← ClearSpend
Privacy Policy
Last updated: 30 June 2026 — ClearSpend v1.1 (Shared Wallet)
Local-first by default. Sharing is your choice.
The short version: If you use ClearSpend on your own, nothing changes
and nothing is collected — you create no account and your transactions, budgets,
categories, and wallets live only on your device (or in your own private iCloud).
Shared Wallet is a separate, opt-in feature. Only when you choose to
share a wallet with another person do we sync that one wallet's records to a
secure cloud so you and the person you invited can co-manage it. Your personal wallets,
budgets, and goals still never leave your device — even if you also use a Shared
Wallet.
1. Two ways to use ClearSpend
ClearSpend has two modes, and they have very different privacy footprints:
| Mode | Account? | Where your data lives |
| Solo (the default for everyone) |
No account. No sign-in. |
On your device only, in Apple’s local SwiftData store. Optionally in your own
private iCloud if you turn on iCloud sync. |
| Shared Wallet (opt-in, paid) |
Yes — you sign in to identify you and the person you invite. |
The shared wallet’s records sync to Google Cloud (Firebase) so both members
can see one live set of records. Everything else stays on your device. |
You are in Solo mode unless you deliberately create or accept a Shared Wallet invite.
You never see a sign-in screen until that moment.
2. Solo mode — no account, nothing collected
- No account creation, no sign-in, and no server contact for your data.
- Your transactions, categories, budgets, goals, and wallets are stored locally on your
device using Apple’s SwiftData framework.
- The cloud-sync code (Firebase) is not even started for a solo user — it is
loaded only the first time you opt into sharing.
- If you enable iCloud sync, your data syncs through your own
Apple iCloud private database (CloudKit). It moves between your Apple devices under your
Apple ID; ClearSpend cannot read your CloudKit data, and it is not sent to us or to any
third party.
3. No bank linking, ever
ClearSpend does not connect to your bank, does not use Plaid or any aggregator, and never
asks for banking credentials or card numbers. You enter your transactions yourself. This is
true in both Solo and Shared modes.
4. Shared Wallet — what the cloud receives
When (and only when) you create or accept a Shared Wallet, some data is sent to and stored
in Google Cloud (Firebase) so that you and the one person you invite can co-manage the same
records. This is what changes, and exactly what is involved.
4.1 Signing in
- Sharing needs real accounts so two people can be told apart and invited securely.
You sign in with Sign in with Apple (primary on iPhone),
Sign in with Google, or email and password.
- With Sign in with Apple you may use Hide My Email, in which case we
receive Apple’s private relay address instead of your real one.
- Sign-in happens only when you start or accept a share. Solo users never sign in.
4.2 What data syncs to the cloud
For a shared wallet, the following is synced to Google Cloud Firestore:
- Shared financial records — the shared wallet and its
transactions (amounts, notes, dates, income/expense flags), its categories, budgets, and
goals. These are the records you and your partner intentionally share.
- Account identity — the user identifier created by Sign in with
Apple / Google / email (a Firebase user ID), and the email address returned by your
sign-in provider (which may be an Apple private-relay address). Used to authenticate you
and manage who belongs to the share.
- Membership records — who the members of the share are, their
roles (owner or member), display name, and when they joined.
- Device notification token (optional) — if, and only if, you turn
on “partner added a transaction” push notifications, a Firebase Cloud
Messaging token is stored so we can deliver those notifications to your device. If you
leave notifications off, no token is collected.
4.3 What stays on your device even with a Shared Wallet
- Your personal wallets and their transactions, categories, budgets,
and goals — never uploaded.
- App settings, onboarding state, streaks, and your purchase/subscription status.
- Receipt photos, if that feature is present, stay on your device in this version.
The privacy boundary is at the wallet level: shared wallets sync; personal wallets do not.
4.4 Who your shared data is shared with
- The person you invite. The whole point of a Shared Wallet is that the
one member you invite can see and edit the shared records. Do not share a wallet with
anyone you would not want to see everything in it.
- Google (Firebase / Google Cloud), as our sub-processor. Google stores
and transmits the shared data on our behalf so the feature can work. Google processes it
under our instructions and its own security and privacy commitments; we do not authorize
Google to use your shared-wallet content for its own purposes.
- We do not sell your data, and we do not share it with
advertisers, data brokers, or anyone else. There are no advertising or tracking SDKs in
the app.
Our sub-processors are listed in section 12.
4.5 Access control
- Only the invited members of a share can read or write its data, enforced by server-side
security rules. A device cannot add itself to a share; only our server-side invite
function can add a validated member.
- Invite links are single-use and expire after 72 hours.
4.6 Retention and deletion of shared data
- Shared records are retained while the share is active. When a wallet is deleted, or you
delete your account, the affected data enters a 30-day recovery window
and is then permanently deleted from our cloud by a scheduled process.
- Leaving a share: when you leave, you keep a local copy of the records
you last synced; the cloud share continues for the remaining member unless it too is
deleted.
- Deleting your account: Settings → delete account removes your
membership from every share. If you are the sole owner of a share, that share is scheduled
for deletion after the 30-day grace period.
- Lapsed subscription: if the Household subscription lapses, the shared
wallet becomes read-only and exportable — it is never deleted or held hostage.
Re-subscribing restores editing.
4.7 Getting your data out (portability)
Either member can export the shared wallet’s records to CSV or JSON at any time,
from within the app. A user can always walk away with a copy of any data they could see.
5. Analytics and crash reporting
ClearSpend contains no third-party analytics SDK and no third-party crash-reporting SDK,
in Solo or Shared mode. We do not build advertising or behavioral profiles. (Apple’s
own optional crash reports, if you have opted into them at the OS level, are handled by
Apple under Apple’s privacy policy, not by us.)
6. Advertising and tracking
There are no ads, no advertising SDKs, and no cross-app or cross-site tracking in
ClearSpend. We do not use the advertising identifier (IDFA), so the App Tracking
Transparency prompt does not apply.
7. Purchases
Pro (one-time) and Household (subscription) purchases are processed by Apple through the
App Store using StoreKit 2, with RevenueCat managing entitlement status. We never see your
card number or payment details; Apple handles payment.
8. Notifications
- Solo mode uses only local, on-device notifications (for example, budget reminders).
- Shared Wallet “partner added a transaction” push notifications are strictly
opt-in and are delivered via Firebase Cloud Messaging. If you do not opt in, no push token
is collected (see 4.2).
9. Device identifiers
We do not collect the advertising identifier (IDFA) or use the device vendor identifier
(IDFV) to track you. The only identifier associated with your cloud data is the
account-derived Firebase user ID created when you sign in for Shared Wallet.
10. Children
ClearSpend is rated 4+ but is a personal-finance tool that is not directed to children
under 13. Shared Wallet requires an account and is intended for adults; see the age
requirement in the Terms of Use.
11. Legal bases and your rights (GDPR / CCPA)
- Solo users: we do not collect or process personal data, so most of
this section simply does not apply — there is nothing on a server to access,
correct, or delete.
- Shared Wallet users, legal bases (GDPR): we process shared-wallet data
to provide the sharing service you requested — the lawful basis is
performance of a contract (delivering the Shared Wallet feature you
signed up for) and, for optional push notifications, your consent. You
may withdraw consent to notifications at any time in settings.
- Your rights: access, correction, deletion, and portability. Deletion
and export are available in-app (sections 4.6–4.7); for anything else, email us
(section 14).
- Controller/processor: for shared-wallet data, Moath Othman (the
developer) is the data controller and Google (Firebase) acts as a processor /
sub-processor under a data processing agreement.
- CCPA: we do not sell or “share” personal information as
those terms are defined under California law, and we do not use it for cross-context
behavioral advertising.
This section is a plain-language summary, not legal advice. Your statutory
rights depend on where you live.
12. Sub-processors and third-party services
Solo mode uses only Apple frameworks on your device. Shared Wallet relies on the following
third parties, each of which processes data under its own terms:
| Provider | What it does for ClearSpend | Applies to |
| Google — Firebase / Google Cloud (Authentication, Cloud
Firestore, Cloud Functions, Cloud Messaging) |
Stores and syncs the shared wallet’s records; authenticates members; delivers
opt-in push notifications; runs the secure invite/membership logic. |
Shared Wallet only |
| Apple (Sign in with Apple, StoreKit, iCloud/CloudKit,
notifications) |
Sign-in, in-app purchases, optional iCloud sync of your own solo data, delivery of
local notifications. |
Both modes |
| RevenueCat |
Manages subscription/entitlement status for Pro and Household. |
Both modes (purchases) |
Google’s handling of the data it processes for us is governed by the Google Cloud /
Firebase Data Processing terms. Their privacy policies:
Firebase,
Apple,
RevenueCat.
13. Changes to this policy
If we change what data is collected, we update the “Last updated” date and note
it in the App Store release notes. A material increase in data collection ships only with an
app update, never silently — and the App Store privacy label is updated in that same
release.
14. Contact
Questions or requests (including data deletion or export help): email
dark2torch@gmail.com. We usually reply within a
business day or two.
A note on financial guidance
ClearSpend is a personal budgeting and expense-tracking tool, not financial, investment,
or tax advice. For guidance specific to your situation, talk to a qualified financial
professional.