Privacy Policy

Safi. Last updated 4 August 2026.

Safi is a personal finance app. This policy explains what we collect, why, who we share it with, and how you can get it back or delete it. We have tried to write it in plain language rather than legal boilerplate.

1. Who we are

Safi is operated by [LEGAL ENTITY NAME], [ADDRESS]. For any privacy question or request, contact [PRIVACY EMAIL]. If you are in a region with a data protection authority, you also have the right to complain to it.

2. What we collect

DataWhy we hold it
Account identity: email address, and name if you provide one To create and secure your account, and to sync your data across devices
Financial records you create: accounts, balances, transactions, categories, budgets, savings goals, recurring payments, investments, notes and tags This is the product. It is stored so it is available to you on any device you sign in to
Settings: language, currency, theme, sound and haptics preferences To present the app the way you configured it
Bank message content, only if you switch on message sync To read an amount and merchant out of a bank alert and turn it into a transaction. See section 4
Subscription status To unlock paid features. Handled by RevenueCat and your app store; we never see your card
Basic product events, such as when a paid feature limit is reached To understand which limits users hit, so we can set them sensibly

We do not collect your bank credentials. Safi never asks for your online banking username, password, PIN or card number, and has no connection to your bank.

3. Payments

Purchases are processed by Apple or Google, not by us. We receive only a confirmation of what you bought and whether it is still active, via RevenueCat. We never receive or store your payment card details. Manage or cancel a subscription in your app store account.

4. Bank message sync

This feature is off by default and only runs after you explicitly turn it on and grant the relevant permission.

In both cases we look for an amount, a merchant and a date, create a transaction, and keep a short excerpt of the message so you can see why a transaction appeared. Messages that do not contain an amount are discarded. You can revoke the permission or the sync token at any time from Settings, which stops all further reading immediately.

5. The AI assistant

When you ask the assistant a question, your question and the relevant slice of your financial data needed to answer it are sent to our AI provider, OpenRouter, which routes it to the underlying model. This is what makes an answer about your own spending possible. We do not permit your data to be used to train models. Do not send information you would not want processed by a third party. If you never use the assistant, none of your data goes to it.

6. Who else processes your data

ProcessorPurpose
ClerkSign in and account security
ConvexDatabase and backend hosting
RevenueCatSubscription status
OpenRouterAI assistant responses, only when you use it
open.er-api.comCurrency exchange rates. No personal data is sent, only currency codes
Apple, GoogleApp distribution and payment processing

We do not sell your data, and we do not share it with advertisers.

7. Where your data is held and for how long

Data is stored on our backend provider's infrastructure, which may be located outside your country. We keep your data for as long as your account exists. If you delete your account, your financial records are deleted. Backups are cycled out within 30 days.

8. Your rights

9. Children

Safi is not directed at children under 13, and we do not knowingly collect their data.

10. Changes

If we change this policy materially we will say so in the app before the change takes effect. The date at the top always reflects the current version.

11. Contact

[PRIVACY EMAIL]