← Cost

Privacy Policy for Cost

Last updated: [9th Sep, 2026]

Cost does not collect your data. There is no account, no sign-in, no analytics, no advertising and no tracking. The developer operates no server and receives nothing about you or your spending.

This policy explains where your data does live, and the few cases where the app hands something to Apple or to a server you choose yourself.

What Cost collects

Nothing. Cost contains no analytics or advertising software and no third-party code of any kind.

Where your data is kept

On your device. Your spending records, categories, tags, notes, the knowledge base the app builds from your corrections, and the receipt images you share are stored in Cost's own container on your device.

In your iCloud, if iCloud is switched on. Cost syncs your records through Apple's CloudKit into the *private* database of your own Apple Account, so your iPhone and your Mac show the same ledger. That data is held by Apple under your account and is not accessible to the developer. Receipt images are not synced — they stay on the device they arrived on.

Deleting the app removes the data on that device. The iCloud copy is managed where every app's is: Settings → your name → iCloud.

How receipts are read

Receipt text is recognised on your device using Apple's Vision framework, and interpreted on your device by Apple Intelligence. The receipt is not uploaded for analysis.

If you configure your own model server

Cost can instead send receipts to a large language model you host yourself (Settings → Local Model) — typically software such as Ollama or LM Studio on your own Mac or another machine on your network.

If you turn this on, the text of a receipt is sent to the address you entered. Images are never sent: the app transcribes them on your device first and transmits only the resulting text. That address is your choice and under your control, and whatever happens to the data there is governed by the software you are running, not by Cost. The feature is off unless you configure it, and by default Cost only offers it where Apple Intelligence is unavailable.

Location

Location is optional, off by default, and attached to a spending record only when you tap to add it. Cost takes a single position fix at that moment; it never tracks you in the background.

To turn the position into a readable place name, the coordinates are sent to Apple's geocoding service. Apple's handling of that request is covered by Apple's own privacy policy. The resulting place name and coordinates are stored with the record, in the same places as the rest of your data.

Camera and photos

Photos you capture or choose are stored in Cost's container so the receipt stays with the record. They are not uploaded anywhere.

Siri, Shortcuts and Spotlight

If you use the Siri shortcuts, your records are indexed on your device so Spotlight and Siri can find them. What Siri itself does with a spoken request is covered by Apple's privacy policy. Dictation in the app's text fields is the system keyboard's own — Cost has no microphone access and requests none.

Children

Cost is not directed at children and collects no data from anyone.

Your rights

Because the developer holds no data about you, there is nothing to request, correct or delete from us. Your records are yours: editable and deletable in the app, and removable from iCloud through your device settings.

Changes to this policy

Any change will be posted at this address with a new date above.

Contact

hashspace.apps@gmail.com