OhKumbu

Privacy Policy

Last updated 28 July 2026

OhKumbu is a personal finance app. It only works if you tell it about your money, so this page is specific about what that means: what is stored, who can see it, and what leaves our servers.

What we collect

What we do not collect

How your data is used

To run the app for you, and nothing else. Your data is not sold, rented, or shared for advertising. It is not used to train anyone's machine learning models.

AI processing

OhKumbu uses Anthropic's Claude API to read what you type, extract expenses from receipts, and write your briefings and monthly reports. To do that, the relevant parts of your financial information are sent to Anthropic's API at the moment the feature runs. Anthropic does not use API inputs or outputs to train its models. Your API requests are made from our servers — your device never holds an API key.

Other services we rely on

Security

Traffic is encrypted in transit. Passwords are hashed with Argon2id. Access tokens expire after fifteen minutes and refresh tokens are revocable and stored in your device's secure keystore. The database and cache are not reachable from the public internet. You can require Face ID, Touch ID or your device passcode to open the app.

How long we keep it

Until you delete it. Deleting an expense removes it immediately. Deleting your account removes your expenses, budgets, financial profile, goals, chat history, receipts and tokens. Backups roll off within twelve months.

Your choices

Children

OhKumbu is not intended for anyone under 13, and we do not knowingly collect their data.

Changes

If this policy changes in a way that affects how your data is handled, we will say so in the app before the change takes effect.

Contact

Questions, or a request to see or delete your data: [email protected].