Privacy notice
In effect from 5 August 2026 · Applies to the Intendente app for iOS and to intendente.net
In short. Your ledger is stored on your device. If you switch synchronisation on, it is also stored in your own private iCloud database. It is stored nowhere else, and on no server of ours. The AI features send out only what a single request needs, and that processing runs on Microsoft Azure, on OpenAI models hosted by Microsoft, in the data region that matches you. The European Union is currently the only region in service, so every request is processed within the EU.
Where your data is stored
Everything you record (expenses, income, categories, budgets, savings goals) is written to a local database on your device. No server operated by us receives it or stores it. Removing the app removes the data.
If you turn synchronisation on, a copy is mirrored into the private CloudKit database of your own Apple account. It sits inside your own iCloud storage quota, under Apple's terms and Apple's encryption. Nobody else can read it, including us: we hold no key and have no access path to it. Its purpose is letting you find your ledger again on another device of yours. You can switch synchronisation off at any time, and doing so deletes that copy.
Receipts are not retained, not even on the device. What a model reads from a receipt is stored as merchant, amount, date and individual lines. The original file stays where it already was, a photo in your library or a PDF among your files, and the app keeps no copy of it.
What leaves the device, and when
Only the AI features send anything out. Each one sends only the information that specific request needs. The ledger as a whole is never transmitted.
| What is sent | When | Purpose |
|---|---|---|
| The sentence you type or dictate to record an entry | When you use AI capture | Turning it into merchant, amount, date and category |
| The photo or PDF of a receipt | When you have one read | Reading the total and the individual lines |
| One month of the ledger: one line per merchant, with amount and category | Once a month, if you open the written report | Producing the monthly report |
| The text of a single entry, roughly 30 words | In the background, when an entry is created or edited | Producing the numeric vector that makes search by meaning work |
| The phrase you are searching for | On each search by meaning | Matching it against those vectors |
Where it is processed
Requests do not go from the app straight to a model. They are received by a service of ours (the “relay”), which checks that you are signed in and hold a current subscription, then forwards the request. The relay stores neither the content of requests nor the responses. It records one thing: how many requests an account has made in the current month, so that a single account cannot exhaust capacity shared by everyone.
The models themselves are OpenAI models hosted by Microsoft inside Microsoft Azure, through the Azure OpenAI Service.
- Requests are not sent to OpenAI. Microsoft is the processor. The models run inside Microsoft's infrastructure under Microsoft's terms, and under those terms the data is not used to train models.
- Processing stays in your region. The deployments used are EU Data Zone deployments, so both the computation and the storage happen inside the European Union. The European Union is currently the only region in service, so this applies to every user. If other regions are added, requests will be processed in the region matching the user, and this page will be updated before that happens.
Your account
An account exists to unlock the AI features and to establish which subscription applies. It does not synchronise your data. That is iCloud, which is separate and runs through Apple.
Accounts are held in AWS Cognito, in the Ireland region, so the account list stays inside the European Union. Three things are held about you, and nothing else:
- an account identifier;
- an email address;
- a count of AI requests for the current month, kept against that identifier.
If you use “Sign in with Apple” together with “Hide My Email”, the address we receive is Apple's forwarding alias rather than your real one. That works: to us the address functions as an identifier. A confirmation code is emailed to you when you register with an email address and a password. Nothing else is ever sent to you.
Subscriptions
Purchases are handled by Apple. We never see, receive or store your payment details. What reaches us is a receipt signed by the App Store stating which subscription is active and until when, and its signature is checked against Apple's certificate chain.
Who else is involved
These are the parties that process anything on our behalf. There are no others, and none of them receives your ledger.
| Who | What they handle | Where |
|---|---|---|
| Apple | The iCloud copy of your ledger, in your own private database; subscription purchases; app distribution | Per Apple's terms |
| Microsoft (Azure, Azure OpenAI) | Runs the relay, and runs the models that process AI requests | European Union |
| Amazon Web Services (Cognito) | Holds the account identifier and email address | Ireland |
How long it is kept, and how to delete it
- Your ledger is kept until you delete it. Erase the ledger from the app's settings, or delete the app, and it is gone from the device.
- The iCloud copy is kept until you switch synchronisation off, which deletes it, or until you delete it from your Apple account.
- Request contents are never kept: the relay does not store them.
- The monthly request count is held against the current month and is not used for anything else.
- Your account is kept until you ask for it to be deleted. Deleting it removes the identifier, the email address and the request count.
What this app does not do
- No analytics SDK, no advertising SDK, no third-party crash reporting, and no third-party code of any kind inside the app.
- No advertising identifier, no device fingerprinting, no cross-app or cross-site tracking.
- No profiling, no automated decision-making with legal effects, and no sale or sharing of data with anyone.
- No bank connection. Bank credentials are never requested and could not be used.
- No access to contacts, location, health data, or other apps' data. The only permissions requested are the camera and the photo library, and only at the moment you photograph or choose a receipt.
- The website sets no cookies and carries no analytics, which is why it asks you for nothing.
Legal basis, and your rights
Under the GDPR, the account and the AI features are processed to perform the contract you enter into by using them. The monthly request count rests on legitimate interest: keeping shared capacity available to the people who paid for it.
You have the right to access, rectify, erase, restrict and object to processing, and the right to data portability. Most of these need nobody but you, because the data is already on your device: exporting, correcting and erasing your ledger all happen inside the app. Requests about the account are answered within 30 days. You can also complain to your national supervisory authority.
Children
Intendente is not directed at children and is not intended for use by anyone under 16. No data is knowingly collected from them.
Changes to this notice
If what is described here changes, whether that is a new processor, a new region or a new category of data, this page is updated and its effective date changes with it. Material changes are announced in the app before they take effect.
Data controller
Lucio Grimaldi, Italy. Write to privacy@intendente.net to exercise any of the rights above, including deletion of your account.