Privacy · 隐私政策

Privacy

Last updated 2026-08-18 · 中文

The short version. We keep what a coupon needs to exist and reach the person you sent it to — nothing else.

What you write on a coupon never goes into analytics. Not the title, not the note, not your handwriting. That is enforced in our server code by a strict property allowlist, not by a promise to be careful.

No advertising SDKs. No cross-app tracking. Nothing sold to anyone.

What we store, and why

When you sign in

When you make a coupon

When you turn on notifications

When you reply to a redeemed coupon

When someone opens a coupon link

Counters

The line we do not cross

The text of a coupon — its title, its note, the handwriting — is never sent to analytics. Analytics events carry only which template was used, which language, and similar labels. Our server drops every other property before anything is sent, and refuses values that don’t look like our own short identifiers.

To be exact about the other direction: what you write is printed onto the coupon itself, and both the coupon page and its image can be read by anyone holding the link — see “Who can see a coupon” below.

We also do not use any advertising or attribution SDK, which is why the app never shows you a tracking permission prompt.

Who else handles it

Our database and images are placed in Cloudflare’s Asia-Pacific region — we ask for Singapore specifically, though Cloudflare treats that as a placement hint rather than a guarantee. Analytics events go to PostHog’s United States cloud.

Who can see a coupon

Anyone holding the link can open and redeem it, and the coupon image itself is served without a login so it can appear in a chat preview. That is how a coupon works — treat the link the way you would treat the coupon. Coupons are not listed anywhere public, and are not searchable.

How long we keep it

Coupons do not expire; a redeemed one stays as a keepsake for both people. If you delete your account:

Your choices

Children

Sweet IOU is made for couples and is not directed at children.

Changes

If this policy changes in a way that matters, we will change the date at the top and say so in the app.

Contact

Questions? Write to yyneo01@gmail.com.


隐私政策(中文)

最后更新 2026-08-18

一句话版。我们只保存「让一张券成立、并送到对方手里」所必需的东西。

你写在券上的话,永远不会进入埋点。标题、寄语、手写签名,一个字都不会。这不是靠我们小心,是服务端一份严格的字段白名单在机器层面兜住的。

不接任何广告 SDK,不做跨应用追踪,不把数据卖给任何人。

我们存了什么,为什么

你登录时

你做一张券时

你打开通知时

你回应一张被兑现的券时

有人打开一条券链接时

计数

我们不越的那条线

券上的内容——标题、寄语、手写——永远不会进入埋点。埋点事件只带「用了哪个模板」「哪种语言」这类标签。服务端在发出之前会丢掉其余所有字段,并拒收长得不像我们自己签发的短标识的值。

另一个方向也说清楚:你写的字印在券面上,而券页与券图对拿到链接的人是可读的——见下面「谁能看到一张券」。

我们也不接任何广告或归因 SDK——这也是这个 App 从不向你弹追踪授权框的原因。

还有谁经手

数据库与图片放在 Cloudflare 的亚太区域——我们明确指定了新加坡,但 Cloudflare 把它当作放置建议而不是保证。埋点事件发往 PostHog 的美国云。

谁能看到一张券

拿到链接的人就能打开并兑换它,券面图本身也不需要登录即可取到(这样它才能在聊天里显示成一张大图)。券本来就是这么用的——请把那条链接当成券本身来对待。券不会出现在任何公开列表里,也搜不到。

保存多久

券不会过期;兑现过的券会作为纪念留给双方。如果你注销账号:

你的选择

儿童

Sweet IOU 面向情侣,不面向儿童。

变更

本政策若发生实质变化,我们会更新顶部的日期,并在 App 内说明。

联系

有问题请写信到 yyneo01@gmail.com