Plain-language legal notice

Privacy Policy

This policy explains what stays on your device, what Dirav may process when you use optional online services, and the choices available to you.

Effective July 12, 2026

01 · Scope

What this policy covers

This Privacy Policy applies to the Dirav mobile application and the optional connected services provided through the Dirav API. Dirav is a local-first budget and money tracker. Its core finance features work without a bank connection and without sending your private finance records to Dirav servers.

Some releases may offer optional account, subscription, family entitlement, device, notification, configuration, and support features. The sections below describe the information those online features may process when they are enabled and you choose to use them.

02 · On-device data

Financial data stored locally

Dirav stores core financial information in the application database on your device. This includes:

Money activity

Accounts, balances, spending limits, expenses, income, transfers, adjustments, and payment details.

Planning

Budgets, goals, loans, repayments, people, and manual exchange rates.

Organization

Custom categories, subcategories, labels, payment types, notes, and reports.

Preferences

Local profile, language, display settings, privacy masking, and backup history.

Not intentionally sent to our API. Dirav application code does not intentionally upload account names or balances, financial records, budgets, goals, loans, custom categories or labels, people, payment types, manual exchange rates, reports, exports, or encrypted backup contents to the Dirav API.

03 · Optional online services

Information connected features may process

If online account features are enabled and you use them, the Dirav API may process the following information:

  • Account and profile: name, email address, hashed password, optional phone number, preferred language, country, and account status.
  • Authentication: access tokens, password-reset information, and Apple or Google identity-provider details when social sign-in is used.
  • Device information: device identifier, platform, app version, optional push-notification token, and device trust, last-seen, or revocation timestamps.
  • Purchases and entitlement: plan, platform, subscription status and dates, transaction reference, and a cryptographic hash of a purchase token. Dirav does not receive your full payment-card details.
  • Family entitlement: family owner/member identifiers, invited email address, membership status, and invitation or acceptance dates.
  • Support: ticket subject and message, priority, app version, device platform, replies, and diagnostics you choose to submit.
  • Service operation: standard request and security information, such as IP address, user agent, session data, and server logs, where generated by the service infrastructure.
Keep support submissions private.

Do not include transactions, balances, budgets, loans, goals, passwords, or other sensitive financial information in support messages or diagnostic payloads.

04 · Use

Why we process connected-service data

We use connected-service information only to operate and protect the features you request, including to:

  • Create and secure an online account, authenticate you, and recover access.
  • Register or revoke trusted devices and deliver optional notifications.
  • Verify, restore, and maintain subscription or purchase entitlements.
  • Manage family access, invitations, and seat limits.
  • Provide app configuration, supported-language, plan, and template information.
  • Respond to support requests and troubleshoot user-submitted diagnostics.
  • Prevent abuse, protect the service, resolve disputes, and meet legal obligations.

Dirav does not use your information for behavioral advertising or to build advertising profiles.

05 · Sharing

Service providers, not data brokers

Dirav does not sell personal information. We may disclose limited connected-service information to providers that help deliver a feature you choose to use, subject to their own terms and privacy practices:

  • Apple or Google for social sign-in, purchases, subscription verification, and restoration, when those features are enabled.
  • Firebase Cloud Messaging or the applicable platform notification service for optional push notifications, when configured.
  • Hosting, database, network-security, email, and support infrastructure providers that process information on our behalf.
  • Authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or enforce agreements.

Dirav does not include advertising features or an analytics SDK in the current application code. The final store disclosures must always match the exact app release and service providers in use.

06 · Backups

User-controlled backup files

When you create a Dirav backup, the app packages local data and settings into a password-protected .dirav file encrypted with AES-256-CBC. The file is written to app-private local storage and is not uploaded to the Dirav API.

You are responsible for remembering the backup password and controlling any copy you export, move, or share. Your device operating system may also include app data in platform-managed device or account backups when those backups are enabled. Apple, Google, or another destination you choose handles those copies under its own terms and privacy policy.

07 · Security

How information is protected

Dirav uses safeguards appropriate to the information and feature involved. Production API traffic uses HTTPS, passwords are stored using secure one-way hashing, authentication uses revocable access tokens, and submitted purchase tokens are stored as cryptographic hashes. User-created Dirav backup files are encrypted as described above.

No method of storage or transmission is completely secure. Dirav does not claim that the local device database is encrypted, and the “hide amounts” feature masks values on screen rather than encrypting stored records. Protect your device with its operating-system lock and keep backup files and passwords secure.

08 · Retention & deletion

Online and local deletion are separate

Local financial data remains on your device until you delete individual records, clear the application data, uninstall the app, erase the device, or delete any backup files you control. Deleting an optional Dirav API account does not automatically remove local data or user-held backup files.

The current automated API deletion process revokes access tokens, marks the online account as deleted, changes the account email used for sign-in, and records the deletion time. It currently retains the account record and associated authentication-provider, device, subscription, entitlement, family, support, and diagnostic records. A fixed retention schedule and complete automated erasure of those associated records have not yet been implemented.

Separate from that current limitation, some information may need to be retained when required for security, fraud prevention, purchase reconciliation, dispute resolution, or legal obligations.

You may request review and deletion of remaining personal information by contacting us below. We will assess the request, verify account ownership where necessary, and explain any information that must be retained for a legitimate legal or operational reason.

09 · Your choices

Access, correction, and privacy requests

Depending on where you live, you may have rights to request access to, correction of, deletion of, or restriction or objection to the processing of your personal information. You can also disable optional notifications in your device settings and stop using connected services while continuing to use Dirav’s local finance features.

An approved public privacy contact has not yet been configured. Dirav must publish that contact before connected account features are released publicly.

10 · Children

Dirav is intended for adults

Dirav is not designed for children. If you believe a child has submitted personal information through an optional online service, contact us so we can review and take appropriate action.

11 · Changes

Updates to this policy

We may update this policy when Dirav’s features, service providers, or legal requirements change. We will update the effective date shown at the top of this page and provide additional notice when required. Your continued use after an update is subject to the revised policy.

12 · Contact

Talk to us about privacy

Contact the Dirav privacy team for policy questions, access or correction requests, or account and personal-data deletion requests.

Privacy contact Pending approved public address