Legal

Privacy policy

Version 2026-10 · Last updated: 2 October 2026 · Applies to the Drachma app (Android and iOS) and this website.

The short version. Your money data never leaves your phone. Drachma has no accounts, no bank connections and no server that stores your data. Everything you enter is encrypted on your device. The only things that can leave the device are optional diagnostics (crash reports and anonymous usage counts from a fixed list), and you can switch both off in Settings at any time. We never see amounts, merchants, categories, notes or names.

1. Who is responsible

Drachma is made by Mohammad Khakpaki, an independent developer. For anything in this policy, contact [email protected]. I am the person responsible for the app's data handling. There is no company, data broker or analytics team behind it.

2. The design: offline-first

Drachma is built so that your financial data cannot leak, because it is never collected. There is:

The app works fully offline. Internet access exists only for the optional diagnostics described in section 5, for occasional in-app announcements and app settings (section 6), for checking a Drachma Plus subscription if you buy one (section 7), and for opening web pages like this one.

3. What stays on your device

Everything you put into Drachma is stored in a local database on your phone, encrypted with SQLCipher (AES-256). The encryption key is generated on your device and protected by your device's secure hardware keystore; it never leaves the device and cannot be exported. This covers:

Receipt photos are stored in the app's private storage, inaccessible to other apps. Your preferences (name, currency, theme, reminder choices and similar) are stored in the app's private settings. Android's cloud auto-backup of app data is deliberately disabled (allowBackup=false), so no copy of the database drifts into a cloud backup you didn't ask for.

4. What we never collect

No amounts. No merchants. No categories. No notes or memos. No goal names. No contact lists, no location, no photos beyond the receipts you deliberately add (which stay on the device). No advertising identifiers. No fingerprinting. Drachma sets no user ID of any kind in any third-party service.

5. Optional diagnostics (the only thing that can leave)

Drachma uses two Google Firebase services to keep the app working well. Both are on by default and both have their own switch in Settings → Your data. The app tells you this during onboarding, and switching either off takes effect immediately.

Crash reports (Firebase Crashlytics)

If the app crashes, a technical report is sent so the bug can be fixed: stack trace, device model, OS version and app version. Crash reports never include your money data; it isn't in the app's crash context to begin with.

Usage statistics (Firebase Analytics)

Anonymous counts of which screens and features get used, so it's clear what to improve. These events are restricted in code to a fixed, closed list: the app is physically unable to log free text, amounts or merchant names into analytics. The complete list:

EventWhat it says (and nothing more)
screen_viewWhich of the app's 13 screens was opened (e.g. "home", "budgets", "settings")
onboarding_step / onboarding_completedProgress through first-run setup (which step, by name)
entry_loggedMethod (keypad / scan / import) and type (expense / income)
scan_completedOutcome (success / cancelled / failed)
import_completedOutcome (success / cancelled / failed) and file kind (pdf / csv / xlsx / image)
statement_parsedThe shape of an imported statement, never its contents: account or card, file format, whether a header was found and the balance checked out, a row-count range (e.g. 6–20), a confidence level and the statement's language
merge_resolvedWhether a duplicate pair was combined or kept separate
budget_wizard_completed / goal_createdThat it happened. No names, no amounts
export_completedThat it happened, and the format (csv / json)
backup_created / backup_restoredThat it happened
notif_toggled / theme_changedWhich reminder was switched (daily, weekly, pace, goals or renewals) and on or off; which theme was picked
review_prompt_requestedThat the app asked your store to show its rating prompt, the moment that triggered it (e.g. "goal milestone"), and whether the prompt opened. Drachma never learns whether or what you rated.
announcement_shown / _cta / _dismissedHow an in-app announcement was received

Advertising-ID collection and ad-personalization signals are disabled in the app's configuration. Diagnostics are processed by Google Firebase on Google's infrastructure under Google's Firebase privacy terms.

6. Announcements, app settings and notifications

Drachma can show occasional in-app notices ("what's new", or a required-update notice) fetched from Firebase Remote Config, and can receive broadcast announcements through Firebase Cloud Messaging. These are one-way broadcasts to all installs: the app subscribes to a public "announcements" topic and does not upload or store your push token anywhere on our side. There is no server of ours to send it to. Which announcements you've dismissed is remembered only on your device.

The same Remote Config channel delivers a few app settings: updates to the vocabulary Drachma uses to read statements, the Free plan's allowances, and when to suggest rating the app. It is a one-way download; nothing about you or your data goes back up.

Everyday notifications are generated locally on your phone and never involve a network: the daily nudge, the weekly recap, budget pace notes, goal celebrations, subscription renewal reminders (Drachma Plus), and an alert if a subscription you marked cancelled charges you again. Scheduled reminders that fall between 22:00 and 08:00 wait until 08:00, and pace notes are skipped during those hours.

7. Drachma Plus purchases (Adapty)

If you subscribe to Drachma Plus, the payment itself is handled entirely by your app store (Google Play or the App Store) under its own terms; Drachma never sees your card or bank details. To know whether Plus is active, the app uses Adapty, a subscription-management service. Adapty receives the store's purchase information (product id, transaction id, subscription price and currency, trial and renewal state) and basic device information (model, OS and app version, locale), tied to a random, install-scoped identifier, never your name, email or anything you typed into the app. It never receives your budget data: no amounts you logged, no merchants, no categories, no goal names. If subscription state can't be checked (you're offline, the store is down), Drachma quietly falls back to the free tier and never locks you out of your own numbers. Adapty processes this data under Adapty's privacy policy.

8. Backups: files you own

When you create a backup, Drachma writes a single .drachma file to a location you pick. It is sealed with AES-256-GCM encryption; the key is derived from a passphrase you choose (PBKDF2-SHA256, 210,000 iterations, minimum 8 characters). The app never transmits this file. If you save it to your own cloud drive, that is between you and your cloud provider. Without your passphrase the file cannot be opened by anyone, including me. Receipt photos are not included in backups.

9. Exports: plain files, deliberately

You can export your complete data as CSV or JSON from Settings, saved to a location you pick. Exports are unencrypted on purpose, because they're for spreadsheets and your own archives, and the app warns you of exactly that when you export. Treat them like the private documents they are.

10. Receipt scanning and statement import

Receipt text recognition runs entirely on your device using a bundled, offline OCR model. The camera capture screen is your phone's own document scanner (Google Play services on Android, Apple's on iPhone), which runs on-device; Play services may download its scanner module once. Bank statements (PDF, CSV, spreadsheets) and e-invoices are parsed locally; password-protected PDFs are opened locally with the password you type, which is used in memory and not stored.

Finding subscriptions and installment plans happens on your device too: Drachma compares your own entries with each other and with a list of known services built into the app. No receipt image, statement content, recognized text or detected subscription is ever transmitted.

11. Permissions

12. Data retention and deletion

Your data lives exactly as long as you keep it. Delete any entry in the app, or delete everything by uninstalling: the encrypted database and its hardware-bound key are destroyed with the app, and there is no server-side copy to chase. Backups and exports you created are yours to keep or delete wherever you put them. Diagnostics already sent are retained by Firebase for its standard limited windows and are not tied to your identity. Subscription records live at your app store and at Adapty for as long as needed to manage the subscription.

13. Your rights

Privacy laws like the GDPR give you rights of access, portability, correction and erasure. Drachma's design means you exercise almost all of them directly: your data is on your device, exportable in full as CSV/JSON, editable in the app, and erased by uninstalling. For anything about diagnostics, including "please make sure nothing of mine persists", email [email protected].

14. Children

Drachma is not directed at children under 13 (or the equivalent minimum age in your country), and I do not knowingly collect personal data from children; by design, the app barely collects personal data from anyone. If you believe a child has used the app and something concerns you, please get in touch.

15. Changes to this policy

If this policy materially changes, the app will tell you: it tracks the version you agreed to and shows a review notice in Settings until you've read and accepted the update. The current version is always at the top of this page and at this address.

16. Contact

Mohammad Khakpaki · [email protected]