Privacy Policy
Last updated 28 July 2026
OhKumbu is a personal finance app. It only works if you tell it about your money, so this page is specific about what that means: what is stored, who can see it, and what leaves our servers.
What we collect
- Account details — your email address, your name, and a hash of your password. We never store the password itself.
- What you enter — expenses, budgets, income sources, investments, debts, assets, goals, and the messages you send in the chat.
- Receipt images you choose to upload, kept so you can look at them again later.
- Preferences — default currency, timezone, and which notifications you want.
- A push token, if you allow notifications, so we can send your morning briefing.
What we do not collect
- Bank credentials. OhKumbu never connects to your bank and has no way to move money. There is nothing to hand over.
- Contacts, photos library, or location.
- Advertising identifiers. There are no ads in OhKumbu.
How your data is used
To run the app for you, and nothing else. Your data is not sold, rented, or shared for advertising. It is not used to train anyone's machine learning models.
AI processing
OhKumbu uses Anthropic's Claude API to read what you type, extract expenses from receipts, and write your briefings and monthly reports. To do that, the relevant parts of your financial information are sent to Anthropic's API at the moment the feature runs. Anthropic does not use API inputs or outputs to train its models. Your API requests are made from our servers — your device never holds an API key.
Other services we rely on
- DigitalOcean — hosting and encrypted backups.
- Sentry — crash reports. These are scrubbed before they are sent: no email addresses, no request bodies, no console logs. Errors are tagged with a numeric account id only.
- Expo push notification service — delivers notifications. It receives the notification text, so keep that in mind if you enable briefings.
- Frankfurter — public exchange rates. It receives currency codes only, never amounts.
- Resend — sends password reset emails.
Security
Traffic is encrypted in transit. Passwords are hashed with Argon2id. Access tokens expire after fifteen minutes and refresh tokens are revocable and stored in your device's secure keystore. The database and cache are not reachable from the public internet. You can require Face ID, Touch ID or your device passcode to open the app.
How long we keep it
Until you delete it. Deleting an expense removes it immediately. Deleting your account removes your expenses, budgets, financial profile, goals, chat history, receipts and tokens. Backups roll off within twelve months.
Your choices
- Export — Settings → Export as CSV gives you everything you've logged.
- Delete — Settings → Delete account removes your data. It is not recoverable afterwards.
- Notifications — every category can be turned off in Settings, or at the OS level.
Children
OhKumbu is not intended for anyone under 13, and we do not knowingly collect their data.
Changes
If this policy changes in a way that affects how your data is handled, we will say so in the app before the change takes effect.
Contact
Questions, or a request to see or delete your data: [email protected].