Pigni Privacy Policy
Pigni is local first. This policy explains which information is processed only on your device, and which information is sent to Apple, a third-party AI service you configure, or another necessary service when you choose to enable an online feature.
1. Information We Process
Your ledgers are stored on your device by default. Information you enter or import may include amounts, currencies, dates and times, merchants, categories, accounts, notes, tags, budgets, refund or reimbursement relationships, transaction candidates, and import records.
When you use screenshot recognition, the app processes the photos or bill screenshots you select, OCR text, and recognition results. When you use voice bookkeeping, it processes recordings and transcribed text. The app also stores feature settings, AI model configurations, membership status, and structured diagnostic logs that exclude transaction content, amounts, merchants, images, prompts, and keys.
When you submit feedback, the app sends your feedback text, app and operating system versions, device type, and language and region. Contact details, screenshots, and structured diagnostics are sent only if you choose to include them. Structured diagnostics contain only fixed stages, results, anonymous correlation IDs, durations, and approximate counts. They exclude ledgers, amounts, merchants, accounts, screenshot content, original OCR text, AI prompts or responses, URLs, and keys.
2. Local Storage and System Permissions
Camera, photo, microphone, speech recognition, notification, and Face ID / Touch ID permissions are requested only when the relevant feature needs them. You can withdraw them in system settings; doing so may make the corresponding feature unavailable. The app receives only whether biometric authentication succeeded, not your biometric templates.
Where your region, operating system, and the app's signing capabilities support it, the FinanceKit transaction picker provides the app with only the transactions you explicitly select for that operation. Pigni stores them as local candidates awaiting confirmation. It does not automatically post them to a ledger, send them to a Pigni server, or retain the original FinanceKit account identifiers. If you separately enable iCloud backup, these saved transaction candidates may be included with other candidate records in the backup.
Third-party AI API keys are stored only in the local Keychain and are used to authenticate with the selected service. They are not included in model message content, ledger exports, or iCloud backups. You can remove a key when deleting its model configuration. Spotlight indexing is off by default; when enabled, it stores only merchants, categories, and dates in the on-device index.
3. AI and OCR
Third-party AI is optional and off by default. The app sends a data type to third-party AI only after you configure and enable a model, the model and request endpoint fall within the permitted scope below, and you turn on that specific data type in Me → Privacy & Security → Data & Privacy. You can also reach this page through AI Models → AI Recognition Settings. Access does not require membership, so you can review recipients or withdraw consent at any time. Enabling a data switch provides ongoing consent for subsequent uses of the same feature type. Some features in the foreground also show the data scope and ask for confirmation before that operation sends it. When you upgrade to this version, earlier AI authorizations become invalid. You must review the current scope and actively authorize it again.
The app retains presets for Alibaba Cloud Model Studio (dashscope.aliyuncs.com), DeepSeek (api.deepseek.com), Zhipu Open Platform (open.bigmodel.cn), Kimi Open Platform (api.moonshot.cn), SiliconFlow (api.siliconflow.cn), and Volcengine Ark (ark.cn-beijing.volces.com), as well as custom Base URL configurations. Presets do not include a developer account or API key, enable data authorization, or send data automatically. **Only the verified scope below may receive your financial content in this version. Other models, presets, and custom routes may retain their configurations and keys and run capability tests using app-generated synthetic content, but cannot receive your financial content.** Saving or enabling a connection, retrieving a model list, or passing a capability test does not remove this restriction.
- Recipient service and operator: Alibaba Cloud Model Studio, operated by 通义云启(杭州)信息技术有限公司 (Tongyi Yunqi (Hangzhou) Information Technology Co., Ltd.).
- Exact models: `qwen3.7-flash` and `qwen3.7-flash-2026-07-15`, supporting the text and image-pixel inputs described in this section. Other models in the same family or whose names start with `qwen` are not thereby permitted.
- Request endpoint: `POST https://dashscope.aliyuncs.com/compatible-mode/v1/chat/completions`, a general-purpose real-time inference API. This scope excludes Coding Plan, Token Plan, third-party marketplace models, other regions, and forwarding addresses.
- Processing region: API inputs and outputs enter and are stored in Beijing; inference is deployed within mainland China. This does not mean every inference runs only in Beijing.
- Public sources: the Model Studio Service Agreement, effective September 2, 2026; the exact model documentation; and the Beijing access and deployment scope. Pigni reviewed these sources on September 8, 2026.
Within this general-purpose API scope, Model Studio processes data under the agreement and request instructions. Delegated processors are bound by purposes and instructions, and data is not used for model training without authorization. Processing required by law or regulators may still occur. This scope does not include additional authorizations or special agreements that change data-processing purposes. When Pigni learns of changes to applicable terms, the model supplier, or the processing scope, it will review the affected route again rather than continuing to permit it based solely on a model name or saved configuration.
Implicit context caching for ordinary Chat requests is automatic and cannot be disabled. It has no uniform fixed retention period; the provider periodically clears caches that have not been used for a long time. Records needed for the service or required by law may also be retained. Correction or deletion can be requested under the service agreement, but legal, security, or backup-related technical restrictions may prevent immediate removal of some copies. A short expiry for explicit caching is not a maximum retention period for all data. Pigni's withdrawal switches cannot delete data the provider has already received. You can contact Pigni for help with rights requests as described in Section 7.
Settings show the selected recipient's provider name, Base URL, model, and protection scope. For features that support automatic fallback, enabling “Automatically try fallback models after failure” allows the same authorized data to be sent only to listed fallback models that still fall within the permitted scope in this section. Unverified routes cannot receive it as fallbacks. A custom Base URL identifies only the direct request endpoint; it does not establish the operator behind it, onward forwarding, or the processing region. An address or a successful connection alone therefore does not enable financial-data sending.
The switches may allow the following data to be sent for the following purposes:
- Automatic category suggestions in the app: the transaction type, the first 240 characters of the merchant or summary, and the first 1,200 characters of locally normalized source text, to suggest a category. Images and recordings are not sent.
- Manual text parsing: the complete text you enter or paste for that operation, to extract transaction candidates. Images and recordings are not sent.
- Screenshot OCR text: text extracted on the device from the screenshot you select, to extract transaction candidates. The original image is not sent.
- Screenshot image: the screenshot you select is re-encoded on your device, and its original GPS/EXIF metadata is removed before its image pixels are sent for visual recognition. Visible content may include merchants, times, amounts, order numbers, accounts, or payment methods. If safe re-encoding fails, the app does not send the image. This route does not silently send local OCR text as a substitute for the image.
- Voice bookkeeping transcript: the complete transcript for that operation, to extract transaction candidates. Third-party AI does not receive recordings or audio files.
- File import text: for PDF, TXT, and Markdown (.md) files, the complete text extracted from the entire file, to extract transaction candidates. The original file is not sent. Structured imports, including CSV, XLS, XLSX, JSON, and Pigni backups (.fmbackup), are processed locally and are not sent to third-party AI.
- Shortcut text: the shortcut input you provide, text extracted by on-device OCR, or text recognized for a pickup code, to extract transactions or pickup codes. Original images are not sent.
- Shortcut image: the image supplied for that shortcut operation is re-encoded on your device and its original GPS/EXIF metadata is removed before its image pixels are sent for visual recognition. If safe re-encoding fails, the image is not sent.
- Financial question-and-answer explanations: only intent codes, currency codes, fact counts, and up to eight numeric values, to turn locally calculated results into a natural-language explanation. The original question, merchants, accounts, images, original OCR text, and recordings are not sent.
To parse data according to your settings, the requests described above may also include your configured prompt templates and JSON Schema, category names and keywords, and the applicable default currency and date. The app does not put third-party AI API keys in business message content, ledger exports, or iCloud backups. Report summaries are processed locally and are not sent to third-party AI.
Text and vision capability tests use only synthetic content generated by the app. They do not read your ledgers, screenshots, recordings, imported files, or financial text you have entered. Tests still send authentication credentials and necessary request information to the configured service. Passing a test demonstrates only that the capability worked for that test; it does not establish verified protection or permission to send financial data.
Turning off a data switch stops requests of that type that have not yet been sent, including retries and fallback model requests. Deferred tasks recheck the authorization version, recipients, routing, and protection scope before sending. Turning a switch back on does not resume old tasks; you must start the operation again. Creating, editing, enabling, or disabling a provider, changing model routing, or changes to recipients or protection scope invalidate existing authorization and unfinished old tasks. You must review the new scope in Data & Privacy and authorize it again. Re-enabling a switch cannot permit an unverified route to receive financial data. Turning off a switch cannot recall data already received by a third party; its retention and deletion remain subject to applicable terms and legal exceptions.
Pigni is responsible for checking the operators and applicable API terms of the third parties it connects to, including data purposes, security, retention, deletion, further sharing, and cross-border processing, and for requiring recipients to provide the same or equivalent protection for shared data as required by this policy and applicable app review rules. Reading terms, saving a configuration, or enabling a switch expresses your informed choice for a specific operation. It does not replace Pigni's verification of protection or require you to guarantee a third party's conduct. Reviewing public sources is not an independent security audit or Apple approval. You can leave external AI disabled and continue using basic on-device features. If the selected vision model or route is unavailable, the app explains its unavailability and any applicable local processing; it does not silently describe OCR text processing as visual recognition of the original image.
4. iCloud Backup
iCloud backup is off by default and is an optional membership feature. When enabled, the app can save ledgers, candidate records, accounts, categories, rules, preferences, and AI configurations without API keys to Apple CloudKit according to your actions or settings. This is a backup, not real-time merging between multiple users.
Source screenshots are not included in new iCloud backups. Source images stored on your device can be removed within the safeguards provided in Ledgers & Data → Storage. Turning off automatic backup stops future automatic uploads; it does not delete existing cloud backups. Older backups that included source screenshots are not automatically deleted when you turn off the switch. On the iCloud Backup page, you can delete all LedgerSnapshot cloud backups. Deletion does not require an active membership or automatic backup to be enabled, and it does not delete your local ledgers. CloudKit data is processed by Apple infrastructure and is subject to your Apple ID, iCloud settings, and Apple's terms.
5. Other Online Services
- Depending on your device, operating system version, and availability, Apple speech recognition may send audio or transcription requests to Apple for processing.
- Membership purchases, purchase restoration, and subscription status are handled through Apple StoreKit. The app does not obtain your full payment card details.
- When you look up an exchange rate, Frankfurter receives only the original currency, ledger currency, and selected date. It does not receive amounts, merchants, notes, accounts, screenshots, or OCR text.
- Feedback is sent over HTTPS to a server operated by the app's operator, to address issues, notify the developer, and display replies. The feedback interface does not require an app account. The server uses an irreversible identifier for the network source to apply rate limits and prevent abuse.
- Local notifications are scheduled by the operating system. Exporting and sharing happen only when you initiate them. Once a file leaves the app, the destination application or storage location you select is responsible for it.
6. Purposes and Sharing Boundaries
We process information only for bookkeeping, recognition, analysis, search, backup, subscription verification, security, diagnostics, and exports you explicitly request. The app does not integrate advertising tracking SDKs, sell personal information, or build advertising profiles from ledger content.
Ledger content is not provided to recipients other than the Apple services and exchange-rate service listed in this policy, third-party AI routes permitted under Section 3 and explicitly authorized by you, export destinations you actively select, and the operator's own server receiving content you choose to include when you voluntarily submit feedback, unless disclosure is legally required.
7. Retention, Deletion, and Withdrawal
Local data is generally retained until you delete its records or clear or remove the app's data. Some deleted transactions remain briefly in Recently Deleted as explained in the app. The system may retain Keychain keys after the app is uninstalled. Please delete or clear them in AI model settings first.
Up to 20 feedback history entries are stored on your device. Feedback and attachments on the server are used only for customer support, replies, security, and abuse prevention, and are retained for a maximum of 180 days by default. You can delete a feedback entry and its server records, attachments, and public replies through the app's feedback history, or request deletion using the contact details in this policy. After deletion, a minimal deletion record may be retained for up to 30 days to complete interrupted cleanup and ensure repeated deletion requests are handled consistently. It excludes feedback content and the original client capability identifier.
You can view, correct, export, and delete ledger data in the app, turn off iCloud backup, Spotlight, notifications, third-party AI models, or any AI data switch, and withdraw system permissions in system settings. Turning off AI data switches stops future sending. Data already received by a third-party service remains subject to that service's retention, use, and deletion rules.
To exercise rights such as access, copying, correction, deletion, restriction of processing, or withdrawal of consent, please contact us using the details on this page. For data already sent to third-party AI, Pigni will help direct your request to the applicable recipient, explain necessary identity verification and information needed to locate the request, and inform you of the outcome or why it could not be completed. Requests remain subject to legal retention requirements, other people's lawful rights, and applicable technical limitations. Deleting local data, withdrawing consent, or submitting a request does not itself mean all remote records and backups have been deleted.
8. Security Measures
The app uses the system sandbox, Keychain, an optional biometric lock, and a privacy cover while in the background to reduce the risk of unauthorized access. No storage or transmission method can guarantee absolute security. Please protect your device, Apple ID, and third-party service keys.
9. Children
The app is not primarily intended for children under 14. If you are under 14, use it with a guardian's consent and guidance. If you discover that relevant information has been processed without guardian consent, please contact the operator.
10. Cross-Border Processing
In this version, third-party AI may receive financial data only within the Beijing access and storage and mainland China inference scope in Section 3. Synthetic capability tests for other configurations or custom addresses may be processed outside mainland China, but cannot include your financial content. A Base URL or provider name alone does not establish the underlying processors or regions. Before making a future route involving cross-border financial-data processing available, the operator must verify its recipients and protection scope, provide specific disclosure, and meet any applicable requirements for separate consent or other conditions. Saving an overseas address does not automatically enable such a route. You can leave external AI disabled.
11. Updates and Contact
If features or processing practices change materially, we will update this policy and notify you through in-app notices or other reasonable means. Where renewed consent is legally required, we will request it again.
Personal information controller: Chentao Fan Privacy contact: xxxkkk0101@foxmail.com