Legal
Privacy Policy
1 Who we are and what this policy covers
This Privacy Policy explains how the OweMe app for iPhone (the "App") handles information, and what we, Palmora Technologies LLC, a limited liability company (LLC), do and do not do with it. In this policy, "we", "us", or "the Developer" means Palmora Technologies LLC. Our postal address, telephone number, and email are in section 20.
The policy covers the App, as distributed through the App Store or, as section 18 explains, through Apple's TestFlight, and this website at https://owe-me.app (section 17). It does not cover Apple's services (iCloud, the App Store, Messages, Contacts, Photos, notifications) or Google's services, which have their own privacy policies linked below. Our Terms and Conditions are a separate document.
2 The short version: your ledger stays with you
The App does not send your ledger to us. Support emails, website hosting and Apple reports are described separately below. In detail:
- There is no account and no sign-in. The App never asks for an email address, a password, or a login.
- There is no OweMe server. No computer we operate ever receives, stores, or processes anything from the App.
- There is no analytics, telemetry, crash-reporting, advertising, or attribution code in the App. The App contains no third-party software development kits at all; it is built only with Apple's own frameworks.
- The App keeps no activity log and sends no diagnostic or usage information anywhere. The one status value it keeps, the last iCloud sync error message, stays on your iPhone (section 4). The App does not read your device's advertising identifier and does not read your clipboard.
- We do not track you. In Apple's sense of the word, that means we do not link data from the App with data from other companies' apps, websites, or offline sources for advertising or measurement, and we do not share data with data brokers.
- We do not receive or share your ledger and do not use analytics or advertising services in the App. The only outside services the App contacts are Apple (iCloud, section 4; App Store search, image servers, and App Store purchases, section 9) and Google (favicon service, section 9); those requests go straight from your iPhone to them under their own privacy policies, linked in this document. If a future version ever shares data with a third party, we will name it here first and require it to protect your data at least as well as this policy describes (section 19).
- Apart from what you write to us yourself (section 20) and the server logs of this website's host (section 17), the only things we can ever receive come from Apple, not from the App, and carry neither your name nor your Apple Account: a crash report or aggregated usage statistic, only if you opted in to Apple's diagnostics program (section 18), and, if you buy OweMe Pro, Apple's sales and subscription reports (section 9). Neither contains anything from your ledger.
- OweMe Pro is bought inside the App, but the purchase is made through Apple's App Store, not with us. We never receive your name, Apple Account, email address, or payment details, and the App itself stores nothing about the purchase: to know whether Pro is on, it reads the purchase records signed by Apple that iOS keeps on your iPhone (section 9).
We do not hold your ledger, so we cannot see, recover, correct, or delete it for you. Everything below about your data describes what happens on your iPhone, in your own iCloud, and in the logo lookup requests described in section 9.
The App's privacy manifest declares no collected data types and no tracking, and we answer Apple's App Privacy questionnaire the same way, so the App's App Store page should show "Data Not Collected". If the store page ever shows anything else, one of the two is wrong; tell us at [email protected] and we will correct it and note the correction in the change log (section 19). Apple counts data as "collected" when it is sent off the device in a way that lets the developer or its partners access it for longer than needed to answer the request. Your ledger does not reach us. Buying OweMe Pro does not change that: the purchase is made through Apple's App Store, the App sends nothing about it to us or to anyone else, and the label covers what a developer and its partners collect, not what Apple's own App Store records about a purchase (section 9). The logo lookups do reach Apple and Google, and Google states that it may keep ordinary request logs (your IP address, the time, and the brand or store domain). Google is not our partner and receives no account or device identifier from the App. If that log concerns you, pick an icon for the record before typing its title or its store: tap the icon tile with the pencil badge at the top of "New Record" (announced as "Choose icon" by VoiceOver). Then no request is made for that record. Section 9 lists the lookups that run without any typing, and what picking an icon can and cannot do for a record you have already saved.
3 What the App stores on your iPhone, and about whom
The App stores what you enter inside its own private storage on your iPhone. Every amount is shown in US dollars.
People you add (information about other people)
Name, a short display name, the line shown under their name (their phone or email when imported from Contacts), phone number, email address, notes you write about the person, a photo, whether you chose that photo yourself, and an archived flag. A person can come from your Contacts (section 5) or be typed in with "Add manually".
Records and payments (about other people, entered by you)
- Financing: product name, store, category, the icon shown on the record and whether you picked it yourself, total amount, amount paid, installment amount, how the installments repeat and the date of the first one, purchase date, next due date, term (the number of installments), the card you used, notes.
- Recurring: title, store or provider, the icon shown on the record, amount, frequency (for example weekly, monthly, yearly, every 2 weeks, or every 3 days), start date, next due date, the day of the month you chose, category, active or paused, the card you used, notes, and, when a logo was found, the identifiers described in section 9.
- One-Time: title, store or provider, the icon shown on the record and whether you picked it yourself, amount, date, category, the card you used, notes, and, once paid, the payment date, method, and notes.
- Payments you record as received: amount, date, a method label ("Zelle", "Cash", or a method you added in "Payment Methods"; older payments may carry "Apple Cash", "Check", "Bank Transfer", or "Other"), notes, the record the payment belongs to, when the entry was created, and, for a payment on a recurring plan, the plan's frequency when the payment was recorded (for example "Monthly").
- Your lists, from Account's "Options": the categories your records can use, each with a name and a color ("Categories"), and the names of the payment methods you record payments with ("Payment Methods"). Until you edit one, the App uses its built-in list and stores nothing for it.
Cards (about you)
Only a nickname, a network ("Visa", "Mastercard", or "None"), the last four digits, a type ("Credit", "Debit", "Store", or "Other"), and notes. The App has no field for a full card number, expiration date, security code, or billing address, and it never connects to a card or a bank.
Your profile (about you)
The name you enter, the file name of your photo if you add one, a random identifier for your profile, three flags (notifications allowed, Contacts allowed, and the "Contact Photos" setting from Account's "Options", section 5), and a flag recording that setup is complete. All of these fields are included in the iCloud copy if Sync is on. The screen called "Account" in the App is where this local profile and the App's settings live. It is not an account with us: nothing on it is registered anywhere, and there is nothing to sign in to or to close.
Cached logo images
App icons and website icons downloaded by the logo lookups in section 9, saved as small image files.
Automatic safety copies
Up to five complete copies of your ledger, each written automatically before iCloud's copy replaced the ledger on your iPhone (section 10), plus up to three copies of a ledger the App found unreadable and set aside. If iCloud's copy has never replaced the ledger on your iPhone, no safety copy exists; the set-aside copies exist only if the App ever found its ledger unreadable.
Preferences and housekeeping
Your list filters and sort orders, which people you marked as reminded this period, the identifier of a person whose deletion is still finishing, a count of edits not yet uploaded, reduced copies of contact photos with their index (section 5), a store-logo index (what the App learned about each store it looked up for a Financing or One-Time record, itemized in section 9), and, only after you have ever turned on iCloud Sync, a small sync bookkeeping file (itemized in section 4). None of this concerns an OweMe Pro purchase, which the App does not store (section 9).
Free-text fields are not checked
"Name", "Notes", "Title", "Store / Provider", and similar fields accept anything. The App does not detect or mask sensitive content. If you type something sensitive, for example a full card number in a card's "Notes", it is stored as typed and synced to iCloud if Sync is on. We recommend keeping such details out of the App.
Your iPhone backups include it
Your ledger, photos, cached logos, the store-logo index, and safety copies are part of your normal iPhone backup (iCloud Backup or a computer backup), as with most apps. This is true even with iCloud Sync off: if iCloud Backup is on for your iPhone, your ledger is inside that backup, protected as Apple describes for iCloud Backup. The sync bookkeeping file is excluded from backups. Backups are governed by Apple's Privacy Policy and iCloud terms, and by how you protect your computer.
4 iCloud Sync (optional)
Off by default; two ways to turn it on
iCloud Sync is off when you install the App, and the App makes no iCloud request until you turn it on. The single exception is the Welcome screen's "Restore from Backup": tapping it asks your own iCloud whether an OweMe backup exists and shows you how many people, records, payments, and cards it holds and when it was last backed up, before you decide. To do that the App reads whether your iPhone is signed in to iCloud and the backup's summary; nothing is uploaded. If you then tap "Restore", the App downloads the backup, with its photos, onto this iPhone. The restore does not need Pro in this version, but Sync stays on afterwards only with OweMe Pro (section 9); the screen says which of the two applies before you tap. With Pro, Sync stays on. Without Pro, Sync turns back off as soon as the backup is on this iPhone; the copy in iCloud stays where it is, and turning Sync on later needs Pro. If iOS has not confirmed your purchase within about two seconds of the tap, a restore with Pro also ends with Sync off; the "iCloud Sync" switch described below turns it back on. Without Pro, a photo the restore could not download (for example one the other iPhone never uploaded) stays missing until Sync is turned on. "Not Now" leaves Sync off. The other way to turn Sync on is the "iCloud Sync" switch in Account, under "iCloud & Data". Turning that switch on needs OweMe Pro (section 9); without it, the switch opens the "OweMe Pro" screen and Sync stays off. You can turn Sync off at any time with the same switch, with or without Pro. If Pro ends while Sync is on, this version leaves Sync on.
What is uploaded
When Sync is on, the App uploads your whole ledger as one file: every person (name, short display name, the line shown under the name, phone, email, notes, photo file name, and an archived flag), every record and payment, every card (nickname, network, last four digits, type, notes), the logo identifiers from section 9, and your profile (the same fields listed in section 3). The store-logo index from section 9 is not uploaded; each iPhone builds its own. It also uploads the photo files themselves: people's photos and your own. Alongside the file it stores a revision number, the time of the change, a random identifier for this installation of the App (not a hardware identifier), and a count of rows per collection. Photos already uploaded stay in the iCloud copy until you delete the whole iCloud copy, even if you later remove or replace a photo in the App or delete the person. To clear out photos of people you have deleted without losing anything on this iPhone: open "Delete Data", choose "iCloud Copy Only", tap "Continue" and confirm with "Delete iCloud Copy", then turn iCloud Sync back on. The App then uploads a fresh copy containing only the photos currently in use.
Once Sync is on, the App also reads two things from iCloud: whether the iPhone is signed in, and an opaque identifier of the signed-in Apple Account, which it keeps on the iPhone only to notice if the account changes. That identifier is never displayed or sent anywhere else. The App also asks iOS to tell it if the signed-in Apple Account changes, and re-checks the account when that happens so it can stop and ask you (see "Never merged silently" below).
The sync bookkeeping file mentioned in section 3 holds:
- a random identifier for this installation;
- that opaque Apple Account identifier;
- whether Sync is on;
- the revision number and time of the last sync;
- the row counts iCloud last confirmed;
- the profile name from your own ledger as iCloud last confirmed it;
- the last sync error message;
- a note if a deletion of the iCloud copy is still pending.
It is excluded from iPhone backups.
Where it goes and who can read it
The copy is stored in the private database of Apple's CloudKit service, inside your own Apple Account, in a container reserved for OweMe. It is not a shared or public database. Your devices signed in to your Apple Account can read it, and so can Apple unless you turn on Advanced Data Protection (see "Encryption, stated honestly" below). We cannot read it: Apple's CloudKit does not give app developers access to users' private databases, so we cannot see, restore, or delete your iCloud copy. Sync connects your own devices only. It cannot share a ledger with another person, and if the iPhone has switched to a different Apple Account the App stops and asks you what to do before uploading or changing anything.
Encryption, stated honestly
Apple encrypts the data in transit and on its servers. Under standard iCloud data protection, Apple holds the encryption keys, which means Apple can access the data and can hand it over if legally required to. If you turn on Advanced Data Protection for iCloud on your Apple Account, only your own trusted devices hold the keys (end-to-end encryption). Under either setting, iCloud's own record metadata remains accessible to Apple and is not protected by the record's end-to-end encryption: the names of the records, the field names, the format markers, and the timestamps iCloud itself keeps for when each record was created and last changed. The App's own bookkeeping values stored alongside the file (its revision number, its own change time, the installation identifier, and the row counts) are stored using CloudKit's encrypted-field feature. The App adds no encryption of its own; it relies entirely on Apple's protections. A shorter version of this explanation appears in the App under "iCloud & Data", "Learn More".
When it syncs
Sync runs only in the foreground: when you open the App, when you return to it, at the moment you leave it (one last upload), and a few seconds after you make a change. The App also re-checks the account if iOS reports that the signed-in Apple Account changed while the App is open. A sync that fails for a temporary reason, such as a poor connection, is retried up to three times; the last error is shown under "iCloud & Data". The App never runs in the background, and there is no push notification. Turning Sync off stops new uploads; it deletes nothing, and the App tells you that the copy already in iCloud stays there.
Never merged silently
The App stops and asks you before it changes anything if:
- it finds a ledger in iCloud that is not the one this iPhone knows;
- the Apple Account has changed;
- an upload or download would remove more than a quarter of a list and more than ten rows from it, remove the whole ledger, or blank your name (smaller removals are applied without a question, so check the "Your Ledger" counts under "iCloud & Data" after a sync if in doubt); or
- the copy it receives is far smaller than expected.
You will see a question such as "Two Copies of Your Data", "Different iCloud Account", or "Upload Paused". Before iCloud's copy replaces the ledger on your iPhone, the App tries to write a safety copy on the iPhone first (section 10). That copy protects this iPhone's ledger only. If you answer "Keep This iPhone", the copy in iCloud is replaced and no copy of it is kept anywhere. If you are unsure which copy is newer, tap "Not Now": nothing is replaced until you choose, and the question shows how many people, records, payments, and cards this iPhone holds and how many iCloud held when the App last checked. An iPhone backup made first (iCloud Backup or a computer backup) keeps this iPhone's ledger; nothing keeps a copy of the one in iCloud.
Apple's terms, quota, and availability
Your iCloud copy counts against your iCloud storage quota and is governed by the Apple iCloud Terms and Conditions and Apple's Privacy Policy. If your iCloud storage is full, the App cannot upload and tells you so; nothing on your iPhone changes. Sync needs an iPhone signed in to iCloud, and does not work where iCloud is restricted, for example by parental controls or a device-management profile.
Deleting the App does not delete the iCloud copy
Removing the App from your iPhone leaves the copy in iCloud in place. To remove it you have two options. In the App, reinstall it and reconnect it to the copy first: on the Welcome screen choose "Restore from Backup", then "Restore" (this downloads the copy; Sync stays on afterwards only with OweMe Pro, but either way this iPhone now knows the copy); then use "Delete Data" in "iCloud & Data" and choose "Everywhere". If you already finished setup on the reinstalled App, turning on "iCloud Sync" in Account reconnects it in the same way, but that switch needs OweMe Pro (section 9); the Welcome screen route above and the iOS Settings route below do not. The App downloads the iCloud copy and, because this iPhone already holds your name, asks "Two Copies of Your Data" first; choose "Use iCloud's Copy". After that, "Delete Data" offers "iCloud Copy Only" and "Everywhere". A freshly installed App that has not been reconnected offers only the local "Delete Data" button, which leaves the iCloud copy in place. Or in the iOS Settings app, tap your name, then "iCloud", then "Manage Storage" (Apple's wording varies by iOS version), find OweMe, and delete its data. Section 11 has the full list of deletion paths.
5 Contacts (optional)
Contacts access is optional. The App asks for it in three places: the "Import Your Contacts" step during setup, whose only button, "Continue", shows the iOS prompt, where you can choose "Don't Allow"; "Import from Contacts" when you choose a person for a record; and turning on "Contact Photos" in Account, under "Options", if iOS has not asked yet. iOS shows its own permission prompt with this purpose text:
"OweMe uses your contacts so you can add a person without typing their info, and to show their current contact photo."
If you restore a backup on the Welcome screen ("Restore from Backup"), setup ends there and the Contacts step is skipped; the App asks the next time you tap "Import from Contacts".
What happens with access:
- To add a person, the App shows Apple's contact picker. It never lists or copies your address book as a whole. While "Contact Photos" is on, it does ask Contacts about the people already in your ledger, as described under "Contact Photos" below.
- When you tap one contact, the App copies that contact's name, first phone number, first email address, and photo into a new person in your ledger. Nothing else is read. If a person with the same name already exists and the phone numbers match (or, when neither has a phone number, the email addresses match, or neither has either), the existing person is reused instead of creating a duplicate.
- iOS may offer to share only selected contacts rather than all of them. The App works either way.
- The copied details stay on your iPhone and, only if you turn on iCloud Sync, in your own iCloud (section 4). They are never sent to us or to anyone else. The App never uses contact details to message, email, or notify anyone on its own (section 8), never builds a contact database for us, and never sells or shares contacts.
You can decline access and still add people: "Import from Contacts" opens Apple's picker, which needs no permission, and "Add manually" lets you type them. You can change access at any time in the iOS Settings app under "Privacy & Security", then "Contacts". Revoking access does not remove people already copied into your ledger; delete them in the App if you wish. Later changes to a contact's name, phone number, or email address in the Contacts app are not mirrored in the App. A change of photo is, while "Contact Photos" is on.
Contact Photos
"Contact Photos" in Account, under "Options", is on by default, and does something only while iOS already allows the App to read Contacts. The App never shows the iOS permission prompt for it on its own: for this feature it asks only when you turn the switch on (the switch shows off while the App cannot read Contacts), and if you declined earlier, turning it on opens iOS Settings instead. While it is on, a person in your ledger is shown with the photo their contact has today, unless you chose that person's photo yourself or removed it in "Edit Profile" (your choice always wins).
To do that, each time the App starts or returns to the foreground, right after a restore or a sync brings in a whole ledger, when you add a person, and when you open a person's "Edit Profile", the App asks Contacts three narrow questions about each person in your ledger who follows Contacts: which contacts have this phone number; if none, which have this email address; if none, which have this name. It does not list or read the rest of your address book, and if iOS shares only selected contacts with the App, only those can be found; the "Contact Photos" row in Account's "Options" then says so and offers "Choose Contacts", Apple's own picker, to share more; the App learns only that the selection changed, keeps nothing from the picker, and asks the same three questions again when it closes. For the contacts that answer, the App reads the name and nickname, the phone numbers, the email addresses, and the photo. A single contact found by phone number or email address is accepted even if its name differs from the name in your ledger; when several are found, only the one with the same name is used; a contact found by name alone is used only if the names are the same and it is the only one.
What the App keeps from this is a reduced copy of each photo and a small index (the person's identifier in your ledger, the copy's file name, and a fingerprint of the photo, so that an unchanged photo is not copied again). The copies stay in the App's cache on this iPhone and the index in the App's preferences. Neither is part of your ledger, and neither is ever uploaded to iCloud. The copies are not included in your iPhone backup (the index is), and iOS may clear the cache on its own, in which case the App copies the photos again. The copy is replaced when the contact's photo changes and removed when the contact has no photo any more, when the person is deleted (the next time the App checks), when you turn "Contact Photos" off, and by a local "Delete Data". Nothing about your contacts is sent to us or to anyone else.
The photo copied into your ledger when you imported the person is a separate thing: it stays in the ledger, is shown when no contact photo is available (for example on an iPhone without Contacts access), and is uploaded to your iCloud if Sync is on. If you pick a photo from your library or remove a person's photo in "Edit Profile", the ledger also records that you chose the photo yourself, and "Use Contact Photo" there undoes that choice.
6 Photos (optional)
To set your own photo ("Add Photo" during setup, or "Edit Profile" in Account) or a person's photo ("Edit Profile" on a person's page), the App uses Apple's photo picker. The picker runs outside the App and needs no permission; the App receives only the one image you tap, never your library. The App shrinks the image to at most 480 pixels on its longest side, re-encodes it as a JPEG (which drops the original file's location and camera metadata), and saves it inside its private storage under a random file name. The photo is shown in the App, included in your iPhone backup, and uploaded to your own iCloud only if Sync is on. "Remove Photo" deletes the file from the iPhone; a copy already uploaded stays in your iCloud copy until you delete the whole iCloud copy (section 4 explains how to refresh the iCloud copy without losing anything). The App never accesses the camera.
7 Notifications (local reminders)
Reminders are optional. The App asks during setup, using the standard iOS prompt: the "Stay on Top of Payments" step has a single button, "Continue", which shows the prompt, and you can decline there with "Don't Allow". It asks again only when you tap the "Notifications" row in Account while iOS has not asked yet. If you allow them:
- Every reminder is a local notification, scheduled by the App on your iPhone. There is no push server, no device token, and nothing is sent anywhere. The iOS prompt asks for alerts, sounds, and badges; each reminder plays the default notification sound (you can silence it in iOS Settings), and the App never puts a number on its icon.
- The App schedules reminders for each open plan (each financing plan with a balance and each active recurring plan; one-time records get none, because their date is the day the charge happened, not a day it falls due), at 9:00 in the morning on the plan's next due days, up to twelve for each plan. A recurring plan that charges more than once a month (every few days or weeks) gets one reminder a month instead, on the first of that month's due days, for the month's total. A due day already in the past is moved forward on the plan's own schedule (installment by installment for a financing plan, cycle by cycle for a recurring plan) to the first due day that is today or later, for the reminder only; the record itself is not changed. A reminder for today is not scheduled once 9:00 has passed. The App rebuilds the set whenever your records change and every time it opens or you return to it. iOS limits pending notifications, so the App keeps sixty: every plan's next reminder first, then the later ones, soonest first.
- The reminder reads "Payment due today" (or the recurring title followed by "due today"), then the person's name, the amount, and the item, for example "Ana owes $45.00 for Phone plan." That text may appear on your lock screen and in Notification Center. If you do not want it visible there, change "Show Previews" in the iOS Settings app under "Notifications".
- There are no marketing, promotional, or activity notifications.
You can turn reminders off at any time in the iOS Settings app under "Notifications", then "OweMe" (or under "Apps", then "OweMe"); once iOS has asked, the "Notifications" row in Account opens the App's page in iOS Settings, where "Notifications" is one tap away. Declining has no effect on any other feature.
If you declined the iOS prompt, you can allow notifications for OweMe in the iOS Settings app at any time; the App checks the permission every time it opens or you return to it, and schedules the reminders then.
If you restore a backup on the Welcome screen ("Restore from Backup"), setup ends there and the notification and Contacts prompts are skipped, so the App does not ask; if iOS had not asked before, reminders stay off until you turn them on with the "Notifications" row in Account.
8 Reminder messages you send
The App can prepare a reminder text for a person. When you tap the message button on a person's page (announced as "Send reminder" by VoiceOver), or the button next to a person in "Collection Day" (a screen that needs OweMe Pro, section 9; the message button on a person's page does not), the App shows Apple's Messages compose screen inside the App. The person's stored phone number is filled in as the recipient, or their email address if you stored no number (the field is left empty if you stored neither), along with a pre-written message. That screen belongs to iOS; the App cannot read what you change in it. The message opens with the person's full name and the current month (the month in which you prepare it), then one line per item with its amount. Recurring plans appear by title (with "(x4)" when charged more than once that month), financing plans by product name with the installment number and term, for example "iPhone (3/12)", and one-time records by title with their date, written in Spanish, for example "Cena (12 sept)". It ends with the total. The month heading (for example "Octubre 2026"), those dates and the line "Total a pagar: $120.00" are in Spanish, and the last line is the word "Zelle", because the template assumes a recipient who reads Spanish and pays you through Zelle. You cannot change the template in this version, but you can edit or delete anything in the compose screen before you press Send, and nothing is sent until you do.
Every reminder is prepared for one person at a time and only when you tap that person's button. There is no "select all" or send-to-everyone option, and the App never sends a message without you seeing it in the compose screen and pressing Send yourself.
From "Collection Day", the App learns only whether you pressed Send, so that it can show "Reminder sent" next to that person for the current period; that mark is kept on your iPhone and can be undone by pressing and holding the row ("Mark as not reminded"). The button on a person's page learns nothing and marks nothing. On an iPhone that cannot send texts, either button copies the text to the clipboard instead; "Collection Day" shows "Message copied" for a moment and marks nothing, since the App cannot know whether you pasted it anywhere.
Messages travel through your carrier (SMS) or Apple's iMessage, under their terms and privacy policies, not through us. "Copy Amount Owed" in the ••• menu on the person's page (announced as "More options" by VoiceOver) places the same text on the clipboard. Anything on the clipboard can be pasted anywhere, and iOS Universal Clipboard may make it available on your other Apple devices. "Export / Share Summary" in the same menu hands a short text summary of one person's balances to Apple's share sheet; you choose where it goes. The App never reads the clipboard.
9 Logo lookups and purchases: the only internet requests besides iCloud Sync
Apart from iCloud Sync (section 4), the App uses the internet for two purposes. The first is to show a real logo on a record, either the service behind a recurring charge or the store behind a Financing or One-Time purchase, and on a saved card, from the card's name. The second is OweMe Pro, the App's optional purchase, which iOS carries out with Apple's App Store; it is described under "Purchases: Apple's App Store" at the end of this section. For the logos, two outside companies are involved, Apple and Google, in the three requests described below. Apart from the text described under request 1 (a recurring record's title or "Store / Provider", a purchase's store, or a saved card's name) and, for request 3, a website domain taken from the App's own lists, never your text, none of these requests carries your name, an account, a device identifier, a person's details, an amount, or anything else from your ledger. A purchase's product name or title is never sent. Like any internet request, each reveals your iPhone's IP address and standard request headers (the App's default user agent) to the service that answers it. We never see these requests; they go straight from your iPhone to Apple or Google and are answered in real time.
Request 1: Apple's App Store search (iTunes Search API)
This is the only request that carries text you typed. It is automatic: there is no confirmation step and no setting to turn it off. It runs in these situations:
- Recurring, in "New Record": while you type the "Title"; while you type "Store / Provider", as long as the title has found no logo; and if you switch the form to "Recurring" with a title already typed.
- Recurring, in "Edit Plan": as the screen opens, and while you change the "Title" or "Store / Provider". This applies only to a plan that has no saved logo and whose icon you did not pick yourself. Opening the screen is enough; you do not need to type anything.
- Financing and One-Time, in "New Record" and "Edit Record": while you type the "Store" (Financing) or "Store / Provider" (One-Time); as "Edit Record" opens for a record that names a store; and if you switch "New Record" to "Financing" or "One-Time" with a store already typed.
- Financing and One-Time, wherever the record is shown: when a record that names a store appears on screen (in Transactions, in Financing, on a person's page, in a record list, or on the record's own page) and this iPhone has no answer for that store yet. This needs no action from you. It covers every such record, including ones that reached this iPhone through a restore or iCloud Sync, and each iPhone does it separately.
- Cards: in "Add Card" and "Edit Card", while you type the card's "Name"; and in "Cards" and "Select Card", when a card appears on screen and this iPhone has no answer for its name yet. The name is sent as you typed it ("Chase Freedom"), or the name of the bank or store the App recognizes in it ("Chase"). A card whose name mentions Apple, such as "Apple Card", is drawn by the App and never looked up. There is no icon to pick for a card, so a card's name is always looked up unless it is shorter than three characters or mentions Apple; if you would rather not send your bank's name, give the card a name that does not mention it.
It does not run for text shorter than three characters, for a Recurring title the App recognizes as one of Apple's own services (iCloud, Apple One, Apple Music, Apple TV, Apple Arcade, Apple News, Apple Fitness, AppleCare), which the App draws itself, or for a record whose icon you picked yourself (see "How to avoid a lookup" at the end of this section).
- When
- While you type, about half a second (425 milliseconds) after you pause; each keystroke cancels the previous lookup. As a screen opens or a record is shown, at once. For a store this iPhone has already looked up, no new search is made (see "What comes back and what is kept").
- What is sent
- One piece of text, together with fixed parameters (software results only, United States storefront, at most five results). For a Recurring record it is the text in "Title". Only if the title finds no logo at all (no confident match here and no brand match in request 3), the text in "Store / Provider" is sent in a second search of the same kind; if the title finds a logo, "Store / Provider" is never sent. For a Financing or One-Time record it is the store, never the product name or the title. If the store you typed matches the App's built-in list of retailers (well-known stores and similar merchants, such as Amazon, Walmart, Costco, Best Buy, The Home Depot, Lowe's, and IKEA, as well as airlines, banks, card issuers, and payment services, such as Chase, Capital One, Klarna, PayPal, and Venmo), the App sends that list's own name for the retailer instead of your text: "Best Buy" when you typed "Best Buy Hialeah", or "PayPal" when you typed "PayPal payment". Otherwise it sends the store text you typed. For a card it is the card's name, or that list's own name for the bank or store the App recognizes in it ("Chase" for "Chase Freedom"). Before sending, the App trims spaces, replaces a curly apostrophe with a straight one, and removes trailing words such as "premium", "family", "familiar", "plus", "pro", "subscription", "suscripción", "plan", "mensual", and "monthly". Because these are free-text fields, whatever you type in them can be sent to Apple. Text like "Netflix" or "Amazon" is fine; if you would name a person or anything private in a Recurring "Title" or "Store / Provider", or in a purchase's store, pick an icon first so nothing is sent.
- Endpoint
- https://itunes.apple.com/search with the parameters term, media=software, entity=software, country=us, and limit=5, over HTTPS, with no authentication.
- To whom and why
- Apple Inc., to find the App Store listing whose name matches the service or store, so that the App can show that app's icon. Governed by Apple's Privacy Policy. Like Google, Apple may keep ordinary request logs (your IP address, the time, and the text sent) under its own policy; the App has no control over that.
- What comes back and what is kept
- Up to five App Store results (app identifier, name, developer name, genre, artwork URLs). The App compares each result's name, and its developer's name, with the text it sent, and uses a result only if it matches closely. For a Recurring record the App then stores that app's identifier and artwork URL on the record when you save it. Those two values become part of your ledger: they are saved on your iPhone and uploaded to your iCloud if Sync is on. For a Financing or One-Time record, or a card, nothing is stored on the record or the card. Instead the App keeps the answer in a store-logo index on this iPhone, one entry per store or card name: a simplified form of the store's name (letters and digits only; for a listed retailer, the list's own name), the matching app's identifier and artwork URL, or the website domain from request 3, or a note that nothing matched, together with the date of the check and the App version that made it. The index is not part of your ledger: it is never uploaded to iCloud. A note that nothing matched stops counting after fourteen days or after an App update, and the store is then looked up again. A lookup that failed, for example offline, is not remembered and is tried again the next time; if Apple's search or the download of its icon failed but Google's icon was found, that icon is kept for an hour, and Apple is asked again after that. A "nothing matched" answer received in "New Record", "Edit Record", "Add Card", or "Edit Card" is not remembered either; only one received for a saved record or card is.
Request 2: Apple's image servers (App Store artwork)
- When
- Right after a confident match in request 1, and again later if the image file is missing from your iPhone when a record that uses it is shown: a recurring record with a stored identifier, or a purchase or card whose store or name is in the store-logo index (for example after restoring or syncing onto a new iPhone).
- What is sent
- A plain request for the artwork URL returned in request 1. No identifiers.
- To whom and why
- Apple's content delivery network, to download the app icon. Governed by Apple's Privacy Policy.
- What comes back and what is kept
- The icon image, saved as a PNG file inside the App's private storage and kept until you delete your data. One download per app identifier.
Request 3: Google's favicon service
- When
- Only if request 1 produced no icon (no confident match, or Apple's image could not be downloaded, or the text was too short for request 1 to run) and the text matches one of the App's built-in lists. For a Recurring record, the title (or, when the title found nothing, the "Store / Provider") must contain one of the App's brand keywords anywhere in the text. That list holds a few dozen well-known brands and covers streaming, music, storage, carriers, internet providers, gyms, gaming, insurance, education, delivery, rideshare, software, VPN, and similar services. Some keywords are ordinary single words such as "drive", "prime", "dish", "steam", or "planet", so an unrelated title can match. For a Financing or One-Time record, the store, and for a card, its name, must match the retailer list described in request 1 (long names anywhere in the text, short ones such as "UPS" or "Ross" only as a whole word) or be nothing more than one of the same brand keywords; a recognized bank or card issuer sends its own domain, for example chase.com for a card named "Chase Freedom". The retailer list has no website for Apple, so a store named "Apple" or "Apple Store" never causes this request. The request runs again later if that image file is missing from your iPhone when the record is shown.
- What is sent
- Only the brand's or retailer's website domain taken from the App's built-in lists (for example netflix.com or lowes.com) and the requested image size. The text you typed is never sent to Google.
- Endpoint
- https://www.google.com/s2/favicons with the parameters domain and sz=128, over HTTPS, with no authentication.
- To whom and why
- Google LLC, to obtain that website's icon. Governed by the Google Privacy Policy and the Google Terms of Service. Google states that it records details of requests such as IP address, time, and request data. Google is the only company other than Apple that the App ever contacts.
- What comes back and what is kept
- The icon image, saved as a PNG file inside the App's private storage; generic placeholder images are discarded. For a Recurring record the domain name is stored on the record and therefore appears in your iCloud copy if Sync is on. For a Financing or One-Time record, or a card, it is kept only in the store-logo index on this iPhone (request 1).
Over time, the set of brands and stores looked up reveals which services you track and where you shop. That information exists only on your iPhone (in the cached files, the records, and the store-logo index), in your iCloud copy if Sync is on (the identifiers on recurring records; store names are part of your records in any case), and in the request logs of Apple and Google under their policies. The lookups are best-effort: they can fail, return a wrong image, or be withdrawn by their providers, and they do not work offline, in which case the App shows a generic symbol.
How to avoid a lookup
Pick an icon yourself. In "New Record", tap the icon tile with the pencil badge at the top (announced as "Choose icon" by VoiceOver) before typing the title or the store: no request is made for that record, and the choice is saved with it, so a purchase's store is not looked up later when the record is shown. For a record you have already saved, the same tile at the top of "Edit Plan" or "Edit Record" (announced as "Change icon") stops the lookups for that record from then on, once you save the change, but it cannot undo one that already ran: a purchase's store may have been looked up the first time the record was shown, and "Edit Plan" runs its lookup as the screen opens. In "Edit Plan", an icon identical to the symbol the App would show for that title anyway does not count as picked. Leaving "Store" or "Store / Provider" empty also prevents a store lookup for that record; other records that name the same store still cause it. Picking an icon later shows your icon instead of the logo. Cached logo files and the store-logo index are removed by a local "Delete Data" (section 11).
Purchases: Apple's App Store (OweMe Pro)
The App is free for a ledger of up to two people and five active debts. OweMe Pro is an optional purchase, "Monthly" (a subscription), "Yearly" (a subscription), or "Lifetime" (paid once), that removes both limits and lets you turn on iCloud Sync and open "Collection Day"; the Terms of Use describe it. The App contains no payment code of its own and no third-party purchase software. It uses StoreKit, the part of iOS that talks to Apple's App Store, and no OweMe server is involved: iOS checks Apple's signature on each purchase on your iPhone.
- When
- When the App starts, every time it comes back to the foreground, and when a subscription reaches its end date while the App is open, it asks iOS which OweMe Pro purchases belong to the Apple Account signed in to the App Store on this iPhone; iOS answers from its own records on the iPhone, so the answer does not need a connection, and refreshes them with Apple when it needs to. While the App is open, iOS also tells it about every change Apple sends (a renewal, a refund, an approved "Ask to Buy" request, a purchase made on another device), and the App asks again. Prices are requested from the App Store only when the "OweMe Pro" screen opens. A purchase happens only when you tap the buy button and confirm on Apple's own payment sheet, and "Restore Purchases" asks Apple to send this Apple Account's purchases again; iOS may ask you to sign in. If nothing is found, the screen says so; if Apple cannot be reached, it says that instead, and a purchase already on your iPhone keeps Pro on.
- What is sent
- The App gives iOS the identifiers of its three products and, when you buy, the product you chose. iOS and the App Store exchange the rest under your Apple Account: the App never sees your Apple Account, name, email address, payment method, or billing address, and it adds no identifier of its own to a purchase. Nothing from your ledger is involved. Like any internet request, these reveal your IP address to Apple.
- To whom and why
- Apple, which charges you, sends your receipt, and handles cancellations and refund requests under the Apple Media Services Terms and Conditions and Apple's Privacy Policy. Apple keeps your purchase history in your Apple Account; we cannot see or delete it.
- What comes back and what is kept
- For each purchase, a record signed by Apple: the product, the purchase date, for a subscription the date it renews or ends, whether it was refunded or revoked, and whether it reaches you through Family Sharing. iOS keeps these records on your iPhone and manages them itself; the App reads and checks them there each time and sends them nowhere. The App itself stores nothing about a purchase: no receipt, no copy of the plan, nothing in its preferences, in your ledger, or in your iCloud copy. That is why a local "Delete Data" leaves Pro in place (erasing your ledger does not undo a purchase). After a reinstall or on a new iPhone, "Restore Purchases" brings Pro back.
- What reaches us
- Apple's sales and subscription reports for developers: how many purchases were made, of which product, on which day, in which country or region and currency, on what kind of device, and the proceeds. For subscriptions Apple also lists events (a trial started, a renewal, a switch between "Monthly" and "Yearly", a cancellation, a refund) under a random subscriber number that Apple creates for this purpose. None of it includes your name, Apple Account, email address, or payment details, the App cannot see that number, and we cannot link any of it to you or to a ledger. We use these reports for accounting and taxes and to see how the App is doing.
If you write to us about a purchase, we may ask for the order number from the receipt Apple emailed you so that we can tell you what to do; we cannot look up a purchase ourselves, and refunds are decided by Apple at reportaproblem.apple.com. Deleting the App or your data does not cancel a "Monthly" or "Yearly" subscription; cancel it in your Apple Account settings (the "OweMe Pro" screen shows a "Manage Subscription" button once you subscribe).
10 Automatic safety copies
The App has no export and no import: it never writes your ledger to a file that you can share or save elsewhere, and it cannot read one. The copies of your ledger that can exist are the one on your iPhone, the one in your own iCloud if Sync is on (section 4), the ones inside your iPhone backups, and the automatic safety copies described here.
Before iCloud's copy replaces the ledger on your iPhone, the App tries to save a complete copy of the ledger inside its private storage, in readable form: people (name, phone, email, notes), records, payments, cards (nickname, network, last four digits, type, notes), the logo identifiers, and your profile (the same fields listed in section 3). Photos are not included; only their file names are. The store-logo index from section 9 is not included, and neither is anything about an OweMe Pro purchase. The App adds no encryption of its own to these files; iOS Data Protection covers them like the rest of the App's storage (section 12). A copy that cannot be written (for example because your iPhone is full) is skipped, not retried, and the replacement still goes ahead. The newest five are kept and older ones are removed. If iCloud's copy never replaces the ledger on your iPhone, no safety copy exists. If the App ever finds its stored ledger unreadable, it sets that data aside in the same folder (newest three kept) rather than overwriting it. These files are not visible in the Files app. You cannot view or restore these copies from inside the App today; they can only be recovered from a computer backup of your iPhone with third-party tools, or by a future version of the App that exposes them. They still contain people you have since deleted. They are included in your iPhone backup and are deleted by a local "Delete Data" (section 11). Choosing "iCloud Copy Only" does not delete them.
11 Retention and deletion
How long data is kept
We hold no copy of your ledger, so we cannot retain or delete it for you. Section 20 explains how we retain support correspondence. Data on your iPhone stays until you delete it or delete the App. Data in your iCloud stays until you delete it. Cached logos and the store-logo index stay until a local "Delete Data"; inside the index, a note that nothing matched a store stops counting after fourteen days or after an App update, and the store is then looked up again. Safety copies rotate (the newest five kept, plus up to three set-aside unreadable ledgers) and are all removed by a local "Delete Data". Pending reminders are rebuilt from your records and disappear when a record is paid or deleted. The App keeps nothing about an OweMe Pro purchase; the records signed by Apple are kept by iOS under Apple's rules (section 9). Apple's sales and financial reports to us (section 9), which name no one, are kept for as long as accounting and tax rules require.
Delete some of it
- A person and everything linked to them: the ••• menu on the person's page (announced as "More options" by VoiceOver), then "Delete Person". This removes their records, payments, and photo from your iPhone. It does not remove that person from the automatic safety copies described in section 10 (up to five earlier versions of your whole ledger, plus up to three set-aside unreadable copies). Those copies stay on your iPhone and in your iPhone backups until you run a local "Delete Data"; there is no way to delete a single safety copy today. If iCloud Sync is on, a photo file already uploaded stays in your iCloud copy until you delete the whole iCloud copy ("Delete Data", then "iCloud Copy Only" or "Everywhere"; section 4 explains how to refresh the copy without losing anything).
- A single record or plan: "Delete Record" or "Delete Plan" at the bottom of its edit screen.
- A payment: swipe it left in "Payment Activity" or "Payment History".
- A card: Account, then "Cards", then the card, then the trash button. Records that used it keep the card's name as text, with its last four digits if you entered them, for example "Sapphire •• 1234".
- A photo: "Remove Photo" in the person's "Edit Profile". With Sync on, a photo already uploaded stays in the iCloud copy until the whole iCloud copy is deleted.
Delete all of it in the App
Open Account (the circle in the top corner of Overview), then "iCloud & Data", then the red "Delete Data" row. The "Delete Data" sheet asks where to delete. You pick one choice, tap "Continue", and the next screen lists what will be removed; nothing is deleted until you tap its red button. The choices are:
- "Everywhere": removes everything on this iPhone and the copy in iCloud, and returns the App to the Welcome screen. Offered when this iPhone knows of an iCloud copy.
- "This iPhone Only": removes everything on this iPhone, returns the App to the Welcome screen, and leaves the iCloud copy in place, so another iPhone can still restore from it.
- "iCloud Copy Only": removes the copy in iCloud and turns Sync off; everything on this iPhone stays.
- If this iPhone has never synced, the sheet opens straight on a single confirmation whose "Delete Data" button removes everything on this iPhone and returns the App to the Welcome screen.
A local erase ("Everywhere", "This iPhone Only", or the single "Delete Data") removes:
- every person, record, payment, and card;
- all photo files the App saved for people and for your profile, including any no longer attached to anyone;
- all cached logo images and the store-logo index;
- all automatic safety copies, including set-aside unreadable ledgers;
- the reduced copies of contact photos and their index (section 5);
- your profile and preferences, including the "reminded" marks;
- all pending reminders.
This cannot be undone.
"This iPhone Only" removes the sync bookkeeping file at once. "Everywhere" and "iCloud Copy Only" first note in that file that the iCloud deletion is pending and remove the file only once iCloud confirms the deletion. If the deletion fails (for example while offline), the App says so, the copy is still there, and the App retries the deletion by itself the next time you open it; turning iCloud Sync back on cancels the pending deletion instead.
A local erase does not remove:
- a plain counter of unsent edits (a number, with no content);
- an OweMe Pro purchase, which belongs to your Apple Account and is kept by iOS, not by the App (section 9);
- copies inside iPhone backups you made earlier;
- the iCloud copy, unless you chose "Everywhere" (you can also remove it separately with "iCloud Copy Only").
Delete the App
Deleting the App from your iPhone removes everything the App stored on the iPhone. It does not remove the iCloud copy (section 4) or copies of the ledger inside iPhone backups you made before deleting it (iCloud Backup or a computer backup); those are removed when the backup is replaced or deleted. It does not cancel a "Monthly" or "Yearly" OweMe Pro subscription either; cancel that in your Apple Account settings (section 9). To remove the iCloud copy afterwards, reinstall the App, choose "Restore from Backup", then "Restore" on the Welcome screen (this reconnects the App to the copy, with or without OweMe Pro; Sync stays on afterwards only with Pro), then use "Delete Data" and choose "Everywhere". If you already finished setup on the reinstalled App, turning on "iCloud Sync" in Account, which needs OweMe Pro (section 9), reconnects it too (choose "Use iCloud's Copy" when the App asks "Two Copies of Your Data"); then "Delete Data" offers "iCloud Copy Only" and "Everywhere". A freshly installed App that has not been reconnected offers only the local "Delete Data" button. Alternatively, use the iOS Settings app: tap your name, then "iCloud", then "Manage Storage", find OweMe, and delete its data. Neither the Welcome screen route nor the iOS Settings route needs a purchase.
Withdraw a permission
- iCloud Sync: switch it off in "iCloud & Data". Nothing new leaves your iPhone; use "Delete Data" to remove what is already there.
- Contacts: iOS Settings app, "Privacy & Security", then "Contacts". People already copied stay in your ledger until you delete them. "Contact Photos" in Account, under "Options", turns the photo lookups off and removes the reduced copies at once.
- Notifications: turn them off in the iOS Settings app under "Notifications", then "OweMe" (the "Notifications" row in Account opens the App's page in iOS Settings, one tap away). To turn them back on, allow them in the same place; if iOS has never asked (because you restored a backup on the Welcome screen, which skips the prompt), tap the "Notifications" row in Account instead, which shows the iOS prompt (section 7).
- Logo lookups cannot be switched off separately. They run while you type a recurring record's title or provider or a purchase's store, as "Edit Plan" opens for a plan that has no logo yet or "Edit Record" opens for a purchase that names a store, whenever a purchase that names a store is shown and this iPhone has no answer for that store yet, while you type a card's name in "Add Card" or "Edit Card", whenever a card is shown in "Cards" or "Select Card" and this iPhone has no answer for its name yet, and again when a stored logo file is missing from your iPhone. Choosing an icon yourself (the icon tile at the top of "New Record", "Edit Plan", or "Edit Record") stops them for that record from then on; section 9 explains what it cannot undo. A card has no icon to pick (section 9).
Deletion requests to us: we cannot delete your ledger because we do not hold it. For questions about these steps, or to request deletion of support correspondence you sent us (section 20), contact [email protected].
12 Security
Your data is protected by your iPhone's own security. The App's storage is covered by iOS Data Protection, which encrypts it when your iPhone has a passcode, and access to the iPhone is governed by your passcode, Face ID, or Touch ID. The App has no separate app lock: anyone who can unlock your iPhone can open the App. Data in iCloud is protected by Apple as described in section 4. Requests to Apple and Google use HTTPS. The App adds no encryption of its own.
No method of storage or transmission is completely secure. Things that help: set a passcode; turn on two-factor authentication for your Apple Account, and Advanced Data Protection if you want end-to-end encrypted iCloud data; and keep a backup of your iPhone. If we ever add an app lock, this section will say so. If you believe your iPhone or Apple Account has been compromised, follow Apple's guidance; we cannot lock, wipe, or recover anything for you.
13 Information about other people in your ledger
Your ledger holds information about other people, entered by you: names, phone numbers, email addresses, photos, notes, and amounts they owe. You control that information and are responsible for it. Because the App never sends that information to us, we cannot see, correct, or delete it, and privacy law treats you, not us, as the person keeping it. In practice that means: if a friend asks what you have written about them, show them their page; if they ask you to fix or remove it, use "Edit Profile" or "Delete Person" on their page (with Sync on, see section 11 for their photo in iCloud). Keeping a private record of money friends owe you is normally your own business; our Terms and Conditions, section 8, explain when business use brings extra obligations. The App never contacts, notifies, or shares anything with the people in your ledger; only you can, by sending a message yourself (section 8). Please keep sensitive details out of the App, and remember that reminder notifications can display a person's name and amount on your lock screen (section 7).
14 Children
The App is not directed to children under 13 (the age used by the US Children's Online Privacy Protection Act, COPPA), and we do not knowingly collect personal information from children; the App does not send us personal information from your ledger. Separately, our Terms require users to be 18 or older, because the App tracks money owed and other people's contact details and is meant for people who can enter into a contract. The App does not check anyone's age. If you are a parent or guardian and believe a child has used the App, delete it from the child's iPhone, which removes everything stored on it, and remove any iCloud copy as described in section 11. The people in your ledger may include a minor (a family member, for example); their name, photo, phone number, and what they owe are stored and synced exactly like an adult's, and you are responsible for that entry (section 13).
15 Your privacy rights
Depending on where you live, privacy law may give you rights to access, correct, delete, restrict, port, or object to the processing of personal data about you, and to withdraw consent. Here is how those rights work for OweMe:
- We hold no personal data about you from the App, so there is nothing for us to access, correct, port, or delete. Your data is under your direct control on your iPhone and in your iCloud, and section 11 explains how to delete it yourself.
- For the iCloud copy, Apple is the service provider; Apple's Privacy Policy and privacy.apple.com explain your rights with Apple.
- For the favicon requests, Google is the service provider; see the Google Privacy Policy.
- For OweMe Pro purchases, Apple holds your purchase history and payment details under its own policy; we hold nothing about your purchase that identifies you, and the reports Apple gives us name no one (section 9).
- We answer support and privacy questions by email at [email protected] on a best-efforts basis and aim to reply within thirty days, and we will help you find the right control in the App.
- If you are in the European Economic Area, the United Kingdom, or Switzerland and believe your rights have been infringed, you may complain to your local data protection authority.
We have not appointed a data protection officer or a representative in the EU or the UK. The App gives us no personal data about you. The only information that ever reaches us is what you choose to include when you write to us (section 20), the routine server logs kept by this website's host (section 17), and two kinds of report from Apple: only if you opted in, the crash reports and aggregated statistics Apple shares with developers (section 18), and Apple's sales and subscription reports about OweMe Pro (section 9). Apple provides both without your name or Apple Account, we cannot link them to you, and they contain nothing from your ledger. We do not sell personal information.
16 International transfers
We transfer nothing anywhere, because we receive nothing from the App. Your iCloud copy is stored by Apple in data centers Apple chooses, which may be outside your country, under Apple's iCloud terms and privacy policy; the logo lookups are answered by Apple and Google servers that may likewise be outside your country, under their policies; and an OweMe Pro purchase is processed by Apple's App Store, on servers Apple chooses, under Apple's terms and privacy policy.
17 This website
This website (https://owe-me.app) is a set of static pages. Our pages do not set cookies or include analytics, advertising or tracking. Fonts, scripts and images are served with the site itself. It has no forms that submit data and no login.
Hosting is provided by Cloudflare, Inc. (Cloudflare Pages). Cloudflare processes connection data, such as IP address, request time, requested page and browser user agent, to deliver and protect the site. Depending on the security features enabled, it may also use security cookies. See its privacy policy and Cloudflare cookie information. We do not download or analyze those logs, and we do not use them to identify you.
18 Apple diagnostics and beta builds
If you have opted in to "Share With App Developers" in the iOS Settings app (under "Privacy & Security", then "Analytics & Improvements"), Apple may share crash reports and aggregated usage statistics for the App with us through Apple's developer tools. Apple provides them without your name or Apple Account; they carry technical details such as the device model, the iOS version, and the time of a crash, and no content from your ledger. This is Apple's program, governed by Apple's Privacy Policy, and it is optional; you can turn it off there at any time. If we look at those reports, we use them only to fix bugs. The App itself contains no crash-reporting code.
Beta builds
If you install the App through Apple's TestFlight, Apple's TestFlight terms apply as well: Apple sends us crash logs from beta builds and any feedback or screenshots you choose to submit through TestFlight. That is the only additional data a beta build can produce; the App itself is unchanged.
19 Changes to this policy
We may update this policy when the App changes or the law changes. The current version is always at this page, and the "Last updated" date at the top tells you when it changed. In the App, a "Privacy Policy" link at the bottom of the Account screen opens this page in every version of the App from [first App version whose Account screen shows the link, normally 1.0.0] onward; earlier builds show no link. The Terms are linked from this page. Because the App has no accounts, we cannot email you. A version of the App that adds a new place your data can go (a new network request, a new service provider, or a new kind of stored data) will show you a one-time notice inside the App the first time you open it. The notice describes the change, links to this page, and appears before the new request is made. We will not add a new network request or service provider without that notice. Such changes are also described in that version's App Store release notes and in the change log below. Smaller changes are noted in the change log only.
Change log
Each entry below names the first App version (as shown at the bottom of the Account screen) to which it applies.
- September 17, 2026 (applies from OweMe 1.0.0, build 1): first version of this policy.
20 Contact
- Name: Palmora Technologies LLC
- Legal form: a limited liability company (LLC)
- Address: 12925 SW 207th Ln, Miami, FL 33177, United States
- Telephone: +1 305-636-8767
- Email: [email protected]
- Website: https://owe-me.app
Email is the fastest way to reach us. If you email us, we receive your email address and whatever you write. We use it only to answer you, do not add it to any list, do not share it, and delete the correspondence once your question is resolved or within twelve months, unless we need to keep it to handle a legal claim. Please do not send your ledger or anyone else's personal details unless we ask for them to solve a specific problem.