Privacy Policy
Arrel · Last updated 24 August 2026
Arrel keeps your financial data on your device. Nothing is sent anywhere unless you sign in to sync it, and even then only to us — never to anyone else, with one exception: if you choose to share a tracker, the people you invite to it see what you enter there. See Shared trackers below.
Arrel works completely without an account. Even if you never sign in, the app makes a few requests that don't need one, and none of them says anything about you. It downloads published exchange rates and the list of currencies it offers, so it can add up money you hold in more than one of them — those requests carry nothing about you, and the answer is the same for everyone who asks. And if you're a Premium subscriber and fetch a live price for an investment, your device asks our server for today's price for the tickers you hold — again nothing that identifies you — which our server answers using CoinGecko for crypto and Marketstack for stocks and ETFs. There is no analytics service, no advertising network, and no third-party SDK of any kind. Signing in is optional and exists for one reason — so your data survives losing your phone, and reaches your other devices.
Who we are
Arrel is developed by Luis Cárdenas ("we", "us"). For anything in this policy, write to support@arrel.app. Our postal address is available on request at that same address.
What stays on your device
Everything you record in Arrel is stored locally on your device and, where you have enabled it, in your own iCloud device backup. This includes:
- Accounts, balances and transactions
- Budgets, categories and recurring payments
- Trackers and their entries
- Investment portfolios, holdings and their history
- Your settings and display preferences
If you are not signed in, we cannot see any of it — there is no copy anywhere but your device and your own backups.
Sync, if you sign in
Creating an account is optional. If you do, Arrel sends the records listed
above to our server at api.arrel.app so your devices stay in step
and your data survives losing a device.
- What we store. Your email address and display name, and the records you create — accounts, transactions, budgets, categories, trackers, investments and settings. Amounts, dates, notes and merchant names are part of those records.
- What we do not store. We hold no payment details, no bank credentials and no connection to any bank. Arrel has no access to your bank accounts and never asks for their passwords.
- Legal basis. Performing the contract you enter into by creating an account (GDPR Article 6(1)(b)). You are not asked to consent to tracking, because there is none.
- Where it is stored. On servers in the European Union. Your records never leave it. The one thing that does is your email address and a single-use link, handed to our mail provider when you ask us to confirm your address or reset your password — see Where you are, and where your data is below.
- How long. For as long as your account exists. Delete the account and it is erased immediately — see Your rights below, which names the two things that outlive it: entries in a tracker you share, and the fact that a subscription was paid for.
- The server does no analysis. It stores and returns your records. It does not calculate your net worth, your budgets or anything else — every figure Arrel shows is worked out on your own device.
- Your devices. When you sign in on an iPhone or iPad, we store a push token for that device — an identifier Apple issues for this app on this device — so we can wake it when a tracker you share changes. Signing out or deleting your account removes it. The Mac app registers nothing.
- Email. We write to you only to confirm your address or to let you reset your password, and only because you asked. There is no newsletter, no product mail and no marketing of any kind, so there is nothing to unsubscribe from.
- Who processes it on our behalf. Our hosting provider, Hostinger Operations UAB (Hostinger), based in the EU — the only sub-processor with access to stored records. Our mail provider, Resend (Plus Five Five, Inc.), in the United States, which delivers those two messages and receives nothing but the address and the link — no records, no balances, and no access to anything we store.
Shared trackers
A tracker is normally yours alone. If you choose to share one — a trip, a house move — with people you invite, this changes what's visible and to whom.
- What other members can see. Every entry's description, amount, currency and date, and your display name (shown as initials — Arrel has no avatars or photos). Nothing else about you.
- What stays private, even in a shared tracker. The transaction it's linked to in your own ledger, and which account — or which currency — you were actually charged in. Only you can see those, never another member.
- The shared total is in one currency — the owner's — so "the trip cost €490" means the same thing to everyone in it.
- Changes are logged. Every member can see who changed what and when, including an amount's value before and after — nothing about a shared tracker's contents changes silently.
- Leaving, being removed, or deleting your account. Your entries survive — so other members' totals don't silently change — but your name is stripped from them and from the membership list.
- If you're the owner and you delete your account, the tracker freezes: no one can invite, remove a member, or edit it further, but everyone keeps read and write access to their own entries. There is currently no way to transfer ownership or unfreeze it afterwards — a real limitation, stated plainly rather than glossed over.
- No discovery. Trackers are never searchable. The only way in is an invite from someone already a member.
What else leaves your device, and when
Only in these situations, and only because you asked:
- Purchases. Subscriptions are processed by Apple. We never see your payment details, your card or your billing address. Apple tells the app whether a subscription is active, and also tells our server when one is bought, renewed, cancelled, lapses or is refunded — so that a refund isn't missed while your device is asleep. What we hold is the subscription's status and Apple's own transaction numbers for it: not a payment record, and nothing that says what you paid with. See Apple's Privacy Policy.
- Sign in with Apple. Optional, and not required to use Arrel. If you use it, Apple handles the sign-in and you choose whether to share or hide your email address.
- Contacting support. If you email us from the Support screen, your mail app sends what you write plus the technical details shown to you on that screen: app version and build, iOS version, device model, language and whether you have a subscription. No balances, transactions or account names are included, and you can see and edit the whole message before sending it.
- Exporting. When you export CSV or a PDF report, the file goes wherever you send it. That destination is your choice and outside our control.
What we do not do
- No analytics or usage tracking
- No advertising, and no advertising identifiers
- No third-party SDKs
- No selling or sharing of personal data, ever
- No use of your records to train anything, ours or anyone else's
- No profiling or automated decision-making
Face ID and Touch ID
If you turn on the app lock, authentication is performed by iOS. Arrel is told only whether it succeeded. Your biometric data is held in your device's Secure Enclave and is never available to the app.
Notifications
Budget alerts and payment reminders are scheduled locally on your device. Nothing is sent to a server to produce them, and nothing about them is reported back to us.
There is one exception, and it shows you nothing. If you are signed in and a member of a shared tracker, our server sends your device a silent signal when another member changes something, so the app can fetch the change rather than wait for the next sync. That signal carries the identifier of the tracker to refresh and nothing else — no amount, no description, no name — and it never produces a notification you can see. It travels through Apple's Push Notification service, which sees the token and the fact of a message, not your records. iPhone and iPad only.
Searching for investments
The list of assets Arrel searches is bundled inside the app. Searching it makes no network request, so what you look up is not observable by us or by anyone else.
How it is protected
Everything between your device and our server travels over HTTPS, and the server accepts nothing in plain text. Passwords are stored as argon2id hashes, never in a form anyone can read back, so we cannot tell you your own password and will never email it to you. If we ever discover a breach affecting your data we will report it to the Spanish data protection authority within 72 hours as the GDPR requires, and tell you directly where the law requires it or where it would matter to you.
No system is perfect, and the honest counterpart to that is the app itself: you can use Arrel with no account at all, in which case there is nothing of yours on our server to breach.
Your rights
These rights are given to everyone who uses Arrel, wherever you live: to know what we hold, to get a copy of it, to correct it, to delete it, to move it elsewhere, and to object to what we do with it. Under the GDPR they are called access, rectification, erasure, restriction, portability and objection; the laws of other countries name them differently and we make no distinction. Most of them you can exercise directly and immediately, without asking us:
- Access and portability — Settings → Export Data gives you everything in CSV, free of charge.
- Erasure, on our server — Settings → Delete Account
removes your account and every record we hold for it, immediately and
permanently. There is no grace period and no recovery. Your data stays on
your device; you have withdrawn it from us. Two things outlive the account,
and both are stated here rather than glossed over:
- Entries you wrote into a tracker you share with others survive with your name removed, so other members' totals don't change — see Shared trackers above.
- The record that a subscription was bought through Apple survives, with your name, your email and every record you wrote detached from it. What is left is Apple's transaction number and a date, pointing at no one. Apple keeps telling us about that subscription whether or not the account still exists, and it is what lets you get back a subscription you already paid for if you sign up again.
- Erasure, on your device — Settings → Data & Privacy → Erase All Data. Deleting the app also removes the local copy, but does not delete your account — use Delete Account for that.
- Rectification — edit or delete any record at any time.
Anything you cannot do from inside the app, ask us at support@arrel.app. We answer within 30 days, free of charge, and we will never treat you differently — a different price, a worse app — for having asked.
Where you are, and where your data is
Arrel is sold wherever the App Store sells it, and holds money in any of the 64 currencies it offers — dollars, pesos, yen and rand as readily as euros. Where you live changes which law protects you. It does not change where the data sits.
If you sign in, your records are stored on servers in the European Union regardless of where you are, and are not transferred out of it. For someone in the EU or the wider EEA that means there is no international transfer of your records at all. For everyone else it means the copy we hold is governed by European data protection law, which is stricter than most of the alternatives — including the law where you live, in most cases.
One narrow exception, and this is us naming it. Sending you a confirmation or password-reset message means handing your email address and a single-use link to Resend (Plus Five Five, Inc.), which is in the United States. That is a transfer outside the EEA, and it is covered by the European Commission's Standard Contractual Clauses under Article 46 of the GDPR. It carries nothing but the address and the link: no records, no balances, no account contents. Nothing is sent unless you ask for it, and an account created with Sign in with Apple that hid its address is never written to at all. If any other processor outside the EEA is ever involved, this policy will name it and name the safeguard, exactly as it does here.
Supporting a currency is not the same as having a presence in that country. We have no office, no establishment and no representative outside Spain.
If you are in the United States
State privacy laws — California's CCPA as amended by the CPRA, and the comparable laws of Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Utah and a growing list of others — give you rights to know, delete, correct and take a copy of your personal information, and to opt out of its sale or sharing, of targeted advertising, and of profiling. The rights are covered by Your rights above, which we apply to everyone. Four things those laws expect us to say plainly:
- We do not sell your personal information, and never have. We do not "share" it either in the sense those laws use, which means disclosing it for cross-context behavioural advertising. Arrel carries no advertising, no ad identifiers and no profiling, so there is nothing here to opt out of. That is a description of how the app is built, not a promise we could quietly stop keeping: there is no third-party SDK in it to send anything anywhere.
- What we collect, in the categories those laws use. Identifiers (your email address, display name, an account identifier, and a device and push identifier); commercial and financial information (the accounts, transactions, budgets, holdings and trackers you record); and other user content (the notes, merchant names and labels you write). All of it comes from you, directly. We keep it to run the app for you, to sync it between your devices and to support you — nothing else — and we disclose it to no one but our hosting provider, who stores it for us.
- Financial information is "sensitive personal information" under several of these laws. We use it for a single purpose: showing it back to you and keeping it in step across your devices. We never use it to infer anything about you, and we do not use or disclose it for any purpose that would give you a right to limit it.
- Agents, and how we verify. You may have an authorised agent act for you; we may ask them for proof and ask you to confirm it. We verify a request by the account it comes from — which is why we ask you to write from the address you signed up with.
These pages set no cookies and run no scripts, so there is no Global Privacy Control signal for them to honour and nothing to track across sites.
If you are in the United Kingdom, or anywhere else
UK users have the same rights under the UK GDPR, and may complain to the Information Commissioner's Office. In the EU and EEA you may complain to your own national supervisory authority, or to Spain's Agencia Española de Protección de Datos, which is ours. Elsewhere — Canada, Brazil, Australia, Japan and the rest — the rights above are yours all the same, and you may complain to whichever authority is responsible where you live. Wherever you are, writing to support@arrel.app reaches a person.
Children
Arrel is not directed at children, and we do not knowingly collect data from anyone under 13 — nor under 16, where the country you live in sets that age, as several EU member states and several US state laws do. If you believe a child has given us data, write to support@arrel.app and we will delete it. We do not knowingly sell or share the personal information of anyone under 16, and we do not sell or share anyone's.
Changes to this policy
If Arrel gains a feature that sends data somewhere new — fetching live market prices, or anything involving a third party — this policy will be updated before that feature ships, and the change will be described here rather than made quietly. That is how sync was introduced.
