TransparentMe — Privacy Policy
DRAFT — NOT LEGAL ADVICE — REQUIRES REVIEW BY A LICENSED ATTORNEY IN THE APPLICABLE JURISDICTION BEFORE USE.
This document was prepared as a working draft to accelerate review. It has not been reviewed or approved by a licensed attorney, it is not legal advice, and it must not be published, distributed, or relied upon until a qualified attorney in the applicable jurisdiction(s) has reviewed, corrected, and finalized it. Every field marked To be completed[PLACEHOLDER] must be completed by the founder and/or attorney before use. Bracketed Attorney note[ATTORNEY NOTE] comments flag decisions that require legal judgment and should be removed before publication. This policy is written to describe the product's actual data practices as understood at the time of drafting; if the product changes, this policy must be updated to remain accurate.
Effective date: To be completed[PLACEHOLDER — effective date] Last updated: To be completed[PLACEHOLDER — last updated date]
1. Who we are and what this policy covers
1.1 This Privacy Policy explains how To be completed[PLACEHOLDER — legal entity name] ("TransparentMe," "we," "us," or "our") handles personal information in connection with the TransparentMe mobile application (the "App"), the website at transparentme.app (the "Website"), the public transparency pages, and related features (together, the "Service").
1.2 TransparentMe is a financial-transparency and record-keeping tool for people running fundraisers. A defining feature of how the Service is built is that your core fund data is processed on your device and stored in your own Apple iCloud / CloudKit account, and that certain content is published publicly at your choice. Both facts shape this policy, so please read it in full.
1.3 Controller. For the purposes of applicable data-protection law, the controller of the personal information described here is To be completed[PLACEHOLDER — legal entity name and registered address]. Attorney note[ATTORNEY NOTE: Because much fund data is stored in the user's own iCloud account and much processing happens on-device, counsel should analyze precisely where TransparentMe acts as a controller, where the user (Organizer) is the controller and TransparentMe (or Apple) a processor, and where Apple is an independent controller. This affects the whole policy, especially Sections 6, 9, and 12.]
1.4 Contact. Privacy questions and requests: To be completed[PLACEHOLDER — privacy contact email]. Data protection officer / EU or UK representative, if applicable: To be completed[PLACEHOLDER — DPO / representative details, or "not applicable"]. Mailing address: To be completed[PLACEHOLDER — business mailing address].
2. A note on how the Service is architected (why it matters for your privacy)
2.1 On-device processing. The App reads receipts and other images using Apple's on-device Vision text-recognition (OCR) and generates suggested descriptions and matches using Apple Foundation Models (on-device artificial intelligence). This processing is designed to happen on your device; the App does not send your receipts to us or to a third-party cloud AI service in order to read them.
2.2 Storage in your iCloud/CloudKit. Your fund's events, receipts, charge records, and ledger are designed to be stored in your own Apple iCloud / CloudKit account and synced across your own devices by Apple. That storage is provided by Apple under Apple's terms and privacy policy; we do not operate a separate server that holds a copy of your private fund data for the core App experience.
2.3 The Website and public pages. The Website and the public transparency pages are hosted on Vercel. Where you use web features — for example, publishing a transparency page or (where available) uploading files through the Website — content may be stored using Vercel's hosting and storage (including Vercel Blob storage). Content you choose to publish is public (Section 8).
2.4 The result is that, for much of the Service, we handle less of your personal information than a typical cloud app, and some of it we may never receive. Where that is the case, we say so below.
3. Information we collect
We collect or process the following categories, depending on how you use the Service.
3.1 Account and identity information (via Sign in with Apple)
When you sign in — in the App or on the Website — using Sign in with Apple, we receive from Apple:
- a stable Apple subject identifier (a unique ID for your account, called the "sub"), which we use as your account key; and
- an email address, if you choose to share it. This may be a private Apple relay address rather than your personal email, and Apple may withhold it entirely.
On the Website, we place a signed session cookie (see Section 7) so you stay signed in. We do not receive or store an Apple password.
3.2 Fund and expense data you enter
Information you create or enter about a fund, for example: fund/case name and code, amounts raised and spent, transfers, expense amounts, dates, vendors, categories, payment-method labels and last-four digits, allocations, paybacks, notes, and descriptions (including descriptions you edit or that the on-device AI drafts for your review). As described in Section 2, this data is designed to live primarily in your own iCloud/CloudKit account; some of it becomes information we process when you publish or use web features.
3.3 Uploaded documents, receipts, and images
Images and documents you capture or upload — receipts, invoices (including PDFs), bank or card charge-alert screenshots, notification screenshots, and camera captures — together with text and values extracted from them by on-device OCR. These files frequently contain sensitive financial and personal information, both yours and, potentially, that of third parties (for example, a vendor, an attorney, a family member, a beneficiary, a donor, or another individual). In the App, these are stored in your iCloud/CloudKit account. If you upload files through the Website, they may be stored using Vercel Blob storage.
3.4 Camera and photo access
With your permission, the App and (where available) the Website access your camera to capture receipts and documents, and the App may access selected images from your photo library as evidence. We access this content to provide the Service; permissions are controlled by your device and browser and can be changed there.
3.5 Device, usage, and log data
When you use the Website, our hosting provider (Vercel) automatically processes standard technical information such as IP address, browser and device type, pages requested, referring pages, and timestamps, in server logs used for security, reliability, and abuse prevention. The App and Website may also generate diagnostic and usage information. Attorney note[ATTORNEY NOTE: Confirm exactly what analytics, crash reporting, or diagnostic tools (if any) are used — including Apple App Analytics — and list them here. Do not overstate or understate. If no analytics SDK is used, say so.]
3.6 Cookies and similar technologies
The Website uses a small number of strictly necessary cookies, principally the signed session cookie that keeps you signed in after Sign in with Apple, and a short-lived cookie used to secure the sign-in round trip. See Section 7.
3.7 Communications
If you contact us (for example, for support), we receive the information you provide, such as your email address and the contents of your message.
3.8 Information about third parties in your content
Because you may upload documents that contain other people's personal information, we may process third-party personal information on your behalf as part of your User Content. You are responsible under the Terms of Service for having the right to provide it and for redacting what should not be public. See Sections 6, 8, and 11.
4. How we use information
We use the information above to:
4.1 Provide the Service — authenticate you via Sign in with Apple; create and maintain your account; let you create funds, enter expenses, capture and upload evidence, organize a ledger, and generate reports and transparency pages;
4.2 Perform on-device processing — read receipts with OCR and draft suggested descriptions and matches with on-device AI, for your review;
4.3 Produce redacted and published outputs — generate donor updates, reports, and public transparency pages, including applying redaction and payment-method anonymization to shared copies, according to your choices;
4.4 Secure and maintain the Service — protect against fraud, abuse, and security incidents; debug, monitor, and improve reliability;
4.5 Communicate with you — respond to requests and send service-related messages;
4.6 Comply with law — meet legal, regulatory, tax, and record-keeping obligations and respond to lawful requests; and
4.7 Enforce our Terms and protect our rights and those of users and third parties.
We do not use your uploaded receipts or fund data to train our own advertising or unrelated machine-learning models, and we do not sell your personal information (Section 10).
5. Legal bases for processing (EEA / UK — GDPR)
Attorney note[ATTORNEY NOTE: Include this section if the Service is offered to individuals in the EEA/UK, and confirm the bases below. Adjust once the controller/processor analysis in 1.3 is settled.]
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to provide the Service you request, including authentication, storage, and publishing;
- Legitimate interests (Art. 6(1)(f)) — to secure the Service, prevent abuse and fraud, and maintain reliability, balanced against your rights;
- Consent (Art. 6(1)(a)) — for camera/photo access and any optional processing that requires consent; you may withdraw consent at any time; and
- Legal obligation (Art. 6(1)(c)) — to comply with applicable law.
Special-category and sensitive data. Documents you upload may contain sensitive information (for example, health-, legal-, or family-related details, or information about minors). Attorney note[ATTORNEY NOTE: Identify the Article 9 condition(s), if any, relied upon (e.g., explicit consent, manifestly made public by the data subject, establishment/defense of legal claims), and reconcile with the reality that Organizers upload third-party sensitive data. This is a significant risk area given fundraisers involving vulnerable people and minors.]
6. On-device processing and your iCloud/CloudKit storage
6.1 The App is designed so that receipts, charge records, ledger events, and other fund data are processed on your device and stored in your own Apple iCloud / CloudKit account. In that architecture, Apple provides the storage and sync, subject to Apple's terms and privacy policy, and much of your fund data is not held on our servers.
6.2 This means: (a) you exercise a large degree of direct control over that data through your Apple account and your device; (b) deleting the App or your associated iCloud data is largely within your own power; and (c) for that data, our ability to access, export, or delete on your behalf is limited, because it lives in your Apple account rather than ours. See Section 11 for how rights requests interact with this design and with our append-only record.
6.3 The App maintains a local safety archive of your sealed evidence and events on your device so that a change to your iCloud sign-in state does not destroy your only copy. You should also keep your own backups/exports of important records.
7. Cookies and session technologies
7.1 The Website uses strictly necessary cookies only:
tm.session— a signed, HTTP-only session cookie set after you sign in with Apple, so you remain signed in (currently up to 30 days). It carries your Apple subject identifier and, if released, your email, in signed form.tm.oauth— a short-lived cookie (about 10 minutes) used during the sign-in round trip to protect against cross-site request forgery; it carries only hashed values, not raw tokens.
7.2 We do not use these cookies for advertising or cross-site tracking. Attorney note[ATTORNEY NOTE: If any analytics or non-essential cookies are added, add a cookie table and, for EEA/UK users, a consent mechanism. Confirm whether a cookie banner is required based on the final cookie set.]
8. Public transparency pages — published content is public
8.1 This is important. A core feature of the Service is that you can publish a public transparency page, donor update, or share link, which donors and the public can open using a fund code or link.
8.2 Content you choose to publish is public. Anyone with the fund code or link may view, save, screenshot, copy, cache, index, or redistribute it. We cannot control what others do with content once it is public, and we cannot guarantee its removal from third-party copies, caches, or search indexes.
8.3 Redaction of published copies. To reduce exposure, the Service applies redaction and anonymization to the copies you publish or share:
- Payment-method identities are anonymized on public/donor copies — for example, an issuer name and card digits are shown as neutral labels such as "Credit Card A," "Bank A," or "Cash," rather than the real institution or account number.
- Certain sensitive content is redacted on published/shared images — for example, card numbers, account last-four digits, issuer branding, addresses, and names flagged for redaction are covered with opaque bars burned into the shared copy.
- Vendor names are shown by default on public pages, because they are part of the evidence of where money went. An Organizer may turn on Withhold vendor names for a fund in their console; that fund's public pages then show each expense's category in place of the name, and say that the names are withheld while a legal matter is ongoing. Amounts, dates, and whether a receipt is on file are unchanged either way, and the setting applies to the public pages only — your own console keeps showing you the real names.
8.4 Redaction is an aid, not a guarantee, and does not apply to everything. Automated redaction can miss or misplace content, and may not detect sensitive information contained only as a logo, graphic, handwriting, or in an unusual format. The full audit report and the underlying originals are unredacted by design and remain under your control; they are not part of what is published to the public page unless you choose to share them. You decide what publishes, and you are responsible for reviewing each item and ensuring anything made public is appropriately redacted and lawful to disclose (see the Terms of Service).
8.5 If your published content includes another person's personal information, you are responsible for having the right to publish it. If you are a person whose information appears on a transparency page and you wish it addressed, contact the Organizer who published it, or contact us at To be completed[PLACEHOLDER — privacy contact email] and we will make reasonable efforts to assist.
9. How information is shared; third-party processors
9.1 We do not sell your personal information (Section 10), and we do not share it except as described here.
9.2 Service providers / processors. We rely on the following third parties to provide the Service, under their respective terms and privacy policies:
- Apple — Sign in with Apple (authentication) and iCloud / CloudKit (storage and sync of your fund data). Apple Privacy Policy: To be completed[PLACEHOLDER — Apple privacy policy URL].
- Vercel — hosting of the Website and public pages, and (where used) Vercel Blob storage for web uploads and published content, plus standard server logging. Vercel Privacy Policy / DPA: To be completed[PLACEHOLDER — Vercel privacy policy / DPA URL].
Attorney note[ATTORNEY NOTE: Confirm this list is complete and current. Add any analytics, crash-reporting, email, or support tools actually in use, with links. Put data-processing agreements in place with each processor and confirm each processor's role (processor vs. independent controller).]
9.3 Public disclosure at your direction. Content you publish is disclosed to the public as described in Section 8.
9.4 Legal and safety. We may disclose information if we believe in good faith it is necessary to comply with law or lawful requests, to enforce our Terms, to detect or prevent fraud or security issues, or to protect the rights, property, or safety of TransparentMe, our users, or the public.
9.5 Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this policy or a successor policy.
10. We do not sell your personal information
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws (including the CCPA/CPRA). We do not use your uploaded content or fund data for third-party advertising.
11. Your privacy rights and choices
11.1 Access, correction, deletion, export, and the append-only record. Subject to applicable law and to the design of the Service, you may request to access, correct, delete, or export your information.
- Because the Service is an append-only evidentiary record, corrections are generally made by adding new entries rather than by erasing prior ones, and closing a fund is a reversible "archive" action rather than a deletion. This preserves the integrity a transparency tool depends on.
- Because much of your fund data lives in your own iCloud/CloudKit account and on your device, you can exercise a great deal of control directly — for example, by editing entries, exporting a full archive, deleting the App, or removing the associated data from your Apple account.
- Where we do hold information (for example, account identifiers, web-published content, session data, and server logs), we will honor valid rights requests as required by law.
- Honest limitation. There is a real tension between (a) statutory rights to erasure and (b) the need to preserve an evidentiary record and to retain certain information for legal, tax, or platform-inquiry purposes, or where content has been published publicly and copied beyond our control. We will explain, when responding to a request, what we can and cannot do and why. Attorney note[ATTORNEY NOTE: Counsel must define the exact process, verification method, response timelines, and the lawful grounds for any refusal or partial fulfillment (e.g., GDPR Art. 17(3), legal-claims/records exemptions, CPRA exceptions), and ensure the Terms of Service and this policy are consistent.]
11.2 How to make a request. Contact To be completed[PLACEHOLDER — privacy contact email]. We will verify your request as required by law before acting. You will not be discriminated against for exercising your rights.
11.3 Camera and photo permissions. You can grant or revoke camera and photo access at any time in your device or browser settings.
11.4 EEA / UK (GDPR) rights. If you are in the EEA or UK, you have rights to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent and to lodge a complaint with your supervisory authority (To be completed[PLACEHOLDER — relevant supervisory authority]). See Section 5 for legal bases.
11.5 California (CCPA/CPRA) rights. If you are a California resident, you have rights to know, access, correct, and delete personal information, to obtain a portable copy, and to limit certain uses, subject to exceptions. We do not sell or "share" personal information (Section 10). You may exercise these rights via the contact above; you may use an authorized agent. Attorney note[ATTORNEY NOTE: Confirm applicability thresholds and add any other U.S. state-law disclosures (e.g., Virginia, Colorado, Connecticut, Texas) and the "categories collected/disclosed in the last 12 months" table required by CPRA.]
11.6 Other jurisdictions. To be completed[PLACEHOLDER — add rights/notices required in other jurisdictions where the Service is offered.]
12. International data transfers
12.1 The Service relies on Apple and Vercel, which may process and store information in the United States and other countries whose data-protection laws may differ from yours. Where we or our processors transfer personal information across borders, we rely on appropriate safeguards where required (for example, the EU Standard Contractual Clauses and the UK Addendum, or an applicable adequacy or certification mechanism). To be completed[PLACEHOLDER — specify transfer mechanism(s) relied upon.] Attorney note[ATTORNEY NOTE: Confirm the transfer mechanism for each processor and complete transfer-impact assessments as needed.]
13. Data retention
13.1 We retain personal information for as long as needed to provide the Service, and thereafter as necessary to comply with legal, tax, accounting, and record-keeping obligations, to preserve the integrity of an evidentiary record, to resolve disputes, and to enforce our agreements.
13.2 Records are designed to be preserved. Consistent with the Service's purpose, fund records are append-only and are retained rather than silently deleted; the product is oriented toward a multi-year retention expectation (for example, records that may be needed to answer a later audit, court, tax, or fundraising-platform inquiry). Much of this data resides in your own iCloud/CloudKit account, so its retention is also within your control. Attorney note[ATTORNEY NOTE: Confirm concrete retention periods for (a) account identifiers, (b) web-published content and Vercel Blob objects, (c) session data and server logs, and (d) support communications, and reconcile them with the erasure-rights analysis in Section 11.]
13.3 Content you have published publicly may persist in third-party copies, caches, or indexes even after you unpublish it or delete your account (Section 8).
14. Security
14.1 We use reasonable technical and organizational measures designed to protect personal information, including: on-device processing of receipts (so sensitive images are not sent to us or a third-party cloud AI to be read); storage in your own Apple iCloud/CloudKit account under Apple's security controls; encryption in transit for web connections (HTTPS); signed, HTTP-only session cookies; redaction and payment-method anonymization applied to shared/published copies; and access controls on web publishing that require authentication.
14.2 No method is perfectly secure. We cannot guarantee absolute security, and you are responsible for the security of your Apple ID and devices and for what you choose to publish. If we become aware of a breach affecting your personal information, we will notify you and authorities as required by law.
14.3 Attorney note[ATTORNEY NOTE: Confirm the security measures actually in place before finalizing, including at-rest encryption for any Vercel Blob objects, access-control specifics for published/private content, and breach-notification procedures.]
15. Children's privacy
15.1 The Service is not directed to children and is intended for users who are at least To be completed[PLACEHOLDER — age minimum] years old. We do not knowingly collect personal information directly from children below that age. If you believe a child has provided us personal information, contact To be completed[PLACEHOLDER — privacy contact email] and we will take appropriate steps.
15.2 Fundraisers may concern or benefit minors, and Organizers may upload documents containing minors' personal information. If you are an Organizer, you are responsible for having the right and any necessary consent to include and, where applicable, to publish such information, and for redacting what should not be public (see the Terms of Service and Section 8). Attorney note[ATTORNEY NOTE: Address COPPA (U.S.), GDPR Article 8, the UK Age Appropriate Design Code, and analogous regimes, and decide what additional safeguards or restrictions apply when an Organizer publishes information about a minor or vulnerable person. This is a heightened-risk area.]
16. Changes to this policy
16.1 We may update this policy from time to time. If we make material changes, we will take reasonable steps to notify you (for example, by updating the "Last updated" date and, where appropriate, an in-app or on-site notice). The current version governs your use of the Service. Please review it periodically.
17. Contact us
Questions, concerns, or privacy requests:
- Privacy contact: To be completed[PLACEHOLDER — privacy contact email]
- Data protection officer / representative (if any): To be completed[PLACEHOLDER — DPO / EU-UK representative]
- Entity and mailing address: To be completed[PLACEHOLDER — legal entity name and business mailing address]
End of Privacy Policy draft. Remove all Attorney note[ATTORNEY NOTE] comments and complete all To be completed[PLACEHOLDER] fields before publication. Ensure this policy remains an accurate description of the product's actual data practices; update it whenever those practices change. Do not publish without review by a licensed attorney in the applicable jurisdiction.