KDC Solutions Legal

Wherewithal Privacy Policy

Effective date: July 16, 2026

Wherewithal is built by Klinetek Solutions ("Klinetek," "we," "us"). This policy explains what information the Wherewithal app handles, what little of it ever leaves your phone, and the choices you control. We wrote it to be read — the short version below is accurate, and the rest is detail.

The short version

What we don't collect

Wherewithal has no user accounts, so we hold no usernames, emails, or passwords. The app contains no analytics or advertising SDKs, no crash reporting, and no third-party trackers. We never ask for your bank login and have no connection to your bank. We do not collect your location, contacts, or any device identifiers tied to you. We do not sell, rent, or share personal information with anyone for marketing, advertising, or any other purpose.

Data stored on your device

Everything you put into Wherewithal — imported transactions, categories and rules, debts, goals, budget scenarios, settings, and your plan status — is stored in files on your device, inside the app's private storage. It is protected by your device's own security (and the optional in-app biometric lock). We keep no copy of it. Nothing here is uploaded, backed up to us, or readable by us. The two features that can send anything at all — AI sorting and Household sync — are described below, and both are things you turn on and choose to use.

You are in full control of this data: the app's "Start fresh" erases it, deleting the app removes it, and the Backup feature exports a file that goes only where you choose to put it. Because we keep no copy, a deleted backup or app cannot be recovered by us.

The optional AI features

Wherewithal's AI features are optional and consent-gated: you choose during setup (and can change any time in the account menu) whether AI auto-sort is on. When it is off, nothing described in this section is sent, and the app falls back to fully on-device sorting rules.

When AI features are on, the following — and only the following — leaves your device, over encrypted connections:

  1. Simplified merchant names. To name and categorize unfamiliar merchants, the app sends short, normalized merchant-name strings (for example, `joes pizza seattle wa`). Before sending, every digit is stripped (so card fragments and account numbers cannot be included), and person-to-person payment descriptions (Zelle, Venmo, Cash App) have the person's name removed — only the service name is sent. Amounts, dates, balances, and account details are never part of these requests. Answers are cached on your device, so a merchant is normally sent once.
  1. Statement text you ask the AI to read. Two features can read a statement: importing transactions from a PDF, and filling in a debt's terms from a lender statement. The app always reads the document on your device first; many statements import with nothing sent at all. When the AI is needed, it receives only text extracted from the statement with identity details removed — the name and address block is dropped and long digit runs (account and agreement numbers) are masked. The PDF file itself is never transmitted, under any circumstance. Scanned-image PDFs, which contain no extractable text, are refused rather than sent. These features tell you before they run, and they simply don't run if AI is off.
  1. No web search. Merchant strings are never turned into web-search queries. An earlier optional feature that could do this was removed entirely; the app's AI calls carry no search tools of any kind.
  1. An anonymous usage counter. AI requests include a random identifier created on your device the first time the app runs, plus a monthly usage-proof code. It is not derived from you or your device's hardware identifiers, and we cannot connect it to your identity. It exists solely to meter fair use of the AI service.

Who processes AI requests

AI requests travel from your device through our relay service (a Cloudflare Worker operated by Klinetek) to Anthropic, the AI provider, and the answer comes back the same way. Our relay does not log or store the contents of requests or responses; it forwards them and keeps only anonymous usage counters. Anthropic processes the request under its commercial API terms, which state that API inputs and outputs are not used to train its models by default. Retention by Anthropic is governed by Anthropic's own policies; we cannot control or delete data held by the AI provider, which is one of the reasons the app minimizes what is sent in the first place.

Service providers involved: Cloudflare, Inc. (relay infrastructure; transit only) and Anthropic, PBC (AI processing). Both act as processors for the limited data described above; neither receives your name, account, or stored financial records from us.

Household sync — sharing with a partner

Household sync is off until you deliberately pair two phones. When you use it, this is exactly what happens.

What is sent. Only the accounts you tick on the send screen: those accounts' transactions (date, amount, description, merchant, category), the account's name and colour, your chosen display name and household name, and the "learned" layer (merchant names, category rules and splits) so your partner's copy sorts itself without re-running the AI. Accounts you do not tick are never included. Note that a transaction description can name the person or business on the other side of it — if you send an account, you are sharing those names with your partner.

How it is protected. The update is encrypted on your phone with a key derived from the pairing code, using AES-256-GCM. That key exists only on the two paired phones. It is never sent to us and we never hold it, so we cannot read what you send, and neither can anyone who obtains the stored file.

What we hold, and for how long. The encrypted bundle waits in a mailbox on our relay until your partner's app collects it. We can see that a household exists (as a one-way hash), roughly when an update was placed and how large it was — never its contents. Bundles are deleted when you recall them and expire automatically after 90 days. We keep no read receipts: neither we nor the sender is told when, or whether, an update was collected.

Leaving. Leaving the household stops future sharing and pulls back any update still waiting. It cannot un-send something your partner has already accepted — that copy lives on their device, exactly like a text message you have already sent.

Purchases

Subscriptions and purchases are handled entirely by Apple's App Store or Google Play. We receive confirmation that a purchase is active — never your name, card number, or billing details. Apple's and Google's own privacy policies govern their processing. Unlock codes you redeem in the app are validated on your device.

Notifications

Reminders (such as payday or upcoming-bill nudges) are scheduled locally on your device and are off by default. No notification data leaves the device.

Legal bases (GDPR)

Where the GDPR or similar laws apply: the AI features process data on the basis of your consent (Art. 6(1)(a)), which you may withdraw at any time in the app; subscription entitlement checks are processing necessary for performance of a contract (Art. 6(1)(b)); anonymous usage metering is our legitimate interest (Art. 6(1)(f)) in preventing abuse of the AI service. Data sent to the AI features is processed in the United States; where required, transfers rely on standard contractual safeguards maintained by our processors.

Your rights

Because your data lives on your device, the most important rights are already in your hands: you can access, correct, export (Backup), and erase (Start fresh / uninstall) everything without asking us. If you are in a jurisdiction with privacy rights (GDPR, UK GDPR, CCPA/CPRA, and similar) you may also contact us to exercise rights over the little data that touches our systems — in practice, anonymous relay usage counters that we cannot connect to you. We do not discriminate against anyone for exercising privacy rights. California residents: we do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we have not done so.

Children

Wherewithal is not directed at children and is not intended for use by anyone under 16 (or the age of digital consent where you live). We do not knowingly collect information from children.

Changes to this policy

If we change this policy, we will update the effective date and note the change in the app's release notes. Material changes to what the AI features send will always be disclosed in the app before they take effect.

Contact

Klinetek Solutions — klinetek@gmail.com

This is the same document that ships inside the app — one source of truth, no drift. © 2026 KDC Solutions™