Privacy policy

Chonji Finance is self-hosted software run by one household for its own finances. It has no other users, no advertising and no analytics.

What it stores

Transactions, receipt photos and bank notification emails are stored on the household's own server. API keys and Gmail access grants entered through the app are stored encrypted (AES-256-GCM); values the operator places in the server's environment file are not.

Gmail

With the account holder's permission, the app reads — read-only — the messages that carry one Gmail label the household chooses (for example “Bank”), solely to record transactions. For any other new message it checks only which labels it has, without downloading its content, and records only its Gmail message id. It never sends, changes or deletes mail. Access can be revoked at any time from the Google Account page (Security → Your connections to third-party apps).

Chonji Finance's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

AI processing

Some features send data to a third-party AI service chosen by the administrator. This is all they send:

  • Receipt photos read by the AI reader, sent as taken (not masked).
  • The subject and body of each bank email, to extract the amount and merchant. Before email text leaves the server, numbers of seven or more digits — account, card and reference numbers — are masked to their last four digits, unless they are written as an amount (after Rp or IDR, or thousands-grouped) or as a date.
  • For category suggestions, the merchant name (with long digit runs masked) and the person's list of categories.
  • For a Goal Village building design, the goal's name, with long digit runs masked.
  • For the Goal Village's monthly flavour, once the person turns it on, a summary of the month: category names with rounded spending shares, a few recurring shop names, goal names and kinds of income. Every digit in those names is replaced, and the summary holds no amounts, dates or accounts.

Receipts read by the on-server reader are not sent to the AI service: the photo and its recognized text stay on this server, and category suggestions for those receipts use learned rules only. HEIC/HEIF uploads are converted to JPEG for storage and preview.

Training.The AI services this app uses say in their published terms that they do not train models on data sent through their API, unless the account that sends it opts in to sharing it with them. Those opt-ins are off by default. For one of them, the app also asks to be routed only to model providers that, by that service's own records, don't collect the data. Those records are the service's best knowledge, not a guarantee.

Retention.One service deletes API data within 30 days, and may keep content its systems flag for a policy violation for up to 2 years. The other doesn't store prompts or replies unless its account opts in. It keeps request details such as the model and token counts, and the model provider behind it may keep data under its own policy. Either may keep data where the law requires.

Ask Chonji

Ask Chonji is an optional chatbot that answers questions about a person's own money. It stays off until that person turns it on, on the Ask Chonji page, after reading this notice:

  • Your questions, and the figures and names needed to answer them, are answered by an AI service outside the app. That includes the names you gave your accounts, goals and loans, and the names of people in your transfers.
  • Long numbers in imported bank text are hidden first.
  • The AI service does not use them to train its models.
  • Chats are kept here for 30 days and you can delete them at any time. You can turn Ask Chonji off, with or without deleting your chats.
  • The app shows your chats to no one else. The admin sees only how much each person spent on questions this month. Whoever runs the server could technically read stored chats.

Stored chats are encrypted (AES-256-GCM), each piece tied to its own chat and person, so a database dump or a backup alone cannot be read. Whoever holds both the database and the server's encryption key (in practice, whoever runs the server) can read stored chats.

The AI service does not keep prompts by default for the models Ask Chonji offers, and deletes API data within 30 days in any case. Content its systems flag for a policy violation may be kept for up to 2 years, or longer where the law requires. It does not use the data to train its models unless the account opts in to sharing it, which is off by default.

Turning Ask Chonji off keeps a person's chats until they expire, 30 days after their last message. “Turn off and delete my chats” on the Ask Chonji page deletes them at once.

Sharing

No data is sold, and nothing is shared with anyone beyond the AI processing described above.

Contact: contact@chonji.one