PRIVACY POLICY
Privacy Policy
For Sanary Money on iPhone and Mac.
Last updated: 21 September 2026
1. Your regular financial records
Regular household finance records, including income, expenses, dates, merchants, amounts, items, categories, and notes, are stored in a database on each of your devices (SQLite) for recording, viewing, editing, and calculation. The data on each device is the primary copy. Sanary does not send or store your regular financial records on servers operated by Sanary or on AWS. No account registration or sign-in is required, and Sanary does not use a Sanary account. For how your data is handled if you turn on optional iCloud sync, see “2. iCloud sync (optional)”.
Item categories are classified on your device. When you explicitly change an item’s category, the pair of item name and category is remembered in a database on your device (SQLite) and applied automatically from then on to items with the same name (an exact match, ignoring differences in leading or trailing spaces, full-width spaces, and letter case). Sanary does not send images, documents, or item names to servers operated by Sanary or to AWS for this classification. You can erase the remembered classifications from this device with “Delete Data on This Device” in Settings. If you turn on iCloud sync, these remembered classifications are included in what syncs (see “2. iCloud sync (optional)”).
2. iCloud sync (optional)
iCloud sync is a free core feature of Sanary Money that lets you sync your financial records between devices, such as your iPhone and Mac. It is off by default and works only if you turn it on in Settings. No Sanary account is required.
When you turn it on, your records are stored in Apple’s CloudKit private database (your own iCloud) and are used to pass changes between devices signed in with the same Apple Account. This is not sending data to servers operated by Sanary, and no data is sent to Sanary’s servers or AWS. Sanary does not receive or view the financial records in your private database.
What syncs
- Income and expenses (including items)
- Budgets
- Recurring expenses
- Remembered item categories
- Home currency
What does not sync
- Free AI usage counts
- Purchase entitlements (AI Unlock and Analysis Unlock are checked through the App Store and StoreKit)
- Financial consultation messages
- Cached insights (AI reviews and analysis results)
- Badges
- Appearance settings such as theme, language, and font
The SQLite database on each device remains the primary copy. iCloud is the path used to pass changes between devices.
Apple’s iCloud terms and privacy policy apply to data stored and processed in iCloud and CloudKit. Sync requires that you are signed in to iCloud, have available iCloud storage, and have a network connection. Depending on the status of Apple’s services, sync may be delayed or may not happen.
For how deletion works when sync is on, and how to manage data in iCloud, see “7. Deleting and managing data”.
3. AI processing
The eight Mac analysis views calculate amounts and totals from local records and display charts. AI interpretations use the calculated information. Ask AI uses your question and relevant financial summaries. Mac AI Import creates suggested entries from images, PDFs, and CSVs, which you can review and edit before saving.
AI features use Foundation Models provided by Apple. AI processing does not go through servers operated by Sanary or through AWS. Processing is performed by Apple’s systems, which may include Apple’s Private Cloud Compute (PCC).
When you run an AI feature, image reading passes the selected images, PDF reading passes page images, EML reading passes extracted email text, and CSV reading passes file contents to Foundation Models. AI monthly reviews, spending analysis, and improvement suggestions process category totals and transaction counts. Financial consultation processes your messages, conversation context, and financial summaries. This data is not sent to Sanary, and Sanary does not receive it. Apple’s terms apply to Apple’s handling of it.
Check reading results before saving. Avoid importing documents containing unnecessary personal information or information about other people.
4. Purchase information
AI Unlock and Analysis Unlock are both one-time, non-consumable purchases. With Universal Purchase, entitlements are shared across iPhone and Mac using the same Apple Account. Purchases are checked through the App Store and StoreKit, separately from iCloud sync of financial records.
Purchases, purchase restoration, and checks for purchased features use Apple’s App Store and StoreKit. Purchase information is processed and verified through Apple’s systems, rather than sending purchase receipts to Sanary’s servers for verification.
5. Support enquiries
We use the reply address, message, and attachments you email us to respond and investigate issues. Support emails created from the app include the app version, build, OS information, and display language. The email is composed in your own mail app and reaches Sanary only if you choose to send it. You can review the draft before sending.
6. External services
AI processing and purchases use Apple’s services (Foundation Models, the App Store, and StoreKit), and iCloud sync, if you turn it on, uses Apple’s iCloud (CloudKit). Each service’s own terms also apply to its handling of data. Processing that uses Apple’s services does not necessarily take place entirely on your device.
7. Deleting and managing data
You can edit and delete financial records in the app. When iCloud sync is on, deleting synced data such as transactions, budgets, and recurring expenses is also carried over to your other devices through sync.
“Delete Data on This Device” in Settings deletes only the data on this device (including remembered item classifications). It does not automatically delete data in iCloud.
Turning iCloud sync off does not automatically delete data that has already synced to iCloud. To manage or delete data in iCloud, use Apple’s iCloud storage management (open your Apple Account in the Settings of your device and manage iCloud storage). Labels and steps vary by OS.
Sanary does not hold a copy of your ledger on servers it operates and does not receive or view the financial records in your private database. For that reason, Sanary cannot restore your financial records after device loss, failure, or deletion.
Contact us below to request access, correction, or deletion of information sent to Sanary, such as support enquiries.
8. Contact and changes
Operator: Sanary, independently operated.
Contact: contact form (info@sanary.jp)
Changes to how information is handled will be announced on this page or through other notices.
Security and third-party disclosure
For information Sanary receives, such as support enquiries, we take reasonable security measures, including access controls.
We do not sell or disclose personal information to third parties except when required by law, necessary to protect life, physical safety, or property, or with your consent. Service providers are managed appropriately.
Information sent to Sanary is handled for as long as needed to respond, meet legal obligations, resolve disputes, and prevent misuse.