Privacy Policy
This policy explains how Left, developed by Rafael Carrascal ("Left", "we", or "us"), handles information when you use the Left iPhone app and its related services.
Information you provide
- Transactions, amounts, descriptions, categories, budgets, goals, recurring items, currencies, and list names that you enter.
- Voice audio processed by Apple's speech-recognition services when you enable voice input. Left receives the resulting transcript.
- Transaction text, locale, currency, time zone, category names, and limited merchant preferences used when you request AI-assisted interpretation.
- Messages you send to our support address.
Automatically processed information
Left and its service providers may process a random app-installation identifier, app version and build, device locale, request identifier, product interactions, coarse onboarding-answer buckets, self-reported acquisition source, experiment assignment, purchase history, subscription status, and diagnostic information. Our API provider also receives the IP address needed to deliver and secure network requests. We use this information to deliver the service, understand product performance, measure onboarding and feature adoption, run the paywall-timing experiment, verify app integrity and subscription access, prevent abuse, restore purchases, and troubleshoot failures.
Where information is stored and processed
Your ordinary finance records are stored in Left's protected local App Group container on your device so the app, widgets, and Shortcuts actions can work together. Left does not connect to your bank, import Wallet history, scrape notifications, sell personal information, or use advertising trackers.
If you explicitly share a list, that list is stored in Apple's iCloud and CloudKit services so invited participants can open it. Left creates invitation-only shares and does not make shared lists public. Removing Left from a device does not by itself delete a list that remains in iCloud or cancel an outstanding share.
AI and voice processing
Left first parses transaction text on your device using deterministic rules. On supported devices, Apple Intelligence's on-device Foundation Models may also interpret the current entry. Inputs processed successfully on device are not sent to Left, Cloudflare, or OpenAI for interpretation.
If local processing cannot confidently interpret an entry, Left asks for your permission before using the online fallback. Only after you allow it, the current transcript and the minimum relevant context described above travel through our Cloudflare-hosted service to OpenAI. You can disable this permission in Left settings and continue using manual and local entry.
The Left API does not intentionally retain raw transcript content after returning the response. It keeps short-lived hashed security, rate-limit, challenge, entitlement-cache, and idempotency records, plus an App Attest public key and replay counter associated with a random installation identifier. Service providers may retain operational records under their own terms and legal obligations.
Product analytics and experiments
Product analytics is enabled by default and can be turned off completely in Left settings under Privacy. Left uses Amplitude Analytics for sessions, app lifecycle, explicitly selected screen and action events, funnels, retention, and cohorts. Left uses Amplitude Experiment to assign and measure the existing paywall-timing test and to keep future notification experiments disabled until intentionally activated. Analytics and experiment data are associated with the same random installation identifier used for subscription access so events can be joined without an email, advertising identifier, or account profile.
Left does not send Amplitude exact budgets, income, transaction amounts, projected savings, merchant names, transaction descriptions, notes, audio, transcripts, user-created category names, or free-form attribution text. Numeric onboarding answers are converted on the device into broad buckets before transmission. Left disables IP-derived location, IDFV, IDFA, automatic control capture, network capture, and session replay in the analytics SDK. Left does not request App Tracking Transparency permission because these analytics are not used to track you across apps or websites.
RevenueCat remains the source of truth for trial and subscription events. A Left-hosted webhook bridge forwards only an approved set of subscription lifecycle fields to the matching Amplitude environment after checking your analytics preference. Left does not also enable a second direct RevenueCat-to-Amplitude integration. Development, TestFlight, sandbox, and App Review data are separated from production analytics.
Service providers
- Apple provides the App Store, StoreKit, speech recognition, App Attest, Shortcuts, on-device Foundation Models where available, and iCloud/CloudKit when you share a list.
- RevenueCat processes purchase history and subscription entitlement information for app functionality and service analytics.
- Amplitude processes the limited product analytics and experiment information described above. It does not receive transaction content or advertising identifiers from Left.
- Cloudflare hosts the API and processes network and security information.
- OpenAI interprets unresolved transaction text only when you permit the online fallback. OpenAI states that API data is not used to train its models by default under its business-data terms.
- Vercel hosts this public website and may process standard web request logs.
Retention and deletion
Local finance data remains until you delete it in Left or remove the app and its data from the device. Shared-list records remain in CloudKit until the owner deletes the shared list or ends the share, subject to Apple's iCloud retention. Most challenge, entitlement-cache, rate-limit, and AI idempotency records on our API expire automatically within 24 hours. A hashed webhook processing receipt may remain for up to 400 days to prevent duplicate subscription events. Analytics consent, an attested public key, and a replay counter may remain associated with the random installation identifier while that installation uses the service. Product analytics and subscription lifecycle records are retained only as needed for the purposes above and according to our providers' configured retention. Support messages are retained as needed to resolve the request and meet legal obligations.
Turning off product analytics stops future app, experiment, notification, and subscription analytics for that installation; it does not automatically erase records already collected. You may request access, correction, or deletion of historical analytics, support, and service information by emailing equipo@coreflowia.com. We may ask for information needed to locate the anonymous installation record. Purchase records controlled by Apple or RevenueCat may need to be handled through those providers. Removing local records does not cancel an App Store subscription.
Security
We use transport encryption, App Attest, subscription verification, request limits, minimal identifiers, protected local files, invitation-only CloudKit shares, and restricted service credentials. Left does not use a public upload bucket. No system can guarantee absolute security.
Children
Left is not directed to children under 13. We do not knowingly collect personal information from children under 13.
International processing and changes
Our providers may process information in countries other than your own. We may update this policy as Left changes. The effective date above identifies the current version.
Contact
Rafael Carrascal
equipo@coreflowia.com