Privacy policy
The short version. Reshta stores the money records you choose to enter, so that you and the people in your household can see them. I do not sell your data, I do not show ads, and there are no third-party trackers or analytics inside the app or on this website. Your data is stored in Ireland. You can delete your account at any time, and deletion is immediate and permanent.
1. Who is responsible for your data
Reshta is built and run by one person, not a company:
- Mykyta Soloviov
- Based in the United States
- [email protected]
Under the UK and EU General Data Protection Regulation (GDPR) I am the data controller for the personal data described in this policy. In this document “I” and “Reshta” mean the same thing, and “you” means anyone who uses the Reshta app or this website.
For any privacy question or request, write to [email protected]. It reaches me directly.
2. What data Reshta collects
Account data
Created when you register, and kept for as long as your account exists:
- An account number generated when you sign up. It identifies your account inside Reshta and is attached to your records so the app knows they are yours. It is meaningless outside Reshta and is never shared.
- Your email address. If you ask to change it, the new address is held separately until you confirm it.
- Your username, first name and last name, if you provide them.
- Your password, stored only as a one-way hash. I never store or see your actual password.
- Your time zone and your default currency, used to work out month boundaries and totals.
- The time you last signed in, and whether your account is pending, active, suspended or deleted.
The financial records you enter
This is the core of the app, and all of it is entered by you. Reshta has no connection to any bank. It cannot read your bank accounts, cards or statements, and it never asks for banking credentials.
- Units — the income sources, spending categories and accounts you set up: name, type, currency, opening balance, current balance and icon.
- Transactions — amounts moved between your units, the direction, the currency, an optional short description, and the date and time.
- Tags — the labels and colours you create to categorise transactions.
Household data
Reshta is built around a household. Every account belongs to one household, and everything described above — units, transactions and tags — belongs to the household rather than to one person. If your household has more than one member, every member can see and change all of it, including transactions and descriptions you added yourself. Reshta has no private or personal-only records. Please keep this in mind before you write anything sensitive into a transaction description.
What is kept on your device
The app does not store your financial records on your device. Units, transactions and tags are held in memory while the app is open and are gone when you close it, so nothing about your money is written to your phone's storage or included in an iCloud backup.
The only things the app saves on your device are your sign-in tokens and a handful of display preferences — your theme, whether cents are shown, which figures are hidden, and your haptic settings. Your sign-in tokens are held in the iOS Keychain, marked so that they never sync to iCloud and never move to another device through a backup.
Technical and log data
Collected automatically when the app or this website talks to the Reshta server, because the request cannot work without it:
- Your IP address.
- Your device type, operating system and browser, taken from the User-Agent your device sends.
- The address requested, the time, how long it took, and a random request ID used to trace errors.
This is written to server logs, which are deleted automatically — the application's own logs after 7 days, and the web server's after 14 days. Nothing in these logs ties them to your account. Reshta does not build profiles from this data and does not use it for advertising.
App Store analytics
Apple may share aggregated usage statistics and crash reports with me through App Store Connect. This happens only if you turned on “Share With App Developers” in your device settings, and you can turn it off at any time under Settings › Privacy & Security › Analytics & Improvements. What I see there is aggregated by Apple and does not identify you. Reshta itself contains no analytics or crash-reporting software.
3. What Reshta does not collect
To be explicit, Reshta does not collect or use any of the following:
- Your location. The app does not request or record it.
- Your contacts, photos, calendar, microphone or camera.
- Your bank, card or payment credentials.
- Device identifiers of any kind. Reshta uses no advertising identifier and no vendor identifier, contains no advertising and no ad networks, and never tracks you across other apps or websites.
- Push notifications. The app does not register for them, so it holds no notification token for your device.
- Tracking cookies. This website sets no analytics or advertising cookies and contains no pixels or third-party tracking scripts. The security provider described in section 5 may set a strictly necessary cookie to tell real visitors from automated attacks; it is not used to track you, and that is why you see no cookie banner here.
- Any special category data under GDPR Article 9, such as health, biometric, religious or political data. Please do not put such information into transaction descriptions.
4. Why Reshta uses your data, and the legal basis
Under GDPR I must have a legal basis for each purpose. These are mine:
- To give you the service you signed up for — creating your account, signing you in, storing and displaying your units, transactions and tags, converting currencies, and sharing records with your household. Legal basis: performance of a contract (Article 6(1)(b)).
- To send you service emails — verifying your email address and resetting your password. Legal basis: performance of a contract (Article 6(1)(b)).
- To keep Reshta secure and working — logging requests, limiting the rate of requests to block abuse, and investigating errors. Legal basis: legitimate interests (Article 6(1)(f)) in running a secure and reliable service. I keep this data for a short time and use the least I can.
- To meet legal duties — keeping or disclosing data where the law requires it, such as answering a valid legal request or responding to a data protection authority. Legal basis: legal obligation (Article 6(1)(c)).
Reshta does not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.
5. Who your data is shared with
I do not sell your personal data, rent it, or share it for anyone else's advertising. Your financial records are never shared with advertisers, data brokers or analytics companies. Data goes only to the following service providers, only so far as each one needs it to do its job, and each is bound by a contract to protect it:
- Amazon Web Services (AWS) — hosting for the server, the database and the backups. Location: Ireland. AWS stores everything described in section 2 but does not use it.
- Cloudflare — sits in front of Reshta, encrypts the connection between your device and the server, and filters malicious traffic. All app and website traffic passes through it, so it processes your IP address, your device and browser details, and the requests you make. It may also receive automatic reports from your browser when a network connection fails. Cloudflare acts on my instructions and does not use your data for its own purposes.
- Mailgun (Sinch) — sends verification and password-reset emails. I use Mailgun's EU infrastructure. It receives your email address and the contents of those emails, and nothing else. No marketing email is sent through it.
- Apple — distributes the app through the App Store and, if you opted in on your device, passes me the aggregated statistics and crash reports described in section 2. Apple handles that data as an independent controller under Apple's own privacy policy, not under mine.
Reshta also fetches daily currency exchange rates from ExchangeRate-API. That request is made by the server for all users at once and contains no personal data — the provider learns nothing about you.
Beyond this, I would disclose personal data only if the law required it — for example a valid court order — or to establish or defend a legal claim. If that ever happens and I am permitted to tell you, I will.
If Reshta is ever transferred to someone else, I will tell you before your data moves, and you will have the chance to delete your account first.
6. Where your data is stored, and international transfers
The Reshta server, its database, its cache and its backups are all located in Ireland. Emails are sent through Mailgun's EU infrastructure.
I run Reshta on my own, and I live in the United States. When I administer the service — for example investigating an error or restoring a backup — I access data that is stored in Ireland from the United States. If you are in the EEA, the UK or Switzerland, that access is a transfer of your personal data outside your region. The United States does not have an adequacy decision that covers an individual in my position, so you should know that your data can be accessed from a country whose privacy laws differ from your own. In practice this access is occasional, limited to what a problem requires, and always over an encrypted connection.
Traffic reaches the server through Cloudflare's global network, which means your requests pass through whichever Cloudflare location is nearest to you before arriving in Ireland. Cloudflare and Apple both process data globally under their own transfer safeguards, described in their own privacy policies.
7. How long your data is kept
- Account and financial records — kept until you delete your account. Reshta does not expire or archive your records on its own.
- Application logs — deleted automatically after 7 days.
- Web-server access logs — rotated daily and deleted automatically after 14 days.
- Backups — kept for 7 days, then overwritten.
- Sign-in sessions — access tokens expire after 24 hours, refresh tokens after 7 days.
- Email verification links — expire after 1 hour.
- Cached account details — held in the server cache for at most 24 hours.
8. Deleting your account
You can delete your account from inside the app. Deletion is immediate and permanent — there is no grace period and no recovery, so please export anything you want to keep first.
When you delete your account:
- Your account record is erased from the database straight away, including your email address, name and password hash.
- All of your sign-in sessions are revoked immediately.
- If you were the last member of your household, the household is erased too, together with every unit, transaction and tag in it.
- If other members remain in your household, the household records stay with them, because those records belong to the household as a whole.
One honest limit: backups are kept for 7 days, so deleted data survives in a backup for up to 7 days before it is overwritten. Backups are never used to bring deleted accounts back.
9. Your rights
If you are in the EEA or the UK, the GDPR gives you the rights below. I extend them to everyone who uses Reshta, wherever you live.
- Access — get a copy of the personal data I hold about you.
- Rectification — correct anything wrong. Most of it you can edit yourself in the app.
- Erasure — delete your data. The in-app delete does this immediately; you can also ask me.
- Portability — receive your data in a machine-readable format, or have it sent to another service where technically feasible.
- Restriction — ask me to pause processing while a dispute is resolved.
- Objection — object to processing based on legitimate interests, such as the security logging in section 4.
- Withdraw consent — where processing relies on consent, withdraw it at any time, without affecting what was done beforehand.
To use any of these, email [email protected] from the address on your account. I will reply within 30 days. There is no charge. I may need to confirm it is really you before I act, to stop someone else getting at your records.
You also have the right to complain to a data protection authority. In the EEA, contact the authority in the country where you live or work. In the UK, contact the Information Commissioner's Office at ico.org.uk. I would appreciate the chance to put things right first.
10. If you live in the United States
Some US states, including California, Colorado, Connecticut and Virginia, give residents privacy rights. I honour the following for every US user, regardless of whether a particular state law applies to an operation of Reshta's size:
- The right to know what personal information is collected and why — set out in sections 2 and 4.
- The right to a copy of your personal information.
- The right to correct it.
- The right to delete it.
- The right not to be discriminated against for exercising these rights. Reshta works exactly the same either way.
Reshta does not sell your personal information, and does not share it for cross-context behavioural advertising. I have never done so and have no plans to. There is therefore nothing for you to opt out of. Reshta does not use your personal information for targeted advertising or profiling.
To exercise any of these rights, email [email protected]. You may use an authorised agent, in which case I will need proof of their authority.
11. How your data is protected
- All traffic between your device and the server is encrypted with HTTPS, and the connection to the database is encrypted too.
- Passwords are stored only as one-way hashes (currently bcrypt) with a unique salt for each user. They cannot be reversed, and I cannot see them.
- Sign-in uses short-lived tokens that can be revoked, and every session expires on its own.
- Every request is scoped to your own household in the database, so one household cannot read another's records.
- Requests are rate-limited to make brute-force and abuse harder.
- On your phone, sign-in tokens are kept in the iOS Keychain and are readable only while the device is unlocked. They are marked never to sync to iCloud and never to transfer to another device through a backup.
- Your financial records are never written to your phone's storage, so they cannot be read off the device or recovered from an iCloud backup.
No service can promise perfect security. If a breach ever affects your personal data and puts your rights at risk, I will notify the relevant authority within 72 hours as GDPR requires, and I will tell you directly when the law requires it or when it is the right thing to do.
12. Children
Reshta is not for children. You must be 16 or older to create an account. I do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has given me their data, email [email protected] and I will delete the account and its data promptly.
13. Changes to this policy
If this policy changes, I will update the date at the top of this page. If a change materially affects your rights or how your data is used, I will also tell you in the app or by email before it takes effect, so you have time to decide whether to keep using Reshta. Previous versions are available on request.
14. Contact
Questions about privacy, or a request about your data, go to [email protected]. It reaches me directly, and I answer within 30 days. If you need a postal address in order to make a formal request or to contact a regulator, email me and I will provide one.