- After account deletion: if you used a one-time benefit (such as the free trial or the Gameya gift) or a feature with a monthly or daily limit, we keep a one-way fingerprint of your sign-in identity — not your email itself, and it can't be turned back into it — together with a record of those benefits, so the same benefit isn't granted twice to a new account. If you never used any of these, nothing is kept. Details in section 6.
- Deletion requests made on our website: we keep the request itself for one year after it is closed, as a record that we carried it out (section 6).
- AI features: we explained in detail what is sent to OpenRouter with your requests — a summary of your financial data, and the images you send to be read (section 4 and section 5).
- Bank messages in the Android version distributed outside Google Play: we clarified that a passcode (OTP) message that also mentions a completed transaction or a balance is sent, so the transaction isn't lost (section 3).
- How we tell you about changes: we clarified how we notify you of future updates to this policy (section 10).
- ORA collects only the data it needs to work — your financial data and your email.
- We don't sell your data or use it for advertising, and there is no tracking across other apps.
- You can delete your account and all your data at any time from inside the app or here (except a small anti-abuse record — see section 6).
- Some smart features send the text of your request (or the image you send) together with a summary of your financial data to an external AI provider so they can work — we don't add your email or your name (unless they're already written in the message or image itself). Details below.
1. Who runs the service
ORA is a personal money-management app. The ORA team is responsible for processing your data. For anything related to your privacy, contact: support@withora.io.
2. Data we collect
| Type | Example | Why | Linked to your account? |
|---|---|---|---|
| Account data | Email, your name if you enter it, user ID | Creating your account, signing you in and contacting you | Yes |
| Financial data | Transactions, accounts, budgets, goals, subscriptions, installments, loans, gold and certificates | This is the core of the service — without it the app has no purpose | Yes |
| Content you upload | Receipt photos, voice recordings of commands, bank message text (if you turn the feature on or paste the message yourself) | Extracting transaction details automatically | Yes |
| Device and usage data | Notification token, device type and operating system, app version | Sending notifications and diagnosing problems | Yes |
| Crash and diagnostic reports | Crash log, the name of the screen at the time of the crash | Fixing crashes | No (aggregated) |
| Purchase data | Subscription status and renewal date | Activating paid features and verifying receipts | Yes |
We do not collect: your location, your contacts, your browsing history, or your advertising identifier. There is no tracking for advertising purposes across other apps or websites.
3. Bank messages
ORA never uploads your message inbox. The text of a bank message reaches us only in these cases:
- On iPhone: only if you yourself create an automation in the Shortcuts app. The automation sends ORA only the messages that contain the keyword you chose (such as “EGP” or your bank's name); the rest of your messages never reach us.
- On Android: the Google Play version has no permission to read messages at all — a message reaches us only when you copy it and paste it yourself into “Read a bank SMS”. In the Android version distributed outside Google Play, if you turn on message reading, the app scans messages on your device itself (new ones, plus messages from recent days if you ask to import them) and sends us only the messages that contain one of the keywords you chose, together with the sender name. One-time passcode (OTP) messages in a format the app recognises are removed on your device before sending — unless the message also mentions a completed transaction or a balance; those are sent so the transaction isn't lost, and our server rejects the passcode messages it recognises without storing their text. The rest of your messages never leave your device.
- The message text is uploaded to our server so we can extract the amount and the merchant from it.
- For the extraction to work, that text is sent to an external AI model provider (OpenRouter), which processes it in real time and returns the result.
- Payment-request messages (such as “So-and-so is requesting that you pay X”) are rejected outright and are never recorded as a transaction.
- A message that arrives automatically (the iPhone automation or automatic reading on Android), if it is a normal bank operation — a debit or a deposit — is recorded and counted in your balance right away, without you confirming it. Messages we are not sure about — such as promotions, loyalty-point redemptions, a merchant confirmation for the same amount as a transaction already recorded, or a declined transaction — are recorded as “Pending” and do not touch your balance or your budget until you confirm them yourself (or according to a decision you saved earlier for that type of message). You can edit or delete any transaction at any time.
- A message you paste into “Read a bank SMS” is not recorded until you review the result and tap “Save transaction”.
- You can stop this feature at any time: on iPhone by turning off or deleting the automation in the Shortcuts app, and in the Android version distributed outside Google Play from the app's settings or by revoking the SMS permission in your device settings. (The Google Play version sends no message except the ones you paste yourself.)
4. The smart assistant and voice commands
When you use the assistant or record an expense by voice, your speech is converted to text and sent to the AI model provider (OpenRouter) to generate the reply, together with a summary of your financial data needed for the answer — such as your account names and balances, your budgets, your spending and income totals, your recent transactions with merchant names, your subscriptions, installments, goals, gold and warranties, and your loans ledger with the names you entered. If you send an image (such as a receipt or an installment contract), it is sent too so it can be read. The provider processes the request in real time. We don't add your email or your name to these requests — but if your name (or email) is already written in a message or image you send (such as a bank SMS or an installment contract), it goes along with it as is.
5. Who your data is shared with
| Party | Purpose | What it receives |
|---|---|---|
| Google Firebase | Notifications and crash reports | Device token, technical crash data |
| OpenRouter | Extracting transaction details and assistant replies | The message or question text, images you send to be read (receipts and contracts), + a summary of your financial data (details in section 4) — without us adding your email or your name (unless they're already written in the message or image itself) |
| Apple / Google | Processing subscriptions and verifying receipts | Purchase data (they handle the payment; we never see your card details) |
| Hosting provider | Running the servers | The data is stored on our servers |
| A user you share your data with | Family sharing and Gameya (savings circle) — at your request | Only what you choose to share, and you can revoke it |
We do not sell your data to anyone, and we don't share it for marketing purposes.
6. Legal basis and retention
We process your data to provide the service you asked us for, and with your consent for optional features (message reading, notifications, camera, microphone).
We keep your data for as long as your account is active. When you delete your account, we delete your personal and financial data from the database. Aggregated, anonymous technical logs may remain for a limited time for operational and security purposes.
In addition, to prevent abuse of one-time benefits: when you delete your account, we keep a one-way keyed fingerprint (HMAC) of your sign-in identity — your email and your Apple or Google account identifier — together with a record of the benefits you already used: the free trial and the Gameya gift (kept with no expiry date), and this month's usage counters for features with a monthly or daily limit, such as the smart features, exports and reports (discarded after that month ends). The fingerprint does not contain your email, your name or any financial data, and it cannot be turned back into your email; we only use it to recognise a new account created with the same identity, so the same benefit isn't granted twice. This is based on our legitimate interest in preventing abuse. If you never used any of these benefits, nothing is kept.
If you request deletion through the account deletion page on our website, we keep the request itself (the email you entered, your reason if you gave one, and the request's status) as a record that we handled it, and delete it one year after the request is closed.
7. Security of your data
- The connection between the app and our servers is fully encrypted (HTTPS/TLS 1.2 or higher) — the app itself refuses unencrypted connections.
- Your session token is stored in the Keychain on iOS, and in encrypted storage with a key held in the Keystore on Android.
- You can lock the app with your fingerprint or face from the settings.
- No system is 100% secure — if a breach affects your data, we will notify you.
8. Your rights
- Access and portability: you can export all your data from inside the app (Settings → Backup).
- Correction: you can edit or delete any transaction or account at any time.
- Deletion: from inside the app (Settings → Delete account) or from the account deletion page. Deletion is final and cannot be undone.
- Withdrawing consent: you can turn off any permission (notifications, camera, microphone, message reading) from your device settings or the app.
9. Children
ORA is not directed at children under 13, and we do not knowingly collect data from them. The “Kids allowance” feature is managed by the parent from their own account, and the child has no separate account.
10. Changes to this policy
If we change anything material, we will update the date shown above and write a clear summary of what changed at the top of this page; the change takes effect from that date. We may also notify you with an in-app notification. You can open this page at any time at withora.io/en/privacy.
11. Contact
For any question or request about your privacy: support@withora.io.