1. Where AI is used
- Financial insights and the health score — a summary of patterns in your own recorded data.
- Cash-flow and budget forecasts — narrative explanation on top of a deterministic calculation.
- Receipt and statement reading — extracting amount, date and merchant from an image or file you upload.
- Transaction categorisation — suggesting a category from the description.
- The planning assistant and advisor chat — answering questions about your figures.
- The SMS / WhatsApp bot — turning "spent 40 at Costco" into a transaction.
Every one of these surfaces is labelled in the interface so you always know when you are reading generated text rather than a number you entered.
2. What models we use and what they are given
We use general-purpose large language models accessed through our hosting platform's API. We do not train, fine-tune or host our own models, and we do not use your data to train anyone's model. Our providers are contractually prohibited from training on data sent through the API.
A model receives only the minimum needed to answer: the figures relevant to the screen you are on, in the currency and language you use. It does not receive your full account, your email address, your bank credentials (we do not have them), or another user's data. Full account numbers are masked before anything is sent.
Prompts and responses are not retained by the provider beyond the short abuse-monitoring window their terms specify, and are never used for advertising.
3. What AI is not allowed to do here
- It cannot move money, open or close accounts, place trades, or change a subscription.
- It cannot read another user's data — every query is scoped to the signed-in account before it reaches a model.
- It cannot delete your records. Destructive actions require an explicit confirmation from you in the interface.
- It does not make automated decisions with legal or similarly significant effects. Nothing here approves, refuses or scores you for credit, insurance, housing or employment.
4. Wrong answers, and how we limit them
Language models can produce fluent, confident and wrong statements. We reduce the blast radius rather than pretend it does not happen:
- All arithmetic — totals, balances, net worth, projections, payoff schedules — is computed in ordinary code, not by a model. The model explains the number; it does not produce it.
- Answers are grounded in your own recorded data and the model is instructed to say when it does not know instead of guessing.
- Generated output is labelled and carries a link to the Financial Disclaimer.
- Extracted values from receipts land in an editable field for you to confirm — nothing is saved from an image without your review.
- Suggested categories are suggestions; the review queue lets you accept or change each one.
5. Prompt injection and untrusted text
Text that arrives from outside — a receipt image, an imported statement, a merchant description, an inbound message — is treated as data, never as instructions. It is delimited before it reaches a model, and the model is instructed to ignore directions embedded in it.
Because a model has no authority to act (see section 3), a successful injection still cannot move money, reach another account or delete anything. That containment is the real defence; the prompt-level hardening is the second layer.
6. Human review
No AI output is reviewed by a person before you see it — we tell you that plainly rather than implying an editorial process that does not exist.
You are the reviewer for anything that gets written to your account: extracted receipt values, suggested categories and bot-created transactions all pass through a confirmation step.
Reported outputs are reviewed by a human. If a report reveals a systematic problem we change the prompt, the grounding or the feature, and we record the change.
7. Reporting a bad output
Use the "Report a wrong answer" control that sits beside the AI notice on any generated surface, open a support ticket from Help, or email eliezereisenbach@gmail.com. We acknowledge within two business days.
Reporting sends us the generated text, the feature it came from and a timestamp. It does not send your financial records.
8. Logging and audit
We log which AI feature ran, for which account, at what time, whether it succeeded and how long it took. We do not log the financial content of prompts. These logs are kept 12 months and are used for debugging, abuse investigation and cost control.
Material changes to how a feature works, which model family it uses, or what data it is given are recorded in our internal model documentation and, when they affect you, announced in the app.
9. Our commitments
- Disclosure — you always know when content was generated.
- Data minimisation — a model gets the least it needs, never the whole account.
- No training on your data — by contract, with every provider.
- Human authority — AI proposes, you decide, and destructive actions always need your confirmation.
- Contestability — you can report any output and get a human answer.
- Fairness — we do not use AI to score, rank or profile users, and we do not price differently based on model output.
These commitments are aligned with Canada's Voluntary Code of Conduct on Advanced Generative AI Systems and the NIST AI Risk Management Framework, and are written to stay compatible with AIDA-style obligations if they come into force.