📄 Legal document

Privacy Policy

Last updated: April 29, 2025 · Version 1.0
🔒 Quick summary
Table of contents

1
Who we are

ChaChing is a personal finance management app developed and maintained by Antônio João Damião Filho ("we", "our", or "developer"), based in Brazil. The app is available on the Apple App Store.

This Privacy Policy describes how we collect, use, store, and protect the information of ChaChing users for iOS. By using ChaChing, you agree to the practices described in this document.

For questions, contact us at: ajdamiaof@gmail.com

2
Data we collect

ChaChing is designed with privacy in mind. Most data stays exclusively on your device. Below we detail what we collect:

✓ Financial data (stored locally)

Transactions, pockets, categories, limits, investments, installments, bank accounts, and cards are stored only on your device, in an encrypted local database. We have no access to this data in the free version.

2.1 Data you provide directly:

  • Transaction amounts, descriptions, and dates
  • Pocket and category names and limits
  • Bank account and credit card information (names/nicknames only, not full numbers)
  • Installment and investment amounts
  • Email account (only for Pro users who opt into cloud sync)

2.2 Automatically collected data:

  • Device language and region (for app localization)
  • iOS version (for compatibility)
  • Anonymous installation identifier (not linked to your identity)
  • Aggregated, anonymous usage data (most-used features, for app improvements)
  • Anonymized crash reports

2.3 Data we do NOT collect:

  • Full credit or debit card numbers
  • Bank passwords or financial institution credentials
  • Geographic location data (GPS)
  • Contacts, photos, or device microphone
  • Biometric data (Face ID/Touch ID are processed locally by iOS)

3
How we use your data

We use collected data exclusively to:

  • Provide the service: process and display your transactions, pockets, and financial reports.
  • Synchronization (Pro): keep your data up to date across multiple devices, when enabled.
  • Product improvements: analyze anonymous usage patterns to identify bugs and improve features.
  • Technical support: diagnose and resolve issues you report to us.
  • Communications: send important app updates, when you authorize.
  • Legal compliance: fulfill applicable legal obligations.

We do not use your financial data for advertising, credit scoring, or any commercial analysis.

4
Storage and security

The security of your data is our priority. We apply the following measures:

Local storage (all users):

  • SQLite database stored in the iOS secure sandbox, inaccessible to other apps.
  • Sensitive data (authentication tokens) stored in the iOS Keychain with AES-256 encryption.
  • iOS Data Protection is enabled, encrypting files at rest.

Cloud storage (Pro users only):

  • Data transmitted via HTTPS/TLS 1.3, encrypted in transit.
  • Servers located in security-certified data centers.
  • Automatic backups with controlled retention.
ℹ️ Shared responsibility

You are responsible for keeping your device secure with a passcode and up-to-date iOS. Unauthorized physical access to your device may compromise app data.

5
Cloud sync (ChaChing Pro)

Users with a ChaChing Pro subscription have access to cloud sync, which enables:

  • Access to data across multiple iOS devices.
  • Automatic backup of financial data.
  • Data recovery when switching devices.

For sync, you need to create an account with an email address. That email is used exclusively for authentication and account recovery. We do not send spam or marketing emails without your explicit consent.

Synced data includes all transactions, pockets, categories, and settings. Sync can be disabled at any time in app settings, keeping data on device only.

When you cancel your Pro subscription, cloud sync is disabled. Data on your device is preserved. Cloud data is retained for up to 90 days after cancellation, during which you can reactivate Pro to recover it, after which it is permanently deleted.

6
Third-party services

ChaChing uses the following third-party services, each with their own privacy policies:

🍎 Apple (App Store, In-App Purchases, StoreKit)

Payment and subscription processing. Apple manages all financial transactions — we do not store credit card data. Apple's Privacy Policy

💳 RevenueCat

In-app subscription management platform. RevenueCat receives anonymous information about subscription status to validate access to ChaChing Pro. It does not share identifiable financial data. RevenueCat's Policy

📊 Usage analytics (anonymous)

We use analytics tools to collect anonymized, aggregated usage data. This data does not allow individual user identification and is used exclusively for product improvements.

We do not use advertising networks, third-party marketing trackers, or any service that monetizes your personal or financial data.

7
Data sharing

We do not sell, rent, or share your personal or financial data with third parties, except in the following limited situations:

  • Service providers: we share minimal necessary data with technical partners (such as cloud hosting) who act on our behalf and are contractually bound to protect your data.
  • Legal obligation: we may disclose data when required by law, court order, or competent governmental authority.
  • Rights protection: when necessary to investigate, prevent, or take action in cases of fraud, security threats, or violations of our terms.
  • Business transfer: in the event of a merger, acquisition, or sale of the app, your data may be transferred. You will be notified in advance and have the option to delete your account.

In all data-sharing cases, we ensure the recipient applies protective measures equivalent to ours.

8
Your rights

Under the Brazilian General Data Protection Law (LGPD — Law No. 13,709/2018), you have the following rights regarding your personal data:

  • Access: request confirmation of what data we hold and receive a copy of it.
  • Correction: request correction of incomplete, inaccurate, or outdated data.
  • Deletion: request deletion of your personal data (except where there is a legal retention obligation).
  • Portability: receive your data in a structured, machine-readable format.
  • Consent withdrawal: revoke previously given consent, without prejudice to prior processing.
  • Objection: object to data processing in case of non-compliance with this policy.
  • Sharing information: know with whom we share your data.
  • Review of automated decisions: request review of decisions made based on automated processing of your data.

To exercise any of these rights, contact us at ajdamiaof@gmail.com. We will respond within 15 business days.

9
Data retention and deletion

Local data: remains on the device until you delete the app or use the "Erase all data" function in app settings.

Cloud data (Pro): retained while you have an active account. After subscription cancellation, retained for 90 days (grace period for reactivation) then permanently deleted.

Account deletion: you can request complete deletion of your account and all associated data by emailing ajdamiaof@gmail.com or using our account deletion page. Deletion is processed within 30 days and is irreversible.

Anonymous analytics data: retained in aggregated, anonymized form indefinitely, as it does not allow individual user identification.

Support logs: data voluntarily shared via support is retained for up to 2 years for technical reference and then deleted.

10
Minors

ChaChing is intended for people aged 13 or older. We do not intentionally collect data from children under 13.

If you are a parent or guardian and believe a minor has provided data to ChaChing without consent, contact us at ajdamiaof@gmail.com. We will delete the data immediately.

11
Changes to this policy

We may update this Privacy Policy periodically. When we make significant changes, we will notify you through:

  • In-app notification on next launch.
  • Updating the "Last updated" date at the top of this document.
  • Email to registered users (changes affecting fundamental rights).

Continued use of the app after change notification constitutes acceptance of the revised policy. If you disagree with the changes, you should stop using the app and may request deletion of your data.

Previous versions of this policy are available upon email request.

12
Contact and rights exercise

To exercise your privacy rights, report concerns, or ask questions about this policy:

Antônio João Damião Filho
ChaChing Developer · We respond within 15 business days
✉️ ajdamiaof@gmail.com

You may also file complaints with the Brazilian Data Protection Authority (ANPD) at www.gov.br/anpd if you believe your rights have not been properly addressed.