Cashfield

Privacy Policy

Version 1.13 · Effective September 28, 2026

Cashfield is operated by Ovesyan Tech Inc. This policy explains what information Cashfield collects, why it collects it, who it is shared with, how long it is kept, and what you can do about it.

It is written from what the application actually does. Where Cashfield cannot guarantee something, this policy says so rather than implying otherwise.

Who we are

Ovesyan Tech Inc. is the controller of the information described in this policy. It is a corporation incorporated under the laws of Canada.

Cashfield is a personal finance application for Canada and the United States that connects to your bank and credit card accounts, imports and categorises your transactions, and shows you what your money is doing.

The person responsible for protecting your personal information is our Founder, Oleksandr Ovesian. You can reach them, and us, at info@ovesyantechinc.com.

How you sign in

Cashfield has no password. You sign in with Apple or with Google, and we receive a signed confirmation from them that you authenticated successfully.

We never see, receive or store your Apple or Google password. From that sign-in we keep a stable identifier that the provider gives us, and your email address if the provider supplies one.

We identify you by that provider identifier and never by your email address. Two sign-ins that happen to share an email address remain two separate accounts.

If you sign in with Apple, Cashfield also keeps a token Apple issues for that sign-in, encrypted. It is used for one thing only: to ask Apple to withdraw Cashfield’s access to your Apple sign-in when you delete your account. It is deleted with your account.

What we collect from your bank

When you connect a financial institution, you do so through Plaid, which handles the connection to your bank. Cashfield then receives from Plaid:

What we never receive

Cashfield never receives, stores or transmits your bank username or password. You enter those inside Plaid, which is a separate application interface Cashfield cannot see into. There is no part of Cashfield capable of accepting a bank credential.

We do not collect your full account numbers, your card numbers, your social insurance or social security number, your address, your phone number, your contacts, your location, your photo library (only a profile photograph, if you choose one, as described below) or your device identifiers for advertising.

We do not take your name or your date of birth from your bank, from Plaid, from your email address or from your Apple or Google account. If Cashfield holds any of those it is because you typed them into your profile yourself, and you can remove them at any time.

What you give us directly

You can add transactions yourself — an expense, income, a refund or a transfer. A manual entry holds the amount, the date, a merchant or description you type, a category, and, for a transfer, where the money moved from and to: a bank account, savings and investments, a credit card or cash.

You can also correct the category Cashfield assigned to any transaction, and tell it that a detected subscription is not one. Those corrections are kept, and they take precedence over anything Cashfield works out for itself.

You can set two preferences: your timezone and the currency you would like totals displayed in.

You can also fill in a profile: a first name, a last name, a date of birth and a gender. Every one of those is optional, you can use all of Cashfield without giving any of them, and you can change or clear each of them whenever you like. They are used to greet you by name and to show who is signed in — they are never used to work out your money, they are never part of what Ask sees, and they are never shared with anyone.

You can also add a profile photograph. It is optional, it is shown on your profile and nowhere else, and you can replace or remove it whenever you like. When you choose one, Cashfield makes a small square copy on your phone and stores that copy privately on our servers; the original stays in your photo library, and Cashfield keeps no location or other details from it. It is never used to work out your money, it is never part of what Ask sees, it is never shared with anyone, and it is deleted with your account.

Cashfield asks to open your photos only at the moment you choose to add one, and never at any other time. You can use every part of Cashfield without allowing it.

What Cashfield works out for itself

From the transactions above, Cashfield derives information it also stores:

Decisions made automatically

Cashfield is for personal accounts, and it decides automatically whether an account you connect is a business account. It decides from what your bank reports about the account — whether the bank says it is personal or business, and what kind of account it is — and, only to refuse, from words in the account’s name. A business account is not added, and none of its transactions or its balance are imported. Where your bank says nothing that settles it, Cashfield asks you rather than deciding.

If an account was refused and you believe it is personal, write to info@ovesyantechinc.com. The person responsible for personal information will tell you what information the decision used and why it was made, correct anything that was wrong, and review the decision.

Everything else Cashfield works out — categories, transfers, recurring payments — describes your transactions rather than deciding anything about you, and you can correct any of it in the app.

Ask Your Money

If you ask Cashfield a question about your finances, the question you typed and the answer you were shown are stored so that a conversation can continue coherently.

What is not stored: the underlying figures the answer was built from, the instructions sent to the AI model, the model's internal reasoning, and anything the model was asked to look up. A conversation holds the two things you actually saw and nothing that would make it a second copy of your finances.

Answers are written by OpenAI, and nothing is sent to OpenAI until you allow it. The first time you ask, Cashfield tells you what would be sent and asks for your permission. The same permission lets Cashfield have OpenAI word your insights and suggest a category for a merchant it does not recognise. Without it, Ask does not send your question, insights keep Cashfield's own wording, and such a merchant stays uncategorised. You can withdraw it at any time in Profile, under Privacy & data; nothing is sent after that. Cashfield keeps your answer and when you gave it, so that you are asked only once.

Records of AI use

When Cashfield uses an AI model for you — to answer a question in Ask, to write an insight, or to suggest a category for a transaction — it keeps a record that it did so: which of those features it was, which model was used, how much text the model read and wrote (counted in tokens, the unit AI providers charge by), how many steps the answer took, and when.

That record contains nothing from your finances: no question, no answer, no amount, no merchant, no account and no category. It exists so that we can understand, and in future limit, what the AI features cost to run. It is kept while your account exists and is deleted with it.

Notifications

Cashfield sends one kind of notification: when an institution you connected needs you to sign in to it again, because new transactions stop arriving until you do. The notification names the institution. It never contains an amount, a balance, a merchant or a transaction, and Cashfield sends no marketing or promotional notifications.

It is sent only if you allow notifications on your phone, and you can turn them off at any time in your phone’s settings.

To send it, Cashfield keeps, for each phone you allowed notifications on: the address Apple or Google gives that phone for notifications, whether it is an iPhone or an Android phone, and the language you chose in Cashfield, so the notification is written in it. It also keeps a record of each notification it decided to send — which kind it was, which of your connected institutions it was about, and when — so that the same one is not sent twice.

A phone’s address is removed when you sign out of Cashfield on it, when Apple or Google reports that it no longer works, and when you delete your account. The record of notifications is kept while your account exists and is deleted with it.

Crash and error reports

Cashfield collects crash and error reports through Sentry, so that we can find and fix bugs. This is not analytics and it is not a record of what you did.

A crash report can contain: the app version and build, the environment, your operating system version and device model, the type of error and the lines of code it happened in, the name of the screen you were on, and the path and status code of recent requests — for example "GET /transactions". It also carries an internal account identifier that means nothing outside our own database, so that several reports can be recognised as coming from one session.

A crash report never contains: your email address, your name, your date of birth, your gender, your sign-in identifier, any merchant, transaction description or amount, any account name or number, any institution, anything you typed into a search box, any question you asked or answer you received, or any credential.

There is no session recording, and Cashfield never captures your screen. A crash report is not analytics and is never used to study how you use the application — that is a separate thing, described in the next section.

Error messages are removed from reports unless we wrote them ourselves, because a message can carry information that something else put into it.

Product analytics

This is off unless you turn it on. Cashfield records nothing described in this section until you switch on Share usage analytics, in Profile under Privacy & data, and nothing at all is recorded before you sign in. When you turn it on, this installation of the app — and the campaign link that brought you to Cashfield, if there was one — is linked to your account from that moment. You can turn it off again at any time, and recording stops straight away. Cashfield keeps your answer and when you gave it.

If you turn it on, Cashfield records a small, fixed list of events about how the application itself is used, so that we can tell whether it works: that a screen was opened, that connecting an institution was started, completed or cancelled, that a first set of data finished importing, that an answer was asked for, that the subscription screen was shown, and that a purchase was started or failed or a free trial or subscription started, renewed, was cancelled or ended. The list is fixed in the application and cannot be added to without a new release.

Each event also carries what is needed to count it correctly: an internal account identifier that means nothing outside our own database, a random identifier for this installation of the app (not an advertising identifier, and replaced when you sign out), the app version, whether it is running on iOS or Android, and — if a link from one of our campaigns brought you to Cashfield — the campaign tags on that link. Alongside the events, PostHog keeps three facts about where you stand, each from a fixed short list: whether you finished setting up, whether you are on a free trial, paying or no longer subscribed, and whether your subscription renews. They never include a price, a store or a date.

An event never contains financial content, and never anything that identifies you to anybody else: no amount, balance, merchant, description, account or institution name, no transaction, no question you asked or answer you were shown, and no email address, name or sign-in identifier.

These events are sent from Cashfield’s own servers, not from your phone. There is no analytics software inside the application, so nothing on your device records your screen, reads what is on it, or watches what you type.

Turning it off stops new events; it does not reach back and remove the ones already recorded. If you would like those removed, write to info@ovesyantechinc.com and we will delete them.

This is not advertising and it is not tracking across other applications. Cashfield collects no advertising identifier, shows no advertising, and shares nothing with advertisers or data brokers.

Why we process this information

Cashfield uses the information above to:

What Cashfield does not do with your information

We do not sell your personal information. We do not share it with advertisers, data brokers or marketing networks. We do not use it to build a profile of you for anyone else, and we do not use your financial data to train artificial intelligence models.

The companies we use

Cashfield relies on a small number of service providers. Each receives only what it needs to do its job.

Where your information is processed

Cashfield serves Canada and the United States, and your information is stored and processed in the United States: the Cashfield service and its database run in Virginia, and Plaid, Sentry, PostHog, OpenAI and RevenueCat process information there too.

If you live in Canada, your information is therefore processed outside Canada, where it is subject to the laws of the United States and may be accessible to courts, law enforcement and national security authorities there.

How long we keep your information

While your account exists, Cashfield keeps your accounts, transactions, categories, corrections, manual entries, recurring payments, preferences and Ask conversations. Nothing is aged out while you use Cashfield — a finance application whose history quietly disappeared would not be one you could rely on.

If you do not use Cashfield for 24 months and no subscription is running, we delete your account, exactly as if you had deleted it yourself (see Deleting your account). Using Cashfield means opening the app while signed in; a bank that goes on syncing does not count. You are not warned first, because Cashfield sends no email.

Written insights are a cache and are regenerated as the underlying figures change.

Records of AI use are kept while your account exists, and deleted with it.

A phone’s notification address is kept until you sign out on that phone or it stops working, and the record of notifications sent is kept while your account exists; both are deleted with it.

The record of your subscription — whether you are in a free trial, subscribed or not, when the current period ends, and the random identifier RevenueCat knows you by — is kept while your account exists, and deleted with it. It is refreshed from Apple or Google through RevenueCat, and holds no price or payment details.

Exchange rate data is not personal information. It describes a currency pair on a date, is the same for everybody, and is not linked to any account.

Disconnecting an institution

When you disconnect an institution, Cashfield revokes its access with Plaid and destroys the stored access credential immediately. No new data arrives from that institution afterwards.

The accounts and transactions imported from it are permanently deleted at the same time, together with your categories, corrections and exclusions on those transactions. Transactions you entered yourself are not affected.

If your free trial or subscription ends without renewing, Cashfield does the same for every institution you have connected, once any grace period Apple or Google allows for a failed payment has passed. Your account, your profile and the transactions you entered yourself remain until you delete them, or until the account is deleted after 24 months without use (see How long we keep your information). Until you subscribe again, Cashfield opens on its subscription screen and nothing else; from there you can still export your data or delete your account, or subscribe and connect your institutions again.

Deleting your account

You can delete your Cashfield account yourself, from Profile, under Privacy & data — or, without a subscription, from the subscription screen Cashfield opens on. No request to us is needed and there is no waiting period.

Deletion happens in this order, and the order matters: every connected institution is disconnected and its access credential revoked; your sign-in is removed; and then your records are permanently deleted from our database. If any step fails, nothing further is deleted and the app tells you plainly that your account still exists.

What is deleted: your transactions — both imported and manually entered — together with their categories, your corrections, links between them, duplicate proposals, your accounts and institutions, your recurring payments, your insights, your Ask conversations, your records of AI use, your notification settings and the record of notifications sent, your subscription record, your profile details and photograph, your preferences, and your account record itself.

If anything about you ever reached PostHog through usage analytics, it is the one exception, and we state it rather than leave it implied: deleting your account tells PostHog that the account is deleted, but the events themselves are removed by hand rather than automatically. They contain no financial content and nothing that identifies you outside our own database. If nothing about you ever reached PostHog, nothing is sent to it when you delete your account either.

Deleting your Cashfield account does not cancel a subscription you bought through the App Store or Google Play. Cancel it in your Apple or Google account settings, or Apple or Google will go on charging you.

Deletion asks you to sign in again first, so that an unlocked phone left on a table is not a deletion waiting to happen.

Afterwards we keep a one-way fingerprint of your sign-in identifier, and nothing else, so that a sign-in from before the deletion cannot reopen the account. The fingerprint cannot be turned back into your identifier. It is kept for at least 30 days, and removed the next time any Cashfield account is deleted after that.

Signing in again afterwards with the same Apple or Google account creates a new, empty Cashfield account. Nothing is restored.

Backups

Your records are removed from Cashfield's active systems immediately when you delete your account.

Our database provider, Supabase, backs up the database once every 24 hours and keeps each backup for 7 days. A record you delete can therefore remain in a backup for up to 7 days afterwards, until that backup expires. We do not claim that deletion is immediate everywhere, because backups are the one place it is not.

Exporting your data

You can export a copy of your data at any time, from Profile, under Privacy & data — or, without a subscription, from the subscription screen Cashfield opens on. The file is a ZIP of spreadsheets containing your transactions, accounts, institutions, recurring payments, preferences, the personal details you gave and your own Ask conversations, together with your profile photograph if you added one.

It is generated at the moment you ask for it and sent straight to your device. Cashfield keeps no copy of it — there is no file on a server, no link that expires, and nothing left behind to clean up. Amounts are in the currency each transaction actually happened in.

The export contains no access tokens and no bank credentials, because those either do not exist or never leave our servers.

How we protect your information

Your session is stored in the device keychain, protected by your device. Cashfield keeps no financial data on your phone: every figure is fetched when you look at it and held only in memory.

The credentials that let Cashfield read your accounts never leave our servers, and are encrypted there with AES-256-GCM before being stored. Traffic between the app, our API and every provider is encrypted in transit, and our database connection requires encryption in production.

Your data is reachable only by you. Every request is authorised from your verified session, never from anything the app asks for, and the database itself is structured so that records belonging to one account cannot be attached to another.

Our logs record which endpoint was called and whether it succeeded. They deliberately do not record search terms, merchants, amounts, categories or anything else about your finances.

No system is perfectly secure, and we do not claim otherwise. Cashfield has not been independently audited or certified.

Your choices

Children

Cashfield is not intended for and is not directed at children. You must be at least 18 years old, or the age of majority where you live if that is higher, to use Cashfield, and we do not knowingly collect information from anyone younger.

Changes to this policy

If this policy changes in a way that affects what we collect or what we do with it, we will update the effective date at the top and make the new version available in the app before the change takes effect.

Contact

Questions about this policy, or about your information, can be sent to info@ovesyantechinc.com.

The person responsible for protecting personal information at Cashfield is our Founder, Oleksandr Ovesian, who can be reached at the same address.