Legal
Privacy Policy
Last updated: 29 July 2026
1. Introduction & Scope
This Privacy Policy explains how personal data is handled in connection with myney, an offline-first personal finance tracker for iOS (the "App", bundle identifier com.slipgoat.myney). The App is made and operated by the independent developer of myney ("we", "us", or "our"). You can contact us at any time at support@slipgoat.xyz, and our full developer and contact details are shown on the myney App Store listing.
myney is designed around a simple principle: your financial data stays on your device. We do not operate our own servers to store your transactions, and we do not run any analytics, tracking, or advertising code. This Policy describes the limited data that is processed to make the App work, who processes it, and the rights you have under laws including the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
This Policy applies to your use of the App. It does not apply to third-party services you separately choose to use, each of which is governed by its own privacy policy (see Section 5).
2. Data We Collect and Why
2.1 Account and authentication data
To let you sign in and to keep your data scoped to you, we use a third-party authentication provider, Auth0 (an Okta company). When you create an account or sign in — using email or a social login via Apple, Google, or Facebook — Auth0 processes identifiers such as your account identifier (a unique sub value), your email address, and authentication tokens. We use a stable account identifier only to associate your locally stored data with your account. Authentication tokens are stored on your device in the iOS secure keychain (via flutter_secure_storage) so that you can remain signed in, including offline.
Purpose: to provide account creation, secure sign-in, and per-user separation of data.
2.2 Purchase and subscription data
If you buy a subscription or make an in-app purchase, the transaction is processed by Apple through the App Store and Apple In-App Purchase. Apple handles your payment; we never receive or store your full payment card details. We use RevenueCat to manage and verify your subscription entitlement state (for example, whether you have an active subscription). RevenueCat processes purchase-related identifiers and receipt/entitlement information associated with your Apple purchase.
Purpose: to process purchases, deliver paid features, and validate your subscription status.
2.3 Financial data you enter (stored on your device)
The financial information you record in the App — transactions, categories, accounts, and budgets — is stored locally on your device in an on-device SQLite database. This data is not uploaded to our servers and is not transmitted to us. It remains under your control on your device.
Purpose: to provide the core functionality of the App entirely on your device.
2.4 Exchange-rate lookups
To display currency conversions, the App fetches exchange rates through a proxy service we operate on Cloudflare Workers. These requests retrieve rate information only. No personal data and no financial data are sent to this service — it simply returns exchange rates.
2.5 Data export and import
You can export your data to, or import it from, XML files. This is a device-local, user-initiated action. Any file you export is under your control; if you choose to share, back up, or transfer that file, you do so yourself and are responsible for how it is handled thereafter.
3. What We Do NOT Collect or Do
- We do not include any analytics, tracking, advertising, or crash-reporting SDKs in the App.
- We do not build advertising or behavioral profiles about you.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
- We do not upload or store your financial transactions on our own servers.
4. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — to provide account authentication and to deliver the App and any purchased subscriptions you have requested.
- Legitimate interests (Art. 6(1)(f)) — to keep the App secure, to prevent fraud and abuse, and to validate subscription entitlements. We balance these interests against your rights and freedoms.
- Consent (Art. 6(1)(a)) — where consent is required, for example if you choose a social login provider or otherwise opt into an optional feature. You may withdraw consent at any time without affecting processing already carried out.
- Compliance with a legal obligation (Art. 6(1)(c)) — where we must retain limited records (for example, purchase records) to meet tax or accounting requirements.
5. Third-Party Processors
We rely on the following third parties, each of which processes only the limited data described above and maintains its own privacy policy:
- Auth0 (Okta) — authentication. https://www.okta.com/privacy-policy/
- Apple (App Store / In-App Purchase) — payment and purchase processing. https://www.apple.com/legal/privacy/
- RevenueCat — subscription entitlement management. https://www.revenuecat.com/privacy/
- Cloudflare — hosting of our exchange-rate proxy (rates only; no personal or financial data sent). https://www.cloudflare.com/privacypolicy/
6. Your Rights Under the GDPR (EU/UK)
If you are in the European Economic Area or the United Kingdom, you have the right to:
- Access — obtain confirmation of whether we process your personal data and a copy of it.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — request deletion of your personal data ("right to be forgotten").
- Portability — receive your data in a structured, commonly used, machine-readable format. Note that your financial data already resides on your device and can be exported by you at any time as XML.
- Objection — object to processing based on legitimate interests.
- Restriction — request that we restrict processing in certain circumstances.
- Withdraw consent — where processing is based on consent, withdraw it at any time.
- Lodge a complaint — with your local data protection supervisory authority.
To exercise any of these rights, contact us at support@slipgoat.xyz. We will respond within the timeframes required by applicable law.
7. Your Rights Under California Law (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know — request the categories and specific pieces of personal information we have collected about you.
- Delete — request deletion of personal information we hold about you.
- Correct — request correction of inaccurate personal information.
- Opt out of sale or sharing — direct a business not to sell or share your personal information. We do not sell or share personal information, so there is nothing to opt out of.
- Non-discrimination — you will not receive discriminatory treatment for exercising any of these rights.
To exercise these rights, contact us at support@slipgoat.xyz. We will verify your request as required by law, and you may use an authorized agent where permitted.
8. Data Retention and Deletion
On-device data: Your financial data lives on your device. You can delete it at any time by clearing the App's data or by uninstalling the App, which removes the local database from your device.
Account data: Authentication data held by Auth0 persists until your account is deleted. To request deletion of your account and associated authentication records, contact us at support@slipgoat.xyz.
Purchase records: Purchase and subscription records held by Apple and RevenueCat are retained in accordance with their policies and any legal, tax, or accounting obligations.
9. International Data Transfers
Our third-party processors (Auth0/Okta, Apple, RevenueCat, and Cloudflare) may process data in countries other than your own, including the United States. Where personal data is transferred out of the EEA or UK, those transfers are protected by appropriate safeguards recognized under applicable law, such as the European Commission's Standard Contractual Clauses or an adequacy decision. Please refer to each processor's privacy policy (Section 5) for details of its transfer mechanisms.
10. Children's Privacy
The App is not directed to children under the age of 13 (or under 16 where a higher age of digital consent applies in your jurisdiction), and we do not knowingly collect personal data from children. If you believe a child has provided personal data, please contact us at support@slipgoat.xyz and we will take appropriate steps to delete it.
11. Security
We take reasonable measures to protect data. Authentication tokens are stored in the iOS secure keychain, and communication with our authentication and rate services uses encrypted (HTTPS/TLS) connections. Because your financial data is stored locally, its security also depends on the security of your device — we recommend using a device passcode, biometric lock, and up-to-date software. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the App after an update takes effect constitutes acceptance of the revised Policy.
13. Contact
For any privacy question or to exercise your rights, contact us at support@slipgoat.xyz.