Privacy Policy
Last updated: August 27, 2026
Ketzie is built to keep your financial information on your device, under your control. A couple of optional features send specific, limited data off your device — but only when, and only because, you choose to use them. This policy explains exactly what stays local and what doesn’t.
The short version
The accounts, balances, bills, and settings you enter are stored encrypted on your device. Ketzie has no advertising and no cross-app tracking, and we never sell your data. Four optional features send data off your device only when you use them:
- AI statement import — if you import a statement, the statement you provide is sent to a third-party AI service to extract your bills.
- Sign-in (optional) — sign in with Google, Apple, an emailed one-time code, or a passkey. Sign-in itself handles only your identity — via Firebase and our own sign-in service.
- Cross-device sync (optional, requires sign-in) — when you sign in on an app version with sync, the financial data you enter is stored encrypted on our servers so your devices stay in step. If you never sign in, nothing syncs.
- Bank linking (optional, requires sign-in) — connect a bank or card through Plaid and Ketzie reads its balances and recent transactions to keep your numbers current. Ketzie never sees your bank password.
Separately, the app sends anonymous usage analytics — coarse, count-level events about which features get used, never the financial information you enter — and you can turn that off with one switch in Settings.
Details below.
Who we are
Ketzie is made and operated by Littlecat LLC, a limited liability company registered in New York. “We” and “our” in this policy mean Littlecat LLC. You can reach us at privacy@ketzie.com.
Information you enter
Everything you add to Ketzie — account names, balances, pay schedule, bills, and your spending buffer — is stored locally on your device, in an encrypted database (AES-256, via SQLCipher) whose key is held only in your device’s secure keystore (iOS Keychain / Android Keystore) and never leaves your device — so the data on disk stays unreadable without your device. It’s also kept out of automatic cloud device backups. Your financial information leaves your device in exactly two cases, both optional and both described below: statement import (you send one statement to be read) and cross-device sync (signed-in users only). A third optional feature, bank linking, brings your bank’s data to your device through our servers without storing it there. If you use none of them, we run no servers that hold your financial information, and deleting the app deletes your data with it.
AI statement import (optional)
To save you from typing everything in, Ketzie can read a bank or card statement and propose your recurring bills. This feature is optional and only runs when you request it.
When you import a statement, the data you provide — pasted text, or a PDF or image you choose — is sent over an encrypted (HTTPS) connection to our own cloud service, which uses Amazon Bedrock (running Anthropic’s Claude model within AWS, on our behalf) to read it and propose bills for you to review and confirm.
If you already track bills in Ketzie and import another statement, the app also sends your bill list (bill names, amounts, and how often they repeat — never balances or account details) along with that statement, so it can propose updates — a price that changed, a new bill, or one that seems to have stopped — instead of duplicates.
- It is used only to identify your bills.
- It is not used to train AI models.
- It is not retained after your bills are returned — it is processed within AWS, on our behalf, and then immediately discarded, and it is not shared with Anthropic.
- Our service does not log the contents of your statement.
- If you never use statement import, nothing is ever uploaded for bill identification.
For a plain-English walkthrough of this feature, see How bill identification works.
Accounts and sign-in (optional)
Ketzie uses Firebase Authentication (a Google service) to manage identity. So your data can be protected and synced across devices, the app creates an anonymous identity with Firebase when you first open it. That involves a request to Firebase and does not include the financial information you enter.
Signing in is optional. You can sign in with Google, Apple, an emailed one-time code, or a passkey. However you sign in, a permanent identity is linked to your data so it can move with you. Signing in also enables cross-device sync, described in the next section.
- Google or Apple — handled by Firebase and the provider you pick, under their respective privacy terms; we never receive your provider password.
- Emailed one-time code — you provide your email address, which we send to our own sign-in service (running on Amazon Web Services) solely to email you a one-time code and identify your account. We don’t use it for marketing.
- Passkey — a passwordless credential created and stored on your device; our sign-in service keeps only its public key to verify future sign-ins. There’s no password, and the private key never leaves your device.
Cross-device sync (optional, requires sign-in)
When you’re signed in on an app version that includes sync, Ketzie keeps your data in step across your devices and can restore it if you get a new phone. Sync is rolling out gradually — beta versions have it today; App Store builds don’t sync yet.
- What syncs: the financial data you enter — accounts, balances, pay schedule, bills, and settings.
- When: only while you’re signed in. If you never sign in, nothing is synced and nothing about your finances is stored on our servers.
- Where and how: synced data travels over an encrypted (HTTPS) connection and is stored encrypted at rest on our servers (Amazon Web Services). It is used solely to provide sync — never for advertising, profiling, or sale.
- Deleting it: Delete account in the app (Settings → Profile → Delete account) removes your synced data from our servers, disconnects any linked banks, and deletes your sign-in identity. Step by step, with exactly what is and isn’t erased: Delete your account.
End-to-end encryption (optional)
You can additionally turn on end-to-end encryption for your synced data (Settings → End-to-end encryption). When you do, your financial records are encrypted on your device with keys that exist only on your devices — our servers store and relay data they cannot decrypt. A breach of our infrastructure, a legal demand for our database, or anyone at Ketzie would get scrambled bytes, not your finances.
Three things to know if you turn it on:
- Your recovery code is the only reset. There is no password reset for encrypted data. You get in with an enrolled device, your one-time recovery code, or a passkey saved to your password manager. If you lose all of those, your encrypted cloud backup is permanently unreadable — by design, we can’t help. (The data on your devices is unaffected.) Ketzie will never ask for your recovery code by email, phone, or chat.
- The narrow exceptions stay the same. Features where you explicitly send data for processing — statement import, and bank-connection data in transit — are processed transiently as described in their own sections and are never stored in readable form. Encryption covers what our servers store.
- What we can still see: that you have an account, when your devices sync, and roughly how many records you have — but not names, amounts, dates, or any of their contents.
When end-to-end encryption is on, the app can register for push notifications so your other devices are alerted to approval requests and recovery use. We store a notification token for each enrolled device to deliver them; the notifications themselves name only the kind of event and carry no financial data.
Bank linking (optional, requires sign-in)
Ketzie can keep your balances current by connecting to your bank or card through Plaid, the bank-connection service most banking apps use. This is optional, and everything works without it — you can keep updating balances by hand.
- Connecting: you sign in to your bank on Plaid’s own screen, inside the app. Your bank username and password go to Plaid, never to Ketzie. Plaid receives an opaque Ketzie account identifier so it can associate the connection with you; it does not receive your name or email from us. Plaid’s handling of your data is described in Plaid’s end-user privacy policy.
- What Ketzie reads: the list of accounts at that institution (names, account types, and the last few digits of each account number), their balances, and their recent transactions — used to keep balances fresh and to recognize recurring charges that match the bills you track.
- What our servers keep: the connection record — the institution, the account names and last digits, the access credential Plaid issues so we can fetch on your behalf, a position marker in the transaction feed, and, when you confirm one, which bill a recurring charge belongs to. Balances and transactions pass through our servers to your device and are not stored on them. On your device they’re stored encrypted like everything else you enter. Plaid notifies our servers when a connection’s status changes (for example, when your bank requires a fresh login); those notices carry no financial data.
- Ending it: disconnect any bank at any time from the app; that revokes Ketzie’s access at Plaid and your accounts return to manual updates. Connections that stay broken, or go unused for an extended period, are disconnected automatically. Deleting your account disconnects every bank and deletes the connection records — see Delete your account.
Usage analytics (with a one-tap opt-out)
To understand which features are working — and nothing more — the app records a small set of coarse usage events, like “finished setup,” “saw a safe-to-spend number for the first time,” or “a statement import succeeded and proposed 1–5 bills.” These events are processed by PostHog, on servers in the European Union.
What these events never contain:
- No financial information. No amounts, balances, or account, bill, or merchant names — and nothing from any statement you import. Events carry only the event name and broad categories (like a count range).
- No identity. Events are tagged with a random identifier created on your device, and we never connect it to your email, your sign-in, or anything else about who you are.
- No tracking. Nothing follows you across other apps or websites, and nothing is used for advertising.
Error reports go through the same channel: if the app crashes or hits an unexpected error, it sends the type of error, where in the app’s own code it happened, and the app version. Before an error report leaves your device, its text is scrubbed of anything you might have entered — names, amounts, email addresses — so it describes the failure, never your data. The analytics switch below turns error reports off too.
Analytics is on by default so we can tell whether Ketzie’s setup and import actually work for new users, and you can turn it off any time in Settings → “Share anonymous usage data.” When it’s off, nothing is sent.
Information we do not collect
Ketzie has no advertising, no cross-app tracking, and no data brokers. We don’t build a profile of you, and we don’t sell or share your information for anyone else’s purposes. The services named above — Amazon Web Services (AI statement import, sign-in, sync, and bank linking), Firebase, Plaid (bank connections), PostHog (usage analytics and error reports), and Shorebird — act as our processors for the specific, limited functions described here, not as buyers of your data.
App updates
Ketzie uses a code-push service (Shorebird) to deliver small over-the-air updates. When the app checks for an update, it makes a network request that may include basic technical metadata — such as your IP address and the app’s version — used solely to determine whether an update applies to your build. No financial or personal information you enter into Ketzie is included in these requests.
Children
Ketzie is not directed at children and does not knowingly collect information from anyone.
Changes to this policy
If this policy changes, we’ll update it here and revise the “Last updated” date. Material changes will be reflected before they take effect.
Contact
Questions about privacy? Email privacy@ketzie.com. This policy is published by Littlecat LLC, New York, the operator of Ketzie.