This document ("DPA") describes how Halim Öztürk / Halim Öztürk ("We", "Us", "Developer") handles personal data in Actual Budget (published as "Actual Budget Spendıng Tracker"). It should be read together with our Privacy Policy, which it must not contradict.
There are two distinct roles, and an earlier version of this page described only the first:
Your budget records. These are stored on your device and in your own private iCloud container. You control them; we cannot read them. For this data, you are the controller and Apple is the infrastructure provider.
Analytics, subscription and push data. For the data described in section 5 below, Halim Öztürk is the data controller, and the companies in section 7 are our processors. We decide what is collected and why, so the responsibility is ours, not yours.
2. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person
"Processing" means any operation performed on Personal Data
"Data Subject" means the individual to whom Personal Data relates
"CloudKit" means Apple's cloud storage service
3. Scope and Purpose
This DPA applies to all Personal Data processed through the Actual Budget app. The primary purpose of processing is to provide personal finance management services to Users, and to measure and improve the app.
4. Data Processing Architecture
The architecture is local-first, but it is not a zero-collection architecture. Accurately:
Your budget records — transactions, categories, budgets, goals, bills, accounts — are stored on your device and synced only to your private iCloud container via Apple's CloudKit. We cannot access, read, or retrieve them.
Separately, the app sends product-usage analytics to Mixpanel and Firebase Analytics. Some of these events include monetary amounts (see section 5).
The app registers for push notifications, and a Firebase Cloud Function operated by us stores a push token record on our Firebase backend. This means it is not true that data never passes through our servers — one narrow record does.
iOS supplies us with an Apple Search Ads attribution token so we can measure our own campaigns.
5. Categories of Data
Stored in your private iCloud container (inaccessible to us):
App functionality, analytics, measuring our own marketing
Approximate Location
City / region / country derived from IP address by the analytics providers (never GPS)
Analytics
Purchases
Subscription and trial status, App Store transaction information
App functionality, analytics, measuring our own marketing
These categories mirror the App Store App Privacy label for this app. None of it is used for tracking, and the label's "Data Used to Track You" section is empty.
6. Data Security Measures
Technical Measures:
iCloud sync encrypted in transit and at rest, managed by Apple
Authentication via Apple ID for iCloud; the app itself has no login
All network requests use encrypted HTTPS connections
Firebase App Check to protect our backend endpoints from abuse
Your budget records are never uploaded to a server we control
Organizational Measures:
Halim Öztürk is a one-person studio; access to analytics dashboards is limited to the developer
Local-first architecture — the smallest practical amount of data leaves the device
Regular security updates
7. Sub-processors
We use the following sub-processors:
Sub-processor
Service
Purpose
Apple Inc.
CloudKit, App Store, Search Ads
Private data storage, payments, campaign attribution
Mixpanel Inc.
Product analytics
Usage events, including the monetary amounts in section 5
Daily currency rates — request contains only currency codes, no user data
8. Data Subject Rights
For your budget records, exercisable by you directly:
Access: View all data in the app or iCloud
Rectification: Edit any data within the app
Erasure: Delete data via app or iCloud settings
Restriction: Disable sync or delete the app
For the data we control (analytics, subscription and push records), e-mail us at the address in section 18 and we will action your request — including access, correction, erasure and portability. We do not sell or share personal information, and we will not discriminate against you for exercising these rights.
9. International Data Transfers
Your iCloud data location is determined by Apple's data centre locations for your account; we do not control or influence it. The analytics, subscription and push data described in section 5 is processed by providers based in the United States, subject to the safeguards set out in their respective privacy policies.
10. Data Retention
Your budget records are retained as long as you maintain them on your device and in your iCloud account
Deleting the app removes the local copy but does not delete iCloud data
You can delete all iCloud data through your Apple Account settings; we have no access to do it for you
Analytics, subscription and push records held by our providers are retained only as long as needed for the purposes in section 5, and we will delete the records tied to your installation on request
11. Data Breach Procedures
In the event of a security issue:
We will notify affected users and, where required, the relevant supervisory authority within 72 hours
Notification will include the nature of the breach and recommended actions
Because your budget records never reach our servers, the exposure of any breach on our side is limited to the analytics, subscription and push data described in section 5
12. Compliance
This DPA is written to support compliance with:
General Data Protection Regulation (GDPR)
California Consumer Privacy Act (CCPA)
Turkish Personal Data Protection Law (KVKK)
Other applicable data protection laws
13. Audit Rights
Users can verify our data practices by:
Reviewing app permissions in iOS Settings
Checking iCloud data storage
Inspecting the app's network activity — you will see requests to our analytics, subscription and push providers as described in section 7, and none carrying your transaction records
Comparing this page against the App Store privacy label and our Privacy Policy, which are kept consistent with each other
14. Termination
Upon termination:
Stop using the app
Your budget records remain in your iCloud until you remove them
Delete iCloud data if desired — we cannot access or delete that data for you
Ask us to delete the analytics, subscription and push records tied to your installation
15. Liability
We accept responsibility as controller for the analytics, subscription and push data described in section 5, and process it in line with applicable data protection law. We are not able to manage your iCloud-stored budget records, which remain under your control.
16. Amendments
We may update this DPA to reflect changes in data protection laws or our practices. Significant changes will be communicated through the app.
17. Governing Law
This DPA is governed by the laws of the United States and applicable international data protection regulations.
Your budget records are stored on your device and in your iCloud account, and you manage them
We collect the analytics, subscription and push data described in section 5 — including monetary amounts inside analytics events — and act as controller for it
None of it is used to track you, sold, or shared with advertisers or data brokers
This page, our Privacy Policy, and the App Store privacy label are intended to say the same thing; if you find them in conflict, please tell us