Privacy Policy — Vavilon Finance

Privacy Policy

Version 4.4  ·  September 3, 2026  ·  Effective for all regions

1. Who We Are

Vavilon is a personal finance app for iOS and macOS. Developer: individual developer registered in the Republic of Kazakhstan. Contact: support@getvavilon.app.

We build a tool for personal financial tracking. We are not a bank, financial institution or investment advisor.

2. What Data We Process

2.1 Data You Enter

  • Financial records: accounts, transactions, loans, assets, goals
  • Names, phone numbers and emails of third parties (in the Loans section only)
  • App settings: currency, language, biometrics
Core principle: by default, all financial data is stored exclusively on your device in a local SwiftData database. It is protected by iOS Data Protection (device-level file encryption tied to your passcode/biometrics) while your device is locked, and loan client data (name, phone, email and notes) additionally receives field-level AES-GCM 256-bit encryption before being stored (see Section 5). We have no access to your data, and we do not create user accounts. Cloud sync (iCloud) is a separate, off-by-default feature that you enable yourself (see Section 3).

2.2 Data We Do Not Collect for Tracking or Advertising

We do not build advertising profiles, do not use behavioral analytics SDKs (no Firebase, Amplitude, Mixpanel), do not sell your data, and do not track you across other apps or websites.

  • Geolocation
  • Advertising identifiers (IDFA)
  • Data about other apps on your device

As disclosed in our App Store Privacy Nutrition Label, some data types are collected and linked to your identity, but only when you actively use a specific opt-in feature: your name and email if you enable Family or Tanda group sharing (visible to the members of that group, not to us — see Section 3.2); a randomly generated device identifier for the referral program (Section 6); and your purchase history via Apple's StoreKit for subscription management (Section 7). We do not create user accounts and do not collect your name or email outside of these specific features.

2.3 Technical Data

When using the AI assistant, our proxy server receives: your device IP address (not stored), a minimized financial context (rounded figures and best-effort removal or masking of common identifiers — see Section 4.1), and the request version. Logs are not kept longer than 24 hours.

When using the referral program, our server receives a randomly generated device identifier, the referral code and an App Store transaction identifier — see Section 6. To determine the device's country when contacting the referral server (for personal-data-localization compliance purposes), we use the "IP Geolocation by DB-IP" database (db-ip.com), distributed under a Creative Commons Attribution 4.0 license. The IP address used for this check is not retained longer than 14 days and is used only to determine country.

2.4 Other External Services

The app contacts two additional external services unrelated to AI:

  • Brandfetch — retrieves logos of known banks and services by domain name (e.g. "netflix.com") for display in your transaction list. Only the domain name is sent, no personal data. Not used for devices with region Russia or Belarus.
  • Open Food Facts — recognizes product names from a scanned barcode in the "Cart" feature. Only the barcode itself is sent, no personal data. Not used for devices with a CIS-region currency (RUB, KZT, UZS, KGS, AZN, BYN, TJS, AMD, TMT).
  • OFD.kz — for Kazakhstan receipt scanning, the app may open the official receipt URL encoded in the QR code at consumer.ofd.kz to retrieve the receipt contents. The transmitted data is the receipt link or receipt identifiers from the QR code, not your app profile.
  • proverkacheka.com — for Russia receipt scanning, the app may send fiscal receipt identifiers from the QR code (FN, FD/document number and FP/fiscal sign) to retrieve the receipt contents. These identifiers are used only for a one-time receipt lookup and are not linked to your identity by Vavilon.

2.5 Security Device Token

On first launch, Vavilon may create a random device token used for anti-abuse protection of App Attest and server requests. This token is generated independently of the referral program consent, does not contain your name, email, phone number or financial records, and is not used for advertising or profiling. It is used only to confirm that requests come from the app installation that created them.

3. Where Data is Stored

Data Type Where Stored Who Has Access
Financial records (by default) User's device (SwiftData) User only
Loan client data (by default) User's device (encrypted) User only
iCloud sync (optional) Private Apple CloudKit database in your personal iCloud account You only. Not available for devices with region Russia, Belarus or Kazakhstan
Data you share via Family Private Apple CloudKit database, accessed via CKShare You and members you explicitly invite
Data you share via Tanda Private Apple CloudKit database, accessed via a shared invite link (CKShare) You and anyone who joins via the group link — see 3.2
Subscription settings Apple StoreKit / App Store Apple + user
AI requests (supported regions) Anthropic API via proxy in Georgia Anthropic (minimized) — only after your explicit consent (see Section 4.2)
AI requests (Russia, Belarus, Kazakhstan) Not processed Arkad is fully unavailable regardless of consent (see Section 4.2)
AI requests (other blocked regions) Not processed Arkad is fully unavailable regardless of consent (see Section 4.2)
Referral data Vavilon server (not stored in Russia, Belarus or Kazakhstan) Vavilon — unavailable in Russia, Belarus, Kazakhstan and the blocked regions listed in Section 4.2. Requires separate explicit consent (see Section 6)

3.1 iCloud Sync

iCloud sync is a separate feature that is off by default. You enable it yourself in Settings or the first time you use Family or Tanda. Once enabled, your app data (including loan records and their contacts) syncs to the private CloudKit database in your personal iCloud account — it is not accessible to us and is protected by your Apple ID.

For devices with region Russia, Belarus or Kazakhstan, iCloud sync is unavailable regardless of user preference, in accordance with personal data localization requirements.

3.2 Family and Tanda

Family and Tanda features let you voluntarily share specific data with members via Apple's sharing mechanism (CKShare). Depending on the feature, this may include: net worth and monthly expenses (Family); group name, contribution amount and currency, dates, and a member's name, email and status (Tanda). Both features require iCloud sync to already be enabled.

Family uses a closed invitation — data is only accessible to those you explicitly invite via Apple Family or by email.

Tanda uses a shareable link invitation — group data is accessible to anyone who opens and accepts that link, not only the person you originally sent it to. If the link reaches someone else (forwarded, posted in a group chat, etc.), they will be able to join the group. Do not post a Tanda invite link publicly, and only share it with people you trust.

4. Arkad AI Assistant and AI Import

Arkad is an AI assistant. His advice is for informational purposes only and does not constitute financial, investment or legal advice.

4.1 Rounding and Data Minimization

Before sending a regular Arkad chat request to the AI system, the app rounds absolute financial figures (income, expenses, free cash flow, debt, assets, net worth, etc.) to 2 significant digits directly on your device — so the AI receives the scale of your finances, not the exact amount. Your goal names are not included in regular chat requests. The app also attempts to remove or mask common identifiers such as names, contacts, account and card numbers before sending data, but arbitrary free text can never be guaranteed to be fully anonymized.

4.2 Consent and Regional Routing

Before you use Arkad for the first time — regardless of your region — the app shows a dedicated consent screen that clearly states which provider will process your requests and where your data goes. Without your explicit consent, Arkad is not used. You can withdraw consent at any time in Settings, which disables Arkad until you consent again.

  • KZ · UZ · KG · AZ · US and other supported regions With consent, requests are processed by Claude API (Anthropic, USA) via a secure proxy.
  • Russia · Belarus · Kazakhstan Arkad is fully unavailable regardless of consent. We do not provide access to Arkad for users with device region Russia, Belarus or Kazakhstan, due to these countries' personal-data-localization requirements.
  • Brazil · all 27 EU member states · United Kingdom · Switzerland · Turkey · India · Colombia · Mexico Arkad is fully unavailable regardless of consent while the required transfer safeguards and impact assessments are not in place.

4.3 What Regular Arkad Chat Does Not Send

  • User names and third-party names
  • Exact transaction amounts
  • Your financial goal names
  • Account and card details
  • Contact information

4.4 AI Providers

Anthropic Privacy Policy: anthropic.com/privacy

4.5 AI Bank Statement Recognition (PDF)

The "AI Import" feature allows recognition of bank statements in PDF format from unknown banks. Before sending data to the AI system, the app applies best-effort masking on your device:

  • Card numbers replaced with "****"
  • Phone numbers replaced with "***"
  • Full names replaced with "[NAME]"
  • Email addresses replaced with "[EMAIL]"

The minimized text (no more than 6,000 characters) is sent to the AI provider only after separate AI-import consent and under the same regional routing rules described in Section 4.2. Because bank statements can contain arbitrary text, Vavilon cannot guarantee that every identifier will be recognized and removed.

AI Import limits:
Free — 3 free recognitions (total)
Premium — 10 recognitions per month (resets on the 1st)

Bank statements from known banks (Halyk, Sberbank, T-Bank and others) are recognized locally on your device without sending data to AI systems.

5. Third-Party Data (Loan Clients)

The Loans section allows storing contact information of people you have lent to or borrowed from: names, phone numbers, emails.

By default, this data is stored only on your device in encrypted form and is never transmitted anywhere. If you choose to enable iCloud sync (see Section 3.1), this data — like the rest of your app data — syncs to your personal private CloudKit database, which remains accessible only to you and is never shared with us or third parties. You are responsible for obtaining consent from these individuals to store their data in your app, as required by your local law.

6. Referral Program

The app may offer a referral program that lets you invite other users and earn bonuses for invitations that lead to a Premium subscription.

Before you use the referral program for the first time, the app shows a dedicated consent screen describing what data is transmitted and why. Without your explicit consent, the feature is not used.

To operate the program, our server receives a randomly generated device identifier (not linked to your name, email or phone number), the referral code, and the App Store transaction identifier required to verify a purchase. This data is not stored in Russia, Belarus or Kazakhstan and is processed with protective measures, including anonymization upon deletion. Our server determines the device's country from its IP address using the DB-IP geolocation database (see Section 2.3); regional eligibility is also verified server-side, independently of the app's own settings.

Since July 30, 2026, requests to the referral server are additionally protected by device-based authorization: each device receives a unique secret token that confirms that requests to your referral data are sent by you and not someone else. If you enable iCloud sync, your referral identifier is migrated to your iCloud account identifier (CloudKit) along with your full bonus and invitation history — this preserves your progress when switching to sync, while the identifier itself remains unlinked to your name, email or phone number.

  • The referral program does not create a bank or payment account — bonuses are granted as temporary access to Premium features and have no cash value
  • You may request deletion of data associated with your participation in the referral program via support@getvavilon.app; some aggregated data needed for fraud prevention and other users' statistics is anonymized rather than fully deleted

The referral program is not available for users with device region Russia, Belarus, Kazakhstan, Brazil, any EU member state, the United Kingdom, Switzerland, Turkey, India, Colombia or Mexico due to data-localization and international-transfer compliance requirements.

7. Subscription and Payments

All payments are processed exclusively through the Apple App Store (StoreKit). We never receive or store bank card, payment system or financial account data.

Refund matters are governed by Apple's policy: support.apple.com.

8. User Rights

Data Deletion

Since all data is stored on your device by default, you have full control over deletion: Settings → Delete All Data, or simply delete the app from your device. If you enabled iCloud sync, also disable it in Settings to stop storing data in CloudKit.

Data Export

CSV data export is available free of charge to all users. Excel and PDF export formats require a Premium subscription.

Withdrawing Consent for Arkad and the Referral Program

You can withdraw your consent to Arkad's data processing and/or to the referral program at any time in the app's Settings — this immediately disables the relevant feature.

Deleting Referral Program Data

You may request deletion of data associated with the referral program (device identifier, referral code, bonus history) via support@getvavilon.app.

For EU Users (GDPR)

  • Right of access — all data is accessible within the app
  • Right to erasure — implemented via the reset function and, for referral data, via a support request
  • Right to portability — implemented via CSV export
  • Right to object — for AI processing questions: support@getvavilon.app

For US Users (CCPA)

  • Right to know what data is processed — described in this policy
  • Right to delete — via the reset function and, for referral data, via a support request
  • Right to opt out of sale — we do not sell personal data

For Russian Users (Federal Law No. 152-FZ)

Personal data of users from Russia is processed only on their device. iCloud sync, the referral program and the Arkad AI assistant are unavailable for RU-region users.

9. Regional Compliance

Region Law Status
🇷🇺 Russia Federal Law No. 152-FZ ✓ Device only. iCloud sync, referral program and Arkad unavailable
🇧🇾 Belarus Personal Data Law ✓ Device only. iCloud sync, referral program and Arkad unavailable
🇰🇿 Kazakhstan Personal Data Law ✓ Device only. iCloud sync, referral program and Arkad unavailable
🇧🇷 Brazil LGPD ⏳ Arkad and the referral program are unavailable pending the required transfer safeguards and impact assessment. Financial tracking, iCloud, Family and Tanda remain available
🇺🇿 🇰🇬 🇦🇿 Central Asia Local laws ✓ Device only, iCloud sync optional, Arkad with consent
🇪🇺 European Union GDPR ⏳ Arkad and the referral program unavailable pending the required transfer safeguards and impact assessment
🇬🇧 🇨🇭 🇹🇷 🇮🇳 🇨🇴 🇲🇽 Other blocked regions Local privacy laws ⏳ Arkad and the referral program unavailable pending the required transfer safeguards and impact assessment
🇺🇸 United States CCPA (California) ✓ No sale of data, Arkad with consent

10. Children and Minors

Vavilon is intended for users 17 years and older (App Store age rating: 17+). We do not intentionally collect data from minors. If you become aware that a minor is using the app, please contact us.

11. Policy Changes

When we make material changes to this Privacy Policy, we will notify users through an app update. The date of the last change is always shown in the document header. Continued use of the app after changes constitutes acceptance of the new version.

12. Contact

For privacy questions: support@getvavilon.app

We respond within 72 hours.