Larder — Privacy Policy
In effect since · last updated · 한국어
Larder is a manual cash-envelope budgeting app. It does not connect to your bank. This policy describes its current data practices.
No bank connection
You enter amounts and transactions yourself. Larder does not connect to your bank or pull data from your financial accounts.
Where your budget lives
Budget data is stored on your device and in Supabase so the app can sync and restore it. It is associated with an anonymous account or, if you sign in, your Sign in with Apple account. Larder's developer and service providers may process this data as needed to operate, secure, support, and comply with legal obligations for the service. A person you invite to a shared budget can also access that shared budget.
Tracking & ad measurement
If you allow tracking through Apple's App Tracking Transparency prompt, Larder uses RevenueCat to collect your advertising identifier and may share that identifier and subscription events with Meta to measure ad performance. If you decline, this advertising-attribution path is disabled. Essential account, sync, and subscription processing still occurs.
The AI coach (OpenAI)
Larder Pro includes a coach you can ask about your money. It works out its figures on your device, and only if you allow it — the app asks the first time you type a question, and you can change your answer any time in Settings › Coach replies by OpenAI — Larder sends your question, the recent questions and replies in that conversation, and your plan through its server (Supabase) to OpenAI in the United States to write the reply. Your plan includes your pay and paydays, bills, envelope names and balances, savings goal, and the spending entries you have logged, with their notes. Your name, email, and Apple ID are not sent, but anything you type into a question or a note is.
Larder's server passes this on and does not store its content; it counts requests only to limit use. OpenAI states that, by default, data sent through its API is not used to train its models and is deleted within 30 days unless a longer period is required by law or is needed to protect its services or others from harm. That is OpenAI's own statement: once data reaches OpenAI, OpenAI's policies govern how it is handled, not ours. If you don't allow it, or turn it off, the coach answers only from its own calculations on your device and nothing is sent.
Versions 1.0.5 and earlier had an earlier form of this, the analyst chat: when you used it, your question, the recent conversation, and a budget summary went through the same server to OpenAI to write the answer. If you still use one of those versions, it works that way until you update.
Sharing a budget with someone
You can invite one other person into a shared budget with a code. Once they join, both of you can read and edit the same envelopes and transactions, and each can see the other's sign-in email. For Hide My Email users, this is Apple's relay address. Leaving the shared budget removes your access to it.
Sign in with Apple
We receive only what Apple shares — at most your email, used as your account label. Hide My Email works fine.
Purchases
Apple processes subscription payments. RevenueCat receives an app user identifier, App Store receipt and purchase or subscription status, and limited technical data to manage entitlements, prevent fraud, provide support, and analyze subscription performance. Larder does not receive your card details.
Error reports
The Larder iPhone app itself also sends crash and error reports to Sentry (Functional Software, Inc., d/b/a Sentry, San Francisco), the same error-monitoring service described below. A crash report goes out the next time you open the app after it crashes; an error report goes out when something fails on our side — a purchase the subscription service rejected, a failed subscription sync, or the coach server failing. Either one carries the app version, your iOS version, device model, screen size, memory, and locale, and, for a crash, where in the code it happened — exception type, stack trace, thread list. It never carries your account, user ID, email, device name, budget figures, notes, coach questions, or purchase amounts, and our Sentry project is set not to store your IP address.
When the coach server fails for a reason on our side — a provider outage, a rejected key, a bug — it sends a short technical report to our error-monitoring service, Sentry: the kind of failure, a status code, and the provider's error code. It is never your question, your figures, or your account.
Either way, the report travels over an encrypted connection (HTTPS). Sentry keeps events for 30 days on our current plan and processes them in the United States. This is only to find and fix crashes and failures. There's no in-app switch for this — a report carries nothing that identifies you. If you'd rather not send any, you can stop using the app and ask us to delete your account.
Where your data is handled
Supabase keeps the synced budget on servers in South Korea (Seoul). OpenAI (coach replies, only if you allow it), RevenueCat (subscriptions), Sentry (crash and error reports), and Meta (ad measurement, only if you allow tracking) process the data described above in the United States. Apple handles payments and Sign in with Apple under Apple's own privacy policy. These countries' data-protection laws may differ from those where you live.
OpenAI processes coach requests on our behalf under its Data Processing Addendum, which includes Standard Contractual Clauses for data from the EU, Switzerland, and the UK. Every transfer uses an encrypted connection (HTTPS).
If coach replies ever move to a different AI provider, we will update this policy and ask for your permission again in the app before any question goes to the new provider.
Erase and account deletion
Settings → “Erase everything & start over” clears local budget data and requests that the synced budget be replaced with an empty copy. “Delete account” requests deletion of the account and its server data. These server operations require a network connection; the app reports a failure so you can retry. Deleting the app removes its local copy but does not by itself delete server data or the account.
What we store, and why
- Budget data you enter
- Envelopes, amounts, transactions, bills, paydays, goals, notes, and related settings — to operate, sync, restore, and support the app. Stored on-device and in Supabase.
- Account identifier
- An anonymous app user ID, or information Apple shares when you sign in, used for authentication, sync, account recovery, and subscription access.
- Purchases
- Apple handles payment. RevenueCat processes an app user ID, receipt, purchase and subscription status, and limited technical data. Larder does not receive card details.
- Ad measurement
- If you allow tracking: your advertising identifier and subscription events may be shared with Meta through RevenueCat to measure ad performance.
- AI coach
- Only if you allow it: your question, the recent conversation history, and your plan — including your spending entries and their notes — are sent through Supabase to OpenAI to write the reply. See “The AI coach” above for the fields and retention.
- Shared budget
- If you invite a partner, both of you can read and write the shared budget and each sees the other's sign-in email. Two people maximum.
Retention & deletion
Budget and account data is retained while needed to provide the service or until you use the relevant erase or account-deletion control. Provider backups, security records, transaction records, or logs may remain for limited periods where required for security, fraud prevention, accounting, dispute handling, or law. You can contact us about an unresolved request.
Security
We use reasonable technical and organizational safeguards appropriate to the service. No storage or transmission method can be guaranteed completely secure.
Your choices and rights
Depending on where you live, you may have rights to access, correct, or delete your personal data, to restrict or object to certain uses of it, to receive a copy of it, and to withdraw a permission you gave. Use the in-app controls or contact support@larderbudget.com; someone you authorize can also ask for you. We may need to verify the request.
If you live in the EU or the UK, you can also lodge a complaint with your local data protection authority. In South Korea, you can contact the Personal Information Dispute Mediation Committee (1833-6972) or the KISA privacy report center (118).
Children
Larder is not directed to children under 13 and does not knowingly collect data from them.
Changes
If this policy changes, we’ll update this page and the “Last updated” date above.
This app was released as Stash and is now called Larder. The developer is unchanged.
Contact
Larder is operated by Yeonwoo Lee, who is also its Privacy officer (개인정보 보호책임자). Questions about your privacy? Contact support@larderbudget.com.