| AI 对话记录 | 账户存续期间保留(可归档/删除) |
| 服务端运行日志 | 短期留存,用于排障与安全审计 |
| 加密备份 | 默认 7 天滚动留存 |
- 超出保存期限后,我们将删除或匿名化处理您的个人信息,法律法规另有规定的除外。
English
- Location: your personal information is stored on servers located within the People’s Republic of China. The Service does not transfer your personal information abroad (the large‑model provider used by the AI assistant is also PRC‑domiciled).
- Retention:
| Category | Retention |
|---|---|
| Account info (username, email, password hash) | For the life of the account; deleted or anonymized within the minimum period required by law after deregistration |
| Device info, activity records | For the life of the account |
| Analytics events (detail) | 180‑day rolling retention; older partitions dropped |
| Analytics (aggregates) | Long‑term (contains no identifiable detail) |
| Holdings / journal / watchlist / annotations / backtests | Controlled by you; retained for the life of the account; you may delete them |
| AI conversations | Retained for the life of the account (archivable/deletable) |
| Server logs | Short‑term, for troubleshooting and security auditing |
| Encrypted backups | 7‑day rolling retention by default |
- After the retention period, we delete or anonymize your personal information unless law requires otherwise.
6. 我们如何保护您的个人信息 / How We Protect Your Information
中文
- 密码采用 bcrypt 加盐哈希存储,绝不明文保存于服务端。
- 客户端与服务器之间、服务器与数据库之间均采用 TLS 加密传输;数据库连接强制
sslmode=require并按 IP 白名单限制。 - 异地备份采用 age 非对称加密后再传输与存储。
- 实行最小权限访问控制,AI/管理类网关使用独立的只读角色与独立密钥体系,相互隔离。
- 我们采取合理的技术与管理措施保护信息安全,但请您理解,互联网环境并非绝对安全。
- 个人信息安全事件:若不幸发生信息泄露等安全事件,我们将按法律法规要求及时启动应急预案,并以适当方式告知您与监管部门。
English
- Passwords are stored as salted bcrypt hashes and never kept in plaintext server‑side.
- Traffic between client–server and server–database is TLS‑encrypted; database connections require
sslmode=requireand are IP‑allowlisted. - Off‑site backups are encrypted with age (asymmetric encryption) before transfer and storage.
- We enforce least‑privilege access control; AI/admin gateways use separate read‑only roles and independent secret pools, isolated from one another.
- We take reasonable technical and organizational measures, but please understand that no internet transmission is absolutely secure.
- Security incidents: in the event of a breach, we will activate our incident‑response plan and notify you and the regulator as required by law.
7. 您的权利 / Your Rights
中文
依据《个人信息保护法》,您对自己的个人信息享有以下权利:
- 查阅、复制:访问并获取我们持有的您的个人信息副本。
- 更正、补充:更正不准确或不完整的信息(账户资料、持仓、日志等可在应用内直接修改)。
- 删除:在符合法定情形时请求删除(您可自行删除自选、持仓、日志、对话等内容)。
- 撤回同意:撤回您此前作出的同意(如停止使用 AI 助手即停止向第三方传输对话内容)。
- 注销账户:注销后我们将删除或匿名化您的个人信息(法律要求保留者除外)。
- 可携带:在符合规定条件时,请求将您的个人信息转移至您指定的主体。
- 解释说明:要求我们对个人信息处理规则进行解释。
行使上述权利,请通过第 10 节联系方式与我们联系;我们将在法定期限内核实并响应。
English
Under PIPL, you have the right to:
- Access & copy the personal information we hold about you.
- Correct & supplement inaccurate or incomplete information (account details, holdings, journal entries can be edited in‑app).
- Delete your information where legally applicable (you can delete watchlists, holdings, journal entries, and conversations yourself).
- Withdraw consent previously given (e.g. ceasing to use the AI assistant stops transmission of conversation content to the third party).
- Deregister your account, after which we delete or anonymize your information (except where law requires retention).
- Portability: request transfer of your personal information to a designated party where conditions are met.
- Explanation of our processing rules.
To exercise these rights, contact us via Section 10; we will verify and respond within the statutory period.
8. 未成年人保护 / Minors
中文
本服务面向具备完全民事行为能力的成年人,不向未满 18 周岁的未成年人提供服务。证券投资相关活动依法要求成年。如果我们发现在未获监护人有效同意的情况下收集了未成年人个人信息,将尽快删除。
English
The Service is intended for adults with full civil capacity and is not offered to persons under 18. Securities‑related activities legally require adulthood. If we learn we have collected a minor’s personal information without valid guardian consent, we will delete it promptly.
9. 本政策的更新 / Updates to This Policy
中文 — 我们可能适时更新本政策。对于重大变更(如处理目的、处理方式、接收方、您的权利行使方式等的变化),我们将通过应用内通知、网站公告等显著方式告知。变更生效后您继续使用本服务,即视为接受更新后的政策。
English — We may update this Policy from time to time. For material changes (e.g. to purposes, methods, recipients, or how you exercise rights), we will notify you prominently via in‑app notice or website announcement. Continued use after the changes take effect constitutes acceptance.
10. 如何联系我们 / Contact Us
中文
- 运营主体 / Operator:【运营方法律主体全称】
- 注册地址 / Address:【注册地址】
- 联系邮箱 / Email:official@avania.cn
- 个人信息保护负责人 / DPO:【负责人或部门 + 联系方式】
- ICP 备案号 / ICP filing:【备案号】
如您对本政策或个人信息处理有任何疑问、意见或投诉,请通过上述邮箱联系我们;我们将在 15 个工作日内答复。
English
- Operator: 【full legal name of operator】
- Registered address: 【address】
- Email: official@avania.cn
- Person responsible for personal‑information protection (DPO): 【name/department + contact】
- ICP filing: 【filing number】
For questions, comments, or complaints about this Policy or our processing of personal information, contact us at the email above; we will respond within 15 working days.