Skip to content
Menu
Get support

Privacy guide

How your financial data is handled

Position separates storage on your iPhone, transient processing by a disclosed AI provider and narrowly limited service metadata. Those are different destinations.

Current app path

Settings → What Position can see; Inbox → document → Privacy receiptThe destination boundaries apply to Position. The in-app labels, matrix and per-document receipts were introduced in Build 125.

Required

  • The document or feature whose route you want to check

Optional

  • A retained original when you want to inspect document evidence
  • Parser learning when you choose to share bounded structural information

What can block completion

  • Legacy or missing route evidence, which Position shows as unavailable rather than guessing
Local financial data
The financial database, ledger, balances, transactions and encrypted retained documents live on the iPhone. Position has no hosted copy of that financial database.
Privacy or AI boundary
Certified statement layouts are processed on-device. When AI is required, selected content may be processed transiently by OpenAI through managed AI or directly with your own key; Position does not retain that content after a managed request.
If it does not work
If route evidence is unavailable, treat the route as unknown. Do not assume it stayed local.

Storage stays on the iPhone

The authoritative financial database—including ledger rows, balances, transactions, merchant history and corrections—lives in encrypted app storage on your iPhone. Retained original statements and document evidence are encrypted locally as well. Position has no hosted copy that the operator can query.

Processing is different from storage

Certified statement layouts are processed on-device. When an unfamiliar document, Chat or another AI feature needs an external model, selected content may be processed transiently by OpenAI after disclosure. Managed AI routes it through Position’s service; use of your own OpenAI key sends it directly to OpenAI. Position does not retain managed request or response content after processing.

What Position can see

The operator can work with narrow support and service records. Those records do not provide a remote path into the financial database or retained documents.

Data destinations and operator access
DataNormal destinationWhat the operator can access
Financial databaseEncrypted app storage on the iPhone and user-controlled encrypted backupsNo hosted copy; the operator cannot query ledger rows, balances, transactions, merchants or corrections.
Original statementsEncrypted document storage on the iPhone under the selected retention controlNo hosted copy; the operator cannot retrieve statement or document content.
Selected AI contentTransient OpenAI processing, through managed AI or directly with your own keyManaged AI forwards selected content but Position does not retain it after the request. Own-key content does not pass through Position.
Managed service metadataPosition’s managed servicePseudonymous credits, usage, allowance and service-status metadata without financial content.
Compatibility healthPosition’s managed service when reporting is enabled for the buildAggregate canonical institution and document/account type only, without a user or device identifier or financial content.
Optional parser learningPosition’s managed service only when you enable parser learningCoded metadata and allowlisted structure without literal document text, identity, filenames, dates, account or card identifiers, balances or transaction values.
Support Position IDPosition’s managed service and support when neededThe operator can use this support identifier. It grants no access to local financial data.

Processing labels and privacy receipts

Build 125 and later can label a document as processed on-device, through managed AI or with your own key. Each document privacy receipt describes the recorded route, whether selected content left the device, the provider when known, Position’s remote-retention result and whether original evidence remains locally.

  • Persisted evidence takes priority over cached interface state.
  • A legacy, missing or unreadable route is shown as unavailable—not inferred to be local.
  • A pending or failed receipt does not claim that imported evidence was committed.
  • Optional parser learning is disclosed separately as a bounded, literal-content-free structural report; it is not statement content.

Originals and retention

While retained, original statements are encrypted on the iPhone. The default retention period is 12 months; Settings can select 3, 6 or 12 months, or forever. Originals needed for review or reconciliation are held while that work depends on them. Removing local data, deleting the managed account and disconnecting managed AI are separate controls.

Use retention, backup and deletion controls

Support and donation are separate

Ordinary support can use a Position ID, app/build context and a reviewed privacy-safe diagnostic preview. It cannot retrieve statements, document content, ledger rows, balances, merchant history or transaction values.

Independent review

No independent privacy review has been completed. Any future review remains planned work until its evidence is completed and published. Position does not claim an independent audit, certification or formal assurance.