Privacy policy
What Clementine collects, why, who else handles it, and what you can do about it. Written to be read.
The short version
- Clementine keeps the money records you put into it so it can show them back to you. That is the only reason it has them.
- It does not sell your information, share it for advertising, or use it to market financial products to you.
- A small number of services process it so the app can work. Each one, and exactly what it sees, is listed on Your data.
- You can download everything, correct it, and ask for it to be deleted.
1. Who we are
“Clementine”, “we” and “us” mean the business that makes the Clementine app and this website. Its registered name and ABN will be printed here before sign-ups open. It is based in Australia.
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, whether or not the Act requires it of a business our size.
To ask anything about this policy or your information, write to the contact address that will be published on this page before sign-ups open.
2. What we collect
If you only visit this website
Nothing that identifies you. The site has no analytics, no advertising cookies and no code from other companies. Like any website, the servers that deliver it (Cloudflare) receive your internet address and the page you asked for in order to send it to you.
If you join the founding-member list
- your email address;
- whether you chose “household”, “side hustle” or neither;
- which page you joined from, and the date and time you ticked the consent box;
- a scrambled fingerprint (a keyed hash) of your internet address and of your browser’s description. These are used only to stop the form being flooded. The address and the description themselves are not stored, and the fingerprints cannot be turned back into them.
If you have a Clementine account
- Account details: your email address, a scrambled (hashed) password, the name you give, and your setup choices.
- Your money records: what you enter, import or connect. Transactions, account names and balances, categories and limits, bills and subscriptions, savings goals, invoices and the clients on them, income, deductions, receipt photos and tax settings.
- Connections you choose to make: the key for your bank feed, the permission you give for Gmail, and your AI key. Each is encrypted before it is stored.
- Your plan: which plan you are on, when it renews or ends, and a reference to your customer record at Stripe. Not your card.
- What you send us: emails you write to us and our replies.
Your records may include information about other people, such as the name and email address of a client on an invoice. Please only add what you are entitled to share with us.
What we do not collect
- Your bank login. You connect your banks with the bank-feed provider, not with us.
- Your card number. You type it on Stripe’s page.
- Your tax file number. Clementine does not ask for it, and you should not enter it.
- Your location, your contacts, or anything about how you use other apps.
We do not ask for sensitive information such as health or political details. A transaction description can reveal that kind of thing, and we treat all of your records with the same care for that reason.
3. Why we collect it and how we use it
- To run the app: to show you your own money, sort it, total it, remind you of what is due, and prepare the invoices, estimates and worksheets you ask for.
- To run your plan: to start your trial, take payment through Stripe if you choose a paid plan, and tell you about your account.
- To keep it working and safe: to find faults, prevent misuse and answer you when you ask for help.
- To email the founding list, once, when founding places open, and after that about your founding membership.
We do not use your information for anything else. We do not build advertising profiles, we do not sell or rent information, and we take no payment from any lender, insurer or other company for access to you.
Nobody at Clementine reads your records in the ordinary course of things. If you ask for help with a problem that can only be understood by looking, we will ask you first.
4. Who else handles it
These services process information for us, or for you, so the app can work. None of them may use it for their own marketing. The full table, with exactly what each one sees and how to switch it off, is on Your data.
- Supabase: database, sign-in and file storage. Everything in section 2 that belongs to an account, and the founding list.
- Cloudflare: delivers this website and the web app.
- PocketSmith: bank feeds, if you connect one. You hold that account with PocketSmith directly, under its terms.
- Google: Gmail, if you connect it, and the Gemini AI model, if you turn AI sorting on. AI sorting sends the public name of a business and your category names, never amounts, dates or account details.
- Stripe: payments, if you choose a paid plan.
We may also disclose information if the law requires it, such as under a court order, and we will tell you if we are allowed to.
Outside Australia
Some of these services store or process information outside Australia. PocketSmith is based in New Zealand, and Google, Stripe, Cloudflare and Supabase are based in the United States and operate data centres in many countries. The country and region where Clementine’s own database is hosted will be confirmed here before sign-ups open. We choose services that commit to protecting information to a standard comparable to the Australian Privacy Principles.
5. Email from us
We only send marketing or announcement email to people who asked for it by ticking the consent box on the founding-list form. Every such email says who it is from and has an unsubscribe link that works, and we act on an unsubscribe within five working days, as the Spam Act 2003 requires. We do not buy lists or pass yours on.
If you have an account we will also send what is needed to run it: sign-in emails, receipts and notices about your plan. Those are not marketing and do not need a subscription.
6. How we protect it
- Everything travels between your device and our servers over an encrypted connection.
- The database enforces, row by row, that an account can read and change only its own records.
- The keys for your bank feed, Gmail and AI are encrypted before they are stored, and are never sent back to your device.
- Passwords are stored only in hashed form. Card details never reach us.
No system is perfectly secure, and we do not claim a certification we do not hold. If something does go wrong, section 9 says what we will do.
7. How long we keep it
- Your account and records: for as long as you have an account. A plan ending does not delete anything; you move to Free.
- The founding list: until you unsubscribe or ask to be removed, or until the founding offer has closed and been delivered.
- Payment records: for as long as tax and accounting law requires us to keep them.
- Emails with us: for as long as they are needed to deal with what you raised.
When information is no longer needed we delete it or remove what identifies you.
8. Seeing, correcting and deleting your information
- See it. Almost everything we hold about you is in the app in front of you. You can also download all of it at any time, on any plan: how to export.
- Correct it. You can edit your records and details in the app. If something is wrong that you cannot change yourself, tell us and we will fix it.
- Delete it. You can ask us to delete your account and everything under it: how to delete your account.
- Ask us. You can ask what we hold about you and how it has been used. We will answer within 30 days and will not charge you for asking.
You do not have to give us any particular information. If you choose not to connect a bank, Gmail or AI, Clementine works without them, with more to enter by hand.
9. If there is a data breach
If information we hold is lost or accessed without authority in a way that is likely to cause serious harm, we will tell the people affected and the Office of the Australian Information Commissioner as soon as we practicably can, say what happened and what it involved, and say what you can do.
10. Complaints
If you think we have mishandled your information, write to the contact address that will be published on this page before sign-ups open. We will reply within 30 days. If you are not satisfied with the answer you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
11. Age
Clementine is for people aged 18 and over. We do not knowingly collect information from anyone younger.
12. Changes to this policy
When this policy changes we will update the date at the top. If a change affects how your information is used in a way you would not expect, we will tell account holders by email before it takes effect.