Privacy policy

Last updated: 2 August 2026

Draft. This document is a working draft and has not been reviewed by a lawyer. It needs checking before the site or the app goes live.

Working draft. Placeholders marked TODO must be resolved and the whole document reviewed before launch. This is not legal advice.

This policy explains how personal data is handled on this website and in the mobile and desktop app. It covers two separate things, the website and the app, because they collect very different amounts of data.

Controller. Sergi Arranz, trading as Cifrea, part of ARSTE. Mayan, Building 2, Unit 712, Abu Dhabi, United Arab Emirates. Contact: see the contact page.

1. The website

What is collected

What is not collected

No account is required to read anything here. There is no login, no comment system, no tracking pixel from a social network, and no sale or sharing of personal data.

2. The app

The principle

Your financial records belong to you. They are stored so that you can use them across your devices and share them with the people in your household. Nothing else. They are never sold, never shared with advertisers, and never analysed to build a profile of you.

What is collected

Where it is stored

Data is hosted by Supabase Inc. (database, authentication and file storage), in the {{TODO: region}} region. Cross-border transfer: because the controller is in the UAE and the infrastructure is in {{TODO: region}}, your data is transferred outside your country of residence. {{TODO: state the safeguard relied upon, e.g. the provider’s standard contractual clauses.}}

Processors used: Supabase Inc. (hosting), Apple Inc. (app distribution, in-app purchases, push notifications if enabled). A current list is on the subprocessors page.

How transactions reach the app

You enter them, or you import a file yourself. The app does not currently connect to your bank, and no bank credential is requested, stored or transmitted.

If a bank-connection feature is added later, this policy will be updated before it ships, it will be something you choose to turn on, and it will never be required in order to use the app.

3. Retention

Website analytics are retained in aggregate only. Newsletter subscriptions are kept until you unsubscribe. App data is kept for as long as your account exists; when you delete your account, your data and any attached files are deleted from the production database within {{TODO: number}} days, and from encrypted backups within {{TODO: number}} days after that.

4. Your rights

Wherever you live, you can:

If you are in the EEA or the UK, these are your rights under the GDPR. If your data is handled under UAE law, the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data gives you broadly equivalent rights.

To exercise anything that the app cannot do by itself, email the address on the contact page. Requests are answered within 30 days.

5. Children

The app is not directed at children under 16 and no account should be created for one.

6. Security

Data is transmitted over TLS and stored on infrastructure with encryption at rest. Access to the production database is restricted to the controller. Row-level security policies isolate every household’s data from every other household’s.

No system is perfectly secure. In the event of a breach affecting your personal data, you will be notified without undue delay, along with the relevant supervisory authority where the law requires it.

7. Changes

Material changes to this policy will be announced on this page and, for app users, inside the app before they take effect. The date at the top always reflects the current version.