Kopeck
Privacy Policy
Last updated: September 18, 2026
Kopeck is a personal budgeting app. This page explains, as plainly as possible, what data the app handles, where it lives depending on the mode you choose, and how to delete it.
01 Where your data lives
Kopeck works with three interchangeable modes, chosen in the app's settings. The mode you pick entirely determines where your data resides — Kopeck itself does not operate a central server that collects your data by default in every mode.
| Mode | Where your data is | Bank connection | Account required |
|---|---|---|---|
| Actual | On the Actual Budget server you self-host and configure yourself | Not available | No |
| Cloud | On the Kopeck project's Supabase infrastructure (hosted in Europe) | Yes, via Enable Banking | Yes |
| Self-hosted | On your own Supabase project, which you set up and control | Yes, via Enable Banking | Yes |
This document describes the practices of the Cloud and Self-hosted modes, the only ones where Kopeck or its providers process data outside your device. In Actual mode, no one other than you (or the server you control) has access to your data. A small on-device cache also speeds up how quickly Cloud/Self-hosted data loads — it always mirrors what is already stored on your Supabase project and is never an independent copy.
02 Account and sign-in
Using Cloud or Self-hosted mode requires an account. When you do, we collect:
- your email address, if you create an account with email/password;
- your Google or Apple account identifier, if you sign in that way — we never see your Google/Apple password, only the authentication token those services hand us;
- your budgeting data: accounts, transactions, categories, budgets, and recurring bills you create or sync within the app.
Each account can only ever access its own data (enforced at the database level, not just within the app).
03 Bank connection
If you choose to connect a bank in Cloud or Self-hosted mode, Kopeck uses Enable Banking, a regulated open banking aggregator (PSD2), to get read-only access to your accounts and transactions. Kopeck never sees or stores your banking credentials — authentication happens directly with your bank, through Enable Banking's secure flow.
Synced data (balances, transactions) is stored the same way as the rest of your data for that mode, described in section 1.
04 AI assistant (optional)
Kopeck offers a conversational assistant, off by default. If you turn it on, you supply your own API key for the provider of your choice (OpenAI, Anthropic, a local Ollama server, or a custom provider).
When you ask the assistant a question, your message — and whatever budgeting context is needed to answer it — is sent directly from your device to the provider you configured, using your own key. Kopeck does not relay or keep these exchanges on its own servers.
You remain subject to your chosen provider's own privacy policy for anything that passes through it. Choosing a local Ollama server keeps your data from leaving your device entirely.
05 What we never do
- No advertising, no third-party ad networks.
- No analytics trackers or audience-measurement SDKs.
- No sale or sharing of your data for commercial purposes.
- No access to your data by anyone other than you, beyond the subprocessors listed in section 9.
06 Security
- Credentials and session tokens are stored in your device's secure keychain (iOS Keychain), never in plain text.
- All network communication uses HTTPS.
- In Cloud and Self-hosted modes, database access is restricted by row-level security (RLS): even in the event of an application flaw, a query can only ever technically return the data belonging to the account making it.
07 Your rights, your deletion
You can view, edit, or export your data directly within the app at any time.
For a permanent deletion of your Cloud or Self-hosted account and everything tied to it (accounts, transactions, budgets, categories, recurring bills, bank connections): go to Settings → Account → Delete my account. This action is immediate and irreversible — there is no grace period and no backup kept after deletion.
In Actual mode, deletion is handled by your own self-hosted server.
08 Data retention
In Cloud and Self-hosted modes, your data is kept for as long as your account exists. It is deleted immediately and entirely as soon as you request account deletion (section 7).
09 Subprocessors
| Provider | Role | Data involved |
|---|---|---|
| Supabase | Database and authentication hosting (Cloud mode) | All Cloud account data |
| Enable Banking | Regulated bank aggregation (PSD2) | Bank balances and transactions, if a bank is connected |
| Your chosen AI provider | Conversational assistant responses, if enabled | The content of your questions and the budgeting context given to the assistant |
10 Minors, changes, contact
Kopeck is not intended for anyone under the age of 16.
This policy may change as the app's features evolve. The "last updated" date at the top of this page reflects any revision.
Have a question about your data, or need help with a specific request?
Contact us