Privacy Policy
Updated: September 10, 2026
Effective: September 10, 2026
PBOC Data (央行数据, the “App”) respects your privacy. This policy explains how the App handles information while providing public macroeconomic and financial data, optional accounts, favorite syncing, and Pro subscriptions. You can browse data and purchase a subscription through Apple without registering or signing in.
Information We Handle
Optional Account Information
If you choose to register, sign in, bind an email address, or reset a password, we process the username and email address you provide, a public account identifier, verification status, and necessary security records. Passwords are stored only as irreversible hashes, never in plaintext. Email verification codes are limited to a specific purpose and validity period.
Favorites and Sync Data
When you are signed out, favorites, interface preferences, language, widget preferences, and cached data are primarily stored on your device. When you sign in, the indicator favorites you choose to sync, including their order and add/remove state, are stored on our server for synchronization across devices using the same account.
Subscriptions and Installation Identifier
To support purchases without an App account, restore purchases, verify subscription status, and associate an entitlement after sign-in, the App stores a randomly generated installation identifier in the Keychain. We also process Apple-provided product identifiers, transaction and original transaction identifiers, purchase environment, purchase and expiration dates, revocation or upgrade status, and App Account Token.
We do not receive or store your Apple Account password, full payment card number, or banking information. Apple processes payments.
Network and Security Information
When you access the backend, our server and hosting providers may temporarily process an IP address, request time, device or client type, API path, and error logs as necessary for transmission, security, abuse prevention, and troubleshooting. The App does not use an advertising identifier or use this information to build an advertising profile.
Optional Data Update Notifications
CPI / PMI update notifications are an optional Pro feature and are off by default. The App initializes JPush only after you accept this policy, enable an alert and authorize system notifications. You can control CPI and PMI separately under Settings — Indicator update alerts or disable notifications in iOS Settings without affecting data browsing or other subscription benefits.
Our server stores your installation identifier, JPush Registration ID, alert preferences, push environment and necessary delivery status. When signed in, the device may be associated with your account to verify Pro eligibility. Each CPI or PMI report produces a grouped notification opening the Prices or Surveys category list.
The App integrates JPush 6.2.2 and the no-IDFA edition of JCore 5.5.1. It does not read IDFA or request advertising tracking permission. SDK location collection is disabled; the App does not request location permission or submit location to the SDK. No-IDFA does not mean that no other device data is processed: push delivery uses the APNs device token, Registration ID, necessary device identifiers such as IDFV, device model and OS version, application information, IP address and network status, delivery information and necessary diagnostics. These support device addressing, APNs connectivity and delivery. We do not provide JPush with account passwords, email addresses, Apple payment information or complete subscription transaction records.
How We Use Information
We use the information described above only to:
- provide public-data lookup, caching, and widget features;
- create and maintain optional accounts and send email verification codes;
- sync indicator favorites for signed-in users;
- verify, restore, and associate Apple Pro subscription entitlements;
- deliver CPI / PMI update notifications you choose to enable;
- secure and troubleshoot the service and prevent abuse; and
- comply with applicable legal obligations.
Service Providers
The App contains no third-party advertising SDK, cross-app tracking SDK, or analytics SDK used for targeted advertising. We do not sell or rent personal information. The following providers may process limited information required for their functions:
- Apple App Store and StoreKit process purchases, renewals, refunds, and subscription status;
- JPush, operated by Shenzhen Hexun Huagu Information Technology Co., Ltd., and Apple APNs provide optional data update notifications. See the Jiguang Privacy Policy and SDK compliance guidance;
- NetEase 163 Mail and your email provider transmit verification codes for registration, sign-in, email binding, or password reset; and
- server and network hosting providers provide APIs, databases, network delivery, security, and service operations.
These providers process information under their own privacy policies and applicable law. We provide only what is necessary for the relevant function.
Retention and Deletion
Account information is retained while the account remains active. Verification codes are usable only for the validity period shown in the App. Session, security, and diagnostic records are retained only for a reasonable period needed to operate and protect the service or meet legal obligations. Subscription transaction records may be retained to verify entitlements, process renewals or refunds, resolve disputes, and comply with legal obligations.
You can delete your account from Settings in the App. Account-linked sessions and cloud favorites are then deleted or disassociated. Apple subscription records that must be retained for transaction verification or legal obligations are disassociated from the deleted account. Uninstalling the App removes most local data; Keychain data may remain under system behavior to support purchase restoration and prevent entitlement loss.
To request access, correction, or deletion of other relevant information, contact us using the email below.
Turning off all indicator alerts or withdrawing privacy consent requests deletion of the server-side push device binding and its delivery records. If the network is unavailable, the operation must be retried when connected. Consent withdrawal also unregisters remote notifications on the device and withdraws SDK information-collection authorization. Deleting an account removes its associated push devices and delivery records. Jiguang's retention, deletion and data-rights procedures are described in its privacy policy; you may also contact us for assistance.
Security
We use reasonable access controls, transport protection, password hashing, time-limited verification codes, and signed transaction validation. No internet transmission or electronic storage method can be guaranteed completely secure. Keep your credentials and email codes confidential.
Children's Privacy
The App is intended for a general audience and is not directed to children. We do not knowingly collect children's personal information. Contact us if you believe a child provided information without appropriate guardian consent.
Policy Changes
We may update this policy when features, service providers, or legal requirements change. Material changes will be communicated through this page or an appropriate notice in the App. The updated date shown above controls.
Contact
For privacy questions or data-rights requests, contact the developer:
- Email:
yokinzhu@gmail.com - Developer website:
https://mrqk.com - ICP filing number: 粤ICP备2024281068号-4A