User Data Privacy Statement
Privacy Policy
Effective from March 31, 2026
Senti ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how personal information is collected, used, and disclosed when you use mysenti.vercel.app, its associated subdomains, and @SentiMoneyBot on Telegram (together, the "Service").
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy and the way your information is handled as described here.
Summary
- Senti is currently operated and managed individually by Ikimi Stephen. That may change in the future, and this policy will be updated if it does.
- We are doing our best to align Senti with the principles and obligations of Kenya's Data Protection Act, 2019. Privacy, minimization, security, and user control are treated as ongoing product responsibilities, and more improvements will continue to roll out over time.
- Senti uses your Telegram-linked identity and the finance information you submit to operate expense capture, reporting, budgeting, and Ask AI features.
- Senti currently uses OpenAI as its only third-party AI provider, and Vercel Analytics as its current website analytics provider. If that changes materially, this policy will be updated.
- We do not sell your personal data. Access to customer data is intended to stay limited to service operations, support, security review, audit trails, bug investigation, and product improvement.
- Senti is built to minimize retained raw customer content after processing. At the same time, limited internal operational and security logging may still retain some customer input where needed for debugging, abuse prevention, or service hardening.
- Senti uses Telegram platform controls together with backend safeguards and provider security controls. We do not state that Telegram bot chats are end-to-end encrypted.
Who Operates Senti
Senti is currently operated solely by Ikimi Stephen. This individual-operator structure may change in the future, and if ownership or operating responsibility changes, this Privacy Policy will be updated to reflect that.
Privacy, legal, support, AI opt-out, and deletion requests are currently handled manually. If you want to opt out of AI-enabled features, ask for deletion of your data, raise a correction request, object to processing, or make a legal/privacy inquiry, contact @IkimiSteves on Telegram.
Built by Ikimi Stephen
Senti was built by Ikimi Stephen in March 2026 after trying to find a low-friction way to track personal expenses for personal use and finding no solution that felt right. Then vibe coding came along, and he decided to build the tool he actually wanted.
Ikimi is a medical school graduate, passionate about AI, and yes, he has a MacBook. It's cool. You should get one -:).
Personal Data Under Kenyan Law
Under Kenya's Data Protection Act, 2019, personal data broadly means information relating to an identified or identifiable natural person. In practice for Senti, that includes data points such as your Telegram identifiers, your names or username where provided through Telegram, message content you send to the bot, structured expense records linked to you, and service logs that can be tied back to your account or activity.
Some finance-related information may be especially sensitive in context, even where every field is not separately classified as sensitive personal data. Senti therefore treats customer finance records and transaction-derived information as confidential user data that should receive elevated care.
Information Senti Collects
Senti currently handles the following categories of information:
- Telegram-linked account data, such as your Telegram user ID, chat ID, first name, last name, username, and language code where available.
- Finance and usage inputs you send to the bot, including plain-text expenses, forwarded or pasted M-PESA transaction messages, budget-related messages, Ask AI prompts, and report requests.
- Structured finance records derived from those inputs, such as expense labels, dates, amounts, subcategory assignments, confirmations, summaries, budget allocations, learned categorization rules, and other user-owned finance records.
- Onboarding, security, and operational data, such as activation events, rate-limit events, access-control events, and session or invite lifecycle data.
- Website analytics data currently collected through Vercel Analytics, which helps us understand aggregate website usage on the public web surface.
How Senti Uses Information
Senti uses personal information to:
- identify, activate, and support users within the Telegram-based bot experience;
- record, organize, and display expense, budget, and reporting information;
- generate insights and Ask AI responses grounded in stored finance records and tool outputs;
- improve parsing accuracy, including learned categorization behavior based on confirmed user actions;
- protect the product against abuse, unauthorized access attempts, and operational failures;
- review narrowly scoped data where necessary for support, bug investigation, audit logging, or service hardening; and
- comply with legal obligations where applicable.
Senti does not describe these purposes as unlimited or unrelated secondary uses. Personal data is intended to be used only for running, protecting, supporting, and improving the Service in ways connected to its finance-tracking functionality.
Expense Parsing, Minimization, And Retention
Senti accepts expense-related input through plain natural-language text and M-PESA-style transaction messages.
The service is designed to reduce raw inputs into the minimum structured information needed to operate the product, such as amount, date, short expense label, category assignment, and related user-owned finance records. Retention controls are also implemented for some expiry-bound system records, including cleanup of expired sessions and aged-out expired invites.
At the same time, the current system still retains some limited raw or near-raw customer input in internal operational paths, including telemetry and review flows used for debugging, audits, abuse prevention, and product improvement. For that reason, this policy does not state that every raw input is immediately destroyed everywhere after processing. Instead, the current position is:
- raw customer content is intended to be minimized after use;
- structured finance records are retained as part of the user's ongoing ledger and product history;
- operational and security logs may retain limited information for support, audit, reliability, and abuse-prevention purposes; and
- retention behavior will continue to tighten as minimization work evolves.
OpenAI Processing
Senti uses OpenAI as its only third-party AI provider.
OpenAI-backed processing is currently used for:
- extracting structured expense candidates from plain-language messages;
- classifying report intent from report-style requests;
- fallback categorization assistance when deterministic rules do not confidently resolve a category;
- generating finance insights; and
- powering Ask AI finance-chat responses that work from stored finance data and tool outputs.
Senti is designed to send only the data needed for the relevant AI task. Depending on the feature, that may include user-submitted text, normalized payee names, budget taxonomy data, summarized spending data, prior chat context needed for continuity, and tool-grounded finance context.
Senti uses the OpenAI API data controls documentation and OpenAI's business data privacy, security, and compliance overview as the baseline public references for how OpenAI handles API customer data. Senti does not state that OpenAI stores nothing at all. Where OpenAI processing is used, provider-side retention, abuse monitoring, and endpoint-specific storage behavior may still apply under OpenAI's published controls.
Security
Senti uses a combination of Telegram platform controls and its own backend safeguards.
Current safeguards reflected in the product include:
- Telegram webhook secret verification at the server boundary;
- restricted server-side and internal backend access paths for protected finance operations, together with infrastructure protections documented in Convex's platform security overview and Convex's note on end-to-end encryption patterns;
- user-status and ownership checks for protected actions;
- rate limiting and security-event logging for onboarding and bot access paths; and
- hashed activation tokens for onboarding flows rather than raw-token database storage.
Senti also relies on encrypted platform-managed storage and transport protections supplied by its infrastructure providers. However, Senti does not claim that Telegram bot chats are end-to-end encrypted. Telegram distinguishes ordinary cloud chats from Secret Chats, and the Bot API does not support Secret Chats.
Rights, AI Opt-Out, And Deletion
Depending on applicable law, you may have rights to request access to your personal information, ask for correction of inaccurate information, object to certain processing, or request deletion or erasure in appropriate circumstances.
Senti does not currently offer a self-service privacy dashboard, self-service AI preference center, or self-service account deletion flow. If you want to opt out of AI features or request deletion of your data, contact @IkimiSteves on Telegram and the request will be handled manually.
Current product limitations do not waive any rights you may have under applicable law.
Cross-Border Processing
Because Senti uses third-party infrastructure and API services, some processing may take place outside Kenya.
Where cross-border processing occurs, Senti intends to rely on provider safeguards, contractual terms, technical controls, and organizational controls appropriate to the service. This policy does not claim a specific transfer mechanism unless and until it has been formally adopted and documented.
Children
Senti is not intended for children unless the service is expressly made available under an appropriate consent and supervision framework. If Senti learns that it has collected information in a way that requires different treatment under applicable law, it may restrict, review, or delete the affected data.
Policy Updates
Senti may update this Privacy Policy from time to time to reflect product changes, legal developments, security improvements, ownership changes, or new user controls.
The current version is effective as of March 31, 2026.