Privacy Policy
Cadora is a subscription and bill tracker. You type in what you pay for; Cadora reminds you before renewals and shows you what it adds up to. It has no account, no sign-up, and it never asks for a bank login.
This policy describes exactly what happens to what you type. Where something does leave your device, it says so plainly rather than hiding behind "we may share data with partners".
Who is responsible for this
Cadora is published by Do Huynh Tuan Khai, an individual developer based in Vietnam, and the data controller for the little that leaves your device. The way to reach us — for a question, or for any request below — is support@aquifer.fyi, which is monitored.
There is no data protection officer, because the processing here does not require one: no profiling, no special-category data, no large-scale monitoring.
The short version
- There is no Cadora server. We operate no backend, no user database, and no login. We cannot see your data, because there is nowhere for it to arrive.
- Your entries sync through your own iCloud, not through us. That is Apple's private CloudKit database tied to your Apple Account. It leaves your device, but only to your other devices.
- Ads are the one third party that collects anything. Cadora shows banner ads to free users via Google AdMob. Premium users see no ads and are never asked to consent to any.
- One optional network request, off unless you switch it on, asks a public server what a euro is worth. It contains nothing about you.
- We sell nothing, and nothing we measure is tied to who you are. Firebase reports crashes and how the app performs — only if you agree to the privacy form — with no name, no account, and nothing you typed.
What Cadora stores, and where
Everything you enter is written to a database on your device: the items you track (name, provider, amount, currency, billing cycle, renewal date, trial end, category, notes), your reminder rules, price history, usage check-ins, cost-split details, and any people you record as paying for something.
Two things are stored separately:
- Your app-lock passcode is never stored. Only a salted, PBKDF2-stretched hash of it (PBKDF2-HMAC-SHA256) goes into the iOS Keychain, marked so it never syncs and never leaves the device. Face ID and Touch ID are handled entirely by iOS; Cadora only receives a yes or no.
- A small widget summary — your monthly total and the next few renewals — is written to a shared app container so the home-screen widgets can read it. It stays on the device.
Device preferences (chosen language, digest schedule, lock settings, exchange-rate cache) live in standard iOS preference storage on the device.
iCloud sync
If you are signed in to iCloud, Cadora syncs your entries across your devices using Apple's CloudKit private database for your Apple Account. This is on whenever iCloud is available. It is a genuine exception to "nothing leaves your device", so to be exact about it:
- What syncs: tracked items, categories, reminder rules, price history, cost-split records, people you recorded as payers, and usage check-ins.
- What never syncs: your app settings, your purchase state, and your passcode hash.
- Who can read it: you. It is your private iCloud database, governed by Apple's privacy policy. We have no access to it and no credentials for it.
- How to switch it off: turn Cadora off under Settings → [your name] → iCloud on your device, or sign out of iCloud. Cadora then keeps working entirely locally.
Other people's details
If you record who pays for something — a parent, a partner, an employer — you may enter their name, relationship, photo, phone number and email. Cadora never reads your Contacts; this is only what you choose to type.
That information is yours to handle responsibly. It is stored like your own entries and, like them, syncs to your private iCloud. It is never transmitted to us or to any advertiser. Delete the person in Cadora and the record goes with them.
Advertising
Free users see a banner ad on some screens, served by Google AdMob. Google is an independent controller of what it collects; see Google's privacy policy and how Google uses data from partner apps.
- Cadora sends Google nothing about what you track. No item names, no amounts, no categories, no notes. The ad request carries no information you typed into the app.
- Personalised ads require two separate yeses: consent in the in-app privacy form (Google's User Messaging Platform, shown where GDPR, the UK GDPR or a US state law requires it) and permission in the iOS "Allow Tracking" prompt. If either is missing, every ad request is marked non-personalised.
- Premium users see no ads and are asked nothing — neither the consent form nor the tracking prompt appears, because nothing about them is ever used to target an ad.
- You can change your choice later: the in-app privacy options in Settings reopen Google's consent form, and iOS tracking permission is under Settings → Privacy & Security → Tracking.
Exchange rates
If you turn on live exchange rates, Cadora fetches a public rates table from
open.er-api.com, at most once a day. The request asks what one US
dollar is worth and carries no identifier, no cookie, and nothing about you or your
items. It is off until you turn it on, and if it fails, Cadora
silently falls back to rates bundled in the app.
Advice and AI
Cadora's suggestions about what to keep, pause, downgrade or cancel are produced on your device by a fixed set of rules over your own entries. There is no cloud model and no inference server.
On devices with Apple Intelligence, Cadora may use Apple's on-device language model to reword an already-decided suggestion into a more natural sentence. It receives the item's name and the reason for the advice — never an amount — and the processing happens on the device. No prompt or entry is sent to us or to any third party.
Crash reports and performance
Cadora uses Google Firebase to measure two things: whether the app crashes (Crashlytics), and whether it performs — whether a screen is reached, whether a step completes, whether something is quietly failing (Google Analytics for Firebase). Both are off until you say yes in the privacy form, and both stay off if you decline or never answer.
What it is for. Finding the parts of the app that are broken or slow, on the devices and iOS versions people actually use. Nothing here is used to build a picture of you, to target ads, or to sell anything to anyone.
Nothing measured is tied to your real identity. Cadora has no account and asks for no name, no email and no sign-in, so there is nothing for a measurement to be attached to. We never connect what Firebase reports to a person, and we could not: we hold no identity to connect it to.
- What is sent: the name of a step (
itemAdded,paywallViewed,appOpenedand similar) with coarse properties such askind = subscription; and, if the app crashes, the stack trace, device model, OS version and app version. - What is never sent: anything you typed. No item names, amounts, currencies, notes, categories, dates, or people. There is no field in an event that can carry them.
- The one identifier involved is a random app-instance number Firebase generates, so that two crashes from the same install can be told apart from two crashes on two devices. It is not your name, your email, or your Apple Account. It is reset if you decline, and again if you delete and reinstall the app.
- If you decline, or are Premium: measurement never starts, and anything gathered before a refusal is erased. Premium users are never shown the form at all, so nothing about them is ever measured.
- Change your mind in Settings → privacy options, which reopens the form. Turning consent off stops collection immediately.
Steps are also written to the device's own log and a short in-memory buffer used for debugging. That part never leaves the device regardless of your answer.
Google acts as an independent controller of what it receives; see Google's privacy policy and how Google uses data from partner apps.
Purchases
Cadora Premium is sold through Apple's In-App Purchase. Payment happens entirely with Apple — we never see your card, your name, or your billing address. Cadora asks Apple only whether an active entitlement exists, and that answer is not stored in your synced data.
Why we are allowed to do this
Under the GDPR and the UK GDPR, every use of your data needs a basis. Cadora's are short, because almost nothing leaves your device:
- What you type, stored on your device and synced through your own iCloud — we are not processing it at all. There is no server of ours, no copy we hold, and no access we could grant. Apple processes your iCloud data under its own agreement with you.
- Ads (Google AdMob) — consent, Article 6(1)(a), collected through Google's privacy form where it is required, plus iOS tracking permission. Withdraw either and the request goes out non-personalised.
- Crash reports and performance (Firebase) — consent, Article 6(1)(a). Collection does not start until you agree and stops when you withdraw. We deliberately did not claim legitimate interest for crash reporting, which some apps do: it would let us collect from people who said no, and it is not worth the asterisk.
- An email you send us — consent, by pressing send. Used only to answer you.
- Exchange rates — no basis needed. The request contains nothing about you.
How long anything is kept
- On your device and in your iCloud: until you delete it. Deleting an item, or the app, removes it locally; the synced copy goes when you delete Cadora's iCloud data.
- Crash reports: Firebase Crashlytics retains them for 90 days.
- Analytics events: Firebase keeps user-level data for 2 months, the shortest retention Google offers. Aggregate reports may be kept longer by Google in a form that is not about any one install.
- Advertising data: held by Google under its own retention policy, not ours.
- Support email: kept as long as needed to resolve your question, then deleted.
Where your data goes
Nothing we operate is outside your device — but two third parties are not:
- Google (AdMob, Firebase) processes data in the United States and other countries. Google states that it relies on the EU–US Data Privacy Framework and Standard Contractual Clauses for these transfers; the current terms are in Google's privacy policy.
- Apple processes your iCloud data under Apple's privacy policy, in the regions Apple operates.
If you are in the EU, the UK or Switzerland and you decline the privacy form, no transfer to Google happens for analytics or crash reporting at all.
Permissions Cadora asks for
Every one of these is optional, requested only when you use the feature it belongs to, and declinable without losing the rest of the app.
| Permission | Why | If you decline |
|---|---|---|
| Calendar | To write your renewal dates into your own calendar | Renewals stay inside Cadora |
| Notifications | To remind you locally before a charge — scheduled on the device, no server | No reminders |
| Photos | To use one of your photos as an item's icon | Use a symbol or monogram instead |
| Face ID / Touch ID | To unlock the app | Use a passcode, or no lock at all |
| Tracking | Only to allow personalised ads | You still see ads, non-personalised |
Data you send us deliberately
If you use Contact or Report a Bug, Cadora opens a draft email to support@aquifer.fyi with your message and a short diagnostic footer: app version, build, iOS version and device model. Nothing is sent until you press send, and you can delete any part of the draft first. We use what you send only to answer you.
Export (CSV or PDF) and sharing put a file wherever you choose to send it. From that point it is governed by whatever service you sent it to, not by Cadora.
Children
Cadora is not directed at children and collects nothing from anyone knowingly. It has no account system, so there is no profile to create.
Your rights
Because Cadora holds no data about you on any server of ours, requests to access, correct, export or delete are things you can do yourself and immediately:
- Access and export: everything you entered is in the app; Settings → Export writes it to a CSV or PDF.
- Delete: delete an item, or delete the app. Deleting the app removes the local database; to remove the synced copy, delete Cadora's data under Settings → [your name] → iCloud → Manage Storage.
- Advertising choices: withdraw ad consent or tracking permission as described above, or buy Premium, which removes ads entirely.
The formal list
The rights the GDPR and the UK GDPR give you are access, rectification, erasure, restriction of processing, objection, and portability, plus the right to withdraw consent at any time. For Cadora they resolve unusually simply:
- Anything you typed — you already hold it and can read, correct, export or delete it in the app, without asking us and without waiting. That is not a workaround for these rights; it is those rights, exercised directly.
- Anything Google holds — because Cadora has no account, we cannot identify you inside Google's data and so cannot action a request there on your behalf. Withdraw consent in the app to stop it, and contact Google for what it already has.
- Withdrawing consent — the in-app privacy options, and iOS tracking permission under Settings → Privacy & Security → Tracking.
Cadora makes no automated decision that has a legal effect on you. Its suggestions are prompts to think, produced on your device, and nothing acts on them but you.
If you think we have got this wrong, you can complain to your data protection authority. In the EU that is the supervisory authority where you live or work — the list is at edpb.europa.eu — and in the UK it is the ICO. We would rather you told us first, at support@aquifer.fyi, but you do not have to.
Changes
If this policy changes, the date at the top changes with it, and material changes will be described in the app's release notes.