EN · RULast updated 29 August 2026.
Your financial records are stored on your device. We do not see them, do not collect them and do not sell them. The only thing that reaches our server is what a shared budget needs, and it arrives encrypted.
Expenses, income, goals, limits, accounts, debts, passes and classes, plus your app settings. All of it sits in the app's storage on your phone.
If you turn syncing on, records are copied through your iCloud. That is your personal Apple storage: we have no access to it. Backups work the same way.
When you start a shared budget, the records you mark as shared go to our server (Firebase Firestore, Google) so the other person can see them.
| The server sees | The server does NOT see |
|---|---|
| the family identifier, member identifiers, edit timestamps, encrypted bytes | amounts, names, notes, member names, balances, all of it is encrypted on the device |
The encryption key is passed hand to hand through an invite code and never reaches the server. The reverse is also true: if the key is lost, we cannot decrypt the records either.
| Data | Why | Processed by |
|---|---|---|
| Anonymous usage statistics: which screens were opened, which actions were taken. No amounts, no names. | To see where people get stuck | Firebase Analytics (Google), Amplitude |
| Crash reports: device model, system version, where it crashed | To fix bugs | Firebase Crashlytics (Google) |
| Subscription and purchase state | To unlock what you paid for | RevenueCat, Apple |
| Your account when you sign in: identifier, name and email if you gave them | To tell family members apart | Firebase Authentication (Google), Apple, Google |
| The fact that the app was installed and launched. No amounts, no names, nothing from your records | To know which ads bring people in | Meta, AppsFlyer |
| Steps of getting started: finished onboarding, logged a first expense, opened the subscription screen. The bare fact of the event, without amounts, names or categories | To see at which step people leave, and to stop paying for ads that bring people who leave straight away | AppsFlyer |
| The device advertising identifier (IDFA). Sent ONLY if you allowed tracking | To connect an install to a particular ad | Meta, AppsFlyer |
Tracking is requested through a separate system dialog. Saying no breaks nothing: the app works in full and we simply do not get the advertising identifier. The launch itself is still counted anonymously, with no link to you personally: without that, advertising an app is technically impossible.
The app settings have a switch that turns the whole collection off, ad measurement included. It does not "reduce the amount", it stops the sending.
You can delete your account and data inside the app. The details are on the account deletion page.
The app is not intended for children under 13, and we deliberately do not collect their data.
If this policy changes we will update the date at the top of the page, and tell you in the app when the change is a meaningful one.