WealthOS

Privacy Policy

Last updated: 20/09/2026

Your financial records and attached files stay on your device. A limited service profile and purchase information are processed online to operate the app and subscriptions.

Privacy PolicyTerms of UseSupportData Deletion

1. Who we are and what this policy covers

WealthOS is provided by the developer identified in the app’s store listing (“we”, “us”, or “our”). This policy covers the mobile app and support you request from us. Contact sm.labs@rediffmail.com for privacy questions or requests.

The app does not require an email/password account or connect to your bank or broker. It does create a service profile using an installation identifier. No advertising SDK or cross-app advertising tracking is used in this version. We do not sell personal information or share it for targeted advertising.

2. Financial records and files on your device

Investments, account balances, income, liabilities, goals, annual spending buckets, notes, reminders, settings, and images or PDFs you attach are stored in the app’s local storage. The app does not automatically upload these records, financial amounts, or file contents to our server or RevenueCat. This version has no cloud portfolio sync or automatic statement extraction.

When you choose an image or PDF, the app makes a local copy of that selected file. It does not request access to your entire photo library. You can remove or replace attachments in the app.

Exported backups include portfolio records, settings and supported attachments. Backup files are not encrypted. Keep them in a location you trust. Restoring a backup creates a local recovery copy before replacing the current portfolio. If you open or share a file with another app or recipient, that destination handles the copy under its own practices.

Your operating system or device backup provider may back up app data according to your settings. Those backups are separate from a cloud sync service operated by us.

3. The limited profile sent to our service

At setup and when you update relevant profile settings, the app sends a generated installation identifier, your selected country and currency, the optional name you enter, and the app version to our service hosted using Supabase. The identifier is also used as the purchase-profile ID described below. The name is optional; you can leave it blank during setup. If you previously supplied a name, clearing it in the app does not currently remove the name saved in your online service profile. Contact us through the deletion or privacy-request process below to remove it from our service.

We use these details to initialize and maintain your service profile, associate subscription status with your installation, and support the app. The identifier is not your advertising ID, bank account number or government identifier.

Our service also logs request timestamps, the installation identifier, and whether a profile was created, updated or returned unchanged. Technical errors are logged when a request fails. Because the app connects at startup and when relevant profile settings change, these records can indicate app/service activity. We use these operational records to support the service and investigate problems.

For supported metal-price estimates, the app requests the metal type and currency. It does not send your quantity, purchase cost, portfolio total or attached documents with that request. Our hosting and network providers may process connection information, such as IP addresses, request timing and technical logs, when serving these requests.

4. Subscriptions and purchase information

Apple or Google processes store payments. We do not receive your payment-card number or bank payment credentials. RevenueCat processes the installation identifier, store purchase receipts or tokens, transaction and product identifiers, subscription status and expiry, and technical information needed to deliver and validate purchases. This can include app/SDK version, operating system, device type, locale, currency and service activity.

RevenueCat can connect when the app starts and when purchases, restoration or subscription status are checked, even if you do not buy a subscription. On iOS, its SDK also sends Apple’s identifier for vendors (IDFV) in service requests. This is different from the advertising identifier (IDFA). Automatic collection of identifiers for advertising-attribution integrations is disabled; that setting does not stop this service-request metadata or the installation identifier explicitly provided by the app.

We use RevenueCat for entitlement access, restoration, billing support, fraud prevention and purchase/revenue reporting. Because the installation identifier connects these records, purchase information can be associated with the optional name and service profile you provided.

See RevenueCat’s privacy information, Apple’s privacy policy and Google’s privacy policy for their respective services.

5. Device permissions and optional features

Optional reminders use device notifications. The reminder title and date are processed on your device; notification visibility follows your device settings. You can turn notifications off in system settings.

Optional biometric locking uses the operating system’s authentication result. We do not receive or store your fingerprint or face template. This screen lock does not encrypt exported backup files. File selection and sharing use your device’s picker and share controls.

6. Support and sharing

If you email support, we receive your email address, any name provided by your email service, your message and any files you choose to send. We use them to answer you, investigate problems and handle your request. Our email provider and yours process the correspondence for delivery and storage.

Please do not send passwords, payment-card details or a full financial backup unless it is necessary and you have reviewed its contents. A subscription order reference or installation identifier is normally more useful for purchase or deletion questions.

We disclose information to the service providers described here as needed to operate the app, and when required by applicable law or to address fraud or security incidents. We do not send your local portfolio to providers merely because you use a paid feature.

7. Retention and deletion

Local records remain until you edit or delete them, restore over them, or remove the app’s data. In Settings, “Delete this device’s portfolio” removes local records, settings, attached files and the recovery copy. It retains the installation identifier and does not delete previously exported files, the online service profile, RevenueCat records or store purchase history.

There is no automatic expiry period for the service profile in this version. Operational logs are retained according to the hosting provider’s configured log-retention period; they are separate from the local portfolio and may include installation identifiers and request activity. You may request its deletion through sm.labs@rediffmail.com. We remove the service profile and associated data we control unless retention is needed for an active service, fraud prevention, a dispute or a legal obligation. If an exception applies, we explain the retained category and reason when responding. Provider backup copies may persist according to the provider’s backup lifecycle.

We keep support correspondence while needed to resolve the request, maintain necessary support records and meet applicable obligations. You may request deletion. Purchase records may need to be retained for billing, fraud prevention, tax, accounting or other legal obligations. Apple and Google control their own transaction records.

Deleting data or uninstalling the app does not cancel a subscription. Manage cancellation through the store that billed you. See Data Deletion for practical steps.

8. Security and international processing

Local app data uses your device’s storage protections. The app’s configured online service connections use HTTPS. No system can guarantee absolute security; protect your device and exported files.

Supabase, RevenueCat, store providers and email providers may process information in countries other than yours, including the United States. Provider processing is subject to the applicable service terms and data-processing arrangements. Where transfer safeguards are required by applicable law, they must apply to that processing. Contact us for information about your request or the providers involved.

9. Your rights and choices

You can change local records and your optional profile name in the app, export a backup, remove local files, revoke device permissions and contact us about service data. Depending on applicable law, you may have rights to access, correct, delete, receive a portable copy, restrict or object to processing, or withdraw consent where processing relies on it. Withdrawal does not affect processing already lawfully completed.

Where a legal basis is required, we process information to provide requested app and purchase services, for legitimate interests in security and reliable operation, to meet legal obligations, and with consent where required for optional processing. You can contact sm.labs@rediffmail.com to exercise your rights. We may request enough information to locate the relevant profile and verify the request, without requiring your portfolio contents.

These choices include applicable rights under European, UK, Brazilian and other local privacy laws. You may also complain to your local data-protection authority. We do not treat a privacy request as permission to send marketing messages.

10. Children

The app is designed for adults organizing their finances and is not directed to children. We do not knowingly collect personal information from children below the applicable minimum age. If you believe a child has provided information to our service, contact sm.labs@rediffmail.com so we can review and address it.

11. This website and policy changes

This policy describes the app and its support. Visiting this website also sends ordinary connection information to the website host; website hosting logs are separate from the app’s local financial records. Contact us with questions about this website.

We will update this policy and its date when the app’s data practices change, and provide additional notice or choices when required. New features such as bank connections, cloud synchronization or statement extraction would require a revised description before being introduced.

Questions about WealthOS? sm.labs@rediffmail.com