← Back to apps

Wimmy Privacy Policy

Apps
Wimmy
Last updated
August 14, 2026

MinSoo Go (the “Developer”) complies with applicable privacy laws, including the Personal Information Protection Act of Korea, and publishes this Privacy Policy for “Wimmy” (the “Service”).

1. Information We Collect

Wimmy has no sign-up and never asks for your name, email, or phone number.

  • All data you enter — transactions, accounts, budgets, savings goals, categories — is stored on your device and in your own iCloud account, and is not stored on the Developer’s servers.
  • iCloud storage is used only to sync your data across your devices. It lives in your personal iCloud space provided by Apple, and the Developer cannot access it.
  • The only exception: when you explicitly run an AI auto-entry feature (receipt/payment-screen scan, payment-text paste, or natural-language quick entry), the image or text is transmitted for analysis as described in Section 4.

2. App Permissions

The Service optionally uses the following permissions:

PermissionPurposeRequired
NotificationsBudget alerts and upcoming recurring-payment remindersOptional
CameraPhotographing receipts (AI scan feature)Optional
Photo LibraryImporting receipt/payment screenshots (AI scan feature)Optional
Face IDApp lockOptional

You can change permissions anytime in iOS Settings. Features unrelated to a denied permission continue to work normally.

3. Network Communication

The Service communicates with external services only for the purposes below.

DestinationPurposeData Transmitted
Korea Public Data Portal (data.go.kr)Fetching Korean public holiday informationNone
Apple iCloudSyncing data to your own iCloud accountYour entered data (stored only in your iCloud)
RevenueCatVerifying and restoring subscription statusAnonymous identifier, App Store purchase receipt
AmplitudeAnonymous usage statistics for product improvementAnonymous device identifier, screen/feature events (never the amounts or contents you enter; no personal identification, no ads or tracking)
Developer’s relay server (Cloudflare) and AnthropicAI auto-entry and monthly report (Section 4)The image you select or the text you enter, or aggregate statistics for that month used to generate the monthly report

4. AI Auto-Entry and Monthly Report Features

The following happens only when you explicitly run the feature in the receipt/payment-screen scan, payment-text paste, natural-language quick entry, or AI monthly report:

  • What is transmitted
    • Auto-entry (scan / paste / quick entry): the receipt/payment-screen image you took or selected, or the text you entered; an anonymous device identifier; an anonymous subscription identifier; and (for quick entry) the names of the categories and accounts you created and the reference date, used to improve recognition accuracy.
    • AI monthly report: aggregate statistics for that month (per-category spending totals, income/expense totals, top merchant names and amounts, daily totals, etc. — summary figures, not individual raw transactions); an anonymous device identifier; an anonymous subscription identifier.
  • How it is processed: the data passes through the Developer’s relay server (Cloudflare Workers) and is analyzed by the AI processor (Anthropic, Claude API).
  • Storage
    • Original images and text, auto-entry recognition results, and the aggregate statistics sent to generate a report are never stored on any server (they are processed transiently and discarded). Recognition results are stored only on your device.
    • The one exception is the generated AI monthly report summary: so that reopening a report for the same month is instant and does not require regeneration, it is cached for up to 90 days, keyed to an anonymous device identifier, then deleted automatically. This summary may contain merchant names and amounts in prose form for spending analysis, but is not linked to any identity information such as name or email.
    • The server keeps a usage count keyed to an anonymous device identifier to manage free-tier and premium limits; the premium daily count is automatically deleted after 48 hours.
    • Server operation logs contain no images or transaction contents. Anthropic does not use transmitted data to train AI models and deletes it after a limited retention period for operational and safety purposes.
  • Please note: payment texts and app-notification screenshots may contain third-party information such as sender names. Recognized content is stored only on your device and is never shared.
  • If you never use these features, no image, text, or statistics are ever transmitted.

International Transfer

During AI analysis, data is temporarily transferred to overseas processors:

RecipientCountryPurposeDataRetention
Cloudflare, Inc.USARelaying analysis requests, caching reports, managing usage countsImage/text/aggregate statistics (transient), AI monthly report summary, usage count keyed to an anonymous identifierOriginal images, text, and aggregate statistics not stored; AI monthly report summary cached up to 90 days then auto-deleted; premium daily usage count auto-deleted after 48 hours
Anthropic, PBCUSAAI image/text/statistics analysisReceipt/payment-screen image or text, or aggregate statistics for the monthly reportDeleted after a limited retention period; not used for training

5. Third Parties and Processors

The Developer never sells or shares your personal information. The following processors are used to operate the Service:

ProcessorTask
RevenueCat, Inc.Subscription status management
Anthropic, PBC / Cloudflare, Inc.AI image/text analysis (only when you run it)
Amplitude, Inc.Anonymous usage statistics

6. Data Retention and Deletion

  • Your data is stored on your device and in your own iCloud. Deleting the app removes on-device data; iCloud-synced data can be deleted in iOS Settings (Settings → Apple Account → iCloud → Manage App Data).
  • You can export your records to a CSV file in the app at any time.

7. Your Rights

You can view, edit, and delete your data directly in the app at any time.

8. Privacy Officer

9. Notice of Changes

Changes to this policy will be announced on this page.

  • First effective date: August 5, 2026
  • Revised: August 14, 2026 (clarified the up-to-90-day caching of AI monthly report summaries)