Privacy policy
Effective 25 September 2026 · Applies to the Fullgrove app for iPhone, iPad and Apple Watch (盛林記帳 in Taiwan) and to fullgrove.com
In short
- Your ledger, the documents behind it and your statement passwords stay on your device. We run no server that stores them.
- Fullgrove never logs in to your bank, never reads other apps and never scrapes screens.
- A short list of things can leave the device, each described below. The ones that involve you are off until you turn them on.
- Settings › Network log in the app lists every host the app contacted and why.
- Who we are
- What stays on your device
- What leaves your device
- Anonymous usage, in detail
- Statement passwords
- What we never do
- This website
- Children
- Keeping and deleting data
- Your rights
- Changes and contact
1. Who we are
Fullgrove is made by Singular Intelligence (奇點智源), based in Taiwan. We are responsible for the personal data described in this policy. You can reach us at [email protected].
2. What stays on your device
Everything you put into Fullgrove is stored and processed on your own device:
- ledger rows, amounts, merchants, categories, notes, budgets, goals and account names;
- the evidence behind each row: statements, bank files, receipts, e-invoices, payment screenshots and photos;
- home inventory, shopping lists and reminders;
- statement passwords (see section 5).
Reading PDFs, recognising text in photos, categorising and matching rows all happen on the device. On-device Apple Intelligence models also run on the device. Share sheet, widgets, Shortcuts and other extensions only hand files to the app; the app does the reading itself when you open it.
When you export a CSV, an archive or an encrypted backup, you choose where it is saved. If you save it to a cloud service, that service's terms apply to the copy.
3. What leaves your device
These are the only exceptions. Each connection is written to Settings › Network log.
| What | Sent to | What is sent | When |
|---|---|---|---|
| Exchange rates | European Central Bank (www.ecb.europa.eu), US Federal Reserve Bank of St. Louis (fred.stlouisfed.org) | A download request for public exchange rates. No ledger data. | When rates need updating |
| Template packs | fullgrove.com | A download request for updated import templates. No personal data is sent. | When templates update |
| Anonymous usage and crash reports | Mixpanel (EU data residency, api-eu.mixpanel.com), Google Firebase Analytics and Firebase Crashlytics | Fixed events listed in section 4, a random install id and crash reports. | Only after you turn on “Share anonymous usage”. Off by default. |
| Optional account | Sign in with Apple, through Google Firebase Authentication | An Apple user id only. No email, no name and none of your ledger. | Only if you sign in |
| Cloud AI | Apple Private Cloud Compute | The single request being answered, such as an assistant question, the column headers of an import, new rows to label, or a photo to name for home inventory. | Only after you turn it on. Each request is logged. |
| Purchases | Apple (App Store) and RevenueCat | Apple handles payment. RevenueCat receives App Store transaction details and a random anonymous id to confirm what you bought. | When you buy or restore |
| Payment pages | The utility or government site you open | What any browser sends to a site you visit. | Only when you open one |
Optional account
The account is optional and uses Sign in with Apple through Google Firebase Authentication. Fullgrove requests no email address and no name, so the account holds an Apple user id only. It exists for features that need to recognise you on more than one device. The account id is never sent to analytics.
Apple Private Cloud Compute
Some features can use a larger Apple model on Apple Private Cloud Compute. This is off until you turn it on. After that, each request contains only what that task needs, and each one appears in the network log. Numbers the assistant shows always come from calculations made on your device.
Purchases and RevenueCat
Subscriptions and the lifetime purchase are sold by Apple through the App Store. We never see your payment details. We use RevenueCat to confirm which plan you have. RevenueCat receives App Store transaction details and a random anonymous id. That id is not linked to your Sign in with Apple account, and RevenueCat receives no ledger data.
In-app payment pages
For scheduled payments, Fullgrove can open a short list of official utility, telecom and government payment pages inside the app: Taipower e-bill, Taiwan Water, Taipei Water, Taipei Gas, Shin Shin Gas, Shin Hai Gas, Chunghwa Telecom, Taiwan Mobile, Far EasTone and the Ministry of Finance tax payment site. Bank sites are never opened in the app.
- The browser session is temporary. Cookies and site data are removed when you close it.
- Fullgrove injects no scripts and reads nothing from the page or its forms. It stores no passwords.
- The address bar is always visible, so you can see which site you are on.
- A capture happens only when you tap “Capture” (擷取). The capture is saved on your device as evidence for that payment.
The site you open receives your visit as it would in any browser, and its own privacy policy applies.
4. Anonymous usage, in detail
“Share anonymous usage” is off until you turn it on, during setup or in Settings › Privacy. Settings › Privacy › “Exactly what is shared” shows the same list as this section.
Only the events below are sent. Every value comes from a fixed list checked by tests; anything else is sent as “other”. Counts are sent as ranges such as “11–100”.
| Event | What it contains |
|---|---|
onboarding_step | which setup screen was shown, and which version of the welcome was used |
onboarding_finished | household size (solo, couple or family), number of goals picked, whether reminders are on |
paywall_shown / paywall_closed | where the Premium screen was opened from, and whether a purchase happened |
import_finished / import_failed | the kind of import (for example statement PDF, CSV, receipt), the number of rows in a range, whether the total matched |
inbox_cleared | how many items were cleared, in a range |
screen_viewed | which main screen was opened (for example Home, Ledger, Reports) |
zoom_changed | which overview level was chosen |
report_opened | which built-in report was opened |
assistant_asked | that the assistant was asked, and whether Private Cloud Compute answered; never the question |
rating_prompted | the moment a rating request was shown |
shared | the kind of thing shared (invite, milestone, app, grove) |
account_signed_in / account_deleted | that the optional account was created or deleted |
Events never contain amounts, merchants, notes, categories you named, account names, dates of your transactions or your location.
- Identifiers. Mixpanel uses a random id created for each install. Firebase uses its app instance id. No advertising identifier (IDFA) is collected, and neither service is given your account id.
- Location. Mixpanel's IP-based location is turned off. Firebase Analytics derives a coarse region from the IP address of the request.
- Crash reports. Firebase Crashlytics sends crash reports under the same setting.
- Advertising. Advertising storage, ad personalisation and user data signals are denied in Firebase. Fullgrove does not track you across apps or websites.
- Turning it off stops sending immediately and resets the Mixpanel id on the device.
Mixpanel stores data in the EU. Google Firebase may process data in the United States and other countries where Google operates.
5. Statement passwords
Passwords for locked statement PDFs are stored only in your device's Keychain. They are available only while a device passcode is set, never leave that device, and need Face ID or Touch ID each time. If your enrolled biometrics change, the saved passwords can no longer be read and you enter them again. Passwords are never logged, synced, exported or sent to any model.
6. What we never do
- Log in to your bank or ask for online banking credentials.
- Read other apps, scrape screens or open bank websites inside Fullgrove.
- Send ledger rows, evidence, amounts, merchants or passwords to analytics or to the account.
- Sell or rent personal data, show ads or track you across apps and websites.
7. This website
fullgrove.com uses no cookies, no analytics, no scripts and no third-party resources. Our web host may keep standard request logs for security and reliability.
8. Children
Fullgrove is meant for adults managing a household. It can keep a child's ledger, which a parent sets up and which stays on the parent's device like the rest of the ledger. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
9. Keeping and deleting data
- Ledger and evidence: deleting the app deletes them from that device. Delete any exports or backups you saved elsewhere yourself.
- Account: delete it in Settings › Account › Delete account. Fullgrove asks you to confirm with Apple, revokes the Sign in with Apple token and deletes the account. Your ledger stays on your device.
- Anonymous usage: turn it off in Settings › Privacy. Events already sent are kept by Mixpanel and Firebase under our project's retention settings. Because they carry only a random install id, we cannot find them by your name or account.
10. Your rights
Depending on where you live, including under Taiwan's Personal Data Protection Act and the EU General Data Protection Regulation, you may ask to access, correct or delete personal data we hold, or object to its use. Most of your data never reaches us, and you can see and delete it in the app. For anything else, write to [email protected]. You can also complain to your local data protection authority.
11. Changes and contact
If this policy changes, we will post the new version here with a new effective date. Questions go to [email protected].
Singular Intelligence (奇點智源), Taiwan.