Legal
Privacy Policy
This page is generated from the text shipped inside the app (lib/core/legal_text.dart), so the website and the app say the same thing.
Last updated: 2026-09-24
1. What we do NOT collect
EasyCost has no analytics SDK, no advertising SDK and no third-party tracking. We do not collect device identifiers for marketing, and we do not build profiles.
2. When you do not sign in
Your ledger stays in a local database on your device. Nothing is uploaded anywhere, and we cannot see any of it.
3. What we receive if you choose to sign in and sync
Signing in uses Sign in with Apple. If you enable cloud sync, we store:
- Your Apple account identifier (the "sub" claim) and, if you allow it, your email address;
- Your first and last name, only if Apple provides it (Apple sends it on first authorization);
- The time of your most recent sign-in (used to tell an active account from an abandoned one);
- Your ledger entries: amount, category, note, timestamp, UTC offset, currency, type and the deletion flag, plus created/updated timestamps used to resolve conflicts;
- A sync cursor per ledger scope: a monotonically increasing counter with no content in it.
We use this data only to sync your ledger between your own devices and (if you join a family) to show the shared ledger to its members. We do not sell it or share it with anyone else.
4. Family sharing
If you create or join a family, we store the family name you choose, its invite code, and the list of members with their role and join time — that is what makes the shared ledger work. The shared ledger is visible to the members of that family. When you leave — or when the owner disbands the family — a copy of the shared ledger is copied back to each member's personal space.
5. Subscriptions
Payments are processed by Apple. We never receive your payment details. To verify a purchase, our server stores your subscription status and expiry date, the App Store transaction identifier behind that subscription, an account token we generate so the purchase can be matched to your account, and a binding record that links that transaction to your account. These are used only to decide what the app unlocks and to verify or restore your purchase — never for advertising or profiling. Binding records are kept for 24 months after they are created (a scheduled database rule deletes them), which is what stops the same subscription from being claimed by a different account.
6. Storage, retention and deletion
Synced data is stored on a server we operate. You can delete your account at any time from Settings → Cloud sync → Delete account; this erases the account, the family membership (a shared ledger is copied back to every member first) and all synced entries from our server immediately. Your ledger on the device is not touched by that action — use Settings → Data to erase it locally, or delete the app. What remains after deletion: the content-free sync counters described in section 3, and subscription binding records for the retention period in section 5 (they contain no name, email or ledger content).
7. Children
EasyCost is not directed at children under 13, and we do not knowingly collect data from them.
8. Changes and contact
If this policy changes, we will note it in the app. Questions: support@letskeep.com.