Skip to content

Trust

Your data is yours.

On-device first. Encrypted at rest. Never sold. Audit log on every action. Export anytime. Delete anytime.

Our principles

  • On-device first

    Your financial data, your work, your shared plans live primarily on your iPhone. The cloud is a sync layer for your other devices and your invited Members, not a surveillance layer for us.

  • Encrypted at rest

    Every Supabase row is encrypted with AES-256, and so are our backups. Your Plaid access token sits in a server-only column your app can never read, and we never store full bank account numbers — only the masked last few digits your bank already shows you.

  • Never sold, never advertised against

    We make money the calm way: subscriptions. We don't run ads. We don't sell anonymized data. We don't hand your data to model trainers. Your data is the product YOU bought, not the product WE sell.

The register

What we collect (and what we don’t)

Plain English. The full legal version lives at /privacy.

ItemWe collect?Why / why not
Email address YesSign in + sync across devices
Apple/Google ID (if used to sign in) YesAuthentication only — never linked to ads
Your financial data (balances, bills, splits) YesThe whole product. Lives encrypted.
Crash + diagnostic logs (anonymized) YesSo we can ship a less-buggy app
Your contacts NoWe don't read your contact book. Ever.
Your location NoMoney doesn't ask. Together asks only for explicit features (e.g. find my house) and never stores history.
Photos / camera roll NoReceipt scans are processed on-device with the Vision framework; image data never leaves your phone unless you explicitly share it.
Browsing data outside OneTruth NoWe can't see anything you do outside our apps.
Your data, sold to anyone NoNot now. Not ever. We're a subscription business.

The map

Where your data lives

  • Supabase (US-East)

    Your synced data lives in Supabase Postgres in AWS us-east-1. Row-level security (RLS) gates every table — even our own engineers can't read your data without going through the same auth as you.

  • Your iCloud (your control)

    Local backups go through your iCloud, encrypted with your Apple ID. We never see them. Migrating to a new iPhone restores everything from your iCloud + a fresh sign-in.

  • Your iPhone keychain

    Auth tokens, vault keys, and biometric-protected credentials live in the iOS Keychain — Apple's hardware-backed secure enclave. Not in our database, not in our logs.

The receipts

Compliance & audits

SOC 2 readiness — on the roadmap. Our infrastructure (Supabase + Stripe + Apple) is already SOC 2 Type II; the remaining work is our own controls audit, scheduled before Work + Together GA.

GDPR + CCPA — every right those frameworks grant (access, portability, deletion, objection) is built into Account → Danger zone, available to every user regardless of geography. No tickets, no waiting.

HIPAA — we don’t collect health data and OneTruth is not HIPAA-covered. If you need HIPAA-grade isolation, our apps aren’t the right fit yet.

No asterisks

Calm software with no asterisks.

Try OneTruth Money. Cancel anytime. Export anytime. Delete anytime.