Privacy Policy
Effective date: June 10, 2026
Iyas does not collect, store, transmit, sell, or share any of your personal data. We have no servers, no user accounts, no analytics, and no trackers. Your financial data lives on your iPhone and stays there.
This policy describes exactly what the app does with data, including the few optional features that use the network or Apple services. We wrote it to be specific rather than legalistic — there is no “data we may collect” boilerplate here, because we do not collect data.
1. Data we collect: none
Iyas is a fully on-device app. Everything you enter — accounts, income, expenses, installments, assets, goals, and your financial profile — is stored in a local database on your iPhone. We (the developer) have no technical means of accessing it. The app has no sign-up, no login, and no backend service of ours that it talks to.
2. On-device storage
Your data is stored in the app’s private container using Apple’s on-device database technology, protected by iOS’s standard data protection and your device passcode. If you delete the app, the local data is deleted with it (unless a copy exists in your personal iCloud — see sections 3 and 4).
3. Optional iCloud sync (Iyas Pro)
If you subscribe to Iyas Pro and have iCloud enabled, the app can sync your data between your own devices using Apple’s CloudKit private database. This means:
- The data goes only to your personal iCloud account, encrypted in transit and at rest by Apple.
- It is technically inaccessible to us — the CloudKit private database can only be read by your Apple ID on your devices.
- Apple’s handling of iCloud data is governed by Apple’s Privacy Policy, not by us.
If you do not subscribe to Pro, or do not enable iCloud, no data leaves the device at all.
4. Device backups
Like any iOS app, Iyas’s local data is included in your normal iPhone backups (iCloud Backup or a computer backup) if you have them enabled. Those backups are managed by Apple/iOS and belong to you.
5. Optional exchange-rate refresh
The app can optionally refresh currency exchange rates and precious-metal prices so that multi-currency totals stay accurate. When you enable this:
- Fiat exchange rates are fetched from open.er-api.com.
- Gold/silver prices are fetched from api.metals.dev (only if you opt in and provide your own API key).
These requests ask only for public price data and contain no personal or financial information — no balances, no transactions, no identifiers from the app. As with any internet request, the contacted service technically sees your IP address; we receive nothing. If you never enable rate refresh, the app makes no such requests.
6. Camera and receipt scanning
If you use receipt scanning, the app asks for camera permission and reads the receipt using Apple’s on-device text recognition (Vision). The photo and the recognized text are processed entirely on your phone and never uploaded anywhere. You can revoke camera access at any time in iOS Settings.
7. On-device AI (Apple Intelligence)
The “Ask Iyas” assistant and the smart extraction features (for example, turning pasted bank SMS text or statements into transactions) are powered by Apple’s on-device Foundation Models, available on devices with Apple Intelligence enabled. Your questions and your financial data are processed on the device; they are not sent to us or to any external AI service by the app. Interactions through Siri are handled by Apple according to Apple’s own privacy practices.
8. Face ID / Touch ID
You can lock the app behind Face ID or Touch ID. Biometric authentication is performed entirely by iOS; the app never sees, stores, or transmits your biometric data — it only receives a yes/no result from the system.
9. Purchases
Iyas Pro is purchased through Apple’s App Store and billed to your Apple ID. Payment is handled entirely by Apple: we never receive your name, payment details, or billing address. The app checks your subscription status locally through Apple’s StoreKit framework.
10. Analytics and third parties
The app contains no analytics SDKs, no advertising frameworks, and no third-party trackers of any kind. This website is a set of static pages and likewise contains no analytics or tracking scripts. The Arabic pages load the Cairo font from Google Fonts, which means your browser requests font files from Google’s servers when viewing those pages.
11. Children
Iyas is a personal-finance tool and is not directed at children under 13. We do not knowingly collect any data from anyone — including children — because the app does not collect data at all.
12. Changes to this policy
If the app’s behavior ever changes in a way that affects privacy — for example, a new optional network feature — we will update this policy, change the effective date at the top, and describe the change plainly. The current version is always at iyas.idemery.com/privacy.html.
13. Contact
Questions about privacy? Email iyas@idemery.com.