Privacy Policy
Last updated: 12 September 2026
This Privacy Policy explains what data Notch ("the app", "we", "us") handles, where it is stored, and the choices you have. The app is designed to be local-first: your financial records are stored on your device. Cloud sync uploads records when you sign in and use premium sync; cloud parsing separately sends the text or image you submit, as described below.
Using the app without an account
You can use the core app as a guest, without creating an account. In guest mode your expenses, accounts, categories and settings are stored only on your device (in an encrypted-at-rest local database provided by your operating system). We do not receive this data, and it is not backed up to our servers. Clearing the app's local data or uninstalling the app permanently deletes it.
Data stored on your device
Regardless of account status, the following is stored locally on your device:
- Transactions you record (amount, category, note, date, payment details you enter)
- Personal and shared accounts you create
- Custom categories, currency and language preferences
- App settings such as theme and onboarding state
Data we process when you sign in
If you create an account or sign in (including Sign in with Apple), we process the following through our authentication and database service providers:
- Your email address and display name
- An account identifier used to associate your data with you
- For premium (sync) users: your transactions, accounts, groups, group memberships and expense splits, so they can sync across your devices and to people you share groups with
Cloud sync uploads your financial records only when you are a premium subscriber and sync is active. Without sync, your saved financial records remain on-device; content you submit for cloud parsing is processed separately as described under AI-assisted features.
Shared groups
If you create or join a shared group, the members of that group can see the expenses, splits and balances within that group, along with your display name. Do not add people to a group unless you intend to share that information with them.
Subscriptions and payments
Premium subscriptions are billed through the Apple App Store. We use a subscription management service to verify purchases and unlock premium features. We do not receive or store your full payment card details. We receive subscription status information (for example, whether your subscription is active, trial, or cancelled, and its renewal date) to unlock premium features.
Notifications
If you enable notifications while signed in, we use a notification delivery service to send push notifications (for example, group activity). This involves storing a device push token linked to your account. You can disable notifications at any time in Settings or your device settings.
Optional product analytics
After a clear in-app disclosure, you can choose whether to share limited product-usage analytics. Analytics are off until you make that choice, and you can withdraw it at any time under Settings > Privacy.
When enabled, we collect events such as which screen or feature was used, whether an action succeeded, broad count or duration ranges, app version, and whether the app was being used as a guest or signed-in account. Each installation uses a random analytics identifier. We rotate it when authentication changes and do not send your account identifier, name, or email to our analytics provider or use them to link analytics activity.
We do not send transaction amounts, balances, currency, descriptions, notes, category or account names, group or transaction identifiers, invite codes, receipt images, voice transcripts, raw error messages, or stack traces to our analytics provider. We do not use these analytics to create personal profiles, record your screen or replay your sessions, or automatically capture your interactions. We disable location processing based on IP addresses.
These analytics are processed in the European Union. Analytics are used only to understand aggregate feature adoption, reliability, and conversion. They are not used for advertising. Analytics use a random installation identifier rather than your account identity. Deleting your account does not automatically identify and erase past analytics events. You can contact us at support@mail.ashmmapp.com with privacy questions or requests.
Crash and diagnostics data
To keep the app stable and fix problems, we use a crash reporting service to collect crash reports and error diagnostics when the app misbehaves. When a crash or handled error occurs, this may include:
- The error type, message and stack trace
- Device information such as model, operating system version and available memory
- The app version and, where set, whether the device is rooted or jailbroken
- A randomly generated installation identifier that is not linked to your name or email
This data is used only to diagnose and fix stability issues. It is not used for advertising or profiling. We aim to avoid including your financial records in error reports, but you should not rely on error diagnostics being free of the values you entered. Crash reports are retained by the provider for a limited period (currently around 90 days). Diagnostics are not collected in development builds.
Feedback you send us
When you use "Send feedback" in Settings you can choose whether to attach a diagnostics report, and it is not attached unless you turn that on. It contains the app version, your device model and operating system version, your language setting, whether you are signed in or subscribed, counts of how many records are stored on your device, and recent warning and error log lines from the current app session. We do not put your expense descriptions, amounts, category names, group names or the names of other people into it, but log lines come from error messages and we cannot guarantee they never quote something you entered. Your message, the diagnostics you attached, and any reply address you enter are stored so we can act on the report, and are sent to our support inbox. If you delete your account, past feedback is kept but is no longer linked to you.
AI-assisted features
- On-device parsing: Voice command entry uses an AI model that runs entirely on your device. The audio-derived text is processed locally and is not sent to us.
- Cloud parsing: Some features, such as receipt scanning and transaction message parsing, send the specific text or image you provide to a third-party AI service solely to extract structured expense data. This content is used only to fulfil your request and is not used to build a profile of you.
Third-party services
We use third-party providers for cloud hosting and storage, authentication, subscription management, notification delivery, crash diagnostics, optional product analytics and AI-assisted expense extraction. Depending on the features you use and your choices, we share the data described in the relevant sections above with these categories of providers to operate those features.
Optional product analytics are processed in the European Union. Cloud AI services receive the specific text or image you submit for parsing. Your app store and sign-in provider also process information under their own privacy terms. Contact us at support@mail.ashmmapp.com with questions about third-party data processing.
Data retention and deletion
- Guest data: deleted when you clear local data or uninstall the app.
- Account data: you can permanently delete your account and its synced data from Settings. Deleting your account removes your profile and associated records from our database. Backups held by our processors may persist for a limited period before being overwritten.
- Product analytics: collection stops immediately when you turn it off. Analytics are retained according to the configured analytics retention period and then expire. Deleting your account stops future account-related server analytics, but cannot identify earlier analytics events for selective deletion because they are not linked to your account.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to withdraw consent. You can exercise most of these directly in the app (export, delete account) or by contacting us at support@mail.ashmmapp.com.
Children
The app is not directed to children under the age required by your local law to consent to data processing, and we do not knowingly collect their data.
Changes to this policy
We may update this policy. Material changes will be reflected by an updated effective date and, where appropriate, an in-app notice.
Contact
For any privacy question or request, contact us at support@mail.ashmmapp.com.