Privacy policy
Updated: October 11, 2026
Edgie is currently in a closed beta test: a small circle of invited people uses it, it is free, and it may change or work with interruptions. These texts describe how the app works today; a legal review has not been done yet.
Who we are
- Edgie is an app that works out how much you can spend until the end of the month. It is made by one developer. It is currently a closed beta test. Questions and data requests: support@edgieapp.com.
- Data controller: an individual developer, [NAME — to be filled in by the owner]. The server is in Germany (Hetzner), so data is stored in the European Union. For users in Russia: your data is stored in the EU, not in Russia.
What data we receive
- Account: name, login (email or phone), password as a hash. We never see or store the password itself.
- Everything you enter: accounts and balances, transactions with names, amounts and dates, recurring bills and income, goals, categories, settings, time zone.
- Bank screenshots are read on your phone. Normally the images are not sent to the server: only the recognised lines of text are sent. The exception is AI parsing, and only if you agreed to it (see “Parsing screenshots with AI”). Photos and logos of accounts stay on your phone.
- Pasted SMS text and a statement file (CSV) are sent to the server to be parsed. The text and the file are not saved; only the transactions and the column format stay in the database.
- Feedback: the message text, a contact if you give one, the app version.
- Email: the address you gave as a login or for password recovery is stored with the account. We send password-recovery and service emails to it.
- Crashes: app and iOS version, error text and technical data, a random installation number and, if you are signed in, your account number. There is no name or email in the report, but in rare cases they may end up in the error text by accident.
- Usage events: a random installation number, the event name and technical details (for example, which screen is shown and which answer you chose in the first-launch questions). If you are signed in, events are linked to your account number. Import learning samples are stored separately and only with your consent (see below).
- Technical data: IP address. The server uses it to limit request rates (counters are kept for up to 2 days), and the web server writes it to its request log (address, time, page address, browser type and the referring page; no request content). We count site visits from this log: only daily totals per page and source are kept in the database, without IP addresses or browser data. The site has no third-party counters or cookies.
- Launch list on edgieapp.com: if you leave your email, we keep the address, the date and the page variant (language) so we can write once about the launch. We delete it on request: support@edgieapp.com.
Why
To calculate the main number, show history and reports, sync data between devices, protect the service from password guessing and fix errors. We do not use it for advertising, profiling or selling data. There are no third-party advertising or analytics services in the app.
Where it is stored
- On a rented server at the hosting provider Hetzner in Germany. The connection between the app and the server is protected by HTTPS.
- A copy of the database is made every night. The last 30 copies are kept on the same server with no separate encryption. In addition, an encrypted copy (AES-256) is sent to Backblaze B2 cloud storage in the EU and kept there for about 31 days. The hosting provider may also take disk snapshots.
Who can see the data
- You, and the people you gave access to. A guest sees the main screen and the calculation but cannot change anything. The second owner of a shared budget sees and edits the shared data. Personal accounts stay hidden from others. Access can be revoked in settings.
- The owner of the service. The admin panel shows: feedback messages with contacts, crash reports (with emails and numbers scrubbed), event statistics by anonymous installation numbers, subscription statistics and the launch-list emails. Accounts, transactions and balances are not in the panel. But the developer technically has access to the whole server and database, and we do not look into data without need (to fix a fault or answer your request).
Who we share data with
- Hosting: Hetzner (Germany) runs the server that holds the data. Backups: Backblaze B2 (EU region) stores encrypted copies of the database; we hold the encryption key, Backblaze cannot read them. Cloudflare serves the site address (DNS) and forwards mail sent to support@edgieapp.com to the developer’s personal mailbox.
- Exchange rates: the server requests general rates from the National Bank of Serbia, open.er-api.com and frankfurter.dev. Your data is not sent in these requests.
- Account logos: if you tap the icon next to the account name or the “Find logo online” button, the app (from your phone, not through our server) sends the name you typed for the account to Wikidata (if the bank is not in the built-in list) and the bank’s website address to Google (google.com/s2/favicons) to get an icon. For a cash account the currency’s country code goes to flagcdn.com. These requests contain no balances or transactions, but those services see the phone’s IP address. Nothing is sent while you type the name: the search runs only when you tap the icon, and there is no separate switch. If you do not want the name to reach third parties, do not open the logo picker or choose a picture from Photos instead.
- Apple: installation through TestFlight and the App Store follows Apple’s rules. With Sign in with Apple we receive an account identifier from Apple and, if you allow it, your name and email (the email may be a private Apple relay address). Purchases are switched off in the beta.
- Email service: emails from the app (password recovery, service emails) are sent by Resend (EU region, Ireland). It receives your email address and the text of the email.
- Screenshot parsing with AI (only with your consent): Anthropic (USA), the Claude model. It receives the screenshot and the text recognised from it (see “Parsing screenshots with AI”).
- There are no ads, trackers, third-party analytics or sale of data.
For how long
- Budget data: as long as the account exists. After you delete the account, budgets where you are the only owner are deleted from the server immediately. They disappear from nightly copies when those rotate (up to 30 days) and from the Backblaze B2 copy in about 31 days. How long disk snapshots are kept depends on the hosting provider.
- A shared budget stays with the second owner; your personal accounts and your membership are deleted.
- Events and crash reports stay after the account is deleted, no longer linked to the account but with the same random installation number. They are kept for up to 12 months: once a day the server deletes records older than that.
- An email from the launch list is kept until you ask to delete it; deleting the account does not affect it.
Parsing screenshots with AI
- This is optional and stays off until you agree. The app asks once, when a screenshot from an unfamiliar bank cannot be parsed on its own; you can turn it off in settings (“Data sources”).
- What is sent: the screenshot (up to five at a time) and the text recognised from it on the phone, through our server to Anthropic (the Claude model). A screenshot may show merchant names, people’s names, amounts and balances.
- Anthropic processes them to return the list of transactions and, under its commercial API terms, does not train its models on them. We do not store the image: it stays in the server’s memory only for the duration of the request and never reaches the database or logs.
- What we store: the parsing rule for your bank’s screen (without your data) and, to check it, a few recent confirmed screens of that bank as text together with what you saved. This is your budget’s data: it is deleted with the budget and the account, after 12 months, and is included in your data export. We also keep a record of AI calls (date, number of tokens, cost, no content); it is deleted with the account.
- When the same banking app has already been learned for several people, the server may build a common rule for that bank. For this the model receives the rules and anonymised screen lines (amounts, dates, names and numbers replaced with markers), not your data.
- Legal basis: your consent. You can withdraw it in settings; what has already been parsed stays in your budget.
Import learning samples
- This is optional and off by default. If you turn on “Help Edgie learn banks” in settings (or agree in the prompt shown at the first unfamiliar bank), after a screenshot is parsed we store an anonymised sample.
- What is stored: lines from the screen with names, amounts and numbers removed; a pseudonymous account hash (it lets us find and delete the samples but not read your name); the bank name.
- What is not stored: the image itself, names, amounts, account or card numbers.
- Period: 12 months, then the sample is deleted. Samples are deleted with the account and are included in your data export. You can withdraw consent in settings.
- Your answer to “Which bank is this?” is stored with your account and is visible to the service owner in aggregate statistics in the admin panel. In a shared budget, if you consented, your samples may include lines from shared screens that show the other person’s transactions; the sample still contains no names or amounts.
- Legal basis: your consent.
Data protection in Europe (GDPR)
- Controller: an individual developer, [NAME — to be filled in by the owner]. Contact: support@edgieapp.com.
- Legal bases: contract (to run the service you ask for), consent (AI parsing and learning samples; it can be withdrawn), legitimate interest (crash reports and anonymous events: to fix errors and understand what is used).
- Transfers outside the EU: Backblaze, Resend, Cloudflare and Anthropic are US companies; we use their European regions where possible and standard contractual terms.
- You have the right to get a copy of your data, to correct and delete it, to object to processing and to withdraw consent (see “Your rights”). You have the right to complain to the data protection supervisory authority of your country.
- For users in Russia: data is stored in the EU, not in Russia.
Your rights
- Export your data: Settings, Account, “Password and data”: “Download operations” (CSV) and “Download all data” (JSON).
- Delete the account and all data: same place, “Delete account”. A password is required, or signing in with Apple again if you use Sign in with Apple.
- Change the password and sign out everywhere: same place.
- Other requests (correct data, get explanations, delete an email from the launch list, feedback messages): support@edgieapp.com.
Children
The app is not intended for children under 16. We do not check age at sign-up.
Changes
If the policy changes, we will update the date on this page. We will tell you about material changes in the app.