Privacy Policy

Costy and exAI · Effective August 1, 2026

We collect only the information needed to provide Costy and exAI. We do not sell personal information or use it for targeted advertising. We do not collect biometric templates, precise location, contacts, government identifiers, or health records.

Information you provide

When you create an account, we store your name, email address, and a securely hashed password. Depending on the features you use, we also store information you choose to submit:

Camera, photos, and biometrics

Costy accesses the camera or a photo you select only when you ask it to process a receipt. Receipt images are sent securely to our service for extraction. Biometric sign-in is performed by your device's operating system. Costy and exAI receive only a success or failure result and never receive or store your fingerprint, face image, or biometric template.

How we use information

We use information to authenticate you, process and organize receipts, provide spending analytics and forecasts, maintain grocery lists and meal plans, track workouts, provide requested AI-assisted features, administer subscriptions, respond to feedback, prevent abuse, and operate and secure the services.

Sharing

We share grocery lists, meal plans, or other supported content with linked users only when you explicitly choose to share it. We use service providers to operate Costy and exAI, including Cloudflare for secure network delivery and Stripe for subscription billing. These providers process information only for their service functions and under their own contractual and legal obligations. We may disclose information when required by law or to protect users and the service.

Retention and deletion

We retain account information and user-created content while your account is active. You can permanently delete your account and associated application data from Settings → Account → Delete account in Costy or Settings → Session & Data → Delete account in exAI. You can also use our web account-deletion page. Limited records may remain temporarily in encrypted backups or when retention is legally required.

Security

Information is encrypted in transit using HTTPS. We use access controls, password hashing, restricted production secrets, and other reasonable safeguards. If you enable trusted-device password recovery, we store the device's public recovery key; the private key remains on your device. We store only hashed versions of one-time recovery codes. We never receive your phone PIN, pattern, password, fingerprint, face data, or private recovery key. No storage or transmission system can be guaranteed completely secure.

Children

Costy and exAI are not directed to children under 13, and we do not knowingly collect information from children under 13.

Changes

We may update this policy when the applications or legal requirements change. We will publish the revised policy here and update its effective date.

Contact

For privacy questions or requests, use Feedback & Requests in either application's settings, or email [email protected].