Skip to content

Privacy Policy

Last updated: April 8, 2026

Διαβάστε στα Ελληνικά →

Tefteri ("we", "our", "us") is a personal finance tracking application for iOS. This Privacy Policy explains how we collect, use, and protect your information when you use our app.

1. Information We Collect

Account Information

When you create an account, we collect your email address and an encrypted password. This information is processed by Firebase Authentication (operated by Google LLC) for the sole purpose of authenticating your identity.

Financial Data

All financial entries you create (income, expenses, taxes, budgets, savings goals, trips) are stored locally on your device using Apple's SwiftData framework. If you enable iCloud sync, this data is also stored in your private iCloud account via Apple's CloudKit service.

We do not have access to your financial data. It is stored either on your device or in your personal iCloud account — never on our servers.

Receipt Photos

If you attach photos to entries (Tefteri Pro feature), the image data is stored locally on your device and synced via your iCloud account. Receipt photos are never transmitted to or stored on our servers.

Purchase Information

In-app purchases (Tefteri Pro) are processed entirely by Apple through StoreKit. We do not collect or store payment information, credit card numbers, or billing details. Apple provides us with a transaction receipt to verify your purchase status.

Local Notifications

Spending alerts and weekly digest notifications are scheduled locally on your device. No data is sent to external servers to generate these notifications.

2. How We Use Your Information

We use your information solely to:

  • Authenticate your identity (Firebase Auth)
  • Provide the core app functionality (local data storage and iCloud sync)
  • Verify your Pro purchase status (StoreKit receipt validation)

We do not use your information for:

  • Advertising or marketing profiling
  • Analytics or behavioral tracking
  • Selling or sharing with third parties
  • Training machine learning models

3. Third-Party Services

Service Provider Purpose Data Shared
Firebase Authentication Google LLC User sign-in Email, encrypted password
Firebase Crashlytics Google LLC Crash reporting (release builds only) Anonymous crash logs, device model, OS version
iCloud / CloudKit Apple Inc. Data sync across devices Your financial data (encrypted, in your private iCloud)
StoreKit Apple Inc. In-app purchases Transaction receipts (managed by Apple)

No other third-party services, SDKs, or trackers are integrated into the app. We do not use Google Analytics, Facebook SDK, or any advertising frameworks.

4. Data Storage & Security

  • Local storage: Financial data is stored on-device using Apple's SwiftData framework with SQLite encryption.
  • iCloud sync: When enabled, data is encrypted in transit and at rest by Apple's CloudKit infrastructure. Data is stored in your private CloudKit container — only accessible by your Apple ID.
  • Authentication: Passwords are hashed and managed by Firebase Authentication. We never store plaintext passwords.
  • Receipt photos: Stored using SwiftData's external storage attribute, synced via iCloud.

5. Data Retention

Your data is retained for as long as you use the app:

  • On-device data: Persists until you delete the app or use the in-app data deletion feature.
  • iCloud data: Persists in your iCloud account until you delete it from the app or remove it from iCloud settings.
  • Firebase account: Persists until you delete your account using the in-app account deletion feature.

When you delete your account through the app:

  • Your Firebase authentication record is permanently deleted
  • Your on-device data is deleted
  • Your iCloud data may persist briefly until CloudKit propagates the deletion

6. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights:

  • Right to Access: Request a copy of your data. You can export your data at any time using the in-app backup feature (JSON format).
  • Right to Rectification: Edit any of your financial entries directly in the app.
  • Right to Erasure: Delete your account and all associated data through Settings → Delete Account.
  • Right to Data Portability: Export your complete financial history as JSON or CSV (Pro).
  • Right to Restrict Processing: You can disable iCloud sync to keep data local-only.
  • Right to Object: You can stop using the app and delete your data at any time.

To exercise any of these rights, contact us at: privacy@tefteri.me

We will respond to your request within 30 days.

7. Children's Privacy

Tefteri is not designed for or directed at children under the age of 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the revised policy.

9. Contact Us

If you have questions about this Privacy Policy or your data:

Email: privacy@tefteri.me

Website: https://tefteri.me

Address: Athens, Greece