Kesse connects to no bank, keeps no transaction history, asks for no permissions and sends nothing anywhere. What it measures is one number per period, and that needs none of those things. This page says exactly what that means and how each sentence is checked.
Every other app in this category connects to your accounts. That means your transaction history is readable by whoever operates the service, and it is the single largest privacy cost in personal finance software. Kesse cannot connect and will not: there is no network code of any kind in it, and the build fails if FinanceKit, ASWebAuthenticationSession, URLSession, URLRequest, CFNetwork, NWConnection, StoreKit or CLLocationManager appears in the sources.
The period totals you typed, the category names you chose, whether you are working in months or weeks, and the amount on hand if you entered one. All of it lives in this app on this device. Deleting the app deletes all of it, because there is nowhere else it exists.
There is no transaction record — no merchant, no time of day, no description — because there is no field for one. This is not an omission to be filled in later. Kesse asks for a period total on purpose: a transaction log you stop keeping is worse than none at all, because you forget it is incomplete and read its total anyway. The build fails if such a field appears in the stored entry type.
One line, and only if you have a paired Apple Watch with the Kesse watch app open: the verdict, the typical period with its band, the number of periods, and the range your money lasts. The period totals themselves never go. That line travels over Apple’s own device link between your phone and your watch and does not reach the internet. If you have no watch, nothing leaves the device at all.
Each claim above corresponds to a check that runs on every build and fails the build if the claim stops being true. The source is scanned with comments stripped for the network and finance symbols listed above, separately for CNContact, CNContactStore, ASIdentifierManager, identifierForVendor and ATTrackingManager. The stored entry type is scanned for any field that would turn it into a transaction record. Every permission key that must be absent is checked for absence. A privacy promise nobody measures is worse than none at all, because people rely on it.
Kesse is a measuring tool. It reports statistics on numbers you typed in and never recommends an action, a product, a provider or an amount. It is not affiliated with any bank, broker or lender, and it is not a regulated financial service.
Kesse contains no user-generated content that anyone else can see, no messaging, no web browsing and no advertising. It has nothing to collect from anyone, of any age. Rated 4+.
If any of this ever changes, this page changes with the release that changes it, and the corresponding build gate changes too — they cannot drift apart.
Questions: hello@norea.studio.