Moon Platform
Exon Platformاکسون پلتفرم

Privacy Policyسیاست حریم خصوصی

Last updated: 6 October 2026آخرین به‌روزرسانی: ۱۴ میزان ۱۴۰۵ (۶ اکتبر ۲۰۲۶)

The short version

Exon Platform is an offline application. Your ledger is stored on your own device, encrypted with your own password. We keep no copy of it, and there is no account to sign in to. If you choose to connect Google Drive, your backups go to your Drive, already encrypted, and we cannot read them. Two optional features carry anything of yours through machines of ours, and neither keeps anything from your book: the relay that lets an employee's phone reach the shop's PC from outside, which passes on only what it cannot read, and a question you ask the assistant, on its way to Google — figures without names.

Who we are

Exon Platform is developed by Moon Platform. For anything in this policy, write to behzad.shahidi0@gmail.com.

What the app stores, and where

Everything you enter — customers, transactions, currencies, categories, settings and images — is written to a database file in the app's private storage on your device. That file is encrypted with SQLCipher using a key derived from the password you set when you create a book. Without that password the file is unreadable, including by us.

The app contains no analytics, no advertising and no tracking of any kind. It does not have user accounts, because there is no service to have an account with. Nothing about a crash is sent anywhere: the app writes a note to a file on your device, and Settings → Report a problem is where you can read that file — folder paths and your book's name removed — and send it yourself if you decide to.

What leaves your device

By default, nothing. Six features can send data, and each is something you start:

  • Local network sync. Your Windows PC and your phone exchange ledger changes directly with each other over your own Wi-Fi, after you pair them with a PIN or a QR code shown on screen. The data does not travel over the internet and does not pass through any server. From version 1.0.7 the exchange is encrypted: the two devices agree a key when they pair, the PIN itself never crosses the network, and a six-digit confirmation code is shown on both screens so you can see that nothing is sitting between them. Earlier versions sent it in the clear on your own network.
  • Working from outside the shop. Off until you switch it on. When it is on, the shop's PC keeps a connection open to a relay we run on Cloudflare, and an employee's phone outside the shop reaches the PC through it. Everything between the phone and the PC is encrypted with a key only those two derive: the relay passes on bytes it cannot read, and an employee's password never leaves the phone and the PC. Only an employee's sign-in, the sync of their own share of the book and a change of their own password travel this way — the PIN that pairs your own devices, and a full backup of the book, never do. The relay keeps one thing for each shop: a hash of the shop PC's key, so that nothing else can answer in that PC's place.
  • Exporting or sharing a file. When you export a backup, a statement, or a problem report, it goes wherever you send it. That is your choice and your responsibility.
  • Google Drive backup. Described in full below.
  • Checking for a new version. Because this app is not on any store, it can ask whether a newer version has been published. The question goes to moonplatform.app, our own address, which reads the answer from the public releases page on GitHub, where the installers are kept; if our address cannot be reached, the app asks GitHub directly. The request carries no identifier of any kind — not an account, not a device id, not your ledger — our address keeps no record of who asked, and nothing is downloaded or installed by the app itself; the answer is a version number and a link. It is asked only when you press the button on the About screen, or, on a device that has already connected Google Drive, at most once a day.
  • Asking the assistant a question. Described in full below.

Google user data

Connecting a Google account is optional and is off until you turn it on. When you connect, the app asks Google for these permissions and no others:

PermissionWhy the app asks for it
openid To complete the sign-in and confirm the connection belongs to the account you chose.
userinfo.email So the settings screen can show you which Google account this device is connected to. The address is stored on your device and sent nowhere.
drive.file To create a folder in your Drive and read, write and delete the backup files the app itself puts there. This permission gives the app access only to files it created. It cannot see, open or list anything else in your Drive.

What is uploaded

Only backups of your own ledger, and only when an automatic or manual backup runs. Each backup is encrypted on your device before it is uploaded, using a key derived from your book password. Neither Google nor we can read the contents.

What we keep

Nothing. Your Google account's access token is stored in your operating system's secure storage — Windows DPAPI or the Android Keystore — on your device only. It is never transmitted to us, never written into a backup, and never included in anything the app exports.

How to disconnect and delete

  • In the app: Settings → Database → Disconnect Google. This removes the stored token from your device immediately and revokes the app's access at Google.
  • At Google: myaccount.google.com/permissions removes the app's access at any time.
  • Backup files already in your Drive are left where they are, because they are yours. Delete the app's folder in Drive if you want them gone.

Exon Platform's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the backup feature described above. It is never sold, never transferred to others, never used for advertising, and never read by a human.

The assistant

The app can answer questions about your own book. There are two ways it can do that, and they are not the same thing:

  • Offline (Windows only). You point the app at a model file on your own disk, and the answer is produced on your computer. Nothing is sent anywhere. It works with the network switched off.
  • Online. The question is answered by Google's Gemini API — either through an endpoint we run, which adds the key and forwards the request, or straight to Google with a key you entered yourself.

What the online route sends is your question, a short extract of the app's own help text, and figures from your book: balances, totals, what was bought and sold, and the period they cover.

Names do not go. Before a request leaves the device, every customer name, phone number and ID number is replaced by a reference — C1, C2 — and the real names are put back into the answer on your device afterwards. The list that maps one to the other stays in memory on your device: it is never sent, never written to disk, and never included in a backup.

This is worth saying plainly: the free service this feature runs on may use what it receives to improve its own models. Figures without names are still your business, so ask with that in mind. If you would rather nothing at all left the device, use the offline assistant, or do not ask.

Our endpoint stores nothing. It holds no database, keeps no copy of a question or an answer, and writes nothing about their contents to a log. It counts requests per internet address for one minute at a time, in memory, to stop a script from spending the quota — that count is not kept and is not an account of who asked what.

The conversation is not saved. It lives in memory while the page is open and is discarded when you leave it, lock the app, switch books or sign out. There is no history for you or anyone else to read afterwards. A key you enter yourself is stored in your operating system's secure storage — Windows DPAPI or the Android Keystore — never in the database and never in a backup.

Children

Exon Platform is a business accounting tool and is not directed at children.

Changes

If this policy changes, the date at the top changes with it, and any change that affects what the app does with Google data will be announced in the app before it takes effect.

خلاصه

اکسون پلتفرم یک برنامهٔ آفلاین است. دفتر شما روی دستگاه خودتان و با رمز خودتان رمزگذاری‌شده ذخیره می‌شود. ما هیچ نسخه‌ای از آن نگه نمی‌داریم و هیچ حسابی هم نیست که واردش شوید. اگر گوگل درایو را وصل کنید، بک‌اپ‌ها به درایو خودِ شما می‌روند، از پیش رمزشده، و ما نمی‌توانیم بخوانیمشان. دو قابلیت اختیاری چیزی از شما را از ماشین‌های ما رد می‌کنند و هیچ‌کدام چیزی از دفترتان نگه نمی‌دارند: سرور رابطی که گوشی کارمند را از بیرون دفتر به کامپیوتر دکان می‌رساند و فقط چیزی را جابه‌جا می‌کند که نمی‌تواند بخواند، و سؤالی که از دستیار می‌پرسید، در راهش به گوگل — ارقام بدون نام.

ما که هستیم

اکسون پلتفرم را Moon Platform می‌سازد. برای هر چیزی در این سند به behzad.shahidi0@gmail.com بنویسید.

اپ چه چیزی و کجا ذخیره می‌کند

هرچه وارد می‌کنید — مشتریان، معاملات، ارزها، دسته‌بندی‌ها، تنظیمات و تصاویر — در یک فایل دیتابیس در حافظهٔ خصوصی اپ روی دستگاه شما نوشته می‌شود. آن فایل با SQLCipher و کلیدی که از رمز انتخابی شما ساخته می‌شود رمزگذاری شده است. بدون آن رمز فایل خوانا نیست، برای ما هم.

اپ هیچ آنالیتیکسی، هیچ تبلیغی و هیچ ردیابی‌ای ندارد. حساب کاربری هم ندارد، چون سرویسی وجود ندارد که کسی در آن حساب داشته باشد. دربارهٔ خطاها هم چیزی خودبه‌خود فرستاده نمی‌شود: اپ یادداشتی در فایلی روی دستگاه خودتان می‌نویسد، و در تنظیمات ← گزارش مشکل می‌توانید همان فایل را بخوانید — با مسیر پوشه‌ها و نام دفترتان برداشته‌شده — و اگر خواستید خودتان بفرستید.

چه چیزی دستگاه شما را ترک می‌کند

به‌صورت پیش‌فرض هیچ‌چیز. شش قابلیت می‌توانند داده بفرستند و هر شش را خودتان شروع می‌کنید:

  • همگام‌سازی شبکهٔ محلی. کامپیوتر و گوشی شما تغییرات دفتر را مستقیم روی وای‌فای خودتان رد و بدل می‌کنند، بعد از آنکه با پین یا کد QR روی صفحه جفتشان کنید. داده از اینترنت عبور نمی‌کند و از هیچ سروری رد نمی‌شود. از نسخهٔ ۱.۰.۷ این تبادل رمزگذاری‌شده است: دو دستگاه هنگام جفت‌شدن یک کلید مشترک می‌سازند، پین‌کد اصلاً از شبکه رد نمی‌شود، و یک کد تأیید شش‌رقمی روی هر دو صفحه می‌آید تا ببینید کسی وسط اتصال نیست. نسخه‌های قبل‌تر این را روی شبکهٔ خودتان بدون رمز می‌فرستادند.
  • کار از بیرون دفتر. تا خودتان روشنش نکنید خاموش است. وقتی روشن باشد، کامپیوتر دکان یک اتصال باز به سرور رابطی نگه می‌دارد که ما روی Cloudflare اجرا می‌کنیم، و گوشی کارمندی که بیرون از دفتر است از همین راه به کامپیوتر می‌رسد. همه‌چیز بین گوشی و کامپیوتر با کلیدی رمز می‌شود که فقط همان دو می‌سازند: سرور رابط بایت‌هایی را جابه‌جا می‌کند که نمی‌تواند باز کند، و رمز کارمند هیچ‌وقت از گوشی و کامپیوتر بیرون نمی‌رود. فقط ورود کارمند، همگام‌سازی سهم خودش از دفتر و تغییر رمز خودش از این راه می‌گذرد — پین جفت‌سازی دستگاه‌های خود شما و پشتیبان کامل دفتر هرگز. سرور رابط برای هر دکان فقط یک چیز نگه می‌دارد: هش کلید کامپیوتر همان دکان، تا کس دیگری نتواند به‌جای آن کامپیوتر جواب بدهد.
  • خروجی گرفتن یا اشتراک فایل. وقتی بک‌اپ، صورت‌حساب یا گزارش مشکل بیرون می‌دهید، هرجا بفرستیدش همان‌جا می‌رود. این انتخاب و مسئولیت شماست.
  • بک‌اپ گوگل درایو. در ادامه به‌طور کامل.
  • بررسی نسخهٔ تازه. چون این اپ روی هیچ فروشگاهی نیست، می‌تواند بپرسد که آیا نسخهٔ تازه‌ای منتشر شده است. این پرسش به moonplatform.app، نشانی خود ما، می‌رود که جوابش را از صفحهٔ عمومی نسخه‌ها در GitHub می‌خواند، همان‌جا که فایل‌های نصب نگه داشته می‌شوند؛ اگر نشانی ما در دسترس نباشد، اپ مستقیم از GitHub می‌پرسد. این درخواست هیچ شناسه‌ای همراه ندارد — نه حساب، نه شناسهٔ دستگاه، نه دفتر شما — نشانی ما هیچ یادداشتی از اینکه چه کسی پرسیده نگه نمی‌دارد، و اپ خودش چیزی دانلود یا نصب نمی‌کند؛ پاسخ فقط یک شمارهٔ نسخه و یک لینک است. این پرسش تنها وقتی انجام می‌شود که دکمه‌اش را در صفحهٔ «درباره» بزنید، یا روی دستگاهی که از قبل به گوگل درایو وصل است، حداکثر روزی یک بار.
  • پرسیدن سؤال از دستیار. در ادامه به‌طور کامل.

اطلاعات حساب گوگل

وصل کردن حساب گوگل اختیاری است و تا خودتان روشنش نکنید خاموش است. هنگام اتصال، اپ این دسترسی‌ها را از گوگل می‌خواهد و هیچ دسترسی دیگری:

دسترسیچرا اپ آن را می‌خواهد
openid برای کامل کردن ورود و اطمینان از اینکه اتصال به همان حسابی است که انتخاب کرده‌اید.
userinfo.email تا صفحهٔ تنظیمات نشان دهد این دستگاه به کدام حساب گوگل وصل است. این نشانی روی دستگاه شما می‌ماند و جایی فرستاده نمی‌شود.
drive.file برای ساختن یک پوشه در درایو شما و خواندن، نوشتن و حذف فایل‌های بک‌اپی که خود اپ آنجا می‌گذارد. این دسترسی فقط به فایل‌هایی است که خود اپ ساخته؛ بقیهٔ درایو شما را نمی‌بیند، باز نمی‌کند و فهرست نمی‌کند.

چه چیزی بالا می‌رود

فقط بک‌اپ‌های دفتر خودتان، و فقط وقتی یک بک‌اپ خودکار یا دستی اجرا شود. هر بک‌اپ پیش از آپلود، روی دستگاه شما و با کلیدی از رمز دفترتان رمزگذاری می‌شود. نه گوگل و نه ما نمی‌توانیم محتوایش را بخوانیم.

ما چه نگه می‌داریم

هیچ. توکن دسترسی حساب گوگل شما در انبار امن سیستم‌عامل خودتان — DPAPI ویندوز یا Keystore اندروید — و فقط روی دستگاه شما ذخیره می‌شود. هرگز به ما فرستاده نمی‌شود، هرگز داخل بک‌اپ نوشته نمی‌شود و هرگز در خروجی‌های اپ نمی‌آید.

قطع اتصال و حذف

  • در اپ: تنظیمات ← پایگاه اطلاعات داده ← قطع اتصال گوگل. توکن ذخیره‌شده فوراً از دستگاه پاک می‌شود و دسترسی اپ نزد گوگل لغو می‌گردد.
  • نزد گوگل: myaccount.google.com/permissions هر زمان دسترسی اپ را برمی‌دارد.
  • بک‌اپ‌هایی که از قبل در درایو شماست سر جایش می‌ماند، چون مال شماست. اگر نمی‌خواهید، پوشهٔ اپ را در درایو پاک کنید.

استفادهٔ اکسون پلتفرم از اطلاعات دریافتی از API های گوگل تابع Google API Services User Data Policy از جمله الزامات Limited Use است. اطلاعات حساب گوگل فقط برای همان قابلیت بک‌اپی که بالا توضیح داده شد به کار می‌رود؛ هرگز فروخته نمی‌شود، هرگز به دیگری منتقل نمی‌شود، هرگز برای تبلیغات استفاده نمی‌شود و هرگز انسانی آن را نمی‌خواند.

دستیار

اپ می‌تواند به سؤال‌های شما دربارهٔ دفتر خودتان جواب بدهد. این کار دو راه دارد و این دو یکی نیستند:

  • آفلاین (فقط ویندوز). خودتان یک فایل مدل روی دیسک خودتان به اپ نشان می‌دهید و جواب روی همان کامپیوتر ساخته می‌شود. هیچ‌چیز جایی فرستاده نمی‌شود و با اینترنت خاموش هم کار می‌کند.
  • آنلاین. جواب را Gemini گوگل می‌دهد — یا از راه نشانی‌ای که ما اجرا می‌کنیم و کلید را خودش اضافه و درخواست را رد می‌کند، یا مستقیم به گوگل با کلیدی که خودتان وارد کرده‌اید.

راه آنلاین این‌ها را می‌فرستد: سؤال شما، تکه‌ای کوتاه از متن راهنمای خود اپ، و ارقام دفترتان — موجودی‌ها، جمع‌ها، خرید و فروش، و دوره‌ای که به آن مربوط‌اند.

نام‌ها نمی‌روند. پیش از آنکه درخواستی دستگاه را ترک کند، نام هر مشتری، شمارهٔ تلفن و شمارهٔ تذکره جایش را به یک نشانه می‌دهد — C1، C2 — و نام‌های واقعی بعداً روی دستگاه خودتان دوباره سر جایشان می‌نشینند. فهرستی که این دو را به هم وصل می‌کند در حافظهٔ دستگاه شما می‌ماند: نه فرستاده می‌شود، نه روی دیسک نوشته می‌شود و نه در بک‌اپ می‌آید.

این را باید صریح گفت: سرویس رایگانی که این قابلیت روی آن کار می‌کند ممکن است از آنچه دریافت می‌کند برای بهتر کردن مدل‌های خودش استفاده کند. ارقام بدون نام هم باز کار و بار شماست، پس با همین حساب بپرسید. اگر ترجیح می‌دهید هیچ‌چیز دستگاه را ترک نکند، از دستیار آفلاین استفاده کنید یا اصلاً نپرسید.

نشانی ما چیزی ذخیره نمی‌کند. نه پایگاه داده‌ای دارد، نه نسخه‌ای از سؤال یا جواب نگه می‌دارد، و نه چیزی از محتوای آن‌ها را در هیچ لاگی می‌نویسد. فقط برای جلوگیری از اینکه یک اسکریپت سهمیه را تمام کند، تعداد درخواست‌ها را برای هر نشانی اینترنتی در بازهٔ یک دقیقه در حافظه می‌شمارد؛ آن شمارش نگه داشته نمی‌شود و حساب‌وکتاب اینکه چه کسی چه پرسیده نیست.

گفت‌وگو ذخیره نمی‌شود. تا وقتی صفحه باز است در حافظه می‌ماند و با بیرون رفتن از صفحه، قفل شدن اپ، عوض کردن دفتر یا خروج از حساب پاک می‌شود. هیچ تاریخچه‌ای نمی‌ماند که بعداً شما یا کس دیگری بخواند. کلیدی هم که خودتان وارد کنید در انبار امن سیستم‌عامل — DPAPI ویندوز یا Keystore اندروید — ذخیره می‌شود، نه در دیتابیس و نه در بک‌اپ.

کودکان

اکسون پلتفرم ابزار حسابداری کسب‌وکار است و مخاطبش کودکان نیستند.

تغییرات

اگر این سند تغییر کند، تاریخ بالای صفحه هم با آن تغییر می‌کند، و هر تغییری که روی کار اپ با اطلاعات گوگل اثر بگذارد پیش از اجرایی شدن در خود اپ اعلام می‌شود.