Privacy policy
اقرأ هذه الصفحة بالعربية ←Dbrni keeps your financial records on your own phone, in an encrypted database. Nothing is sent anywhere unless you switch on a feature that sends it, and each of those is off until you turn it on.
We cannot read your financial data. Not as a policy — as a consequence of how it is stored.
What the app stores, and where
Everything you enter — accounts, transactions, budgets, goals, bills, subscriptions, income — is written to a database file on your device.
That file is encrypted with SQLCipher. The key is 32 random bytes generated on your device on first run and held in the iOS Keychain. It never leaves the device and is never transmitted.
A consequence worth stating plainly: if that key is lost, the data cannot be recovered by anyone, including us. This is what "encrypted" means. The app will not delete your records if it happens — it stops and tells you — but the only way back is a backup you made yourself, or an account you signed in to.
What leaves your device
Four features send data off the phone. All are off by default, or require an account, and each is a separate decision.
1. Sync across devices (requires an account)
Once you are signed in, your records are copied to Google Firestore under your account, so any device you sign in to has them. This happens by itself — when you open the app, when you return to it, and shortly after you change something — because a safety net you have to remember to use is not one. There is also a Sync now button for when you want to be certain before switching phones.
If you never sign in, none of this happens and nothing leaves the device.
Not synced, by deliberate choice: your device settings — language, theme, your PIN, and the app-lock configuration.
Stored data on the server is protected by rules that permit access only to the signed-in account that owns it. Google processes it as our infrastructure provider; see Google's own privacy terms for what that entails.
2. Backups (opt-in, you control where they go)
Save a backup writes a single encrypted file and hands it to your phone's share sheet. Where it goes from there — Files, iCloud, email, a cable — is your choice, and the app has no part in it.
The file is encrypted with a passphrase you choose. We never see the passphrase and it is not stored anywhere. A backup whose passphrase is lost cannot be opened by anyone.
The backup is a standard SQLCipher database, not a proprietary format. It can be opened with ordinary command-line tools, without this app. That is deliberate: data you can only recover through our software is not really yours.
3. Importing from the previous version (opt-in, one-off)
If you used the earlier version of this app, signing in lets Dbrni read your old records and copy them into the local database. It only reads; it never modifies or deletes the old data.
4. Better wording from the Coach (requires an account)
The Coach works out its observations on your device, from your own figures. When you are signed in, the wording of those observations may be improved by a language model — Claude, run by Anthropic — through our own server.
What is sent: the kind of observation, and the numbers already worked out for it, such as "restaurants, up 38%, 380.00 more than usual".
What is not sent: your transactions, the merchants you paid, your account names, your balances, any dates, or even which category an observation is about. Observations are labelled by position in a list, so nothing identifying what you actually spend money on leaves the phone in order for a sentence to be rewritten.
The figures are never recomputed by the model, and the server rejects any reply containing a number it was not given. If anything about this is unavailable — no account, no connection, no answer — the app uses its own wording.
What the app does not do
- No analytics. No usage tracking, no session recording, no crash reporting service, no advertising identifier, no third-party SDK that observes what you do.
- No advertising, and no data shared with advertisers or data brokers.
- No selling of data, in any sense of the word, including the broad definitions used by CCPA and similar laws.
- No profiling for anyone else's benefit. Every figure — the insights, the plan, the health score — is computed on your device, from your own records, and stays there. The one exception is the Coach's wording, described above.
- No account required. The app is fully usable without ever signing in. Signing out never deletes what is on the phone.
Bank messages (SMS)
Not in this app. Dbrni does not request, read or store SMS messages, and does not hold the permission to. iOS provides no mechanism for an app to read messages, and Dbrni is an iOS app.
Permissions
| Permission | Why | When it is asked for |
|---|---|---|
| Notifications | Bill and budget reminders | Only when you switch reminders on |
| Face ID / biometrics | Unlocking the app | Only when you switch the app lock on |
Nothing is requested at first launch. If you decline any of these, the rest of the app works normally.
Children
Dbrni is not directed at children under 13, and we do not knowingly collect information from them.
Your data, and getting it out
Because your data is on your device, most rights people have to ask a company to exercise, you can simply do:
- Access and portability — Save a backup, or export your transactions as CSV or PDF.
- Deletion — delete the app. That removes the local database. If you have used sync, write to the address below to have the server copy deleted.
- Correction — edit anything, at any time, in the app.
Changes
If this policy changes in a way that affects what leaves your device, the app will say so before the change takes effect, rather than relying on you re-reading this page.
Contact
Published by Abdullah Laghbi, an individual developer, Saudi Arabia.
Questions, or a request to delete a synced copy: Mr.Abdullah@outlook.com