This Privacy Policy ("Policy") describes how Soon Duan Zhi Benedict, operating as AVI (the "Operator", "we", "us", or "our"), collects, uses, discloses, and protects the personal data of users ("you" or "User") of the AVI mobile application (the "Application").
The Operator is committed to protecting your personal data and to complying with the Personal Data Protection Act 2012 of Singapore ("PDPA"). This Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have in relation to it.
By using the Application, you consent to the collection, use, and disclosure of your personal data in the manner described in this Policy. If you do not agree with this Policy, please do not use the Application.
This Policy should be read together with our Terms and Conditions, which are available in the Application and govern your use of the Application.
We collect only the personal data that is necessary to provide you with the Application's features. In this Policy, "collect" means data that reaches us — our servers, or the third parties described in Section 6. Some information a feature needs is kept only on your device and never reaches us; where that is the case, we say so explicitly, using words like "kept on your device", so the two are never confused. The categories of personal data we collect are set out below.
When you create an account, we collect:
When you record expenses in the Application, we collect: transaction amount; transaction date; spending category (e.g., dining, transport, groceries); which card you used for the transaction; how you paid (for example, card or mobile wallet); estimated miles or points earned; any note you choose to add to the transaction; and merchant name — only if you have given consent for the "Enhanced Sync" feature, which syncs merchant names across your devices. A transaction may also arrive through Tap to Track (Section 2.10) rather than being typed in by you; the fields we collect are the same either way. A transaction note is free text you write, so please avoid putting sensitive information in it.
We collect information about which credit card types and templates you have configured in the Application (e.g., "DBS Altitude Visa", "OCBC 90°N Mastercard"), the nickname and statement day you give a card, and — if you choose to record it — the date you opened it. We do not collect: your credit card number, your card verification value (CVV / CVC), your full primary account number (PAN), your card expiry date, or your card PIN or online banking password — and you must never enter any of them.
One exception, kept on your device only. If you set up Tap to Track (Section 2.10), the card label your own device's automation sends may end in the last four digits of a card — for example "Trust Visa ···· 4291". That label is stored on your device only, is used only to recognise which of your cards a payment belongs to, is never uploaded to our servers, and is removed when you delete your data in the Application. We never receive it, and we never collect any other part of a card number.
When you add loyalty programme balances, we collect: the name of the loyalty programme (e.g., KrisFlyer, Asia Miles, Cathay); your current points or miles balance; and points expiry dates, if you choose to record them. If you transfer or redeem points, we also keep any note you add to that transfer or redemption. If you remove a card from the Application, we keep its name and issuing bank as a record of your history.
We maintain records of the consents you have given within the Application, including the type of consent and the date and time it was given or withdrawn.
When you contact us or send feedback: the Application version and your device platform (iOS/Android) are attached automatically, because a bug report without them cannot be acted on. You may optionally attach a diagnostics block — your operating-system version, whether Online Sync is on, and whether you are signed in — which is shown to you in full before you send it. Free-text messages are scanned on your device and any card number found is removed before the message is sent. With Analytics consent: device operating system type and version, crash reports, and anonymised usage analytics (see Section 4.2).
For the avoidance of doubt, we do not collect: your bank account numbers or bank account credentials; your credit card numbers, CVV, PAN, or card expiry dates; your online banking login credentials or passwords; your exact income, salary, or financial statements; or your precise real-time location (we do not use location-based services).
One thing is asked for and kept on your device only: during first-time setup, and again at any time from your profile, you may tell the Application a broad income band (for example, "$60k–$120k") and your residency status, so it can show you which cards you are actually eligible for. Both questions are optional and can be skipped. Both are stored on your device only, are never uploaded to our servers, and are removed when you delete your data in the Application.
If you allow notifications, we store a push-notification token for your device installation, together with the platform (iOS/Android). We use it only to send the reminders and alerts you have enabled in the Application. The token identifies your installation of the Application, not you: it is not stored alongside your name, email, transaction, or card data. Turning notifications off in your device settings stops us using it but does not by itself delete the stored token. See Sections 6.1 and 7.1.
If you send feedback or contact support from within the Application, we collect the message you write, the diagnostic fields described in Section 2.6, and an identifier for your installation of the Application, which lets us recognise repeated reports from the same device and enforce anti-spam limits. If you have turned on Online Backup & Sync, that identifier is the same as your account identifier. Messages are scanned on your device and any card number is removed before sending. See Section 7.1 for what happens to a support message if you later delete your account.
Where you have set Tap to Track up, the following can reach AVI when you make a card payment: the transaction amount; the merchant name, where your automation supplies one; the time it happened; a reference supplied by the automation; and the card label your device's automation supplies (for example "Trust Visa ···· 4291"), which may include the last four digits of the card. This data reaches AVI through a link on your own device, which the automation you set up opens at the moment of a payment. Because that link is a standard iOS mechanism, another app on your phone could in principle send AVI the same kind of message — which is why AVI never records a transaction automatically: every arrival is shown to you first and nothing is stored until you confirm it. If you dismiss it, nothing is written anywhere.
Once you confirm an arrival, the transaction itself is recorded exactly as one you typed in, and is treated by this Policy in exactly the same way (Section 2.2). The card label is kept separately, on your device only. It is used only to recognise which of your cards a payment belongs to, is never uploaded to our servers, is limited to a small number of recent labels, and is removed when you delete your data in the Application. AVI never guesses which card a label means: an unrecognised label becomes a question for you to answer, not a card record.
Tap to Track gives AVI no access to Apple Wallet, no access to your bank or card issuer's systems, no transaction history, and no standing connection to any financial institution. It receives one transaction at a time, only when your own device sends one.
Turning it off. The automation lives in your own phone's Shortcuts and Settings, which AVI cannot reach, modify, or delete. There is no separate on/off switch inside the Application: Tap to Track is on for you because you built the automation, and it stops when you remove it there. Removing it does not delete transactions you have already confirmed.
If Screen Log is released, it will read a screenshot you choose to give it — of a receipt, or of your own banking app's transaction screen — in order to fill in a transaction for you. From that image AVI will extract and record only five fields: the amount; the card used, and of the card only its last four digits, never the full number; the date; the recipient; and the merchant name. Everything else visible in the image — including any account number, balance, reference or other text — will be read only in order to locate those five fields, and will never be written to any file, log, backup, retry queue, or crash report.
The image itself will be discarded once it has been read, unless you choose to keep it — see Section 4.8. Screen Log will also check the image for content that looks sensitive, such as what appears to be a full card number or an identity-card number, and warn you before anything is kept, so you can retake the screenshot instead. That check will run in memory only; what it matched will never be recorded.
Directly from you when you: create an account; manually enter transaction, card, or loyalty data; adjust settings; or communicate with us. With your Analytics consent, automatically: crash reports and anonymised usage statistics. Automatically, on every launch, regardless of consent: the Application checks Expo's update service for a new version and checks our card-catalogue database for updated card information; as with any network request, each discloses your device's IP address to that service, and no account, transaction or usage data is sent with either — see Section 6.1. From an automation on your own device, if you have set one up: Tap to Track (Section 2.10) hands AVI one transaction at a time, which is stored only once you confirm it.
We do not obtain your personal data from any third-party data brokers, social media platforms, or financial institutions. We do not connect to or scrape your bank or card issuer's systems — and Tap to Track does not change this: it receives one transaction at a time from a link your own device opens, and gives AVI no access to Apple Wallet, no transaction history, and no standing connection to any financial institution.
In accordance with the PDPA, we only collect and use your personal data for the specific purposes set out below. We will not use your personal data for any purpose not described in this Policy without first obtaining your consent.
If you grant Analytics consent (which you can do or revoke at any time in Settings): collecting crash reports and anonymised usage data to identify bugs and improve app performance; and analysing feature usage patterns to inform future product development. This is not active in the current version of the Application; there is no analytics or crash-reporting service built into it, so if you grant this consent, nothing is collected until we say so in an updated version of this Policy.
If you grant Marketing consent: sending you tips on maximising miles earnings; notifying you of new Application features, promotions, and card offers; and sending newsletters and updates relevant to credit card miles in Singapore. This is not active in the current version of the Application; if you grant this consent, nothing is sent until we say so in an updated version of this Policy.
If you grant Enhanced Sync consent: storing merchant names associated with your transactions in order to synchronise a consistent transaction history across your devices. Revoking this consent stops new merchant names being synced; it does not remove merchant names already stored on our servers — you can delete those transactions individually, or delete your account (Section 8.5) to remove everything.
If you click an "Apply Now" link within the Application, you will be directed to the card issuer's own official website. The Application does not link to comparison or aggregator platforms, and the Operator currently participates in no affiliate or referral programme and receives no commission if you subsequently apply for a financial product. Following such a link does not involve the sharing of your personal data with the card issuer. Any personal data you submit on the card issuer's website is governed solely by that party's privacy policy.
AVI is local-first: your data stays on your device unless you turn on Online Backup & Sync. If you grant this consent (which you can do or revoke at any time), we store a copy of your account, transaction, card, and loyalty data on our cloud servers (Supabase — see Sections 6 and 10) so that you can back it up and synchronise it across your devices. You may turn Online Sync off at any time; when you do, the cloud copy of your data is deleted and your data remains on your device.
Where you have set up Tap to Track (Section 2.10), we use what your automation sends to show you a transaction for confirmation, and — once you confirm it — to create a transaction record in the Application in the same way as one you enter yourself. Tap to Track is part of AVI Pro, which is free of charge during the beta. Access to it is never conditional on you granting AVI any data permission unrelated to Tap to Track: in particular, it does not require an account and does not require Online Backup & Sync.
Tap to Track is not switched on by a consent setting inside the Application, because setting it up is itself the deliberate act: you build the automation on your own phone, and every single transaction it produces is shown to you and saved only if you confirm it. To stop it, remove the automation in your phone's Shortcuts and Settings — see Section 2.10.
If Screen Log is released, a receipt image will be discarded once AVI has read the five fields described in Section 2.11 from it. Keeping the image will be off by default. If you turn on "Keep my receipt images" — which you will be able to do or revoke at any time, and which you will also be asked about at the moment of each capture — a copy of the image will be stored on your device and, only if you have also enabled Online Backup & Sync, in our cloud storage as well. Cloud storage of a receipt image requires an account and Online Backup & Sync; with Online Sync off, a kept image stays on your device only, and the Application will tell you so before you turn image storage on. Retention and deletion are described in Section 7.2.
Screen Log itself is intended to be part of AVI Pro. Access to it will never be conditional on you granting any data permission unrelated to Screen Log — keeping images is a separate choice from using the feature, and declining to keep them will not withhold it.
Under the PDPA, we process your personal data on the following legal bases: Contractual necessity for core service functionality; Consent for optional features (analytics, marketing, enhanced sync, and — if released — receipt image storage), which you may withdraw at any time; and Legitimate interests / legal obligation for security, fraud prevention, and legal compliance.
We do not sell your personal data to any third party. We may share your personal data only in the following limited circumstances:
Two things we will add here rather than assume: if Screen Log is released and you turn on image keeping, a kept image stored in the cloud would be stored with Supabase Inc. under the same arrangements as your other synced data; and if reading a receipt image ever needs a third-party service rather than being done entirely on your device, we will name that service here and disclose it to you within the Application before any image is sent to it. As of this Policy, Screen Log does not exist, no image is stored anywhere, and no such service is in use.
We may disclose your personal data where required or permitted by law, including to comply with a court order, subpoena, legal process, or regulatory requirement; to protect our legal rights or property; or to investigate or prevent suspected fraud or illegal activity.
In the event of a merger, acquisition, reorganisation, or sale of all or substantially all of our assets, your personal data may be transferred to the acquiring entity, subject to that entity being bound by obligations at least as protective as this Policy.
Active account: retained for as long as your account is active. Anonymised data may be retained indefinitely. Legal retention: certain records may be retained longer where required by law.
Deleted account: the personal data held in your account — your profile, transactions, cards, loyalty balances and consent records — is permanently deleted from our systems within 30 days. Everything held on your device is deleted immediately, including the Tap to Track card labels described in Section 2.10. Two things are not part of your account and are handled separately, described immediately below: any support message you have sent us (Section 2.9), and a push-notification token for your device (Section 2.8).
The commitment, so it is on the record before anything is built: if you turn on "Keep my receipt images", a kept image will be stored on your device and, if Online Backup & Sync is on, in our cloud storage; either copy will be kept for up to 3 months from the date of capture and then deleted automatically. Turning "Keep my receipt images" off stops new images being kept; it will not retroactively delete images already kept. You will be able to delete a single kept image from within the transaction it belongs to, keeping the transaction itself; to delete every kept image at once from Settings, without deleting anything else; and to delete all of them together with everything else by deleting your account. Each of those will remove the image from both places it is held.
To exercise any of these rights, please contact us at the details in Section 14 or use the relevant settings in the Application.
You may request a copy of the personal data we hold about you. Email us at [email protected] with the subject line "Data Access Request". We will respond within 30 days.
If any personal data we hold is inaccurate or incomplete, you may request that we correct it. Most data can be corrected directly within the Application.
Where processing is based on your consent, you may withdraw it at any time via the Privacy settings in the Application. Withdrawing consent will not affect the lawfulness of processing carried out prior to withdrawal.
To the extent required by the PDPA, you may have the right to receive certain personal data in a commonly used machine-readable format. Please contact us to enquire.
You may delete your account at any time from the Account Settings within the Application. What is deleted, when, and the two limits that remain until our in-progress fixes are complete, are set out in full in Section 7.1 — please read that section, not this one, for the current, accurate position.
If you believe we have not handled your personal data in accordance with the PDPA, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore — Website: www.pdpc.gov.sg, Email: [email protected], 10 Pasir Panjang Road, #03-01 Mapletree Business City, Singapore 117438.
We implement appropriate technical and organisational measures to protect your personal data, including: encryption in transit (TLS 1.2+); encryption at rest on Supabase servers; access controls; data minimisation; and secure authentication via Supabase Auth. Encryption at rest on our hosting provider's servers is a property of that provider, described in its own documentation, rather than something we apply ourselves. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you suspect your account has been compromised, please contact us immediately.
On your device: because AVI is local-first, most users' data never leaves their phone. It is held in the Application's private storage, which the operating system isolates from other apps, and sign-in credentials are held in the device keychain/keystore. If your device has Face ID or Touch ID set up, you can add a further lock in Settings; once it is on, your device passcode works as a fallback. The Application does not apply its own separate encryption on top of the operating system's, so the security of on-device data depends on your device being locked and up to date. A device backup you have switched on — iCloud or Google — may include this data, as it does for any app on your phone.
The Application is operated from Singapore. Where you have enabled Online Backup & Sync, your personal data is stored on Supabase servers and may be transferred to and stored in the United States. Any support message you send is also stored on Supabase servers regardless of whether you use Online Backup & Sync — see Section 6.1. Where you have allowed notifications, a push-notification token is transmitted through Expo (650 Industries, Inc., USA) and stored on Supabase servers — see Section 6.1. Where personal data is transferred outside Singapore, we ensure appropriate safeguards are in place in accordance with Section 26 of the PDPA. By using the Application, you consent to such transfers, subject to the protections described in this Section.
The Application is intended for users who are at least 18 years of age. We do not knowingly collect personal data from individuals under 18. If you believe a child under 18 has provided us with personal data, please contact us immediately at [email protected].
The Application is a mobile application and does not use browser cookies. It uses locally stored data (device storage) for two purposes. Most of it is your preferences and settings, and the Tap to Track card labels described in Section 2.10, all of which stay on your device and are never transmitted to us. A small number of items — a support message queued to send (Section 2.9), and a Tap to Track transaction you have confirmed but which the Application has not finished recording (Section 2.10) — hold something you have already asked the Application to act on, until it can be. A queued support message is on its way to us; a Tap to Track arrival is not, unless Online Backup & Sync is on. Either way, those items are described in the sections covering that data, not here. If we introduce a web-based companion portal in future, we will update this Policy accordingly.
We reserve the right to update this Privacy Policy at any time. Where changes are material, we will provide at least fourteen (14) days' notice before they take effect, via an in-application notice, a push notification, or — if you have an account — an email to the address associated with it. Your continued use after the effective date constitutes acceptance of the updated Policy.
Data Controller / Operator:
Soon Duan Zhi Benedict
Operating as: AVI
Email: [email protected]
Singapore
We aim to respond to all data-protection enquiries within five (5) business days and to resolve data access and correction requests within 30 days of receipt.