1. Introduction
Stashly is a privacy-first personal finance tracker. Our core philosophy is that your financial data belongs to you and only you. We operate no servers, you need no account, and there is no copy of your records anywhere but on your own device.
Two features send data over a network, and both are described in full below: household sharing, which sends a summary directly to a partner's device only when you deliberately pair with them, and exchange rates, which downloads public reference rates without telling anyone anything about you. Nothing else about your finances is transmitted, ever.
2. Data Collection and Usage
Stashly follows a Zero Data Collection policy:
- Personal Information: No account registration or login is required. We do not collect names, emails, or any identifying information.
- Financial Data: All financial records (providers, accounts, transactions, and balances) are entered manually and stored exclusively on your device.
- Third-Party Access: We do not use third-party analytics, telemetry, or advertising SDKs with access to your data.
- No Profiling: We build no profile of you, and no automated decision-making is applied to your data.
3. This Website
Everything above describes the app. This website is a separate thing, and it does measure a little: we count visits, which pages are read, which country the request came from, and whether somebody left for the App Store or Google Play. That is how we know whether any of this is worth writing.
- No cookies: The measurement is configured to store nothing in your browser, which is why you are not being asked to accept anything.
- No profile: Because nothing is stored, a second visit cannot be recognised as yours. We see visits, not people.
- Nothing from the app: The website has no access to your financial data. It has never left your device, so there is nothing here to reach.
The measurement is done with Google Analytics, in its cookie-free configuration.
4. Data Storage and Security
We employ industry-standard security measures:
- Local Storage: All data is persisted locally using encrypted storage via LocalForage.
- Encryption at Rest: Data is encrypted using AES-256-GCM. The encryption key is generated on your device and stored securely in the native iOS Keychain or Android Keystore. This key never leaves the device.
- Biometric Authentication: If enabled, the app uses native APIs (Face ID, Fingerprint) for access control. No biometric data is ever read or stored by the app.
- Device Backups Excluded: On Android, the app is excluded from Google Auto Backup and device-to-device transfer. A restored copy of the encrypted data would be unreadable without the hardware-held key, so we do not let it be copied in the first place. Use the app's own export instead.
5. Backup and Portability
- User-Initiated Backups: You may explicitly export your data as an encrypted snapshot.
- Encryption: Backups are protected with a password of your choice using PBKDF2-SHA256 (600,000 iterations) and AES-256-GCM encryption. Files exported by older versions of the app used 100,000 iterations and remain readable.
- Password Recovery: There is none. If you lose the password, nobody - including us - can recover the contents.
- Cloud Services: If you upload your encrypted backup to a third-party service (e.g., iCloud, Google Drive), it remains encrypted and inaccessible without your specific password.
6. Household Sharing (Optional)
If you choose to pair with a partner, the two devices exchange data directly with each other - over a QR code shown on screen, or over Bluetooth. There is no server in between, and we never receive any of it.
- Only on your initiative: Nothing is shared until you pair, and pairing requires both people to act on their own device at the same time.
- What is shared: A summary of your accounts (names, balances and currencies), your monthly history, and the display name you chose. Individual transactions are never shared.
- Encryption: The exchange is end-to-end encrypted with keys agreed directly between the two devices. Pairing shows a short numeric code on both screens for you to compare, so a third device cannot interpose itself.
- Your partner's copy: Once shared, that data sits on their device, where their own settings govern it. Unpairing removes their data from yours, and vice versa - it cannot remove your data from their device.
- Removal: You can remove a paired partner, and the data they sent you, at any time - including after a subscription has ended.
7. Exchange Rates
If you hold accounts in more than one currency, the app downloads published reference rates from the Frankfurter service, which republishes European Central Bank rates.
- Nothing about you is sent. The request carries no account, no identifier and no API key. It asks for the entire rate table, so it does not even reveal which currencies you hold.
- Only when needed: If you use a single currency, the app makes no rate requests at all.
- No background activity: Rates are refreshed when you open the app if the stored table is more than a day old, or when you ask for it in Settings. There is no polling and no background service.
8. Reminders
The optional reminder to update your balances is a local notification, scheduled on your device by the app itself. There is no push service, no notification token and no server. The reminder text never contains an amount, a balance or an account name, so nothing sensitive appears on your lock screen.
9. Subscriptions and Payments
Stashly uses a freemium model managed via native In-App Purchases.
- Payment Details: Purchases are processed by Apple (App Store) or Google (Google Play). We never see your payment details.
- RevenueCat: To recognise your subscription across app restarts and reinstalls, our subscription-management provider RevenueCat, Inc. processes a randomly generated app identifier and your purchase history on our behalf, as a data processor under a data-processing agreement (revenuecat.com/privacy).
- Kept Separate: This is the only personal data processed on our behalf, and it is never combined with your financial data, which stays on your device.
10. Support Requests
If you use the feedback option in Settings, your own e-mail app composes a message that includes the app version, build identifier, operating system and device model, so that we can reproduce what you are describing. You can see the whole message before sending it, and sending it is entirely your choice. We use it only to answer you.
11. Your Rights
Under UK and EU data protection law you have rights of access, rectification, erasure, restriction, portability and objection. Because your financial data exists only on your device, you exercise most of these directly:
- Access and rectification: View and edit everything in the app.
- Portability: Use the export feature for a complete copy of your data.
- Erasure: Delete records in the app, remove a paired partner, or uninstall the app, which removes all locally stored data.
- Purchase records: For the subscription identifier described in section 9, contact us and we will instruct RevenueCat accordingly.
You also have the right to complain to your data protection authority - in the UK, the Information Commissioner's Office (ico.org.uk).
12. Children
Stashly is not directed at children under 13, and we knowingly process no children's data.
13. Changes to This Policy
We will update this page and the "Last Updated" date above whenever anything changes. Material changes will also be noted in the app's release notes.