Privacy note

What we store. The bank SMS your phone chooses to send us, the transactions we read out of them, your budget settings, and the weekly briefs written about your own numbers. Nothing else is collected.

What we never see. Your bank credentials or one-time passcodes — OTP messages are detected and dropped at the door, never stored. Card numbers are masked before storage.

Who can see raw messages. When a message can’t be read automatically, the app’s operator (Omar) reviews a masked copy to add support for your bank’s format — long numbers are reduced to their last two digits first. A masked sample may also be sent to Google’s Gemini AI to draft the parsing rule; Google retains such requests for abuse monitoring for up to 55 days. Weekly briefs are generated by the same AI from your own totals, on a paid tier configured not to train on your data.

How long. Unreadable and declined messages are deleted after 90 days. Transactions stay until you delete them or your account.

Where it lives. On servers in Frankfurt (EU).

Your rights. Settings → Download my data gives you everything as one file, including any samples drafted from your messages. Settings → Delete my account erases every row — and every outstanding sign-in — immediately and irreversibly.

Who else. No ads, no data sales, no third-party analytics. The beta is invite-only: nothing is collected from your phone before you are approved.

Questions: omardawoud@kanabco.net · v2 — 1 Sep 2026

← Back to sign in