Privacy Policy
This is a translation. If the English and Thai versions differ, the Thai version applies. The app itself is in Thai — menu names here are translated: Me = ฉัน · Help = ช่วยเหลือ · Help improve Pak-Jod = ช่วยพัฒนาผักจด · Backup = สำรองข้อมูล · For you to check = รอคุณดู.
In short
- Your transactions and accounts stay on your iPhone, backed up to your own iCloud Drive · Slip photos stay in your photo library — the Pak-Jod team can't access them
- No account, no ads, no trackers
- Data is sent only when you turn it on (Help improve Pak-Jod) or tap send on a problem report, feedback or an answer
- You can delete what you've sent from inside the app
1. Data on your iPhone
Pak-Jod reads slip photos from the albums of the banking apps you allow, and turns them into transactions on your iPhone. All of it is stored on your iPhone. We have no server of our own, there is no login, and we cannot see this data.
- Transactions, your accounts, recurring items, names you've set, and the text read from slips — used to show summaries and to tell transfers between your own accounts apart
- A summary for widgets (left to spend, spent today, recurring item names) — stored in a file shared by the app and its widgets on your iPhone; amounts are hidden while the iPhone is locked
- A 7-day activity log (no names, account numbers or amounts) — old entries are deleted automatically; it is only used if you send a problem report
- Photos stored in iCloud Photos may be downloaded by iOS before they are read — this is done by your own iOS and iCloud
Deleting the app without a backup (section 2) deletes all data on your iPhone.
2. Backups in your iCloud Drive
- Pak-Jod backs up the data in section 1, plus your settings, report history and anything still waiting to be sent (not slip photos or logs), as a
.pakjodfile to your own iCloud Drive once a day — on by default, turn it off at Me › Backup - The files are in your iCloud storage (kept by Apple, using your space) in a folder named "ผักจด" · the Pak-Jod team cannot access them · The app does not go online itself — it writes the file on your iPhone and iOS uploads it
- Slip photos aren't in the backup (they're already in your photo library). The file keeps each photo's ID and time, so after a restore the app can find the same photo in your library and link it again — on your iPhone, the same way it reads slips
- The last 7 days + 4 weekly backups are kept (older ones are deleted automatically) · Delete them in the app or in the Files app
- Reinstall the app or move to a new iPhone with the same Apple ID → the app finds the file and asks whether to restore · Restoring replaces all data on the iPhone (the app keeps a "before restore" copy first)
- Export to a file (no password) → the file contains all your financial data and is in your care once exported
3. Permissions the app asks for
- Photos: reads photos only in albums created by banking apps (such as K PLUS, SCB EASY) to read the QR code and text on slips — on your iPhone, photos are never uploaded · The app does not open photos in other albums (it only sees album names and photo counts, used in section 4 when you turn it on or tap send) · iOS has no read-only option, so the app asks for read/write access but never edits or deletes photos · The only thing it writes: slip photos you share into Pak-Jod yourself, saved to a "ผักจด" (Pak-Jod) album in your photo library (without full photo access, a copy is kept inside the app instead) · "Limited" access works too
- Sharing a slip into Pak-Jod: photos you share from another app (such as a slip a friend sent in a chat) are read on your iPhone like slips from banking albums, and never sent anywhere
- Notifications: local notifications only (payday, daily summary), no push from a server
- Face ID / Touch ID (if you turn on App Lock): iOS does the check and only tells the app "passed / failed" — the app never sees face or fingerprint data
4. Data sent to the team only when you choose
Apart from backups in your own iCloud (section 2), nothing leaves your iPhone except in the 3 cases below. All of them go to Apple's iCloud (CloudKit), in Pak-Jod's own space.
4.1 Help improve Pak-Jod (off until you turn it on)
Turn on or off at Me › Help improve Pak-Jod. There are 3 separate switches.
| Switch | What is sent | When |
|---|---|---|
| Misread slip samples | The slip text with names replaced by [name-A] and every digit (including amount, date and time) replaced by random digits in the same format · bank · reader used · why it was flagged · what kind of thing you corrected (no real values) · app and iOS version | When you confirm or correct a transaction the app misread (once per slip, at most 20 per day) |
| Shop names and categories | The shop name (with company words, branch numbers and road / soi / district removed) and the category you chose | When you set or change the category of a transaction from a slip — only names that look like shops; people's names, your name and transfers to your own accounts are never sent |
| Slip reading stats | Weekly counts per bank, reader and slip layout: how many slips were read, flagged, corrected by you, deleted, and had no QR ("slip layout" is a code computed from the order of the labels on the slip after names are hidden) · names of not-yet-supported finance apps that have an album on your iPhone (only names on the app's built-in list, such as TrueMoney) and the number of photos in that album · the number of other albums whose names look like finance apps (count only, no names) · app and iOS version | Once a week, only for weeks that had slips |
Never sent: slip photos, original slip text, real amounts and dates, account numbers, your name and the names of people you pay, notes, and names of albums that are not on the finance app list · Before sending a slip sample the app checks it again; if the check fails, that slip is not sent · See a preview made from your real data under "Preview what's sent".
4.2 Problem reports and feedback (sent only when you tap send)
From Me › Help › Report a problem or Send feedback to the team (or from an error message in the app) — this does not need "Help improve Pak-Jod" to be on · You can read everything before sending under "See what will be sent" · or choose "Send with another app" (Mail, LINE, AirDrop, etc.)
- 7-day activity log (optional): step names, counts, durations, memory used by the app, error codes — no names of people or shops, account numbers, phone numbers, reference numbers, amounts, slip text, photos or notes
- Device info (optional): app and iOS version, device model, language, photo and notification permission status, number of transactions, time zone, the settings used to calculate your balance such as payday and transaction counts (no amounts), and the names and photo counts of the albums on your iPhone (used to learn what banking apps name their albums — no photos)
- Crash information (if any) — a stack trace from iOS
- Masked slip text (only when reporting from a transaction and you tick it): names become [name], account and reference numbers become x, and the amount of that slip is included; the slip photo is not attached
- The message, contact details and screenshots (up to 2) that you add yourself — sent as entered
- "Send feedback" leaves the log and device info unticked (you can tick them)
4.3 Answers to short in-app questions (sent only when you tap send)
Sometimes a question appears in "For you to check" (answering is optional) · Tapping "Send answer" sends: the options you picked, any text you typed (the "Other" field and the comment field), and the app version · One answer per question per device; answering again replaces it · Turn questions off at Me › Help improve Pak-Jod › In-app questions
For all 3 cases
- Stored in: Apple's iCloud (CloudKit), which may be outside Thailand; permissions are set so other people cannot read it — only the developer can (and you can read your own) · Requires being signed in to iCloud on your iPhone; if it can't be sent yet (no internet, not signed in), the app keeps it on your iPhone and sends it later
- Who sent it: Apple attaches a random ID that is unique to this app (not your Apple ID, email or name) — we can tell that several items came from the same device, but not who you are, unless you add contact details to a report
- Why: only to fix problems, improve slip reading and categories, and decide what to build next
5. How long we keep it, and deleting it
- Help improve Pak-Jod (including reading stats) and answers to questions: up to 12 months (old data is deleted every month)
- Problem reports and feedback: up to 90 days
- Data that has had personal details removed, or has been combined into statistics that can't identify anyone (such as shop names with categories, masked slip text samples, survey results), may be kept longer than the periods above to improve the app — with no sender IDs, contact details, screenshots or logs
- Delete it yourself any time: Me › Help improve Pak-Jod › Delete everything I've sent (deletes slip samples, shop names, stats and answers sent from this device) · Help › Sent reports (swipe left = also deletes it from iCloud)
- Withdraw consent: turning a switch off stops sending immediately and clears anything waiting to be sent for that switch · turning off "In-app questions" stops the questions
6. No ads, no trackers
The app uses no third-party advertising, analytics or crash-reporting SDKs and does not track you across apps · We do not sell or share your data, or use it for advertising · This website has no cookies, no analytics, and loads nothing from other websites.
7. Children
Pak-Jod is not designed for children, and we do not knowingly collect children's data.
8. Your rights (Thailand PDPA)
You can ask to access, correct or delete data you have sent by emailing us below (include the report code, such as PJ-7F3K2, if you have one) · Help-improve data and answers can be deleted in the app (section 5) · Everything else is on your iPhone and in your iCloud.
9. Changes to this policy
If the app starts sending a new kind of data, we will update this policy and ask you in the app before it starts · The effective date is at the top of this page.