Kakebo: Budget + AI
Privacy Policy

Last updated: 2026-07-24

1. Introduction

Kakebo is a personal-finance app developed by Aurélien Ribon, an individual developer operating under the brand "Auline" ("we", "our" or "us"). We are the data controller for the personal data processed through the app. We place great importance on protecting the privacy of our users ("you" or "user"). This Privacy Policy explains what data we collect, why, how it is processed, where it is hosted, and the rights you have over it. It complies with the EU General Data Protection Regulation (GDPR).

2. Data we collect

2.1. Financial entries

When you record an expense or income, we store the details you provide (date, amount, category, label, recurrence and related flags) so you can access them later and sync them across your own devices. Each account's data is stored in its own file, independently from other users' data.

2.2. Account information

Your account is identified by your email address. There is no password. We also store a random, app-generated device identifier (called "icode" — this is NOT a hardware, advertising or tracking identifier), your app version, the account creation date, the last day the app was used, and your subscription tier. We also keep your custom expense categories and your saved AI prompts.

2.3. Voice dictation audio

If you use voice dictation, the audio is recorded on your device and sent to our server, which forwards it to Mistral AI for transcription. The audio is processed in memory only and is never stored on our servers. The resulting transcript and the expense details extracted from it are processed solely to create the corresponding expense.

2.4. AI usage metering

To enforce the monthly AI credit included with your plan, we keep monthly counts and the cost of your AI calls. This is fair-use metering data, not the content of your conversations.

2.5. Personal API key

If you use the optional "AI connections" feature, we store the personal REST API key you generate so external AI tools of your choice can access your data through our API.

2.6. Diagnostic logs

To operate and debug the service, we keep diagnostic logs of errors and technical events. These logs may include the device identifier, your email address, the app version and the platform (iOS or Android). They are stored on AWS CloudWatch and automatically deleted after 30 days.

2.7. What we do NOT collect

We do not use any analytics or tracking SDK, we serve no advertising, we run no third-party crash-reporting SDK, and we collect no browsing or behavioral analytics. We never sell your data.

3. How we use your data

We process your data solely to provide the service: to store your entries and sync them across your devices, to power the AI features you request, to identify your account and manage your subscription, to enforce the monthly AI credit, and to keep the service secure and working (diagnostics and debugging). We do not use your data for advertising or profiling.

4. AI processing

Voice transcription is powered by Mistral AI, a French provider (EU). The other AI features (the chat assistant, expense extraction and AI comments) are powered by OpenAI's API. To answer your requests, the relevant expense data (amounts, categories, labels and dates) is included in the requests sent to OpenAI. Under both providers' API terms, data submitted through the API is not used to train their models. OpenAI is based in the United States; see section 6 for how this transfer is covered.

5. Third-party processors

We rely on a limited set of processors, each acting on our behalf for a specific purpose: We do not use any other processors, and in particular no analytics, advertising or tracking providers.

6. Hosting and international transfers

Your account and app data are hosted in the European Union: financial entries in AWS S3 and settings, categories and prompts in AWS DynamoDB, both in region eu-west-3 (Paris). Our application server runs on an OVH VPS in France. The only transfer outside the EU is to OpenAI in the United States for AI processing; this transfer is covered by appropriate safeguards, namely OpenAI's Data Processing Addendum and the EU Standard Contractual Clauses.

7. Data security

We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure or destruction. Because your account has no password and is identified by your email, and because a personal API key grants full access to your account's data, you are responsible for keeping access to your email inbox and any generated API key secure.

8. Retention and deletion

We keep your data for as long as your account is in use. You can delete your account and its data directly from the application settings, or by contacting us at support@auline.cc. Diagnostic logs are automatically deleted after 30 days.

9. Your rights

In accordance with GDPR, you have the following rights: To exercise any of these rights, please contact us at support@auline.cc. You also have the right to lodge a complaint with your local data protection authority.

10. Consent

By using the application, you consent to the collection and use of your data as described in this Privacy Policy. You can stop all further data collection by not using the AI and sync features and by uninstalling the application; to have your stored data deleted, contact us at support@auline.cc.

11. Changes to this Privacy Policy

We may modify this Privacy Policy from time to time. Any changes will be published on this page with an updated date. We encourage you to review this page regularly to stay informed.

12. Contact

If you have any questions or concerns about this Privacy Policy or the processing of your personal data, please contact us at support@auline.cc.