Ownspend · Legal

Privacy Policy

Last updated: 22 September 2026

Local-first by default. Sharing is your choice.
The short version: If you use Ownspend on your own, you create no account and your transactions, budgets, categories, and wallets live only on your device. A few things do leave it, and none of them is your money: anonymous crash reports, a device record used to send app reminders and news, counters for our own “more from us” cards, and — only if you send it — whatever you write in the feedback form. Sections 5, 8 and 9 say exactly what each one contains. Shared Wallet is a separate, opt-in feature. Only when you choose to share a wallet with another person do we sync that one wallet's records to a secure cloud so you and the person you invited can co-manage it. Your personal wallets, budgets, and goals still never leave your device — even if you also use a Shared Wallet.

1. Two ways to use Ownspend

Ownspend has two modes, and they have very different privacy footprints:

ModeAccount?Where your data lives
Solo (the default for everyone) No account. No sign-in. On your device only, in Apple’s local SwiftData store.
Shared Wallet (opt-in, free) Yes — you sign in to identify you and the person you invite. The shared wallet’s records sync to Google Cloud (Firebase) so both members can see one live set of records. Everything else stays on your device.

You are in Solo mode unless you deliberately create or accept a Shared Wallet invite. You never see a sign-in screen until that moment.

2. Solo mode — no account, and none of your money leaves the device

Solo mode means no account and no sync of your finances. It does not mean the app is silent: a small amount of non-financial data is sent for crash reporting, notifications and product measurement, and it is itemised in sections 5 and 8. Nothing in any of it is a transaction, an amount, a note, a merchant, a category, a budget or a goal.

3. No bank linking, ever

Ownspend does not connect to your bank, does not use Plaid or any aggregator, and never asks for banking credentials or card numbers. You enter your transactions yourself. This is true in both Solo and Shared modes.

4. Shared Wallet — what the cloud receives

When (and only when) you create or accept a Shared Wallet, some data is sent to and stored in Google Cloud (Firebase) so that you and the one person you invite can co-manage the same records. This is what changes, and exactly what is involved.

4.1 Signing in

4.2 What data syncs to the cloud

For a shared wallet, the following is synced to Google Cloud Firestore:

4.3 What stays on your device even with a Shared Wallet

The privacy boundary is at the wallet level: shared wallets sync; personal wallets do not.

4.4 Who your shared data is shared with

Our sub-processors are listed in section 12.

4.5 Access control

4.6 Retention and deletion of shared data

4.7 Getting your data out (portability)

Either member can export the shared wallet’s records to CSV or JSON at any time, from within the app. A user can always walk away with a copy of any data they could see.

4.8 Location

Ownspend can tag an expense with where you spent, so you can see it on a map. This is entirely optional and never automatic:

5. Analytics, crash reporting and product measurement

Crash reporting. Ownspend uses Firebase Crashlytics so that a crash on any device — solo or shared — can be diagnosed and fixed. A crash report contains a stack trace, your device model, the OS version and an app-generated installation identifier. It never contains your transactions, amounts, notes, categories, wallets, or anything you typed into the app.

Usage analytics. Firebase Analytics is present in the app but collection is switched off when the app launches and stays off unless it is enabled by a remote configuration flag. If it is ever switched on, it records anonymous events about how features are used — never your financial data, and never anything that identifies you personally. We do not build advertising or behavioral profiles.

Product measurement. Two small first-party counters write to our own Google Firestore project. Neither ever receives a transaction, amount, note, merchant, category, budget or goal.

6. Advertising and tracking

There are no ads, no advertising SDKs, and no cross-app or cross-site tracking in Ownspend. We do not use the advertising identifier (IDFA), so the App Tracking Transparency prompt does not apply.

7. Purchases

Pro purchases — a one-time lifetime unlock, or a monthly or yearly subscription — are processed by Apple through the App Store using StoreKit 2, with RevenueCat managing entitlement status. We never see your card number or payment details; Apple handles payment.

Your purchase status does leave the device, so we should be exact about it. The RevenueCat SDK starts with the app for every user and checks whether this install has Pro. If you have signed in for Shared Wallet, RevenueCat also notifies our server when your entitlement changes, and we store the result against your account, because the shared-wallet features you get depend on it: whether you are entitled and to what tier, when it expires, which product it was, and whether the purchase was a real one or an Apple test purchase. What we store is the entitlement, never a card number, and never what you bought elsewhere. Your Pro flag is also included if you send feedback (section 5).

8. Notifications

9. Device identifiers

We do not collect the advertising identifier (IDFA), and we do not use the device vendor identifier (IDFV) to track you. We do not track you across other companies’ apps or websites, and we never join your data with anyone else’s (section 6). The one thing worth naming, because “no cross-app anything” would overstate it: the “more from us” cards ask iOS whether our own other apps are installed on this device, so we do not advertise something you already have and can tell whether a recommendation worked. That is a yes/no question about our apps only. Several identifiers exist, and each is limited to one job. The ones we create and use directly are:

Two more are created by services we use rather than by us. RevenueCat mints an app-user id when the app starts, so it can tell whether this install has Pro; it begins anonymous, but if you sign in for Shared Wallet the app links it to your account id, so from then on it is not anonymous. And if you turn on Shared Wallet notifications, Firebase Cloud Messaging issues a delivery token. Both are covered by those providers’ own terms, listed in section 12.

10. Children

Ownspend is rated 4+ but is a personal-finance tool that is not directed to children under 13. Shared Wallet requires an account and is intended for adults; see the age requirement in the Terms of Use.

11. Legal bases and your rights (GDPR / CCPA)

This section is a plain-language summary, not legal advice. Your statutory rights depend on where you live.

12. Sub-processors and third-party services

Apart from crash reporting (section 5) and notifications (section 8), solo mode uses only Apple frameworks on your device. The services below process data for Ownspend; all but Engagement Center are third parties operating under their own terms — Engagement Center is infrastructure we run ourselves.

ProviderWhat it does for OwnspendApplies to
Google — Firebase / Google Cloud (Crashlytics, Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, Cloud Messaging) Receives crash reports and the product-measurement counters and feedback described in section 5 (all users); and, for Shared Wallet only, stores and syncs the shared wallet’s records, receipt photos and any place you tagged, authenticates members, delivers opt-in push notifications, and runs the secure invite/membership logic. Crash reports + product measurement: all users. Sync: Shared Wallet only
Engagement Center (engage.puzzpics.com) — operated by us, not a third party Stores the device record described in section 8 and sends reminders and app news via Apple Push Notification service. Never receives your financial data. Everyone (delivery only if you allow notifications)
Apple (Sign in with Apple, StoreKit, notifications) Sign-in, in-app purchases, delivery of local notifications. Both modes
RevenueCat Manages purchase and entitlement status for Pro. Both modes (purchases)

Google’s handling of the data it processes for us is governed by the Google Cloud / Firebase Data Processing terms. Their privacy policies: Firebase, Apple, RevenueCat.

13. Changes to this policy

If we change what data is collected, we update the “Last updated” date and note it in the App Store release notes, and the App Store privacy label is updated in that same release. One honest exception to “only with an app update”: as section 5 describes, usage analytics are switched off at launch and could be switched on by a remote configuration flag without shipping a new build. If we ever turn that on we will say so here and in the label first.

14. Contact

Questions or requests (including data deletion or export help): email dark2torch@gmail.com. We usually reply within a business day or two.

A note on financial guidance

Ownspend is a personal budgeting and expense-tracking tool, not financial, investment, or tax advice. For guidance specific to your situation, talk to a qualified financial professional.