Privacy Policy
Last updated: March 22, 2026
Cappybara ("we", "our", or "the app") is a personal expense tracking app that scans Thai bank transfer slips. Your privacy is important to us. This policy explains what data we collect and how we use it.
1. Data We Collect
Transaction Data: When you scan a bank slip or manually add a transaction, we store the amount, date, destination name, bank name, category, and notes. This data is stored locally on your device.
Account Information: If you sign in with Apple, we receive your Apple User ID and optionally your name and email. This is used solely for cloud sync authentication.
Google Account (Optional): If you connect Google Sheets, we request access to create and write to a single spreadsheet in your Google Drive. We do not access any other files in your Drive.
2. How We Use Your Data
- Display your transaction history and spending summaries within the app
- Sync transactions to our cloud server (optional, requires sign-in)
- Export transactions to a Google Sheet you own (optional, requires Google sign-in)
3. Data Processing
On-Device OCR: Bank slip scanning is performed entirely on your device using Apple's Vision framework. Your bank slip images are never uploaded to any server.
Cloud Sync: If you sign in, transaction data (amounts, dates, categories — not images) may be synced to our server hosted on Cloudflare. This is optional.
4. Google API Services
Cappybara's use of Google API services adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only request the minimum scopes needed:
spreadsheets(to create and write to your expense sheet) anddrive.file(to share the sheet with our sync service) - We do not use Google user data for advertising or any purpose other than providing the expense tracking features you requested
- We do not transfer Google user data to third parties except as necessary to provide the app's features
- We do not use Google user data to train AI or machine learning models
5. Data Sharing
We do not sell, rent, or share your personal data with third parties. We do not serve ads. We do not use analytics or tracking services.
6. Data Retention
Your transaction data is stored locally on your device. If you use cloud sync, data is retained on our server until you delete your account. You can delete all server-side data by signing out and contacting us.
7. Data Security
All communication between the app and our server uses HTTPS encryption. Authentication tokens are stored in iOS Secure Storage (Keychain).
8. Children's Privacy
Cappybara is not directed at children under 13. We do not knowingly collect data from children.
9. Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.
10. Contact
If you have questions about this privacy policy, contact us at: jeffjirapat@gmail.com