Kuma

Privacy Policy

Ching Yu Dai, independent developer · Effective September 14, 2026

The short version

Kuma is a personal expense-logging app operated by Ching Yu Dai, an independent developer. We collect the information needed to record your expenses and show them back to you. We do not sell your data, show ads, or use your data to build an advertising profile. One thing is worth knowing before the details: to understand what you type, we send your message to an AI provider that processes it outside the United States. That is explained below.

What we collect

Account. You sign in with Apple, and we never see or handle a password. Our authentication provider holds your email address, which may be an Apple private-relay address, and gives Kuma an account identifier. Kuma’s own database stores that identifier, a display name if you set one, and when the account was created. If you use Sign in with Apple, we store an encrypted credential from Apple solely so we can request revocation of your Apple authorization when you delete your account.

What you tell Kuma. We store the messages you send, Kuma’s replies, and the entries produced from them: amount, merchant, category, direction (money out or money in), note, and timestamps. We also store the corrections you make and a record of how a merchant has been categorized, which may support a future preference-learning feature. Preference learning is currently off.

Voice input. If you use the microphone button, Kuma listens only while a voice session is open. Apple’s speech recognition turns what you say into text, and depending on your device and language that audio may be processed on Apple’s servers rather than on the device. Kuma does not receive or store the audio itself. The transcription appears in the text box, where you can edit it; it becomes a message only if you send it, and is then handled like anything else you type.

Using the app. We record which action each message triggered, weekly and monthly entry counts and daily turn counts used to apply plan lines and safety limits, period-scoped limit lifts, and, if you ask for a manual lift, the request. When you accept the Terms of Service we record which version you accepted and when. When you allow, withdraw, or restore AI processing, we record the notice version, your choice, where you made it, and when.

Subscriptions. If you buy or restore Kuma+, Apple gives Kuma signed transaction and subscription-status information. We store the product identifier, original and latest transaction identifiers, purchase and expiration dates, renewal status, environment, and verified lifecycle notifications so we can provide and secure your plan. We do not receive or store your card number or Apple ID payment credentials.

Feedback. If you use Send feedback, the form sends what you write, the feedback type, app version and build, the screen you sent it from, and the device platform. It does not attach ledger entries, chat messages, account details, or screenshots.

Technical. We process limited technical and diagnostic information (app version, device and operating-system details, the method, path, status and timing of requests, and crash or error reports) to keep the service secure and reliable. Requests are rate-limited using your IP address, which Kuma stores only as a one-way digest, never in readable form; our hosting provider’s own request logs may record the address itself. We do not access your device’s location services, contacts, photo library, HealthKit data, or advertising identifier.

Tap capture and local notifications

If you configure Tap capture in Apple Shortcuts, iOS passes the purchase details you connect to Kuma, such as amount, merchant, currency, transaction date, category, and a card label. Kuma does not receive card numbers, payment credentials, bank balances, or your full Wallet history through this feature. Pending purchase records and a sign-in token are stored in the device-only iOS Keychain. Pending records are associated with the signed-in account and may remain across sign-out so that the same account can resume review. Local records are subject to age and capacity limits and are cleaned up when Kuma processes them; they are not a permanent backup. Deleting your account from this device also clears its local tap records. Records on another device may remain until that device processes account removal or cleans them up.

A local notification may show the merchant and amount on your lock screen, depending on iOS preview settings. You can hide previews or turn off notifications in iOS Settings, and disable or delete the automation in Shortcuts to stop new tap capture. Dismissing a notification does not add the purchase or remove the pending review card.

When you open Kuma, AI categorization may process the purchase as described below. Only choosing Add (including Add from a notification) sends the approved structured expense to your Kuma ledger. The stored record includes the amount, merchant, category, source and a deduplication identifier; the server also stores a conversation receipt and action record. The card label and source transaction date are not stored as ledger fields. Skip does not add an expense.

How we use your data

We use your information to sign you in, turn what you type into a structured entry, provide your ledger, summaries, and conversation history, respond to support and privacy requests, apply usage limits, prevent abuse, and diagnose and fix problems. We do not use your information for advertising and do not sell it to data brokers.

AI processing

Kuma uses DeepSeek to interpret messages and prepare replies. DeepSeek receives the message you send. To interpret and respond to many messages, including determining whether a message is bookkeeping or conversation, it may also receive limited recent conversation context, and the structured information needed to provide the requested response, such as an amount, merchant, category, direction, or a figure calculated from your ledger. Tap categorization sends the purchase amount and merchant, with your account currency; it does not send your card label or conversation history. We do not send your account identifier, email address, display name, sign-in credentials, or your complete ledger. Your messages are your own words, though, so anything identifying or sensitive that you choose to type is part of what is sent.

Before starting Sign in with Apple, Kuma asks you separately for permission to share this information with DeepSeek. For Chat, DeepSeek receives nothing until you submit a message. If you also configure Tap capture, opening Kuma can send the captured purchase amount and merchant to DeepSeek for a category suggestion before you choose Add. Tap categorization requires the expanded AI permission that describes this use; receiving a tap alone does not contact DeepSeek or write a ledger entry. If you do not give permission, Kuma does not start sign-in because third-party AI processing is required to interpret entries and prepare replies. You can later withdraw permission from the Account screen. Withdrawing stops new messages and tap purchases from being sent to DeepSeek; your existing ledger remains available. You can still review and add a structured tap purchase with a category you choose without calling DeepSeek.

Information sent to DeepSeek may be processed and stored outside the United States, including in China. DeepSeek’s public API terms do not guarantee that information from Kuma will be excluded from model training, offer no training opt-out, and do not state a fixed retention duration for that information. DeepSeek’s general privacy policy says that it does not cover end-user data in downstream applications. Deleting information from Kuma does not retract information already submitted to DeepSeek.

Who we share it with

We disclose information to service providers that help operate Kuma, including providers for account authentication, App Store billing and subscription status, cloud hosting and data storage, AI message processing, speech recognition, crash diagnostics and support, and hosting and security for our public website. Each provider receives only the information needed to perform its function, and each processes it under its own terms and privacy policy. Apple processes sign-in information, voice input when you use it, and Kuma+ purchases and subscription status as described under “What we collect.” DeepSeek processes message content and limited recent conversation context as described under “AI processing.” Our diagnostics and support provider receives crash and error reports, limited authentication and usage-limit events, and any feedback you choose to send; those events do not include message text, ledger contents, account identity, screenshots, or sign-in credentials. We do not sell or rent personal information.

We may also disclose information when we believe in good faith that the law requires it, or that it is reasonably necessary to comply with legal process, to enforce our Terms of Service, or to protect the rights, safety, or property of you, of us, or of the public.

If Kuma is ever transferred to a company we form or to a successor in a merger, acquisition, or sale of the business, your information transfers with the service. It stays subject to this policy, or to a successor policy that is at least as protective, and we will tell you in the app before any material change takes effect.

Tracking

Kuma does not track your activity over time across third-party websites or services for advertising, and we do not knowingly allow others to do so through Kuma. Because we do not engage in this tracking, browser Do Not Track signals do not change our practices.

Keeping and deleting your data

We keep your data (your ledger, your messages, Kuma’s replies, and your corrections) for as long as your account is active. We do not delete your messages on a schedule: remembering what you said is part of what Kuma is for.

Deleting an entry removes it from your visible ledger, but the entry remains stored and marked as deleted while your account is active. Deleting your account removes these deleted entries from Kuma’s active database.

You can delete your account at any time from the Account screen, under “Delete account.” Account deletion removes your active Kuma profile, ledger, conversations, corrections, merchant records, activity records, subscription records in Kuma’s database, the records of your Terms acceptance and AI-processing choices, and your authentication identity. If you used Sign in with Apple and the required credential is available, we also request revocation of your Apple authorization. Limited deletion markers and retry records may remain temporarily to prevent account resurrection and to complete provider revocation. We also keep a record that each Apple subscription notification has already been handled, so a replayed notification cannot be applied twice; that record holds Apple’s notification and transaction identifiers, and no Kuma account or ledger data. Deletion is permanent and cannot be undone. Deleting a Kuma account does not cancel a Kuma+ subscription or erase Apple’s purchase records; manage or cancel that subscription through Apple.

Two limits we want to be plain about. Deleting your account removes the data described above from Kuma’s own systems, but it does not retract message text already sent to our AI processing provider, and we do not control how long that provider retains it. And backup copies and security logs may persist according to provider retention schedules and are deleted or overwritten through those providers’ ordinary processes.

Your choices

You can edit an entry, or remove it from your ledger, in the app. You can withdraw or restore permission for new AI processing from the Account screen; withdrawing keeps your existing ledger available but prevents new messages from being interpreted. You can delete your account from the Account screen. To ask for access to, correction of, or deletion of your personal information, or to ask a privacy question, email us at admin@get-kuma.com. We may need to verify that a request is associated with your account before acting on it.

Security

Sign-in is handled by Apple, so Kuma never handles a password. Access controls are designed to keep one person’s ledger separate from another’s, and our database provider encrypts database storage and backups at rest. That protects your data from outside access; it does not put it beyond our own reach. Authorized service systems can read the information needed to operate Kuma, and our AI processing provider receives your messages as described above. No method of electronic storage or transmission is completely secure, but we work to protect the information we hold.

Who can use Kuma

Kuma is offered only in the App Store countries and regions we select and is for people aged 13 and older; if you are under the age of majority where you live, you need a parent or guardian’s permission to use it. Kuma is not directed to children under 13, and we do not knowingly collect their data.

Changes to this policy

If we change this policy we will update the effective date above and, for significant changes, tell you in the app.

Contact

Questions about your privacy? Reach us at admin@get-kuma.com. Kuma’s Terms of Service are available from the Account screen and alongside this policy on our website.