Privacy Policy
// The Short Version
- Your financial records live on your iPhone. We have no account system and no server that stores your finances — we can't see them.
- No ads, no analytics, no tracking.
- The one exception is PATCH, an optional AI assistant that is off by default. When you use it, your question and the details needed to answer it go through our server to OpenAI.
- This page explains exactly what is sent.
1. Who we are
DollarGuard is made by James Heap, operating as HEAP BRANDS, a sole proprietorship in Qualicum Beach, British Columbia, Canada ("we", "us"). Contact: [email protected].
2. What stays on your iPhone
Everything you enter is stored only on your iPhone, in the app's private storage:
- accounts, balances, transactions, notes, categories, payees and payers
- recurring rules, settings, and the app's internal change log
Your passcode is stored as a one-way hash in the iPhone Keychain, on this device only. We never receive any of this unless you use PATCH (section 4).
Protection: the app asks iOS to encrypt its files whenever your iPhone is locked (Apple's "complete unless open" file protection). DollarGuard adds its own passcode, optional Face ID, and a privacy screen that hides your numbers in the app switcher.
3. Voice input
Voice entry uses Apple's on-device speech recognition. Your audio never leaves your phone. If you use voice with PATCH, only the resulting text is sent, as described in section 4.
4. PATCH, the optional AI assistant
PATCH is off until you turn it on in Settings and accept a notice screen. When it's on, each time you send PATCH a message, the following goes to our server and then to OpenAI:
- Your message (typed, or transcribed on your phone from voice) and the recent conversation — so PATCH can answer
- Your account names, types, currencies and balances, your category list, and the date range and number of your records — so PATCH knows what you have
- Transaction details PATCH looks up to answer you: dates, amounts, payees/payers, categories, accounts and notes
- Your recurring rules, when relevant
- The first name you gave PATCH, if you gave one — so it can address you
- A random identifier created when you first used PATCH (not your Apple ID and not your phone's hardware ID) — to enforce fair-use limits and stop abuse
- Your IP address and app version, which any internet request reveals
Who receives it:
- Cloudflare, Inc. runs our small server ("dg-patch-proxy"). It holds our OpenAI key, checks fair-use limits and forwards your request. It keeps usage data only: message counts under your random identifier (deleted automatically 40 days after your last PATCH message) and short request logs with a shortened, scrambled form of that identifier, the AI model, timing and status (kept for a few days). It does not keep the content of your messages or your financial details.
- OpenAI, L.L.C. writes PATCH's answers. We ask OpenAI not to store the responses. Under OpenAI's API policies, API data isn't used to train its models by default and may be kept for up to 30 days to monitor for abuse.
- Both companies process data in the United States (Cloudflare also at its global network edge), so your information may be accessed under US law.
What PATCH can change: PATCH can propose adding or editing a transaction. Nothing is saved to your records until you tap [ APPLY ].
Turning PATCH off stops all sending, deletes PATCH's chat history from your phone, and replaces the random identifier with a new one.
5. Backups and exports
- iCloud backup (optional, off by default). If you turn it on, DollarGuard saves a daily backup file to your own iCloud Drive and keeps the last 7. Apple stores it under your Apple account; we can't access it. DollarGuard doesn't add its own encryption to this file — it's protected by your Apple account and Apple's iCloud encryption (end-to-end if you use Apple's Advanced Data Protection).
- Your iPhone backups. Your DollarGuard data is included in your own iPhone/iCloud device backups, according to your iOS settings.
- Exports. CSV and backup files you export go wherever you send them.
6. Purchases
Purchases and subscriptions are processed by Apple. We never see your card or payment details, your name or your Apple ID. To confirm a PATCH subscription, the app sends Apple's signed purchase record (product, dates and anonymous transaction IDs) to our server, which checks it with Apple's signature.
7. What we don't do
- No advertising.
- No analytics or tracking SDKs.
- No selling or renting data.
- No data brokers.
- No bank connections.
If you choose to share crash reports with developers in your iOS settings, Apple may pass us anonymous crash logs.
8. How long things are kept
- On your iPhone: until you delete it. Deleting the app, or Settings → Reset App, erases the app's data on the phone. Export files you created may remain in Files.
- PATCH chat history on your phone: 30 days after the last message, or until you turn PATCH off.
- Cloudflare: usage counts up to 40 days after your last PATCH message; request logs a few days.
- OpenAI: see section 4.
9. Your rights
Under Canadian privacy law (PIPEDA, and BC's PIPA where it applies) you can ask what personal information we hold about you, ask us to correct or delete it, and withdraw your consent (turn PATCH off).
Because your records are on your phone, you already control them directly — we hold no copy. For PATCH data, contact us and tell us roughly when you used PATCH. We'll explain what can be identified: usually nothing, because we only hold a random identifier.
10. Security incidents
If we learn of a breach of security safeguards involving personal information under our control that creates a real risk of significant harm, we'll notify affected users and the Office of the Privacy Commissioner of Canada as the law requires.
11. Children
DollarGuard isn't directed at children under 13, and we don't knowingly collect their information.
12. Changes
When this policy changes, we'll update the version and date at the top. If a change affects what is sent off your device, we'll show it in the app before it takes effect.
13. Contact
Privacy questions or requests: [email protected]. Privacy officer: James Heap.