Privacy Policy
Last updated September 23, 2026
CashWard is built around one rule: your financial data stays on your device. There's no account, no sign-in, and no server — this policy is short because there's very little to explain.
01What CashWard stores
Everything you enter — household and person names, province of residence, account names and balances, transactions, income sources and compensation details, bills, subscriptions, budgets, debt terms, insurance policies and quotes, and any documents you choose to attach — is stored in a local database on your device only. CashWard never asks for and never stores your Social Insurance Number, banking passwords or PINs, or full credit/debit card numbers.
02CashWard doesn't connect to your bank
You enter balances and transactions yourself, or import them from a CSV, OFX, or QFX file you download from your own bank's website. That file never leaves your device.
03Documents you attach
You can attach a copy of a document — a bill or statement, an insurance policy or quote, a photo of one — to a bill, policy, or quote, so it can be opened from the screen it belongs to. Attached copies are stored inside CashWard's local database on your device, alongside everything else. CashWard never uploads them, never reads or analyzes their contents, and never extracts anything from them; it only keeps the copy and shows it back to you using Apple's built-in Quick Look preview. Because a bill or policy can contain account or policy numbers, licence details, or an address, attach only what you're comfortable keeping on the device. Adding a photo uses Apple's own photo picker, which lets CashWard receive only the specific photo you choose — CashWard never gets access to your photo library.
04Backups you create
Settings > Backup & Restore can save everything in CashWard — including attached documents — as a single file to a location you choose, such as a drive or a folder in iCloud Drive. That file is created and saved by your device; CashWard does not send it anywhere and has no copy of it.
A backup is not encrypted unless you set a password. Anyone who obtains the file can read everything in it. With a password, the contents are protected with AES-256 encryption, and there is no way to recover a forgotten password — not even for CashWard's developer.
You can restore a backup on this or another device from the same screen. CashWard also keeps a few automatic safety copies of your data in its own folder on your device — before a new version first opens it, and before a restore replaces anything — so you can recover if something goes wrong. These stay on the device, in the same data folder as the rest of your CashWard data, and are removed the same way as the rest of it (see 11).
05Face ID / Touch ID / device passcode (App Lock)
If you turn on "Require Face ID / Touch ID" in Settings, CashWard uses Apple's LocalAuthentication framework to lock the app behind your device's own biometric or passcode check. CashWard never sees, receives, or stores your biometric data or your passcode — the operating system handles the entire check and only tells CashWard yes or no.
06Apple Calendar
If you turn on "Sync to Apple Calendar" in Settings, CashWard creates a dedicated "CashWard" calendar and adds an event for each upcoming bill, subscription renewal, and payday — event titles include the item's name and dollar amount. Turning this off deletes the CashWard calendar and every event in it. If your device syncs its calendars through iCloud or another account, these events sync the same way any other calendar event does — that's a setting on your device, not something CashWard controls.
07Notifications
If you turn on bill reminders in Settings, CashWard schedules local notifications via Apple's UserNotifications framework, entirely on your device. There's no server involved, so there's nothing to send them through.
08iCloud sync (planned, not yet available)
When iCloud sync ships, it will use your own private iCloud account (Apple's CloudKit private database) — the same one-to-one relationship as iCloud Photos or iCloud Notes. CashWard's developer will not be able to see your synced data. This policy will be updated with full detail, and the App Store listing will disclose it, before that feature ships.
09No analytics, no tracking, no advertising
CashWard contains no analytics, advertising, or tracking of any kind. No third party ever receives your data.
10No account required
CashWard does not require you to create an account, sign in, or provide your name or email address to use any feature.
11Data deletion
Deleting a household, account, bill, policy, attached document, or other item removes it from the local database immediately. On iPhone and iPad, deleting the CashWard app removes its entire local database, attached documents, and safety copies from your device. On a Mac, moving the app to the Trash does not by itself remove your data, because it lives in a folder in your Library rather than inside the app — to remove everything, also delete CashWard's data folder (Settings > Backup & Restore > Show Safety Copies in Finder opens its Backups folder; the folder that contains it is the data folder). Because there's no server, there's no separate copy anywhere for CashWard's developer to delete on request — aside from any backup you've made yourself (a CashWard backup file, or an operating-system backup like Time Machine or an iCloud device backup), which CashWard has no visibility into.
12Children's privacy
CashWard is intended for adults managing their own household finances. It is not directed at children, and CashWard does not knowingly collect data from children.
13Changes to this policy
If CashWard's data practices change — most notably when iCloud sync becomes available — this page will be updated first, with a revised "last updated" date above, and the change will be reflected in the App Store listing.
14Contact
Questions about this policy can be sent to shadowteam@shadowaccess.ca.