Kebijakan Privasi
1. Ringkasan
Pocket Hero adalah aplikasi pencatat keuangan pribadi yang berjalan sepenuhnya di perangkat Anda.
- Catatan keuangan Anda tidak pernah disimpan di server kami. Kami mengoperasikan satu server, dan perannya sempit: ia meneruskan permintaan fitur AI ke Google (dan, untuk pesan chat sederhana, ke TypeSafe), menghitung berapa banyak permintaan yang dibuat tiap akun, dan menyimpan bukti langganan bagi yang berlangganan. Isi permintaan itu tidak disimpan di sana. Lihat Bagian 6.2 dan 6.7.
- Fitur AI memerlukan Anda masuk dengan akun Google atau Apple. Dari proses itu kami hanya menerima alamat email akun tersebut — dipakai untuk mengenali pemilik langganan dan membedakan satu pengguna dari yang lain. Seluruh fitur lain berjalan tanpa akun. Lihat Bagian 4.4 dan 6.8.
- Anda dapat menghapus akun itu sendiri dari dalam aplikasi lewat Pengaturan → Akun → Hapus Akun, terpisah dari tombol yang menghapus data di perangkat. Lihat Bagian 8.
- Tidak ada analitik, pelacak, atau iklan apa pun di dalam aplikasi ini. Satu-satunya yang dikirim tanpa Anda minta adalah laporan kerusakan teknis (Firebase Crashlytics) saat aplikasi berhenti bekerja atau membeku — isinya keterangan teknis, bukan catatan keuangan, email, atau pengenal akun Anda. Lihat Bagian 6.9.
- Seluruh catatan keuangan Anda disimpan di basis data lokal pada perangkat Anda sendiri.
- Fitur AI bersifat opsional dan mati secara bawaan. Fitur ini hanya aktif setelah Anda menyetujuinya secara eksplisit. Seluruh fitur lain berfungsi tanpa koneksi internet.
- Jika Anda menyalakan fitur AI, data keuangan yang relevan dengan pertanyaan Anda dikirim ke server kami dan diteruskan ke Google, atau ke TypeSafe untuk pesan chat sederhana. Bacalah Bagian 6 dengan saksama sebelum menyalakannya.
2. Identitas dan Kontak Pengendali Data
Sesuai Pasal 21 UU No. 27 Tahun 2022 tentang Pelindungan Data Pribadi (UU PDP), pengendali data pribadi untuk aplikasi ini adalah:
Alamat: Jakarta Pusat, DKI Jakarta, Indonesia
Email kontak: zentrasolution.ai@gmail.com
Nomor tanda daftar PSE Lingkup Privat (Komdigi): 029934.01/DJAI.PSE/09/2026
Aplikasi ini tidak menunjuk Pejabat Pelindungan Data (DPO) karena tidak melakukan pemrosesan data pribadi dalam skala besar dan tidak melakukan pemantauan rutin dan sistematis terhadap subjek data (Pasal 53 UU PDP).
3. Prinsip Dasar: Data Anda Tinggal di Perangkat Anda
Aplikasi ini tidak melakukan sinkronisasi catatan keuangan ke cloud. Seluruh data yang Anda masukkan disimpan dalam basis data SQLite lokal di penyimpanan privat aplikasi pada perangkat Anda, dan tidak ada satu pun catatan keuangan yang disalin ke server kami. Satu-satunya pengecualian, dan hanya bila Anda memakai fitur AI: Anda perlu masuk dengan akun Google atau Apple, sehingga alamat email akun itu beserta angka pemakaian AI tersimpan di server kami (Bagian 4.4 dan 6.2). Masuknya Anda tidak menyalin satu pun catatan keuangan ke mana pun; yang dipindahkan hanyalah pertanyaan yang Anda kirim ke fitur AI, itu pun hanya saat Anda memakainya.
Konsekuensinya, dua hal berlaku bersamaan: pengembang tidak pernah dapat mengakses data Anda, dan pengembang juga tidak dapat memulihkan data Anda jika perangkat Anda hilang, rusak, atau aplikasi dihapus. Tanggung jawab pencadangan sepenuhnya ada pada Anda (lihat Bagian 6.4).
4. Data yang Disimpan Aplikasi di Perangkat Anda
Semua data berikut Anda masukkan sendiri. Aplikasi tidak mengambil data apa pun dari sumber lain di perangkat Anda tanpa tindakan Anda.
4.1 Data keuangan
| Kategori | Isi |
|---|---|
| Dompet / rekening | Nama, jenis (tunai, bank, e-wallet, kartu kredit, rekening saham/RDN), saldo, mata uang, limit kartu kredit, tanggal cetak dan jatuh tempo tagihan, ikon dan warna |
| Transaksi | Judul, jumlah, catatan bebas, tanggal dan waktu, jenis (pemasukan/pengeluaran/transfer), kategori, dompet asal dan tujuan, biaya transfer, rincian transaksi terpisah (split) |
| Kategori | Nama, ikon, warna, jenis |
| Anggaran (budget) | Nama, batas, mata uang, periode, kategori terkait, deskripsi |
| Target (goal) | Nama, jumlah target, jumlah terkumpul, tenggat |
| Utang / piutang | Nama pihak terkait, alasan, jenis, jumlah pokok, jumlah terbayar, catatan, tag, tanggal |
| Kepemilikan saham | Kode saham, jumlah lot, harga rata-rata, catatan keyakinan (conviction note) |
| Transaksi terjadwal dan templat | Detail transaksi berulang yang Anda siapkan sendiri |
4.2 Data profil dan preferensi
- Nama tampilan yang Anda tulis sendiri (opsional)
- Foto profil dan foto latar yang Anda pilih sendiri, disimpan sebagai JPEG terenkode di preferensi lokal (opsional)
- Preferensi: mata uang, bahasa, mode tema, tampilan kategori, urutan dompet, status kunci biometrik, status izin notifikasi, status persetujuan AI
- Kurs mata uang yang tersimpan sementara (cache) beserta waktu pengambilannya
4.3 Riwayat percakapan AI
Jika Anda memakai fitur Chat, seluruh percakapan disimpan secara lokal: teks pesan Anda, jawaban model, usulan tindakan yang belum Anda konfirmasi, dan gambar kecil (thumbnail) dari foto yang Anda lampirkan atau yang Anda bagikan ke Pocket Hero dari aplikasi lain. Foto yang pernah Anda pindai tetap tersimpan di riwayat chat sampai Anda menghapusnya.
4.4 Akun dan sesi untuk fitur AI
Aplikasi tidak lagi meminta kunci API Google Gemini Anda; kunci itu kini milik pengembang dan berada di server kami, tidak pernah ada di perangkat Anda.
Sebagai gantinya, untuk memakai fitur AI Anda masuk dengan akun Google atau Sign in with Apple (sebelum 4 September 2026 pendaftarannya anonim; lihat Bagian 6.8 mengenai alasan perubahan ini). Dari proses itu kami menerima alamat email akun tersebut dan sebuah pengenal internal (UUID) — tidak ada nama lengkap, nomor telepon, daftar kontak, maupun akses apa pun ke akun Google atau Apple Anda selain itu. Bila Anda memakai Hide My Email milik Apple, yang sampai ke kami hanyalah alamat penerusan bikinan Apple, bukan email asli Anda.
Di perangkat, aplikasi menyimpan token sesi dari proses masuk itu beserta alamat email akun Anda, supaya Pengaturan dapat menampilkan akun mana yang sedang masuk. Token disimpan terenkripsi: Android Keystore (AES-GCM) di Android, dan Keychain di iOS. Token dan email itu tidak ikut terhapus ketika Anda menekan Hapus Data Saya — tombol itu menghapus data di perangkat, sedangkan langganan Anda tercatat atas akun tersebut, sehingga menghapusnya justru akan memutus langganan yang sudah Anda bayar. Untuk menghapus akun beserta catatannya di server, gunakan Pengaturan → Akun → Hapus Akun (Bagian 8). Token dan email juga hilang saat Anda keluar dari akun atau menghapus (uninstall) aplikasi, tetapi keluar dari akun tidak menghapus catatan di server — hanya Hapus Akun yang melakukannya.
4.5 Catatan penting tentang empat digit kartu
Tampilan kartu kredit di aplikasi menampilkan empat digit yang dibuat acak oleh aplikasi semata-mata sebagai hiasan visual. Aplikasi tidak pernah meminta, menerima, atau menyimpan nomor kartu, CVV, PIN, tanggal kedaluwarsa, kredensial perbankan, atau data pembayaran apa pun.
4.6 Data pihak ketiga di dalam kolom teks bebas
Beberapa kolom bersifat teks bebas: nama pihak pada catatan utang/piutang, catatan dan judul transaksi, serta catatan keyakinan saham. Anda mungkin menuliskan nama orang lain atau informasi yang berkaitan dengan orang lain di situ. Perlu Anda ketahui: data tersebut ikut tersimpan di perangkat Anda, dan ikut terkirim ke Google apabila Anda memakai fitur AI dan model perlu membaca catatan tersebut. Anda bertanggung jawab atas data orang lain yang Anda masukkan ke aplikasi ini.
5. Data yang TIDAK Dikumpulkan Aplikasi Ini
Untuk menghindari keraguan, aplikasi ini tidak mengumpulkan, tidak mengakses, dan tidak mengirim ke pengembang:
- Identitas Anda, di luar satu hal yang kami sebutkan terbuka: alamat email akun Google atau Apple yang Anda pakai untuk masuk ke fitur AI (Bagian 4.4 dan 6.8). Kami tidak pernah meminta nomor telepon, tanggal lahir, alamat, nama lengkap, atau kata sandi Anda — kata sandi akun Anda diketik di halaman Google atau Apple, bukan di aplikasi ini — dan seluruh fitur selain AI berjalan tanpa akun sama sekali
- Lokasi, baik presisi maupun perkiraan
- Daftar kontak, SMS, riwayat panggilan, kalender
- Daftar aplikasi terpasang
- Pengenal perangkat, Advertising ID, atau pengenal iklan apa pun
- Rekaman audio. Aplikasi tidak memiliki izin mikrofon
- Data penggunaan dan analitik perilaku. Aplikasi tidak mencatat layar mana yang Anda buka, tombol mana yang Anda tekan, atau berapa lama Anda memakainya — kecuali pada saat aplikasi berhenti bekerja, dan hanya sebatas yang dijelaskan pada Bagian 6.9
- Data biometrik. Sidik jari dan wajah Anda diproses sepenuhnya oleh sistem operasi; aplikasi hanya menerima jawaban berhasil atau gagal
Tidak ada SDK pihak ketiga untuk iklan, pelacakan lintas aplikasi, atau analitik perilaku yang tertanam dalam aplikasi ini. Satu-satunya SDK pihak ketiga yang tertanam adalah pelapor kerusakan (crash) yang dijelaskan pada Bagian 6.9; ia hanya berbicara saat aplikasi gagal, tidak mengikuti Anda ke aplikasi lain, dan tidak dipakai untuk iklan.
Perubahan dari versi sebelumnya, agar tidak ada yang tersembunyi. Sampai pembaruan ini, daftar di atas menyebutkan bahwa aplikasi tidak mengirim laporan kerusakan sama sekali. Itu tidak lagi benar: sejak 13 September 2026 aplikasi memuat Firebase Crashlytics, dan Bagian 6.9 menjelaskan apa saja yang dikirim. Pelaporan ini menyatu dengan persetujuan Anda atas dokumen ini dan tidak memiliki sakelar tersendiri di Pengaturan: sebelum Anda menyetujui dokumen ini, tidak ada satu pun laporan yang terkirim; bila Anda tidak menyetujuinya, aplikasi tidak dapat digunakan dan Anda dapat mengekspor data lalu menghapus pemasangannya.
Statistik dari toko aplikasi, agar tidak ada yang tersembunyi. Daftar di atas berbicara tentang apa yang dikumpulkan oleh aplikasi ini. Terpisah dari itu, Google Play dan Apple App Store sebagai penyelenggara toko memberi kami laporan tentang aplikasi yang kami terbitkan: jumlah pemasangan dan penghapusan, negara, jenis perangkat dan versi sistem operasi, penilaian dan ulasan, serta laporan kerusakan (crash) dan performa. Data itu dikumpulkan oleh Google dan Apple melalui layanan toko dan sistem operasi mereka sendiri — bukan oleh kode aplikasi ini — dan tunduk pada kebijakan privasi mereka, bukan kebijakan ini. Bentuk yang sampai ke kami adalah agregat: kami tidak dapat mengenali Anda sebagai perorangan darinya, dan tidak ada satu pun dari data itu yang berisi catatan keuangan Anda, yang tetap berada di perangkat Anda.
6. Pihak Ketiga dan Transfer Data ke Luar Wilayah Indonesia
6.1 Google Gemini API, hanya jika Anda menyalakan fitur AI
Fitur AI (Chat, Pindai Transaksi, Impor Cerdas, Analisis Investasi) mengirim data ke Google melalui generativelanguage.googleapis.com. Server Google berada di luar wilayah Indonesia. Sejak versi ini, pengiriman itu tidak lagi langsung dari perangkat Anda: ia melewati server kami terlebih dahulu — lihat Bagian 6.2, yang merupakan bagian tak terpisahkan dari penjelasan ini. Sebagian pesan Chat yang sederhana dijawab oleh model lain, Jev dari TypeSafe, dan tidak sampai ke Google — lihat Bagian 6.10.
Fitur ini mati secara bawaan. Saat pertama kali Anda membuka fitur AI, aplikasi menampilkan dialog persetujuan. Selama Anda belum menyetujui, tidak ada satu pun jalur di dalam aplikasi yang dapat mengirim data Anda: pemeriksaan persetujuan dilakukan pada lapisan jaringan, bukan sekadar pada tampilan.
Data yang dikirim bergantung pada fitur yang Anda pakai:
| Fitur | Yang dikirim ke Google |
|---|---|
| Chat | Pesan yang Anda ketik, dan, sesuai permintaan model saat menjawab pertanyaan Anda, daftar dompet, transaksi, anggaran, target, utang/piutang, dan kepemilikan saham Anda. Pengiriman ini dibatasi: bila model tidak menyebut rentang tanggal, hanya transaksi 90 hari terakhir yang disertakan; catatan bebas pada transaksi serta nama pihak dan alasan pada utang/piutang tidak disertakan kecuali pertanyaan Anda memang membutuhkannya; utang yang sudah lunas tidak disertakan kecuali diminta |
| Lampiran foto di Chat | Seluruh isi foto yang Anda lampirkan, dikirim utuh tanpa dipotong, hanya diperkecil ke sisi terpanjang 1280 piksel |
| Pindai Transaksi | Seluruh isi foto struk, bukti pembayaran, atau bukti transaksi saham yang Anda pindai, atau yang Anda bagikan ke Pocket Hero dari aplikasi lain (misalnya dompet digital atau m-banking), diperkecil ke sisi terpanjang 1280 piksel |
| Impor Cerdas | Seluruh isi berkas yang Anda pilih, misalnya rekening koran, termasuk data pihak lawan transaksi yang tercantum di dalamnya |
| Analisis Investasi | Daftar dompet dan kepemilikan saham Anda |
Dasar hukum transfer ke luar wilayah Indonesia. Pengiriman ini adalah transfer Data Pribadi ke luar wilayah hukum Republik Indonesia sebagaimana diatur Pasal 56 UU PDP. Kami tidak mendasarkannya pada penilaian tingkat pelindungan negara tujuan (Pasal 56 ayat (2)), tidak pula pada perjanjian pelindungan yang mengikat antara kami dan Google (Pasal 56 ayat (3)) — kami memang tidak memiliki perjanjian semacam itu. Dasar yang kami pakai adalah persetujuan Anda yang sah, eksplisit, dan spesifik menurut Pasal 56 ayat (4) UU PDP. Karena itulah fitur AI mati secara bawaan, persetujuan diminta terpisah sebelum pengiriman pertama, dan dapat Anda cabut kapan saja.
Kunci API sekarang milik pengembang, dan itu memperbesar tanggung jawab kami. Sebelumnya Anda mendaftar sendiri di Google AI Studio dan lalu lintas AI berjalan di luar jangkauan kami. Sekarang permintaan itu melewati server kami memakai kunci kami, sehingga secara teknis kami dapat melihat isinya saat sedang lewat. Kami memilih untuk tidak menyimpannya (Bagian 6.2), tetapi kami tidak menyembunyikan bahwa kemampuannya kini ada. Aplikasi inilah yang menyusun permintaan dan menentukan data apa yang disertakan, dan kami tetap berkedudukan sebagai pengendali data atas seluruh rancangan pengiriman itu.
Kedudukan Google. Google bukan prosesor data pribadi yang bekerja atas perintah kami: Google memproses data yang kami teruskan berdasarkan syarat layanannya sendiri, untuk tujuannya sendiri (termasuk pelatihan model pada tingkat gratis), dan kami tidak dapat memerintahkannya. Karena itu Google berkedudukan sebagai pengendali data yang berdiri sendiri, bukan prosesor kami, sehingga tidak ada perjanjian pengendali–prosesor sebagaimana dimaksud Pasal 51 UU PDP di antara kami. Konsekuensinya bagi Anda: hak-hak Anda atas data yang telanjur terkirim dijalankan langsung terhadap Google, sebagaimana disebut pada Bagian 9.
Pada tingkat gratis, Google menyatakan menggunakan konten yang dikirimkan untuk melatih dan meningkatkan produknya, dan peninjau manusia dapat membaca masukan serta keluaran API. Pada tingkat berbayar, Google menyatakan tidak menggunakan konten Anda untuk melatih model.
Karena kunci yang dipakai sekarang milik pengembang, tingkat layanan itu kami yang menentukan, bukan Anda — dan Anda tidak punya cara memverifikasinya sendiri. Maka anggaplah pelatihan model dan peninjauan oleh manusia sebagai kemungkinan yang nyata, dan jangan nyalakan fitur AI jika Anda tidak bersedia menanggungnya. Ketentuan Google dapat berubah sewaktu-waktu; rujukan yang berlaku adalah ai.google.dev/gemini-api/terms dan policies.google.com/privacy.
Anda dapat mencabut persetujuan kapan saja melalui Pengaturan → Berbagi Data AI. Pencabutan berlaku seketika untuk seluruh permintaan berikutnya. Pencabutan tidak menarik kembali data yang telanjur dikirim ke Google sebelumnya; untuk itu Anda perlu menghubungi Google secara langsung.
6.2 Server PocketHero sendiri (Supabase), hanya jika Anda menyalakan fitur AI
Sejak versi ini, permintaan fitur AI tidak lagi berjalan langsung dari perangkat Anda ke Google. Permintaan itu dikirim lebih dulu ke satu fungsi milik kami yang berjalan di Supabase (Supabase, Inc.), dan fungsi itulah yang meneruskannya ke Google — atau, untuk pesan chat sederhana, ke TypeSafe (Bagian 6.10) — memakai kunci API milik pengembang. Server Supabase yang kami pakai berada di luar wilayah Indonesia, sehingga dasar hukum transfer pada Bagian 6.1 berlaku sama untuk pengiriman ini.
Mengapa harus lewat server? Karena kunci API sekarang milik pengembang dan kamilah yang menanggung biayanya. Tanpa satu titik yang dapat menghitung dan menolak, siapa pun yang membongkar aplikasi dapat memakai kunci itu sebagai layanan AI gratis atas tagihan kami.
Apa yang disimpan di server itu:
- Akun Anda: sebuah pengenal pengguna (UUID) dan alamat email dari akun Google atau Apple yang Anda pakai untuk masuk. Tidak ada nama lengkap, nomor telepon, kata sandi, maupun pengenal perangkat yang ikut tersimpan.
- Untuk akun itu, per hari: jumlah permintaan AI, serta jumlah token masukan dan keluaran — angka pemakaian, bukan isinya.
- Catatan persetujuan AI. Untuk pengenal itu: nomor versi teks persetujuan yang Anda setujui, waktu Anda menekan Setuju menurut perangkat Anda, dan waktu server kami pertama kali melihat persetujuan itu. Ini bukan untuk mengenali Anda, melainkan bukti bahwa fitur AI tidak pernah dinyalakan tanpa persetujuan — kewajiban kami sebagai pengendali data menurut Pasal 20 UU PDP. Tidak ada isi permintaan Anda yang ikut tercatat.
- Bukti langganan, bila Anda membeli. Untuk pengenal itu: nomor kuitansi pembelian dari Google Play atau App Store, nama toko tersebut, id produk yang Anda beli, dan tanggal berakhirnya. Rinciannya pada Bagian 6.7.
- Alamat IP pada data sesi masuk, sementara. Supabase mencatat alamat IP perangkat Anda pada data sesi saat Anda masuk, sebagaimana lazimnya layanan autentikasi. Kami tidak memakainya untuk apa pun, jadi kami menghapusnya otomatis setiap jam. Artinya IP pada data sesi itu paling lama tersimpan satu jam, lalu hilang permanen dan tidak lagi dapat dihubungkan dengan angka pemakaian di atas.
- Log teknis server, paling lama 1 hari. Setiap permintaan ke server kami — permintaan fitur AI, proses masuk, pemeriksaan langganan, dan pengambilan kurs — otomatis dicatat oleh Supabase di log teknis, bukan oleh kode kami. Log itu berisi: waktu, alamat endpoint, kode status, alamat IP, perkiraan lokasi yang diturunkan dari IP (negara, provinsi, kota, kode pos), nama penyedia internet, jenis aplikasi/perangkat yang mengirim (user agent), serta pengenal akun (UUID) dan pengenal sesi yang terbaca dari token masuk; log proses masuk juga memuat alamat email Anda. Isi permintaan Anda tidak ada di dalamnya. Kami tidak dapat mematikan pencatatan ini karena ia bagian dari infrastruktur Supabase; kami hanya membukanya bila perlu menyelidiki gangguan atau penyalahgunaan. Supabase menghapus log itu otomatis setelah 1 hari pada paket layanan yang kami pakai saat ini. Hapus Akun tidak mempercepat penghapusannya.
Apa yang TIDAK disimpan di server itu: isi pesan chat Anda, foto, berkas yang Anda impor, dompet, transaksi, anggaran, target, utang/piutang, kepemilikan saham, maupun jawaban model. Data itu melewati server sebagai lalu lintas dan diteruskan; ia tidak dituliskan ke basis data mana pun milik kami, dan tidak ikut tercatat di log server — log teknis di atas tidak pernah memuat isi permintaan. Kami tidak dapat membaca kembali percakapan Anda kemarin, karena tidak ada salinannya pada kami. Yang kami minta Anda pahami dengan jujur: selama data itu sedang lewat, secara teknis ia berada di infrastruktur kami — jaminan di sini adalah janji dan rancangan, bukan ketidakmampuan teknis.
Kedudukan Supabase. Supabase, Inc. menjalankan infrastruktur atas instruksi kami dan tidak memakai data itu untuk tujuannya sendiri; dalam kerangka UU PDP, Supabase adalah prosesor, sedangkan pengendalinya tetap kami. Kebijakan privasinya: supabase.com/privacy.
Penghapusan. Menghapus (uninstall) aplikasi tidak menghapus baris-baris itu dari server kami, karena kami tidak punya cara mengetahui perangkat mana yang dicopot. Yang menghapusnya adalah Pengaturan → Akun → Hapus Akun: seluruh isi daftar di atas — akun beserta emailnya, angka pemakaian, catatan persetujuan, dan catatan langganan — terhapus permanen dalam satu tindakan, tanpa perlu mengirim permintaan kepada kami dan tanpa menunggu. Anda tetap dapat memakai jalur email pada Bagian 2 bila Anda tidak lagi dapat membuka aplikasinya. Dua hal yang perlu Anda ketahui sebelum menekannya, keduanya juga ditampilkan pada dialog konfirmasi di aplikasi: menghapus catatan persetujuan berarti menghapus pula bukti bahwa Anda pernah menyetujuinya, dan yang tertinggal setelahnya hanyalah dua catatan yang keduanya sudah diputus dari identitas Anda — catatan pembelian, dan penghitung pemakaian harian yang melekat pada langganan alih-alih pada akun (Bagian 8).
6.3 Kurs mata uang
Untuk mengonversi saldo antar mata uang, aplikasi mengambil tabel kurs dari server PocketHero sendiri (Supabase). Sebelumnya berkas itu diambil langsung dari CDN pihak ketiga cdn.jsdelivr.net; sejak 2 September 2026 tidak lagi, sehingga tidak ada pihak ketiga yang terlibat dalam pembaruan kurs.
Permintaan ini kosong: ia tidak memuat data keuangan Anda, tidak memuat mata uang yang Anda pilih, dan tidak memuat pengenal apa pun — aplikasi hanya meminta seluruh tabel kurs dan melakukan perhitungannya sendiri di perangkat Anda. Berbeda dengan Bagian 6.1 dan 6.2, permintaan ini tidak memerlukan persetujuan fitur AI dan tidak disertai sesi masuk apa pun. Seperti setiap permintaan HTTP, server kami menerima alamat IP dan waktu permintaan; keduanya tidak kami simpan ke basis data mana pun, tetapi ikut tercatat di log teknis Supabase selama paling lama 1 hari (lihat Bagian 6.2).
Kurs itu sendiri sama untuk semua pengguna dan tidak terkait dengan siapa pun. Aplikasi menyimpannya di perangkat Anda dan hanya memperbaruinya bila salinan itu sudah lebih tua dari 24 jam.
6.4 Pencadangan dan ekspor yang Anda lakukan sendiri
Fitur Cadangkan dan Pulihkan memungkinkan Anda menyimpan salinan data ke lokasi yang Anda pilih sendiri, serta mengekspor ke CSV atau JSON.
Ekspor CSV dan JSON tidak pernah dienkripsi, di kedua platform. Begitu Anda menyimpan salah satu berkas ini ke Google Drive, iCloud Drive, kartu SD, folder unduhan, atau mengirimkannya lewat aplikasi pesan, berkas itu keluar dari seluruh perlindungan aplikasi ini dan tunduk pada kebijakan privasi layanan tujuan tersebut. Simpanlah hanya di tempat yang Anda percayai.
6.5 Layanan sistem operasi
- Kamera dan galeri foto dibuka hanya ketika Anda menekan tombol pindai atau lampirkan. Aplikasi hanya menerima foto yang Anda pilih.
- Berbagi dari aplikasi lain. Saat Anda menekan Bagikan pada sebuah gambar di aplikasi lain lalu memilih Pocket Hero, aplikasi hanya menerima gambar yang Anda bagikan itu, bukan isi galeri Anda. Gambar tersebut diproses sama seperti foto yang Anda pindai: dikirim untuk dibaca hanya jika Anda sudah menyetujui pemrosesan AI, dan setiap transaksi yang terbaca baru tersimpan setelah Anda mengonfirmasinya.
- Biometrik (sidik jari atau Face ID) diproses seluruhnya oleh sistem operasi. Aplikasi tidak pernah melihat data biometrik Anda.
- Notifikasi hanya berupa pengingat lokal — jatuh tempo tagihan kartu kredit, transaksi terencana, dan pengingat merawat karakter hero di dalam aplikasi — yang dijadwalkan di perangkat Anda. Tidak ada layanan push, tidak ada token perangkat, dan tidak ada server yang terlibat.
6.6 Pemeriksaan versi minimum
Saat dibuka, aplikasi mengambil sebuah berkas kecil dari pockethero.pages.dev (Cloudflare Pages) yang hanya berisi nomor versi minimum yang masih kami dukung. Permintaan ini tidak memuat data apa pun tentang Anda — tidak ada data keuangan, tidak ada pengenal perangkat, dan tidak ada nomor pemasangan. Aplikasi hanya membaca angka tersebut lalu membandingkannya dengan versi yang terpasang di perangkat Anda. Seperti setiap permintaan HTTP, Cloudflare sebagai penyedia hosting dapat melihat alamat IP dan waktu permintaan Anda. Berkas legal yang Anda buka dari Pengaturan dilayani dari alamat yang sama.
6.7 Pembelian dan langganan
Fitur AI dijual sebagai langganan. Seluruh pembayaran diproses oleh toko tempat Anda memasang aplikasi ini: Google Play (Google LLC) di Android, dan App Store (Apple Inc.) di iPhone dan iPad. Kami tidak pernah menerima, memproses, atau menyimpan nomor kartu maupun data pembayaran Anda, dan kami tidak melihat nama atau alamat email akun Google maupun Apple ID Anda pada proses pembelian itu.
Yang kami simpan hanyalah bukti bahwa langganan itu ada: nomor kuitansi pembelian dari toko yang bersangkutan (token pembelian dari Google Play, atau original transaction id dari App Store), nama toko tersebut, id produk, dan tanggal berakhirnya, tersimpan di server kami (Bagian 6.2) dan terhubung ke akun tempat Anda masuk (Bagian 4.4) — bukan ke data pembayaran Anda, yang tidak pernah kami terima. Aplikasi mengirim nomor kuitansi itu ke server kami, lalu server kami menanyakannya langsung ke Google atau ke Apple untuk memastikan langganan tersebut benar-benar aktif; kami tidak pernah mempercayai klaim dari aplikasi itu sendiri. Riwayat pembelian selengkapnya tetap berada di Google Play atau App Store dan tidak kami salin.
Pembatalan dan pengembalian dana berlangsung di toko tempat Anda membeli — Google Play atau App Store; server kami baru mengetahuinya pada pemeriksaan berikutnya. Menghapus akun (Bagian 8) juga menghapus catatan langganan itu, dengan satu konsekuensi yang perlu Anda ketahui dan yang kami tampilkan pada dialog konfirmasinya: catatan itulah satu-satunya bukti hak Anda pada kami, sehingga menghapusnya menutup akses fitur AI meskipun langganan Anda masih berjalan dan masih ditagihkan oleh toko tersebut. Penutupan itu tidak permanen: selama periode yang sudah Anda bayar masih berjalan, akses dapat dikembalikan dengan masuk memakai akun baru lalu menekan Pulihkan Pembelian, karena hak langganan mengikuti bukti pembelian di toko dan bukan akun yang Anda hapus. Menghapus akun bukan pembatalan langganan — pembatalan dilakukan di Google Play atau App Store, dan sebaiknya Anda lakukan lebih dulu.
6.8 Masuk dengan Google atau Apple
Sejak 4 September 2026, fitur AI memerlukan Anda masuk dengan akun Google (Google LLC) atau Sign in with Apple (Apple Inc.). Proses masuk berlangsung pada lembar (sheet) masuk bawaan sistem milik Google atau Apple yang muncul di atas aplikasi — Anda memilih akun yang sudah ada di perangkat, dan bila sistem itu tidak tersedia barulah proses masuk Google dialihkan ke halaman milik Google yang dibuka di peramban perangkat Anda. Pada semua jalur tersebut, kata sandi Anda tidak pernah diketik di dalam aplikasi ini dan tidak pernah kami lihat. Yang kembali ke aplikasi hanyalah tanda masuk (token) dan alamat email akun tersebut.
Mengapa berubah dari anonim? Dengan pendaftaran anonim, pengenal pengguna dibuat ulang setiap kali aplikasi dipasang ulang, sehingga batas pemakaian dan bukti langganan tidak dapat bertahan — langganan yang sudah dibayar bisa hilang hanya karena ganti perangkat, dan biaya layanan AI yang kami tanggung tidak dapat dijaga. Akun menyelesaikan keduanya sekaligus. Kami sadar ini menambah satu data pribadi yang sebelumnya tidak ada, dan itulah sebabnya perubahan ini disampaikan lewat persetujuan ulang, bukan diam-diam.
Google dan Apple memproses proses masuk itu menurut kebijakan privasi mereka sendiri, dan server keduanya berada di luar wilayah Indonesia — dasar hukum transfer pada Bagian 6.1 berlaku sama untuk pengiriman ini. Kebijakan mereka: policies.google.com/privacy dan apple.com/legal/privacy.
Kami tidak pernah meminta izin apa pun atas akun Anda selain identitas dasar itu: tidak ada akses ke Gmail, Drive, kontak, kalender, maupun foto Anda.
6.9 Laporan kerusakan (Firebase Crashlytics)
Sejak 13 September 2026 aplikasi memuat Firebase Crashlytics (Google LLC). Tujuannya satu: mengetahui bahwa aplikasi berhenti bekerja atau membeku di perangkat Anda, dan di bagian kode mana hal itu terjadi. Tanpa ini, satu-satunya laporan yang kami terima adalah keluhan yang harus Anda tulis sendiri, dan kerusakan yang hanya muncul di sebagian perangkat praktis tidak dapat kami perbaiki.
Kapan ia berbicara. Crashlytics tidak mengirim apa pun selama aplikasi berjalan normal. Ia mengirim laporan hanya ketika aplikasi berhenti tiba-tiba (crash), membeku sehingga sistem operasi menghentikannya (ANR), atau ketika aplikasi menemui kesalahan yang sudah kami tangani namun tetap ingin kami ketahui — misalnya sebuah pencadangan yang gagal dipulihkan. Laporan itu dikirim pada saat aplikasi dibuka berikutnya, bukan seketika.
Yang ada di dalam sebuah laporan:
- Jejak kesalahan teknis (stack trace): daftar nama fungsi di dalam kode kami yang sedang berjalan saat kerusakan terjadi, beserta nomor barisnya
- Keterangan perangkat dan aplikasi: model perangkat, pabrikan, versi sistem operasi, orientasi layar, sisa memori dan ruang penyimpanan, status baterai, apakah perangkat di-root atau jailbreak, serta versi aplikasi yang Anda pasang
- Nama layar yang sedang Anda buka saat kerusakan terjadi — sebatas namanya di dalam kode, misalnya
HeroDetailatauReports. Bukan isi layarnya, dan bukan dompet, kategori, atau transaksi mana pun yang sedang ditampilkan - Sebuah pengenal pemasangan yang dibuat oleh Crashlytics untuk membedakan satu pemasangan dari pemasangan lain, sehingga sepuluh laporan dari satu perangkat tidak terhitung sebagai sepuluh pengguna. Pengenal itu bukan pengenal perangkat maupun Advertising ID: ia tidak dibaca dari perangkat, dibuat ulang bila aplikasi dipasang ulang, dan tidak dapat dipakai untuk mengenali Anda di aplikasi lain
Yang tidak pernah ada di dalamnya. Kami tidak mengirimkan catatan keuangan Anda, saldo, transaksi, nama dompet, riwayat percakapan AI, foto, alamat email, maupun basis data Anda — baik seluruhnya maupun sepotong. Kami juga tidak menyalakan Firebase Analytics, dan tidak memasang Advertising ID atau SDK pelacakan apa pun. Sifat laporannya teknis, bukan perilaku: ia menjelaskan kode kami yang gagal, bukan apa yang Anda lakukan.
Satu batas yang perlu Anda ketahui secara jujur. Sebuah jejak kesalahan dapat memuat pesan kesalahan yang ditulis oleh kode kami sendiri, dan pesan seperti itu pada prinsipnya dapat memuat sebuah nilai yang sedang diproses saat kegagalan terjadi. Kami tidak pernah sengaja menaruh data keuangan Anda di sana, dan tidak ada satu pun kolom pada daftar di atas yang dirancang untuk memuatnya. Kami menyebutkannya karena kami tidak dapat menjamin kemungkinan itu nol untuk setiap kerusakan yang belum pernah terjadi.
Kedudukan Google. Google LLC menjalankan Crashlytics atas instruksi kami dan menurut Firebase Data Processing and Security Terms; dalam kerangka UU PDP Google adalah prosesor, sedangkan pengendalinya tetap kami. Servernya berada di luar wilayah Indonesia, sehingga dasar hukum transfer pada Bagian 6.1 berlaku sama untuk pengiriman ini. Kebijakan privasinya: policies.google.com/privacy, dan keterangan Google sendiri tentang data yang dikumpulkan Crashlytics: firebase.google.com/support/privacy.
Persetujuan dan cara menolak. Pelaporan ini dimatikan sejak awal di dalam aplikasi dan baru menyala setelah Anda menyetujui dokumen ini beserta Syarat dan Ketentuan — tidak ada satu pun laporan yang terkirim sebelum itu. Ia tidak memiliki sakelar tersendiri di Pengaturan, dan sengaja tidak digabungkan dengan sakelar Berbagi Data AI: keduanya perkara yang berbeda, dan sakelar AI hanya mengatur pengiriman ke Gemini pada Bagian 6.1. Menolak pelaporan kerusakan karena itu berarti tidak menyetujui dokumen ini; pada layar persetujuan tersedia tombol untuk mengekspor data Anda dan untuk menghapusnya dari perangkat, sehingga Anda dapat berhenti tanpa kehilangan catatan Anda.
Berapa lama disimpan. Google menyimpan data kerusakan Crashlytics paling lama 90 hari, lalu memusnahkannya. Kami tidak menyalin laporan itu ke tempat lain dan tidak menggabungkannya dengan akun Anda pada Bagian 4.4 — kami sengaja tidak mengirimkan pengenal akun maupun alamat email Anda ke Crashlytics, sehingga sebuah laporan kerusakan tidak dapat kami hubungkan dengan akun Anda.
6.10 TypeSafe (model Jev), hanya jika Anda menyalakan fitur AI
Sejak 19 September 2026, sebagian pesan Chat dijawab lebih dulu oleh Jev, model bahasa milik TypeSafe AI, Inc. (Amerika Serikat), alih-alih oleh Google Gemini. Jev hanya dipakai untuk pesan teks yang sederhana: mencatat satu pengeluaran, pemasukan, atau transfer antardompet (“kopi 20rb”), menanyakan satu total atau saldo (“pengeluaran bulan ini berapa?”), serta sapaan singkat. Pesan yang lebih rumit, serta setiap pesan yang tidak dapat dijawab Jev dengan cukup yakin, diteruskan ke Google Gemini seperti biasa (Bagian 6.1). Pesan yang disertai foto tidak pernah dikirim ke Jev.
Yang dikirim ke TypeSafe: teks pesan yang Anda ketik, balasan asisten tepat sebelumnya (paling banyak 500 karakter) bila ada, serta daftar nama dompet dan kategori Anda sebagai pilihan jawaban. Saldo, riwayat transaksi, anggaran, target, utang/piutang, kepemilikan saham, email, dan pengenal akun Anda tidak dikirim. Jumlah uang pada pesan dibaca oleh kode kami sendiri, bukan oleh Jev, dan total atau saldo yang ditanyakan dihitung di perangkat Anda.
Pengiriman ini berjalan dari server kami (Bagian 6.2) memakai kunci API milik pengembang, hanya setelah Anda menyetujui fitur AI, dan tunduk pada persetujuan serta dasar hukum transfer yang sama dengan Bagian 6.1 (Pasal 56 ayat (4) UU PDP): server TypeSafe berada di Amerika Serikat, di luar wilayah Indonesia. Server kami tidak menyimpan isi pesan maupun jawaban Jev; yang tercatat hanya angka pemakaian (jumlah permintaan dan token), sama seperti untuk Gemini.
Kedudukan TypeSafe. Kebijakan privasi TypeSafe menyatakan bahwa ia tidak melatih atau menyempurnakan model apa pun dengan masukan yang dikirimkan kepadanya dan tidak membuka masukan itu kepada pihak ketiga selain penyedia layanannya sendiri. TypeSafe memproses permintaan kami untuk menjalankan fitur yang Anda minta; kebijakan tersebut tidak menyebut masa simpan yang pasti untuk masukan API, hanya “selama wajar diperlukan untuk menyediakan layanan”. Ketentuan TypeSafe dapat berubah sewaktu-waktu; rujukan yang berlaku adalah typesafe.ai/privacy.
Mencabut persetujuan AI (Bagian 6.1) menghentikan pengiriman ke TypeSafe sekaligus ke Google. Untuk data yang telanjur terkirim, hubungi TypeSafe secara langsung.
7. Dasar Hukum dan Tujuan Pemrosesan
| Aktivitas | Tujuan | Dasar hukum (UU PDP Pasal 20) |
|---|---|---|
| Menyimpan catatan keuangan di perangkat | Menjalankan fungsi utama aplikasi yang Anda pasang | Pemenuhan perjanjian dengan subjek data, Pasal 20 ayat (2) huruf b |
| Menyimpan preferensi dan profil | Menyesuaikan tampilan sesuai pilihan Anda | Pemenuhan perjanjian, Pasal 20 ayat (2) huruf b |
| Menyimpan akun (pengenal dan alamat email) untuk fitur AI | Mengetahui pemilik langganan, dan menjaga hak yang sudah Anda bayar tetap ada saat ganti perangkat | Pemenuhan perjanjian dengan subjek data, Pasal 20 ayat (2) huruf b |
| Menghitung pemakaian AI per akun di server kami | Membatasi penyalahgunaan dan menanggung biaya layanan AI yang kami bayar | Kepentingan yang sah, Pasal 20 ayat (2) huruf f |
| Mengirim data ke server kami lalu ke Google Gemini atau TypeSafe (Jev) | Menjalankan fitur AI yang Anda minta | Persetujuan yang sah, eksplisit, dan spesifik, Pasal 20 ayat (2) huruf a jo. Pasal 22 |
| Menyimpan dan memverifikasi bukti langganan | Memberi akses fitur AI yang Anda beli, dan mencegah satu langganan dipakai banyak orang | Pemenuhan perjanjian dengan subjek data, Pasal 20 ayat (2) huruf b |
| Mengambil kurs mata uang | Konversi antar mata uang | Pemenuhan perjanjian, Pasal 20 ayat (2) huruf b |
| Log teknis server oleh Supabase (Bagian 6.2), disimpan paling lama 1 hari | Menjaga keamanan server dan menyelidiki gangguan atau penyalahgunaan | Kepentingan yang sah, Pasal 20 ayat (2) huruf f |
| Pengingat lokal (jatuh tempo kartu kredit, transaksi terencana, perawatan hero) | Fitur yang Anda aktifkan sendiri | Persetujuan, Pasal 20 ayat (2) huruf a |
| Mengirim laporan kerusakan teknis ke Firebase Crashlytics (Bagian 6.9) | Mengetahui dan memperbaiki kerusakan serta pembekuan aplikasi yang tidak dapat kami temukan sendiri | Kepentingan yang sah, Pasal 20 ayat (2) huruf f, dalam batas persetujuan Anda atas dokumen ini |
| Menyimpan catatan pembelian tanpa identitas setelah akun Anda dihapus | Memenuhi kewajiban menyimpan bukti transaksi untuk pembukuan dan perpajakan | Kewajiban hukum pengendali, Pasal 20 ayat (2) huruf d, jo. Pasal 28 ayat (11) UU KUP |
Data keuangan pribadi termasuk data pribadi spesifik menurut Pasal 4 ayat (2) UU PDP. Karena itu persetujuan untuk fitur AI diminta terpisah dari pemasangan aplikasi, disampaikan dalam bahasa yang jelas, dan dapat ditarik kembali dengan cara yang sama mudahnya dengan cara memberikannya.
8. Penyimpanan, Retensi, dan Penghapusan
Data Anda tersimpan selama aplikasi terpasang. Catatan keuangan Anda tidak memiliki masa retensi di sisi pengembang, karena catatan itu tidak pernah berada di sisi pengembang. Dua hal yang memang berada di sisi kami memiliki masa retensinya sendiri: catatan akun dan langganan, yang diuraikan pada tabel dan paragraf di bawah, serta laporan kerusakan teknis pada Bagian 6.9 yang dimusnahkan Google setelah 90 hari dan tidak terhubung dengan akun Anda.
| Cara | Yang terhapus |
|---|---|
| Menghapus satu catatan di dalam aplikasi | Catatan tersebut, seketika dan permanen |
| Pengaturan → Hapus Data Saya, atau tombol Hapus data saya dari perangkat ini pada layar persetujuan ulang | Seluruh data keuangan, seluruh riwayat chat beserta foto di dalamnya, serta nama tampilan dan foto profil maupun foto latar yang Anda pilih. Dompet dan kategori bawaan dibuat ulang agar aplikasi tetap dapat digunakan. Sebelum menghapus, aplikasi menampilkan dialog konfirmasi yang merinci apa yang dihapus dan apa yang dipertahankan. |
| Pengaturan → Akun → Hapus Akun | Akun Anda di server kami beserta seluruh yang menempel padanya: alamat email, angka pemakaian AI, catatan persetujuan AI, dan catatan langganan. Data di perangkat Anda tidak ikut terhapus — gunakan Hapus Data Saya untuk itu. Dialog konfirmasinya merinci keduanya sebelum ada yang dihapus. |
| Keluar dari akun (Pengaturan → Akun → Keluar) | Tidak ada. Hanya sesi di perangkat ini yang berakhir; data di perangkat dan catatan di server tetap utuh. |
| Menghapus (uninstall) aplikasi | Seluruh basis data dan preferensi lokal. Catatan di server kami tidak ikut terhapus, karena kami tidak dapat mengetahui perangkat mana yang dicopot. |
Yang sengaja dipertahankan oleh Hapus Data Saya: akun Anda beserta catatan langganan yang terikat padanya (lihat Bagian 4.4). Keduanya tidak memuat data keuangan Anda, dan mempertahankannya berarti Anda dapat menghapus seluruh data di perangkat lalu melanjutkan paket berbayar yang sama tanpa membayar dua kali. Jika akun itu pun ingin Anda hapus, gunakan Hapus Akun pada baris di atas.
Yang tetap kami simpan setelah akun dihapus, dan mengapa. Bila Anda pernah membeli langganan, satu baris catatan pembelian tetap kami simpan: platform toko, id produk, nomor kuitansi (token pembelian) dari Google atau Apple, dan tanggal berlakunya. Baris itu diputus dari identitas Anda pada saat penghapusan — kolom yang menghubungkannya dengan akun dihapus, sehingga tidak ada lagi cara di basis data kami untuk mengetahui bahwa pembelian itu milik Anda.
Dasarnya adalah benturan dua kewajiban yang keduanya mengikat kami: hak penghapusan pada Pasal 8 UU PDP, dan kewajiban menyimpan bukti transaksi untuk pembukuan dan perpajakan — Pasal 28 ayat (11) UU KUP mewajibkan dokumen dasar pembukuan disimpan 10 tahun. Anonimisasi adalah jalan yang memenuhi keduanya: data pribadi Anda hilang, bukti transaksinya tinggal. Pasal 43 ayat (2) UU PDP sendiri mengizinkan penundaan penghapusan sepanjang data masih diperlukan untuk memenuhi kewajiban penyimpanan menurut peraturan perundang-undangan. Catatan itu kami musnahkan setelah masa 10 tahun tersebut lewat. Riwayat pembelian selengkapnya tetap berada di Google Play atau App Store dan tunduk pada kebijakan mereka, bukan kebijakan ini.
Hal kedua yang tetap kami simpan, dan hanya bila Anda berlangganan: penghitung pemakaian AI harian yang melekat pada langganan Anda, bukan pada akun Anda. Isinya tiga hal per hari: tanggal, jumlah permintaan AI, dan jumlah token masukan dan keluaran — angka pemakaian, bukan isinya, sama seperti penghitung per akun pada Bagian 6.2. Yang membedakannya, penghitung ini tidak menyimpan pengenal akun maupun alamat email Anda; yang dipakai sebagai penanda adalah sidik jari satu arah (hash SHA-256) dari nomor kuitansi pembelian Anda. Sidik jari itu tidak dapat dikembalikan menjadi nomor kuitansinya, dan nomor kuitansi itu sendiri — sebagaimana dijelaskan di atas — tidak menunjuk kepada siapa pun tanpa akses ke konsol Google Play atau App Store.
Mengapa yang ini tidak ikut terhapus. Batas pemakaian wajar harian hanya bermakna bila ia tidak dapat disetel ulang. Bila penghitung ini ikut terhapus bersama akun, siapa pun dapat memulihkan jatah hariannya berkali-kali dalam satu hari dengan menghapus akun lalu memulihkan pembeliannya — dan biaya yang timbul ditanggung bersama oleh semua pengguna dalam bentuk plafon harian layanan yang lebih cepat habis. Kami memilih menyimpan angka tanpa identitas ini justru agar kami tidak perlu menyimpan pengenal perangkat atau memaksa pendaftaran yang mengikat, yang keduanya akan mengetahui lebih banyak tentang Anda, bukan lebih sedikit. Dasar hukumnya kepentingan yang sah, Pasal 20 ayat (2) huruf f UU PDP. Kami menyimpannya selama langganan yang bersangkutan masih relevan bagi pembukuan, dan memusnahkannya bersama arsip pembelian pada masa 10 tahun yang sama.
Satu pengecualian yang disengaja: Hapus Data Saya tidak mematikan persetujuan AI Anda. Menghapus data bukanlah menarik persetujuan, dan mematikannya secara diam-diam akan membuat Anda dihadang dialog persetujuan yang tidak Anda minta pada penggunaan berikutnya. Untuk menarik persetujuan, gunakan sakelar Berbagi Data AI di Pengaturan.
Angka statistik, yang bukan catatan tentang Anda. Kami menyimpan beberapa pencacah agregat sederhana: berapa akun yang pernah terdaftar, berapa yang sudah dihapus, berapa di antaranya yang pernah memakai fitur AI, dan jumlah total pemakaian AI. Semuanya berbentuk satu angka yang naik — misalnya dari 20 menjadi 21 — tanpa satu pun kolom yang menyebutkan akun mana yang menaikkannya. Angka-angka ini tidak ikut terhapus saat Anda menghapus akun, karena tidak ada yang bisa dihapus di sana: tidak ada baris milik Anda, hanya sebuah bilangan. Catatan yang benar-benar tentang Anda — alamat email, angka pemakaian AI yang tercatat atas akun Anda, catatan persetujuan, catatan langganan — tetap terhapus seluruhnya sebagaimana tabel di atas, dengan satu batas yang kami sebutkan terbuka dua paragraf di atas: penghitung pemakaian harian yang melekat pada langganan, bukan pada akun, tidak ikut terhapus.
Berkas cadangan yang telah Anda simpan di luar aplikasi tidak ikut terhapus oleh tindakan mana pun di atas. Anda harus menghapusnya sendiri.
9. Hak Anda sebagai Subjek Data
Pasal 5 sampai Pasal 13 UU PDP memberi Anda hak-hak berikut. Karena data Anda berada di perangkat Anda sendiri, sebagian besar hak ini dapat Anda jalankan langsung tanpa perlu mengajukan permintaan kepada siapa pun:
| Hak | Dasar | Cara menggunakannya |
|---|---|---|
| Informasi tentang pemrosesan | Pasal 5 | Dokumen ini, dan dialog persetujuan di dalam aplikasi |
| Akses dan memperoleh salinan | Pasal 7 | Buka aplikasi, atau ekspor ke CSV/JSON lewat Cadangkan dan Pulihkan |
| Memperbaiki data | Pasal 6 | Sunting catatan mana pun langsung di aplikasi |
| Menghapus data | Pasal 8 | Hapus per catatan, Pengaturan → Hapus Data Saya untuk data di perangkat, dan Pengaturan → Akun → Hapus Akun untuk akun beserta catatannya di server kami. Jika Anda tidak menyetujui perubahan dokumen ini, tombol Hapus Data Saya tersedia langsung pada layar persetujuan ulang, tanpa perlu menyetujui apa pun terlebih dahulu. Batasnya disebutkan terbuka pada Bagian 8: catatan pembelian yang sudah dianonimkan, dan pencacah agregat yang tidak memuat catatan tentang siapa pun |
| Menarik persetujuan | Pasal 9 | Pengaturan → Berbagi Data AI, berlaku seketika |
| Keberatan atas keputusan otomatis | Pasal 10 | Aplikasi tidak pernah mengambil keputusan otomatis atas diri Anda. Setiap usulan tindakan dari AI selalu menunggu konfirmasi Anda sebelum dijalankan. |
| Menunda atau membatasi pemrosesan | Pasal 11 | Matikan sakelar Berbagi Data AI. Aplikasi tetap berfungsi penuh secara luring |
| Portabilitas data | Pasal 13 | Ekspor JSON atau CSV lewat Cadangkan dan Pulihkan |
| Menggugat dan menerima ganti rugi | Pasal 12 | Hubungi kami lewat email pada Bagian 2, atau ajukan pengaduan kepada lembaga berwenang |
Untuk data yang sudah terkirim ke Google atau TypeSafe, hak-hak di atas dijalankan terhadap pihak tersebut sesuai kebijakan privasi masing-masing, karena pengembang tidak menyimpan dan tidak dapat mengakses data tersebut.
10. Keamanan
Langkah teknis yang diterapkan (Pasal 35 dan Pasal 39 UU PDP):
- Data disimpan di penyimpanan privat aplikasi, tidak dapat diakses aplikasi lain pada perangkat yang tidak dibobol (non-root atau non-jailbreak)
- Pencadangan otomatis Android dimatikan (
allowBackup="false"), sehingga basis data tidak ikut tersalin ke cloud Google - Di iOS, berkas basis data dikecualikan dari cadangan iCloud/iTunes dan diberi kelas perlindungan
NSFileProtectionCompleteUntilFirstUserAuthentication - Seluruh basis data dienkripsi di penyimpanan (SQLCipher, AES-256), di Android maupun di iOS. Kuncinya dibuat acak di perangkat Anda dan dilindungi Android Keystore di Android atau iOS Keychain di iOS; kunci itu tidak pernah meninggalkan perangkat dan tidak pernah kami ketahui
- Token sesi AI dienkripsi dengan Android Keystore (AES-GCM) atau iOS Keychain
- Seluruh komunikasi jaringan menggunakan HTTPS
- Kunci aplikasi dengan biometrik tersedia dan dapat Anda aktifkan
- Saat kunci biometrik aktif, Android menonaktifkan tangkapan layar dan menyembunyikan pratinjau aplikasi di daftar aplikasi terbaru, sehingga isi layar tidak terbaca dari sana tanpa membuka kunci
Server kami tidak menyimpan satu pun catatan keuangan — yang ada di sana hanya pengenal anonim, angka pemakaian, dan bukti langganan (Bagian 6.2 dan 6.7) — sehingga kebocoran pada server itu tidak mengungkap data keuangan siapa pun. Meski begitu, kami tidak lagi menyatakan bahwa skenario kebocoran terpusat mustahil: bila terjadi kegagalan pelindungan data pribadi pada server itu, kami akan memberitahukannya sesuai kewajiban 3 x 24 jam pada Pasal 46 UU PDP. Hal yang sama berlaku bila ditemukan celah keamanan pada aplikasi yang berpotensi mengungkap data di perangkat: kami mengumumkannya melalui pembaruan halaman ini dan catatan rilis aplikasi.
11. Batas Usia
Aplikasi ini ditujukan untuk pengguna berusia 18 tahun ke atas dan tidak dirancang untuk anak. Kami tidak dengan sengaja mengumpulkan data anak. Sesuai Pasal 25 dan Pasal 26 UU PDP, pemrosesan data anak memerlukan persetujuan orang tua atau wali. Jika Anda berusia di bawah 18 tahun, jangan gunakan fitur AI tanpa persetujuan orang tua atau wali Anda.
12. Izin Perangkat yang Diminta
| Izin | Platform | Untuk apa | Wajib? |
|---|---|---|---|
| Internet | Android | Fitur AI dan pembaruan kurs | Ya, tetapi hanya terpakai saat fitur tersebut digunakan |
| Kamera | Android dan iOS | Memotret struk atau bukti transaksi | Tidak |
| Galeri foto | iOS | Memilih foto yang sudah ada | Tidak |
| Biometrik / Face ID | Android dan iOS | Mengunci aplikasi | Tidak |
| Notifikasi | Android dan iOS | Pengingat jatuh tempo kartu kredit, transaksi terencana, dan perawatan hero | Tidak |
| Alarm & pengingat | Android | Memunculkan pengingat tepat waktu saat aplikasi sedang ditutup | Tidak |
| Berjalan saat perangkat dinyalakan | Android | Menjadwalkan ulang pengingat setelah perangkat dinyalakan ulang | Tidak |
Aplikasi ini tidak meminta izin mikrofon, lokasi, kontak, maupun akses penyimpanan menyeluruh.
13. Perubahan Kebijakan Ini
Kebijakan ini diperbarui setiap kali ada perubahan pada aplikasi yang mengubah data apa yang keluar dari perangkat, data apa yang disimpan, kepada siapa data dibagikan, atau apa yang aplikasi nyatakan kepada Anda. Nomor versi dan tanggal di bagian atas halaman ini menandai perubahan tersebut.
Untuk perubahan yang memperluas pemrosesan data pribadi Anda secara material, misalnya penambahan penerima data baru, kami akan meminta persetujuan baru dari Anda di dalam aplikasi. Persetujuan lama tidak dianggap berlaku untuk pemrosesan baru.
14. Hubungi Kami
Pertanyaan, permintaan pelaksanaan hak, atau keluhan mengenai pelindungan data dapat dikirim ke alamat email pada Bagian 2.
Sebagian besar hak pada Bagian 9 dapat Anda jalankan sendiri di dalam aplikasi, seketika, tanpa perlu menunggu kami. Untuk permintaan yang memang harus kami tangani, kami menanggapi paling lambat 3 x 24 jam sejak permintaan diterima, sesuai tenggat yang ditetapkan Pasal 30 (perbaikan data), Pasal 32 (akses), Pasal 40 (penarikan persetujuan), dan Pasal 41 (penundaan dan pembatasan pemrosesan) UU PDP. Tenggat ini berbeda dari tenggat 3 x 24 jam pada Pasal 46 yang mengatur pemberitahuan kegagalan pelindungan data (lihat Bagian 10).
Jika Anda tidak puas dengan tanggapan kami, Anda berhak mengajukan pengaduan kepada lembaga pelindungan data pribadi yang berwenang di Republik Indonesia.
Privacy Policy
1. Summary
Pocket Hero is a personal finance app that runs entirely on your device.
- Your financial records are never stored on our server. We do operate one server, and its role is narrow: it forwards AI requests to Google (and, for simple chat messages, to TypeSafe), counts how many requests each account makes, and holds proof of a subscription for those who buy one. The contents of those requests are not stored there. See Sections 6.2 and 6.7.
- The AI features require you to sign in with a Google or Apple account. All we receive from that is the email address on the account — used to know who a subscription belongs to and to tell one user from another. Every other feature works with no account at all. See Sections 4.4 and 6.8.
- You can delete that account yourself from inside the app under Settings → Account → Delete Account, separately from the button that deletes the data on your device. See Section 8.
- There is no analytics, tracking, or advertising of any kind in this app. The one thing sent without you asking is a technical crash report (Firebase Crashlytics) when the app stops working or freezes — it carries technical details, not your financial records, email, or account identifier. See Section 6.9.
- All of your financial records are stored in a local database on your own device.
- The AI features are optional and off by default. They turn on only after you explicitly agree. Every other feature works with no internet connection at all.
- If you turn the AI features on, financial data relevant to your question is sent to our server and passed on to Google, or to TypeSafe for simple chat messages. Read Section 6 carefully before enabling them.
2. Data Controller Identity and Contact
Under Article 21 of Law No. 27 of 2022 on Personal Data Protection (UU PDP), the data controller for this app is:
Address: Jakarta Pusat, DKI Jakarta, Indonesia
Contact email: zentrasolution.ai@gmail.com
Private Scope Electronic System Operator (PSE) registration number (Komdigi): 029934.01/DJAI.PSE/09/2026
No Data Protection Officer is appointed, as this app does not process personal data on a large scale and does not carry out regular and systematic monitoring of data subjects (Article 53 UU PDP).
3. Core Principle: Your Data Stays on Your Device
The app syncs no financial records to the cloud. Everything you enter is stored in a local SQLite database in the app's private storage on your device, and none of it is copied to our server. The single exception, and only if you use the AI features: you sign in with a Google or Apple account, so that account's email address and your AI usage figures are held on our server (Sections 4.4 and 6.2). Signing in copies no financial records anywhere; the only thing that leaves the device is the question you send to the AI features, and only while you are using them.
Two things follow from this at once: the developer can never access your data, and the developer also cannot recover your data if your device is lost or damaged or the app is uninstalled. Backups are entirely your responsibility (see Section 6.4).
4. Data the App Stores on Your Device
You enter all of the following yourself. The app does not pull data from any other source on your device without an action from you.
4.1 Financial data
| Category | Contents |
|---|---|
| Wallets / accounts | Name, type (cash, bank, e-wallet, credit card, stock/RDN account), balance, currency, credit limit, statement and due dates, icon and colour |
| Transactions | Title, amount, free-text note, date and time, type (income/expense/transfer), category, source and destination wallet, transfer fee, split details |
| Categories | Name, icon, colour, type |
| Budgets | Name, limit, currency, period, linked categories, description |
| Goals | Name, target amount, amount saved, deadline |
| Debts and receivables | Counterparty name, reason, type, principal, amount repaid, notes, tags, dates |
| Stock holdings | Ticker, lots, average price, conviction note |
| Planned transactions and templates | Recurring transaction details you set up yourself |
4.2 Profile and preferences
- A display name you type yourself (optional)
- Profile and background photos you choose yourself, stored as encoded JPEG in local preferences (optional)
- Preferences: currency, language, theme mode, category view, wallet order, biometric lock state, notification prompt state, AI consent state
- Cached exchange rates and the time they were fetched
4.3 AI chat history
If you use the Chat feature, the whole conversation is stored locally: your message text, the model's replies, action proposals you have not confirmed, and thumbnails of photos you attach or share into Pocket Hero from another app. Photos you have scanned remain in chat history until you clear it.
4.4 The account and session for the AI features
The app no longer asks for your Google Gemini API key; that key is now the developer's and lives on our server, never on your device.
Instead, to use the AI features you sign in with a Google account or with Sign in with Apple (before 4 September 2026 this registration was anonymous; Section 6.8 explains why that changed). From that we receive the email address on the account and an internal identifier (a UUID) — no full name, no phone number, no contacts, and no access of any kind to your Google or Apple account beyond that. If you use Apple's Hide My Email, all that reaches us is the relay address Apple generates, not your real one.
On the device, the app stores the session token from that sign-in along with your account email, so Settings can show which account is signed in. The token is stored encrypted: Android Keystore (AES-GCM) on Android, Keychain on iOS. Neither is deleted by Delete My Data — that button deletes what is on the device, while your subscription is recorded against the account, so deleting it would cut you off from a subscription you already paid for. To delete the account and its server-side records, use Settings → Account → Delete Account (Section 8). The token and email also go away when you sign out or uninstall, but signing out does not delete anything on the server — only Delete Account does.
4.5 Important note about the card's last four digits
The credit card visual in the app shows four digits that are randomly generated by the app purely as decoration. The app never asks for, receives, or stores card numbers, CVV, PIN, expiry dates, banking credentials, or any payment data.
4.6 Third-party data inside free-text fields
Several fields are free text: counterparty names on debts, transaction notes and titles, stock conviction notes. You may write other people's names or information about other people there. Be aware that this data is stored on your device and is also sent to Google if you use the AI features and the model needs to read those notes. You are responsible for other people's data that you enter into this app.
5. Data This App Does NOT Collect
For the avoidance of doubt, this app does not collect, access, or send to the developer:
- Your identity, apart from the one thing we state openly: the email address on the Google or Apple account you sign in with for the AI features (Sections 4.4 and 6.8). We never ask for your phone number, date of birth, address, full name, or password — your account password is typed on Google's or Apple's own page, never in this app — and every feature other than AI works with no account at all
- Location, precise or approximate
- Contacts, SMS, call history, calendar
- The list of installed apps
- Device identifiers, Advertising ID, or any advertising identifier
- Audio recordings. The app holds no microphone permission
- Usage data and behavioural analytics. The app does not record which screens you open, which buttons you press, or how long you use it — except at the moment the app stops working, and then only as far as Section 6.9 describes
- Biometric data. Your fingerprint and face are processed entirely by the operating system; the app receives only a success or failure result
No third-party SDK for advertising, cross-app tracking, or behavioural analytics is embedded in this app. The only third-party SDK embedded is the crash reporter described in Section 6.9; it speaks only when the app fails, does not follow you into other apps, and is not used for advertising.
What changed from the previous version, so that nothing is hidden. Until this update, the list above stated that the app sends no crash reports at all. That is no longer true: as of 13 September 2026 the app embeds Firebase Crashlytics, and Section 6.9 sets out exactly what is sent. This reporting is bound to your acceptance of this document and has no separate switch in Settings: before you accept this document not a single report is sent; if you do not accept it, the app cannot be used and you may export your data and uninstall.
Store statistics, so that nothing is hidden. The list above is about what this app collects. Separately from that, Google Play and the Apple App Store, as the store operators, give us reports about the app we publish: install and uninstall counts, country, device model and OS version, ratings and reviews, and crash and performance reports. That data is collected by Google and Apple through their own store and operating system services — not by this app's code — and is governed by their privacy policies, not this one. What reaches us is aggregate: we cannot identify you as an individual from it, and none of it contains your financial records, which stay on your device.
6. Third Parties and Transfers Outside Indonesia
6.1 Google Gemini API, only if you enable the AI features
The AI features (Chat, Scan Transaction, Smart Import, Investment Analysis) send data to Google via generativelanguage.googleapis.com. Google's servers are located outside Indonesia. As of this version that transmission no longer goes from your device to Google directly: it passes through our own server first — see Section 6.2, which is part of this disclosure and not a footnote to it.
These features are off by default. The first time you open an AI feature the app shows a consent dialog. Until you agree, no path in the app can transmit your data: the consent check happens at the network layer, not merely in the interface.
| Feature | What is sent to Google |
|---|---|
| Chat | The messages you type, and, as the model requests while answering you, your wallets, transactions, budgets, goals, debts, and stock holdings. What is sent is bounded: with no date range named by the model, only the last 90 days of transactions are included; transaction notes, and counterparty names and reasons on debts, are left out unless your question calls for them; settled debts are left out unless asked for |
| Photo attachment in Chat | The entire photo you attach, sent whole and uncropped, only downscaled to 1280 pixels on its long edge |
| Scan Transaction | The entire photo of the receipt, payment confirmation, or stock trade proof you scan, or share into Pocket Hero from another app (such as an e-wallet or mobile banking app), downscaled to 1280 pixels on its long edge |
| Smart Import | The entire contents of the file you select, such as a bank statement, including counterparty data it contains |
| Investment Analysis | Your wallets and stock holdings |
Legal basis for the transfer out of Indonesia. This transmission is a transfer of personal data outside the jurisdiction of the Republic of Indonesia within the meaning of Article 56 UU PDP. We do not rely on an assessment of the destination country's level of protection (Art. 56(2)), nor on a binding protection agreement between us and Google (Art. 56(3)) — we hold no such agreement. The basis we rely on is your valid, explicit, and specific consent under Article 56(4) UU PDP. That is why the AI features are off by default, why consent is requested separately before the first transmission, and why you can withdraw it at any time.
The API key is now the developer's, and that widens our responsibility. Previously you registered your own key at Google AI Studio and the AI traffic was beyond our reach. Those requests now pass through our server on our key, which means we technically can see their contents in transit. We choose not to store them (Section 6.2), but we will not pretend the capability is absent. It is this app that builds the request and decides what data goes into it, and we remain the data controller for that whole design.
Google's role. Google is not a personal data processor acting on our instructions: it processes what we forward under its own terms of service, for its own purposes (including model training on the free tier), and we cannot direct it. Google therefore stands as an independent data controller rather than our processor, which means there is no controller–processor agreement between us within the meaning of Article 51 UU PDP. What this means for you: your rights over data already sent are exercised directly against Google, as stated in Section 9.
On the free tier, Google states that it uses submitted content to train and improve its products, and that human reviewers may read API input and output. On the paid tier, Google states that it does not use your content to train its models.
Because the key in use is now the developer's, that tier is our choice rather than yours — and you have no way to verify it yourself. So treat model training and human review as real possibilities, and do not enable the AI features unless you are willing to accept them. Google's terms may change; the governing references are ai.google.dev/gemini-api/terms and policies.google.com/privacy.
You can withdraw consent at any time via Settings → AI Data Sharing. Withdrawal takes effect immediately for all subsequent requests. It does not recall data already sent to Google; for that you must contact Google directly.
6.2 PocketHero’s own server (Supabase), only if you enable the AI features
As of this version, AI requests no longer travel from your device straight to Google. They are sent first to a function of ours running on Supabase (Supabase, Inc.), and that function forwards them to Google — or, for simple chat messages, to TypeSafe (Section 6.10) — using the developer’s API key. The Supabase servers we use are outside Indonesia, so the transfer basis stated in Section 6.1 applies equally to this leg.
Why a server at all? Because the API key is now the developer’s and we pay for it. With no single point that can count and refuse, anyone who takes the app apart could use that key as a free AI service billed to us.
What is stored there:
- Your account: a user identifier (a UUID) and the email address of the Google or Apple account you signed in with. No full name, phone number, password, or device identifier is stored with it.
- Per account, per day: the number of AI requests, and the input and output token counts — usage figures, not content.
- A record of your AI consent. Per identifier: the version number of the consent text you accepted, the time your device says you tapped Agree, and the time our server first saw that consent. This is not there to identify you; it is evidence that the AI features were never switched on without consent — our duty as data controller under Article 20 UU PDP. None of your request content is recorded with it.
- Proof of a subscription, if you buy one. Per identifier: the receipt identifier from Google Play or the App Store, which store it came from, the product id you bought, and its expiry date. See Section 6.7.
- An IP address in sign-in session data, briefly. Supabase records your device’s IP address in the session data when you sign in, as authentication services generally do. We have no use for it, so it is deleted automatically every hour. The IP in that session data is therefore held for at most one hour, then permanently removed and no longer linkable to the usage figures above.
- Technical server logs, for at most 1 day. Every request to our server — AI requests, sign-in, subscription checks, and currency-rate fetches — is logged automatically by Supabase, not by our code. Those logs hold: the time, the endpoint address, the status code, your IP address, an approximate location derived from it (country, region, city, postal code), your internet provider’s name, the kind of app/device sending it (the user agent), and your account identifier (UUID) and session identifier read from the sign-in token; sign-in logs also contain your email address. None of your request content is in them. We cannot switch this logging off, as it is part of Supabase’s infrastructure; we only open it when we need to investigate an outage or abuse. Supabase deletes these logs automatically after 1 day on the service plan we currently use. Delete Account does not make that happen any sooner.
What is NOT stored there: your chat messages, photos, imported files, wallets, transactions, budgets, goals, debts, stock holdings, or the model’s replies. That data passes through the server as traffic and is forwarded on; it is not written to any database of ours, and does not appear in our server logs either — the technical logs above never contain request content. We cannot read back yesterday’s conversation, because we hold no copy of it. What we ask you to understand honestly: while that data is passing through, it is technically inside our infrastructure — the guarantee here is a promise and a design, not a technical impossibility.
Supabase’s role. Supabase, Inc. runs infrastructure on our instructions and does not use that data for its own purposes; in UU PDP terms Supabase is a processor and we remain the controller. Its privacy policy: supabase.com/privacy.
Deletion. Uninstalling the app does not delete those rows from our server, because we have no way to know which device was removed. What deletes them is Settings → Account → Delete Account: everything in the list above — the account and its email, the usage figures, the consent record, and the subscription record — is permanently deleted in one action, with no request to send us and no waiting. The email route in Section 2 remains available if you can no longer open the app. Two things to know before you press it, both also shown in the app's confirmation dialog: deleting the consent record also deletes the evidence that you ever gave consent, and what remains afterwards is only a purchase record already severed from your identity (Section 8).
6.3 Currency rates
To convert balances between currencies the app fetches a rate table from PocketHero’s own server (Supabase). It used to fetch that file directly from the third-party CDN cdn.jsdelivr.net; as of 2 September 2026 it no longer does, so no third party is involved in a rate update.
The request is empty: it carries none of your financial data, not the currency you selected, and no identifier of any kind — the app asks for the whole rate table and does the arithmetic on your device. Unlike Sections 6.1 and 6.2, this request needs no AI consent and carries no sign-in session. As with any HTTP request, our server receives your IP address and the time of the request; neither is written to any database of ours, but both appear in Supabase’s technical logs for at most 1 day (see Section 6.2).
The rates themselves are the same for every user and are tied to no one. The app stores them on your device and refreshes them only once that copy is more than 24 hours old.
6.4 Backups and exports you make yourself
Backup & Restore lets you save a copy of your data to a location you choose, and export to CSV or JSON.
CSV and JSON exports are never encrypted, on either platform. The moment you save any of these files to Google Drive, iCloud Drive, an SD card, your downloads folder, or send one through a messaging app, it leaves every protection this app provides and becomes subject to that destination service's privacy policy. Keep them only where you trust.
6.5 Operating system services
- Camera and photo library open only when you tap scan or attach. The app receives only the photo you pick.
- Sharing from another app. When you tap Share on an image in another app and choose Pocket Hero, the app receives only the image you shared, not the rest of your photo library. It is handled exactly like a photo you scan: sent to be read only if you have accepted AI processing, and any transaction read from it is saved only after you confirm it.
- Biometrics (fingerprint or Face ID) are handled entirely by the operating system. The app never sees your biometric data.
- Notifications are local reminders only — credit card due dates, planned transactions, and nudges to care for the in-app hero character — scheduled on your device. There is no push service, no device token, and no server involved.
6.6 Minimum version check
On launch, the app fetches a small file from pockethero.pages.dev (Cloudflare Pages) containing only the lowest app version we still support. This request carries no data about you — no financial data, no device identifier, no installation ID. The app simply reads that number and compares it against the version installed on your device. As with any HTTP request, Cloudflare as the hosting provider can see your IP address and the time of the request. The legal documents you open from Settings are served from the same address.
6.7 Purchases and subscriptions
The AI features are sold as a subscription. All payments are processed by the store you installed this app from: Google Play (Google LLC) on Android, and the App Store (Apple Inc.) on iPhone and iPad. We never receive, process, or store your card or payment details, and we do not see the name or email address on your Google account or Apple ID as part of that purchase.
All we store is proof that the subscription exists: the receipt identifier from that store (the purchase token from Google Play, or the original transaction id from the App Store), which store it came from, the product id, and its expiry date, held on our server (Section 6.2) against the account you signed in with (Section 4.4) — never against your payment details, which we never receive. The app sends that identifier to our server, and our server asks Google or Apple directly whether the subscription is genuinely active; we never trust a claim made by the app itself. The full purchase history stays with Google Play or the App Store and is not copied here.
Cancellations and refunds happen in the store you bought from — Google Play or the App Store; our server only learns of them at the next check. Deleting your account (Section 8) also deletes that subscription record, with one consequence worth knowing, which we also show in the confirmation dialog: it is the only proof of your entitlement we hold, so deleting it closes off the AI features even while your subscription is still running and still being billed by that store. Deleting your account is not a cancellation — cancelling happens in Google Play or the App Store, and is best done first.
6.8 Signing in with Google or Apple
Since 4 September 2026, the AI features require you to sign in with a Google account (Google LLC) or with Sign in with Apple (Apple Inc.). The sign-in happens in Google's or Apple's own system sign-in sheet, presented over the app — you pick an account already on the device — and only if that system sheet is unavailable does Google sign-in fall back to Google's own page opened in your device's browser. On every one of those paths, your password is never typed inside this app and is never seen by us. All that comes back to the app is a sign-in token and the email address on the account.
Why the change from anonymous? With anonymous registration the user identifier was recreated on every reinstall, so neither usage limits nor proof of a subscription could survive — a subscription already paid for could be lost by changing phones, and the AI costs we carry could not be held in check. An account solves both at once. We are aware this adds one piece of personal data that was not there before, which is exactly why the change is delivered through a fresh consent screen rather than quietly.
Google and Apple process that sign-in under their own privacy policies, and their servers are outside Indonesia — the transfer basis in Section 6.1 applies equally to this leg. Their policies: policies.google.com/privacy and apple.com/legal/privacy.
We never request any permission on your account beyond that basic identity: no access to your Gmail, Drive, contacts, calendar, or photos.
6.9 Crash reports (Firebase Crashlytics)
As of 13 September 2026 the app embeds Firebase Crashlytics (Google LLC). Its purpose is one thing: to tell us that the app stopped working or froze on your device, and which part of the code it happened in. Without it, the only report we get is a complaint you have to write yourself, and a failure that only appears on some devices is in practice unfixable.
When it speaks. Crashlytics sends nothing while the app is running normally. It sends a report only when the app stops abruptly (a crash), freezes to the point that the operating system kills it (an ANR), or hits an error we already handle but still want to know about — a backup that failed to restore, for example. The report is sent the next time the app is opened, not at the moment it happens.
What a report contains:
- A technical error trace (stack trace): the list of function names inside our own code that were running when the failure occurred, with their line numbers
- Device and app details: device model, manufacturer, operating system version, screen orientation, free memory and storage, battery state, whether the device is rooted or jailbroken, and the app version you have installed
- The name of the screen you were on when the failure occurred — only its name in the code, such as
HeroDetailorReports. Not its contents, and not which wallet, category, or transaction was on display - An installation identifier created by Crashlytics to tell one installation apart from another, so that ten reports from one device are not counted as ten users. That identifier is not a device identifier and not an Advertising ID: it is not read from the device, it is recreated if the app is reinstalled, and it cannot be used to recognise you in any other app
What is never in it. We do not send your financial records, balances, transactions, wallet names, AI chat history, photos, email address, or your database — neither in whole nor in part. We also do not enable Firebase Analytics, and we embed no Advertising ID and no tracking SDK of any kind. The reports are technical, not behavioural: they describe our code failing, not what you did.
One limit we state honestly. An error trace can carry an error message written by our own code, and a message like that can in principle carry a value that was being processed when the failure happened. We never deliberately put your financial data there, and none of the fields listed above is designed to hold it. We mention it because we cannot promise that possibility is zero for every failure that has not happened yet.
Google's role. Google LLC runs Crashlytics on our instructions and under the Firebase Data Processing and Security Terms; in UU PDP terms Google is a processor and we remain the controller. Its servers are outside Indonesia, so the transfer basis stated in Section 6.1 applies equally to this leg. Its privacy policy: policies.google.com/privacy, and Google's own account of what Crashlytics collects: firebase.google.com/support/privacy.
Consent, and how to refuse. This reporting is off from the start inside the app and only switches on once you have accepted this document and the Terms — not a single report is sent before that. It has no separate switch in Settings, and it is deliberately not folded into the AI Data Sharing switch: they are different matters, and the AI switch governs only what is sent to Gemini under Section 6.1. Refusing crash reporting therefore means not accepting this document; the consent screen offers buttons to export your data and to erase it from the device, so that you can stop without losing your records.
How long it is kept. Google retains Crashlytics crash data for at most 90 days and then destroys it. We do not copy those reports anywhere else and do not join them to your account under Section 4.4 — we deliberately send neither your account identifier nor your email address to Crashlytics, so a crash report cannot be linked back to your account by us.
6.10 TypeSafe (the Jev model), only if you enable the AI features
Since 19 September 2026, some Chat messages are answered first by Jev, a language model from TypeSafe AI, Inc. (United States), instead of by Google Gemini. Jev is used only for simple text messages: recording a single expense, income, or transfer between your own wallets (“coffee 20k”), asking for one total or balance (“how much did I spend this month?”), and short greetings. Anything more involved, and every message Jev cannot answer with enough confidence, goes on to Google Gemini as usual (Section 6.1). A message with a photo attached is never sent to Jev.
What is sent to TypeSafe: the text of the message you typed, the assistant’s immediately preceding reply (at most 500 characters) if there is one, and the names of your wallets and categories as answer options. Your balances, transaction history, budgets, goals, debts, stock holdings, email, and account identifier are not sent. The amount of money in a message is read by our own code, not by Jev, and any total or balance you ask for is calculated on your device.
This transfer runs from our server (Section 6.2) on the developer’s API key, only after you have consented to the AI features, and rests on the same consent and transfer basis as Section 6.1 (Article 56(4) UU PDP): TypeSafe’s servers are in the United States, outside Indonesia. Our server stores neither the message nor Jev’s answer; it records only usage figures (request and token counts), just as it does for Gemini.
TypeSafe’s role. TypeSafe’s privacy policy states that it does not train or fine-tune any model on the input sent to it and does not disclose that input to any third party other than its own service providers. TypeSafe processes our requests to deliver the feature you asked for; its policy gives no fixed retention period for API input, only “as long as reasonably necessary to provide the Services”. TypeSafe’s terms may change at any time; the governing reference is typesafe.ai/privacy.
Withdrawing your AI consent (Section 6.1) stops sending to TypeSafe as well as to Google. For data already sent, contact TypeSafe directly.
7. Legal Basis and Purpose of Processing
| Activity | Purpose | Legal basis (UU PDP Art. 20) |
|---|---|---|
| Storing financial records on the device | Delivering the core function of the app you installed | Performance of a contract with the data subject, Art. 20(2)(b) |
| Storing preferences and profile | Presenting the app the way you chose | Performance of a contract, Art. 20(2)(b) |
| Storing an account (identifier and email address) for the AI features | Knowing who a subscription belongs to, and keeping the access you paid for when you change devices | Performance of a contract with the data subject, Art. 20(2)(b) |
| Counting AI usage per account on our server | Limiting abuse of the AI capacity we pay for | Legitimate interest, Art. 20(2)(f) |
| Sending data to our server and on to Google Gemini or TypeSafe (Jev) | Delivering the AI feature you requested | Valid, explicit, specific consent, Art. 20(2)(a) in conjunction with Art. 22 |
| Fetching exchange rates | Currency conversion | Performance of a contract, Art. 20(2)(b) |
| Technical server logs kept by Supabase (Section 6.2), for at most 1 day | Keeping the server secure and investigating outages or abuse | Legitimate interest, Art. 20(2)(f) |
| Local reminders (credit card due dates, planned transactions, hero care) | A feature you enable yourself | Consent, Art. 20(2)(a) |
| Sending technical crash reports to Firebase Crashlytics (Section 6.9) | Learning about and fixing crashes and freezes we cannot find on our own | Legitimate interest, Art. 20(2)(f), within the bounds of your acceptance of this document |
| Keeping a purchase record with no identity attached after your account is deleted | Meeting the obligation to retain proof of a transaction for bookkeeping and tax | Legal obligation of the controller, Art. 20(2)(d), read with Art. 28(11) of the KUP Law |
Personal financial data is specific personal data under Article 4(2) UU PDP. Consent for the AI features is therefore requested separately from installing the app, presented in plain language, and can be withdrawn as easily as it was given.
8. Storage, Retention, and Deletion
Your data is retained for as long as the app is installed. Your financial records have no retention period on the developer's side, because those records are never on the developer's side. Two things that are on our side have retention periods of their own: the account and subscription records set out in the table and paragraphs below, and the technical crash reports in Section 6.9, which Google destroys after 90 days and which are not linked to your account.
| Action | What is deleted |
|---|---|
| Deleting an individual record in the app | That record, immediately and permanently |
| Settings → Delete My Data, or the Delete my data from this device button on the re-consent screen | All financial data, all chat history including the photos in it, and your display name along with any profile and background photos you chose. Default wallets and categories are recreated so the app remains usable. Before anything is deleted, the app shows a confirmation dialog spelling out what goes and what stays. |
| Settings → Account → Delete Account | Your account on our server and everything attached to it: the email address, the AI usage figures, the AI consent record, and the subscription record. Data on your device is not deleted — use Delete My Data for that. The confirmation dialog spells out both before anything is deleted. |
| Signing out (Settings → Account → Sign out) | Nothing. Only the session on this device ends; the data on the device and the records on the server are both left intact. |
| Uninstalling the app | The entire local database and preferences. Records on our server are not deleted, because we cannot know which device was removed. |
Deliberately kept by Delete My Data: your account and the subscription record tied to it (see Section 4.4). Neither holds any of your financial data, and keeping them is what lets you delete everything on the device and still resume the paid plan you already bought instead of paying twice. If you want the account gone as well, use Delete Account in the row above.
What we still keep after an account is deleted, and why. If you ever bought a subscription, one purchase record is retained: the store platform, the product id, the receipt number (purchase token) from Google or Apple, and its validity dates. That record is severed from your identity at the moment of deletion — the column linking it to an account is dropped, so nothing in our database can any longer say the purchase was yours.
The reason is a collision between two obligations that both bind us: the right to erasure in Article 8 UU PDP, and the duty to retain proof of a transaction for bookkeeping and tax — Article 28(11) of the KUP Law requires accounting source documents to be kept for 10 years. Anonymisation satisfies both: your personal data is gone, the transaction evidence remains. Article 43(2) UU PDP itself permits deletion to be deferred so long as the data is still needed to meet a statutory retention duty. We destroy those records once that 10-year period has passed. The full purchase history stays with Google Play or the App Store and is governed by their policies, not this one.
One deliberate exception: Delete My Data does not turn off your AI consent. Deleting data is not the same as withdrawing consent, and silently revoking it would confront you with a consent dialog you never asked for on next use. To withdraw consent, use the AI Data Sharing switch in Settings.
Backup files you have already saved outside the app are not deleted by any of the above. You must delete those yourself.
9. Your Rights as a Data Subject
Articles 5 to 13 UU PDP grant you the following rights. Because your data lives on your own device, you can exercise most of them directly, without submitting a request to anyone:
| Right | Basis | How to exercise it |
|---|---|---|
| Information about processing | Art. 5 | This document, and the in-app consent dialog |
| Access and obtain a copy | Art. 7 | Open the app, or export to CSV/JSON via Backup & Restore |
| Rectification | Art. 6 | Edit any record directly in the app |
| Erasure | Art. 8 | Delete per record, Settings → Delete My Data for what is on the device, and Settings → Account → Delete Account for the account and its records on our server. If you do not accept a change to this document, the Delete My Data button is available directly on the re-consent screen, without having to accept anything first. There is one limit, stated openly in Section 8: the anonymised purchase record |
| Withdraw consent | Art. 9 | Settings → AI Data Sharing, effective immediately |
| Object to automated decisions | Art. 10 | The app never makes an automated decision about you. Every AI action proposal waits for your confirmation before it runs. |
| Suspend or restrict processing | Art. 11 | Turn off the AI Data Sharing switch. The app remains fully functional offline |
| Data portability | Art. 13 | Export JSON or CSV via Backup & Restore |
| Claim and receive compensation | Art. 12 | Contact us at the email in Section 2, or file a complaint with the competent authority |
For data already sent to Google or TypeSafe, these rights are exercised against that party under its own privacy policy, because the developer neither stores nor can access it.
10. Security
Technical measures in place (Articles 35 and 39 UU PDP):
- Data is stored in the app's private storage, inaccessible to other apps on a non-rooted, non-jailbroken device
- Android auto-backup is disabled (
allowBackup="false"), so the database is not copied to Google's cloud - On iOS the database files are excluded from iCloud/iTunes backup and given the
NSFileProtectionCompleteUntilFirstUserAuthenticationprotection class - The entire database is encrypted at rest (SQLCipher, AES-256), on both Android and iOS. Its key is generated randomly on your device and protected by the Android Keystore on Android or the iOS Keychain on iOS; the key never leaves the device and is never known to us
- The AI session token is encrypted with Android Keystore (AES-GCM) or the iOS Keychain
- All network communication uses HTTPS
- An optional biometric app lock is available
- While the biometric lock is on, Android suppresses screenshots and the app's preview in the recent-apps list, so its contents cannot be read from there without unlocking
Our server stores no financial records — only an anonymous identifier, usage figures, and subscription proof (Sections 6.2 and 6.7) — so a breach of that server would expose nobody’s financial data. We nonetheless no longer claim that a centralised breach is impossible: should a personal data protection failure occur on that server, we will notify as required by the 3x24-hour duty in Article 46 UU PDP. The same applies if a security flaw in the app that could expose on-device data is found: we will disclose it through an update to this page and the app release notes.
11. Minimum Age
This app is intended for users aged 18 and over and is not designed for children. We do not knowingly collect children's data. Under Articles 25 and 26 UU PDP, processing children's data requires parental or guardian consent. If you are under 18, do not use the AI features without your parent's or guardian's consent.
12. Device Permissions Requested
| Permission | Platform | What for | Required? |
|---|---|---|---|
| Internet | Android | AI features and exchange rate updates | Yes, but used only when those features are used |
| Camera | Android and iOS | Photographing receipts or transaction proofs | No |
| Photo library | iOS | Choosing an existing photo | No |
| Biometrics / Face ID | Android and iOS | Locking the app | No |
| Notifications | Android and iOS | Credit card due dates, planned transactions, and hero care reminders | No |
| Alarms & reminders | Android | Showing reminders on time while the app is closed | No |
| Run at startup | Android | Rescheduling reminders after the device restarts | No |
The app requests no microphone, location, contacts, or broad storage permission.
13. Changes to This Policy
This policy is updated whenever a change to the app alters what data leaves the device, what is stored, who it is shared with, or what the app tells you it does. The version number and date at the top of this page mark those changes.
For changes that materially expand the processing of your personal data, such as adding a new data recipient, we will request fresh consent from you in the app. Prior consent will not be treated as covering new processing.
14. Contact Us
Questions, requests to exercise your rights, or data protection complaints can be sent to the email address in Section 2.
Most of the rights in Section 9 you can exercise yourself inside the app, immediately, without waiting for us. For requests that do require us to act, we respond within 3 x 24 hours of receiving them, the deadline set by Article 30 (rectification), Article 32 (access), Article 40 (withdrawal of consent), and Article 41 (suspension and restriction of processing) UU PDP. This is a different clock from the 3 x 24 hours in Article 46, which governs data breach notification (see Section 10).
If you are not satisfied with our response, you have the right to lodge a complaint with the competent personal data protection authority of the Republic of Indonesia.