Obol (“Obol”, “we”, “us”) makes a personal budgeting app for iOS and Android. This policy explains what we collect, why, who else touches it, and how to get it back or have it erased. It covers the Obol mobile app and this website.
Financial data is among the most revealing data a person owns. The design rule we hold ourselves to is that the honest answer to “do you have X?” should usually be “we never collected it.”
What we collect
We collect only what the app needs to work:
- Your email address. It is your sign-in identifier, and the address we use to verify your account and send a password reset.
- The financial records you create. Expenses, income, budgets, buckets, accounts, categories, bills, installments and subscriptions — amounts, dates, merchant names, notes and any receipt image you choose to attach.
- Your profile and preferences. Display name, preferred currency, language and locale, and your app settings.
- Questions you ask the assistant. What you type or say to Ask Obol, plus the spending context needed to answer it.
We do not collect data you have not provided. There is no ad SDK, no analytics profile built on you, and no tracking of you across other apps or websites.
What we never collect
- Your bank credentials. Obol never asks for online-banking usernames, passwords or one-time codes, and has no bank connection to log in to.
- Raw message text. See “Automatic detection” below.
- Audio recordings. See “Voice entry” below.
- Contacts, precise location, or your photo library. Obol asks for a single photo only when you pick one to attach to an expense.
Turning bank messages into expenses
This is strictly opt-in and off until you set it up. Obol never reads your messages by itself: on iPhone, apps are not permitted to read SMS or notifications at all, and Obol does not ask for that permission. It only ever sees a message you hand it — by pasting one in, or through an Apple Shortcut you build once that forwards them.
A message you hand over is parsed on your device, not on our servers. Obol pulls out a small set of normalised fields — amount, currency, merchant, date, transaction type and, where present, the last four digits of a card — and only those are ever stored.
The raw text of a message is never uploaded and never stored. Obol does not read, extract or retain one-time passcodes, passwords, full card numbers, PINs or account numbers, and anything that is not a transaction notification is discarded.
Voice entry
Your microphone is used only while you are actively holding a recording — never in the background, and permission is requested at the moment you tap the microphone rather than when you open a screen. Obol does not record or store the audio.
Speech is converted to text by your device's own speech-recognition service (Apple's on iOS, Google's on Android). On iOS that may involve sending audio to Apple for processing; your operating system tells you so when it asks for permission. The resulting text is then handled exactly like something you typed. Nothing is saved to your ledger until you confirm it, and you can always type the expense instead.
Turning the recognised text into an amount, merchant and date is done by our AI provider, and it is covered by the same consent switch as the assistant. While that switch is on, the transcribed words are sent for parsing and the transcript is saved to your account so the entry can be audited and corrected; you can see and delete it with the rest of your data. Leave the switch off and voice still works — Obol interprets what you said on your device instead, and nothing about it is sent or stored on our servers.
Receipts and photos
Receipt and invoice photos stay on your device. Obol does not upload them, does not send them to our AI provider, and does not read them to extract a total — you enter the amount, merchant and date yourself. When you attach a photo to an expense, what is saved with that record is a reference to the file on your phone, not the picture. Because that reference points at your device’s own storage, an attached photo will not appear on a different device.
The AI assistant
Ask Obol answers using your own records. To do that, your question and the relevant slice of your spending data are sent to our AI provider, which returns an answer. Our provider does not use this content to train its models. Chat history is off by default and can be cleared at any time in the app.
The assistant produces informational summaries of your own data. It is not financial, tax or investment advice, and it can be wrong — your records remain the source of truth.
How your data is stored and protected
- Records are stored with our hosting and database provider under row-level security, so every row is reachable only by the account that owns it — this is enforced by the database, not only by app code.
- Data is encrypted in transit (HTTPS/TLS) and at rest by our hosting provider.
- Your sign-in session is held in your device's secure keychain or keystore rather than in plain storage, and sessions expire on a fixed schedule.
- You can put the whole app behind Face ID, Touch ID or your device passcode with the in-app lock.
- Keys for our AI provider live server-side only; they are never shipped inside the app.
Who else processes your data
We use a small number of processors, each for a single stated purpose:
- Hosting, database and authentication — stores your account and records and runs our server-side functions.
- AI provider — turns what you type or say into a structured expense, and answers your questions about your own spending. Photos are never sent to it.
- Your device platform's speech recognition (Apple or Google) — only if you use voice entry.
- Subscription management — processes and validates Pro purchases and tells our server when a subscription starts, renews or ends. It receives a purchase identifier for your account, not your financial records.
- Crash reporting (servers in the EU) — receives a technical report when the app crashes: the error, where in the code it happened, the device model and OS, and an anonymous account identifier. It is deliberately given nothing else. Amounts, merchants, category names, your email and your IP address are stripped before anything is sent, screenshots are never attached, and crash reporting is switched off entirely in development builds.
- App stores — Apple and Google handle distribution, and any purchase is processed by them, not by us. We never see your payment card.
We never sell your data, and we never share it for advertising or share it with data brokers.
International transfers
Our providers may process data in countries other than your own. Where that happens we rely on our providers' standard contractual protections for such transfers.
How long we keep it
Your records are kept for as long as your account exists, because they are the app. When you delete your account, the account and its records are deleted — see Data Deletion Instructions. Backups held by our hosting provider roll off on that provider's own schedule.
Your rights and choices
Inside the app, at any time, you can:
- Turn automatic detection off, or never turn it on.
- Export everything you have in Obol as a JSON file.
- Correct or delete any individual record.
- Clear your assistant chat history.
- Delete your account permanently, which cascades through every record we hold for you.
Depending on where you live you may also have the right to access, correct, port, restrict or object to our processing of your data, and to complain to your local data-protection authority. Write to support@obolapp.com and we will act on it. We do not charge for these requests.
Children
Obol is a personal-finance app intended for adults. It is not directed at children, we do not knowingly collect data from children, and the app contains no content or features aimed at them. If you believe a child has created an account, write to us and we will remove it.
This website
obolapp.com is a static site. It sets no cookies, runs no analytics, and embeds no third-party scripts or trackers. The contact form composes a message in your own email app rather than transmitting anything to us. Standard web-server access logs may be retained by our host for security and diagnostics.
Changes to this policy
If we change this policy we will update the date at the top of this page, and material changes will be communicated in the app before they take effect.
Contact
Privacy questions and data requests: support@obolapp.com. Anything else: support@obolapp.com. You can also reach us from Settings → Support inside the app.