Privacy Policy
Effective Date: June 16, 2026 App: Winnie Operator: Winnie, a sole proprietorship operated by Austin Beckett Contact: support@winnie-app.com
At a Glance
Winnie is a personal financial planning app. Here is what you should know upfront:
- No bank linking. Winnie never connects to your bank, brokerage, or any financial institution. All financial information is entered by you manually.
- No ads inside Winnie. Winnie does not show you advertisements. We do run ads for Winnie on other platforms (such as Facebook and Instagram), and — only with your permission — we measure how those ads perform. See "Advertising and Measurement" below.
- Tracking is your choice. Before using your device's advertising identifier, we ask for permission through Apple's App Tracking Transparency. If you decline, we rely only on privacy-preserving, aggregate measurement that does not identify you.
- We never sell your data. We do not sell or rent your personal information, and we never share your financial data, goals, name, or email for advertising.
- Guest mode available. You can use Winnie without creating an account. In guest mode, your data stays on your device and is never transmitted to any server.
1. Information We Collect
Account Information
When you create an account, we collect:
- Display name — the name you choose during onboarding
- Email address — your email or Apple Private Relay address (if you use Sign in with Apple's "Hide My Email" feature)
- User ID — a unique identifier generated by Firebase Authentication
Passwords are hashed and managed by Firebase Authentication. We never store or have access to your password in plain text.
Profile Information (Optional)
You may optionally provide:
- Avatar selection — a choice from preset illustrations (no photo uploads)
- Age range — a broad range (e.g., 25–34), with a "Prefer not to share" option
- Gender — with a "Prefer not to share" option
All profile fields are optional and can be left blank or set to "Prefer not to share."
Financial Information (User-Entered)
You may enter financial information including:
- Monthly take-home income
- Savings rate and savings balance
- Retirement balance
- Savings goals (names, target amounts, current balances, target dates)
- Contributions toward goals
- Savings plans and projections
All financial data is entered manually by you. Winnie does not connect to banks, brokerages, credit cards, or any external financial service. We have no access to your actual account balances, transactions, or financial accounts.
Preference Data (Local Only)
The following preferences are stored on your device in UserDefaults and are never transmitted to our servers:
- Appearance mode (light, dark, or system)
- Onboarding draft state (cleared on completion)
- Goal sorting and filtering preferences
- Whether you have seen certain informational screens
Notification Preferences
If you enable weekly savings reminders, your preferred day and time are stored in your account to schedule local notifications on your device. Winnie does not use remote push notifications.
Guest Mode
If you use Winnie without creating an account, a random session identifier is stored on your device in UserDefaults. This identifier is used only to associate your local data within the app. No account is created, no data is transmitted to any server, and the identifier has no connection to your identity.
Advertising and Attribution Data
If — and only if — you grant permission through Apple's App Tracking Transparency, we and our advertising partner Meta may process a limited set of measurement data: your device advertising identifier (IDFA), a Meta-assigned anonymous identifier, and app events such as installs and Winnie+ purchases. This is used solely to measure the performance of ads we run for Winnie on other platforms. If you decline, your IDFA is not used. See "Advertising and Measurement" below.
2. What We Do Not Collect
Winnie does not collect any of the following:
- Location data
- Contacts or address book
- Photos, camera, or media library access
- Microphone or audio data
- Health or fitness data
- Biometric data (Face ID / Touch ID are handled by iOS, not by Winnie)
- Browsing or search history
- Clipboard contents
- Crash reports or diagnostic logs (we do not use Crashlytics or any crash reporting service)
- Call logs or SMS data
We collect your device advertising identifier (IDFA) only if you grant permission through App Tracking Transparency, and only for the ad measurement described in "Advertising and Measurement." If you decline, it is not collected or used.
3. How We Use Your Information
We use your information for the following purposes only:
- Core functionality — to store your goals, contributions, savings plans, and projections so you can track your financial progress
- Partner collaboration — to share relevant financial data between linked partners (see "Partner Data Sharing" below)
- Authentication — to sign you in and secure your account
- Local notifications — to send weekly savings reminders at your chosen day and time, processed entirely on your device
- Purchase management — to manage your Winnie+ access via Apple's StoreKit framework and RevenueCat's entitlement service (see "Third-Party Services" below)
- Analytics — to understand how features are used so we can improve the app. We collect anonymous usage events (e.g., "goal created," "plan saved") via Firebase Analytics. These events are not tied to your financial data and do not include goal names, amounts, or any personally identifiable information.
- Advertising measurement — to understand which of the ads we run on other platforms bring new people to Winnie, so we can advertise efficiently and keep Winnie free of in-app ads and subscriptions (see "Advertising and Measurement" below)
What We Do Not Use Your Information For
- Showing advertisements inside Winnie
- Selling or renting your information to third parties
- Sending marketing or promotional emails
- Building advertising profiles about you
- Sharing your financial data, goal contents, name, or email for advertising
- Training machine learning models
4. Advertising and Measurement
Winnie shows no advertisements inside the app and has no subscription. To sustain the app, we run ads for Winnie on third-party platforms — primarily Meta (Facebook and Instagram). To spend our advertising budget responsibly, we measure which of those ads lead to app installs and Winnie+ purchases.
App Tracking Transparency
When it becomes relevant, Winnie presents Apple's App Tracking Transparency prompt asking whether you allow tracking.
- If you allow: your device advertising identifier (IDFA) may be used to match an install or purchase back to an ad you saw, giving us more accurate measurement.
- If you decline or take no action: we do not use your IDFA. We rely solely on Apple's privacy-preserving, aggregate measurement (SKAdNetwork / AdAttributionKit), which does not identify you individually.
You can change your choice at any time in iOS Settings > Privacy & Security > Tracking. Declining does not disable or limit any feature of the app.
What we share for measurement
For this measurement we use the Meta SDK and our purchase provider, RevenueCat. The information involved is limited to:
- Your device advertising identifier (IDFA) — only if you allowed tracking
- A Meta-assigned anonymous identifier
- App events such as installs and Winnie+ purchases (including the purchase amount)
We never share your name, email address, goals, contributions, income, or any other financial details with Meta. Meta processes this information in accordance with its own privacy policy: https://www.facebook.com/privacy/policy/
5. Partner Data Sharing
Winnie allows two people to link their accounts as partners to plan finances together. When you link with a partner:
Shared between partners:
- Display name and avatar
- Savings goals (names, target amounts, current balances, contributions)
- Savings plans and projections
- Activity history (contributions, goal completions)
- Financial profile (income, savings rate)
Never shared with your partner:
- Secret goals — goals you mark as secret are enforced as private by our database security rules. Your partner cannot see, access, or know about them. This is not just a UI setting; it is enforced at the database level.
- Your email address
- Your password or authentication credentials
Both partners consent to data sharing when they link their accounts via invite code. Either partner can leave the partnership at any time.
6. How We Store Your Data
Guest Mode
In guest mode, all data is stored locally on your device using SwiftData (Apple's on-device database). This data:
- Is included in your device's iCloud or local backups
- Is deleted when you uninstall Winnie
- Is never transmitted to any server
Authenticated Mode
When you create an account, your data is stored in Google Cloud Firestore:
- Encrypted in transit via TLS (Transport Layer Security)
- Encrypted at rest by Google Cloud's infrastructure
- Offline cache — Firestore maintains a local cache so the app works without an internet connection. Changes sync automatically when connectivity is restored.
Security Measures
- Firebase App Check with Apple's App Attest — verifies that requests to our database come from the authentic Winnie app
- Firestore Security Rules — enforce that users can only access their own data (and shared data for linked partners). These rules are enforced server-side and cannot be bypassed by the app.
- Cryptographic UUIDs — all entity identifiers are randomly generated UUIDs
- No unauthenticated access — all database reads and writes require a valid, authenticated user
Logging
Winnie uses Apple's `os.log` framework for on-device diagnostic logging during development. These logs stay on your device, are never transmitted to our servers, automatically redact sensitive information (financial amounts, personal details), and are not collected, aggregated, or analyzed by us.
7. Third-Party Services
Winnie uses the following third-party services:
- Firebase Authentication (Google) — user sign-in and account management. Receives your email and display name.
- Cloud Firestore (Google) — cloud database for authenticated users. Stores all data you enter.
- Firebase App Check (Google) — verifies authentic app requests. Receives a device attestation token.
- Cloud Functions for Firebase (Google) — server-side operations such as invite-code validation. Receives request-specific data.
- Firebase Analytics (Google) — anonymous feature-usage analytics. Receives anonymous event data (e.g., "goal created"), device type, and OS version. Never receives goal names, amounts, or other content you enter.
- StoreKit (Apple) — on-device purchase processing. Handles purchase transactions.
- RevenueCat (RevenueCat, Inc.) — validates your purchase with Apple and manages Winnie+ access. Receives an anonymous app user identifier and purchase transaction data, and forwards purchase events to Meta for the ad measurement described above. Never receives your name, email, or financial data.
- Meta SDK (Meta Platforms, Inc.) — measures the performance of ads we run on Meta platforms. Receives app events (install, purchase), a Meta anonymous identifier, and your device advertising identifier (IDFA) only if you allow tracking. Never receives your name, email, goals, or financial data.
All payment processing remains through Apple.
Relevant third-party privacy policies:
- Google: https://policies.google.com/privacy
- Apple: https://www.apple.com/legal/privacy/
- RevenueCat: https://www.revenuecat.com/privacy
- Meta: https://www.facebook.com/privacy/policy/
Services we do not use:
- No in-app advertising networks (we do not show ads in Winnie)
- No crash reporting services (no Crashlytics)
- No social media login SDKs
- We do not sell your personal information to data brokers
8. Data Retention and Deletion
Active Account
Your data is retained for as long as your account exists and you continue to use the service.
Account Deletion — Solo User
If you delete your account and are not linked to a partner, all of your data is permanently deleted, including your user profile, all goals and contributions, all savings plans, all activity history, any unused invite codes, and your couple document and financial profile.
Account Deletion — Partnered User
If you delete your account while linked to a partner:
- Your user profile is deleted
- Your secret goals are deleted
- Shared goals, contributions, plans, and activities remain accessible to your partner
- Your partner is notified that you have left the partnership
This ensures that your partner does not lose shared financial planning data they also contributed to.
Guest Mode
If you use Winnie in guest mode, uninstalling the app removes all data. There is nothing to delete on our servers because no server account was created.
Invite Codes
Invite codes for partner linking expire after 7 days and are automatically cleaned up.
How to Delete Your Account
You can delete your account at any time from Profile > Account Info within the app. Deletion is immediate and cannot be undone.
9. Your Rights and Choices
- Access your data — All data you have entered is visible within the app at any time.
- Correct your data — You can edit your profile, goals, contributions, and plans directly in the app.
- Delete your data — You can delete your account from Profile > Account Info. See "Data Retention and Deletion" above.
- Manage ad tracking — You can allow or deny tracking at any time in iOS Settings > Privacy & Security > Tracking. Denying does not affect any app feature.
- Revoke Apple Sign-In — If you signed in with Apple, you can revoke Winnie's access in iOS Settings > [Your Name] > Sign-In & Security > Sign in with Apple.
- Disable notifications — You can disable savings reminders in the app or revoke notification permission in iOS Settings.
- Use guest mode — You can use Winnie without creating an account, keeping all data on your device.
- Data export — To request a copy of your data, contact us at support@winnie-app.com.
10. International Users
Winnie is operated from Ontario, Canada. If you create an account, your data is processed and stored by Google Cloud Firestore, which operates data centers in the United States and other countries. Where you allow ad tracking, Meta may process the limited measurement data described above in the United States. By creating an account, you consent to the transfer and processing of your data outside your country of residence.
11. Children's Privacy
Winnie is not directed at children. We do not knowingly collect personal information from children under the age of 13. If you believe that a child under 13 has provided personal information through Winnie, please contact us at support@winnie-app.com, and we will take steps to delete that information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Effective Date" at the top of this page. Your continued use of Winnie after changes are posted constitutes your acceptance of the updated policy. When feasible, we will communicate material changes within the app.
13. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Winnie Austin Beckett support@winnie-app.com https://www.winnie-app.com/support