Pendi

Privacy policy

This policy covers the Pendi Android application. It is written to match what the app actually does; every claim below is grounded in the shipped behavior.

Effective date: August 28, 2026. Last updated: August 28, 2026. Data controller: Elkin Cardoso Leyton, independent developer, Colombia. Contact: [email protected].

The short version

Your data lives on your device and the app works without you signing in. Sharing a space with your family syncs that space's content through Google Firebase, and you can separately turn on a backup of your Personal space, which uploads it to the same place. Neither happens unless you ask for it. Bank notifications are read on your device, and nothing is read at all until you grant notification access; once you do, the app your phone uses for SMS and the messaging and mail apps named in the app's own list start active as channels and pass on only what carries an amount and a money word, the bank and wallet apps found installed from a recognised store start active under that same rule until one tap widens them, and an app identified only by what it can do rather than by name, or installed from somewhere other than a recognised store, stays listed and off until you switch it on; every source can be switched off, one by one or all at once. The AI assistant is offered during setup and is active once you accept it there, after which a reduced fragment of a captured notification can leave the phone without you tapping anything each time; personal and sensitive data never leaves the phone, only minimized masked fragments do, and you can turn the assistant off at any time. Nothing is sold, there are no ads, and no advertising identifiers are collected.

Who is responsible for your data

Pendi is developed and published by Elkin Cardoso Leyton, a natural person working as an independent developer in Ibagué, Colombia. There is no company behind it. He is the data controller for the processing described in this policy, and the contact route is [email protected], the same address shown on Support and on Delete your account.

Data stored on your device

Tasks, lists, budgets, accounts, movements, categories, people, reminders and settings are stored locally in the app's private storage. Backups are user-initiated, encrypted, and saved where you choose. Uninstalling the app deletes its local data.

Transaction detection (notification access)

If you enable detection, the app reads system notifications from the sources that are active, to recognize payment notifications and turn them into movements you confirm. Which sources start active depends on how the app identifies each one, and on whether you have ever chosen sources yourself. On a phone where you have not, the app your phone uses for SMS and the messaging and mail apps named in the app's own list start active; on a phone where you have, that same change is offered to you as one tap instead of being made for you. Those are CHANNELS: they carry somebody else's message and hold no free pass, so a notification from one of them is only ever processed when it carries both an amount and a money word, and an ordinary text or mail is discarded without being stored. The bank and wallet apps the app finds installed from a recognised store start active as well, held to that same money rule, until one tap widens that row to the rest of its notifications, including the ones with no figure. Any other app the list names, found installed from a recognised store, starts active under the money rule too. An app identified only by what it can do rather than by name, and any app installed from somewhere other than a recognised store, are listed and off until you switch them on, as is the rest of the list. A bank or wallet app the list names and you switch on yourself is read whether or not its notifications look like money, because that is what you asked for by turning it on. Every source can be switched off, one by one or all at once. Reading and interpreting happen on your device, and the full text of the notification never leaves the phone.

Here is what can leave it. Once you accept the assistant during setup, and while it is on, the app sends a reduced fragment of the notification to ask for the category of the expense, and it does so on its own, without you tapping anything, as soon as the capture reaches the inbox. Before that fragment goes out, the phone removes email addresses, masked account or card tails, and any run of four digits or more, so account numbers and card numbers do not leave. What travels is the merchant name and the amount, and on the category question the amount is masked to its shape ($###.###) instead of being sent, because that answer never needed the real figure. Your category names travel with it as the list of options to choose from, ordered from the one you use most, and that ordering is itself information about what you spend on. You can disable any source, or detection entirely, at any time.

Optional account and shared spaces

The app can operate a lightweight anonymous session (no email, no password) to enable its managed AI tier and shared content. If you share a space with family members, the content of that shared space (its tasks, lists, budgets and movements) syncs through Google Firebase (Firestore) so members see the same data. Your Personal space is not uploaded unless you turn on Settings > Account > Back up the Personal space. When you do, its content is uploaded to Firestore under your own account, where only that account can read it, and it stays there until you delete the account. Google's infrastructure processes this data as our provider; we do not sell it or use it for advertising.

AI features

There are two tiers. They are used to suggest the category of an expense, parse what you dictate by voice, help you create a rule, and summarize your week.

Pendi AI (managed). The reduced fragments described above travel to a service of our own hosted on Cloudflare Workers, which passes them to the language model that processes them. Requests carry a daily quota, we do not use them to train models, and they carry no account or card numbers.

Bring your own key (Gemini). The fragment goes straight from your device to Google under Google's terms; we never see your key in our services and it is stored encrypted on the device, protected by the Android keystore.

Who processes the managed tier's fragments

These are the processors the managed tier can route to, each with the company and the jurisdiction it operates from. Your fragments can be processed outside Colombia by any of them.

Which of them serves a given request is decided server-side and can change without a new app release, which is why this list, and not the app's screens, is where it is kept current; if a change alters what this policy says, we announce it in the app's changelog first. Accounts on the free lane are never routed past the house lane under any condition: when the house allowance runs out on a free account the assistant simply stops suggesting for the rest of the day, and the app's own rules and learned merchants keep working on the device. Note that “free” here means the lane the server resolves your account to, and a trial, a founder grant or a referral grant puts an account on the paid lane without any payment. Nothing about the fragments changes on either route, the same minimization applies, and no account or card numbers are included.

What is sent, on each of the four paths

The assistant makes four kinds of request, and what leaves the phone is different on each. Personal and sensitive data never leaves the phone; what travels is minimized and masked. Your family's names are replaced with opaque tokens before any request is built, and email addresses, card tails and any run of four digits or more are stripped.

When it starts, and how to stop it

A fresh install starts on Pendi AI rather than on no assistant at all, so the managed tier is the one selected for you, and the app asks you to authorize the transfer during first-run setup, on a screen that shows what would be sent and states that it can be processed outside Colombia. The assistant is active once you accept it there. If you decline, or leave setup without accepting, nothing is sent: the request stops on the phone, no session is created, and the app keeps working on its own rules. If you are updating from an earlier version of the app, you do not walk that setup screen again, and an answer you gave to an older version of this disclosure does not carry over to a changed one: it reads as no answer at all, the assistant stays silent, and the question is put to you again either when a feature next needs it or from the Settings > AI row you open yourself. Once you accept, the app signs in anonymously to Firebase (no email, no password) so the requests can be attributed to a quota. You can withdraw that authorization, or turn the assistant off, under Settings > AI; with it off detection keeps working with the app's local rules, the rest of the app is fully functional, and the other things this policy describes (sync, backup, push registration) are unaffected because they were never part of the assistant.

Voice dictation

Dictation runs on your device. The audio is handled by Android's own speech recognizer and the app never records it to a file, never stores it and never uploads it. Pendi asks for the offline pack first, and when your phone does not have one for that language the recognizer answers over the network instead, the same way your keyboard's microphone does: the audio goes to your phone's speech provider under their terms, and never to us. Under Settings > Voice you can ask Pendi to start with the online recognizer and skip the offline attempt.

Under Settings > Voice there is one switch, “Improve Pendi with my dictations”, and it is off unless you turn it on. With it on, two things happen together. Your dictations are kept on the phone with what the app understood from them, which is what lets a misreading be reproduced and fixed. And the TEXT the recognizer produced, together with the language it was spoken in, is queued and sent to us so the parser can be improved with real phrasing instead of invented examples. Nothing else travels with it: not the audio, not what the app parsed out of the sentence, not where it was saved. The upload waits for a network, so being offline delays it and never loses it, and it is attributed to your account the same way the feedback channel is.

Turning the switch off stops the sharing, deletes the dictations kept on the phone, and discards anything still waiting to be sent. It does not delete what already arrived; write to the contact address above for that. The setting is deliberately left out of backup files, so restoring a backup onto a new phone never turns sharing on for you.

Contacts

Only if you use the contact import feature, and only at the moment you pick a contact, the app reads that entry's name, phone number and photo to create a person in your space. The photo needs the Contacts permission and the app asks for it right there; the name and the phone number are imported without any permission at all. There is no background contacts access and no bulk read of your address book. If you later save that person into a shared space, their name, phone number and any email you typed sync to Firestore with the rest of the space, and the photo stays on your device.

Crash reporting

Production builds send anonymous crash reports (stack traces, device model, OS version) through Firebase Crashlytics so defects can be fixed. Crash reports contain no financial content and no notification text. Google documents that Crashlytics keeps crash stack traces and the associated identifiers for 90 days, and then starts removing them from live and backup systems. You can read that in Privacy and Security in Firebase.

The Firebase Analytics library travels inside the app because it is the companion piece Crashlytics ships with, but its collection is off in the app's manifest, the advertising-identifier permissions it would otherwise contribute are stripped from the build, and the app logs no analytics events. In other words: no usage metrics and no app-instance identifier are collected. Crashlytics is a separate product and it does work: the crash reports described in the paragraph above are sent.

What we never do

Data deletion

Local data: use Settings > Account > Erase the data on this device, which erases everything the app keeps on that phone in one action and signs you out first so nothing downloads again, or uninstall the app, which does the same. You can also still delete in parts: the captured text under Settings > Movement detection, the sample data, and the contents of the Vault. Shared-space data: leave or delete the space in-app; deletion propagates to the synced copy. Turning the Personal-space backup off stops further uploads but does not remove what is already there; deleting your account does. Anonymous session data and AI quota counters: request deletion by email and include your space identifier from Settings. We answer deletion requests at the contact address above. The complete account deletion steps are on Delete your account.

Your rights over your data

Pendi is published from Colombia, so Colombian data-protection law applies to your personal data: Ley 1581 de 2012 and Decreto 1377 de 2013. The data controller is Elkin Cardoso Leyton, an independent developer in Colombia, the same person named in Who is responsible for your data above. As the data subject you can know what data of yours is processed and what for, update it when it has gone out of date, rectify it when it is incomplete or wrong, delete it with the steps and the limits described in Data deletion, and revoke the authorization you gave to process it.

There is a single channel for all of it: write to [email protected] from the address you use with Pendi, or include your space identifier from Settings. Queries, complaints and deletion requests all go there.

The windows the law sets and we meet: a query (consulta) is answered within ten business days, and if we cannot, we tell you why and by what date, and answer within five more business days at most. A complaint (reclamo) is handled within fifteen business days, and if we cannot, we tell you why and by what date, and handle it within eight more business days at most. If you believe a request was not handled properly, you can file a complaint with the Superintendencia de Industria y Comercio, Colombia's personal-data protection authority.

This section is a summary. For users in Colombia the governing text is the Spanish version of this policy, Política de privacidad, because that is the language the law is written and enforced in.

Children

The app is a family organization tool intended for adults and is not directed at children under 13.

Changes

Material changes to this policy will be announced in the app's changelog before they take effect.

Questions about your privacy? Write to [email protected], visit Support or Delete account.