Privacy Policy

Privacy Policy — AI Money

Effective date: July 22, 2026

This Privacy Policy describes how CuentaTe (“we,” “us,” or “our”), represented by Daniela Maria Cardona, collects, uses, shares, and protects your information when you use our mobile application, AI Money (the “App”). CuentaTe acts as the data controller of your personal data.

AI Money is a personal finance tracking and organization tool (a personal ledger), not a wallet or payment service: the App never moves money or executes transactions. When you see the word “logged,” it means the entry was recorded in your ledger, not that a payment was “made.”

We are committed to protecting your privacy. By using the App, you agree to the collection and use of information in accordance with this policy and, where the law requires it, we ask for your explicit consent before enabling sensitive features.

1. Information We Collect

To provide a personalized financial experience, seamless authentication, and AI-powered features, we collect specific types of data.

A. Information You Provide to Us

  • Account Information: you can use the App anonymously or create an account. When you register or sign in via email/password, Google, Apple, or Facebook, we collect your name and email address to create and manage your account. Authentication is handled through Firebase Authentication (Google).
  • Profile & Preferences: we store preferences in our cloud database, such as your financial goals, country, default currency, AI preferences, avatar (emoji or photo), language, and timezone.
  • Custom Categories: the names and icons of your custom categories may be stored in the cloud to stay consistent across devices when you have AI Money Cloud or the WhatsApp integration enabled (see Section 7).
  • Financial Data & AI Queries: your detailed transaction ledger, debts, and loans are stored locally on your device by default and are never sent to our servers. When you actively choose to use our AI assistant, we send your name and the specific date-range transactions you select to our AI service to fulfill your request.
  • Phone Number (WhatsApp): if you opt to link your account with our WhatsApp assistant, we store your phone number in our cloud so messages you send the bot can be routed to your account.
  • Taxes Lead Data (Colombia): only if you expressly authorize it (see Section 6), we store your name, phone, email, and country so our accounting team can contact you.
  • Communications and Feedback: when you contact us for support, feedback, or suggestions, we may collect your name, email, and the contents of your message or attachments, solely to respond to you and improve the App.

B. Information Collected Automatically

  • Device Identifiers: we collect device IDs (such as the Advertising ID) for advertising and analytics services.
  • Usage Data: screens viewed, taps, and events, to understand usage and improve the experience (Firebase Analytics).
  • Diagnostics & Crashes: we collect crash data, non-fatal errors, and performance data to improve stability (Firebase Crashlytics). These reports do not include your transactions.
  • Coarse Location: your IP address may be used to estimate your general location (city/country) for analytics and advertising. We do not collect precise GPS location.
  • Camera and Photo Library: with your permission, you may capture or upload images of receipts to log expenses (see Section 3).
  • Microphone and Voice: with your permission, you may dictate expenses or talk to the assistant (see Section 3).

C. Automatic Transaction Capture (optional, only with your permission)

The App offers features that detect financial movements to save you manual entry. All are off by default and require you to grant explicit operating-system permissions; you can revoke them at any time in your device or App settings:

  • Bank SMS (Android only): if you enable it and grant the RECEIVE_SMS/READ_SMS permissions, the App reads your banks’ SMS messages and sends the message content to our AI service (OpenAI) to extract the transaction. Only the resulting structured transaction is saved.
  • Bank and payment notifications (Android only): if you enable the notification listener (BIND_NOTIFICATION_LISTENER_SERVICE), we read notifications from your banking and Google Pay apps and send their text to OpenAI for the same purpose.
  • Apple Pay / Google Pay: via iOS Shortcuts or the Android notification listener, payment alerts are processed in the background and their content is sent to OpenAI to extract the transaction.

Be aware that in these features the text of the SMS, notification, or payment alert —which may include amounts, merchants, and partial account details— leaves your device to our backend and OpenAI solely to extract the transaction. We do not store the original message: only the structured transaction (amount, category, title, date).

2. How We Use Your Information

  • Functionality & Authentication: verify your identity, manage your account, and sync your preferences across devices.
  • AI Features: generate financial insights from the data you provide or the captures you authorize.
  • Multi-Device Sync (Optional): if you enable AI Money Cloud (Pro), keep your transactions and categories synchronized.
  • Subscriptions: manage your AI Money Pro plan and entitlements.
  • Advertising: display ads that allow us to offer the App for free.
  • Analytics & Improvement: analyze usage trends, fix crashes, and improve performance.
  • Taxes (Colombia): if you authorize it, connect you with our accounting team.

3. AI Processing of Receipts, Voice, and Documents

Receipts: when you capture or upload a receipt photo, the image is encoded and sent to OpenAI (gpt-4o, vision) via our Cloud Function to extract amounts, dates, and merchant. We do not perform on-device OCR.

Voice: your operating system’s speech recognizer (Apple on iOS, Google on Android) converts your voice into text; then only the text —not the audio— is sent to OpenAI. That recognition is performed by your OS under Apple’s or Google’s privacy practices, which may process the audio on their servers.

Scope of AI: data you send to OpenAI is processed strictly to generate the requested response or extract the requested transaction. Because we use their enterprise service, OpenAI does not use your personal or financial data to train their public models.

4. Third-Party Service Providers

We do not sell your personal data. We share data with trusted third-party providers required for the App’s operation:

  • OpenAI — AI service: powers the assistant and transaction extraction (chat, receipt vision, transcribed voice, SMS, notifications, payments, and WhatsApp messages). OpenAI Privacy Policy
  • Google / Firebase — cloud infrastructure: authentication (Firebase Auth), profile and (where enabled) transaction storage (Firestore), server logic (Cloud Functions), analytics (Firebase Analytics), and crash diagnostics (Firebase Crashlytics). Google Privacy Policy
  • RevenueCat — subscription management: manages your AI Money Pro subscription; receives an account identifier to link your subscription to your profile. RevenueCat Privacy Policy
  • Google AdMob — advertising: displays ads and may use device identifiers and coarse location. On iOS, we will ask for your permission via Apple’s App Tracking Transparency (ATT) prompt before any cross-app tracking. Google AdMob & Privacy
  • Meta (WhatsApp) — messaging: delivers our optional WhatsApp assistant; messages you send it pass through Meta’s infrastructure. WhatsApp Privacy Policy
  • Amazon Web Services (AWS): hosts the public exchange-rate table the App queries. These queries do not include personal data. AWS Privacy
  • Apple iCloud (iOS only): hosts the backups you initiate of your local data, under your control and Apple’s privacy practices. Apple Privacy

5. Couples Space (shared fund)

If you create or join a Couples Space, the App creates a shared common fund with the other person. In that shared space we store only: aggregated amounts and the movements of the common fund (who contributed, amount, currency, date, and title), together with your name and avatar, mirrored when you join.

We never share your accounts, balances, or your personal transactions. The source account of a contribution stays 100% local on your device and is never visible to the other person.

6. Colombia Taxes, reminders and Habeas Data

The Taxes section (available to users in Colombia or with COP currency) can help you find out whether you must file income tax and avoid missing the deadline. The «should I file this year?» guide and your deadline calculation are processed on your device and are not sent to our servers.

Each-season reminder (optional, with your authorization): if you turn on the «Notify me each season» switch, you will see and accept an explicit authorization. Only then do we store, in a restricted record, your name, phone (if you linked WhatsApp), email and country, together with the evidence of your authorization (the exact text you accepted, its version, language and date), so we can message you when the next season opens. This switch is off by default: if you don’t turn it on, we store none of this data.

Checking for someone else: if you check a third party’s deadline, that calculation is ephemeral and 100% on your device; we do not store their ID number, the date, or any of that person’s data.

Habeas Data (Law 1581 of 2012): you may access, update, rectify and delete your data, and revoke your authorization at any time —by turning off the switch or emailing servicios@cuentate.com—. Upon revocation we stop contacting you; we keep proof that the authorization existed while it was in force, as the law requires. If in the future we offer to have an accountant from our team contact you, that will likewise require your express authorization.

7. Data Storage and Retention

AI Money is local-first: by default your transaction ledger lives on your device and is never sent to our servers. You can enable cloud storage explicitly. The table below shows where each type of data resides based on your plan and integrations:

Your situationCategoriesTransactions (manual / in-app)Transactions via WhatsApp bot
Free, no WhatsApp linkedLocal onlyLocal only
Free, WhatsApp linkedLocal + cloudLocal onlyCloud (written by the bot)
Pro, AI Money Cloud OFFLocal onlyLocal onlyCloud (written by the bot, if WhatsApp linked)
Pro, AI Money Cloud ONLocal + cloudLocal + cloudCloud (written by the bot, if WhatsApp linked)

AI Money Cloud (Pro)

Pro subscribers can enable AI Money Cloud, an optional service that backs up and syncs your transactions and categories across devices. It is off by default; you can toggle it in Profile → Data → AI Money Cloud.

WhatsApp Integration

When you link your number, we store in the cloud your number (international format), a linked flag, and your custom categories to classify messages. Messages you send the assistant (text, audio transcriptions, and images) are processed in real time; we do not store the raw messages, audio, or images: only the structured transaction, tagged with the source whatsapp.

Retention Windows

  • Local data: retained on your device until you delete it or uninstall the App.
  • AI Money Cloud (Pro active): retained while your subscription is active.
  • AI Money Cloud after Pro ends: your cloud copy is preserved for 6 months as a grace period; then non-WhatsApp transactions are removed automatically. Bot-created transactions are preserved while your account is active and your number stays linked.
  • If you disable AI Money Cloud manually: your copy is preserved for 30 days and then removed; you can re-enable within that window to cancel removal.
  • iCloud backup (iOS): governed by Apple’s practices; we never read your iCloud.
  • WhatsApp data: if you unlink, your number is removed from your profile; bot transactions remain as historical records.
  • Taxes lead: retained for the duration of the advisory season or until you revoke your authorization.
  • Diagnostics and analytics: retained in aggregate per Firebase retention policies.
  • Account deletion: you may request deletion of your account and all cloud data from Profile → Account. Local data is removed by uninstalling the App.

8. International Data Transfers

CuentaTe operates from Colombia, but our providers (OpenAI, Google/Firebase, RevenueCat, Meta, AWS, and Apple) process and store data primarily in the United States and other countries. By using the App and the features that send data to these providers, you understand that your information may be transferred outside your country of residence. Where required by law (e.g., the EU GDPR), these transfers rely on mechanisms such as Standard Contractual Clauses or other appropriate safeguards.

9. Security

We use commercially acceptable means to protect your information. All communication between the App and our servers or third-party services is encrypted using SSL/TLS. Cloud data is protected by security rules restricting reads and writes to the authenticated owner. No method of transmission over the internet is 100% secure.

10. Children’s Privacy

The App is not intended for children under 13 (or the minimum age your jurisdiction requires, e.g., 16 in parts of the EU). We do not knowingly collect data from children. If we discover that a child has provided us personal data, we will delete it immediately.

11. Your Data Rights (GDPR / CCPA / Habeas Data)

Depending on your jurisdiction, you have the right to:

  • Access the personal data we hold about you and learn how we process it.
  • Request correction or update of inaccurate data.
  • Request deletion of your account and cloud-stored data.
  • Revoke consents granted (AI, automatic captures, Taxes, advertising).
  • Opt out of personalized advertising via your device settings (and, on iOS, via ATT).
  • Port your data and object to certain processing.
  • Choose whether to enable cloud sync (AI Money Cloud) at all.

To exercise them, contact us at servicios@cuentate.com or use the “Delete Account” feature within the App.

12. Legal Bases for Processing (GDPR)

Where the GDPR applies, we process your data based on: your consent (AI features, SMS/notification/payment captures, WhatsApp, Taxes, personalized advertising), performance of a contract (account, subscription, sync), and our legitimate interest (security, diagnostics, and service improvement).

13. Changes to This Policy

We may update this Policy from time to time. We will post the new version on this page and update the effective date. You are advised to review it periodically.

14. Contact Us