Privacy Policy
Masarefy is a personal finance app for tracking expenses, income, wallets, budgets, and goals. We designed it to be local-first: your financial data stays on your device unless you explicitly opt in to sync it through your own iCloud account. We do not run a backend server that holds your financial data, and we do not sell any data to anyone.
This policy explains what the app handles, where it goes, and the choices you control.
1. Data we handle
1.1 Data you enter
Transactions, wallets, categories, budgets, goals, gold holdings, merchants, SMS parsing rules, your name (optional), preferred currency, language, theme, and accent color.
Storage: locally on your device using Apple's SwiftData. If you turn on iCloud Sync in Settings, this data is synced through Apple's CloudKit using your private iCloud database — which is owned by you, not by us. We have no access to it.
1.2 SMS messages you import
Masarefy can convert bank or wallet SMS messages into transactions. The app does not read your SMS inbox automatically. SMS content reaches the app only when:
- you paste a message into the parser, or
- you trigger it via an iOS Shortcut or Intent that you have configured.
Parsed messages produce a transaction in your local database. The original SMS body is not transmitted off your device by the app.
1.3 Widget data
The app shares a small slice of your data (recent transactions, balance summary) with its own home-screen and lock-screen widgets via an iOS App Group container. This stays on your device.
1.4 Diagnostic / telemetry data (optional)
Crash reports and basic in-app diagnostics may be collected via the Luciq SDK only if you have left telemetry enabled and the build you installed has the SDK linked. When active, this can include device model, OS version, app version, anonymous session identifiers, and crash stack traces. It does not include your transactions, balances, contact info, or SMS content. You can disable telemetry in Settings → Privacy / Diagnostics.
1.5 On-device debug logs (optional, off by default)
If you turn on Debug logs in Settings, the app keeps a rolling local buffer (max 256 KB) of internal events such as SMS parser outcomes. These logs stay on your device and are never uploaded automatically. You can view, share (at your initiative), or clear them at any time from More → App.
1.6 Notifications (optional)
The app may post local notifications (e.g., to confirm an SMS-triggered Shortcut succeeded). These are generated on your device by iOS; we do not send push notifications from a server.
2. What we do not do
- We do not collect your name, email, phone number, or any contact information.
- We do not require an account, sign-in, or login.
- We do not have a backend server that stores your financial records.
- We do not use third-party advertising or marketing trackers.
- We do not sell, rent, or share your data with third parties.
- We do not access your iOS contacts, photos, location, microphone, or camera.
- We do not read your SMS inbox.
3. Third parties
The only third parties involved in normal operation are:
- Apple — provides iCloud / CloudKit sync (when you enable it), App Store and TestFlight distribution, and standard iOS services. Your data in iCloud is governed by Apple's Privacy Policy.
- Luciq — provides crash reporting and in-app feedback (only when telemetry is enabled and the SDK is linked into the installed build). See Luciq's privacy documentation for details on what they process on our behalf.
We do not use any other third-party SDKs that collect data.
4. Your choices and controls
- Disable iCloud sync — Settings → Data & Backup. Stops syncing to your iCloud account; existing data on the device is unaffected.
- Disable telemetry — Settings → Privacy / Diagnostics. Stops crash and diagnostic reporting from this device.
- Wipe all data — Settings → Danger Zone → Wipe all data. Deletes your local Masarefy database. If iCloud sync is on, the deletion will propagate to your iCloud copy.
- Export your data — Settings → Data & Backup → Export CSV. You can take your data with you at any time.
- Delete the app — uninstalling Masarefy removes its on-device data. Data previously synced to your iCloud private database remains in your iCloud account until you delete it from iCloud settings.
5. Data retention
Local data persists on your device until you wipe it or delete the app. iCloud-synced data persists in your private iCloud database until you remove it from iCloud. If telemetry is enabled, diagnostic data is retained by Luciq according to their retention policy.
6. Children's privacy
Masarefy is not directed at children under 13. We do not knowingly collect personal information from children.
7. Security
Your local data is stored inside the app's iOS sandbox and protected by iOS file-system encryption when your device is locked. iCloud sync uses Apple's encrypted CloudKit transport. Because your data lives in your own iCloud account, its security depends on your Apple ID's protection — we strongly recommend two-factor authentication on your Apple ID.
No method of electronic storage is 100% secure, and we cannot guarantee absolute security.
8. International users
Masarefy operates globally. If you enable iCloud sync, Apple may store your data in data centers outside your country of residence per Apple's iCloud terms.
9. Changes to this policy
We may update this policy as the app evolves. The “Effective date” above will reflect the latest revision. Material changes will be highlighted in the app's release notes (More → What's new).
10. Contact
Questions or requests about your data:
If you would like a copy of any data we may hold about you, or to ask us to delete it, email us from the address associated with your inquiry and allow up to 30 days for a response.