Institutional Privacy Manifesto
Adopted in the interest of user sovereignty, financial dignity, and institutional-grade transparency.
The Behavioral Firewall
SpendSitter implements what we call a Behavioral Firewall: a protective layer that sits between you and impulse spending without ever observing, recording, or transmitting your financial activity. In an economy engineered to bypass deliberation—one-click checkout, frictionless payments, urgency-driven design—the Behavioral Firewall restores the moment of choice that belongs to you.
Our Android Accessibility Layer is the technical embodiment of this principle. It operates in read-only mode, recognizing only that a checkout flow is in progress. It does not capture transaction amounts, merchant names, account numbers, or card details. It does not build a profile of your spending. It simply surfaces a brief pause, giving you the space to decide whether this purchase aligns with your goals. The firewall protects your attention and your sovereignty; it does not surveil your behavior.
Zero-Knowledge Architecture
Zero-knowledge is not a feature we add; it is the foundation we build on. SpendSitter is designed such that we never see, store, or transmit personally identifiable information. The Android Accessibility Layer distinguishes between context and content: we detect that a payment screen is present, but we do not read what is on it. We have no database of purchases. We have no behavioral analytics. We have no data to lose, because we do not collect it.
This is an architectural constraint, not a policy promise. Our systems are built so that the possibility of PII exposure is eliminated by design. All spending logic—the detection of checkout flows, the timing of interventions, the decision to surface a pause—runs on-device. No behavioral data leaves your phone. No server receives signals about when, where, or how often you encounter our layer. Your device, your data, your control.
The Anti-Monetization Pledge
We will never sell user data. We will never monetize behavioral insights or purchase patterns. We will never partner with predatory lenders or payday advance services. Our revenue model is aligned with user outcomes: we succeed when you build financial resilience, not when you are exploited. This pledge is binding.
SpendSitter is committed to these principles as a condition of our existence. We invite scrutiny, and we hold ourselves accountable to the users who place their trust in us.