Senta Privacy Policy
Effective date: 8 October 2026
Who we are: Senta is made by an independent developer ("we"). Questions: hi@davidodejobi.com.
The short version
- There is no Senta account and no Senta cloud sync. Your ledger is stored on your phone.
- If your phone backs up to iCloud or Google, your Senta data is included in that backup. You control that in your phone's settings. Senta keeps no copy.
- When Senta's on-device reader isn't sure about something you share, the image or text is sent through Senta's server to an AI provider to read. Senta's server doesn't store it. The AI provider handles it under its own terms.
- Senta has no ads and no tracking. Crash reports go to Sentry unless you turn them off. Anonymous usage statistics are sent only if you say yes. Neither ever includes your transactions or what you share.
- You can export your transactions, and erase your ledger, receipts and settings, from Settings.
What is stored on your phone
| Data | Where |
|---|---|
| Transactions: amount, currency, converted amount and exchange rate, money in or out, merchant, category, note, date | Senta's database in the app's private storage |
| Savings goals and contributions | Same database |
| Receipt and screenshot images from confirmed captures | App documents folder (receipts/) |
| Shares waiting to be read (text, or a copy of the image) | Database and capture_queue/; removed once you confirm or dismiss them, or once they turn out not to be a transaction |
| Settings: display name, ledger currency, lock method and timeout, balance masking | App preferences |
| This month's count of AI reads | App preferences |
| A random install ID (a UUID created on first use) | App preferences |
| Cached exchange rates | App preferences |
| App PIN | Stored only as a salted SHA-256 hash in the iOS Keychain or Android secure storage; the PIN itself is never stored |
Senta doesn't encrypt its database on top of your phone's own storage encryption. Protect your phone with a passcode, and use Senta's app lock (PIN or biometrics) if others use your phone.
Device backups
Senta doesn't exclude its data from device backups. If iCloud Backup (iPhone) or Google backup (Android) is on, your Senta data is included, and it may come back if you restore or reinstall. Those backups are held by Apple or Google under their terms, and you control them in your phone's settings. Senta never receives them.
What leaves your phone, and why
1. Senta AI (reading what you share)
You can share, paste or scan a bank alert, screenshot or receipt into Senta. Senta first reads it on the phone: Apple Vision on iPhone, Google ML Kit on Android, then Senta's own pattern reader. If that read is confident about both the amount and whether money came in or went out, nothing is sent.
Otherwise, and when you're online and within the free AI limit, Senta sends the following over an encrypted (HTTPS) connection to Senta's proxy server (Heroku, EU region):
- the image as shared (up to 8 MB), or the text (up to 4,000 characters). The image file is sent with any metadata it contains. For a photo, that can include when it was taken, the device, and sometimes location. Screenshots don't normally include location.
- your ledger currency code (for example
NGN), to help read ambiguous currency symbols - the random install ID, used only to limit how often each install can use Senta AI
A share made while you're offline or out of AI reads may wait on your phone and be sent automatically the next time Senta opens online.
There is no setting to turn Senta AI off. An entry you add by hand is never sent.
What the proxy does. It checks the request, passes the image or text and the currency code to the AI provider, and returns the provider's reading: whether it's a transaction, the amount, currency, money in or out, merchant, date, description, source type and confidence. You review and confirm every transaction before it's saved. The proxy doesn't send your install ID or your IP address to the AI provider.
What the proxy keeps. It doesn't store the image or the text. Its application logs record, for each request: a random request ID, the input type (image or text), the size in bytes, the image format, the currency code, the AI provider and model, how long it took, and five fields from the result (whether it's a transaction, currency, money in or out, source type, confidence). For failed requests the logs record the error code. They don't record the image, the text, the amount, the merchant, the date, the description or the install ID. If the AI provider rejects a request, only the error status is logged, never the provider's message.
Like any web server, the proxy and its host (Heroku) see your IP address. Heroku's request logs include it, along with the time, path, status and timing. Log retention: Heroku keeps only recent logs, for up to about a week..
To enforce usage limits, the proxy counts requests per install ID and per IP address (each per minute and per day), plus a global daily cap. These counters are held in memory only and never written to disk. Daily counts reset each UTC day, and everything is lost when the server restarts.
We use the proxy logs only to run Senta AI: to keep it working, investigate errors and abuse, and measure read quality in aggregate (for example, how often reads succeed and how confident they are). They're never used to identify you or build a profile.
The AI provider. In production the proxy sends the request through OpenRouter (openrouter.ai), which passes it to the company that runs the AI model we've chosen (we may change models over time). Google's Gemini API is kept as a backup provider. The provider receives the image or text plus the currency code, processes it under its own terms, and may keep it for a limited time (for example, for abuse monitoring) as those terms allow. We don't control that. OpenRouter processes data in the United States and says it does not store the content of requests by default. The model provider behind it handles the request under its own terms.
2. Exchange rates
To convert between currencies, Senta downloads public exchange rates from open.er-api.com, at most about once a day (they're cached on the phone). The request contains nothing about you or your money, but that service sees your IP address.
3. Google Play services text recognition (Android only)
On Android, Senta's on-device text reader is Google ML Kit, provided through Google Play services. Images are read on the phone. Google states that ML Kit sends Google: device information (such as manufacturer, model, OS version and build), the app's package name and version, per-installation identifiers, performance metrics, API configuration, event types and error codes, over HTTPS, and that it doesn't transfer this data to third parties. Google Play services may also download the text-recognition model. See Google's ML Kit data disclosure. On iPhone, Senta uses Apple's Vision framework, which runs entirely on the device.
4. What you choose to export
Export Transactions creates a CSV file and opens your phone's share sheet. Once you send the file somewhere, it's handled by that app or person, not Senta.
Crash reports and usage statistics
Two services help us fix bugs and understand which features get used. Senta has no advertising or tracking tools. Neither service ever receives:
- your transactions, amounts or balances;
- merchants, notes, categories or goals;
- the alerts, text or images you share, paste or scan, or what Senta reads from them;
- your name, your PIN, or any file names.
Crash reports (Sentry). If Senta crashes or hits an unexpected error, it sends a crash report to Sentry (Functional Software, Inc.), which processes it for us.
- A report holds the type of error and where in Senta's code it happened (a stack trace), plus the app version.
- It also holds basic device details: model, operating-system version, language and region, time zone, screen size, memory and storage.
- Before sending, Senta removes the error's message text, any record of what you did before the error, network details and file paths.
- Sentry also gets a random ID for this installation and when app sessions start and end, so we can measure how often Senta crashes.
Crash reports are on by default. To turn them off, go to Settings → Security & Privacy → Send crash reports. The change takes effect immediately.
Anonymous usage statistics (PostHog). Only if you agree, Senta sends anonymous usage events to PostHog (PostHog Inc.), on its servers in the EU. Senta asks once, and the answer stays "no" unless you tap Share.
- Events are labels such as "app opened", "capture started from a share", "capture saved; the merchant field was edited" or "app lock turned on with a PIN".
- Each event carries only those labels, the app version and basic device details: model, operating-system version, language, time zone, screen size and network type.
- Each install has a random ID that isn't linked to you.
You can change this anytime in Settings → Security & Privacy → Share anonymous usage data. Turning it off stops sending immediately and replaces the random ID.
Delete All Data replaces the usage-statistics ID and asks again before sending anything. Your crash-report choice is kept.
Both services see your IP address when data arrives but are set not to store it. Data is sent encrypted (HTTPS). Crash reports are kept for up to 90 days and usage events for up to 12 months.
The Google ML Kit data described above is the only other data a third-party SDK in the app sends.
Permissions
- Camera: to scan receipts and alerts when you choose to
- Photos: to pick a screenshot when you choose to
- Face ID / biometrics: to unlock Senta if you turn on the app lock
- Internet: for Senta AI and exchange rates
Senta doesn't read your notifications, SMS inbox or contacts, and never asks for your bank login.
Website analytics
Our website counts visits with PostHog (PostHog Inc.), on its servers in the EU. It records which page was opened, where the visit came from, your screen width, and whether the "Join the beta" buttons were used or the form was sent. It does not use cookies and stores nothing in your browser, and each visit gets a new random ID, so visits can't be linked to you or to each other. It never receives your email address. It is switched off if your browser sends Do Not Track or Global Privacy Control. PostHog sees your IP address when the data arrives but is set not to store it.
Joining the beta list
If you join the beta on our website, we store your email address, the phone type you choose (optional) and the time you signed up. We use them only to invite you to test Senta. The list is kept in Google Firebase (Cloud Firestore) in the EU (Europe multi-region), and only we can read it. We delete the list when the beta ends, or sooner if you ask. To be removed sooner, email us.
Keeping and deleting your data
- Delete a transaction: it's hidden from your ledger and totals, but its details and any receipt image stay on your phone until you use Delete All Data.
- Settings > Delete All Data: erases every transaction (including hidden ones), goal, receipt image, waiting share, temporary file, your PIN and all settings from the phone, then restarts Senta. It deliberately keeps the random install ID and this month's AI-read count (month and number), because without them deleting your data would reset the free AI limit and the server's per-install limits. It also keeps your crash-report choice, so an opt-out stays an opt-out.
- Not covered by Delete All Data: copies already in your iCloud or Google backup, and files you exported. Manage those yourself. (On iPhone, the share extension briefly keeps a copy of each image you share in a folder shared between the app and the extension. Senta deletes it once it has its own copy, and Delete All Data clears that folder.)
- Uninstalling Senta removes its data from the phone. On iPhone, the hashed PIN may stay in the Keychain after uninstalling.
- On the server: Senta keeps no copy of your ledger or of what you shared, so there's nothing for us to delete there apart from the logs and counters described above. Heroku keeps only recent logs, for up to about a week.
Your rights
Your ledger is on your phone, so you can see, change, export or delete it yourself at any time. For questions about the proxy logs, or anything else in this policy, contact hi@davidodejobi.com. Because the logs don't contain your name, account or content, we may not be able to link a log entry to you.
You can ask us to give you a copy of any personal data we hold about you, to correct it, to delete it, or to stop using it, and you can withdraw your consent at any time (for example, switch off usage statistics in Settings). The data we hold is limited to the beta list, the server logs and the crash and usage data described above, so most of what you can ask about is that. We use your data on these grounds: your consent (usage statistics, the beta list), to run the service you asked for (reading what you share), and our legitimate interest in keeping Senta secure and fixing crashes.
If you think we have handled your data wrongly, please contact us first. You can also complain to your data protection authority. Your authority is the one in your country. If a breach puts your data at risk, we will tell the regulator within 72 hours and tell you if you are likely to be affected.
Senta is used in many countries. The services above run in different places: the beta list and PostHog in the EU, and OpenRouter in the United States. The proxy host and Sentry may also process data outside your country. Each provider is bound by its own data protection terms, such as standard contractual clauses. We do not sell or share your personal information for advertising.
Children
Senta is not directed at children under 16 and is intended for people aged 16 or over. We do not knowingly collect personal data from anyone under 16, and will delete it if we learn we have.
Security
Connections to Senta's server use HTTPS. Senta's AI provider key stays on the server and never ships in the app. The app PIN is stored only as a salted hash in the platform's secure storage. No system is perfectly secure; if we learn of a problem that affects you, we'll tell you through the app or the policy page.
Changes to this policy
We'll update this page and the in-app summary when Senta's handling of data changes, and change the effective date above.
Contact
Senta, an independent developer