Quorfin is an offline-first personal finance app for iOS and Android. This policy explains, in plain terms, what happens to your data when you use it. The short version: almost nothing leaves your device, and the one thing that can is entirely your choice.
Quorfin has no account system and no backend server. There is no sign-up, login, or authentication of any kind, so we never collect or see:
Everything you enter into Quorfin, transactions, budgets, goals, recurring items, reports, and any receipt photos you attach, is stored locally on your device using field-level AES encryption at rest. The app can be locked behind your device's biometric authentication (Face ID, Touch ID, or fingerprint). If you create a backup, it is encrypted and password-protected, and it stays under your control: on your device or wherever you choose to save it. We never receive a copy of it.
Quorfin includes an AI Advisor that can answer questions about your finances. By default it runs entirely on-device, using deterministic, rule-based logic (keyword and category matching, not a machine-learning model), and no data leaves your phone.
Cloud AI is a separate, optional mode. It is disabled by default and only activates if you turn on two separate toggles in Settings → AI: a consent toggle and a "cloud AI" toggle.
When you enable it, the question you ask, a snapshot of relevant financial data, and/or a receipt photo you choose to include is sent directly from your device to Google's Gemini API, using an API key you supply and that is stored only in your device's secure storage. Quorfin does not run a server in between and does not retain a copy of what is sent. That data is subject to Google's Privacy Policy. You can turn either toggle off at any time in Settings, after which no further data is sent.
Because your data lives only on your device, deleting it is entirely in your hands. Clearing Quorfin's app data or uninstalling the app permanently removes everything, there is no server-side copy for us to retain or delete on your behalf.
Quorfin is not directed at children under 13, and since the app collects no personal information from any user, none is knowingly collected from children.
User data is protected with field-level AES encryption at rest, optional biometric app lock, and crash-safe encryption key rotation. Because data never leaves your device (except the narrow, opt-in Cloud AI case above), the app's attack surface is limited to the device itself.
If this policy changes, the update will be posted at this same URL with a revised effective date above. Continued use of Quorfin after a change constitutes acceptance of the revised policy.
Questions about this policy or Quorfin's data practices can be sent to support@kcacuin.com.