Privacy Policy — Troshkali

Last updated: 23 September 2026

Troshkali helps you decide whether you can afford a purchase before you make it. To do that it needs to know what you earn, what you have committed, and what you have spent. This page explains exactly what is stored, where it goes, and how to get rid of it.

For any question about this policy or your data, contact troshkalik@gmail.com.

What is collected

DataWhy
Email address and password To create and secure your account. Passwords are handled by Google Firebase Authentication and are never stored on Troshkali's servers.
Monthly income and fixed costs To calculate your safe-to-spend pool.
Savings goals — label, target amount, target date, amount saved To calculate how a purchase affects a goal.
Purchases and payment plans — item name, amount, date, category To track what you have spent and what is committed.
Written monthly analyses — the headline, reading and suggestion So a month's analysis is there when you come back to it, and so next month's can say whether the suggestion was kept.
Subscription status To know whether your account has Troshkali Pro.
Your currency and time zone To write amounts the way you write them, and to count your months and days from where you are rather than from where the server is. The time zone is read from your device; neither is used to locate you, and neither is shared with anyone.

Troshkali does not connect to your bank, and does not ask for card or account numbers. Everything above is entered by you. There is no advertising, no analytics SDK, and no tracking across other apps or websites.

The camera

Troshkali Pro can read a price off a price tag or a receipt so you do not have to type it in. If you use it, the app asks for camera permission the first time.

Photographs are never uploaded and never stored. The text is recognised on your device by Apple's Vision framework, which runs entirely offline. The picture exists only in memory while you are looking at it, and is discarded when you close the scanner — it is not written to your photo library, not saved by the app, and not sent to Troshkali's servers or to anyone else. The only thing that leaves the scanner is the number you confirm, which is filled into a form for you to check and edit, exactly as if you had typed it.

You can also choose an existing photo instead of taking one. Troshkali does not request access to your photo library to do this: the picker runs outside the app and hands back only the single image you select.

Who your data is shared with

Troshkali uses five processors, and nothing else:

ServiceWhat it receives
Google Firebase Authentication Your email address and password, to sign you in.
Fly.io (application hosting, Frankfurt) Everything listed in the table above, in transit, while the server handles your requests. Nothing is stored there.
Neon (PostgreSQL hosting, AWS Frankfurt) Everything listed in the table above, at rest.
Anthropic (the Claude API) Only if you have turned AI features on. You are asked once, before anything is sent, and you can turn them off again at any time under Settings → AI features — at which point nothing further is sent to Anthropic and the app writes your verdicts itself.

While they are on: when you ask for a verdict, the item name, the amount, your remaining monthly pool, days left in the month, and your goal's label and amounts are sent. When you ask for a written analysis of your spending, your monthly totals, spending by category, your pool and goal, the names and amounts of your payment plans, subscriptions and largest recent purchases, and last month's suggestion are sent. In both cases they are sent only so that Claude can write the explanation.

Your email address, your name and your account identifier are never sent. The affordability decision itself is computed on Troshkali's own servers by ordinary arithmetic — Claude only writes the wording, which is why turning this off costs you no numbers.
RevenueCat (subscriptions) Subscription and purchase events, linked to your Troshkali account identifier. Payment itself is handled by Apple; neither RevenueCat nor Troshkali sees your card details.

Your data is never sold, and never shared for advertising. It is not used to train any AI model.

Where your data is stored

In the European Union — the database is hosted in Frankfurt, Germany, and the application server runs there too, on Fly.io. Firebase, Anthropic and RevenueCat may process data outside the EU under their own safeguards.

How long it is kept

Until you delete it. Your account and everything in it stays as long as the account exists.

Deleting your account

In the app: Settings → Account → Delete account. This is immediate and permanent. It removes your budget, goals, purchases and payment plans from the database, and removes your sign-in credentials from Firebase. There is no recovery afterwards, and no separate request to make.

Deleting your account does not cancel an active App Store subscription — Apple handles that, under Settings → Apple Account → Subscriptions.

Your rights

You can access, correct, export or delete your data. Access and correction are built into the app; deletion is the button above. For an export, or anything else, write to troshkalik@gmail.com and you will get a reply within 30 days. If you are in the EU or EEA and believe your data has been mishandled, you may complain to your national data protection authority.

Children

Troshkali is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child has created an account, contact troshkalik@gmail.com and it will be removed.

Changes to this policy

If this policy changes materially, the date at the top will change and the app will say so before the change takes effect.