Legal
App privacy notice
This draft describes the current offline iPhone build. It will be reviewed and completed with the operator’s legal details before public distribution.
Last updated
The short version
The current Nummiro iPhone app has no advertising, analytics, third-party SDKs or bank connection, and makes no network requests. Records you enter stay in a protected file on your device unless you deliberately export them. Nummiro does not receive those records.
The app contains the code for signing in to a Nummiro account, and it isswitched off and points at no server. There is nothing to sign in to, and the app cannot reach the network while it stays that way. When accounts are switched on, signing in will send an email address and a password — and never your money records, which stay on the device. This notice will be rewritten before that happens.
The app has not been publicly distributed. This notice documents the build being tested; it is not a claim that an App Store product is available.
What this covers
This notice covers the offline Nummiro iPhone application. The website and waitlist are covered by the separate website privacy policy.
The application will be offered by [controller — company or individual], of [jurisdiction] at [address]. Those details and the effective date must be completed before public distribution.
Data in the app
The app can store information you choose to enter, including:
- accounts and manually entered balances;
- income, expenses, transfers, adjustments and categories;
- recurring bills, budgets, savings goals and planning preferences;
- appearance, haptic, app-lock, onboarding and reminder preferences.
Derived figures such as safe-to-spend and the 30-day forecast are calculated on the device from those records. The app does not connect to a bank or automatically download transactions, and no Nummiro account — present or future — changes that: the records are what the app is for, and they are not uploaded.
Device permissions
If you enable app lock, iOS performs Face ID, Touch ID or device-passcode authentication; the app does not receive or store biometric data. If you enable local reminders, iOS asks for notification permission. Both features are optional and can be disabled in the app or device settings.
Storage and protection
The ledger is stored as one versioned file in the app’s private container using iOS complete file protection and atomic writes. The current build has no sync service and sends no copy to Nummiro. Optional app lock adds an identity check before opening the interface; it does not replace the security of the device passcode.
Export and import
You can deliberately export the complete ledger as JSON or entries as CSV using the iOS share sheet. Once you choose another app, person or storage destination, that recipient’s privacy practices apply. Import accepts a validated Nummiro ledger file and shows a preview before replacing the current ledger; it does not silently merge records.
Deletion
Delete All Data removes the app’s ledger records, saved ledger file and Nummiro preferences from that installation. Copies you previously exported, or copies contained in a device backup controlled by Apple, are outside the app and must be managed at their destination.
Device backups
Your device settings determine whether application data is included in an encrypted computer backup or iCloud device backup. Those services are provided by Apple and governed by your Apple settings and agreement. The current app does not operate a separate Nummiro backup service.
Future accounts, cards or connected services
Card, cash-reload and bank-connected services are not part of the current app. They would require regulated partners, identity checks, network services and a materially different privacy notice. Accounts are further along than the rest of that list — the sign-in code is written and tested — but no less switched off: no server exists to sign in to, and a test asserts the app ships with no address for one. This notice must be updated and presented before any such data collection begins.
Contact
Questions about this notice can be sent to[email protected].