Spendy Privacy Policy
Effective date: August 5, 2026
This Privacy Policy explains how Onessa ("we," "us," or "our") handles information when you use Spendy on Apple platforms, including its widgets and related extensions (collectively, the "App").
1. Privacy at a Glance
We do not use advertising, cross-app tracking, or third-party analytics SDKs. We do not operate a separate server that receives a copy of your ledger. Your Spendy content is stored on your device and, when iCloud is available, in your private iCloud or CloudKit storage.
2. Information Handled by the App
- Financial and app content: Transactions, account and budget information, tags, notes, recurring items, attachments, receipt images, scanned text, and related settings that you create in the App.
- Calendar and reminders: If you grant permission, Spendy can display calendar events and reminders alongside your financial timeline. It can also create, update, or delete reminders when you ask it to.
- Contacts: If you grant permission, Spendy may look up a contact image to identify a participant in a shared ledger. Your address book is not uploaded to Onessa.
- Camera, photos, and files: Content you choose to capture or import can be attached to a transaction or used for backup and restore features.
- Biometric authentication: If App Lock is enabled, Apple performs Face ID or Touch ID authentication. Spendy receives only the authentication result, not your biometric data.
- Preferences and diagnostics: Display choices, selected lists, feature settings, sync state, and locally generated diagnostic logs needed to operate or troubleshoot the App. Diagnostic logs remain on your device unless you choose to share them.
Spendy does not request or use precise location data. You can grant or revoke optional system permissions in Apple Settings; disabling a permission may make the related feature unavailable.
3. Storage, Sync, and Sharing
Spendy stores its database and attachments locally and may use Apple iCloud, CloudKit, and iCloud Drive to sync them across your devices. If you use iCloud sharing, the ledger content you choose to share is made available to the people you invite. Apple processes iCloud and sharing data under Apple's Privacy Policy.
4. Network and Third-Party Services
- Exchange rates: Spendy may request public exchange-rate data directly from the Bank of Korea. The request includes a date range and standard network information, such as your IP address, but does not include your ledger content.
- App Store purchases: Apple processes purchases, subscriptions, receipts, and entitlement status. We do not receive your full payment-card details.
- Optional external integrations: If you install or use an integration such as Claude on macOS, information you choose to use with that integration may be provided to the external service and handled under that provider's terms and privacy policy.
- Links: Opening a web link from the App sends the request to that website under its own privacy practices.
We do not sell or rent your information.
5. Information You Send to Us
If you email us for support, we receive your email address and the information you choose to include. We use it only to respond, troubleshoot, protect the App, and comply with applicable law.
6. Retention and Deletion
App content remains until you delete it or remove it through the relevant Apple service. Uninstalling Spendy removes local app data but may not delete copies in iCloud, shared ledgers, backups, Calendar, Reminders, or an external integration. Because we do not hold your private ledger on an Onessa server, we generally cannot delete it for you. You can manage iCloud data through your Apple account and remove calendar or reminder items in the corresponding Apple apps.
Support emails are retained only as long as reasonably necessary to handle the request and meet legal obligations.
7. Security
Spendy uses Apple platform protections such as app sandboxing, system permission controls, Keychain or biometric authentication where applicable, and iCloud security. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
8. Children's Privacy
Spendy is not directed to children under 13, and we do not knowingly collect personal information from children through an Onessa-operated service. If you believe a child has sent personal information to us, contact us so we can review and delete it where applicable.
9. Changes to This Policy
We may update this Policy when the App or legal requirements change. The effective date above identifies the latest version.
10. Contact Us
For privacy questions, contact jake@onessa.app.