Privacy
Your data, your context, no hidden fine print.
This page explains what CIBI collects, how that information is used, and how to contact us if you want access, deletion, export, or correction.
Last updated: September 17, 2026
1. What This App Does
CIBI (Can I Buy It?) helps users evaluate planned purchases, manage budgets, track transactions, and monitor one active savings goal.
The app is for informational purposes only and does not constitute financial advice.
2. Information We Collect
Depending on how you use the app, we may collect the following categories of data:
- Account information, including email address and authentication identifiers when you create an account or sign in with providers like Google or Apple.
- Financial information you provide, including income, budgets, one active savings goal, recurring expenses, categories, transaction amounts, transaction notes, and purchase decisions.
- Scan images and extracted purchase details. When you choose to scan a price tag or receipt, CIBI captures the image and processes it to extract details such as prices and item information. See "AI Scanning of Price Tags and Receipts" below for how scan images are handled.
- Chat messages, if you connect chat purchase logging. That covers the voice notes, messages, and photos you send our bot, plus the chat and message identifiers the chat service sends with them. See "Chat Purchase Logging" below.
- Device and diagnostics information, including crash logs, technical diagnostics, and performance information if analytics or crash-reporting tools are enabled.
- Support communications, including messages and contact details you send when requesting help.
3. Demo Mode
If you use the in-app demo mode, the app may store sample or locally created demo data on your device to let you explore the product without creating an account.
Demo mode is intended for product evaluation only.
4. How We Use Information
We use information to:
- provide the budgeting and purchase-decision features
- extract purchase details from price tag and receipt scans you choose to capture
- authenticate users and maintain sessions
- sync account data across devices, if applicable
- improve app stability and performance
- respond to support requests
- comply with legal obligations
5. AI Scanning of Price Tags and Receipts
CIBI includes an optional scan feature. When you choose to scan a price tag or receipt, the app compresses and resizes the image on your device and then sends it to our backend and an AI provider so we can extract purchase details such as prices and item information.
This transmission happens only when you use the scan feature. The image is sent off your device to fulfill that real-time scan request.
- CIBI does not store scan images in your account. The compressed image is not saved to your account record or shown in your history.
- The AI provider processes each scan request transiently. We send scan requests with a no-retention setting, so the provider is instructed not to store scan images or use them to train its models.
- To measure scan accuracy and investigate failed scans, we record a diagnostic trace of each scan with LangSmith, our observability provider. That trace includes the same compressed image, the scan mode, your category names, and the remaining spendable amount used to evaluate the purchase. Traces are deleted after 14 days.
- A trace carries no account identifier, email address, or device identifier, so it cannot be linked back to your account. That also means a trace cannot be located and removed for a specific account if you delete your account; traces age out on that 14-day schedule instead. A receipt image inside a trace may still show information printed on the receipt, such as the merchant or the items you bought.
- We keep non-image metadata about a scan, such as scan status, the provider and model used, the extracted price, and the resulting budget classification.
- Our analytics never receive photos, receipt or price tag images, image URLs, raw text read from an image, or raw item names.
6. Chat Purchase Logging
CIBI includes an optional chat logging feature. It does nothing until you connect a chat account yourself from the app's settings, and you can disconnect at any time from the same place.
When you connect, the app asks our backend for a single-use link code and opens the chat app so you can send it to our bot. That code associates your chat with your CIBI account so we can tell whose purchases a later message describes. Telegram is the only chat service currently supported.
After that, a voice note, message, or photo you send the bot is delivered to our backend by the chat service, processed to extract the purchases it describes, and returned to you as a draft you confirm or discard. Nothing is written to your account until you confirm it.
- The AI provider that reads a scan also reads chat messages, under the same no-retention setting, so it is instructed not to store your message or use it to train its models.
- Chat messages are recorded in the same diagnostic traces described in section 5, kept for up to 14 days. A trace of a chat log contains the message itself, meaning the audio of a voice note or the text you typed, so anything you said or wrote in it is present in that trace for those 14 days.
- We store the link between your chat and your CIBI account, the list of purchases extracted from each message, and metadata about how it was processed. We do not keep the original audio or photo in your account.
- A draft you neither confirm nor discard can no longer be confirmed after 24 hours. Its record stays in your account until you delete your account, at which point your chat link and all chat drafts are deleted with it.
- The chat service is a third party we do not control. Your messages to the bot and the bot's replies live in that chat under that service's own privacy policy and retention rules, on their servers and on your device. Our replies summarize the purchases we read and your spending so far this month, so that spending information appears in the chat and remains there unless you delete those messages.
7. How Data Is Stored
The current version of the app uses Supabase-hosted backend services for authenticated account data and secure transport over HTTPS/TLS.
Scan images used by the price tag and receipt scan feature are not stored in your account. A copy is retained for up to 14 days in a diagnostic trace, as described in section 5.
Chat purchase logging data, described in section 6, is stored in the same backend as your other account data. Audio and photos sent to the bot are not stored in your account.
The app may also store some information locally on the device, including session state and demo-mode data, using device storage.
8. Third-Party Services
The app may use third-party service providers, including:
- Supabase for authentication and hosted database services
- Telegram, if you choose to connect chat purchase logging, as the chat service that delivers your messages to our bot
- Google's Gemini API as the AI provider that extracts purchase details from price tag scans, receipt scans, and chat messages
- LangSmith for scan diagnostics, accuracy monitoring, and failure investigation
- Apple Sign In and Google Sign In for authentication
- Expo services and related mobile infrastructure
- Optional analytics, subscription, or crash-reporting tools if enabled in a given build
9. How We Share Information
We do not sell personal information.
We may share information only in the following limited situations:
- with service providers that help us operate the app
- when required by law, court order, or regulatory request
- to protect our legal rights, users, or systems
- during a merger, acquisition, or asset sale, if applicable
10. Data Retention
We keep personal and financial data only as long as needed to operate the service, comply with legal obligations, resolve disputes, and enforce agreements.
Demo-mode data stored locally may remain on the device until the app is deleted or local storage is cleared.
Chat drafts, described in section 6, stop being confirmable after 24 hours but remain in your account until you delete your account or disconnect the chat.
Scan diagnostic traces, described in section 5, are kept for up to 14 days and then deleted automatically. Because a trace carries no account identifier, it is not removed by deleting your account and instead ages out on that fixed schedule.
11. Your Rights
Depending on your location, you may have rights to:
- access your personal data
- request correction of inaccurate data
- request deletion of your data
- request export of your data
- withdraw consent where processing is based on consent
12. Children
The app is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
13. Security
We use reasonable administrative, technical, and organizational safeguards to protect data. However, no method of transmission or storage is completely secure.
14. International Transfers
If you use the app outside the country where our systems are operated, your information may be processed in other countries where privacy laws may differ.
15. Changes To This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will revise the date above and, where appropriate, provide additional notice.
16. Contact
For privacy questions or requests, contact:
- Company: CIBI
- Email: privacy@getcibi.com
- Support URL: https://getcibi.com/support
- Website: https://getcibi.com