Privacy Policy

Last updated: September 20, 2026 · Pinegrass Technologies Private Limited

This page describes information used by Ari, optional controls and ways to request access or deletion.

1. Information used by the service

2. Voice input and AI features

Voice input uses platform speech-recognition services. Depending on the operating system and recognizer, audio may be processed by that service; on-device-only processing is not guaranteed. Ari uses the resulting text to prepare a draft.

AI features may send your message and relevant recorded financial context to the configured AI provider, including DeepSeek or Gemini. Expense parsing applies pattern-based redaction to some sensitive strings, but this is not a guarantee that every identifying detail is removed. Do not enter PINs, OTPs, passwords or card credentials into notes or chat. AI drafts require review.

3. Optional product measurement

Measurement is off until you separately opt in. It records selected action names, opaque event identities, server receipt times, notification dispatch/acceptance/open times and verified billing lifecycle events. Billing measurement also stores a consent-scoped pseudonymous subscription reference, provider event time and available billing-cycle start/end times; it does not store raw provider subscription IDs. Measurement does not copy amounts, merchants, notes, recordings or message content. This first-party flow has no third-party analytics SDK or session replay.

Events expire after 90 days from receipt; notification markers expire 90 days from dispatch. Billing observations expire when either their provider event time or receipt time is 90 days old; expired cycle timestamps are cleared. Reports exclude expired history. Physical deletion occurs during maintenance or applicable ingestion/export operations. Your current consent identifier, start time and timezone remain until withdrawal. Expired activation timestamps are replaced by a flag, not a new activation.

Turn off “Help improve Ari” to erase retained measurement events, legacy counts and current consent state. A later opt-in creates a new consent period. Private Mode suppresses device measurement events; it does not withdraw account-level consent for server billing or notification processing. A staff/test exclusion marker, where applicable, remains until removed or the account is deleted.

4. Services involved

Depending on the enabled feature and deployment configuration, services include Supabase authentication/database, Railway backend hosting, Vercel website hosting, configured AI providers, Sentry diagnostics, Expo and platform notification services, Google sign-in, RevenueCat and app stores, Razorpay checkout, and a bank-linking provider such as Setu. A provider-hosted screen has that provider's own data handling and permission controls. This page does not assert a particular deployment region or unverified contractual safeguard.

5. Storage, access and deletion

Core account records remain until you remove them or delete the account. Measurement retention is described above. Billing/audit records, delivery deduplication records, service logs and provider backups have separate retention requirements and controls; contact support for the applicable details. A fixed backup-erasure deadline is not promised here.

Settings provides data export and account deletion. Deletion requires password reauthentication with the current flow; if that is unavailable for your sign-in method, contact support. The backend revokes refresh sessions before requesting account deletion. Successful primary-data deletion does not itself prove immediate removal from every backup or third-party system.

Local bills belong to the account on the current device. Confirmed deletion attempts to remove that local copy. Copies on another device or unattributed legacy device records may require separate removal. Export contents distinguish server data from locally available records.

6. Your controls and requests

You can edit supported records, change notification preferences, disable optional measurement, manage microphone/notification permissions in device settings, and use bank-provider permission controls. Contact starhunter7@gmail.com for access, correction, deletion or other privacy requests. We may need to verify account ownership. This description does not limit rights available under applicable law.

7. Contact and updates

Pinegrass Technologies Private Limited
starhunter7@gmail.com

Material changes are reflected in the update date. See also account deletion and Terms of Service.