Arizu Studio ("we", "us", "our") operates Money Tracker, a personal finance record-keeping service made up of an Android application, a public website at https://arizu.id and supporting systems (together, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, how we use, share, protect and retain it, and what rights you have. We act as the personal data controller for the Service.
We handle personal data in accordance with Law No. 27 of 2022 on Personal Data Protection ("UU PDP"), Law No. 11 of 2008 on Electronic Information and Transactions as amended ("UU ITE"), Government Regulation No. 71 of 2019 on the Operation of Electronic Systems and Transactions, and Google Play's developer policies. Where you live outside Indonesia, we also honour the data subject rights described in section 12, in the manner of GDPR-style rights, to the extent the law of your country applies to you.
By creating an account you confirm that you have read this Policy. Where we rely on your consent for a specific activity, we ask for it separately and you may withdraw it at any time.
1. Our Privacy Principles
- Minimal staff visibility. Our staff cannot view your transactions, balances, budgets or reports. The administration tools used by our staff are designed so that this information is not available to them.
- No sale of personal data. We do not sell your personal data and we do not use your financial records to build advertising profiles.
- You review before saving. Receipt scanning only proposes data. Nothing becomes a transaction until you confirm it.
- No money handling. Money Tracker is a record-keeping tool. It never moves money, never holds funds and never asks for your banking credentials.
- Accountability. Every action our staff take on user accounts is recorded in an audit log.
2. Personal Data We Collect
2.1 Data you give us
- Account data: your name, email address, password (stored only as a salted hash and never in readable form), whether your email address is verified, your plan, account timestamps, and optional profile information you choose to add.
- Financial records you enter: transactions (income or expense, amount, category, notes, date, associated money source and, optionally, a brand or merchant), custom categories, budgets, recurring transactions, and transfers between your own money sources.
- Money sources: the sources or "pockets" you create, such as bank accounts, cards, e-wallets or cash. For these we ask for a type, a holder name, and short details depending on the type (for example a bank, provider or card type name, and the last four digits of a card, where you choose to supply them), and an opening balance. Please never enter full card numbers, security codes, PINs or banking passwords. We do not ask for them.
- Receipt images: photographs or uploads that you submit for scanning.
- Communications: messages you send to support, including any information you include in them.
2.2 Data created when you use the Service
- AI scanning data: the result returned by the AI provider for a receipt (merchant, date, items and totals), a record of the scan request (time, outcome and processing duration), and your daily scan count.
- Device and security data: a hashed device identifier, device manufacturer and model, operating system version, app version, IP addresses, user-agent, sign-in events (time, outcome, device and IP), registered devices, and security events such as new-device or unusual-activity alerts and blocked-device attempts.
- Subscription data: your plan and, for purchases, the order and subscription identifiers, product, status, renewal and expiry dates and verification results that we receive from Google. We do not receive your payment card details.
- Notifications: notifications and announcements delivered to you inside the app, and records that you have read them.
- Automatic transaction capture data (optional): see section 6.
2.3 Data from third parties
From Google we receive purchase and subscription status information as described above. Our advertising provider, where it applies to you, may collect device and advertising identifiers directly under its own policy (section 7.3).
3. How We Use Personal Data, Legal Bases and Retention
Under UU PDP, we process personal data only on a valid lawful basis: your consent, performance of a contract with you, compliance with a legal obligation, or our legitimate interests (which we weigh against your rights). The table below summarises each purpose. Retention periods are explained in more detail in our Data Retention Policy.
| Data category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data (name, email, password hash, plan, timestamps) | Create and run your account; sign you in; communicate with you about the Service | Contract performance | While your account is open; deleted on account closure |
| Transactions, categories, budgets, recurring entries, transfers, money sources | Provide the record-keeping features you request; CSV export | Contract performance | Until you delete them or close your account; never deleted automatically |
| Receipt images and scan results | Extract receipt details for you to review; support; quality assurance; abuse investigation | Consent (when you choose to scan) and contract performance; legitimate interest for support and abuse prevention | Images and scan results are kept while your account is open and removed on account closure; AI usage logs are kept for up to 400 days |
| Device, sign-in and security data | Fraud prevention, account security, new-device and anomaly alerts, blocked-device handling | Legitimate interest; legal obligation where applicable | Sign-in events up to 400 days; security events and registered devices while your account is open |
| Subscription and billing verification data | Verify purchases, grant and revoke paid access, handle refunds, accounting | Contract performance; legal obligation | Billing verification log up to 730 days |
| Email messages (verification, password reset, subscription expiry notices, security alerts, service announcements) | Operate and secure your account and inform you about the Service | Contract performance; legitimate interest | Verification and reset tokens up to 30 days; in-app notifications up to 180 days |
| Staff action audit log | Accountability, security and dispute resolution | Legitimate interest; legal obligation where applicable | Up to 730 days |
| Rewarded advertising (Free plan scan unlocks) | Fund the Free plan | Contract performance; consent where the advertising provider requires it | Our ad confirmation tokens are removed within days of expiry; the ad provider's retention is governed by its own policy |
| Optional notification capture | Propose or record transactions from payment notifications | Consent (Android notification access) | Resulting transactions follow the transaction row above |
| Support correspondence | Respond to requests and resolve problems | Contract performance; legitimate interest | For as long as needed to resolve the matter and handle follow-up questions |
| Rolling database backups | Disaster recovery | Legitimate interest | The most recent daily backups only (14 by default), so removed data disappears from backups as they rotate |
We do not make decisions about you that have legal effect or similarly significant effect based solely on automated processing. Receipt scanning is an assistance feature in which you confirm the outcome.
4. Staff Access to Your Data
We have deliberately limited what our staff can see. Authorised staff using our administration panel cannot view your transactions, balances, budgets or reports.
Staff can see only the following, and only when needed for support, security, billing or legal compliance:
- your account profile and status;
- plan and subscription records;
- the types of your money sources (but not their balances);
- AI usage logs, including the stored result of a receipt scan (merchant, date, items and totals returned by the AI provider), as explained below;
- sign-in history, registered devices and security events; and
- support actions taken on your account.
The stored result of a receipt scan is the only category of content derived from information you submitted that staff may view. It is stored in encrypted form and is used for support, quality assurance and the investigation of abuse. Each time staff view it, the access is recorded in an audit log.
Staff may also suspend or block an account or a device (in which case the reason is shown to you in the app), send you a password reset link by email, and delete accounts. Staff access is limited by role-based permissions. The administration panel requires strong passwords, supports and can enforce two-factor authentication (TOTP), signs staff out after a period of inactivity, and records every administrative action in the audit log.
5. Receipt Scanning and AI Processing
When you scan a receipt, the image is checked and re-encoded by us. This removes embedded metadata such as EXIF data, including location. The cleaned image is stored privately on our server, in a location that is not publicly accessible, and sent securely to the third-party AI provider that we have currently selected. We may configure providers such as Anthropic, Google, DeepSeek, xAI or OpenAI, and the one that is active at the time of your scan is used. The provider returns the merchant, date, items and totals, which we show to you for review. The AI provider receives the receipt image and our extraction instructions. We do not send your name, email address or account identifier to the provider.
We store the AI response in encrypted form for support, quality and abuse investigation (see section 4). Merchant or brand names found on receipts may be added to a shared merchant list used to suggest brands; that list contains no personal data and is not linked to you.
The AI provider is a separate organisation and may process data under its own terms and in countries outside Indonesia (see section 8). Because a receipt can contain personal information about other people, please do not scan receipts that show sensitive third-party data such as complete card numbers. You can avoid AI processing entirely by entering transactions manually; no feature of the Service requires you to scan. Full details are in our AI & Receipt Scanning Notice. We do not use your data to train AI models. The terms of the AI provider apply to what the provider does with the data it receives and are outside our control.
6. Optional Automatic Transaction Capture
On plans where it is available, you may allow Money Tracker to read the notifications that other apps (for example banking or e-wallet apps) post on your device, using Android's notification access permission. This is off unless you explicitly grant the permission, and you can revoke it at any time in your Android settings.
The recognition of an amount, income or expense type and source name is carried out on your device. The app does not upload the raw notification text for analysis by an AI provider. When a payment notification is recognised, the app creates a transaction in your account. The note of that transaction contains the title and text of the notification, shortened to 255 characters, which is therefore stored with your other transaction notes. Because notifications may display personal details, you should enable this feature only for apps whose notifications you are comfortable having recorded as notes, and you can edit or delete the entries at any time. Notifications from Money Tracker itself are ignored.
7. Sharing of Personal Data
We share personal data only as follows, and never for sale.
7.1 Service providers (processors)
- Google: Google Play and Google Play Billing process your subscription payments. We exchange purchase tokens and status information with Google to verify and manage your entitlement.
- AI providers: described in section 5.
- Email delivery: we send messages through an SMTP email server that we operate or contract, which processes your email address and the content of the message.
- Hosting and infrastructure providers: which store and process data on our behalf under confidentiality and security commitments.
7.2 Authorities and legal process
We disclose personal data to authorities only where required by a valid legal process or by law, for example a court order or lawful request from a competent Indonesian authority. We will limit disclosure to what is legally required and, where lawful, tell you about it.
7.3 Advertising provider
Free plan users watch a rewarded video advertisement before each receipt scan. Where such an advertisement is shown, a third-party advertising provider may process device and advertising identifiers and similar data under its own privacy policy, and we do not control that processing. This applies to Free plan scan unlocks only. We do not share your transactions, receipts or financial records with any advertising provider, and paid plans do not require advertisements to scan.
7.4 Business transfers
If we are involved in a merger, acquisition or sale of assets, personal data may be transferred to the successor, which will be bound by this Policy or must tell you of any change in advance.
8. International Transfers
Some of the providers we use, notably AI providers and Google, may process data on servers outside Indonesia. When personal data is transferred outside Indonesia, we ensure, as required by UU PDP, that the receiving country has an equal or higher level of personal data protection than Indonesia, or otherwise that adequate and binding safeguards are in place, such as contractual commitments, or we obtain your consent where required.
9. Cookies, Local Storage and Tracking
Our public website pages and our administration panel use only strictly necessary storage, such as session and anti-forgery (CSRF) tokens and authentication, to keep the site secure and working. We do not use third-party analytics or tracking cookies on our public pages. The Android app stores your sign-in token and preferences on your device, and the app lock setting stays on your device.
10. Security
We protect personal data with technical and organisational measures appropriate to the risk, including:
- HTTPS encryption in transit in production, and security headers on our interfaces;
- passwords stored only as salted hashes, with password policy checks, sign-in rate limiting and account lockout after repeated failed attempts;
- token-based authentication for the app, with the ability to revoke sessions and devices;
- encryption of sensitive stored fields, such as stored AI responses and service credentials, using strong encryption (AES-256-GCM);
- strict validation of uploads, removal of image metadata and private storage of receipt images;
- cross-site request forgery protection;
- on the administration panel, two-factor authentication, a password policy, idle timeout, role-based permissions and audit logging;
- device registration and alerts for new or unusual devices; and
- queries restricted to the data each user or staff role is permitted to see.
No system is perfectly secure. You help protect your account by choosing a strong, unique password, keeping your device secure and reporting suspected misuse promptly.
10.1 Data breaches
If a failure to protect personal data occurs, we will investigate promptly and, as required by UU PDP, notify affected users and the competent data protection authority in writing within 3 x 24 hours of becoming aware of it, describing the personal data involved, how it happened, what we have done and what you can do. Where the law requires, we will also give public notice.
11. Retention
We keep personal data only as long as necessary for the purposes described in this Policy and as required by law. Your transactions, budgets, categories and money sources are never deleted automatically; they stay until you delete them or close your account. Operational logs are removed on a schedule: currently up to 730 days for the staff audit log and billing verification log, up to 400 days for sign-in events and AI usage logs, and up to 180 days for in-app notifications. Short-lived technical records such as sign-in attempts and email verification or password reset tokens are removed after days or weeks. Our database is also backed up daily, and we keep only the most recent backups (14 by default), so removed data can persist in those backups until they rotate out. Please see the Data Retention Policy and the Close Account Policy for details.
12. Your Rights
Under UU PDP and, where applicable to you, GDPR-style laws in other jurisdictions, you have the right to:
- Access your personal data and obtain information about how it is processed;
- Rectify inaccurate or incomplete data (you can edit most of it directly in the app);
- Erase your data, including by deleting your account in the app;
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interest and to certain automated processing;
- Withdraw consent at any time, for example by revoking notification access in Android settings or by choosing not to use AI scanning. Withdrawal does not affect processing carried out before it;
- Data portability - you can export your transactions as CSV from the app, and may ask us for other data you provided in a commonly used format; and
- Complain to us, or to the competent data protection authority in Indonesia or your country.
To exercise a right, email arizu.team@gmail.com from the address registered to your account. We may need to verify your identity first. We will respond within 14 days. If your request is complex or we receive many requests, we may extend this once, by a reasonable period, and we will tell you why. Some requests may be refused or limited where the law allows or requires, for example to keep records we are legally obliged to retain, to protect the rights of others, or where a request is manifestly unfounded. We will explain the reason.
13. Children
You must be at least 17 years old to use the Service, or have the consent of a parent or guardian if you are under the age of legal majority where you live. The Service is not directed to children under 13 and we do not knowingly collect their data. Where we learn that we hold personal data of a child without the required consent, we will delete it. Parents or guardians may contact arizu.team@gmail.com.
14. Third-Party Links and Services
The Service may link to third-party websites or rely on third-party services such as Google Play. We are not responsible for their privacy practices; please read their policies.
15. Changes to This Policy
We may update this Privacy Policy to reflect changes in the Service, our practices or the law. We will notify you of material changes in the app or by email before they take effect, and show the new version and effective date with the Policy. Where the law requires your consent for a new use of your data, we will ask for it.
16. Contact Us
For questions, requests or complaints about this Privacy Policy or our handling of personal data, contact our data protection contact:
- Email: arizu.team@gmail.com
- General support: arizu.team@gmail.com
- Postal address: Arizu Studio, Grand Depok City, Cluster Gardenia, Kota Depok, Jawa Barat, 16412, Indonesia.
Related documents: Terms and Conditions, AI & Receipt Scanning Notice, Data Retention Policy and Close Account Policy.