Clear by design

Privacy, in plain language.

What we process, why we process it and the choices you have.

1. About this policy

This policy explains how MoneyOak handles information in the iPhone app and on moneyoak.app. MoneyOak is operated by Omar Zaki. For questions about your information, contact support@moneyoak.app.

Effective and last updated: October 9, 2026.

2. Information we process

  • Account information: your email address, MoneyOak user identifier, sign-in provider and any name supplied by that provider. Email/password authentication is handled by Supabase; passwords are not included in budget exports.
  • Your financial records: account names, types, balances and currencies; transactions, notes, tags and dates; categories and subcategories; budgets, recurring schedules, templates, preferences and imported records.
  • Receipts: images you choose to attach and any recognized text saved with them. Native iPhone text recognition runs on your device. Receipt content is included in synchronization when you use cloud sync.
  • Subscription information: Apple and RevenueCat process purchase identifiers, subscription status, your MoneyOak user identifier and device/network information needed to validate and restore purchases. We do not receive your full payment-card details from Apple.
  • Support messages: information you choose to email us, including attachments. Please avoid sending financial exports or receipt images unless needed, and remove unrelated private information.
  • Technical information: our hosting, authentication, currency-rate and subscription providers may process IP addresses, request timestamps, device or browser information and service logs to deliver and protect their services.

MoneyOak does not require bank-login credentials or automatically connect to your bank accounts. Do not put banking passwords, PINs or full payment-card numbers in transaction notes.

3. How information is used

We process information to provide sign-in, maintain your budget, synchronize across devices, retrieve currency rates, manage Premium access, answer support requests, handle deletion and protect the service against abuse.

Automatic daily sync is enabled by default. You can disable it, change its frequency or run a manual sync in Settings. Your device also keeps a local copy for offline use. Online currency requests send currency codes and the selected provider to Frankfurter; they do not need your transaction amounts, account names or receipt contents.

MoneyOak does not include advertising or advertising trackers and does not sell your financial records. This website does not add analytics scripts, advertising cookies or a mailing-list form.

4. Service providers and sharing

We use services that process information needed for their functions:

ProviderPurposeMore information
SupabaseAuthentication, synchronized financial records and private receipt storagePrivacy policy
Apple / GoogleYour selected sign-in provider; Apple also handles iOS purchases; Gmail stores support correspondenceApple · Google
RevenueCatSubscription validation, status and restorationPrivacy policy
FrankfurterReference currency ratesService information
CloudflareWebsite hosting, delivery, security and support email forwardingPrivacy policy

These services may process information in countries other than your own. We may also disclose information where required by law, to investigate abuse or to protect users and the service. We do not provide your financial records to other users.

5. Device permissions and security

Photo access is used when you choose a receipt image. Notifications are optional and can be changed in Settings and in iOS. Face ID or the device passcode is used through Apple’s system authentication when you enable the app lock; MoneyOak does not receive your face image or biometric template.

Cloud requests use HTTPS and account-scoped access controls. Cloud synchronization is not end-to-end encryption: our hosting services process the data stored on their servers. Local financial snapshots rely on operating-system protections; app lock is an additional interface gate, not separate encryption of every saved file.

Exports can be password-encrypted when you choose a password. Exports without a password and CSV files are readable. Protect your exported files and password; MoneyOak cannot recover a lost backup-encryption password. No online service or device can promise absolute security.

6. Retention and account deletion

Your financial records remain while your account is active or until you remove them. Deleting an individual receipt or transaction can leave an uploaded receipt object in private storage; full account deletion removes your stored receipts.

To delete your login and cloud data, use Settings → Account → Delete my account, confirm the action and verify your identity. We remove private receipts and delete the login and synchronized financial records. The device that completes deletion clears its local budget after server confirmation. Apple access is revoked for accounts linked to Sign in with Apple.

To recover from an interrupted deletion, we retain a private receipt containing the former user identifier, a random deletion request identifier and timestamps. It contains no financial records. Completed receipts become eligible for cleanup after 30 days when another deletion starts; pending receipts remain until the operation can finish.

Account deletion does not erase exports you saved elsewhere, offline copies on other devices, or transaction and security records retained by Apple, RevenueCat or other providers under their policies. It does not cancel an App Store subscription. Delete those files separately and manage your subscription with Apple.

Support correspondence may be kept as needed to resolve your request and handle follow-up, legal or security needs. Provider logs and any operational backups follow the relevant retention settings and requirements.

7. Your choices and requests

You can edit records in the app, export a backup or CSV, change sync preferences, control optional permissions and delete your account. Depending on the law that applies to you, you may have additional rights to access, correct, delete or restrict processing of your information, request a portable copy or make a complaint to a privacy authority.

Contact support@moneyoak.app for privacy requests or if you cannot access the in-app deletion option. We may need to verify ownership before acting on account-related requests. Never send your password, one-time verification code or Apple private key.

8. Policy changes

We will update this page when our information practices change and revise the date above. If a change requires additional notice or consent, we will provide it through the app or another appropriate channel.