Kakebo: Budget + AI
Privacy Policy
Last updated: 2026-07-24
1. Introduction
Kakebo is a personal-finance app developed by Aurélien Ribon, an individual developer operating under the brand
"Auline" ("we", "our" or "us"). We are the data controller for the personal data processed through the app. We place
great importance on protecting the privacy of our users ("you" or "user"). This Privacy Policy explains what data we
collect, why, how it is processed, where it is hosted, and the rights you have over it. It complies with the EU
General Data Protection Regulation (GDPR).
2. Data we collect
2.1. Financial entries
When you record an expense or income, we store the details you provide (date, amount, category, label, recurrence
and related flags) so you can access them later and sync them across your own devices. Each account's data is stored
in its own file, independently from other users' data.
2.2. Account information
Your account is identified by your email address. There is no password. We also store a random, app-generated device
identifier (called "icode" — this is NOT a hardware, advertising or tracking identifier), your app version, the
account creation date, the last day the app was used, and your subscription tier. We also keep your custom expense
categories and your saved AI prompts.
2.3. Voice dictation audio
If you use voice dictation, the audio is recorded on your device and sent to our server, which forwards it to
Mistral AI for transcription. The audio is processed in memory only and is never stored on our servers. The
resulting transcript and the expense details extracted from it are processed solely to create the corresponding
expense.
2.4. AI usage metering
To enforce the monthly AI credit included with your plan, we keep monthly counts and the cost of your AI calls. This
is fair-use metering data, not the content of your conversations.
2.5. Personal API key
If you use the optional "AI connections" feature, we store the personal REST API key you generate so external AI
tools of your choice can access your data through our API.
2.6. Diagnostic logs
To operate and debug the service, we keep diagnostic logs of errors and technical events. These logs may include the
device identifier, your email address, the app version and the platform (iOS or Android). They are stored on AWS
CloudWatch and automatically deleted after 30 days.
2.7. What we do NOT collect
We do not use any analytics or tracking SDK, we serve no advertising, we run no third-party crash-reporting SDK, and
we collect no browsing or behavioral analytics. We never sell your data.
3. How we use your data
We process your data solely to provide the service: to store your entries and sync them across your devices, to
power the AI features you request, to identify your account and manage your subscription, to enforce the monthly AI
credit, and to keep the service secure and working (diagnostics and debugging). We do not use your data for
advertising or profiling.
4. AI processing
Voice transcription is powered by Mistral AI, a French provider (EU). The other AI features (the chat assistant,
expense extraction and AI comments) are powered by OpenAI's API. To answer your requests, the relevant expense data
(amounts, categories, labels and dates) is included in the requests sent to OpenAI. Under both providers' API terms,
data submitted through the API is not used to train their models. OpenAI is based in the United States; see section
6 for how this transfer is covered.
5. Third-party processors
We rely on a limited set of processors, each acting on our behalf for a specific purpose:
- OpenAI — AI processing (chat, expense extraction, AI comments). US-based.
- Mistral AI — voice transcription. France (EU).
- Amazon Web Services (AWS) — data storage and infrastructure, region eu-west-3 (Paris, EU).
- OVH — application server hosting, France (EU).
- RevenueCat — subscription management; receives only the random device identifier.
- Apple App Store & Google Play — payment processing for subscriptions; we never see your payment details.
We do not use any other processors, and in particular no analytics, advertising or tracking providers.
6. Hosting and international transfers
Your account and app data are hosted in the European Union: financial entries in AWS S3 and settings, categories and
prompts in AWS DynamoDB, both in region eu-west-3 (Paris). Our application server runs on an OVH VPS in France. The
only transfer outside the EU is to OpenAI in the United States for AI processing; this transfer is covered by
appropriate safeguards, namely OpenAI's Data Processing Addendum and the EU Standard Contractual Clauses.
7. Data security
We implement appropriate technical and organizational measures to protect your data against unauthorized access,
alteration, disclosure or destruction. Because your account has no password and is identified by your email, and
because a personal API key grants full access to your account's data, you are responsible for keeping access to your
email inbox and any generated API key secure.
8. Retention and deletion
We keep your data for as long as your account is in use. You can delete your account and its data directly from the
application settings, or by contacting us at support@auline.cc. Diagnostic logs are automatically deleted after 30
days.
9. Your rights
In accordance with GDPR, you have the following rights:
- Right of access: You can request access to the personal data we hold about you.
- Right to rectification: You can request correction of inaccurate or incomplete data.
- Right to erasure: You can request deletion of your personal data.
-
Right to restriction of processing: You can request limitation of data processing in certain circumstances.
- Right to object: You can object to the processing of your data for legitimate reasons.
- Right to data portability: You can request a copy of your data in a portable format.
To exercise any of these rights, please contact us at support@auline.cc. You also have the right to lodge a
complaint with your local data protection authority.
10. Consent
By using the application, you consent to the collection and use of your data as described in this Privacy Policy.
You can stop all further data collection by not using the AI and sync features and by uninstalling the application;
to have your stored data deleted, contact us at support@auline.cc.
11. Changes to this Privacy Policy
We may modify this Privacy Policy from time to time. Any changes will be published on this page with an updated
date. We encourage you to review this page regularly to stay informed.
12. Contact
If you have any questions or concerns about this Privacy Policy or the processing of your personal data, please
contact us at support@auline.cc.