1. General provisions and scope
This Privacy Policy describes how data is handled in the Voice Finance mobile app for iOS and on the official website voicefinance.app.
It applies to: the Voice Finance app; the official website; and correspondence with support at support@voicefinance.app.
It does not apply to Apple's services (App Store, iCloud, Apple Speech, StoreKit), which Apple provides to you directly under its own terms and privacy policy, nor to third-party websites and services that may be linked from the app or the website.
By using the app or the website you confirm that you have read this Policy.
2. Who the developer is and how to contact us
The owner and developer of Voice Finance is Individual Entrepreneur Kirill Mikhailovich Paramonov (the “Developer”).
Address: 3 Prospekt Mira, Apt. 44, Krasnoznamensk, Moscow Oblast, 143090, Russian Federation. INN (Taxpayer Identification Number): 500604796798. OGRNIP (Primary State Registration Number of the Individual Entrepreneur): 322508100269063.
For any question about this Policy, contact support@voicefinance.app. Full registration details are in section 24.
3. What the app does not collect or send to the Developer
The app is designed so that the Developer never receives your financial data. Specifically:
- the app creates no Voice Finance account: there is no sign-up, login, password or profile;
- the Developer operates no server or database to which your transactions could be sent;
- the app uses no pixels, trackers or cross-site tracking tools and does not track you across apps or websites;
- the free version shows rewarded ads and collects pseudonymized product analytics — both are described in sections 15 and 16, and neither receives your financial records;
- the app does not collect contacts, photos, location or browsing history, does not ask for tracking permission and does not use the device advertising identifier (IDFA);
- the Developer has no access to your card number or other payment credentials — these are handled solely by Apple.
Saying “no data is ever processed” would be inaccurate: if you voluntarily write to support, the Developer receives your email address and the contents of your message. That case is described in section 11.
4. Your financial records
As you use the app you create financial records: transactions (income and expenses), amounts, currencies, dates, transaction titles and merchants, categories, budgets and limits, and derived figures — analytics, category statistics, forecasts and the “Available to spend today” guide.
All of this is created and stored on your device and, if you use iCloud, synced through your personal iCloud storage (section 6). The Developer neither receives nor can access these records. Analytics and forecasts are computed locally on the device.
The app also stores local categorization rules derived from your own category corrections. Such rules hold normalized keys (for example an item or merchant name) and the category you chose; they contain no amounts and no original phrases.
“Available to spend today” is calculated locally from your own data and is an informational guide, not financial advice.
5. Local storage
Financial records and learned rules are stored in the app's local database on your device (SwiftData). App settings — language, appearance, base currency, haptics, onboarding completion — and a cache of market exchange rates are stored in the device's local storage.
Only the app itself can access this data, within the sandbox that iOS provides.
The original phrase you spoke or typed is not stored in the database. It exists only in a temporary draft until the transaction is saved. Any values left over from earlier versions of the app are cleared at launch.
6. iCloud and CloudKit
Purpose. Sync makes your transactions available across your devices and restores them when you reinstall the app or change device.
How it works. The app uses the CloudKit mechanism built into SwiftData and stores data in the private database of your personal iCloud account (private CloudKit). Sync works if you are signed in to iCloud and have not turned iCloud off for Voice Finance in system settings.
Apple's role. Apple acts as the storage and sync infrastructure provider and processes this data under its own terms and privacy policy.
Developer access. The private iCloud database belongs to your Apple account. The Developer cannot access its contents, cannot view, export or restore your records, and receives no information about them.
Your control. You manage sync through the system: you can turn iCloud off for Voice Finance, change iCloud settings, or delete the app's data from iCloud. The app also offers full deletion of all financial data and learned rules, which covers the records in your iCloud.
Deletion and restoration. The Developer cannot restore deleted data, holding no copy of it. Restoration is possible only through Apple and only to the extent Apple provides.
7. Voice input
Microphone access. The microphone is used solely to add transactions by voice. Recording happens only while you hold the microphone button. Microphone and speech-recognition permissions are requested separately and can be revoked in system settings; manual entry remains available.
How audio is processed. Speech-to-text is performed by Apple's system component Apple Speech (SFSpeechRecognizer). When your device and the selected language support on-device recognition, the app explicitly requests the offline mode. Where such support is unavailable, audio may be sent to Apple's infrastructure for processing under Apple's terms.
Audio storage. The app does not save audio as files and does not transmit it to the Developer. The current session's audio buffers are held in memory only — solely to allow one retry of recognition in the alternate language — and are cleared as soon as the transaction is recognized, the retry completes, or the session is cancelled.
Purpose limitation. Your speech and the recognized text are not used for advertising, profiling, building ad segments, or training the Developer's models.
8. Parser and processing of recognized text
Recognized or manually entered text is processed by the app's local parser, which determines the transaction type, amount, currency, date, title and category. Parsing runs on the device and requires no network transmission of the text.
The result is shown to you for review before saving. The original phrase is not written to the database (section 5).
9. StoreKit and Premium
What Apple handles. Purchase, payment, renewal, cancellation and refunds of the subscription are handled by Apple through your Apple account. Apple processes payment credentials, purchase history and related information under its own terms and privacy policy.
What the app receives. The app uses StoreKit 2 and reads the current entitlement information from the system: the identifier of the purchased product and whether the purchase has been revoked. Premium features are enabled or disabled on that basis. This information does not leave the device.
What the Developer does not receive. The Developer has no access to your card number, banking details, billing address or other payment data, and receives no per-user purchase information from the app.
The aggregated sales statistics that the App Store makes available to developers in its own interface are produced by Apple and do not identify you.
10. Diagnostic data and crash reports
The app contains no third-party crash-reporting or error-monitoring services.
The app writes technical entries to the device's system log (os.log). These contain only service events and error codes; amounts, transaction titles, categories, recognized phrases and record identifiers never appear in the log.
If you have enabled sharing of diagnostics and usage data in iOS settings, Apple may provide the Developer with aggregated crash and performance reports. That exchange is controlled by you through system settings and is carried out by Apple.
11. Support requests
Support is provided by email at support@voicefinance.app. When you contact support, the Developer receives the email address you write from, the contents of your message, and any materials you attach.
When you write from within the app, the message is pre-filled with technical information: the app version and build number, the iOS version, the device model and the selected interface language. This helps reproduce the problem. You see the message before sending and may edit or remove any part of it.
This information is used solely to answer your request and resolve the problem described. It is not used for advertising or mailings and is not shared with third parties, except the email service provider that delivers and stores the correspondence.
Please do not send financial amounts, transaction titles or lists, database exports, payment credentials, passport data or other identity documents to support. They are not needed to resolve technical issues.
11.1. Suggest an idea
The app's Settings include "Suggest an Idea". It is a channel separate from support: you write what is missing or what could work better, and attach images if you want to.
What you send goes to a serverless function on the official website, which relays the message to a private Telegram chat available only to the Developer. Neither the text nor the images are stored on the server — not in a database, not in file storage, not in logs. Only the number of attachments and an error code ever reach the console.
Five technical fields travel with the text — the app version and build number, the language selected in the app, the device model and the iOS version. The same set has accompanied support emails for years, and it is the complete set: nothing else is added.
Images are attached by you and only by hand. The app never reaches into your photo library on its own, never picks a shot for you and attaches nothing by default. Any attachment can be removed before sending. Before it is sent, an image is downscaled and re-encoded to JPEG on your device, which also drops the picture's metadata — including the capture coordinates, if the camera wrote any.
No identifier is created for this feature: no advertising ID, no hidden one, no persistent one. A submission cannot be linked to your financial records, because those never leave the device (section 4).
To limit how often submissions may be sent, the server keeps counters only: an irreversible hash of the IP address and the timestamps of recent submissions, plus a technical request identifier so that retrying after a dropped connection cannot create a second message. The IP address itself is never stored in the clear and never passed to Telegram. The rate records live no longer than a day, the request identifier for 30 minutes. These counters contain no text, no images, no device model and no app version.
Sending is entirely voluntary and happens only when you tap the button. If you do not include contact details, a reply is impossible — the Developer does not work out who sent it. When you need an answer, write to support (section 11).
What reaches Telegram is processed under that service's own terms — see the Telegram Privacy Policy.
Do not put amounts, transaction names, statements or anything you would rather not hand to a third party into a suggestion: the message travels through Telegram.
12. The official website and web analytics
The voicefinance.app website is static and is hosted by Netlify.
As with any request to a website on the internet, the hosting provider's infrastructure technically processes network requests: IP address, date and time of the request, the requested page address, and browser and operating-system type. This processing is necessary to deliver pages and maintain security, and is carried out by Netlify as the infrastructure provider.
The website runs two independent web-analytics services: Cloudflare Web Analytics and Yandex Metrica. They are unconnected and are described separately below.
Cloudflare Web Analytics
A privacy-focused web-analytics service. It is used only to obtain aggregated statistics on page visits and page performance, including Core Web Vitals. This helps us understand which pages are opened and how quickly they load.
Cloudflare Web Analytics is not used by the Developer for advertising, profiling, session replay, building advertising segments or tracking visitors across sites, and is not used to identify individual visitors. According to Cloudflare's documentation, the service uses no cookies and applies no fingerprinting. Only aggregate reports are available to the Developer, and an individual cannot be identified from them. As with any request to a website, the Cloudflare and hosting infrastructure does technically process the request itself — including the IP address, the time of the request, the page address and browser details; the terms of that processing are set by those providers' own documents. Cloudflare acts here as an infrastructure provider and processes data under its own terms — see the Cloudflare Privacy Policy.
Yandex Metrica
The website carries Yandex Metrica tag no. 111135249. The tag loads asynchronously and does not block page loading.
The tag collects technical, de-identified information about the visit:
- which pages were opened, in what order, and how you moved between them;
- the traffic source: the address of the page you arrived from (the referrer), or a marker for a direct entry;
- clicks on page elements and on links, including departures to external sites;
- scroll depth — 25, 50, 75, 90 and 100 per cent — and time spent on the page;
- the fact that the App Store block came into view, on its own, without being tapped;
- the selected site language (Russian or English) and the selected theme (light, dark or system);
- browser and operating-system type and version, device type, screen resolution;
- technical browser identifiers that Yandex Metrica stores in cookies — see subsection 12.1;
- on article pages, a stable technical identifier of the article, its category and its language.
In event parameters the website sends only technical values it generated itself: the page type, the language, the article identifier and category, and the name of the element that was clicked. For external links only the domain name is sent, never the full address.
Event parameters never contain: page addresses with query strings, e-mail addresses, search queries, the contents of input fields or forms, article text, or any user identifiers.
The ecommerce feature is not enabled in the tag: the website sells nothing.
Session Replay and maps
Session Replay (Webvisor), the click map and the scroll map are enabled in the tag. They are used to analyse visitor behaviour on the website: to understand how articles are read, where people stop, and what they fail to find.
Session Replay may produce a de-identified recording of interaction with the page — cursor movement, scrolling, clicks and window resizing.
That said:
- the website contains no forms, no input fields and no registration — there is simply no text for you to type on it;
- should such elements be added later, the website automatically marks every input, textarea, select, form and e-mail link with the Yandex Metrica service classes
ym-disable-keysandym-hide-content, which forbid recording their contents; - your financial records, amounts, transaction titles and voice input are never sent to the website and cannot be: the app and the website are not technically connected;
- no passwords are ever requested, because the website has no accounts.
Calling Yandex Metrica fully anonymous would be inaccurate. The service stores a pseudonymous browser identifier in cookies and processes the IP address on its own side. Your name is not available to the Developer, but this information cannot be called fully anonymous either — which is why this Policy speaks of de-identified web analytics rather than anonymous analytics.
The Developer has access to aggregate reports, Session Replay recordings and the maps for website visits. The Developer does not use Yandex Metrica to show advertising on the website, to build advertising segments, or to track visitors across sites.
The service is operated by Yandex LLC, which processes data on its own side under its own documents. The service names three governing documents:
- Terms of Use of Yandex Metrica and AppMetrica;
- User Agreement for Yandex Services;
- Yandex Privacy Policy.
Why this is needed
Information about website visits is processed in order to:
- keep attendance statistics: how many pages are opened and which sections are in demand;
- improve the structure and the performance of the website;
- understand the demand for individual articles and for the features described;
- find errors and places where visitors fail to find what they need.
Article view and like counters
Articles have a view counter and a like button. When an article is opened and when a like is pressed, the browser calls a serverless function of this website and sends only the technical identifier of the article. No IP address, no browser details and no visitor identifier are stored: the website keeps just two numbers per article — the view count and the like count.
12.1. Cookies and local storage
The website previously set no cookies. With Yandex Metrica in place that has changed: the service uses cookies and similar technologies, including the browser's local storage (localStorage).
The cookies relevant to this implementation are listed below, with the purpose and lifetime given by the official Yandex Metrica documentation:
_ym_uid— 1 year; identifying site users;_ym_d— 1 year; the date of the user's first session;_ym_fa— 1 year; a service cookie that, together with_ym_uid, identifies site users;_ym_isad— 20 hours; determining whether a visitor has an ad blocker;_ym_metrika_enabled— 60 minutes; checking that the other cookies are installed correctly;_ym_visorc_*— 30 minutes; allowing Session Replay to function;_ym_hostIndex— 1 day; limiting the number of requests;gdpr,is_gdpr,is_gdpr_b— up to 2 years; identifying visitors who fall under the GDPR.
Besides cookies, Yandex Metrica stores service values in the browser's localStorage — in particular _ym_uid and _ym_retryReqs, plus values whose names contain the tag number: _ym[tag number]_lastHit, _ym[tag number]_lsid, _ym[tag number]_reqNum.
The full, current list is published by the service: temporary files installed by Yandex Metrica. The actual set may differ depending on the browser, its settings and the service's settings, which is why only files confirmed by that documentation are listed here.
The website itself additionally stores three technical values in your browser's localStorage. They are never sent anywhere and stay on your device: vf-theme — the selected theme; vf-liked-articles — the articles you have liked, so a like is not counted twice; vf-viewed-articles — the articles whose view has already been counted.
The website uses no advertising pixels, no advertising trackers, no cross-site tracking tools and no personal-data collection forms. Fonts and other resources are served from the site itself, without external CDNs.
How to opt out
No cookie consent banner is implemented on the website. You can opt out using your browser and the service itself:
- block or delete cookies in your browser settings — for all sites, or only for voicefinance.app. Once the cookies are deleted, Yandex Metrica will no longer recognise your browser as the same one;
- use the service's official opt-out — the Yandex Metrica opt-out page. The opt-out holds for as long as the value it sets remains in your browser;
- use a browser or an extension that blocks analytics tags;
- clear the site's localStorage in your browser — this removes both the Yandex Metrica service values and the site's own three values listed above.
The Developer cannot promise the automatic deletion of statistics already collected. Information about visits that have already happened sits with Yandex LLC and is retained and deleted under that service's own rules; no deletion mechanism exists on the website's side. Opting out and clearing cookies stop further collection but do not delete what was collected earlier. A deletion request may be sent to the Developer at support@voicefinance.app and will be passed on within the limits the service allows.
13. Third-party services
The following third-party providers are actually used:
- Apple — app distribution (App Store), sync (iCloud/CloudKit), speech recognition (Apple Speech), subscriptions and payments (StoreKit), system diagnostics;
- Netlify — hosting of the official website and of the server function through which the AI Summary runs (see section 14);
- OpenAI — processing of an aggregated financial summary by a language model, only when the AI Summary feature is used and only after your consent (see section 14);
- Cloudflare — delivery and protection of the official website, and Cloudflare Web Analytics (aggregated visit and performance statistics, see section 12);
- exchange-rate providers — api.frankfurter.dev (European Central Bank data) and www.cbr-xml-daily.ru (Bank of Russia data). Only currency codes are sent; amounts, transaction titles and user identifiers are not. As with any network request, the service operator can technically see the device's IP address;
- Yandex — three separate services that should not be conflated: rewarded advertising in the free version of the app through the Yandex Advertising Network (section 15); pseudonymized product analytics for the app through AppMetrica (section 16); de-identified web analytics for the official website through Yandex Metrica, including Session Replay and the maps (section 12). AppMetrica runs only in the app and Yandex Metrica only on the website; they are unconnected and exchange no data;
- an email service provider — delivery and storage of support correspondence.
Apart from the services listed above, no other third-party advertising or analytics SDKs are embedded in the app. No advertising mediation and no other advertising networks are integrated.
14. AI Summary
When generating an AI summary, the app sends the user-selected aggregated financial metrics to the external AI service OpenAI. This transfer takes place only after the user gives separate consent and is used solely to generate the response. Raw audio recordings, banking details, and account data are not sent.
The feature is available only to users with an active Premium subscription. Consent is requested immediately before an AI summary is generated — not at installation and not on first launch.
Premium only, and only on request. The feature requires an active Premium subscription. It does not run when the app opens, does not run in the background and never runs automatically: an analysis starts only after you tap “Create AI analysis”.
Separate consent. Before the first send, the app shows a consent screen listing what is and is not transmitted. The consent checkbox is not pre-ticked, and the confirm button stays disabled until you tick it. Without confirmation no request is built and nothing is sent.
What is sent. Only an aggregated financial summary for the selected period:
- income and expense totals for the period, and the net result;
- per-category sums, shares and operation counts, where a category is an identifier from the app's fixed list — never text you typed;
- total operation count, average daily spending and savings rate;
- the currency code (for example, RUB) and the period identifier;
- a series of daily expense totals showing the shape of spending, with no dates attached;
- the Apple-signed subscription receipt, used to check eligibility; it carries transaction facts only.
What is not sent. The following are never transmitted: audio recordings and recognized phrases, individual operations, merchant names, operation titles and notes, names, addresses, location, banking or payment details, and persistent user or device identifiers, including the advertising identifier. Budget figures are not transmitted.
The set of transmitted fields is constrained by the request structure in the app and checked again on the server against a closed list: a request carrying any field not named above is rejected in full and never reaches the model provider.
Who processes it. The summary is sent to OpenAI and processed by a language model. The app never contacts OpenAI directly: the request passes through a Voice Finance server function hosted on Netlify. The OpenAI access key exists only in that function's protected environment and is not present in the app. Financial figures and the model's text are not written to server logs.
Basis, and processing on OpenAI's side. The legal basis for the transfer is your consent, given on the screen shown before a summary is generated. How and for how long OpenAI processes the data is governed by OpenAI's own terms, not by this Policy; the Developer does not control this and makes no representations about it.
Withdrawing consent. You can withdraw consent at any time in Settings → AI usage. Once withdrawn, the app stops sending data and the feature becomes unavailable. All other analytics are computed on device and keep working unchanged. Withdrawal does not affect the lawfulness of processing carried out beforehand. Re-enabling shows the explanation and asks for confirmation again.
What the app stores. Only the fact of consent, the date it was given and the date of the last analysis are kept locally. Neither the summary sent nor the text received is stored on the Developer's servers.
The result is produced by a language model, is informational only, and is not financial, tax, legal or investment advice. It may contain errors and must not be the sole basis for a decision. The AI does not change your operations, categories or budgets, and performs no financial actions.
15. Advertising
The free version shows rewarded ads: a short video that, once watched in full, unlocks the next batch of transaction recognitions. Ads are supplied by the Yandex Advertising Network through the Yandex Mobile Ads SDK.
When it appears. Only in response to something you do: when the free recognition allowance is spent and you try to recognize another transaction, or when you tap «Watch an ad» on the Analytics screen yourself. No ad plays at launch, none runs in the background, and none interrupts your work. Subscribers with an active Premium subscription see no ads at all.
Advertising is not personalized. The app does not ask for tracking permission, does not use the device advertising identifier (IDFA) and takes no part in tracking across apps or websites. The advertising SDK is told that consent to process personal data for advertising has not been given, and location collection is switched off. Ads are selected without a profile of you.
What Yandex processes to serve ads and guard against fraud. The advertising SDK processes, on the Yandex Advertising Network's side, technical details of the device and the request: device model, operating-system version, language, connection type, the IP address and the approximate region derived from it, the ad-unit identifier, service identifiers for the impression and details of the impression itself. What that processing covers is set by Yandex's own documents. Your financial records, recognized phrases, amounts, currencies, categories, transaction titles and AI Summary text are not available to the advertising network — the app does not send them.
Apple attribution. The app supports SKAdNetwork, Apple's mechanism for reporting an app install to an advertising network in aggregate form, without identifying the user or the device. No third-party advertising networks and no mediation partners are integrated.
How to opt out. A Premium subscription removes advertising entirely. You can also close any ad at any point — no reward is granted in that case, and nothing else follows from it.
Processing by the advertising network happens on its side and is governed by Yandex's own documents. The app receives no information about you from the advertising network and never links ad impressions to your financial records.
16. Product analytics
To understand which features are used and where errors occur, the app sends product events to AppMetrica. The analytics describe what happened in the app, never what it was about. The data is pseudonymized: it carries no name, no email address and no other direct identifier, but AppMetrica assigns the app installation a technical identifier of its own so that one installation can be told from another.
Which events are sent. A closed list of 53 events:
- app: the app opening; onboarding finishing;
- recognition: a voice recognition starting; being cancelled; failing; finding no speech; the free allowance running out;
- transactions: a transaction created by voice; created manually; an edit starting; an edit saved; an edit cancelled; a transaction deleted;
- AI Summary: a summary requested; consent confirmed; a summary created; a summary failing;
- Premium: a purchase starting; a purchase completing; purchases restored;
- ads for recognitions: an ad requested; shown; watched in full; closed without a reward; failing;
- ads for advanced analytics: an ad requested; shown; watched in full; closed without a reward; failing;
- screens and settings: the Home, History, Analytics, Premium and Settings screens opening; the theme being changed; the interface language being changed;
- navigation inside the app: tapping «Available today», «Income» and «Expenses» on the Home screen; opening the currency picker; opening and running a search in History; opening the History filters and applying a filter; opening the Categories, Spending rhythm, Insights and Forecast sections and their detail cards in Analytics; choosing a plan and starting a restore in Premium.
The two advertising flows have event names of their own, so it is visible which of them an ad was shown for — and no event carries a free-form text parameter.
Which parameters accompany an event. Technical ones only: app version, build number, interface language and device model (for example, iPhone14,3). An event carries nothing else.
What the app never sends. Never sent: the text of a spoken or typed phrase, transaction amounts, currencies, categories, product or merchant names, notes, AI Summary content, your Apple Account identifier or your email address. The app creates no user profile, never requests or transmits the advertising identifier (IDFA), and collects no location.
What AppMetrica may nevertheless process. Like any analytics service, AppMetrica processes technical details of the request and the installation on its side: its own installation identifier, device characteristics and operating-system version, session details, the time of the event and the IP address the request came from. What that processing covers is set by AppMetrica's own documents. Your financial records, amounts, categories, transaction text and AI Summary content are not sent to that service under any setting.
What the Developer receives. Only aggregate reports in the AppMetrica interface: how often an action happened, in which app versions and on which device models. The Developer does not export that data or connect it to an individual, and has no access to your financial records — those never leave your device and your iCloud.
An event records that something happened and nothing about what it concerned: «a recognition succeeded», with no amount, no category and no transaction text.
How to opt out. Opting out is done inside the app: About → Privacy and analytics → Product analytics. Once it is off the app stops sending product events; the choice is saved and stays in force until you switch it back on. You can turn it on and off at any time, with no need to reinstall the app. This is the primary and only way to switch the app's product analytics off: the iOS system settings limit advertising tracking and some system diagnostics, but they do not control whether the app sends product events.
17. Purposes and grounds for processing
The Developer processes a limited amount of information, and only in the following cases:
- support requests — purpose: reviewing the request, replying and resolving the problem; ground: your own request and the performance of obligations connected with providing the app;
- technical operation of the website — purpose: delivering pages and maintaining security; ground: the legitimate interest in keeping the website operational;
- advertising in the free version — purpose: offering the app free of charge and granting the reward for a watched ad; ground: the legitimate interest in funding the free version. The processing is carried out by the Yandex Advertising Network on its side and under its own documents; the Developer receives no advertising data about you;
- de-identified website analytics — purpose: attendance statistics, improving the structure and performance of the website, understanding the demand for articles and for the features described, and finding errors; ground: a stated legitimate interest in developing the website. The processing on their side is carried out by Cloudflare and Yandex LLC under their own documents; opting out is described in section 12.1;
- pseudonymized product analytics — purpose: understanding which features are used and where errors occur; ground: a stated legitimate interest in improving the app. You can switch product events off inside the app at any time — About → Privacy and analytics → Product analytics. The processing on its side is carried out by AppMetrica under its own documents; the Developer receives only aggregate reports of how often actions happen.
Financial records inside the app are not processed by the Developer, who never receives them.
18. Retention and deletion
- Data in the app is kept on your device until you delete it or delete the app. Deleting the app removes the local database from the device.
- Data in iCloud is kept in your iCloud account until you delete it through the app or the system. Deleting the app alone may not remove the iCloud copy — use the app's delete-all-data function or iCloud settings.
- Support correspondence is kept for as long as needed to handle the request and confirm its outcome, and is deleted when no longer needed, unless the law requires otherwise.
- Technical website infrastructure records are kept by the hosting provider for a limited period under its own rules.
- Data held by external providers — the Yandex Advertising Network, AppMetrica, OpenAI, the hosting provider and the email service provider — is kept by those providers, and its retention periods are set by their own policies and documentation, not by this Policy. The Developer does not control that data and cannot delete it on a provider's behalf.
- Product analytics. Switching «Product analytics» off stops the app from sending new events — from that moment the app no longer produces them. Events AppMetrica has already received remain on its side and are kept and deleted under AppMetrica's rules. The Developer cannot guarantee that this historical data is deleted immediately, because an external provider controls it; the terms of that processing are described in the Terms of Use of Yandex Metrica and AppMetrica.
19. Security
The app is built to minimize risk: financial data never leaves your device and your iCloud, there are no accounts and no server-side database, and the amount of information the Developer processes is kept to a minimum. Data is protected by the iOS app-isolation mechanisms and, when iCloud is used, by Apple's protections.
That said, no app, device or method of transmission can guarantee absolute security. The Developer cannot guarantee protection against every possible incident, including those arising from loss of control over your device or Apple account, and recommends using a passcode, Face ID/Touch ID and Apple's two-factor authentication.
20. Your rights and how to exercise them
Most rights you exercise directly, without contacting the Developer: at any time you can view, edit or delete your records, delete all app data, reset the learned categorization rules, turn off iCloud sync, revoke microphone and speech-recognition permissions, and delete the app.
For the information the Developer actually processes (support correspondence), you may request access to it, its correction or its deletion. Write to support@voicefinance.app.
The Developer cannot provide access to your financial records or restore them, having no access to them.
You also have the right to contact the competent data-protection authority in your jurisdiction.
21. Children and minors
Voice Finance is intended for personal expense tracking and is not directed specifically at children. The app does not ask for your age and does not collect information that would establish it.
The app's age rating and parental-control options are provided through the App Store and Apple's Screen Time settings. If you are a parent or legal guardian and believe a child has sent personal data to the Developer through support, write to support@voicefinance.app and that information will be deleted.
22. International infrastructure and applicable law
The Developer is registered in the Russian Federation. Apple's services, the website hosting, Cloudflare, the Yandex Advertising Network, AppMetrica and Yandex Metrica, OpenAI (when the AI Summary is used), the exchange-rate providers and the email service provider use their own infrastructure, which may be located in various countries; any transfer of data by those providers is carried out under their own terms and rules.
This Policy does not limit the rights granted to you by the mandatory provisions of the law of your country of residence.
23. Changes to this Policy
This Policy may be updated when the app's functionality or the set of services used changes. The current version is always published on this page together with its effective date.
Material changes that expand the data processed take effect no earlier than their publication; such changes will be announced in the app or on the website.
24. Contact and registration details
- Owner and developer: Individual Entrepreneur Kirill Mikhailovich Paramonov
- Address: 3 Prospekt Mira, Apt. 44, Krasnoznamensk, Moscow Oblast, 143090, Russian Federation
- INN (Taxpayer Identification Number): 500604796798
- OGRNIP (Primary State Registration Number of the Individual Entrepreneur): 322508100269063
- Date of state registration: May 25, 2022
- Registration authority: Interdistrict Inspectorate of the Federal Tax Service No. 23 for the Moscow Region
- Contact: support@voicefinance.app
25. Effective date
This version of the Privacy Policy takes effect on July 30, 2026.