Safi. Last updated 4 August 2026.
Safi is a personal finance app. This policy explains what we collect, why, who we share it with, and how you can get it back or delete it. We have tried to write it in plain language rather than legal boilerplate.
Safi is operated by [LEGAL ENTITY NAME], [ADDRESS]. For any privacy question or request, contact [PRIVACY EMAIL]. If you are in a region with a data protection authority, you also have the right to complain to it.
| Data | Why we hold it |
|---|---|
| Account identity: email address, and name if you provide one | To create and secure your account, and to sync your data across devices |
| Financial records you create: accounts, balances, transactions, categories, budgets, savings goals, recurring payments, investments, notes and tags | This is the product. It is stored so it is available to you on any device you sign in to |
| Settings: language, currency, theme, sound and haptics preferences | To present the app the way you configured it |
| Bank message content, only if you switch on message sync | To read an amount and merchant out of a bank alert and turn it into a transaction. See section 4 |
| Subscription status | To unlock paid features. Handled by RevenueCat and your app store; we never see your card |
| Basic product events, such as when a paid feature limit is reached | To understand which limits users hit, so we can set them sensibly |
We do not collect your bank credentials. Safi never asks for your online banking username, password, PIN or card number, and has no connection to your bank.
Purchases are processed by Apple or Google, not by us. We receive only a confirmation of what you bought and whether it is still active, via RevenueCat. We never receive or store your payment card details. Manage or cancel a subscription in your app store account.
This feature is off by default and only runs after you explicitly turn it on and grant the relevant permission.
In both cases we look for an amount, a merchant and a date, create a transaction, and keep a short excerpt of the message so you can see why a transaction appeared. Messages that do not contain an amount are discarded. You can revoke the permission or the sync token at any time from Settings, which stops all further reading immediately.
When you ask the assistant a question, your question and the relevant slice of your financial data needed to answer it are sent to our AI provider, OpenRouter, which routes it to the underlying model. This is what makes an answer about your own spending possible. We do not permit your data to be used to train models. Do not send information you would not want processed by a third party. If you never use the assistant, none of your data goes to it.
| Processor | Purpose |
|---|---|
| Clerk | Sign in and account security |
| Convex | Database and backend hosting |
| RevenueCat | Subscription status |
| OpenRouter | AI assistant responses, only when you use it |
| open.er-api.com | Currency exchange rates. No personal data is sent, only currency codes |
| Apple, Google | App distribution and payment processing |
We do not sell your data, and we do not share it with advertisers.
Data is stored on our backend provider's infrastructure, which may be located outside your country. We keep your data for as long as your account exists. If you delete your account, your financial records are deleted. Backups are cycled out within 30 days.
Safi is not directed at children under 13, and we do not knowingly collect their data.
If we change this policy materially we will say so in the app before the change takes effect. The date at the top always reflects the current version.