Barya

Privacy

Barya collects nothing, because there is nowhere for it to send anything. The app makes no network requests at all.

Effective 14 September 2026 · applies to Barya 1.0.0 on iPhone

In one line

Your spending stays on your phone.

There is no account to make, no sign-in, no server, no analytics, no advertising, no tracking and no third-party software development kit inside the app. Nothing you type, photograph or import is transmitted anywhere, and I have no way of seeing any of it.

That is not a promise about how the data is handled once collected. It is that the data is never collected: the app has no code that opens a network connection.

What Barya stores

On your device, and only there.

Your ledger. Every expense you record, with its amount, the category you filed it under, and the date and time. It is kept in a database in the app's private storage on your phone, encrypted with AES-256. The encryption key is held in the iOS Keychain, not in the app and not written down anywhere else.

Your settings. Budgets, categories, currency, appearance, text size and whether the app lock is on. The same private storage, the same encryption.

A backup copy. Unless you switch it off, Barya keeps a plain-text JSON copy of your ledger in its own documents folder, so a reinstall or a new phone can pick up where the old one left off. That folder is included in your own iCloud device backup if you have iCloud backup turned on, which means the copy travels through your Apple account and not through mine. The copy is not encrypted, which the app says in those words in Settings rather than implying more. Turn it off in Settings → Backup, and erasing the ledger deletes it.

Camera and photos

The receipt never leaves the phone.

When you scan a receipt, Barya asks iOS for camera access and takes one photograph. That image is written to the app's temporary cache, read by Apple's own on-device text recognition, and deleted immediately after.

The image is never uploaded, never added to your photo library, and never sent to any recognition service. The whole scan works with the phone in airplane mode, which is the simplest proof of it.

Camera access is asked for only when you open the scanner, and declining it leaves the rest of the app working exactly as before.

Statements

The PDF is read where it sits.

When you import a bank or card statement, you pick the file yourself through the system file picker; Barya cannot see your files otherwise. The PDF's text is extracted on the phone. If the statement is a scan rather than typed text, the page images are written to the app's temporary cache, read by the same on-device text recognition, and deleted.

Barya never connects to your bank, asks for banking credentials, or sends the statement anywhere. It reads the file you handed it, shows you the rows it found, and writes only the ones you keep ticked.

Face ID and the app lock

Barya asks, iOS answers.

Turning on the app lock makes Barya ask the operating system to confirm it is you, using Face ID, Touch ID or your device passcode. Barya receives a yes or a no. Your face, your fingerprint and your passcode are handled entirely by iOS and are never available to the app.

When you export

You choose where it goes.

Exporting a CSV or a JSON backup writes the file to the app's temporary folder and hands it to the iOS share sheet. Where it goes next is whatever you pick: Files, Mail, a message, a cloud drive. Once it leaves through the share sheet it is covered by whatever you sent it to, not by this policy. The exported files are plain text so a spreadsheet can open them, which means they are readable by anything that can read the file.

What Apple sees

The purchase, not the ledger.

Buying Barya is a transaction between you and Apple. Apple handles the payment and gives me sales figures in aggregate: how many copies sold, in which countries. I never receive your name, your email, your card details or any way to identify you. Apple's handling of that purchase is covered by Apple's privacy policy.

Apple may also report a crash to me if you have crash sharing enabled in your iOS settings. Those reports come from Apple, are anonymous, and contain no part of your ledger. That is a setting on your phone, not something Barya turns on.

Your rights

You already hold everything.

Because there is no server, there is no request to file. Your data is on your phone, in your hands:

  • To read it, open the app, or export a CSV.
  • To take it elsewhere, export a CSV or a JSON backup.
  • To correct it, tap any row in the Ledger.
  • To delete it, use Settings → Backup → Erase all, which clears the ledger and the backup copy, or delete the app, which removes everything.

I cannot delete your data for you, recover it for you, or look at it, because I never have it. That cuts both ways, and it is the trade the app is built around.

Children

Rated for everyone.

Barya is a calculator and a list. It collects no personal information from anybody, of any age, and it has no content, no messaging, no links out and no advertising. It is not directed at children specifically, but nothing in it puts a child at risk.

Changes

If this ever changes, it changes here.

If a future version of Barya ever needed to send something somewhere, it would be asked for in the app, described on this page, and declared in the App Store's privacy card before that version shipped. The date at the top of this page says when it was last revised.

Contact

Ask me directly.

Barya is made by Dustine Jao in Manila, Philippines. Questions about this policy, or about anything the app does, go to the person who wrote it.

Email
dustinejao@gmail.com

Usually answered within two or three days.