Privacy Policy
Effective date: 2026-07-14
Version: 1.1
1) Data Controller
The controller of personal data is:
Canario-Lab / Chrumek App
Contact e-mail: chrumek@chrumek.app
2) Scope and Purpose
The Chrumek app is an app for tracking savings through records of "temptations" and confirmed transfers/saved amounts.
We do not operate user accounts and we do not collect data that allows us to identify you directly.
3) App data: on the device and in iCloud
Data you enter in the app, including savings entries, amounts, dates, categories, confirmed transfers, goals, category customizations, and synchronized settings, is stored in the app's local database on your device. When the device is signed in to iCloud and iCloud is available, this data is synchronized between your devices through the private CloudKit database and iCloud key-value storage associated with your Apple ID.
Synchronization is triggered by an actual change to app data or a synchronized setting. Merely opening another tab, switching a chart, or viewing a screen does not create data to upload. If iCloud is temporarily unavailable, the app continues to use the local copy and the system retries synchronization when the service becomes available again.
This data is not sent to Canario-Lab servers. iCloud and CloudKit are Apple services, and data in iCloud is processed according to Apple's terms and privacy rules. A manual backup and a CSV export are separate files created only at your request. Restoring a backup replaces the current app state; restored data and deletions may then synchronize to your other devices.
4) Features Requiring System Access
The app may use system features and related data only to the extent necessary for operation:
- Notifications (UNUserNotificationCenter) - if you enable reminders, the iOS system delivers notifications according to your settings.
- Language / region / currency / theme - used to format app content and appearance (without sending to us).
- iCloud / CloudKit - synchronizes app data and settings between your devices through your private iCloud when the service is available.
5) Bug Reports / Support Contact
If you use the "Report a bug" option or contact support:
- the app may create an e-mail draft in your mail application,
- the content may include diagnostic information (e.g., app version, iOS, language/currency settings) - exactly what you see in the e-mail content before sending,
- sending takes place only if you approve it yourself.
A sent e-mail is processed by your mail provider and by us as the recipient, solely for handling your request.
6) Purchases and Premium Access (Apple + RevenueCat)
If paid features (subscriptions or a one-time lifetime access purchase) are available in the app:
- payments are processed by Apple (App Store / In-App Purchases / StoreKit),
- the app uses RevenueCat as an infrastructure provider for purchase and Premium access handling (including offer presentation, access status verification, recognizing an active subscription or lifetime purchase, and granting premium access).
As part of purchase and Premium access handling, technical data related to the purchase may be processed, such as:
- transaction/purchase identifiers and product information,
- Premium access status (active/inactive), subscription status (e.g., renewals), or information about a one-time purchase,
- a technical user identifier used to link Premium access status (e.g., an anonymous App User ID generated by the SDK).
RevenueCat processes this data to provide purchase and Premium access handling services (as a processor), and Apple processes payment-related data in accordance with its own policies.
7) Analytics and tracking
The app may use Firebase Analytics to collect anonymous data about how the app is used (for example: adding an entry, completing a transfer, reaching the free-transfer limit, viewing the Premium offer screen, or tapping the main button on that screen).
This data does not include entry contents, amounts, goal names, categories, prices, purchase plans, payment details, or information that directly identifies you. The data is not linked to the user's identity or a specific device. We use it only to analyze how the app works, improve stability, and improve features.
We do not use analytics data to sell data or for advertising profiling.
8) Website (landing page)
If you visit our website, the hosting provider (e.g., GitHub Pages) may automatically process standard technical data in server logs (including IP address, browser type, date and time of request) for security, diagnostics, and service continuity purposes. The scope and rules of processing result from the hosting provider's policies.
9) Data recipients
- Apple, for iCloud and CloudKit synchronization, App Store purchases, and system services,
Data may be disclosed only to:
- payment and Premium access service providers: Apple and RevenueCat (purchase handling and access status),
- analytics service providers: Google Firebase Analytics (anonymous app event analytics),
- public authorities, where required by law.
10) Storage Period
- Data entered in the app is stored locally and, when iCloud is available, in your private iCloud until you delete it. Removing the app from one device does not necessarily remove the synchronized copy from iCloud or your other devices.
- E-mail correspondence data is retained for as long as needed to handle the request and to defend against claims (if necessary).
11) User Rights (EU/EEA)
If, in a given case, we process your personal data (e.g., when you send us an e-mail), you have the right to:
- access, rectification, erasure, and restriction of processing,
- object,
- lodge a complaint with the competent supervisory authority.
The scope of information obligations follows in particular from Article 13 GDPR.
12) Security
We apply reasonable organizational and technical safeguards appropriate to the service. Protecting your device and Apple ID, and keeping an independent manual backup, are also important parts of security.
13) Policy Changes
The policy may be updated with changes to app functions or legal requirements. The current version will be published on the app website.