Privacy Policy
Datum is built on a simple premise: your spending history is your own. This policy explains, plainly, what that means in practice.
The Short Version
Datum doesn't have servers that store your data. Everything you log — amounts, notes, photos, locations, moods — stays on your device and syncs only through your own personal iCloud account, which Apple encrypts and which we cannot access. We don't run analytics, we don't track you across apps or the web, and we don't sell or share your information with advertisers, because there are no advertisers in Datum.
What Datum Collects and Where It Lives
Everything you enter into Datum — expense and income amounts, notes, categories, collections, moods, and photos you attach — is stored locally on your device using Apple's SwiftData framework, and synced across your own devices via your personal iCloud account using CloudKit. We (the developer) never see this data. It is not transmitted to any server we operate, because Datum doesn't have one.
Location data. When you log an entry, Datum can use your device's location (via Apple's MapKit) to suggest a place name and category. This lookup happens entirely on your device. Datum does not send your GPS coordinates, location history, or any part of this data to us or to any third party. If you deny location permission, Datum works normally — you'll just need to fill in the place yourself.
Photos. Photos you attach to an entry are stored the same way as everything else: locally, then synced through your own iCloud account. We never receive a copy.
Third-Party Services
Datum makes network requests to exactly two outside services, and neither receives anything that identifies you personally:
- Frankfurter (frankfurter.app) — a free, open-source currency exchange rate API. Datum requests the current exchange rate for your home currency. No personal or transaction data is included in this request.
- RevenueCat — validates your subscription status if you purchase Premium. This involves your App Store transaction receipt, handled per RevenueCat's own privacy policy, to confirm your entitlement. It does not receive your expense data.
Datum does not use any analytics SDK, advertising network, or crash-reporting service that phones home with usage data.
Smart Logging
Datum's smart logging features — place and category suggestions, and (if enabled) speech-to-text for voice entries — run entirely on-device using Apple's MapKit and Speech frameworks. Nothing about your purchases, location, or voice is sent off your device for these features.
Your Data, Your Control
- Export. You can export your full history as CSV or JSON at any time from Settings, for your own records or to move to another app.
- Deletion. Deleting an entry, category, or the app itself removes that data from your device and, on next sync, from your iCloud account. Because we don't hold a copy, there's nothing further for us to delete on our end.
- iCloud. Your data's sync and backup are governed by your Apple ID and iCloud settings, and by Apple's own privacy practices, which you can review at apple.com/privacy.
Children's Privacy
Datum is not directed at children under 13, and we do not knowingly collect data from children under 13.
Changes to This Policy
If this policy changes in a material way, we'll update the "Last updated" date above and, where appropriate, note the change in the app's release notes.
Contact
Questions about this policy or how Datum handles your data can be sent through chris-wang.com.
Back to Datum