Privacy Policy
Effective September 9, 2026 · Last updated September 9, 2026
Savvey Cash (“Savvey Cash,” “we,” “us,” or “our”) is a personal cash-envelope app for iPhone. This policy explains what we collect, why, who we share it with, and the choices you have.
Savvey Cash is not a bank, does not connect to your bank accounts, and does not receive card or merchant feeds. Amounts you enter are your own records, stored on your device unless this policy says otherwise.
Who is responsible. Savvey Cash is currently operated by an individual based in Malaysia. We intend to register a Malaysian company under the name Savvey Cash. Until that registration is complete, the operator of the app is the controller of your personal data. After registration, this policy will be updated to name that company.
Contact: hello@savvey.cash
If you do not agree with this policy, do not create an account or use the app.
1. Who this policy applies to
This policy applies to the Savvey Cash iOS app and the website at savvey.cash (a marketing site without analytics or advertising cookies).
The app is intended for people 13 years of age or older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, email us and we will delete it.
2. Summary
- Budget data (envelopes, spends, cash on hand): stored on your iPhone. We do not currently upload envelopes or transactions to our servers.
- Account: email (or Apple Hide My Email), sign-in method, first and last name.
- Onboarding / profile: gender, date of birth, goals, allocation day, currency, optional profile photo (custom photos stay on the device).
- Payments: Apple processes the App Store purchase. We learn whether you have Premium, not your card number.
- Analytics: product events in the app only, identified by a random account ID — not your email or name. We do not send balances, envelope titles, remarks, or exact dates of birth to analytics. The website does not use analytics.
- Crash reports: technical diagnostics without attaching your name, email, or account ID.
- Notifications: on-device only. We do not send remote push from our servers.
- Email: transactional account email (for example, confirm your address). We do not send marketing email today. We plan to send optional product/marketing email later; we will only do that with a lawful basis and an unsubscribe option.
- Support: email only, hello@savvey.cash.
- Ads / tracking: no ads, no Advertising Identifier (IDFA), no sale of personal information.
3. Information we collect
3.1 Information you provide
Account and sign-in: email address (including Apple Hide My Email if you use it); password (email accounts only; we never receive your Apple or Google password); first name and last name; sign-in method (Apple, Google, or email).
Onboarding and Profile: gender; date of birth (age gate and product personalization); goals you select, and optional “other” text; Allocation Day and display currency; optional profile photo or a preset avatar (custom photos stay in the app’s private files on the device).
Budget records you create: envelope names, types, amounts, schedules, remarks, transaction history, and cash-on-hand figures. These records run the app on your device. They are included if you use Export Data. They are not currently synced to our cloud database.
Support: whatever you include when you email hello@savvey.cash.
Optional third-party pages: if you open Feedback Board (UserJot) or Message the Founder (Instagram), those services’ own policies apply to what you submit there.
3.2 Information collected automatically
On the device: local database, settings, notification permission, and a cached Premium status so the app can work offline; auth tokens in the iOS Keychain.
When you are online: a signed-in user ID so we can operate your account; profile fields we store remotely (Section 4); subscription / entitlement status; app analytics events and crash diagnostics; technical data our processors typically receive (such as IP address, device and OS version, request time). We do not use this for advertising.
We do not collect precise location, your contacts, microphone, health data, or photos except an avatar you choose.
3.3 What we do not send to analytics
We do not send to PostHog: amounts, balances, monthly allocation figures, envelope titles, transaction remarks, exact date of birth, exact Allocation Day, notification clock times, avatar images, email, name, IDFA, or GPS.
Identify is the account UUID only. Session replay and UI autocapture are off. The website has no analytics snippet.
4. How we use information
- Provide the app — account, onboarding, envelopes on device, Premium, local reminders.
- Verify subscription — confirm Premium (including trial) before gated actions when you are online.
- Improve the product — sanitised in-app analytics (funnels, whether a save succeeded, paywall outcomes).
- Keep the app reliable — crash and error reports.
- Communicate — necessary account and security email. Marketing email is not sent today. When we introduce it, it will be optional, identified as such, and include unsubscribe.
- Support — reply to email you send us.
- Legal and safety — comply with law, prevent abuse, protect our rights.
Legal bases. Where GDPR/UK GDPR applies: contract (providing the app); legitimate interests (security, product improvement, crash diagnosis); consent (notifications; future marketing email; analytics where consent is required); legal obligation. Where Malaysia’s Personal Data Protection Act 2010 applies, we process personal data for the purposes stated in this policy.
5. Storage and sharing
We do not sell personal information. We do not share it for cross-context behavioural advertising.
Processors (on our instructions):
- Supabase — account, remote profile, entitlement records, account deletion. Typical data: user ID, email, names in auth metadata, profile fields (gender, date of birth, goals, and similar), Premium entitlement flags. Not envelope or transaction tables in the current product.
- Apple — Sign in with Apple, App Store billing, on-device notification APIs. Per Apple’s policies for those features.
- Google — Sign in with Google (if you choose it). Per Google’s policies.
- RevenueCat — subscription status for Apple In-App Purchase. App User ID (our account UUID), entitlement events. Card data stays with Apple.
- PostHog (United States) — in-app product analytics. Account UUID, allowlisted event names and non-financial properties.
- Sentry (United States) — crash / performance diagnostics. Stack traces, device/OS, breadcrumbs. Default PII is off; we do not attach your user ID.
- UserJot / Instagram — optional pages you open. Only if you use those destinations.
PostHog and Sentry are configured in the United States. Other processors may also process data in the US and elsewhere. If you are in the EEA/UK, that can involve an international transfer under those vendors’ safeguards (for example Standard Contractual Clauses).
Paid features are licensed under Apple’s Standard Licensed Application End User License Agreement: https://www.apple.com/legal/internet-services/itunes/dev/stdeula/. Apple’s privacy practices apply to App Store purchases.
6. Notifications
If you allow notifications, Daily Brief and Evening Check are scheduled locally on your iPhone. We do not run a push server for those reminders. Turn them off in iOS Settings at any time.
7. Payments
Premium is an auto-renewable subscription through the App Store. Apple processes payment. We receive entitlement (trial / active / expired). Manage or cancel in iOS Settings → Apple ID → Subscriptions, or Manage Subscription in Profile.
8. Guest use, sign-out, export, and deletion
Guest onboarding. You can finish onboarding before creating an account. Draft answers stay on the device. That is not a full cloud account.
Sign out. Ends the remote session. Local budget data on that iPhone is kept. Sign-out does not delete your account.
Export. On the Delete Account confirmation flow you can export envelopes and history as CSV and JSON from the device. Cloud envelope sync is not available yet, so export is local data only.
Delete account. Profile → Delete Account (two-step) deletes the Auth user and associated profile/entitlement rows, then wipes local app data on that device. We make a best-effort deletion of the PostHog person tied to your account UUID. Sentry crash logs are not keyed to your account and generally cannot be erased individually.
Deletion does not remove Apple’s purchase records, information we must keep if the law requires it, or content you posted on UserJot or Instagram.
After deletion, a new install is a new identity.
9. Retention
- On-device budget data: until you delete the app, delete the account, or wipe the device.
- Account and remote profile: until you delete the account.
- Support email: as long as needed to handle your request and for a reasonable follow-up period.
- Analytics (PostHog): up to 24 months, then deleted or aggregated.
- Sentry: according to Sentry’s project retention (typically weeks to a few months).
10. Security
Network calls use TLS. Tokens are stored in Keychain. Server account data is isolated per user. Raw finances are not sent to analytics. No system is perfectly secure. You are responsible for your device passcode and Apple ID.
Savvey Cash is a record-keeping app. It is not a bank, and it is not tax or legal advice.
11. Your rights
Depending on where you live (including Malaysia, the EEA/UK, and California), you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent.
- Edit name and settings in Profile.
- Use Export Data / Delete Account in the app.
- Email hello@savvey.cash for anything the app cannot do.
We will not discriminate against you for exercising privacy rights. We do not “sell” or “share” personal information as those terms are used in the CCPA/CPRA.
You may complain to a data protection authority (in Malaysia, the Personal Data Protection Department, where applicable).
12. International users
We operate from Malaysia. Processors (including PostHog and Sentry) process data in the United States and possibly other countries. If that is not acceptable, do not create an account.
13. Changes
We may update this policy. The “Last updated” date will change. Material changes will be posted at https://www.savvey.cash/privacy. Continued use after an update means you accept the revised policy, except where law requires consent.
When Savvey Cash is registered as a company in Malaysia, we will update the controller details on this page.
14. Contact
Savvey Cash
Operated from Malaysia
Email (privacy, support, and all enquiries): hello@savvey.cash
App: Savvey Cash for iOS