1. What Truffle does
Truffle is an offline-first budget tracker. Your transactions, budgets, categories, savings jars, and related ledger records are stored locally on your device. Truffle does not currently sync your financial ledger to the cloud.
2. What may leave your device
Most features work locally. If you choose AI capture, Truffle uploads the receipt photo or voice recording you submit so it can be processed and returned as a suggested transaction. This can happen while you are signed out through an anonymous service identity.
If you sign in, Truffle processes the identity information supplied by your sign-in provider, such as your email address and provider identifier. Optional location features use device location only when you choose to add a place to a transaction.
3. Service providers
- Supabase provides authentication, private storage, and the backend job that handles AI capture.
- Cloudflare Turnstile helps protect sign-in and anonymous service access from abuse. Its use is subject to the Turnstile Privacy Addendum.
- OpenRouter routes AI requests to the configured inference provider. The app does not send your ledger to this service.
- OneSignal may process a device notification identifier when notifications are enabled.
- RevenueCat processes subscription and purchase status when you use Truffle Plus.
- Sentry receives limited diagnostic information from release builds so crashes and operational errors can be investigated.
Truffle does not sell your personal information. It does not use your financial ledger for advertising.
4. Local storage and exports
The local ledger database is encrypted with a key held by the operating system's secure storage. Receipt photos and voice recordings are stored in the app's private storage but are not separately encrypted. Device backups are disabled for Truffle's private profile data.
Backups you choose to export are unencrypted files. Treat an exported backup as sensitive financial information and store it accordingly.
5. Retention and deletion
We retain service data only as needed to provide the relevant feature, prevent abuse, maintain security, meet legal obligations, and resolve support requests. AI capture data may include the uploaded media, the processing result, and job metadata for the period needed to complete or recover the job.
You can request deletion of your Truffle account and associated account data through the account deletion page. We may ask you to verify ownership of the account before processing the request. Some information may be retained where required for security, fraud prevention, legal compliance, or financial recordkeeping; we will explain this if it applies.
6. This website
This website is a static information resource. The account deletion form opens a pre-filled email to truffle@fxlui.com; the website does not store form submissions.
7. Contact
Questions about privacy or deletion can be sent to truffle@fxlui.com.