This Privacy Policy explains how PT Kasankaf Digital Solution ("Kasankaf" or "we") processes your personal data when you use the Finanseal app on Android and iOS, the website https://finanseal.omnikaf.com and related services (together, "Finanseal").
For the processing described here, we are the Personal Data Controller under Law No. 27 of 2022 on Personal Data Protection (the "PDP Law") and its implementing regulations, including PP 33/2026. Financial data is specific personal data, so we hold it to a higher standard of protection.
1. Summary
- Finanseal is a record-keeping app. We don't hold or move money and don't connect to any bank account.
- Notifications are filtered on your phone. Anything not about money is dropped without being stored, and OTP codes are never sent anywhere.
- To read amounts and merchants, masked payment text goes to our AI provider (Anthropic, United States) only with your consent. Images are never sent.
- Your data is encrypted on your phone, on our servers, in backups and in transit.
- We don't sell your data, don't show ads, and don't use your data to train AI.
- You can access, correct, export (CSV) and delete your data, and withdraw consent at any time.
2. Who we are
Personal Data Controller: PT Kasankaf Digital Solution, Jakarta, Indonesia.
3. Data we process
Account data
Email address, name, username, language, time zone, how you sign in (Google, Apple or an email code) with the account identifier from Google or Apple, plan and trial status, and the consents you give.
Financial records
What you log or confirm in Finanseal: transactions (amount, date, merchant, category, notes, tags), accounts and wallets with the balances you enter, budgets, savings goals, debts and loans, recurring bills, and receipt photos you attach. This is specific personal data.
Captured payment text
Text from payment notifications (Android), screenshots and receipts (read by OCR on your phone), voice transcripts, and e-receipts you forward. See "Notifications, screenshots, receipts and voice" for details.
Device and technical data
A device identifier the app creates, platform, model, operating system and app version, push notification token, IP address and security logs, crash reports, and a count of AI feature use (counts, not content) for plan limits.
Product analytics
Only with your consent: app usage events (such as finishing onboarding or opening a recap), without amounts and without merchant names. Analytics run on our own servers.
Support and feedback
The messages you send, their topic, and your email if you include it.
Payments
Purchases are processed by Google Play or the App Store. We don't receive your card number or payment details; we only receive subscription status (product, validity, renewal) through RevenueCat.
4. Where data comes from
- From you, when you sign up, log entries or contact us.
- From your phone, with the permissions you grant (notification access, photos, microphone, camera).
- From Google or Apple when you sign in with them (email, name, account identifier).
- From Google Play, the App Store and RevenueCat for subscription status.
- From other members of a shared workspace, for the records they create in a workspace you belong to.
5. Purposes and legal bases
We only process data for the purposes below. Where a purpose needs consent, we ask for separate consent for each purpose.
| Purpose | Data | Legal basis |
|---|---|---|
| Providing your account, logging, syncing across devices, reports and exports | Account, financial records, device data | Performance of a contract (Terms of Service) |
| Automatic logging from payment notifications (Android) | Notification text that passes the on-phone filter | Explicit consent (can be withdrawn) |
| Reading amounts, merchants and categories with AI; Ask Sealy | Masked payment text; your questions and summaries of workspace data | Explicit consent (can be withdrawn) |
| Period summary email | Email, summary of the period | Consent (on by default, can be turned off any time) |
| Product analytics | Usage events without amounts or merchants | Consent (off by default) |
| Improving the on-phone notification filter | Masked text samples | Consent (off by default) |
| Promotional email | Email, language | Consent (off by default) |
| Subscriptions and plan access | Subscription status from the app stores | Performance of a contract |
| Security, abuse prevention, rate limiting | IP address, logs, device data | Legitimate interest and legal obligation |
| Customer support | Messages, email, related account data | Performance of a contract |
| Meeting legal and tax obligations and lawful requests from authorities | The data lawfully requested | Legal obligation |
6. Consent and how to withdraw it
You can see and change every consent at any time in Settings > Privacy & data in the app. Withdrawing consent doesn't affect processing that was lawful before you withdrew it.
Some features need a particular consent. For example, without AI processing consent, automatic logging still detects payments and reads the amount on your phone, and you fill in the merchant and category yourself.
7. Notifications, screenshots, receipts and voice
- Notifications (Android). With your permission, Finanseal sees notifications arriving on your phone. A filter on the phone scores each one by its amounts, finance words and app. Notifications below the threshold are dropped without being stored and never leave the phone.
- OTP codes and promos are blocked. OTP and verification codes, promos and ads are blocked on the phone even when they contain amounts, and are never sent. Notifications Android hides because they contain an OTP aren't read; Finanseal only counts them.
- Masking. Before candidate payment text is sent, long runs of digits (such as account numbers) are replaced with symbols, and names are masked where possible.
- Screenshots and receipts. Text is read (OCR) on your phone. Only the text is sent for extraction; images stay on your phone unless you attach one to a transaction as a receipt.
- Voice. Speech is turned into text on your phone where the device supports it, or by the operating system's speech service. We only receive the transcript.
- Forwarded email (Premium). E-receipts you forward to your Finanseal address are processed to extract the transaction. Do not forward emails that contain OTP codes or passwords.
- You can mute any app or turn notification access off at any time.
8. AI processing
We use AI services from Anthropic, PBC (United States) as a Personal Data Processor to extract transactions from payment text, suggest categories, and answer questions in Ask Sealy.
- The AI is only called from our servers; the service key never ships in the app.
- Only the text needed is sent, after masking. Images and OTP codes are never sent.
- Anthropic is bound by a data processing agreement with standard data protection clauses. We request zero data retention, and the data we send isn't used to train models.
- Ask Sealy answers from your workspace data through query functions we define. The AI doesn't write its own database queries, and it gives no investment advice and recommends no financial products.
- AI results can be wrong. Unsure captures go to your Review inbox for you to confirm, and you can always edit or delete the result. AI results aren't used to make decisions with legal effects on you.
9. Who we share data with
We don't sell your personal data and don't share it for advertising. We only share what's needed with:
- Service providers that help us run Finanseal: server hosting and backups, email delivery, AI processing (see above), subscription status from the app stores, sign-in with Google or Apple, and push notifications. They act on our instructions under written agreements and may only use the data for the services they provide to us.
- Members of a shared workspace see the records in that workspace, including who logged what. Transactions in your personal workspace are visible to no one unless you move them.
- Authorities, when required by law and through a lawful request.
- A successor business, in a merger, acquisition or transfer of business. We will tell you in advance, and this policy will keep protecting your data.
10. Transfers outside Indonesia
Some of our service providers process data outside Indonesia. We only make transfers the PDP Law allows: to countries with an equal or higher level of protection, or with adequate and binding safeguards such as data processing agreements with standard data protection clauses.
Before transferring, we assess the impact on the protection of your data. For the continuous flow of data to our AI provider we don't rely on consent alone; we rely on binding agreements, data minimisation and masking, and zero retention. We will adjust the basis for transfers if the data protection authority issues new rules or adequacy assessments.
11. Security
- Every connection uses TLS.
- The database on your phone is encrypted, with keys kept in Android Keystore or the iOS Keychain.
- Our server database and its backups are encrypted at rest; backups are stored away from the main server.
- Staff access is limited to what is needed, uses two-step authentication, and is logged.
- App lock with fingerprint, Face ID or PIN; passwordless sign-in.
- We review security before launch and regularly after, and we test restoring from backups.
No system is risk-free. Keep your phone and email secure, and never give your OTP code or PIN to anyone, including people claiming to be from Finanseal.
12. How long we keep data
| Data | Kept for |
|---|---|
| Account and financial records | As long as your account is active |
| Transactions in Trash | 30 days, then permanently deleted |
| Notifications not about money | Never stored |
| Email sign-in and account deletion codes | 10 minutes |
| Server security logs | 90 days |
| Feedback and support conversations | Until resolved, at most 2 years, or until your account is deleted |
| Purchase transaction records | As long as tax regulations require |
| Record that an account deletion request was honoured | As long as needed to show compliance, without your financial data |
When your account is deleted (in the app or on the account deletion page): every device is signed out at once and there is a 7-day grace period. Signing in again within that period cancels the deletion. After it, your account and personal data are deleted from our systems, and from backups within 30 days of the request. Shared workspaces you own pass to another member; transactions you added to someone else's workspace remain part of that workspace.
13. Your rights
Under the PDP Law, you have the right to:
- be informed about the processing of your data;
- access your data and get a copy of it;
- complete, update and correct inaccurate data;
- receive your data in a commonly used format (CSV export is available on every plan);
- end processing and have your data deleted;
- withdraw the consent you have given;
- object to decisions based solely on automated processing;
- suspend or restrict processing;
- sue for and receive compensation for violations in the processing of your personal data;
- complain to the personal data protection authority.
You can exercise most of these rights directly in the app (Settings > Privacy & data). For anything else, email hello@kasankaf.com. We may ask you to verify your identity, and we respond within the time limits set by the PDP Law.
14. If a data breach happens
If a personal data protection failure happens, we will notify you and the competent authority in writing within 3×24 hours of becoming aware of it. The notice covers the data affected, when and how it happened, and the steps we are taking to handle and recover from it.
15. Children
Finanseal is meant for users aged 18 and over. Users under 18 may only use Finanseal with the consent and supervision of a parent or guardian, for example as a member of a family workspace. If we learn we are processing a child's data without that consent, we will delete it.
16. Website and cookies
This website uses no ads, third-party trackers or analytics cookies. We only set a "theme" cookie if you choose light or dark mode. Forms on this website (feedback and account deletion) are sent to our servers, and server logs (IP address, browser type) are kept for security.
17. Changes to this policy
We may update this policy. For important changes we will tell you in the app or by email at least 14 days before they take effect, and ask for new consent where needed. The date at the top shows the latest version.
18. Contact us
- PT Kasankaf Digital Solution, Jakarta, Indonesia
- Email: hello@kasankaf.com