Perfinance Privacy Policy
Version 1.0 — Effective and last updated August 1, 2026
This Policy explains how Perfinance (“Perfinance,” “the application,” “the service,” “we,” or “us”) processes information in the Perfinance iOS application, the website at perfinance.carfloapps.com, and related support services during the current demo/pre-release phase.
1. Scope and important summary
Perfinance is a personal-finance organization tool. It does not connect to bank accounts, ask for online-banking credentials, or collect payment-card numbers. You decide whether information entered in the app is real, approximate, or fictional.
Financial information is kept on your device by default. Cloud synchronization and external artificial-intelligence features are separate, optional functions. The app requires an account, but declining cloud sync or AI processing does not prevent use of non-AI, local-only functions.
2. Information we process
Depending on the features you choose, we process:
- Account and profile data: Supabase authentication ID, email address, display name and authentication-provider information made available through Sign in with Apple or Google. We also keep language, settings, onboarding state, legal and consent versions, and timestamps.
- Financial and user content: transactions, income, expenses, amounts, dates, descriptions or merchants, notes, accounts and account names, categories, budgets, saving goals and contributions, private savings, shared expenses, participant names, currency and financial-month settings, reports, summaries, import candidates, and AI-generated results you decide to save.
- Selected files and speech: images, photographs, PDFs, CSVs, and Excel files you select for import; extracted text and parsed candidate records; microphone audio handled through Apple speech services; and transcripts you choose to submit to Smart Voice.
- Subscription and purchase data: App Store product, entitlement and transaction identifiers, RevenueCat customer identifier (based on your account ID), subscription status, country/currency and price information made available by Apple or RevenueCat. We do not receive your complete payment-card details.
- AI service data: feature name, request and idempotency identifiers, model/provider identifiers, token or AI Unit estimates and actual use, status, timing, safe error codes, and quota balance. Perfinance’s database is designed not to store AI prompts, model responses, or raw financial content in these accounting records.
- Technical and security data: server request data that infrastructure providers may record, such as IP address, timestamps, authentication details, app/OS version, device or network metadata, response status and security logs. If Sentry is enabled in a production build, it may receive scrubbed crash/error and diagnostic information; default personal-information collection, screenshots, view hierarchy, performance tracing and session tracking are disabled in Perfinance’s configuration.
- Communications: the email address and content you send to support, privacy or legal addresses, plus delivery and security metadata maintained by email providers.
- Website data: request, IP, browser/device, security and delivery logs and strictly necessary cookies that Cloudflare or the host may use. The legal site is not intended to use advertising or behavioral analytics cookies.
We found no advertising SDK, cross-app tracking SDK, advertising identifier use, bank connection, remote-push token collection, or public user-content publishing in the launch implementation. Notifications are scheduled locally on the device.
3. Local storage and optional cloud sync
Financial data is stored as files in the app’s iOS sandbox. Perfinance does not add a separate application-level encryption layer to those files; it relies on iOS sandbox and device security protections. Face ID or device authentication can restrict the Private Savings interface, but this is not a separate encrypted vault.
If you enable cloud sync, Perfinance uploads structured financial data to Supabase so it can synchronize across devices signed in to your account. This includes the financial categories listed above, including Private Savings and participant names. Cloud sync is available to Free and Pro users, with different limits shown in the app. It is account-wide.
If you disable cloud sync, the app first preserves the device copy and requests permanent deletion of synchronized financial rows from the cloud. If the deletion request cannot finish, the app records a retry and keeps sync disabled locally. Re-enabling sync uploads remaining local records again.
Signing out removes account-scoped local data from that device. Deleting the app or losing a device can permanently destroy local-only data. Keep your own backups or enable sync if this risk is unacceptable. A copy may remain on another device until that device signs out, loses authorization, or its local app data is removed.
4. Imports and temporary files
Local import may create a temporary app copy and extracted text. Parsed candidates remain on the device while you review them. Finishing or canceling removes temporary files on a best-effort basis; records you accept become financial transactions.
For an AI-assisted import, the selected original is uploaded through Perfinance’s Supabase backend to private temporary storage and then sent, or converted and sent, to Google Gemini. Images may be sent inline; spreadsheet text may be sent in chunks; PDFs may use Google’s file service. Perfinance requests deletion after processing or cancellation and does not offer permanent document storage. Interrupted or abandoned processing can delay cleanup until operational cleanup runs. Provider security/abuse copies and logs are governed by provider terms.
Request/session metadata may remain for quota, abuse prevention, integrity and dispute handling. It may identify file type, count, processing state, storage path while active, token use and timestamps, but is not intended to store the original document or prompt content.
5. Artificial intelligence and speech
External AI is optional and requires a separate consent. It is available only to users who affirm they are at least 18. Declining leaves non-AI functions available.
Data varies by feature:
- AI chat may receive the question and, after a per-request disclosure, selected transactions, amounts, dates, types, descriptions, categories, accounts, budgets, aggregates and related context needed for the question.
- Insights may receive financial summaries, limited transaction samples, category and trend aggregates, budgets, goals and shared-expense aggregates. Private Savings and transaction notes are excluded by implementation.
- AI import receives the selected file or its extracted content and returns candidate records for your review.
- Smart Voice sends the transcript and category context after consent. Apple’s speech-recognition service may process microphone audio even when Smart Voice is not used.
Requests go from the app to Perfinance’s Supabase Edge Functions and then to the Gemini Developer API. Direct account identifiers such as your name, email, password and Perfinance user ID are intentionally excluded from AI prompt context, but descriptions, documents or participant names can themselves contain personal data.
Google’s treatment depends on the production Cloud project and billing status. Under Google’s current terms, paid Gemini API content is not used to improve Google products, although limited abuse-monitoring retention may apply; unpaid-service content may be used to improve products and reviewed by humans. Perfinance must verify that its production API project has active billing before launch. Until that is confirmed, do not submit sensitive, confidential or third-party information to AI functions.
AI and speech results can be wrong, incomplete, outdated or misleading. Review and correct every import and result. They are not financial, accounting, tax, investment or legal advice.
6. Purposes
We use information to authenticate users; provide local storage, synchronization, imports, reports and requested AI results; manage subscriptions and entitlements; enforce quotas; restore purchases; secure and troubleshoot the service; prevent fraud and abuse; keep required consent and deletion evidence; communicate with users; comply with law; and establish or defend legal claims.
Where consent is legally required, optional cloud sync and external AI processing rely on the consent shown in the app and may be declined. You may withdraw cloud consent by disabling sync. AI consent can be avoided by not using AI; contact us to exercise applicable rights. Other processing is necessary to provide the account/service you request, meet legal obligations, or protect legitimate security and legal interests, as applicable.
7. Providers and international processing
We use or expect to use:
- Supabase: authentication, database, Edge Functions, private temporary file storage and optional cloud synchronization.
- Apple: iOS, App Store distribution, Sign in with Apple, speech recognition, in-app purchases, billing, refunds and subscription management.
- Google: Sign in with Google, on-device ML Kit components, and Gemini external AI processing.
- RevenueCat: subscription customer, purchase-status and entitlement management.
- Sentry: conditional crash/error diagnostics only when a release is built with a Sentry DSN.
- Cloudflare: website DNS, hosting/delivery and security, subject to final production configuration.
- Zoho Mail: mailbox hosting, subject to final production configuration.
- Resend: transactional email delivery, subject to final production configuration.
These providers have their own terms and privacy notices. Processing can occur in Mexico, the United States and other countries where providers or subprocessors operate. Those countries may have different protections. We use service configuration, contracts and security controls appropriate to the service and applicable law; we do not promise that data remains exclusively in Mexico.
We may also disclose information when required by law, to protect users or service security, in connection with a lawful transfer of the service, or with your direction. We do not sell or rent personal information, display third-party ads, use financial data for behavioral advertising, or share data for cross-context behavioral advertising.
8. Retention and deletion
- Local data remains until you delete it, sign out, remove the app, or otherwise clear it.
- Cloud financial data remains while cloud sync is enabled and is hard-deleted when sync is disabled or the account is deleted, subject to completion/retry and infrastructure backups.
- Original import files are temporary as described above; accepted parsed records remain until you delete them.
- Account/profile data remains while the account is active. Account deletion removes authentication, profile and financial rows from active systems and anonymizes the base user record.
- Limited legal-consent, AI-consent, deletion, subscription, purchase and AI-usage/accounting events may remain after deletion where needed for legal evidence, accounting, fraud prevention, service integrity and disputes. Some current audit records retain an authentication UUID; Perfinance is reviewing minimization of that identifier.
- Support/legal communications, provider logs and backups remain only as needed for their operational, security, legal and restoration purposes and then are deleted or de-identified under the applicable schedule.
Maximum schedules for billing, AI accounting, audit, support, delivery, infrastructure logs and backups are being finalized before production publication. See provider notices for provider-controlled retention. We do not use deleted cloud financial data as an archival user document.
To delete your account, use the in-app deletion flow. This does not cancel an Apple subscription; cancel separately in Apple subscription settings. Apple and RevenueCat may retain transaction records. Other devices may retain local copies as described above.
9. Your choices and rights
You can edit/delete financial records, decline or disable cloud sync, decline AI processing, manage local notifications in iOS, manage/cancel subscriptions through Apple, and delete your account in the app.
Depending on applicable law, you may request access, correction, deletion, opposition/objection, restriction, portability, or withdrawal of consent. In Mexico these include ARCO rights. Email contact@carfloapps.com with your request, the right requested, enough information to identify the account, and a description of the relevant data. We may securely verify identity and may deny or limit a request where law permits or requires. We will respond within applicable legal periods. You may complain to the competent privacy authority.
California and other U.S. residents may request applicable access, correction and deletion rights and information about disclosures. Perfinance does not sell or share personal information for cross-context behavioral advertising and will not discriminate for exercising applicable privacy rights.
10. Security
We use authentication, access controls, row-level security, private storage, transport encryption and provider security controls. No system is perfectly secure. Protect your device, Apple/Google account and sign-in session, and do not submit information you are not authorized to process.
11. Age
Perfinance is not designed specifically for children. The general service is for people age 13 or older. A minor must have parent/legal-guardian authorization where applicable. External AI features are restricted to people age 18 or older due to provider terms. Contact us if you believe a child provided data contrary to this Policy.
12. Changes
Material changes may be announced in the app and can require acceptance or acknowledgment of a new version. The effective date above identifies this version. Spanish and English versions are intended to be substantively equivalent; mandatory legal interpretation rules remain unaffected.
Contact
For questions or requests related to Perfinance, you may use the following contact channels:
- Support: support@carfloapps.com
- Privacy and personal data: contact@carfloapps.com
- Legal matters: legal@carfloapps.com