← ClearSpend

Privacy Policy

Last updated: 30 June 2026 — ClearSpend v1.1 (Shared Wallet)

Local-first by default. Sharing is your choice.
The short version: If you use ClearSpend on your own, nothing changes and nothing is collected — you create no account and your transactions, budgets, categories, and wallets live only on your device (or in your own private iCloud). Shared Wallet is a separate, opt-in feature. Only when you choose to share a wallet with another person do we sync that one wallet's records to a secure cloud so you and the person you invited can co-manage it. Your personal wallets, budgets, and goals still never leave your device — even if you also use a Shared Wallet.

1. Two ways to use ClearSpend

ClearSpend has two modes, and they have very different privacy footprints:

ModeAccount?Where your data lives
Solo (the default for everyone) No account. No sign-in. On your device only, in Apple’s local SwiftData store. Optionally in your own private iCloud if you turn on iCloud sync.
Shared Wallet (opt-in, paid) Yes — you sign in to identify you and the person you invite. The shared wallet’s records sync to Google Cloud (Firebase) so both members can see one live set of records. Everything else stays on your device.

You are in Solo mode unless you deliberately create or accept a Shared Wallet invite. You never see a sign-in screen until that moment.

2. Solo mode — no account, nothing collected

3. No bank linking, ever

ClearSpend does not connect to your bank, does not use Plaid or any aggregator, and never asks for banking credentials or card numbers. You enter your transactions yourself. This is true in both Solo and Shared modes.

4. Shared Wallet — what the cloud receives

When (and only when) you create or accept a Shared Wallet, some data is sent to and stored in Google Cloud (Firebase) so that you and the one person you invite can co-manage the same records. This is what changes, and exactly what is involved.

4.1 Signing in

4.2 What data syncs to the cloud

For a shared wallet, the following is synced to Google Cloud Firestore:

4.3 What stays on your device even with a Shared Wallet

The privacy boundary is at the wallet level: shared wallets sync; personal wallets do not.

4.4 Who your shared data is shared with

Our sub-processors are listed in section 12.

4.5 Access control

4.6 Retention and deletion of shared data

4.7 Getting your data out (portability)

Either member can export the shared wallet’s records to CSV or JSON at any time, from within the app. A user can always walk away with a copy of any data they could see.

5. Analytics and crash reporting

ClearSpend contains no third-party analytics SDK and no third-party crash-reporting SDK, in Solo or Shared mode. We do not build advertising or behavioral profiles. (Apple’s own optional crash reports, if you have opted into them at the OS level, are handled by Apple under Apple’s privacy policy, not by us.)

6. Advertising and tracking

There are no ads, no advertising SDKs, and no cross-app or cross-site tracking in ClearSpend. We do not use the advertising identifier (IDFA), so the App Tracking Transparency prompt does not apply.

7. Purchases

Pro (one-time) and Household (subscription) purchases are processed by Apple through the App Store using StoreKit 2, with RevenueCat managing entitlement status. We never see your card number or payment details; Apple handles payment.

8. Notifications

9. Device identifiers

We do not collect the advertising identifier (IDFA) or use the device vendor identifier (IDFV) to track you. The only identifier associated with your cloud data is the account-derived Firebase user ID created when you sign in for Shared Wallet.

10. Children

ClearSpend is rated 4+ but is a personal-finance tool that is not directed to children under 13. Shared Wallet requires an account and is intended for adults; see the age requirement in the Terms of Use.

11. Legal bases and your rights (GDPR / CCPA)

This section is a plain-language summary, not legal advice. Your statutory rights depend on where you live.

12. Sub-processors and third-party services

Solo mode uses only Apple frameworks on your device. Shared Wallet relies on the following third parties, each of which processes data under its own terms:

ProviderWhat it does for ClearSpendApplies to
Google — Firebase / Google Cloud (Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging) Stores and syncs the shared wallet’s records; authenticates members; delivers opt-in push notifications; runs the secure invite/membership logic. Shared Wallet only
Apple (Sign in with Apple, StoreKit, iCloud/CloudKit, notifications) Sign-in, in-app purchases, optional iCloud sync of your own solo data, delivery of local notifications. Both modes
RevenueCat Manages subscription/entitlement status for Pro and Household. Both modes (purchases)

Google’s handling of the data it processes for us is governed by the Google Cloud / Firebase Data Processing terms. Their privacy policies: Firebase, Apple, RevenueCat.

13. Changes to this policy

If we change what data is collected, we update the “Last updated” date and note it in the App Store release notes. A material increase in data collection ships only with an app update, never silently — and the App Store privacy label is updated in that same release.

14. Contact

Questions or requests (including data deletion or export help): email dark2torch@gmail.com. We usually reply within a business day or two.

A note on financial guidance

ClearSpend is a personal budgeting and expense-tracking tool, not financial, investment, or tax advice. For guidance specific to your situation, talk to a qualified financial professional.