BACK

Privacy Policy

Effective date: 13 September 2026

Pelana is operated by Adrianto Dwitomo (publicly known as Adri Dwitomo), an individual based in Singapore ("Pelana", "we", "us", or "our"). This Privacy Policy explains how information is handled when you use the Pelana website and, when available, the mobile application, related support channels, and services used to deliver subscriptions or optional on-device AI models. The website currently offers a free early-access waitlist and support contact; it does not take subscription payments.

Pelana is designed around a local-first principle: your day-to-day financial records and Pela conversations are intended to stay on your device rather than being uploaded to a Pelana server.

1. Who is responsible for your data

The individual responsible for Pelana is:

Adrianto Dwitomo (Adri Dwitomo)

Singapore

Privacy / data-protection contact: Adri Dwitomoadri@pelana.app

If applicable under local law, this contact also serves as Pelana's public data-protection contact.

2. What this Policy covers

This Policy covers information handled through:

  • the Pelana website and early-access waitlist;
  • the Pelana iOS application;
  • Pelana's subscription and entitlement functionality;
  • optional download of Pelana's on-device Private AI model; and
  • communications you choose to send to Pelana support or privacy contacts.

It does not replace the privacy policies of Apple, RevenueCat, Hugging Face, your mobile carrier, or other third-party services you choose to use.

3. Pelana's local-first design

Financial and planning data

Information you enter or create in Pelana — such as transactions, account labels and balances, categories, budgets, goals, recurring items, notes, imported rows, currencies, and planning information — is designed to be stored locally on your device in Pelana's app storage.

Pelana does not operate a server-side financial profile for this information in the current version of the app.

Pela conversations and Private AI

Pela can use an optional AI model that runs locally on your supported device. When the local model is used, your prompts, financial context supplied to the model, and generated responses are processed on your device. Pelana does not send those conversations to Pelana servers for AI training.

Onboarding, preferences, and game progress

Your onboarding answers, selected Adventurer, local preferences, Adventure progression, XP, and Adventure Coins are designed to be stored locally as part of your app data unless a feature expressly tells you otherwise.

Device motion

Pelana may use device-motion information for visual interactions such as the Quest Card tilt effect. This sensor input is used for the on-screen interaction and is not intended to be transmitted to Pelana as a user profile.

4. Information that may leave your device

Even though Pelana is local-first, a limited amount of information is processed by third parties when you use certain features.

A. App Store purchases and subscriptions

Pelana uses Apple's in-app purchase system and RevenueCat to offer and verify Quest Card / Pelana subscription access.

Depending on the configuration and transaction, Apple and/or RevenueCat may process information such as:

  • subscription product and purchase history;
  • Apple receipt or transaction information;
  • entitlement status and expiration information;
  • an anonymous or app-specific customer identifier; and
  • limited technical information needed to operate, validate, restore, and troubleshoot purchases.

Pelana does not receive your full payment-card details from Apple. Your local financial ledger and Pela conversation content are not sent to RevenueCat merely because you subscribe.

B. Private AI model download

If you choose to download Pelana's Private AI model, the app connects to the model host and its storage/CDN infrastructure, currently Hugging Face-hosted infrastructure. As with an ordinary internet download, the hosting provider may receive request metadata such as your IP address, device/network information, request time, and the model file requested.

The model-download request does not need to include your Pelana financial records, budgets, transactions, or Pela conversation content.

Once downloaded, the supported model is intended to run locally on your device.

C. Support and privacy communications

If you contact us, we receive the information you choose to provide, which may include your email address, message, screenshots, logs, or other attachments. Please avoid sending unnecessary financial or sensitive information in support messages.

We use support information to respond to you, investigate issues, keep appropriate support/security records, and meet legal obligations.

D. Website waitlist and support form

If you join the early-access waitlist through this website, we collect your email address and limited referral or campaign information such as UTM parameters and referrer. The website uses Supabase to store the waitlist record and Resend to manage the related email contact and send an eligible one-time confirmation. This website form does not offer a product-update opt-in or create a new marketing subscription. If you previously gave consent, a repeat submission through this form does not erase that historical choice.

If you use the website support form, we send your selected topic, name, email address, and message to adri@pelana.app through Resend so we can reply. The message is not added to the waitlist or stored in Pelana's Supabase waitlist table. Our email provider may process and retain delivery records or message content under its service terms. Please do not include account numbers or financial details in the form.

Vercel hosts the website and may process normal connection and request information needed to deliver and protect it. The waitlist and support forms also use a hidden spam field and basic request limits.

5. How we use information

Where Pelana or its service providers process information, it is used only for purposes such as:

  • providing and maintaining Pelana;
  • storing and presenting your local finance and planning data;
  • running Pela and the optional Private AI on your device;
  • processing, verifying, restoring, and managing subscription entitlements;
  • delivering the optional model download;
  • protecting Pelana against fraud, security incidents, abuse, or technical failures;
  • responding to support, privacy, or legal requests; and
  • complying with applicable law and App Store requirements.

We do not use your local financial ledger or local Pela conversations for targeted advertising.

6. What Pelana does not do

In the current version of Pelana:

  • we do not sell your personal information;
  • we do not share your personal information for cross-context behavioural advertising;
  • we do not run third-party advertising in the app;
  • we do not use your local financial records or local Pela conversations to train a Pelana-hosted AI model; and
  • downloading the Private AI model does not upload your financial records or conversations to the model host.

If Pelana's practices materially change, we will update this Policy and the App Store privacy disclosures as required before or when the change takes effect.

7. Service providers and disclosures

Pelana relies on a small number of third parties for specific functions:

Apple

Apple processes App Store downloads, in-app purchases, subscription billing, receipts, refunds, and Apple-account subscription management under Apple's own terms and privacy practices.

RevenueCat

RevenueCat provides subscription infrastructure used to validate purchases and determine subscription entitlements. RevenueCat may process purchase history, receipt/transaction information, technical information, and app/customer identifiers needed to provide that service.

Hugging Face / model-delivery infrastructure

Hugging Face-hosted services and related CDN/storage endpoints currently deliver the optional on-device model file. They may receive normal network/download metadata. They are not used by Pelana to process your local finance data or local Pela prompts as part of the model download.

Support and operational providers

If you contact us, providers used for email, hosting, or support may process the information necessary to deliver that communication or host Pelana's public legal/support pages.

Supabase stores the website waitlist record. Resend processes waitlist contacts, confirmation delivery, optional product-update preferences, and support-form email delivery. Vercel hosts and serves the website. These website flows do not receive your local financial ledger or Pela conversations.

Legal and security disclosures

We may disclose information that we actually possess or control when we reasonably believe disclosure is required to comply with law, enforce legal rights, investigate fraud or security incidents, or protect users, Pelana, or the public. We cannot disclose local Pelana data that we do not possess.

We select and use service providers for defined purposes and expect them to protect information consistently with applicable law and their contractual obligations.

8. Legal bases where required

Depending on your location and the type of processing, Pelana may rely on one or more of the following legal bases:

  • performance of a contract, such as providing Pelana and verifying your subscription;
  • consent, where you make an optional choice or where consent is required by law;
  • legitimate interests, such as securing Pelana, preventing abuse, and maintaining the service, where those interests are not overridden by your rights; and
  • legal obligations, such as responding to valid legal requests or retaining records required by law.

Where processing is based on consent, you may withdraw that consent. Withdrawal does not make earlier lawful processing unlawful and may affect the optional feature that depended on the consent.

9. Retention and deletion

Data stored only on your device

Local Pelana data generally remains on your device until you edit or delete an individual supported record, remove a downloaded model, or uninstall the app. The current release does not enable a complete in-app deletion control. Deleting the app normally removes its local app container from that device, subject to operating-system behaviour and any copies or backups you separately created.

Uninstalling Pelana does not cancel an App Store subscription. Subscription cancellation is managed through Apple.

Backups and exports

Pelana contains backup and export foundations, but financial CSV export and encrypted-backup controls are not enabled in the current release. If a future release enables an export or encrypted backup, any copy you create will remain wherever you save or share it until you delete it. You will be responsible for protecting exported copies, and Pelana will not be able to recover a passphrase it does not possess.

Private AI model

The downloaded model remains on the device until you remove it using available model-management controls, clear Pelana's local data, or uninstall the app, subject to operating-system behaviour.

Subscription records

Apple and RevenueCat retain purchase, receipt, entitlement, and related records according to their own legal, accounting, fraud-prevention, and service requirements. Pelana may need limited subscription status to support restore and access decisions even after a subscription expires.

Website waitlist records

We keep waitlist contact details while the early-access programme is active or until you ask us to remove them, unless a longer period is reasonably needed for a legal or security purpose. You can request removal or withdraw any earlier product-update consent by emailing adri@pelana.app. Withdrawing product-update consent does not by itself remove your waitlist place; tell us if you also want the record deleted. We may retain a limited record needed to honour an opt-out or meet legal obligations.

Support records

Support/privacy communications are retained only as long as reasonably needed to resolve the request, maintain security or business records, establish or defend legal claims, or meet legal obligations.

10. Your choices and privacy rights

Pelana's current release lets you review and correct supported financial records and remove downloaded Private AI models. Financial CSV export, encrypted backup, and a complete in-app deletion control are not enabled in this release.

The current release pauses access to the main app, including these in-app controls, when a paid Quest Card entitlement ends. Cancellation or expiry does not erase the local data. You can contact the privacy address below about a rights request. Because financial records are stored locally and are not available to us, we generally cannot retrieve, correct, export, or delete records on your device for you.

For information Pelana or a service provider controls, you may also have rights under applicable law, including rights to:

  • know or be informed about processing;
  • access personal data;
  • correct inaccurate data;
  • request deletion or erasure;
  • restrict or object to certain processing;
  • receive portable data where applicable;
  • withdraw consent where processing depends on consent; and
  • complain to a competent data-protection authority.

These rights may be subject to legal exceptions. We may ask for information reasonably necessary to verify a request before disclosing or deleting information.

To make a privacy request, contact Adri Dwitomo at adri@pelana.app.

For purchase records controlled by Apple, subscription management, cancellation, and certain purchase/privacy requests may need to be handled through your Apple Account or Apple directly.

California residents

If the California Consumer Privacy Act or similar California law applies to Pelana and to your information, you may have rights to know, access, correct, delete, opt out of sale or sharing, limit certain uses of sensitive personal information, and exercise those rights without unlawful discrimination.

Pelana does not sell personal information or share it for cross-context behavioural advertising in the current version of the app.

EEA / UK users

Where the GDPR or equivalent law applies, you may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, as applicable to the processing at issue.

Singapore users

Where Singapore's Personal Data Protection Act applies, you may have rights and protections relating to notification, consent, access, correction, protection, retention, and overseas transfers, subject to statutory exceptions.

11. Security

Pelana uses reasonable technical and organisational measures designed for a local-first finance application. The release architecture is designed to keep financial records in local app storage and to protect sensitive local data with encryption and platform security mechanisms where applicable.

You are also responsible for protecting your device, device passcode, Apple Account, exported files, and backup passphrases.

No software, device, network, encryption system, or storage method can be guaranteed absolutely secure. If we learn of a security incident involving personal information under our control, we will investigate and provide notices required by applicable law.

12. International processing

Apple, RevenueCat, Hugging Face, and other operational providers may process limited information in countries other than the country where you live. Where applicable law requires safeguards for international transfers, we will rely on lawful transfer mechanisms or providers that offer appropriate protections.

13. Children

Pelana is not directed to children under 13. If the law where you live requires a higher age to consent independently to data processing or enter into these Terms, you should use Pelana only with the involvement and permission of a parent or legal guardian as required by law.

If we learn that information under our control was collected from a child in violation of applicable law, we will take appropriate steps to delete or otherwise address it.

14. Changes to this Policy

We may update this Privacy Policy to reflect changes in Pelana, legal requirements, security practices, or service providers. We will update the effective date and, where required or appropriate, provide additional notice in the app or through another reasonable channel.

If a change requires your consent under applicable law, we will seek that consent rather than relying only on continued use.

15. Contact

Contact person: Adri Dwitomo

Privacy and data-protection questions or requests: adri@pelana.app

Support: adri@pelana.app

Operator / data controller:

Adrianto Dwitomo (Adri Dwitomo)

Singapore