The short version
Exon Platform is an offline application. Your ledger is stored on your own device, encrypted with your own password. We keep no copy of it, and there is no account to sign in to. If you choose to connect Google Drive, your backups go to your Drive, already encrypted, and we cannot read them. Two optional features carry anything of yours through machines of ours, and neither keeps anything from your book: the relay that lets an employee's phone reach the shop's PC from outside, which passes on only what it cannot read, and a question you ask the assistant, on its way to Google — figures without names.
Who we are
Exon Platform is developed by Moon Platform. For anything in this policy, write to behzad.shahidi0@gmail.com.
What the app stores, and where
Everything you enter — customers, transactions, currencies, categories, settings and images — is written to a database file in the app's private storage on your device. That file is encrypted with SQLCipher using a key derived from the password you set when you create a book. Without that password the file is unreadable, including by us.
The app contains no analytics, no advertising and no tracking of any kind. It does not have user accounts, because there is no service to have an account with. Nothing about a crash is sent anywhere: the app writes a note to a file on your device, and Settings → Report a problem is where you can read that file — folder paths and your book's name removed — and send it yourself if you decide to.
What leaves your device
By default, nothing. Six features can send data, and each is something you start:
- Local network sync. Your Windows PC and your phone exchange ledger changes directly with each other over your own Wi-Fi, after you pair them with a PIN or a QR code shown on screen. The data does not travel over the internet and does not pass through any server. From version 1.0.7 the exchange is encrypted: the two devices agree a key when they pair, the PIN itself never crosses the network, and a six-digit confirmation code is shown on both screens so you can see that nothing is sitting between them. Earlier versions sent it in the clear on your own network.
- Working from outside the shop. Off until you switch it on. When it is on, the shop's PC keeps a connection open to a relay we run on Cloudflare, and an employee's phone outside the shop reaches the PC through it. Everything between the phone and the PC is encrypted with a key only those two derive: the relay passes on bytes it cannot read, and an employee's password never leaves the phone and the PC. Only an employee's sign-in, the sync of their own share of the book and a change of their own password travel this way — the PIN that pairs your own devices, and a full backup of the book, never do. The relay keeps one thing for each shop: a hash of the shop PC's key, so that nothing else can answer in that PC's place.
- Exporting or sharing a file. When you export a backup, a statement, or a problem report, it goes wherever you send it. That is your choice and your responsibility.
- Google Drive backup. Described in full below.
- Checking for a new version. Because this app is not on any store, it can ask whether a newer version has been published. The question goes to moonplatform.app, our own address, which reads the answer from the public releases page on GitHub, where the installers are kept; if our address cannot be reached, the app asks GitHub directly. The request carries no identifier of any kind — not an account, not a device id, not your ledger — our address keeps no record of who asked, and nothing is downloaded or installed by the app itself; the answer is a version number and a link. It is asked only when you press the button on the About screen, or, on a device that has already connected Google Drive, at most once a day.
- Asking the assistant a question. Described in full below.
Google user data
Connecting a Google account is optional and is off until you turn it on. When you connect, the app asks Google for these permissions and no others:
| Permission | Why the app asks for it |
|---|---|
openid |
To complete the sign-in and confirm the connection belongs to the account you chose. |
userinfo.email |
So the settings screen can show you which Google account this device is connected to. The address is stored on your device and sent nowhere. |
drive.file |
To create a folder in your Drive and read, write and delete the backup files the app itself puts there. This permission gives the app access only to files it created. It cannot see, open or list anything else in your Drive. |
What is uploaded
Only backups of your own ledger, and only when an automatic or manual backup runs. Each backup is encrypted on your device before it is uploaded, using a key derived from your book password. Neither Google nor we can read the contents.
What we keep
Nothing. Your Google account's access token is stored in your operating system's secure storage — Windows DPAPI or the Android Keystore — on your device only. It is never transmitted to us, never written into a backup, and never included in anything the app exports.
How to disconnect and delete
- In the app: Settings → Database → Disconnect Google. This removes the stored token from your device immediately and revokes the app's access at Google.
- At Google: myaccount.google.com/permissions removes the app's access at any time.
- Backup files already in your Drive are left where they are, because they are yours. Delete the app's folder in Drive if you want them gone.
Exon Platform's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the backup feature described above. It is never sold, never transferred to others, never used for advertising, and never read by a human.
The assistant
The app can answer questions about your own book. There are two ways it can do that, and they are not the same thing:
- Offline (Windows only). You point the app at a model file on your own disk, and the answer is produced on your computer. Nothing is sent anywhere. It works with the network switched off.
- Online. The question is answered by Google's Gemini API — either through an endpoint we run, which adds the key and forwards the request, or straight to Google with a key you entered yourself.
What the online route sends is your question, a short extract of the app's own help text, and figures from your book: balances, totals, what was bought and sold, and the period they cover.
Names do not go. Before a request leaves the device, every customer name,
phone number and ID number is replaced by a reference — C1, C2
— and the real names are put back into the answer on your device afterwards. The list
that maps one to the other stays in memory on your device: it is never sent, never written to
disk, and never included in a backup.
This is worth saying plainly: the free service this feature runs on may use what it receives to improve its own models. Figures without names are still your business, so ask with that in mind. If you would rather nothing at all left the device, use the offline assistant, or do not ask.
Our endpoint stores nothing. It holds no database, keeps no copy of a question or an answer, and writes nothing about their contents to a log. It counts requests per internet address for one minute at a time, in memory, to stop a script from spending the quota — that count is not kept and is not an account of who asked what.
The conversation is not saved. It lives in memory while the page is open and is discarded when you leave it, lock the app, switch books or sign out. There is no history for you or anyone else to read afterwards. A key you enter yourself is stored in your operating system's secure storage — Windows DPAPI or the Android Keystore — never in the database and never in a backup.
Children
Exon Platform is a business accounting tool and is not directed at children.
Changes
If this policy changes, the date at the top changes with it, and any change that affects what the app does with Google data will be announced in the app before it takes effect.
خلاصه
اکسون پلتفرم یک برنامهٔ آفلاین است. دفتر شما روی دستگاه خودتان و با رمز خودتان رمزگذاریشده ذخیره میشود. ما هیچ نسخهای از آن نگه نمیداریم و هیچ حسابی هم نیست که واردش شوید. اگر گوگل درایو را وصل کنید، بکاپها به درایو خودِ شما میروند، از پیش رمزشده، و ما نمیتوانیم بخوانیمشان. دو قابلیت اختیاری چیزی از شما را از ماشینهای ما رد میکنند و هیچکدام چیزی از دفترتان نگه نمیدارند: سرور رابطی که گوشی کارمند را از بیرون دفتر به کامپیوتر دکان میرساند و فقط چیزی را جابهجا میکند که نمیتواند بخواند، و سؤالی که از دستیار میپرسید، در راهش به گوگل — ارقام بدون نام.
ما که هستیم
اکسون پلتفرم را Moon Platform میسازد. برای هر چیزی در این سند به behzad.shahidi0@gmail.com بنویسید.
اپ چه چیزی و کجا ذخیره میکند
هرچه وارد میکنید — مشتریان، معاملات، ارزها، دستهبندیها، تنظیمات و تصاویر — در یک فایل دیتابیس در حافظهٔ خصوصی اپ روی دستگاه شما نوشته میشود. آن فایل با SQLCipher و کلیدی که از رمز انتخابی شما ساخته میشود رمزگذاری شده است. بدون آن رمز فایل خوانا نیست، برای ما هم.
اپ هیچ آنالیتیکسی، هیچ تبلیغی و هیچ ردیابیای ندارد. حساب کاربری هم ندارد، چون سرویسی وجود ندارد که کسی در آن حساب داشته باشد. دربارهٔ خطاها هم چیزی خودبهخود فرستاده نمیشود: اپ یادداشتی در فایلی روی دستگاه خودتان مینویسد، و در تنظیمات ← گزارش مشکل میتوانید همان فایل را بخوانید — با مسیر پوشهها و نام دفترتان برداشتهشده — و اگر خواستید خودتان بفرستید.
چه چیزی دستگاه شما را ترک میکند
بهصورت پیشفرض هیچچیز. شش قابلیت میتوانند داده بفرستند و هر شش را خودتان شروع میکنید:
- همگامسازی شبکهٔ محلی. کامپیوتر و گوشی شما تغییرات دفتر را مستقیم روی وایفای خودتان رد و بدل میکنند، بعد از آنکه با پین یا کد QR روی صفحه جفتشان کنید. داده از اینترنت عبور نمیکند و از هیچ سروری رد نمیشود. از نسخهٔ ۱.۰.۷ این تبادل رمزگذاریشده است: دو دستگاه هنگام جفتشدن یک کلید مشترک میسازند، پینکد اصلاً از شبکه رد نمیشود، و یک کد تأیید ششرقمی روی هر دو صفحه میآید تا ببینید کسی وسط اتصال نیست. نسخههای قبلتر این را روی شبکهٔ خودتان بدون رمز میفرستادند.
- کار از بیرون دفتر. تا خودتان روشنش نکنید خاموش است. وقتی روشن باشد، کامپیوتر دکان یک اتصال باز به سرور رابطی نگه میدارد که ما روی Cloudflare اجرا میکنیم، و گوشی کارمندی که بیرون از دفتر است از همین راه به کامپیوتر میرسد. همهچیز بین گوشی و کامپیوتر با کلیدی رمز میشود که فقط همان دو میسازند: سرور رابط بایتهایی را جابهجا میکند که نمیتواند باز کند، و رمز کارمند هیچوقت از گوشی و کامپیوتر بیرون نمیرود. فقط ورود کارمند، همگامسازی سهم خودش از دفتر و تغییر رمز خودش از این راه میگذرد — پین جفتسازی دستگاههای خود شما و پشتیبان کامل دفتر هرگز. سرور رابط برای هر دکان فقط یک چیز نگه میدارد: هش کلید کامپیوتر همان دکان، تا کس دیگری نتواند بهجای آن کامپیوتر جواب بدهد.
- خروجی گرفتن یا اشتراک فایل. وقتی بکاپ، صورتحساب یا گزارش مشکل بیرون میدهید، هرجا بفرستیدش همانجا میرود. این انتخاب و مسئولیت شماست.
- بکاپ گوگل درایو. در ادامه بهطور کامل.
- بررسی نسخهٔ تازه. چون این اپ روی هیچ فروشگاهی نیست، میتواند بپرسد که آیا نسخهٔ تازهای منتشر شده است. این پرسش به moonplatform.app، نشانی خود ما، میرود که جوابش را از صفحهٔ عمومی نسخهها در GitHub میخواند، همانجا که فایلهای نصب نگه داشته میشوند؛ اگر نشانی ما در دسترس نباشد، اپ مستقیم از GitHub میپرسد. این درخواست هیچ شناسهای همراه ندارد — نه حساب، نه شناسهٔ دستگاه، نه دفتر شما — نشانی ما هیچ یادداشتی از اینکه چه کسی پرسیده نگه نمیدارد، و اپ خودش چیزی دانلود یا نصب نمیکند؛ پاسخ فقط یک شمارهٔ نسخه و یک لینک است. این پرسش تنها وقتی انجام میشود که دکمهاش را در صفحهٔ «درباره» بزنید، یا روی دستگاهی که از قبل به گوگل درایو وصل است، حداکثر روزی یک بار.
- پرسیدن سؤال از دستیار. در ادامه بهطور کامل.
اطلاعات حساب گوگل
وصل کردن حساب گوگل اختیاری است و تا خودتان روشنش نکنید خاموش است. هنگام اتصال، اپ این دسترسیها را از گوگل میخواهد و هیچ دسترسی دیگری:
| دسترسی | چرا اپ آن را میخواهد |
|---|---|
openid |
برای کامل کردن ورود و اطمینان از اینکه اتصال به همان حسابی است که انتخاب کردهاید. |
userinfo.email |
تا صفحهٔ تنظیمات نشان دهد این دستگاه به کدام حساب گوگل وصل است. این نشانی روی دستگاه شما میماند و جایی فرستاده نمیشود. |
drive.file |
برای ساختن یک پوشه در درایو شما و خواندن، نوشتن و حذف فایلهای بکاپی که خود اپ آنجا میگذارد. این دسترسی فقط به فایلهایی است که خود اپ ساخته؛ بقیهٔ درایو شما را نمیبیند، باز نمیکند و فهرست نمیکند. |
چه چیزی بالا میرود
فقط بکاپهای دفتر خودتان، و فقط وقتی یک بکاپ خودکار یا دستی اجرا شود. هر بکاپ پیش از آپلود، روی دستگاه شما و با کلیدی از رمز دفترتان رمزگذاری میشود. نه گوگل و نه ما نمیتوانیم محتوایش را بخوانیم.
ما چه نگه میداریم
هیچ. توکن دسترسی حساب گوگل شما در انبار امن سیستمعامل خودتان — DPAPI ویندوز یا Keystore اندروید — و فقط روی دستگاه شما ذخیره میشود. هرگز به ما فرستاده نمیشود، هرگز داخل بکاپ نوشته نمیشود و هرگز در خروجیهای اپ نمیآید.
قطع اتصال و حذف
- در اپ: تنظیمات ← پایگاه اطلاعات داده ← قطع اتصال گوگل. توکن ذخیرهشده فوراً از دستگاه پاک میشود و دسترسی اپ نزد گوگل لغو میگردد.
- نزد گوگل: myaccount.google.com/permissions هر زمان دسترسی اپ را برمیدارد.
- بکاپهایی که از قبل در درایو شماست سر جایش میماند، چون مال شماست. اگر نمیخواهید، پوشهٔ اپ را در درایو پاک کنید.
استفادهٔ اکسون پلتفرم از اطلاعات دریافتی از API های گوگل تابع Google API Services User Data Policy از جمله الزامات Limited Use است. اطلاعات حساب گوگل فقط برای همان قابلیت بکاپی که بالا توضیح داده شد به کار میرود؛ هرگز فروخته نمیشود، هرگز به دیگری منتقل نمیشود، هرگز برای تبلیغات استفاده نمیشود و هرگز انسانی آن را نمیخواند.
دستیار
اپ میتواند به سؤالهای شما دربارهٔ دفتر خودتان جواب بدهد. این کار دو راه دارد و این دو یکی نیستند:
- آفلاین (فقط ویندوز). خودتان یک فایل مدل روی دیسک خودتان به اپ نشان میدهید و جواب روی همان کامپیوتر ساخته میشود. هیچچیز جایی فرستاده نمیشود و با اینترنت خاموش هم کار میکند.
- آنلاین. جواب را Gemini گوگل میدهد — یا از راه نشانیای که ما اجرا میکنیم و کلید را خودش اضافه و درخواست را رد میکند، یا مستقیم به گوگل با کلیدی که خودتان وارد کردهاید.
راه آنلاین اینها را میفرستد: سؤال شما، تکهای کوتاه از متن راهنمای خود اپ، و ارقام دفترتان — موجودیها، جمعها، خرید و فروش، و دورهای که به آن مربوطاند.
نامها نمیروند. پیش از آنکه درخواستی دستگاه را ترک کند، نام هر مشتری،
شمارهٔ تلفن و شمارهٔ تذکره جایش را به یک نشانه میدهد — C1،
C2 — و نامهای واقعی بعداً روی دستگاه خودتان دوباره سر جایشان مینشینند.
فهرستی که این دو را به هم وصل میکند در حافظهٔ دستگاه شما میماند: نه فرستاده میشود، نه روی
دیسک نوشته میشود و نه در بکاپ میآید.
این را باید صریح گفت: سرویس رایگانی که این قابلیت روی آن کار میکند ممکن است از آنچه دریافت میکند برای بهتر کردن مدلهای خودش استفاده کند. ارقام بدون نام هم باز کار و بار شماست، پس با همین حساب بپرسید. اگر ترجیح میدهید هیچچیز دستگاه را ترک نکند، از دستیار آفلاین استفاده کنید یا اصلاً نپرسید.
نشانی ما چیزی ذخیره نمیکند. نه پایگاه دادهای دارد، نه نسخهای از سؤال یا جواب نگه میدارد، و نه چیزی از محتوای آنها را در هیچ لاگی مینویسد. فقط برای جلوگیری از اینکه یک اسکریپت سهمیه را تمام کند، تعداد درخواستها را برای هر نشانی اینترنتی در بازهٔ یک دقیقه در حافظه میشمارد؛ آن شمارش نگه داشته نمیشود و حسابوکتاب اینکه چه کسی چه پرسیده نیست.
گفتوگو ذخیره نمیشود. تا وقتی صفحه باز است در حافظه میماند و با بیرون رفتن از صفحه، قفل شدن اپ، عوض کردن دفتر یا خروج از حساب پاک میشود. هیچ تاریخچهای نمیماند که بعداً شما یا کس دیگری بخواند. کلیدی هم که خودتان وارد کنید در انبار امن سیستمعامل — DPAPI ویندوز یا Keystore اندروید — ذخیره میشود، نه در دیتابیس و نه در بکاپ.
کودکان
اکسون پلتفرم ابزار حسابداری کسبوکار است و مخاطبش کودکان نیستند.
تغییرات
اگر این سند تغییر کند، تاریخ بالای صفحه هم با آن تغییر میکند، و هر تغییری که روی کار اپ با اطلاعات گوگل اثر بگذارد پیش از اجرایی شدن در خود اپ اعلام میشود.