Privacy Policy

Xavier — Expense Tracker

Last updated: 29 July 2026

The short version: Xavier collects no personal data. Your expenses live only on your iPhone, encrypted at rest. There are no accounts and no tracking, and nothing is ever sent to us — we run no servers. One optional feature, Bring your own key, sends some of your data to an AI provider you choose, using your account with them. It is off unless you turn it on.

Who this applies to

This policy covers the Xavier — Expense Tracker app for iOS (“Xavier”, “the app”, “we”, “us”). By using Xavier you agree to this policy.

Data we collect

None. Xavier does not collect, sell, or share any personal information. We have no servers that receive your data, no analytics or advertising SDKs, and no account system. We cannot see your expenses — not as a promise, but because there is no mechanism by which they could reach us.

This remains true whether or not you use Bring your own key. That feature sends data from your phone directly to a provider you have your own account with; it does not route through us, and we receive no copy of it.

Where your data lives

Backups

If you choose to back up your data, the backup is written to your own iCloud account, managed by Apple under Apple’s privacy policy. Backups never pass through any infrastructure operated by us.

Camera and photos

If you scan a receipt, Xavier uses your camera (or a photo you pick) only to read the receipt on your device, using Apple’s built-in on-device text recognition. Access is requested only when you use that feature.

Receipt images are never uploaded anywhere — not to us, not to any AI provider, not to anyone. This is true even with Bring your own key switched on: no photo is ever sent off your device.

Face ID

You can optionally lock the app with Face ID. Authentication is handled entirely by iOS — your biometric data is never accessed by, or shared with, Xavier.

The assistant

By default, Xavier’s assistant runs on Apple’s on-device Foundation Models, built into iOS. Nothing you type into the assistant leaves your iPhone, and no key or account is required.

Bring your own key (optional, off by default)

You can optionally supply your own API key from OpenAI or Anthropic, in Settings → Assistant, to use that provider’s model instead of the on-device one. This is switched off unless you turn it on. When it is on, your requests go directly from your iPhone to that provider, using your key and your own billing relationship with them. They never pass through any infrastructure we operate — we operate none — and we receive no copy of them.

What is sent to the provider you chose:

What is never sent: your database, in whole or in part — there is no bulk upload or sync; your backups; receipt images or any other photo; and your API key to anyone other than the provider it belongs to. Your key is stored in the iOS Keychain on your device and is never recorded in logs.

The provider’s own terms govern what they do with what you send them, including how long they keep it and whether they use it to improve their models. That is a relationship between you and them, under the account and key you supplied; we are not a party to it and have no visibility into it. Please read their policies: OpenAI · Anthropic.

To turn it off: switch Bring your own key off in Settings → Assistant and delete the stored key there. The assistant returns to running entirely on your device. Deleting the app removes the key from the Keychain along with your data. Data already sent to a provider is managed through your account with that provider.

Third parties

Xavier includes no third-party analytics, advertising, or tracking SDKs, and no data is shared with anyone for advertising, profiling, or any purpose of our own. The only circumstance in which your data reaches a third party is Bring your own key, which you switch on yourself, using your own account with the provider you pick.

Children’s privacy

Xavier is rated 4+ and collects no data from anyone, including children under 13. Bring your own key requires an API key from an AI provider, which those providers do not issue to children; it is off by default and the app is fully usable without it.

Changes to this policy

If this policy changes, we’ll update this page and revise the “last updated” date above. Material changes will be reflected here before they take effect.

Contact

Questions about privacy? Email taedevelops@gmail.com.