Privacy Policy
Effective: 31 May 2026 · Last updated: 31 May 2026
The short version
- We never sell your data. Not to ads. Not to anyone. Ever.
- Your data is yours. You can export it any time and delete your account in one click.
- We collect only what's needed to give you the product — your accounts, transactions, goals, and AI conversations.
- Your data is encrypted in transit (TLS 1.2+) and at rest.
- We use OpenAI in two places. Capture: a receipt photo or voice note you record is sent to OpenAI to read the amount, date and merchant — this is how capture works, so it is not optional. AI Advisor is separate and opt-in; when you enable it, a snapshot of your finances is sent with each question. In both cases the data is used only to answer that one request and is not used for training.
- We comply with Malaysia's PDPA 2010. EU/UK users are covered by GDPR-equivalent rights.
Who we are
AI Money Compass ("we", "us") is a personal finance management application operated as a beta product. For the purposes of Malaysia's Personal Data Protection Act 2010 (PDPA), we are the data user. Contact: david95oo1@gmail.com.
What we collect
Account data: email, name, hashed password, optional 2FA secret.
Financial data you provide: bank accounts, transactions (manual + statement imports), commitments, goals, investment holdings, tax claims.
Third-party-sourced data (when you connect): moomoo positions + cash flow (via OpenD agent on your device), bank PDF/CSV statement contents you upload.
Usage data: server request logs kept for security and debugging. The iOS app contains no analytics, advertising or tracking SDKs — nothing about how you use the app is sent anywhere.
Capture: receipt photos and voice recordings you capture are sent to OpenAI to extract the amount, date and merchant. The audio is transcribed and discarded; the photo is read, not retained by OpenAI.
AI Advisor (if enabled): each prompt sent to OpenAI includes a snapshot of your finances at that moment. OpenAI does not train on this data per their enterprise terms.
How we use it
- Provide the service: render your dashboard, compute analytics, generate AI responses.
- Improve the service: aggregated, anonymised feature use only.
- Security: detect abuse, fraud, account takeover.
- Communications: critical service emails (password reset, security). Optional weekly digest (opt-in).
We do not: sell data, share with advertisers, use your data to train ML models, or hand over to third parties for marketing.
Sharing
Limited essential processors, each bound by data processing agreements:
- Supabase — database hosting (Tokyo region, AWS ap-northeast-1)
- Vercel — web hosting
- Cloudflare — DNS, DDoS protection
- OpenAI — reads receipt photos and transcribes voice notes you capture, and answers AI Advisor questions if you enable it. Per-request only; no training on your data
- Resend — transactional email delivery
Your rights
You can at any time:
- Access all your data — in the app, More → Account & data → Export my data (one-click JSON)
- Correct any field via the Records / Settings page
- Delete your account — in the app, More → Account & data → Delete my account. Hard-purge within 30 days.
- Restrict / object to processing — pause your account by emailing us
- Portability — the export is JSON, importable anywhere
- Withdraw consent for AI Advisor — turn it off in the web app under Settings. Capture-time processing can be avoided by entering transactions manually instead of by photo or voice.
Retention
Active account data: retained while account is active. Audit logs: 12 months. Backups: encrypted, 30 days rolling. After deletion: 30-day grace then hard-purged.
Security
Read our full security stance. TLS 1.2+ in transit · AES-256 at rest · bcrypt password hashing · row-level tenant isolation · session cookies HttpOnly+Secure+SameSite=Lax · login rate-limit · audit logging.
If you discover a vulnerability: david95oo1@gmail.com. We do not pursue good-faith researchers.
International transfers
Data is stored in Japan (Supabase, AWS ap-northeast-1, Tokyo). Content you send to OpenAI — captured receipts and voice notes, and AI Advisor prompts if you enable it — transits through OpenAI infrastructure in the US. Standard Contractual Clauses are in place.
Cookies
Strictly necessary: session cookie (Lax, HttpOnly, Secure). No advertising or analytics cookies.
Changes
Material changes notified in-app + email at least 14 days before taking effect.
Contact
This Privacy Policy is intended as a clear, plain-language statement. It is provided in good faith and reflects our actual practices. Where ambiguity arises, we will interpret in the user's favour.