1. What data Defter handles
Defter works with the following kinds of data, all stored locally on your device:
- Apple Card, Apple Cash, and Apple Savings data — read through Apple's FinanceKit framework, only after you tap "Connect Apple Wallet" and approve the system prompt. Defter reads transaction history, balances, and account metadata.
- Manually entered or imported transactions — anything you type, scan from a receipt, or import via CSV / OFX.
- Cards, budgets, savings goals, recurring rules, obligations, and preferences that you create inside the app.
- Chat history with Defter's on-device AI assistant (if you use the Ask tab).
- Receipt photos that you choose to scan. Photos are processed on-device by Apple's Vision framework and are not retained after text extraction.
2. Where the data lives
All app data is stored in Defter's private app sandbox on your iPhone, in an encrypted on-device database. It is included in your iCloud / encrypted iTunes backups according to the standard iOS behavior for app sandbox data.
Downloaded AI model files are stored in a system cache directory and are explicitly excluded from iCloud backup. iOS may reclaim them under storage pressure; Defter re-downloads on demand.
3. What we do not do
- We do not store your financial data on any server.
- We do not collect analytics, telemetry, crash reports, advertising IDs, or any device identifiers.
- We do not transmit your transactions, balances, card details, account numbers, budgets, goals, or chat messages off your device.
- We do not sell, rent, or share your data with anyone.
- We have no ability to access your data, even if compelled to — we don't have it.
4. Network requests Defter does make
Defter is offline-first. The only network calls it makes are:
- HuggingFace (huggingface.co) — only if you go to "AI Models" and choose to download a local language model. The request includes a model identifier and standard HTTP headers; it does not include any of your financial data. You can decline this entirely and use Apple Foundation Models instead (zero network).
- Apple Foundation Models — Apple's on-device system model. Inference runs locally on your iPhone. Apple's own privacy terms apply to that framework.
- Defter's bank-aggregation service — only if you connect a non-Apple bank through Plaid. See section 5 for the full story; the short version is that transactions pass through but aren't stored.
- Apple ID servers — required for Sign in with Apple, which is the identity mechanism for the optional bank connection. Standard Apple authentication applies.
5. Optional bank aggregation via Plaid
Defter offers an opt-in integration with Plaid to connect supported non-Apple US banks. This feature is disabled by default and clearly marked in Settings → Connect bank. When you opt in:
- You sign in with Apple Sign In. We use an anonymous, Apple-issued identifier as your per-device user id. We do not request your email or name.
- You authenticate with your bank inside Plaid Link, which loads in an in-app web view. We never see or store your bank username or password.
- Plaid issues an access token for the connected institution. We encrypt that token before storing it and use it only to fetch your data on your behalf.
- When the app pulls transactions, our server proxies the call to Plaid, normalizes the response, and forwards it to your iPhone. We do not store transaction bodies on our server — they pass through.
- You can disconnect at any time from Settings → Connect bank. Disconnect revokes the access token at Plaid and deletes the encrypted row from our database.
This service runs on infrastructure located in the United States; we don't log requests at the application layer.
6. Apple FinanceKit usage
If you connect Apple Wallet via FinanceKit (a separate, on-device feature), Defter reads Apple Card / Apple Cash / Apple Savings transactions and balances directly. FinanceKit data never leaves your device — this path doesn't involve Plaid or any other server. You can revoke FinanceKit access in iOS Settings → Privacy & Security → Financial Information or in Defter's settings.
7. Notifications
If you enable notifications, Defter schedules local notifications (statement close, payment due, budget thresholds, high utilization, balance reminders) using UserNotifications. These are generated entirely on your device. Defter does not send push notifications from a server.
8. Biometric authentication
If you enable Face ID / passcode lock, Defter uses Apple's LocalAuthentication framework. Biometric data never leaves the Secure Enclave; Defter only receives a yes/no result.
9. Children
Defter is not directed to children under 13 and does not knowingly collect data from them. If you don't opt in to a bank connection, no financial data leaves the device.
10. Your rights
You have full control over your data:
- Export everything as CSV from Settings → Export all data.
- Delete on-device data immediately from Settings → Account & data → Delete all on-device data. This clears every Defter model on your iPhone (cards, transactions, budgets, preferences, etc.).
- Disconnect a single bank from Settings → Connect bank → trash icon. Revokes the access token at Plaid and deletes the encrypted row from our database.
- Delete your entire Defter account from Settings → Account & data → Delete account. This permanently removes your account record, revokes every bank connection, and removes every session token. Then it wipes the on-device data and signs you out. There is no undo.
- Uninstall the app to delete everything on your device. If you used the optional bank connection and want that removed too, run "Delete account" before uninstalling, or email us (section 12) with the Apple ID you signed in with.
11. Changes
If this policy ever changes materially, the new version will be posted at this URL with an updated "Last updated" date. We don't push notifications about policy changes — please re-check this page if relevant.
Disconnecting a bank
When a bank connection is removed — by you, by a plan downgrade, or when a subscription ends — we delete the connection with our banking data provider, which revokes our access to that institution. Transactions and balances already synced remain in your account until you delete them or delete your account.
12. Contact
Questions: defter@mediterraai.com
Mediterra AI LLC