01. Who operates the app
Money Manager is a personal finance tracker for iPhone, operated by Ivan Asenov Ivanov, based in Bulgaria.
Contact address: ul Borimechka 11, Plovdiv, Bulgaria
Privacy contact: ivanivanov.ii726@gmail.com
Support contact: ivanivanov.ii726@gmail.com
Website: https://money.0xivanov.dev
Money Manager’s initial launch is for Bulgaria. This policy covers the Money Manager iOS app and the backend services that support its features. Some features involve external services, as described below.
02. Information we process and why
Account information
We store your email address, internal user ID and account creation and update timestamps to recognize your account and associate your records with it. Password-based accounts also have a password hash used for authentication. Apple-linked accounts store an Apple user identifier and an encrypted refresh token to support Apple sign-in. Your email may be an Apple private relay address.
Connected bank information
To maintain authorized bank connections and synchronize account information, we store the institution and country, authorization and session identifiers, consent status and expiry, connected account identifiers, currencies, account details returned by the provider and synchronization timestamps. Bank balances are retrieved through our backend and displayed in the app. Money Manager’s connection flow does not ask you to submit your bank password to our backend.
Bank balances are fetched for display; there is no dedicated storage of historical bank-balance snapshots in the reviewed implementation. Financial summaries are calculated from stored transactions.
Records you enter or import
We store income and expenses, descriptions, amounts, currencies, dates, categories, import identifiers and selected bank transaction metadata to organize and display your financial activity. We also store budgets, scheduled transactions, investment records and investment schedules to provide the app’s budgeting and tracking features.
Original CSV import files are sent to the backend and parsed in memory. The import process stores transaction records and fingerprints used to detect duplicates, rather than the original file. Your source file remains wherever you selected it, such as Files or iCloud Drive; deleting your Money Manager account does not delete that copy.
On-device financial insights and local settings
Financial insights are generated on your device using information available in the app. On supported devices, Apple’s on-device Foundation Models technology may generate a written summary of findings calculated by Money Manager. Otherwise, the app uses locally generated calculations and templates.
Money Manager does not transmit financial-report inputs to an external AI service for report generation. Generated reports are cached on your device. This on-device processing is separate from the backend storage and bank integrations used to provide the app’s other features.
The report cache uses keys that contain the account email. The app also stores appearance and privacy preferences, transaction-classification identifiers, local push-token information and temporary CSV export files. Cached reports have no time-based expiry.
The local-data deletion fix is implemented and tested in the updated iOS source, but users need the next uploaded build to receive it. That build clears cached reports after successful account deletion. Appearance preferences remain, as do user-owned import files and exports saved outside the app.
The cleanup update is not yet available in an uploaded build. Until it is available, account deletion may leave the local data described in the deletion section.
Notifications
To deliver notifications and manage delivery, we process device push tokens, platform, app identifier, push environment, notification preferences, notification content and delivery status and attempt records. Spending notification text can include transaction descriptions, amounts, currency and an account label. Apple receives the device token and notification payload when delivering iPhone push notifications.
Completed or permanently failed notification content and delivery records are removed on the first hourly cleanup after 30 days from their last update, provided no delivery is active or recently updated. Pending notifications normally expire 24 hours after creation while the delivery worker is running, with at most eight delivery attempts. Outages can delay that transition; once delivery is completed or permanently failed, the 30-day cleanup applies.
Push tokens are retained until account deletion. Invalid or unregistered devices are deactivated, but stored tokens have no separate age-based expiry.
Operational logs
Our backend produces HTTP request logs containing request ID, method, URL path, response status and size, duration and client IP address. Error and background-worker logs record failures and processing results. These logs support troubleshooting, service operation and reliability monitoring. Recent production logs are accessible.
The normal request logger does not include request bodies or authorization headers. This does not establish what may appear in other infrastructure or error logs.
Centralized logs are retained for seven days from the log-entry time, plus the configured delay before physical deletion.
The exact delay before physical deletion and retention of any logs outside the centralized system have not been established in this notice.
Support correspondence
Support and privacy requests sent to the contact email are handled directly by Ivan Asenov Ivanov to respond to the request and carry out applicable actions.
A retention period for support emails and attachments has not yet been established. Application cleanup does not control the support mailbox. Requests sent to the listed Gmail address are handled through that email service; its processing locations and contractual arrangements have not been verified for this notice.
Legal grounds
The operator has not yet completed a documented assessment of the legal basis for each processing purpose. This notice describes the confirmed data practices and does not assert that this assessment is complete.
03. Service providers
Different providers support different parts of Money Manager. Each data flow described here relates to that provider’s role; it does not mean all providers receive all your information.
Apple sign-in and notifications
Apple authenticates users through Sign in with Apple. Our backend exchanges authorization codes and tokens with Apple and receives an Apple identifier and a verified email address when available. If you choose Hide My Email, the email may be a private relay address. See Apple’s explanation of Hide My Email.
Apple Push Notification service delivers iPhone notifications and receives the device token and notification payload. Spending notifications can contain transaction descriptions, amounts, currency and an account label.
Enable Banking
Enable Banking facilitates bank authorization and read-only access to account information, balances and transactions. Requests use provider account and session identifiers and date ranges. Interactive requests may also forward your client IP address and browser or device request headers.
Marketstack
Marketstack supplies stock catalog and historical-price information. Requests from our backend include search text or ticker symbols, relevant date ranges and the application’s provider credential. Those requests do not explicitly include your email address or full portfolio records.
Other market-data services
Frankfurter is enabled for currency conversion and Kraken for cryptocurrency pricing. Coinbase is enabled for cryptocurrency history requests reaching more than approximately 700 days back. These integrations use market identifiers and dates rather than customer bank credentials.
The applicable contractual entities, processing locations, retention and transfer arrangements for these market-data services have not yet been verified.
Infrastructure and other recipients
The backend runs on an operator-managed virtual private server (VPS) provided by netcup GmbH in a data center in Germany. netcup GmbH provides the infrastructure hosting the backend that processes account and financial information. The contracted hosting provider is netcup GmbH, registered under HRB 705547 at the District Court of Mannheim; see netcup’s legal notice. PostgreSQL runs on the same VPS and stores application data. Two Raspberry Pi devices located in Bulgaria are used for backups.
The contractual processing roles, subprocessors, provider retention and transfer arrangements have not yet been fully verified. The provider descriptions here identify the confirmed services and data flows; they are not a guarantee that provider-held data stays in one country or is erased with the app account.
04. Data storage and security
Account and financial information is processed by our backend hosted on a netcup VPS in Germany, with application data stored in PostgreSQL on that VPS. Backups use two Raspberry Pi devices located in Bulgaria. Both devices are managed exclusively by the application operator, who alone has administrative and physical access to them. The iPhone app stores its session token in the system Keychain.
The following security measures are implemented:
- The production app connects to an HTTPS backend address.
- Password authentication uses bcrypt password hashing.
- Apple refresh tokens are encrypted using AES-256-GCM.
- Deployment secrets are stored encrypted.
- Protected API operations use authentication and account ownership checks.
- Apple authentication validates signed tokens and the associated authentication claims.
Backup protections and limits
Backup archives on the Raspberry Pi devices are encrypted using AES-256-CBC through OpenSSL CMS. An unencrypted temporary database dump exists during backup creation and is removed afterward. VPS-local dumps are compressed but are not encrypted by the backup script; full-disk encryption has not been verified.
The live backup database connection requires TLS and targets the private WireGuard address. Its TLS setting does not establish verification of the server certificate’s identity.
These measures do not guarantee absolute security. They do not establish that all backups or intermediate files are encrypted at rest, that the entire database is encrypted, or that the service uses end-to-end encryption or holds security certification.
05. Retention, account deletion and backups
Account and financial records persist until you remove them through supported actions or delete your account.
Retention rules
- Account and financial records: until you remove the records through supported actions or delete your account.
- Completed or permanently failed notifications: removed on the first hourly cleanup after 30 days from the last update, provided no delivery is active or recently updated.
- Pending notifications: normally expire 24 hours after creation while the delivery worker is running; delivery attempts are capped at eight. Outages can delay this transition. The 30-day cleanup applies after delivery reaches a completed or permanently failed state.
- Push tokens: until account deletion. Deactivated invalid or unregistered devices have no separate age-based token expiry.
- Cached reports: no time-based expiry; removed by successful account deletion in the updated iOS build, which still needs to be uploaded for users.
- Legacy quarantine records: 30 days from placement in quarantine, or earlier when the associated account is deleted.
- Backups: removed by hourly cleanup after 29 days from file modification time, normally backup creation. This leaves a margin below 30 days. Account deletions are reapplied before restored data goes live.
- Centralized logs: seven days from log-entry time, plus the configured physical-deletion delay.
- Account-deletion markers: 35 days from account deletion. These retain identifiers and timestamps, not financial contents, to support reapplying deletions after a restore.
Support email and attachment retention, the centralized-log physical-deletion delay and any separate infrastructure-log retention have not yet been established in this notice. The app’s cleanup does not control the mailbox.
Disconnecting a bank
Disconnecting a bank revokes access and removes the saved connection. Previously imported transactions remain in your account.
Deleting your account
To request deletion in the app, open Profile, scroll to Delete account, tap it and confirm. See Support for the steps and error guidance.
Successful account deletion removes the user and linked application database records, including transactions, categories, budgets, schedules, investment records, bank connections, Apple identity records, push-device records and linked notification records.
Before deleting the account, the backend attempts to revoke bank sessions and Apple access. If revocation fails, account deletion can fail and require retrying. After successful deletion, the app clears its session token and displayed account data.
Local data and app versions
The local-data deletion gap is fixed in the iOS source and tested. Users need the next uploaded build to receive that fix. Older builds may leave cached AI reports and email-containing cache keys, privacy preferences, transaction-classification identifiers, locally stored push-token information and temporary CSV export files after account deletion.
In the updated build, successful account deletion clears the affected local data. Appearance preferences remain. Your original CSV import files and exports you saved outside the app remain outside the app’s control and are not deleted with your account.
The cleanup fix is not yet available in an uploaded build. Contact support if you need help understanding what account deletion removes in your installed version.
You may also request account deletion by email using the privacy-request contact below.
Logs, backups and older records
Deleted information may remain in an older backup until that backup expires. Hourly backup cleanup removes files after 29 days from their modification time, normally creation. Account-deletion markers are retained for 35 days and deletions are reapplied before restored data goes live. Centralized logs follow the seven-day period and configured physical-deletion delay described above.
Legacy quarantine cleanup is deployed. The production quarantine table was empty when checked. Any records placed there are removed after 30 days or earlier on deletion of their associated account.
Provider-held records
- Enable Banking: the backend requests deletion of the bank session.
- Sign in with Apple: the backend revokes the stored Apple refresh token.
- Push notifications: linked notification and device records are deleted from our database. No request is implemented to erase previously delivered notifications or Apple’s delivery records.
- Market-data providers: no per-user deletion request is implemented.
Revoking access does not establish that a provider erases all its records. Provider logs, backups and other retained records depend on the provider’s policies and contractual terms. Deleting Money Manager or your account does not delete records held by your bank.
Exact provider-held retention and contractual deletion arrangements have not yet been verified.
06. Your privacy rights and requests
Depending on the laws that apply to you, rights may include access to your personal information, correction, deletion, a copy in a portable format, restriction of or objection to certain processing, and withdrawal of consent where processing is based on consent. You may also have a right to complain to a relevant privacy authority.
Money Manager is operated by Ivan Asenov Ivanov.
For support or privacy requests, including access to your personal data, corrections or account deletion, contact ivanivanov.ii726@gmail.com.
Requests are handled directly by Ivan Asenov Ivanov. We may ask for information reasonably necessary to verify account ownership before sharing or deleting personal data. Never send your password or bank login credentials.
We respond without undue delay, normally within one month. If an extension is legally permitted and necessary, we will explain the reason and expected response time within that first month.
Do not send complete financial statements with your request.
Rights may be subject to conditions and exceptions under applicable law. Contact the operator using the address above to exercise your rights or ask about the information described in this notice.
07. International processing
The operator is based in Bulgaria, the backend and PostgreSQL database are hosted on the VPS in Germany, and the two backup devices are located in Bulgaria. Financial-report generation and report caching take place on your device. Other processing locations depend on the services and providers involved.
Processing countries and transfer arrangements for other providers have not yet been verified. Backend hosting in Germany and backups in Bulgaria do not establish that all processing remains within Europe.
08. Children’s privacy
Money Manager is intended for adults. No age-verification or parental-consent flow is implemented.
If you believe a child has provided personal information through Money Manager, contact the operator so the request can be reviewed. A dedicated child-data handling procedure has not been established.
For a concern about a child’s information, the privacy contact is ivanivanov.ii726@gmail.com.
09. Updates to this policy
This policy may be updated as the app or its data practices change. The effective date at the top will identify the applicable version.
Updates will be published on this page with a revised effective date. Automated in-app and email notifications for policy changes are not currently implemented.
For help using the app, visit Support.