Shmoney
  • Home
  • Terms
  • Privacy

Privacy Policy

Last Updated: March 23, 2026

🔒 Our Core Privacy Promise

Shmoney processes all your MPESA transaction data locally on your device. Your SMS messages, transaction history, and financial information NEVER leave your phone and are NEVER uploaded to our servers or any cloud service.

1. Introduction

This Privacy Policy describes how Shmoney ("we," "our," or "us") collects, uses, stores, and protects your information when you use our mobile application (the "App"). By using Shmoney, you agree to the collection and use of information in accordance with this policy.

Shmoney is operated from Kenya and is intended for use by residents of Kenya and other jurisdictions where MPESA is available. This policy complies with the Kenya Data Protection Act, 2019, and other applicable data protection laws.

2. Information We Collect and How We Collect It

2.1 SMS Messages and MPESA Transaction Data

The App requests permission to read SMS messages on your device solely to extract MPESA transaction information. This includes:

  • Transaction amounts and dates
  • Transaction types (send money, withdraw, deposit, pay bill, buy goods)
  • Recipient/sender names and phone numbers
  • Transaction reference numbers
  • MPESA balance information
  • Transaction costs and fees

IMPORTANT: All SMS data is processed and stored ONLY on your local device. We do NOT transmit, upload, or store your SMS messages or MPESA transaction data on any external servers.

2.2 Device Information

We may collect limited device information to ensure the App functions properly:

  • Device model and manufacturer
  • Operating system version
  • App version
  • Device language settings
  • Crash logs and error reports (anonymized)

2.3 Usage Data

We may collect anonymized, aggregated analytics data about how you use the App, including:

  • Features accessed
  • Session duration
  • App performance metrics

This data is collected in a way that does NOT identify you personally and does NOT include your transaction data.

2.4 Information You Provide Directly

  • Account registration information (if you create an account for backup/sync features)
  • Email address (if you contact customer support)
  • Budget preferences and categories you create
  • Custom notes or tags you add to transactions

3. Ask Shmoney AI Feature - Optional AI-Powered Insights

🤖 How Ask Shmoney AI Works and Protects Your Privacy

The Ask Shmoney AI feature is COMPLETELY OPTIONAL and requires your explicit consent before any data is used.

3.1 What Ask Shmoney AI Does

Ask Shmoney AI is an optional feature that allows you to ask questions about your spending patterns and receive AI-powered insights based on your transaction data. This feature uses artificial intelligence to analyze your financial data and provide personalized responses to your queries.

3.2 Critical Privacy Protections for AI Feature

We have implemented strict data minimization and privacy protections for the AI feature:

  • NO Personal Identifiable Information (PII) is sent to AI servers:
    • Recipient names are NEVER sent
    • Phone numbers are NEVER sent
    • Transaction reference numbers are NEVER sent
    • Individual transaction details containing personal information are NEVER sent
  • Only Aggregated, Anonymized Data is used:
    • Total spending amounts by category (e.g., "Food: KES 5,000")
    • Transaction counts (e.g., "15 transactions this week")
    • Spending trends (e.g., "30% increase compared to last month")
    • Category percentages (e.g., "Transport represents 20% of spending")
    • Time-based aggregates (e.g., "Average daily spending: KES 300")
    • Budget comparisons (e.g., "80% of food budget used")

3.3 Explicit Consent Required

The Ask Shmoney AI feature requires your explicit, informed consent BEFORE any data is processed:

  • You must actively enable the AI feature through an opt-in consent screen
  • The consent screen clearly explains what data will be used (aggregated statistics only)
  • The consent screen clearly explains what data will NOT be sent (personal information, names, phone numbers)
  • You can withdraw consent and disable the AI feature at any time in the App settings
  • If you do not provide consent, the AI feature is completely disabled and no data is processed for AI purposes
  • The App's core functionality (transaction tracking, categorization, budgeting, reports) works fully without the AI feature

3.4 How Your Data is Used for AI (Only with Consent)

When you enable Ask Shmoney AI and ask a question:

  • The App computes aggregated statistics locally on your device
  • Only these aggregated, anonymized statistics are sent to our AI service provider's servers
  • The AI processes these statistics to generate insights and answer your question
  • The response is sent back to your device and displayed in the App
  • No conversation history containing your data is permanently stored on AI servers

3.5 Example of What is Sent vs. NOT Sent

What IS sent to AI (only with your consent):

  • "Total spending in March: KES 15,000"
  • "Food category: KES 5,000 (33%)"
  • "Transport category: KES 3,000 (20%)"
  • "Number of transactions: 42"
  • "Average transaction amount: KES 357"

What is NEVER sent to AI:

  • ❌ "Sent KES 500 to John Doe (0712345678)"
  • ❌ "Received KES 1,000 from Jane Smith"
  • ❌ Transaction reference numbers like "ABC123XYZ"
  • ❌ Specific transaction dates and times
  • ❌ Individual transaction descriptions
  • ❌ Any message that identifies specific people or phone numbers

3.6 AI Service Providers

When you use Ask Shmoney AI, we use third-party AI service providers to process your queries. These providers:

  • Only receive aggregated, anonymized statistics (never personal information)
  • Process data in accordance with their own privacy policies and applicable laws
  • Are contractually obligated to protect your data and use it only for providing the AI service
  • Do not have access to your raw transaction data, SMS messages, or personal information

3.7 Data Retention for AI Feature

When using Ask Shmoney AI:

  • Aggregated statistics are only transmitted when you actively ask a question
  • No persistent record of your statistics is stored on our servers or AI providers' servers
  • Conversation sessions are temporary and not linked to your identity
  • You can delete all AI interaction history from within the App at any time

3.8 Disabling Ask Shmoney AI

You can disable the Ask Shmoney AI feature at any time by:

  • Going to App Settings → Privacy → Ask Shmoney AI
  • Toggling off "Enable AI Insights"
  • Withdrawing your consent for data use

After disabling, no aggregated data will be sent to AI services, and the App will continue to function normally with all other features intact.

4. How We Use Your Information

4.1 Primary Use - On-Device Processing

Your MPESA transaction data is used exclusively on your device to:

  • Display your transaction history
  • Categorize expenses automatically
  • Calculate spending totals and averages
  • Monitor budget limits and provide alerts
  • Create financial reports and visualizations

4.2 App Improvement

Anonymized usage data may be used to:

  • Improve App functionality and user experience
  • Identify and fix bugs
  • Develop new features
  • Analyze App performance

4.3 Customer Support

If you contact us for support, we may use your email address and issue description to assist you.

5. Data Storage and Security

5.1 Local Storage

All MPESA transaction data is stored in encrypted format on your device using industry-standard encryption methods. This data is stored in the App's private storage area and is not accessible to other applications on your device.

5.2 No Cloud Storage

We do NOT maintain cloud servers that store your MPESA transaction data, SMS messages, or financial information. Your data remains exclusively on your device under your control.

5.3 Security Measures

We implement appropriate technical and organizational security measures, including:

  • Encryption of data at rest on your device
  • Secure coding practices to prevent unauthorized access
  • Regular security audits and updates
  • Minimal data collection philosophy
  • Secure transmission protocols (HTTPS/TLS) for any data sent to AI services (aggregated data only)

5.4 Device Lock Protection

We strongly recommend that you:

  • Use a device lock (PIN, password, fingerprint, face recognition)
  • Keep your device software up to date
  • Install apps only from official app stores
  • Enable device encryption if available

6. Data Sharing and Disclosure

We do NOT sell, rent, trade, or otherwise share your MPESA transaction data or SMS messages with any third parties.

6.1 Service Providers

We may use third-party service providers for:

  • Analytics (anonymized data only)
  • Crash reporting (anonymized data only)
  • App hosting and distribution (through Google Play Store, Apple App Store)
  • AI-powered insights (aggregated, anonymized statistics only - requires your explicit consent)

These providers do NOT have access to your MPESA transaction data, SMS messages, or personal identifiable information.

6.2 Legal Obligations

We may disclose information if required by law, court order, or government regulation, including:

  • Response to valid legal process
  • Protection of our legal rights
  • Investigation of fraud or security issues
  • Protection of user safety

Note: Since we do not collect or store your transaction data on our servers, we cannot provide it to third parties even if requested.

6.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, user information may be transferred. We will notify you via email and/or prominent notice in the App before your information is transferred and becomes subject to a different privacy policy.

7. Your Rights and Choices

7.1 Access and Control

You have the right to:

  • Access: View all data stored by the App on your device
  • Deletion: Delete your data at any time by uninstalling the App or using the in-app data deletion feature
  • Correction: Edit transaction categories, notes, and budget settings
  • Export: Export your transaction data for personal use
  • AI Opt-Out: Disable Ask Shmoney AI at any time to prevent aggregated data from being used

7.2 SMS Permissions

You can revoke SMS permissions at any time through your device settings. Note that revoking this permission will prevent the App from automatically tracking new MPESA transactions.

7.3 Analytics Opt-Out

You can disable anonymized analytics collection in the App's settings menu.

7.4 Marketing Communications

If you receive marketing emails from us, you can unsubscribe using the link in the email or by contacting us directly.

8. Children's Privacy

Shmoney is not intended for use by children under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately, and we will take steps to remove such information.

9. Third-Party Links and Services

The App may contain links to third-party websites or services (e.g., Google Play Store, social media, AI service providers). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

10. International Data Transfers

Since all MPESA transaction data is stored locally on your device, there are no international data transfers of your financial information. Any anonymized analytics data or aggregated statistics (if you enable Ask Shmoney AI) may be processed on servers located outside Kenya, but this data does not contain personally identifiable information, names, phone numbers, or individual transaction details.

11. Data Retention

Your MPESA transaction data is retained on your device for as long as you use the App. You can delete specific transactions, clear all data, or uninstall the App at any time to permanently remove your data from your device.

We may retain anonymized analytics data for up to 2 years for business analysis and App improvement purposes.

For Ask Shmoney AI: Aggregated statistics are only processed in real-time when you ask questions and are not persistently stored on our servers or AI providers' servers.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy in the App
  • Updating the "Last Updated" date at the top of this policy
  • Sending an in-app notification or email (if you have provided one)
  • Requiring re-consent for Ask Shmoney AI if changes affect how AI data is processed

Your continued use of the App after changes become effective constitutes your acceptance of the revised policy.

13. Compliance with Kenya Data Protection Act

We comply with the Kenya Data Protection Act, 2019, and recognize your rights under this legislation, including:

  • Right to be informed about data processing
  • Right of access to your data
  • Right to correction of inaccurate data
  • Right to deletion of your data
  • Right to object to processing
  • Right to data portability
  • Right to withdraw consent (including for Ask Shmoney AI)

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: [email protected]
Address: [Your Business Address], Nairobi, Kenya
Data Protection Officer: [DPO Name and Contact]

15. Complaints

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with:

Office of the Data Protection Commissioner
Nairobi, Kenya
Website: www.odpc.go.ke
Email: [email protected]

Summary - Your Privacy Matters

Remember: Shmoney is designed with privacy as a core principle. Your MPESA transaction data stays on your phone, encrypted and secure. We cannot access it, we don't want to access it, and we will never sell it. You are in complete control of your financial data.

Ask Shmoney AI is optional: If you choose to use it, only aggregated statistics (totals, categories, trends) are sent to AI servers - never your personal information, recipient names, or phone numbers. You can disable this feature at any time.


© 2026 Shmoney. All rights reserved. | Home | Terms of Service | Privacy Policy