Privacy

Privacy, in plain words.

Artos is a small 4-week pilot built by a student at SMU. This page explains exactly what happens to your data. It is written to align with Singapore's PDPA.

Your statement files

Screenshots and PDFs you upload are processed in memory and released the moment extraction finishes. They are never written to disk and never stored, whether extraction succeeds or fails. There is no file to delete because no file is kept.

What we store

Only the extracted transaction details you confirm (date, description, amount, category), your accounts and budgets, your login (email, username, hashed password), usage events recorded against your account (which feature you used and when, never the contents of your transactions), and any feedback you send, which is stored word for word. The extraction model is told never to return account or card numbers, and we defensively mask any long digit run before saving, so a stored description should never contain an account or card number.

Usage and what it costs to run

Two more things get written down against your account. Opening the app records a timestamp, so all it says is that you showed up and when. Uploading a statement records what the AI call cost to read it: the token counts going in and out, and what that works out to in dollars.

Neither one ever contains amounts, merchant names, category names, or anything else from inside your statements. They are here for two reasons. During the pilot they show which parts of Artos people actually come back to, which is how it gets better. And the founder pays the AI bill for every upload out of his own pocket, so seeing usage and cost per account is the trade for a pilot that charges you nothing. Delete your account and both go with everything else.

Screen recordings during the pilot

During the pilot, and only during the pilot, Artos records what happens on screen once you are signed in: where you tap, what you scroll past, which screen you were on when you gave up. Signed out, nothing is recorded at all. It is the closest thing to sitting beside you while you try it, and it is how the confusing parts get found.

Everything financial is blanked out in your browser before anything is sent. Amounts, merchant names, category names, and anything you type are replaced with solid blocks first, so the recording never holds them at any point. What arrives is the shape of the screen and what you did on it.

Only the founder watches them. They stop the day Artos opens to the public, which is a switch being turned off rather than a promise to remember. The recording is done by PostHog, on servers in Frankfurt, and that is also where the recordings sit: they are not inside Artos, so deleting your account does not reach them. They are wiped when the rest of the pilot data is, and sooner than that if you email and ask.

Where it lives
Render hosts the app (Singapore region).
MongoDB Atlas stores your data.
Anthropic API reads each statement to extract transactions, under commercial API terms that do not train on your data. The text sent for extraction and the text returned may be kept for up to 30 days for abuse monitoring, then deleted.
Sentry records technical errors only. It never receives your file contents, transaction details, or account numbers.
PostHog holds the masked screen recordings during the pilot (EU region, Frankfurt). The financial parts are blanked out in your browser, so they never reach it.
What the founder can and cannot see

Usage events are recorded against your account, not anonymously: each notes which feature you used and when (for example opening the dashboard or sending feedback), never the contents of your transactions. The admin view mostly reads these as counts and rates across testers, but they are tied to your account, not aggregated away. Any feedback you send is stored word for word and is read by the founder. As the operator of the database, the founder can technically access stored records for support and debugging, but does not browse them, and never sees your raw statement files because they are never stored.

Your rights

You control your data from your profile, which offers two options, both immediate:

Delete all transactions clears your transactions so you can start fresh. Your accounts, budgets, categories, and login are kept.
Delete account permanently removes your login and everything stored about you: transactions, accounts, budgets, categories, uploads, and usage events. The app-open timestamps and the processing cost records go with it. It asks for your password to confirm and cannot be undone.
The pilot screen recordings are the one exception. They sit with PostHog rather than inside Artos, so deleting your account does not reach them. Email and yours are removed; otherwise they go when the pilot data does.
When the pilot ends

At the end of the 4-week pilot, tester data is deleted unless you have asked to keep your account for the next version. You will be told before any deletion happens.

Contact

Data protection contact: Dewa (SMU). Email: imnuza@proton.me. Reach out to ask what is stored about you, to correct it, or to request deletion.