Privacy Policy
What personal data Sincejar collects, why, with whom it is shared, and the rights you have over it.
1. Who we are
Sincejar ("we", "us") provides a personal finance and expense tracking service at sincejar.360framed.com and through an Android application, and an iOS application once released (together, the "Service"). This Privacy Policy explains what personal data we collect, why we collect it, with whom it is shared, how long it is kept, and the rights you have over it.
The data controller is Jason Pieter Kusumajaya, an individual sole trader, of Jl Taman Ubud Asri I No. 15, Tangerang, Banten 15810, Indonesia. For any privacy question or request, contact support@sincejar.360framed.com.
2. Personal data we collect
• Account data: email address, display name, optional profile photo, hashed authentication credentials, two-factor authentication settings, and an OAuth identifier if you sign in with a third-party provider (GitHub).
• Financial records you create: descriptions, amounts, currencies, categories, dates, tags, budgets, subscriptions you track, and notes. You decide what you enter. Please do not enter another person's data without a lawful basis.
• Content submitted to AI Features: only if you enable AI Features: the text you type into natural-language entry or AI chat, images of receipts you scan, and a summary of your spending that is attached to AI chat requests so that answers are relevant to you.
• Planning and organisation data you create: savings goals and the amounts you record against them, trips (a name, a date range and a budget), spending rules you define, and any tags or categories you add.
• Your money profile: only if you choose to fill it in: a monthly income figure, a pay day, fixed monthly costs, goals and a free-text note about what you are trying to change. You tell us these; we do not calculate or verify them. If AI Features are enabled, this profile is included in AI chat requests so the assistant stops asking you the same questions. Leave it blank and nothing is sent.
• Change history: an append-only record of changes to your expenses, budgets, tags, categories and goals: what changed, from what value to what value, and when. It exists so you can restore something you deleted. See section 8 for how long it is kept.
• Files you import: if you use bulk import, the contents of the spreadsheet or statement file you upload, held as reviewable rows until you commit or discard the import.
• Subscription data: your plan, the store product identifier, a store transaction identifier, the subscription expiry date and renewal status. Payment is made to Google (or Apple, once the iOS app is released); we never receive your card number, security code or bank details.
• Device and technical data: IP address, browser or device type, operating system, app version, time zone, a push-notification token (if you allow notifications), and security logs such as sign-in events and failed attempts.
• Preferences: theme, colour, language, currency and notification settings, stored on your device and in your profile.
We do not collect precise or approximate location, contacts, calendar data, health data, biometric data, audio recordings, browsing history or advertising identifiers. We do not ask for your postal address, phone number or any government identification number. At sign-up we ask for your year of birth solely to confirm that you meet the minimum age; it is checked on your device and is not stored.
3. Device permissions
• Camera and photo library: used only when you choose to scan a receipt or set a profile photo. Receipt images are sent to an AI provider only if AI Features are enabled.
• Notifications: used for reminders and account alerts you have enabled. You may withdraw this permission at any time in your device settings.
We do not request access to your microphone, location or contacts.
4. Purposes and legal bases
We process personal data to: (a) create and operate your account and synchronise your records across devices; (b) provide dashboards, budgets, reports and exports; (c) provide AI Features that you have enabled; (d) verify and manage subscriptions; (e) send transactional messages such as two-factor codes, sign-in alerts, password resets and notifications you have enabled; (f) secure the Service and prevent fraud and abuse; and (g) comply with legal obligations.
Where the GDPR, the UK GDPR, Indonesia's Personal Data Protection Law (UU No. 27 of 2022) or a similar law applies, we rely on: performance of a contract for (a), (b), (d) and (e); your explicit consent for (c) and for push notifications; our legitimate interests in operating a secure service for (f); and legal obligation for (g).
We do not use your personal data for advertising, we do not profile you for marketing purposes, and we do not make decisions producing legal or similarly significant effects about you by automated means.
5. AI Features
AI Features are disabled by default. Nothing is sent to an AI provider until you enable them, and our servers refuse AI requests while they are disabled. We request your explicit consent separately from acceptance of this Policy because a free-text description or a photographed receipt may incidentally reveal special-category data (for example relating to health or religion), for which explicit consent is the applicable legal basis (GDPR Art. 9(2)(a)).
If you have filled in your money profile (section 2), it is included in AI chat requests while AI Features are enabled, so the assistant does not re-ask what you have already told it. It is transmitted on the same basis as everything else in this section and stops being sent the moment you clear the fields or disable AI Features.
When enabled, the content you submit is transmitted to our AI providers solely to generate the requested result. It is processed transiently, is not used by us to train AI models, and is subject to the providers' contractual commitments not to train on API data. You may withdraw consent at any time in Settings; withdrawal stops all further transmission immediately but cannot recall content already processed. Declining affects AI Features only; all other features remain available.
The interactive demonstration on our home page is not connected to any account. Text typed into it is sent to an AI provider to produce a reply. Please use example data only and do not enter real financial or sensitive information into it.
6. Processors and recipients
We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising. We disclose it only to the service providers below, each acting on our instructions under a data processing agreement, and to public authorities where required by law.
• Dewaweb, our hosting provider in Indonesia: hosting of the website, API, database and email; processes your account data, financial records, requests, IP addresses, server logs and the emails we send you (Indonesia).
• OpenRouter Inc. and the AI model providers it routes requests to: AI inference, only when AI Features are enabled (United States and other countries where those model providers operate).
• Google LLC and GitHub Inc.: only if you choose to sign in with them: they confirm your identity and share your name and email address with us, under their own privacy policies.
• Expo (650 Industries, Inc.), Firebase Cloud Messaging and, once the iOS app is released, Apple Push Notification service: delivery of push notifications; process your push token and notification content (United States).
• Google LLC and, once the iOS app is released, Apple Inc.: sale of subscriptions and verification of purchases, under their own privacy policies.
Exchange rates are retrieved by our server from a public rates service; no personal data is sent in those requests.
7. International transfers
Your data may be processed outside your country of residence, including in Indonesia and the United States. Where personal data is transferred from the EEA, the UK or Indonesia to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) incorporated into each processor's data processing agreement, together with any additional safeguards required by UU PDP.
8. Retention
Change history is kept for three months on the Basic plan and for as long as your account exists on the Pro plan. It is recorded on every plan so that an upgrade does not begin with an empty history; on Basic, entries older than three months are deleted automatically. Deleting your account deletes the history with it.
Imported files are held as reviewable rows only until you commit or discard the import, and the staged rows are deleted when you do.
We keep your personal data while your account is active. When you delete your account in Settings, or ask us to do so, we delete your account data and financial records within 30 days. Backups containing deleted data expire on a rolling basis within 35 days. We retain limited records for longer only where required for legal, tax, billing or fraud-prevention purposes, and only for as long as that obligation lasts. Security logs are kept for up to 30 days.
9. Security
Data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. Access is restricted per account, administrative access is limited and logged, and two-factor authentication is available for your account. No system is completely secure.
If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it where required, and notify affected users without undue delay where the breach is likely to result in a high risk to their rights, as required by UU PDP and the GDPR.
10. Your rights
Subject to applicable law, you have the right to: be informed about processing; access and obtain a copy of your data; correct inaccurate data; delete your data; receive your data in a portable format; restrict or object to processing; withdraw consent at any time without affecting the lawfulness of prior processing; and lodge a complaint with a supervisory authority.
You may export or delete your data directly in Settings, or contact support@sincejar.360framed.com. We respond within 30 days (or any shorter period required by law, such as the 72-hour response period for certain requests under UU PDP) and may need to verify your identity before acting.
Indonesia. As we are established in Indonesia, UU PDP applies to our processing. You may lodge a complaint with the personal data protection authority designated under UU PDP.
European Economic Area (the EU, Iceland, Liechtenstein and Norway), the United Kingdom and Switzerland. The GDPR, the UK GDPR and the Swiss Federal Act on Data Protection (FADP) apply to our processing of your data. You may lodge a complaint with the supervisory authority of your country of residence or place of work (in Switzerland, the Federal Data Protection and Information Commissioner).
California and other US states: notice at collection. In the preceding 12 months we have collected the following categories of personal information, from you directly, from your device, and from Apple or Google for subscriptions: identifiers (name, email address, account ID, IP address, push token); commercial information (plan and subscription status); internet or other electronic network activity (security and sign-in logs); and user content you enter, including your financial records. Account log-in credentials (email and password) are sensitive personal information; we use them only to provide and secure the Service, so no right to limit applies. We use these categories for the purposes in Section 4, disclose them only to the service providers in Section 6, and keep them for the periods in Section 8.
We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the preceding 12 months; we have no actual knowledge of selling or sharing the personal information of consumers under 16. You have the right to know, access, correct and delete your personal information and not to be discriminated against for exercising these rights. You may submit a request by email; an authorised agent may submit a request on your behalf with proof of authorisation. We verify requests by confirming control of the account's email address.
California "Shine the Light" (Civil Code § 1798.83). We do not disclose personal information to third parties for their own direct-marketing purposes.
Do Not Track and Global Privacy Control (CalOPPA). No third party collects personal information about your online activities over time or across different websites through the Service, and we do not track you across other sites. Because there is no sale, sharing or cross-site tracking to switch off, a browser Do Not Track or Global Privacy Control signal does not change how the Service behaves; we treat such a signal as an opt-out request and there is nothing further to opt out of.
Users under 18 (California Business and Professions Code § 22581). You can remove any content or information you have submitted to the Service at any time: delete an individual entry, a budget or a note in the app, or delete your whole account in Settings, or ask us to remove it by email. The Service does not publish your content to other users.
Brazil. If the LGPD applies to you, you may exercise the rights set out in Article 18 of the LGPD by contacting us, and may petition the ANPD.
11. Cookies and local storage
We use one strictly necessary cookie to keep you signed in (an httpOnly session cookie that scripts on the page cannot read) and store preferences in your browser's local storage. We do not use analytics, advertising or cross-site tracking cookies or scripts, and therefore do not display a consent banner. If this changes, we will request your consent before any non-essential technology is used. Details are set out in our Cookie Policy.
12. Children
The Service is not directed at children and may not be used by anyone under 16 years of age, or the higher minimum age of digital consent in their country. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this Policy
We may update this Policy. We will give at least 30 days' notice of material changes by email or in-app notice, and the "Last updated" date at the top of this page always reflects the current version.
14. Contact
Jason Pieter Kusumajaya, trading as Sincejar, Jl Taman Ubud Asri I No. 15, Tangerang, Banten 15810, Indonesia. Email: support@sincejar.360framed.com.