"Privacy-first" is close to meaningless as a claim, because no company describes itself as privacy-second. The only version worth reading is the specific one: which decisions were made differently, and what they cost.
The photo that stays on the phone
Reading a receipt, a recipe card, or a serial plate is text recognition, and text recognition runs on the device. That is slower and slightly worse than sending the image to a server, and it means a photograph of your shopping or your paperwork never leaves your phone. Where a feature genuinely cannot run locally, the app says so before the shutter, not in a policy document.
The vault we cannot open
Documents in the vault are encrypted on the device with a key derived from a phrase we never receive. We cannot read them, cannot recover them, and cannot be compelled to produce them. The cost is real and non-negotiable: lose the phrase and the data is gone.
And no third parties in a child's account
No analytics SDKs, no advertising identifiers, no background location. A child's account exists to let them see their own schedule and their own chores, and it is not a data collection opportunity.