Privacy Policy
Last updated: 21st July 2026
Who we are
MoneyTracker UK ("we", "us") provides the MoneyTracker UK iOS app. If you have any question about this policy or how your data is handled, contact our data protection point of contact at dpa@moneytracker.uk.
The short version
Your financial data - accounts, transactions, budgets, goals - is stored only on your device and synced between your own devices through your personal iCloud account. We do not have a server that stores it, cannot see it, and could not hand it over even if asked. The only personal data we hold ourselves is your email address, and only if you join the waitlist below or otherwise contact us directly.
What we collect
If you join the waitlist
Just your email address, which we use to email you when the app is available and for related announcements. You can ask us to delete it at any time by emailing dpa@moneytracker.uk.
If you use the app
The app has no account or login system. Your accounts, transactions, budgets, goals, and net worth history are stored using Apple's SwiftData framework and synced across your own devices exclusively through your personal iCloud account (Apple's CloudKit). This data is encrypted in transit and at rest by Apple's infrastructure and is never transmitted to, or stored on, any server we operate. See Apple's iCloud security overview for how that encryption works.
Bank connections
Linking a bank account uses Lunch Flow, a third-party open banking data platform - not a service we operate. When you link a bank:
- You sign in to (or create) your own Lunch Flow account and connect your bank directly on Lunch Flow's own site, in a secure in-app browser session - we never see, receive, or store your bank login credentials, or your Lunch Flow account credentials.
- Because it's your own Lunch Flow account, Lunch Flow bills you directly for your bank connection, separately from MoneyTracker UK - see lunchflow.app for their current pricing. We don't receive any part of that payment and never see your billing details.
- Our backend only brokers the one step of the connection that genuinely needs a server-side secret - handing your device a Lunch Flow authorisation link to open, then later exchanging a one-time code (or a refresh token your device already holds) for an access token. It doesn't store your tokens or any resulting account/transaction data; your device holds its tokens securely in the iOS Keychain and requests your account and transaction data directly from Lunch Flow itself.
- You can remove all linked bank connections at once from within the app (Profile > withdraw age confirmation), or manage or revoke access at any time directly through your own Lunch Flow account.
Device/app integrity checks
The app uses Apple's App Attest to let our backend verify that a request comes from a genuine, unmodified copy of the app on genuine Apple hardware. This is a hardware-backed cryptographic check tied to your device, not to you personally - it does not identify you or link to your Apple ID.
Age verification
MoneyTracker UK as a whole is restricted to users aged 16 and over (see "Children" below). Within that, manual account and transaction tracking - including importing a PDF bank statement - is available to anyone 16+; linking a bank, and using Spending Trends (which reviews your spending on-device using Apple Intelligence), are further restricted to adults aged 18 and over - for these, the app asks the operating system to confirm you're 18 or older using Apple's Declared Age Range API. Apple returns a declared age range (for example, "18-24") - either shared by you, or by a parent/guardian if your device is in a Family Sharing group - never your exact birthdate. If you decline to share it, those specific features simply stay unavailable; there is no self-declared fallback. We only store the resulting confirmation and declared range on your device itself - it isn't synced to iCloud, and it's never sent to, or stored on, any server we operate. You can withdraw this confirmation at any time from your profile, which removes any bank-linked accounts (your manually entered data and transaction history aren't affected) and locks the restricted features again until you confirm your age once more.
TestFlight beta testing
If you install MoneyTracker UK through Apple's TestFlight beta programme rather than the App Store, Apple collects some information itself as part of running TestFlight - for example, your email address (to invite you), install/update activity, and, if you choose to share it, crash logs and any feedback you submit through the TestFlight app. This is collected and processed by Apple under Apple's own privacy policy, separately from anything described elsewhere on this page - we only see feedback you choose to submit, not device-level diagnostics Apple gathers for its own purposes.
Server logs
Like virtually all web servers, our backend (hosted on Google Cloud Run) automatically logs basic request metadata - your IP address, the time of the request, and which endpoint was called - for every request it receives. We use this only to diagnose problems (for example, working out why a bank link failed) and to detect abuse. These logs are automatically deleted after 7 days and are never used for analytics, tracking, or profiling.
Who we share data with
- Lunch Flow - if you choose to link a bank, you connect directly with your own Lunch Flow account (a separate service with its own billing relationship with you) to retrieve your account and transaction data; our backend only brokers the one-off connection handshake, as described above.
- Apple - for iCloud sync and App Attest, governed by Apple's own privacy policy.
- Google Cloud Platform - our backend and waitlist list run on Google Cloud (Cloud Run and Firestore), which processes data on our behalf under Google's standard cloud data processing terms.
We do not use advertising trackers or analytics SDKs, and we do not sell or rent your data to anyone.
Your rights
Under UK GDPR you have a number of rights over your personal data. Because almost none of your financial data ever reaches our servers in the first place, most of these are already in your hands directly in the app, rather than something you need to request from us:
- Access - your accounts, transactions, budgets, goals, and net worth history are visible in the app at all times; there's no separate copy on our side to request. The only personal data we hold ourselves is your waitlist email (if you joined one) and backend request logs - we don't hold any bank-connection tokens ourselves, since those live only on your device and within your own Lunch Flow account - email dpa@moneytracker.uk for a copy of any of that.
- Rectification - correct anything wrong directly in the app; for your waitlist email, just email us the correction.
- Erasure - delete the app (or specific data within it) to remove your financial data from your device and, once iCloud sync catches up, from iCloud too. To remove your waitlist email or any backend-held data, email us and we'll delete it.
- Restriction and objection - you can ask us to stop processing your data (e.g. stop emailing you, or stop retaining a connection token) by emailing us; we only keep the minimum needed to run the service securely (see "Server logs" above).
- Portability - your data already lives in a format you fully control on your own device. The app includes a built-in CSV export (Settings > Data) for your accounts, transactions, goals, and budgets, as well as standard iOS/iCloud backup and file tools - none of it needs anything from us.
- Automated decision-making - budget categorisation, bill detection, and Spending Trends' AI-generated insights all run entirely on your device, are always visible and editable (or, for Spending Trends, just informational) rather than acted on automatically, and don't produce any legal or similarly significant effect - so this doesn't meaningfully apply here.
- Withdrawing consent - if you joined the waitlist, you can unsubscribe or ask us to delete your email at any time.
We'll respond to any request within one calendar month, as UK GDPR requires (longer for genuinely complex requests, in which case we'll tell you why). We may ask you to verify your identity first, so nobody else can request access to or deletion of your data by pretending to be you.
If you're unhappy with how we've handled your data or a request, you can complain to the UK's data protection regulator, the Information Commissioner's Office (ICO).
Children
MoneyTracker UK requires users to be at least 16 years old. Linking a bank, and using Spending Trends, go further and require you to be 18 or older - even though some UK banks issue accounts to 16-17 year-olds, we've deliberately chosen not to support linking those accounts here. We don't knowingly collect data from, or knowingly allow use of the app by, anyone under 16.
Because 16-17 year-olds can use MoneyTracker UK for manual account and transaction tracking, the app falls within the scope of the ICO's Age Appropriate Design Code ("Children's Code"). In line with its standards, the app already collects no more data than it needs to function (see "What we collect" above), carries no advertising or tracking SDKs and does not profile users for marketing, defaults every account to private on-device storage with no public or shareable profile, and uses no nudge techniques to encourage sharing more data or weakening privacy settings. The features that involve the most sensitive processing - linking a bank, and Spending Trends - are restricted to adults 18+ regardless.
How we handle the 16+ minimum
We don't verify the 16+ minimum with the same certainty as the 18+ gate - there's no equivalent of Apple's Declared Age Range API for it, just a Terms of Service requirement, backed by the App Store's own 16+ age rating for the app's listing, which Apple enforces at the account level via Screen Time content restrictions for anyone signed in with an Apple Account registered under that age. That's a real additional layer, but neither we nor Apple can be fully certain of it - it relies on the age someone (or their parent, for a child's account) originally gave Apple. Rather than pretend that gives us certainty it doesn't, we follow the Code's own alternative for services in this position: apply the standards' protections to everyone, not only to users we can confirm are children. That's why the protections described above - data minimisation, no profiling or advertising, private-by-default on-device storage, no nudge techniques - apply to every MoneyTracker UK user regardless of age, rather than only kicking in for people we've identified as 16 or 17.
Spending Trends and profiling
Spending Trends analyses your spending patterns to generate its insights, which likely makes it "profiling" in the technical UK GDPR sense (automated processing to evaluate aspects of your behaviour), whatever else is true about how limited it is in practice. In its favour: it's restricted to verified adults, it runs entirely on your device with nothing sent to us or anyone else, its output is purely informational text you can ignore, and no decision is made about you anywhere as a result of it. We're not asserting that combination puts it outside the Code's profiling standard entirely - that's a legal judgement call, not ours to make unilaterally - only that it's a meaningfully lower-risk form of profiling than most, and that it can't reach a 16 or 17 year-old in the first place.
In plain terms, if you're 16 or 17
You can add your own accounts and transactions by hand, import a PDF bank statement, and use budgets, bill reminders, and goals - all of that stays on your phone and your own iCloud, and we never see it. Linking an actual bank, and Spending Trends (the AI feature), are switched off for you until you're 18 - that's not us judging you, it's just where we've drawn the line for the features that touch real bank data or use AI. If anything on this page doesn't make sense, or you're not sure what something means, email dpa@moneytracker.uk and ask - we'd rather explain it than have you guess.
If you believe someone under 16 has given us personal data (for example, by joining the waitlist), contact dpa@moneytracker.uk and we'll delete it.
Changes to this policy
If we make material changes to this policy, we'll update the date at the top of this page. Continued use of the app after a change means you accept the updated policy.
Contact
Questions, requests, or concerns about your data: dpa@moneytracker.uk.