Privacy Policy

Last updated: 10 October 2026

Fundstash is a personal finance app for Android and iPhone. It is built so that your financial data stays on your phone. There is no Fundstash account and no Fundstash server that receives your transactions, messages, receipts or questions. This policy explains what the app stores, the few network requests it can make, and the choices you have.

1. Summary

2. Data stored on your device

The app stores the following only on your phone, in an SQLite database encrypted with AES-256 (SQLCipher). The encryption key is generated on the phone and kept in the iOS Keychain or Android Keystore.

Uninstalling the app deletes this data. “Clear all local data” in Settings deletes it without uninstalling.

3. Permissions and what they are used for

PermissionWhy
SMS (Android only, optional)To read bank and wallet messages on the device and record completed debits and credits. Promotions, OTPs and personal messages are ignored. Message content is never uploaded.
Camera and photos (optional)To scan receipts. Text recognition runs on the device (Google ML Kit, or Apple Vision on iPhone).
Contacts (optional)To pick a friend’s name when splitting a bill. Only the name you pick is used; the app does not read or copy your address book.
Notifications (optional)Local reminders: budget alerts and monthly debt reminders. They are scheduled on the device; no push service is used.
Face ID / fingerprint (optional)To lock the app. Biometric data is handled by the operating system and never seen by the app.

On iPhone, apps cannot read messages. If you set up the optional Shortcuts automation, iOS hands each incoming text to the app on your device, where it is processed the same way.

4. On-device AI

Fundstash can use an on-device language model to categorise entries, read natural-language notes, double-check imported messages and answer questions in “Ask Fundstash”. It uses Apple Intelligence (iPhone) or Gemini Nano through Android AICore where the phone supports them, or a small open model (Qwen3 0.6B) that you can choose to download. All of these run on your phone; your text and questions are not sent to us or to the model providers.

5. Network requests

The app works offline. It only uses the network in these cases, each started by you:

Like any internet request, these providers can see your IP address. Their own privacy policies apply to those requests.

6. Backups, exports and sharing

Backups are created only when you ask. A full backup is encrypted with a password you choose (AES-256-GCM, key derived with PBKDF2); without the password it cannot be read, by us or anyone else. CSV exports can optionally be encrypted the same way. You decide where a backup or export goes (for example Files, Drive or email); that service’s terms then apply.

When you share a split bill, the link contains the bill details (description, amount, names you entered). They sit after the “#” in the link, which browsers never send to a web server; the fundstash.app page that shows them decodes them in the reader’s browser.

7. This website

fundstash.app is a static website served by Cloudflare. It sets no cookies and loads no analytics, fonts or scripts from other companies. Cloudflare processes standard request data (such as IP address) to deliver and protect the site.

8. Children

Fundstash is not directed at children under 13 and does not knowingly collect any data from anyone.

9. Your choices

You can deny or revoke any permission in your phone’s settings, switch off SMS import, on-device AI and the assistant in the app, delete the downloaded AI model, and delete all data at any time. Because we hold no data about you, there is nothing for us to access, correct or delete on our side.

10. Changes

If this policy changes, the new version will be posted here with a new date. Material changes will also be noted in the app’s release notes.

11. Contact

Questions about privacy: privacy@fundstash.app.