Summary
- We process the financial records you enter only to provide Cevixa to you — and, in shared spaces, to that space’s members.
- We don’t sell your data or use it for advertising. The app contains no third-party advertising, analytics or marketing tracking.
- We don’t connect to your bank. You add your own records.
- Receipt text is read on your phone; the image is sent to our server only when you save the record, and it is stored encrypted.
- You can export your data at any time and delete your account from inside the app.
- Demo mode runs entirely on your device and sends no data to our server.
Controller and contact
Cevixa is developed and provided by Ahmet Kutay Karacair, who is the controller of your personal data.
For any privacy question or request: destek@appcevixa.com
Data we process
Account information
- Sign-in provider identifier: the unique account identifier Apple or Google creates for you.
- Email address is not stored: we do not request your email from Apple. Google includes your email address at sign-in; it is not saved to your account or used.
- Name: Apple provides it only on first sign-in and only if you share it; Google provides it if it is on your profile. It is shown to other members of your shared spaces.
- Session and provider tokens: needed to keep you signed in and to revoke Sign in with Apple when you delete your account. They are stored hashed or encrypted on the server.
- Preferences: language, main currency, time zone and notification preferences.
Financial records (what you enter)
- Income, expenses and refunds: amount, currency, date, category, description and exchange rate used.
- Budgets, bills and subscriptions, payment status, shopping lists and your custom categories.
- Change history of records (who changed what and when).
- Rows of CSV files you import; unconfirmed previews are deleted after 7 days.
Descriptions and notes may contain personal information. Please don’t write other people’s sensitive information in these fields.
Receipt images
When you add an expense from a receipt, text recognition happens on your phone (Apple Vision); the image is not sent anywhere at this stage. When you save the record, the image is converted into a JPEG with metadata such as location removed, and stored encrypted together with the merchant name and item names and quantities. Receipts may show your name, address or the last digits of your card.
Shared spaces
When you join a Home or Trip/Group space, your membership, role, the records you add to that space, “paid by” and “bought by” details, and receipt images of shared expenses are visible to all members of that space. Records in your personal space are never shared with any shared space.
Notifications
If you turn on server reminders for shared bills, we store your device’s push address (APNs token) encrypted. Personal reminders are scheduled only on your device.
Technical data
- App version and platform (for compatibility checks).
- IP address: used for short-lived rate limiting to prevent abuse.
- Error logs: server logs never contain amounts, descriptions, receipt content or session tokens.
What we don’t collect
We don’t collect bank credentials, card numbers, contacts, location, the advertising identifier (IDFA) or in-app behavioural analytics.
Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Creating your account and signing you in | Provider identifier, name, session tokens | Performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Storing your records, showing summaries and reports, converting currencies | Financial records, receipts, preferences | Performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Running shared spaces | Name, membership, shared records | Performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) |
| Sending shared bill reminders | Push address, bill details | Performance of a contract at your request; iOS asks for notification permission separately |
| Keeping the service secure, preventing abuse, making backups | IP address, technical logs, encrypted backups | Legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) |
| Legal obligations and responding to requests | Information you share in your request | Legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)) |
We don’t use your data for automated decision-making or profiling.
Sharing and international transfers
We don’t sell your personal data or share it with anyone for advertising. Data reaches third parties only in these cases:
- Apple: for Sign in with Apple, revoking it on account deletion and (if you enable them) delivering notifications.
- Google: to verify your identity if you sign in with Google.
- Hosting: service data is kept on a server we operate; the company providing the server infrastructure is technically in a position to access it.
- Shared space members: only the information you add to that space, as described above.
- Authorities: when required by applicable law.
Exchange rates come from the European Central Bank’s public reference data; no personal data is sent to the ECB.
Because Apple’s and Google’s servers are located outside Türkiye and may be outside the EU, sign-in and notification operations involve international transfers of personal data. These transfers rely on the safeguards provided for in Chapter V of the GDPR and Article 9 of the KVKK.
Retention and deletion
- While your account is open, your records are kept.
- Deleted records stay in “Recently deleted” for 30 days and are then permanently removed together with their receipt images.
- Unconfirmed CSV previews are deleted after 7 days.
- Encrypted backups are kept for at most 30 days.
When you delete your account
In the app, go to Profile → Delete account (step-by-step instructions are on the Support page).
- All your sessions end immediately, access to your data stops and notifications are turned off.
- Your personal records, receipts and change history are permanently erased from our live systems — normally within minutes, and at the latest within 24 hours.
- If you used Sign in with Apple, your Apple authorisation is revoked.
- Records you added to shared spaces remain there so the other members’ history stays intact, but your name and account link are removed and they appear as “Former member”. Shared spaces you own and haven’t handed over become read-only archives for the remaining members.
- Copies in encrypted backups expire automatically within 30 days. If a backup is ever restored, deleted accounts are deleted again; they don’t come back.
We recommend making a copy first with Profile → Export my data. Deletion cannot be undone.
Security
- All traffic between the app and our server is encrypted with HTTPS (TLS).
- Receipt images, provider tokens and push addresses are stored encrypted with separate keys. Backups are encrypted.
- Your session key is stored in the iPhone Keychain, bound to that device.
- The database sits on a network that isn’t reachable from the internet, and the app server connects to it only over an encrypted connection.
No system is entirely risk-free. If a personal data breach occurs, we will notify the competent authority and, where required, you, within the legal deadlines.
Your rights
Under GDPR Articles 15–22 and KVKK Article 11 you have the right to access your data, have it corrected or erased, restrict or object to processing, receive a portable copy, learn which third parties it was transferred to, and seek compensation for unlawful processing.
You can do most of this yourself in the app: edit your records, get a machine-readable JSON copy with Export my data, and close your account with Delete account.
For anything else, email destek@appcevixa.com. Because we do not store email addresses, we may ask you for additional information from within the app to verify that the request is yours. We respond free of charge within one month at the latest.
If you’re not satisfied with our response, you can lodge a complaint with the data protection authority in your EU country of residence or, in Türkiye, with the Personal Data Protection Board (KVKK).
This website
appcevixa.com uses no cookies, analytics or third-party tracking code. Fonts are served from our own server. No visitor access logs are kept for this site.
Other
Children
Cevixa is not designed for children under 16, and we don’t knowingly collect data from this age group.
Changes
When we update this policy we change the effective date. We announce significant changes in the app or on this page.