App Privacy Policy

Last updated: August 16, 2026

This policy explains how personal information is handled when you use The Cash AI app and its backend, synchronization, report-delivery, and support services (together, the "App Services"). The Cash AI is the controller responsible for the processing described here and is referred to as "we", "us", or "our" below.

The public landing and support website has a separate Website Privacy Notice. The App Terms of Service govern use of the App Services.

1. Information We Handle

1.1 Account, Authentication, and Session Information

The App uses Clerk for passwordless email authentication. Clerk and the App Services handle your email address, user and authentication identifiers, verification and authentication status, and active-session information. Session information can include a session identifier, browser or device type, IP address, approximate city and country derived from network information, activity time, status, and expiry time.

1.2 User-Entered App Data and Settings

We store information you add to the App so that it can be synchronized and used across features. This includes user-created account, category, and group names; category type and currency; opening balances and balances calculated from the records; transaction dates, amounts, source and destination, notes, and tags; creation dates and record identifiers; and display or ordering choices.

Synchronized settings include the base currency, reporting period, income-display choice, custom currency identifiers, import status, feature preferences, and Safe Mode or app-lock settings. Where the App stores a security PIN value, it stores a derived hash rather than the PIN itself.

1.3 Subscription Information

RevenueCat manages subscription entitlements. The App provides RevenueCat with your user identifier for The Cash AI and receives information such as product and entitlement status, trial or subscription expiry, renewal status, and billing-issue status. If a purchase is made through Apple or another supported marketplace, that marketplace processes the purchase under its own terms and provides the status needed to activate features.

1.4 Device, Request, and Diagnostic Information

We handle information needed to connect, secure, and diagnose the App Services, including app and operating-system version, device or browser type, IP address, user agent, request and user identifiers, requested API route, response status, timing, and related request metadata. Sentry may receive crash, performance, device, and diagnostic information when the App reports an error.

1.5 Reports, Email, and Support

If you request email delivery of a report, the report content and your primary account email address are processed to deliver it through Mailgun and the participating email providers. If you contact support, we handle your contact details, message, attachments, and related support records.

2. Optional AI Processing

AI features are optional. One saved AI data-transfer choice, disabled by default, controls both AI report analysis and voice transaction input. Data is sent for an AI feature only after you enable that choice and request the feature. You can disable it in Data Management to stop future AI transfers. Disabling it does not undo processing that you previously requested.

2.1 AI Report Analysis

When you request AI analysis for a report, the App sends OpenAI the report period and currency; totals, counts, averages, balances, rates, and comparisons; account, group, category, and tag names used in report breakdowns; and selected largest income and spending records. A selected record can include its date, amount, source and destination names, note, and tag labels. This is more detailed than anonymous or purely aggregated statistics, so review the records used for a report before requesting AI analysis.

2.2 Voice Transaction Input

When you request voice input, the App sends OpenAI the recording, requested language, and a vocabulary prompt containing the names of visible accounts, categories, groups, currencies, and tags for transcription. It then sends the transcript for parsing together with locale, time zone, current date, and the names and identifiers of those visible items. The parsing request also includes aggregate category and tag usage counts to improve matching. These requests do not include the list of individual existing transactions or account balances.

The resulting items are editable drafts and are not stored as transactions until you approve them. A temporary audio file created on our backend is deleted after transcription. This backend deletion does not determine OpenAI's own processing or retention.

2.3 OpenAI Request Controls

The OpenAI Responses API calls used for report analysis and transcript parsing include a stable pseudonymous safety identifier derived from your user identifier for abuse prevention. None of the AI requests described above include your email address. For those Responses API calls, our backend setsstore: false so OpenAI does not retain response application state. Unless an account has approved and enabled stricter data controls, OpenAI states that Responses API abuse-monitoring logs may include customer content and are retained for up to 30 days, subject to longer legal retention where required. The audio transcription request is a separate API call; OpenAI's current endpoint table states that this endpoint has no abuse-monitoring or application-state retention. The applicable controls are explained in OpenAI's API data controls. We do not describe these transfers as anonymous.

3. Purposes and Legal Bases

We process information for the following purposes:

4. Providers and Other Recipients

The App Services use the following providers for the stated functions:

The categories of information described above are disclosed to these providers for the stated functions, subject to the service configuration and each provider's legal role. A marketplace or email provider may process information independently under its own notice. We may also disclose information where required by law or reasonably necessary to protect users, the App Services, or legal rights. We do not sell personal information.

5. Retention and Account Deletion

Account settings and user-entered app records are retained while your account is active so the App can provide synchronization and reporting. When an account-deletion request completes successfully, the active settings, category, tag, and transaction records associated with the user are deleted from the App database and the Clerk user account is deleted.

Deletion from active systems does not necessarily remove information immediately from security logs, backups, delivered email, marketplace records, or records independently retained by a provider. Request and diagnostic logs are kept for the time needed to secure, operate, and troubleshoot the App Services. Support communications are kept for the time needed to resolve the request, maintain an appropriate support history, resolve disputes, and comply with law. Backups and provider records expire under the applicable backup cycle, provider policy, or legal requirement.

Voice recordings on our backend are retained only for the temporary transcription process described in Section 2.2. OpenAI, Sentry, Mailgun, RevenueCat, marketplaces, and other providers apply their configured retention rules. You may contact us for more information about retention that applies to your data.

6. Security

We use technical and organizational measures appropriate to the information and the App Services, including encrypted network transport between the App and backend. No method of electronic storage or transmission guarantees absolute security.

Planned client-side encryption

We plan to introduce optional client-side encryption in August 2026. It is not an active protection unless and until it appears in a released App version and you enable it. If released, an in-product notice will identify the fields protected on the device before synchronization, the operational metadata and requested transfers that remain outside that protection, and the consequences of losing the encryption password and recovery phrase. The release date and final scope may change if security or reliability testing requires it.

7. International Processing

Providers may process information in countries other than the one where you live. Where applicable law requires a safeguard for an international transfer, the transfer must use the required mechanism. You may contact us for information about safeguards applicable to your data.

8. Your Rights and Choices

Depending on where you live, you may have rights to request access, correction, deletion, restriction, or portability of personal information, to object to certain processing, and to withdraw consent where it is relied upon. You may also have the right to complain to the data-protection authority responsible for your place of residence or work. These rights may be subject to conditions and exceptions under applicable law.

The App provides data export and account-deletion controls. You may also contact us at support@thecash.ai. We may request information needed to verify your identity and protect the account concerned.

9. Children

The App Services are not directed to children under 13, and we do not knowingly request personal information from them. A parent or guardian who believes a child has provided information may contact us. A higher minimum age may apply where the user lives.

10. Changes to This Policy

We may update this policy when the App Services, provider configuration, our practices, or applicable law changes. We will publish the updated policy and revise the date above. We will provide additional notice before a material change and request consent where required by law.

11. Contact

Questions, complaints, or privacy requests can be sent to support@thecash.ai.