Last updated: 23 September 2026
Troshkali helps you decide whether you can afford a purchase before you make it. To do that it needs to know what you earn, what you have committed, and what you have spent. This page explains exactly what is stored, where it goes, and how to get rid of it.
For any question about this policy or your data, contact troshkalik@gmail.com.
| Data | Why |
|---|---|
| Email address and password | To create and secure your account. Passwords are handled by Google Firebase Authentication and are never stored on Troshkali's servers. |
| Monthly income and fixed costs | To calculate your safe-to-spend pool. |
| Savings goals — label, target amount, target date, amount saved | To calculate how a purchase affects a goal. |
| Purchases and payment plans — item name, amount, date, category | To track what you have spent and what is committed. |
| Written monthly analyses — the headline, reading and suggestion | So a month's analysis is there when you come back to it, and so next month's can say whether the suggestion was kept. |
| Subscription status | To know whether your account has Troshkali Pro. |
| Your currency and time zone | To write amounts the way you write them, and to count your months and days from where you are rather than from where the server is. The time zone is read from your device; neither is used to locate you, and neither is shared with anyone. |
Troshkali does not connect to your bank, and does not ask for card or account numbers. Everything above is entered by you. There is no advertising, no analytics SDK, and no tracking across other apps or websites.
Troshkali Pro can read a price off a price tag or a receipt so you do not have to type it in. If you use it, the app asks for camera permission the first time.
Photographs are never uploaded and never stored. The text is recognised on your device by Apple's Vision framework, which runs entirely offline. The picture exists only in memory while you are looking at it, and is discarded when you close the scanner — it is not written to your photo library, not saved by the app, and not sent to Troshkali's servers or to anyone else. The only thing that leaves the scanner is the number you confirm, which is filled into a form for you to check and edit, exactly as if you had typed it.
You can also choose an existing photo instead of taking one. Troshkali does not request access to your photo library to do this: the picker runs outside the app and hands back only the single image you select.
Troshkali uses five processors, and nothing else:
| Service | What it receives |
|---|---|
| Google Firebase Authentication | Your email address and password, to sign you in. |
| Fly.io (application hosting, Frankfurt) | Everything listed in the table above, in transit, while the server handles your requests. Nothing is stored there. |
| Neon (PostgreSQL hosting, AWS Frankfurt) | Everything listed in the table above, at rest. |
| Anthropic (the Claude API) |
Only if you have turned AI features on. You are asked once, before
anything is sent, and you can turn them off again at any time under
Settings → AI features — at which point nothing further is sent to Anthropic and
the app writes your verdicts itself.
While they are on: when you ask for a verdict, the item name, the amount, your remaining monthly pool, days left in the month, and your goal's label and amounts are sent. When you ask for a written analysis of your spending, your monthly totals, spending by category, your pool and goal, the names and amounts of your payment plans, subscriptions and largest recent purchases, and last month's suggestion are sent. In both cases they are sent only so that Claude can write the explanation. Your email address, your name and your account identifier are never sent. The affordability decision itself is computed on Troshkali's own servers by ordinary arithmetic — Claude only writes the wording, which is why turning this off costs you no numbers. |
| RevenueCat (subscriptions) | Subscription and purchase events, linked to your Troshkali account identifier. Payment itself is handled by Apple; neither RevenueCat nor Troshkali sees your card details. |
Your data is never sold, and never shared for advertising. It is not used to train any AI model.
In the European Union — the database is hosted in Frankfurt, Germany, and the application server runs there too, on Fly.io. Firebase, Anthropic and RevenueCat may process data outside the EU under their own safeguards.
Until you delete it. Your account and everything in it stays as long as the account exists.
In the app: Settings → Account → Delete account. This is immediate and permanent. It removes your budget, goals, purchases and payment plans from the database, and removes your sign-in credentials from Firebase. There is no recovery afterwards, and no separate request to make.
Deleting your account does not cancel an active App Store subscription — Apple handles that, under Settings → Apple Account → Subscriptions.
You can access, correct, export or delete your data. Access and correction are built into the app; deletion is the button above. For an export, or anything else, write to troshkalik@gmail.com and you will get a reply within 30 days. If you are in the EU or EEA and believe your data has been mishandled, you may complain to your national data protection authority.
Troshkali is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child has created an account, contact troshkalik@gmail.com and it will be removed.
If this policy changes materially, the date at the top will change and the app will say so before the change takes effect.