Fondari

Privacy policy

Last changed: 9 September 2026. This English text is the governing version.

Fondari is run by [Operator name], [Operator address]. You can reach us at [support address]. This page says what the app stores, where, who can read it, and for how long. It is written from the same table we build the app from, so it should never disagree with what the software does.

Using Fondari without an account

Out of the box, Fondari keeps everything on your phone: accounts, entries, bills, budgets, gold and silver, settings. The data sits in an encrypted database whose key lives in your phone's keystore. Nothing about you reaches our server.

The app fetches exchange rates and metal prices from our server twice a day. That request carries no account, no identifier and no data of yours. You can turn it off in Settings, Privacy, and type rates by hand instead.

Using Fondari with an account

Cloud sync and shared accounts need a Fondari account: an email address and a password, or a Google or Apple sign-in. When you create one, our server stores:

We never ask for or store your name, your phone number, your contacts or your location.

Who can read your data

How your data is protected depends on the mode you choose. In Private mode, your financial data and files are encrypted with a key that stays on your device; we cannot read them, and we cannot recover them if you lose your passphrase and recovery key. In Standard mode, your data and files are encrypted in transit and at rest, but the encryption key is held on our servers. This means we are technically able to access and read your transactions, notes and uploaded files, and it means that unauthorised access to our servers could expose them. If you do not want anyone but yourself to be able to read your data, choose Private mode.

Both modes are free. You choose when you turn sync on, and you can switch later in Settings. In Private mode, the strength of the protection also depends on the passphrase you choose: anyone holding a copy of our database could try to guess it, one slow attempt at a time.

In both modes the server can see what is listed above under "with an account", including how many records you have, how large they are, when they change and which member of a shared account wrote them. It cannot see amounts, titles, notes, tags or categories in Private mode.

Sharing an account

When you invite someone, the invitation mail names your email address and goes to theirs. Members see every entry in the shared account with a colour dot for who added it. Nicknames are stored inside the encrypted account data. Private labels you give members stay on your phone only. When a member leaves or is removed, they keep nothing new from that moment: in Private mode the account's key is changed and the data re-encrypted.

Receipts and files

Photos, PDFs and videos you attach are stored on our server, encrypted. In Private mode they are encrypted on your phone before upload; in Standard mode our server encrypts them, so the paragraph above applies to files as well. Text recognised in a receipt is worked out on your phone and stored encrypted with the file. Files are available on the Plus and Max tiers, and to every member of an account one of them sponsors.

Your phone keeps a copy of the files you have opened, so they load again without downloading. You choose how much room that copy may take in Settings, Files, and setting it to nothing means no file is kept on the phone at all. A file you open in another app, such as a PDF, is written out unencrypted for as long as that app needs it and removed afterwards.

On Android, the text recognition is done by a component of Google Play services that runs on your phone. Your photo is never sent to Google. The component does report technical information about itself to Google: your device model and system version, the app package and version, an identifier for the installation, timing measurements and error codes. On iPhone the recognition is part of the operating system and reports nothing.

Sign-in providers and stores

If you choose to sign in with Google or Apple, that provider receives the sign-in request and gives us a token with your email address (Apple may give a private relay address). We ask for nothing else.

If you buy a subscription, the App Store or Google Play handles the payment and gives us a signed proof of purchase. We keep the identifier that store uses for your subscription, and we ask the store again from time to time whether it is still running, so your tier is right even if you change it outside the app. We never see your card, your name or your address, and we do not keep the price you paid.

Usage statistics

Fondari counts which screens and buttons are used, anonymously, to improve the app. The count runs on our own server. It uses a random id that changes every time you open the app, so nothing links one session to another or to your account. It never includes amounts, notes, names, tags, categories or your IP address (the last part of the address is masked before storage). Turn it off in Settings, Privacy; the switch stops all sending at once.

Crash reports

Off unless you turn them on. A report holds the error, the stack trace, the app version, the operating system version and the device model, and goes to our own server. No ids, no addresses, no screenshots. Kept 30 days.

Where the data lives

Our server is in [Server location] and is operated by us. If we ever move files to an object storage provider, the provider will see encrypted objects, their sizes and dates, and nothing else; we will name the provider here first. Mail is sent from our own server.

How long we keep things

WhatHow long
Your account and recordsUntil you delete them
Deleted entriesA marker stays 90 days so your other devices learn about the deletion
Signed-in devicesUntil you sign them out, 90 days idle, one year at most
Codes sent by mail10 minutes
Mail and rate-limit counters7 days, as hashes
Security log (ids and actions only)1 year
Server logs7 days, without IP addresses
Files after a sponsor's tier endsVisible 30 days, hidden, deleted after 90
Encrypted backups of the serverAge out within 35 days

Deleting your account

In the app: Settings, Delete account. Without the app: fondari.nx-lab.com/delete-account. Your account and everything on the server are deleted at once and for good; to use cloud sync again you would create a new account. A subscription is yours to cancel in the store; we cannot cancel it for you. Data on your phone is yours to keep or remove.

Your data, your copy

Export everything from the app at any time as CSV, PDF or JSON, or as an encrypted backup file. The export is built on your phone; nothing is sent to us for it.

Your rights

You can see, correct, export and delete your data yourself in the app. If you want anything else, or want to complain, write to [support address]. You may also complain to the data protection authority where you live.

Children

Fondari is not designed for children and we do not knowingly collect data from them.

Changes

If this page changes, the date at the top changes with it, and a change that affects what we can read is shown in the app before you continue.