Privacy Policy

Last updated 15 August 2026 · Applies to Pahust for iPhone, iPad, Mac and Apple Watch.

The short version. Pahust has no account system, no server, no analytics and no third-party SDKs. Nothing about you or your money is sent to the developer or to anyone else. Your plan lives on your device and, if you choose, in your own private iCloud database, which the developer cannot read.

1. What is collected

Nothing. Not anonymised, not aggregated, not "for improving the product". There is no analytics framework in the app, no crash-reporting service, no advertising identifier, no attribution SDK and no third-party code of any kind. The app's privacy manifest declares no collected data types and no tracking domains, which is why the App Store listing shows Data Not Collected.

There is no sign-in and no user record, because there is no server for one to live on.

2. Where your data is

Everything you enter — income streams, accounts, rules, planned expenses, goals, debts, the people they involve, balances you record, any photos you attach — is stored in a database on your device.

If you are signed into iCloud, that database is mirrored to your own iCloud private database so your iPhone, iPad, Mac and Watch see the same plan. This uses Apple's CloudKit private database, which is tied to your Apple Account. The developer has no access to it, cannot query it, and receives no notification that it exists. If you are not signed into iCloud, the app keeps working entirely locally and tells you so in Settings.

A small summary of the next payday (the date, the transfers and their ticked state) is also written into a shared container on the same device so the widgets and the Watch app can display it. That container never leaves the device.

3. What the app sends over the network, and to whom

Pahust makes network requests to exactly two hosts. Both are public endpoints that require no key, no account and no authorisation.

Host What for What is in the request
query1.finance.yahoo.com Currency-pair quotes used to suggest planning rates (for example USDRUB=X, BTC-USD). Fetched once per launch, and again if you tap "Update all rates". The currency pair, and nothing else the app adds. The request carries a generic desktop-browser User-Agent string.
iss.moex.com Public Moscow Exchange quotes, used only in the optional Investments sheet when you have typed a ticker. The ticker symbol you typed.

These requests contain no account, no key, no device identifier and nothing about your plan. They do not say who is asking; they ask what a dollar or a share costs. As with any request from any app, the operator of that service can see the IP address it came from and what was asked for — that is a property of the internet, not something Pahust adds to.

The rate refresh can be switched off entirely in Settings → Planning → Update on launch. The app is fully functional offline: the forecast never waits on a network call and never fails because one failed.

4. Permissions the app may ask for, all optional

Declining any of these leaves the rest of the app fully usable.

5. The on-device assistant

On devices running iOS or macOS 26 with Apple Intelligence enabled, an optional assistant can draft an expense from a note you typed, suggest where unallocated money could go, and explain a figure in prose. It uses Apple's on-device model framework and runs on your device. Nothing is sent to the developer, and the app does not send your plan anywhere in order to use it.

It can never write to your plan — it returns proposals you choose to apply — and no number the app states ever comes from it. Every figure in Pahust is deterministic arithmetic over your own inputs. The assistant can be switched off completely in Settings → Assistant, and where the framework is unavailable the feature is simply absent.

6. Diagnostics and logs

The app writes technical logs on the device using Apple's unified logging. By design these cannot contain your money: log messages are compile-time constants, and values are attached through a mechanism that has no way to publish a balance, a name or an amount. Logs stay on the device and are never transmitted.

7. Exports and backups

You can export your plan as a spreadsheet, CSV, PDF, a calendar file, or a complete JSON backup, and you can create an encrypted local backup with a passphrase. These files are produced only when you ask for them, and they go wherever you send them. Once a file leaves the app it is under your control and this policy no longer governs it — exported files contain real amounts, including when the app's "hide amounts" mode is on.

8. Purchases

If you buy Pahust Plus, the transaction is handled entirely by Apple. The developer never sees your name, your payment details or your address — only Apple's anonymous confirmation, through the system, that a purchase exists on your Apple Account. Apple's own privacy policy governs that transaction.

9. Children

Pahust is not directed at children and collects nothing from anyone, including children.

10. Deleting your data

Settings → Erase everything removes every record the app holds. Because the database is mirrored through your own iCloud account, erasing on one device removes it from the others as they sync. Deleting the app removes its local database with it. There is nothing held anywhere else, and therefore no deletion request to send anyone.

11. This website

This site is a handful of static files. It sets no cookies, runs no analytics, loads no fonts, scripts or images from anyone else, and has no embedded third-party content. Whoever hosts it can see the ordinary facts of a web request — your IP address and which page you asked for. Pahust adds nothing to that and receives nothing from it.

12. Changes

If this policy changes, the date at the top changes with it, and a material change will be noted in the app's release notes. There is no mailing list to notify, because there is no mailing list.

13. Contact

Questions about this policy, or about anything the app does: tepoyanpet@gmail.com.

Pahust is made by Tepoyan Studio.