Effective 8 September 2026
Privacy policy
Dramless is a personal budgeting app. This page explains what it collects, where that data lives, who else can see it, and how to get rid of it.
The short version
- Your money data is kept on your device. Signing in is optional.
- If you sign in, the same data is copied to our cloud so your devices agree, and we store your account's email address and user id.
- We do not show ads, we do not sell or share your data, and we do not build profiles of you.
- You can wipe your data from your device and from the cloud at any time from Settings.
On your device
The iOS and Android apps keep everything in one SQLite database file on the device: your accounts and cards, categories, budgets, transactions, transfers, the currencies you enabled, and the exchange rates the app has downloaded. Signed out, nothing in that file leaves the device unless you export it yourself.
The browser app has no local database. While you are signed in it keeps a copy of your cloud data in your browser's storage so pages load without re-downloading, and it stores your chosen language, your display currency, and cached exchange rates there too. Signing out deletes that copy.
Signing in
Sign-in is optional and only exists to turn on cloud sync. There is no password anywhere in Dramless and no code to type. Sign-in runs through Supabase Auth with three methods:
- Sign in with Apple. Apple gives us a stable identifier for your account and, if you allow it, your email address. If you use Hide My Email, Apple gives us a private relay address instead of your real one, and that relay address is all we ever see. Sometimes no address is handed over at all, and the account works the same.
- Sign in with Google. Google gives us a stable identifier for your account and the email address on it.
- Email link (browser app only). You type an address, we mail a sign-in link to it, and opening that link signs you in.
You can link Apple, Google, and email to the same account, and unlink any of them as long as one remains. We store what the provider hands over — the identifier and the email address, when there is one — and nothing else about your provider account.
In the cloud, once you sign in
Signed in, your data is stored on our server so your devices stay in step. That is:
- your account's user id and email address;
- your ledger — accounts, cards, categories, budgets, transactions, transfers, counterparty names, and which currencies you enabled;
- the text of any bank message you imported (see below);
- a record of each row you deleted — the table, the row's key, and when it was deleted — so a delete on one device also happens on the others.
The server also computes reconciliation corrections over its copy of your ledger, so a balance shown on the web or through a connected app matches what a phone would show.
Exchange rates are not part of this: each device downloads its own copy and they are never uploaded.
Our database and sign-in run on Supabase, in its Frankfurt, Germany region (EU). This website and its endpoints run on Vercel, also in Frankfurt, Germany.
Bank message import
Dramless does not read the messages on your phone, and it never asks for permission to. You bring one message to the app yourself — by sharing it or pasting it — and the app parses the text on the device, with no network request. The part of the message that matched is saved alongside the transaction, so every imported figure stays traceable to the text it came from.
That saved text is treated like the rest of your ledger: it stays on the device while you are signed out, and it is copied to the cloud once you sign in. It is never written to logs.
Exchange rates
To convert between currencies, Dramless downloads a daily rate table from Exchange Rate API (open.er-api.com), at most once a day. That request carries no account, no identifier, no amount, and not even which currencies you use — it always asks for the same full table.
Connected AI apps
You can connect a third-party AI client to Dramless so it can read and edit your cloud data on your behalf. Nothing is connected unless you do it: authorization happens on our page, which shows you the client's identity, the address it will return to, and what it is asking for, before you approve or deny it.
An approved client reads and writes the cloud copy of your data as you — the same data described above. It cannot reach anything that only lives on your device. You can see every client you have approved at dramless.app/apps and revoke any of them; a revoked client loses access immediately.
Logs
The connected-apps endpoint keeps operational logs so we can tell whether the service is up and fast: an id joining the events of one request, which tool was called, whether it succeeded, how long it took, and the status our database returned. Those logs deliberately contain no user id, no client id, no credentials, no request contents, no response data, no amounts, and no imported message text. The iOS, Android, and browser apps send us no analytics of their own.
Who else is involved
- Supabase — hosts the database and runs sign-in.
- Vercel — hosts this website and the connected-apps endpoint.
- Apple and Google — identify you when you choose their sign-in.
- Exchange Rate API — serves the daily rate table, receiving no data about you.
- AI clients you have approved — read and write your cloud data until you revoke them.
There is nobody else. We show no ads, run no ad or analytics SDKs, and do not sell, rent, or share your data with anyone for their own purposes.
Keeping and deleting your data
- Reset app (iOS and Android, in Settings) deletes everything on the device. If you are signed in, it asks whether the cloud copy should go too or stay for your other devices.
- Remove all data from cloud (browser app, in Settings) empties your cloud data while leaving you signed in.
- Records of deletions are kept on the server for 180 days after the delete, then removed. They exist so a delete reaches your other devices.
- Cloud snapshots. The server takes a daily point-in-time copy of your data so a bad change can be rolled back. Snapshots are kept for 30 days, except that the most recent one is always kept — so a snapshot taken before you wiped your cloud data can outlive that window.
- Local backups on iOS and Android are files on your own device; the app keeps the last 7 and deletes older ones. They are not uploaded anywhere.
- Deleting your account. There is no in-app account deletion yet. Email a.svidchenkov@gmail.com from the address on your account and we will delete the account, its data, and its snapshots.
While your account exists, your ledger is kept as long as you keep it there — we do not expire it.
Children
Dramless is not directed at children. We do not knowingly collect data from anyone under 13, or under 16 where local law sets that age. If a child's account has been created, write to us and we will delete it.
Changes to this policy
When Dramless changes what it collects or who it involves, this page is updated and the effective date at the top changes with it. The current version is always here at dramless.app/privacy.
Contact
Questions, requests for a copy of your data, and deletion requests all go to a.svidchenkov@gmail.com.