Privacy Policy — MoneyFlux
Effective date: September 15, 2026 · Last updated: September 15, 2026
MoneyFlux ("the App") is developed and published by Taras Chernysh, an independent software developer based in Ukraine ("we", "us", "the Developer").
This Privacy Policy explains how MoneyFlux handles information. The short version: your records live on your device and in your own private iCloud, where only you can read them. Three companies process something on our behalf — RevenueCat for your subscription, Cloudflare for the small relay we run, and OpenAI for the optional AI assistant — and none of them receives an individual transaction, a balance or an account number.
1. Summary
| Question | Answer |
|---|---|
| Do we receive your transactions, balances or account numbers? | No. Individual records stay on your device and in your own private iCloud, where only you can read them. |
| Is there a server of ours? | One, and only for the AI assistant. A small relay that holds the OpenAI key so the App never has to. It stores no ledger and keeps no copy of what you ask. |
| Do we use analytics, ad or tracking SDKs? | No ads, no advertising identifier, no attribution or behavioural analytics, and no cross-app tracking. RevenueCat shows us aggregate subscription charts; that is the only reporting we have. |
| Who else processes anything? | Four: Apple, RevenueCat, Cloudflare and OpenAI — and OpenAI only if you switch the assistant on. Section 10 names what each one receives. |
| Do you need an account to use MoneyFlux? | No. The App has no accounts and no sign-in, so there is no account to delete. |
| Where is your data stored? | On your device, and — through Apple's CloudKit — in your own private Apple iCloud account. |
| Is the AI assistant on by default? | No. It stays off until you read a screen naming OpenAI and tap Allow, and you can switch it off again at Settings → AI Assistant. |
| Which devices? | iPhone and iPad, and Mac through Mac Catalyst. The AI assistant needs Apple's App Attest hardware, so it runs on iPhone and iPad only. |
2. Who We Are, and When We Are a Controller
The Developer is Taras Chernysh, an independent developer established in Ukraine. Contact details are in section 20.
We act as a data controller for four narrow things: the subscription record held at RevenueCat, the per-device record and operational logs at our AI relay, an AI assistant request while it is in transit through that relay, and any support email you choose to send us.
We are not a controller of the ledger you build inside the App. Those records live in your device's storage and, through Apple's CloudKit, in your own private iCloud account. Apple processes that under its own relationship with you, and we have no access to it.
Where the EU or UK GDPR applies, the legal bases we rely on are:
| Processing | Legal basis |
|---|---|
| Your subscription and the entitlement checks that unlock paid features | Art. 6(1)(b) — performance of the contract you entered when you subscribed |
| The AI assistant | Art. 6(1)(a) — your consent, which you can withdraw at any time |
| Abuse prevention, the per-device quota and the spending ceiling | Art. 6(1)(f) — our legitimate interest in keeping a public endpoint from being drained. The data involved is minimal and pseudonymous, and there is no less intrusive way to do it |
| Answering a support email you send us | Art. 6(1)(b) and 6(1)(f) — supporting the App and responding to you |
3. What We Never Receive
None of the following is collected, transmitted, sold, rented, or otherwise processed by us:
- Your name, email address, phone number, or postal address
- Your bank credentials, card numbers, or banking logins (the App never asks for them and cannot connect to a bank)
- Your individual transactions, balances, account numbers or IBANs, categories, accounts, loans, recurring payments, notes, or tags
- The bank statement files (CSV/PDF) that you import
- Your contacts, photos, microphone, or location
- Your advertising identifier (IDFA) — there is no App Tracking Transparency prompt because there is nothing to track
- Usage analytics, behavioural events, session recordings, or crash telemetry sent to us
Two third-party libraries ship inside the App. Factory is dependency-injection plumbing: it opens no connections and touches no user data. RevenueCat handles subscriptions and is described in section 8. Everything else the App sends, it sends over code we wrote, from one directory of the source tree, to one address — our AI relay. There is no advertising, attribution or analytics SDK of any kind.
MoneyFlux's App Store privacy information ("App Privacy" on its App Store product page) declares four types — Purchase History, Device ID, Other Financial Info and Other User Content — each marked linked to you, each for App Functionality, and none for Tracking. The first two describe the subscription. The last two describe the AI assistant and apply only once you have switched it on. They are declared as linked because we can look a subscription up by the identifier involved — not because we hold your name, which we do not. The label and this Policy describe the same thing.
4. Data You Create Inside the App
All content you create or import — accounts, transactions, categories, budgets, recurring payments, loans, capital, positions, tags, notes, and imported bank statements — is stored locally on your device in an app-private database (Apple Core Data).
Bank statement files that you import are parsed on your device. MoneyFlux currently reads PrivatBank and MonoBank CSV statements, and Oschadbank, Scotiabank, Raiffeisen Bank and A-Bank PDF statements, as well as a CSV format for trading positions. You export the file from your bank yourself and pick it with the system file picker; the App never connects to a bank and never asks for a banking login. The file contents are not uploaded anywhere. Once parsing is finished, MoneyFlux keeps only the records you chose to import.
You remain the sole owner and controller of this data at all times.
5. Files You Export
MoneyFlux can produce a per-dataset CSV, a multi-page PDF statement, and a full JSON backup you can restore from. All three are generated on your device and handed to the system share sheet.
We receive no copy of any of them. Once you send an export to Files, Mail, a messaging app, or any other service, it is outside the App's protection and governed by whatever you sent it to. A JSON backup contains your complete ledger in readable form — keep it as carefully as you would keep a bank statement.
6. iCloud Sync
MoneyFlux uses Apple's CloudKit private database to synchronise your data between your own Apple devices.
- Data is stored in your personal iCloud account, not in any account or infrastructure belonging to the Developer.
- The Developer has no access to your iCloud container, and cannot read, export, or restore your data.
- Sync is handled entirely by Apple's frameworks and is governed by Apple's privacy practices. See Apple's Privacy Policy: https://www.apple.com/legal/privacy/
- MoneyFlux follows your Apple Account's iCloud setting. To stop the App syncing, turn it off in Settings → your Apple Account → iCloud → Saved to iCloud → MoneyFlux on iPhone or iPad, or in System Settings → your Apple Account → iCloud on a Mac. The App itself has no separate switch.
7. Device Permissions and System Features
MoneyFlux may use the following, always with your consent:
| Feature | Purpose | Leaves your device? |
|---|---|---|
| Files access | To let you pick a bank statement (CSV/PDF) for import | No |
| Notifications | Local reminders for upcoming recurring payments, loan due dates and capital revaluation | No — scheduled locally on your device |
| Face ID / Touch ID / Optic ID / device passcode | To lock the App. Off by default | No — authentication is performed by the operating system; the App only receives a success or failure result and never sees your biometric data |
| iCloud | Sync between your own devices | Only to your own iCloud account |
| App Attest / Secure Enclave | Proves to our relay that a request came from a genuine, unmodified copy of the App | Only when the AI assistant is on. A key handle generated on your device leaves; it carries no name, account or advertising identifier |
You can revoke any of these permissions at any time in your device's Settings.
8. Subscriptions and Payments
MoneyFlux is free to download. Some features are part of MoneyFlux Premium, an auto-renewing subscription offered monthly and annually. Apple takes the payment through the App Store. We never see or store your payment card details.
RevenueCat, Inc. (United States) is our processor for subscription state. It receives:
- the App Store transaction (receipt) for a purchase;
- an anonymous app user identifier that the RevenueCat SDK generates for your installation — we never call its login method, so this identifier carries no email address, no name and no Apple Account ID;
- a device-scoped identifier that the SDK sends by default.
It does not receive a transaction of yours, a balance, an account, a statement, or anything you typed into the App.
This exists so that the App — and our AI relay — can tell whether your subscription is active. Every RevenueCat dashboard integration is switched off: no data is forwarded from RevenueCat to any analytics, attribution or advertising service, and no webhook of ours receives it. See RevenueCat's privacy policy: https://www.revenuecat.com/privacy/. Transfers to the United States are covered in section 11.
9. The AI Assistant
9.1 What it is, and where it runs
The AI assistant is an optional Premium feature available on three screens — Analytics, Positions and Commitments. It answers questions in words, using figures your device has already calculated. The model is not permitted to produce a number of its own; it is handed a summary and writes the sentence.
It requires Apple's App Attest hardware, so it runs on iPhone and iPad only — not in the Mac (Catalyst) build and not in the Simulator.
9.2 It is off until you turn it on
No request is made before you have seen a screen naming OpenAI and tapped Allow and continue. You can switch it back off at Settings → AI Assistant → "Allow sending summaries", and the App stops sending immediately. Withdrawing consent does not affect processing that already took place, and nothing else in the App stops working — every other screen behaves exactly as it did before.
9.3 Exactly what is sent
One summary, for the screen you asked from, together with the question you typed (capped at 300 characters), a single language code, and a single currency code. The App refuses to send two currencies in one request, because nothing downstream may add them together.
From Analytics (spending): the period label; income, expenses, net and the transaction count; the same four figures for the previous period; category names with amount and share; top merchant names with amount and visit count; weekday averages; and recurring payment names with amount and next date.
From Positions: a label describing the slice on screen; counts of visible, funded, watching, liquidated and stalled positions; a summary total; and, for each trader, their name, their signal, closed and stalled counts, win rates, what they claimed, what their own quoted prices imply, and what your money actually did.
From Commitments: monthly and annual recurring totals; amounts still outstanding lent and borrowed; active subscription and loan counts; what falls due next (name, amount, date); and what is overdue (amount, date, days overdue, and whether it is lent or borrowed).
9.4 What is never sent
- An individual transaction
- An account number or IBAN, or a balance
- A bank name, or any statement file
- The name of anyone you have lent to or borrowed from — this is deliberately left out of the payload; the amount and the age identify the loan instead
- Your name, email address or postal address
- Your location, or your advertising identifier
9.5 Who processes it, in order
- Your device computes the figures and signs the request with a key held in its Secure Enclave.
- Our relay, which runs on Cloudflare Workers, checks that signature, checks your subscription with RevenueCat, applies a monthly limit, then forwards the summary to OpenAI and passes the answer back. It stores no request and no answer. What it does keep, per device, is: the attestation public key, a counter that stops a request being replayed, the anonymous subscription identifier, and a tally of how many requests you have made this month. Its operational log records which screen was asked about, token counts, whether a question was present, and the first eight characters of the key handle — never the figures, the question, or the answer.
- OpenAI writes the sentence, from a prompt our relay builds. The App never chooses a model; the model is pinned on our side, and the endpoint accepts data, not prompts.
The relay exists for one reason: an OpenAI key that ships inside an app can be extracted from the binary by anyone who downloads it. Holding the key on a server is what keeps it out of the App.
9.6 How long it is kept
Our relay keeps no request content at any point. The per-device record persists for as long as the installation does; section 15 explains how to have it deleted. Operational logs are retained by Cloudflare for a short operational window under their own policy.
OpenAI does not use inputs or outputs from this API to train any model. They are retained for up to 30 days for abuse monitoring, and then deleted.
We have not yet contracted Zero Data Retention with OpenAI. Until we do, that 30-day abuse-monitoring window is the accurate statement, and we would rather publish it than a flattering one. When Zero Data Retention is in place this paragraph will say that inputs are not retained at all, and the change will be dated on this page.
9.7 Where it goes
Our relay runs on Cloudflare's global edge network. OpenAI processes in the United States. See section 11.
9.8 What it cannot do
The assistant observes; it does not advise. It is instructed never to calculate, never to convert a currency, never to value, forecast or recommend anything — and a question asking for any of those is answered as out of scope.
Those instructions constrain it; they do not guarantee it. An answer can still be incomplete or mistaken. It is not financial, investment, tax, accounting or legal advice, and you should check anything you intend to act on against your own records. See section 2.1 of the Terms of Use.
9.9 Limits
Up to 50 requests per device per month, and an overall daily spending ceiling across all users. When either is reached, the assistant answers that it is unavailable. These limits exist to keep a public endpoint from being drained — not to profile you.
10. Sub-processors and Recipients
These are every company that processes anything on our behalf. The list is exhaustive as of the date at the top of this page.
| Who | What they do for us | What they receive | Where | Their policy |
|---|---|---|---|---|
| Apple Inc. / Apple Distribution International | App Store distribution, iCloud (CloudKit private database), StoreKit payments, App Attest verification | Your ledger inside your own iCloud account, which we cannot access; your purchase; and confirmation that a device attested | Apple's global infrastructure | apple.com/legal/privacy |
| RevenueCat, Inc. | Subscription state. Our relay also asks RevenueCat whether your subscription is active before each assistant request | The App Store transaction, an anonymous app user identifier, and a device-scoped identifier | United States | revenuecat.com/privacy |
| Cloudflare, Inc. | Hosts our AI relay (Workers and Durable Objects). Not a pass-through: it holds per-device state on our behalf | The assistant request in transit; per device, the attestation key, a replay counter, the anonymous subscription identifier and a monthly tally; plus metadata logs | Cloudflare's global edge | cloudflare.com/privacypolicy |
| OpenAI | Writes the assistant's sentences | The summary described in section 9.3 and your typed question — only if you enabled the assistant | United States | openai.com/policies/privacy-policy |
Adding a new sub-processor means a new version of this page, dated — and, if it widens what leaves your device, a fresh consent screen in the App.
11. International Transfers
The Developer is established in Ukraine. Where the EU or UK GDPR applies to you, it applies to us under Article 3(2).
Transfers outside the EEA and the UK take place for two things: your subscription record, which goes to RevenueCat in the United States, and — only if you enabled the assistant — an assistant request, which goes to OpenAI in the United States. Our relay runs on Cloudflare's global edge network, so a request may be handled at a location near you.
These transfers are made under each provider's data processing terms. Any transfer performed by Apple as part of iCloud sync is governed by Apple's own terms and its relationship with you.
12. How Long Things Are Kept
| What | Where | How long |
|---|---|---|
| Your ledger | Your device and your own private iCloud | Until you delete it. We hold no copy |
| Exported CSV, PDF or JSON files | Wherever you sent them | Under your control. We receive none of them |
| Subscription record | RevenueCat | For the life of the subscription record, under RevenueCat's own retention policy. Deletable on request |
| Per-device record at our relay (attestation key, replay counter, anonymous subscription identifier, monthly tally) | Our Cloudflare relay | Kept while the installation exists. No request content at any point. Deleted on request — see section 15 |
| Relay operational logs (screen asked about, token counts, status, eight-character key prefix) | Cloudflare | A short operational window set by Cloudflare |
| An assistant request and its answer | OpenAI | Not used for training. Up to 30 days for abuse monitoring, then deleted |
| The answer you see on screen | Your device, in memory | Not written to the App's database |
| A support email you send us | The Developer's mailbox | Up to 24 months |
13. Security
On your device, your data is protected by the operating system's application sandbox and, when your device is locked with a passcode, by full-device encryption. iCloud data is encrypted in transit and at rest by Apple, in your account. You can enable an additional Face ID, Touch ID, Optic ID or passcode lock inside MoneyFlux; it is off by default.
For the AI relay: every request is signed by a key held in your device's Secure Enclave and verified against Apple, so a request from anything other than a genuine, unmodified build is refused. The OpenAI key lives only in the relay's secret store and never ships inside the App. Figures, questions and answers are excluded from logging by design. Per-device and global rate limits cap abuse.
There is no database of MoneyFlux users' financial records anywhere outside your own devices and your own iCloud — the relay holds counters and keys, not ledgers. No system is perfectly secure, however, and you are responsible for keeping your device and Apple Account secure.
Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it and, where the law requires it, affected users. Because we hold no email addresses, notice to users is given in the App's release notes and on this page.
14. Children
MoneyFlux is not directed at children under 13, or under 16 where local law sets that age for consent-based processing. The AI assistant additionally requires a paid subscription, and therefore an Apple Account able to transact.
We have no way to verify age and do not knowingly process a child's personal data. If you believe a child has used the assistant, email us and we will delete the relay's per-device record.
15. Your Rights
15.1 General rights (all users)
Privacy laws such as the EU and UK GDPR, the Law of Ukraine "On Personal Data Protection", Canada's PIPEDA, and the CCPA/CPRA grant rights of access, correction, deletion, portability, objection, and withdrawal of consent. With MoneyFlux those rights split in two.
Rights you exercise yourself, on the device. Your ledger is in your hands, not ours, so access, correction, export and erasure are immediate and need no request to us:
- Access and portability — every record is visible in the App, and you can export CSV, PDF or a full JSON backup at any time.
- Correction — edit or delete any record inside the App.
- Erasure — delete individual records, or use Settings to erase everything on the device and in iCloud; then delete the App; then, if you wish, remove its iCloud data in Settings → your Apple Account → iCloud → Manage Account Storage → MoneyFlux → Delete Data.
- Withdrawal of consent — switch the AI assistant off at Settings → AI Assistant, and stop using optional features such as notifications at any time.
Rights you exercise against us. We hold three things, and you can ask us about any of them: the subscription record at RevenueCat, the per-device record and operational logs at our AI relay, and any support email you sent us. Email us at the address in section 20 and tell us which right you want to exercise.
One practical limitation, stated plainly: the relay's per-device record is keyed by an attestation identifier that the App does not currently display, so we cannot locate it from an email address alone. Tell us your subscription's purchase date and App Store country and we will locate and delete the subscription record, and the device record bound to it. We are working on a way for the App to delete the device record directly when you withdraw consent.
15.2 European Economic Area and UK users (GDPR)
The controller is Taras Chernysh, Ukraine, contactable at the address in section 20. The legal bases we rely on are set out in section 2.
You have the rights of access, rectification, erasure, restriction of processing, objection, and data portability, and the right to withdraw your consent to the AI assistant at any time — withdrawal does not affect the lawfulness of processing carried out before it.
No decision producing legal effects concerning you, or similarly significantly affecting you, is made by automated means. The assistant writes sentences; it changes nothing in your records and decides nothing about you.
You may lodge a complaint with your local supervisory authority, with the UK Information Commissioner's Office, or with the Ukrainian Parliament Commissioner for Human Rights.
15.3 California users (CCPA/CPRA)
In the preceding twelve months we have collected the following categories of personal information:
- Identifiers — an anonymous app user identifier, a device-scoped identifier, and an attestation key identifier.
- Commercial information — your subscription purchase history.
- Only if you enabled the AI assistant: other financial information (the aggregated totals described in section 9.3) and user content (the question you typed).
We collect these to provide the subscription and the assistant, and to prevent abuse of our relay. The sources are you and your device. We disclose them only to the sub-processors named in section 10.
We do not sell personal information, do not share personal information for cross-context behavioural advertising, do not use sensitive personal information to infer characteristics, do not offer financial incentives, and do not discriminate against users for exercising applicable privacy rights.
To submit a request, email chernyshtar@gmail.com with the subject line "CCPA Privacy Request". We aim to respond within 45 days, extendable as the law allows.
15.4 Turkish users (KVKK)
Under Turkey's KVKK you may learn whether your personal data is processed, request information about the purposes of processing, learn the recipients, and request correction or deletion.
Sections 2, 10 and 12 answer the first three of those in advance. For correction or deletion, email us at the address in section 20 and we will honour the request to the extent applicable.
15.5 Canadian users (PIPEDA)
If PIPEDA applies to you, you may request access to, correction of, or deletion of personal information we hold — that is, the three items listed in section 15.1. Where a breach creates a real risk of significant harm, we will report it as PIPEDA requires. Contact details are in section 20.
16. Support Email and Diagnostics
When you use Settings → Support, the App opens your mail app with a pre-filled message. You send it; the App transmits nothing on its own.
The pre-filled block contains the App's version and build number, your device model identifier (for example
iPhone17,1), your operating system version, your language code and your device's locale currency. That is a machine-readable diagnostic, not an identifier of you —
and you can delete those lines before sending
if you would rather not include them. Anything else in the email is whatever you chose to write.
Support emails are kept in the Developer's mailbox for up to 24 months.
17. App Store and Apple
MoneyFlux is distributed through the Apple App Store. Apple may collect information related to your download, device, and — if you have opted in to sharing analytics with developers — aggregated, anonymised crash and usage statistics. This collection is performed by Apple under Apple's own terms, not by us. Any such reports we may view in App Store Connect are aggregated and cannot be used to identify you or to see your financial data.
If you use the AI assistant, its App Attest attestation is verified against Apple's servers. Apple sees that a device attested — not what you asked.
18. Changes to This Policy
We may update this Privacy Policy from time to time — for example, if new features change how data is handled. The updated version will be posted on this page with a revised "Last updated" date, and material changes will additionally be announced in the App's release notes.
A material change that widens what leaves your device takes effect only after you have been shown a fresh consent screen in the App. This version replaces the version dated August 20, 2026.
19. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of Ukraine, and disputes relating to this Policy are subject to the jurisdiction of the courts of Ukraine.
If you reside in a jurisdiction with non-waivable privacy rights (including under GDPR, CCPA/CPRA, KVKK, PIPEDA, or other applicable law), nothing in this section limits those mandatory rights.
20. Contact and Support
This is the support and contact point for MoneyFlux — for questions about this Privacy Policy, about the App's data practices, or for help with the App itself. The Developer, not Apple, is solely responsible for support.
Taras Chernysh
Independent developer, Ukraine
Email: chernyshtar@gmail.com
For privacy rights requests, please email us with a clear subject line such as "Privacy Rights Request" and include:
- your country or state of residence;
- the specific right you want to exercise (for example: access, correction, deletion, objection, restriction, or portability);
- if your request concerns the subscription or the AI assistant, the purchase date and App Store country of your subscription, so that we can locate the record.
We aim to respond to all enquiries within 30 days, or within the timeframes required by applicable law.