Track. Earn. Fly.

Privacy Policy

Version 2.0 · Effective Date: 24 August 2026 · Replaces Version 1.0 of 14 July 2026
This Privacy Policy is issued in compliance with the Personal Data Protection Act 2012 (No. 26 of 2012) of Singapore ("PDPA") and its subsidiary regulations, including the Personal Data Protection Regulations 2021. If you have questions about how we handle your personal data, you may contact us at the details in Section 14 or lodge a complaint with the Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.

1. Introduction

This Privacy Policy ("Policy") describes how Soon Duan Zhi Benedict, operating as AVI (the "Operator", "we", "us", or "our"), collects, uses, discloses, and protects the personal data of users ("you" or "User") of the AVI mobile application (the "Application").

The Operator is committed to protecting your personal data and to complying with the Personal Data Protection Act 2012 of Singapore ("PDPA"). This Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have in relation to it.

By using the Application, you consent to the collection, use, and disclosure of your personal data in the manner described in this Policy. If you do not agree with this Policy, please do not use the Application.

This Policy should be read together with our Terms and Conditions, which are available in the Application and govern your use of the Application.

Local-first by design: By default, the data you enter is stored only on your device and is not uploaded to our servers. Your data is stored in the cloud (see Sections 6 and 10) only if you choose to turn on Online Backup & Sync (Section 4.6). If you use AVI in local-only mode, we do not hold your transaction, card, or loyalty data on our servers.

2. Personal Data We Collect

We collect only the personal data that is necessary to provide you with the Application's features. In this Policy, "collect" means data that reaches us — our servers, or the third parties described in Section 6. Some information a feature needs is kept only on your device and never reaches us; where that is the case, we say so explicitly, using words like "kept on your device", so the two are never confused. The categories of personal data we collect are set out below.

2.1 Account Data

When you create an account, we collect:

2.2 Transaction Data

When you record expenses in the Application, we collect: transaction amount; transaction date; spending category (e.g., dining, transport, groceries); which card you used for the transaction; how you paid (for example, card or mobile wallet); estimated miles or points earned; any note you choose to add to the transaction; and merchant name — only if you have given consent for the "Enhanced Sync" feature, which syncs merchant names across your devices. A transaction may also arrive through Tap to Track (Section 2.10) rather than being typed in by you; the fields we collect are the same either way. A transaction note is free text you write, so please avoid putting sensitive information in it.

2.3 Card Data

We collect information about which credit card types and templates you have configured in the Application (e.g., "DBS Altitude Visa", "OCBC 90°N Mastercard"), the nickname and statement day you give a card, and — if you choose to record it — the date you opened it. We do not collect: your credit card number, your card verification value (CVV / CVC), your full primary account number (PAN), your card expiry date, or your card PIN or online banking password — and you must never enter any of them.

One exception, kept on your device only. If you set up Tap to Track (Section 2.10), the card label your own device's automation sends may end in the last four digits of a card — for example "Trust Visa ···· 4291". That label is stored on your device only, is used only to recognise which of your cards a payment belongs to, is never uploaded to our servers, and is removed when you delete your data in the Application. We never receive it, and we never collect any other part of a card number.

IMPORTANT: AVI does not require and you should never enter your full card number, CVV, PIN, or any online banking credentials into the Application. If you are ever prompted for these details by anything claiming to be AVI, please contact us immediately as this may indicate a security issue.

2.4 Loyalty Programme Data

When you add loyalty programme balances, we collect: the name of the loyalty programme (e.g., KrisFlyer, Asia Miles, Cathay); your current points or miles balance; and points expiry dates, if you choose to record them. If you transfer or redeem points, we also keep any note you add to that transfer or redemption. If you remove a card from the Application, we keep its name and issuing bank as a record of your history.

2.5 Consent Records

We maintain records of the consents you have given within the Application, including the type of consent and the date and time it was given or withdrawn.

2.6 Technical Data

When you contact us or send feedback: the Application version and your device platform (iOS/Android) are attached automatically, because a bug report without them cannot be acted on. You may optionally attach a diagnostics block — your operating-system version, whether Online Sync is on, and whether you are signed in — which is shown to you in full before you send it. Free-text messages are scanned on your device and any card number found is removed before the message is sent. With Analytics consent: device operating system type and version, crash reports, and anonymised usage analytics (see Section 4.2).

2.7 Data We Do Not Collect

For the avoidance of doubt, we do not collect: your bank account numbers or bank account credentials; your credit card numbers, CVV, PAN, or card expiry dates; your online banking login credentials or passwords; your exact income, salary, or financial statements; or your precise real-time location (we do not use location-based services).

One thing is asked for and kept on your device only: during first-time setup, and again at any time from your profile, you may tell the Application a broad income band (for example, "$60k–$120k") and your residency status, so it can show you which cards you are actually eligible for. Both questions are optional and can be skipped. Both are stored on your device only, are never uploaded to our servers, and are removed when you delete your data in the Application.

2.8 Notification Data

If you allow notifications, we store a push-notification token for your device installation, together with the platform (iOS/Android). We use it only to send the reminders and alerts you have enabled in the Application. The token identifies your installation of the Application, not you: it is not stored alongside your name, email, transaction, or card data. Turning notifications off in your device settings stops us using it but does not by itself delete the stored token. See Sections 6.1 and 7.1.

2.9 Support Messages

If you send feedback or contact support from within the Application, we collect the message you write, the diagnostic fields described in Section 2.6, and an identifier for your installation of the Application, which lets us recognise repeated reports from the same device and enforce anti-spam limits. If you have turned on Online Backup & Sync, that identifier is the same as your account identifier. Messages are scanned on your device and any card number is removed before sending. See Section 7.1 for what happens to a support message if you later delete your account.

2.10 Automated Transaction Data (Tap to Track)

Only if you set it up yourself. Tap to Track is an optional feature for AVI Pro users, being rolled out during the beta. It does nothing at all unless you build an automation for it yourself, in Apple's Shortcuts app, on your own phone. If you have not done that, nothing in this section describes any data we hold about you.

Where you have set Tap to Track up, the following can reach AVI when you make a card payment: the transaction amount; the merchant name, where your automation supplies one; the time it happened; a reference supplied by the automation; and the card label your device's automation supplies (for example "Trust Visa ···· 4291"), which may include the last four digits of the card. This data reaches AVI through a link on your own device, which the automation you set up opens at the moment of a payment. Because that link is a standard iOS mechanism, another app on your phone could in principle send AVI the same kind of message — which is why AVI never records a transaction automatically: every arrival is shown to you first and nothing is stored until you confirm it. If you dismiss it, nothing is written anywhere.

Once you confirm an arrival, the transaction itself is recorded exactly as one you typed in, and is treated by this Policy in exactly the same way (Section 2.2). The card label is kept separately, on your device only. It is used only to recognise which of your cards a payment belongs to, is never uploaded to our servers, is limited to a small number of recent labels, and is removed when you delete your data in the Application. AVI never guesses which card a label means: an unrecognised label becomes a question for you to answer, not a card record.

Tap to Track gives AVI no access to Apple Wallet, no access to your bank or card issuer's systems, no transaction history, and no standing connection to any financial institution. It receives one transaction at a time, only when your own device sends one.

Turning it off. The automation lives in your own phone's Shortcuts and Settings, which AVI cannot reach, modify, or delete. There is no separate on/off switch inside the Application: Tap to Track is on for you because you built the automation, and it stops when you remove it there. Removing it does not delete transactions you have already confirmed.

2.11 Receipt Image Data (Screen Log)

Not available. Nothing described in this section is built. The Application does not read receipts or screenshots today, has no such feature to turn on, and does not request access to your camera or photo library. This section records what we have committed to do if Screen Log is released. This Policy will be updated to describe the released feature, and to confirm the deletion arrangements in Section 7.2, before Screen Log is made available to anyone.

If Screen Log is released, it will read a screenshot you choose to give it — of a receipt, or of your own banking app's transaction screen — in order to fill in a transaction for you. From that image AVI will extract and record only five fields: the amount; the card used, and of the card only its last four digits, never the full number; the date; the recipient; and the merchant name. Everything else visible in the image — including any account number, balance, reference or other text — will be read only in order to locate those five fields, and will never be written to any file, log, backup, retry queue, or crash report.

The image itself will be discarded once it has been read, unless you choose to keep it — see Section 4.8. Screen Log will also check the image for content that looks sensitive, such as what appears to be a full card number or an identity-card number, and warn you before anything is kept, so you can retake the screenshot instead. That check will run in memory only; what it matched will never be recorded.

3. How We Collect Your Personal Data

Directly from you when you: create an account; manually enter transaction, card, or loyalty data; adjust settings; or communicate with us. With your Analytics consent, automatically: crash reports and anonymised usage statistics. Automatically, on every launch, regardless of consent: the Application checks Expo's update service for a new version and checks our card-catalogue database for updated card information; as with any network request, each discloses your device's IP address to that service, and no account, transaction or usage data is sent with either — see Section 6.1. From an automation on your own device, if you have set one up: Tap to Track (Section 2.10) hands AVI one transaction at a time, which is stored only once you confirm it.

We do not obtain your personal data from any third-party data brokers, social media platforms, or financial institutions. We do not connect to or scrape your bank or card issuer's systems — and Tap to Track does not change this: it receives one transaction at a time from a link your own device opens, and gives AVI no access to Apple Wallet, no transaction history, and no standing connection to any financial institution.

4. Purposes of Collection and Use

In accordance with the PDPA, we only collect and use your personal data for the specific purposes set out below. We will not use your personal data for any purpose not described in this Policy without first obtaining your consent.

4.1 Core Service (No Additional Consent Required)

4.2 Analytics (Consent-Based)

If you grant Analytics consent (which you can do or revoke at any time in Settings): collecting crash reports and anonymised usage data to identify bugs and improve app performance; and analysing feature usage patterns to inform future product development. This is not active in the current version of the Application; there is no analytics or crash-reporting service built into it, so if you grant this consent, nothing is collected until we say so in an updated version of this Policy.

4.3 Marketing Communications (Consent-Based)

If you grant Marketing consent: sending you tips on maximising miles earnings; notifying you of new Application features, promotions, and card offers; and sending newsletters and updates relevant to credit card miles in Singapore. This is not active in the current version of the Application; if you grant this consent, nothing is sent until we say so in an updated version of this Policy.

4.4 Enhanced Sync (Consent-Based)

If you grant Enhanced Sync consent: storing merchant names associated with your transactions in order to synchronise a consistent transaction history across your devices. Revoking this consent stops new merchant names being synced; it does not remove merchant names already stored on our servers — you can delete those transactions individually, or delete your account (Section 8.5) to remove everything.

4.5 Apply Links to Card Issuers

If you click an "Apply Now" link within the Application, you will be directed to the card issuer's own official website. The Application does not link to comparison or aggregator platforms, and the Operator currently participates in no affiliate or referral programme and receives no commission if you subsequently apply for a financial product. Following such a link does not involve the sharing of your personal data with the card issuer. Any personal data you submit on the card issuer's website is governed solely by that party's privacy policy.

4.6 Online Backup & Sync (Consent-Based)

AVI is local-first: your data stays on your device unless you turn on Online Backup & Sync. If you grant this consent (which you can do or revoke at any time), we store a copy of your account, transaction, card, and loyalty data on our cloud servers (Supabase — see Sections 6 and 10) so that you can back it up and synchronise it across your devices. You may turn Online Sync off at any time; when you do, the cloud copy of your data is deleted and your data remains on your device.

4.7 Automated Transaction Capture — Tap to Track

Where you have set up Tap to Track (Section 2.10), we use what your automation sends to show you a transaction for confirmation, and — once you confirm it — to create a transaction record in the Application in the same way as one you enter yourself. Tap to Track is part of AVI Pro, which is free of charge during the beta. Access to it is never conditional on you granting AVI any data permission unrelated to Tap to Track: in particular, it does not require an account and does not require Online Backup & Sync.

Tap to Track is not switched on by a consent setting inside the Application, because setting it up is itself the deliberate act: you build the automation on your own phone, and every single transaction it produces is shown to you and saved only if you confirm it. To stop it, remove the automation in your phone's Shortcuts and Settings — see Section 2.10.

4.8 Receipt Image Storage — Screen Log (Consent-Based)

Not available. See Section 2.11. Nothing in this section describes anything the Application does today.

If Screen Log is released, a receipt image will be discarded once AVI has read the five fields described in Section 2.11 from it. Keeping the image will be off by default. If you turn on "Keep my receipt images" — which you will be able to do or revoke at any time, and which you will also be asked about at the moment of each capture — a copy of the image will be stored on your device and, only if you have also enabled Online Backup & Sync, in our cloud storage as well. Cloud storage of a receipt image requires an account and Online Backup & Sync; with Online Sync off, a kept image stays on your device only, and the Application will tell you so before you turn image storage on. Retention and deletion are described in Section 7.2.

Screen Log itself is intended to be part of AVI Pro. Access to it will never be conditional on you granting any data permission unrelated to Screen Log — keeping images is a separate choice from using the feature, and declining to keep them will not withhold it.

5. Legal Basis for Processing

Under the PDPA, we process your personal data on the following legal bases: Contractual necessity for core service functionality; Consent for optional features (analytics, marketing, enhanced sync, and — if released — receipt image storage), which you may withdraw at any time; and Legitimate interests / legal obligation for security, fraud prevention, and legal compliance.

6. Disclosure of Personal Data to Third Parties

We do not sell your personal data to any third party. We may share your personal data only in the following limited circumstances:

6.1 Data Processors

Two things we will add here rather than assume: if Screen Log is released and you turn on image keeping, a kept image stored in the cloud would be stored with Supabase Inc. under the same arrangements as your other synced data; and if reading a receipt image ever needs a third-party service rather than being done entirely on your device, we will name that service here and disclose it to you within the Application before any image is sent to it. As of this Policy, Screen Log does not exist, no image is stored anywhere, and no such service is in use.

6.2 Legal Disclosure

We may disclose your personal data where required or permitted by law, including to comply with a court order, subpoena, legal process, or regulatory requirement; to protect our legal rights or property; or to investigate or prevent suspected fraud or illegal activity.

6.3 Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of all or substantially all of our assets, your personal data may be transferred to the acquiring entity, subject to that entity being bound by obligations at least as protective as this Policy.

7. Data Retention

7.1 General

Active account: retained for as long as your account is active. Anonymised data may be retained indefinitely. Legal retention: certain records may be retained longer where required by law.

Deleted account: the personal data held in your account — your profile, transactions, cards, loyalty balances and consent records — is permanently deleted from our systems within 30 days. Everything held on your device is deleted immediately, including the Tap to Track card labels described in Section 2.10. Two things are not part of your account and are handled separately, described immediately below: any support message you have sent us (Section 2.9), and a push-notification token for your device (Section 2.8).

Two things are handled differently from the rest of your account, stated plainly rather than left to be discovered. Support messages. A message you have sent is kept — not deleted outright, because it may still be useful as a bug report or a record of a complaint — and deleting your account removes both the account link and the identifier for your installation, so the message no longer points at you or at your device. This cannot reach free text: if you typed your name, email, or other personal details into the message itself, that text remains as written, because no automated process can reliably identify and remove personal details from prose — email us (Section 14) if you want a specific message deleted outright. Push-notification tokens. When you delete your account, the Application asks our servers to delete the token for your device, and tells you in the Application if that could not be done.

7.2 Receipt Images (Screen Log)

Not available, and this section is a commitment about a future release, not a description of anything running today. No receipt image is stored by AVI anywhere, because no part of Screen Log is built. Screen Log will not be released until (a) the Application can delete a stored image from both your device and our servers, including when you delete your account, and (b) the automatic deletion described below actually runs on a schedule. This Policy will be updated to confirm both before the feature is made available. Until you read that update here, do not rely on this section.

The commitment, so it is on the record before anything is built: if you turn on "Keep my receipt images", a kept image will be stored on your device and, if Online Backup & Sync is on, in our cloud storage; either copy will be kept for up to 3 months from the date of capture and then deleted automatically. Turning "Keep my receipt images" off stops new images being kept; it will not retroactively delete images already kept. You will be able to delete a single kept image from within the transaction it belongs to, keeping the transaction itself; to delete every kept image at once from Settings, without deleting anything else; and to delete all of them together with everything else by deleting your account. Each of those will remove the image from both places it is held.

8. Your Rights Under the PDPA

To exercise any of these rights, please contact us at the details in Section 14 or use the relevant settings in the Application.

8.1 Right of Access

You may request a copy of the personal data we hold about you. Email us at [email protected] with the subject line "Data Access Request". We will respond within 30 days.

8.2 Right of Correction

If any personal data we hold is inaccurate or incomplete, you may request that we correct it. Most data can be corrected directly within the Application.

8.3 Right to Withdraw Consent

Where processing is based on your consent, you may withdraw it at any time via the Privacy settings in the Application. Withdrawing consent will not affect the lawfulness of processing carried out prior to withdrawal.

8.4 Right to Data Portability

To the extent required by the PDPA, you may have the right to receive certain personal data in a commonly used machine-readable format. Please contact us to enquire.

8.5 Right to Account Deletion

You may delete your account at any time from the Account Settings within the Application. What is deleted, when, and the two limits that remain until our in-progress fixes are complete, are set out in full in Section 7.1 — please read that section, not this one, for the current, accurate position.

8.6 Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with the PDPA, you may lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore — Website: www.pdpc.gov.sg, Email: [email protected], 10 Pasir Panjang Road, #03-01 Mapletree Business City, Singapore 117438.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including: encryption in transit (TLS 1.2+); encryption at rest on Supabase servers; access controls; data minimisation; and secure authentication via Supabase Auth. Encryption at rest on our hosting provider's servers is a property of that provider, described in its own documentation, rather than something we apply ourselves. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you suspect your account has been compromised, please contact us immediately.

On your device: because AVI is local-first, most users' data never leaves their phone. It is held in the Application's private storage, which the operating system isolates from other apps, and sign-in credentials are held in the device keychain/keystore. If your device has Face ID or Touch ID set up, you can add a further lock in Settings; once it is on, your device passcode works as a fallback. The Application does not apply its own separate encryption on top of the operating system's, so the security of on-device data depends on your device being locked and up to date. A device backup you have switched on — iCloud or Google — may include this data, as it does for any app on your phone.

10. Cross-Border Data Transfers

The Application is operated from Singapore. Where you have enabled Online Backup & Sync, your personal data is stored on Supabase servers and may be transferred to and stored in the United States. Any support message you send is also stored on Supabase servers regardless of whether you use Online Backup & Sync — see Section 6.1. Where you have allowed notifications, a push-notification token is transmitted through Expo (650 Industries, Inc., USA) and stored on Supabase servers — see Section 6.1. Where personal data is transferred outside Singapore, we ensure appropriate safeguards are in place in accordance with Section 26 of the PDPA. By using the Application, you consent to such transfers, subject to the protections described in this Section.

11. Children

The Application is intended for users who are at least 18 years of age. We do not knowingly collect personal data from individuals under 18. If you believe a child under 18 has provided us with personal data, please contact us immediately at [email protected].

12. Cookies and Similar Technologies

The Application is a mobile application and does not use browser cookies. It uses locally stored data (device storage) for two purposes. Most of it is your preferences and settings, and the Tap to Track card labels described in Section 2.10, all of which stay on your device and are never transmitted to us. A small number of items — a support message queued to send (Section 2.9), and a Tap to Track transaction you have confirmed but which the Application has not finished recording (Section 2.10) — hold something you have already asked the Application to act on, until it can be. A queued support message is on its way to us; a Tap to Track arrival is not, unless Online Backup & Sync is on. Either way, those items are described in the sections covering that data, not here. If we introduce a web-based companion portal in future, we will update this Policy accordingly.

13. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy at any time. Where changes are material, we will provide at least fourteen (14) days' notice before they take effect, via an in-application notice, a push notification, or — if you have an account — an email to the address associated with it. Your continued use after the effective date constitutes acceptance of the updated Policy.

14. Contact Us

Data Controller / Operator:
Soon Duan Zhi Benedict
Operating as: AVI
Email: [email protected]
Singapore

We aim to respond to all data-protection enquiries within five (5) business days and to resolve data access and correction requests within 30 days of receipt.

End of Privacy Policy · Version 2.0 · Effective 24 August 2026 · Issued under the Personal Data Protection Act 2012 of Singapore.
Terms & Conditions · AVI