Privacy policy
Last changed: 9 September 2026. This English text is the governing version.
Fondari is run by [Operator name], [Operator address]. You can reach us at [support address]. This page says what the app stores, where, who can read it, and for how long. It is written from the same table we build the app from, so it should never disagree with what the software does.
Using Fondari without an account
Out of the box, Fondari keeps everything on your phone: accounts, entries, bills, budgets, gold and silver, settings. The data sits in an encrypted database whose key lives in your phone's keystore. Nothing about you reaches our server.
The app fetches exchange rates and metal prices from our server twice a day. That request carries no account, no identifier and no data of yours. You can turn it off in Settings, Privacy, and type rates by hand instead.
Using Fondari with an account
Cloud sync and shared accounts need a Fondari account: an email address and a password, or a Google or Apple sign-in. When you create one, our server stores:
- your email address, encrypted at rest and decrypted only to send you mail, plus a keyed hash of it so we can find your account;
- a verifier of a key derived from your password on your phone; the password itself never leaves your phone;
- if you turn on two-factor sign-in: the secret, encrypted at rest, and hashes of your backup codes;
- your signed-in devices: a random device id, the platform and app version, and when each was last seen;
- which accounts you own or share and with whom;
- your entries, bills, budgets, gold and silver and settings as encrypted records, with their ids, kinds, sizes, timestamps and who wrote them;
- your tier and, if you bought a subscription, the store's transaction reference;
- your language, so mail arrives in it.
We never ask for or store your name, your phone number, your contacts or your location.
Who can read your data
How your data is protected depends on the mode you choose. In Private mode, your financial data and files are encrypted with a key that stays on your device; we cannot read them, and we cannot recover them if you lose your passphrase and recovery key. In Standard mode, your data and files are encrypted in transit and at rest, but the encryption key is held on our servers. This means we are technically able to access and read your transactions, notes and uploaded files, and it means that unauthorised access to our servers could expose them. If you do not want anyone but yourself to be able to read your data, choose Private mode.
Both modes are free. You choose when you turn sync on, and you can switch later in Settings. In Private mode, the strength of the protection also depends on the passphrase you choose: anyone holding a copy of our database could try to guess it, one slow attempt at a time.
In both modes the server can see what is listed above under "with an account", including how many records you have, how large they are, when they change and which member of a shared account wrote them. It cannot see amounts, titles, notes, tags or categories in Private mode.
Sharing an account
When you invite someone, the invitation mail names your email address and goes to theirs. Members see every entry in the shared account with a colour dot for who added it. Nicknames are stored inside the encrypted account data. Private labels you give members stay on your phone only. When a member leaves or is removed, they keep nothing new from that moment: in Private mode the account's key is changed and the data re-encrypted.
Receipts and files
Photos, PDFs and videos you attach are stored on our server, encrypted. In Private mode they are encrypted on your phone before upload; in Standard mode our server encrypts them, so the paragraph above applies to files as well. Text recognised in a receipt is worked out on your phone and stored encrypted with the file. Files are available on the Plus and Max tiers, and to every member of an account one of them sponsors.
Your phone keeps a copy of the files you have opened, so they load again without downloading. You choose how much room that copy may take in Settings, Files, and setting it to nothing means no file is kept on the phone at all. A file you open in another app, such as a PDF, is written out unencrypted for as long as that app needs it and removed afterwards.
On Android, the text recognition is done by a component of Google Play services that runs on your phone. Your photo is never sent to Google. The component does report technical information about itself to Google: your device model and system version, the app package and version, an identifier for the installation, timing measurements and error codes. On iPhone the recognition is part of the operating system and reports nothing.
Sign-in providers and stores
If you choose to sign in with Google or Apple, that provider receives the sign-in request and gives us a token with your email address (Apple may give a private relay address). We ask for nothing else.
If you buy a subscription, the App Store or Google Play handles the payment and gives us a signed proof of purchase. We keep the identifier that store uses for your subscription, and we ask the store again from time to time whether it is still running, so your tier is right even if you change it outside the app. We never see your card, your name or your address, and we do not keep the price you paid.
Usage statistics
Fondari counts which screens and buttons are used, anonymously, to improve the app. The count runs on our own server. It uses a random id that changes every time you open the app, so nothing links one session to another or to your account. It never includes amounts, notes, names, tags, categories or your IP address (the last part of the address is masked before storage). Turn it off in Settings, Privacy; the switch stops all sending at once.
Crash reports
Off unless you turn them on. A report holds the error, the stack trace, the app version, the operating system version and the device model, and goes to our own server. No ids, no addresses, no screenshots. Kept 30 days.
Where the data lives
Our server is in [Server location] and is operated by us. If we ever move files to an object storage provider, the provider will see encrypted objects, their sizes and dates, and nothing else; we will name the provider here first. Mail is sent from our own server.
How long we keep things
| What | How long |
|---|---|
| Your account and records | Until you delete them |
| Deleted entries | A marker stays 90 days so your other devices learn about the deletion |
| Signed-in devices | Until you sign them out, 90 days idle, one year at most |
| Codes sent by mail | 10 minutes |
| Mail and rate-limit counters | 7 days, as hashes |
| Security log (ids and actions only) | 1 year |
| Server logs | 7 days, without IP addresses |
| Files after a sponsor's tier ends | Visible 30 days, hidden, deleted after 90 |
| Encrypted backups of the server | Age out within 35 days |
Deleting your account
In the app: Settings, Delete account. Without the app: fondari.nx-lab.com/delete-account. Your account and everything on the server are deleted at once and for good; to use cloud sync again you would create a new account. A subscription is yours to cancel in the store; we cannot cancel it for you. Data on your phone is yours to keep or remove.
Your data, your copy
Export everything from the app at any time as CSV, PDF or JSON, or as an encrypted backup file. The export is built on your phone; nothing is sent to us for it.
Your rights
You can see, correct, export and delete your data yourself in the app. If you want anything else, or want to complain, write to [support address]. You may also complain to the data protection authority where you live.
Children
Fondari is not designed for children and we do not knowingly collect data from them.
Changes
If this page changes, the date at the top changes with it, and a change that affects what we can read is shown in the app before you continue.