Ringkasan
- Data usaha Anda tersimpan di perangkat Anda. Data usaha tidak pernah dikirim ke server pengembang, dan pengembang tidak menerima data Anda.
- Sinkron Google Drive bersifat opsional dan memakai Google Drive milik Anda sendiri, hanya di folder data khusus aplikasi.
- Tokoni tidak memakai iklan, tidak memakai pelacak/analitik, dan tidak menjual atau membagikan data.
1. Data yang disimpan di perangkat
Data yang Anda masukkan, seperti profil usaha, produk, pelanggan, supplier, nota penjualan, pembelian, stok, kas, pengeluaran, hutang/piutang, pengguna dan peran, serta log aktivitas, disimpan di penyimpanan lokal perangkat (IndexedDB browser atau penyimpanan aplikasi Android). PIN pengguna tidak disimpan dalam bentuk asli, melainkan sebagai hash (PBKDF2).
2. Sinkron & backup Google Drive (opsional)
Bila Anda memilih Hubungkan Google Drive, Tokoni meminta izin akses dengan cakupan https://www.googleapis.com/auth/drive.appdata. Dengan izin ini Tokoni hanya dapat membuat, membaca, mengubah, dan menghapus file di folder data aplikasi miliknya sendiri di Google Drive Anda. Folder ini tersembunyi dari tampilan Drive biasa. Tokoni tidak dapat melihat atau mengakses file, foto, atau dokumen lain di Drive Anda.
File yang disimpan Tokoni di folder tersebut:
- file perubahan data dan rangkuman data untuk menyamakan data antar-perangkat Anda;
- file backup data (maksimal 10, yang paling lama dihapus otomatis);
- keterangan perangkat yang terhubung: nama & kode perangkat, jenis perangkat, nama pengguna dan cabang yang aktif, serta waktu sinkron terakhir.
Tokoni juga membaca alamat email dan nama tampilan akun Google yang terhubung. Informasi ini hanya dipakai untuk menampilkan akun mana yang tersambung dan untuk memilih akun yang sama saat sesi diperbarui. Informasi ini disimpan di perangkat Anda dan tidak dikirim ke pihak lain.
Data di Google Drive tunduk pada Kebijakan Privasi Google. Komunikasi antara Tokoni dan Google memakai koneksi terenkripsi (HTTPS) langsung dari perangkat Anda ke Google.
Login Google di versi web
Versi web Tokoni di app.tokoni.my.id memakai fungsi login kecil yang berjalan di Cloudflare Workers, agar Anda tidak perlu login ulang setiap jam. Fungsi ini hanya menukar kode login Google dengan token akses. Refresh token disimpan terenkripsi di cookie browser Anda (HttpOnly, tidak bisa dibaca skrip halaman) dan tidak disimpan di server. Data usaha Anda tidak pernah melewati fungsi ini; sinkron tetap langsung dari perangkat Anda ke Google Drive. Memilih Putuskan mencabut izin di Google dan menghapus cookie tersebut. Permintaan ke fungsi ini diproses Cloudflare sesuai Kebijakan Privasi Cloudflare. Aplikasi Android tidak memakai fungsi ini.
3. Izin perangkat
- Kamera: untuk memindai barcode dan mengambil foto (misalnya foto produk atau bukti pengeluaran) bila Anda memakai fitur tersebut. Gambar diproses dan disimpan di perangkat.
- Bluetooth, USB, dan jaringan lokal: untuk mencetak ke printer yang Anda pilih. Data yang dikirim hanya isi nota yang dicetak.
- Sidik jari / biometrik: pencocokan dilakukan oleh sistem operasi perangkat. Tokoni hanya menerima hasil berhasil atau gagal, tidak pernah menerima data sidik jari.
4. Layanan pihak ketiga
- Google Identity Services dan Google Drive API: hanya bila sinkron Google Drive diaktifkan.
- WhatsApp: bila Anda memilih mengirim nota atau tagihan lewat WhatsApp, Tokoni membuka WhatsApp dengan pesan yang bisa Anda periksa sebelum dikirim.
5. Kepatuhan terhadap kebijakan data pengguna Google
Penggunaan dan pemindahan informasi yang diterima Tokoni dari Google API mematuhi Google API Services User Data Policy, termasuk ketentuan Limited Use. Data dari Google hanya dipakai untuk fitur sinkron dan backup yang Anda gunakan, tidak dipakai untuk iklan, tidak dijual, dan tidak dibaca oleh manusia.
6. Menghapus data & mencabut akses
- Data di perangkat: hapus lewat menu Backup & Sinkron, Hapus data, atau hapus aplikasi/data situs di browser.
- Memutus sinkron: menu Backup & Sinkron, Putuskan.
- Mencabut izin Google: buka myaccount.google.com/permissions, pilih Tokoni, lalu hapus akses.
- Menghapus data Tokoni di Google Drive: buka Google Drive di web, Setelan, Kelola aplikasi, cari Tokoni, lalu pilih Hapus data aplikasi tersembunyi.
7. Keamanan
Karena data tersimpan di perangkat, keamanannya bergantung pada keamanan perangkat Anda. Gunakan kunci layar, aktifkan PIN pengguna di Tokoni, dan buat backup secara berkala.
8. Anak-anak
Tokoni ditujukan untuk pelaku usaha dan tidak ditujukan untuk anak di bawah 13 tahun.
9. Perubahan kebijakan
Bila kebijakan ini berubah, versi terbaru akan dimuat di halaman ini dengan tanggal berlaku yang baru.
10. Kontak
Pertanyaan tentang privasi dapat disampaikan melalui halaman GitHub Tokoni.
Privacy Policy (English)
Effective date: October 6, 2026
Summary
Tokoni stores all business data locally on the user's device. Business data is never sent to the developer's servers; the developer does not receive, collect, or store user data. Tokoni contains no ads, analytics, or trackers, and never sells or shares data.
Data stored on the device
Business profile, products, customers, suppliers, sales receipts, purchases, inventory, cash accounts, expenses, payables/receivables, users and roles, and the activity log are stored in the device's local storage (browser IndexedDB or Android app storage). User PINs are stored only as PBKDF2 hashes.
Optional Google Drive sync and backup
If the user chooses to connect Google Drive, Tokoni requests the https://www.googleapis.com/auth/drive.appdata scope only. This lets Tokoni create, read, update, and delete files in its own hidden application data folder in the user's Google Drive. Tokoni cannot see or access any other files in the user's Drive. The folder contains sync change files and snapshots used to keep the user's devices in sync, backup files (at most 10), and a small record of each connected device (device name and code, device type, active user and branch name, and last sync time).
Tokoni also reads the connected Google account's email address and display name, solely to show which account is connected and to select the same account when the session is refreshed. This information is stored only on the user's device.
All communication with Google happens directly between the user's device and Google over HTTPS.
Web sign-in helper
The web version at app.tokoni.my.id uses a small sign-in function on Cloudflare Workers so users stay signed in. It only exchanges the Google authorization code for tokens; the refresh token is stored encrypted in an HttpOnly cookie in the user's browser and is not stored on any server. Business data never passes through this function; sync goes directly from the device to Google Drive. Disconnecting revokes access at Google and deletes the cookie. The Android app does not use this function.
Device permissions
Camera (barcode scanning and photos the user chooses to attach), Bluetooth/USB/local network (printing receipts to the user's printer), and biometrics (verified by the operating system; Tokoni only receives a success or failure result).
Google API Services User Data Policy
Tokoni's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the sync and backup features the user enabled. It is not used for advertising, not sold, not transferred to third parties, and not read by humans.
Deleting data and revoking access
Local data can be deleted in the app (Backup & Sync, then Delete data) or by uninstalling the app or clearing site data. Drive sync can be disconnected in the app. Access can be revoked at myaccount.google.com/permissions. Tokoni's hidden data can be removed in Google Drive under Settings, Manage apps, Tokoni, Delete hidden app data.
Children
Tokoni is intended for business owners and is not directed to children under 13.
Changes and contact
Updates to this policy will be posted on this page with a new effective date. Questions can be submitted via the Tokoni GitHub page.