Privacy Policy

Essential Finance Guide

Effective date: 2026-10-08

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Essential Finance Guide stores lesson completion, study dates, the last opened lesson, monthly income, expense category names and amounts, and savings goal names, targets, saved amounts and deadlines on your device. Your optional display name and currency preference stay on your device. The app automatically creates a random installation secret in the device Keychain. When a connection is available, it sends progress, budgets and goals to our backend over HTTPS. The backend stores these records, update timestamps, revision numbers and a SHA-256 hash of the installation secret. There are no accounts, bank connections, analytics, advertising SDKs or payment services. Public website and API requests also reach Railway infrastructure, which can process IP addresses, request times, URLs, response statuses and technical network information.

How we use information

Local storage lets you read lessons and manage your budget and goals offline. Server storage synchronizes the records of the same installation when connectivity returns. The secret authorizes access to that installation’s data; it is not a shared password. Dates and completion records calculate your learning progress and study streak. Goal amounts and deadlines calculate planning estimates. Optional local notifications announce a recorded savings goal reaching its target. Technical hosting information supports service operation, reliability and protection against abuse.

Service providers and sharing

Railway hosts the backend, its persistent volume and public privacy page and receives the requests necessary to provide that infrastructure. The application uses Apple device facilities for Keychain storage, local notifications and operating-system data protection. It does not send goal notifications through an email or remote push provider. We do not sell personal information or use analytics, advertising, CRM or social sign-in providers. Hosting infrastructure may generate technical logs; the application server does not intentionally log installation secrets or record payloads. Information may be disclosed when legally required.

Data retention

Device records remain until you delete them through the app or remove its local storage. Keychain behavior is controlled by iOS and the installation secret can remain after uninstalling the app; it is configured as device-only and is not intended for transfer to a different device. Server records remain until you use Delete all personal data; there is no automatic age-based deletion schedule. This service creates no application-level copies or backup jobs. Device backups and any infrastructure backups or technical logs are controlled separately by their providers. We have not established a fixed retention period for those provider-managed copies or logs.

Deleting your information

Settings provides Delete all personal data. Before a server request, the app writes a durable deletion status on the device to prevent old cached records from being synchronized again if cleanup is interrupted. A successful deletion removes the installation’s progress, budgets and goals from the active server database, removes the local record file and preferences, and cancels pending goal notifications. This action requires internet access and working device storage. If preparation fails, no deletion request is sent. If a later step fails, deletion remains pending and old cached records are isolated from synchronization until you retry in Settings; the app does not show completed deletion. Reset learning progress only resets learning records and queues the reset for synchronization. Uninstalling the app alone does not request server deletion. Deletion from the active database does not guarantee immediate erasure of provider-managed backups or infrastructure logs. There is no sign-in or recovery service after the installation secret is lost.

Permissions and your choices

Notification permission is optional and is requested only when you select Enable goal completion alerts in Settings. You can refuse or withdraw it in iOS Settings without losing lessons, budgets or goals. Notifications are scheduled locally and do not verify a bank balance. The app does not request location, camera, microphone, contacts or photo-library access. Network access is used for synchronization and opening the public policy. You can use the local features without a connection; pending changes are kept on your device.

Your privacy rights

You can inspect and edit your learning records, budgets, goals, display name and currency in the app and request deletion through Settings. Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing, or obtain a copy of your personal information. Contact barclay.zouche@icloud.com for privacy questions or rights requests. We may need information sufficient to verify authority over the installation’s data, but you should never email your installation secret. Because there are no accounts, losing that secret can prevent us from identifying or recovering your records. You may also contact the relevant data protection authority where applicable.

Security

The app uses HTTPS for server communication and keeps the automatically generated secret in device-only Keychain storage. The backend checks the secret for every private request and isolates records using its hash. It validates payloads, enforces request limits and uses transactional SQLite storage on a persistent Railway volume. Local records are written atomically using iOS file protection. These measures reduce risk but no system can guarantee absolute security. Anyone with access to an unlocked device may be able to view its app records; protect your device and do not share its installation secret.

Children’s privacy

This app is intended for adults learning to manage personal finances, particularly ages 18 to 35, and is not directed to children. We do not ask for birth dates or intentionally collect children’s information. If you believe a child has provided personal information, contact barclay.zouche@icloud.com so we can address the request within the limits of installation-based identification.

Changes to this policy

We may update this policy when application behavior, processing or hosting practices change. The current version and effective date are published on this page and linked in app Settings. Material changes will be reflected in the policy and, when appropriate, an app update. Review this page periodically for the current practices.