Privacy Policy

Last updated: September 2026. Written to be understood, not to cover ourselves.

Leer en español →

The core idea

Alebri has three modes, and you choose which one to use. Each stores a different amount of information — from none at all (Local mode) to the minimum needed to automate (Gmail mode). None of them is required, you can combine them, switch between them, or delete everything whenever you want.

🔒 Local mode (the web app)

Everything you record at alebri.vercel.app lives only in your browser's local storage (localStorage). There are no accounts and no server storing your transactions. If you clear your browser data, it is gone — which is why the export button exists.

If you enable the optional AI features (screenshot capture with vision, or the chat), the text or image is sent to Anthropic's API (Claude) for that single analysis and is not stored on any server of ours. The AI chat only receives your aggregated monthly totals, never the full list of your transactions.

☁️ Backup to your own Google Drive (optional)

Local mode does not lose your data… unless you lose or wipe the device. To prevent that, you can optionally enable a backup that is stored in your own Google Drive — not on a server of ours.

Which permission we request: only drive.appdata, a scope that grants access exclusively to a hidden, Alebri-specific folder inside your Drive. With that scope Alebri cannot see, list or touch any other file in your Google Drive. We never ask for your password — you authorize on Google's own screen.

What is stored and where: a single file (alebri-backup.json) containing your expenses, rules and budgets, inside that hidden folder in your Drive. We neither store nor read that backup — it is yours and it lives in your Google account. You can delete it or revoke the permission at any time at myaccount.google.com/permissions.

💬 WhatsApp mode

If you message the Alebri bot, we store in a database (Railway/Postgres): your WhatsApp number and the expenses you record (amount, merchant, category, date). We do not read your WhatsApp conversations beyond the message you send us to record an expense, and we do not access your contacts or any other chats.

Commands that control this: exportar (we send you a CSV with everything we store) and borrar todo (permanently deletes your number, your expenses and any associated Gmail connection, with double confirmation).

⚡ Automatic mode with Gmail (opt-in)

This mode is entirely optional. If you type conectar gmail, we send you to Google's official screen to authorize access — we never see or ask for your password.

Exactly what we read: our server queries your Gmail with a filter that only includes senders that are Peruvian banks and wallets (Yape, Plin, BCP, Interbank, BBVA, Scotiabank, and similar). That filter is part of the Gmail API query itself — in practice we never list or download a message that does not come from those senders. Your personal, work, or any other email is never touched.

What we store: from the bank email we do process, we extract the expense (amount, merchant, category, date) and store it together with the message identifier, so the same email is not processed twice. The body and the subject of the email are never stored — they are read in memory, used to extract the data, and discarded.

The access token for your Gmail is stored encrypted (AES-256-GCM) in our database, never in plain text. You can revoke it at any time by typing desconectar gmail on WhatsApp, or directly at myaccount.google.com/permissions. When you do, we delete the stored token and the stored message identifiers; the expenses already recorded remain yours, and you can delete them with borrar todo.

When connecting your Gmail, Google may show a screen warning that the app is not verified. That is true and we do not hide it: Google's verification for this kind of scope is a long process we have not completed yet. You can continue via Advanced, or simply not use this mode — the bot and the app work fine without it.

Compliance with Google API Services User Data Policy

Alebri's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, regarding the data we obtain from your Gmail, we commit to:

  • Only for the feature you asked for. The data is used solely to record your expenses and show them back to you — the user-facing feature you enabled this mode for. Nothing else.
  • We do not transfer it to third parties, except where necessary for security purposes, to comply with applicable law, or as part of a merger or acquisition previously disclosed and with your consent.
  • No human reads your email. Processing is automatic. A human could only access it if you expressly authorize it to resolve a specific issue, if required by law, or on aggregated and anonymized data.
  • Never for advertising, and never to train AI models for purposes beyond your own expense tracking.
  • Never sold. Not to advertisers, not to banks, not to anyone.

Data retention and deletion

We keep your data for as long as you use Alebri. There is no automatic expiry, because the whole point of the app is to let you look back at previous months. You are always in control:

  • desconectar gmail — revokes the Google token, and deletes both the token and the stored Gmail message identifiers on our side, immediately.
  • borrar todo — permanently deletes your number, every expense, and every associated record. It cascades: nothing of yours is left behind.
  • exportar — sends you a CSV with everything we hold about you, before you delete anything.
  • In Local mode there is nothing for us to delete: clearing your browser data removes everything.

Third parties involved

  • Meta (WhatsApp Business API) — carries the messages between you and the bot.
  • Google (Gmail API) — only if you enable automatic mode.
  • Google Drive (appdata) — only if you enable the backup; the file lives in your own Drive, not on our servers.
  • Anthropic (Claude) — only when the optional AI is enabled, to read screenshots or answer chat questions.
  • Railway (Postgres) — where the database for the bot and Gmail mode lives.

Questions

If any of this is unclear, or you want us to delete something specific, message the WhatsApp bot or reach us through the channels in the app.

See also the terms of service →