Privacy Policy
The short version: SpendTally does not collect, transmit, sell, or share any of your data. Everything stays on your iPhone.
One-sentence summary: We don't have a server. We can't see your costs, income, or goals — because we never receive them.
1. Who we are
SpendTally is a single-person indie iOS app made by SpendTally ("we", "us", "the developer"). You can reach the developer at oveshdev@gmail.com.
2. What this app does
SpendTally helps you see the yearly cost of recurring spending (subscriptions, gym memberships, daily coffees, etc.) so you can decide what to keep and what to cut. It is a local-only iOS app for iPhone, built natively in Swift and SwiftUI.
3. Data we do NOT collect
Unlike most apps, SpendTally does not collect any of the following — because we have no server, no analytics, and no third-party SDKs to receive them:
- Name, email, phone number, or any contact information
- Account credentials (there is no account)
- Costs, income, or financial information you enter
- Savings goals or progress
- Payment history or transaction records
- Location, contacts, photos, calendar, microphone, camera
- Device identifiers (IDFA, IDFV, MAC, advertising ID)
- Crash reports or performance telemetry
- Analytics events, screen views, taps, or session data
- Browsing history or search history
4. Where your data lives
All data you enter in SpendTally is stored locally on your iPhone using Apple's SwiftData framework. It never leaves your device, except in the following two cases — both of which you control:
4.1. iCloud Backup
If you have iCloud Backup turned on for your iPhone (Apple's setting, not ours), your iOS device automatically includes SpendTally's local data in the encrypted backup that is uploaded to your private iCloud account. This backup is end-to-end encrypted by Apple and is only accessible to you with your Apple ID. We cannot read, decrypt, or access this backup.
To exclude SpendTally data from iCloud Backup, go to Settings → [your name] → iCloud → Manage Account Storage → Backups → [your device] → Show All Apps → SpendTally → toggle off.
4.2. Local export
SpendTally includes an in-app export feature that writes a JSON file containing your data to a location you choose (e.g. the Files app, AirDrop, or a share sheet target). We never see this export — it goes directly from the app to the destination you pick. You can use this to back up to your own cloud service, or to delete the data and re-import later.
5. Third parties
SpendTally contains no third-party SDKs, no analytics, no ad networks, no crash reporters, and no tracking pixels. There is no one else to whom your data could be sent.
The only external services the app interacts with are:
- Apple iCloud Backup — only if you have it on (see §4.1).
- Apple App Store — for installation, updates, and review. Apple does not share your financial data with us; they only confirm that you downloaded the app.
6. Children
SpendTally is not directed to children under 13. We do not knowingly collect any information from children. Because the app does not collect any information from anyone, this policy is satisfied for all users regardless of age.
7. Your rights
You have full control over your data at all times:
| Right | How to exercise it |
|---|---|
| Access your data | Open SpendTally — everything is visible in the app |
| Export your data | Use the in-app Export feature to save a JSON copy |
| Correct your data | Edit any cost, goal, or income value directly in the app |
| Delete your data | Settings → Clear All Data, or delete the app |
| Stop iCloud backup | Disable backup for SpendTally in iOS Settings (§4.1) |
8. Data retention
Your data is retained on your device until you delete it (via the in-app Clear All Data button or by deleting the app) or until you restore the device from a backup that predates the data. We have no copy of your data, so there is nothing to retain or delete on our side.
9. International users
SpendTally is designed to comply with the following privacy frameworks:
- GDPR (EU/EEA): We are a data controller of nothing, because we collect no data. You retain all rights under GDPR, exercised entirely within the app.
- CCPA/CPRA (California): We do not "sell" or "share" personal information because we do not collect it.
- UK GDPR / Data Protection Act 2018: Same as GDPR.
- PIPEDA (Canada): Same posture as above.
The legal basis under GDPR for our not processing your data is that there is no processing to legitimize.
10. Security
Your data is protected by the iPhone's hardware security: the SwiftData store is stored in the app's sandboxed container, which is protected by iOS's app-level sandbox, the device passcode / Face ID, and (if enabled) the device's Secure Enclave. We do not implement additional encryption because we do not transmit the data over any network.
11. Changes to this policy
We may update this privacy policy as the app evolves. The "Effective" date at the top of this page will always reflect the current version. If we ever introduce a feature that involves transmitting data off-device (which we do not currently plan to), we will:
- Update this policy and the in-app privacy notice before the feature ships,
- Request your explicit consent before any data is sent, and
- Provide an in-app way to opt out.
Material changes will be announced on the in-app What's New screen.
12. Contact
Questions, concerns, or data requests? Email oveshdev@gmail.com. The developer reads every message personally.
For support and FAQs, see the Support page.
13. App Store privacy details
For transparency, here is how SpendTally answers Apple's App Store privacy questions:
| Data type | Collected? | Used to track? |
|---|---|---|
| Contact Info | No | No |
| Financial Info | No | No |
| Health & Fitness | No | No |
| Location | No | No |
| Sensitive Info | No | No |
| Contacts | No | No |
| User Content | No | No |
| Browsing History | No | No |
| Search History | No | No |
| Identifiers | No | No |
| Usage Data | No | No |
| Diagnostics | No | No |
| Purchases | No | No |
The reason "Financial Info" is marked No — even though the app stores financial data you enter — is that Apple's privacy question asks whether the developer collects data from the device, not whether the user stores data locally. We collect nothing, so the answer is No.