So there's no room for doubt, here is what we never do:
To work at all, the app keeps a few things locally on your device. They stay there: our servers never see them, apart from the checks described in section 5.
Deleting the app removes all of it from your device. The only thing that can exist outside your phone is the membership-check records described in section 5 — ask us and we will delete the one tied to your current reference code.
Everyday use — opening the book, asking, reading your answer — is entirely offline and makes no network requests at all. Only these things reach the network:
Only the last two cases involve a server of ours. What those requests leave behind is listed in section 5; we keep no other per-user logs.
Purchases, renewals, restores and refunds are handled entirely by the Apple App Store. We cannot see or store your payment method, card number, name or billing address.
The app only asks the system whether this device currently holds a valid purchase. The answer is a yes or a no, with no identity attached. To manage or cancel a subscription, go to Settings → Apple Account → Subscriptions.
If you used an earlier version of The Book of Answers, this one reads the local records the old version left inside the same app sandbox (reference code, questions remaining, language preference, membership marker) so nothing breaks for you.
This happens entirely on your device — nothing is sent anywhere — and it is read-only: the old data is left exactly as it was.
If you had a membership in the old version, the app also sends the purchase receipt issued by Apple to our server once, so your membership carries over without you having to restore it by hand. The receipt carries no name, no Apple ID and no payment details, but it does contain Apple's own transaction identifiers and purchase dates. We use it for that single check and never store the receipt itself; once it checks out, nothing is sent again. If that request cannot complete — no network, for instance — the app tries again on a later launch, at most three times in all; repeated attempts with the same result are merged into that one record rather than stored again. The same check also runs when you tap “Restore Purchase” and the App Store cannot recover your membership. You trigger that one yourself, so it does not count towards the three attempts above.
To be exact about that one request: our server keeps a single record — the date and time, the in-app reference code described in section 2, which membership product it was, whether the check succeeded, and whether it came from Apple's production or sandbox environment. It does not keep the receipt itself, your IP address, or any location derived from it. The purpose is to be able to investigate if a membership you paid for fails to carry over; the legal basis is our legitimate interest in honouring a purchase you already made. We do not delete the record on a fixed schedule: it is kept for as long as that purchase may still need to be honoured, and a lifetime membership has no end date. Write to the address in section 9 quoting your reference code — shown at the foot of the Help page — and we will delete it. That record is tied to the in-app reference code from section 2: there is only ever one per code — if the outcome changes we update it rather than add another. Deleting the app generates a new code, so a later check would start a new record.
This app is not directed to children under 13 (or the higher age set by the law where you live), and we do not knowingly collect personal information from children. The only thing that ever leaves the device is the membership-check record described in section 5, which contains no name, age or contact detail — so this holds equally for every user.
Where the GDPR in the EU and UK, the CCPA/CPRA in California, or comparable laws give you rights, you may access, correct or delete your personal data, or object to its processing.
For this app: apart from the membership-check records described in section 5, we hold no data about you. Uninstalling clears everything on your device; to have that one record erased, write to the address in section 9 and quote your reference code. We never sell or share personal information, and never use it for cross-context behavioural advertising. If you are in the EEA or the UK, you also have the right to complain to your local data protection authority. When this policy says “that record”, it means the one tied to your current in-app reference code. If you have reinstalled the app, the old code is gone — and we cannot link those older records to you either: they carry no name, no Apple ID, no IP address and nothing else that could point back to you.
This policy may change as the app does. If anything material changes — a feature that needs the network, for instance — we will say so prominently inside the app and update the date at the top of this page.
Any privacy question, request or complaint is welcome at Levi.xiaolw@gmail.com. I answer personally.