Senta

Senta Privacy Policy

Effective date: 8 October 2026
Who we are: Senta is made by an independent developer ("we"). Questions: hi@davidodejobi.com.

The short version

What is stored on your phone

DataWhere
Transactions: amount, currency, converted amount and exchange rate, money in or out, merchant, category, note, dateSenta's database in the app's private storage
Savings goals and contributionsSame database
Receipt and screenshot images from confirmed capturesApp documents folder (receipts/)
Shares waiting to be read (text, or a copy of the image)Database and capture_queue/; removed once you confirm or dismiss them, or once they turn out not to be a transaction
Settings: display name, ledger currency, lock method and timeout, balance maskingApp preferences
This month's count of AI readsApp preferences
A random install ID (a UUID created on first use)App preferences
Cached exchange ratesApp preferences
App PINStored only as a salted SHA-256 hash in the iOS Keychain or Android secure storage; the PIN itself is never stored

Senta doesn't encrypt its database on top of your phone's own storage encryption. Protect your phone with a passcode, and use Senta's app lock (PIN or biometrics) if others use your phone.

Device backups

Senta doesn't exclude its data from device backups. If iCloud Backup (iPhone) or Google backup (Android) is on, your Senta data is included, and it may come back if you restore or reinstall. Those backups are held by Apple or Google under their terms, and you control them in your phone's settings. Senta never receives them.

What leaves your phone, and why

1. Senta AI (reading what you share)

You can share, paste or scan a bank alert, screenshot or receipt into Senta. Senta first reads it on the phone: Apple Vision on iPhone, Google ML Kit on Android, then Senta's own pattern reader. If that read is confident about both the amount and whether money came in or went out, nothing is sent.

Otherwise, and when you're online and within the free AI limit, Senta sends the following over an encrypted (HTTPS) connection to Senta's proxy server (Heroku, EU region):

A share made while you're offline or out of AI reads may wait on your phone and be sent automatically the next time Senta opens online.

There is no setting to turn Senta AI off. An entry you add by hand is never sent.

What the proxy does. It checks the request, passes the image or text and the currency code to the AI provider, and returns the provider's reading: whether it's a transaction, the amount, currency, money in or out, merchant, date, description, source type and confidence. You review and confirm every transaction before it's saved. The proxy doesn't send your install ID or your IP address to the AI provider.

What the proxy keeps. It doesn't store the image or the text. Its application logs record, for each request: a random request ID, the input type (image or text), the size in bytes, the image format, the currency code, the AI provider and model, how long it took, and five fields from the result (whether it's a transaction, currency, money in or out, source type, confidence). For failed requests the logs record the error code. They don't record the image, the text, the amount, the merchant, the date, the description or the install ID. If the AI provider rejects a request, only the error status is logged, never the provider's message.

Like any web server, the proxy and its host (Heroku) see your IP address. Heroku's request logs include it, along with the time, path, status and timing. Log retention: Heroku keeps only recent logs, for up to about a week..

To enforce usage limits, the proxy counts requests per install ID and per IP address (each per minute and per day), plus a global daily cap. These counters are held in memory only and never written to disk. Daily counts reset each UTC day, and everything is lost when the server restarts.

We use the proxy logs only to run Senta AI: to keep it working, investigate errors and abuse, and measure read quality in aggregate (for example, how often reads succeed and how confident they are). They're never used to identify you or build a profile.

The AI provider. In production the proxy sends the request through OpenRouter (openrouter.ai), which passes it to the company that runs the AI model we've chosen (we may change models over time). Google's Gemini API is kept as a backup provider. The provider receives the image or text plus the currency code, processes it under its own terms, and may keep it for a limited time (for example, for abuse monitoring) as those terms allow. We don't control that. OpenRouter processes data in the United States and says it does not store the content of requests by default. The model provider behind it handles the request under its own terms.

2. Exchange rates

To convert between currencies, Senta downloads public exchange rates from open.er-api.com, at most about once a day (they're cached on the phone). The request contains nothing about you or your money, but that service sees your IP address.

3. Google Play services text recognition (Android only)

On Android, Senta's on-device text reader is Google ML Kit, provided through Google Play services. Images are read on the phone. Google states that ML Kit sends Google: device information (such as manufacturer, model, OS version and build), the app's package name and version, per-installation identifiers, performance metrics, API configuration, event types and error codes, over HTTPS, and that it doesn't transfer this data to third parties. Google Play services may also download the text-recognition model. See Google's ML Kit data disclosure. On iPhone, Senta uses Apple's Vision framework, which runs entirely on the device.

4. What you choose to export

Export Transactions creates a CSV file and opens your phone's share sheet. Once you send the file somewhere, it's handled by that app or person, not Senta.

Crash reports and usage statistics

Two services help us fix bugs and understand which features get used. Senta has no advertising or tracking tools. Neither service ever receives:

Crash reports (Sentry). If Senta crashes or hits an unexpected error, it sends a crash report to Sentry (Functional Software, Inc.), which processes it for us.

Crash reports are on by default. To turn them off, go to Settings → Security & Privacy → Send crash reports. The change takes effect immediately.

Anonymous usage statistics (PostHog). Only if you agree, Senta sends anonymous usage events to PostHog (PostHog Inc.), on its servers in the EU. Senta asks once, and the answer stays "no" unless you tap Share.

You can change this anytime in Settings → Security & Privacy → Share anonymous usage data. Turning it off stops sending immediately and replaces the random ID.

Delete All Data replaces the usage-statistics ID and asks again before sending anything. Your crash-report choice is kept.

Both services see your IP address when data arrives but are set not to store it. Data is sent encrypted (HTTPS). Crash reports are kept for up to 90 days and usage events for up to 12 months.

The Google ML Kit data described above is the only other data a third-party SDK in the app sends.

Permissions

Senta doesn't read your notifications, SMS inbox or contacts, and never asks for your bank login.

Website analytics

Our website counts visits with PostHog (PostHog Inc.), on its servers in the EU. It records which page was opened, where the visit came from, your screen width, and whether the "Join the beta" buttons were used or the form was sent. It does not use cookies and stores nothing in your browser, and each visit gets a new random ID, so visits can't be linked to you or to each other. It never receives your email address. It is switched off if your browser sends Do Not Track or Global Privacy Control. PostHog sees your IP address when the data arrives but is set not to store it.

Joining the beta list

If you join the beta on our website, we store your email address, the phone type you choose (optional) and the time you signed up. We use them only to invite you to test Senta. The list is kept in Google Firebase (Cloud Firestore) in the EU (Europe multi-region), and only we can read it. We delete the list when the beta ends, or sooner if you ask. To be removed sooner, email us.

Keeping and deleting your data

Your rights

Your ledger is on your phone, so you can see, change, export or delete it yourself at any time. For questions about the proxy logs, or anything else in this policy, contact hi@davidodejobi.com. Because the logs don't contain your name, account or content, we may not be able to link a log entry to you.

You can ask us to give you a copy of any personal data we hold about you, to correct it, to delete it, or to stop using it, and you can withdraw your consent at any time (for example, switch off usage statistics in Settings). The data we hold is limited to the beta list, the server logs and the crash and usage data described above, so most of what you can ask about is that. We use your data on these grounds: your consent (usage statistics, the beta list), to run the service you asked for (reading what you share), and our legitimate interest in keeping Senta secure and fixing crashes.

If you think we have handled your data wrongly, please contact us first. You can also complain to your data protection authority. Your authority is the one in your country. If a breach puts your data at risk, we will tell the regulator within 72 hours and tell you if you are likely to be affected.

Senta is used in many countries. The services above run in different places: the beta list and PostHog in the EU, and OpenRouter in the United States. The proxy host and Sentry may also process data outside your country. Each provider is bound by its own data protection terms, such as standard contractual clauses. We do not sell or share your personal information for advertising.

Children

Senta is not directed at children under 16 and is intended for people aged 16 or over. We do not knowingly collect personal data from anyone under 16, and will delete it if we learn we have.

Security

Connections to Senta's server use HTTPS. Senta's AI provider key stays on the server and never ships in the app. The app PIN is stored only as a salted hash in the platform's secure storage. No system is perfectly secure; if we learn of a problem that affects you, we'll tell you through the app or the policy page.

Changes to this policy

We'll update this page and the in-app summary when Senta's handling of data changes, and change the effective date above.

Contact

Senta, an independent developer