Privacy Policy — RichAuntie

Last updated: 22 August 2026

RichAuntie is a personal expense tracker built to be private by default. This policy explains exactly what happens to your data.

1. Your data lives on your device

Your transactions, categories, budgets, and settings are stored locally on your device (in the browser's IndexedDB / localStorage). We do not have a server that holds your ledger, and we cannot see it.

2. Optional cloud sync — end-to-end encrypted

If you turn on Cloud Sync, your data is encrypted on your device (AES-GCM, with a key derived from your sync code) before it is uploaded. Our server stores only the encrypted blob and can never read its contents. Your sync code and encryption key never leave your device. If you lose your sync code, the data cannot be decrypted by anyone, including us.

3. Receipt scanning (third-party AI)

If you use "Scan receipt", the photo you choose is sent — over an encrypted connection, through our processing endpoint — to Anthropic (the Claude API) solely to extract the amount, date, merchant, and category. We do not store the image; it is processed and discarded. Anthropic processes the image under its own terms; per Anthropic's policy, API inputs are not used to train its models. If you do not use receipt scanning, no images are ever sent anywhere. Before the first upload we ask for your explicit confirmation.

4. Bank & credit-card statement import (third-party AI)

If you use "Import Bank / Credit card statement", the file you choose — a CSV, PDF or photo of a statement — is sent, over an encrypted connection and through our processing endpoint, to Anthropic (the Claude API) solely to extract the transaction date, description, amount and a suggested category, and to produce a readable label for each line. We ask for your explicit confirmation before the first upload. We do not store the file; it is processed and discarded. Anthropic processes it under its own terms; per Anthropic's policy, API inputs are not used to train its models.

The extracted transactions are shown to you for review and are only written into your ledger — which stays on your device — when you tap "Add". If you do not use statement import, no statement ever leaves your device.

5. Advertising (free version only)

The free version of RichAuntie shows ads supplied by Google AdMob. To serve them, the Google Mobile Ads SDK may collect device and usage information such as a device advertising identifier, coarse location inferred from your IP address, and basic app-interaction data. This is handled by Google under Google's Privacy & Terms, not by us — we never receive your ledger data through it, and your transactions are never shared with advertisers.

Personalized ads are opt-in. On iOS, we ask for permission through Apple's App Tracking Transparency prompt. If you decline (or never respond), you still see ads, but they are non-personalized and no advertising identifier is used to track you across other apps and websites. You can change this at any time in iOS Settings → Privacy & Security → Tracking.

Subscribers see no ads. An active RichAuntie Pro subscription removes advertising entirely, and the ads SDK is not initialised.

6. No accounts, no analytics on your ledger

RichAuntie has no sign-up and no analytics or third-party trackers on your financial data. To enforce the free monthly receipt-scan and statement-import limits, an anonymous random identifier (a UUID) is generated on your device and sent only with those requests. It is not linked to your identity and contains no personal information.

7. Children

RichAuntie is a general-audience utility and is not directed at children under 13.

8. Deleting your data

Because data is local, you can remove it by deleting your entries, clearing the app's website data, or uninstalling. If you used Cloud Sync, stopping sync leaves the encrypted copy until it expires or is overwritten.

9. Changes

We may update this policy; the "Last updated" date will change accordingly.

10. Contact

Questions about privacy: yuxuanchin95@gmail.com

This document is a good-faith plain-language summary, not legal advice. Before selling RichAuntie in your market (and especially for GDPR/EU, UK, CCPA/California users), have a qualified lawyer review it and add any jurisdiction-specific terms.