Skip to content
LEMNISCIA
  • Services
  • Apps
  • About
  • Privacy
  • Contact
Start a project
All privacy policies

Alcove — Privacy Policy

Last updated: 16 August 2026 Effective: 16 August 2026

On this page

  • Summary
  • 1. Who we are
  • 2. Information we collect
  • 3. Device permissions
  • 4. Who we share data with
  • 5. Identity tiers
  • 6. Legal bases
  • 7. Data retention
  • 8. Delete your account & data
  • 9. Security
  • 10. Children's privacy
  • 11. International transfers
  • 12. Your rights
  • 13. Changes
  • 14. Contact us

This Privacy Policy applies to the Alcove mobile application (com.lemniscia.alcove), published by LEMNISCIA ("we", "us"). It explains what data the app accesses, collects, uses and shares, how long we keep it, and how you can delete it. The in-app Privacy Center (Nest → Privacy) summarises the same facts in plain language. Your use of the app is also governed by the Alcove Terms of Service.

The short version

  • Your financial records live on your device. Browsing, editing, budgets, insights, streaks and reminders all work locally and offline.
  • AI capture is optional and processed in the cloud, never stored. Voice clips, typed capture text and receipt photos are sent encrypted to our AI processor, used once, and discarded. Alcove never stores your audio or receipt images on its servers.
  • Sync is opt-in. Nothing financial leaves your device until you sign in and explicitly turn on sync. Synced data is stored in the EU.
  • Payments are handled by Google Play (or the App Store on iOS). We never see your card or bank details.
  • No ads. No data sales. No tracking across apps. No third-party analytics SDKs.

1. Who we are

Alcove is operated by LEMNISCIA, a software studio based in Ireland. Contact us at [email protected].

2. Information we collect

2.1 AI capture (optional features)

Data When Where it goes Why
Voice audio (short push-to-talk clips) Only while you hold the mic during a voice capture Streamed via our EU backend to the AI provider (OpenAI); discarded after processing — never written to storage Transcribe and extract the expense you spoke, answer the question you asked
Typed natural-language text Only when you use typed capture or ask a question Same path as audio (text only) Same
Receipt photos Only when you choose to scan a receipt (camera or gallery, both optional) Downscaled on your device, sent via our EU backend to the AI provider; discarded after processing — the photo itself is kept only on your device, attached to the record Read the amount, date and merchant off the receipt
Capture context (your category, account and ledger names, recent merchant names, locale, today's date) With each AI capture Sent alongside the audio/text/photo So the result matches your own categories. Never includes balances, totals, or transaction history
Capture telemetry (no audio, no text, no photos, no amounts): latency, confidence scores, which fields you corrected, outcome Per AI capture Our EU database, under your user ID Enforcing the free-tier quota; measuring accuracy so the feature improves

Hands-free confirmation ("yes" / "cancel" / "fix" after a read-back) is recognised on your device and that audio never leaves it. The spoken read-back itself is generated on-device (text-to-speech).

2.2 Your financial data

  • Financial records (transactions, categories, accounts, budgets, recurring rules, settings, optional mood words) are uploaded only if you sign in and enable sync in an explicit consent step — to an EU-hosted database with row-level security, so only your account can read your rows. Without sign-in + sync, your records exist only on your device and are removed when you uninstall the app.
  • CSV export runs only when you start it yourself: a file is generated on your device and handed to the share destination you choose. The export flow states plainly that the file contains real amounts.

2.3 Identity and account

  • Anonymous user ID — created lazily at your first AI capture (never at install), so the free monthly quota can be enforced.
  • Email address — only if you sign in with email.
  • Google / Apple sign-in — only if you choose them; we receive your email address and basic profile to create your account, nothing else from your Google/Apple account.

2.4 Purchases (Alcove Plus)

If you subscribe to Alcove Plus, Google Play (or the App Store on iOS) processes the payment under its own terms and privacy policy. Our EU backend receives and stores the purchase token, product ID and subscription state — enough to verify the purchase, unlock Plus on your account, and honour cancellations and refunds. We never receive your card number, bank details, or billing address. Purchase tokens are stored server-side only and are never exposed to other users or clients.

2.5 App analytics and diagnostics

  • Product events (e.g. "onboarding completed", "paywall viewed") — never amounts, notes, merchants, moods or transcripts; this is enforced in code at the point of emission. First-party only, stored in our EU database; no third-party analytics SDK.
  • Crash reports — sent to Sentry only in builds where crash reporting is enabled, and scrubbed on your device before sending: amounts, notes, merchant names, transcripts and email addresses are removed.
  • Currency exchange rates — when you use the exchange tool, our backend fetches public reference rates (ECB); the request contains no personal data.

2.6 What stays on your device only

  • The app-lock PIN (stored only as a salted hash in your device's secure storage — it never syncs) and the biometric opt-in flag.
  • Reminder and digest notifications (scheduled locally; their content is amount-free by construction).
  • Home-screen widgets (rendered from a local snapshot; amounts are masked whenever hidden-amounts or app lock is on).
  • Receipt images, streaks, hands-free confirmation audio, and text-to-speech.

2.7 What Alcove does not do

Alcove does not: read your bank accounts, access your contacts, track your location, track you across other apps or websites, show ads, sell or share data for advertising, or allow your data to be used to train AI models.

3. Device permissions

Permission Used for Requested
Microphone Recording a voice capture, only while you hold the mic At first voice use, after an in-app explanation — never at install
Camera Scanning a receipt Only when you open the receipt scanner
Notifications Optional gentle reminders, the weekly digest, renewal reminders Only if you turn reminders on

Denying any permission leaves the rest of the app fully usable — manual Quick Entry is always available and works offline.

4. Who we share data with

We share data only with the service providers below, only to provide the app's features. We do not sell personal data and we do not share it for advertising.

Recipient Role Data Location Safeguards
Supabase Database, authentication, functions hosting (processor) Account identity, synced records (if enabled), telemetry, purchase state EU (Frankfurt) Data processing agreement; per-account row-level isolation. Privacy policy
OpenAI Speech-to-text, text extraction, receipt reading (processor) Voice clips, typed capture text, receipt photos, capture context — each used once and discarded US DPA + EU Standard Contractual Clauses; API data not used for training; no balances, totals or history are ever sent. Privacy policy
Sentry Crash reporting (processor) Crash reports, PII-scrubbed on device before sending EU/US per configuration DPA; scrubbing before events leave the device. Privacy policy
Google Play Payment processing for subscriptions (independent controller) Your purchase, under Google's own terms — Google privacy policy
Google / Apple Optional sign-in (independent controllers) Sign-in under their own privacy policies — Standard OAuth / Sign in with Apple

5. Identity tiers

  • Local (default): no account. Records stay on the device. AI capture is unavailable (it requires the quota service).
  • Anonymous (first AI use): a random ID is created so the free monthly quota can be enforced. Your financial records still never leave the device at this tier — only capture telemetry and quota counts exist server-side.
  • Signed in (optional): email, Google, or Apple. Enables sync/backup after an explicit consent step that lists exactly what uploads. The app-lock PIN never syncs. Signing in from an anonymous session keeps the same ID, so your quota history and any Plus entitlement carry over.

6. Legal bases for processing (GDPR / UK GDPR)

  • Contract: providing the app, sync/backup, and your Plus subscription.
  • Consent: AI capture (voice, typed, receipt), the sync upload, notifications.
  • Legitimate interests: first-party product analytics, crash diagnostics, abuse and quota enforcement.
  • Legal obligation: purchase and tax records.

7. Data retention

  • Audio, capture text, receipt photos (server-side): not retained — discarded after processing.
  • Deleted records: recoverable on-device for 30 days ("Recently deleted"), then purged; synced deletions follow the same rule.
  • Capture telemetry and product events: kept while your account exists, then deleted with it.
  • Synced financial data: kept until you delete it or delete your account.
  • Purchase records: kept while needed to honour your subscription and as long as accounting and tax law require, typically 6 years under Irish law.
  • Local-only data: yours; uninstalling the app removes it (the app reminds you to export first when you set up app lock).

8. Delete your account and data

You can delete your account and the data associated with it at any time:

  • In the app: Nest → Profile → account options (sign-out offers remove-from-device; delete any record directly in the app).
  • Without the app: follow the steps on our Alcove data-deletion page, or email [email protected] from the address you signed in with. We complete deletion within 30 days.

Deletion removes your synced records, telemetry, quota history and entitlement rows. Purchase records that tax law requires us to keep are retained only as long as that law requires. Data that exists only on your device is deleted by you: remove it in-app or uninstall the app.

9. Security

  • TLS encryption for everything in transit.
  • Row-level security on every synced table — only your account can read your rows, verified by automated tests.
  • The AI provider key never ships inside the app; all AI calls go through our backend, which enforces quotas before any model is called.
  • Optional app lock: PIN stored only as a salted hash in your device's secure storage; biometric data never leaves your device (we only receive yes/no from the operating system).
  • On-screen amounts can be masked ("hidden amounts"), and that masking also applies to widgets and spoken output.

10. Children's privacy

Alcove is a personal-finance app intended for users aged 16 and over. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

11. International data transfers

Your stored data is in the EU. The voice/text/photo processing moment happens with a US provider (OpenAI) under EU Standard Contractual Clauses. If validation succeeds we will evaluate an EU-hosted AI endpoint.

12. Your rights

If you are in the EU/EEA or UK, you have the rights of access, rectification, erasure, restriction, portability and objection (GDPR Art. 15–21), and the right to lodge a complaint with your supervisory authority. To exercise any right, email [email protected]. You can also use Alcove entirely without an account, which is the strongest privacy setting we can offer.

13. Changes to this policy

We will update this policy at this URL and in-app before any change in what we process. Material changes are called out in release notes and, where required, presented for renewed consent.

14. Contact us

  • Email: [email protected]
  • App: Alcove (com.lemniscia.alcove)
  • Publisher: LEMNISCIA

Back to all privacy policies

LEMNISCIA

Software studio building tools people love.

Company

  • Services
  • Apps
  • About
  • Contact

Apps

  • ReadBridge
  • Alcove
  • All privacy policies

Legal

  • Privacy hub
  • ReadBridge privacy
  • Alcove privacy
  • Alcove terms
  • Contact us

© 2026 LEMNISCIA. All rights reserved.

Made with care · Privacy