Privacy policy

Last updated: 1 August 2026

The short version. Reshta stores the money records you type in, so that you can see them. No ads, no trackers, no analytics, and I never sell your data. Everything is stored in Ireland. You can export all of it at any time, and you can delete your account at any time — deletion is immediate and permanent. If you subscribe, Apple handles the payment and I never see your card details.

1. Who I am

Reshta is built and run by one person: Mykyta Soloviov, based in the United States — [email protected]. In this document “I” and “Reshta” mean the same thing, and “you” means anyone who uses the Reshta app or this website. Every privacy question or request goes to that email address and reaches me directly.

2. What I collect

Your account

An account number generated at sign-up (meaningless outside Reshta, never shared); your email address, and a new one held separately until you confirm it if you ask to change it; your password as a one-way hash only — I never see the real one; your time zone and default currency; the time you last signed in; and whether the account is pending, active, suspended or deleted.

The records you enter

All of it typed by you: units (the cards in the app — name, type, currency, opening and current balance, icon), transactions (amount, direction, currency, optional note, date and time) and tags (labels and colours). Reshta has no connection to any bank. It cannot read your accounts, cards or statements, and it never asks for banking credentials.

These records are stored under a household. Sharing a household is not available yet — there is no invite screen and no way to add a second member, so your household is you alone and nobody else can see your records. I will update this policy before that changes. Even so, please do not write anything sensitive into a transaction note.

What is on your device

In normal use your records are never written to your phone. They live in memory while the app is open and are gone when you close it, so nothing about your money reaches your phone's storage or an iCloud backup. The app saves only your sign-in tokens — in the iOS Keychain, marked never to sync to iCloud and never to move to another device through a backup — and a few display preferences (theme, cents, hidden figures, haptics).

The one exception is an export you ask for. It is written to the app's temporary folder, which iOS keeps out of backups; each new export replaces the last, and iOS clears the folder itself. Once you save or send the file, it is an ordinary file wherever you put it — no longer under Reshta's control or covered by this policy.

Technical and log data

Collected automatically whenever the app or this website talks to the server, because the request cannot work without it: your IP address; your device type, operating system and browser from the User-Agent; and the address requested, the time, how long it took and a random request ID used to trace errors. Application logs are deleted automatically after 7 days and web-server logs after 14. Nothing in them is tied to your account, and none of it is used for profiling or advertising.

Apple

If you turned on “Share With App Developers” on your device, Apple sends me aggregated usage statistics and crash reports that do not identify you. You can turn it off under Settings › Privacy & Security › Analytics & Improvements. Reshta itself contains no analytics or crash-reporting software.

A Reshta Subscription is bought through Apple's In-App Purchase. Apple processes the payment and holds your payment details — I never receive your card number, billing address or Apple Account details. The app asks Apple, on your device, whether your subscription is active; that answer stays between your device and Apple and is never sent to my server. Apple shows me only aggregated sales figures.

What I never collect

Your location, contacts, photos, calendar, microphone or camera. Your bank, card or payment credentials. Device or advertising identifiers of any kind — Reshta contains no ads, no ad networks, and never tracks you across other apps or websites. Push notification tokens; the app does not register for notifications. Analytics or advertising cookies, pixels or third-party scripts on this website — the security provider in section 4 may set one strictly necessary cookie to tell real visitors from automated attacks, which is why you see no cookie banner.

3. Why I use it, and the legal basis

  • To run the service you signed up for — creating your account, signing you in, storing and showing your units, transactions and tags, and converting currencies.
  • To send service emails — verifying your address and resetting your password.
  • To provide the subscription — checking with Apple, on your device, whether it is active.
  • To keep Reshta secure and working — logging requests, rate-limiting abuse, investigating errors. I keep the least I can, for the shortest time I can.

Your email address and password are required to have an account at all; everything else is yours to give or not. There is no automated decision-making or profiling with legal or similarly significant effects.

4. Who it is shared with

I do not sell, rent or share your data for anyone's advertising. It goes only to these providers, only as far as each needs to do its job, and each is bound by a contract to protect it:

  • Amazon Web Services — the server, database and backups. In Ireland. AWS stores your data but does not use it.
  • Cloudflare — sits in front of Reshta, encrypts the connection and filters malicious traffic. All traffic passes through it, so it processes your IP address, device and browser details, and the requests you make.
  • Mailgun (Sinch), EU infrastructure — sends verification and password-reset emails. It receives your email address and those messages, nothing else. No marketing email is ever sent.
  • Apple — distributes the app, processes subscription payments, and passes me the opt-in aggregated statistics above. Apple does this as an independent controller under Apple's own privacy policy, not mine.

5. Where it is stored, and transfers

The server, database, cache and backups are all in Ireland, and email goes through Mailgun's EU infrastructure. I run Reshta alone and live in the United States, so when I administer it — investigating an error, restoring a backup — I reach data stored in Ireland from there, over an encrypted connection and only as far as the problem requires.

Cloudflare routes your requests through its nearest location before they arrive in Ireland, and Cloudflare and Apple both operate globally. Where they process EEA or UK data outside that region, they do so under the safeguards in their own data processing terms — the EU and UK Standard Contractual Clauses and, where they are certified, the EU–US Data Privacy Framework. Email me and I will point you to the relevant terms.

6. How long it is kept

  • Account and financial records — until you delete your account. Nothing expires or is archived on its own.
  • Application logs — 7 days. Web-server logs — 14 days.
  • Backups — 7 days, then overwritten.

7. Deleting your account

You can delete your account inside the app. It is immediate and permanent — no grace period, no recovery — so export anything you want to keep first, using Settings › Data › Export Data. Your account record goes from the database straight away, including your email address, name and password hash; every sign-in session is revoked; and because you are always the only member of your household, the household is erased with it, together with every unit, transaction and tag. Nothing is left behind.

One honest limit: backups live for 7 days, so deleted data survives in a backup that long before being overwritten. Backups are never used to bring deleted accounts back.

Deleting your account does not cancel a Reshta Subscription — that lives with Apple. Cancel it under Settings › your name › Subscriptions, or Apple will keep charging you.

8. How it is protected

  • HTTPS between your device and the server, and an encrypted connection to the database.
  • Passwords stored only as one-way hashes (currently bcrypt) with a unique salt each. They cannot be reversed and I cannot see them.
  • Short-lived, revocable sign-in tokens; every session expires on its own. Requests are rate-limited against brute force and abuse.
  • Every request is scoped to your own household in the database, so one household cannot read another's records.
  • On your phone, tokens sit in the iOS Keychain, readable only while the device is unlocked, and never sync or transfer. Your records are never written to phone storage at all.
  • An export you have saved is protected by none of this. It is not encrypted and has no password — anyone who can open it can read every unit and transaction in it. Think before you email it or put it in shared storage.

No service can promise perfect security. If a breach ever puts your rights at risk I will notify the relevant authority within 72 hours as the GDPR requires, and tell you directly where the law requires it or where it is simply the right thing to do.

9. Changes, and contact

If this policy changes I will update the date at the top. If a change materially affects your rights or how your data is used, I will also tell you in the app or by email before it takes effect. Previous versions are available on request.

Everything goes to [email protected], which reaches me directly and is answered within 30 days.