Effective July 26, 2026

Privacy Policy

This policy explains how ClarusFi processes information, what remains on your device, and the controls available to you.

ClarusFi is local-first. Core wealth records, imported files, screenshots, and on-device OCR results remain on your device unless you deliberately use a feature that clearly explains a remote transfer.

Who operates ClarusFi

ClarusFi is developed and operated by Fanghao Zhang. Questions about this policy or requests concerning your data can be sent to puretoolskit@proton.me.

Data that stays local

Accounts, balances, holdings, transactions, planned cash flows, reviews, imported CSV or statement content, screenshots, OCR output, and saved AI drafts are stored locally by default. Optional manual iCloud backup uses your private Apple CloudKit database.

Remote AI

Remote AI is optional and requires in-app consent. ClarusFi sends only the records needed for the task you choose. Normal AI processing does not retain financial records, imported files, screenshots, prompts, conversations, or AI answers in application content logs.

A random installation identifier, App Attest proof, subscription status, and limited usage metrics are processed for authentication, fraud prevention, quota enforcement, reliability, and cost control. Metrics may include model route, token counts, latency, status, and estimated cost, but not account names or asset values.

Voice input

Voice input is optional. When you start it, microphone audio is sent only to produce editable text. Temporary audio is deleted after transcription, failure, or cancellation. Audio and transcript content are not retained in ClarusFi service logs.

Optional analytics and contributions

Analytics is off by default and controlled separately from AI access. If enabled, ClarusFi limits analytics to approved product and reliability fields.

Agent improvement contributions are also off by default. You must select a response, inspect the redacted exchange, and confirm before sending it. A contributed exchange excludes the installation identifier and other conversations, is encrypted, expires after the configured retention period (30 days by default), and can be deleted using the receipt stored on your device.

Service providers

  • Apple provides StoreKit, App Attest, and optional private iCloud backup.
  • RevenueCat processes subscription entitlement status.
  • Alibaba Cloud processes AI and optional speech requests after in-app consent.

These providers process information under their own terms and privacy commitments and may process data in countries other than your own.

Your choices and deletion

You can independently disable remote AI, analytics, or contributions; delete contributed exchanges; export or erase local records; revoke iCloud access; and manage subscriptions through Apple. Deleting the app removes its local data, subject to any backups you separately chose to create.

Security and children

ClarusFi uses platform security controls and minimizes remote data, but no system can guarantee absolute security. ClarusFi is not directed to children under 13, and we do not knowingly collect their personal information.

Changes and contact

Material changes will be reflected by the effective date on this page and, where appropriate, communicated in the app. Contact puretoolskit@proton.me for privacy questions or requests. Please do not include balances, statements, screenshots, prompts, or other private financial records.