Privacy

Privacy Policy

Learn how Cofra stores expense data, uses private iCloud synchronization, handles support correspondence, and hosts this website.

Last updated:

Policy identity

Cofra Documentation operates Cofra and is responsible for this policy. More about the operator is available at www.craftzcatdev.blog. Privacy questions can be sent to privacy@cofra.site.

What this policy covers

This policy covers the Cofra app for iPhone and iPad, the Cofra widget, this documentation website, and information you choose to send when requesting support.

Information Cofra handles

Cofra handles the information you enter to provide its expense-management features:

  • Expense amounts in a validated ISO 4217 currency, spending dates and times, optional notes, category assignments, and optional monthly fund assignments.
  • Category names or overrides, symbols, ordering, archive state, and related timestamps.
  • Monthly spending-fund names, allowances, category defaults, and related timestamps.
  • App-generated identifiers and timestamps needed to maintain records and synchronize changes.
  • Your appearance, in-app language, and default entry-currency preferences, stored locally on the device.
  • A replaceable widget snapshot containing native aggregate totals by stored currency, expense counts, dates, calendar and time-zone identifiers, a focus currency code, and seven daily totals. The widget snapshot does not contain individual notes or category names.

Expense search runs on your device against existing expense, category, and fund records. This release does not create a Spotlight or Siri search index and does not send search queries to a Cofra server.

Cofra does not require a Cofra account. The audited release does not include advertising, tracking, payment processing, social sharing, or third-party analytics and crash-reporting SDKs.

Local storage and private iCloud synchronization

Cofra stores expenses, categories, and monthly funds on your device using SwiftData. When iCloud is available for Cofra, those records synchronize through your private iCloud/CloudKit database so they can remain consistent across devices signed in to the same Apple Account.

Apple states that only the user can access a private CloudKit database by default, that the user owns its content, and that private records are not visible in the developer portal. Private synchronization still transfers data off your device to Apple's iCloud service. Review Apple's CloudKit private database documentation and Apple Account and iCloud privacy information for details about Apple's processing.

The widget snapshot is stored in Cofra's local App Group so the widget can display recent aggregates. It is a presentation cache, not a second authoritative financial database, and Cofra replaces it as expense data changes.

How Cofra uses information

Cofra uses app data only to provide the features you request, including expense entry and editing, category and fund management, summaries, on-device search and filtering, local CSV export of expenses, private iCloud synchronization, and widget presentation.

Cofra does not sell expense information or use it for advertising or cross-app tracking. Apple processes synchronized information as the provider of iCloud and CloudKit under Apple's own terms and privacy policy.

Documentation website and Vercel

This website is hosted on Vercel. Vercel may process operational request information such as IP address, approximate location derived from IP address, browser or device information, requested URL, timestamps, and diagnostic or security logs. Vercel describes this processing in its Privacy Notice.

This website uses Vercel Web Analytics to measure aggregated documentation traffic. Vercel documents that Web Analytics does not use cookies, does not store identifiers that track people across other websites, and identifies visitors with a hash created from the incoming request that is discarded after 24 hours. Each recorded data point may include a timestamp, page URL, referrer, filtered query parameters, approximate geolocation, browser, operating system, and device type. See Vercel's Web Analytics privacy documentation.

This website also uses Vercel Speed Insights to measure Core Web Vitals and related performance metrics. Vercel documents that Speed Insights records anonymous data points that are not tied to an individual visitor or IP address. Each data point may include the route, URL, network speed, browser, device type, operating system, country, a Web Vital value, and a limited attribution selector. See Vercel's Speed Insights privacy documentation.

Website analytics and Speed Insights are separate from the Cofra iOS app. They do not receive expense records, categories, funds, or iCloud data. The current Cofra Docs source does not load advertising technology or third-party advertising trackers, and it does not set application cookies or use browser local storage. Operational logs are controlled by Vercel and retained according to the applicable Vercel plan and service configuration. Cofra does not use website logs, Web Analytics, or Speed Insights to profile visitors for advertising.

Support correspondence

When you contact support, the message may include your email address, the content you write, and attachments you choose to send. Your email provider and the operator's email provider process that correspondence to deliver and respond to it.

Please do not send passwords, Apple Account credentials, full expense histories, CloudKit records, financial account details, or unredacted screenshots. Support correspondence is retained only as reasonably needed to respond, maintain necessary records, prevent abuse, and meet legal obligations. You may request deletion of a support message, subject to obligations that require retention.

Retention, deletion, access, and export

App records remain on your device and, when enabled, in your private iCloud database until you delete or change them. You can edit and delete individual expenses in Cofra and manage categories and monthly funds from the app. Changes synchronize between devices when iCloud is available, so propagation may not be immediate.

Deleting the Cofra app does not necessarily delete data already stored in iCloud. Apple provides controls for reviewing and deleting data stored by third-party apps in iCloud; see Apple's iCloud storage guidance.

You can view your expense, category, and fund data in Cofra. Version 1.2.0 and later provide a local UTF-8 CSV export of expenses: Settings exports the full ledger, and Expenses exports the currently visible search and filter results. The file is written on your device and shared through the system share sheet. Cofra does not upload the export to a Cofra-controlled server. Categories and funds appear in that file as names and identifiers on expense rows, not as standalone exports. Import is not included.

Because expense records live in your private CloudKit database, the operator cannot retrieve, export, or delete those records for you by default.

Age rating

The App Store age rating for the current Cofra release is 4+. That rating describes the live store listing. Cofra is a personal expense ledger; this policy does not claim that the app is directed at children.

Policy changes

This policy may change when Cofra adds features, providers, or data practices. Material updates will be published on this page and the last-updated date will change. The policy in effect when information is processed governs that processing.