Draft — pending legal review. Last generated from the app's actual data flows on 2026-09-21.
Cently Privacy Policy
This policy describes what Cently ("the app") collects, stores, and shares, and why. Cently is built around one rule: your bank SMS/notification text and full financial detail are parsed and stored on your device, never on a server, unless you explicitly turn on an opt-in feature described below.
What stays on your device, always
- Every transaction, account, budget, category, and note you create or that Cently captures from bank SMS/notifications.
- The original SMS/notification text is never written to disk anywhere, ever — only a one-way cryptographic hash is kept, solely to detect duplicate messages.
- Your local database is encrypted at rest using your device's own storage protections; a PIN/biometric app-lock is available in Settings.
What Cently reads from your phone, and why
- SMS (Android only, optional): read-only access to incoming bank SMS, used solely to detect and parse transaction messages on-device. You can decline this permission — Cently falls back to reading bank notifications instead (see below), or manual entry.
- Notification access (Android only, optional): used as a fallback capture path when SMS permission isn't granted or on builds that don't request SMS at all. Android delivers every notification to an app with this access; Cently checks each one on your device for a bank transaction. Anything that is not about money is discarded immediately: its text, its sender and its time are not stored. You can turn this access off at any time in Android settings or from the Privacy dashboard.
- iPhone: iOS gives no app access to your messages or to other apps' notifications. On iPhone you can paste or share a bank message into Cently yourself; it is read on your device the same way.
What is ever sent to Cently's servers, and what's in it
By default, nothing about your finances leaves your device. The following features are all off unless you turn them on, and each sends only what's described:
- Encrypted sync / Family vault (opt-in): if you sign in and enable sync, your data is encrypted end-to-end on your device before it's uploaded — Cently's servers store only opaque ciphertext and cannot read amounts, merchants, categories, or notes. Sync requires an email address (used only for a one-time login code) and issues a session token to identify your encrypted data blob.
- Ask Cently (opt-in, Pro): when enabled, each question sends the question as you typed it, your budget names and aggregate figures (e.g. "total spent in Food this month") to Cently's server, which passes them to Anthropic's Claude model to write the answer. This is encrypted in transit but not end-to-end, so it can be read by Cently's server and Anthropic in order to answer. Individual transactions, merchant names, notes, photos, account numbers and bank messages are never sent.
- Parser accuracy telemetry (opt-in, off by default): if enabled in the Privacy dashboard, sends aggregate counts of how bank-SMS parsing performed (e.g. "3 auto-added, 1 needs review") — never the message text, merchant, or amount.
- Anonymous usage statistics (PostHog, self-hosted; opt-in, off by default): only if you turn on "Anonymous usage statistics" in the Privacy dashboard. Event names with counts (e.g. "onboarding completed", "insight dismissed"), never amounts, merchants, notes or messages. Turning it off stops it immediately.
- Crash reports (Sentry; opt-in, off by default): only if you turn on "Send crash reports" in the Privacy dashboard. A report contains the error and where in the code it happened. User identity, HTTP request details, screenshots, and any run of 4+ digits or email address in the error text or breadcrumbs are removed before it leaves your device. No performance or session tracking.
- Billing (RevenueCat): contacted only once you open the Pro screen, buy, or restore a purchase. It receives an anonymous app user ID and your store receipt to confirm your subscription; your payment details stay with the app store and Cently never sees them.
- Help Cently learn a bank (optional, one message at a time): if a bank message isn't recognised you may choose to send its pattern. Every number and email is masked before you see it, you remove anything else personal, and nothing is sent until you confirm and tap Submit.
- Gold prices: if you track gold as an asset, the app fetches current gold prices for your currency. The request contains only the currency code.
Your controls
- The in-app Privacy dashboard (Settings → Privacy dashboard) shows exactly how many bytes have been sent to Cently's server this month, and toggles for every opt-in feature above.
- Delete everything (local): Settings → Privacy dashboard → "Delete everything" permanently erases every account, transaction, budget, and setting on this device.
- Delete your account (server-side): if you've ever enabled sync, the same screen lets you delete your encrypted sync data from Cently's servers as well. See "Account deletion" below.
Account deletion
If you have signed in for sync at any point, you can request full deletion of your server-held encrypted data at any time from Settings → Privacy dashboard → "Delete my Cently account". This is irreversible and removes your synced op-log, vault key material, and any snapshot from Cently's servers immediately. If you never enabled sync, there is no server-side account to delete — everything already lives only on your device, and "Delete everything" (above) is the complete equivalent.
Data retention
Encrypted sync data persists on Cently's servers only for as long as your account exists. Crash reports and anonymous analytics events are retained per Cently's self-hosted PostHog and Sentry project retention settings (to be finalized before launch).
Children's privacy
[Placeholder — Shan/legal to confirm the intended minimum age and add the relevant clause; Cently does not knowingly target or collect data from children.]
Changes to this policy
If this policy changes materially, the update will be reflected on this page with a new generation date.
Contact
[Placeholder — Shan to add a real support/contact email before this goes live.]