Privacy Policy
This is the same Privacy Policy shown inside the Worthline app.
The short version
Worthline collects nothing. There are no accounts, no servers we run, no third parties, no in-app analytics, no advertising, and no telemetry. Your financial data is stored only on your device, in a database encrypted with a key derived from your passphrase. (Two exceptions, both under your control: if you turn on sync, encrypted copies of your changes go to a server you choose — see “Sync between devices” below — and the app stores may share aggregate, anonymous statistics with us — see “App-store analytics” below.)
We — the developer — never receive, see, or have any way to access your data. There is nothing on our end to leak, sell, or hand over, because nothing ever reaches us.
What is stored, and where
Everything you enter lives in a single encrypted database file on your device, plus its encrypted receipt files and encrypted backups. The encryption key is wrapped by your passphrase and never leaves the device in usable form. Losing the passphrase means losing access to the data — by design, there is no recovery and no back door.
If you turn on reminders, the notifications your device delivers are composed while the vault is open and then held by the operating system outside Worthline’s encryption — that is what lets them appear while the app is closed. By default they name a category and a date (“A payment is due this Friday”), never an amount; including item names is a separate opt-in with its own warning. Already-delivered notifications remain in the operating system until dismissed. On Android the schedule itself is also kept in the app’s private storage, outside the encrypted database, so reminders survive a restart — it holds the same notification text and nothing more, and turning reminders off deletes it.
Two things are deliberately stored outside that encryption, because the lock screen has to be able to read them before the vault is unlocked. If you set a lock-screen passphrase hint, the hint is kept unencrypted on your device — it is optional, refused if it contains your passphrase, and readable by anyone who can use your device. And the app keeps a small unencrypted note about your backups — which folder they are in, how many, and when the newest was made (on a Mac, also the folder-access token that lets the locked app check that folder; it is unusable by any other app or person). It names the folder, never any of your financial data. Neither travels in a backup or a transfer file.
Biometric unlock (Face ID, Touch ID, or fingerprint), when you enable it, stores a copy of the key in your device’s secure hardware. That copy never leaves the device and never travels in a backup or transfer.
Backups and transfers you choose
If you turn on your device’s system backup (iCloud / Finder on Apple devices, or Google backup on Android), the app’s encrypted database rides along in those backups as ciphertext. Once it is in iCloud or Google, it is governed by Apple’s or Google’s privacy policies, not this one, and it stays there until you delete it from that account. You control this with a switch in Settings, and it is your choice; the app never sends anything on its own.
A transfer file you export to move your data to another device is also encrypted and only ever goes where you send it. Your passphrase is never inside it.
Sync between devices (optional)
If you turn on sync, Worthline connects to a WebDAV server that you choose and that you have an account on — for example your own Nextcloud. Every change is encrypted on this device, under a key derived from your passphrase, before it is uploaded. The server stores only encrypted data and never sees your passphrase. What the server operator can see is what any file host can see: that encrypted files of certain sizes were written at certain times, and the network address of the device that wrote them.
One thing does travel with your encrypted data: the key file that holds your encryption key wrapped by your passphrase — a copy of the same non-secret file that sits beside your vault and in your backups, with this device’s own settings left out. It is useless without the passphrase, but anyone who can read the server’s files — the operator, someone who breaches it, or its trash and version history — can try to guess your passphrase offline, for as long as they like. A strong passphrase is what protects you.
The server address, your username, and the app password you enter — typed, or scanned from a setup code another of your devices displayed — are kept encrypted on this device beside your vault key. A setup code carries those three details sealed to your family’s encryption key, readable only by a device that already holds your vault, and it expires ten minutes after it is shown. They never travel in a backup or a transfer file, and sync is set up separately on each device. Turning sync off stops all connections from this device; the encrypted files already on the server stay there until you delete them yourself — and your server may keep deleted files in its trash and version history, so empty those there too.
If the same thing is changed on two devices before they sync, the later change wins — “later” as judged by the devices’ own clocks, which can disagree. The replaced value is not announced; it survives only in the Recent sync activity list. A server you do not control can delay sync, withhold changes from a device, or lose them — it cannot read your data or alter it without the app noticing.
Sync is not a backup: it copies your current data between your devices, so a deletion or a mistake travels with everything else. Keep making backups.
Sync is off unless you turn it on. With it off, Worthline contacts a server only when you take a sync action yourself: pressing “Test Connection” or “Turn On Sync” on the sync setup page, connecting from a scanned setup code, joining a family from the first-run screen, or replacing this device’s data with a family’s. Each of these signs in with the address and app password you provided — typed, or scanned from a setup code; the connection test makes a Worthline-Sync folder if there isn’t one and writes and deletes two small scratch files to check the server enforces the rules sync depends on, and joining downloads your family’s encrypted data. None of your financial data is sent by any of them, and nothing you did not ask for is kept. (On Apple devices the App Store itself checks your purchase status and fetches prices when you open the Supporter page — that is Apple, not us, and it carries none of your data; see “App-store analytics” below.)
No tracking
Apart from a sync server you connect yourself, and your app store’s own purchase checks, the app makes no network requests to us or to any third party in the course of normal use. It does not contain advertising or analytics SDKs. It does not build a profile of you.
App-store analytics (aggregate and anonymous)
Apple and Google may share aggregate, anonymous statistics about the app with us — for example how many people installed it, roughly how many use it, and crash or performance rates. This is gathered and anonymized by Apple or Google at the platform level, only from users who opt into sharing diagnostics with them; Worthline itself contains no analytics code. We receive only aggregate numbers and cannot link any of it to you or to any individual.
You can turn this off on your device: on iPhone, Settings → Privacy & Security → Analytics & Improvements → “Share With App Developers”; on Android, in your device’s usage & diagnostics setting.
Children
Worthline is a general-purpose planning tool and is not directed at children. Because it collects no data at all, it collects no data from anyone, including children.
Contact
Questions about privacy: hello@worthline.app. Because we hold no data about you, there is no account to close and no personal data for us to delete or export on request — it is already only on your device, under your control.