This Privacy Policy applies to Kotori on iOS.
Data Processing
Kotori does not upload your financial data to the developer's servers.
Everything you record is processed locally on your device:
- Recording expenses you enter by voice, text, Siri, or Shortcuts
- Converting speech to text on-device (Apple Speech framework)
- Parsing and categorizing entries on-device, optionally accelerated by Apple Intelligence where supported
- Learning your categorization preferences locally — this learning data stays on your device
- Storing transactions, wallets, and categories locally (Core Data)
iCloud Sync
If you enable it, your ledger syncs across your own devices through your private iCloud account (Apple CloudKit). This data lives in your personal iCloud; the developer cannot access it.
Microphone & Speech Recognition
The microphone is used only while you are actively recording an entry. Audio is used for on-device speech recognition and is not sent to the developer.
Diagnostic Logs
Kotori can record diagnostic logs to help investigate problems with the app. This is off by default, and recording starts only after you turn it on yourself inside the app.
- Diagnostic logs contain nothing that points to you as a person. They hold no content from your entries (merchant names, amounts, notes), no speech transcripts, and no identifier tied to your iCloud account
- What they do hold is the app's internal activity (which operations ran, when, and where they failed) together with device-level details: your device model, iOS version, language and region, app version, and the app's operating environment (such as sync and Apple Intelligence availability)
- They also hold counts derived from your ledger (for example, how many entries a screen displayed, or how many were queued for sync or re-categorization) and the answer you gave to the tracking permission prompt (whether you allowed it). These are numbers and a yes-or-no answer only, never the content of the entries themselves (merchant names, amounts, notes)
- Kotori stores diagnostic logs only on this device, and does not send them to the developer's servers, or to any server
- Logs leave your device only when you export them and pick a recipient yourself — the app never sends them automatically
- There is no contact form or send button inside the app. Kotori only records and exports the file; whether to send it, and to whom, is entirely your decision
- The switch that turns diagnostic logging on and off, and the button that deletes what has already been recorded, both live on the Diagnostic Log page. To open it, go to the More tab and tap the Version row five times in a row; that page holds Export Log and Delete Log, so you can erase the logs yourself whenever you want
Diagnostic logs never grow without bound. They are capped in size (roughly 1–2 MB in total), and once the cap is reached the oldest entries are replaced by newer ones. No third-party crash-reporting or analytics SDK is included for this feature.
Third-Party Advertising
Kotori may display ads through Google AdMob where available. Google may collect:
- Device identifiers
- Coarse location derived from IP
- Ad interaction data
See Google's Privacy Policy for details.
European Users (EEA & UK)
If you are in the European Economic Area (EEA) or the United Kingdom, the following applies to you.
Consent for advertising. In the EEA and the UK, Kotori shows an in-app consent dialog provided by the Google User Messaging Platform (UMP). Personalized ads are served only after you give your consent; if you do not consent, ads are served in non-personalized or limited form, or may not be served at all. You can change or withdraw your consent at any time inside the app under More → Personalized Ads.
Data recipients. Advertising data is received and processed by Google AdMob and its certified advertising partners. See Google's Privacy Policy for details.
Your rights under the GDPR / UK GDPR. You have the right to:
- Access the personal data held about you
- Have inaccurate data corrected
- Have your data erased
- Restrict the processing of your data
- Receive your data in a portable format
- Object to the processing of your data
- Withdraw consent at any time — withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal
- Lodge a complaint with your local data protection supervisory authority
To exercise these rights, please use the contact form in the Contact section below.
Data Retention
- Your transactions and settings remain on your device (and in your iCloud, if sync is enabled) until you delete them or remove the app
- Diagnostic logs are different: they do not stay on your device indefinitely. They are capped at roughly 1–2 MB in total, and once the cap is reached the oldest entries are replaced by newer ones — they are not wiped on a schedule, so only the most recent activity is kept. You can also erase them yourself at any time with Delete Log on the Diagnostic Log page, and removing the app deletes the logs with it
- Advertising-related data is handled according to Google's own policies
Your Choices
- You can use the app entirely without voice by typing entries
- You can disable microphone, Siri, or iCloud access in system settings at any time
- Diagnostic logging is off by default and records only after you turn it on; you can turn it off again at any time. The switch, and the button that deletes logs already recorded, are on the Diagnostic Log page — open the More tab and tap the Version row five times in a row
- You can manage ad and privacy preferences through your device settings and any consent flow provided by the app or Google
Children's Privacy
Kotori is not directed to children under 13, and the app does not knowingly collect personal information from children.
Changes to This Policy
This Privacy Policy may be updated from time to time. The updated version will be posted with a revised date.
Contact
For privacy and personal-data inquiries (including requests to access, correct, or delete your data), please use this form.
Inquiries you send us (and the email address you provide, if any) are collected and stored via Google Forms to respond to your request.