Privacy Policy
Last updated: July 26, 2026
What this app does
The app infers the likely items behind your card transactions from the transaction data itself — amount, merchant, date, and currency — combined with public menu and price information and your own past confirmations. It never requires receipt photos or manual entry.
Data we process
- Transaction records you connect (merchant descriptor, amount, currency, timestamp). Access is read-only.
- Your confirmations and corrections of predicted items, stored so future predictions reflect your actual habits.
- Public menu and price data for merchants, which contains nothing about you.
Pseudonymization, not “anonymity”
Before any inference runs, your identity is replaced with an opaque pseudonym. The inference engine and its data stores never receive your name, email address, account number, or bank credentials. We deliberately do not call this “anonymous”: a purchase history is identifying by nature, and per-user learning means your data is singled out to serve you. Our commitment is minimization and strict separation of identity from inference — not a claim we couldn't keep.
Third parties
Item ranking uses large-language-model APIs. Prompts sent to these providers contain the merchant, amount, candidate items, and prior statistics — never your name or any account identifier. We use only provider tiers that are contractually barred from training on submitted data; a tier whose terms cannot be verified is treated as disqualified. We do not sell personal data, and we do not share it with data brokers or advertisers.
Connecting Apple Wallet
Where platform APIs allow (such as Apple's FinanceKit), transaction history is read on your device with your explicit permission, and you can revoke that permission at any time in system settings. You choose which transactions are imported — nothing is read in the background.
For each transaction you import, the app reads:
- merchant name, and the descriptor your bank or card network sent
- amount and currency, as billed
- for a purchase made abroad: the amount in the local currency and the exchange rate your card issuer applied
- the transaction date, the date it settled, and whether it is a purchase, refund, fee, or similar
- the merchant category code — the industry code your card network assigns to the merchant
- an account identifier, so transactions from different cards stay separate
There is no cardholder name, card number, or address in any of this. Imported transactions are stored on your device. They are sent to our server only to be itemized, and are not kept there — with one exception: when you confirm or correct an itemization, that correction is stored together with its transaction, under your pseudonym, because your own confirmations are what make your future predictions better.
Retention and deletion
Corrections and inferred history are kept to serve you and improve your own predictions. You can request deletion of everything tied to your pseudonym at any time by contacting us; deletion removes both stored records and the mapping between you and the pseudonym.
Contact
Questions or requests: heeyun@heeyunlee.com.