Privacy policy

Your numbers are yours.

What we collect, what we do with it, and what we never do.
Effective July 28, 2026 · applies to the benji app and benji.cash
No bank logins
benji never connects to your bank. You type your numbers in.
Never sold
Your data is not sold and not shared with advertisers.
Encrypted, isolated
Stored encrypted. One account can never read another's data.
Delete anytime
One tap in Settings removes your account and data.
01

Who we are

benji is operated by benji (benji.cash) ("we", "us"). This policy explains what we collect, how we use it, and the choices you have. Questions? hello@benji.cash.

02

What we collect

  • Account details. Your email address and sign-in credentials, handled securely by our authentication provider.
  • The financial information you enter. Income, spending, savings, debts, goals, and your answers to benji's questions. You type these in yourself.
  • Basic technical and security data. Device type, app version, and the logs needed to keep the service running and secure. We briefly process your network address for abuse prevention; rate-limit records store only a one-way hash and expire automatically. Logs do not record your financial values.
  • Subscription status. Whether you have an active benji Premium subscription, so we know which features to unlock. Apple processes the payment; we never see your card number.
03

How we use it

  • To compute and show your stage, your plan, and your next move. Calculations run on our systems.
  • To generate an optional live chat reply, but only after you explicitly allow the named AI processor. The data can include your question, up to 12 recent messages, and plan context such as age, income, spending, savings, debts, goals, holdings, insurance, dependents, and risk preferences.
  • To run the service: sign-in, syncing between your devices, and abuse prevention.
  • To manage subscriptions. Purchases are handled by Apple and our subscription partner, RevenueCat, which receive your purchase status and a random account id, never your financial figures.
04

Your live-AI choice

Launch status: Live third-party AI is disabled for this release. benji's standing, next-move, and plan-recap answers run from your plan on your device, and benji does not transmit your question, chat history, or financial plan context to an AI processor. The controls below describe the consent boundary that must be active before live AI can be enabled in a later release.

Before the first live AI request, benji names every third party in the active processor chain and explains the information it would receive. Nothing is sent until you choose Allow and send. That action creates an authenticated, server-held grant for your account, limited to live chat and the exact processor, model, and routing receipt. The public configuration receipt is not permission by itself. Choosing Not now keeps the question on your device and leaves the rest of benji available. You can revoke the account grant in Settings → Data → AI data sharing. benji keeps the local marker until the server confirms revocation, so the app never falsely says sharing stopped. A processor or approved model configuration change always requires a new choice.

Our production allowlist supports only these disclosed processors: Anthropic; Google for Gemini; Groq; or OpenRouter together with Google for Gemini through Google AI Studio. The active chain is identified in the consent screen. For the OpenRouter chain, requests are pinned to Google AI Studio only, with provider fallback disabled, required request parameters enforced, and data-collecting provider routes denied. The server blocks live AI unless the configured provider, HTTPS endpoint and path, model, and routing policy exactly match this approved inventory. We require commercial API terms and settings that do not use benji customer content to train general-purpose models; limited provider retention may still occur for security, abuse prevention, or legal compliance under the provider's commercial terms.

Purpose boundary: The live-chat grant applies only when you deliberately send a question in Chat. Complete Your Picture remains deterministic and on-device in this release; it does not reuse chat permission for adaptive AI questions.

05

What we never do

  • Sell your data.
  • Share your financial information with advertisers.
  • Send your financial values to analytics tools.
  • Connect to your bank. We can't. There is no connection.
06

Where your data lives

Your data is stored with our database provider, Supabase, encrypted in transit and at rest. Access is isolated per account: row-level security means one user's data is never readable by another.

07

Deleting your data

Delete your account in the app (Settings → Delete account) or follow the data deletion steps. Deletion removes your account and stored financial data from production systems. Backups expire within 30 days.

08

Your rights

Depending on where you live, you may have rights to access, correct, export, or erase your personal data. Email hello@benji.cash and we'll respond within 30 days.

09

Children

benji is not directed at children under 13, or the higher minimum age in your country, and we do not knowingly collect their data.

10

Changes & contact

If this policy changes, the date above updates and material changes are announced in the app.

benji · benji.cash · hello@benji.cash