How your data is protected

Most of what Rejynx knows about you never leaves your phone. Here’s where each thing is kept, what can leave, and how.

On your phone

Your bills, with the messages and statements they were read from, your money in and out, your chats and “What left my phone” are kept in the app’s own database on your phone, encrypted with a key that stays on it. Other apps can’t read it: your phone keeps each app’s storage to itself.

  • Your SMS (Android, only if you allow it): read on the phone for bills, payments and money in and out. The messages never leave it, and neither do OTPs, personal messages, or the transactions and balances read from your bank’s messages. From a message that isn’t a bill, a payment or a bank alert, nothing is kept.
  • Your Gmail, if you connect it: your phone reads your bill emails from Google itself. The emails, your sign-in and the bills found in them never reach our server or an AI provider: a question about your bills leaves those bills out, and the answers the phone gives itself still use them.
  • Bill messages you add and PDF statements you import are read on the phone, locked statements too: the password you type opens the file there and isn’t saved. Their text is never sent anywhere.
  • Deleting a chat or a bill overwrites it in the database file, so it isn’t left behind in the file’s free space. A deleted chat’s questions that went to the cloud stay listed in “What left my phone”, by their first 60 characters, until you delete the app.
  • Backups are off unless you turn them on (Settings → Back up to iCloud, or to Google on Android). Off, the database stays out of iCloud, computer and Google backups and out of phone-to-phone transfers. On, only the encrypted database goes: see Encryption.

What can leave your phone

These requests go to our server, and only these:

  • A question the phone can’t answer itself, sealed, with what it takes (below).
  • A check of your plan, if you buy one: the store’s proof of your purchase, sealed the same way, when you buy or restore a plan and about once a day while you have one. Our server asks Apple or Google about it, and keeps only the plan and when it ends, never the proof.
  • Signing in, only if you choose to: the token Apple or Google gave your phone, sealed the same way; then a session, sealed inside each question and plan check; and to sign out or delete your account, that session.
  • A request for the list of AI providers, or each plan’s limits, when the chat, the model menu or Plans opens. It carries nothing about you.

All but the lists carry a random ID the app made, sealed inside. Beside the sealed part, not inside it, each carries the app’s key (the same in every copy of the app), and all but the lists a one-way code from the random ID, which can’t be turned back into it (see Encryption). None of them says anything about you.

Elsewhere, only when you choose to: your phone reads Gmail from Google itself if you connect it, your UPI app gets the payment you tap Pay for, and Apple or Google keeps your encrypted backup if you turn backups on. Who gets what names each one.

The phone answers the bill questions it recognises (“pay the Airtel one”), and those stay on it. A question for the cloud takes:

  • your question, as you wrote it;
  • the chat’s earlier questions and the cloud’s answers, so the answer fits the conversation: 20 messages at most, counting this question;
  • your bills, when the question has one of the words bill(s), due, pay, paid, payment(s), card(s), EMI, salary, money, spend, spent, owe, amount or Rs, or the ₹ sign; or any word of three letters or more from one of your payees’ names, as a word of its own (with an LIC bill, “my LIC premium” counts, and “public” doesn’t). Then it takes your upcoming bills and those paid in the last 60 days, 50 at most, each as the six fields of the allow-list below, whether the bill was typed, pasted, from a PDF or read from your SMS. Never a bill from Gmail, or one a payment read from Gmail marked paid: a note under the answer says how many it left out (“2 Gmail bills kept on phone”).

So questions that aren’t about your bills can take them too: “How do I pay attention in class?” does, for one. What left my phone shows which questions took bills, and how many.

To our server, all of it goes sealed: encrypted on your phone so that only our server’s own process can open it (see Encryption). With your own AI key, it goes straight to your provider instead.

It never takes the text of the messages or statements your bills were read from, OTPs or personal messages, UPI IDs, account or card numbers, your transactions and balances, questions you kept on the phone, or what the phone answered itself: questions about your money are answered on the phone. What you write goes as you wrote it, though: a bank’s message about your account pasted into the chat is kept on the phone, but a biller’s message pasted into a chat question goes with that question. To have one read on the phone only, use Add a bill → Paste a bill message.

Turn on Ask before using cloud in Settings and each question waits for your yes. What left my phone lists your latest 500 questions that went to the cloud: the first 60 characters of each, when it went, where it went and how it ended, how many chat messages and bills went with it, and the names of the bill fields. It doesn’t keep the values that went, or the earlier messages’ text.

The allow-list

A bill leaves the phone as six fields and nothing else: payee, category, amount, minimum due, due date and status (upcoming or paid). The rule is enforced twice:

  • the app builds each bill from those six fields only;
  • our server turns away any request whose bills carry another field, before any AI model sees it. A test fails if that check is ever loosened.

Your own AI key

You can bring your own key for Groq, Cloudflare or OpenRouter (Settings → Your own AI key).

  • The key is kept in your phone’s secure storage: the iOS Keychain, or on Android storage encrypted with a key in the Android Keystore. It stays on this phone: a backup never brings it to another one.
  • Your questions then go from your phone straight to that provider. Our server never sees them, their answers or the key.
  • That provider’s own terms, and your own account’s settings, apply to what you send it, not ours: our zero data retention at Groq covers only our account.

Our server

Our server opens your sealed question, passes it to an AI provider and streams the answer back to you, sealed.

  • It keeps no copy of your questions or answers, or the bills that came with them. It opens them only in its own memory, and never writes what you asked or what came back to its database or its logs.
  • What it does keep: each day’s count of cloud answers, for your phone (by a keyed hash of its random ID) and, if you sign in, your account, to hold each plan to its daily limit, forgotten when the day ends; a plan’s end, linked to your phone and account; for each purchase checked, a keyed hash of it with the phones and accounts that use it, so one purchase gives its plan to 5 phones and 2 accounts at most, each forgotten a month after it last checked; and only if you sign in, your account: a random ID, a keyed hash of your Apple or Google ID, your email if they gave one (encrypted with our own key), the day you signed up. Settings → Delete account deletes it at once.
  • When a provider fails, it writes one line: the provider, the model and the error message the provider gave. Our server puts nothing of your question, the answer or a key in it.
  • To stop abuse, it counts requests per phone, by a one-way code from the phone’s random ID, and per network address. The code travels as a plain request header beside the sealed question, so the web server in front of ours can read it too; the ID itself goes sealed, so neither the web server nor anyone on the way can use it. The ID is 32 random bytes the app makes the first time it needs one, kept in your phone’s secure storage, and it isn’t linked to you. On iPhone the Keychain keeps it when the app is deleted, so a new install is the same phone, and its free answers for the day don’t start again. The counts are kept in memory and forgotten within minutes.
  • The web server in front of it keeps a standard access log: network address, time, the address asked for, the response and the user agent. When it turns a request away for coming too often, it notes that in its error log. Neither log includes what you asked, which travels, sealed, in the body of the request: the web server can’t open it.
  • Everything to and from it travels over HTTPS.

AI providers

Answers come from Groq, Cloudflare Workers AI or OpenRouter. On Auto, our server asks Groq first, then Cloudflare, then OpenRouter, moving on when one is busy, down or silent. You can also pick one in the model menu.

  • Through our server, a provider gets Rejynx’s instructions, the question and the fields above, from our server’s address, with our account’s key: not your network address, your phone’s ID or anything else about you.
  • What they say they do with it. Groq’s zero data retention is on for our account, so Groq doesn’t log or store it, or its answers (Groq’s own page), and its contract doesn’t let it train on it. Cloudflare says it doesn’t train on it and stores it only if a storage service is used, which we don’t, but it gives no retention period and doesn’t promise to keep nothing. OpenRouter doesn’t keep prompts or train on them, and our server asks it, on every question, to use only hosts that keep nothing and don’t collect data; when none is free, OpenRouter doesn’t answer rather than use another. Which host keeps what is the host’s own promise as OpenRouter knows it, not a guarantee. We can’t check any of this from outside: it’s each company’s own promise.
  • The line under each answer names the model and the provider that gave it, and Settings → Where your data goes names every company that can receive anything. Their own words, with links, are on Who processes data for us.

Encryption

  • In transit: HTTPS between the app and our server, between our server and the providers, and between your phone and the provider when you use your own key.
  • Sealed to our server: inside HTTPS, each question, with its bills, is encrypted on your phone to our server’s public key (HPKE, the Internet standard RFC 9180), so only our server’s own process can open it: not the web server in front of it, its logs, or anything on the way. The answer comes back sealed the same way, piece by piece, so only your phone can read it, and a piece changed or cut off on the way is refused. A copy of a sealed question sent again gives nothing away: it’s refused, or answered sealed afresh, so only the phone that asked could read it. A check of your plan is sealed the same way.
  • What can’t be sealed: that you asked, when, and roughly how long it was; the request headers beside the sealed part, which are the code from the random ID and the app’s key; and the answer’s headers, which say which provider and model answered, whether it was Fast or Thinking, and with OpenRouter which host. On Auto, Thinking means the question was long or looked like planning (a word such as “plan”, “compare” or “budget”). The web server in front of ours can read these, and so could anyone who could see inside HTTPS.
  • Your bills, chats and money: the database is encrypted (SQLCipher) with a key made on your phone and kept in its secure storage, for this phone only.
  • Your account on our server, if you sign in: your email encrypted with our own key (AES-256-GCM), your Apple or Google ID kept only as a keyed hash, and each session only as its hash, on a disk Oracle encrypts. Your phone keeps its session in its secure storage.
  • Backups, if you turn them on: on iPhone, the encrypted database goes into your iCloud and computer backups, and a copy of its key into your iCloud Keychain, which Apple encrypts end to end. On Android, the database and its key go only into a backup encrypted end to end with your screen lock, or a direct phone-to-phone transfer; with no screen lock, nothing is backed up.
  • Your own key: encrypted by your phone’s secure storage, and no backup brings it to another phone.

Payments and reminders

  • Rejynx never moves money, and never asks for your UPI PIN, an OTP or your card number. Pay hands your UPI app the payee’s UPI ID and name, the amount, and a short note (such as “HDFC 9012 bill”), and your UPI app takes it from there: you confirm the payment there. Your UPI app, your bank and the payee handle it under their own terms; Rejynx gets nothing back.
  • Reminders are set on your phone as local notifications. No push service is involved, so nothing about your bills goes through a server to remind you.

Who gets what

Every company that can receive anything from Rejynx, and only when the feature needs it:

  • Oracle Cloud hosts our server in Singapore. Questions, plan checks and sign-ins reach it sealed, opened only in our server’s memory; beside them only the code from the random ID, the app’s key and your network address. Its disk, which Oracle encrypts, holds our server’s small database of accounts, plans, purchases’ phones and each day’s counts.
  • Groq, Cloudflare Workers AI and OpenRouter (and the host OpenRouter picks) answer the questions our server passes on, as above.
  • Apple and Google check a purchase: our server sends the purchase’s ID (Apple) or token (Google), nothing else.
  • Apple and Google sign you in, only if you choose to, on their own sheet, asking only for your email (on Android, Google’s sign-in gives your name and picture too; our server keeps neither). When you delete an account made with Apple, our server sends Apple a one-time code from your phone, to take back Rejynx’s access.
  • Apple (iCloud) and Google keep your encrypted database, Money’s records included, only if you turn backups on.
  • Google answers your phone when you connect Gmail. Our server isn’t involved.
  • Your UPI app gets the payment you tap Pay for.
  • Zoho hosts our email, so it holds what you write to us, a report on an answer included (it starts with only where the answer came from).

What each gets, when, why and for how long is on Who processes data for us, and in the app under Settings → Where your data goes.

No trackers, here or in the app

  • The app has no advertising, analytics, tracking, crash-reporting or telemetry code, and our server sends none to anyone.
  • This site sets no cookies, runs no scripts and loads nothing from other sites. Its Content Security Policy tells your browser to refuse anything that tries.

Reporting a security problem

Email hello@raheed.dev with what you found and how to see it. Please give us time to fix it before telling anyone else, and don’t access other people’s data while you look.