TL;DR
Almost everything lives on your phone. The few things that don't are encrypted before they ever reach us, and we can't read them. And if you turn on Data Sync, your data goes to your server, not ours.
Here's the long version, with all the technical receipts.
Your SMS, expenses, and budgets never leave your phone.
The whole personal-finance side of Totals (SMS parsing, transactions, budgets, analytics, the unified ledger, your accounts) runs entirely on your device. We have no servers reading your bank notifications. We never will.
SMS access is the deal you approve upfront.
When you grant SMS permission, you're allowing Totals to read messages from supported bank senders and turn them into your transactions and analytics. That's the entire use. It happens on your device, works fully offline, and messages from actual humans are never touched. Nothing is uploaded, ever.
Data Sync only goes where you point it.
Totals can push your transactions, accounts, and budgets to a server you choose (your VPS, your homelab, your own API). It's off by default and lives behind an explicit consent screen. When it's on, your phone talks directly to your server over HTTPS. There is no Totals relay in the middle, so we never see a byte of it. It's strictly one-way: Totals pushes and never reads anything back. Your server credentials live in your phone's keystore, not in the app database. One honest caveat: once data lands on your server, protecting it is your job. We can't secure what we never touch.
Shared groups: encrypted before they touch the network.
When you split expenses with friends, the amounts, names, and reasons are encrypted on your phone with a key only you and the other group members have. Our server receives an unreadable blob, relays it to the other phones, and deletes it once it's delivered. We can see that something moved between devices. We cannot see what.
What the server actually holds, in plain English.
A random group ID (a string of letters and numbers that means nothing without the key). A list of public keys for the devices in each group (public keys are the “safe” half of cryptographic identity, and they're meant to be shared). Encrypted blobs awaiting delivery. Push notification tokens so we know which phone to wake up when something new arrives. That's the lot.
What the server never holds.
No email. No phone number. No name. No password. No bank SMS content. No decrypted expense data. No group names or display names (those are encrypted too). No PIN. No private keys. No record of what you've typed, searched, or budgeted for.
Identity backup is opt-in and end-to-end encrypted.
If you want to recover your groups after losing your phone, you can set a PIN. The PIN encrypts a backup of your cryptographic identity, which is uploaded to our server in sealed form. The PIN itself never leaves your device. If our database were ever fully compromised, attackers would walk away with sealed blobs they can't open. Don't want this? Don't set a PIN. We never store anything we weren't explicitly asked to.
Push notifications carry no content.
When a friend adds a shared expense, your phone receives a generic “there's new activity” ping from Google or Apple's notification service. The actual content is fetched and decrypted on your device after the ping. Google and Apple see “a notification went to this device.” Nothing more.
We don't track you, and we couldn't if we tried.
There's no usage analytics, no telemetry, no fingerprinting, no “anonymous” identifiers that are secretly traceable. We don't know if you're using the app right now, how often, or what features you like. We'll find out you exist if you join a shared group with someone, and even then, all we know is “a device with this public key is in this group.”
We don't sell data. We don't have data to sell.
Same energy as before: you can't sell what you don't have. Our business model is not data harvesting. It's still “we're figuring it out, but it's definitely not that.”
Retention: as short as we can get away with.
Encrypted shared-expense payloads are deleted within 30 days, or sooner once everyone has received them. Inactive groups are deleted about a year after the last shared expense. Authentication challenges expire in 60 seconds. Identity backups stay as long as you want them. Delete the backup, it's gone.
Term 1:
Your money is your money. We just help you count it. We aim for 100% parsing accuracy, but banks change their SMS formats without warning us, so some transactions may parse incorrectly or not at all. Cross-check anything important against your actual bank records. If the numbers look off, let us know and we'll fix it.
Term 2:
We are not a bank, a financial advisor, or your mom. Don't make financial decisions based solely on what our app says. We're reading your SMS notifications, not predicting the stock market.
Term 3:
Your recovery PIN is your recovery PIN. We never see it, we can never reset it, and we cannot recover your data if you forget it. Choose something you'll remember. Write it down somewhere safe if you have to.
Term 4:
If you find a bug, tell us. If you find a feature you love, also tell us. We thrive on both validation and constructive criticism.
Term 5:
We reserve the right to make the app even better without asking your permission first. Revolutionary, we know.
Term 6:
Your sync server is your sync server. If you point Data Sync at an endpoint, everything that happens to the data after it arrives (security, backups, who else can read it) is between you and that server. Point it somewhere you trust.
Don't trust our promises. Verify them. The entire backend is open source. Every line of code that handles your encrypted data lives in a public repository. If you spot us doing something this policy says we don't, open an issue and we'll buy you dinner.
Don't want even our zero-knowledge server in the loop? Self-host the backend. The server is designed to be run by anyone. You can use Totals without ever talking to a server we control.
And the personal-finance side of the app still works 100% offline. Turn off your WiFi. Enable airplane mode. Wrap your phone in aluminum foil. You'll still get your spending breakdown. All you'll miss is shared expenses syncing with your friends' phones and Data Sync pushing to your server, because those are the features that genuinely need a network.
Things might change down the road. But if they do, it will be entirely opt-in. We'll ask nicely, explain what and why, and you'll say yes or no. No sneaky toggles, no pre-checked boxes, no “by continuing to breathe you agree to our new terms.”
If we ever need anything from you, you'll know about it before we do.
Last updated when we shipped Data Sync. The core promise hasn't changed: nothing our server has is anything our server can read, and your Data Sync traffic never touches us at all. If you ever catch us breaking that promise, the code is open. Call us on it.